Secure Wireless Discovery and Pairing for ATMs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated Teller Machines (ATMs) face security concerns with wireless connectivity due to the risk of Denial of Service (DoS) attacks and the impracticality of managing secure wireless access, as existing solutions require extensive monitoring and centralized updates, which are vulnerable to hacking and misuse.
Innovation Solution
A system for secure wireless discovery and pairing that uses a Time-based One Time Password (TOTP) algorithm and shared secrets to dynamically change and verify connection settings and pairing codes, allowing devices to manage their own security without manual updates or central server oversight, ensuring secure and authorized connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If ATMs implement wireless connectivity to enable remote access and support functions, then device functionality and accessibility are improved, but security vulnerability increases due to exposure to wireless DoS attacks and unauthorized access
Solution Approach 1:
The patent implements dynamic security credentials that automatically rotate and expire. Discovery codes and pairing codes are generated with time-based validity periods and automatically change, making static attacks ineffective. This dynamic approach allows wireless connectivity while mitigating DoS attacks through automatic credential invalidation.
Solution Approach 2:
The system performs preliminary authentication by validating discovery codes and pairing codes before establishing wireless connections. Security credentials are pre-configured with validity parameters, and the ATM verifies these credentials in advance of any data transmission, preventing unauthorized access attempts.
2Reliability
If centralized servers manage security information for ATMs, then security policy enforcement is improved, but security risk increases due to servers becoming lucrative targets for hackers
Solution Approach 1:
The patent extracts security credential management from centralized servers and implements it locally within each ATM. Each device generates and stores its own discovery codes and pairing codes independently, eliminating the centralized repository that would be a hacker target while maintaining consistent security policies through standardized local implementation.
Solution Approach 2:
ATMs autonomously generate, store, and manage their own security credentials without requiring centralized server intervention. The system performs self-authentication using locally stored discovery codes and pairing codes, with automatic credential rotation and expiration management, reducing dependency on vulnerable centralized infrastructure.
3Reliability
If security information is manually updated at ATMs, then security control is improved, but operational complexity and time consumption increase
Solution Approach 1:
The system implements automatic periodic rotation of security credentials including discovery codes and pairing codes. Credentials are generated with predetermined validity periods and automatically expire and renew without manual intervention, providing continuous security control while eliminating the time-consuming manual update process.
Solution Approach 2:
The patent replaces manual mechanical security updates with automated electronic credential generation and rotation. The system uses algorithmic generation of discovery codes and pairing codes with automatic expiration and renewal, substituting human-operated manual updates with automated computational processes that occur without personnel intervention.
4Ease of operation
If ATMs continuously monitor wireless channels for connection requests, then wireless accessibility is improved, but exposure to wireless attacks increases
Solution Approach 1:
The patent introduces discovery codes as an intermediary authentication mechanism between the ATM and wireless devices. Instead of continuously monitoring and accepting any connection requests, the ATM uses discovery codes as a filtering intermediary that validates intended connections before establishing wireless communication, reducing exposure to malicious attacks while maintaining accessibility for authorized devices.
Data Source
AI summary
A terminal selectively and passively monitors for predefined wireless network discovery advertisements/requests. Requests that match what are expected by the terminal or requests that are in a predefined format are verified. The requests lack any connection pairing passcode; rather, the passcodes are separately provided from connecting devices only after the discovery requests are verified. The terminal independently authenticates the passcodes before authorizing wireless sessions between the devices and the terminal. Wireless discovery settings are continuously changed by the terminal and are valid for only a preset time window, each setting corresponds to a Time-based One Time Password (TOTP) representing a passcode; the TOTP is dependent on and valid only for the corresponding setting and the corresponding time window. In an embodiment, the connection requests are preauthorized by a server for a time window in the future, and the terminal authenticates the requests without interaction with the server.


