Professional Documents
Culture Documents
Chapter 10 ATM
Chapter 10 ATM
ATMs
An
Chapter 10 ATM
module implemented in
tamper-resistant hardware
o IBM 4758 crypto processor
o Security module is at bank
o All crypto computations done in security
Chapter 10 ATM
Chapter 10 ATM
Chapter 10 ATM
8807012345691715
FEFEFEFEFEFEFEFE
A2CE126C69AEC82D
0224126269042823
0224
6565
6789
Problems
Early on, encryption done in software
Not feasible for all pairs of banks to share
keys, so KDC used (VISA)
Large number of trans, so corners cut
Chapter 10 ATM
Chapter 10 ATM
Unexpected Attacks
Shoulder surfing to get PIN, copy acct
number from receipt
One system --- telephone calling card, ATM
thought previous card inserted
One system --- output 10 bills when 14digit test sequence entered
One bank issued same PIN to everybody
Fake ATM to collect PINs
Steal the ATM (camera is inside ATM)
Chapter 10 ATM
ATMs
Biggest
Chapter 10 ATM
Chapter 10 ATM
Chapter 10 ATM