Settlement Terminal Tamper-Resistant Program Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing settlement terminals are vulnerable to tampering, which can be detected but not effectively prevented, and once tampered with, they cannot be restored to normal operation without updating the deleted programs or data.

Innovation Solution

A settlement terminal with a dual-program structure, where one set of programs is encrypted with different keys, allowing for automatic update from a first set to a second set upon tampering detection, ensuring continuous operation by switching to a secure version.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tamper detection technology is implemented to detect changes to the terminal, then the ability to detect tampering is improved, but the terminal can be easily bypassed if the detection configuration is known

Engineering Contradiction:
Improvetamper detection capabilityVSAvoidvulnerability to known detection methods
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-storing multiple sets of programs (first set and second set) with different encryption keys before any tampering occurs. When tampering is detected, the system can immediately switch to a pre-prepared secure state without requiring external intervention or complex real-time cryptographic operations, thus maintaining security even if the detection method is known.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies parameter changes by switching between different encryption keys (first key and second key) and different program sets based on the tampering detection result. This dynamic parameter change ensures that even if one encryption scheme is compromised, the system can transition to a different cryptographic parameter set, maintaining security against known detection methods.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If programs or data are deleted to prevent further operation after tampering, then security is improved, but the terminal cannot be restored to normal operation

Engineering Contradiction:
Improvesecurity after tamperingVSAvoidrestoration capability
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The system performs preliminary action by pre-storing multiple sets of programs (first set and second set) with different encryption keys before any tampering occurs. When tampering is detected, the system can immediately switch to a pre-prepared secure state without requiring external intervention or complex real-time cryptographic operations, thus maintaining security even if the detection method is known.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements discarding and recovering by deleting the first set of programs (which may be compromised) while preserving the ability to restore normal operation through the second set of programs. The system can discard the tainted program set and recover functionality by switching to the alternative encrypted program set, thereby maintaining both security and restoration capability.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If the terminal switches to a secure state upon tampering detection, then security is improved, but operational downtime increases

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidoperational downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-storing multiple sets of programs (first set and second set) with different encryption keys before any tampering occurs. When tampering is detected, the system can immediately switch to a pre-prepared secure state without requiring external intervention or complex real-time cryptographic operations, thus maintaining security even if the detection method is known.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies skipping by rapidly transitioning from the compromised first program set to the secure second program set upon tampering detection. This quick switch minimizes the time the terminal remains in a vulnerable or non-operational state, effectively rushing through the security transition to restore safe operation with minimal downtime.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10318933B2Settlement terminal and method of protecting data stored in the settlement terminal against tampering
Publication Date: 2019.06.11 TOSHIBA TEC KK
  • US10318933B2 patent drawing
  • US10318933B2 patent drawing
  • US10318933B2 patent drawing

AI summary

A settlement terminal includes a card reader, a settlement processing unit including a processor programmed to carry out a settlement process using information acquired through the card reader and a tampering detection process, a storage device in which a first set of programs is stored after encryption by a first key and a second set of programs is stored after encryption by a second key, each set of programs including a first program for operating the card reader, and a second program for carrying out the settlement process. Upon detection of tampering, the processor of the settlement processing unit notifies an external terminal of the tampering and upon receiving an update instruction from the external terminal, updates a current set of programs used for operating the card reader and carrying out the settlement process from the first set to the second set.