Mobile Payment Code Segmentation for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile payment systems lack security and efficiency in transactions, and do not provide 100% protection against common attacks, especially when using QR codes, barcodes, or additional hardware and software for communication with merchants.
Innovation Solution
A method for generating a secure code using encryption and encoding techniques, involving a client, a first server, and a second server, where the code is split into public and private parts, with the public part displayed as a QR code and the private part stored on the second server, ensuring only authorized entities can decrypt and complete transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional mobile payment systems use QR codes, barcodes, or additional hardware for transactions, then communication with merchants is enabled, but security against attacks is compromised and 100% protection cannot be assured
Solution Approach 1:
The authorization code is segmented into two distinct parts: a public part that can be displayed to the user and a private part that remains securely stored on the server. This segmentation allows the system to maintain ease of operation by displaying readable information while ensuring security by keeping the sensitive private component separate and protected from exposure during the transaction process
Solution Approach 2:
The patent introduces an intermediary encoding mechanism that transforms sensitive authorization data into a secure format. The encoding method acts as a mediator between the private data and its display representation, ensuring that even if the public part is exposed, the underlying sensitive information remains protected through the one-way encoding transformation
2Ease of operation
If sensitive information is displayed during transaction for user verification, then user authorization is enabled, but information exposure creates security vulnerabilities
Solution Approach 1:
The authorization information is divided into public and private components, allowing the public part to be safely displayed for user verification while the private part remains hidden on the server, thus enabling user authorization without exposing sensitive information
Solution Approach 2:
The sensitive private information is extracted from the displayable content and stored separately on the server. Only the non-sensitive public part is extracted for display purposes, eliminating the harmful factor of information exposure while maintaining the functionality of user verification
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method for generating a code and a method comprising the authorization of an operation carried out by a client on a first server. A second server generating an authorization code according to an encoding method is involved in the authorization. The operations can be transactions, access to a web page, user-to-user payments, user-to-business payments, online user-to-business payments, cash withdrawal in automated teller machines, etc.