ATM Security via Component Alteration and Self-Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated transaction machines (ATMs) are vulnerable to fraudulent activities such as 'jackpotting,' where large quantities of banknotes are dispensed quickly to unauthorized individuals, highlighting a need for enhanced security measures to prevent unauthorized access and memory replacement.

Innovation Solution

The method involves partially disengaging and altering a component of the ATM, such as a currency cassette, to render it non-conforming, then re-engaging it after replacing the memory component, which requires pairing with the computing device only if the altered component is properly reinserted and detected as conforming, thereby preventing fraudulent memory replacement and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If memory component is replaced in ATM, then system can be maintained or upgraded, but security vulnerability increases due to potential fraudulent memory replacement

Engineering Contradiction:
Improvememory replacementVSAvoidsecurity
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The system performs preliminary actions by altering a component (such as a currency cassette or door) to a non-conforming state before memory replacement, and requires this non-conforming state to be detected after re-engagement. This preliminary setup ensures that only authorized personnel who can properly alter and re-engineer the component can perform memory replacement, preventing fraudulent attempts while allowing legitimate maintenance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures are enhanced to prevent fraudulent memory replacement, then security improves, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ATM system performs self-verification by automatically detecting whether the altered component is in a conforming or non-conforming state after re-engagement. The computing device autonomously determines whether to permit memory replacement based on the detected state, eliminating the need for complex external verification procedures or additional security hardware, thus enhancing security while maintaining simplicity.

Inventive Principle:
Principle #25Self-service

3Reliability

If component alteration process is implemented, then fraudulent access is prevented, but operation time increases

Engineering Contradiction:
ImprovesecurityVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system requires only a partial alteration of a component (such as removing a panel or changing the position of a component) to create a non-conforming state, rather than requiring complete disassembly or complex modifications. This partial action is sufficient to prevent fraudulent access while minimizing the time and effort required for legitimate maintenance operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3815057B1Method of operating an automated transaction machine for enhanced security
Publication Date: 2024.04.03 DIEBOLD NIXDORF INCORPORATED
  • EP3815057B1 patent drawingFigure 1
  • EP3815057B1 patent drawingFigure 2
  • EP3815057B1 patent drawingFigure 3

AI summary

A method of operating an automated transaction machine (ATM) can include receiving a token from a user. The method can also include confirming a personal identification number (PIN) of the user and dispensing banknotes in response to the confirming. The method can also include at least partially disengaging a first component of the ATM from a remainder of the ATM. The method can also include altering the first component to a non-conforming condition after being at least partially disengaged. The method can also include re-engaging the first component with the ATM after being altered. The method can also include replacing a second component of the ATM after the re-engaging. Replacing the second component can include pairing the second component with a computing device of the ATM. The pairing can be responsive at least in part to the altering.