IP Library Granted Patent US 7,229,009
Granted Patent B1
US 7,229,009 · App. 11/359,912 · Granted Jun 12, 2007

Automated banking machine component authentication system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,229,009
App. No.
11/359,912
Granted
Jun 12, 2007
Kind
B1
Abstract

An automated banking machine is provided which includes a first component and a second component. The first component is operative generate a first hash of a first identity data and a public key associated with the second component. The first component is operative to encrypt a randomly generated secret key using the public key associated with the second component. The second component is operative to receive at least one message from the first component which includes the encrypted secret key and the first hash. The second component is operative to decrypt the secret key with a private key that corresponds to the public key. The second component is operative to permit information associated with a transaction function to be communicated between the first and second components which is encrypted with the secret key when the first hash is determined by the second component to correspond to the first component.

Claims (64)

1. An automated banking machine comprising:

a computer, wherein the computer includes at least one hardware device, wherein the hardware device includes identity data;

a cash dispenser in operative connection with the computer, wherein the cash dispenser includes an input device, wherein the input device is operative to receive an input through manual operation of the input device;

a safe, wherein the input device of the cash dispenser is located within the safe, wherein the computer is located in the machine outside the safe, wherein the cash dispenser is responsive to an input received through manual operation of the input device carried out within the safe to cause the cash dispenser to accept the identity data of the hardware device, wherein the cash dispenser is operative to establish a secure communication session with the computer responsive to the accepted identity data, wherein the cash dispenser is operative to dispense cash responsive to at least one message received through the secure communication session.

2. The machine according to claim 1 , wherein the cash dispenser includes at least one data store, wherein the cash dispenser is operative to store the received identity data in the at least one data store of the cash dispenser.

3. The machine according to claim 2 , wherein the cash dispenser includes a processor in operative connection with the at least one data store, and wherein the processor is operative to generate at least one authentication value from the identity data, wherein the cash dispenser is operative to establish the secure communication session with the computer responsive to the at least one authentication value.

4. The machine according to claim 1 , wherein the identity data includes at least a portion of a serial number of the hardware device.

5. A method comprising:

a) receiving with an input device located within a safe of an automated banking machine, at least one input responsive to manual operation of the input device carried out within the safe, wherein the automated banking machine includes a cash dispenser;

b) responsive to (a), accepting with the cash dispenser, data associated with of a hardware device of a computer of the automated banking machine, wherein the computer is located outside the safe;

c) establishing a secure communication session between the computer and the cash dispenser responsive to the data accepted in (b); and

d) dispensing cash from the machine through operation of the cash dispenser responsive to at least one message received through the secure communication session.

6. The method according to claim 5 , wherein the cash dispenser includes at least one data store, further comprising:

e) subsequent to (b), storing the data accepted in (b) in the at least one data store of the cash dispenser.

7. The method according to claim 5 , further comprising:

e) subsequent to (b), generating with the cash dispenser, at least one authentication value from the data accepted in (b),

wherein in (c) the cash dispenser is operative to enable the secure communication session to be established with the computer responsive to the at least one authentication value.

8. The method according to claim 5 , wherein the data accepted in (b) includes at least a portion of a serial number of the hardware device.

9. The method according to claim 5 , wherein the safe includes a door, wherein in (a) the door is open.

10. Computer readable media bearing instructions which are operative to cause a computer in an automated banking machine to cause the machine to carry out a method comprising:

a receiving with an input device located within a safe of the automated banking machine, at least one input responsive to manual operation of the input device carried out within the safe, wherein the automated banking machine includes a cash dispenser;

b) responsive to (a), accepting with the cash dispenser, data associated with a hardware device of the computer of the automated banking machine, wherein the computer is located outside the safe;

c) establishing a secure communication session between the computer and the cash dispenser responsive to the data accepted in (b); and

d) dispensing cash from the machine through operation of the cash dispenser responsive to at least one message received through the secure communication session.

11. Apparatus comprising:

an automated banking machine including:

a computer, wherein the computer includes at least one processor;

at least one transaction function device in operative connection with the computer, wherein the at least one transaction function device includes at least one device processor;

a first component operative in the at least one computer, wherein the first component is operative to resolve first identity data; and

a second component in operative connection with the at least one transaction function device;

wherein the first component is operative to cause to be generated at least one first authentication value responsive to the first identity data, wherein the computer responsive to the first component is operative to cause a randomly generated secret key to be generated, wherein the computer is operative to cause the generated secret key to be encrypted using a public key associated with the second component, wherein the computer is operative to cause at least one message to be sent to the second component which at least one message includes the encrypted secret key and the at least one first authentication value, wherein the second component is operative to cause the secret key to be decrypted with a private key that corresponds to the public key, wherein the second component is operative to cause at least one second authentication value and the first authentication value to be analyzed through operation of the at least one device processor to determine if the first authentication value and the second authentication value have a predetermined relationship, wherein responsive to the first authentication value and the second authentication value having the predetermined relationship, the second component is operative to enable the at least one transaction function device to perform a transaction function in response to at least one message received from the computer.

12. The apparatus according to claim 11 , wherein the second component is operative to resolve second identity data, wherein the second component is operative to cause to be generated the at least one second authentication value responsive to the second identity data.

13. The apparatus according to claim 12 , wherein the machine further includes a safe, wherein the transaction function device includes an input device, wherein the input device is located within the safe, wherein the computer is located in the machine outside the safe, wherein the second component is operative responsive to an input received through the input device to accept the first identity data from the computer, wherein the resolved second identity data corresponds to the accepted first identity data.

14. The machine according to claim 13 , wherein the transaction function device includes a cash dispenser, wherein the transaction function includes dispensing cash.

15. The apparatus according to claim 14 , wherein the at least one transaction function device includes at least one data store, wherein the second component is operative to cause the accepted first identity data to be stored in the at least one data store of the at least one transaction function device.

16. The machine according to claim 15 , wherein the computer is in operative connection with at least one component, wherein the at least one component includes the first identity data stored therein.

17. A method comprising:

a) resolving first identity data through operation of a computer in an automated banking machine responsive to at least one component in operative connection with the computer;

b) generating through operation of the computer at least one first authentication value responsive to the first identity data;

c) generating through operation of the computer a randomly generated secret key;

d) encrypting through operation of the computer the secret key using a public key associated with a transaction function device of the automated banking machine;

e) sending at least one message from the computer to the transaction function device which includes the encrypted secret key and the at least one first authentication value;

f) decrypting the secret key with the transaction function device using a private key that corresponds to the public key associated with the transaction function device;

g) analyzing through operation of the transaction function device, the at least one first authentication value and at least one second authentication value and determining that the at least one first authentication value and the at least one second authentication value have a predetermined relationship; and

h) responsive to (g) enabling the transaction function device to perform at least one transaction function in response to at least one encrypted message received from the computer.

18. The method according to claim 17 , wherein prior to (g) further comprising:

i) resolving second identity data with the transaction function device; and

j) generation through operation of the transaction function device, the at least one second authentication hash from the second identity data.

19. The method according to claim 18 , wherein the automated banking machine includes a safe, wherein the transaction function device includes an input device, wherein the input device is located within the safe, wherein the computer is located outside the safe, further comprising:

k) receiving an input through the input device;

l) responsive to (k), accepting with the transaction function device, the first identity data from the computer, wherein in (i) the resolved second identity data corresponds to the accepted first identity data.

20. The method according to claim 19 , wherein in (h) the transaction function device includes a cash dispenser and the transaction function includes dispensing cash.

21. The method according to claim 20 , further comprising:

m) storing the accepted first identity data in at least one data store of the transaction function device.

22. The method according to claim 21 , wherein in (a) the first identity data corresponds to at least a portion of a serial number of the at least one component.

23. Computer readable media bearing instructions which are operative to cause a computer in an automated banking machine to cause the machine to carry out the a method comprising:

a) resolving first identity data through operation of the computer in the automated banking machine responsive to at least one component in operative connection with the computer;

b) generating through operation of the computer at least one first authentication value responsive to the first identity data;

c) generating through operation of the computer a randomly generated secret key;

d) encrypting through operation of the computer the secret key using a public key associated with a transaction function device of the automated banking machine;

e) sending at least one message from the computer to the transaction function device which includes the encrypted secret key and the at least one first authentication value;

f) decrypting the secret key with the transaction function device using a private key that corresponds to the public key associated with the transaction function device;

g) analyzing through operation of the transaction function device, the at least one first authentication value and at least one second authentication value and determining that the at least one first authentication value and the at least one second authentication value have a predetermined relationship; and

h) responsive to (g) enabling the transaction function device to perform at least one transaction function in response to at least one encrypted message received from the computer.

Assignments (20)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: DIEBOLD SELF-SERVICE SYSTEMS
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 069889/0890 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (2025 EUR NOTES REEL/FRAME 053271/0067) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064641/0836 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (2025 USD NOTES REEL/FRAME 053270/0783) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064642/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (NEW TERM LOAN REEL/FRAME 062299/0717) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064642/0288 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (2026 NOTES REEL/FRAME 062299/0794) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064642/0202 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (R/F 062299/0618) Recorded Jun 16, 2023
From: GLAS AMERICAS LLC
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064008/0852 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jun 7, 2023
From: JPMORGAN CHASE BANK, N.A.
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064021/0405 →
RELEASE OF SECURITY INTEREST IN PATENTS INTELLECTUAL PROPERTY Recorded Jan 10, 2023
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: DIEBOLD NIXDORF, INCORPORATED (F/K/A DIEBOLD, INCORPORATED); DIEBOLD SELF-SERVICE SYSTEMS
Reel/Frame 062338/0429 →
NOTICE OF SUCCESSOR AGENT AND ASSIGNMENT OF SECURITY INTEREST (INTELLECTUAL PROPERTY) - EUR NOTES Recorded Jan 6, 2023
From: U.S. BANK TRUSTEES LIMITED, AS RESIGNING AGENT; DIEBOLD NIXDORF, INCORPORATED, AS GRANTOR; DIEBOLD SELF-SERVICE SYSTEMS, AS GRANTOR
To: GLAS AMERICAS LLC, AS THE SUCCESSOR AGENT
Reel/Frame 062308/0587 →
NOTICE OF SUCCESSOR AGENT AND ASSIGNMENT OF SECURITY INTEREST (INTELLECTUAL PROPERTY) - USD NOTES Recorded Jan 6, 2023
From: U.S. BANK NATIONAL ASSOCIATION, AS THE RESIGNING AGENT; DIEBOLD NIXDORF, INCORPORATED, AS GRANTOR; DIEBOLD SELF-SERVICE SYSTEMS, AS GRANTOR
To: GLAS AMERICAS LLC, AS THE SUCCESSOR AGENT
Reel/Frame 062308/0499 →
PATENT SECURITY AGREEMENT - SUPERPRIORITY Recorded Jan 5, 2023
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 062299/0618 →
PATENT SECURITY AGREEMENT - TERM LOAN Recorded Jan 5, 2023
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 062299/0717 →
PATENT SECURITY AGREEMENT - 2026 NOTES Recorded Jan 5, 2023
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 062299/0794 →
SECURITY INTEREST (ABL) Recorded Dec 29, 2022
From: DIEBOLD NIXDORF, INCORPORATED
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 062250/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED ON REEL 044013 FRAME 0486. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE FROM DIEBOLD NIXDORF, INCORPORATED TODIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD NIXDORF, INCORPORATED. Recorded Aug 27, 2020
From: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD, INCORPORATED
To: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 053622/0112 →
SECURITY INTEREST (NOTES) Recorded Jul 21, 2020
From: DIEBOLD NIXDORF, INCORPORATED (F/K/A DIEBOLD, INCORPORATED); DIEBOLD SELF-SERVICE SYSTEMS
To: U.S. BANK TRUSTEES LIMITED
Reel/Frame 053271/0067 →
SECURITY INTEREST (NOTES) Recorded Jul 21, 2020
From: DIEBOLD NIXDORF, INCORPORATED (F/K/A DIEBOLD, INCORPORATED); DIEBOLD SELF-SERVICE SYSTEMS
To: U.S. BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 053270/0783 →
CHANGE OF NAME Recorded Sep 26, 2017
From: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD, INCORPORATED
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 044013/0486 →
PATENT SECURITY AGREEMENT Recorded Aug 17, 2016
From: DIEBOLD, INCORPORATED; DIEBOLD SELF SERVICE SYSTEMS
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 039723/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2006
From: PARSONS, DONALD; EDWARDS, JUDITH; MCCOY, DONALD; BLOCK, JAMES
To: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD, INCORPORATED
Reel/Frame 017603/0806 →