Point-of-Sale Terminal Encryption for Payment Card Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern financial systems, sensitive payment card information is vulnerable to unauthorized access during transaction processing, leading to potential data breaches and costly consequences for affected customers.

Innovation Solution

Implementing cryptographic techniques such as symmetric key cryptography, public key infrastructure (PKI), and identity-based encryption (IBE) to encrypt payment card information at point-of-sale equipment, with re-encryption performed by a gateway using format-preserving encryption algorithms to secure data transmission and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If payment card information is transmitted in plaintext for processing, then transaction processing efficiency is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvetransaction processing efficiencyVSAvoidunauthorized access to payment card data
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption of payment card data at the point-of-sale terminal before transmission. The encryption is applied in advance to the data leaving the terminal, ensuring that any intercepted data during transmission is already encrypted and unusable to attackers. This preliminary protective action maintains security without impacting processing efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption layer that mediates between the point-of-sale terminal and the transaction processing system. The encrypted data serves as an intermediary form that preserves transaction integrity while preventing direct access to plaintext card information during transmission and storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to payment card data, then security is improved, but processing complexity increases

Engineering Contradiction:
Improvesecurity of payment card informationVSAvoidencryption and decryption operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service encryption where the point-of-sale terminal automatically encrypts its own output data without requiring external intervention. The terminal itself performs the encryption operation on data as it leaves the terminal, eliminating the need for separate encryption devices or complex centralized encryption management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies parameter changes by transforming the payment card data into an encrypted form with different cryptographic parameters. The data undergoes a parameter transformation through encryption algorithms, changing its state from plaintext to ciphertext while maintaining its essential transactional properties for authorized processing.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If sensitive data is stored for transaction processing, then transaction authorization capability is improved, but vulnerability to data breaches increases

Engineering Contradiction:
Improvetransaction authorization capabilityVSAvoiddata breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption of payment card data at the point-of-sale terminal before transmission. The encryption is applied in advance to the data leaving the terminal, ensuring that any intercepted data during transmission is already encrypted and unusable to attackers. This preliminary protective action maintains security without impacting processing efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption layer that mediates between the point-of-sale terminal and the transaction processing system. The encrypted data serves as an intermediary form that preserves transaction integrity while preventing direct access to plaintext card information during transmission and storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10817874B2Purchase transaction system with encrypted payment card data
Publication Date: 2020.10.27 MICRO FOCUS LLC
  • US10817874B2 patent drawing
  • US10817874B2 patent drawing
  • US10817874B2 patent drawing

AI summary

Systems and methods are provided for securing payment card information. A user may present a payment card such as a credit card to point-of-sale equipment. The point-of-sale equipment may encrypt the payment card information. An encryption algorithm may be used that takes as inputs a first part of the payment card information, a tweak formed by a second part of the payment card information, and an encryption key. The encrypted payment card information may be conveyed to a gateway over a communications network. The gateway may identify which encryption algorithm was used in encrypting the payment card information and may re-encrypt the payment card information using a format preserving encryption algorithm. A network-based service may be used to remotely perform functions for the gateway.