QR Access Credential Routing for Secure Cross-App Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for accessing resources using QR codes are vulnerable to hacking and require cumbersome manual updates of access data across multiple applications when it expires or becomes compromised.
Innovation Solution
A method and system that utilizes a unique identifier and access data reference identifier to facilitate secure remote transactions by communicating with a remote server computer to retrieve and validate access data, enabling seamless transaction processing across applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access data is stored on a communication device for use with multiple applications, then the user can access resources across applications, but the access data becomes vulnerable to hacking and requires manual updates across all applications when expired or compromised
Solution Approach 1:
The patent extracts the access data from the communication device and stores it on a remote server. The communication device only retains a reference identifier, not the actual access data. This extraction resolves the contradiction by maintaining multi-application accessibility (the reference identifier can be used across applications) while eliminating security vulnerabilities (the sensitive access data never resides on the user's device where it could be hacked).
Solution Approach 2:
The patent introduces a remote server as an intermediary between the user's communication device and the access data. The server acts as a mediator that stores the sensitive access data securely while providing it to applications only when needed and authorized. This intermediary resolves the contradiction by enabling cross-application access through the reference identifier while protecting the actual access data from exposure on the user's device.
2Reliability
If access data is manually updated in each application when expired or compromised, then each application has current access data, but the process becomes cumbersome and difficult especially when dealing with multiple applications
Solution Approach 1:
The patent implements self-service by automatically managing access data updates on the remote server. When access data expires or needs updating, the system automatically retrieves new access data from the resource provider and updates it on the server without requiring user intervention. The user simply needs to re-scan the QR code or initiate access, and the system handles the update process automatically across all applications, resolving the contradiction between maintaining current valid data and ease of operation.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring the system to automatically handle access data updates. The remote server is set up in advance to monitor access data validity, automatically retrieve updated credentials when needed, and push updates to all connected applications. This preliminary setup eliminates the need for manual updates by each user across multiple applications, resolving the contradiction between data freshness and operational ease.
3Reliability
If a centralized system stores access data remotely, then security is improved and updates are automated, but the system complexity increases with remote servers and database management
Solution Approach 1:
The patent applies universality by designing the remote server to perform multiple functions: storing access data, managing updates across applications, validating credentials, and communicating with resource providers. This multi-functional approach resolves the contradiction by consolidating complexity into a single centralized system that handles all security and update management, rather than distributing complexity across multiple applications on user devices.
Data Source
AI summary
A method is disclosed. The method includes receiving, by an application on a communication device from an access device, a unique identifier associated with a resource provider in a transaction. The method also includes transmitting, by the application, a message comprising the unique identifier and an access data reference identifier associated with access data to a remote server computer associated with the application. The remote server computer searches a database for access data using the access data reference identifier, retrieves the access data, and provides the access data to a transport computer which processes the transaction using the access data.


