ATM Anomaly Detection via Electromagnetic Signal Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security technologies are inadequate for reliably and efficiently detecting anomalies and security threats in automated teller machines (ATMs) and computing devices, leading to potential security breaches.

Innovation Solution

A server-based, ATM-based, and computing device-based anomaly and security threat detection system that establishes baseline features using machine learning algorithms on electromagnetic radiation and I/O electrical signals, comparing them to test features to identify deviations indicative of security vulnerabilities, and performs countermeasures such as alerting, auto-fixing, or isolating the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual inspection of ATMs is performed, then security threats can be detected, but the process is error-prone and inefficient

Engineering Contradiction:
Improvedetection reliabilityVSAvoidinspection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical inspection with an automated electronic detection system that captures electromagnetic radiation signals from ATM components. This substitution eliminates human error while continuously monitoring component integrity, thereby improving both reliability and productivity simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables ATMs to self-diagnose security threats by automatically capturing and analyzing electromagnetic signals from their own components. The ATM's built-in detection mechanism allows it to identify tampering or anomalies without external manual inspection, improving efficiency while maintaining high detection reliability.

Inventive Principle:
Principle #25Self-service

2Reliability

If current information security technologies are used, then basic security monitoring is provided, but anomaly detection is unreliable and inefficient

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes baseline electromagnetic radiation patterns for each ATM component during normal operation before security threats occur. This preliminary characterization allows the system to quickly compare future signals against known good patterns, enabling rapid and reliable anomaly detection without time-consuming manual analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces slow, unreliable manual anomaly detection with automated electromagnetic signal analysis. The system continuously monitors component signals and immediately identifies deviations from baseline patterns, dramatically reducing detection time while improving reliability through consistent automated analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If electromagnetic radiation signals are analyzed for component identification, then unique component signatures can be detected, but the system complexity increases

Engineering Contradiction:
Improvecomponent identification precisionVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs a universal electromagnetic signal capture approach that can identify and characterize multiple different component types using the same detection mechanism. The system captures radiation signals from various components (microprocessors, memory, circuits) and uses pattern recognition to distinguish them, achieving high identification precision without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates electromagnetic signal profiles or copies of normal component behavior patterns during baseline establishment. These signal copies serve as reference templates for future comparison, enabling precise component identification and anomaly detection while keeping the detection system relatively simple through pattern matching rather than complex real-time analysis.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Effectively detects anomalies and security threats in ATMs and computing devices, reducing the risk of unauthorized access and improving the reliability of information security by analyzing unique electrical and EM radiation patterns, thereby enhancing data protection.

Implementation Method 1

The first set of signals may include electromagnetic (EM) radiation signals, Input/Output (I/O) electrical (e.g., voltage and current) signals

Methodology Applied
Scientific EffectElectromagnetic radiation: Electromagnetic Induction

Data Source

PatentUS11556637B2Information security system and method for anomaly and security threat detection
Publication Date: 2023.01.17 BANK OF AMERICA CORP
  • US11556637B2 patent drawing
  • US11556637B2 patent drawing
  • US11556637B2 patent drawing

AI summary

A system for detecting security threats in a computing device receives a first set of signals from components of the computing device. The first set of signals includes intercommunication electrical signals between the components of the computing device and electromagnetic radiation signals propagated from the components of the computing device. The system extracts baseline features from the first set of signals. The baseline features represent a unique electrical signature of the computing device. The system extracts test features from a second set of signals received from the component of the system. The system determines whether there is a deviation between the test features and baseline features. If the system detects the deviation, the system determines that the computing device is associated with a particular anomaly that makes the computing device vulnerable to unauthorized access.