Website Authentication via Encrypted QR Code Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing web site access are inadequate in preventing phishing attacks, as they require complex user interactions and do not easily allow verification of the authenticity of the site, leading to increased risk of fraud.
Innovation Solution
A method involving a user terminal to enter a personal, unpredictable message, which is encrypted by the web site server, displayed, and then decrypted by a second terminal, allowing the user to verify the authenticity of the site by recognizing the original message, ensuring it matches the intended site.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificates are used to verify website authenticity, then security against phishing is improved, but user interface complexity increases and becomes incomprehensible to general users
Solution Approach 1:
The patent creates a simplified visual copy of the website's authentication data in the form of a QR code. Instead of requiring users to interpret complex digital certificates, the system generates a machine-readable visual representation that can be easily scanned and verified by a mobile device, making certificate verification accessible to all users regardless of technical knowledge
Solution Approach 2:
The patent replaces the manual mechanical process of visually inspecting and interpreting complex certificate information with an automated optical scanning system. The mobile device's camera captures the QR code, and software automatically decrypts and verifies the authentication data, substituting human cognitive effort with automated machine processing
2Reliability
If extended certificates are used to display verified identity, then website authenticity verification is improved, but user interface complexity and information overload increase
Solution Approach 1:
The patent extracts the essential authentication information from complex extended certificates and encodes it into a compact QR code format. This visual representation contains only the critical verification data needed for authentication, eliminating unnecessary interface elements and presenting information in a simplified, easily consumable visual form
Solution Approach 2:
The patent utilizes visual encoding in the QR code where different visual patterns and color schemes can indicate various authentication states. The visual appearance of the code provides immediate intuitive feedback about the website's authenticity status, replacing complex text-based certificate information with intuitive visual signals
3Reliability
If manual URL entry is required to avoid phishing, then security is improved, but user convenience and productivity decrease
Solution Approach 1:
The patent performs preliminary authentication by generating and displaying the QR code on the website before the user completes any action. The authentication verification is automatically executed in the background during page loading, so when the user receives the notification and scans the code, the heavy verification work has already been done, enabling rapid confirmation without manual URL entry
Solution Approach 2:
The patent introduces a notification system as an intermediary between the website and the user. Instead of requiring direct user action to verify the URL, the system automatically communicates authentication status through a push notification, which serves as a mediator that conveys security information without requiring the user to manually verify anything
4Reliability
If spam filters are used to reduce phishing emails, then the number of phishing attempts received is reduced, but phishing risk and sophistication of attacks increase
Solution Approach 1:
The patent implements a feedback mechanism where the authentication QR code provides immediate visual confirmation of the website's legitimacy. This feedback loop allows users to instantly verify they are on the correct site before entering any information, creating a real-time verification system that counteracts sophisticated phishing attempts regardless of how well-spam filters perform
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for securing access to a website which includes, in series: a step (202) of a first user terminal accessing said site; a step (206) of entering a message with the user terminal on a page of the site; a step (208) of transmitting the message to a server of the website; a step (210) of the server of the website encrypting the message in order to form a visible code; a step (212) of displaying the visible code on a display screen of the first user terminal; a step (216) of taking an image of the visible code using a second user terminal, optionally identical to the first user terminal; a step (218) of decrypting the code using the second user terminal; and a step (220) of providing the user with the message decrypted by the second user terminal.