ATM PIN Entry Interface with Asymmetric Visual Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of memory-containing cards for electronic commerce has made them attractive targets for criminals, particularly in skimming attacks at ATMs, where data stored on the cards and PINs are compromised, leading to unauthorized transactions.
Innovation Solution
A system for verifying electronic financial transactions involves generating a user interface with a security code, associating different portions of the code with distinct parts of a user input device, including visual indicia dissimilar to the code portion, and randomizing the order of the code portions, making it difficult for criminals to capture the PIN and security code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PIN entry methods are used at ATMs, then ease of operation is maintained, but security against skimming attacks deteriorates
Solution Approach 1:
The security code is divided into multiple portions and associated with different parts of the user input device. Each portion of the code is mapped to a specific input device part, creating segmented verification steps that prevent criminals from capturing the complete security code through traditional skimming methods.
Solution Approach 2:
Visual indicia are made dissimilar to the actual code portions they represent. The visual representation displayed to the user does not directly resemble the actual code being entered, creating an asymmetric relationship that prevents criminals from observing and recording the actual security code through visual means.
2Ease of operation
If security codes are displayed with clear visual indicia, then ease of operation improves, but vulnerability to visual capture attacks worsens
Solution Approach 1:
The visual indicia associated with code portions are deliberately made dissimilar to the actual code portions. This asymmetric design allows users to easily identify and select the correct portions while preventing criminals from visually capturing the actual security code, as the displayed visual indicators do not reveal the true code values.
3Ease of operation
If the order of code portions is fixed, then ease of operation improves, but security against prediction attacks worsens
Solution Approach 1:
The order in which code portions are presented to the user is randomized and can change between different verification instances. This dynamic reordering prevents criminals from predicting the sequence of code portions, adding a layer of security while still maintaining ease of operation through clear visual guidance for each randomized position.
Data Source
AI summary
Techniques are provided for verifying an electronic financial transaction. In certain implementations, verifying an electronic financial transaction includes generating a user interface including a security code, the user interface associating different portions of the code with different parts of a user input device, and associating at least one code portion with a user input device part having visual indicia dissimilar to the visual representation of the code portion. Verifying an electronic financial transaction also includes detecting activation of the user input device in a manner that generates a code, and determining whether the generated code corresponds to the security code.


