Secure Controller for Retail Payment Terminal Content Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional payment terminals at retail devices, such as fuel dispensers, face security risks when allowing third-party content, as non-secure prompts can be used to fraudulently request sensitive information, compromising customer data.
Innovation Solution
A retail payment and content switching system with a secure controller that switches between secure and non-secure content sources based on the security mode, ensuring only authorized prompts are displayed and customer input is encrypted, preventing unauthorized access to sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If third parties are allowed to connect to the payment terminal to provide additional content, then the customer experience is enhanced with rich advertising and loyalty program content, but the risk of fraud increases as perpetrators can provide fake prompts to acquire private information
Solution Approach 1:
The system segments content sources into secure and non-secure categories, allowing third-party content providers to contribute advertising and loyalty program content while maintaining a clear separation from secure payment operations. The payment terminal controller selectively processes content from authorized non-secure sources during non-transaction periods without compromising the security of sensitive payment information collection.
Solution Approach 2:
The payment terminal controller acts as an intermediary that verifies and manages content from third-party sources. It authenticates content providers, controls when their content is displayed, and ensures that secure payment prompts are not compromised by third-party content, thereby mediating between content provision needs and security requirements.
2Reliability
If the payment terminal displays only secure content during transactions, then fraud prevention is improved, but the ability to provide advertising and promotional content is reduced
Solution Approach 1:
The system implements periodic switching between secure and non-secure content modes based on transaction state. During active transactions, only secure payment-related content is displayed. During non-transaction periods, the terminal periodically displays advertising and promotional content from authorized third-party sources, creating a rhythmic alternation that maintains security while providing content variety.
Solution Approach 2:
The content display system is made dynamic by allowing the payment terminal controller to adjust content sources based on real-time transaction conditions. The system transitions between displaying secure payment prompts and authorized third-party content, optimizing the balance between fraud prevention and customer engagement based on current operational context.
3Ease of operation
If the payment terminal collects and processes customer information, then transaction functionality is enabled, but the risk of information being skimmed by eavesdroppers increases if the information is not encrypted
Solution Approach 1:
The system changes the encryption parameter of data transmission based on the presence of third-party content sources. When third-party content is being processed or when in non-secure mode, the terminal applies encryption to customer information to prevent skimming. This parameter change ensures that transaction processing remains functional while protecting against information theft during vulnerable states.
Data Source
AI summary
A retail payment, advertising, and content switching system and method are disclosed. According to one embodiment, a secure content source or a non-secure content source is allowed to drive a customer user interface, respectively, without compromising security requirements. The content may be video, audio, prompts, or any other type of content. A secure controller is provided to control one or more user input devices and a user interface access module to control whether a secure source or a non-secure source drives the user interface, depending on the security mode of the system. The secure controller, the user interface access module, and the customer input devices are provided in an anti-tampering module. The secure controller prevents the non-secure source from providing unauthorized prompts on the customer user interface to “fake out” the customer so that sensitive customer information is not passed “in the clear.”


