Method of operating an automated transaction machine

The method fortifies ATM security by using AES keys and RSA pairs for firmware protection, addressing vulnerabilities from quantum computers, ensuring secure firmware updates and communications.

WO2025193296A1PCT designated stage Publication Date: 2025-09-18DIEBOLD NIXDORF INCORPORATED
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/059152
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-11
Filing Date
2024-12-09
Publication Date
2025-09-18

AI Technical Summary

Technical Problem

Existing ATM systems face security vulnerabilities, particularly with the advent of quantum computers, which can compromise RSA encryption, leading to potential firmware tampering and unauthorized access.

Method used

Implementing a method that loads and utilizes AES keys for firmware protection, combined with RSA asymmetric key-pairs for verification and encryption, and a secure key distribution system to ensure secure firmware updates and communications, even in the presence of quantum computers.

Benefits of technology

Enhances the security of ATM systems by providing robust firmware protection and secure communication, ensuring integrity and authenticity of updates, even when RSA encryption is compromised by quantum computers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024059152_18092025_PF_FP_ABST
    Figure US2024059152_18092025_PF_FP_ABST
Patent Text Reader

Abstract

A method of operating an ATM can include loading, to a memory of a computing device sub-component of the ATM, a public key of a manufacturer Rivest–Shamir–Adleman (RSA) asymmetric key-pair. The method can also include loading, to the memory of the computing device sub-component of the ATM, at least one Advanced Encryption Standard (AES) key. The method can also include configuring a first firmware update of a firmware of the computing device sub-component of the ATM to utilize the manufacturer RSA asymmetric key-pair for firmware protection. The method can also include configuring, after the configuring the first firmware update, a second firmware update of the firmware of the computing device sub-component of the ATM to utilize the at least one AES key for firmware protection.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD OF OPERATING AN AUTOMATED TRANSACTION MACHINECROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims the priority benefit of United States Provisional PatentApplication Serial No. 63 / 563,678 for a METHOD OF OPERATING A SYSTEM THAT PROCESSES TRANSACTIONS, filed on March 11, 2024, which is hereby incorporated by reference in its entirety.BACKGROUND1. Field

[0002] The present disclosure relates to a method of operating a system that processes transactions, such as financial transactions, and includes an automated transaction machine (ATM) and server remote from the ATM.2. Description of Related Prior Art

[0003] An ATM is an electronic telecommunications and computing device that enables account holders of a financial institution to perform transactions, such as cash withdrawal, check deposit and account balance inquiries, without the need for a human bank teller. The ATM includes a processor and memory. The processor executes an operating system during operation. It has been estimated that there are over three million ATMs installed throughout the world. During a transaction, by way of example, the account holder identifies himself / herself by first inserting a plastic card into the ATM of a financial institution. The card contains a magnetic stripe or a chip that contains accountidentification information. Secondary or “personal” authentication information is then provided by the account holder by entering a personal identification number (PIN) which must match the PIN stored in the financial institution's database.

[0004] The background description provided herein is for the purpose of generally presenting background context of the disclosure. Work of the presently named inventor, to the extent it is described in this background section, as well as aspects of the description that may not otherwise qualify as prior art at the time of filing, are neither expressly nor impliedly admitted as prior art against the present disclosure.SUMMARY

[0005] This section provides a simplified summary in order to provide a basic understanding of some aspects described herein. This summary is not an extensive overview and is not intended to identify “key” or “critical” elements of the present disclosure or to delineate the scope of the various aspects described herein. The purpose of this portion of the document is to present some concepts in a simplified form as a prelude to the more detailed description that is presented later.

[0006] A method of operating an ATM can include loading, to a memory of a computing device sub-component of the ATM, a public key of a manufacturer Rivest-Shamir-Adleman (RSA) asymmetric key-pair. The method can also include loading, to the memory of the computing device sub-component of the ATM, at least one Advanced Encryption Standard (AES) key. The method can also include configuring a first firmware update of a firmware of the computing device subcomponent of the ATM to utilize the manufacturer RSA asymmetric key-pair for firmware protection. The method can also include configuring, after the configuring the first firmware update, a second firmware update of the firmware of the computing device sub-component of the ATM to utilize the at least one AES key for firmware protection.

[0007] According to other features, the configuring of the first firmware update can be further defined as configuring the first firmware update of the firmware of the computing device subcomponent of the ATM to utilize the manufacturer RSA asymmetric key-pair for firmware protection by signing the first firmware update with a first key of the RSA asymmetric key-pair. The configuring of the second firmware update can be further defined as configuring, after the configuring the first firmware update, the second firmware update of the firmware of the computing device sub-component of the ATM to utilize only the at least one AES key for firmware protection by encrypting the second firmware update with a firmware encryption key and encrypting the firmware encryption key the at least one AES key. The method can also include verifying, with the computing device sub-component of the ATM, before the configuring the second firmware update, the first firmware update with a second key of the manufacturer RSA asymmetric key-pair. The method can also include decrypting, with the computing device sub-component of the ATM, after the configuring the second firmware update, a firmware encryption key with the at least one AES key.

[0008] In other features, the method can also include generating, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, the at least one AES key and assigning the at least one AES key to a serial number of the computing device sub-component of the ATM. The method can also include positioning the ATM at a location for use by bank customers. The method can also include transmitting, with the KeyDistribution Host key and certificate module, the at least one AES key to the computing device subcomponent of the ATM before the positioning.

[0009] According to additional features, the loading of the at least one AES key can further comprise transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key in a key block constructed of the at least one AES key and a key block header and an identifier of the Key Distribution Host key and certificate module, wherein the identifier is defined by a digital certificate of the Key Distribution Host key and certificate module.

[0010] According to other features, the loading of the at least one AES key can further comprise transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with a TR34 key to facilitate remote key loading.

[0011] In other features, the loading of the at least one AES key can further comprise transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with an enciphered key block.

[0012] According to additional features, the loading of the at least one AES key can further comprise transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with an ephemeral key enciphered with a public key of the computing device sub-component of the ATM.

[0013] According to other features, the loading of the at least one AES key can further comprise transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with a key token signed with a private signature key of the Key Distribution Host key and certificate module.

[0014] In other features, the method can also include generating, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, a firmware encryption key. The method can also include encrypting, by the Key Distribution Host key and certificate module, the second firmware update with the firmware encryption key. The method can also include encrypting, by the Key Distribution Host key and certificate module, the firmware encryption key with the at least one AES key. The method can also include calculating, with the Key Distribution Host key and certificate module, a Hash based Message AuthenticationCode value for the computing device sub-component of the ATM using a Secure Hash Algorithm and the at least one AES key as the secret.

[0015] According to additional features, the at least one AES key can be further defined as at least a first AES key and a second AES key. Further, the encrypting the firmware encryption key can be further defined as encrypting, by the Key Distribution Host key and certificate module, the firmware encryption key with the first AES key. Further, the calculating, with the Key Distribution Host key and certificate module, the Hash based Message Authentication Code value with the second AES key as the secret.

[0016] According to other features, the method can also include concatenating, with the Key Distribution Host key and certificate module, the encrypted firmware encryption key and the Hash based Message Authentication Code value and the encrypted second firmware update to define a concatenated file. The method can also include receiving, with an ATM Application / XFS Application module of the ATM, from the Key Distribution Host key and certificate module, the concatenated file. The method can also include confirming, with the ATM Application / XFS Application module, a serial number of the computing device sub-component of the ATM. The method can also include extracting, with the ATM Application / XFS Application module, in response to the confirming, the encrypted firmware encryption key and the Hash based Message Authentication Code value and the encrypted second firmware update from the concatenated file. The method can also include transmitting, from the ATM Application / XFS Application module, to the computing device sub-component of the ATM, after the extracting, the encrypted firmware encryption key and the Hash based Message Authentication Code value and the encrypted second firmware update.

[0017] In other features, the method can also include verifying, with the computing device sub-component of the ATM, after the transmitting, the Hash based Message Authentication Code value with the at least one AES key. The method can also include decrypting, with the computing device sub-component of the ATM, in response to the verifying, the encrypted firmware encryption key the at least one AES key. The method can also include decrypting, with the computing device sub-component of the ATM, the second firmware update with the decrypted firmware encryption key. The method can also include loading, with the computing device sub-component of the ATM, the decrypted second firmware update.

[0018] According to additional features, the method of claim 1 can also include operating the computing device sub-component of the ATM with the firmware in a first configuration for a first period of time. The method can also include verifying, with the computing device sub-component of the ATM, the first firmware update with a key of the manufacturer RSA asymmetric key-pair. Themethod can also include loading, with the computing device sub-component of the ATM, the verified first firmware update and thereby changing the firmware to a second configuration. The method can also include operating the computing device sub-component of the ATM with the firmware in the second configuration for a second period of time after the first period of time. The method can also include decrypting, with the computing device sub-component of the ATM, the second firmware update with the at least one AES key. The method can also include loading, with the computing device sub-component of the ATM, the decrypted second firmware update and thereby changing the firmware to a third configuration. The method can also include operating the computing device subcomponent of the ATM with the firmware in the third configuration for a third period of time after the second period of time.BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The detailed description set forth below references the following drawings:

[0020] Figure 1 is a functional block diagram of an exemplary ATM according to one or more implementations of the present disclosure;

[0021] Figure 2 is a functional block diagram of an exemplary financial transaction computing system according to one or more implementations of the present disclosure;

[0022] Figure 3 is a first portion of a swimlane diagram showing a method that can be executed according to one or more implementations of the present disclosure; and

[0023] Figure 4 is a second portion of the swimlane diagram started in Figure 3.DETAILED DESCRIPTION

[0024] Referring now to the drawings, Figure 1 discloses a functional block diagram of an exemplary ATM 10 according to one or more implementations of the present disclosure. The ATM 10 includes different structures and subsystems for receiving input from a user and executing transactions. The ATM 10 includes a computing device 12. The exemplary computing device 12 has one or more processors and a non-transitory, computer readable medium. The computing device 12 operates under the control of an operating system, kernel and / or firmware and executes or otherwise relies upon various computer software applications, components, programs, objects, modules, data structures, etc. The exemplary computing device 12 can operate under the control of the Windows® operating system. The computer readable medium (memory) of the computing device 12 can include random access memory (RAM) devices comprising the main storage of computing device 12, as well as any supplemental levels of memory, e.g., cache memories, non-volatile or backup memories (e.g.,programmable or flash memories), read-only memories, etc. In addition, the memory may be considered to include memory storage physically located elsewhere from RAM in the computing device 12, such as any cache memory in a processor, as well as any storage capacity used as a virtual memory. The computing device 12 can also include one or more mass storage devices, e.g., a floppy or other removable disk drive, a hard disk drive, a direct access storage device (DASD), an optical drive (e.g., a CD drive, a DVD drive, etc.), and / or a tape drive, among others, represented by memory 46.

[0025] The exemplary ATM 10 also includes a display 14. The computing device 12 can control the display 14 to present information to the user for furthering completion of the transaction. The display 14 can be a touch screen that allows the user to enter information through the display 14. The exemplary display 14 is configured to transmit any user-entered information to the computing device 12.

[0026] The exemplary ATM 10 also includes a key pad 16 and an encryption module 18. Generally, the combination of a key pad and an encryption module are referred to in the art as an encrypted pin pad (EPP). The exemplary key pad 16 includes a plurality of keys, such as key 20. The exemplary encryption module 18 has one or more processors and a non-transitory, computer readable medium. The user can press the keys of the key pad 16 to enter a Personal Identification Number (PIN) or other numerical data. It is noted that the may also enter a PIN through the display 14. The key pad 16 is placed in communication with the encryption module 18 and therefore the numbers of the PIN are received by the encryption module 18. It is noted that the communication of the PIN is direct and secure; the PIN cannot be intercepted between the key pad 16 and the encryption module 18. The PIN is then encrypted by the encryption module 18 to define a PIN block. The encryption module 18 includes a network encryption key and applies the network encryption key to encrypt the PIN to the PIN block. The exemplary encryption module 18 is configured to transmit the PIN block to the computing device 12, which can direct the PIN block away from the ATM 10 during the completion of a financial transaction.

[0027] The exemplary ATM 10 also includes a card reader 22. The card reader 22 can receive a token from the user, such as a card. The card reader 22 can be configured to execute read and write operations with respect to any storage medium fixed to the user’s card. The exemplary card reader 22 can be configured to read data from a magnetic strip on the back of a card or a chip embedded in the card. The exemplary card reader 22 can be configured to transmit any data read from the user’s card to the computing device 12, which can direct the data read from the card away from the ATM 10 during completion of a financial transaction. The exemplary card reader 22 can also be configuredto receive commands and data from the computing device 12 and change data stored on the user’s card.

[0028] The exemplary ATM 10 also includes a printer module 24. The computing device 12 can control the printer module 24 to print a receipt when a transaction has been completed. The printer module 24 can communicate one or more messages to the computing device 12, such as a maintenance message regarding the need to refill printer paper.

[0029] The exemplary ATM 10 also includes an article exchange unit 26. In the exemplary embodiment, the article exchange unit 26 is configured to receive items such as checks. An exemplary article exchange unit 26 can include a drum on which received items are stored. The exemplary article exchange unit 26 includes a slot 28 open to an exterior of the ATM 10 for the receipt of such items. In other embodiments of the present disclosure, an article exchange unit can be configured to facilitate the receipt of other items, different than paper. The article exchange unit 26 can include one or more sensors and transmit signals from any such sensors to the computing device 12 to execute an exchange. The computing device 12 can control the article exchange unit 26 in response to such signals. For example, the article exchange unit 26 can include a sensor that detects receipt of an item such as a check. The article exchange unit 26 can include a further sensor in the form of a scanner that generates an image of the received item and transmits the image to the computing device 12. When an exchange involves the dispensation of an article to the user, the computing device 12 can control the article exchange unit 26 to dispense the item(s) requested by the user.

[0030] The exemplary ATM 10 also includes a printer module 30. The printer module 30 can generate a continuous record of all transactions executed by the ATM 10. The computing device 12 can control the printer module 30 to supplement the record after each transaction has been completed. The printer module 30 can communicate one or more messages to the computing device 12, such as a maintenance message regarding the need to refill printer paper.

[0031] The exemplary ATM 10 also includes an access module 32. The access module 32 can be positioned proximate to a rear side of the ATM 10 and spaced from a front side of the ATM 10. The access module 32 can be utilized by service and support technicians. For example, the access module 32 can be utilized by a field engineer to complete software updates to the computing device 12. The access module 32 can also be utilized when non-software updates and maintenance is performed, such as the refilling of printer paper or currency.

[0032] The exemplary ATM 10 also includes a transceiver 34. The exemplary transceiver 34 is configured to facilitate communication between the computing device 12 and other computingdevices that are distinct from and physically remote from the computing device 12. An example of such a remote computing device is a server computing device, such as a banking or financial institution server communicating with a plurality of ATMs or a switch of the financial network. The exemplary transceiver 34 places the computing device 12 in communication with one or more networks, such as network 36. The network 36 can be a local area network (LAN), a wide area network (WAN) such as the Internet, a Multi -protocol label switching (MPLS) network, a cellular network such as operated by cellular phone companies, a secure financial communications network, or any combination thereof. The network 36 can be a financial / bank network such as NYCE, PULSE, PLUS, Cirrus, AFFN, Interac, Interswitch, STAR, LINK, MegaLink, or BancNet. The transceiver 34 can transmit data and requests for input generated by the computing device 12 and receive responses to these requests, directing these responses to the computing device 12.

[0033] The exemplary ATM 10 also includes a transceiver 38. The exemplary transceiver 38 is configured to facilitate communication between at least one of the encryption module 18 and the computing device 12 and other computing devices that are distinct from and physically proximate to the ATM 10. An example of such a proximate computing device is a smartphone (a mobile computing device) possessed by the user, referenced at 56 in Figure 2. The dashed connection lines in Figure 1 represent optional interconnections. The exemplary transceiver 38 can place the user’s smartphone in communication with the encryption module 18, the computing device 12, or both. The exemplary transceiver 38 can implement various communication protocols. For example, the transceiver 38 can be a Near Field Communication (NFC) device. Alternatively, the transceiver 38 can be a Bluetooth beacon. The transceiver 38 can transmit and receive data and requests for input generated by the encryption module 18 and / or the computing device 12, such transmissions occurring with the user’s smart phone for example.

[0034] The exemplary ATM 10 also includes a currency dispenser 40. The currency dispenser 40 can dispense banknotes, such as currency. The currency dispenser 40 can be a recycler, capable of moving currency in a direction to dispense to a user of the ATM 10 and also capable of moving currency in a direction to store in a cassette of the ATM 10. The currency dispenser 40 can include gears, shafts, belts, rollers, plates, motors, and other structures commonly applied in currency dispensers. The exemplary currency dispenser 40 is shown positioned primarily in a safe 42, but a currency dispenser applied in one or more embodiments of the present disclosure can include components in the safe 42 and in the upper portion or head of the ATM 10. One or more cassettes or cash boxes 44 are also positioned and protected in the safe 42. Banknotes are stored in the cassettes 44 for disbursement to a user of the ATM 10. Banknotes received from the customer can be storedin one or more of the cassettes. The exemplary currency dispenser 40 can extract the banknotes from one or more of the cassettes 44 and direct them out of the ATM 10 through the slot 28. The exemplary currency dispenser 40 thus communicates with the slot 28 in parallel with the exemplary article exchange unit 26. The exemplary currency dispenser 40 can communicate with and be controlled by the computing device 12 for at least some operations. Each of the cassettes 44 can engage the currency dispenser 40 through a rack whereby the positioning of the cassettes is controlled. Further, the each of the cassettes 44 and the currency dispenser 40 can include mating connectors of any form, whereby a positive interconnection is confirmed electronically. When one or more of the cassettes 44 and the currency dispenser 40 are not properly interconnected, a signal or lack thereof can be communicated to the computing device 12 whereby an error message is generated or the ATM 10 can be disabled.

[0035] The exemplary ATM 10 also includes a scanner 48. The scanner 48 can scan, for example, at least a portion of a display of a smart phone and communicate the scanned display to the computing device 12. A token can be displayed on the display of the smart phone and thus scanned by the scanner 48. The token can be a bar code, a quick response (QR) code, a number, a string of alphanumeric characters, a weblink, or some other symbolic indicia or biometric data. The exemplary scanner 48 is configured to transmit any scanned data to the computing device 12, which can direct the scanned away from the ATM 10 during completion of a financial transaction.

[0036] Figure 2 is a functional block diagram of an exemplary system 50 according to one or more implementations of the present disclosure. The exemplary system 50 includes the ATM 10. The exemplary system 10 also includes a computing device 52, which is a server computing device in the exemplary embodiment of the present disclosure. The computing device 52 can be a banking core and can access a database 54 of accounts maintained or held by a financial institution. The exemplary computing device 52 has one or more processors and a non-transitory, computer readable medium. The system 50 can be operated by a financial institution and the user can be an account holder of the financial institution. Other implementations of the present disclosure, by way of example and not limitation, can be a system operated by a merchant of consumer goods, a provider of healthcare-related products, or a delivery company.

[0037] The ATM 10 and the computing device 52 can communicate over the network 36. Transmissions over the network 36 may be encrypted and may include Message Authentication Codes (MACs) to enhance security. MACs can be appended to messages sent from and received by a device such as the ATM 10. MACs verify that the messages sent and the messages received are identical and also confirm that messages originate from an approved source. The computing devices 12 and52 can also apply Transport Layer Security (TLS) or Secure Sockets Layer (SSL) protocols and include respective firewalls to enhance security. The computing device 52 can also communicate with user computing devices, such as a user’s tablet computer 58, over a network 60. The network 60 can be a local area network (LAN), a wide area network (WAN) such as the Internet, a Multiprotocol label switching (MPLS) network, a cellular network such as operated by cellular phone companies, a financial network, or any combination thereof.

[0038] It is noted that the exemplary bank core 52 can be in communication with a plurality of ATMs and the disclosure herein of communications and interactions between the bank core 52 and the ATM 10, as well as components thereof, can be applicable to communications and interactions between the bank core 52 and other ATMs.

[0039] In the exemplary embodiment of the present disclosure, the computing device 12 of ATM 10, also referred to as the primary PC or controller of the ATM 10, can be assigned and store a digital certificate including a unique Rivest-Shamir-Adleman (“RSA”) asymmetric key-pair for enhancing security during the transmitting and receiving of data, such as firmware updates. In one or more embodiments of the present disclosure, various sub-components of the ATM 10, computing device sub-components, may each have its own digital certificate that includes an RSA key pair. For example, the EPP and / or the dispenser 40, or any other sub-component within the ATM 10 that includes firmware, can be assigned and store a digital certificate including a unique, “sub-component” RSA asymmetric key -pair. A firmware update can be signed by a first key of another RSA key pair, a “manufacturer” RSA key pair. The first key can be a private key of the manufacturer RSA key pair. The firmware update, signed by the first key, can then be transmitted to the appropriate subcomponent within the ATM 10 that has been loaded with the second key the manufacturer RSA key pair, the public key, and verified with the second key of the manufacturer RSA key pair. The term “manufacturer” is used herein not as a limitation that only the maker of the ATM 10 or a maker of a sub-component of the ATM 10 can control firmware updates in embodiments of the disclosure, but is used merely as adjective in order to differentiate RSA key pairs that are discussed herein. In one or more embodiments of the present disclosure, only a public key of the manufacturer RSA key pair is loaded into the sub-component of the ATM 10 to allow the firmware signed by the holder of the private key of the manufacturer RSA key pair to be verified by the sub-component. The public key of the manufacturer RSA key pair can be encapsulated in a certificate.

[0040] One or more sub-components of the ATM 10 can have a unique, respective “subcomponent” RSA key pair that can be utilized in various processes. For example, the sub-component RSA key pair can be used when securely importing an Advanced Encryption Standard (“AES”)symmetric key, for at least one purpose that is described in greater detail below. Each sub-component RSA key-pair has a corresponding certificate and includes a private key that is stored within that subcomponent. Step 88, detailed below, is a step of generating a sub-component RSA key-pair and the corresponding certificate is stored at step 114 below. This device unique sub-component RSA keypair can be used for Trusted Device Communications and End-to-End. In the present disclosure, the device unique sub-component RSA key pair can be used to import a device unique AES symmetric key and this will be detailed in steps 116 - 136 below. The following features can encrypt the AES symmetric key with the public key of the device sub-component RSA key pair: import firmware protection AES symmetric key; import end-to-end symmetric key as disclosed in U.S. Pat. No. 10970975B2 which is incorporated herein by reference; and establish a symmetric session key for Trusted Device Communications (TDC) to secure the USB connection between the ATM PC 12 and the device sub-component.

[0041] Figure 2 also shows a manufacturing server 62. The manufacturing server 62 can communicate with all of the distinct computing devices of the ATM 10 to load software on these devices during the assembly of the ATM 10 (represented by double arrow 61), before the ATM 10 is placed into service in the field. Manufacturing of the ATM 10 thus includes the assembly of mechanical and electromechanical components as well as the loading of desired software. The communication between the manufacturing server 62 and each of the distinct computing devices of the ATM 10 can be over any kind of network, wirelessly such as by Bluetooth™, or over a wired connection. In one or more embodiments of the present disclosure, there is no connection between the manufacturing server 62 and the ATM 10 once the ATM 10 leaves a location at which the ATM 10 is at least partially manufactured / assembled. Software and firmware updates for the ATM 10 can be loaded manually by ATM technicians via a site visit. Financial Institutions can also establish remote connections to their ATMs for the purpose of installing (and updating) software. Financial institutions can obtain software and firmware updates from the manufacturer / provider of the ATM and install these updates remotely or manually.

[0042] As set forth above, each of the ATM 10’s computing device sub-components may be loaded with its own digital certificate and each digital certificate can include an RSA, private-public key pair. When the ATM 10 is placed in use in the field, each of the ATM 10’s computing device sub-components can utilize their respective sub-component RSA key pair for secure communications, such as, by way of example and not limitation, firmware updates. However, Figures 3 and 4 are consecutive portions of a swimlane diagram showing an exemplary method that can be executed according to one or more implementations of the present disclosure to enhance the security ofcommunications. Figures 3 and 4 show an exemplary method in which a symmetric key is loaded on an ATM computing device sub -component, to be held in secret and brought into use when RSA encryption is compromised by quantum computers.

[0043] As shown in Figure 3, the components executing actions in the exemplary method include a Key Distribution Host (KDH) key and certificate module 66, a Digital Certificate Authority (DCA) 68, a database 70, a provisioning application (app) 72, a ATM Application / XFS Application module 74 of the ATM 10, and a Key Receiving Device (KRD) 76 that is representative of a computing device sub-component of the ATM 10. The KDH module 66 and the provisioning app 72 can be operating on the manufacturing server 62. The DCA 68 can be an entity independent of the ATM manufacturer and the financial institution that operates the ATM 10 and the bank core 52. The database 70 can be maintained by the manufacturer of the ATMs along with the manufacturing server 62. The ATM Application / XFS Application module 74 of the ATM 10 can operate on the main PC of the ATM 10 (such as the computing device 12).

[0044] At 78, the KDH module 66 generates unique keys for a predetermined number of ATMs. The predetermined number can be the number of ATMs being manufactured at that time or could be a different number. Each key that is generated is assigned to one sub-component of one of the ATMs that is being manufactured. Each key can be correlated to the serial number of the particular sub-component. Each of these keys is designated herein as Kn, where the “n” can correspond to the serial number of the particular sub-component. Thus, each key is device specific, device unique. Each exemplary key Kn is a symmetric key and not a key of an asymmetric key pair. At 80, this correlation of keys to ATM sub-component serial numbers is communicated to the database 70 and stored in the database 70.

[0045] Each key Kn can be a 128-bit AES key and for firmware protection. The key Kn can be desirable to provide security when the RSA protocol is undermined when the use of quantum computers becomes prevalent or even merely begins. At that time, it is likely that Transport Layer Security (“TLS”) and Trusted Device Communications (“TDC”) will not be reliable to ensure secure communications. Further, Remote Key Loading (“RKL”) and End-to-End (“E2E”) will not be reliable to securely establish a new key. The AES key Kn may be unused for an extended period of time and thus define a long-term secret shared by the manufacturing server 62 and the exemplary subcomponent of the ATM 10. Firmware updates can be accomplished under the security provided by the AES key after quantum computers compromise RSA signatures. Prior to quantum computers compromising RSA signatures, firmware updates can be accomplished under the security provided by RSA key pairs. A 128-bit AES key Kn can be chosen because the key strength is similar to thestrength of a 2048-bit RSA asymmetric key pair. The AES key Kn can be random or can be derived by using a one-way function on a master key.

[0046] Actions 82 - 86 detail the issuance of a digital certificate to the KDH module 66. The issuance of a digital certificate to the KDH module 66 enhances the security of loading a key Kn on the KRD 76. At 82, the KDH module 66 transmits a certificate signing request (CSR) to the DCA 68. At 84, the DCA 68 creates and stores a copy of the digital certificate. At 86, the DCA 68 transmits the digital certificate, designated as CTkdh (the digital certificate of the KDH module 66), to the KDH module 66. The digital certificate CTkdh includes a KDH identifier IDkdh.

[0047] Actions 88 - 114 detail the issuance of a digital certificate to the KRD 76 (the exemplary, particular sub-component of the ATM 10). The issuance of a digital certificate to the KRD 76 enhances the security of loading a key Kn on the KRD 76. At 88, the KRD 76 generates a sub-component RSA key pair. At 90, the provisioning app 72 transmits a directive to the KRD 76 for the KRD 76 to generate a CSR. The provision app 72 facilitates communication between the KDH module 66 and the KRD 76.

[0048] At 92, the KRD 76 creates and stores the CSR. At 94, the KRD 76 transmits the CSR to the provisioning app 72. At 96, the provisioning app 72 transmits a request to the KRD 76 for the KRD 76 to generate a random number. At 98, the KRD 76 creates and stores the random number Rkrd. At 100, the KRD 76 transmits the random number Rkrd to the provisioning app 72.

[0049] At 102, the provisioning app 72 transmits the CSR and random number Rkrd generated by the KRD 76 to the KDH module 66. The KDH module 66 can store the random number Rkrd. At 104, the KDH module 66 transmits the CSR generated by the KRD 76 to the DCA 68, thus requesting a digital certificate on behalf of the KRD 76. At 106, the DCA 68 creates and stores a digital certificate for the KRD 76. At 108, the DCA 68 transmits the digital certificate CTkrd to the KDH module 66. The KDH module 66 can store a copy of the digital certificate CTkrd. The digital certificate CTkrd includes a KRD identifier IDkrd. At 110, the KDH module 66 transmits the digital certificate CTkrd to the provisioning app 72. At 112, the provisioning app 72 transmits the digital certificate CTkrd to the KRD 76. At 114, the KRD 76 stores its digital certificate CTkrd.

[0050] Actions referenced from 116 in Figure 3 through 136 in Figure 4 detail the loading of the key Kn to the KRD 76 (the exemplary, particular sub-component of the ATM 10). It is noted that the actions 116 - 136 can occur during the manufacturing of the ATM 10, before the ATM 10 is placed for use in the field. It is also noted that actions 88-136 can also occur in a facility that repairs ATM devices. At 116, the KDH module 66 transmits a serial number of the KRD 76 as part of a request to the database 70 to retrieve the key Kn that corresponds to the serial number of the KRD76. It is noted that key Kn to be retrieved was generated and stored at action 78. At 118, the database 70 transmits the retrieved, device unique key Kn to the KDH module 66. At 120, the KDH module 66 retrieves the digital certificate CTkrd, which was received at 108. At 122, the KDH module 66 retrieves the random number Rkrd, which was received at 102. In regards to steps 120 and 122, there may be some timelapse since steps 102 and 108 or the KDH module 66 may have provisioned some other device so it is possible that the values retrieved at steps 102 and 108 must be retrieved again or would correspond to the current KRD device that keys are being loaded into.

[0051] At 124, the KDH module 66 transmits the digital certificate CTkdh to the KRD 76, through the provisioning app 72. At 126, the KRD 76 verifies the digital certificate CTkdh.

[0052] As shown in Figure 4, at 128, the KDH module 66 transmits / sends to the KRD 76, via the provisioning app 72, a TR34 key to facilitate remote key loading, a generated ephemeral key Ke, a constructed key block with the key Kn and a key block header KBH & IDkdh, an enciphered key block BE, an enciphered ephemeral key with a public key of the KRD 76, and a key token KTkdh signed with a private signature key Skdh.

[0053] At 130, the KRD 76 verifies the signature and the random number, deciphers the ephemeral key and key block BE, validates the KDH identifier IDkdh, and stores the symmetric key Kn. At 132, the KRD 76 calculates a key check value KVC(Kn). At 134, the KRD 76 transmits the key check value KVC(Kn) to the KDH module 66. At 136, the KDH module 66 verifies the key check value KVC(Kn) to ensure that the KRD 76 received the key Kn as it was transmitted.

[0054] Actions referenced at steps 138 - 166 in Figure 4 detail the secure transfer of a firmware update to the KRD 76. It is noted that the actions 138 - 166 can occur after the manufacturing of the ATM 10, after the ATM 10 has been placed for use in the field. At 138, the KDH module 66 transmits a request to the database 70 for the device unique key Kn of the particular sub-component that is to receive the firmware update. It is also noted that the actions 138 - 166 can occur after other firmware updates were loaded on the KRD device 76 using RSA protocols for security. The actions 138 - 166 can be performed once the operators of the bank core 52 and / or the server 62 have determined that RSA protocols are compromised by the prevalent use of quantum computers.

[0055] At 140, the key Kn is transmitted by the database 70 to the KDH module 66. At 142, the KDH module 66 generates a firmware encryption key FWkey. At 144, the KDH module 66 encrypts the firmware update with the firmware encryption key FWkey and encrypts the firmware encryption key FWkey with the symmetric key Kn of the KRD 76. At 146, the KDH module 66 calculates a Hash based Message Authentication Code (HMAC) value for the KRD 76 using a SecureHash Algorithm (SHA256) and the device unique key, Kn, as the secret. At 148, the KDH module 66 concatenates the device unique encrypted FWkey and the HMAC value and also the encrypted firmware update (FW) file for the KRD device 76.

[0056] While not shown in the swimlane diagram, the concatenated file is transmitted by the KDH module 66 to the ATM Application / XFS Application module 74. At 150, the ATM Application / XFS Application module 74 transmits a request to the KRD 76 to confirm the serial number of the KRD 76. At 152, the KRD 76 transmits its serial number to the ATM Application / XFS Application module 74. The completion of actions 150 and 152 confirm that the KRD device 76 is the correct device to receive the concatenated file. At 154, the ATM Application / XFS Application module 74 extracts the encrypted firmware encryption key FWkey and the encrypted firmware update from the concatenated file. At 156, the ATM Application / XFS Application module 74 extracts the HMAC for the KRD 76, the HMAC(Ksn). At 158, the ATM Application / XFS Application module 74 transmits the encrypted firmware encryption key FWkey and HMAC and the encrypted firmware update to the KRD 76. At 160, the KRD 76 verifies the HMAC using the device unique key Kn. At 162, the KRD 76 decrypts the encrypted firmware encryption key FWkey using the device unique key Kn. At 164, the KRD 76 decrypts the encrypted firmware file FW using the now-decrypted firmware encryption key FWkey. At 166, the KRD 76 loads the FW file.

[0057] It is noted that a firmware update sent to device sub-component is embedded into a PKCS (Public Key Cryptography Standards) PKCS #7 Signed-data message. The signing certificate and intermediate CA certificate are also included in the PKCS #7 Signed-data message. Only the root of trust (e.g. the root CA certificate) is hard-coded into the device sub-component base firmware.

[0058] In one or more embodiments of the present disclosure, two device unique keys, Knl and Kn2 could be created and assigned to each ATM. Each key Km and Km can be used for a single purpose. In such embodiments, step 78 would be modified such that the KDH module 66 would generate two unique keys for a sub-component of each ATM. In such embodiments, steps 116 - 136 can be executed twice, once to load Km and second time to load Km. Such embodiments can be desirable to use each keys for a different operational purpose. For example, at step 144, the KDH module 66 could encrypt the firmware encryption key FWkey with the symmetric key Knl of the KRD 76. Continuing this example, at step 146, the KDH module could 66 calculate a Hash based Message Authentication Code (HMAC) for the KRD 76 using a Secure Hash Algorithm (SHA256) and the device unique key, Km, as the secret.

[0059] What has been described above includes examples of the subject innovation. It is, of course, not possible to describe every conceivable combination of components or methodologies forpurposes of describing the disclosed subject matter, but many further combinations and permutations of the subject innovation are possible. The use of any and all examples, or exemplary language (e.g., “such as”) provided herein is intended merely to be illustrative and does not pose a limitation on the scope of any innovation disclosed herein unless otherwise claimed. The word “exemplary” is used to mean serving as an example, instance, or illustration. Any aspect or design described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects or designs. Rather, use of the word “exemplary” is intended to present concepts in a concrete fashion. Further, any statements set forth within the Detailed Description of this document and addressing a prior art device(s) are the observations of the inventors and such statements themselves are not prior art or admissions as to what is prior art.

[0060] As used herein, the singular forms “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. Unless indicated otherwise by context, the term “or” is to be understood as an inclusive “or.” Terms such as “first”, “second”, “third”, etc. when used to describe multiple devices or elements, are so used only to convey the relative actions, positioning and / or functions of the separate devices, and do not necessitate either a specific order for such devices or elements, or any specific quantity or ranking of such devices or elements. Use of the terms “about” or “approximately” are intended to cover values that are above and / or below a stated value or range, or within manufacturing tolerances, as would be understood by one having ordinary skill in the art in the respective context. In some instances, this may encompass values in a range of approx. + / -10%; in other instances there may be encompassed values in a range of approx. + / -5%; in yet other instances values in a range of approx. + / -2% may be encompassed; and in yet further instances, this may encompass values in a range of approx. + / -!%.

[0061] It will be understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof, unless indicated herein or otherwise clearly contradicted by context. Recitations of a value range herein, unless indicated otherwise, serves as a shorthand for referring individually to each separate value falling within the stated range, including the endpoints of the range, each separate value within the range, and all intermediate ranges subsumed by the overall range, with each incorporated into the specification as if individually recited herein. Unless indicated otherwise, or clearly contradicted by context, methods described herein can be performed with the individual steps executed in any suitable order, including: the precise order disclosed, without any intermediate steps or with one or more further steps interposed between thedisclosed steps; with the disclosed steps performed in an order other than the exact order disclosed; with one or more steps performed simultaneously; and with one or more disclosed steps omitted, unless expressly contradicted by the text herein or context.

[0062] While the present disclosure has been described with reference to one or more exemplary embodiments, it is to be understood that various changes may be made and equivalents may be substituted for elements thereof without departing from the scope of the present disclosure. In addition, many modifications may be made to adapt a particular situation or material to the teachings of the present disclosure without departing from the essential scope thereof. Therefore, it is intended that the present disclosure not be limited to a particular embodiment disclosed herein as the best mode contemplated for carrying out this present disclosure, but that the present disclosure will be viewed as covering any embodiment falling within the scope of the appended claims. Various aspects or features described herein may be implemented as a method, apparatus, or article of manufacture using standard programming and / or engineering techniques.

[0063] Also, the right to claim for patent coverage a particular sub-feature, a sub-component, or a sub-element of any disclosed embodiment, singularly or in one or more sub-combinations with any other sub-feature(s), sub-component(s), or sub-element(s), is hereby unconditionally reserved by the Applicant. Also, particular sub-feature(s), sub-component(s), and sub-element(s) of one embodiment that is disclosed herein can replace particular sub-features, sub-components, and subelements of another embodiment disclosed herein or can supplement and be added to another embodiment unless expressly indicated otherwise by the drawings or this specification. The inventor also assert that any of the claims set forth after this detailed description can be combined with any other claim or claims regardless of whether or not there is a direct line of dependency, unless there is an express indication in this text or the drawings unambiguously indicating that such a combination is not possible. The order of the claims and the lines of dependency are irrelevant to the various ways that the features, elements, sub-elements, components, sub-components, etc. of the present disclosure can be combined and thus claimed. Further, the use of the word “can” in this document is not an assertion that the subject preceding the word “can” is unimportant or unnecessary or “not critical” relative to anything else in this document. The word “can” is used herein in a positive and affirming sense and no other motive should be presumed. More than one patentable “invention” may be disclosed in the present disclosure and it is noted that an “invention” is defined by the content of a patent claim and not by the content of descriptive text or drawings.

Claims

CLAIMSWhat is claimed is:

1. A method of operating an automated transaction machine (ATM) comprising: loading, to a memory of a computing device sub-component of the ATM, a public key of a manufacturer Rivest-Shamir-Adleman (RSA) asymmetric key-pair; loading, to the memory of the computing device sub-component of the ATM, at least one Advanced Encryption Standard (AES) key; configuring a first firmware update of a firmware of the computing device sub-component of the ATM to utilize the manufacturer RSA asymmetric key-pair for firmware protection; and configuring, after said configuring the first firmware update, a second firmware update of the firmware of the computing device sub-component of the ATM to utilize the at least one AES key for firmware protection.

2. The method of claim 1 wherein said configuring the first firmware update is further defined as: configuring the first firmware update of the firmware of the computing device subcomponent of the ATM to utilize the manufacturer RSA asymmetric key -pair for firmware protection by signing the first firmware update with a first key of the manufacturer RSA asymmetric key-pair.

3. The method of claim 2 wherein said configuring the second firmware update is further defined as: configuring, after said configuring the first firmware update, the second firmware update of the firmware of the computing device sub-component of the ATM to utilize only the at least one AES key for firmware protection by encrypting the second firmware update with a firmware encryption key and encrypting the firmware encryption key the at least one AES key.

4. The method of claim 2 further comprising: verifying, with the computing device sub-component of the ATM, before said configuring the second firmware update, the first firmware update with a second key of the manufacturer RSA asymmetric key-pair.

5. The method of claim 4 further comprising: decrypting, with the computing device sub-component of the ATM, after said configuring the second firmware update, a firmware encryption key with the at least one AES key.

6. The method of claim 1 further comprising: generating, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, the at least one AES key and assigning the at least one AES key to a serial number of the computing device sub-component of the ATM; positioning the ATM at a location for use by bank customers; and transmitting, with the Key Distribution Host key and certificate module, the at least one AES key to the computing device sub-component of the ATM before said positioning.

7. The method of claim 1 wherein said loading the at least one AES key further comprises: transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key in a key block constructed of the at least one AES key and a key block header and an identifier of the Key Distribution Host key and certificate module, wherein the identifier is defined by a digital certificate of the Key Distribution Host key and certificate module.

8. The method of claim 1 wherein said loading the at least one AES key further comprises: transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with a TR34 key to facilitate remote key loading.

9. The method of claim 1 wherein said loading the at least one AES key further comprises: transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with an enciphered key block.

10. The method of claim 1 wherein said loading the at least one AES key further comprises: transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with an ephemeral key enciphered with a public key of the computing device sub-component of the ATM.

11. The method of claim 1 wherein said loading the at least one AES key further comprises: transmitting, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, to the computing device sub-component of the ATM, the at least one AES key with a key token signed with a private signature key of the Key Distribution Host key and certificate module.

12. The method of claim 1 further comprising: generating, with a Key Distribution Host key and certificate module operating on a first server computing device of a manufacturer of the ATM, a firmware encryption key; and encrypting, by the Key Distribution Host key and certificate module, the second firmware update with the firmware encryption key.

13. The method of claim 12 further comprising: encrypting, by the Key Distribution Host key and certificate module, the firmware encryption key with the at least one AES key.

14. The method of claim 13 further comprising: calculating, with the Key Distribution Host key and certificate module, a Hash based Message Authentication Code value for the computing device sub-component of the ATM using a Secure Hash Algorithm and the at least one AES key as the secret.

15. The method of claim 14 wherein the at least one AES key is further defined as at least a first AES key and a second AES key and wherein: said encrypting the firmware encryption key is further defined as encrypting, by the Key Distribution Host key and certificate module, the firmware encryption key with the first AES key; and said calculating, with the Key Distribution Host key and certificate module, the Hash based Message Authentication Code value for the computing device sub-component of the ATM using the Secure Hash Algorithm and the second AES key as the secret.

16. The method of claim 14 further comprising: concatenating, with the Key Distribution Host key and certificate module, the encrypted firmware encryption key and the Hash based Message Authentication Code value and the encrypted second firmware update to define a concatenated file.

17. The method of claim 16 further comprising: receiving, with an ATM Application / XFS Application module of the ATM, from the Key Distribution Host key and certificate module, the concatenated file; and confirming, with the ATM Application / XFS Application module, a serial number of the computing device sub-component of the ATM.

18. The method of claim 17 further comprising: extracting, with the ATM Application / XFS Application module, in response to said confirming, the encrypted firmware encryption key and the Hash based Message Authentication Code value and the encrypted second firmware update from the concatenated file; and transmitting, from the ATM Application / XFS Application module, to the computing device sub-component of the ATM, after said extracting, the encrypted firmware encryption key and the Hash based Message Authentication Code value and the encrypted second firmware update.

19. The method of claim 18 further comprising: verifying, with the computing device sub-component of the ATM, after said transmitting, the Hash based Message Authentication Code value with the at least one AES key; decrypting, with the computing device sub-component of the ATM, in response to said verifying, the encrypted firmware encryption key the at least one AES key; decrypting, with the computing device sub-component of the ATM, the second firmware update with the decrypted firmware encryption key; and loading, with the computing device sub-component of the ATM, the decrypted second firmware update.

20. The method of claim 1 further comprising: operating the computing device sub-component of the ATM with the firmware in a first configuration for a first period of time; verifying, with the computing device sub-component of the ATM, the first firmware update with a key of the manufacturer RSA asymmetric key-pair; loading, with the computing device sub-component of the ATM, the verified first firmware update and thereby changing the firmware to a second configuration; operating the computing device sub-component of the ATM with the firmware in the second configuration for a second period of time after the first period of time; decrypting, with the computing device sub-component of the ATM, the second firmware update with the at least one AES key; loading, with the computing device sub-component of the ATM, the decrypted second firmware update and thereby changing the firmware to a third configuration; and operating the computing device sub-component of the ATM with the firmware in the third configuration for a third period of time after the second period of time.

Citation Information

Patent Citations

  • System and methods for secure firmware validation

    US20210049279A1

  • System and method to perform digital authentication using multiple channels of communication

    US20230020843A1

  • Offline interaction system and method

    US20230344649A1