QR Code Segmentation for Secure Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The authentication of user identity in electronic transactions is vulnerable to interception and misuse due to the capture of wireless network traffic containing security questions and biometric identifiers, making existing methods insecure against fraudulent activities.

Innovation Solution

A method involving the disassembly of QR codes into non-overlapping portions, where only one portion is transmitted, preventing unauthorized access to biometric identifiers or security questions, and reassembly on the mobile device for secure authentication, ensuring that only the user and the enterprise can access the authentication information during transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complete QR codes containing authentication information are transmitted over network, then authentication can be performed, but security is compromised due to interception of network traffic

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork traffic interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the QR code into multiple portions, where only a first portion is transmitted over the network while the second portion remains local. This segmentation ensures that even if network traffic is intercepted, the complete authentication information cannot be obtained, thus resolving the contradiction between enabling authentication and preventing interception.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a structure where the first portion of the QR code contains embedded information that allows the mobile device to retrieve and display the second portion locally. This nested structure ensures that the authentication information is progressively revealed only to authorized devices, maintaining security while enabling authentication.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of operation

If QR code portions are transmitted to enable authentication, then user identity can be verified, but unauthorized access to authentication information may occur

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication information exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

By segmenting the QR code into transmitted and non-transmitted portions, the patent enables authentication to proceed while preventing unauthorized access to complete authentication information. The first portion transmitted contains sufficient information for the mobile device to reconstruct the full QR code locally, maintaining ease of operation without information exposure.

Inventive Principle:
Principle #1Segmentation

3Reliability

If biometric identifiers and security questions are transmitted for authentication, then user verification is achieved, but fraudulent transactions become possible through captured data

Engineering Contradiction:
Improveidentity verificationVSAvoidfraudulent transaction capability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments authentication information such that biometric identifiers and security questions are never transmitted over the network in complete form. Only encrypted portions are transmitted, which cannot be used for fraudulent transactions without the corresponding local portions, thus eliminating the harmful factor while maintaining verification reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the first portion of the QR code acts as a key to retrieve the second portion locally. This intermediary structure ensures that authentication information is accessible only through authorized intermediaries (the mobile device with the correct first portion), preventing fraudulent transactions while enabling legitimate verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9892404B2Secure identity authentication in an electronic transaction
Publication Date: 2018.02.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9892404B2 patent drawing
  • US9892404B2 patent drawing
  • US9892404B2 patent drawing

AI summary

An approach is provided for securely authenticating an identity of a user participating in an electronic transaction. A request for a biometric identifier/security question is converted to a first Quick Response (QR) code. Based on user attributes and a request from the user's mobile device to a computer to initiate the transaction, the first QR code is disassembled into first and second portions. The first portion, but not the second portion, is sent to the mobile device. Responsive to the mobile device receiving and converting the biometric identifier/answer to the security question to a second QR code, and disassembling the second QR code into first and second portions, the second QR code is reassembled. The transaction is authorized based on whether the biometric identifier/answer matches a data repository record.