Mobile Device Keypad for Secure Credential Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems using keypads at transaction terminals, such as ATMs, are vulnerable to attacks due to untrusted user interfaces, and existing solutions requiring trust-based integration between mobile devices and back-end systems are costly and difficult to implement.
Innovation Solution
A mobile device-based authentication system that uses a short-range communication device and keypad interface application to establish a secure authentication channel with the transaction terminal, allowing users to enter credentials on their trusted mobile device instead of the terminal's keypad, with a handshake protocol ensuring the terminal's trustworthiness before credential transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users enter credentials directly on the terminal keypad, then the access control function is simple to implement, but the security is compromised because the terminal keypad is untrusted and can be monitored or compromised
Solution Approach 1:
The patent introduces a mobile device as an intermediary between the user and the terminal keypad. The mobile device runs a keypad application that captures credentials locally, preventing direct exposure to the untrusted terminal keypad while still enabling access control functionality.
Solution Approach 2:
The system segments the credential entry function from the terminal keypad by implementing it as a separate mobile device application. This separation allows the credential capture to occur in a trusted environment (mobile device) while the terminal remains responsible for authentication verification.
2Reliability
If a trust-based integration model is used between mobile device and back-end systems, then security is enhanced, but the implementation becomes costly and difficult
Solution Approach 1:
The terminal acts as an intermediary that verifies credentials without requiring deep trust integration with the mobile device or back-end systems. The mobile device's keypad application captures credentials, the terminal verifies them, and the back-end system processes authentication independently, reducing implementation complexity.
Solution Approach 2:
The mobile device's keypad application performs self-service credential capture and transmission, eliminating the need for complex trust-based integration between the mobile device and back-end systems. The system leverages existing mobile device security mechanisms to handle credential management autonomously.
3Object-affected harmful factors
If the terminal keypad is used for credential entry, then the device complexity is low, but the system becomes vulnerable to attacks such as scanners, hidden cameras, and shoulder surfing
Solution Approach 1:
The mobile device serves as a mediator that captures credentials in a secure, private environment away from physical surveillance attacks. The credential capture occurs on the mobile device's display and keyboard, which are not visible to shoulder surfers or captured by hidden cameras at the terminal location.
Solution Approach 2:
The patent replaces the physical terminal keypad with a virtual keypad implementation on the mobile device. This substitution eliminates the physical interface that is vulnerable to scanners and visual attacks, while maintaining the credential entry functionality through software-based input methods.
Data Source
AI summary
An authentication channel is established between a mobile device and a transaction terminal that uses a keypad for access control. The terminal keypad is assumed to be untrusted, whereas the mobile device has a trusted interface that only the device user can access and use. The transaction terminal includes a short-range communication device, and a keypad interface application configured to communicate with an external keypad device in lieu of the transaction terminal's own keypad. The mobile device includes a mobile app. In response to detecting a user access request, a handshake protocol is performed between the keypad interface application in the transaction terminal and the keypad interface function in the mobile device. If the handshake protocol succeeds, the user is notified that the transaction terminal is trusted. The user then enters his or her password and/or PIN on the mobile device in lieu of direct entry via the terminal keypad.


