Passwordless Web Checkout Using QR Codes and SMTP Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Standard web-based checkouts require customers to remember passwords for each transaction, deterring repeat purchases and posing security risks, as they often rely on a single identifier for verification.
Innovation Solution
A system that uses multiple identifiers such as phone number, email address, and social media account information, authenticated through SMS, email, and social media, to facilitate secure web-based checkouts without passwords, utilizing secret pins and alternative link formats like SMS and social media messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard web-based checkout requires password authentication, then security is maintained, but user convenience deteriorates and repeat purchases are deterred
Solution Approach 1:
The patent introduces SMS messages as an intermediary authentication mechanism between the customer and the website. Instead of requiring direct password entry on the website, the system sends a verification code via SMS to the customer's phone, which then authenticates the customer. This mediator approach maintains security while significantly improving convenience, as customers don't need to remember or re-enter passwords for each transaction.
Solution Approach 2:
The patent replaces the mechanical password-based authentication system with an SMS-based verification system. The traditional mechanical process of remembering and entering passwords is substituted with an automated SMS code delivery and verification process. This substitution maintains the security function while eliminating the user burden of password management, thereby improving ease of operation.
2Reliability
If single identifier verification is used, then checkout process is simple, but security and customer identification reliability are reduced
Solution Approach 1:
The patent merges multiple identification methods into a unified authentication system. It combines website login credentials with SMS verification codes and phone number-based identification. By merging these different identification mechanisms, the system achieves more reliable customer identification without significantly increasing the complexity at any single step, as the SMS verification acts as a simple additional layer rather than a complex multi-step process.
3Productivity
If password-protected accounts are required for each vendor, then account security is maintained, but customer convenience and time efficiency deteriorate
Solution Approach 1:
The patent applies preliminary action by having customers provide their phone numbers during the initial registration process, and by having the system pre-configure SMS verification capabilities. During subsequent transactions, the system automatically sends verification codes via SMS without requiring customers to manually log in or re-enter authentication information. This preliminary setup enables rapid, secure transactions without the time-consuming password entry process.
Data Source
AI summary
A method, system, and computer-readable medium are disclosed for improving computer network security using Simple Mail Transfer Protocol (SMTP) and a Quick Response (QR) code to authenticate users prior to granting access to a secure webpage. A vendor system receives a transaction request from a user and obtains a user identifier. The vendor system communicates with an e-commerce system to generate a QR code containing a token and a transaction-specific link. The token is generated based on the user identifier and transaction details. When the user activates the link, an email response is automatically transmitted via SMTP to the e-commerce system, which authenticates the token to verify the user. Upon successful authentication, the e-commerce system notifies the vendor system, which then grants the user access to the secure webpage.


