Secure Connection Between Security Meshes in POS Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Point of Sale (POS) devices face security vulnerabilities due to potential physical attacks and tampering, which can compromise sensitive financial information, necessitating enhanced tamper-proofing mechanisms to protect against unauthorized access and data breaches.

Innovation Solution

Implementing multiple security meshes with integrated security processors and secure connections between them, utilizing tamper detection circuits and secure memory to ensure secure data transfer and encryption of payment information, along with a unique pre-shared key for secure communication, allowing for flexible and secure configuration of POS devices with interchangeable components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security meshes are implemented with secure connections, then security and data protection are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device is divided into multiple security meshes, each housing a security processor and secure memory. This segmentation isolates sensitive functions and data into separate protected zones, improving security through physical and logical separation while managing complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure connection protocol acts as an intermediary between security meshes, establishing authenticated communication channels. The protocol includes handshake procedures, key exchange mechanisms, and encryption/decryption processes that mediate data transfer while maintaining security boundaries between meshes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If tamper detection circuits are implemented on security processors, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

Tamper detection circuits are merged directly into the security processor architecture, combining security processing and tamper detection functions in a single integrated component. This reduces overall device complexity by eliminating separate detection hardware while maintaining enhanced detection capability through unified design

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If secure memory is implemented for each security processor, then data protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Secure memory is segmented and allocated to each security processor individually, creating isolated protected storage zones. This segmentation ensures that compromise of one security processor does not expose data in other secure memory zones, improving data protection through architectural isolation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Secure memory is nested within each security mesh, creating a hierarchical protection structure where memory is physically enclosed and protected by the mesh. This nesting provides multiple layers of protection - physical barriers at the mesh level and cryptographic protection at the data level

Inventive Principle:
Principle #7Nested doll (Nesting)

4Adaptability or versatility

If security meshes are made interchangeable with detachable casings, then adaptability is improved, but security requirements increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security mesh architecture is designed with detachable casings that allow dynamic reconfiguration of the device. Security processors and secure memory can be exchanged between meshes, enabling adaptability for different applications while maintaining security through consistent cryptographic protection and authenticated connection protocols

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Security connections between meshes are established through preliminary authentication and key exchange procedures before data transfer. This preliminary action ensures that even though meshes are physically interchangeable, security is maintained through pre-established trusted relationships and encrypted communication channels

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240362604A1Point of sale device with secure connection between security meshes
Publication Date: 2024.10.31 FISERV INC
  • US20240362604A1 patent drawing
  • US20240362604A1 patent drawing
  • US20240362604A1 patent drawing

AI summary

Systems and methods involving secure connections between security meshes are disclosed herein. One disclosed device includes a first security processor located within a first security mesh, a first casing having a connector and supporting the first security mesh and the applications processor, a second security processor located within a second security mesh, and a second casing connected to the first casing via the connector and supporting the second security mesh. The first security processor and second security processor are programmed to generate a unique pre-shared key independently on both the first security processor and the second security processor using an elliptic key exchange and establish a secure connection between the first security processor and the second security processor using the unique pre-shared key.