Secure CAT Payment Kiosk PCI-DSS Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment card processing systems, particularly in kiosks like postal services kiosks, face difficulties in simplifying compliance with restrictive and costly data security standards such as PCI-DSS, especially in unmonitored and insecure environments.
Innovation Solution
A payment processing system that includes a computerized sales transaction device and a secure card activated terminal (CAT) where sensitive payment card information is securely obtained and processed by the CAT, with the transaction device only receiving authorization approval information, thus avoiding the need for the transaction device to comply with PCI-DSS requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the computerized sales transaction device processes and stores sensitive payment card information, then it can complete payment transactions, but it must comply with restrictive and costly PCI-DSS security requirements
Solution Approach 1:
The patent extracts the sensitive payment card information handling function from the computerized sales transaction device and places it exclusively in the secure CAT device. The transaction device only receives authorization approval information, not the actual card data, thereby removing the burden of PCI-DSS compliance from the transaction device while maintaining full payment processing capability.
Solution Approach 2:
The payment processing system is segmented into two distinct functional components: the computerized sales transaction device that handles transaction logic and the secure CAT device that exclusively handles sensitive card information. This segmentation allows each component to have specialized security requirements, simplifying compliance for the transaction device.
2Adaptability or versatility
If the kiosk is placed in an unmonitored and insecure environment, then it provides convenient customer access, but it becomes vulnerable to data breaches and fraudulent acquisition of payment card data
Solution Approach 1:
The secure CAT device acts as an intermediary between the transaction device and the payment card information. It is the sole component that directly handles sensitive card data, creating a security boundary that protects the rest of the system. This intermediary approach allows the kiosk to be deployed in unmonitored environments while maintaining data security through cryptographic protection and controlled access points.
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The secure CAT device implements high-level security measures (cryptographic protection, secure element storage), while the transaction device operates with standard security. This localized quality approach enables deployment flexibility while maintaining reliability where it matters most.
Data Source
AI summary
An apparatus for facilitating payment using a payment card includes a computerized sales transaction device structured to determine a monetary amount for a sale, and a secure card activated terminal (CAT) device in electronic communication with the computerized sales transaction device. The computerized sales transaction device sends the monetary amount to the secure CAT device. The secure CAT device is structured to: (i) obtain sensitive payment card information from the card, (ii) automatically request in a secure, encrypted manner authorization for the sale using the monetary amount and the sensitive payment card information, (iii) receive in a secure, encrypted manner authorization approval for the sale, and (iv) in response to receiving the authorization approval, send purchase authorization approval information to the computerized sales transaction device. The computerized sales transaction device never receives the sensitive payment card information.


