CLOUD-BASED POINT-OF-SALE PLATFORM
Disclosed herein are apparatus, method, and system embodiments for securing a cloud-based point-of-sale device. An embodiment includes a processing module and a communication module. The processing module is configured to operate with an operating system (OS) secured against alteration and to perform one or more purchase transactions. The communication module is configured to selectively enable acceptance of data via a secure communications path.
1 . A register device comprising:
a processing module configured to operate with an operating system (OS) secured against alteration and to perform one or more purchase transactions; and
a communication module configured to selectively enable acceptance of data via a secure communications path.
2 . The register device of claim 1 , wherein the communication module is configured to transmit register device activity data via the secure communications path to a back-end system.
3 . The register device of claim 2 , wherein the processing module is configured to accept a modification from the back-end system to address one or more identified security threats based on the register device activity data.
4 . The register device of claim 2 , wherein the register device activity data comprises user preferences, software patches, merchant inventory data, employee information, financial transactions, office management transactions, or a combination thereof.
5 . The register device of claim 1 , further comprising:
a peripheral device port.
6 . The register device of claim 5 , wherein the peripheral device port comprises a Universal Serial Bus port configured to provide power to and to disable data input from the peripheral device.
7 . The register device of claim 1 , wherein the communication module is further configured to disable the acceptance of data except in response to a request initiated by the register device.
8 . The register device of claim 1 , further comprising a security circuit configured to store a certificate and to validate the OS, based on the certificate.
9 . A method comprising:
providing an operating system (OS) secured onto a processing module of a register device used to perform one or more purchase transactions, wherein the operating system is secured against alteration; and
selectively enabling, with a communication module, acceptance of data via a secure communications path.
10 . The method of claim 9 , further comprising:
transmitting register device activity data via the secure communications path to a back-end system to identify one or more security threats based on the register device activity data.
11 . The method of claim 9 , further comprising:
providing power to a peripheral device via a peripheral device port of the register device; and
disabling data input, from the peripheral device to the register device, via the peripheral device port.
12 . The method of claim 9 , wherein the selectively enabling acceptance of data comprises communicating with a back-end system via a wired communication path, a wireless communication path, or a combination thereof.
13 . A system comprising:
a back-end system; and
a register device in communication with the back-end system, wherein the register device comprises:
a processing module configured to operate with an operating system (OS) secured against alteration and to perform one or more purchase transactions; and
a communication module configured to selectively enable acceptance of data via a secure communications path from the back-end system.
14 . The system of claim 13 , wherein the back-end system configured to communicate via the secure communications path comprises a networked enterprise storage system configured to store register device activity data accepted from the register device.
15 . The system of claim 14 , wherein the register device activity data comprises user preferences, software patches, merchant inventory data, employee information, financial transactions, office management transactions, or a combination thereof.
16 . The system of claim 14 , wherein the back-end system is configured to identify one or more security threats based on the register device activity data.
17 . The system of claim 16 , wherein the processing module is configured to accept a modification from the back-end system to address the one or more identified security threats.
18 . The system of claim 13 , wherein the register device further comprises:
a peripheral device port.
19 . The system of claim 18 , wherein the peripheral device port comprises a Universal Serial Bus port configured to provide power to and to disable data input from a peripheral device.
20 . The system of claim 13 , wherein the register device further comprises a security circuit configured to store identification data and an encryption key and to verify, based on the identification data and encryption key, that an update is authentic.