ATM Controller Validation via Displayed Security Indicia
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated banking machines face security risks due to unauthorized access to hardware and network communication, leading to potential modifications and theft of transaction information.
Innovation Solution
The system includes a secure cabinet with a display and banknote storage inside, and a keypad and computer outside, displaying security indicia visible only when the cabinet is opened, with a comparator to validate the identity of the controller using entered indicia and a security token, ensuring only authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the computer is located outside the secure cabinet, then the machine is easier to access and operate, but the computer is more vulnerable to unauthorized physical access and modification
Solution Approach 1:
The system divides the machine into secure components (inside cabinet: display, banknote storage) and accessible components (outside cabinet: keypad, computer), with validation occurring at the boundary through displayed indicia that must be entered into the external keypad
Solution Approach 2:
The displayed indicia serve as an intermediary validation mechanism between the external keypad and the internal secure controller, ensuring that only authorized operations can access the secure components
2Adaptability or versatility
If the machine is connected to network with TCP/IP protocols, then the machine can communicate and transfer data, but the machine becomes vulnerable to network-based hacking attacks
Solution Approach 1:
The system performs preliminary validation through displayed indicia before allowing any network communication or data transfer to occur, preventing unauthorized network access by validating the controller's identity in advance
Solution Approach 2:
The system provides feedback through displayed indicia that must be correctly entered to validate operations, creating a verification loop that prevents unauthorized network communications
3Object-affected harmful factors
If the secure cabinet is made more secure, then unauthorized physical access is prevented, but authorized operators may have difficulty accessing components for maintenance
Solution Approach 1:
The system enables authorized operators to self-validate their access rights through the displayed indicia and keypad interface, eliminating the need for physical keys or manual authentication while maintaining security
Data Source
AI summary
A computer implemented method for validating the identity of a controller for an automated banking machine based on displayed indicia. The method includes detecting access to a secure compartment of an automated banking machine, displaying a security indicia visible from the secure compartment, receiving the security indicia at an input device and a first controller accessible from outside of the secure compartment, and validating the identity of the controller based on the received security indicia.


