Certificate-Based Mobile Authentication via QR Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for online banking transactions are vulnerable to fraud due to the transfer of confidential data in unencrypted forms, allowing attackers to intercept and forge data, leading to increased risks of unauthorized transactions and financial losses.
Innovation Solution
Implementing a certificate-based authentication system using smart mobile devices with X.509 certificates and Public Key Infrastructure (PKI) technology for secure two-factor authentication, where the private key is generated and stored on the mobile device, ensuring secure communication through SSL channels and reducing the risk of data interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If confidential data is transferred in unencrypted form between authentication components, then the authentication process is simple and fast, but the security is compromised and data can be intercepted and forged by attackers
Solution Approach 1:
The patent extracts confidential data (card number, amount, account number) from the authentication process. Instead of transmitting these sensitive details over the network, only a QR code containing a transaction identifier is exchanged. The actual confidential information remains localized on the terminal and is never transmitted, thereby eliminating the security vulnerability while maintaining authentication functionality.
Solution Approach 2:
The patent introduces a QR code as an intermediary carrier for authentication data exchange. Rather than directly transmitting confidential banking information between terminal and mobile device, the system uses a QR code containing only a transaction identifier as a safe mediator. This intermediary approach enables authentication while preventing exposure of sensitive data during transmission.
2Ease of operation
If QR codes contain confidential transaction data for authentication, then the authentication process is straightforward, but the confidential data becomes accessible to anyone with a QR code reader
Solution Approach 1:
The patent removes confidential transaction data from the QR code content. The QR code contains only a transaction identifier, not the actual sensitive information such as card number, amount, or account number. This extraction ensures that even if someone scans the QR code, they cannot access the confidential banking data, while the authentication process remains user-friendly.
3Reliability
If the terminal displays transaction data for user confirmation, then the user can verify the transaction, but the data can be forged if the terminal is compromised
Solution Approach 1:
The patent uses a QR code as an intermediary that carries a transaction identifier from the terminal to the mobile device. The mobile device then communicates with the authentication server to verify the transaction. This intermediary approach allows the user to verify transactions through the mobile device while preventing direct forgery through terminal compromise, as the mobile device independently validates the transaction with the server.
Data Source
AI summary
The invention relates to a method for authenticating a user (10) at an entity (16), the method comprising the steps of detecting, by means of a contact module (20) of the entity (16), a contacting of the user (10) made in a browser of a terminal (12), and sending, by means of the contact module (20), a network address of an authentication module (24) of the entity (16) to a mobile device (14) of the user (10) in an authentication message, verifying the acceptability of an entity certificate of the authentication module (24) by means of the mobile device (14) based on the network address, and verifying acceptability of a user certificate of the mobile device (14) by means of the authentication module (24), and in case the entity certificate and the user certificate are acceptable, authenticating the user (10) at the entity (16) by establishing a communication channel (114, 120, 114, 120) between the mobile device (14) and the authentication module (24), whereas in case the entity certificate or the user certificate is not acceptable, rejecting the user (10) at the entity 16. The invention also relates to a system for authenticating a user (10) at an entity (16).


