Key points are not available for this paper at this time.
QR phishing, or “quishing”, is an emerging cyber threat that uses malicious QR codes to trick users into revealing sensitive information. The QR code scanning increased by 433% between 2021 and 2023, while phishing attacks exploded by 270% in 2024 alone; these increased statistics make urgent measures against quishing necessary. To secure QR code interactions, this work introduces a centralised system that integrates per-code AES-GCM encryption with key derivation (HKDF), real-time revocation checks, and blockchain-based integrity verification. The design employs a secure, three-tier service-oriented architecture that logically separates cryptographic services to protect sensitive operations and enables online verification via RESTful APIs.The Key contributions to this paper are: (1) A distributed three-tier architecture separating Blockchain Server, Key Management Server, and Verifier components, (2) Cryptographic key derivation ensuring the compromise of one QR code does not affect others, (3) Real-time revocation mechanism using distributed blockchain propagation for immediate response against compromised codes, and (4) mobile-optimised web interface along with validation of enterprise-scale performance. The experimental results show that the proposed system successfully prevents quishing attacks without sacrificing performance, making it suitable for enterprise deployment.This approach enhances users’ trust and presents an efficient countermeasure for quishing attacks, ensuring the integrity of data through cryptographic verification, real-time revocation, and authentication of QR code across diverse environments.
Yalda et al. (Sat,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: