Encryption Module Integration in Token Data Capture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Token-based systems face security vulnerabilities due to the risk of stolen or counterfeited tokens being used for unauthorized access, leading to significant financial losses, as seen in credit and charge card fraud.

Innovation Solution

Implementing data security techniques such as encryption within token systems, where data is encrypted on the token itself and as it is read, using encryption modules that encapsulate encryption algorithms and keys, and providing secure transaction modules for decryption and re-encryption to enhance security and prevent tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption modules are integrated into data capture devices, then security against stolen or counterfeited tokens is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the encryption module with the data capture device by integrating the encryption algorithm and key storage directly into the read head assembly. This merging allows the same physical component that reads token data to also encrypt it, eliminating the need for separate encryption hardware and reducing overall system complexity while maintaining enhanced security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The read head is designed to perform multiple functions: it captures data from tokens using magnetic, optical, or other sensing mechanisms, and simultaneously encrypts that data using integrated encryption algorithms. This multi-functionality eliminates the need for separate encryption devices and simplifies the system architecture while providing robust security against stolen or counterfeited tokens.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If encryption is implemented at the data capture device, then security against fraud is improved, but manufacturing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The encryption capability is built into the data capture device during manufacturing, so that encryption is automatically performed as part of the data capture process itself. This preliminary integration means that encryption is handled as a standard feature rather than an add-on, simplifying the overall manufacturing process and reducing the need for separate encryption hardware assembly steps.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption modules with encapsulated algorithms and keys are used, then security against tampering is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption algorithm and key storage are nested within the read head assembly, which itself is integrated into the data capture device. This nested structure allows the encryption components to be contained within existing hardware boundaries, providing tamper resistance through physical encapsulation while avoiding the need for additional external encryption modules or separate key management systems.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS9123042B2Pin block replacement
Publication Date: 2015.09.01 VERIFONE INC
  • US9123042B2 patent drawing
  • US9123042B2 patent drawing
  • US9123042B2 patent drawing

AI summary

Systems and methods for performing token transactions are provided. In one embodiment, the invention provides for processing token transactions, including receiving an encrypted password for a debit card transaction, wherein the password was secured using encrypted debit-card information, decrypting the password using encrypted debit-card information for the debit card, recreating the password using actual debit-card information for the debit card, and forwarding the recreated password for subsequent transaction processing. The invention is suitable for implementation with other types of tokens in addition to debit-card tokens as well. The invention can be implemented in a scenario where the password includes a PIN block that is created by combining a clear or encrypted PIN for the token with token information.