Encrypted QR Code Roaming for Website Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current browser synchronization methods for website accounts and passwords are insecure, as they rely on third-party servers, making them vulnerable to unauthorized access and data loss in case of server hacks.
Innovation Solution
A method and system for roaming website accounts and passwords that uses encryption and QR codes to securely synchronize data between clients without relying on a third-party server, ensuring that only verified users can access and transfer account information, and includes a verification process to ensure the reliability of the transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If browser synchronization stores website accounts and passwords on a third-party server, then users can access their data across multiple terminals, but the security risk increases due to potential server hacks and unauthorized access
Solution Approach 1:
The patent extracts the sensitive data (website accounts and passwords) from the third-party server environment and stores it locally on the user's terminal. The encryption key is derived from user biometric information stored only on the device, eliminating the need to store sensitive data on external servers while maintaining cross-terminal accessibility through encrypted backups.
Solution Approach 2:
The patent segments the authentication process into multiple independent components: biometric data storage, encryption key generation, and encrypted data storage. Each component operates independently with strict access controls, so that even if one component is compromised, the others remain secure. This segmentation prevents a single point of failure that could lead to complete data breach.
2Object-affected harmful factors
If website accounts and passwords are stored locally on the terminal, then security is improved, but the user cannot access the data when using a different terminal
Solution Approach 1:
The patent performs preliminary encryption of the website accounts and passwords using the user's biometric-derived key before storing the encrypted data. This preliminary action ensures that even if the data is transferred to another terminal, it remains encrypted and inaccessible without the original biometric key, thus maintaining security while enabling portability.
Solution Approach 2:
The patent introduces an intermediary encrypted backup mechanism that allows data to be stored locally for security while providing a secure transfer path to other terminals. The encrypted backup acts as an intermediary that preserves security during transit and storage, allowing the user to restore data on new terminals without exposing plaintext credentials.
3Ease of operation
If the browser account is left logged in on an unreliable terminal, then convenience is improved, but the risk of malicious use of stored credentials increases
Solution Approach 1:
The patent implements beforehand cushioning by requiring biometric authentication for every access to stored credentials, even on trusted terminals. This prior cushioning measure ensures that convenience is not compromised by frequent full authentications, while still maintaining security through the inherent security of biometric data that cannot be stolen or shared.
Data Source
AI summary
A method and system for roaming website accounts and passwords are provided. The method is operational on a first client and includes: authenticating website accounts and passwords that have been stored; obtaining the stored website addresses, accounts and passwords according to a success verification; encrypting the stored website addresses, accounts and passwords for generating encrypted information, and generating a first QR code to be obtained by a second client according to the encrypted information. The website accounts and passwords are roamed and synchronized to be shared. The synchronization process verifies the accounts and passwords, and would not need a third-party server. Risk of data lost in case that the third-party server is attacked would be eliminated, and the safety for the accounts and passwords is improved.


