Website Authentication via Encrypted QR Code Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing web site access are inadequate in preventing phishing attacks, as they require complex user interactions and do not easily allow verification of the authenticity of the site, leading to increased risk of fraud.

Innovation Solution

A method involving a user terminal to enter a personal, unpredictable message, which is encrypted by the web site server, displayed, and then decrypted by a second terminal, allowing the user to verify the authenticity of the site by recognizing the original message, ensuring it matches the intended site.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are used to verify website authenticity, then security against phishing is improved, but user interface complexity increases and becomes incomprehensible to general users

Engineering Contradiction:
Improvewebsite authentication reliabilityVSAvoiduser verification ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a simplified visual copy of the website's authentication data in the form of a QR code. Instead of requiring users to interpret complex digital certificates, the system generates a machine-readable visual representation that can be easily scanned and verified by a mobile device, making certificate verification accessible to all users regardless of technical knowledge

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the manual mechanical process of visually inspecting and interpreting complex certificate information with an automated optical scanning system. The mobile device's camera captures the QR code, and software automatically decrypts and verifies the authentication data, substituting human cognitive effort with automated machine processing

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If extended certificates are used to display verified identity, then website authenticity verification is improved, but user interface complexity and information overload increase

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidinterface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication information from complex extended certificates and encodes it into a compact QR code format. This visual representation contains only the critical verification data needed for authentication, eliminating unnecessary interface elements and presenting information in a simplified, easily consumable visual form

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent utilizes visual encoding in the QR code where different visual patterns and color schemes can indicate various authentication states. The visual appearance of the code provides immediate intuitive feedback about the website's authenticity status, replacing complex text-based certificate information with intuitive visual signals

Inventive Principle:
Principle #32Color changes

3Reliability

If manual URL entry is required to avoid phishing, then security is improved, but user convenience and productivity decrease

Engineering Contradiction:
Improvephishing prevention reliabilityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary authentication by generating and displaying the QR code on the website before the user completes any action. The authentication verification is automatically executed in the background during page loading, so when the user receives the notification and scans the code, the heavy verification work has already been done, enabling rapid confirmation without manual URL entry

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a notification system as an intermediary between the website and the user. Instead of requiring direct user action to verify the URL, the system automatically communicates authentication status through a push notification, which serves as a mediator that conveys security information without requiring the user to manually verify anything

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If spam filters are used to reduce phishing emails, then the number of phishing attempts received is reduced, but phishing risk and sophistication of attacks increase

Engineering Contradiction:
Improvephishing protection reliabilityVSAvoidphishing attack sophistication
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the authentication QR code provides immediate visual confirmation of the website's legitimacy. This feedback loop allows users to instantly verify they are on the correct site before entering any information, creating a real-time verification system that counteracts sophisticated phishing attempts regardless of how well-spam filters perform

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3350973B1Method for website authentication and for securing access to a website
Publication Date: 2021.10.20 ADVANCED TRACK & TRACE SA
  • EP3350973B1 patent drawingFigure 1
  • EP3350973B1 patent drawingFigure 2
  • EP3350973B1 patent drawingFigure 3

AI summary

The invention relates to a method for securing access to a website which includes, in series: a step (202) of a first user terminal accessing said site; a step (206) of entering a message with the user terminal on a page of the site; a step (208) of transmitting the message to a server of the website; a step (210) of the server of the website encrypting the message in order to form a visible code; a step (212) of displaying the visible code on a display screen of the first user terminal; a step (216) of taking an image of the visible code using a second user terminal, optionally identical to the first user terminal; a step (218) of decrypting the code using the second user terminal; and a step (220) of providing the user with the message decrypted by the second user terminal.