Optoelectronically Readable Code for Secure User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods using optoelectronically readable codes lack a comprehensive solution for ensuring the integrity and security of user authentication, particularly in accessing controlled areas, as they do not effectively combine visual verification with secure token validation.

Innovation Solution

The method integrates a secret, encrypted security token with an image of an authorized user or object into an optoelectronically readable code, allowing for both visual integrity checks and secure token authentication, using encryption and checksums to prevent manipulation, and enabling wireless transmission for secure access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only a security token is used in the optoelectronically readable code, then authentication security is maintained, but visual verification of user integrity is lost

Engineering Contradiction:
Improveauthentication securityVSAvoidvisual verification
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines a security token with image data into a single optoelectronically readable code. The code contains both the encrypted security token and the image of the authorized user, allowing simultaneous visual verification and secure authentication when the code is read by the access control device

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The optoelectronically readable code serves multiple functions: it acts as a visual identification medium displaying the user's image, contains an encrypted security token for authentication, and provides tamper-evident verification through checksum validation, replacing the need for separate identification and authentication elements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If image data is added to the optoelectronically readable code, then visual verification capability is improved, but code complexity and manipulation risk increase

Engineering Contradiction:
Improvevisual verificationVSAvoidcode structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The code structure is segmented into distinct functional components: an image data portion for visual verification, an encrypted security token portion for authentication, and a checksum portion for integrity verification. This segmentation allows each component to be processed independently while maintaining overall code functionality

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies encryption to the security token portion and generates a checksum based on both the image data and security token. These parameter changes (encryption and checksum generation) protect the code from manipulation while maintaining its visual and authentication functions

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption is applied to the security token, then authentication security is enhanced, but processing time and computational requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security token is encrypted in advance when the optoelectronically readable code is generated and stored. This preliminary encryption action ensures that the token is already protected when needed for authentication, eliminating the need for real-time encryption processing during the authentication transaction

Inventive Principle:
Principle #10Preliminary action

4Reliability

If a checksum is generated from image data and security token, then tamper detection capability is improved, but code complexity increases

Engineering Contradiction:
Improvetamper detectionVSAvoidcode structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The checksum function is segmented as a distinct component that separately processes the image data and security token portions of the code. This segmentation allows the checksum to be generated and validated as an independent integrity check without complicating the core image and token storage functions

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3971846A1Method for authenticating with an optoelectronically readable code and access control device and computer program therefor
Publication Date: 2022.03.23 ASTRA GESELLSCHAFT FUR ASSET MANAGEMENT MBH & CO KG
  • EP3971846A1 patent drawingFigure 1
  • EP3971846A1 patent drawingFigure 2
  • EP3971846A1 patent drawing

AI summary

A method for authentication using an optoelectronically readable code (5) is described. The optoelectronically readable code (5) contains image data associated with an image of an authorized user (N) or object, and a secret, encrypted security token. The image data associated with the image, together with the security token, form a combined encrypted payload in the optoelectronically readable code (5).The integrity of the user (N) of the optoelectronically readable code (5) is verified by decrypting the payload contained in the optoelectronically readable code (5), reading the image data associated with the image from the decrypted payload, and comparing the image associated with the read image data with the corresponding appearance of the user (N) or object initiating authentication with the optoelectronically readable code (5). Furthermore, the user (N) or object is authenticated by verifying the security token contained in the optoelectronically readable code (5).