Encrypted QR Code Roaming for Website Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current browser synchronization methods for website accounts and passwords are insecure, as they rely on third-party servers, making them vulnerable to unauthorized access and data loss in case of server hacks.

Innovation Solution

A method and system for roaming website accounts and passwords that uses encryption and QR codes to securely synchronize data between clients without relying on a third-party server, ensuring that only verified users can access and transfer account information, and includes a verification process to ensure the reliability of the transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If browser synchronization stores website accounts and passwords on a third-party server, then users can access their data across multiple terminals, but the security risk increases due to potential server hacks and unauthorized access

Engineering Contradiction:
Improvecross-terminal data accessVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive data (website accounts and passwords) from the third-party server environment and stores it locally on the user's terminal. The encryption key is derived from user biometric information stored only on the device, eliminating the need to store sensitive data on external servers while maintaining cross-terminal accessibility through encrypted backups.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authentication process into multiple independent components: biometric data storage, encryption key generation, and encrypted data storage. Each component operates independently with strict access controls, so that even if one component is compromised, the others remain secure. This segmentation prevents a single point of failure that could lead to complete data breach.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If website accounts and passwords are stored locally on the terminal, then security is improved, but the user cannot access the data when using a different terminal

Engineering Contradiction:
ImprovesecurityVSAvoiddata accessibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary encryption of the website accounts and passwords using the user's biometric-derived key before storing the encrypted data. This preliminary action ensures that even if the data is transferred to another terminal, it remains encrypted and inaccessible without the original biometric key, thus maintaining security while enabling portability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encrypted backup mechanism that allows data to be stored locally for security while providing a secure transfer path to other terminals. The encrypted backup acts as an intermediary that preserves security during transit and storage, allowing the user to restore data on new terminals without exposing plaintext credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the browser account is left logged in on an unreliable terminal, then convenience is improved, but the risk of malicious use of stored credentials increases

Engineering Contradiction:
ImproveconvenienceVSAvoidmalicious use risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements beforehand cushioning by requiring biometric authentication for every access to stored credentials, even on trusted terminals. This prior cushioning measure ensures that convenience is not compromised by frequent full authentications, while still maintaining security through the inherent security of biometric data that cannot be stolen or shared.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS9525667B2Method and system for roaming website account and password
Publication Date: 2016.12.20 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9525667B2 patent drawing
  • US9525667B2 patent drawing
  • US9525667B2 patent drawing

AI summary

A method and system for roaming website accounts and passwords are provided. The method is operational on a first client and includes: authenticating website accounts and passwords that have been stored; obtaining the stored website addresses, accounts and passwords according to a success verification; encrypting the stored website addresses, accounts and passwords for generating encrypted information, and generating a first QR code to be obtained by a second client according to the encrypted information. The website accounts and passwords are roamed and synchronized to be shared. The synchronization process verifies the accounts and passwords, and would not need a third-party server. Risk of data lost in case that the third-party server is attacked would be eliminated, and the safety for the accounts and passwords is improved.