Augmented Smart Tag Security for Contactless POS Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing smart tag and code verification systems lack effective security measures to ensure the legitimacy and integrity of NFC, RFID, QR codes, and barcodes, particularly in contactless POS transactions, making users vulnerable to malicious content and security compromises.
Innovation Solution
The Augmented Smart Tag Security (ASTS) system transforms video and media inputs of POS terminals and associated contextual data into validation methods and instructions, using a remote server to verify the trustworthiness of tags and codes by analyzing captured media and contextual information, thereby regulating access and action on stored data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If smart tags and codes (NFC, RFID, QR codes, barcodes) are used for contactless transactions, then transaction convenience and speed are improved, but security vulnerability and risk of malicious content increase
Solution Approach 1:
The system performs preliminary verification of smart tags and codes before allowing transactions. A remote server validates the authenticity and integrity of tags/codes by analyzing captured media (images, video) and contextual data, checking against a database of known malicious content. This preliminary security check enables fast transactions while blocking malicious content in advance.
Solution Approach 2:
The patent introduces an intermediary verification system between the user device and the smart tag/code. The remote server acts as a mediator that receives media captures and contextual data, performs security analysis, and returns validation results. This intermediary layer enables contactless transaction speed while adding security verification that would be too complex for the user device alone.
2Reliability
If security verification of smart tags and codes is implemented, then security reliability is improved, but system complexity and processing time increase
Solution Approach 1:
The complex security verification logic is moved to a remote server that acts as an intermediary. The user device only needs to capture media and send requests, while the remote server handles the complex analysis of contextual data, media processing, and database queries. This distributes system complexity away from the user device while maintaining comprehensive security verification.
Solution Approach 2:
The system uses automatically captured media (images, video) and contextual data from the user device to perform self-verification of smart tags and codes. The remote server automatically analyzes this data without requiring manual user input or complex user-side processing, enabling security verification while keeping the user interface simple.
3Measurement precision
If media capture and analysis is performed for verification, then measurement precision of tag legitimacy is improved, but use of energy and processing resources increase
Solution Approach 1:
The energy-intensive media analysis and verification processing is performed on the remote server rather than the user device. The user device only captures media and transmits data, consuming minimal energy. The remote server handles the computationally intensive tasks of analyzing images, video, and contextual data to determine tag legitimacy with high precision.
Solution Approach 2:
The system creates a digital copy (media capture) of the smart tag or code for verification purposes. Instead of directly processing the physical tag with high energy consumption, the system captures an optical/electronic copy and analyzes this copy remotely. This copying approach enables precise verification while minimizing local energy usage.
Data Source
AI summary
A method comprising receiving file captured by the mobile device, determining a file format of the captured file, and extracting contextual data from the captured file. The method includes querying a data source associated with a reference and receiving validation information regarding the contextual data. The method includes generating and transmitting a message based on the validation information for use in determining whether to allow the mobile device to interact with an endpoint corresponding to the reference.


