POINT OF SALE (POS) PERSONAL IDENTIFICATION NUMBER (PIN) SECURITY
    2.
    发明申请
    POINT OF SALE (POS) PERSONAL IDENTIFICATION NUMBER (PIN) SECURITY 有权
    销售点(POS)个人识别号码(PIN)安全

    公开(公告)号:US20130103948A1

    公开(公告)日:2013-04-25

    申请号:US13649841

    申请日:2012-10-11

    Applicant: Attaullah Baig

    Inventor: Attaullah Baig

    Abstract: A key is securely injected into a POS PIN pad processor in its usual operating environment. In response to entry of a personal identification number (PIN) into a PIN pad, the processor puts the PIN into a PIN block; puts additional random data into the PIN block; and encrypts the entire PIN block using asymmetric cryptography with a public key derived from the injected key residing in the PIN pad processor. The corresponding private key may be held securely and secretly by an acquirer processor for decrypting the PIN block to retrieve the PIN. The encrypted random data defends the PIN against dictionary attacks. Time stamp data and constant data encrypted with the PIN block enables a defense of the PIN against replay attacks and tampering. The method may also include accepting the PIN from a mobile phone in communication with the processor.

    Abstract translation: 在其通常的操作环境中,密钥可靠地注入POS PIN垫处理器。 响应于将个人识别号码(PIN)输入到PIN垫中,处理器将PIN放入PIN块中; 将额外的随机数据放入PIN块; 并且使用具有从驻留在PIN贴片处理器中的注入键导出的公开密钥的非对称加密来加密整个PIN块。 相应的私钥可以被获取者处理器安全地和秘密地保存,用于解密PIN块以检索PIN。 加密的随机数据保护PIN免受字典攻击。 使用PIN块加密的时间戳数据和常量数据可以防止PIN对重放攻击和篡改。 该方法还可以包括从与处理器通信的移动电话接受PIN。

    Point of sale (POS) personal identification number (PIN) security
    3.
    发明授权
    Point of sale (POS) personal identification number (PIN) security 有权
    销售点(POS)个人识别号码(PIN)安全

    公开(公告)号:US08819428B2

    公开(公告)日:2014-08-26

    申请号:US13649841

    申请日:2012-10-11

    Applicant: Attaullah Baig

    Inventor: Attaullah Baig

    Abstract: A key is securely injected into a POS PIN pad processor in its usual operating environment. In response to entry of a personal identification number (PIN) into a PIN pad, the processor puts the PIN into a PIN block; puts additional random data into the PIN block; and encrypts the entire PIN block using asymmetric cryptography with a public key derived from the injected key residing in the PIN pad processor. The corresponding private key may be held securely and secretly by an acquirer processor for decrypting the PIN block to retrieve the PIN. The encrypted random data defends the PIN against dictionary attacks. Time stamp data and constant data encrypted with the PIN block enables a defense of the PIN against replay attacks and tampering. The method may also include accepting the PIN from a mobile phone in communication with the processor.

    Abstract translation: 在其通常的操作环境中,密钥可靠地注入POS PIN垫处理器。 响应于将个人识别号码(PIN)输入到PIN垫中,处理器将PIN放入PIN块中; 将额外的随机数据放入PIN块; 并且使用具有从驻留在PIN贴片处理器中的注入键导出的公开密钥的非对称加密来加密整个PIN块。 相应的私钥可以被获取者处理器安全地和秘密地保存,用于解密PIN块以检索PIN。 加密的随机数据保护PIN免受字典攻击。 使用PIN块加密的时间戳数据和常量数据可以防止PIN对重放攻击和篡改。 该方法还可以包括从与处理器通信的移动电话接受PIN。

Patent Agency Ranking