Optoelectronically Readable Code for Secure User Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods using optoelectronically readable codes lack a comprehensive solution for ensuring the integrity and security of user authentication, particularly in accessing controlled areas, as they do not effectively combine visual verification with secure token validation.
Innovation Solution
The method integrates a secret, encrypted security token with an image of an authorized user or object into an optoelectronically readable code, allowing for both visual integrity checks and secure token authentication, using encryption and checksums to prevent manipulation, and enabling wireless transmission for secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If only a security token is used in the optoelectronically readable code, then authentication security is maintained, but visual verification of user integrity is lost
Solution Approach 1:
The patent combines a security token with image data into a single optoelectronically readable code. The code contains both the encrypted security token and the image of the authorized user, allowing simultaneous visual verification and secure authentication when the code is read by the access control device
Solution Approach 2:
The optoelectronically readable code serves multiple functions: it acts as a visual identification medium displaying the user's image, contains an encrypted security token for authentication, and provides tamper-evident verification through checksum validation, replacing the need for separate identification and authentication elements
2Ease of operation
If image data is added to the optoelectronically readable code, then visual verification capability is improved, but code complexity and manipulation risk increase
Solution Approach 1:
The code structure is segmented into distinct functional components: an image data portion for visual verification, an encrypted security token portion for authentication, and a checksum portion for integrity verification. This segmentation allows each component to be processed independently while maintaining overall code functionality
Solution Approach 2:
The patent applies encryption to the security token portion and generates a checksum based on both the image data and security token. These parameter changes (encryption and checksum generation) protect the code from manipulation while maintaining its visual and authentication functions
3Reliability
If encryption is applied to the security token, then authentication security is enhanced, but processing time and computational requirements increase
Solution Approach 1:
The security token is encrypted in advance when the optoelectronically readable code is generated and stored. This preliminary encryption action ensures that the token is already protected when needed for authentication, eliminating the need for real-time encryption processing during the authentication transaction
4Reliability
If a checksum is generated from image data and security token, then tamper detection capability is improved, but code complexity increases
Solution Approach 1:
The checksum function is segmented as a distinct component that separately processes the image data and security token portions of the code. This segmentation allows the checksum to be generated and validated as an independent integrity check without complicating the core image and token storage functions
Data Source
Figure 1
Figure 2
AI summary
A method for authentication using an optoelectronically readable code (5) is described. The optoelectronically readable code (5) contains image data associated with an image of an authorized user (N) or object, and a secret, encrypted security token. The image data associated with the image, together with the security token, form a combined encrypted payload in the optoelectronically readable code (5).The integrity of the user (N) of the optoelectronically readable code (5) is verified by decrypting the payload contained in the optoelectronically readable code (5), reading the image data associated with the image from the decrypted payload, and comparing the image associated with the read image data with the corresponding appearance of the user (N) or object initiating authentication with the optoelectronically readable code (5). Furthermore, the user (N) or object is authenticated by verifying the security token contained in the optoelectronically readable code (5).