ATM Token Cash Withdrawal Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing financial transaction systems at ATMs are vulnerable to unauthorized access due to the potential exposure of compromised cards, which can lead to unauthorized access to funds in financial accounts.

Innovation Solution

A system that generates and authenticates tokens associated with financial accounts, using a server token and device token for authentication, along with a server PIN, to secure transactions at ATMs, employing encryption and near-field communication (NFC) for secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional card-based authentication is used at ATMs, then ease of operation is maintained, but security against unauthorized access deteriorates due to compromised cards

Engineering Contradiction:
ImprovesecurityVSAvoidoperation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a token as an intermediary between the user and the financial account authentication system. Instead of directly using the card, the user generates a token that serves as a temporary credential. This token is then used in place of the card at the ATM, preventing direct exposure of the compromised card while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a temporary copy (token) of the authentication credentials stored on the user's device. This token copy contains the necessary information to access the financial account but is separate from the original card data. The token can be transmitted to the ATM without exposing the actual card, thus securing the original credential while enabling authentication.

Inventive Principle:
Principle #26Copying

2Productivity

If card information is exposed during transactions, then transaction speed is maintained, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improvetransaction speedVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent employs disposable tokens that are generated temporarily for each transaction or session. These tokens have limited validity periods and can be discarded after use or when no longer needed. This approach allows rapid generation of new credentials without exposing long-term card information, maintaining transaction speed while reducing the window of opportunity for unauthorized access.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If tokens are generated and authenticated through multiple steps, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service functionality where the user's mobile device automatically generates and manages tokens without requiring manual intervention. The device handles token creation, storage, and transmission autonomously, reducing the perceived complexity for the user. The authentication process is streamlined so that users simply initiate a transaction and the system handles the complex token authentication in the background.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10762483B2ATM token cash withdrawal
Publication Date: 2020.09.01 BANK OF AMERICA CORP
  • US10762483B2 patent drawing
  • US10762483B2 patent drawing
  • US10762483B2 patent drawing

AI summary

Embodiments of the invention are directed to a system for managing financial tokens associated with a financial account, whereby the system is directed towards generating and authenticating tokens associated with the financial account in order to grant access to a user to conduct financial transactions on the financial account using an Automated Teller Machine (ATM). The system is configured to generate a server token that is associated with at least one financial account; communicate, to a first mobile device, a server packet comprising at least the server token; receive, from an ATM, a security packet comprising at least a device token; authenticate the device token, the authentication comprising comparing the device token with the server token, thereby resulting in a successful authentication of the device token; and communicate the successful authentication to the ATM.