QR Code Authentication System for PKI Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems, particularly those using Public Key Infrastructure (PKI) on smartphones, face challenges due to the difficulty in entering long PKI keys and the risk of key misuse when devices are stolen, making them unsuitable for secure transactions.

Innovation Solution

The method employs sets of authentication codes comprising private key containers, public key containers, and secrets like passwords or PIN codes, encoded in QR-codes, RFID tags, or NFC tags, which are read using mobile terminals to authenticate entities without storing PKI keys on the device, ensuring high security and device independence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI keys are stored on the smartphone device, then authentication functionality is enabled, but security is compromised due to device theft or information copying

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the PKI keys from the smartphone device and stores them externally on secure servers. The device only holds references to these keys, not the keys themselves. This extraction resolves the contradiction by enabling authentication functionality while eliminating the security risk of storing sensitive keys on potentially compromised devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces secure servers as intermediaries that hold and manage the PKI keys. Instead of direct storage on the device, the system uses these intermediary servers as a trusted third party to store, protect, and provide access to the keys. This mediator approach enables authentication while maintaining security by keeping keys away from vulnerable devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If long PKI key strings are required for authentication, then security is enhanced, but user-friendliness deteriorates due to difficulty in manual entry

Engineering Contradiction:
ImprovePKI securityVSAvoidkey entry
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses QR codes as visual copies of the authentication information. Instead of requiring users to manually type long PKI key strings, the system generates QR code representations that users can scan with their cameras. This copying approach maintains the security of long key strings while dramatically improving ease of operation through simple scanning actions.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical typing process with an optical scanning process. Users substitute manual keyboard entry with camera-based QR code scanning. This substitution eliminates the tedious manual entry of long key strings while preserving the security benefits of using comprehensive PKI keys, as the optical scanning automatically captures the full key information.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If authentication systems are designed for specific devices, then device-specific security can be optimized, but versatility across different terminal types is reduced

Engineering Contradiction:
Improvedevice-specific securityVSAvoidterminal compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication system that works across multiple device types including smartphones, tablets, and computers. By using platform-independent technologies like QR codes and web-based authentication flows, the system achieves multi-functionality. This universal approach maintains device-specific security optimizations while enabling broad adaptability across different terminal types through a common authentication protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2695354B1Method and system for authenticating entities by means of terminals
Publication Date: 2020.07.22 BUNTINX
  • EP2695354B1 patent drawingFigure 1
  • EP2695354B1 patent drawingFigure 2
  • EP2695354B1 patent drawingFigure 3

AI summary

In the proposed method users (A, B) are provided with sets of authentication codes (3,4,5), each set comprising at least one secret (3), a private key container (4) and a matching public key container (5), the private and public key container generated from respectively a first string (1) comprising a domain name of an authentication server system (10) and a PKI private key and a second string (2) comprising the same domain name and a matching PKI public key. Upon receipt on the authentication server system (10) of one of the first strings (1) as a result of a first user reading the respective private key container (4), an action definition procedure is performed in which the first user is requested to enter a secret (3) of the same set of authentication codes (3,4,5). If a check returns a positive result, the first user can define a set of actions to be performed upon receipt of the second string (2) belonging to the same set of authentication codes on the authentication server system (10).