180 likes | 301 Views
Supplementary to Presentation on Kiosk Services. ATM System Overview TrigMax Enterprise Solutions Mason Liu, Ph.D. Case Study – Wall Mount ATM. System Overview. Capacity Operate up to 1,000 ATM terminals in parallel Software environment Linux InforMix or Oracle Database
E N D
SupplementarytoPresentation on Kiosk Services ATM System Overview TrigMax Enterprise Solutions Mason Liu, Ph.D.
Case Study – Wall Mount ATM TrigMax Enterprise Solutions
System Overview • Capacity • Operate up to 1,000 ATM terminals in parallel • Software environment • Linux • InforMix or Oracle Database • ISO8583 Financial Data Exchange Protocol • Security • DES-ANSI X3.92:1981 data encryption • Public-Key based ISO 7816 security infrastructure • Message Authentication Code (MAC) deployment • ISO 9564:1991 for Personal PIN protection • EMV certified • Multi-level TCP/IP networks with VLAN TrigMax Enterprise Solutions
Architecture Partitions • System Topology • Network Structure • Kiosk Terminal • Edge Server • Main Server • Security TrigMax Enterprise Solutions
Technology Overview > System Topology Kiosk Sub-net LAN ADSL CDMA MODEM Virtual LAN Kiosk Edge Server Main Network 3rd Party Edge Server Bank Main Server 3rd Party Network TrigMax Enterprise Solutions
Architecture > Network Structure Network architecture defines following components: • Multi-layer network topology • Terminal – server connection scheme • TCP/IP Client/Server interaction • Run-Time environment • Web based secured https access • Data distribution • Web based applications • SQL database TrigMax Enterprise Solutions
Architecture > Kiosk Terminal • Hardware and peripheral modules • Software and environment • Human-machine interface • Network interface Following considerations are needed in designing the kiosk terminal: TrigMax Enterprise Solutions
Architecture > Kiosk Terminal > Hardware • LCD and touch-screen display • Secured metal keypad, YDT220 • CDMA2000-1X / GPRS, sync/async Modem, LAN(RJ45), RS232 • Printer • ISO7812standard 1,2, or 3 track reader • ISO7816ICcard(APDU I/O) • Network NIC • Power TrigMax Enterprise Solutions
Architecture > Kiosk Terminal > Parts List TrigMax Enterprise Solutions
Architecture > Kiosk Terminal > Software • Basic requirement - Remote upgradeable • Security drivers • EMV standard card driver • ISO 7816 IC card interface • ISO 8583 card-based transaction protocol • Keypad driver, touch screen driver • Printer driver • Unified Network driver for broadband, wireless, and serial port connections • Multimedia display drivers • Image and video (MPG, JPG, GIF, Flash) • Audio (mp3, au) TrigMax Enterprise Solutions
Architecture > Kiosk Terminal > Human-Machine Interface • Support commercial applications • Support multimedia A / V display • Support image processing • Value-added advertisement – online remote update • User friendly interactive interface TrigMax Enterprise Solutions
Architecture > Kiosk Terminal > Network Interface • Support variety of TCP/IP based communication methods • Wireless • Cellular • Wired – Ethernet, Serial, DSL, modem • Generic driver interface • ISO 8583 – Standard for Financial Transaction Card Originated Messages TrigMax Enterprise Solutions
Architecture > Edge Server • Major functionalities • Kiosk terminal management • Transaction status tracking • Software environment • Network interface TrigMax Enterprise Solutions
Architecture > Edge Server > Software Environment • Security Measures • Security key manager • Dynamic key generation and distribution • Security monitoring • Data Transaction Measures • Transaction recording and dispatch • Error handling, recovery • Operation monitoring TrigMax Enterprise Solutions
Architecture > Edge Server > Software Components The software package consists of following components: • Kiosk (ATM side) interface module • Main server (bank side) interface module • Database (Oracle) management module • Security management module TrigMax Enterprise Solutions
Architecture > Security • Support the Public-Key based ISO 7816 security infrastructure • Support EMV protocol • Security measurements: Access control, Identification, Authentication, Data integrity, Data protection, Channel monitoring, error concealment. TrigMax Enterprise Solutions
Architecture > Security > Keys PSAM (Payment Secure Application Module) MAC (Message Authentication Code) TrigMax Enterprise Solutions
Architecture > Security > Data Safety • Network safety • Firewalls in routers • Virtual sub-net (VLAN) partitions • Safety in data transfer • Deployment of MAC for data integrity • Encryption for data protection • Safety in data storage • Identification (access, owner, transaction) • Encryption TrigMax Enterprise Solutions