Terminal Device Failover Via Secure Mobile Internet Connection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
POS systems face operational challenges when hardware/network/power failures disrupt connections to local and wide area networks, rendering them inaccessible and unusable, necessitating a secure alternate connection to remote servers over the public internet.
Innovation Solution
A mobile internet connection device establishes a temporary local wireless network, enabling a terminal device to connect securely to a remote server using a certificate-based protocol and VPN tunnel, ensuring trust and security through operator credentials and access tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a terminal device connects to a remote server over the public internet as an alternate connection, then service availability is improved during network failures, but security is worsened due to inherent insecurity of public internet communications
Solution Approach 1:
A mobile internet connection device serves as an intermediary between the terminal device and the public internet. It establishes a temporary local wireless network that acts as a secure gateway, mediating all communications between the terminal device and remote servers over the public internet while maintaining security through localized trust boundaries.
Solution Approach 2:
Security credentials including certificates and encryption keys are pre-configured on both the terminal device and the mobile internet connection device before connectivity is needed. This preliminary setup enables immediate secure connection establishment when network failures occur, without requiring security configuration during the emergency connection phase.
2Reliability
If a temporary local wireless network is established by a mobile internet connection device, then secure connection to remote services is enabled, but device complexity is increased
Solution Approach 1:
The mobile internet connection device performs multiple functions: it provides internet connectivity, establishes wireless network infrastructure, manages security credentials, and facilitates certificate-based authentication. By consolidating these diverse functions into a single mobile device, the system avoids the complexity of separate dedicated devices for each function.
Solution Approach 2:
The terminal device autonomously detects the temporary wireless network, retrieves connection information, and establishes secure connections using pre-configured credentials without requiring manual configuration or complex setup procedures. The system self-manages the security handshake and connection establishment processes.
3Reliability
If certificate-based trust negotiation protocol is used to establish secure connection, then security is improved, but connection establishment time is increased
Solution Approach 1:
Security certificates, cryptographic keys, and trust negotiation parameters are pre-configured on both the terminal device and the mobile internet connection device before connectivity is needed. This preliminary setup eliminates the need for time-consuming certificate exchange and verification procedures during actual connection establishment, reducing latency while maintaining security.
Data Source
AI summary
In some implementations, a computer system for providing a terminal device with a secure remote service connection can include the terminal device, an internet connection device, and a remote server. A temporary local wireless network and a sharable internet connection can be established by the internet connection device, and connection information can be output for the temporary local wireless network. The terminal device can detect the connection information and can connect to the temporary local wireless network. A secure connection can be established between the terminal device and the remote server. After establishing the secure connection, the remote server can receive operator credentials from the terminal device, and can transmit an access token to the terminal device. The terminal device can transmit a request to access a terminal device service hosted by the remote server, and the remote server can execute application code for the terminal device service.


