2D Barcode Security via Server-Side Access Address

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for generating and reading 2D barcodes, especially those involving private information, face security concerns due to the risk of enciphered information being cracked and increased costs for enciphering and deciphering, as well as inadequate security measures for private information indicators.

Innovation Solution

A method and system where a terminal sends private information to a server to generate an information access address comprising an information identifier, check identifier, and time identifier, which is used to create a 2D barcode. The server stores the private information and returns the access address to the terminal, allowing secure access to the private information upon scanning, ensuring security without the need for enciphering and deciphering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private information is enciphered before generating a 2D barcode, then security of private information is improved, but cost of generating and reading the barcode increases due to enciphering and deciphering operations

Engineering Contradiction:
Improvesecurity of private informationVSAvoidcost of generating and reading barcode
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the private information from the barcode generation process itself. Instead of enciphering the private information and embedding it in the barcode, the system separates the private information storage (on server) from the barcode content (public access address), thereby eliminating the need for enciphering/deciphering operations while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism - a public access address that mediates between the barcode (public domain) and the private information (secure domain). This access address contains verification codes and time identifiers that enable secure retrieval without direct exposure of private information, eliminating the need for traditional enciphering methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private information is directly stored in the 2D barcode, then ease of reading is improved, but security of private information deteriorates as it cannot be protected

Engineering Contradiction:
Improveease of reading barcodeVSAvoidsecurity of private information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the information into two distinct parts: a public access address (embedded in barcode for easy scanning) and private information (stored securely on server). The access address contains segmented verification elements (verification code, time identifier) that enable security checks without exposing private information, thus maintaining both ease of reading and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The public access address serves as an intermediary that enables easy barcode reading while preventing direct access to private information. When the barcode is scanned, the access address triggers a secure verification process on the server side, mediating between the convenient barcode format and the security requirements of private information protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If verification codes and time identifiers are added to the access address, then security of private information is improved, but complexity of generating and reading barcode increases

Engineering Contradiction:
Improvesecurity of private informationVSAvoidcomplexity of generating and reading barcode
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of the access address by incorporating verification codes and time identifiers as additional data elements. These parameters enable dynamic security verification - the time identifier ensures the access address is valid only within a specific time window, while the verification code provides authentication - without fundamentally changing the barcode generation and reading process.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3132385B1Methods and systems for generating and reading 2d barcodes
Publication Date: 2024.12.18 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • EP3132385B1 patent drawingFigure 1~2
  • EP3132385B1 patent drawingFigure 3~4
  • EP3132385B1 patent drawingFigure 5

AI summary

The present disclosure discloses methods and terminals for generating and reading a 2D barcode and servers, and belongs to the field of information processing technologies. The method for generating a 2D barcode includes: acquiring private information input by a user, and sending the private information to a server through a network; receiving an information access address returned, through the network, by the server; and generating a 2D barcode including the information access address. The method for reading a 2D barcode includes: acquiring a 2D barcode including an information access address, and scanning the 2D barcode, to obtain the information access address included in the 2D barcode, the information access address being for accessing private information; sending the information access address to a server through a network; and receiving the private information returned, through the network, by the server, and using the private information as a reading result of the 2D barcode. In the present disclosure, private information is replaced with an information access address, so that security of private information is ensured, and enciphering and deciphering are not needed, so that costs of generating and reading a 2D barcode are reduced, and an application scope of a 2D barcode is broadened.