Remote POS Terminal Disable via Security Violation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Point of sale (POS) terminals are vulnerable to tampering and data theft, with thieves using dummy devices or modifying legitimate terminals to steal transaction card data, necessitating a system for detecting fraudulent activity and remotely disabling compromised terminals.

Innovation Solution

A terminal management server with a data transceiver and processor that receives data from POS terminals indicating security parameter violations, classifies these as potential fraudulent activity, and sends commands to disable the terminal's functionality, including the ability to discontinue transaction processing until an override authentication code is entered.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If POS terminals are deployed to enable various payment methods, then customer payment options and merchant functionality are improved, but vulnerability to tampering and data theft increases

Engineering Contradiction:
Improvepayment methodsVSAvoidtampering and data theft
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security checks and monitoring before fraudulent activity can occur. The terminal management server continuously monitors POS terminals for signs of tampering and classifies violations of security parameters, taking preventive action before data theft can be completed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where the terminal management server receives data from POS terminals about security parameter violations, classifies these as potential fraudulent activity, and sends commands back to disable the terminal. This closed-loop feedback mechanism enables continuous security monitoring and responsive action.

Inventive Principle:
Principle #23Feedback

2Reliability

If security monitoring and remote disabling functionality is implemented, then detection and mitigation of fraudulent activity is improved, but system complexity increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal management server acts as an intermediary between multiple POS terminals and the fraud detection system. This central化的 mediator handles data reception, classification of security violations, and disabling commands, simplifying the overall system architecture while maintaining high reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If POS terminals are disabled upon detecting security violations, then protection against data theft is improved, but operational disruption increases

Engineering Contradiction:
Improvedata theft riskVSAvoidterminal operation continuity
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system provides feedback to merchants and customers about the status of POS terminals. When a terminal is disabled due to security violations, the system can communicate this information and provide updates, allowing for transparent management of operational disruptions while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11004050B2Server and method for remotely disabling a compromised point-of-sale terminal
Publication Date: 2021.05.11 THE TORONTO DOMINION BANK
  • US11004050B2 patent drawing
  • US11004050B2 patent drawing
  • US11004050B2 patent drawing

AI summary

A terminal management server includes a data transceiver, and a data processor in communication with the data transceiver. The data transceiver is configured to receive from a point-of-sale terminal data indicative of a violation detected by the point-of-sale terminal of one or more security parameters. The violation is indicative of a compromise of the point-of-sale terminal. The data processor is configured to (i) classify the detected violation as potential fraudulent activity, and (ii) in response to the data processor classifying the detected violation as potential fraudulent activity, cause the data transceiver to send a command to the point-of-sale terminal disabling functionality of the point-of-sale terminal. One or more of the security parameters may include a status of a network connection between the point-of-sale terminal and the terminal management server, and the detected violation may include a termination of the network connection.