Cardless ATM Authentication via Online Credentials and One-Time Passcodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Financial institutions face challenges in providing customers with convenient and secure access to their accounts, especially when customers do not have a physical banking card or token, as existing systems often require these credentials for authentication.

Innovation Solution

Implementing an account management computing platform that allows customers to access automated teller devices using online banking credentials, such as usernames, passwords, one-time passcodes, and biometrics, providing limited access and enabling features like emergency withdrawals and card reporting without the need for physical cards or PINs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical banking cards or tokens are required for authentication, then security is improved, but convenience deteriorates when customers lose or cannot access their physical cards

Engineering Contradiction:
Improveaccount securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an account management computing platform as an intermediary between the automated teller device and the customer. This platform receives authentication credentials from the customer, validates them, and generates authentication tokens that enable access to the automated teller device without requiring physical cards. The platform acts as a mediator that translates traditional card-based authentication into cardless authentication, resolving the contradiction between maintaining security and improving convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical physical card system with an electronic/digital authentication system. Instead of requiring customers to physically insert a card into the automated teller device, the system uses electronic credentials ( usernames, passwords, one-time passcodes) transmitted through a computing platform. This substitution eliminates the need for physical cards while maintaining authentication security, thereby improving convenience without compromising reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If online banking credentials are accepted for cardless access, then convenience is improved, but security risks increase due to potential credential compromise

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The account management computing platform performs preliminary authentication and validation of customer credentials before granting access to the automated teller device. The platform verifies usernames, passwords, and one-time passcodes in advance, and only generates authentication tokens for verified credentials. This preliminary action ensures that compromised or invalid credentials cannot be used to access the automated teller device, mitigating security risks while maintaining convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic authentication where the system adapts its security requirements based on the authentication method used. For cardless access using online credentials, the system dynamically requires additional verification steps (such as one-time passcodes) compared to traditional card-based access. This dynamic approach adjusts security measures in real-time to maintain appropriate security levels while enabling convenient cardless access.

Inventive Principle:
Principle #15Dynamics

3Reliability

If limited access is provided to customers without physical cards, then security is maintained, but functionality is reduced

Engineering Contradiction:
Improveaccount securityVSAvoidtransaction functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the automated teller device and account management platform can adjust the level of access granted based on authentication verification. For customers authenticated through the cardless system, the platform can dynamically enable additional functions beyond basic transactions, such as card replacement services, account management, and higher withdrawal limits, depending on the verification level and customer needs. This dynamic adaptability allows the system to maintain security while providing versatile functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The account management computing platform serves multiple functions: it authenticates customers, generates authentication tokens, validates credentials, manages cardless access policies, and enables various transaction types. By consolidating these diverse functions into a single universal platform, the system can provide comprehensive service capabilities to cardless customers without compromising security, thereby improving adaptability and versatility while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10013684B2Processing cardless transactions at automated teller devices
Publication Date: 2018.07.03 BANK OF AMERICA CORP
  • US10013684B2 patent drawing
  • US10013684B2 patent drawing
  • US10013684B2 patent drawing

AI summary

Methods, systems, and computer-readable media for processing cardless transactions at automated teller devices are presented. In some embodiments, a computer system may receive, from an automated teller device associated with a financial institution, login input comprising one or more online banking credentials associated with a customer of the financial institution. Subsequently, the computer system may validate the login input. If the login input is valid, the computer system may generate a one-time passcode. Then, the computer system may send, to a customer mobile device associated with the customer, the one-time passcode. Thereafter, the computer system may receive, from the automated teller device, passcode input. Subsequently, the computer system may validate the passcode input. If the passcode input is valid, the computer system may generate a customer authentication message. Then, the computer system may send, to the automated teller device, the customer authentication message.