Transaction Terminal Architecture for Secure Offline and Online Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing transaction terminals face challenges in conducting secure transactions without a communication network, leading to complexity, high costs, and lengthy maintenance due to overabundant components and functionalities, which are not necessary for all operations.
Innovation Solution
Implementing a transactional terminal with separate online and standalone components, each with distinct logic and secure memory areas, allowing transactions to be conducted locally or online based on network availability, using a root component for basic functions accessible only in read mode.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the terminal embeds a large number of superabundant functionalities to handle transactions without communication network, then the terminal can operate independently, but the device complexity and maintenance difficulty increase
Solution Approach 1:
The terminal software is segmented into two distinct transactional components: an online transactional component for network-based operations and a standalone transactional component for offline operations. This segmentation allows the terminal to handle different operational modes separately, reducing overall software complexity while maintaining both online and offline capabilities.
Solution Approach 2:
The terminal is designed with multi-functionality to handle both online and offline transactions through a unified architecture. The root component provides common functions accessible by both transactional components, enabling the terminal to operate independently when needed while also supporting network-based operations when available.
2Reliability
If the terminal includes separate online and standalone transactional components with distinct logic, then transaction security is improved, but the device complexity increases
Solution Approach 1:
The transactional logic is divided into separate online and standalone components with distinct execution paths. Each component has its own secure memory area, preventing interference between online and offline transaction logic. This segmentation enhances security by isolating sensitive operations while managing complexity through modular architecture.
Solution Approach 2:
Both transactional components share common root functions and secure memory spaces for basic operations. The root component provides shared resources (cryptographic functions, memory management) that are accessible by both components in read mode, reducing redundancy and managing complexity through resource sharing.
3Reliability
If the terminal uses separate secure memory spaces for different transactional components, then data security is improved, but the manufacturing cost increases
Solution Approach 1:
The secure memory space is segmented into distinct areas for online and standalone transactional components. Each component has dedicated memory space for its specific data, preventing unauthorized access and data interference. This segmentation enhances data security while using efficient memory management to control manufacturing costs.
Solution Approach 2:
The root component provides universal access to common secure memory areas and cryptographic functions for both transactional components. This shared infrastructure reduces the total memory capacity required compared to completely isolated systems, balancing security requirements with manufacturing cost considerations.
Data Source
AI summary
A method for processing a transaction using a transaction device of a user, carried out within an electronic transaction terminal called a transaction terminal, and includes at least one connection interface for connecting to at least one communication network. Such a method includes: determining the availability of a communication network recorded in a secure memory space of the terminal; receiving an instruction to carry out a transaction; and selecting from an online transaction component and an autonomous transaction component, a transaction component to be activated in accordance with the communication network availability, the autonomous transaction component being activated when any communication network is unavailable, and carrying out the transaction by means of the activated transaction component, the transaction components using a root component which executes basic functions common to the two transaction components, the functions of the root component being protected and only accessible when read by the transaction components.

