IP Library Granted Patent US 9,264,228
Granted Patent B2
US 9,264,228 · App. 14/178,174 · Granted Feb 16, 2016

System and method for a secure display module

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,264,228
App. No.
14/178,174
Granted
Feb 16, 2016
Kind
B2
Abstract

A system for a secure display module includes a display element array, a driver controller, a communication interface, a host controller and a cryptographic engine. The display element array includes one or more segments, and the driver outputs are configured to drive the one or more segments, respectively. The host controller is configured to send commands and data to the driver controller via the communication interface and the cryptographic engine is configured to encrypt communication data between the display element array and the host controller.

Claims (96)

1. A system for a secure display module comprising:

a display element array comprising one or more segments;

a display controller comprising driver outputs to drive the one or more segments, respectively;

a Personal Identification Number (PIN) pad;

a communication interface;

a host controller;

a cryptographic engine to enable performance of cryptographic operations on data,

the cryptographic operations comprising one or more of data encryption, authentication, digital signature, or hashing,

wherein the cryptographic engine stores one or more cryptographic keys for the performance of the cryptographic operations,

said one or more cryptographic keys are symmetric;

wherein a first portion of the data comprises commands and data to be sent by the host controller to the display controller via the communication interface, and

the commands and data are encrypted by the host controller before being sent to the display controller; and

a second portion of the data comprises PIN digits based on positional inputs entered at the PIN pad,

wherein the encrypted commands and data sent from the host controller are decrypted by the display controller, and information displayed on the display element array is generated from the decrypted commands and data.

2. The system of claim 1 , wherein the cryptographic engine stores one or more identification tokens for mutual authentication with the host controller.

3. The system of claim 1 , wherein the one or more cryptographic keys comprise one of fixed key, master-session key or Derived Unique Key Per Transaction (DUKPT).

4. The system of claim 1 , wherein the display element array further comprises elements comprising light-emitting diodes, seven-segment, fourteen-segment, sixteen-segment display elements, mechanical flip disc display elements and wherein the elements are in the form of pixels, line segments or icons.

5. The system of claim 1 , further comprising an application to display a randomized number grid in the display element array, and wherein the positional inputs entered at the PIN pad correspond to the randomized number grid.

6. The system of claim 5 , wherein the positional inputs entered at the PIN pad are sent to the display module, and further wherein

the PIN digits are decoded by the display module, from the entered positional inputs,

an encrypted PIN is generated based on the PIN digits, and the encrypted PIN is sent back to the PIN pad.

7. A method for a secure display module comprising:

providing a display element array comprising one or more segments;

providing a display controller comprising driver outputs to drive the one or more segments, respectively;

providing a Personal Identification Number (PIN) pad;

providing a communication interface;

providing a host controller;

providing a cryptographic engine to enable performance of cryptographic operations on data,

said data comprising a first portion of data and a second portion of data,

the cryptographic operations comprising one or more of data encryption, authentication, digital signature, or hashing,

wherein the cryptographic engine stores one or more cryptographic keys for the performance of the cryptographic operations, and

said one or more cryptographic keys are asymmetric;

encrypting, by the host controller, said first portion of data using the stored one or more cryptographic keys,

wherein the first portion comprises commands and data to be sent by the host controller to the display controller via the communication interface;

sending said encrypted first portion of data to the host controller;

encrypting said second portion of data using the stored one or more cryptographic keys,

wherein the second portion comprises PIN digits based on positional inputs entered at the PIN pad;

decrypting, by the display controller, the encrypted commands and data sent from the host controller; and

displaying, on the display element array, information generated from the decrypted commands and data.

8. The method of claim 7 , wherein the cryptographic engine stores one or more identification tokens for mutual authentication with the host controller.

9. The method of claim 7 , wherein the one or more cryptographic keys comprise one of fixed key, master-session key or Derived Unique Key Per Transaction (DUKPT).

10. The method of claim 7 , wherein the display element array further comprises elements comprising light-emitting diodes, seven-segment, fourteen-segment, sixteen-segment display elements, mechanical flip disc display elements and wherein the elements are in the form of pixels, line segments or icons.

11. The method of claim 7 , further comprising providing an application to display a randomized number grid in the display element array, and wherein the positional inputs entered at the PIN pad correspond to the randomized number grid.

12. The method of claim 11 , further comprising sending the positional inputs entered at the PIN pad to the display module;

decoding, at the display module, the entered positional inputs into the PIN digits;

generating an encrypted PIN based on the encrypting of the second portion of data; and

sending the encrypted PIN back to the PIN pad.

13. A method for a secure display module comprising:

providing a display element array comprising one or more segments;

providing a display controller comprising driver outputs to drive the one or more segments, respectively;

providing a Personal Identification Number (PIN) pad and an application to display a randomized number grid in the display element array,

wherein the PIN pad is used to enter positional inputs corresponding to the randomized number grid;

providing a communication interface;

providing a host controller;

sending the positional inputs entered at the PIN pad to the display module;

decoding, at the display module, the entered positional inputs into PIN digits;

providing a cryptographic engine to enable performance of cryptographic operations on data,

said data comprising a first portion of data and a second portion of data,

the cryptographic operations comprising one or more of data encryption, authentication, digital signature, or hashing,

wherein the cryptographic engine stores one or more identification tokens for mutual authentication with the host controller,

wherein the cryptographic engine stores one or more cryptographic keys for the performance of the cryptographic operations, and

said one or more cryptographic keys are symmetric;

encrypting, by the host controller, said first portion of data using the stored one or more cryptographic keys,

wherein the first portion comprises commands and data to be sent by the host

controller to the display controller via the communication interface;

sending, by the host controller, the encrypted first portion of data to the display controller;

encrypting said second portion of data using the stored one or more cryptographic keys,

wherein the second portion comprises the PIN digits;

generating an encrypted PIN based on the encrypting of the second portion of data;

sending the encrypted PIN back to the PIN pad;

decrypting, by the display controller, the encrypted commands and data sent from the host controller; and

displaying, on the display element array, information generated from the decrypted commands and data.

14. A method for a secure display module comprising:

providing a display element array comprising one or more segments;

providing a display controller comprising driver outputs to drive the one or more segments, respectively;

providing a Personal Identification Number (PIN) pad and an application to display a randomized number grid in the display element array,

wherein the PIN pad is used to enter positional inputs corresponding to the randomized number grid;

providing a communication interface;

providing a host controller;

sending the positional inputs entered at the PIN pad to the display module;

decoding, at the display module, the entered positional inputs into PIN digits;

providing a cryptographic engine to enable performance of cryptographic operations on data,

said data comprising a first portion of data and a second portion of data,

the cryptographic operations comprising one or more of data encryption, authentication, digital signature, or hashing,

wherein the cryptographic engine stores one or more identification tokens for mutual authentication with the host controller,

wherein the cryptographic engine stores one or more cryptographic keys for the performance of the cryptographic operations, and

said one or more cryptographic keys are asymmetric;

encrypting, by the host controller, said first portion of data using the stored one or more cryptographic keys,

wherein the first portion comprises commands and data to be sent by the host controller to the display controller via the communication interface;

sending, by the host controller, the encrypted first portion of data to the display controller;

encrypting said second portion of data using the stored one or more cryptographic keys,

wherein the second portion comprises the PIN digits;

generating an encrypted PIN based on the encrypting of the second portion of data;

sending the encrypted PIN back to the PIN pad;

decrypting, by the display controller, the encrypted commands and data sent from the host controller; and

displaying, on the display element array, information generated from the decrypted commands and data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2022
From: BBPOS LIMITED
To: STRIPE, INC.
Reel/Frame 061790/0031 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2019
From: LO, CHI WAH; TSAI, HWAI SIAN
To: BBPOS LIMITED
Reel/Frame 047962/0078 →