ATM PIN Entry Interface with Asymmetric Visual Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of memory-containing cards for electronic commerce has made them attractive targets for criminals, particularly in skimming attacks at ATMs, where data stored on the cards and PINs are compromised, leading to unauthorized transactions.

Innovation Solution

A system for verifying electronic financial transactions involves generating a user interface with a security code, associating different portions of the code with distinct parts of a user input device, including visual indicia dissimilar to the code portion, and randomizing the order of the code portions, making it difficult for criminals to capture the PIN and security code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PIN entry methods are used at ATMs, then ease of operation is maintained, but security against skimming attacks deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security code is divided into multiple portions and associated with different parts of the user input device. Each portion of the code is mapped to a specific input device part, creating segmented verification steps that prevent criminals from capturing the complete security code through traditional skimming methods.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Visual indicia are made dissimilar to the actual code portions they represent. The visual representation displayed to the user does not directly resemble the actual code being entered, creating an asymmetric relationship that prevents criminals from observing and recording the actual security code through visual means.

Inventive Principle:
Principle #4Asymmetry

2Ease of operation

If security codes are displayed with clear visual indicia, then ease of operation improves, but vulnerability to visual capture attacks worsens

Engineering Contradiction:
Improveease of operationVSAvoidvisual capture vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The visual indicia associated with code portions are deliberately made dissimilar to the actual code portions. This asymmetric design allows users to easily identify and select the correct portions while preventing criminals from visually capturing the actual security code, as the displayed visual indicators do not reveal the true code values.

Inventive Principle:
Principle #4Asymmetry

3Ease of operation

If the order of code portions is fixed, then ease of operation improves, but security against prediction attacks worsens

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The order in which code portions are presented to the user is randomized and can change between different verification instances. This dynamic reordering prevents criminals from predicting the sequence of code portions, adding a layer of security while still maintaining ease of operation through clear visual guidance for each randomized position.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7725388B2Verification of electronic financial transactions
Publication Date: 2010.05.25 ENT SERVICES DEV CORP LP
  • US7725388B2 patent drawing
  • US7725388B2 patent drawing
  • US7725388B2 patent drawing

AI summary

Techniques are provided for verifying an electronic financial transaction. In certain implementations, verifying an electronic financial transaction includes generating a user interface including a security code, the user interface associating different portions of the code with different parts of a user input device, and associating at least one code portion with a user input device part having visual indicia dissimilar to the visual representation of the code portion. Verifying an electronic financial transaction also includes detecting activation of the user input device in a manner that generates a code, and determining whether the generated code corresponds to the security code.