This specification relates to a patent application of invention that foresees a multibank biometric authentication system applied in automatic teller machines, which preferably has three biometric sensors.
Nowadays, financial institutions are replacing their security solutions for bank account access through an automated teller machine (ATM), which occurs by entering personal passwords, security codes, personal information and other combinations of numerical, syllabic and similar information, which are generally entered by users upon accessing, via biometric authentication solutions.
Currently, on the financial institutions branch, there is no provision of a system that enables the biometric authentication of several banks in one ATM network used by such banks, where such biometric authentication can be based on at least three different sensors.
The applicant acts within the context described above, being a company that manages a network of multibank ATMs that are used by users of several financial institutions, where each one of it must preferably adopt three security solutions with biometric authentication.
The applicant, hereinafter referred to as Company “X” in this specification, after a long development period enabled the system to attend users of financial institutions adopting different biometric authentication solutions.
The Company “X”, interested in providing improvements regarding security when using automatic teller machines, after countless researches and tests, created and developed this “MULTIBANK BIOMETRIC AUTHENTICATION SYSTEM APPLIED IN AUTOMATIC TELLER MACHINES WITH BIOMETRIC SENSORS”, which must be placed with highlights among its counterparts and personalized before the consumer market because it presents a multibank biometric authentication system preferably using three biometric sensors, system where financial institutions may choose to adopt one of the biometric technologies on the market, which may include fingerprint biometric authentication (using fingerprint sensors), vein biometric authentication (using palm vein or finger vein sensors), to authenticate its users. It is worth underlining that the herein claimed matter does not approach technical and/or functional characteristics of these biometric sensors genres.
The system created by the financial institutions via information of physical characteristics of each user preferably uses three market biometric authentication technologies fingerprint biometric authentication (using fingerprint sensor), vein biometric authentication (using palm vein or finger vein sensors), considering that, this way, the usage and access to bank account of each user by ATM of the Company “X” will be performed with biometric technologies selected by each one of the financial institutions.
The “Multibank Biometric Authentication System Applied in Automatic Teller Machines Preferably with Three Biometric Sensors” will be comprehensively described with reference to drawings related below, where:
According to the presented on drawings above displayed, on the System proposed by the Company “X”, the biometric information of Users “U” are required from the financial institution informing which biometric sensors are available to be used by its User “U” on the ATM terminal in use. The financial institution verifies the biometric sensors available on the ATM terminal and sends the corresponding biometric characteristics (biometric templates encrypted) for authentication of User “U” using the market biometric technology selected by the financial institution, being, for example, palm vein, finger vein or fingerprint, or even any other proper technology and performs the transaction via biometric authentication.
For purposes of information,
Firstly, a biometric key is defined between the financial institution 16 and the Host of the Company “X” and a key for each ATM terminal between the Host of the Company “X” and ATM terminals, with this key being periodically changed.
The biometric encrypted template is an important identification of the User “U” and needs to be securely stored and transported by the biometric key defined between the financial institution 16 Host and Company “X”, being translated on the Host of Company “X” for the ATM key and, subsequently, submitted to the requesting ATM. Thus, a security architecture is defined for transporting the referred templates between the financial institution and software of biometric devices of ATM terminals from the Company “X” (as it may be understood by observing
The Company “X” performs biometric authentications applied in market ATM 1, for Users “U” of financial institutions, through information of physical characteristics of each User “U” for preferably three market biometric authentication technologies being used, for example, fingerprint sensors 2, finger vein sensors 3, or palm vein sensors 4.
The present system also enables transactions to be performed requesting only biometric authentication with the market technology selected by the financial institution (such as fingerprint 2, finger vein 3 or palm vein 4) and/or requesting contingency security mechanisms (“PIN”, “TAN CODE” and “TOKEN”), or even further, to be performed requesting the combination of security devices and mechanisms, i.e., as example: biometry and card password; biometry and “PIN”; biometry, “PIN”, “TAN CODE” and/or “TOKEN”; no biometry with card password, “PIN”, “TAN CODE” and “TOKEN”; or even further, only biometry. A “TAN CODE” is a transaction authentication number used in online banking as a one-way use of single passwords to authorize financial transactions. TANs are a second layer of security above and beyond traditional single-password authentication. A “TOKEN” is an electronic device that generates passwords, usually without physical connection to the computer, and in some versions it can also be connected to a USB port.
As seen in
The present invention also starts the transportation on security of personal characteristics. For transportation of personal characteristics (biometric templates 15A or 15B or 15C) of User “U”s, a biometric key (27A or 27B or 27C) between the financial institution (16A or 16B or 16C) and the Host of the Company “X”, and a key (28A or 28B) between the Host of the Company “X” and the ATM (1A or 1B) is defined, this key being periodically changed. Each financial institution (16A,16B or 16C) will perform the exchange of biometrics information through a specific encryption key and which can be dynamically exchanged with Company “X”. Company “X” will translate the template (15A, 15B or 15C) into the ATM terminal encryption key (28a or 28b). Company “X” will be responsible for the ATM terminal key. Each ATM terminal will have its encryption key and can be dynamically switched.
Regarding the security solution, the biometric template (15A or 15B or 15C) is an important identification of the User “U” and needs to be securely stored and transported by the biometric key (27A or 27B or 27C) defined between the Host of the Company “X” and the financial institution (16A or 16B or 16C). The template is then translated on the Host of the Company “X” for the key (28A or 28B) of the ATM (1A or 1B) and then submitted to the requesting ATM (1A or 1B). Thus, a security architecture is defined for transportation of the referred biometric templates (15A or 15B or 15C) between the financial institution (16A or 16B or 16C) and the ATMs (1A or 1B) of the Company “X”.
The present invention monitors one, two or three biometric sensors (2, 3 and/or 4) present on the ATM terminal 1. It enables to monitor which market biometric technologies (fingerprint 2, finger vein 3 and/or palm vein 4) are present on the ATM terminals (1A or 1B) and the respective states (present, operable, inoperable or disconnected sensor from the ATM CPU).
This invention provides a set of biometric sensors (2, 3 and/or 4) to perform biometric authentication 14 incorporated to an ATM terminal 1 to enable financial institutions to select security devices and biometric technology that will be used for transaction authorization of the User “U” on ATM terminal 1. The set of biometric sensors (2, 3 and/or 4) that enable biometric authentication 14 allow the ATM terminal 1 to search for registration information 17 and biometric templates 15 on the financial institution 16 indicating on the request message 17, the biometric technologies (biometric sensors 2, 3 and/or 4 installed), the respective types and states of biometric sensors (operable or not). The financial institution 16 verifies the type of biometric sensors (2, 3 and/or 4) installed on the ATM terminal 1 and selects security devices and/or the biometric technology for transaction authorization 14 of the User “U”.
In this moment, other security devices might be submitted by the financial institution 16 to be captured on the ATM 1, such as, for example, the card password, the positive identification number or access letter, the “TAN CODE” and the “TOKEN”.
Thus, the system is presented positively flexible and configurable for usage of security devices and/or biometric technologies (2, 3 and/or 4) in ATM terminals 1. The system enables financial institutions to select biometric technologies on the market (2, 3 and/or 4), and keep performing transactions on ATM terminals 1 of the Company “X” using the security devices and biometric technologies used in their networks. Examples: requesting only biometric authentication 14; transactions performed requesting contingency devices “PIN”, “TAN CODE” and “TOKEN”; transactions performed requesting the combination of following devices: biometry and card password; biometry and “PIN”; biometry, card identification, “TAN CODE” or “TOKEN”; no biometry with card password, “PIN”, “TAN CODE” and “TOKEN”, or only biometry.
Regarding the macro validation sequence of the User “U” with biometric authentication, the User “U” initiates the session in the ATM—example: inserts the card to read the identification of the User “U” or the User “U” chooses transaction without card and type their identification 18; the ATM requests for financial institution 16 the registration information 17 of the User “U”; then ATM terminal 1 receives 17A the cadastral information (smart card treatment, biometrics and other security devices); then if the User “U” started the card session, the ATM performs validation 21 of the “CHIP Smart Card” of the User “U”; prompts User “U” to place finger (
Screen 5 of
Screen 6 of
Screen 1 of
Screen 2 of
Screen 3 of
Regarding the macro validation sequence of the User “U” with biometric authentication 14, the User “U” starts the session on the ATM 1, for example, User “U” inserts card 18 for magnetic stripe scanning; the ATM 1 requests to the financial institution 16 the registration information 17 of the User “U”; then the ATM 1 receives registration information 17A (smart card treatment, biometry and other security devices); subsequently, the ATM requests to insert card 18 and validates 21 the Smart Card CHIP of the User “U” card; requests the User “U” to position its finger or hand palm to perform the biometric authentication 14 of the User “U”; requests and captures the password 23 of the User “U”; requests the selection of transaction, value, requests authorization and complete the transaction.
As seen in
When one of these errors occur, the ATM submits incident 26 in real time to the financial institution 16.
Only for example purposes, the biometric treatment with finger or hand palm scanning error (
With this incident, the amount of biometric scanning errors is flagged (
When it occurs, the amount of biometric scan errors 25 is updated, the biometric sensor is enabled once again for finger or hand palm scanning, requesting the User “U” to position its finger (
It requests the User “U” not to move its finger or hand palm until scanning and the match (finger or hand palm authentication) are completed; new transaction completed with authentication error (after three attempts of biometric scanning—capture and authentication).
When the third error occurs, the referred incident 26 is submitted to flag the User “U” biometric authentication error. A screen (
The amount of biometric scanning errors is updated and the sensor becomes unavailable for this User “U”, considering that for the “unavailable sensor” incident some rules are provided, among which the cable disconnection of ATM CPU biometric sensor, i.e., the biometric sensor is monitored via “XFS” commands and the triggering of this sensor must disable the biometric sensor. The operation restart of the biometric sensor (2, 3 or 4) is performed only with operation tests (remote or local).
Moreover, it becomes unavailable as well when a number of consecutive biometric validation errors 25 occurs, i.e., the number of possible errors 25 is configured on the Host of the Company “X” and is submitted via communication network to the ATM terminal 1. Errors are counted whenever the biometric scanning error 25 occurs, regardless if it happened to one or several Users “U”. Each unsuccessful hand palm-scanning attempt is accounted as an error 25. When an OK scan occurs (capture and authentication OK), the amount of errors 25 returns to zero.
In cases of unavailable biometric sensors (2, 3 and/or 4), on the start of a transaction, the ATM 1 submits the information query message 17 to the financial institution 16 with the information that sensors (fingerprint 2, finger vein 3 and palm vein 4) are present, but inoperative for use.
The financial institution 16 might submit the answer of the information query request 17A with the security data currently used to validate the User “U”—IDPOS/TAN CODE/TOKEN. Transaction authorization will be performed as if the ATM terminal 1 did not have the biometric sensor (2, 3 or 4) installed.
Information of installed biometric sensors (2, 3 and/or 4), available and unavailable, is submitted by the ATM 1 system to monitoring systems of the Company “X”.
The information submitted on biometric sensors (2, 3 and/or 4) monitoring are: (1) The status of sensors installed on the ATM terminal 1 that are: sensor status: inexistent; operative; inoperative; or disconnected, and (2) The monitoring of sensors (2, 3 or 4) that is performed by the ATM 1 that scans statuses and submits it to ATM monitoring systems of the Company “X”.
Regarding transaction processing, it is worth underlining that transaction records reporting that biometric authentication 14 occurred on the ATM 1 and the transaction base storage of the Company “X” are processed and displayed in managerial reports.
The system starts operational functions (ATM supervisor), i.e., the operational functions that allow technicians of the Company “X” to diagnose and correct problems on biometric sensors (2, 3 and/or 4), local or remotely.
The system started operational functions, which are sensor error diagnostic, biometric sensor tests (2, 3 and/or 4) and synchronization of biometric keys (28A or 28B), where the sensor error diagnostic provides, in turn, the diagnostic function of the operator menu for biometric sensor error flagging and automatic call for execution of problem correction function (biometric sensor tests); and alteration of diagnostic function of operator menu to flag update error of biometric keys on ATM 1 and automatic call to force the update of keys (28A or 28B).
A second operational function provides biometric sensors tests (2, 3 and/or 4), performed by biometric data capture and validation execution.
And further yet, one last operational function consists on synchronization of biometric keys (28A or 28B) that forces the exchange of biometric keys with the server of the Company “X” and it can be performed automatically or by remote operation.
As seen in
The diagram depicted in
In
The sensor support 30 is connected to the ATM Security Card 32, the biometric sensors 2, 3 and 4 are in turn connected to the respective USB ports 33, 33A and 33B which are in turn connected to the CPU 34.
The CPU 34 also has another USB port 33C which, in turn, receives the connection from the ATM Security Card 32.
The ATM Security Card 32 further connects a set of LEDs 35 indicating 36 the positioning of the palm of the user's hand, which assembly is installed in the sensor holder 30 and is intended to guide the positioning of the palm of the User “U's” hand atop the palm vein 4 biometric sensor.
Finally, the fingerprint (2), finger vein (3) and palm vein (4) sensors are respectively connected to the USB ports 33, 33A and 33B positioned adjacent the CPU 34 of the ATM terminal 1.
The method of biometric ATM authentication 14 applied in self-service terminals can be understood from the observation of
Referring to
Although the invention is detailed, it is important to understand that it does not limit its application to details and stages herein described. The invention is capable of other modalities and being practiced or executed in a variety of methods. It must be understood that the terminology herein applied is for description purposes and not for limitation.
Number | Date | Country | Kind |
---|---|---|---|
10-2014-010137-3 | Apr 2014 | BR | national |
This application is a Continuation-in-Part of U.S. patent application Ser. No. 16/032,631, filed on Jul. 11, 2018 and which is a continuation of U.S. patent application Ser. No. 14/697,852, filed on Apr. 28, 2015 both of which are hereby incorporated by reference in their entirety. This application claims the benefit of Brazilian Application No. 10-2014-010137-3, filed on Apr. 28, 2014 which is hereby incorporated by reference in its entirety.
Number | Date | Country | |
---|---|---|---|
Parent | 14697852 | Apr 2015 | US |
Child | 16032631 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 16032631 | Jul 2018 | US |
Child | 16227640 | US |