ATM Terminal Authentication via Unique Identifier Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in authenticating the authenticity of financial transaction terminals, such as ATMs, due to sophisticated identity theft methods like ATM spoofing, where fake machines capture account and personal identification information, and existing methods are insufficient to verify the legitimacy of ATMs, especially with the rise of wireless network connectivity.

Innovation Solution

A system and method that involves generating terminal authentication data by combining financial account data with a unique identifier of the terminal, such as a MAC address or IP address, to verify its authenticity against a list of known identifiers, and then retrieving and displaying a shared secret for user confirmation before proceeding with the transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network address spoofing and wireless network connectivity are used, then ATM can be made more versatile and accessible, but authentication reliability deteriorates as fake ATMs can mimic legitimate ones

Engineering Contradiction:
ImproveATM connectivity optionsVSAvoidATM authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a terminal authentication system as an intermediary between the ATM and the financial network. This system verifies the authenticity of ATMs by checking their unique identifiers (MAC addresses, IP addresses, or other device identifiers) against a trusted database before allowing them to process transactions, thus preventing spoofed ATMs from gaining unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication of the ATM terminal before any financial transactions occur. The terminal authentication system validates the ATM's identity in advance by comparing its unique identifier against authenticated terminal identifiers stored in the financial transaction processing system, ensuring that only legitimate ATMs can proceed with transactions

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If shared secret is provided to ATM for authentication, then user authentication is enabled, but security vulnerability increases as the shared secret can be captured by fake ATMs

Engineering Contradiction:
ImproveUser authenticationVSAvoidShared secret capture
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication of the ATM terminal itself before establishing any authentication mechanisms with users. By validating the terminal's unique identifier against a trusted database first, the system ensures that even if a shared secret is distributed, it will only reach authenticated, legitimate ATMs and not spoofed devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal authentication system acts as an intermediary layer that verifies ATM authenticity before allowing the ATM to receive shared secrets or process user credentials. This intermediate validation step prevents fake ATMs from capturing shared secrets by blocking them from the authentication process entirely

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If unique terminal identifier is used for authentication, then ATM authenticity can be verified, but device complexity increases due to additional authentication infrastructure

Engineering Contradiction:
ImproveATM authenticity verificationVSAvoidAuthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service authentication mechanism where ATMs automatically provide their unique identifiers (MAC addresses, IP addresses, or other device identifiers) and the terminal authentication system automatically validates them against the trusted database without requiring manual intervention or complex cryptographic key management at the ATM level

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs multiple types of unique identifiers (MAC addresses, IP addresses, and other device identifiers) that can serve the same authentication function. This multi-functional approach allows the system to work with different identifier types without requiring separate authentication infrastructures for each type, thereby reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9235832B1Systems and methods for detecting transactions originating from an unauthenticated ATM device
Publication Date: 2016.01.12 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US9235832B1 patent drawing
  • US9235832B1 patent drawing
  • US9235832B1 patent drawing

AI summary

A system, method, and computer-usable medium are disclosed for authenticating a financial transaction terminal, such as an automated teller machine. A user provides financial account data, such as an account number, which is then combined with a unique identifier of the financial transaction terminal to generate terminal authentication data. The terminal authentication data is provided to a terminal authentication system, which extracts the financial account data and the unique identifier of the financial transaction terminal. The unique identifier of the financial transaction terminal is compared to a list of authentic financial transaction terminal identifiers. If its authenticity is confirmed, then a shared secret corresponding to the user's financial account data is provided to the authenticated financial transaction terminal. The user is queried as to the authenticity of the shared secret. If the response is affirmative, then the user is prompted to provide user authentication information, such as a Personal Identification Number (PIN), and the transaction proceeds. Otherwise, the transaction is discontinued.