Optical Barcode Authentication for Mobile Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for mobile telecommunications terminals lack sufficient security, as user names and passwords can be easily compromised, and two-factor authentication is not feasible due to the lack of interfaces for electronic ID card reading in conventional terminals.

Innovation Solution

A method involving a first authentication code stored securely on the terminal and a second code transmitted during registration, where both codes are required to generate an authentication key, with the second code displayed on a user computer system and optically captured by the terminal, ensuring only the rightful owner can authenticate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication methods (username/password) are used, then ease of operation is improved, but security is worsened because credentials can be spied out, guessed, or compromised

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent steps: initial registration with username/password, separate one-time password generation and transmission via barcode, and final authentication code verification. This segmentation prevents single-point compromise and requires multiple independent authentication factors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by generating and transmitting the one-time password via barcode before the actual authentication occurs. This preliminary code exchange establishes a secure foundation that prevents man-in-the-middle attacks during the subsequent authentication process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If two-factor authentication using electronic ID card is used, then authentication security is improved, but device complexity is worsened due to lack of reading interfaces in conventional terminals

Engineering Contradiction:
Improveauthentication securityVSAvoidterminal interface requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical interface requirement (physical ID card reader) with an optical system (camera-based barcode scanning). This substitution eliminates the need for specialized hardware interfaces while maintaining two-factor authentication security through visual code capture.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If barcode is used for authentication data transmission, then ease of operation is improved, but security is worsened because third parties can potentially gain knowledge of the barcode

Engineering Contradiction:
Improveauthentication processVSAvoidcode transmission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system uses periodic action by generating a one-time password that is valid only for a single authentication transaction. Each barcode contains a unique, time-limited code that expires after use, preventing replay attacks and ensuring that even if a barcode is captured, it cannot be reused.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3319003B1Method and system for authenticating a mobile telecommunication terminal on a service computer system and mobile telecommunication terminal
Publication Date: 2020.09.16 BUNDESDRUCKEREI GMBH
  • EP3319003B1 patent drawingFigure 1
  • EP3319003B1 patent drawingFigure 2

AI summary

A method for authenticating a mobile telecommunications terminal (102) to a service computer system (104) via a public network (110), wherein the mobile telecommunications terminal (102) has a secure memory area (122) in which a first authentication code (124) is stored, and wherein a second authentication code (128) is stored in the service computer system (104), the second authentication code (128) being associated with a user ID, comprises the following steps: - establishing a network connection between a user computer system (106) and a service computer system (104) via the public network (110), - authenticating the user to the service computer system (104) via the user computer system (106) and the network connection, in particular using two-factor authentication,wherein a user ID is sent from the user computer system (106) to the service computer system (104) via the network connection, - sending the second authentication code (128) associated with the user ID to the user computer system (106) via the network connection, - displaying the second authentication code (128) to a display device (154) of the user computer system (106), - authenticating the user (132) to the mobile telecommunications terminal (102) by capturing user-specific information, - optically capturing the second authentication code (128) by the mobile telecommunications terminal (102) from the user computer system (106), - generating an authentication key (130) from the first and the second authentication codes (124, 128) by the mobile telecommunications terminal (102),- Establishing a mobile communication connection between the mobile telecommunications terminal (102) and the service computer system (104) via the public network (110), - Authenticating the mobile telecommunications terminal (102) to the service computer system (102) using the authentication key (130) via the mobile communication connection.