Payment Terminal Security Event Reporting via EMV Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack an efficient mechanism for reporting security information from payment terminals to remote servers without modifying existing communication protocols, making it difficult to detect fraud, anomalies, or attacks during transactions.

Innovation Solution

A method that involves detecting events during transactions, generating security information, and sending it to a remote server within a transaction message, allowing for better evaluation and management of terminal events without altering the EMV protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security information is reported from terminal to remote server, then security monitoring capability is improved, but communication protocol complexity increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by embedding security information within existing transaction message fields (such as replacing transaction datum in data elements) rather than creating a separate communication protocol. This allows security monitoring to be implemented without adding protocol complexity, as the security information travels through the existing message exchange infrastructure between terminal and remote server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If existing communication protocols are modified to include security information, then security information transmission is improved, but protocol compatibility and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity information transmissionVSAvoidprotocol compatibility
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent merges security information transmission with existing transaction data communication by embedding security information within standard transaction message fields. Instead of modifying protocols to add separate security channels, the security information is combined with regular transaction datum in existing data elements, maintaining protocol compatibility while enabling security information transmission.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The transaction message fields are given multi-functionality by using them to carry both regular transaction data and security information. The same communication infrastructure serves dual purposes: normal transaction processing and security event reporting, eliminating the need for protocol modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Difficulty of detecting and measuring

If security information is embedded in transaction messages, then security event detection is improved, but data processing complexity increases

Engineering Contradiction:
Improvesecurity event detectionVSAvoiddata processing complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts security information from complex transaction analysis and places it in dedicated fields within transaction messages. By taking out security-relevant data and positioning it in identifiable locations within the message structure, security event detection is simplified without significantly increasing overall processing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3261014B1Method for sending security information
Publication Date: 2019.09.11 IDEMIA FRANCE SAS
  • EP3261014B1 patent drawingFigure 1
  • EP3261014B1 patent drawingFigure 2~4
  • EP3261014B1 patent drawingFigure 5~7

AI summary

The invention relates to a method for sending security information implemented by a terminal (T), said method comprising the following steps: - receiving, during a transaction in progress, a first transaction data from an electronic device (CD) with which said terminal (T) cooperates; - detecting an event encountered by the terminal (T) during the transaction in progress; - generating a transaction message including an indicator showing the inclusion of the first data in a field of the message; - inserting, in the field of the transaction message, a security information in place of the first transaction data, the security information being representative of said event; and - sending, to a remote server (SV1), the transaction message including the security information.