QR Code Transaction Security via Layered Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication methods between sales terminals and transaction control servers are vulnerable to 'Man in the Middle' and 'brute force' attacks, compromising security during transactions.

Innovation Solution

Enhancing the QR code content with a second random string and using multiple encryption algorithms to create complex encrypted messages, which increase entropy and make 'brute force' attacks impractical, while preventing external analysis of protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard QR code communication is used between sales terminal and transaction control server, then ease of operation is improved, but security is worsened due to vulnerability to Man in the Middle and brute force attacks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies parameter changes by modifying the QR code content structure to include additional security parameters. Specifically, it adds a second random string and multiple encryption layers to the traditional QR code data, transforming the communication protocol from simple to secure without changing the fundamental QR code mechanism. This resolves the contradiction by enhancing security parameters while maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses composite materials analogy by creating a composite encryption structure. It combines multiple encryption algorithms (first and second encryption algorithms with different keys) and multiple random strings (first and second random strings) into a layered security framework. This composite approach provides robust security against various attacks while preserving the ease of QR code-based operation.

Inventive Principle:
Principle #40Composite materials

2Reliability

If encryption algorithms are added to secure communication, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the encryption process into distinct segments or layers. It uses a first encryption algorithm with a first key for initial encryption, then a second encryption algorithm with a second key for additional security. Each layer can be independently implemented and managed, reducing the complexity burden on any single component while achieving cumulative security benefits.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediaries in the form of random strings that mediate between the encryption processes. The first random string is used in the first encryption layer, and the second random string is used in the second encryption layer. These intermediaries add security complexity without requiring the terminal or server to manage overly complex encryption logic directly, as the random strings serve as manageable intermediating elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2987124B1Method and system for improving the security of electronic transactions
Publication Date: 2019.05.29 ONEY BANK
  • EP2987124B1 patent drawingFigure 1

AI summary

• - construction by the server (2) and the sale terminal (1) respectively of first and second encrypted messages; • - construction by the sale terminal (1) of a third encrypted message, using the second encrypted message, then transmission of same to the server (2); • - decryption by the server (2) of the third encrypted message, using the first encrypted message; • - construction by the server (2) of a fourth encrypted message on the basis of the content of the third decrypted message, using the first encrypted message, then transmission of same to the sale terminal (1); • - decryption by the sale terminal (1) of the fourth encrypted message, using the second encrypted message. • The sale terminal 1 generates and displays a set of information relative to the transaction in the form of a QR code 5, for example. This identification information will then be supplemented by a random chain consisting of a series of random characters, generated by the sale terminal 1. The decryption key is generated using two random numbers.