Secure Controller for Retail Payment Terminal Content Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional payment terminals at retail devices, such as fuel dispensers, face security risks when allowing third-party content, as non-secure prompts can be used to fraudulently request sensitive information, compromising customer data.

Innovation Solution

A retail payment and content switching system with a secure controller that switches between secure and non-secure content sources based on the security mode, ensuring only authorized prompts are displayed and customer input is encrypted, preventing unauthorized access to sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third parties are allowed to connect to the payment terminal to provide additional content, then the customer experience is enhanced with rich advertising and loyalty program content, but the risk of fraud increases as perpetrators can provide fake prompts to acquire private information

Engineering Contradiction:
Improvecontent provision capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments content sources into secure and non-secure categories, allowing third-party content providers to contribute advertising and loyalty program content while maintaining a clear separation from secure payment operations. The payment terminal controller selectively processes content from authorized non-secure sources during non-transaction periods without compromising the security of sensitive payment information collection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The payment terminal controller acts as an intermediary that verifies and manages content from third-party sources. It authenticates content providers, controls when their content is displayed, and ensures that secure payment prompts are not compromised by third-party content, thereby mediating between content provision needs and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the payment terminal displays only secure content during transactions, then fraud prevention is improved, but the ability to provide advertising and promotional content is reduced

Engineering Contradiction:
Improvefraud preventionVSAvoidcontent variety
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements periodic switching between secure and non-secure content modes based on transaction state. During active transactions, only secure payment-related content is displayed. During non-transaction periods, the terminal periodically displays advertising and promotional content from authorized third-party sources, creating a rhythmic alternation that maintains security while providing content variety.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The content display system is made dynamic by allowing the payment terminal controller to adjust content sources based on real-time transaction conditions. The system transitions between displaying secure payment prompts and authorized third-party content, optimizing the balance between fraud prevention and customer engagement based on current operational context.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If the payment terminal collects and processes customer information, then transaction functionality is enabled, but the risk of information being skimmed by eavesdroppers increases if the information is not encrypted

Engineering Contradiction:
Improvetransaction processingVSAvoidinformation skimming risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system changes the encryption parameter of data transmission based on the presence of third-party content sources. When third-party content is being processed or when in non-secure mode, the terminal applies encryption to customer information to prevent skimming. This parameter change ensures that transaction processing remains functional while protecting against information theft during vulnerable states.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11169954B2System and method for controlling secure content and non-secure content at a fuel dispenser or other retail device
Publication Date: 2021.11.09 GILBARCO INC
  • US11169954B2 patent drawing
  • US11169954B2 patent drawing
  • US11169954B2 patent drawing

AI summary

A retail payment, advertising, and content switching system and method are disclosed. According to one embodiment, a secure content source or a non-secure content source is allowed to drive a customer user interface, respectively, without compromising security requirements. The content may be video, audio, prompts, or any other type of content. A secure controller is provided to control one or more user input devices and a user interface access module to control whether a secure source or a non-secure source drives the user interface, depending on the security mode of the system. The secure controller, the user interface access module, and the customer input devices are provided in an anti-tampering module. The secure controller prevents the non-secure source from providing unauthorized prompts on the customer user interface to “fake out” the customer so that sensitive customer information is not passed “in the clear.”