Encrypted Colorgram Tokens for Mobile Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods for mobile devices are inadequate for secure financial transactions, as they lack the necessary security level, especially in peer-to-peer transactions, and existing technologies such as QR-codes and two-factor authentication are vulnerable to fraud due to their limitations in data storage capacity and complexity.

Innovation Solution

A smartphone app that uses encrypted colorgrams to authenticate users by pushing encrypted colorgrams from a transaction server to mobile devices, where they are decrypted and verified through a camera image, combining what-you-have, what-you-know, and who-you-are security factors for multi-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (PIN, password) are used, then ease of operation is maintained, but security level is insufficient for financial transactions

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses colorgrams with specific color patterns and transitions to encode authentication information. Different colors represent different authentication states or data elements, allowing secure verification through visual color changes rather than requiring users to remember or input complex codes.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The system changes parameters such as color intensity, hue, saturation, and temporal patterns of color display to encode authentication data. These parameter variations provide high entropy authentication without requiring users to manage complex passcodes, as the color dynamics automatically provide cryptographic strength.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If QR codes are used for authentication, then ease of operation is improved, but data storage capacity is insufficient for secure transactions

Engineering Contradiction:
Improvedata storage capacityVSAvoidcode structure
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent transitions from traditional 2D QR codes to dynamic colorgrams that utilize temporal dimension (color changes over time) and spectral dimension (multiple colors simultaneously). This adds new dimensions to data encoding capacity while maintaining the simplicity of visual presentation, allowing much more information to be encoded in the same visual space.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The colorgram combines multiple visual elements (different colors, patterns, and temporal variations) into a composite authentication structure. This composite approach allows the system to encode far more data than traditional monochrome QR codes while maintaining ease of visual verification and authentication.

Inventive Principle:
Principle #40Composite materials

3Reliability

If multi-factor authentication is implemented, then security level is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication strengthVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication factors into a single integrated colorgram display and verification system. The what-you-have (device), what-you-know (color pattern recognition), and who-you-are (user-specific color sequences) factors are combined in one visual authentication mechanism, reducing the complexity of managing multiple separate authentication systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8868902B1Characteristically shaped colorgram tokens in mobile transactions
Publication Date: 2014.10.21 CRYPTITE LLC
  • US8868902B1 patent drawing
  • US8868902B1 patent drawing
  • US8868902B1 patent drawing

AI summary

A transaction security process includes authentication and identification parts for pushing an encrypted colorgram for user authentication and persona descriptors for user identification from a transaction server to a first personal trusted device. A decryption of the colorgram is displayed on the first personal trusted device. An image is captured by a second personal trusted device. An encryption of the image captured from the second personal trusted device is uploaded to the transaction server. The persona descriptors are used to build a composite rendering for identification of the first user to the second user. The second user clicks “OK” if they recognize the composite drawing as a reasonable persona of the first user.