Secure Connection Between Security Meshes in POS Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Point of Sale (POS) devices face security vulnerabilities due to potential physical attacks and tampering, which can compromise sensitive financial information, necessitating enhanced tamper-proofing mechanisms to protect against unauthorized access and data breaches.
Innovation Solution
Implementing multiple security meshes with integrated security processors and secure connections between them, utilizing tamper detection circuits and secure memory to ensure secure data transfer and encryption of payment information, along with a unique pre-shared key for secure communication, allowing for flexible and secure configuration of POS devices with interchangeable components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security meshes are implemented with secure connections, then security and data protection are improved, but device complexity increases
Solution Approach 1:
The device is divided into multiple security meshes, each housing a security processor and secure memory. This segmentation isolates sensitive functions and data into separate protected zones, improving security through physical and logical separation while managing complexity through modular design
Solution Approach 2:
A secure connection protocol acts as an intermediary between security meshes, establishing authenticated communication channels. The protocol includes handshake procedures, key exchange mechanisms, and encryption/decryption processes that mediate data transfer while maintaining security boundaries between meshes
2Difficulty of detecting and measuring
If tamper detection circuits are implemented on security processors, then detection capability is improved, but device complexity increases
Solution Approach 1:
Tamper detection circuits are merged directly into the security processor architecture, combining security processing and tamper detection functions in a single integrated component. This reduces overall device complexity by eliminating separate detection hardware while maintaining enhanced detection capability through unified design
3Reliability
If secure memory is implemented for each security processor, then data protection is improved, but device complexity increases
Solution Approach 1:
Secure memory is segmented and allocated to each security processor individually, creating isolated protected storage zones. This segmentation ensures that compromise of one security processor does not expose data in other secure memory zones, improving data protection through architectural isolation
Solution Approach 2:
Secure memory is nested within each security mesh, creating a hierarchical protection structure where memory is physically enclosed and protected by the mesh. This nesting provides multiple layers of protection - physical barriers at the mesh level and cryptographic protection at the data level
4Adaptability or versatility
If security meshes are made interchangeable with detachable casings, then adaptability is improved, but security requirements increase
Solution Approach 1:
The security mesh architecture is designed with detachable casings that allow dynamic reconfiguration of the device. Security processors and secure memory can be exchanged between meshes, enabling adaptability for different applications while maintaining security through consistent cryptographic protection and authenticated connection protocols
Solution Approach 2:
Security connections between meshes are established through preliminary authentication and key exchange procedures before data transfer. This preliminary action ensures that even though meshes are physically interchangeable, security is maintained through pre-established trusted relationships and encrypted communication channels
Data Source
AI summary
Systems and methods involving secure connections between security meshes are disclosed herein. One disclosed device includes a first security processor located within a first security mesh, a first casing having a connector and supporting the first security mesh and the applications processor, a second security processor located within a second security mesh, and a second casing connected to the first casing via the connector and supporting the second security mesh. The first security processor and second security processor are programmed to generate a unique pre-shared key independently on both the first security processor and the second security processor using an elliptic key exchange and establish a secure connection between the first security processor and the second security processor using the unique pre-shared key.


