信息网络安全 ›› 2014, Vol. 14 ›› Issue (8): 67-70.doi: 10.3969/j.issn.1671-1122.2014.08.012

• Orginal Article • Previous Articles     Next Articles

A Hybrid Authentication Service System for 2D Barcode in O2O Application

ZHANG Yong-qiang1, TANG Chun-ming2, 3   

  1. 1.Guangdong Certificate Authority CO. Ltd., Guangzhou Guangdong 510100, China;
    2.School of Mathematics and Information Science, Guangzhou University, Guangzhou Guangdong 510006, China;
    3. Key Laboratory of Mathematics and Interdisciplinary Sciences of Guangdong Higher Education Institutes, Guangzhou University, Guangzhou Guangdong 510006, China
  • Received:2014-06-27 Online:2014-08-01

Abstract: As an information carrier, the 2D barcodes can bring consumers quick and convenient shopping experiences. However, the 2D barcodes must overcome the security challenges in the mobile internet environment, such as information leak and tampering, user authentication and repudiation. The capacity of 2D barcodes used in O2O application is limited and not suitable for embedding the digital certificates and certificate chains to utilize user authentication in traditional PKI system. In this paper, a technical solution is proposed to authenticate the electronic tag data in 2D barcodes, which is combining PKI and IBC cryptography. The length of public key in IBC, which is generated according to dedicated rules from digital certificates of PKI entity, is shortest to be used in 2D barcodes. The private key is securely delivered to the end user using a handshake authentication protocol. The signature and verification process are also designed to meet the security requirements in O2O appliances. Based on the proposal, the private keys of IBC system can be securely transferred to the users, and a trusting chain for the IBC digital signatures is established from the PKI digital certificates. A trusting network framework may be set up to authenticate the electronic tag data, and meet the security challenges in the capacity limited 2D barcodes, including data privacy, user authentication and trusting chain, etc.

Key words: 2D barcode, O2O, authentication service, PKI, IBC

CLC Number: