Mobile-Initiated Transactions Using Dynamic QR Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing financial transaction methods using smart devices face interoperability challenges due to varying hardware and software requirements, and conventional QR code methods lack flexibility and security, particularly against replay attacks.
Innovation Solution
Utilizing visual codes, such as QR codes, in conjunction with public key cryptography to facilitate transactions between user devices and terminals, enabling interoperability without requiring NFC hardware and eliminating the need for a central middleware, while employing host card emulation (HCE) for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NFC hardware is installed in terminals to enable mobile financial transactions, then transaction security and interoperability are improved, but hardware installation costs and device complexity increase
Solution Approach 1:
The patent uses visual codes (QR codes) as a copy or representation of the NFC communication protocol. Instead of requiring physical NFC hardware, the system creates a visual code that encodes terminal information and authentication data, which the mobile device scans and processes to establish secure transactions. This copying approach maintains security functionality while eliminating the need for complex NFC hardware installation in terminals.
Solution Approach 2:
The patent replaces the mechanical/NFC-based contactless communication system with a visual code-based system. The NFC electromagnetic coupling mechanism is substituted with optical code scanning and processing, allowing terminals without specialized hardware to participate in secure mobile financial transactions through software-based HCE (Host Card Emulation) and visual code communication.
2Device complexity
If conventional QR code methods are used for transactions, then hardware requirements are reduced, but security against replay attacks and transaction flexibility are insufficient
Solution Approach 1:
The patent makes the QR code dynamic by incorporating time-varying elements and terminal-specific authentication data into the visual code structure. The code includes terminal identifiers, timestamps, and cryptographic authentication information that changes with each transaction, preventing replay attacks. The system dynamically generates and validates codes based on current transaction parameters and terminal state, maintaining security while keeping hardware requirements low.
Solution Approach 2:
The patent introduces an intermediary authentication layer using visual codes that mediates between the mobile device and terminal. The QR code serves as an intermediary carrier that encapsulates terminal information, authentication tokens, and transaction parameters. This intermediary structure enables secure communication without direct hardware coupling, allowing the system to achieve both low hardware requirements and high security through the coded information carrier.
3Adaptability or versatility
If a central middleware is used to facilitate transactions between mobile devices and terminals, then interoperability is improved, but system complexity and points of failure increase
Solution Approach 1:
The patent extracts the middleware function from a centralized architecture and distributes it to individual terminals through visual code-based communication. Each terminal independently generates and processes its own authentication codes and transaction parameters, eliminating the need for a central middleware server. This extraction maintains interoperability by ensuring all terminals use the same visual code protocol while reducing system complexity by removing the centralized intermediary layer.
Solution Approach 2:
The patent enables terminals to perform self-service authentication and transaction facilitation through locally generated visual codes. Each terminal independently creates authentication codes containing its own identifiers and transaction parameters without requiring central middleware intervention. The mobile device scans and validates these self-generated codes, allowing terminals to autonomously participate in secure transactions and reducing overall system architecture complexity.
Data Source
AI summary
A transaction is pre-staged by providing transaction preferences, such as a financial instrument, a transaction type, and a transaction amount, to a user device. The user device captures a visual code at a terminal, such as an ATM. The visual code includes terminal attributes, including a signed hash and call-back URI. The user device authenticates the visual code using the signed hash and requests the transaction through the issuer server. The issuer server creates and sends the card data to the call-back URI. The terminal uses the card data to create a transaction request it routes to through its acquirer server.


