Fuel dispenser user interface system architecture.
Abstract
A vending machine can include a touch display and a touch controller operatively connected to the touch display and configured to transmit display data to the touch display and receive input data from a touchscreen function of the touch display. The vending machine also includes a secure device operatively connected to the touch display for securing the display by managing touch input information provided to one or more applications based on the input data received from the touchscreen functionality. The vending machine has a processor operatively connected to the secure device for communicating access requests for the touch display to the secure device from the one or more applications along with an indication of whether the one or more applications are signed by an authorized entity. The secure device manages the touch input information provided to the one or more applications further based at least in part on the indication.

Term
7.2 yearsleft in the term
Expires 26 November 2033.
- Priority
- Filed
- Granted
- Today
- Expires
24 claims: 1 independent, 23 dependent
- 1REIVINDICACIONES Habiéndose descrito la invención como antecede, se reclama como propiedad lo contenido en las siguientes reivindicaciones:operativa, con la pantalla y configurado para transmitir los datos de visualización en la pantalla y para recibir los datos de entrada de una función de pantalla táctil de la pantalla;un dispositivo seguro conectado, en forma operativa, con la pantalla y configurado para asegurar la pantalla al menos mediante el manejo de la información de entrada de toque proporcionada a una o más aplicaciones en función al menos en parte de los datos de entrada recibidos a partir de la funcionalidad de pantalla táctil;y un procesador conectado, en forma operativa, con el dispositivo seguro y configurado para comunicar las peticiones de acceso de la pantalla al dispositivo seguro de la una o más de las aplicaciones junto con una indicación de si la una o más de las aplicaciones están firmadas por una IMPI* INSTITUTO MEXICANO DF. I.A KXOPIEDALi INDUSTRIAL entidad autorizada, en donde el dispositivo seguro permite pero limita la información de entrada de toque proporcionada a la una o más de las aplicaciones si la una o más las aplicaciones están firmadas por la entidad autorizada pero no están relacionada con el pago de bienes o servicios vendidos en la máquina expendedora.
- 2La máquina expendedora de conformidad con la reivindicación 1, caracterizada porgue el dispositivo seguro maneja la información de entrada de toque al menos en parte limitando la información de entrada de toque comunicada a la una o más de las aplicaciones cuando la una o más de las aplicaciones no están firmadas por la entidad autorizada.
- 3La máquina expendedora de conformidad con la reivindicación 2, caracterizada porque el dispositivo seguro limita la información de entrada de toque al menos en parte comunicando una indicación de uno de un número fijo de las regiones relacionadas con los datos de entrada recibidos a partir de la funcionalidad de pantalla táctil a la una o más de las aplicaciones no firmadas por la entidad autorizada.
- 4La máquina expendedora de conformidad con la reivindicación 2, caracterizada porque el dispositivo seguro limita la información de entrada de toque al menos en parte absteniéndose de comunicar los datos de entrada a la una o más aplicaciones no firmadas por la entidad autorizada. IMPI ,, -4Ζ7^».'·Γί·;ί5 :.· instituto mexicano LA PROPIEDA· f* •NDUSTIIAL
- 5La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el dispositivo seguro maneja la información de entrada de toque al menos en parte comunicando las coordenadas relacionadas con los datos de entrada recibidos a partir de la funcionalidad de pantalla táctil cuando la una o más aplicaciones están firmadas por la entidad autorizada.
- 6La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el procesador establece un canal seguro con el dispositivo seguro para la comunicación de las peticiones de acceso y las indicaciones al mismo.
- 7La máquina expendedora de conformidad con la reivindicación 6, caracterizada porque el procesador mantiene el canal seguro al menos en parte enviando un mensaje consistente de verificación de conexión al dispositivo seguro.
- 8La máquina expendedora de conformidad con la reivindicación 7, caracterizada porque el dispositivo seguro desactiva la pantalla basado al menos en parte en la determinación que el mensaje consistente de verificación de conexión no es recibido del procesador con respecto a un período de tiempo.
- 9La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el procesador es INSTITUTO MEXICANO DE LA PROPIEDAD VΛ INDUSTRIAL * configurado para almacenar una lista de una o más firmas de entidades autorizadas y para determinar si la una o más de las aplicaciones están firmadas por una firma de una entidad autorizada al menos en parte determinando si la firma está en la lista de una o más firmas.
- 10La máquina expendedora de conformidad con la reivindicación 9, caracterizada porque la lista de la una o más de las firmas incluye una firma que corresponde con el fabricante de la máquina expendedora o el sitio de venta al menudeo en el cual opera la máquina expendedora.
- 11La máquina expendedora de conformidad con la reivindicación 9, caracterizada porque el dispositivo seguro comunica una lista de la una o más firmas al procesador en función del establecimiento de un canal seguro con el procesador.
- 12La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el dispositivo seguro comprende el controlador de toque.
- 13La máquina expendedora de conformidad con la reivindicación 12, caracterizada porque el dispositivo seguro comprende una placa curva de anti-manipulación que encierra el controlador de toque.
- 14La máquina expendedora de conformidad con la reivindicación 13, caracterizada porque la placa curva de anti-manipulación comprende una malla de alambre configurada IMPI INSTITUTO MEXICAN. DE LA ÍÜOI'ILDAD INDUSTRIAL para detectar la remoción de la placa curva de antimanipulación .
- 15La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el dispositivo seguro comprende un dispositivo de entrada (PED) de número de identificación personal (PIN).
- 16La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el dispositivo seguro es conectado, en forma operativa, con la pantalla al menos mediante un cable acoplado con un conector de dispositivo del dispositivo seguro y otro conector de dispositivo de la pantalla.
- 17La máquina expendedora de conformidad con la reivindicación 16, caracterizada porque el conector de dispositivo o el otro conector de dispositivo comprenden componentes que detectan la remoción al menos del cable.
- 18La máquina expendedora de conformidad con la reivindicación 17, caracterizada porque el dispositivo seguro es configurado para borrar al menos una porción de una memoria en donde los componentes detectan la remoción del por lo menos un cable.
- 19La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque comprende además una tarjeta de circuito impreso de interconexión de concentrador (HIP) y un segundo procesador, en donde el procesador y el segundo procesador son instalados en los lados adyacentes de la HIP.
- 20La máquina expendedora de conformidad con la reivindicación 1, caracterizada además porque comprende componentes de distribución de combustible configurados para facilitar la distribución de combustible, para medir una cantidad de combustible suministrado en una transacción, y para dar salida a una cantidad hacia el dispositivo seguro para su presentación en la pantalla, en donde el dispositivo seguro además es configurado para manejar la operación al menos de uno de los componentes de distribución de combustible para controlar la distribución de combustible.
- 21La máquina expendedora de conformidad con la reivindicación 1, caracterizada porque el dispositivo seguro determina si la una o más aplicaciones están firmadas por una entidad autorizada en función al menos en parte de si un canal seguro es establecido con la una o más aplicaciones.
- 22La máquina expendedora de conformidad con la reivindicación 21, caracterizada porque la una o más de las aplicaciones establecen el canal seguro con el dispositivo seguro en función al menos en parte en el cifrado de las comunicaciones con el dispositivo seguro.
- 23La máquina expendedora de conformidad con la reivindicación 22, caracterizada porque la una o más aplicaciones obtienen uno o más códigos de cifrado para el ΙΜΡΪ@ cifrado de la comunicación como parte de un proceso de verificación para la una o más aplicaciones, en donde la una o más aplicaciones están firmadas con una firma del fabricante de la máquina expendedora como parte del proceso 5 de verificación.
- 24La máquina expendedora de conformidad con la reivindicación 22, caracterizada porque el dispositivo seguro cifra una porción de la información de entrada de toque para la comunicación con la una o más aplicaciones a través del 10 canal seguro. * INSTITUTO MEXICANO DE LA 7ROHEDAD INDUSTRIAL
Independent claims24
320 paragraphs in 35 sections, as filed
(54) Title: FUEL DISTRIBUTOR USER INTERFACE SYSTEM ARCHITECTURE.
(54) Title: FUEL DISPENSER USER INTERFACE SYSTEM ARCHITECTURE.
(57) Summary
A vending machine may include a touch screen and a touch controller operatively connected to the touch screen and configured to transmit display data to the touch screen and to receive input data from a display function. touch screen touch. The vending machine also includes a secure device operatively connected to the touch screen to secure the screen by handling the touch input information provided to one or more applications based on the input data received from the touch screen functionality. The vending machine has a processor operatively connected to the secure device for communicating touch screen access requests to the secure device of one or more applications along with an indication of whether one or more of applications are signed by an authorized entity. The secure device handles the touch input information provided to one or more of the applications in addition based at least in part on the prompt.
(57) Abstract
A vending machine can include a touch display and a touch controller operatively connected to the touch display and configured to transmit display data to the touch display and receive input data from a touchscreen function of the touch display. The vending machine also includes a secure device operatively connected to the touch display for securing the display by managing touch input information provided to one or more applications based on the input data received from the touchscreen functionality. The vending machine has a processor operatively connected to the secure device for communicating access requests for the touch display to the secure device from the one or more applications along with an indication of whether the one or more applications are signed by an authorized entity. The secure device manages the touch input information provided to the one or more applications further based at least in part on the indication.
TO GO
PATENT TITLE No. 353246
Headlines):
GILBARCO, INC .; GILBARCO SRL
Home:
D nomination:
Classification;
Inventor (s)
IMPI
7300 W. Friendly Avenue, Greensboro, North Carolina, 27410, USA; Via de 'Cattani 220 / G, 1-50145, Firenze, ITALY
FUEL DISTRIBUTOR USER INTERFACE SYSTEM ARCHITECTURE.
CIP: G06F21 / 36 »GO6F7 / O4; 'GOéF2l / 52;' 0O6F21 / 57; G06Q20 / 00
CPC: G06F21 / 36; G06F21 / 44; G06F21 / &? 006 ^ 21/57; G06F21 / 83; G06F21 / 84
R0DG6R K. WILLIAMS; GIQv4 ^ fr € AF ^ H.LI '· i' V ,.
Number:
MX / a / 2015/006785
<img file="MX353246B_D0001.tif" />
<img file="MX353246B_D0002.tif" />
to go
US US '' '.,., 29 2012 •, <2S0 nbwi¿wiiíiltedd2C> 13
Validity: Twenty years
Expiration Date: November 26, 2033 Issue Date: January 5, 2018 *.
The reference patent W'etarga based on entos t
In accordance with the artletop the Le from the date of submission of the Sun
P
Who subscribes to this title is based on the provisions of HwíicW (Official Gazette of the Federation (6tO.h) s27 / 06/1991, rélprmá || a on 01/25/2006, 06/05 / 2009,06 / 01 / 2010,4M> 8/2 »lo, | r Regulations of the Mexican Institute of faAepteií articles 1, 3 °, 4 ', 5 ° fraction V subsection a), .16 frai 12/27/1999, amended on 10/10 / 2002, 07/29 / 200® Deputy Generals, Coordinator, Directors Di '' <sup><<<<></sup> t X. ·<sup>1</sup> , articles l '/ Z'fratxi ^ f ^ · ^ yy5 $ (Jeta tey of Industrial Property.
<img file="MX353246B_D0003.tif" />
and twenty extendable extensions, counted to er vigenBsJÍMerechos.
uerieiaies / -vjjuriius, k_.uuruiriauui, uticGiuies l> i ~ -
Departmental and other subordinates of the Mexican Institute *% e laRaífaed ^ dulStrial. 08/04/2004 and 09/13/2007). 'of the Industrial Property Law • tBÍ' 17 (08/1999, 01/26/2004, 06/16/2005, aór> V maso a), 4<sup>or</sup> and 12th sections I and III of ld / 07/2004, 07/28/2004 and 09/07/2007); utoMexicano de la Propiedad Industrial (DOF Ácuwdo that delegates powers to the Directors, Divisional Deputy Directors, Coordinators F. 12/15/1999, amended on 02/04/2000, 07/29/2004,
This letter is signed with an advanced electronic signature (FIEL), based on articles 7 BIS 2 of the Industrial Property Law; 3 of its Regulations, and 1 fraction III, 2 fraction V, 26 BIS and 26 TER of the Agreement establishing the guidelines for the use of the Electronic Payment and Services Portal (PASE) of the Mexican Institute of Industrial Property, in the procedures indicated.
<img file="MX353246B_D0004.tif" />
DIVISIONAL DIRECTOR OF PATENTS NAHANNY CANAL REYES
Original string:
NAHANNY MARISOL CANAL REYES | 00001000000403252793 | Administration Service
Tax | 1695 || MX / 2018/2562 | MX / a / 2015/006785 | PCT patent title | 1223 | GAGV | Page (s) 1 | 2hVHeOWkhzAFHEJ8mTtrpV3Nz50 =
Digital stamp:
IWGsvZ4CPTeoY + OW9c187HYkSln8QfHAmBdyVT / Zb3eCKCcqFODYqOg + l8 / Ht9E / odHqzENg4uLvQXISkigKJtGseb
G6EF3NN1ksawEP8uZ7CJfemA7tljAcAnpr9u1mn + 1q9UZWRUtlX97Lf2G33zr1kd63ShD349GVj4ksh3dKMPP5g1xS
U5GH3J8AatF49buRZ5enaF / 7v2MOL05ydYPYWZgU6TVO5ELkmwRmqEuHSegCHID9xgvJRMCYgHj¡F5tWgRAIhDqtQHQQHB4BZHQQBzBQHZBQQB4HZQQ04
Sand! No 550. Floor 1, Pueblo Santa María Pepepán, Xochimilco, 16020. Mexico City.
(55) 53340700 www.gob.mx/impi
<img file="MX353246B_D0005.tif" />
3Μ
IMPI MEXICAN INSTITUTE OF THE INDUSTRIAL PRUHF.OAp
<img file="MX353246B_D0006.tif" />
USUÁRWDE INTERFACE SYSTEM ARCHITECTURE
FUEL DISTRIBUTOR
Field of the Invention
The subject matter described herein relates generally to fuel dispensers, and more specifically, relates to the user interfaces employed by fuel dispensers.
Background of the Invention
Typically, fuel dispensers include a controller configured to handle sensitive payment information received from a user to effect payment for distributed fuel to the user. Sensitive payment information is usually provided to the fuel distributor by means of one or more components, such as a card reader and a PIN pad. Any sensitive payment information received by the PIN pad is generally encrypted and transmitted to the controller regardless of whether the PIN pad uses a separate controller. Because the controller is configured to handle sensitive payment information, it is usually subject to some manual offline certification.
Ref .: 257081 security requirements imposed on the devices that handle this information, which could include a '> *. -O process.
IΜ ί 'ι fNáCTlT'J'rO MHX'CANC “* ™ k ^' 2?
ΙΝΟΙλ'ΤΚΙ * I
Some dealers employ large display screens, not only to invite the user to enter payment information, select fuel grades, choose car wash, etc., using a PIN pad or other buttons, but also to display o Present advertisements, loyalty information, kitchen menus within a service station, and other information. Existing touch-sensitive displays allow user interaction by touching regions on the screen. However, due to certain regulations these touch-sensitive displays may be limited in the functionality provided to users.
Add it from the invention
The following presents a simplified summary of one or more aspects of the subject matter described herein to provide a basic understanding of the subject matter. This summary is not an extensive overview of all aspects covered, it is not intended to identify the key or critical elements of all aspects or to delineate the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that follows. Various aspects described herein relate to the control of a touch screen by means of a secure device
<img file="MX353246B_D0007.tif" />
INSTITUTO MWCANO M LA TSOP! £ DAL> INDUSTRIAL
<img file="MX353246B_D0008.tif" />
that regulates the functionality allowed paxa — ap licué i cutas' er related devices that access the touch screen, if the access is for the content display and / or for the reception of the touch input related to this content. In one example, functionality may be restricted for certain applications depending on the type of the applications, depending on whether the applications are signed with a signature from an authorized entity, depending on whether another application is currently using the touch screen. , and / or the like. Additionally, functionality may vary in these scenarios, such as offering a limited number of touch regions on the touch screen for applications that are not signed with a signature from an authorized entity and / or applications that are of a certain type. Anti-tamper devices can be used to facilitate the physical security of various devices, such as the device that controls the touch screen, the processor that runs the applications, etc.
For the achievement of the foregoing and related purposes, one or more of the aspects comprises the characteristics hereinafter, which are fully described and particularly pointed out in the claims. The following description and the attached figures point out certain characteristics in detail
<img file="MX353246B_D0009.tif" />
MEXICAN INSTITUTE »ε INDUSTRIAL aroeildad
<img file="MX353246B_D0010.tif" />
illustrative of one or more of the aspects, however; These characteristics are indicative of a few of the various ways in which the principles of various aspects could be employed, and it is intended that this description include all these aspects and their equivalents.
Brief Description of the Figures
Hereinafter, the aspects will be described in conjunction with the attached figures, provided to illustrate and not to limit the aspects described, where the same designations could denote the same elements, and in which:
Figure 1 is a partially schematic perspective view of a fuel feed environment in accordance with the aspects described herein;
<td>The</td><td>Figure 2 is</td><td>a</td><td>view in</td><td>raised</td><td>frontal</td>
<td>partially</td><td>schematic of</td><td>a</td><td>distributor</td><td colspan="2">made out of fuel</td>
<td>what could i</td><td>be used in</td><td>the</td><td>environment of</td><td colspan="2">feed</td>
<td>fuel</td><td>from Figure 1</td><td>of</td><td colspan="2">according to</td><td>aspects</td>
<td>described in</td><td>the present;</td><td></td><td></td><td></td><td></td>
Figure 3 is a schematic representation of the components of a user interface of a fuel dispenser according to the aspects described herein;
Figure 4 is an example system of use in a fuel distributor that allows the entry of
<img file="MX353246B_D0011.tif" />
INSTITUTO MEXICANO 3g LA? RO «AGE: ndu;> T! U Touch screen; and
Figure 5 is an example methodology for processing access requests to a touch screen.
Detailed description of the invention
In the following, various aspects will be referred to in detail, one or more examples of which are illustrated in the attached figures. Each example is provided by way of explanation, and not limitation of aspects. In fact, it will be apparent to those skilled in the art that modifications and variations may be
<td>made</td><td>in the aspects</td><td>described</td><td>without</td><td>turn away</td><td>of the</td>
<td>scope o</td><td>spirit of the</td><td>themselves.</td><td>By</td><td>example,</td><td>the</td>
<td colspan="2">illustrated features o</td><td>described</td><td>how</td><td>part of</td><td>a</td>
example could be used in another example to produce yet another example. Thus, the aspects described are intended to cover such modifications and variations and to fall within the scope of the appended claims and their equivalents.
Herein, various aspects are described that relate to the control of a touch screen that uses a secure device in a fuel dispenser to provide a level of control over the functionality of the touch screen. In this way, the functionality of the sensitive screen
<img file="MX353246B_D0012.tif" />
touch may be limited for certain applications ^ oii & su --- En *<sup>i</sup>tnr "<sup>w</sup>For example, a driver for the touch screen may limit functionality for applications based on the type of application, based on whether the applications are signed by an authorized entity, based on whether another application is using the touch screen , and / or the like. For example, the controller may limit the touch screen at least in part by filtering the event related input information provided to one or more of the applications, by blocking access of the touch screen of one or more of the applications. applications, and / or the like.
In a specific example, the controller may operate within a fuel distributor's Personal Identification Number (PIN) input device (PED), or at least one device that comprises a subset of PED components in this example, the PED may include one or more device connectors for coupling the touch screen to provide the display data therewith and / or receive touch input events therefrom. The PED can provide secure override control of the touch screen via the controller. The PED may also communicate with one or more related applications or devices to provide
<img file="MX353246B_D0013.tif" />
FROM | _A INDUSTRIAL PROPERTY some functionality of the screen sens-ibio -— ai — the same subject to the safe control of cancellation.
For example, a System Module (SoM) can establish a secure channel with the PED to communicate encrypted application data to the PED. When the SoM runs an application signed by an authenticated entity, it can indicate to the PED that the data to / from the application is from an authenticated source. Based on this information, the PED determines and accordingly provides the level of touch screen access to the application.
Furthermore, although it is illustrated and described as included in a fuel dispenser, it will be appreciated that the aspects described herein can be similarly applied substantially to any vending machine that processes transaction payment from other processes involving confidential information while maintaining the ability to run other applications.
Certain aspects of the modalities described herein are related to the fuel feed environment, fuel dispensers, and user interfaces for fuel dispensers, examples of which could be found in the United States Patent Publications. United Nos. 2009/0265638 (titled System and Method for Controlling
<td>T 1J T) Ϊ</td><td>z '.....</td>
<td>.1MP i</td><td></td>
<td>MEXICAN INSTITUTE</td><td> '/*' - ·· ’ <sup>:</sup> ‘</td>
<td>OE THE PROPERTY</td><td>· ..., 'ij'</td>
<td>INDUSTRIAL</td><td> —*</td>
Secure Content and Non-Secure Content at a Fuel 'Dispenser ^ or Other Retail Device and filed on October 10, 2008), 2011/0047081 (titled Secure Reports for electronic Payment Systems, and filed on August 20, 2009), 2010 / 0268612 (titled Payment Processing System for Use in a Retail Environment Having Segmented Architecture, and filed on January 19, 2010), 2011/0134044 (titled Fuel Dispenser User Interface, and filed on June 09, 2010), 2012/0166343 (titled Fuel Dispensing Payment System for Secure Evaluation of Cardholder Data, and filed on December 22, 2010), 2011/0238511 (titled Fuel Dispenser Payment System and Method, and filed on March 07, 2011), 2012 / 0286760 (titled Fuel Dispenser Input Device Tamper Detection Arrangement, and filed on May 11, 2011), 2011/0231648 (titled System and Method for Selective Encryption of Input Data During a Retail Transaction, and filed on May 27, 2011), 2012/0059694 (titled Fuel Dispenser Application Framework and filed on August 03, 2011), and 2013/0300453 (titled Fuel Dispenser Input Device Tamper Detection Arrangement and filed on May 09, 2012 ), United States Patent Nos. 7, 607,576 (titled Local Zone Security Architecture for Retail Environments and published on October 27, 2009), 8, 392,846 (titled Virtual PIN pad for Fuel Payment Systems, and filed on
<img file="MX353246B_D0014.tif" />
<sup>TO</sup>'V
<img file="MX353246B_D0015.tif" />
January 2010), and 8, 558,685 (ti Γ11Ί a da R Amnt a__E ^ ijagú.ay. Tamper Detection Using Data Integrity Operations and filed on August 29, 2011), European Patent Application No. 1, 408,459 ( titled Secure Controller of Outdoor Payment You end up in Compliance with EMV Specifications and published on April 14, 2004). Each of the foregoing applications and patents is incorporated herein by reference as if it were designated in its entirety herein and is published for all uses.
FIG. 1 is a partially schematic perspective view of a fuel feed environment 100 adapted to provide fuel and to accept payment for distributed fuel. The fuel supply environment 100 includes at least one fuel distributor 200a and a central facility 102. Typically, one or more additional fuel dispensers, such as fuel dispenser 200b, could also be included within fuel feed environment 100. Fuel feed environment 100 could also include an awning system 104 that provides protection for fuel distributors 200a and 2 0 0b.
Central facility 102 includes a point-of-sale (POS) device 106 and a site controller 108 and could include additional computing devices, such as
INSTITUTO Mexicano de LA PRONEIJAÜ industrial as cashier workstations and / <T yeieiite -; - Bn — el. Illustrated example, POS 106 includes an associated card reader and payment terminal 110. Each of POS 106 and site controller 108 could also include a display, a touch screen, and / or other devices, such as a printer. . It should be understood that the functionality of POS 106, site controller 108, and any of the additional computing devices within central facility 102 could be incorporated into a single computer or server. Alternately, these computing devices could be interconnected, operationally, through a local area network (LAN). An example of a suitable system that could be used in conjunction with the subject matter described herein combines the functions of POS 106 and site controller 108, with which multiple payment terminals 110 could be operatively connected, is the PASSPORT system offered by Gilbarco Inc. of Greensboro, North Carolina.
<td>Will be</td><td>appreciated that the</td><td colspan="3">power environment of</td>
<td colspan="2">fuel 100 could include a</td><td colspan="2">number of others</td><td>components</td>
<td>that facilitates</td><td>the distribution of</td><td>fuel.</td><td>In</td><td>the example</td>
<td>provided</td><td>by Figure 1,</td><td>for example,</td><td>the</td><td>environment of</td>
<td>feeding</td><td>made out of fuel</td><td>100 includes</td><td colspan="2">two tanks</td>
<td>underground</td><td>storage</td><td>(USTs, for</td><td>their</td><td>acronyms in</td>
English) 112 and 114 configured to store fuel
<img file="MX353246B_D0016.tif" />
MEXICAN INSTITUTE »<- DF. LA? RCmi> AD Ct-x ·· INDUSTRIAL '-? -.
which is available for purchase. For example, USTs 112 and 114 could be stacked with their respective grades of fuel. USTs 112 and 114 are in fluid communication with an underground network of pipelines 116 with which distributors 200a and 200b are connected. As a result, fuel stored within USTs 112 and 114 could be supplied to dealers for purchase. Furthermore, in one example, information regarding USTs 112 and 114 (eg, tank level, environmental gauge, such as temperature around the tank, etc.) can be communicated to POS 106, the controller of site 108, or other device to allow tank monitoring and / or notification of other problems.
FIG. 2 is a partially schematic front elevation view of a fuel distributor 200 that could be used as the fuel distributors 200a and 200b in the fuel feed environment of FIG. 1. The fuel distributor 200 includes an interface for user 202 including a first controller 204, a second controller 206, a display 208, a card reader 210, and a number pad
212. The controller
204 is operatively connected to the controller
206 and with the screen
208, while controller 206 is operatively connected to controller 204 with card reader 210 and pad
IMPI
INSTITUTE, ΜΕΧϋ'ΛΝ. ' <sup>| C</sup> -a numeric 212. It will be appreciated that user interface 202 could include other components, such as a cash acceptor and / or a receipt printer, etc. Preferably, each of the controllers 204 and 206 includes an Ethernet adapter and communicates with the other controller by means of the transmission control protocol and the Internet protocol [eg, the transmission control protocol (TCP, ) / Internet Protocol (IP), User Datagram Protocol (UDP), etc.), as explained below. Alternatively, controllers 204 and 206 could be connected via a universal serial bus (USB) connection and could be configured to communicate via a USB connection or other wired or wireless connection ( for example, Bluetooth, a wireless local area network (WLAN), etc.). In one example, one or more of controllers 204 and 206 could be included within fuel dispenser 200 devices, such as display 208, PIN pad 212, etc., as described hereinafter, and In some examples, one or more of the 204 and 206 controllers may not be present, or may be replaced by another controller where the remaining controller implements the functionality so that the
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL replaced controller not necessary.
<img file="MX353246B_D0017.tif" />
For purposes of the following explanation, it will be appreciated that the card reader 210 could be any device or combination of devices configured to receive the data from the payment cards supplied by the users that contain the sensitive or confidential account information or payment (referred , generally, herein as sensitive information or confidential information). Card reader 210, for example, could be a magnetic strip card reader, a smart card reader, a contactless card reader, a radio frequency (RF) reader, or any combination thereof. Thus, the term payment card as used herein is intended to include magnetic strip cards, smart cards, contactless cards, and RF devices, as well as other forms of cards and devices that are configured to store and provide account information. The information received from this payment card is referred to herein as the payment data for explanation purposes, while the portion of the payment data sufficient to identify the account associated with the payment card is referred to as the sensitive payment data. In this way, it will be appreciated that the payment data as used herein could include both sensitive information
<img file="MX353246B_D0018.tif" />
MEXICAN INSTITUTE
FROM O *. PZO - INDUSTRIAL UNIT
<img file="MX353246B_D0019.tif" />
as not sensitive to payment. In addition, it will be appreciated that sensitive payment data may include other confidential information such as a PIN associated with the payment card, and which is also generally referred to as sensitive data, confidential information, or similar terms. .
In the currently described example, card reader 210 is configured to accept payment data from various types of payment cards, including credit and debit cards, prepaid and gift cards, travel cards, any type of card local / private, etc., accepted by the fuel feed environment 100.
It should be appreciated that card reader 210 could also be configured to receive account information from unpaid cards and other cards, such as loyalty, frequent shopper, rewards, points, advantage, and club cards. In addition, mobile payment can be provided, so the card does not need to be used to pay at the fuel distributor.
200 and / or the communication of a mobile device in the fuel distributor (for example, a near field communication (NFC, by its
NFC at the fuel distributor, a communication initiated through a mobile network, etc.,) can be used to initiate payment. The number pad 212
<img file="MX353246B_D0020.tif" />
it is also configured to receive the payment data '; such as the PIN associated with a payment card and / or mobile payment.
For at least this reason, the number pad 212 could be referred to in the following explanation as a PIN or PED pad.
In addition it will be appreciated that the fuel distributor 200 also includes various fuel distribution components configured to facilitate fuel delivery to a vehicle. For example, fuel dispenser 200 additionally includes a pipe network 214, a gauge 216, a push button 218, a valve 220, a hose 222, and a nozzle 224, which can be duplicated to allow multiple degrees supply made out of fuel. Controller 204 is operatively connected to one or more of these components, such as push button 218 and valve 220, to control the operation thereof and / or to manage fuel delivery by fuel distributor 200 Pipeline network 214 is in fluid communication with underground pipeline network 116, as described in Figure 1, to receive fuel from the USTs. Pipe network 214, hose 222, and nozzle 224 are also in fluid communication to supply fuel to a vehicle. In other examples described herein, fuel distributor 200 could include one of controllers 204 and
<img file="MX353246B_D0021.tif" />
INSTITUTE .MF, XIC<sup>TO</sup>NC
FROM THE 7RCHSDAD .ndustsjal
<img file="MX353246B_D0022.tif" />
06, in this case controller 2 06 could operate ies · fuel distribution components in place (or in addition).
User interface 202 is configured to facilitate fuel distribution and acceptance of payment for distributed fuel. For example, screen 208 is configured to provide instructions to the user regarding the fueling process and to view totals during and at the completion of the transaction. Display 208 can be a liquid crystal display (LCD), a light emitting diode (LED) display, a plasma display, etc. In addition, display 208 may be a touch screen or a non-touch screen. Card reader 210 and PIN pad 212 are configured to accept payment data (eg, as provided by the user). That is, card reader 210 can be configured to receive account information from a payment card, such as a credit or debit card. The PIN pad 212 is configured to receive at least the information associated with the payment card, such as a PIN from a debit card, the fractured zip code of a credit card, etc. In one example, the PIN 212 pad may be a physical PED, such as a code number pad, and / or
<img file="MX353246B_D0023.tif" />
IΜ
MEXICAN INSTITUTE "
From LA? RDi> Industrial £ DA0 -a virtual PED on screen 208 can be used! KJIñoes' described herein. As noted previously, other devices could be included within user interface 202, which could also be configured to facilitate financial transactions for distributed fuel. For example, a cash acceptor could be configured to handle transactions involving cash payments, while a receipt printer is configured to print the receipt based on completion of the fuel feeding process if desired.
User interface 202 could also be configured to exchange information with the user unrelated to fuel feed transactions. For example, display 208 could be configured to provide advertisements or other information to the user, such as advertisements regarding items available for sale at the associated convenience store. The PIN 212 pad (or a set of soft keys, such as those referred to below) could be configured to receive user selection regarding information displayed on the screen, such as whether the user is interested in nearby amusements or distractions . In this regard, for example, the PIN 212 pad can be used in conjunction with the card reader
<img file="MX353246B_D0024.tif" />
s 210 and / or screen 208 to communicate data that is not
<img file="MX353246B_D0025.tif" />
as sensitive as payment information.
Furthermore, a fuel feed environment 100 (Figure 1) can be configured so that the fuel dispenser 200 could be operatively connected to a wide area network (WAN) 228, just like the Internet. It should be understood that the fuel distributor 200 could be connected either directly to the WAN 228 or indirectly via one or more additional components, such as one or more devices 226. It will be appreciated that additional components could include routers, switches, gateways, and other devices that participate in the LAN referred to above. In one example, the devices
226 they may include one or more of the POS 106, the site controller 108 with which the fuel distributor is directly connected, etc. Alternately, fuel dispenser 200 is operatively connected to POS 106 and / or site controller 108 indirectly via LAN. An example of a proper configuration of the fuel feed environment computing devices is noted in US Patent Publication No.
2010/0268612, as previously mentioned. It should also be understood that other external resources, such as a
<img file="MX353246B_D0026.tif" />
IMPI TNSTmTO MEXICANO
FROM the industrial PROPERTY server 230, could be operatively connected to the WAN 228 and could be accessible to the fuel dispenser 200 and / or the fuel feed environment 100 (Figure 1) via the WAN.
Figure 3 illustrates a fuel distribution system 300 that provides touch-sensitive display functionality. For example, the fuel distribution system 300 may provide video services from a host 230 or other external device source. The fuel distribution system 300 includes a fuel distributor 200 with a display
<td colspan="2">touch sensitive 208</td><td>and</td><td>a</td><td>PED</td><td> 212 .</td><td>In</td><td>addition, the</td>
<td>distributor of</td><td colspan="2">fuel</td><td> 200</td><td>can</td><td colspan="2">include</td><td>a processor</td>
<td>device</td><td>filiar</td><td colspan="2">(AFP)</td><td> 302 ,</td><td>or</td><td>other</td><td>device</td>
electronic, to run applications that could access screen 208 through PED 212. AFP 302 may also include a system module (SoM) 304 that provides a system for running applications and / or interfacing with the PED 212. System 300 also includes LAN 226, POS 106, WAN 228, and Host 230. For example, fuel dispenser 200 can communicate on LAN 226 through POS 106 or another component, such as a router or other network device. In addition, LAN 226 can be coupled with WAN 228 (for example, directly through POS 106, through
IMPI 07¾
INSTITUTO MEXICANO 7, '- DE LA RXOPlEÜAD t. «- ¡.. · ί' V
INíXISTKlAL other network devices, etc.), and of estcT — iu<sup>,</sup>dllt? l<sup>r</sup>'ST', '™ pt [ed ^ ”' · allow fuel distributor 200 to communicate with remote components, such as drag 230. In yet another example, fuel distributor 200 can access WAN 22 8 a through other components, such as an integrated cellular modem (not shown) that allows access to WAN 228 through a mobile network (not shown), and / or the like.
The fuel distribution system 300 allows fuel supply or fill operation by means of a plurality of fuel distribution components (not shown). Additionally, host 230 could provide video, such as advertisements or other content, to one or more applications running on AFP 302, or could provide the application or at least some functionality thereof in a service model, etc. . In either case, the AFP 302 may require at least some access to screen 208 for one or more applications running on it. PED 212 can manage access to screen 208, as described, to ensure its security. Secure communications between PED 212 and screen 208 can be beneficial in this example, to prevent applications from obtaining confidential information through screen 208 when they are not authorized.
For example, PED 212 can secure
<img file="MX353246B_D0027.tif" />
<img file="MX353246B_D0028.tif" />
INSTITUTE M .-. XICA.S Say LA
INDUSTRIAL
<img file="MX353246B_D0029.tif" />
<img file="MX353246B_D0030.tif" />
communications to / from screen 208 by controlling screen 208 by means of a secured touch controller 206. In one example, PED 212 could not include the number pad, since touch screen 208 could be used to transmit numerical data. In this example, PED 212 may be a secure device that includes other electronic devices or components used by PEDs to prevent tampering or counterfeiting (eg, wire mesh). For example, since PEDs are typically used to obtain PIN numbers, zip fracture codes, or other information for processing transaction payments, PEDs are physically secured, as described herein, to avoid unauthorized entry or other access that could cause the exposure of this information. PEDs can be physically secured in accordance with the specifications of one or more of the standardization organizations to ensure adequate protection for users who use PEDs. In either case, the PED 212 can provide physical anti-tampering components or other measures by which the secured touch controller 206 is secured. PED 212 can also employ one or more controllers (not shown), printed circuit boards (PCBs), processors, etc.,
<img file="MX353246B_D0031.tif" />
MEXICAN INSTITUTE 'OF PROPERTY ζ' INDUSTRIAL '<
<img file="MX353246B_D0032.tif" />
<img file="MX353246B_D0033.tif" />
to provide the functionality described in — ie — preeeafee '»-
PED 212 can be connected to screen 208 by means of a 3 06 cable, or other communication means, to control access thereto. In addition, PED 212 can be connected to AFP 3 02 and / or SoM 3 04 via cable 308, or other communication means. Furthermore, it will be appreciated that cables 306 and / or 308 can be directly connected to the secured touch controller 206 and / or electronic devices in communication therewith. In any case, the SoM 3 04 can establish a secure channel with the PED 212 that facilitates access to certain functions of the screen 208, such as the screen output, the touch input information, etc. In one example, SoM 304 can verify whether applications running on AFP 302 that require access to touch screen 208 are signed by authorized entities, and can use PED 212 to provide different levels of functionality and / or or security based on this. In other examples, unsigned applications may attempt limited access to screen 208 through an unsecured direct connection between AFP 302 and PED 212.
In one example, PED 212 can provide varying levels of access to display 208 by means of a secured touch controller 206 based on at least one of the
<img file="MX353246B_D0034.tif" />
IMPI
INSTITUTO MEXICANO DE LA MIOriEDAD INDUSTRIAL screen status 208, if an application qqg rRgiiiflraacceso is signed, if an access request originates from SoM 3 04 or AFP 3 02, one or more parameters in the request, and / or Similar. In one example, PED 212 can provide access to at least one of the screen functionality of screen 208, the touch input events on screen 208, the limited touch input information (eg, a limited number of regions that can be touched), and / or the like. In this way, for example, PED 212 can provide limited or touchless input event information to unsigned applications or may require access directly from AFP 302, while providing full input touch event information. to signed applications that access PED 212 through SoM 304.
Cables 306 and 308 can be secured to prevent tampering therewith to achieve unauthorized access to display 208 and / or associated input touch data. In one example, the 3 06 cable could be any suitable cable, such as a flexible circuit mount, an Ethernet cable, a universal serial bus (USB) cable, etc., securely mated with the 208 display and / or the PED 212. According to one example, a flexible circuit assembly could take the form of a tamper-proof cable as described
IMPI
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL
<img file="MX353246B_D0035.tif" />
in the United States Patent Publication lio ·. · 2013/0300453. As referenced earlier in this example, the flexible circuit assembly includes two or more layers and is in electrical communication with the secure area on PED 212, which may include the secured touch controller 206. Each of these layers can include a thin flexible dielectric substrate that has conductors in it. Signal conductors can be surrounded by a conductor pattern that defines a wire mesh. In this way, if access is attempted by means of signal conductors, such as by separating the layers, the wire mesh is interrupted, which can trigger an anti-tamper event. For example, these events may include deletion of certain information (for example, encryption information, payment information or other sensitive information, etc.), from the memory of the Touch 2 06 secured controller, PED 212, the AFP 3 02, SoM 304, etc., withdrawing from service the Touch Assured Controller 2 06, PED 212, Display 2 08, AFP 302, SoM 304, etc., and / or the like. In one example, a suitable adhesive is used to connect these different layers together to form the mesh.
When assembled, these layers define a cable that runs between the connector portions on the display 208 and the PED 212 (or the secured driver of / i
touch 2 06). One end can be connected to the £ ÍVjl X li.
INSTIT'JTO MEXICANO DE. · 'Of the flexible circuit assembly screen 208 by means of
306 a portion
X ...
. A • z 'of connector thereof and another end of flexible circuit assembly 306 may be connected to PED 212 (or the tapped controller 206) by means of a connector portion thereof. Similarly, SoM 304 (or AFP
302) may have a connector portion for connection of cable 308, and PED 212 (or secured touch controller 206) may have another connector portion for cable 308. The connector portions could take the form of any device. secure connector, such as the connector portion 312 discussed in the US Patent application
United States No. 13 / 467,592. The connector portions could be connected to the display 208, the PED 212 (or the secured touch controller 2 06), the SoM 3 04 (or the AFP 302), using a suitable adhesive, such as the conductive adhesive described in United States Patent Application No. 13 / 467,592.
As noted previously, the cable may include internal conductors that directly connect and allow electronic communications between PED 212 (or touch assured controller 206) and display 208. In one example, touch assured controller 206 It can be implemented on a printed circuit board inside PED 212, and the cable can be connected from the PCB to the
<img file="MX353246B_D0036.tif" />
m *. or.;. t
MEXICAN INSTITUTE! AND 'OF INDUSTRIAL PROPERTY screen 208. In another example, screen 208 could include a screen controller 322, which may be a hidden controller that transmits touch input events through cable 306 and / or causes display of the data received through cable 306. In one example, display controller 322 can exist on a PCB on display 208, and the cable can run from the PCB on display 208 to the PCB of PED 212. This may allow PED 212 to send data, such as display data, securely to display 208 within flexible circuit tamper-proof assembly 302, and / or to securely receive touch input events from the screen 208.
Due to the flexibility of the flexible circuit assembly, it will be appreciated that the display 208 can be hinged relative to the PED 212 while being electrically connected to the PED 212. Additionally, a flexible circuit assembly allows the display 2 08 is mounted in a physical location on fuel distributor 200 separate from the mounting location of PED 212. It will be appreciated that similar wiring such as 308 wire can be used between PED 212 and SoM 304.
In one example, a flexible circuit assembly
<img file="MX353246B_D0037.tif" />
employed as
<img file="MX353246B_D0038.tif" />
308 can be
<img file="MX353246B_D0039.tif" />
<img file="MX353246B_D0040.tif" />
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL
<img file="MX353246B_D0041.tif" />
batten or a similar cable that connects the corons put t es. j> ar a.la ------ - - ♦ communication between them. In one example, a flexible circuit assembly can include multiple cables, where at least one cable carries the video data, and the other cable is used for security detection. In one example, a cable facilitates communication of the display data between the PED 212 and the display 208 and has the security overlay layers, as described, that trigger an anti-tamper event if tamper is detected. In this way, this cable can include a switch circuit in at least one cable connector that uses a ground connection on the component to detect removal of the cable, which can trigger an anti-tamper event (for example, deletion memory, component service separation, etc.). In this example, another cable may provide the network security circuit connected in series with two dome switches (or other suitable switches to detect separation or movement of one or more components), and may be attached or otherwise mounted on the other cables and / or circuit can be connected, so that the dome switch is used to determine if a clamp is assembled through a connector on the other cable, which can trigger an anti-tamper event.
This cable may continue to another dome switch between the 208 display and a bezel, or another portion of a
<img file="MX353246B_D0042.tif" />
fuel distributor, to determine if the display
208 it is removed from it; this can also trigger an anti-tamper event.
In either case, anti-tampering triggered events can trigger various functionalities, and triggering different switches can trigger different event functionalities, in one example. In addition, the functionalities may require different resolutions. For example, removal on display 208 from the bezel may cause PED 212 and / or display 208 to be removed from service, so that the display can be reinstalled to contact the bezel, and normal operation can resume. Removing cable 308 from PED 212 or SoM 304, however, may cause the encryption information used to communicate between PED 212 and SoM 304 to be erased. Resetting encryption information may require a technician to replace cable 308, and / or reset encryption information between PED 212 and SoM 304 in a cleared room for reinstallation at fuel dispenser 200, and / or or the like. It will be appreciated that various events capable of being triggered can be used in this regard with variable remedial measures to reset the events.
In one example, the multiple 306 and 310 cables and connectors can be used to connect the display
<img file="MX353246B_D0043.tif" />
208 and PED 212 and / or the multiple cables —30-8- -y - --3-1-2 — and connectors can be used to connect PED 212 and SoM 304. For example, two cables and two connector sets they can be used to connect the display 208 with the PED 212 (or the secured touch controller 206). In one example, PED 212 (and / or touch secured controller 206) includes a touch device connector that allows touch input information through a cable, and a video device connector that allows display of functionality through the other. For example, cable 306 can be connected to the touch device connector, it can be secured, as described, while the other cable 310 displaying functionality can be connected to the video device connector, and would not need to be secured. . A similar configuration can be used to connect PED 212 with SoM 304 (or AFP 302) using cables 308 and 312.
In an example described in further detail below, the screen output from SoM 304 (or AFP 302) could be provided to screen 208 via PED 212 via cables 312 and 310 without prior related application authentication ; in this way, the display data received through the video device connectors can be provided to the display 208 for display without authentication. By
MEXICAN INSTITUTE;
DS LA. 'INDUSTRIAL RORISTY
<img file="MX353246B_D0044.tif" />
On the contrary, in this example, the data that will be provided to an application using the touch device connector via cables 306 and 308 may first require that the application be authenticated by SoM 304 and / or PED 212 before that the input be provided with it by the assured touch controller 206. Furthermore, data communicated through cables 3 06 and / or 3 08 can be encrypted through the secure channel, and in one example, data through cables 310 and 312 would not need to be encrypted.
Figure 4 illustrates an example system 4 00 for controlling a touch screen by means of a secured touch controller. System 400 includes a touch screen 402 communicatively coupled with a secure device 404 and / or a secured touch controller 406 thereof. In addition, system 400 includes an AFP 408 for executing one or more applications that uses one or more touch screen 402 functions. AFP 408 may include a SoM 410, as described, for handling communication with touch screen 4 02 by means of a secure device 404. It will be appreciated that touch screen 402 may be similar to screen 208, Secure device 404 can be similar to PED 212 (for example, with or without PIN pad), AFP 408 can be similar to AFP 302, SoM 410 can be similar to SoM 304, etc.
ινπτγπό mfjgcanq
Ο € THE INDUSTRIAL PROPERTY is ·
Xi ...
Secure device 404 may include a touch event processor 412 that can obtain touch events from touch screen 402, and can determine the information it provides to AFP 408, SoM 410, etc., based on one or more considerations regarding the application to which the touch input refers. In another example, the touch event processor 412 may indicate a form of the touch input information to the touch screen 402 for sending the information to the touch assured controller 406. In addition, the assured controller of Touch 406 can be secured on the secure device 404 by means of a curved anti-tamper plate 414. It will be appreciated that the wiring to / from the touch screen 402 and / or the SoM 410 (or the AFP 408) can be installed underneath the anti-tamper curved plate as well to prevent physical access thereto. In addition, for example, AFP 408 can be installed on a PCB hub interface (HIP), which can include two AFPs (eg, one on each side) for a dual-sided fuel dispenser.
According to an example, secure device 404 can handle access to touch screen 402, which may be based on the parameters received in a request to access touch screen 402, if the touch screen
402 is in use by an application, and / or the like. In a 'ΐ Μ. ΡI
Ν · Γ- <1Τ) MEXICAN? Ε THE PROPERTY
INDUSTRIAL example, secure device 404 may limit access to touch screen 402 for certain applications by allowing only screen access, limited touch access, full touch access, and / or the like. For example, limited touch access would include allowing access to one or more limited regions of touch screen 402 and / or limiting the number of active touch regions on touch screen 402. Secure device 404 can limit access to touch screen 402 based on at least one of one or more parameters associated with an application accessing touch screen 402, if the access request starts from SoM 410 or of AFP 408, if an application that accesses the touch screen 4 02 is signed by an authorized entity, etc.
In one example, SoM 410 can verify if applications requesting access to touch screen 402 are signed by an authorized entity. This may occur depending on the reception of a request to access the touch screen 402, depending on the application execution in the SoM 410, and / or the like. SoM 410 can indicate whether the application is signed by an authorized entity to secure device 404 (for example, as an explicit indication, as part of an application access request, as part of a connection verification message sent while the application is running,
<img file="MX353246B_D0045.tif" />
etc.). In one example, the SoM 410 can check if the applications are signed, and can compare the signature of the same with a stored list of signatures of authorized entities to determine if one or more of the applications are signed by a signature of an authorized entity . The signature list may include a signature that corresponds with the manufacturer of a fuel distributor or retail site, payment institution, etc., as further described herein. Also, in one example, the SoM 410 can be provided with the signature list (for example, in a clear room before the SoM 410 is installed at a fuel dispenser), you can get the signature list from a remote source (for example, depending on the installation of a fuel distributor, such as a proposed list of one or more entities, etc.), you can obtain the signature list of the secure device 404 (for example, depending on the establishment of the secure channel), and / or the like.
In addition, the SoM 410 can establish a secure channel with the secure device 404 and can communicate the indication through the secure channel. In another example, communication with the secure device 404 through the secure channel may involve the application being signed by an authorized entity in this example, the SoM 410 can also communicate with the secure device 404 through another
<img file="MX353246B_D0046.tif" />
ιλ la frfUriEDAD í “OS INDUSTRIAL ** ·> £> <♦ 'link where the application is not signed<sup>1</sup> pui una unUldud -, ^ ........ authorized. In yet another example, SoM 410 may re st rict ct ict touch screen 402 communication of application requests from unsigned applications by an authorized entity to secure device 404, and AFP 408 may communicate the request outside of SoM 410. In either case, the secure device 404 can determine if the application is signed and / or if it is a related signing entity, and in this way, it can determine the information regarding the application and the level of access to provide the application by means of an assured touch controller 406 depending on the information.
In one example, the AFP 408 may include a secure chip 416, with which the SoM 410 can communicate to obtain the information establishing the secure channel with the secure device 404. The SoM 410 may include the secure chip 416, in one example. . Wherein the secure chip 416 is present, the secure chip 416 and the secure device 404 can be provided with the related encryption information to enable encrypted communications with the secure device 404 using the encryption information (eg, encryption codes , certificates or other functions). This can occur in a clear room or otherwise prior to installation in a fuel dispenser to ensure tamper-proof provisioning. In
DF LA PHOFiEDAP
INDUSTRIAL
<img file="MX353246B_D0047.tif" />
addition, as described, where the - caught Cieñes peanut detected in a cable between the secure device 404 and the SoM 410 or another component of the system 400, the contents of the secure chip 416 can be erased (for example, by the secure chip 416 based on tamper detection by secure chip 416, SoM 410, or other device in AFP 408) to ensure integrity of encryption information established prior to installation.
In another example, where secure chip 416 is not used to establish the secure channel with secure device 404, SoM 410 can be configured with the encryption information (eg, encryption codes, certificates, or other functions). For example, the SoM 410 can run a software setup process with the secure device 404 where the SoM 410 can store the encryption information in memory. In another example, a given application running on SoM 410 may receive an encryption code for which secure device 404 has a corresponding encryption code that facilitates secure communications between them. For example, encryption codes may correspond to a public / private code pair of a public code cryptography algorithm (for example, Rivest, Sharnir, and Adleman (RSA), Diffe-Hellman, digital signature standard (DSS), etc.).
In this example, the 404 secure device can be programmed with the private code,
<img file="MX353246B_D0048.tif" />
running on SoM 410 can be provided with a matching public code that allows the establishment of the secure channel. In one example, the application obtains the public code as part of an authentication process, which can occur before the application runs at the fuel dispenser. Application authentication may occur outside of the fuel distribution environment, in one example, so that applications may be signed or otherwise associated with certain parties (for example, a retail site operated by the distributor of fuel). Where the associated entity is authorized to run applications at the fuel distributor, the application may then be signed with a signature from the manufacturer of the fuel distributor (or another signature that allows the application to run at a given fuel distributor). As part of this signature, the application can obtain the public code for encryption of communications for the secure device 404. For example, the public code may be unique for the authorized entity to run the application.
Subsequently, the application can be run on SoM 410, the manufacturer's signature is verified by SoM 410 and / or the secure device 404 to determine the level of access it provides to the 4 02 touch screen, and the code encrypt communications through the secure channel.
IMPI
INSTITUTO MEXICANO DE U PROPIEDAD INÜUSTPUL for the 404 a secure device
Secure device 404 can try to establish a secure channel with the
SoM 410 for the given application using the encryption code pair (and / or
If successful, the secure device 404 can consider the application as signed by an authorized entity, consequently, it can provide the appropriate level event information from the touch screen 402 with it (for example, the level information by coordinate , level by movement or similar information). If unsuccessful, the secure device 404 may consider the application as unsigned by an authorized entity, and consequently may limit the touch screen event information 402, as described (for example, by providing only the level information by region of a touch event for a limited number of regions on the touch screen 402). In these examples, it will be appreciated that the secure chip 416 could be present and could be used to store the encryption information of an application or could otherwise be received from the secure device 404.
SoM 410 can notify the secure device 404 when an application is signed by an authorized entity through the secure channel, which can occur depending on
<img file="MX353246B_D0049.tif" />
of the application execution, as part of a touch screen access pet240lon 402, and / or the like. In one example, the SoM 410 may require or request touch input information from the secure device 04 04 for a given application. The secure device 404 can obtain the touch input information from the secured touch controller 406 for delivery to the SoM 410 based on the request of the application when the secure device 404 determines that the application is signed by an authorized entity. In this way, when interactions of the togue screen 402 occur (for example, the user touches the togue screen 4 02), the touch event processor 412 can process the related event information and can provide the information to the 404 secure device for your communicational SoM 410. In one example, the touch event processor 412 can interpret the touch data to include the coordinates of the interaction, the type of interaction (eg, touch, sweep, double hit, etc.), and / or Similar. The secure device 404 can determine at least a subset of the information it provides to the SoM 410 based on the information regarding an application that requires the touch input information.
For example, for applications signed by an authorized entity (such as a vendor manufacturer
IMPI Mexican institute OF PROPERTY
INDUSTRIAL
<img file="MX353246B_D0050.tif" />
fuel, an operator of a retail site.
Secure device 404 can communicate touch input coordinates and related interactions on the touch screen
402 to SoM 410, and the
SoM
410 You can supply the data to the application running in the same or otherwise in AFP 408.
Applications signed by an authorized entity may include paid applications that are provided with a pad
PIN, a kitchen menu app for the retail site, etc., and the specific touch input information can be provided to these apps running on AFP 408 or SoM 410 via secure device 404. For example, secure device 404 can encrypt touch information for communication over the secure channel with the SoM.
410 for these applications, as described. In either case, applications can perform substantially any pipeline and can receive touch event specific information on the pipeline. This may enable the proper supply and operation of a PIN pad on the touch screen 402, in one example.
For applications that are signed by an unauthorized and / or unsigned entity, the secure device 404 can return the more generic information regarding the touch input on the touch screen 402, such as the
-I XVI K1
<img file="MX353246B_D0051.tif" />
Indication of one of a number of regions ~ in Trá'S ^ 'OrraL'Touch occurs, or you can restrict the provision of any input information from Touch applications.
These applications could include advertising applications.
tamper event applications input, or information information.
In
Providing this limited touch information can mitigate the occurrence of applications that are no longer receiving are receiving one of the touch, given the data amount from which it could not be that the touch of limited discarded a specific example, The secure device can limit the touch screen to adjacent or non-adjacent regions of
402, and may return an indication of which occurs authorized. Functionality in a pad
404
402 By defining eight the touch screen a region within the touch input in an essential way, this is the number screen appropriately used because the input susceptible regions of the applications allows to limit not the touch 4 02 in this example, digit 10 does not it can be for just being an application cannot be received touched, mitigates the possible manipulation for confidential of the user that uses
402. In one example, it will be appreciated that authorized for eight in this way, information will be obtained from the touch screen of the application that
IMPI
MEXICAN INSTITUTE
DE LA MOHEDA!) INDUSTRIAL
<img file="MX353246B_D0052.tif" />
running on SoM 410 or the secure chip 416 can define the size and location of the eight touch regions, or the secure device 404 can use a default setting for the size and location of the region. In either case, in one example, the secure device 404 could allow the unauthorized application to specify when it is displayed in the regions.
Communications between secure device 404 and SoM 410 can be encrypted, as described. In one example, all communications between them can be encrypted (including all events on touch screen 402). In another example, a portion of the events on the touch screen 402 may be encrypted by the secure device 404 (for example, using the private code) prior to being sent to the SoM 410. In this regard, in some examples, physical security measures described herein could not be used (for example, secure chip 416, curved anti-tamper plate 414, security for wiring between SoM 410 and device Secure 404, etc.), since stealth eavesdropping can be hidden by encrypted communications.
In addition, for example, secure device 404 can ensure that it has substantially constant communication with SoM 410 as another security measure in this example, where secure device 404 detects that communication with SoM 410 is interrupted v / o that he
<img file="MX353246B_D0053.tif" />
MEXICAN INSTITUTE DF. INDUSTRIAL PROPERTY secure channel is not established, secure device 404 can at least restrict communication of touch input information with SoM 410, can disable touch screen 402, etc. In one example, SoM 410 can consistently verify communication with secure device 404 to keep the channel secure. This may include sending a connection verification message to secure device 404. In this way, where a connection verification message is not detected by the secure device 404 for a period of time, this could indicate tampering, and the secure device 404 can restrict the sending of the touch input to the SoM. 410, you can disable touch screen 402 (eg, by means of a secured touch controller 406), and / or the like. It will be appreciated that the connection verification message can substantially include any message transmitted to secure device 404 to indicate proper operation of SoM 410. In addition, for example, SoM 410 can apply an authenticity parameter to the connection verification message to allow secure device 404 to verify its authenticity to ensure that the connection verification message is from SoM 410 (for example , and not from a theft device that purports to misrepresent
IMPI
INSTITUTO MEXICANO D £ LA FAOHÍDaD! N¿XJSTklAL
<img file="MX353246B_D0054.tif" />
SoM 410). For example, the dS'l 'authenticity parameter' application may include the SoM 410 that encrypts the connection verification message, and may decrypt the connection verification message (for example, using a pair of codes) to ensure that the message be of SoM 410. In another example, the application of the authenticity parameter may include the SoM 410 that includes an invalid value as part of the connection verification message, and the secure device 404 can verify the invalid value (for example, using one or more functions) to ensure that the message is from SoM 410.
The SoM 410 can include a kernel-level application, such as the operating system, which can communicate with the secure device 404, establishing the secure channel with the secure device 404, etc. In this regard, the core level application of the SoM 410 can keep the channel secure with the secure device 404 and a request to access touch screen 402 may or may not be from an authorized application. For example, applications may run on SoM 410 (or AFP 408 and may require touch screen 402 access via SoM 410), and the SoM 410 kernel-level application can determine if applications are signed by an authorized entity, as described herein, and may indicate this to the secure device 404.
TMR
M.-1XICAN INSTITUTE <? WHERE IS THE PAOF; = '' Am · ,. ; .- ·: indu <t; ual ·· “* _
In addition, a curved ant-i-ma-miptri-a-ed-en —- 4-14 plate can close the 406 touch-assured controller as well as can mitigate tampering with the 406 controller and / or any of the cables that mate controller 406 with touch screen 402. As described, anti-tamper curved plate 414 may include mesh capable of detecting movement, removal, or other tampering with curved plate 414 or components located therein. In addition, a secure cable can be used to couple the 406 touch-lock controller (eg, underneath the anti-tamper curved plate 414) with the 402 touch-screen. The secure cable can be similar to the circuit mount flexible discussed earlier in an example. Also, for example, touch screen 402
<td>you can use one or</td><td>plus</td><td colspan="3">microswitches u</td><td colspan="2">others</td>
<td>detection mechanisms</td><td>than</td><td>detect</td><td>of the</td><td>movement</td><td>or</td><td>the</td>
<td>removal thereof.</td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>With reference</td><td>to</td><td>Figure</td><td> 5,</td><td colspan="2">is illustrated</td><td>the</td>
methodology that can be used in accordance with various aspects described herein. While, for the purposes of simplicity of explanation, the methodology is shown and described as a series of stages, it will be understood and appreciated that the methodology is not limited by the order of the stages, since some stages, according to one or more aspects , they can occur in different orders and / or in a way
IMPI G Mexican Institute 'í ς. J
DE! .A pri w: · i '· r *.
! NHJSTR; aI ··· concurrent with other stages of which they are mocfcgadag -— and-.
described herein. For example, those skilled in the art will understand and appreciate that the methodology could alternatively be represented as a series of interrelated states or events, such as in a state diagram.
Furthermore, not all the illustrated stages may be required to implement the methodology according to one or more aspects.
Figure 5 illustrates an example methodology
500 for processing input data received on a touch screen. For example, methodology 500 may be implemented by a secure device, as described, that manages touch screen access for one or more applications. At 502, the input data can be received from the touch screen functionality of a touch screen.
For example, the input data can be related to the coordinates of the touch interaction on the touch screen, the type of interaction and for example, a single touch, a double hit, a sweep, etc.), and / or the like. .
In 504, it can be determined whether the application is authorized, which may include determining whether the application is signed by an authorized entity or not at all signed. This may impact the touch input information (if any) provided by the application. In addition,
<img file="MX353246B_D0055.tif" />
the determination can be made by comparing a f lLiiid * of —'l'a46
<img file="MX353246B_D0056.tif" />
application with a list of signatures of authorized entities, receiving the related indication of a
SoM or other device, as described. In addition, the determination may be based on whether a secure channel is established with the application or related processor on which the application is running. As described, the application can use a public code to secure communications, and communications can be decrypted with a private code. Where communications are properly decrypted, this may indicate that the application is authorized at 504.
When the application is authorized, in 504, the input data can be provided to the application in
506. This may include communicating input data as it is received, such as coordinates or touch interaction type information. In addition, the input data can be formatted before being supplied to the application. Furthermore, the input data can be encrypted, as described. In either case, the authorized application receives more specific touch input information than an unauthorized application.
When the application is not authorized at 504, the touch input information can be determined by restricting the input data at 508. This may include the
IMPI
INSTITUTO MiXICANO <Xí
Say LA AROFIE DAD V * '·' '». / · .-. + wousTRiAL —determination of a region in which 1 as — infceicao oi one e — offset occur based on input data such as touch input information. Therefore, only information regarding the number of limited touch regions can be provided to unauthorized applications to prevent false applications from obtaining conventional information (for example, when displaying a PIN pad). In other examples, restricted touch input information may indicate the occurrence of a touch event, or other limited information. The touch input information is provided to the unauthorized application at 510.
While one or more aspects have been previously described, it should be understood that any and all equivalent modalities of the aspects presented are included within the scope and spirit of the same. The aspects represented are presented only by way of example and are not intended as limitations based on the various aspects that can be implemented in view of the descriptions. In this way, it should be understood by those of ordinary experience in this technique that the subject matter presented is not limited to these aspects because modifications can be made. Therefore, it is contemplated that any and all of these modalities are included in the subject matter presented that could fall within
<img file="MX353246B_D0057.tif" />
IMPI
MEXICAN INSTITUTE
OF THE EKOFICITY
INDUSTRIAL of the scope and spirit of it.
It is noted that in relation to this date, a better method known by the applicant for carrying out such a practiced invention is the one that is clear from the present description of the invention.
<img file="MX353246B_D0058.tif" />
<img file="MX353246B_D0059.tif" />
MEXICAN INSTITUTE
OF THE INDUSTRIAL PSOHtDAC
<img file="MX353246B_D0060.tif" />
'v
<img file="MX353246B_D0061.tif" />
Contents35
66 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66
29 members in 12 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 201261731211 | United States of America | P | |
| 201261731211 | United States of America | P | |
| 61731211 | United States of America | – | |
| 14089443 | United States of America | – | |
| 201314089443 | United States of America | A | |
| 201314089443 | United States of America | A | |
| 2013071897 | United States of America | W | |
| 2013071897 | United States of America | W | |
| 14089443 | – | – | – |
| 61731211 | – | – | – |
| PCTUS2013071897 | – | – | – |
| US201261731211P | – | – | – |
| US201314089443 | – | – | – |
| WO2013US71897 | – | – | – |
Members29
| Document | Office | Kind | |
|---|---|---|---|
| US2014150056A1 | United States of America | A1 | |
| CA2893054A1 | Canada | A1 | |
| CA3139040A1 | Canada | A1 | |
| WO2014085399A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2014085399A3 | World Intellectual Property Organization (WIPO) | A3 | |
| SG11201504202PA | Singapore | A | |
| AU2013352397A1 | Australia | A1 | |
| EP2926304A2 | European Patent Office (EPO) | A2 | |
| EA201500578A1 | Eurasian Patent Organization (EAPO) | A1 | |
| CN105121530A | China | A | |
| US9268930B2 | United States of America | B2 | |
| EP2926304A4 | European Patent Office (EPO) | A4 | |
| US2016171253A1 | United States of America | A1 | |
| MX2015006785A | Mexico | A | |
| US9715600B2 | United States of America | B2 | |
| BR112015012485A2 | Brazil | A2 | |
| MX353246BThis record | Mexico | B | |
| NZ709444A | New Zealand | A | |
| CN105121530B | China | B | |
| AU2019204491A1 | Australia | A1 | |
| AU2013352397B2 | Australia | B2 | |
| MY177973A | Malaysia | A | |
| AU2019204491B2 | Australia | B2 | |
| EP2926304B1 | European Patent Office (EPO) | B1 | |
| EP3913562A1 | European Patent Office (EPO) | A1 | |
| EP3913562A4 | European Patent Office (EPO) | A4 | |
| CA2893054C | Canada | C | |
| BR112015012485B1 | Brazil | B1 | |
| CA3139040C | Canada | C |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 353246
- Publication, DOCDB
- 353246
- Publication, EPODOC
- MX353246
- Application
- 2015006785
- Application, DOCDB
- 2015006785
- Application, EPODOC
- MX20150006785
Titles2
- Spanish
- ARQUITECTURA DE SISTEMA DE INTERFAZ DE USUARIO DE DISTRIBUIDOR DE COMBUSTIBLE.
- English
- FUEL DISPENSER USER INTERFACE SYSTEM ARCHITECTURE.
Classification
- CPC, 6
- G06F21/52
- G06F21/83
- G06F21/57
- G06F21/36
- G06F21/44
- G06F21/84
- IPC, 5
- G06F21 36
- G06F7 04
- G06F21 52
- G06F21 57
- G06Q20 00