NFT-Based Card Authentication Against Skimmer Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods at resource event apparatuses, such as ATMs and POS devices, are vulnerable to skimmer devices and do not effectively differentiate between genuine and imitation card devices, as well as verify the identity of the card device user beyond conventional credentials.

Innovation Solution

The use of card device-specific and user credential-specific Non-Fungible Tokens (NFTs) stored in a distributed ledger, where NFTs are generated using card and user information and verified through consensus by decentralized nodes, ensuring authenticity and uniqueness, and linked for dual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication credentials (PIN, signature, photo ID) are used, then authentication can be performed, but the system is vulnerable to skimmer devices and imitation card devices

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidskimmer device vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by generating and storing cryptographic hashes of card device characteristics and user credentials in a distributed ledger before authentication events occur. This pre-established trusted database enables later verification without requiring physical possession of original credentials, thereby preventing skimmer device attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic hash functions and distributed ledger technology as intermediaries between the authentication credentials and the verification process. These intermediaries transform physical credentials into immutable digital representations that cannot be replicated by skimmer devices, solving the vulnerability to imitation card devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system stores and verifies card device characteristics and user credentials in a distributed ledger, then authentication security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The distributed ledger serves multiple functions simultaneously: it stores card device characteristics, stores user credentials, provides verification services, and maintains immutable audit trails. This multi-functionality reduces the need for separate systems for each function, thereby managing complexity while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service authentication where the distributed ledger automatically verifies credentials without requiring manual intervention from authentication personnel. The cryptographic verification process is self-executing, reducing operational complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12112328B1System for enhanced authentication using non-fungible tokens (NFTs)
Publication Date: 2024.10.08 BANK OF AMERICA CORP
  • US12112328B1 patent drawing
  • US12112328B1 patent drawing
  • US12112328B1 patent drawing

AI summary

Enhanced authentication at resource event apparatuses of a card device and, in some instances, the user of the card device. Card device-specific Non-Fungible Tokens (NFTs) are generated and, in some instance, user credential-specific NFTs are generated. The NFTs are stored within a distributed ledger of a distributed trust computing network, which provides verification as the uniqueness and authenticity of the NFTs. Once a resource event is initiated at a resource event apparatus, card device-related information and, in some instance, user credential-related information is received, and the information is compared to the corresponding NFT as a means of authenticating the card device and, in some instances, the card device and the linked user of the card device. As a result, the use of imitation card devices is prevented and, in some instances, the identity of the user of the card device is authenticated and deemed to be linked to the card device.