Security Processor Key Management for Self-Service Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Self-service terminals, such as ATMs, are vulnerable to security compromises due to inherent security holes, particularly in transactions conducted without human oversight, which can lead to unauthorized access and data breaches.

Innovation Solution

Implementing a cryptographic infrastructure via a security processor that manages independent cryptographic relationships between the terminal and its peripherals, using separate encryption key infrastructures for communications with the host and peripheral devices, ensuring secure and compartmentalized transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single cryptographic key infrastructure is used for both host communication and peripheral devices, then device complexity is reduced, but security reliability deteriorates due to compromised peripheral access

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the cryptographic infrastructure into separate segments: a first cryptographic key infrastructure for host communication and a second cryptographic key infrastructure for peripheral devices. This segmentation isolates security risks, so that compromise of one infrastructure does not affect the other, thereby improving security reliability without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security processor acts as an intermediary that manages both cryptographic infrastructures. It securely communicates with the host using the first infrastructure while independently managing the second infrastructure for peripheral devices. This intermediary role allows the system to maintain separate security domains while coordinating through a single security processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If independent cryptographic infrastructures are implemented for host and peripheral communications, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the management of both cryptographic infrastructures into a single security processor. Although the infrastructures themselves are separate, their management is consolidated in one component, which reduces overall system complexity while maintaining the security benefits of independent key infrastructures for host and peripheral communications.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If security peripherals are managed independently of the host cryptographic infrastructure, then security reliability is improved through compartmentalization, but ease of operation deteriorates due to independent key management

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security processor performs self-service by automatically managing both cryptographic infrastructures without requiring manual intervention. It handles key distribution, certificate validation, and cryptographic operations for both host and peripheral communications autonomously, thereby maintaining ease of operation while implementing independent security management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10445710B2Security device key management
Publication Date: 2019.10.15 NCR ATLEOS CORP
  • US10445710B2 patent drawing
  • US10445710B2 patent drawing
  • US10445710B2 patent drawing

AI summary

A method includes using a cryptographic infrastructure via a security processor in a device to communicate with a host, and managing, via the security processor, a cryptographic relationship with a security peripheral coupled to the security processor independent of the cryptographic infrastructure used to communicate with the host.