NFC Mobile Authentication for ATM PIN Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ATM and unattended point-of-transaction devices face vulnerabilities in two-factor authentication, particularly with regards to PIN interception and unauthorized access, due to the need for users to enter sensitive information directly on the device, which can be compromised by tampering or surveillance.
Innovation Solution
Implementing near-field communication (NFC) technology in mobile devices to securely transmit PINs and transaction information between a mobile device and an ATM, establishing a secure wireless link with the bank, and using transaction identifiers that are valid only for a limited time and specific geographic locations to prevent unauthorized use.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users enter PIN and account information directly at the ATM keypad, then the transaction can be completed quickly and simply, but the system becomes vulnerable to PIN interception and unauthorized access
Solution Approach 1:
The patent introduces a mobile device as an intermediary between the user and the ATM. The mobile device receives account information and PIN from the user, then transmits this data to the ATM via NFC for authentication. This intermediary approach isolates the user from direct interaction with the ATM keypad, preventing PIN interception while maintaining authentication security.
Solution Approach 2:
The patent replaces the mechanical keypad input method with a wireless NFC transmission system. Instead of physically entering the PIN at the ATM keypad where it can be intercepted, the user enters the PIN on their mobile device and transmits it securely via NFC to the ATM, eliminating the mechanical vulnerability of keypad exposure.
2Adaptability or versatility
If the ATM uses a central clearinghouse to manage transactions, then multiple card types can be supported in a single device, but the system complexity increases
Solution Approach 1:
The patent makes the mobile device universal by enabling it to function as both the authentication carrier and the transaction initiation device. The mobile device can store different card profiles and communicate with various ATM types, allowing a single device to handle multiple card types and transaction scenarios without requiring the ATM itself to manage all card types directly.
3Reliability
If the mobile device transmits PIN and account information wirelessly to the ATM, then PIN interception is prevented, but the need for secure wireless transmission infrastructure increases system complexity
Solution Approach 1:
The mobile device serves as a secure intermediary that holds the PIN and account information locally. It establishes a secure NFC connection with the ATM to transmit this sensitive data wirelessly. This intermediary approach enables secure wireless transmission without requiring complex infrastructure, as the mobile device's secure element handles the authentication and encryption.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security by preventing PIN interception and unauthorized transactions, as sensitive information is entered remotely and transmitted securely, and transaction identifiers are transient and location-restricted, reducing the risk of fraudulent activities.
Implementation Method 1
transmitting to the unattended point-of-transaction device, via near field communication (NFC), information indicating that the transaction is being initiated
Data Source
AI summary
A method for a mobile device to conduct a transaction with an unattended point-of-transaction device is disclosed. The method comprises transmitting to the unattended point-of-transaction device, via near field communication (NFC), information indicating that the transaction is being initiated; receiving from the unattended point-of-transaction device, via NFC, credentials indicating that the unattended point-of-transaction device is authorized to engage in the transaction; and transmitting to the unattended point-of-transaction device, via NFC, secure information indicating to the unattended point-of-transaction device that the mobile communication device is authorized to conduct the transaction. The secure information may be a PIN entered into the mobile device or a data record specifying an action to be performed by the unattended point-of-transaction device. The data record may be generated by the mobile device based on the entry into the mobile device of the PIN and information specifying the action to be performed by the unattended point-of-transaction device.


