Document Value Processing Device Security Circuit Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

ATMs and similar devices face challenges in enhancing firmware security to prevent offline attacks, particularly in ensuring encrypted communication and protecting against unauthorized access and operation.

Innovation Solution

A document of value processing device with a secured chamber, a handling device, a control circuit, and a security circuit that receives and verifies cryptographically processed signals to enable or disable the handling device's operation, preventing unauthorized access and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secured chamber with handling device is used to protect documents of value, then physical security is improved, but the device can still be vulnerable to electronic attacks and unauthorized operation

Engineering Contradiction:
Improvephysical securityVSAvoidelectronic attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A security circuit is introduced as an intermediary component between the control circuit and the handling device. This security circuit receives cryptographically processed signals, verifies their authenticity, and only permits handling device operation when verification succeeds. This intermediary layer blocks unauthorized electronic attacks while maintaining legitimate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces purely mechanical/physical security measures with a cryptographic verification system. Instead of relying solely on physical barriers, the system uses electronic cryptographic signal verification to control the handling device, substituting mechanical security with a more sophisticated electronic security mechanism that is resistant to traditional electronic attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cryptographic verification is implemented in the security circuit, then protection against unauthorized operation is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against unauthorized operationVSAvoidsecurity circuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional components: a security circuit dedicated to cryptographic verification, a control circuit for overall system control, and a handling device for physical operations. This segmentation isolates the complex cryptographic functions to a specialized security circuit, making the overall system more manageable and maintainable despite the inherent complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security circuit performs self-verification of cryptographic signals without requiring external intervention. The circuit autonomously receives cryptographically processed signals, verifies their authenticity using embedded verification logic, and independently controls the handling device operation based on verification results, reducing the need for complex external security management.

Inventive Principle:
Principle #25Self-service

3Reliability

If the security circuit verifies cryptographic signals before enabling handling device operation, then security against offline attacks is improved, but operation time increases

Engineering Contradiction:
Improvesecurity against offline attacksVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Cryptographic verification is performed as a preliminary action before the handling device is enabled for operation. The security circuit verifies the authenticity of cryptographic signals in advance, ensuring that only authorized operations can proceed. This preliminary verification prevents unauthorized offline attacks while the time overhead is minimized by performing verification only when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cryptographic verification process is designed to complete quickly by efficiently processing and verifying cryptographic signals without unnecessary delays. The security circuit rushes through the verification process as rapidly as possible while maintaining security, minimizing the time overhead and allowing legitimate operations to proceed with minimal interruption.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentEP3376482B1Document of value processing device and method for operating a document of value processing device
Publication Date: 2022.06.22 WINCOR NIXDORF INT GMBH
  • EP3376482B1 patent drawingFigure 1
  • EP3376482B1 patent drawingFigure 2
  • EP3376482B1 patent drawingFigure 3

AI summary

According to various embodiments, a document of value processing device may include: a secured chamber configured to accommodate one or more documents of value and to protect at least one handling device from unauthorized access; the at least one handling device disposed inside the secured chamber to handle at least an output of the one or more documents of value out of the secured chamber may; a control circuit coupled to the at least one handling device to control an operation of the at least one handling device; and a security circuit disposed inside the secured chamber. The security circuit is configured to receive a cryptographically processed signal, to verify the received cryptographically processed signal, and to disable or enable the operation of the at least one handling device based on a verification result.