Mobile Device Keypad for Secure Credential Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems using keypads at transaction terminals, such as ATMs, are vulnerable to attacks due to untrusted user interfaces, and existing solutions requiring trust-based integration between mobile devices and back-end systems are costly and difficult to implement.

Innovation Solution

A mobile device-based authentication system that uses a short-range communication device and keypad interface application to establish a secure authentication channel with the transaction terminal, allowing users to enter credentials on their trusted mobile device instead of the terminal's keypad, with a handshake protocol ensuring the terminal's trustworthiness before credential transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users enter credentials directly on the terminal keypad, then the access control function is simple to implement, but the security is compromised because the terminal keypad is untrusted and can be monitored or compromised

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mobile device as an intermediary between the user and the terminal keypad. The mobile device runs a keypad application that captures credentials locally, preventing direct exposure to the untrusted terminal keypad while still enabling access control functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the credential entry function from the terminal keypad by implementing it as a separate mobile device application. This separation allows the credential capture to occur in a trusted environment (mobile device) while the terminal remains responsible for authentication verification.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a trust-based integration model is used between mobile device and back-end systems, then security is enhanced, but the implementation becomes costly and difficult

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The terminal acts as an intermediary that verifies credentials without requiring deep trust integration with the mobile device or back-end systems. The mobile device's keypad application captures credentials, the terminal verifies them, and the back-end system processes authentication independently, reducing implementation complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The mobile device's keypad application performs self-service credential capture and transmission, eliminating the need for complex trust-based integration between the mobile device and back-end systems. The system leverages existing mobile device security mechanisms to handle credential management autonomously.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If the terminal keypad is used for credential entry, then the device complexity is low, but the system becomes vulnerable to attacks such as scanners, hidden cameras, and shoulder surfing

Engineering Contradiction:
Improvevulnerability to attacksVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The mobile device serves as a mediator that captures credentials in a secure, private environment away from physical surveillance attacks. The credential capture occurs on the mobile device's display and keyboard, which are not visible to shoulder surfers or captured by hidden cameras at the terminal location.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the physical terminal keypad with a virtual keypad implementation on the mobile device. This substitution eliminates the physical interface that is vulnerable to scanners and visual attacks, while maintaining the credential entry functionality through software-based input methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10102402B2Mobile device-based keypad for enhanced security
Publication Date: 2018.10.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10102402B2 patent drawing
  • US10102402B2 patent drawing
  • US10102402B2 patent drawing

AI summary

An authentication channel is established between a mobile device and a transaction terminal that uses a keypad for access control. The terminal keypad is assumed to be untrusted, whereas the mobile device has a trusted interface that only the device user can access and use. The transaction terminal includes a short-range communication device, and a keypad interface application configured to communicate with an external keypad device in lieu of the transaction terminal's own keypad. The mobile device includes a mobile app. In response to detecting a user access request, a handshake protocol is performed between the keypad interface application in the transaction terminal and the keypad interface function in the mobile device. If the handshake protocol succeeds, the user is notified that the transaction terminal is trusted. The user then enters his or her password and/or PIN on the mobile device in lieu of direct entry via the terminal keypad.