Authenticated Self-Service Terminal Access via Cryptographic Peripheral

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Automated Teller Machines (ATMs) and Self-Service Terminals (SSTs) face challenges in providing secure access to authenticated personnel, with mechanical locks being inadequate, key management being difficult, and lack of adequate audit trails, leading to unauthorized access and potential malware integration.

Innovation Solution

A method for authenticated SST access involves presenting an authentication token on the terminal's display, obtaining an access command from a server, and validating it through a peripheral device before granting access, ensuring only authorized personnel can access internal components or administrative interfaces, with a secure audit trail maintained.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mechanical locks and key management systems are used for SST access, then physical security is provided, but security is compromised due to weak locks, duplicated keys, and lack of audit trails

Engineering Contradiction:
Improveaccess securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces mechanical lock and key systems with an electronic authentication system. The SST uses an authentication token displayed on screen, which is validated by a peripheral device against commands from a server, eliminating the need for physical keys and mechanical locks. This substitution provides stronger security without the management complexities of mechanical systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a server as an intermediary between the authentication token and the access control system. The server validates the authentication token and generates access commands, which are then verified by a peripheral device. This intermediary layer provides centralized control, audit trails, and eliminates the need for complex key management while maintaining physical security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication tokens and server validation are implemented, then access security is improved, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is designed to be self-service in that the SST itself generates and displays the authentication token on its screen. The peripheral device then validates this token autonomously by communicating with the server. This self-service approach simplifies the overall system by eliminating the need for external authentication hardware or manual intervention, reducing complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If peripheral device validation is required for access commands, then unauthorized access is prevented, but access process time increases

Engineering Contradiction:
Improveaccess authorizationVSAvoidaccess processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by displaying the token on the SST screen before the actual access command is executed. The peripheral device validates this token in advance, and only after successful validation is the access command processed. This preliminary action ensures that unauthorized access is prevented while the actual access process remains efficient, as the validation occurs before the user attempts to access the SST.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11055682B2Authenticated self-service terminal (SST) access
Publication Date: 2021.07.06 NCR ATLEOS CORP
  • US11055682B2 patent drawing
  • US11055682B2 patent drawing
  • US11055682B2 patent drawing

AI summary

An SST facilitates authentication of a user through an external service via a mobile device operated by the user. The SST also obtains independent verification of an access command sent from a server through a cryptographic peripheral module integrated into the SST before sending a command to grant authenticated access to the SST in response to the access command.