Graphic Payment Code Security via Module Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face security challenges in providing sensitive graphic code information, such as offline payment codes, due to the risk of theft or interception, which compromises the integrity of transactions in mobile payment applications.

Innovation Solution

Implementing a security verification process between modules, where a second module verifies the trustworthiness of a first module and associated user information before providing graphic code information, using an interface module for secure communication and encryption with asymmetric keys to ensure data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If graphic code information is provided to other applications, then functionality and user convenience are improved, but security risks increase due to potential theft or interception

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an interface module as an intermediary between the payment application and other applications. This module acts as a secure gateway that controls and manages the provision of graphic code information, preventing direct access and potential theft while still enabling functionality through controlled interfaces

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements security verification mechanisms before graphic code information is provided to other applications. By performing preliminary security checks and trust verification, the system prevents potential security breaches before they can occur, rather than relying on post-breach detection

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If security verification is performed on modules and users, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security verification process into distinct segments: module trust verification and user identity verification. This segmentation allows each verification step to be handled independently through the interface module, managing complexity by breaking down the overall security process into manageable parts

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If graphic code information is transmitted to first module, then functionality is improved, but risk of unauthorized access increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The interface module serves as a protective intermediary that mediates the transmission of graphic code information to the first module. It verifies the legitimacy of the first module before allowing information transmission, thereby enabling functionality while preventing unauthorized access through the intermediary's security controls

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3487142B1Providing and obtaining graphic payment code information
Publication Date: 2023.09.06 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3487142B1 patent drawingFigure 1
  • EP3487142B1 patent drawingFigure 2A
  • EP3487142B1 patent drawingFigure 2B

AI summary

The present application relates to a method and device for providing and obtaining graphic code information, and a terminal. The method for providing graphic code information is applied on a device comprising a first module, a second module, and an interface module, wherein the interface module corresponds to the second module. The method comprises: the second module verifying through the interface module whether the first module is a trusted module; the second module receiving target user information and verifying whether the target user information is in a logged-in state on the second module, wherein the target user information is pre-associated with the interface module; and after verifying that the first module is a trusted module and the target user information is in the logged-in state on the second module, the second module generating graphic code information and transmitting the graphic code information to the first module through the interface module. Embodiments of the present application can ensure the security of a process for providing graphic code information, and prevent the graphic code information from being stolen or intercepted.