QR Code Transaction Security via Layered Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication methods between sales terminals and transaction control servers are vulnerable to 'Man in the Middle' and 'brute force' attacks, compromising security during transactions.
Innovation Solution
Enhancing the QR code content with a second random string and using multiple encryption algorithms to create complex encrypted messages, which increase entropy and make 'brute force' attacks impractical, while preventing external analysis of protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard QR code communication is used between sales terminal and transaction control server, then ease of operation is improved, but security is worsened due to vulnerability to Man in the Middle and brute force attacks
Solution Approach 1:
The patent applies parameter changes by modifying the QR code content structure to include additional security parameters. Specifically, it adds a second random string and multiple encryption layers to the traditional QR code data, transforming the communication protocol from simple to secure without changing the fundamental QR code mechanism. This resolves the contradiction by enhancing security parameters while maintaining operational simplicity.
Solution Approach 2:
The patent uses composite materials analogy by creating a composite encryption structure. It combines multiple encryption algorithms (first and second encryption algorithms with different keys) and multiple random strings (first and second random strings) into a layered security framework. This composite approach provides robust security against various attacks while preserving the ease of QR code-based operation.
2Reliability
If encryption algorithms are added to secure communication, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent applies segmentation by dividing the encryption process into distinct segments or layers. It uses a first encryption algorithm with a first key for initial encryption, then a second encryption algorithm with a second key for additional security. Each layer can be independently implemented and managed, reducing the complexity burden on any single component while achieving cumulative security benefits.
Solution Approach 2:
The patent introduces intermediaries in the form of random strings that mediate between the encryption processes. The first random string is used in the first encryption layer, and the second random string is used in the second encryption layer. These intermediaries add security complexity without requiring the terminal or server to manage overly complex encryption logic directly, as the random strings serve as manageable intermediating elements.
Data Source
Figure 1
AI summary
• - construction by the server (2) and the sale terminal (1) respectively of first and second encrypted messages; • - construction by the sale terminal (1) of a third encrypted message, using the second encrypted message, then transmission of same to the server (2); • - decryption by the server (2) of the third encrypted message, using the first encrypted message; • - construction by the server (2) of a fourth encrypted message on the basis of the content of the third decrypted message, using the first encrypted message, then transmission of same to the sale terminal (1); • - decryption by the sale terminal (1) of the fourth encrypted message, using the second encrypted message. • The sale terminal 1 generates and displays a set of information relative to the transaction in the form of a QR code 5, for example. This identification information will then be supplemented by a random chain consisting of a series of random characters, generated by the sale terminal 1. The decryption key is generated using two random numbers.