QR Code Authentication System for Contactless Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems lack secure verification of identities and authenticity between parties, especially in scenarios requiring remote interaction, and fail to record operations effectively without in-person interaction.
Innovation Solution
A communication system using mobile devices with sensors and displays, which decodes contactless identification data to authenticate users through an authentication server, enabling secure access and communication without in-person interaction by generating access tokens and facilitating communication mode selection between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless identification scanning is used for access control, then ease of operation is improved, but reliability of identity verification deteriorates
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the scanning device and the access control system. The server receives the identification data from the scanned code, performs cryptographic verification, and validates the user's identity through multiple authentication factors. This intermediary layer maintains the ease of contactless scanning while ensuring reliable identity verification through server-side cryptographic validation.
Solution Approach 2:
The system implements feedback mechanisms where the authentication server communicates verification results back to the access control system. The server provides cryptographic proof of authentication and validates the legitimacy of the requestor, creating a closed-loop verification process that ensures reliable identity confirmation while maintaining contactless operation.
2Ease of operation
If in persona interaction is eliminated for remote access, then ease of operation is improved, but reliability of authentication deteriorates
Solution Approach 1:
The patent replaces the mechanical requirement of in-person interaction with cryptographic authentication mechanisms. Instead of requiring physical presence for verification, the system uses digital signatures, cryptographic tokens, and server-side validation to authenticate users remotely. This substitution maintains authentication reliability while enabling contactless remote access operations.
Solution Approach 2:
The authentication server acts as a trusted intermediary that performs cryptographic verification in place of in-person authentication. The server validates user identities through digital credentials and cryptographic proofs, providing the same level of assurance as in-person verification without requiring physical presence. This intermediary mechanism enables reliable remote authentication.
3Device complexity
If traditional access control systems are used, then device complexity is reduced, but security level deteriorates
Solution Approach 1:
The patent introduces an authentication server as a centralized intermediary that handles complex cryptographic operations and security validation. This server-based approach consolidates security complexity in a dedicated component, allowing the access control devices themselves to remain relatively simple while achieving high security levels through server-side cryptographic verification and centralized credential management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A first device, with a sensor (e.g. camera) and a display, and configured to generate control data by decoding information embodied in a scanned (212) QR code having address data of an authentication server and identification data associated with a second device. The first device configured to: transmit (216) an authentication request to the authentication server (42), receiving (220) an authentication and/or access token from the authentication server and transmitting (222) a contact data request associated with the identification data to a data service, the contact data allowing the first device to establish communication with the second device, and the contact data request including the token, transmit (230) a communication request to the data service according to the contact data, the data service generates and issues (232) a user alert or notification identifying at least a mode of communication.