Inspiration:QR codes are convenient for authentication and access, but a static QR code can potentially be copied, shared, or reused by an unauthorized person. We wanted to build a system where simply possessing a QR image would not be enough to gain access.

This led us to the idea of SecureQR, where QR codes are designed to be temporary and verifiable rather than permanently reusable

What it does:SecureQR provides a secure QR-based verification workflow:

Generates one-time QR codes

Uses trusted cryptographic keys to verify authenticity

Allows QR codes to be revoked

Prevents previously used QR codes from being reused

Verifies whether a QR code is valid before granting access

Provides a foundation for secure temporary authentication and access management

The goal is to add a security layer between a QR code and the resource or service it protects.

How we built it:The project was developed as a mobile-based cybersecurity application with a secure verification backend.

The main components are:

QR Generator – Creates temporary QR credentials.

QR Scanner – Scans and extracts the QR information.

Trusted Key System – Uses cryptographic keys to verify that a QR code was generated by a trusted source.

One-Time Verification – Tracks QR usage so a valid QR cannot simply be reused.

Revocation System – Allows compromised or invalid QR credentials to be revoked.

Backend Verification – Validates QR requests and returns the verification result.

Secure Access Flow – Grants access only after successful verification.

Challenges we ran into:One of the biggest challenges was designing the QR workflow so that security was not dependent only on the QR image itself.

We had to think about:

How to prevent QR reuse

How to verify that a QR was generated by a trusted source

How to handle revoked credentials

How the mobile application should communicate with the backend

How to balance security with a simple user experience

How to test invalid, expired, reused, and revoked QR codes

Accomplishments that we're proud of:We’re proud of building a working cybersecurity-focused QR verification concept that combines one-time QR codes, trusted cryptographic keys, and QR revocation into a single secure access workflow.

We’re especially proud of turning a common QR-based process into a security-focused solution while learning practical concepts such as authentication, cryptography, backend verification, and access control.

What we learned:Building SecureQR helped us understand how different cybersecurity concepts work together in a practical application.

We learned about:

QR-based authentication

Cryptographic key verification

Secure client-server communication

Temporary credentials

Access control

Token validation

Revocation mechanisms

Secure application design

Mobile application development

🚀

What's next for SecureQR – Secure One-Time QR Verification:## What's Next for SecureQR

Our next step is to make SecureQR more robust, scalable, and practical for real-world use.

  • Stronger authentication: Add biometric or multi-factor authentication for sensitive access.
  • Advanced QR security: Introduce QR expiration, replay-attack protection, and stronger token validation.
  • Real-time revocation: Improve the backend so compromised QR credentials can be revoked instantly.
  • Cloud deployment: Deploy the backend infrastructure for reliable real-world access.
  • Security monitoring: Add logs and alerts for suspicious or repeated verification attempts.
  • Broader use cases: Adapt SecureQR for campuses, events, offices, visitor management, and temporary digital identity verification.
  • Production release: Improve UI, performance, testing, and security before releasing SecureQR as a production-ready application.

Our long-term goal is to turn SecureQR into a reliable temporary-access platform where QR credentials are secure, verifiable, time-limited, and difficult to reuse or abuse.

Built With

  • access-control
  • android
  • android-studio
  • api-security
  • authentication
  • authorization
  • backend
  • cryptography
  • cybersecurity
  • digital-identity
  • flask
  • information
  • kotlin
  • one-time-tokens
  • python
  • qr-code
  • rest-api
  • secure-qr
  • sqlite
Share this project:

Updates

Submission history