Cross-channel ATM Authentication via Mobile Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to enable efficient cardless authentication of individuals at ATMs or kiosks, particularly when customers lack physical identification or banking cards, leading to inconvenience and privacy concerns with ID scanning.
Innovation Solution
A method and communication network that utilizes a mobile device to authenticate identity via a trusted computing system, using a unique identifier displayed on the device, which interacts with an authentication provider module to verify the individual's identity independently of the trusted system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ID scanning hardware is installed on ITMs for authentication, then authentication capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a mobile device as an intermediary that carries authentication credentials (QR code, biometric data, or token) between the customer and the ITM. This eliminates the need for ID scanning hardware on the ITM, as the mobile device itself serves as the portable authentication medium that can be read by standard cameras or sensors already present on the terminal.
Solution Approach 2:
The patent replaces physical ID card scanning hardware with software-based authentication methods using mobile devices. Instead of mechanical/optical ID scanners, the system uses camera-based QR code reading, biometric sensors, or wireless communication to verify customer identity, thereby eliminating specialized hardware requirements.
2Reliability
If physical ID cards are scanned for authentication, then identity verification is improved, but processing time increases
Solution Approach 1:
The patent implements preliminary action by pre-registering customer biometric data, photos, and authentication tokens in the mobile device before the authentication event. During the actual authentication at the ITM, the pre-stored data is immediately presented for verification, eliminating the time-consuming process of physical ID card scanning and manual data entry.
Solution Approach 2:
The patent creates digital copies of physical identification data (photos, biometric templates, personal information) and stores them securely in the mobile device. These digital copies are then transmitted to the ITM for verification, replacing the need to physically scan or manually input data from physical ID cards, thereby significantly reducing authentication time.
3Measurement precision
If physical ID cards are scanned and transmitted, then authentication accuracy is improved, but privacy concerns increase
Solution Approach 1:
The patent extracts only the essential authentication elements (biometric data, photo, personal information) from the complete physical ID card and stores them in the mobile device. During authentication, only these extracted essential elements are transmitted to the ITM, rather than transmitting the entire ID card image or unnecessary personal data, thereby reducing privacy exposure while maintaining authentication accuracy.
Solution Approach 2:
The patent uses disposable or temporary authentication tokens (such as time-limited QR codes or single-use verification codes) that are generated for each authentication session and then discarded. This approach maintains authentication security without requiring long-term storage or transmission of sensitive personal information, thereby reducing privacy concerns.
Data Source
AI summary
A method is disclosed in which a first computing device of a trusted computing system detects an input event indicating that an individual at the first computing device wishes to authenticate their identity. The first computing device transmits an authentication request, for authenticating the identity of the individual, to a server of the trusted computing system and displays a unique identifier comprising a request identifier for the authentication request on a display of the first computing device. An authentication provider module configured to authenticate the identity of the individual independently of the trusted computing system receives the request identifier from the mobile device. The authentication provider module authenticates the identity of the individual. The server receives a response to the authentication request from the authentication provider module. The server transmits the response to the first computing device to thereby authenticate the identity of the individual at the first computing device.


