ATM BIOS Boot Password Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated banking machines are vulnerable to unauthorized access and malicious software due to their booting behavior from portable media, which can lead to security breaches and unauthorized transactions.
Innovation Solution
The automated banking machine incorporates a BIOS program with password protection for booting, requiring users to input a boot password for alternative storage device drives, ensuring that only authorized users can modify the boot sequence and access portable bootable media, thereby enhancing security and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the ATM computer boots from portable bootable media (floppy disk, CD-ROM) without authentication, then it enables authorized users to service the machine by loading setup programs and diagnostic tools, but it allows unauthorized users to insert malicious software and compromise the system security
Solution Approach 1:
The patent implements preliminary authentication by requiring a boot password to be entered before the system allows booting from alternative storage device drives. This preliminary action prevents unauthorized users from loading malicious software while still allowing authorized service personnel to access portable bootable media for maintenance and setup tasks.
2Ease of operation
If the BIOS is configured to boot from alternative storage device drives without password protection, then it enables easy access to service functions and operating system installation, but it creates security vulnerabilities that allow unauthorized modification of boot sequence and system compromise
Solution Approach 1:
The patent applies different access controls to different storage device drives. The primary storage device drive (hard drive) remains accessible without password for normal operations, while alternative storage device drives (floppy disk drive, CD-ROM drive) require password authentication. This local quality differentiation maintains ease of operation for legitimate users while enhancing system security against unauthorized access.
3Adaptability or versatility
If the ATM includes multiple bootable storage device drives for serviceability, then it enables flexible booting options for installation and maintenance, but it increases the attack surface for unauthorized users to insert malicious media
Solution Approach 1:
The system performs preliminary authentication checks before allowing boot operations from alternative storage device drives. By requiring password verification in advance, the system maintains the flexibility of having multiple bootable drives for serviceability while preventing unauthorized users from exploiting these additional interfaces for security breaches.
Data Source
AI summary
An automated banking machine is provided that selectively controls the booting of the machine for different storage device drives. The machine may include at least one computer. The automated banking machine may also include at least one transaction function device, such as a cash dispenser, in operative connection with the computer. The computer of the machine may include a BIOS setup program with a BIOS program password and at least one BIOS boot password. When no alternative bootable media is detected, the computer is operative to automatically boot from a specified default bootable media. If an alternative bootable media is detected, the computer is operative to prompt a user to input the BIOS boot password. If the inputted password is valid, the computer is operative to boot from the alternative media. If no password is inputted, the computer is operative to automatically boot from the default bootable media.


