Method and Device for Protecting Data Entered by Means of a Non-Secure User Interface

US2025045452A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2025045452-A1
Application numberUS-202418917218-A
CountryUS
Kind codeA1
Filing dateOct 16, 2024
Priority dateOct 18, 2018
Publication dateFeb 6, 2025
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In the field of payment terminals, a new generation of feature-rich payment terminals is emerging. These payment terminals are mass-produced and the level of security provided for data entry operations is low because the primary function of these communication terminals is not the entry of sensitive data. As a result, the data relating to payment transactions entered via these payment terminals are entered with a level of security that is not adequate as regards the sensitivity of the data entered. Accordingly, a communication terminal is provided, which secures data entered via a user interface of a communication terminal, by transmitting them among a stream of dummy data, and by encrypting all data, those actually entered by a user and the dummy data, before the transmission thereof to a secure data processing device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A secure transmission method for securely transmitting data entered via a user interface of a communication terminal to a secure data processing device, the method being implemented by a module for processing the entered data comprised in the communication terminal and comprising: receiving an encryption table from the secure processing device, receiving, from the user interface, a group of data sets comprising a first data set actually entered via the user interface and a plurality of second data sets, the entry whereof has been emulated by the user interface, encrypting, via said encryption table, all of the data sets received, and transmitting all of the encrypted data sets to the secure processing device. 2 . The secure transmission method according to claim 1 comprising, upon receiving a message confirming a decryption of the first data set from the secure processing device, establishing communication with a processing server. 3 . A communication terminal comprising: a user interface adapted for entering data, and at least one processor configured to process the entered data by: receiving an encryption table from the secure processing device, receiving, from the user interface, a group of data sets comprising a first data set actually entered via the user interface and a plurality of second data sets, the entry whereof has been emulated by the user interface, encrypting, via said encryption table, all of the data sets received, and transmitting all of the encrypted data sets to the secure processing device. 4 . The communication terminal according to claim 3 , further comprising a secure data processing device for securely processing the data entered via the user interface of the communication terminal, the secure data processing device comprising at least one processor configured to: transmit the encryption table to the module for processing the entered data, transmit said plurality of second data sets to the user interface, receive said plurality of second data sets encrypted using said encryption table in a phase during which: the data of the first data set, actually entered via the user interface and encrypted using said encryption table, are received by the secure data processing device. 5 . The communication terminal according to claim 3 , wherein the user interface consists of a touch screen. 6 . A non-transitory computer-readable medium comprising a processing module stored thereon comprising program code instructions for implementing a secure data transmission method when the instructions are executed by a processor of a communication terminal, the instructions configuring the communication terminal to securely transmit data entered via a user interface of a communication terminal to a secure data processing device by: receiving an encryption table from the secure processing device, receiving, from the user interface, a group of data sets comprising a first data set actually entered via the user interface and a plurality of second data sets, the entry whereof has been emulated by the user interface, encrypting, via said encryption table, all of the data sets received, and transmitting all of the encrypted data sets to the secure processing device.

Assignees

Inventors

Classifications

  • Verifying personal identification numbers [PIN] · CPC title

  • Access to banking information through M-devices · CPC title

  • using a touch-screen or digitiser, e.g. input of commands through traced gestures · CPC title

  • Payment applications installed on the mobile devices · CPC title

  • Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2025045452A1 cover?
In the field of payment terminals, a new generation of feature-rich payment terminals is emerging. These payment terminals are mass-produced and the level of security provided for data entry operations is low because the primary function of these communication terminals is not the entry of sensitive data. As a result, the data relating to payment transactions entered via these payment terminals…
Who is the assignee on this patent?
Banks And Acquirers Int Holding
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Feb 06 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).