Secure PIN Entry via Dummy Sequence Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current ATM security systems are vulnerable to skimming attacks, which compromise user PINs and bank card information, as existing solutions have not been completely satisfactory in preventing unauthorized access.

Innovation Solution

A user device and method for secure PIN entry that involve a user interface, processor, and memory to receive and parse a group of inputs, including a dummy sequence, an indicator sequence, and an access sequence, transmitting the access sequence for authentication, and granting or denying access based on a match with the associated confidential access code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PIN entry methods are used at ATMs, then users can access their bank accounts conveniently, but the system becomes vulnerable to skimming attacks where thieves can record PINs and card information

Engineering Contradiction:
Improvesecurity against skimming attacksVSAvoidsimplicity of PIN entry
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The PIN entry process is segmented into multiple sequences: a first sequence of inputs (dummy data), a second sequence (actual PIN), and optionally a third sequence. This segmentation prevents skimmers from capturing the complete PIN in one continuous entry, as the system processes and validates sequences separately, with the first sequence acting as a decoy that confuses recording devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by requiring users to enter a first sequence of dummy inputs before entering the actual PIN. This preliminary dummy entry serves to迷惑 skimming devices, causing them to record incorrect data first. The system validates this preliminary sequence separately from the actual PIN sequence, ensuring that even if skimmers record the dummy data, they cannot obtain the real PIN.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures like security guards or visual verification are implemented, then ATM security is improved, but the complexity and cost of the system increases

Engineering Contradiction:
ImproveATM securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ATM system provides self-service security by automatically processing multiple input sequences and validating them against stored patterns. The system independently handles the security verification without requiring external security guards or complex visual verification systems. The multi-sequence validation is performed entirely by the ATM's processor, reducing external security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameter of PIN entry from a single continuous sequence to multiple discrete sequences with different validation rules. This parameter change allows the system to maintain high security through complex validation logic while keeping the physical ATM interface simple and unchanged. The complexity is shifted from hardware/security infrastructure to software processing.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11915241B2Systems and methods for the secure entry and authentication of confidential access codes for access to a user device
Publication Date: 2024.02.27 CAPITAL ONE SERVICES LLC
  • US11915241B2 patent drawing
  • US11915241B2 patent drawing
  • US11915241B2 patent drawing

AI summary

The present disclosure relates to systems and method for securely entering a confidential access code into a user device. A system for allowing secure entry of a confidential access code into a user device may include one or more memories storing instructions and one or more processors configured to execute instruction to perform operations. The operations may include receiving a request for confidential access, prompting the user, via the user interface, to enter a group of inputs into a single-entry field, receiving a dummy sequence of inputs, receiving or providing an indicator signal, receiving an access sequence of inputs, parsing the group of inputs received to identify the access sequence of inputs based on the location of the indicator signal, comparing the access sequence of inputs to the confidential access code associated with the user, and granting or denying access to the confidential information based on the results.