Two-Dimensional Code Verification for Sensitive Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity verification methods, such as static and dynamic passwords, are vulnerable to theft by third parties using Trojan viruses, increasing user learning and operation costs, and do not effectively ensure real identity verification during sensitive operations like online transactions.

Innovation Solution

A sensitive operation verification method using a two-dimensional code that initiates a verification process by scanning information, allowing a terminal device to send verification requests to a server for user identity verification without requiring user login, thereby simplifying operations and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static password or dynamic password verification is used, then user identity verification can be performed, but the system becomes vulnerable to third-party theft using Trojan viruses

Engineering Contradiction:
Improveidentity verification securityVSAvoidvulnerability to Trojan virus theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a two-dimensional code as an intermediary carrier between the user and the verification server. Instead of directly transmitting passwords that can be stolen by Trojans, the system uses the two-dimensional code to carry verification information that is dynamically generated and bound to the user's device, making it impossible for third parties to steal credentials through virus infection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical password input system with an optical scanning system. Users scan a two-dimensional code displayed on the server side using their device's camera, and the scanned information is automatically transmitted for verification. This eliminates the need for users to manually input passwords, thereby removing the vulnerability to Trojan virus theft that exploits manual input methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual password input verification is required, then user identity can be verified, but user learning costs and operation costs increase

Engineering Contradiction:
Improveidentity verificationVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service verification by automatically generating and scanning two-dimensional codes. The server side automatically creates the code containing user identification information, and the scanning process is automated through the device's camera and processing capabilities, eliminating the need for users to manually input passwords or remember verification procedures, thereby reducing learning and operation costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The two-dimensional code is pre-generated and displayed on the server side before the verification process begins. The code contains all necessary verification information in advance, so when the user scans it, the verification can proceed immediately without requiring the user to learn or remember complex verification procedures, thereby simplifying operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional verification methods are used, then security can be maintained, but the verification process requires user login which increases operation time

Engineering Contradiction:
ImprovesecurityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a verification process that skips the traditional login step entirely. Instead of requiring users to log in and then perform verification, the system directly generates a two-dimensional code that contains the user's identification information. When scanned, this code immediately triggers verification without any intermediate login steps, thereby rushing through the verification process and reducing time loss.

Inventive Principle:
Principle #21Skipping (Rushing through)

Solution Approach 2:

User identification information is pre-embedded in the two-dimensional code before the verification process begins. This preliminary action of pre-preparing the verification data in the code allows the verification to proceed directly without requiring time-consuming login operations, thereby reducing verification time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9703971B2Sensitive operation verification method, terminal device, server, and verification system
Publication Date: 2017.07.11 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9703971B2 patent drawing
  • US9703971B2 patent drawing
  • US9703971B2 patent drawing

AI summary

The present disclosure discloses a sensitive operation verification method, a terminal device, a server, and a verification system. The method includes: scanning, by a first terminal device, a two-dimensional code for initiating a sensitive operation, and obtaining information in the two-dimensional code, the information in the two-dimensional code being at least used to uniquely determine the sensitive operation; and sending, by the first terminal device, a first verification request to a verification server, the first verification request carrying verification information of the first terminal device and the information in the two-dimensional code.