Method, recording medium, apparatus and system for preventing fraud order

By implementing a unique counter value system with hash value verification and time interval checks for NFC or QR tags, the issue of false orders in unattended ordering systems is addressed, ensuring accurate and secure ordering processes.

WO2025150679A1PCT designated stage expired Publication Date: 2025-07-17COUPANG CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/017277
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-12
Filing Date
2024-11-05
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Unattended ordering systems in stores are vulnerable to false orders due to exploitation of NFC or QR tags, leading to operational confusion, inventory waste, and financial loss.

Method used

Incorporating a unique counter value in access information generated by tagging a user terminal for a tag, verifying the validity of requests through hash values and time intervals, and ensuring each tag has a unique value to prevent false orders.

Benefits of technology

Prevents false orders while allowing multiple users to order within a store or at a table, maintaining order accuracy and reducing operational and financial losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024017277_17072025_PF_FP_ABST
    Figure KR2024017277_17072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method, a recording medium, an apparatus, and a system for preventing a fraud order. The method according to an embodiment of the present disclosure is performed by an electronic apparatus and may comprise the steps of: acquiring, from a user terminal, a first request for requesting a web page related to a product order, the first request being performed on the basis of access information generated by first tagging of the user terminal for a tag; determining whether or not the first request is valid; and providing the web page to the user terminal, according to the determination that the first request is valid.
Need to check novelty before this filing date? Find Prior Art

Description

Methods, recording media, devices and systems for preventing false orders

[0001] The present disclosure relates to a method, recording medium, device and system for preventing false orders for products ordered using tags, etc. in a store.

[0002] With the recent advancement of e-commerce, more and more places, such as restaurants, are enabling table-level unmanned ordering. For example, some stores allow customers to place orders using their smartphones or other user devices, eliminating the need for separate devices like kiosks, by attaching or installing NFC tags or QR tags (codes) to each table. By implementing unmanned ordering in these stores, customers can conveniently place orders, and store staff can accurately and conveniently confirm customer orders.

[0003] However, in this case, there is a risk of exploitation of NFC or QR tags. For example, a customer may receive a URL through tagging an NFC tag, tagging or duplicating a QR tag, or duplicating the URL itself, and then place an order outside the store after leaving. If a fraudulent order occurs, the store may experience operational disruption, loss of personnel (e.g., inventory waste), and financial losses. Therefore, technologies are needed to minimize these risks by preventing fraudulent orders and strengthen the security of the ordering system.

[0004] A technical problem to be solved through one embodiment of the present disclosure is that, in ordering a product in a store, a counter value is included in access information generated by tagging of a user terminal to a tag, and a unique counter value is provided for each access information, so that it can be used to determine whether an order is false.

[0005] Another technical problem to be solved through one embodiment of the present disclosure is to enable each tag to have a unique value, include the unique value in the access information, and verify it so that it can be used to determine whether or not an order is false.

[0006] Another technical problem to be solved by one embodiment of the present disclosure is to enable two or more people to order within a store or at a table within a store while preventing false orders.

[0007] The technical problems of the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art of the present disclosure from the description below.

[0008] A method performed by an electronic device according to one embodiment of the present disclosure may include the steps of: obtaining a first request for a web page related to a product order from a user terminal, wherein the first request is performed based on connection information generated by a first tagging of the user terminal for a tag; determining whether the first request is valid; and providing the web page to the user terminal based on a determination that the first request is valid.

[0009] In one embodiment, the connection information includes a first hash value for a first counter value according to the first tagging and a second hash value for a unique value of the tag, the first request includes information about the first hash value and information about the second hash value, and the first counter value may be a counter value according to the first tagging for the tag.

[0010] In one embodiment, the connection information may further include a third hash value for identification information identifying the store where the tag is located or a table within the store, and the first request may further include information regarding the third hash value.

[0011] In one embodiment, the step of determining whether the first request is valid may include: obtaining the first counter value based on a pre-stored hash value for the first hash value and the first counter value; obtaining the identification information based on the pre-stored hash value for the third hash value and the identification information; identifying a second request having the same identification information as the identification information, which was received prior to the first request and determined to be valid; determining whether the first counter value is a recent value that has increased from a second counter value corresponding to the second request; and determining that the first request is valid based on a determination that the first counter value is the recent value.

[0012] In one embodiment, the step of determining that the first request is valid based on a determination that the first counter value is the most recent value may include the step of determining whether the second hash value and a pre-stored hash value for the unique value are identical; and the step of determining that the first request is valid based on a determination that the second hash value and a pre-stored hash value for the unique value are identical.

[0013] In one embodiment, the method may include: determining whether a time interval between the time of obtaining the first request and the second request is less than or equal to a predetermined grace time interval based on a determination that the first counter value is not the most recent value; and determining that the first request is valid based on a determination that the time interval is less than or equal to the predetermined grace time interval.

[0014] In one embodiment, the step may include determining that the first request is invalid based on a determination that the time interval exceeds the predetermined grace time interval.

[0015] In one embodiment, the method may include: obtaining information indicating a number of digits available in a table identified by the identification information based on a determination that the first counter value is not the most recent value; determining whether a difference between the first counter value and the second counter value is less than the number of digits; and determining that the first request is valid based on a determination that the difference between the first counter value and the second counter value is less than the number of digits.

[0016] In one embodiment, the first request further includes information indicating a time point at which the connection information is generated, and the step of determining whether the first request is valid may include the step of determining whether a time interval between a time point at which the connection information is generated and a time point at which the first request is obtained is greater than or equal to a predetermined waiting time interval; and the step of determining that the first request is invalid based on a determination that the time interval is greater than or equal to the predetermined waiting time interval.

[0017] In one embodiment, the tag includes at least one of a Near-Field Communication (NFC) tag or a QR code, and can be recognized by the user terminal through short-range communication.

[0018] In one embodiment, the QR code may be updated at predetermined time intervals as a digital QR code.

[0019] In one embodiment, the connection information may be a Uniform Resource Locator (URL) of the web page.

[0020] In one embodiment, the predetermined grace period may be from 1 minute to 5 minutes.

[0021] A non-transitory computer-readable recording medium according to one embodiment of the present disclosure records instructions to be executed by one or more processors, and the instructions may be configured to cause the one or more processors to perform any one of the above-described methods when the instructions are executed.

[0022] An electronic device according to one embodiment of the present disclosure comprises: a communication interface configured to communicate with at least one user terminal; one or more processors; and one or more memories storing instructions to be executed by the one or more processors, wherein, upon execution of the instructions, the one or more processors may be configured to perform any one of the above-described methods.

[0023] A system according to one embodiment of the present disclosure may include at least one user terminal; a tag recognizable by the at least one user terminal; and the electronic device described above configured to transmit and receive data with the at least one user terminal.

[0024] According to the present disclosure, in ordering products in a store, a counter value is included in the access information generated by tagging of a user terminal to a tag, and a unique counter value is provided for each access information, thereby making it possible to determine whether a false order is made.

[0025] According to the present disclosure, by assigning a unique value to each tag, including the unique value in the access information, and verifying this, it is possible to determine whether or not a false order has been placed.

[0026] According to the present disclosure, it is possible to prevent false orders while allowing two or more people to order within a store or at a table within a store.

[0027] The effects according to the technical idea of ​​the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description of the specification.

[0028] FIG. 1 illustrates an environment in which an electronic device according to one embodiment of the present disclosure can be applied.

[0029] FIG. 2 is a block diagram of an electronic device according to one embodiment of the present disclosure.

[0030] FIG. 3 is a configuration diagram of connection information according to one embodiment of the present disclosure.

[0031] Figure 4 is a flowchart illustrating a method according to one embodiment of the present disclosure.

[0032] Figure 5 is a flowchart illustrating a method according to one embodiment of the present disclosure.

[0033] The various embodiments described in this disclosure are exemplified for the purpose of clearly explaining the technical concept of this disclosure and are not intended to be limited to specific embodiments. The technical concept of this disclosure includes various modifications, equivalents, alternatives, and embodiments selectively combined from all or part of the embodiments described in this disclosure. Furthermore, the scope of the technical concept of this disclosure is not limited to the various embodiments presented below or the specific descriptions thereof.

[0034] Terms used in this disclosure, including technical or scientific terms, unless otherwise defined, may have the meaning commonly understood by a person of ordinary skill in the art to which this disclosure belongs.

[0035] The expressions "includes," "may include," "comprises," "may have," "have," and "may have" used in this disclosure indicate the presence of a target feature (e.g., a function, operation, or component), but do not exclude the presence of other additional features. In other words, such expressions should be understood as open-ended terms that imply the possibility of including other embodiments.

[0036] The singular expressions used in this disclosure may include the plural meaning unless the context clearly indicates otherwise, and the same applies to the singular expressions set forth in the claims.

[0037] The expressions "first," "second," or "first", "second", etc. used in this document, unless the context indicates otherwise, are used to refer to multiple similar objects and to distinguish one object from another, and do not limit the order or importance among the objects.

[0038] As used herein, the expressions "A, B, and C", "A, B, or C", "A, B, and / or C", or "at least one of A, B, and C", "at least one of A, B, or C", "at least one of A, B, and / or C", etc., may refer to each of the listed items or to all possible combinations of the listed items. For example, "at least one of A or B" may refer to (1) at least one A, (2) at least one B, (3) at least one A and at least one B.

[0039] The expression "based on" as used in this disclosure is used to describe one or more factors that influence a decision, act of judgment, or action described in a phrase or sentence containing this expression, and this expression does not exclude additional factors that influence the decision, act of judgment, or action.

[0040] As used herein, the expression that a component (e.g., a first component) is “connected” or “connected” to another component (e.g., a second component) may mean that the component is directly connected or connected to the other component, as well as connected or connected via a new other component (e.g., a third component).

[0041] The expression "configured to" used in the present disclosure may have the meanings of "set to", "having the ability to", "modified to", "made to", "capable of", etc., depending on the context. This expression is not limited to the meaning of "specifically designed in hardware", and for example, a processor configured to perform a specific operation may mean a general purpose processor that can perform the specific operation by executing software, or a special purpose computer that is structured through programming to perform the specific operation.

[0042] The term "web page" used in this disclosure may mean a tangible or intangible space that serves as a basis for users' use by integrating and managing services related to product ordering, and may also be interchangeably referred to as "platform," "software," "application," or "solution" in a comprehensive manner, although there may be differences in the specific meanings thereof.

[0043] Hereinafter, various embodiments of the present disclosure will be described with reference to the attached drawings. In the attached drawings and the description of the drawings, identical or substantially equivalent components may be assigned the same reference numerals. Furthermore, in the description of various embodiments below, duplicate descriptions of identical or corresponding components may be omitted, but this does not mean that such components are not included in the embodiments.

[0044] FIG. 1 illustrates an environment in which an electronic device according to one embodiment of the present disclosure can be applied.

[0045] The electronic device (110) is connected to a user terminal (120) via a network and can communicate with each other. In addition, the user terminal (120) may be composed of, for example, at least one user terminal (120) and may acquire access information for accessing a web page related to a product order by tagging a tag (130) attached to a table in a store. The tag (130) includes at least one of an NFC (Near-Field Communication) tag and a QR code and can be recognized by the user terminal (120) through short-range communication. The type of tag (130) is not limited thereto and may be configured in various ways within the scope of the problem to be solved by the present invention.

[0046] The electronic device (110) may be a device for managing e-commerce services. For example, e-commerce services may refer to unmanned ordering services where products (e.g., food, etc.) are purchased (ordered) within a store (e.g., a restaurant, etc.). The electronic device (110) may be a device for managing web pages that provide e-commerce services. The electronic device (110) may configure various information as web pages on a website (web page) or application and provide them to the user terminal (120). Specifically, the electronic device (110) may be a device that provides various information related to product sales to the user terminal (120), provides products purchased (ordered) by the user terminal (120) to the store manager or staff, and prepares the products. In addition, the electronic device (110) may obtain a connection request from the user terminal (120) and verify the validity of the connection request using various methods described below.

[0047] The user terminal (120) may be a device for a user to purchase (order) a product using an e-commerce service. The user terminal (120) may be implemented as a terminal capable of transmitting and receiving various information with the electronic device (110) via a network. For example, the user terminal (120) may be one of a computer, a laptop, a portable communication terminal (such as a smartphone), a portable multimedia device, a wearable device, or an HMD. However, the type of the user terminal (120) is not limited thereto, and the user terminal (120) may be any device that includes an input / output interface capable of receiving information from a user or outputting information to a user, and that can communicate with the electronic device (110) or other devices via a network.

[0048] The user terminal (120) can provide information received from the electronic device (110) to the user, and can receive input from the user and transmit it to the electronic device (110). Specifically, the user terminal (120) can obtain inputs from the user to call various pages, and generate commands to call various pages in response to the obtained inputs. The user terminal (120) can transmit commands to the electronic device (110) to instruct the calling of various pages. The input obtained from the user can include various forms of input, such as touch using a touch pad or touch screen, voice recognition, clicks using a mouse, and other electronic inputs. The user terminal (120) can receive various pages from the electronic device (110) and output the received various pages.

[0049] A network may serve to connect an electronic device (110) and a user terminal (120) or other external device. For example, the network may provide a connection path so that a user terminal (120) can be connected to the electronic device (110) and transmit and receive packet data with the electronic device (110). The network may be implemented as any type of wired or wireless network, such as a local area network (LAN), a wide area network (WAN), a mobile radio communication network, or Wibro (Wireless Broadband Internet).

[0050] FIG. 2 is a block diagram of an electronic device according to one embodiment of the present disclosure.

[0051] An electronic device (200) can process information regarding an e-commerce service. In one embodiment, the electronic device (200) may include one or more processors (210), one or more memories (220), and a communication interface (230) as components. In one embodiment, at least one of the components of the electronic device (200) may be omitted, or another component may be added to the electronic device (200). In one embodiment, additionally or alternatively, some of the components may be implemented in an integrated manner or implemented as a single or multiple entities. In the present disclosure, one or more processors (210) may be referred to as a processor (210). The expression “processor (210)” may mean a set of one or more processors, unless the context clearly indicates otherwise. In the present disclosure, one or more memories (220) may be referred to as a memory (220). The expression "memory (220)" may mean a set of one or more memories, unless the context clearly indicates otherwise. In one embodiment, at least some of the components inside / outside the electronic device (200) may be connected to each other via a bus, a General Purpose Input / Output (GPIO), a Serial Peripheral Interface (SPI), or a Mobile Industry Processor Interface (MIPI), and may exchange information (data, signals, etc.).

[0052] The processor (210) may control at least one component of an electronic device (200) connected to the processor (210) by running software (e.g., commands, programs, etc.). In addition, the processor (210) may perform various operations related to the present disclosure, such as calculations, processing, data generation, and processing. In addition, the processor (210) may load data from or store data in the memory (220). In one embodiment, the processor (210) may control the communication interface (230) to request various types of information from a user terminal (120), an e-commerce server, etc., and receive various types of information from the user terminal (120), the e-commerce server, etc.

[0053] The processor (210) can generate a page related to an e-commerce service and provide information about the generated page to the user terminal (120). For example, the page provided by the processor (210) may include a page regarding the types of products (e.g., food, etc.) offered by a store (e.g., restaurant, etc.), a page for ordering a product selected by the user, etc. In addition, the page provided by the processor (210) may also include a page for paying for a product ordered by the user, if necessary. The page provided by the processor (210) is not limited thereto and may be configured in various ways within the scope of the problem to be solved by the present invention.

[0054] The memory (220) can store various information (data). The information stored in the memory (220) is information acquired, processed, or used by at least one component of the electronic device (200), and may include software (e.g., commands, programs, etc.). The memory (220) may include volatile and / or non-volatile memory. In the present disclosure, the commands or programs are software stored in the memory (220), and may include an operating system for controlling the resources of the electronic device (200), an application, and / or middleware for providing various functions to the application so that the application can utilize the resources of the electronic device (200). In one embodiment, the memory (220) may store commands that, when executed by the processor (210), cause the processor (210) to perform operations. The memory (220) may store at least a portion of information received from a database via the communication interface (230) and / or information transmitted to the database via the communication interface (230). Specifically, the memory (220) can store information regarding an e-commerce service and commands executed by the processor (210). In addition, the memory (220) can store, for example, connection information, etc., which will be described later.

[0055] The communication interface (communication interface, 230) can perform wireless or wired communication between the electronic device (200) and a database or other external electronic device. For example, the communication interface (230) can perform wireless communication according to a method such as eMBB (enhanced Mobile Broadband), URLLC (Ultra Reliable Low-Latency Communications), MMTC (Massive Machine Type Communications), LTE (Long-Term Evolution), LTE-A (LTE Advance), NR (New Radio), UMTS (Universal Mobile Telecommunications System), GSM (Global System for Mobile communications), CDMA (Code Division Multiple Access), WCDMA (Wideband CDMA), WiBro (Wireless Broadband), WiFi (Wireless Fidelity), Bluetooth (Bluetooth), NFC (Near Field Communication), GPS (Global Positioning System), or GNSS (Global Navigation Satellite System). For example, the communication interface (230) may perform wired communication according to a method such as Universal Serial Bus (USB), High Definition Multimedia Interface (HDMI), Recommended Standard-232 (RS-232), or Plain Old Telephone Service (POTS). In one embodiment, the electronic device (200) may be implemented by being integrated with another device. In this case, the communication interface (230) may function as a connection circuit or interface connecting the electronic device (200) and the other device.

[0056] According to one embodiment of the present invention, the processor (210) of the electronic device (110) may obtain a first request requesting a web page related to a product order from the user terminal (120). Here, the first request may be performed based on access information generated by the first tagging of the user terminal (120) with respect to the tag. For example, when the tag (130) is tagged by the user terminal (120), access information for accessing the web page may be provided to the user terminal (120), and when the corresponding access information is selected by the user terminal (120), the first request requesting the web page may be provided to the electronic device (110).

[0057] FIG. 3 is a configuration diagram of connection information according to one embodiment of the present disclosure.

[0058] According to one embodiment of the present invention, the connection information may be, for example, a Uniform Resource Locator (URL) of a web page. Specifically, the connection information may include a first hash value (310) for a first counter value according to the first tagging and a second hash value (320) for a unique value of the tag (130). Here, the first counter value is a counter value according to the first tagging of the tag (130), and may be configured as a value that increases (for example, increases by 1) each time the tag (130) is tagged by the user terminal (120), and this counter value may be calculated as a hash value to configure the first hash value (310). In addition, the unique value of the tag (130) may be configured as a value corresponding to a signature by a private key, for example, and this unique value may be calculated as a hash value to configure the second hash value (320). The first request may include information about a first hash value (310) and information about a second hash value (320).

[0059] Furthermore, according to one embodiment of the present invention, the access information may further include a third hash value (330) for identification information that identifies the store or table within the store where the tag (130) is located. Here, the identification information is information for distinguishing orders performed by the user terminal (120) from each other, and may be distinguished by store or table within the store. If the identification information is distinguished by store, for example, for fast food orders performed at a quick-service restaurant, the validity verification or authenticity determination of the first request, as described below, may be performed. Furthermore, if the identification information is distinguished by table within the store, the validity verification or authenticity determination of the first request, as described below, may be performed for product orders performed at each table. This identification information may be calculated as a hash value to constitute the third hash value (330). Furthermore, the first request may further include information regarding the third hash value (330).

[0060] According to one embodiment of the present invention, in connection information, each time a tag (130) is tagged by a user terminal (120), a counter value increases (changes), and the increased (changed) counter value, the unique value of the tag (130), and identification information regarding the order can each be calculated as a hash value. Accordingly, each time a tag (130) is tagged by a user terminal (120), new connection information (e.g., URL), i.e., unique connection information having a different address string, can be generated.

[0061] According to one embodiment of the present invention, the processor (210) may determine whether the first request described above is valid, and provide a web page to the user terminal (120) based on the determination that the first request is valid. Specifically, in determining whether the first request is valid, the processor (210) may obtain a first counter value based on a first hash value (310) included in the first request and a hash value stored in advance for the first counter value, and may obtain identification information based on a third hash value (330) included in the first request and a hash value stored in advance for the identification information. For example, the first hash value (310) included in the first request and a hash value stored in advance for the first counter value may be compared, and the first counter value may be obtained based on a determination that the two hash values ​​are identical. Additionally, for example, the identification information can be obtained by comparing the third hash value (330) included in the first request with a hash value stored in advance for the identification information, and determining that the two hash values ​​are identical.

[0062] Next, the processor (210) may identify a second request having the same identification information as the aforementioned identification information, which was received and determined to be valid prior to the first request. This may, for example, refer to a second request made by a user terminal of a user who visited and placed an order for a product prior to the user terminal (120) that sent the first request, at a specific table within the store where the first request was made.

[0063] Next, the processor (210) may determine whether the first counter value is a latest value increased from the second counter value corresponding to the second request, and may determine that the first request is valid based on the determination that the first counter value is a latest value. For example, if the second counter value corresponding to the second request is 10 and the first counter value corresponding to the first request is 11, and if the first counter value (i.e., 11) is a latest value received as the first request, the first request may be determined to be valid. In addition, for example, if the second counter value corresponding to the second request is 10 and the first counter value corresponding to the first request is 12, and a request corresponding to the counter value 11 has not been acquired by the electronic device (110), if the first counter value (i.e., 12) is a latest value received as the first request, the first request may be determined to be valid.

[0064] Also, for example, there may be a case where the second counter value corresponding to the second request is 12, and the first counter value corresponding to the first request is 11. That is, the tag (130) is first tagged by the user terminal (120) generating the first request to generate the first counter value (i.e., 11), and then is tagged by the user terminal generating the second request to generate the second counter value (i.e., 12), but there may be a case where the second request is acquired by the electronic device (110) before the first request. In this case, since the first counter value is neither an increased value from the second counter value nor a recent value, it may be determined that the first request corresponding to the first counter value is invalid. This will be described in detail later.

[0065] According to one embodiment of the present invention, in determining that the first request is valid based on a determination that the first counter value is a recent value, the processor (210) may determine whether the second hash value (320) included in the first request is the same as a hash value pre-stored for the unique value, and may determine that the first request is valid based on a determination that the second hash value (320) is the same as a hash value pre-stored for the unique value. Alternatively, the configuration for determining whether the second hash value (320) included in the first request is the same as a hash value pre-stored for the unique value, and the configuration for determining that the first request is valid based on a determination that the second hash value (320) is the same as a hash value pre-stored for the unique value, may be performed together with at least one of the configuration for obtaining the first counter value described above or the configuration for obtaining the identification information. By verifying whether the second hash value (320) is the same, it is possible to determine whether the signature by the private key is the same, and thereby determine whether the first request is due to forgery or duplication of the tag (130).

[0066] According to one embodiment of the present invention, upon determining that the first counter value is not a recent value, the processor (210) may determine whether a time interval between the time of obtaining the first request and the second request is less than or equal to a predetermined grace time interval, and upon determining that the time interval is less than or equal to the predetermined grace time interval, determine that the first request is valid. For example, there may be a case where the second counter value corresponding to the second request is 12, and the first counter value corresponding to the first request is 11. That is, although the tag (130) is first tagged by the user terminal (120) generating the first request to generate the first counter value (i.e., 11), and then tagged by the user terminal generating the second request to generate the second counter value (i.e., 12), there may be a case where the second request is obtained by the electronic device (110) before the first request. In this case, the first counter value may not be a value that has increased from the second counter value, nor may it be a recent value.

[0067] In this case, it is determined whether the time interval between the time of obtaining the first request and the second request is less than or equal to a predetermined grace period, and if it is determined that the time interval is less than or equal to the predetermined grace period, the first request may be determined to be valid. Specifically, the predetermined grace period may be 1 minute to 5 minutes, and an appropriate time interval may be selected from among these. For example, if the predetermined grace period is 1 minute, the second request may be determined to be valid if it has a second counter value corresponding to a recent value (i.e., 12), and if the first request corresponding to the first counter value (i.e., 11) is obtained within 1 minute of obtaining the second request, the first request may also be determined to be valid. This can be utilized when two or more users place orders within a store or at a table within a store. For example, consider a case where users A and B sit at a table and order food. In this case, even if user A tags a tag (130) with a user terminal, then user B tags a tag (130) with a user terminal, and then user B first selects a URL generated on the user terminal to access the web page, if user A selects the URL generated on the user terminal within 1 minute thereafter, user A can also be allowed to access the web page.

[0068] According to one embodiment of the present invention, if the time interval exceeds a predetermined grace period, the processor (210) may determine that the first request is invalid. Continuing with the example above, if the predetermined grace period is 1 minute, the second request is determined to be valid because it has a second counter value (i.e., 12) corresponding to a recent value, and if the first request is obtained more than 1 minute after the time at which the second request was obtained, the first request may be determined to be invalid. For example, if user A tags a tag (130) with a user terminal, then user B tags a tag (130) with a user terminal, and then user B first selects a URL generated on the user terminal to access a web page, and if user A selects a URL generated on the user terminal more than 1 minute after that, access to the web page may not be permitted. In this case, a message may be provided to user A's user terminal (120) to tag the tag (130) again. In this way, it is possible to prevent a situation where a user places a false order outside the store by simply tagging the tag (130) with a user terminal and receiving a URL to the user terminal.

[0069] According to one embodiment of the present invention, upon determining that the first counter value is not a recent value, the processor (210) may obtain information indicating the number of digits available in the table identified by the identification information, determine whether the difference between the first counter value and the second counter value is less than the corresponding digit, and determine that the first request is valid upon determining that the difference between the first counter value and the second counter value is less than the corresponding digit. For example, if there are four digits available at a specific table in the store, it can be assumed that up to four users place an order together. In this case, if each person tags the tag (130) with a user terminal once, the counter values ​​may be sequentially generated in a manner such as 11, 12, 13, and 14, and the difference between the counter values ​​may be at most 3. Therefore, upon determining that the difference between the first counter value and the second counter value is less than the corresponding digit, the first request may be determined to be valid.

[0070] According to one embodiment of the present invention, the first request may further include information indicating the point in time at which the connection information is generated. Specifically, the point in time at which the connection information is generated in the user terminal (120) can be determined by the tag (130) being tagged by the user terminal (120), and information indicating this point in time can be included in the first request and provided to the electronic device (110). Alternatively, a separate timer may be provided to record the point in time at which the tag (130) is tagged by the user terminal (120), and information indicating this point in time can be included in the first request and provided to the electronic device (110). The configuration regarding the point in time at which the connection information is generated is not limited thereto, and may be configured in various ways within the scope of the problem to be solved by the present invention.

[0071] In addition, according to one embodiment of the present invention, in determining whether the first request is valid, the processor (210) may determine whether the time interval between the time at which the connection information is generated and the time at which the first request is obtained is greater than or equal to a predetermined waiting time interval, and may determine that the first request is invalid based on the determination that the time interval is greater than or equal to the predetermined waiting time interval. As described above, since information regarding the time at which the connection information is generated is included in the first request and the time at which the first request is received by the electronic device (110) can be confirmed, the time at which the connection information is generated and the time at which the first request is obtained can be determined, and whether the time interval between the two times is greater than or equal to the predetermined waiting time interval can be determined. In addition, the first request may be determined to be invalid based on the determination that the time interval is greater than or equal to the predetermined waiting time interval.

[0072] For example, the predetermined waiting time interval may be 1 to 5 minutes, and an appropriate time interval may be selected from among these. If the predetermined waiting time interval is 1 minute, a URL may be generated on the user terminal by user A tagging the tag (130) with the user terminal, and if the URL is not selected for more than 1 minute from this point, the URL may be invalidated. At this time, a message may be provided to the user terminal (120) of user A to tag the tag (130) again. This prevents a situation where a user only tags the tag (130) with the user terminal, receives a URL, and then later places a false order.

[0073] According to one embodiment of the present invention, a QR code may be used as a tag (130), and the QR code may be updated as a digital QR code at predetermined time intervals. Since the QR code is updated at predetermined time intervals, duplication or unauthorized use of the QR code can be prevented. For example, it can be assumed that user A receives a URL by directly tagging the QR code with a user terminal (120), duplicating the QR code and tagging the duplicated QR code to receive the URL, or duplicating the URL generated in this manner, and then places a false order. In this case, the QR code is updated after a predetermined time interval, and the corresponding URL is also updated accordingly, so that the URL used for the false order can be invalidated.

[0074] According to one embodiment of the present invention, the first request may further include current location information, including GPS information, of the user terminal (120) transmitting the first request. Accordingly, the processor (210) may determine whether the location from which the first request was transmitted is within the store, and if it is determined that the location from which the first request was transmitted is not within the store, the processor may determine that the first request is invalid.

[0075] According to one embodiment of the present invention, when providing a web page to a user terminal based on a determination that the first request is valid, the processor (210) may request user authentication from the user terminal (120). User authentication may be accomplished by fingerprint recognition, facial recognition, or an authentication code updated at predetermined intervals within the store. If user authentication is successful, the processor (210) may enable ordering through the web page, and if user authentication is not successful, may block access to the web page.

[0076] According to one embodiment of the present invention, the processor (210) learns order patterns by monitoring multiple order statuses, and can invalidate orders corresponding to abnormal order patterns or subject them to additional verification processes, such as the aforementioned user authentication. For example, if an abnormally large or repetitive order is received based on the learned order patterns, the processor (210) can invalidate orders corresponding to these abnormal order patterns or subject them to additional verification processes, such as the aforementioned user authentication.

[0077] According to one embodiment of the present invention, at least one camera or infrared sensor capable of monitoring the inside of a store or a table within the store may be additionally provided. Accordingly, the processor (210) may, after acquiring a first request, determine whether the first request is valid based on a detection result from at least one of the camera or infrared sensor. Specifically, identification information regarding the store or the table within the store may be extracted using the third hash value (330) included in the first request, and by comparing this identification information with the detection result described above, it may be determined whether the first request was actually made at the store or at a table within the store.

[0078] FIG. 4 is a flowchart illustrating a method according to an embodiment of the present disclosure. Referring to FIG. 4, the method (400) may include a step of obtaining a first request requesting a web page related to a product order from a user terminal (S410), wherein the first request is performed based on access information generated by the user terminal's first tagging of a tag, a step of determining whether the first request is valid (S420), and a step of providing the web page to the user terminal based on a determination that the first request is valid (S430).

[0079] FIG. 5 is a flowchart illustrating a method according to an embodiment of the present disclosure. Referring to FIG. 5, the method (500) may include, in a step (S420) of determining whether a first request is valid, a step (S510) of obtaining a first counter value based on a hash value stored in advance for a first hash value and a first counter value, a step (S520) of obtaining identification information based on a hash value stored in advance for a third hash value and identification information, a step (S530) of identifying a second request having the same identification information as the identification information that was received before the first request and determined to be valid, a step (S540) of determining whether the first counter value is a recent value increased from a second counter value corresponding to the second request, and a step (S550) of determining that the first request is valid based on a determination that the first counter value is a recent value.

[0080] In the flowcharts according to the present disclosure, each step of the method or algorithm is described in a sequential order. However, the steps may be performed in any order that can be arbitrarily combined, in addition to being performed sequentially. The description of the flowcharts or flowcharts of the present disclosure does not exclude changes or modifications to the method or algorithm, and does not imply that any step is essential or desirable. In one embodiment, at least some of the steps may be performed in parallel, iteratively, or heuristically. In another embodiment, at least some of the steps may be omitted, or other steps may be added.

[0081] Various embodiments according to the present disclosure may be implemented as software on a machine-readable recording medium. The software may be software for implementing various embodiments described in the present disclosure. The software may be inferred from various embodiments described in the present disclosure by programmers skilled in the art to which the present disclosure pertains. For example, the software may be a program including machine-readable commands (e.g., instructions, codes, or code segments). The device may be a device capable of operating according to commands called from a recording medium, such as a computer. In one embodiment, the device may be a computing device according to various embodiments described in the present disclosure. In one embodiment, the processor of the device may execute the called command, causing components of the device to perform functions corresponding to the command. The recording medium may refer to any type of recording medium that stores data and can be read by the device. The recording medium may include, for example, ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage, etc. In one embodiment, the recording medium may be implemented in a distributed form, such as in a network-connected computer system. In this case, the software may be distributed, stored, and executed in the computer system. In another embodiment, the recording medium may be a non-transitory computer-readable recording medium. A non-transitory computer-readable recording medium refers to a tangible medium that exists regardless of whether data is stored semi-permanently or temporarily, and does not include signals that are transmitted transitively.

[0082] While the technical concepts of the present disclosure have been described through various embodiments, the technical concepts of the present disclosure encompass various substitutions, modifications, and variations that can be made within the scope understandable to those of ordinary skill in the art to which the present disclosure pertains. Furthermore, it should be understood that such substitutions, modifications, and variations are encompassed within the scope of the appended claims.

Claims

1. In a method performed by an electronic device, A step of obtaining a first request for requesting a web page related to a product order from a user terminal, wherein the first request is performed based on access information generated by first tagging of the user terminal for a tag; a step of determining whether the first request is valid; and A method comprising the step of providing the web page to the user terminal upon determining that the first request is valid.

2. In paragraph 1, The above connection information includes a first hash value for a first counter value according to the first tagging and a second hash value for a unique value of the tag, The first request includes information about the first hash value and information about the second hash value, A method wherein the first counter value is a counter value according to the first tagging for the tag.

3. In paragraph 2, The above connection information further includes a third hash value for identification information that identifies the store where the tag is located or the table within the store, A method wherein the first request further includes information regarding the third hash value.

4. In paragraph 3, The step of determining whether the above first request is valid is: A step of obtaining the first counter value based on a hash value stored in advance for the first hash value and the first counter value; A step of obtaining the identification information based on the third hash value and the hash value stored in advance for the identification information; A step of identifying a second request having the same identification information as the first request, which was received and determined to be valid prior to the first request; a step of determining whether the first counter value is a recent value increased from the second counter value corresponding to the second request; and A method comprising the step of determining that the first request is valid based on a determination that the first counter value is the most recent value.

5. In paragraph 4, The step of determining that the first request is valid based on a determination that the first counter value is the most recent value is: A step of determining whether the second hash value and the pre-stored hash value for the unique value are identical; and A method comprising the step of determining that the first request is valid based on a determination that the second hash value and the pre-stored hash value for the unique value are identical.

6. In paragraph 4, determining whether the time interval between the time of obtaining the first request and the second request is less than or equal to a predetermined grace time interval based on a determination that the first counter value is not the most recent value; and A method comprising the step of determining that the first request is valid based on a determination that the time interval is less than or equal to the predetermined grace time interval.

7. In paragraph 6, A method comprising the step of determining that the first request is invalid based on a determination that the time interval exceeds the predetermined grace time interval.

8. In paragraph 4, A step of obtaining information indicating the number of digits available in the table identified by the identification information, based on a determination that the first counter value is not the most recent value; a step of determining whether the difference between the first counter value and the second counter value is less than the number of digits; and A method comprising the step of determining that the first request is valid based on a determination that a difference between the first counter value and the second counter value is less than the number of digits.

9. In paragraph 1, The first request further includes information indicating when the connection information is generated, The step of determining whether the above first request is valid is: A step of determining whether the time interval between the time at which the above connection information is generated and the time at which the first request is obtained is longer than a predetermined waiting time interval; and A method comprising the step of determining that the first request is invalid based on a determination that the time interval is greater than or equal to the predetermined waiting time interval.

10. In paragraph 1, A method wherein the tag includes at least one of an NFC (Near-Field Communication) tag or a QR code and is recognizable by the user terminal through short-range communication.

11. In paragraph 10, The above QR code is a digital QR code, and is updated at predetermined time intervals.

12. In paragraph 1, The above connection information is a URL (Uniform Resource Locator) of the above web page.

13. In paragraph 6, A method wherein the predetermined grace time interval is from 1 minute to 5 minutes.

14. In a non-transitory computer-readable recording medium recording instructions to be executed by one or more processors, A non-transitory computer-readable recording medium, wherein the instructions, when executed, cause the one or more processors to perform the method of any one of claims 1 to 13.

15. A communication interface configured to communicate with at least one user terminal; one or more processors; and comprising one or more memories storing instructions to be executed by said one or more processors; An electronic device, wherein, upon execution of the above instructions, the one or more processors are configured to perform the method of any one of claims 1 to 13.

16. At least one user terminal; a tag recognizable by at least one user terminal; and A system comprising an electronic device according to claim 15, configured to transmit and receive data with at least one user terminal.

Citation Information

Patent Citations

  • WEB Service System And Method Based On NFC Having Simulation Protection Function

    KR101700400B1

  • NFC Payment System and Method for Complementing the Private Information Problem by Changing the Path of Providing to Billing Information

    KR1020160062806A

  • Wound covering material for oral wound protection and self-treatment using adhesive polymer

    KR1020220055901A

  • APPARATUS AND METHOD for displaying codes

    KR102575213B1

  • Method, system, and device for generating, storing, using, and validating NFC tags and data

    US20190349352A1