Certificate-Based Mobile Authentication via QR Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for online banking transactions are vulnerable to fraud due to the transfer of confidential data in unencrypted forms, allowing attackers to intercept and forge data, leading to increased risks of unauthorized transactions and financial losses.

Innovation Solution

Implementing a certificate-based authentication system using smart mobile devices with X.509 certificates and Public Key Infrastructure (PKI) technology for secure two-factor authentication, where the private key is generated and stored on the mobile device, ensuring secure communication through SSL channels and reducing the risk of data interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If confidential data is transferred in unencrypted form between authentication components, then the authentication process is simple and fast, but the security is compromised and data can be intercepted and forged by attackers

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts confidential data (card number, amount, account number) from the authentication process. Instead of transmitting these sensitive details over the network, only a QR code containing a transaction identifier is exchanged. The actual confidential information remains localized on the terminal and is never transmitted, thereby eliminating the security vulnerability while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a QR code as an intermediary carrier for authentication data exchange. Rather than directly transmitting confidential banking information between terminal and mobile device, the system uses a QR code containing only a transaction identifier as a safe mediator. This intermediary approach enables authentication while preventing exposure of sensitive data during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If QR codes contain confidential transaction data for authentication, then the authentication process is straightforward, but the confidential data becomes accessible to anyone with a QR code reader

Engineering Contradiction:
Improveauthentication easeVSAvoiddata accessibility to attackers
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent removes confidential transaction data from the QR code content. The QR code contains only a transaction identifier, not the actual sensitive information such as card number, amount, or account number. This extraction ensures that even if someone scans the QR code, they cannot access the confidential banking data, while the authentication process remains user-friendly.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the terminal displays transaction data for user confirmation, then the user can verify the transaction, but the data can be forged if the terminal is compromised

Engineering Contradiction:
Improvetransaction verificationVSAvoiddata forgery risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent uses a QR code as an intermediary that carries a transaction identifier from the terminal to the mobile device. The mobile device then communicates with the authentication server to verify the transaction. This intermediary approach allows the user to verify transactions through the mobile device while preventing direct forgery through terminal compromise, as the mobile device independently validates the transaction with the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2929671B1Method and system for authenticating a user using a mobile device and by means of certificates
Publication Date: 2017.02.22 MICROSEC SZAMITASTECHN FEJLESZTO ZRT
  • EP2929671B1 patent drawing
  • EP2929671B1 patent drawing
  • EP2929671B1 patent drawing

AI summary

The invention relates to a method for authenticating a user (10) at an entity (16), the method comprising the steps of detecting, by means of a contact module (20) of the entity (16), a contacting of the user (10) made in a browser of a terminal (12), and sending, by means of the contact module (20), a network address of an authentication module (24) of the entity (16) to a mobile device (14) of the user (10) in an authentication message, verifying the acceptability of an entity certificate of the authentication module (24) by means of the mobile device (14) based on the network address, and verifying acceptability of a user certificate of the mobile device (14) by means of the authentication module (24), and in case the entity certificate and the user certificate are acceptable, authenticating the user (10) at the entity (16) by establishing a communication channel (114, 120, 114, 120) between the mobile device (14) and the authentication module (24), whereas in case the entity certificate or the user certificate is not acceptable, rejecting the user (10) at the entity 16. The invention also relates to a system for authenticating a user (10) at an entity (16).