Decentralized ATM Biometric Authentication via Local Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric identification systems increase cybersecurity risks due to the need for additional security measures and the vulnerability of centralized storage of biometric information, making it an attractive target for hackers.

Innovation Solution

A method where biometric readings are used to update local user records on network devices, allowing for decryption and authentication without accessing the Internet, reducing the risk of data breaches by storing encrypted information locally and retrieving it through a decentralized network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric information is stored in centralized storage, then authentication functionality is achieved, but security risk increases making centralized storage an attractive target for hackers

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the centralized authentication system into distributed kiosk clusters, where each kiosk maintains local user records independently. This segmentation eliminates the single point of failure (centralized storage) while preserving authentication functionality across multiple decentralized nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts biometric information from centralized storage and places it in encrypted form within local user records at individual kiosks. By taking out the sensitive data from the centralized repository and distributing it locally, the system reduces the security risk associated with centralized storage while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If additional security measures are implemented for biometric identification, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements security measures locally at each kiosk rather than centrally. Each kiosk independently encrypts and stores user records locally, generating decryption keys without requiring centralized key management. This local quality approach provides robust security while avoiding the complexity of centralized security infrastructure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system enables each kiosk to autonomously perform security functions including local encryption, key generation, and authentication verification. By making each node self-sufficient for security operations, the system achieves strong security protection without requiring complex centralized security management infrastructure.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If biometric information is stored locally at network devices, then security risk is reduced, but data accessibility may be limited

Engineering Contradiction:
Improvesecurity riskVSAvoiddata accessibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent creates user records that are universally accessible across all kiosk clusters through encrypted distribution. Each kiosk can store and access the same encrypted user record locally, enabling any kiosk in the network to authenticate users without requiring centralized access. This multi-functionality ensures both security through local storage and accessibility through network-wide availability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11502842B2Cluster-based security for network devices
Publication Date: 2022.11.15 CAPITAL ONE SERVICES LLC
  • US11502842B2 patent drawing
  • US11502842B2 patent drawing
  • US11502842B2 patent drawing

AI summary

A system may include a first automated teller machine (ATM) and a second ATM, wherein the first ATM and the second ATM are in communication via a local area network. The first ATM obtains a user input value, generate an encryption key based on the user input value, and generates encrypted authentication information based on the encryption key. The first ATM also obtains a first biometric reading, updates a user record based on the first biometric reading, and stores the encrypted authentication information at the first ATM in association with the user record. The second ATM obtains a second biometric reading and a duplicate value, retrieves the encrypted authentication information associated with the user record based on the second biometric reading, generates a decryption key based on the duplicate value, and decrypts the encrypted authentication information to retrieve the authentication information.