Banking Terminal Security Module Dynamic Access Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional banking systems require multiple login stages and hierarchical access structures, which are inflexible and inefficient, limiting user access to specific roles and functionalities without allowing seamless transitions between different access levels based on varying authentication methods.

Innovation Solution

A terminal with a security module that maps different access spaces to multiple types of personal authentication elements, allowing users to access various functionalities based on a combination of authentication methods, such as passwords, biometrics, and behavioral information, without strict hierarchical constraints, enabling flexible role-based access and streamlined login processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional hierarchical access control system with multiple login stages is used, then security is maintained through strict access levels, but system flexibility and user convenience deteriorate due to rigid role assignments and multiple authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system changes the parameters of authentication by accepting multiple types of personal authentication elements (biometric, knowledge-based, possession-based) instead of traditional single-factor authentication. This allows dynamic adjustment of access levels based on the combination and strength of authentication elements provided, resolving the contradiction between maintaining security and providing access flexibility.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The access control system transitions from static hierarchical roles to dynamic access spaces where users can be granted temporary, context-specific access based on their authentication elements. The security module dynamically maps authentication elements to appropriate access spaces, allowing the system to adapt access levels in real-time without compromising security.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple login stages with different user IDs and passwords are required for different access levels, then security is enhanced through layered authentication, but system complexity and operational efficiency worsen due to multiple login processes

Engineering Contradiction:
ImprovesecurityVSAvoidlogin process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple authentication mechanisms (biometric scanners, password inputs, token readers) into a single authentication interface. The security module consolidates the verification of multiple personal authentication elements into one unified process, eliminating the need for separate login stages while maintaining enhanced security through multi-factor authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The terminal is designed with universal authentication capabilities that can handle multiple types of personal authentication elements through a single interface. The security module provides multi-functional access control by mapping different authentication element types to various access spaces, allowing one system to serve multiple security requirements simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If strict hierarchical access structures are enforced, then security control is maintained through defined roles, but system adaptability worsens as users cannot access appropriate functionalities based on varying authentication methods

Engineering Contradiction:
Improveaccess controlVSAvoidrole-based access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments access control into distinct access spaces, each corresponding to specific functionalities or data areas. The security module maps different combinations of personal authentication elements to different access spaces, allowing fine-grained control where users gain access to specific segments of the system based on their authentication profile rather than rigid hierarchical roles.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different levels of authentication elements are assigned to different access spaces based on the security requirements of each specific function or data area. High-security access spaces require stronger authentication combinations, while lower-security spaces accept weaker authentication, creating local quality variations in access control that enhance both security and adaptability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9898726B2Security system
Publication Date: 2018.02.20 GLORY GLOBAL SOLUTIONS INT
  • US9898726B2 patent drawing
  • US9898726B2 patent drawing
  • US9898726B2 patent drawing

AI summary

A terminal for use in a retail banking system comprises an interface for receiving multiple types of personal authentication elements. An authentication request for a user is associated with one or more of these types of element. The terminal also comprises a security module for providing access to a plurality of different access spaces of the system, each space comprises a different respective function or combination of functions of the system. For each access space, the security module provides a mapping between that access space and a respective one or more of the types of personal authentication element. Based on this mapping, the security module is thus configured to grant the user with access to one of the access spaces on condition of being mapped to the one or more types of personal authentication element associated with the authentication request for the user, and on condition those elements are verified.