Secure Transaction Terminal Gateway Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Transaction terminals with media handling devices, such as ATMs, face continuous security threats due to centralized processing and numerous peripheral devices, which are vulnerable to attacks, leading to ongoing cycles of redesigning hardware and software to address security vulnerabilities.

Innovation Solution

A secure transaction terminal gateway with a single motherboard featuring physically separated processing environments – an application environment for centralized processing and a security environment for handling security interactions, connected via a single secure bus, reduces the need for peripheral device resources and enhances security by custom encryption and 'hard' and 'soft' security approaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If centralized processing is used to access financial networks and authorize transactions, then transaction functionality is improved, but security vulnerabilities increase due to more attack access points

Engineering Contradiction:
Improvetransaction functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into two separate processing environments: a secure processing environment that handles security-critical operations (transaction authorization, account validation, PIN verification) and an application processing environment that handles user interface and non-critical functions. This segmentation isolates security vulnerabilities to specific domains, preventing attacks from compromising the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security node acts as an intermediary between the application node and peripheral devices. All communications between the application environment and security-sensitive components must pass through this secured gateway, which validates and filters data streams. This intermediary architecture creates controlled access points that prevent direct exploitation of peripheral devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple peripheral devices are added to handle currency and authentication, then transaction capabilities are improved, but the number of security access points increases

Engineering Contradiction:
Improvetransaction capabilitiesVSAvoidnumber of security access points
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Multiple peripheral devices (currency dispensers, card readers, PIN pads, authentication modules) are logically consolidated under a single security node. Instead of each device having independent security processing, they all interface through the unified security environment, reducing the number of independent security access points while maintaining full transaction capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security node is designed as a universal interface that can authenticate and control multiple different types of peripheral devices through standardized protocols. This multi-functional security gateway handles currency handling, card authentication, PIN verification, and transaction authorization through a single secured access point rather than requiring separate security implementations for each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware and software are redesigned continuously to address security attacks, then security is improved, but development time and costs increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security measures are built into the system architecture from the beginning rather than added as reactive patches. The dual-environment architecture, secure boot process, encrypted communication channels, and authenticated peripheral interfaces are implemented during initial system design and deployment. This preliminary security integration eliminates the need for continuous redesign cycles in response to attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates defense-in-depth strategies that anticipate potential attacks before they occur. Multiple layers of security (hardware-based authentication, encrypted data streams, validated communication protocols, isolated processing environments) are pre-configured to cushion against various attack vectors. This proactive security cushioning reduces the impact of attacks and eliminates the need for frequent redesigns.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS20250104085A1Secure transaction terminal gateway
Publication Date: 2025.03.27 NCR ATLEOS CORP
  • US20250104085A1 patent drawing
  • US20250104085A1 patent drawing
  • US20250104085A1 patent drawing

AI summary

A secure transaction terminal gateway device is provided. The gateway device includes a single motherboard. The motherboard includes an application processing environment and a security processing environment. Peripheral connections and communications are directly processed and authenticated directly on the security processing environment and indirectly communicated from the secure processing environment to the application processing environment. Communication between the application processing environment and security processing environment is made via an on-motherboard wired secure connection between an application environment port and a security environment port. In an embodiment, the single motherboard is an automated teller machine (ATM) motherboard.