Segmented Payment Architecture for Retail Fueling Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In retail fueling environments, existing payment processing systems face challenges in complying with Payment Card Industry Data Security Standards (PCI DSS) due to the requirement that all components, including those not handling sensitive information, must be compliant, leading to difficulties in changing or upgrading systems without undergoing an arduous certification process.
Innovation Solution
A payment processing system is designed with a segmented architecture, where the POS module is separated from the device module that handles payment card data, allowing only the payment transaction device and card reader to handle sensitive information, thus isolating components that do not handle payment card data from those that do, reducing the scope of PCI DSS compliance requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all components including non-payment handling components are integrated into a single device, then the system can provide comprehensive functionality, but the entire system must comply with PCI DSS requiring arduous certification process
Solution Approach 1:
The system is divided into two separate devices: a payment processing device that handles sensitive payment card data and complies with PCI DSS, and a POS device that provides comprehensive retail functionality but does not handle payment data. This segmentation allows each device to have focused compliance requirements, reducing the overall certification burden while maintaining full system functionality.
Solution Approach 2:
The payment processing functionality is extracted from the POS device into a separate dedicated payment processing device. This extraction removes the PCI DSS compliance burden from the POS device, allowing it to operate without the arduous certification process while the specialized payment device handles compliance requirements.
2Reliability
If the entire POS system is subject to PCI DSS compliance, then security standards are maintained, but any changes require arduous recertification process
Solution Approach 1:
By segmenting the system into payment processing and POS functionality, only the payment processing device requires PCI DSS compliance. This allows the POS device to be modified, updated, or enhanced without triggering recertification requirements, as long as the modifications do not affect payment data handling.
Solution Approach 2:
Extracting payment processing into a separate device isolates the compliance burden. The POS device can be freely modified for new retail functions, and the payment device can be independently updated for security improvements without affecting each other's certification status.
3Ease of operation
If non-compliant GUI components are included in the POS device, then user functionality is enhanced, but the entire POS device becomes noncompliant with PA-DSS
Solution Approach 1:
The GUI and user interface components are placed entirely within the POS device, which does not handle payment data. This allows the development of rich, functional user interfaces without PA-DSS constraints, while the separate payment processing device maintains full compliance by handling only essential payment data functions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A retail fueling environment (300) having a secure LAN portion including a plurality of fuel dispensers (102), each fuel dispenser (102) generating non-sensitive transaction data and having a customer interface with a dispenser card reader (105) and a PIN pad (110) to receive sensitive payment information from a customer, characterized in that the retail fueling environment (300) includes: (a) a store LAN portion of the retail fueling environment (300) comprising a server workstation (106) having a cashier work station (124) that provides means for effecting a transaction for one or more items offered for sale by the retail fueling environment (300), the store LAN portion of the retail fueling environment (300) does not handle sensitive payment information and is segmented from the secure LAN portion that handles the sensitive payment information; and, (b) at least one customer card reader (116) for receiving the sensitive payment information from the customer, the customer card reader (116) being a part of the secure LAN portion of the retail fueling environment (300) and associated with the server workstation (106); (c) an enhanced dispenser hub (302) that is part of the secure LAN portion of the retail fueling environment (300), the enhanced dispenser hub device (302): (i) receives the sensitive payment information from the dispenser card reader (105) or from the at least one customer card reader (116); (ii) receives the non-sensitive transaction data from the fuel dispensers (102); (iii) comprises a network payment module (128) and transmits the sensitive payment information and non-sensitive transaction data such that the: - sensitive payment information is not transmitted to the store LAN portion of the retail fueling environment and is transmitted to a financial institution for validation of the transaction using the network payment module (128); and, - non-sensitive transaction data is transmitted to the server workstation (106); and, (iv) comprises a forecourt module (126) that controls the operation of the fuel dispensers (102).