Everything about Personal Identification Number totally explained
A
personal identification number (PIN) is a secret numeric
password shared between a user and a system that can be used to authenticate the user to the system. Typically, the user is required to provide a non-confidential user identifier or token (such as a banking card) and a confidential PIN to gain access to the system. Upon receiving the User ID and PIN, the system looks up the PIN based upon the User ID and compares the looked-up PIN with the received PIN. The user is granted access only when the number entered matches with the number stored in the system.
PINs are most often used for
ATMs but are increasingly used at the
Point of sale, especially for
debit cards. Throughout Europe the traditional in-store credit card signing process is being replaced with a system where the customer is asked to enter their PIN instead of signing. In the UK and Ireland this goes under the term '
Chip and PIN', since PINs were introduced at the same time as
EMV chips on the cards. In other parts of the world, PINs have been used before the introduction of EMV. Apart from financial uses,
GSM mobile phones usually allow the user to enter PIN between 4 and 8 digits length. The PIN is recorded in the
SIM card.
In
2006,
James Goodfellow, the inventor of the personal identification number, was awarded an OBE in the
Queen's Birthday Honours List.
PIN Length
The concept of a PIN originates with the inventor of the
ATM,
John Shepherd-Barron. One day in 1967, while thinking about more efficient ways banks could disburse cash to their customers, it occurred to him that the candy
vending machine model was a proven fit. For
authentication Shepherd-Barron at first envisioned a six-digit numeric code, given what he could reliably remember. His wife however preferred four digits, which became the standard.
PIN Security
Financial PINs are often 4-digit numbers in the range 0000-9999, resulting in 10,000 possible numbers. However, some banks don't give out numbers where all digits are identical (such as 1111, 2222, ...) or consecutive (1234, 2345, ...) or numbers that start with one or more zeroes. Many PIN verification systems allow three attempts, thereby giving a card thief a 1/3333 chance to guess the correct PIN before the card is blocked. This holds only if all PINs are equally likely and the attacker has no further information available, which hasn't been the case with some of the many PIN generation and verification algorithms that banks and ATM manufacturers have used in the past.
If a mobile phone PIN is entered incorrectly three times, the
SIM card is blocked until a
Personal Unblocking Code (PUC), provided by the service operator, is entered. If the PUC is entered incorrectly ten times, the SIM card is permanently blocked, requiring a new SIM card.
In
2002 two PhD students at
Cambridge University,
Piotr Zieliński and
Mike Bond, discovered a security flaw in the PIN generation system of the
IBM 3624, which was duplicated in most later hardware. Known as the
decimalization table attack, the flaw would allow someone who has access to a bank's computer system to determine the PIN for an ATM card in an average of 15 guesses.
English language usage
The term "PIN number" (hence "
personal identification number number") is commonly used, which is an example of
RAS syndrome (Redundant Acronym Syndrome).
Reverse PIN hoax
Rumours have been in e-mail circulation claiming that in the event of entering a PIN into an ATM backwards, police will be instantly alerted as well as money being ordinarily issued as if the PIN had been entered correctly. The intention of this scheme would be to protect victims of muggings; however, despite the
system being proposed for use in some American states, there are no ATMs currently in existence that employ the software.
Further Information
Get more info on 'Personal Identification Number'.
|
External Link Exchanges
Do you know how hard it is to get a link from a large encyclopaedia? Well we're different and will prove it. To get a link from us just add the following HTML to your site on a relevant page:
<a href="http://personal_identification_number.totallyexplained.com">Personal identification number Totally Explained</a>
Then simply click through this link from your web page. Our crawlers will verify your link, extract the title of your web page and instantly add a link back to it. If you like you can remove the words Totally Explained and embed the link in article text.
As long as your link remains in place, we'll keep our link to you right here. Please play fair - our crawlers are watching. Your site must be closely related to this one's topic. Any kind of spamming, dubious practises or removing the link will result in your link from us being dropped and, potentially, your whole site being banned. |