POS Network Segmentation via VLAN Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Local area networks (LANs) with point of sale devices face security concerns due to the need to segregate sensitive payment data from non-point of sale devices, as current practices are difficult to maintain and may compromise data security when both wired and wireless connections are combined, especially in smaller merchant setups.
Innovation Solution
Implementing a data control system using a wireless router that defines separate virtual local area networks (VLANs) for point of sale and non-point of sale devices, with secure connections and encryption to isolate sensitive data transmission, ensuring only approved devices communicate within and outside the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If point of sale devices are allowed to communicate with non-point of sale devices on the same LAN, then network flexibility and ease of operation are improved, but data security and reliability deteriorate
Solution Approach 1:
The patent divides the LAN into separate VLANs - a POS VLAN for point of sale devices and a non-POS VLAN for other devices. This segmentation allows both types of devices to coexist on the same physical network infrastructure while maintaining logical separation, thus achieving network flexibility without compromising data security.
Solution Approach 2:
The patent introduces a network appliance as an intermediary device that sits between the POS VLAN and non-POS VLAN. This appliance monitors and controls data traffic between the two VLANs, allowing necessary communications while blocking unauthorized access to cardholder data, thereby enabling network flexibility while maintaining security.
2Reliability
If separate physical networks are maintained for point of sale devices and other devices, then data security is improved, but device complexity and ease of operation worsen
Solution Approach 1:
The patent merges separate physical networks into a single physical LAN infrastructure while maintaining logical separation through VLANs. This consolidation reduces hardware requirements, simplifies network management, and lowers complexity while preserving the security benefits of network segmentation through software-based virtualization.
3Adaptability or versatility
If both wired and wireless connections are combined on the same LAN, then network versatility is improved, but data security deteriorates due to potential weaknesses in wireless connectivity
Solution Approach 1:
The patent segments the network into VLANs that can accommodate both wired and wireless devices. By assigning wireless POS devices to the POS VLAN and isolating them from the non-POS VLAN, the system maintains connection flexibility while preventing wireless connectivity from compromising the security of cardholder data transmissions.
Data Source
AI summary
A data control system prevents non-point of sale devices (135, 155) from sending data over an external network (160) via a secure connection reserved for point of sale devices (125, 145), but allows non-point of sale devices (135, 155) to send data over the external network (160) other than via the secure connection. The secure connection is, for example, a virtual private network connection. The data control system may allow the data from non-point of sale devices (135, 155) to be sent only if it is not destined for a restricted destination. The restricted destination may be, for example, a payment host (170) or secure host (180) on the external network (160).


