Card-Swipe Sequence Authentication for Skimmer-Resistant ATMs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication systems at ATMs and other terminals are vulnerable to skimmers and cameras, which can steal card information and PINs, making it difficult for users to detect malicious activity and maintain security without burdening them with complex PINs.

Innovation Solution

Implementing a card-swipe sequence authentication method that involves multiple card swipes, where the sequence includes timing and type variations, eliminating the need for PIN entry and making it harder for skimmers to obtain necessary information, by using a computing device to detect and store card information and authenticate users based on the sequence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single card swipe and PIN entry method is used, then the authentication process is simple and fast, but it is vulnerable to skimmers and cameras that can steal card information and PINs

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity against skimmers and cameras
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple distinct card swipes instead of a single swipe. Each swipe captures different card information, and the sequence of swipes creates a segmented authentication process that cannot be captured by traditional skimmers or cameras in a single moment, thereby maintaining simplicity while improving security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by capturing card information through multiple swipes before completing authentication. The first swipe captures initial card data, and subsequent swipes capture additional information or verification data, allowing the system to build a complete authentication profile before final verification, making it difficult for skimmers to capture all necessary information

Inventive Principle:
Principle #10Preliminary action

2Reliability

If longer or more complicated PIN numbers are used, then security against skimmers is improved, but the burden on users to remember and accurately provide the PIN increases

Engineering Contradiction:
Improvesecurity against skimmersVSAvoiduser burden to remember and provide PIN
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention extracts the PIN entry step entirely from the authentication process. Instead of requiring users to enter a PIN (whether simple or complicated), the system uses multiple card swipes to capture and verify card information sequences, eliminating the need for users to remember or type complex PINs while maintaining strong security through the multi-swipe verification process

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If multiple card swipes are required for authentication, then security is enhanced by preventing traditional skimmers from accessing user accounts, but the authentication process becomes more complex

Engineering Contradiction:
Improvesecurity against information theftVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The card reader device performs multiple functions within a single authentication interaction: it reads card information, tracks swipe sequences, verifies authentication data, and provides user feedback. This multi-functionality allows the system to implement complex security protocols without requiring multiple separate devices or complex user actions, as the single card reader handles all authentication tasks through programmed sequence verification

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11227289B2Systems and methods for user authentication using card-swipe sequence
Publication Date: 2022.01.18 CAPITAL ONE SERVICES LLC
  • US11227289B2 patent drawing
  • US11227289B2 patent drawing
  • US11227289B2 patent drawing

AI summary

Systems and methods for user authentication using an authentication sequence are disclosed. The disclosed systems and methods may include a computing device for authenticating a user. The computing device may include at least one processor and at least one computer-readable medium. The at least one computer-readable medium can containing instructions that, when executed by the at least one processor, cause the computing device to perform operations. The operations may include receiving an authentication sequence provided by one or more authentication objects and authenticating the user based on the authentication sequence. The authentication sequence can be a card-swipe sequence and authentication can be performed based on characteristics of the card-swipe sequence, such as the cards used, the order the cards are used in the sequence, the timing of card use, and the type of card swipe.