Valuables dispensing device and method for operating a valuables dispensing device

By integrating an identification feature in the control device and a verification device within the safe to monitor verification information, the valuable article output device is protected from unauthorized access, ensuring secure operation.

DE102017200722B4Active Publication Date: 2025-05-08NG BRANCH TECH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102017200722
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2017-01-18
Publication Date
2025-05-08
Estimated Expiration
2037-01-18

AI Technical Summary

Technical Problem

Automated teller machines and similar valuable article output devices are vulnerable to unauthorized access and tampering, particularly through manipulated control devices that bypass authorization checks.

Method used

Incorporating an identification feature in the control device and a verification device within the safe, which monitors verification information generated using the identification feature to prevent unauthorized access by putting the output device into a blocking state.

Benefits of technology

Effectively prevents unauthorized output of valuable articles by ensuring that only authorized control devices can operate the output device, thereby enhancing the security of the valuable article output device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A valuables dispensing device (1), in particular an ATM, comprising: a safe (2) for storing valuables (3), a control unit (4) located outside the safe (2) configured to provide a dispensing command, and a dispensing device (5) located inside the safe configured to dispense a valuable (3) stored in the safe (2) in response to the dispensing command, wherein the control unit (4) has an identification feature (6), and the valuables dispensing device (1) comprises a verification device (7) located inside the safe (2) configured to monitor verification information generated using the identification feature (6) and, depending on the monitoring, to put the valuables dispensing device (1) into a locked state in which the dispensing of valuables (3) is blocked.wherein the valuable item dispensing device (1) comprises a first communication channel (8) between the control unit (4) and the dispensing device (5) for transmitting the dispensing command, and a second communication channel (9) between the control unit (4) and the verification device (7) for transmitting the verification information, characterized in that the control unit (4) is configured to check whether it is connected to the first communication channel (8) and / or whether communication with the dispensing device (5) is possible, and to provide the verification device (7) with the verification information only if one or both of these checks are successful.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a valuables dispensing device, in particular an ATM, comprising: a safe for storing valuables, a control device located outside the safe, which is designed to provide a dispensing command, and a dispensing device located inside the safe, which is designed to dispense a valuables stored in the safe in response to the dispensing command.

[0002] Such a valuables dispensing device serves to protect valuables from unauthorized access. Typically, the control device is configured to receive requests to dispense valuables and check whether the requests are legitimate or originate from an authorized person. If so, the control device provides the dispensing command, which in turn causes the dispensing device to dispense a valuable item from the safe.

[0003] Valuables dispensing devices are often the target of criminal attacks. Unauthorized individuals regularly attempt to gain access to the valuables stored in the safe. This is typically done by forcibly opening the safe, for example, by blasting it.

[0004] In recent years, there have also been attempts to gain unauthorized access to valuables by issuing the dispensing command via a manipulated control device. In particular, attempts have been made to replace the control device located outside the safe with a manipulated control device that allows the dispensing command to be issued without authorization verification, so that the dispensing command provided by the manipulated control device can trigger the dispensing of valuables to an unauthorized person.

[0005] WO 2016 / 134421 A1 describes a security system designed to prevent unauthorized cash dispensing from a cash dispenser. The cash dispenser is located in a physically protected area. A host controller is provided outside the physically protected area and is configured to issue dispensing instructions to the cash dispenser via a dispensing instruction data connection. An access authorization device located within the physically protected area is configured to receive verification signals via a verification data connection and to block transmission of dispensing instructions via the dispensing instruction data connection if the verification signals are not received or are incorrect.Access authorization software operatively associated with the host controller is configured to send the verification signals to the access authorization device.

[0006] WO 2005 / 111956 A1 describes an ATM in which an anti-surveillance device is arranged. The anti-surveillance device is configured to detect radio signals and determine whether the radio signals are likely to represent video data being transmitted in the vicinity of the ATM. The ATM has an output unit capable of outputting a signal representing a command to shut down a power supply to the ATM.

[0007] One object of the invention is to modify the valuables dispensing device mentioned above so that it is better protected against unauthorized access to the stored valuables.

[0008] The object is achieved for the valuables dispensing device mentioned at the outset by the features specified in the characterising part of claim 1.

[0009] The control device has an identification feature. Furthermore, the valuables dispensing device has a verification device located within the safe. The verification device is designed to monitor verification information generated using the identification feature and, depending on the monitoring, to place the valuables dispensing device into a locked state in which the dispensing of valuables is blocked.

[0010] By providing the identification feature, the control device is made identifiable, preferably uniquely identifiable, so that the control device can be distinguished from a tampered control device using the identification feature. If the control device is then replaced with a tampered control device, this can be detected by the verification device, which then sets the valuables dispensing device to the locked state, in which no more valuables are dispensed. Because this verification device is located in the safe, it is protected against tampering.

[0011] The valuables monitoring device is thus effectively protected against unauthorized expenditure of valuables by replacing the control device.

[0012] A particularly advantageous feature is that the valuables dispensing device described above requires only very minor modifications for this purpose. Thus, it is only necessary to equip the control device with the identification feature and / or a function for generating the verification information and to provide the verification device in the safe. The other components can remain unchanged. In particular, the dispensing device or the dispensing device's software does not need to be modified. This makes the inventive approach particularly well-suited for retrofitting.

[0013] The identification feature is monitored, in particular, by transmitting the verification information from the control device to the verification device, and by the verification device checking whether the transmitted verification information corresponds to the expected verification information. If the transmitted verification information corresponds to the expected verification information, the verification device does not set the valuables dispensing device to the locked state. If the transmitted verification information does not correspond to the expected verification information, or if no verification information is received, the verification device sets the valuables dispensing device to the locked state.

[0014] The valuable item dispensing device comprises a first communication channel between the control device and the dispensing device for transmitting the dispensing command, as well as a second communication channel between the control device and the verification device for transmitting the verification information. The control device is configured to check whether it is connected to the first communication channel and / or whether communication with the dispensing device is possible, and to provide the verification information to the verification device only if one or both of these checks are successful.

[0015] Advantageous embodiments are the subject of the subclaims.

[0016] According to one embodiment, the identification feature comprises a key, preferably a public key of an asymmetric cryptosystem. The control device is expediently designed to generate the verification information using the key. The use of a key can be advantageous for two reasons in particular. Firstly, the control device is already made identifiable by the key itself. Preferably, the verification device knows the key or has the associated private key, so that the verification device can already identify the control device based on the key underlying the verification information. Furthermore, the encryption prevents the content of the verification information from being intercepted and read by an unauthorized person during transmission.

[0017] The valuables dispensing device has a first communication channel between the control device and the dispensing device for transmitting the dispensing command. The valuables dispensing device has a second communication channel between the control device and the verification device for transmitting the verification information. Consequently, a separate communication channel is provided for the transmission between the control device and the verification device. The first communication channel previously used for communication between the control device and the dispensing device can thus be retained unchanged.

[0018] According to a further embodiment, the second communication channel is an encrypted communication channel. This ensures that the information transmitted between the control device and the verification device cannot be intercepted or read.

[0019] Preferably, the second communication channel is encrypted using the above-mentioned key.

[0020] According to a further embodiment, the verification device is designed to provide the control device with test information, preferably within the scope of a repeated, in particular periodic, transmission. The control device is expediently designed to generate the verification information based on the test information and the identification feature. Because the test information underlying the verification information originates from the verification device, the verification device can monitor the verification information with respect to the originally provided test information.

[0021] According to a further embodiment, the verification device is designed to provide the identification feature to the control device, preferably as part of an initialization procedure. In this way, the control device and the verification device can be coordinated with each other in a simple and practical manner.

[0022] According to a further embodiment, the verification device is designed to place the valuables dispensing device into the locked state by de-energizing the dispensing device. Consequently, the dispensing device can be effectively prevented from dispensing valuables.

[0023] According to a further embodiment, the verification device is designed as an additional component, in particular as an additional circuit board. A verification device designed in this way can be retrofitted particularly easily.

[0024] According to a further embodiment, the control device is configured to monitor its own state and generate the verification information depending on the monitoring of the state. This prevents the control device from continuing to send the verification information to the verification device even though the control device is no longer connected to the output device.

[0025] The invention further relates to a method for operating a valuables dispensing device having a safe for storing valuables and a dispensing device located in the safe for dispensing a valuable item in response to a dispensing command, comprising the steps of: providing the dispensing command on a first communication channel (8) by a control device located outside a safe, checking by the control device (4) whether it is connected to the first communication channel (8) and / or whether communication with the dispensing device (5) is possible, providing verification information generated using the identification feature (6) to a verification device (7) located inside the safe via a second communication channel (9) if one or both of these checks are successful, monitoring the verification information by the verification device, and,Depending on the monitoring, placing the valuables dispensing device in a locked state in which the dispensing of valuables is blocked.

[0026] The method can expediently be carried out by means of one of the above-described embodiments of the valuables dispensing device or can be designed accordingly.

[0027] Exemplary embodiments are explained below with reference to the drawing. Fig. 1 a schematic representation of a valuables dispensing device and Fig. 2 a flowchart of a method for operating a valuables dispensing device.

[0028] The Fig. 1 shows a schematic representation of a valuables dispensing device 1. The valuables dispensing device 1 is, for example, an ATM.

[0029] The valuables dispensing device 1 comprises a safe 2. The safe 2 serves to store valuables 3. The valuables 3 are, for example, cash, in particular banknotes.

[0030] The valuables dispensing device 1 further comprises a control device 4 located outside the safe 2, which is configured to provide a dispensing command. The control device 4 has an identification feature 6.

[0031] Furthermore, the valuables dispensing device 1 comprises a dispensing device 5 located within the safe, which is designed to dispense a valuables 3 stored in the safe 2 in response to the dispensing command.

[0032] Finally, the valuables dispensing device 1 also includes a verification device 7 located within the safe 2. The verification device 7 is designed to monitor verification information generated using the identification feature 6. The verification device 7 is further designed to place the valuables dispensing device 1 into a locked state depending on the monitoring. In the locked state, the dispensing of valuables 3 is blocked.

[0033] This design of the valuables dispensing device 1 prevents the unauthorized provision of the dispensing command and the resulting unauthorized dispensing of a valuable 3 by replacing the control device 4 with a manipulated control device. Thus, the security of the valuables dispensing device 1 is increased.

[0034] Exemplary designs of the individual components of the valuables dispensing device 1 are explained below.

[0035] As already mentioned above, the valuables dispensing device 1 is, by way of example, an ATM. Alternatively, the valuables dispensing device 1 can also be any other device in which valuables are stored in a safe and can be dispensed. For example, it can also be a token dispensing machine, in particular a ticket machine, or a parcel dispensing machine.

[0036] If the valuables dispensing device 1 is designed as an ATM, it can in particular be a pure dispensing machine or a combination device in which both the dispensing and the deposit of money is possible.

[0037] The valuables dispensing device 1 has, for example, a housing 11 in which the safe 2 and the control device 4 are housed. The housing 11 is, for example, essentially box-shaped.

[0038] The safe 2 is exemplified as a lockable, box-shaped container. The safe 2 is preferably armored. For example, the safe 2 is made of steel. According to an embodiment not shown, the safe 2 is permanently embedded in a wall at the installation location of the valuables dispensing device or is otherwise reinforced with a floor or wall at the installation location.

[0039] The safe 2 has a dispensing opening not shown in the figure, for example a dispensing slot, from which a valuable item 3 located in the safe 2 can be dispensed from the safe 2.

[0040] One or more valuables 3 can be stored in the safe 2. The valuables 3 can be, for example, money, in particular banknotes, tokens, tickets, packages, and / or other items.

[0041] The dispensing device 5 is housed in the safe 2. The dispensing device 5 has, for example, an dispensing control device 16, expediently a microcontroller, and a conveying device 17, expediently an electrically driven conveyor belt.

[0042] By way of example, the dispensing device 5 comprises a dispensing module (not shown) in which one or more cash cassettes are arranged. The dispensing device 5 is expediently supplied with power via an electrical line 12.

[0043] The dispensing device 5 is configured to receive a dispensing command from the control device 4 and, in response to the dispensing command, to dispense a valuable object 3. For example, the dispensing command is received by the aforementioned dispensing control device 16, which then instructs the conveying device 17 to dispense a specific valuable object 3. The valuable object 3 is then dispensed, for example, through the aforementioned dispensing opening from the safe 2 and, in particular, also from the valuable object dispensing device 1.

[0044] The valuables dispensing device 1 has, for example, a user interface 10. The user interface 10 refers to the group of peripheral devices with which a user of the valuables dispensing device 1 directly interacts. For example, the user interface 10 can include a monitor, a card reader (not shown), and / or a keypad.

[0045] Using the user interface 10, the user can select the valuable item 3 to be dispensed. For example, the user can select the amount of money to be dispensed. Furthermore, the user interface 10 is used to verify the user's authorization. This is done in a known manner, for example, by scanning a card and verifying a PIN entered by the user.

[0046] The user interface 10 is connected to the control device 4. The control device 4 is expediently designed to control and / or coordinate the operations performed by the user interface 10. In particular, the control device is designed to process the data entered via the user interface 10. Typically, the control device 4 is designed to check, based on the data entered via the user interface 10, whether the user has the authorization required for the requested valuable object 3. This is done, for example, by comparing data with an external server via a communication connection (not shown). If the control device 4 determines that the required authorization exists, the control device 4 issues the output command to the output device 5.

[0047] The control device 4 can be, for example, a PC. For example, a standard operating system runs on the control device 4. Preferably, the functions for providing the identification feature 6 in the control device 4 and for generating and transmitting the verification information are provided by an additional software component installed on the control device 4.

[0048] The control device 4 is communicatively connected to the output device 5 via a first communication channel 8. The communication channel 8 is provided, for example, via a cable. For example, the connection is provided via a USB interface.

[0049] The communication channel 8 has a connection, for example a connector, in particular a USB port, which is located outside the safe 2. It is therefore in principle possible to connect a manipulated control device to the communication channel 8 without having to open the safe 2. In order to connect a manipulated control device to the communication channel 8, it is only necessary to disconnect the connection of the communication channel 8 from the control device 4 and connect it to the manipulated control device. The manipulated control device is, for example, a control device that does not perform an authorization check of a user or an output request, but instead directly issues the output command, so that the output command is also issued in the event of unauthorized requests or for unauthorized users.

[0050] The measure according to the invention already explained above of equipping the valuables dispensing device 1 with the identification feature 6 and the verification device 7 ensures that when the control device 4 is separated from the valuables dispensing device 1, at least no more valuables 3 can be dispensed, even if an dispensing command is transmitted to the dispensing device 5.

[0051] By way of example, the identification feature 6 is information stored in the control device 4, using which the control device 4 generates the verification information, which is then transmitted to the verification device 7.

[0052] For example, the identification feature 6 comprises a cryptographic key, and the control device 4 is configured to generate the verification information using the cryptographic key. In particular, the control device 4 is configured to encrypt test information with the key and thus generate the verification information. The key is expediently the public key of an asymmetric cryptosystem.

[0053] Preferably, the test information is varied so that the verification information transmitted from the control device 4 to the verification device 7 also varies. In particular, a different piece of verification information can be transmitted with each transmission from the control device 4 to the verification device 7.

[0054] Conveniently, the control device 4 is configured to monitor its own state and generate the verification information depending on the monitored state. In particular, the control device 4 is configured not to generate the verification information if a specific state exists, for example, if it is determined that the control device 4 is not connected to a specific component, in particular the communication channel 8, of the valuable item dispensing device 1. If the specific state does not exist, the control device 4 generates the verification information.

[0055] The control device 4 checks whether it is still connected to the communication channel 8 and / or whether communication with the output device 5 is possible. Only if one or both of these checks are successful does the control device 4 provide the verification information to the verification device 7.

[0056] The check as to whether the control device 4 is connected to the communication channel 8 can be carried out on a physical and / or logical level. For example, the control device 4 can check, by detecting one or more electrical properties, whether the communication channel 8 or the line of the communication channel 8 is physically connected to a connection of the control device 4 provided for connection to the communication channel 8. The electrical properties are, in particular, electrical properties of the line of the communication channel 8. Alternatively or additionally, the control device 4 can check, on a logical level, whether the control device is connected to the communication channel 8 by communicating with the output device 5, preferably bidirectional communication.For example, the control device 4 can send a test signal to the output device 5 for this purpose and check whether the output device 5 responds to the test signal.

[0057] The control device 4 is expediently designed such that the test criteria for determining whether the control device 4 is connected to the communication channel 8 can be selected and / or adapted.

[0058] As already explained above, the control device 4 communicates with the output device 5 via the communication channel 8, which is also referred to as the first communication channel 8. The first communication channel 8 is, for example, an unencrypted communication channel; that is, the communication between the control device 4 and the output device 5 takes place unencrypted. In particular, the output command is transmitted unencrypted.

[0059] For communication between the control device 4 and the verification device 7, a further communication channel—the second communication channel 9—is provided. The verification information is transmitted from the control device 4 to the verification device 7 via the second communication channel 9. Preferably, the second communication channel 9 is encrypted; that is, the information transmitted via the second communication channel 9 is encrypted. Encryption is expediently performed using the aforementioned key. The second communication channel 9 can be provided via a wired or wireless communication link.

[0060] The communication channels 8 and 9 can be provided via separate physical lines; that is, the first communication channel 8 is provided via a first line and the second communication channel 9 is provided via a second line different from the first line. The communication channels 8 and / or 9 can be provided, for example, as serial connections, in particular as USB connections.

[0061] Communication channels 8 and 9 can also be provided over the same physical line. In this case, communication channels 8 and 9 can be logical and virtual communication channels, respectively.

[0062] Based on the verification information transmitted via the second communication channel 9, the verification device 7 performs a monitoring process. For example, the verification device 7 checks whether verification information is being transmitted and whether the transmitted verification information corresponds to the expected verification information. If this is not the case, the verification device 7 sets the valuables dispensing device 1 to the locked state.

[0063] The verification device 7 comprises, for example, a control unit 14 and a switching unit 15. The control unit 14 is configured, for example, to communicate with the control device 4 via the second communication channel 9 and to monitor the verification information. Furthermore, the control device 14 can be configured to control the switching unit 15.

[0064] The verification device 7 is preferably designed as an additional component, in particular as an additional circuit board. In particular, the control unit 14 and the switching unit 15 are arranged together on the additional circuit board. The additional circuit board is preferably provided in addition to a circuit board already present in the safe 2, for example, in addition to a circuit board on which components of the dispensing device 5 are arranged. For example, the verification device 7 is designed to be pluggable and is mounted in the safe 2 by means of a plug-in connection.

[0065] As already mentioned above, the verification device 7 is designed to place the valuables dispensing device 1 into the locked state. In particular, the verification device 7 is designed to place the valuables dispensing device 1 into the locked state by de-energizing the dispensing device 5. This is expediently done with the aid of the switching unit 15, which is connected between the electrical line 12 and the dispensing device 5 and can thus interrupt the power supply to the dispensing device 5.

[0066] The switching unit 15 is expediently designed as a self-closing relay, so that in the event that the switching unit 15 itself is no longer controlled, the power supply of the output device 15 is also interrupted.

[0067] Alternatively or in addition to the interruption of the power supply described above, the blocking state can also be established by the verification device 7 issuing a blocking command to the dispensing device 5, which causes the dispensing device 5 to not dispense any valuables, even if the dispensing device 5 receives an dispensing command. Furthermore, it is possible to establish the blocking state by interrupting the first communication channel 8 from the verification device 7.

[0068] Preferably, the verification device 7 is configured to provide the identification feature 6 to the control device 4, preferably as part of an initialization procedure. If the identification feature 6 is a cryptographic key, the verification device 7 can be configured to generate this key and then transmit it to the control device 4 via the communication channel 9. The key can expediently be generated using a random number generator, for example, a pseudorandom number generator.

[0069] The verification device 7 expediently generates two keys, in particular a public and a private key of an asymmetric cryptosystem. The verification device 7 can then transmit the public key to the control device 4 so that it can generate the verification information.

[0070] Furthermore, it is also possible for the verification device 7 to generate two key pairs of an asymmetric cryptosystem - one key pair for communication from the verification device 7 to the control device 4 and one key pair for communication from the control device 4 to the verification device 7. Accordingly, the verification device 7 can send two keys to the control device 4 during initialization - a public key for encrypting the communication directed to the verification device 7 and a private key for decrypting the communication from the verification device 7.

[0071] By way of example, the verification device 7 is configured to provide test information. The test information is preferably provided as part of a repeated, in particular periodic, transmission to the control device 4.

[0072] The test information can be, for example, a pattern, in particular a randomly generated pattern. In particular, the test information is a bit sequence with a predetermined format. The test information is expediently generated using a random generator, for example, a pseudorandom generator. The verification device 7 is expediently designed to generate test information at regular intervals.

[0073] The test information is then transmitted to the control device 4 via the second communication channel 9. The test information is expediently transmitted in encrypted form.

[0074] By way of example, the control device 4 is designed to generate the verification device 7 based on the test information and the identification feature, in particular the key mentioned above.

[0075] The control device 4 is preferably designed to modify the received test information in a predetermined manner after any necessary decryption. For example, the control device 4 is designed to modify predetermined parts of the test information, for example, predetermined parts of the pattern or predetermined positions of the bit sequence, in a predetermined manner, for example, by setting them to 0 or 1.

[0076] Furthermore, the control device 4 is designed to encrypt the modified test information with the aid of the key, in particular the public key provided by the verification device 7, and to transmit it to the verification device 7 via the communication channel 9.

[0077] The aforementioned measures performed by the control device 4 can be performed, in particular, by the additional software component installed in the control device 4. In particular, the additional software component is configured to receive, decrypt, modify, encrypt, and transmit the test information to the control device 4. The additional software component can also be configured to perform the previously explained check of the state of the control device 4.

[0078] As already mentioned above, the verification device 7 is designed to monitor the verification information. This is achieved, in particular, by the verification device 7 being designed to check whether the verification information is received within a predetermined time period. This check can be performed, in particular, at regular intervals. The time period can preferably be started when the verification device 7 transmits the test information to the control device 4. If no verification information is received within the time period, the verification device 7 sets the valuables dispensing device 1 to the locked state.

[0079] If verification information is received within the time period, the verification device 7 checks whether the received verification information corresponds to the expected verification information. If this is not the case, the verification device 7 sets the valuables dispensing device 1 to the locked state.

[0080] To check whether the received verification information corresponds to expected verification information, the verification device 7 proceeds, for example, as follows: First, the verification device 7 decrypts the verification information using a key stored in the verification device 7, preferably the aforementioned private key. The verification device 7 then checks the modified test information against the originally provided test information. The verification device 7 expediently knows the modification made by the control device, so that the verification device 7 can check whether the received modified test information actually corresponds to the test information that the control device 4 was intended to generate based on the originally provided test information.This test information shall also be referred to as expected modified test information.

[0081] If the verification device 7 determines that the received modified test information does not correspond to the expected modified test information, the verification device 7 places the valuable item dispensing device 1 in the locked state. If the verification device 7 determines that the received modified test information corresponds to the expected test information, the verification device 7 does not place the valuable item dispensing device 1 in the locked state.

[0082] The Fig. 2 shows a flowchart of a method 20 for operating the valuables dispensing device 1.

[0083] The method 20 comprises steps 21, 22, and 23. In step 21, the dispensing command is provided by the control device 4. In step 22, the identification feature 6 and / or the verification information is monitored by the verification device 7. In step 23, depending on the monitoring, the valuables dispensing device 1 is placed in a blocking state in which the dispensing of valuables 3 is blocked. It should be noted that steps 22 and 23 can occur independently of step 21 and, in particular, can also occur before the execution of step 21.

Claims

[1] A valuables dispensing device (1), in particular an ATM, comprising: a safe (2) for storing valuables (3), a control device (4) located outside the safe (2) which is designed to provide a dispensing command, and a dispensing device (5) located inside the safe which is designed to dispense a valuables (3) stored in the safe (2) in response to the dispensing command, wherein the control device (4) has an identification feature (6), and the valuables dispensing device (1) comprises a verification device (7) located inside the safe (2) which is designed to monitor verification information generated using the identification feature (6) and, depending on the monitoring, to put the valuables dispensing device (1) into a blocking state in which the dispensing of valuables (3) is blocked,wherein the valuable object dispensing device (1) comprises a first communication channel (8) between the control device (4) and the dispensing device (5) for transmitting the dispensing command, and a second communication channel (9) between the control device (4) and the verification device (7) for transmitting the verification information, , characterized by that the control device (4) is designed to check whether it is connected to the first communication channel (8) and / or whether communication with the output device (5) is possible, and to provide the verification information to the verification device (7) only if one or both of these checks is successful. [2] Valuables dispensing device (1) according to claim 1, characterized bythat the identification feature (6) comprises a key, preferably a public key of an asymmetric cryptosystem, and the control device (4) is designed to generate the verification information using the key. [3] Valuables dispensing device (1) according to one of the preceding claims, characterized by that the second communication channel (9) is an encrypted communication channel. [4] Valuables dispensing device (1) according to one of the preceding claims, characterized by that the verification device (7) is designed to provide the control device (4) with test information, preferably within the framework of a repeated, in particular periodic, transmission, and the control device (4) is designed to generate the verification information based on the test information and the identification feature. [5] Valuables dispensing device (1) according to one of the preceding claims, characterized by that the verification device (7) is designed to provide the identification feature (6) to the control device (4), preferably as part of an initialization procedure. [6] Valuable item dispensing device (1) according to one of the preceding claims, characterized by that the verification device (7) is designed to put the valuable object dispensing device (1) into the blocking state by de-energizing the dispensing device (5). [7] Valuable item dispensing device (1) according to one of the preceding claims, characterized by that the verification device (7) is designed as an additional component, in particular as an additional circuit board. [8] Valuables dispensing device (1) according to one of the preceding claims, characterized bythat the control device (4) is designed to monitor its own state and to generate the verification information as a function of the monitoring of the state. [9] A method for operating a valuables dispensing device (1) with a safe (2) for storing valuables (3) and a dispensing device (5) located in the safe for dispensing a valuable item (3) in response to a dispensing command, comprising the steps of: providing (11) the dispensing command on a first communication channel (8) by a control device (4) located outside a safe, checking by the control device (4) whether it is connected to the first communication channel (8) and / or whether communication with the dispensing device (5) is possible, providing verification information generated using an identification feature (6) to a verification device (7) located inside the safe via a second communication channel (9) if one or both of these checks are successful, monitoring (12) the verification information by the verification device (7), and,depending on the monitoring, setting (13) the valuables dispensing device (1) into a blocking state in which the dispensing of valuables (3) is blocked.,

Citation Information

Patent Citations

  • Method and apparatus for protecting an input terminal from video surveillance

    WO2005111956A1

  • Security system for cash handling machine

    WO2016134421A1