Reference is made to the following patent and patent applications, owned by assignee, the disclosures of which are hereby incorporated by reference, which are believed to relate to subject matter related to the subject matter of the present application:
U.S. Pat. No. 6,853,093; U.S. Published Patent Applications No. 2007/0152042 and 2009/0184850; and U.S. patent application Ser. No. 12/666,054.
The present invention relates generally to secure keypad devices and more particularly to data entry devices having anti-tamper functionality.
The following U.S. Patent Publications are believed to represent the current state of the art and are hereby incorporated by reference:
The present invention seeks to provide improved secure keypad devices.
There is thus provided in accordance with a preferred embodiment of the present invention a data entry device including a housing formed of at least two portions, data entry circuitry located within the housing, at least one case-open switch assembly operative to sense when the housing is opened and tamper indication circuitry operative to receive an input from the at least one case-open switch assembly and to provide an output indication of possible tampering with the data entry circuitry located within the housing. The at least one case-open switch assembly includes an arrangement of electrical contacts arranged on a base surface and a resiliently deformable conductive element, which defines a short circuit between at least some of the arrangement of electrical contacts only when the housing is closed. The resiliently deformable conductive element includes an at least partially continuous circumferential flange fixed at least two locations thereat in electrical contact with at least one of the electrical contacts at least two corresponding locations on the base surface, a circumferential portion having a cross sectional configuration which includes two mutually spaced arches, a central portion disposed in a case-open operative orientation at a first distance from the base surface and a contact portion located interiorly of the central portion and disposed in a case-open operative orientation at a second distance from the base surface, less than the first distance.
Preferably, the arches of the circumferential portion are at least at a distance from the base surface which exceeds the first distance.
In accordance with a preferred embodiment of the present invention the central portion is generally flat. Additionally or alternatively, the contact portion is generally flat.
Preferably, the resiliently deformable conductive element defines a short circuit between some, but not all, of the arrangement of electrical contacts when the housing is closed.
In accordance with a preferred embodiment of the present invention the arrangement of electrical contacts arranged on a base surface includes an outer ring, at least one intermediate ring and a central contact. Additionally, the at least one intermediate ring includes an outer intermediate ring and an inner intermediate ring.
Preferably, the outer intermediate ring is a continuous ring. Alternatively, the outer intermediate ring is divided into plural elements.
In accordance with a preferred embodiment of the present invention the central portion of the resiliently deformable conductive element contacts the central contact when the housing is closed. Additionally, when the central portion of the resiliently deformable conductive element contacts the central contact, the outer intermediate ring is thereby electrically connected with the central contact.
Preferably, when the central portion of the resiliently deformable conductive element contacts the central contact, no part of the resiliently deformable conductive element is in electrical contact with either the outer ring or the inner intermediate ring. Additionally, the outer ring and the inner intermediate ring are both coupled to a voltage VDD via a first resistor, the outer intermediate ring is grounded, and the central contact is coupled to voltage VDD via a second resistor.
In accordance with a preferred embodiment of the present invention the input to the tamper indication circuitry includes an indication of whether the deformable conductive element is simultaneously in contact with both the central contact and the outer intermediate ring. Additionally or alternatively, the input to the tamper indication circuitry includes an indication of whether the inner intermediate ring is short circuited with at least one of the central contact and the outer intermediate ring. Alternatively or additionally, the input to the tamper indication circuitry includes an indication of whether the outer ring is short circuited with the outer intermediate ring.
Preferably, a separation between the contact portion of the resiliently deformable conductive element and the central contact is less than 0.1 mm. Additionally or alternatively, a force required to establish electrical contact between the contact portion of the resiliently deformable conductive element and the central contact is approximately 200 grams.
Preferably, the data entry device also includes an anti-tampering grid, formed of a multiplicity of interconnected anti-tampering electrical conductors in a circuit board associated with the tamper indication circuitry.
There is also provided in accordance with a preferred embodiment of the present invention a case-open switch assembly for a data entry device including a housing, the case-open switch assembly including an arrangement of electrical contacts arranged on a base surface and a resiliently deformable conductive element, which defines a short circuit between at least some of the arrangement of electrical contacts only when the housing is closed. The resiliently deformable conductive element includes an at least partially continuous circumferential flange fixed at least two locations thereat in electrical contact with at least one of the electrical contacts at least two corresponding locations on the base surface, a circumferential portion having a cross sectional configuration which includes two mutually spaced arches, a central portion disposed in a case-open operative orientation at a first distance from the base surface and a contact portion located interiorly of the central portion and disposed in a case-open operative orientation at a second distance from the base surface, less than the first distance.
The present invention will be understood and appreciated more fully from the following detailed description, taken in conjunction with the drawings in which:
The present invention seeks to provide an improved security system for electronic devices, especially tamper-protected point of sale terminals and other devices containing sensitive information, such as personal data and encryption keys. For the purposes of the present description and claims, the term “point of sale terminals” includes, inter alia, PIN pads, electronic cash registers, ATMs, card payment terminals and the like.
The point of sale terminals preferably include a housing, an anti-tamper protected enclosure located within the housing and adapted to contain the sensitive information, anti-tamper protection circuitry located within the anti-tamper protected enclosure and case open switches electrically coupled to the anti-tamper protection circuitry for protecting against unauthorized access to the interior of the anti-tamper protected enclosure.
Preferably, a confidential data storage element is located within the anti-tamper protected enclosure. Additionally or alternatively a data entry element is also mounted in the housing.
Preferably, the anti-tamper protection circuitry is operative, in the event of unauthorized opening on the housing to perform at least one of the following actions: generate an alarm indication, disable the device and erase the sensitive data.
Reference is now made to
As seen in
It is a particular feature of an embodiment of the present invention that the housing element 102 includes on an underside surface 112 thereof a plurality of spaced case open switch actuation protrusions 114.
A resilient key mat 116, preferably formed of a resilient plastic or rubber, defines a plurality of depressible keys 118, preferably integrally formed with the remainder of key mat 116, which partially extend through key apertures 110. Underlying each of keys 118 is a key actuation protrusion 120. Disposed at multiple locations on key mat are case open switch actuation responsive displaceable portions 122, each including a top facing protrusion 124, which is engaged by a corresponding case open switch actuation protrusion 114, and a bottom facing protrusion 126.
It is a particular feature of a preferred embodiment of the present invention that when the housing is closed, case open switch actuation protrusions 114 engage corresponding protrusions 124 and cause displacement of corresponding case open switch actuation responsive displaceable portions 122 in a direction indicated by an arrow 128. Opening of the housing retracts case open switch actuation protrusions 114 from corresponding protrusions 124 and enables displacement of corresponding case open switch actuation responsive displaceable portions 122 in a direction opposite to that indicated by arrow 128 as a result of resilience of the case open switch actuation responsive displaceable portions 122 and key mat 116.
Underlying key mat 116 is a light guide element 130 which includes an array 132 of apertures 134 which accommodate key actuation protrusions 120. It is a particular feature of a preferred embodiment of the present invention that light guide element 130 also includes a plurality of apertures 136, which accommodate bottom facing protrusions 126 of case open switch actuation responsive displaceable portions 122.
Underlying light guide element 130 and preferably adhered to an underside surface thereof is a key contact layer 140. Key contact layer 140 preferably includes an array 142 of raised resilient conductive domes 144, such as those commercially available from Snaptron, Inc. of Windsor, Colo., USA. It is a particular feature of an embodiment of the present invention that key contact layer 140 also includes a plurality of apertures 146 which accommodate bottom facing protrusions 126 of case open switch actuation responsive displaceable portions 122, particularly when displaced in the direction of arrow 128, when the housing is closed.
An anti-tampering grid 150, formed of a multiplicity of interconnected anti-tampering electrical conductors in a flexible printed circuit board (PCB) is optionally provided between the light guide element 130 and the key contact layer 140.
Underlying key contact layer 140 is an electrical circuit board 160, which functions, inter alia, as a key contact pad board, defining a plurality of pairs of adjacent electrical contact pads 162, each pair underlying a corresponding dome 144, preferably made of carbon, metal or combination of carbon/metal. The arrangement of key contact layer 140 and of electrical circuit board 160 is such that depression of a key 118 by the finger of a user causes dome 144 to establish electrical contact with and between a corresponding pair of electrical contact pads 162 lying thereunder and in registration therewith. When key 118 is not depressed, no electrical contact exists between dome 144 and a pair of corresponding electrical contact pads 162 or between the adjacent pads of the pair.
Electrical circuit board 160 preferably includes an anti-tampering grid 164 formed of a multiplicity of interconnected anti-tampering electrical conductors. The anti-tampering grids 150 and 164 are coupled to anti-tampering detection circuitry 166.
In accordance with a preferred embodiment of the present invention, case-open switches, which sense physical tampering and opening of the housing, are provided, each preferably including the following structure:
The arrangement of electrical contacts 170 preferably includes an outer ring 174, an optionally quartered outer intermediate ring 176, an inner intermediate ring 178, and a central contact 180. It is appreciated that outer intermediate ring 176 may be a continuous ring or may be divided into any number of elements.
It is a particular feature of an embodiment of the present invention that the resiliently deformable conductive element 172 includes an at least partially continuous circumferential flange 184 fixed at least two locations 186 thereat in electrical contact with at least two quadrants of outer intermediate ring 176, a circumferential portion 188 having a cross sectional configuration which includes two mutually spaced arches 190 (as seen in
When the housing is opened by at least approximately 0.75 mm, one or more of the plurality of spaced case open switch actuation protrusions 114 is retracted from one or more corresponding top facing protrusions 124 of one or more case open switch actuation responsive displaceable portions 122, whose resilience causes corresponding retraction of one or more bottom facing protrusions 126, whose retraction reduces the pressure on one or more central portion 192 of one or more resiliently deformable conductive elements 172. This results in at least one contact portion 194 becoming separated from a corresponding contact 180.
Reference is now made to
As seen generally in
This pressure contact displaces the central portion 192 downwardly in the direction of arrow 128 such that contact portion 194 of resiliently deformable conductive element 172 is in touching and electrical contact with central contact 180, thus electrically connecting outer intermediate ring 176 with central contact 180. It is noted that due to the particular configuration and construction of resiliently deformable conductive element 172, no part of resiliently deformable conductive element 172 is in electrical contact with either of rings 174 and 178.
As seen in
An attempt to tamper with the case open switch by short circuiting central contact 180 and outer intermediate ring 176 will also short circuit inner intermediate ring 178 with contact 180 and/or outer intermediate ring 176 or short circuit outer ring 174 with outer intermediate ring 176 and may be detected by measuring a voltage V1. During normal operation, where no tampering is detected, V1 is equal to VDD. An attempt to tamper with the case open switch causes voltage V1 to be zero.
Anti-tampering circuitry 166 (
Attempts to tamper with the case open switch, as by applying conductive adhesive under resiliently deformable conductive element 172 or insertion of a conductive element under resiliently deformable conductive element 172 may be made in order to establish an electrical connection between ring 176 and contact 180 even when the housing is open.
Such attempts to tamper can be expected to result in establishment of an electrical connection between the resiliently deformable conductive element 172, rings 176 and central contact 180 on the one hand and at least one of rings 174 and 178, thus producing an alarm.
It is a particular feature of the present invention that the required displacement of resiliently deformable conductive element 172 along arrow 128 into a case closed operative orientation is relatively small. This may be seen by reference to
Additionally, circumferential flange 184 preferably is attached by soldering thereof, at discrete locations 186 therealong, to outer intermediate ring 176 and the provision of circumferential portion 188 having a cross sectional configuration which includes two mutually spaced arches 190 reduces the amount of force required to displace contact portion 194 into electrical contact with contact 180. Preferably the required force is about 200 grams.
Furthermore, the angular displacement of resiliently deformable conductive element 172 between case open and case closed operative orientations is small, resulting in high reliability of reversion to a case open orientation when the housing is opened, even after having been closed for a long time.
The above features make attempts to tamper difficult.
It is appreciated by persons skilled in the art that the present invention is not limited by what has been particularly shown and described hereinabove. Rather the scope of the present invention includes both combinations and subcombinations of various features described hereinabove as well as variations and modifications thereto which would occur to a person of skill in the art upon reading the above description and which are not in the prior art.
Number | Name | Date | Kind |
---|---|---|---|
3466643 | Moorefield | Sep 1969 | A |
3735353 | Donovan et al. | May 1973 | A |
3818330 | Hiroshima et al. | Jun 1974 | A |
3941964 | Yoder | Mar 1976 | A |
4486637 | Chu | Dec 1984 | A |
4527030 | Oelsch | Jul 1985 | A |
4593384 | Kleijne | Jun 1986 | A |
4749368 | Mouissie | Jun 1988 | A |
4807284 | Kleijne | Feb 1989 | A |
4847595 | Okamoto | Jul 1989 | A |
5086292 | Johnson et al. | Feb 1992 | A |
5237307 | Gritton | Aug 1993 | A |
5239664 | Verrier et al. | Aug 1993 | A |
5353350 | Unsworth et al. | Oct 1994 | A |
5506566 | Oldfield et al. | Apr 1996 | A |
5559311 | Gorbatoff | Sep 1996 | A |
5586042 | Pisau et al. | Dec 1996 | A |
5627520 | Grubbs et al. | May 1997 | A |
5675319 | Rivenberg et al. | Oct 1997 | A |
5861662 | Candelore | Jan 1999 | A |
5877547 | Rhelimi | Mar 1999 | A |
5998858 | Little et al. | Dec 1999 | A |
6288640 | Gagnon | Sep 2001 | B1 |
6359338 | Takabayashi | Mar 2002 | B1 |
6396400 | Epstein, III et al. | May 2002 | B1 |
6414884 | DeFelice et al. | Jul 2002 | B1 |
6438825 | Kuhn | Aug 2002 | B1 |
6463263 | Feilner et al. | Oct 2002 | B1 |
6466118 | Van Zeeland et al. | Oct 2002 | B1 |
6563488 | Rogers et al. | May 2003 | B1 |
6646565 | Fu et al. | Nov 2003 | B1 |
6669100 | Rogers et al. | Dec 2003 | B1 |
6830182 | Izuyama | Dec 2004 | B2 |
6853093 | Cohen et al. | Feb 2005 | B2 |
6874092 | Motoyama et al. | Mar 2005 | B1 |
6912280 | Henry | Jun 2005 | B2 |
6917299 | Fu et al. | Jul 2005 | B2 |
6921988 | Moree | Jul 2005 | B2 |
6936777 | Kawakubo | Aug 2005 | B1 |
7170409 | Ehrensvard et al. | Jan 2007 | B2 |
7270275 | Moreland et al. | Sep 2007 | B1 |
7283066 | Shipman | Oct 2007 | B2 |
7497378 | Aviv | Mar 2009 | B2 |
7528717 | Benjelloun et al. | May 2009 | B2 |
7784691 | Mirkazemi-Moud et al. | Aug 2010 | B2 |
7843339 | Kirmayer | Nov 2010 | B2 |
7898413 | Hsu et al. | Mar 2011 | B2 |
20040031673 | Levy | Feb 2004 | A1 |
20040118670 | Park et al. | Jun 2004 | A1 |
20040120101 | Cohen et al. | Jun 2004 | A1 |
20050081049 | Nakayama et al. | Apr 2005 | A1 |
20050184870 | Galperin et al. | Aug 2005 | A1 |
20060049255 | Von Mueller et al. | Mar 2006 | A1 |
20060049256 | Von Mueller et al. | Mar 2006 | A1 |
20060192653 | Atkinson et al. | Aug 2006 | A1 |
20070040674 | Hsu | Feb 2007 | A1 |
20070102272 | Sano et al. | May 2007 | A1 |
20070152042 | Mittler | Jul 2007 | A1 |
20070204173 | Kuhn | Aug 2007 | A1 |
20080135617 | Aviv | Jun 2008 | A1 |
20080180245 | Hsu et al. | Jul 2008 | A1 |
20080278353 | Smith et al. | Nov 2008 | A1 |
20090058628 | Kirmayer | Mar 2009 | A1 |
20090184850 | Schulz et al. | Jul 2009 | A1 |
20110063109 | Ostermöller | Mar 2011 | A1 |
20110248860 | Avital et al. | Oct 2011 | A1 |
20120025983 | Ben-Zion et al. | Feb 2012 | A1 |
20120106113 | Kirmayer | May 2012 | A1 |
20120180140 | Barrowman et al. | Jul 2012 | A1 |
Number | Date | Country |
---|---|---|
2241738 | Aug 1974 | DE |
60101096 | Jul 2004 | DE |
0 375 545 | Jun 1990 | EP |
0375545 | Jun 1990 | EP |
1421549 | May 2004 | EP |
1432031 | Jun 2004 | EP |
1676182 | Jul 2006 | EP |
1421549 | Aug 2007 | EP |
1432031 | Mar 2008 | EP |
1676182 | Apr 2008 | EP |
2911000 | Jul 2008 | FR |
892198 | Mar 1962 | GB |
1369739 | Oct 1974 | GB |
8608277 | Apr 1986 | GB |
2372363 | Aug 2002 | GB |
2411756 | Sep 2006 | GB |
2002108711 | Apr 2002 | JP |
2003100169 | Apr 2003 | JP |
0163994 | Aug 2001 | WO |
03019467 | Mar 2003 | WO |
2005041002 | May 2005 | WO |
WO 2005086546 | Sep 2005 | WO |
WO 2009091394 | Jul 2009 | WO |
2010082190 | Jul 2010 | WO |
Entry |
---|
U.S. Office Action dated May 13, 2010, which issued during the prosecution of Applicant's U.S. Appl. No. 11/845,435. |
International Preliminary Report on Patentability dated Jul. 19, 2011 issued in International application No. PCT/IL2009/000724. |
Kremin, et al., “Capacitive sensing—waterproof capacitance sensing”, Cypress Perform, Dec. 2006. |
Van Ess, Dave; “Capacitive touch switches for automotive applications”, http://www.automotivedesignline.com/, Feb. 2006. |
An Office Action dated Apr. 10, 2012, which issued during the prosecution of U.S. Appl. No. 12/758,150. |
An Office Action dated May 13, 2010, which issued during the prosecution of Applicant's U.S. Appl. No. 11/845,435. |
A Notice of Allowance dated Sep. 10, 2010, which issued during the prosecution of Applicant's U.S. Appl. No. 11/845,435. |
An Office Action dated Oct. 26, 2004, which issued during the prosecution of U.S. Appl. No. 10/326,726. |
An Office Action dated May 28, 2004, which issued during the prosecution of U.S. Appl. No. 10/326,726. |
An International Search Report and a Written Opinion both dated Apr. 30, 2012, which issued during the prosecution of Applicant's PCT/US2012/020142. |
Number | Date | Country | |
---|---|---|---|
20110215938 A1 | Sep 2011 | US |