IP Library Granted Patent US 8,474,698
Granted Patent B1
US 8,474,698 · App. 13/335,062 · Granted Jul 2, 2013

Banking system controlled responsive to data bearing records

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,474,698
App. No.
13/335,062
Granted
Jul 2, 2013
Kind
B1
Abstract

An automated banking machine operates to cause financial transfers responsive to data read from data bearing records. The automated banking machine includes a card reader operative to read card data from user cards corresponding to financial accounts. The automated banking machine also includes a display and a printer to produce records of financial transactions carried out with the machine. The machine is operative to cause a computer determination to be made that the card data corresponds to an authorized machine user. The automated banking machine may also include a storage device that is operative to unlock a secured area including information thereon that is used by the automated banking machine to carry out financial transfers.

Claims (29)

1. Apparatus comprising:

an automated banking machine that operates responsive at least in part to data read from data bearing records to cause financial transfers, wherein the automated banking machine includes a plurality of hardware devices including:

a card reader operative to read card data from user cards, wherein the card data corresponds to financial accounts;

a cash dispenser;

an encrypting PIN pad (EPP); and

at least one storage device;

at least one computer processor in operative communication with the card reader, the cash dispenser, the encrypting PIN pad, and the at least one storage device, wherein the at least one computer processor is operative to cause:

a computer determination to be made that card data read from a card corresponds to a financial account concerning which financial transfers are authorized to be conducted through machine operation; and

at least one financial transfer at least one of to the financial account, from the financial account, or any combination thereof, responsive at least in part to the determination;

a trusted platform module (TPM) in operative connection with the at least one computer processor,

wherein the at least one computer processor is operative to use the TPM to encrypt secret data, wherein the at least one computer processor is operative to cause the secret data to be decrypted by the TPM responsive at least in part to a determination that an at least one predetermined component stored in the automated banking machine remains unaltered, wherein the decrypted secret data is usable by at least one of the hardware devices to enable at least one of the hardware devices to facilitate financial transfers with the automated banking machine.

2. The apparatus according to claim 1 , wherein the at least one computer processor is operative to cause the TPM to encrypt the secret data in at least one sealed storage, wherein the sealed storage includes an encrypted file stored on the at least one storage device.

3. The apparatus according to claim 2 , wherein the at least one hardware device that is operative responsive at least in part to the secret data, includes the at least one storage device, wherein the secret data includes an authentication key.

4. The apparatus according to claim 3 , wherein the at least one storage device includes at least one storage device processor, wherein the at least one storage device includes at least one unsecured area and at least one secured area, wherein the at least one storage device processor is operative to use the authentication key to unlock the at least one secured area to enable the at least one computer processor to access information included in the at least one secured area, wherein the at least one storage device processor is operative to enable the at least one computer processor to access the information included in the at least one unsecured area when the at least one secured area is locked and prevented by the at least one storage device processor from being accessed by the at least one computer processor.

5. The apparatus according to claim 4 , further comprising at least one bootloader software component stored on the at least one unsecured area, wherein the automated banking machine is operative to cause the at least one bootloader software component to execute in the at least one computer processor, wherein the at least one bootloader software component is operative to cause the TPM to decrypt the authentication key from the at least one sealed storage, wherein the at least one bootloader software component is operative to cause the authentication key decrypted by the TPM to be sent to the at least one storage device processor to cause the at least one secured area to be unlocked.

6. The apparatus according to claim 5 , wherein the at least one secured area includes a plurality of encrypted operating system software components and a plurality of encrypted automated banking machine software components, wherein the at least one storage device processor is operative to decrypt the operating system software components and the automated banking machine software components included in the at least one secured area using a symmetrical key responsive at least in part to the at least one secured area being unlocked.

7. The apparatus according to claim 6 , wherein the at least one bootloader software component is operative to cause at least a portion of the operating system software components to be validated, and is operative to cause the at least one computer processor to initiate booting of at least one of the operating system software components by the at least one computer processor.

8. The apparatus according to claim 7 , wherein the TPM includes a plurality of platform configuration registers (PCRs), wherein the computer processor is operatively configured to cause at least one of the PCRs to be extended with a measurement of the at least one predetermined component, wherein the at least one bootloader software component is operative to cause the TPM to decrypt the authentication key from, the at least one sealed storage responsive at least in part to data stored in the at least one PCR, which data matches data previously stored in the at least one PCR when the at least one sealed storage was generated.

9. The apparatus according to claim 8 , wherein the at least one predetermined component includes at least one of a BIOS, an extensible firmware interface (EFI), a unified EFI (UEFI), or any combination thereof.

10. The apparatus according to claim 9 , wherein the at least one predetermined component corresponds to a plurality of predetermined components, wherein the computer processor is operatively configured to cause the at least one PCR to be extended with respective measurements of each of the respective predetermined components, wherein the at least one bootloader software component is operative to cause the TPM to decrypt the authentication key from the at least one sealed storage responsive at least in part to data stored in the at least one PCR with respect to the plurality of predetermined components, which data matches data previously stored in the at least one PCR when the at least one sealed storage was generated, wherein the predetermined components include the at least one bootloader software component.

11. The apparatus according to claim 10 , further comprising at least one policy file included in the at least one secured area, wherein the at least one policy file includes a list of software components to validate, wherein the at least one bootloader software component is operative to cause at least one of the portion of the operating system software components, a portion of the automated banking machine software components, or any combination thereof to be validated responsive at least in part to the at least one policy file.

12. The apparatus according to claim 11 , wherein the at least one bootloader software component is operative to validate the at least one policy file.

13. The apparatus according to claim 10 , wherein the at least one bootloader software component includes a boot manager software component, wherein the automated banking machine includes at least one display device and at least one input device, wherein the boot manager software component is operative to cause the computer processor to cause the at least one display device to output a user interface, wherein the user interface includes a plurality of user selectable options selectable via inputs through the at least one input device, wherein the user selectable options correspond to a plurality of respective functions of the at least one bootloader software component that are operative to configure the at least one storage device.

14. The apparatus according to claim 13 , wherein the predetermined components include the boot manager software component.

15. The apparatus according to claim 14 , wherein the automated banking machine includes at least one port in operative connection with the at least one computer processor, wherein the boot manager software component is operative to output a message that prompts a user to input a password through operation of the at least one input device, wherein responsive at least in part to at least one token device in operative connection with the at least one port and an input of the password through operation of the at least one input device, the boot manager software component is operative to cause the at least one computer processor to cause the at least one display device to output the user interface.

16. The apparatus according to claim 15 , wherein the plurality of user selectable options include at least one function of the at least one bootloader software component that is operative to cause the at least one computer processor to at least one of backup information, restore information, or any combination thereof to the at least one secured area of the at least one storage device.

17. The apparatus according to claim 15 , wherein the at least one token device includes a further authentication key, wherein the boot manager software component is operative responsive at least in part to the at least one token device in operative connection with the at least one port and the further authentication key to cause the at least one computer processor to cause the at least one display device to output a user selectable option associated with pairing the at least one storage device to the at least one computer processor, wherein the at least one bootloader software component is operative to cause the at least one computer processor to use the TPM to generate the at least one sealed storage responsive at least in part to selection of the user selectable option associated with pairing the at least one storage device to the at least one computer processor.

18. The apparatus according to claim 17 , wherein the boot manager software component is operative to cause the computer processor to cause the at least one display device to output challenge data, wherein the boot manager software component is operative to output a message through the display device that prompts a user to input response data through operation of the at least one input device, wherein the at least one boot manager software component is operative responsive at least in part to the challenge data and the response data to generate a further authentication key that is usable to be communicated to the at least one storage to device to cause the at least one storage device to unlock the at least one secured area.

19. The apparatus according to claim 15 , further comprising a bootloader restoration software component, wherein the bootloader restoration software component is operative to cause the at least one computer processor to write at least a portion of the at least one bootloader software component on a master boot record of the at least one storage device.

Assignments (24)
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT RECORDED AT R/F 066599/0767 Recorded Dec 19, 2024
From: PNC BANK, NATIONAL ASSOCIATION, AS AGENT
To: DIEBOLD SELF-SERVICE SYSTEMS; DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 069743/0497 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 066545/0078 Recorded Dec 19, 2024
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 069743/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 6, 2024
From: DIEBOLD SELF-SERVICE SYSTEMS
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 069532/0253 →
SECURITY INTEREST Recorded Feb 14, 2024
From: DIEBOLD NIXDORF, INCORPORATED; DIEBOLD SELF-SERVICE SYSTEMS
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 066599/0767 →
SECURITY INTEREST Recorded Feb 9, 2024
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 066545/0078 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (2025 EUR NOTES REEL/FRAME 053271/0067) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064641/0836 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (2025 USD NOTES REEL/FRAME 053270/0783) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064642/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (2026 NOTES REEL/FRAME 062299/0794) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064642/0202 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (NEW TERM LOAN REEL/FRAME 062299/0717) Recorded Aug 18, 2023
From: GLAS AMERICAS LLC, AS COLLATERAL AGENT
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064642/0288 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (R/F 062299/0618) Recorded Jun 16, 2023
From: GLAS AMERICAS LLC
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064008/0852 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jun 7, 2023
From: JPMORGAN CHASE BANK, N.A.
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 064021/0405 →
RELEASE OF SECURITY INTEREST IN PATENTS INTELLECTUAL PROPERTY Recorded Jan 10, 2023
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: DIEBOLD NIXDORF, INCORPORATED (F/K/A DIEBOLD, INCORPORATED); DIEBOLD SELF-SERVICE SYSTEMS
Reel/Frame 062338/0429 →
NOTICE OF SUCCESSOR AGENT AND ASSIGNMENT OF SECURITY INTEREST (INTELLECTUAL PROPERTY) - USD NOTES Recorded Jan 6, 2023
From: U.S. BANK NATIONAL ASSOCIATION, AS THE RESIGNING AGENT; DIEBOLD NIXDORF, INCORPORATED, AS GRANTOR; DIEBOLD SELF-SERVICE SYSTEMS, AS GRANTOR
To: GLAS AMERICAS LLC, AS THE SUCCESSOR AGENT
Reel/Frame 062308/0499 →
NOTICE OF SUCCESSOR AGENT AND ASSIGNMENT OF SECURITY INTEREST (INTELLECTUAL PROPERTY) - EUR NOTES Recorded Jan 6, 2023
From: U.S. BANK TRUSTEES LIMITED, AS RESIGNING AGENT; DIEBOLD NIXDORF, INCORPORATED, AS GRANTOR; DIEBOLD SELF-SERVICE SYSTEMS, AS GRANTOR
To: GLAS AMERICAS LLC, AS THE SUCCESSOR AGENT
Reel/Frame 062308/0587 →
PATENT SECURITY AGREEMENT - SUPERPRIORITY Recorded Jan 5, 2023
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 062299/0618 →
PATENT SECURITY AGREEMENT - TERM LOAN Recorded Jan 5, 2023
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 062299/0717 →
PATENT SECURITY AGREEMENT - 2026 NOTES Recorded Jan 5, 2023
From: DIEBOLD NIXDORF, INCORPORATED
To: GLAS AMERICAS LLC, AS COLLATERAL AGENT
Reel/Frame 062299/0794 →
SECURITY INTEREST (ABL) Recorded Dec 29, 2022
From: DIEBOLD NIXDORF, INCORPORATED
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 062250/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED ON REEL 044013 FRAME 0486. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE FROM DIEBOLD NIXDORF, INCORPORATED TODIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD NIXDORF, INCORPORATED. Recorded Aug 27, 2020
From: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD, INCORPORATED
To: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 053622/0112 →
SECURITY INTEREST (NOTES) Recorded Jul 21, 2020
From: DIEBOLD NIXDORF, INCORPORATED (F/K/A DIEBOLD, INCORPORATED); DIEBOLD SELF-SERVICE SYSTEMS
To: U.S. BANK TRUSTEES LIMITED
Reel/Frame 053271/0067 →
SECURITY INTEREST (NOTES) Recorded Jul 21, 2020
From: DIEBOLD NIXDORF, INCORPORATED (F/K/A DIEBOLD, INCORPORATED); DIEBOLD SELF-SERVICE SYSTEMS
To: U.S. BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 053270/0783 →
CHANGE OF NAME Recorded Sep 26, 2017
From: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD, INCORPORATED
To: DIEBOLD NIXDORF, INCORPORATED
Reel/Frame 044013/0486 →
PATENT SECURITY AGREEMENT Recorded Aug 17, 2016
From: DIEBOLD, INCORPORATED; DIEBOLD SELF SERVICE SYSTEMS
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 039723/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2012
From: BILLETT, NICK; CRALLIE, CHARLES E.; HARRIS, RICHARD; CLUGSTON, ANDREW; KONECNY, ANNE; CREWS, TIM; EDWARDS, JUDITH
To: DIEBOLD SELF-SERVICE SYSTEMS DIVISION OF DIEBOLD, INCORPORATED
Reel/Frame 027729/0239 →