Continuous Biometric ATM Session Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The lack of human supervision at ATM locations creates security risks, as customers may become distracted or abandon their sessions, allowing malicious individuals to take over their accounts, with existing time-out mechanisms being insufficient to prevent theft.
Innovation Solution
Implementing a system with a facial recognition camera and additional biometric identifiers, such as QR code scanning, to continuously authenticate users throughout their ATM session, ensuring ongoing authorization and transmission of identity information to maintain session security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ATM operates without human supervision to provide wide location access, then customer convenience and accessibility are improved, but security risk increases due to potential session takeover
Solution Approach 1:
The system performs continuous biometric authentication throughout the ATM session rather than only at initialization. The biometric sensor repeatedly verifies the customer's identity during the session, ensuring continuous security monitoring while allowing the ATM to operate unattended in remote locations.
Solution Approach 2:
The system provides continuous feedback by monitoring biometric data during the session and comparing it against the authorized customer's biometric profile. This real-time feedback mechanism detects when an unauthorized person attempts to use the session and triggers appropriate security responses.
2Reliability
If time-out cancellation mechanism is used to prevent unauthorized access, then security is partially improved, but it is insufficient to prevent theft during distracted or abandoned sessions
Solution Approach 1:
The system performs biometric authentication in advance at session initialization and then continues to verify the customer's identity throughout the session. This preliminary and ongoing authentication ensures that even if the customer becomes distracted or temporarily leaves, the system has already verified and continuously monitors their identity.
Solution Approach 2:
Instead of relying solely on time-out cancellation, the system maintains continuous biometric verification throughout the entire session. This continuous authentication provides ongoing security that prevents unauthorized access even when the customer is temporarily absent, going beyond the limitations of simple time-out mechanisms.
3Reliability
If continuous biometric authentication is implemented throughout ATM session, then security against session takeover is significantly improved, but device complexity increases
Solution Approach 1:
The system uses the customer's own biometric characteristics (fingerprint, iris, facial features, or voice) for authentication. These biometric traits are inherently unique to each individual and require no additional tokens, cards, or complex credentials. The customer simply presents themselves, and the system automatically verifies their identity, reducing the need for complex external authentication mechanisms.
Solution Approach 2:
The system replaces traditional mechanical authentication methods (keypad PIN entry, card insertion, physical tokens) with biometric sensing technology. This substitution eliminates the need for physical interaction devices and simplifies the authentication process to automatic biometric verification, reducing mechanical complexity while enhancing security.
Data Source
AI summary
Systems and methods for authenticating a user's identity at an ATM are provided. One method may include capturing at least a portion of user's facial information using a facial recognition camera. The method may also include receiving information using an additional biometric scanner. The method may further include using one or more device handlers to receive information related to the captured portion of the user's facial information from the facial recognition camera and to receive information related to the additional biometric scanner. The one or more device handlers may also be used for determining one or more routing destinations for said information related to the captured portion of the user's facial information, for said information and for said information received from the additional biometric scanner. The method may also include transmitting the information received by the facial recognition camera and the information received from the additional biometric scanner for initially authorizing an ATM session, or information corresponding thereto, to said one or more routing destinations. The transmitting may further maintain the ATM session by continuing, following an initial authorization, for the duration of the ATM session, only authorization information corresponding to the information received by the facial recognition camera to the one or more routing destinations.


