ATM BIOS Boot Password Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated banking machines are vulnerable to unauthorized access and malicious software due to their booting behavior from portable media, which can lead to security breaches and unauthorized transactions.

Innovation Solution

The automated banking machine incorporates a BIOS program with password protection for booting, requiring users to input a boot password for alternative storage device drives, ensuring that only authorized users can modify the boot sequence and access portable bootable media, thereby enhancing security and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the ATM computer boots from portable bootable media (floppy disk, CD-ROM) without authentication, then it enables authorized users to service the machine by loading setup programs and diagnostic tools, but it allows unauthorized users to insert malicious software and compromise the system security

Engineering Contradiction:
Improvebooting capability from portable mediaVSAvoidmalicious software loading
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication by requiring a boot password to be entered before the system allows booting from alternative storage device drives. This preliminary action prevents unauthorized users from loading malicious software while still allowing authorized service personnel to access portable bootable media for maintenance and setup tasks.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the BIOS is configured to boot from alternative storage device drives without password protection, then it enables easy access to service functions and operating system installation, but it creates security vulnerabilities that allow unauthorized modification of boot sequence and system compromise

Engineering Contradiction:
Improveaccess to service functionsVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies different access controls to different storage device drives. The primary storage device drive (hard drive) remains accessible without password for normal operations, while alternative storage device drives (floppy disk drive, CD-ROM drive) require password authentication. This local quality differentiation maintains ease of operation for legitimate users while enhancing system security against unauthorized access.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the ATM includes multiple bootable storage device drives for serviceability, then it enables flexible booting options for installation and maintenance, but it increases the attack surface for unauthorized users to insert malicious media

Engineering Contradiction:
Improvebooting flexibilityVSAvoidsecurity breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication checks before allowing boot operations from alternative storage device drives. By requiring password verification in advance, the system maintains the flexibility of having multiple bootable drives for serviceability while preventing unauthorized users from exploiting these additional interfaces for security breaches.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7849011B1Automated banking machine bootable media authentication
Publication Date: 2010.12.07 DIEBOLD NIXDORF INCORPORATED
  • US7849011B1 patent drawing
  • US7849011B1 patent drawing
  • US7849011B1 patent drawing

AI summary

An automated banking machine is provided that selectively controls the booting of the machine for different storage device drives. The machine may include at least one computer. The automated banking machine may also include at least one transaction function device, such as a cash dispenser, in operative connection with the computer. The computer of the machine may include a BIOS setup program with a BIOS program password and at least one BIOS boot password. When no alternative bootable media is detected, the computer is operative to automatically boot from a specified default bootable media. If an alternative bootable media is detected, the computer is operative to prompt a user to input the BIOS boot password. If the inputted password is valid, the computer is operative to boot from the alternative media. If no password is inputted, the computer is operative to automatically boot from the default bootable media.