Triple-Factor Authentication for Public Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication mechanisms for public terminals, such as ATMs and POS systems, rely on single-factor authentication (e.g., PIN-based) which are vulnerable to compromise, leading to security risks and inefficiencies in user authorization.

Innovation Solution

Implementing a triple-factor authentication system that includes a physical credential, a mobile device authentication mechanism (e.g., biometric or password), and a user-selected authentication mechanism within a secure application, using a unique code generated based on the public terminal and user identifiers to enhance security and reduce overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication (e.g., PIN-based) is used, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is divided into three separate factors: (1) possession of a physical credential device, (2) knowledge of a PIN code, and (3) biometric verification through fingerprint or facial recognition. Each factor is independently verified, creating layered security that maintains user convenience while significantly improving reliability compared to single-factor authentication.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple-factor authentication is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthorization securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors into a unified authentication flow managed by a single authentication module. The physical credential device, PIN input, and biometric sensor are integrated into one coherent process where each factor builds upon the previous one, reducing the perceived complexity for users while maintaining high security reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

A credential verification server acts as an intermediary between the public terminal and the authentication factors. The server receives authentication data from the terminal, performs the multi-factor verification, and returns authorization decisions. This mediator simplifies the terminal's complexity while ensuring reliable security verification through centralized credential validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional authentication methods are used, then ease of operation is maintained, but susceptibility to compromise increases

Engineering Contradiction:
Improveoperation simplicityVSAvoidvulnerability to compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of the physical credential device before requesting the PIN, and preliminarily validates the credential format and authenticity before proceeding to biometric verification. This preliminary action prevents obvious compromises early in the process and maintains operational simplicity by guiding users through pre-validated steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the authentication parameters from simple PIN verification to a multi-parameter system including physical credential identification, PIN code, and biometric data. Each parameter is transformed into a secure format (e.g., cryptographic verification of credential device, hashed PIN storage, encrypted biometric templates) that resists compromise while maintaining ease of operation through automated processing.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11675888B2Systems and methods for authenticating a user at a public terminal
Publication Date: 2023.06.13 CAPITAL ONE SERVICES LLC
  • US11675888B2 patent drawing
  • US11675888B2 patent drawing
  • US11675888B2 patent drawing

AI summary

Systems and methods for authenticating a user to access a public terminal are described. Disclosed embodiments may include reading, using the physical credential reader, a user identifier from the physical credential device. Disclosed embodiments may also include transmitting the public terminal identifier and the user identifier to a secure server. Further, disclosed embodiments may include receiving, after completing the transmission, a unique code from the secure server. Disclose embodiments may additionally include displaying the unique code on the display device. Disclosed embodiments may include receiving, after displaying the unique code, an authentication message from the secure server. Disclosed embodiments may further include, responsive to receiving the authentication message, authorizing the user to use a terminal command at the public terminal.