Authentication Server Two-Dimensional Code Forgery Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing systems for two-dimensional codes lack a method to detect forgery, which can lead to malicious website connections and potential malware infections when fraudulent URLs are read, posing a risk to mobile communication clients.
Innovation Solution
An authentication server and system that embeds authentication information into two-dimensional codes using Elliptic Curve Cryptography, allowing the authentication server to verify the integrity of the codes and prevent forgery by comparing encrypted and decrypted bit sequences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If two-dimensional codes are used for information delivery, then ease of information acquisition is improved, but vulnerability to forgery and malicious alteration increases
Solution Approach 1:
The patent applies preliminary action by embedding authentication information (authentication bits) into the two-dimensional code during the code generation phase, before the code is read or used. This allows the authentication server to verify the code's integrity later by comparing the embedded authentication bits with freshly generated ones, preventing forgery while maintaining ease of information delivery
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the two-dimensional code and the reader. The server generates authentication information, embeds it in the code, and verifies it when the code is read. This intermediary layer provides security verification without affecting the ease of information acquisition for legitimate users
2Reliability
If authentication information is embedded in two-dimensional codes, then security against forgery is improved, but device complexity increases
Solution Approach 1:
The patent applies self-service by making the two-dimensional code carry its own authentication information within its structure. The authentication bits are embedded directly in the code, and the authentication server can verify them without requiring additional external authentication mechanisms or complex hardware modifications to the reader devices
Solution Approach 2:
The patent changes the parameter structure of the two-dimensional code by incorporating authentication bits as an additional parameter within the code's data structure. This allows authentication information to be embedded without fundamentally changing the code's format or requiring complex additional components, thus limiting the increase in system complexity
Data Source
Figure 1
Figure 2
Figure 3(A)~3(B)
AI summary
In an authentication system 1, a mobile communication client 20 transmits to an authentication server 30 a bit signal that includes an image capture bit sequence obtained by capturing an image of a self-aware two-dimensional code 200 having authentication information embedded in a correction area, and a number bit sequence that indicates a serial number of an authentication application program being stored in storage 23. The authentication server 30 authenticates the user of the mobile communication client 20 and the self-aware two-dimensional code 200. Subsequently, the authentication server 30 transmits designated information expressed by the self-aware two-dimensional code 200 to the mobile communication client 20, on the condition that the user and the self-aware two-dimensional code 200 are successfully authenticated. Consequently, the mobile communication client 20 is able to acquire the designated information expressed by the self-aware two-dimensional code 200.