Secure Password Transfer for POS Terminals via Encrypted Security Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for transferring password-protected devices, such as point of sale terminals, fail to ensure stringent security requirements are met during manufacturing and deployment, particularly in transitioning passwords between locations without sharing access.

Innovation Solution

A method involving the generation of encrypted security files using one-way encryption functions and secure codes, allowing secure password changes at each location, ensuring devices are inaccessible with previous passwords and only accessible with new location-specific passwords, maintaining security throughout the transfer process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-protected devices are transferred between locations using conventional methods, then the transfer process is simple and fast, but security requirements are not met and passwords may be compromised

Engineering Contradiction:
ImprovesecurityVSAvoidtransfer process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating encrypted security files at the receiving location before the actual device transfer. These security files contain encrypted passwords that will be used to secure the devices during transit and at the destination, ensuring security is established in advance rather than during the transfer process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces encrypted security files as an intermediary mechanism between the shipping location and receiving location. These files contain encrypted password information that mediates the secure transfer process, allowing password changes without direct password sharing or complex manual security procedures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If passwords are shared between locations for device access, then device accessibility is maintained, but security is compromised and unauthorized access may occur

Engineering Contradiction:
Improvedevice accessibilityVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system extracts the password information from the direct communication channel between locations by encrypting it within security files. The passwords are taken out of the plain text form and embedded in encrypted format, allowing device accessibility to be maintained through the encrypted credentials while preventing unauthorized access

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter of password transmission from plain text to encrypted format. By transforming the password parameter through encryption using one-way encryption functions, the system maintains device accessibility for authorized users while significantly enhancing password security during transfer and storage

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security files are transmitted to shipping location, then password-protected devices can be secured during transit, but transmission security may be compromised

Engineering Contradiction:
Improvedevice security during transitVSAvoidtransmission security risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption of password information at the receiving location before transmission to the shipping location. This preliminary action ensures that the security files contain already-encrypted data, reducing the security risks during transmission since the sensitive information is already protected

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical or manual password transmission methods with cryptographic encryption mechanisms. Instead of physically securing passwords or using manual handoff procedures, the system uses one-way encryption functions and secure file transmission protocols to protect against transmission security risks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9635020B2Password-protected physical transfer of password-protected devices
Publication Date: 2017.04.25 VERIFONE INC
  • US9635020B2 patent drawing
  • US9635020B2 patent drawing
  • US9635020B2 patent drawing

AI summary

A method for password-protected physical transfer of password-protected devices including at a receiving location, generating at least one security file including an encrypted element generated using a one-way encryption function utilizing at least one secure code, transmitting the at least one security file to a shipping location at which the password-protected devices are located, at the shipping location, using at least one shipping location password, loading the at least one security file into at least one password-protected device, shipping the at least one password-protected device to the receiving location and at the receiving location, employing the at least one secure code to supply an input to the at least one password-protected device and employing the at least one security file to enable establishment of at least one receiving location password for the at least one password-protected device which replaces the at least one shipping location password.