System and method to prevent unauthorized usage of card readers and modular electronic funds transfer point of sale device
A contactless card reader comprises a contactless card reader front-end coupled to a processor. A communications module is coupled to the processor and a set of sensors is coupled to the processor. The set of sensors determines parameters related to the location, orientation and motion of the card reader. The processor receives the parameters from the set of sensors and utilizes the parameters and scenario configuration data to evaluate a rule. The result of the evaluation of the rule results in a limitation on the operation of the card reader. The communications module is configured to intermittently receive the scenario configuration data from external sources.
1 . A terminal device certified to process card-based requests, the terminal device comprising:
a first subsystem that processes a first card data in a card-based request received by the terminal device, the first subsystem certified against a first standard and against a second standard that is different from the first standard;
a second subsystem, communicatively coupled with the first subsystem, that processes a second card data during the card-based request, the second subsystem certified against the first standard and the second standard, wherein certification of the terminal device to process card-based requests is based at least in part on both the first subsystem and the second subsystem being certified against the first standard and the second standard; and
a new subsystem that replaces one of the first subsystem or the second subsystem, wherein only the new subsystem is recertified against the first standard and the second standard, without recertifying the terminal device as a whole, and without recertifying the first subsystem when the second subsystem is replaced or the second subsystem when the first subsystem is replaced, thereby maintaining certification of the terminal device to process new card-based requests.
2 . The terminal device of claim 1 , wherein the first subsystem comprises a card reading interface subsystem, and the first standard comprises an account data security standard.
3 . The terminal device of claim 2 , wherein the second subsystem comprises a card holder authentication subsystem, and the second standard comprises one of a card holder authentication security standard.
4 . The terminal device of claim 2 , wherein the processing the card-based requests comprises:
obtaining parameters corresponding to a location, an orientation, or a motion of the terminal device;
evaluating a rule based on the parameters; and
limiting an operation of the card reading interface subsystem based at least on the evaluation of the rule.
5 . The terminal device of claim 1 , further comprising:
the first subsystem reads card data from a card used in making the card-based request and transmits the card data to the second subsystem, the first card data comprising the card data read by the first subsystem; and
the second subsystem receives the card data from the first subsystem, and authenticates the card-based request at least in part based on the card data, the second card data comprising the card data received from the first subsystem.
6 . The terminal device of claim 5 , wherein the first subsystem encrypts the card data prior to transmission of the card data to the second subsystem.
7 . The terminal device of claim 5 , wherein the second subsystem receives user authentication information and performs an offline authentication with the card used in the card-based request.
8 . The terminal device of claim 7 , wherein the user authentication information comprises a personal identification number (PIN).
9 . The terminal device of claim 5 , wherein the second subsystem receives user authentication information, encrypts the user authentication information, and transmits the encrypted user authentication information to a remote server for approval of the card-based request.
10 . The terminal device of claim 1 , wherein the first subsystem and the second subsystem are comprised in separate, independent devices of the terminal device.
11 . The terminal device of claim 1 , wherein cards associated with the card-based requests include one or more of magnetic stripe cards, chip cards, contactless cards, or device emulated cards.
12 . A method of operating a terminal device certified to process card-based requests, the method comprising:
configuring a first subsystem for processing a first card data in a card-based request received by the terminal device against a first standard and against a second standard that is different from the first standard;
configuring a second subsystem for processing a second card data during the card-based request, the second subsystem communicatively coupled with the first subsystem, against the second standard and against the first standard, wherein certification of the terminal device to process the card-based requests is based on both certification of the first subsystem and the second subsystem against the first standard and the second standard; and
in response to replacing one of the first subsystem or the second subsystem with a new subsystem, recertifying only the new subsystem against the first standard and the second standard, without recertifying the terminal device as a whole, and without recertifying the first subsystem when the second subsystem is replaced or the second subsystem when the first subsystem is replaced, thereby maintaining certification of the terminal device to process new card-based requests.
13 . The method of claim 12 , further comprising:
reading, by the first subsystem, card data from a card used in making the card-based request, and transmitting the card data to the second subsystem, the first card data comprising the card data read by the first subsystem; and
receiving, by the second subsystem, the card data from the first subsystem, and authenticating the card-based request at least in part based on the card data, the second card data comprising the card data received from the first subsystem.
14 . The method of claim 13 , wherein the first subsystem encrypts the card data prior to transmission of the card data to the second subsystem.
15 . The method of claim 13 , wherein the second subsystem receives user authentication information and performs an offline authentication with the card used in the card-based request.
16 . The method of claim 13 , wherein the second subsystem receives user authentication information, encrypts the user authentication information, and transmits the encrypted user authentication information to a remote server for approval of the card-based request.
17 . The method of claim 12 , wherein the first subsystem and the second subsystem are comprised in separate, independent devices of the terminal device.
18 . A non-transitory machine readable storage medium storing instructions, which when executed by a terminal device, causes the terminal device to perform operations for operating the terminal device certified to process card-based requests, the operations comprising:
configuring a first subsystem for processing a first card data in a card-based request received by the terminal device against a first standard and against a second standard that is different from the first standard;
configuring a second subsystem for processing a second card data during the card-based request, the second subsystem communicatively coupled with the first subsystem, against the second standard and against the first standard, wherein certification of the terminal device to process the card-based requests is based on both certification of the first subsystem and the second subsystem against the first standard and the second standard; and
in response to replacing one of the first subsystem or the second subsystem with a new subsystem, recertifying only the new subsystem against the first standard and the second standard, without recertifying the terminal device as a whole, and without recertifying the first subsystem when the second subsystem is replaced or the second subsystem when the first subsystem is replaced, thereby maintaining certification of the terminal device to process new card-based requests.
19 . The non-transitory machine readable medium of claim 18 , the operations further comprising:
reading, by the first subsystem, card data from a card used in making the card-based request, and transmitting the card data to the second subsystem, the first card data comprising the card data read by the first subsystem; and
receiving, by the second subsystem, the card data from the first subsystem, and authenticating the card-based request at least in part based on the card data, the second card data comprising the card data received from the first subsystem.
20 . The non-transitory machine readable medium of claim 19 , wherein the second subsystem receives user authentication information, encrypts the user authentication information, and transmits the encrypted user authentication information to a remote server for approval of the card-based request.