Triple-Factor Authentication for Public Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication mechanisms for public terminals, such as ATMs and POS systems, rely on single-factor authentication (e.g., PIN-based) which are vulnerable to compromise, leading to security risks and inefficiencies in user authorization.
Innovation Solution
Implementing a triple-factor authentication system that includes a physical credential, a mobile device authentication mechanism (e.g., biometric or password), and a user-selected authentication mechanism within a secure application, using a unique code generated based on the public terminal and user identifiers to enhance security and reduce overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single-factor authentication (e.g., PIN-based) is used, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The authentication process is divided into three separate factors: (1) possession of a physical credential device, (2) knowledge of a PIN code, and (3) biometric verification through fingerprint or facial recognition. Each factor is independently verified, creating layered security that maintains user convenience while significantly improving reliability compared to single-factor authentication.
2Reliability
If multiple-factor authentication is implemented, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent combines multiple authentication factors into a unified authentication flow managed by a single authentication module. The physical credential device, PIN input, and biometric sensor are integrated into one coherent process where each factor builds upon the previous one, reducing the perceived complexity for users while maintaining high security reliability.
Solution Approach 2:
A credential verification server acts as an intermediary between the public terminal and the authentication factors. The server receives authentication data from the terminal, performs the multi-factor verification, and returns authorization decisions. This mediator simplifies the terminal's complexity while ensuring reliable security verification through centralized credential validation.
3Ease of operation
If traditional authentication methods are used, then ease of operation is maintained, but susceptibility to compromise increases
Solution Approach 1:
The system performs preliminary verification of the physical credential device before requesting the PIN, and preliminarily validates the credential format and authenticity before proceeding to biometric verification. This preliminary action prevents obvious compromises early in the process and maintains operational simplicity by guiding users through pre-validated steps.
Solution Approach 2:
The patent changes the authentication parameters from simple PIN verification to a multi-parameter system including physical credential identification, PIN code, and biometric data. Each parameter is transformed into a secure format (e.g., cryptographic verification of credential device, hashed PIN storage, encrypted biometric templates) that resists compromise while maintaining ease of operation through automated processing.
Data Source
AI summary
Systems and methods for authenticating a user to access a public terminal are described. Disclosed embodiments may include reading, using the physical credential reader, a user identifier from the physical credential device. Disclosed embodiments may also include transmitting the public terminal identifier and the user identifier to a secure server. Further, disclosed embodiments may include receiving, after completing the transmission, a unique code from the secure server. Disclose embodiments may additionally include displaying the unique code on the display device. Disclosed embodiments may include receiving, after displaying the unique code, an authentication message from the secure server. Disclosed embodiments may further include, responsive to receiving the authentication message, authorizing the user to use a terminal command at the public terminal.


