Secure Terminal Activation via Dual-Source Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure terminal activation methods require the presence of two operators on-site, which is inconvenient and inefficient, especially for electronic payment terminals and cash dispensers, due to the need for dual manual verification according to PCI standards.
Innovation Solution
A method that allows a secure terminal to be activated using two distinct activation information items received from separate entities, where the terminal requires both items to become operational, with one item being encrypted and decrypted using a stored encryption key, and the other item generated and sent by an authorization server after verifying operator and terminal authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If double manual verification by two operators is implemented according to PCI standards, then terminal security is improved, but operator presence requirement increases
Solution Approach 1:
An authorization server is introduced as an intermediary between operators and terminals. The server receives activation requests, verifies operator credentials against stored credentials, and sends activation codes to terminals. This mediator enables secure remote verification without requiring physical presence of multiple operators at the terminal location.
Solution Approach 2:
The manual mechanical verification process (two operators physically present) is replaced with an automated electronic system. The authorization server automatically verifies operator credentials and sends activation codes electronically, substituting the mechanical interaction of multiple operators with an automated digital verification system that maintains security while reducing physical presence requirements.
2Reliability
If two separate operators are required for terminal activation, then activation security is improved, but activation time increases
Solution Approach 1:
Operator credentials are pre-stored in the authorization server database before activation is needed. When activation is required, the server simply retrieves and verifies these pre-stored credentials rather than performing complex verification procedures, significantly reducing activation time while maintaining security.
Solution Approach 2:
The time-consuming manual coordination between two operators is replaced with automated electronic verification. The authorization server instantly verifies credentials and sends activation codes electronically, reducing activation time from potentially hours of manual coordination to seconds of automated processing while maintaining equivalent or superior security.
3Ease of operation
If activation information is transmitted without encryption, then transmission simplicity is improved, but information security deteriorates
Solution Approach 1:
The activation code is transformed by encrypting it with the terminal's public key before transmission. This parameter change converts the plain text activation code into encrypted ciphertext, ensuring that even if intercepted, the information cannot be used without the corresponding private key. The terminal can still verify and process the encrypted code using its stored private key.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to an activation method by an operator of a terminal (4), the activation of the terminal enabling secure data exchange between the terminal (4) and a secure server, characterised in that it comprises the following steps for the terminal (4): - receiving from the operator (2) a first activation data item, - receiving from an authorisation server (3) a second activation data item, - using the first and second activation data items to activate the terminal.