BIOS Credential Management for ATM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated Teller Machines (ATMs) face security breaches due to unauthorized access to the Basic Input/Output System (BIOS), and managing BIOS passwords for field engineers is challenging, as they need access for diagnostic purposes while posing a security risk if compromised.

Innovation Solution

A method for BIOS credential management involves creating entries in a data store for credentials, communicating them to service engineers, and automatically generating and updating unique, random passwords for each ATM, ensuring secure access and minimizing human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BIOS password protection is implemented for security, then security is improved, but field engineers cannot access BIOS for diagnostic purposes

Engineering Contradiction:
ImproveBIOS securityVSAvoidField engineer access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments password management by creating distinct password types: administrator passwords for security management and service passwords for field engineers. This segmentation allows different access levels - the ATM BIOS remains protected with administrator passwords while field engineers can obtain temporary service passwords for diagnostic purposes without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary password management system that acts as a mediator between security requirements and field engineer needs. This system generates, distributes, and revokes service passwords automatically, allowing field engineers to access BIOS when needed while maintaining security through controlled password lifecycle management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If field engineers are given BIOS passwords for service access, then ease of operation is improved, but security risk increases due to potential password leakage

Engineering Contradiction:
ImproveField engineer service accessVSAvoidPassword leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements disposable, single-use service passwords that are generated temporarily for field engineers and automatically invalidated after use or expiration. These temporary passwords are akin to disposable keys - they provide necessary access when needed but cannot be reused, minimizing the impact of potential leakage since compromised passwords become useless after one use or expiration.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent makes password lifecycles dynamic by automatically generating, distributing, and revoking service passwords based on service needs. Passwords are not static but change over time - field engineers receive temporary passwords for specific service periods, and the system automatically rotates passwords to maintain security while enabling ongoing service access.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If manual password management is used, then ease of manufacture is improved, but productivity decreases due to physical visits required for password changes

Engineering Contradiction:
ImprovePassword management simplicityVSAvoidPassword update efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent implements self-service password management where the system automatically generates, distributes, and revokes service passwords without requiring manual intervention from administrators. The password management system serves itself by automatically rotating passwords, notifying field engineers of temporary credentials, and invalidating expired passwords, eliminating the need for physical visits while maintaining simple operation through automated workflows.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10909516B2Basic input/output system (BIOS) credential management
Publication Date: 2021.02.02 NCR ATLEOS CORP
  • US10909516B2 patent drawing
  • US10909516B2 patent drawing
  • US10909516B2 patent drawing

AI summary

A Basic Input/Output System (BIOS) agent on a Self-Service Terminal (SST) coordinates with a BIOS credential manager that determines when to communicate a BIOS credential for the SST and when to re-generate and re-set a new BIOS credential for the SST.