Graphical Barcode and Card Reader Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Credit card theft and data skimming enable fraudulent transactions, particularly in online financial dealings where user and service provider identities are not adequately authenticated, leading to increased phishing attempts and unauthorized access.
Innovation Solution
Implementing a system that uses a card reader to authenticate users through unique magnetic card information and swipe characteristics, combined with graphical authentication indicia such as QR codes, to verify identities and prevent replay attacks during transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional online transaction systems are used without authentication, then ease of operation is improved, but reliability deteriorates due to credit card theft and fraudulent transactions
Solution Approach 1:
The system performs preliminary authentication actions before the actual transaction. A graphical authentication indicia (QR code) is generated and displayed beforehand, containing encoded authentication data. The user scans this code with their mobile device, which then validates the authentication information before allowing the transaction to proceed. This preliminary authentication step prevents fraudulent transactions while maintaining ease of use.
Solution Approach 2:
The patent introduces a graphical authentication indicia (QR code) as an intermediary element between the user and the transaction system. This QR code serves as a mediator that encodes authentication information and can be scanned by the user's mobile device. The intermediary translates complex authentication requirements into a simple visual code that users can easily interact with, thereby maintaining ease of operation while improving reliability.
2Reliability
If graphical authentication indicia (QR codes) are implemented, then reliability is improved by preventing replay attacks, but device complexity increases
Solution Approach 1:
The system uses disposable, single-use graphical authentication indicia (QR codes) that are generated for each transaction or session. Each QR code contains a unique authentication token that can only be used once. After scanning, the QR code becomes invalid, preventing replay attacks. This approach uses simple, inexpensive visual elements rather than complex cryptographic protocols, improving reliability while minimizing device complexity.
Solution Approach 2:
The patent uses optical copying (QR code scanning) as a simple authentication mechanism. Instead of requiring complex cryptographic key exchanges or biometric verification systems, the system encodes authentication data into a visual QR code that can be copied optically by the user's camera. This copying mechanism is simple to implement and effectively prevents replay attacks since each QR code is unique and single-use.
3Reliability
If card reader authentication with magnetic information reading is used, then reliability is improved by distinguishing unique card characteristics, but manufacturing precision requirements increase
Solution Approach 1:
The system changes the parameters being measured from the card, moving beyond standard magnetic stripe data. The card reader captures additional magnetic characteristics such as subtle variations in magnetic field strength, timing of magnetic transitions, and physical properties of the magnetic material. These parameter changes allow the system to create a unique magnetic fingerprint for each card, improving reliability for fraud detection without requiring higher manufacturing precision in card production.
Data Source
AI summary
A method for authenticating an online transaction or a log-in process is provided. The method comprises: receiving image data of a visual graphical barcode from a user device, and the visual graphical barcode is configured to be displayed on an unauthenticated device for conducting the online transaction; analyzing the image data to obtain a transaction validation identifier (ID); comparing the transaction validation ID to a pre-stored validation ID; comparing a first set of collection data from the user device to a second set of collection data that is pre-stored; and determining whether to approve or reject the online transaction based on (1) a match between the transaction validation ID and the pre-stored validation ID, and (2) a match between the first set of collection data and the second set of collection data that is pre-stored.


