QR Code Authentication for Secure Password Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in managing and remembering multiple passwords for different web services, leading to confusion or forgetfulness, as each service may have unique password requirements.

Innovation Solution

A method and system that uses a mobile terminal device with a security element to authenticate a user to a web server by generating a QR code containing a server URL, public key, and identification element, which is scanned to retrieve and encrypt a stored password, then submitted to an authentication server for decryption and use in accessing the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users store multiple passwords for different web services, then security is improved, but user memory burden and confusion increase

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a mobile terminal device as an intermediary between the user and web services. This device stores passwords securely and automatically transmits them to web servers via QR code scanning, eliminating the need for users to manually remember and type multiple passwords while maintaining security through encrypted storage and transmission

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users use complex passwords for security, then protection against attacks is improved, but password management difficulty increases

Engineering Contradiction:
Improveprotection against attacksVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile terminal device automatically manages complex passwords by storing them in encrypted form and retrieving them on-demand. The system performs self-service functions including automatic password generation, secure storage, and transmission without requiring users to manually handle complex password creation or memorization

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile terminal acts as a mediator that handles complex password management tasks. It stores passwords in encrypted form using strong algorithms and transmits them securely via QR codes, allowing users to benefit from strong password protection without the burden of managing them manually

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If passwords are transmitted securely using encryption, then security is improved, but transmission complexity increases

Engineering Contradiction:
Improvesecure transmissionVSAvoidtransmission process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual password transmission (typing passwords into web forms) with automated optical recognition technology. The mobile terminal captures QR codes containing encrypted password data and automatically transmits them to the web server, eliminating manual intervention while maintaining security through cryptographic encryption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system uses QR codes as optical copies of password credentials. Instead of transmitting passwords directly through text input, the encrypted password data is encoded into visual QR code format, captured by the mobile terminal's camera, and automatically processed for transmission to the web server

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3053317B1Method for authentication with respect to a server
Publication Date: 2018.06.13 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP3053317B1 patent drawingFigure 1
  • EP3053317B1 patent drawingFigure 2
  • EP3053317B1 patent drawing

AI summary

The invention relates to a method, to devices, and to a system for authenticating a user of a computer unit (30) with respect to a server (40). The method comprises the following steps: requesting password-protected access to the server (40) by means of the computer unit (30); outputting a code containing a URL address of the server (40) by means of the computer unit (30); capturing the code and extracting the URL address of the server (40) from the code by means of a mobile terminal (12); determining a password stored in a security element (20) of the mobile terminal (12) in connection with the URL address of the server (40); transmitting the password to an authentication server (50); retrieving the password from the authentication server (50) by means of the computer unit (30); and authenticating the user of the computer unit (30) with respect to the server (40) by means of the password.