Monolithic sensor device, protection system for detecting tampering in ATM terminals and method for recognizing tampering patterns in ATM terminals

The system uses AI-based pattern recognition with audio, vibration, and infrared sensors to distinguish ATM tampering from environmental disturbances, enhancing security and reducing power consumption.

WO2025208194A1PCT designated stage Publication Date: 2025-10-09PROCOMP AMAZONIA IND ELECTRONICSA

Patent Information

Application Number
PCT/BR2025/050119
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-05
Filing Date
2025-03-28
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Existing ATM security systems face challenges in distinguishing between real attacks and environmental disturbances, particularly with seismic sensors that generate false alerts from external factors like heavy trucks or subway trains, and mesh networks are costly and have coverage gaps.

Method used

A system utilizing a processing platform with artificial intelligence for pattern recognition, combining audio, vibration, and infrared sensors, employing deep learning to differentiate between tampering attempts and normal environmental disturbances, with a fraud detection system and energy-efficient design.

Benefits of technology

Effectively identifies tampering attempts on ATMs by differentiating sound recordings and vibrations from normal environmental conditions, reducing false alarms and maintaining low power consumption while ensuring robust security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BR2025050119_09102025_PF_FP_ABST
    Figure BR2025050119_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention provides a system, method, and intelligent device for detecting attempts to tamper with automated terminals. The system comprises a processing unit, a data acquisition subsystem, a self-test subsystem, a power monitoring system, a tamper detection system and an intelligent agent system. The system is in communication with a sensor system comprising a plurality of sensors which provide monitoring information of the ATM terminal, such as vibration, brightness and audio aspects. By means of an artificial intelligence model using a convolutional neural network (CNN), the system can recognise patterns and distinguish a real attack from normal disturbances in the environment.
Need to check novelty before this filing date? Find Prior Art

Description

MONOLITHIC SENSOR DEVICE, PROTECTION SYSTEM FOR TAMPERING DETECTION IN ATM TERMINALS AND METHOD FOR RECOGNITION OF TAMPERING PATTERNS IN ATM TERMINALS FIELD OF APPLICATION

[0001] The present invention discloses an intelligent system for detecting attempted breaches of ATMs, using pattern recognition to distinguish between a real attack and normal behavior. This technology is particularly applicable in the field of artificial intelligence focused on ATM security in banking networks. DESCRIPTION OF THE STATE OF THE TECHNIQUE

[0002] Self-service banking devices, widely known as ATMs (Automated Teller Machines), provide remarkable convenience for executing transactions and accessing resources available within the banking network. These terminals eliminate the need for an intermediary, allowing financial institution customers to conduct transactions without the intervention of a bank employee. In the ATM environment, the customer is identified by inserting a plastic card equipped with a chip containing security information.

[0003] These devices play a crucial role in providing 24 / 7 banking services, making them potential targets for criminal activity. Therefore, the security measures implemented in ATMs are essential to ensure the integrity of transactions and the protection of financial resources.

[0004] Given the high number of attempted breaches of ATM terminals, companies responsible for developing these devices constantly need to improve their security systems to mitigate the impacts of criminal activities.

[0005] One of the key aspects of ATM security is their strategic location. Installing ATMs in well-lit, busy, and visible areas helps deter criminal activity. Additionally, installing high-quality surveillance cameras near ATMs not only provides visual records but also acts as a preventative measure.

[0006] The physical design of ATMs is another critical factor in security. Many ATMs are constructed with durable materials and include tamper-resistant features, such as reinforced steel plates and advanced electronic locks. These devices are designed to resist physical tampering attempts, protecting the cash stored inside.

[0007] Electronic security also plays a crucial role. ATMs are equipped with intrusion detection systems that can alert authorities in the event of a break-in attempt. Furthermore, transactions are protected by robust encryption and multi-factor authentication to ensure the safety of customer information.

[0008] Another measure used is the implementation of skimming prevention technologies, which is a technique in which fraudulent devices are installed in ATMs to capture bank card data. The use of anti-skimming devices and regular inspection of ATMs are common practices to mitigate this type of threat.

[0009] According to the president of the Brazilian Federation of Banks (Febraban), Isaac Sidney, “Financial institutions operate primarily on two fronts: significant investment in improving physical security, in the order of R$9 billion per year, and intense cooperation with authorities responsible for public security.” (SIDNEY, Isaac. Interview given to the communications department. Febraban, São Paulo, March 17, 2023. Available at: https: / / portal.febraban.org.br / noticia / 3906 / pt-br / . Accessed on: January 31, 2024.).

[0010] Given the high number of attempted breaches and the high investments, research has been frequently carried out with the aim of improving security and ensuring the integrity of these ATM terminals.

[0011] In this regard, patent document IN202241027547 (2022) reveals an embedded device aimed at preventing crimes at ATM terminals. This device uses an Arduino controller to process real-time data collected through vibration and infrared sensors. This system uses MEMS (Micro-Electro-Mechanical Systems) sensors to detect suspicious movements around the ATM. When a theft is detected, the system emits an audible signal, automatically closes the teller door, and releases chloroform gas to incapacitate the thief. Furthermore, the system records the theft and sends a message to the nearest police station via GSM (Global System for Mobile Communications) technology.

[0012] Patent document IN202241062177 (2022), which discloses the use of an Arduino device in conjunction with a vibration sensor, leveraging IoT technology. The vibration sensor detects abnormal movements and transmits the information to the system controller. When an anomaly is detected, the system emits a continuous beep to alert nearby people and automatically closes the ATM door, preventing the thief from escaping. Additionally, the system sends alert messages to the nearest police station and bank branches using IoT technology.

[0013] Another document is patent US5537938A (USA), which discloses an anti-theft device for ATMs that blurs or defaces banknotes stored in cassettes / containers inside the ATM after a security breach. This device releases a dye or ink, stored under pressure, into a distribution manifold that is integrally connected to the banknote cassette and in communication with its interior. after receiving an actuation signal. The signal is preferably activated by an electrical device that triggers the release of ink into the cassette. In one embodiment, the distribution manifold is automatically connected and disconnected from the tank during cassette changes, without the need for user intervention.

[0014] Patent IN201841025056 (2018) uses vibration, pressure, temperature sensors, cameras and a microcontroller, employing GSM technology to send SMS alerts to both the police and the bank's premises when it detects an attempted intrusion into the ATM terminal.

[0015] Patents IN20201 101 1 101 (2020) implement devices aimed at protecting ATM terminals. It is an anti-theft system for automated teller machines (ATMs) capable of distinguishing between normal users and potential attackers. The system involves input detection and authentication phases. During input detection, finger movement is analyzed, identifying start and end points. In the authentication phase, features are extracted, and a gradient boosting tree-based classification protocol is used to categorize the user. A camera captures live images to detect suspicious activity. The transaction only proceeds if the user is classified as normal and no suspicious activity is identified.

[0016] Patent document IN202141055342 (2021) implements devices aimed at protecting ATM terminals. The invention proposes to implement secure access to ATMs by authorized personnel, remotely monitoring and closing doors using specific hardware. The system is based on M2M (Machine-to-Machine) and integrates devices for capturing events transmitted over networks. The proposed anti-theft model uses an Embedded Web Server (EWS) based on ARM11 and Linux. It includes RFID (Radio-Frequency Identification) and DC motors for closing doors.

[0017] Patent document IN20201 1012153 discloses a security system for ATMs comprising a mapped vibration sensor that detects unusual vibrations that indicate theft or fraud activity and that generates a command signal if the vibration exceeds a threshold level.

[0018] Patent document JP2004213590 discloses the installation of vibration sensors, separation sensors, and similar devices in safes or similar devices. When a criminal act occurs, such as breaking or removing the safe without following a prescribed procedure, these sensors detect the criminal activity. In response, a clear signal is triggered, resulting in measures such as spraying ink on banknotes or perforating the notes inside the safe.

[0019] Patent document KR200379853 discloses the incorporation of a human body detection sensor in the ATM and a vibration sensor in the ATM, both wirelessly connected to a security terminal. This connection is established through the construction of a security system that connects the terminal to the wired network. When a person approaches the ATM and the vibration sensor detects movement due to external physical force, the detection signals are combined. In response, a voice alert of theft is issued directly from the location and from a designated center. This security system enables an immediate response to the theft of cash or checks from ATMs, sending alerts to relevant authorities, such as police stations and managers.

[0020] Patent document CN204559775 discloses an intelligent ATM monitoring system consisting of a control module. This control module is connected to an infrared sensor, a vibration sensor, and an alarm module. The control module is connected to computers connected via a serial port, and the computer uses a video acquisition module connected via a USB line. Specific models mentioned include stc89c52rc for the control module, E18- D80NK for the infrared sensor, SW-420 for the vibration sensor, T3200 for the video acquisition module, and WT588D-U for the alarm module. This utility model offers benefits such as a simple structure, reduced cost, and effective monitoring capability for ATMs.

[0021] Patent document US6508397 discloses a multi-layered security system to prevent theft from advanced automated teller machines (ATMs). The system includes access control, an infrared detector, impact sensors, a heavy-duty security chest, and a glass blocking plate. These measures aim to deter, detect, and prevent break-ins, making ATM theft significantly more difficult.

[0022] To minimize the effects of attempted tampering with ATM terminals, some models can be equipped with seismic sensors that are sensitive to vibrations caused by attack tools such as blowtorches, drills, cutting discs, thermal lances, among others.

[0023] One limitation of technologies that employ seismic sensors is that they have difficulty distinguishing between a real attack on an ATM and vibrations caused by the environment, such as those caused by a heavy truck or subway train near the terminal. Therefore, the alert generated by the seismic sensor must be confirmed through an alternative method so that protective measures can be triggered.

[0024] Another reliable approach is the use of a protective mesh network, which surrounds the safe's internal walls. No technology has proven as effective as the mesh network, and it is the primary means of protecting ATMs against attacks (Sujith, 2014). The mesh network is an electrical circuit that runs through the area to be protected and can be activated in the event of an interruption in the network, indicating an attack on the ATM.

[0025] However, the main disadvantage of the mesh network is the high development cost, which requires customization for each model. terminal. Another disadvantage is the existence of areas without coverage in the mesh network, making the system vulnerable, for example, to drill attacks.

[0026] In this context, the state of the art would benefit from a system composed of a processing platform and an intelligent model based on artificial intelligence for pattern recognition in sound recordings, accelerations and infrared light detection, capable of identifying and differentiating attempts to violate the ATM terminal from casual disturbances in the environment. OBJECTIVES OF THE INVENTION

[0027] In order to solve the problems of the prior art, it is an objective of the present invention to provide a system consisting of a processing platform and an intelligent model based on artificial intelligence.

[0028] It is an objective of the present invention to provide a system for recognizing patterns of sound recordings, acceleration and infrared light detection capable of identifying attempts to tamper with the ATM terminal.

[0029] It is an objective of the present invention to provide a system capable of identifying attempts to tamper with the ATM terminal by differentiating sound recordings from normal environmental disturbances.

[0030] It is an objective of the present invention to provide a method of detecting and identifying attempted tampering with the ATM terminal by differentiating sound recordings from normal environmental disturbances.

[0031] Finally, it is an objective of the present invention to provide a device complying with an artificial intelligence model for detecting and identifying attempts to tamper with the ATM terminal by differentiating sound recordings from normal environmental disturbances. SUMMARY OF THE INVENTION

[0032] In order to achieve the presented objectives, the present invention provides a protection system for detecting tampering in ATM terminals. The system comprises the following modules: a processing unit coupled to a sensor unit, wherein the sensor unit comprises a plurality of sensors that monitor at least vibration, light, and audio; a data acquisition subsystem that performs sequential capture of sensors during a predefined time interval; an intelligent agent module for detecting bank terminal tampering, which detects ATM attack patterns; a self-test subsystem, which verifies the functionality of the sensors; a power monitoring system that maintains low power consumption; and a fraud detection system.

[0033] Furthermore, the present invention discloses a method for recognizing ATM terminal tampering patterns, comprising the following steps: Data Input that receives and processes data from sensors (audio, accelerometer, infrared); Pre-processing / Segmentation that performs pre-processing and segmentation of the raw data to make it readable and compatible with the intelligent detection model; Classification Model Using Deep Learning, which applies a deep learning model to identify complex patterns in the segmented data; Classification that classifies the signal segments as attacks or normal situations, based on the patterns learned by the deep learning model representing the categories that are identified by the intelligent model, which may be: a) vibration attack, b) thermal attack and; c) normality situation, as described below; Policies that include guiding policies and rules to ensure decisions aligned with security objectives;and Relay Activation which activates corresponding relays or mechanisms in response to the classification, implementing additional security measures or triggering alerts.;

[0034] Furthermore, the present invention provides a monolithic sensor device used in a system for detecting tampering in ATM terminals, comprising a printed circuit board equipped with audio, vibration and infrared sensors; signal processing circuit and microcontroller, in communication with embedded software and artificial intelligence model. BRIEF DESCRIPTION OF THE FIGURES

[0035] The subject matter of the present invention will become completely clear in its technical aspects from the detailed description that will be made based on the figures listed below, in which: Figure 1 presents a block diagram of the system architecture, in which its main modules are defined.; Figure 2 shows an example of data collection for each type of sensor, namely audio, vibration and light sensors; Figure 3 shows an example of the intelligent model's predictions; Figure 4 shows the relay activations based on the policy algorithm; Figure 5 shows the confidence value over time; and Figure 6 shows a breakdown of the Intelligent Agent module, responsible for the artificial intelligence algorithm. DETAILED DESCRIPTION

[0036] In order to solve the technical problems previously mentioned, the present invention discloses a system, method and device for monitoring ATM terminals with the aim of detecting and differentiating tampering attempts from normal environmental disturbances.

[0037] According to the representation of the system architecture available in Fig. 1, the referred system, named protection system (001), is formed by a processing unit (002), a data acquisition subsystem (003), a self-test subsystem (004), an energy monitoring system (005), a fraud detection system (006) and an intelligent agent system (007).

[0038] The processing unit (002) is in communication with a sensor system formed by a plurality of sensors, which provide monitoring information of the ATM terminal. These sensors monitor aspects such as vibration, brightness and audio, as defined below: - Audio Sensor (Microphone): This device, a microphone, captures sounds from the environment and can detect patterns or noises that may suggest suspicious or unusual activity, such as break-ins with sounds of breaking, cutting or drilling; - Vibration Sensor (Accelerometer): The accelerometer, by detecting vibrations, identifies unusual movements or vibrations that deviate from the ATM's normal operating pattern. Examples include detecting break-in attempts, physical manipulation, or abnormal vibrations from tools. - Light Sensor (Infrared): This sensor measures the intensity of infrared light, useful for detecting changes in ambient brightness and identifying suspicious activity. Practical examples include identifying rapid temperature increases associated with thermal attacks during break-in attempts.

[0039] Fig. 2 presents the data collected by each type of sensor. The submodule presented in Figure 2 of the classification model using deep neural networks (015) is responsible for developing the system's intelligence. Data acquisition subsystem

[0040] The data acquisition subsystem (003) sequentially captures sensor data over a predefined time interval. After defining the sensors and selecting the sampling rates, the acquired data is in raw, unprocessed format and may contain noise. This data undergoes a preprocessing step, as shown in Figure 6, which converts it to a readable and compatible format. with the intelligent attack detection and classification model. Subsequently, the data is organized, validated, and sent to the intelligent agent submodule (007). This approach aims to effectively prepare the data for analysis and detection of potential attacks on the ATM system.

[0041] In a preferred implementation example, 1-second time intervals are used at a sampling rate of 16 kHz for audio and 50 Hz for the accelerometer and infrared, which is sufficient to capture the characteristics of the environment and attack tools. Due to the limited memory available for the intelligent model, the volume of data that can be stored and processed is quite limited. Larger time intervals may generate a data volume that exceeds this capacity. Self-test subsystem

[0042] The self-test system (004) is responsible for ensuring that the sensors are operating correctly. It performs this verification in two distinct ways. The first approach involves sensors that do not require activation for validation. In other words, the self-test system (004) verifies the operation of these sensors without the need for external stimulation. The second approach encompasses sensors that require stimulation for validation. In this case, the self-test system automatically stimulates the sensors and then takes a reading to verify that the elements have been correctly sensitized. These two verification methods ensure the correct functioning of the sensors used in the system, thus ensuring the effectiveness of ATM terminal monitoring. Energy monitoring system

[0043] The main objective of the energy monitoring system (005) is to maintain low system power consumption without compromising the efficiency of high-processing resources. To achieve this goal, the system monitors two consumption blocks: the Standard Power System (SCP) and the Low Power System (SBC).

[0044] The SCP covers components and circuits with higher power consumption, being disabled in the event of a power outage to minimize consumption. The SBC includes components with lower power consumption, remaining active even without the main power supply, resulting in reduced energy consumption.

[0045] The system's input conditions are determined by the presence or absence of main power, and the output consists of power control in the SCP and SBC blocks. Thus, the management system seeks to optimize operational efficiency by adapting to power conditions to ensure efficient energy consumption.

[0046] Fraud detection system

[0047] The Fraud Detection System (006) is designed to mitigate the risks of fraud or illegitimate tampering involving the manufacturing, installation, or unauthorized access of the proposed solution in ATM terminals. This system incorporates specific mechanisms for the solution's comprehensive security, including devices dedicated to verifying the correct closure of the cabinet. This measure ensures that the terminal's integrity is preserved after installation, preventing unwanted exposure. This system also integrates ultrasonic sensors capable of detecting changes in the relative proximity or movement of the solution within the ATM terminal, reinforcing security against external interference. Furthermore, these sensors are essential for protecting self-test systems, safeguarding them against manipulation by field operators or during the production and installation stages.By identifying distinctions between legitimate and suspicious activity, the fraud detection system establishes direct communication with the ATM terminal processing units, promptly flagging any attempted violations so that appropriate corrective measures can be taken.

[0048] Intelligent Agent Module

[0049] As seen in Fig. 1, this module consists of the following blocks: classification model (008), which refers to the system's tool classification and normality model; activation policies (009); and event recording processing (010), which is responsible for persisting data captured by the sensors for a short period. The event recording submodule (010) is responsible for persisting the captured data. This persistence process is triggered by an anomaly inference made by the artificial intelligence model. After this trigger, a set of eleven inferences and the data collection that generated these inferences are persisted.In detail, of this persisted set, there are five inferences before the anomaly inference that triggered the entire persistence process, the anomaly inference itself, and the five subsequent ones, totaling the eleven inferences mentioned, in addition to the entire data set that generated these inferences. Since each inference is performed on samples equivalent to one second, the number of saved samples is equivalent to eleven seconds at the time an anomaly occurs. These samples saved when an anomaly occurs serve to support understanding during system audits.

[0050] Furthermore, the intelligent agent module (007), as seen in Fig. 6, is responsible for the artificial intelligence algorithm that detects attack patterns on the ATM terminal. It is composed of the following submodules: - Sensors Data Input (013): Receives and processes data from the sensors (audio, accelerometer, infrared) used in the system. In this way, this submodule adapts the data to the expected input of the intelligent model. The System has three main sensors: audio, to capture sound characteristics of the environment; the accelerometer, which captures vibration characteristics and monitors the movement of the ATM terminal, such as tilt, vibration, rotation, and oscillation, which are usually a direct reflection of a person's action or the physical environment in which the terminal is located; and infrared, which detects infrared light intensity, as seen in Fig.2. - Pre-processing / Segmentation (014): Performs pre-processing and segmentation of raw data to make it readable and compatible with the intelligent detection model. This employs techniques used in problems involving sensor signal processing, such as fixed-window segmentation and the sliding window technique. The default time window is 1 second, with 16,000 samples for the audio sensor, 50 samples for the acceleration sensor, and 50 samples for the infrared sensor (50 Hz). Different sensor types (audio, acceleration, infrared) have distinct data characteristics, and segmentation allows the analysis to be adapted to each sensor type. For example, 16,000 samples for audio and 50 samples for acceleration and infrared indicate an adaptation to the nature of each data type (high frequency for audio, lower for others).Segmentation into fixed time windows allows for real-time analysis, essential for applications that require rapid responses, such as security systems. - Classification Model Using Deep Learning (015): Applies a deep learning model to identify complex patterns in segmented data. The classification model using deep neural networks (015) is responsible for developing the system's intelligence. Sensor data is fed into a convolutional neural network that abstracts the most relevant features of each sensor, generating a fixed-size vector that represents compact information from the audio, accelerometer, and infrared sensors. This intermediate, compact vector represents a more abstract level of the raw data, more accurate and noise-free, with more relevant information compared to the original data taken individually. A dense neural network is used to learn patterns from this intermediate, compact vector and then decide whether a signal segment is a terminal attack or a normal situation. This process requires low-computational-cost algorithms because. The device used in the system has limited computing resources, such as power, processing, and storage capacity. Therefore, the following steps occur: • Sensor data passes through 1D convolutional layers. These layers are responsible for applying convolution operations to the input data. Convolution allows the network to learn important patterns and features in the sensory data. The use of 1D convolutional layers suggests that convolution occurs along one dimension, maintaining the sequential or temporal nature of the data. • After convolution, ReLU activation is applied. The ReLU function is an activation function that introduces nonlinearities by discarding negative values ​​and replacing them with zero. This helps to introduce nonlinearities and the network's ability to learn more complex patterns in the data. • L2 regularization is then applied to prevent overfitting. Overfitting occurs when the model fits the training data very well but does not generalize well to new data. L2 regularization penalizes large weight coefficients, encouraging the network to maintain smaller weights and thus reduce the risk of overfitting. • Between some of these convolutional layers, dimensionality reduction techniques are applied, reducing the spatial size of the data while maintaining the most important features. • The output of these steps, which now contains more abstract and relevant features, is processed by dense layers. • Dense layers, also known as fully connected layers, learn complex patterns and relationships between the extracted features. These layers are responsible for performing the final classification based on the information learned during neural network training. - Classification (016): Classifies signal segments as attacks or normal situations, based on the patterns learned by the model. Deep learning. Represents the categories identified by the intelligent model, which can be: a) vibration attack, b) thermal attack, and c) normal situation, as described below: • Vibration attacks, such as attempted break-ins or physical tampering with the ATM, generate distinct and irregular vibration patterns. High vibration intensities and sudden changes in frequency may indicate an attack. Vibration attacks tend to last longer than normal vibrations caused by normal interactions with the ATM. • A thermal attack, such as the use of a blowtorch to access the terminal, is characterized by a rapid and abnormal increase in temperature. Consistently high temperature readings, above normal standards, are a strong indicator of a thermal attack. In an environment with stable temperatures, sudden and significant variations detected by the infrared sensor can signal an attack. • Slight, regular movements and vibrations, such as those caused by normal terminal operation or common user interactions. Temperature readings that remain within expected limits for the terminal's operating environment. There are no abrupt changes or abnormal patterns in the data from either sensor. - Policies (017): May include policies and guiding rules to ensure decisions are aligned with security objectives. Thus, this module is equipped with a trust algorithm that implements punishment and reward situations based on the predictions of the intelligent model. The "Trust Algorithm (017)" was developed to manage the system's response based on the predictions of the intelligent model, dynamically adjusting a trust score. The algorithm makes decisions about activating a 'relay' (possibly a control device, such as a relay or similar switch). Decisions to activate or deactivate the 'relay' are based on whether the trust score exceeds certain thresholds, previously configured as part of the policy. security. In other words, the trust algorithm assigns rewards to a variable (trust value) when normal situations are detected (up to a maximum value). However, a penalty is assigned to the trust value when attack situations are detected, and its trust value is decreased (down to a minimum value). Depending on the trust value calculated by the trust algorithm, a relay activation signal is triggered by the relay activation submodule (018), so that appropriate measures can be taken, such as inking banknotes, activating a bank branch alarm, among others. Furthermore, these thresholds determine how quickly the trust score can vary in response to prediction patterns, providing flexible response dynamics. Figures 3, 4, and 5 represent a specific event in which some type of attack occurs on an ATM terminal.Figure 3 shows examples of the intelligent model's predictions, Figure 4 highlights relay activations based on the policy algorithm, and Figure 5 displays the evolution of the trust value over time. These visual representations help understand how the system responds to security events. - Relay Activation (018): Activates corresponding relays or mechanisms in response to the classification, implementing additional security measures or triggering alerts. Method for recognizing violation patterns in bank terminals To recognize bank terminal violation patterns and differentiate them from normal environmental disturbances, the aforementioned protection system (001) follows the steps described below: - Receiving data collected from measurements made by a plurality of sensors from different domains; - Pre-processing and segmentation of raw data to make it readable and compatible with the intelligent model; - Mapping attack patterns on ATM terminals using a machine learning algorithm with data classification in the categories: vibration attack; thermal attack; normality situation; in which the vibration attack is the detection of an abnormal vibration pattern, which may indicate a break-in attempt; in which the thermal attack is the detection of a rapid and abnormal increase in temperature; and in which the normality situation is the detection of regular movements and vibrations, compatible with the normal operation of the ATM; - Construction of a confidence algorithm to minimize the occurrence of false positives; - Decision making on whether or not to activate the alarm based on policy and rules systems; - Activation of the attack signaling relay.

[0051] Monolithic sensor device

[0052] The system utilizes a monolithic array of sensors arranged in a concentrated manner in a single area of ​​the ATM vault, capable of detecting infrared radiation emitted by flames or sparks generated by tools used to attack ATMs. The device is equipped with audio, vibration, and infrared sensors; a signal processing circuit; a microcontroller; embedded software; and an artificial intelligence model.

[0053] The present invention, in addition to presenting a device that concentrates the sensors, is capable of processing the captured information to determine whether an attack is being initiated on the ATM, thus enabling action to be taken before the ATM is breached. Additionally, with active monitoring of the sensors, it is possible to adapt the data collected to each specific ATM. In other words, an ATM located near a highway with heavy vehicle traffic is expected to capture greater noise and vibrations, so the system adapts to this situation.

[0054] It should be understood that the present description does not limit the application to the details described herein and that the invention is capable of other modalities and to be practiced or performed in a variety of ways, within the scope of the claims. Although specific terms have been used, such terms should be construed in a generic and descriptive sense and not for the purpose of limitation.

Claims

CLAIMS 1. “PROTECTION SYSTEM (001) FOR DETECTING TAMPERING IN ATM TERMINALS”, characterized by the fact that it comprises the following modules: - a processing unit (002) coupled to a sensor unit, wherein the sensor unit comprises a plurality of sensors that monitor at least vibration, luminosity and audio; - a data acquisition subsystem (003) that performs sequential capture of the sensors during a predefined time interval; - an intelligent agent module for detecting violations of the bank terminal (007), which detects attack patterns on the ATM; - a self-test subsystem (004), which checks the functioning of the sensors; - an energy monitoring system (005) that maintains low energy consumption; and - a system for detecting fraud (006).

2. “SYSTEM”, according to claim 1, characterized by the fact that it identifies: a) vibration attack; b) thermal attack; and c) normality situation.

3. “SYSTEM”, according to claim 1, characterized by the fact that it recognizes patterns and identifies attempts to violate ATM terminals through an artificial intelligence model using a convolutional neural network (CNN).

4. “SYSTEM”, according to claim 1, characterized by the fact that the intelligent agent (007) comprises the following submodules: classification model (008), which refers to the tool classification model and system normality; activation policies (009) equipped with a trust algorithm that implements punishment and reward situations based on the predictions of the intelligent model; and processing event recording (010) responsible for performing a persistence operation on the captured data.

5. “SYSTEM” according to any one of claims 1 to 4, characterized in that the artificial intelligence algorithm comprises the following submodules: - Sensors Data Input (013) that receives and processes data from sensors (audio, accelerometer, infrared); - Pre-processing / Segmentation (014) which performs pre-processing and segmentation of raw data to make it readable and compatible with the intelligent detection model; - Classification Model Using Deep Learning (015), which applies a deep learning model to identify complex patterns in segmented data; - Classification (016) that classifies the signal segments as attacks or normal situations, based on the patterns learned by the deep learning model, represents the categories that are identified by the intelligent model, which can be: a) vibration attack, b) thermal attack and; c) normal situation, as described below; - Policies (017) that include guiding policies and rules to ensure decisions are aligned with security objectives; and - Relay Activation (018) that activates corresponding relays or mechanisms in response to the classification, implementing additional security measures or triggering alerts.

6. “METHOD FOR RECOGNIZING ATM TERMINAL VIOLATION PATTERNS”, applied in the security system as defined in claim 1, characterized by the fact that it comprises the following steps: - Receiving data collected from measurements made by a plurality of sensors from different domains; - Pre-processing and segmentation of raw data to make it readable and compatible with the intelligent detection model; - Mapping attack patterns on ATM terminals using machine learning algorithm; - Classification of data into the following categories: vibration attack; thermal attack; normal situation; where vibration attack is the detection of an abnormal vibration pattern, which may indicate a break-in attempt; where thermal attack is the detection of a rapid and abnormal increase in temperature; and where the normal situation is the detection of regular movements and vibrations, compatible with normal ATM operation; - Construction of a confidence algorithm (017) to minimize the occurrence of false positives; - Decision-making on whether or not to activate the alarm based on the policy and rules systems, where the decision is made by the guiding policies and rules that determine whether there is an attack in progress; and - Activation of the attack signaling relay, which triggers measures such as alarm activation and inking of banknotes.

7. “MONOLITHIC SENSOR DEVICE” used in a system for detecting tampering in ATM terminals, as defined in claim 1, characterized by the fact that it comprises a printed circuit board equipped with audio, vibration and infrared sensors; signal processing circuit and microcontroller, in communication with embedded software and an artificial intelligence model.

8. “DEVICE” according to claim 7, characterized in that the audio sensors are preferably microphone devices, the vibration sensors are preferably accelerometer devices, and the light sensors are preferably infrared devices.

Citation Information

Patent Citations

  • Improved safe

    EP0848130A2

  • Cash spoiling system

    EP3117408A1

  • Counter-fraud measures for an ATM device

    US10769896B1

  • Automated banking machine system and monitoring

    US9070233B2

Cited By

  • CONTROL UNIT FOR OPERATING MODES OF AUTOMATED DEPOSIT MACHINE

    RU244917U1