ATM Terminal Authentication via Unique Identifier Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in authenticating the authenticity of financial transaction terminals, such as ATMs, due to sophisticated identity theft methods like ATM spoofing, where fake machines capture account and personal identification information, and existing methods are insufficient to verify the legitimacy of ATMs, especially with the rise of wireless network connectivity.
Innovation Solution
A system and method that involves generating terminal authentication data by combining financial account data with a unique identifier of the terminal, such as a MAC address or IP address, to verify its authenticity against a list of known identifiers, and then retrieving and displaying a shared secret for user confirmation before proceeding with the transaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network address spoofing and wireless network connectivity are used, then ATM can be made more versatile and accessible, but authentication reliability deteriorates as fake ATMs can mimic legitimate ones
Solution Approach 1:
The patent introduces a terminal authentication system as an intermediary between the ATM and the financial network. This system verifies the authenticity of ATMs by checking their unique identifiers (MAC addresses, IP addresses, or other device identifiers) against a trusted database before allowing them to process transactions, thus preventing spoofed ATMs from gaining unauthorized access
Solution Approach 2:
The patent implements preliminary authentication of the ATM terminal before any financial transactions occur. The terminal authentication system validates the ATM's identity in advance by comparing its unique identifier against authenticated terminal identifiers stored in the financial transaction processing system, ensuring that only legitimate ATMs can proceed with transactions
2Ease of operation
If shared secret is provided to ATM for authentication, then user authentication is enabled, but security vulnerability increases as the shared secret can be captured by fake ATMs
Solution Approach 1:
The patent performs preliminary authentication of the ATM terminal itself before establishing any authentication mechanisms with users. By validating the terminal's unique identifier against a trusted database first, the system ensures that even if a shared secret is distributed, it will only reach authenticated, legitimate ATMs and not spoofed devices
Solution Approach 2:
The terminal authentication system acts as an intermediary layer that verifies ATM authenticity before allowing the ATM to receive shared secrets or process user credentials. This intermediate validation step prevents fake ATMs from capturing shared secrets by blocking them from the authentication process entirely
3Reliability
If unique terminal identifier is used for authentication, then ATM authenticity can be verified, but device complexity increases due to additional authentication infrastructure
Solution Approach 1:
The patent implements a self-service authentication mechanism where ATMs automatically provide their unique identifiers (MAC addresses, IP addresses, or other device identifiers) and the terminal authentication system automatically validates them against the trusted database without requiring manual intervention or complex cryptographic key management at the ATM level
Solution Approach 2:
The patent employs multiple types of unique identifiers (MAC addresses, IP addresses, and other device identifiers) that can serve the same authentication function. This multi-functional approach allows the system to work with different identifier types without requiring separate authentication infrastructures for each type, thereby reducing overall system complexity
Data Source
AI summary
A system, method, and computer-usable medium are disclosed for authenticating a financial transaction terminal, such as an automated teller machine. A user provides financial account data, such as an account number, which is then combined with a unique identifier of the financial transaction terminal to generate terminal authentication data. The terminal authentication data is provided to a terminal authentication system, which extracts the financial account data and the unique identifier of the financial transaction terminal. The unique identifier of the financial transaction terminal is compared to a list of authentic financial transaction terminal identifiers. If its authenticity is confirmed, then a shared secret corresponding to the user's financial account data is provided to the authenticated financial transaction terminal. The user is queried as to the authenticity of the shared secret. If the response is affirmative, then the user is prompted to provide user authentication information, such as a Personal Identification Number (PIN), and the transaction proceeds. Otherwise, the transaction is discontinued.


