Virtual Terminal PIN Encryption for Hardware-Free Secure Transfers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional PIN entry systems require dedicated hardware and expose PIN information to data transfer service providers, compromising security and privacy.

Innovation Solution

A virtual terminal hosted by a secure element on a multipurpose device encrypts PINs and transaction data using multiple layers of encryption, ensuring secure data transfer without the need for separate hardware and allowing plain format PIN usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional PIN entry systems are used, then PIN entry functionality is achieved, but security and privacy are compromised due to exposure to data transfer service providers

Engineering Contradiction:
ImprovesecurityVSAvoidPIN information exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A virtual terminal is introduced as an intermediary component between the user and the data transfer service provider. The virtual terminal, hosted by a secure element, captures PIN entries, encrypts them using multiple layers of encryption, and transmits only the encrypted data. This intermediary prevents direct exposure of PIN information to unauthorized entities while maintaining the necessary functionality for secure PIN entry.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated hardware is used for PIN entry, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of using dedicated physical hardware, the patent creates a virtual copy of the terminal functionality through software. The virtual terminal is implemented as a software component hosted within a secure element, replicating the security functions of dedicated hardware without requiring separate physical devices. This approach maintains security while reducing overall device complexity by eliminating the need for additional hardware components.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The secure element serves multiple functions: it hosts the virtual terminal, performs encryption operations, and manages security protocols. By making the secure element multi-functional, the system avoids adding separate dedicated hardware for PIN entry, thereby reducing device complexity while maintaining security through the consolidation of security-related functions in a single component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple layers of encryption are used, then data protection is improved, but processing time increases

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs encryption operations in advance and stores the encrypted PIN data in the secure element. When a data transfer is needed, the pre-encrypted data can be quickly retrieved and transmitted without repeating the full multi-layer encryption process, thereby reducing processing time while maintaining strong data protection through the multiple layers of encryption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12407517B2Secure pin entry using a virtual terminal
Publication Date: 2025.09.02 APPLE INC
  • US12407517B2 patent drawing
  • US12407517B2 patent drawing
  • US12407517B2 patent drawing

AI summary

Techniques for using a virtual terminal on a multipurpose device for PIN entry to authorize a data transfer are described herein. These techniques provide the secure receipt of each PIN digit by the device and encryption of the PIN multipurpose device and while the PIN entry data is transferred, while still providing the information to a server for further processing.