SST Thin Client OS Restricts Execution to Authorized Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing technologies for managing and servicing Automated Teller Machines (ATMs) across multiple bank branches result in highly coupled, heterogeneous environments, leading to inefficiencies and high costs due to the need for client-centric and installation-specific expertise, as well as infrequent asset updates and limited customization capabilities.
Innovation Solution
The implementation of Self-Service Terminal (SST) thin clients, which include an operating system, an authorized thin-client application, and an authorized agent, configured to restrict execution to authorized applications, access predefined peripheral devices, and manage updates from an authorized server, enabling secure, customizable, and efficient operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional ATM servicing approaches are used with client-specific experts, then each bank branch can be serviced with customized solutions, but the servicing cost and complexity increase significantly
Solution Approach 1:
The patent implements a universal servicing platform that can service multiple different bank branches and ATM configurations through a single centralized system. The web-based interface and centralized asset management system provide universal access and control, eliminating the need for client-specific experts while maintaining the ability to handle diverse ATM configurations across different branches.
Solution Approach 2:
The patent introduces a centralized asset management system and web-based interface as intermediaries between the servicing organization and various ATM installations. This intermediary layer abstracts the complexity of different ATM configurations, allowing servicing engineers to interact with a standardized interface rather than dealing with heterogeneous client-specific systems directly.
2Reliability
If servicing engineers physically visit each ATM for software asset service, then direct access to hardware is ensured, but the time and cost for servicing increase
Solution Approach 1:
The patent implements self-service capabilities through the centralized asset management system that can remotely update, configure, and manage software assets on ATMs without requiring physical engineer presence. The system automatically distributes software updates and configurations to targeted ATMs, enabling the system to service itself remotely while maintaining reliable hardware access through authenticated remote connections.
Solution Approach 2:
The patent extracts the software asset management functions from the physical ATM locations and consolidates them into a centralized asset management system. This separation allows software updates and configurations to be managed remotely from a central location, eliminating the need for engineers to physically travel to each ATM while maintaining the ability to directly access and modify software assets.
3Reliability
If asset updates are performed infrequently due to security concerns, then system security is maintained, but the assets become outdated and less functional
Solution Approach 1:
The patent implements a dynamic asset update system that can rapidly deploy security patches and software updates to ATMs across the network. The centralized asset management system enables on-demand updates that can be pushed to individual ATMs or groups of ATMs based on security requirements, allowing the system to adapt quickly to new security threats while maintaining controlled update deployment.
Solution Approach 2:
The patent implements preliminary security measures by pre-configuring and pre-testing software updates in the centralized asset management system before deploying them to ATMs. The system prepares update packages in advance with embedded security credentials and authentication mechanisms, ensuring that security is built into the update process itself rather than relying solely on infrequent update cycles.
4Ease of manufacture
If coarse-grain customization is applied across the entire fleet, then implementation is simpler, but fine-grain customization capabilities are lost
Solution Approach 1:
The patent implements local quality by enabling different levels of customization for different ATMs or groups of ATMs within the same fleet. The centralized asset management system allows configuration parameters to be set at multiple granularities - fleet-wide defaults for common settings and location-specific or device-specific overrides for customized requirements, maintaining both simplicity and flexibility.
Solution Approach 2:
The patent segments the customization hierarchy into multiple levels: fleet-wide configurations, branch-level configurations, and individual ATM configurations. This segmentation allows coarse-grain customization to be applied broadly across the fleet for simplicity while enabling fine-grain customization at specific segments where needed, without requiring complete customization of every single ATM.
Data Source
AI summary
Self-Service Terminal (SST) thin clients and operation thereof are provided. A SST includes an operating system (OS), and authorized thin-client application, and an authorized agent. The OS is configured to restrict execution on the SST to authorized applications. The authorized thin-client application is configured to access predefined peripheral devices within the SST and an authorized server. In an embodiment, the authorized agent is configured to connect to the authorized server to: manage updates to the OS received from the authorized server and receive customizations from the authorized server to configure the authorized thin-client application.


