Trust Code Generation for Forgery-Proof Optical Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of optical codes in various applications has made them vulnerable to attacks, such as phishing, where users' valuable information can be compromised, necessitating a method to enhance their authenticity and integrity checks.
Innovation Solution
A method that generates and verifies a 'trust code' within optical codes, using a combination of cryptographic hashing and asymmetric encryption, allowing users to verify the integrity and authenticity of the data without an online connection, using a smartphone's software to check the trust code before accessing linked information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If optical codes are used in open systems without centralized verification, then ease of operation and accessibility are improved, but reliability and security deteriorate due to vulnerability to phishing attacks
Solution Approach 1:
The patent applies preliminary action by pre-generating cryptographic hash values and digital signatures during the optical code creation process. The trust code containing hashed data and cryptographic signatures is embedded into the optical code before it is presented to the user. This allows the mobile device to perform offline verification of the code's authenticity and integrity without requiring real-time connection to a centralized verification system, thus maintaining both ease of operation and reliability.
2Reliability
If cryptographic verification methods are implemented in optical codes, then reliability and security are improved, but device complexity increases due to additional verification components
Solution Approach 1:
The patent applies the taking out principle by extracting the cryptographic verification functionality from complex centralized systems and embedding it directly into the optical code itself. The trust code contains pre-computed hash values, digital signatures, and verification data that can be independently validated by the mobile device. This extraction simplifies the overall system architecture by eliminating the need for complex real-time communication infrastructure while maintaining high reliability through self-contained verification capabilities.
Solution Approach 2:
The patent implements self-service by enabling the mobile device to autonomously verify the authenticity and integrity of optical codes using the cryptographic data embedded within the trust code. The verification process uses the device's existing camera and processing capabilities to compute hash values and validate digital signatures locally, without requiring external verification services or complex additional hardware. This self-service approach maintains reliability while minimizing device complexity.
3Reliability
If online connection is required for verification, then reliability is improved through centralized checking, but loss of time occurs due to network dependency
Solution Approach 1:
The patent applies preliminary action by pre-computing and embedding all necessary verification data (hash values, digital signatures, trust codes) into the optical code during its creation. This allows the mobile device to perform complete verification offline using only the data contained within the code itself, eliminating network latency and connection requirements. The centralized verification accuracy is maintained through cryptographically secure hash functions and digital signatures, while verification time is reduced to the speed of local computational processing.
Data Source
Figure 1
Figure 2
AI summary
The application relates to a method for generating a signature (SIGNATURE) for a trust code, which serves to ensure the authenticity and integrity of data (DATA) presented in an optical code, wherein the data (DATA) comprises a data link, in particular a link, and a trust code for presentation in an optical code, in particular a 2D code. Furthermore, the application relates to a method for ensuring the authenticity and integrity of a data link, as well as the software provided for this purpose.