Self-Service Terminal PIN Authentication via Mobile Bijection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing self-service terminals, such as ATMs, face challenges in securely entering identification data for authentication without compromising product quality, usability, or safety, especially in cost-effective solutions for developing markets, where the risk of spying on sensitive information like PINs is not adequately addressed.

Innovation Solution

A method and system that generate a bijection of identification data, where the user enters pseudo-PINs represented by letters or symbols on their smartphone, with the actual mapping stored on a server, ensuring that only the server can authenticate the correct PIN entry, thus preventing spying.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional keypad (EPP) is used for PIN entry, then authentication can be performed, but the system is vulnerable to spying on sensitive information

Engineering Contradiction:
Improveauthentication securityVSAvoidspying on PIN
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary layer between the user and the authentication system. Instead of directly entering the PIN on a physical keypad, the user enters the PIN on their mobile device which then communicates with the terminal. This intermediary mobile device acts as a secure channel that prevents external spying while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into multiple components: the mobile device handles PIN entry and initial authentication, while the terminal handles transaction processing. This segmentation separates the sensitive PIN entry function from the terminal, reducing the terminal's vulnerability to spying attacks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If high-quality components and comprehensive features are used in self-service terminals, then security and usability are improved, but production costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidproduction cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The mobile device performs self-service authentication functions that would otherwise require expensive specialized hardware in the terminal. The mobile device's existing camera, display, and processing capabilities are utilized for PIN entry and verification, eliminating the need for the terminal to have expensive secure input devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile device serves multiple functions: it acts as the PIN entry device, provides a display for transaction information, and serves as a communication interface with the terminal. This multi-functionality eliminates the need for the terminal to have separate specialized components for each function, reducing overall system cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If a mobile device is used for PIN entry instead of a terminal keypad, then spying is prevented, but the terminal requires additional communication infrastructure

Engineering Contradiction:
Improvespying preventionVSAvoidcommunication infrastructure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The terminal utilizes existing communication infrastructure (mobile network, Wi-Fi) that is already present in the mobile device. By leveraging the mobile device's existing communication capabilities, the system avoids needing to build specialized communication hardware, thus preventing spying while minimizing added complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10229399B2Method and system for secure entry of identification data for the authentication of a transaction being performed by means of a self- service terminal
Publication Date: 2019.03.12 WINCOR NIXDORF INT GMBH
  • US10229399B2 patent drawing
  • US10229399B2 patent drawing
  • US10229399B2 patent drawing

AI summary

A system for authentication and execution of a transaction at a self-service terminal. The system has a first computerized unit (PINSRV) which, in correspondence to a first data set comprising first elements (0, 1, 2, 3, . . . 9) from which the identification data (PIN) are derived, generates a second set of data with second elements (A, B, C, . . . , J), each of which is unambiguously assigned to one of the first elements. A monitor (DISP) is structurally connected to the self-service terminal (ATM) and displays the unambiguous assignment of the second elements to the first elements. A user terminal (MD) is structurally separated from the self-service terminal (ATM), and assigned to a user (CSM) and displaying the second elements (A, B, C, . . . , J) thus to allow the user to enter the input data (#PIN) at the user terminal (MD).