Self-Service Terminal PIN Authentication via Mobile Bijection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing self-service terminals, such as ATMs, face challenges in securely entering identification data for authentication without compromising product quality, usability, or safety, especially in cost-effective solutions for developing markets, where the risk of spying on sensitive information like PINs is not adequately addressed.
Innovation Solution
A method and system that generate a bijection of identification data, where the user enters pseudo-PINs represented by letters or symbols on their smartphone, with the actual mapping stored on a server, ensuring that only the server can authenticate the correct PIN entry, thus preventing spying.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional keypad (EPP) is used for PIN entry, then authentication can be performed, but the system is vulnerable to spying on sensitive information
Solution Approach 1:
The patent introduces an intermediary layer between the user and the authentication system. Instead of directly entering the PIN on a physical keypad, the user enters the PIN on their mobile device which then communicates with the terminal. This intermediary mobile device acts as a secure channel that prevents external spying while maintaining authentication functionality.
Solution Approach 2:
The authentication process is segmented into multiple components: the mobile device handles PIN entry and initial authentication, while the terminal handles transaction processing. This segmentation separates the sensitive PIN entry function from the terminal, reducing the terminal's vulnerability to spying attacks.
2Reliability
If high-quality components and comprehensive features are used in self-service terminals, then security and usability are improved, but production costs increase
Solution Approach 1:
The mobile device performs self-service authentication functions that would otherwise require expensive specialized hardware in the terminal. The mobile device's existing camera, display, and processing capabilities are utilized for PIN entry and verification, eliminating the need for the terminal to have expensive secure input devices.
Solution Approach 2:
The mobile device serves multiple functions: it acts as the PIN entry device, provides a display for transaction information, and serves as a communication interface with the terminal. This multi-functionality eliminates the need for the terminal to have separate specialized components for each function, reducing overall system cost.
3Object-affected harmful factors
If a mobile device is used for PIN entry instead of a terminal keypad, then spying is prevented, but the terminal requires additional communication infrastructure
Solution Approach 1:
The terminal utilizes existing communication infrastructure (mobile network, Wi-Fi) that is already present in the mobile device. By leveraging the mobile device's existing communication capabilities, the system avoids needing to build specialized communication hardware, thus preventing spying while minimizing added complexity.
Data Source
AI summary
A system for authentication and execution of a transaction at a self-service terminal. The system has a first computerized unit (PINSRV) which, in correspondence to a first data set comprising first elements (0, 1, 2, 3, . . . 9) from which the identification data (PIN) are derived, generates a second set of data with second elements (A, B, C, . . . , J), each of which is unambiguously assigned to one of the first elements. A monitor (DISP) is structurally connected to the self-service terminal (ATM) and displays the unambiguous assignment of the second elements to the first elements. A user terminal (MD) is structurally separated from the self-service terminal (ATM), and assigned to a user (CSM) and displaying the second elements (A, B, C, . . . , J) thus to allow the user to enter the input data (#PIN) at the user terminal (MD).


