Virtual Terminal PIN Encryption for Hardware-Free Secure Transfers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional PIN entry systems require dedicated hardware and expose PIN information to data transfer service providers, compromising security and privacy.
Innovation Solution
A virtual terminal hosted by a secure element on a multipurpose device encrypts PINs and transaction data using multiple layers of encryption, ensuring secure data transfer without the need for separate hardware and allowing plain format PIN usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional PIN entry systems are used, then PIN entry functionality is achieved, but security and privacy are compromised due to exposure to data transfer service providers
Solution Approach 1:
A virtual terminal is introduced as an intermediary component between the user and the data transfer service provider. The virtual terminal, hosted by a secure element, captures PIN entries, encrypts them using multiple layers of encryption, and transmits only the encrypted data. This intermediary prevents direct exposure of PIN information to unauthorized entities while maintaining the necessary functionality for secure PIN entry.
2Reliability
If dedicated hardware is used for PIN entry, then security is improved, but device complexity increases
Solution Approach 1:
Instead of using dedicated physical hardware, the patent creates a virtual copy of the terminal functionality through software. The virtual terminal is implemented as a software component hosted within a secure element, replicating the security functions of dedicated hardware without requiring separate physical devices. This approach maintains security while reducing overall device complexity by eliminating the need for additional hardware components.
Solution Approach 2:
The secure element serves multiple functions: it hosts the virtual terminal, performs encryption operations, and manages security protocols. By making the secure element multi-functional, the system avoids adding separate dedicated hardware for PIN entry, thereby reducing device complexity while maintaining security through the consolidation of security-related functions in a single component.
3Reliability
If multiple layers of encryption are used, then data protection is improved, but processing time increases
Solution Approach 1:
The system performs encryption operations in advance and stores the encrypted PIN data in the secure element. When a data transfer is needed, the pre-encrypted data can be quickly retrieved and transmitted without repeating the full multi-layer encryption process, thereby reducing processing time while maintaining strong data protection through the multiple layers of encryption.
Data Source
AI summary
Techniques for using a virtual terminal on a multipurpose device for PIN entry to authorize a data transfer are described herein. These techniques provide the secure receipt of each PIN digit by the device and encryption of the PIN multipurpose device and while the PIN entry data is transferred, while still providing the information to a server for further processing.


