Secure IC Pass-Through Path for POS Display Emulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
POS terminals face challenges in securely managing display content, as rogue software can exploit the display to steal financial information, and existing architectures struggle to balance security with the need to display untrusted, high-resolution video without compromising processing power.
Innovation Solution
A secure integrated circuit with a keypress entry interface and a pass-through data path operates in two modes: one mode disables the keypress entry interface while enabling the pass-through data path for untrusted content, and another mode enables keypress entry while disabling the pass-through data path for authenticated content, allowing secure financial transactions and flexible use of the display for other purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a one-chip architecture is used to integrate security functions and display control, then device complexity is reduced, but the microcontroller does not have enough processing power to decode and display high-resolution video at high frame rates
Solution Approach 1:
The system is divided into two separate chips: a secure microcontroller handling security functions and a general-purpose microcontroller handling video decoding and display control. This segmentation allows each component to be optimized for its specific function, resolving the contradiction between low complexity and high processing power.
2Adaptability or versatility
If the display is used to show untrusted content from external sources, then adaptability and versatility are improved, but security risks increase as rogue software could exploit the display to steal financial information
Solution Approach 1:
The secure microcontroller acts as an intermediary between the external untrusted content source and the display. It monitors and controls what content is displayed, blocking any attempts by rogue software to exploit the display for stealing financial information, thus maintaining security while allowing versatile display usage.
Solution Approach 2:
The system dynamically switches between two operational modes: a secure mode where the secure microcontroller controls the display for financial transactions, and a flexible mode where untrusted content can be displayed. This dynamic switching allows the system to adapt to different security requirements while maintaining both security and versatility.
3Reliability
If the display is reserved exclusively for secure financial transaction applications, then security is improved, but the display cannot be used for other purposes such as advertising or cash register functions
Solution Approach 1:
The system implements dynamic mode switching that allows the display to be used exclusively for secure financial transactions when needed, while also enabling it to display advertising or cash register information when security requirements are not active. This resolves the contradiction by making the display usage flexible rather than fixed.
Solution Approach 2:
The display system is designed to perform multiple functions: secure financial transaction display, advertising display, and cash register display. The secure microcontroller enables the display to safely handle different types of content for different purposes, making the display universal while maintaining security when required.
4Power
If a two-chip architecture is used to separate security functions from display control, then processing power for video decoding is improved, but device complexity increases
Solution Approach 1:
The system is divided into two separate chips with clearly defined responsibilities: the secure microcontroller handles security-critical functions while the general-purpose microcontroller handles video decoding and display control. This segmentation increases processing power for video while keeping each individual chip relatively simple, resolving the contradiction between processing power and complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An integrated circuit has a keypress entry interface and a pass-through data path. In a pass-through mode, the keypress entry interface is disabled and the pass-through data path is enabled such that untrusted information (for example, video) from an external untrusted source can be driven into the integrated circuit, through the pass-through data path, and out of the secure integrated circuit and to a display. In a trusted mode, the keypress entry interface is enabled and is usable to receive keypress information in a financial transaction. The pass-through data path is, however, disabled so that unauthorized information cannot be driven through the integrated circuit to the display. Signed images previously stored on the integrated circuit can be verified and driven to the display in a secure fashion. The architecture is flexible and allows an external general purpose video decoder to be used to drive the display in the pass-through mode.