ATM Proximity Binding for Secure Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in determining how to authorize and bind individual computing devices to financial accounts securely, especially when the device is not initially associated with the user's financial institution, requiring a method to verify the device and user identity while enabling access to financial transactions.

Innovation Solution

An automated teller machine (ATM) detects the computing device's proximity, prompts the user to bind the device to their financial account, receives a unique identifier, and transmits application authorization to enable operations, leveraging identity verification data from the device and telecommunications systems for secure binding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an individual computing device is not initially associated with a financial institution, then the device cannot access financial account operations, but requiring initial association limits device provisioning flexibility and user convenience

Engineering Contradiction:
Improvedevice provisioning convenienceVSAvoidfinancial account security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an ATM as an intermediary device that mediates between the individual computing device and the financial institution's computing system. The ATM facilitates secure binding by acting as a trusted intermediary that verifies device identifiers and establishes secure associations without requiring pre-existing device-financial institution connections, thus resolving the contradiction between provisioning convenience and financial security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary binding actions at the ATM before the device needs to access financial operations. The device identifier is bound to the financial account in advance through the ATM's computing system, creating a pre-established secure association that enables subsequent convenient access without compromising security

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the ATM binds the computing device to the financial account using unique identifier verification, then secure authorization is achieved, but the binding process complexity increases

Engineering Contradiction:
Improveauthorization securityVSAvoidbinding process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex binding and authorization logic from the individual computing device and relocates it to the ATM's authentication circuit and the financial institution's computing system. The device only needs to provide its unique identifier, while the ATM handles the complex verification, binding, and authorization token generation, thus achieving secure authorization without increasing device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables self-service binding where the device automatically provides its unique identifier to the ATM, and the ATM autonomously performs verification, binding to the financial account, and authorization token generation without requiring manual configuration or complex user intervention, simplifying the overall binding process while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11741445B1Provisioning of an individual computing device via ATM
Publication Date: 2023.08.29 WELLS FARGO BANK NA
  • US11741445B1 patent drawing
  • US11741445B1 patent drawing
  • US11741445B1 patent drawing

AI summary

An automated teller machine (ATM) includes a network interface and an authentication circuit configured to receive data indicative of an interaction with the ATM by a user, detect that an individual computing device is in proximity to the ATM, determine that the individual computing device is not associated with a financial account, display a prompt comprising instructions to bind the individual computing device of the user to the financial account, receive data comprising a unique identifier of the individual computing device of the user, bind the individual computing device to the financial account based at least in part on the received unique identifier of the individual computing device of the user, and transmit, to the individual computing device, an application authorization, the application authorization authorizing an application to complete operations associated with the financial account via the bound individual computing device of the user.