Settlement Terminal Tamper-Resistant Program Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing settlement terminals are vulnerable to tampering, which can be detected but not effectively prevented, and once tampered with, they cannot be restored to normal operation without updating the deleted programs or data.
Innovation Solution
A settlement terminal with a dual-program structure, where one set of programs is encrypted with different keys, allowing for automatic update from a first set to a second set upon tampering detection, ensuring continuous operation by switching to a secure version.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tamper detection technology is implemented to detect changes to the terminal, then the ability to detect tampering is improved, but the terminal can be easily bypassed if the detection configuration is known
Solution Approach 1:
The patent implements preliminary action by pre-storing multiple sets of programs (first set and second set) with different encryption keys before any tampering occurs. When tampering is detected, the system can immediately switch to a pre-prepared secure state without requiring external intervention or complex real-time cryptographic operations, thus maintaining security even if the detection method is known.
Solution Approach 2:
The patent applies parameter changes by switching between different encryption keys (first key and second key) and different program sets based on the tampering detection result. This dynamic parameter change ensures that even if one encryption scheme is compromised, the system can transition to a different cryptographic parameter set, maintaining security against known detection methods.
2Reliability
If programs or data are deleted to prevent further operation after tampering, then security is improved, but the terminal cannot be restored to normal operation
Solution Approach 1:
The system performs preliminary action by pre-storing multiple sets of programs (first set and second set) with different encryption keys before any tampering occurs. When tampering is detected, the system can immediately switch to a pre-prepared secure state without requiring external intervention or complex real-time cryptographic operations, thus maintaining security even if the detection method is known.
Solution Approach 2:
The patent implements discarding and recovering by deleting the first set of programs (which may be compromised) while preserving the ability to restore normal operation through the second set of programs. The system can discard the tainted program set and recover functionality by switching to the alternative encrypted program set, thereby maintaining both security and restoration capability.
3Reliability
If the terminal switches to a secure state upon tampering detection, then security is improved, but operational downtime increases
Solution Approach 1:
The system performs preliminary action by pre-storing multiple sets of programs (first set and second set) with different encryption keys before any tampering occurs. When tampering is detected, the system can immediately switch to a pre-prepared secure state without requiring external intervention or complex real-time cryptographic operations, thus maintaining security even if the detection method is known.
Solution Approach 2:
The patent applies skipping by rapidly transitioning from the compromised first program set to the secure second program set upon tampering detection. This quick switch minimizes the time the terminal remains in a vulnerable or non-operational state, effectively rushing through the security transition to restore safe operation with minimal downtime.
Data Source
AI summary
A settlement terminal includes a card reader, a settlement processing unit including a processor programmed to carry out a settlement process using information acquired through the card reader and a tampering detection process, a storage device in which a first set of programs is stored after encryption by a first key and a second set of programs is stored after encryption by a second key, each set of programs including a first program for operating the card reader, and a second program for carrying out the settlement process. Upon detection of tampering, the processor of the settlement processing unit notifies an external terminal of the tampering and upon receiving an update instruction from the external terminal, updates a current set of programs used for operating the card reader and carrying out the settlement process from the first set to the second set.


