WO2016141819A1 - 一种信息的防伪造方法、信息识别方法及装置 - Google Patents
一种信息的防伪造方法、信息识别方法及装置 Download PDFInfo
- Publication number
- WO2016141819A1 WO2016141819A1 PCT/CN2016/075374 CN2016075374W WO2016141819A1 WO 2016141819 A1 WO2016141819 A1 WO 2016141819A1 CN 2016075374 W CN2016075374 W CN 2016075374W WO 2016141819 A1 WO2016141819 A1 WO 2016141819A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- user
- additional information
- retained
- favorite
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/108—Source integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/121—Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
- H04W12/122—Counter-measures against attacks; Protection against rogue devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/128—Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
Definitions
- the present invention relates to the field of communication network technologies, and in particular, to an information anti-counterfeiting method, an information identifying method and a device.
- SMS Short message service
- spam messages mainly refer to illegal content such as advertisements and frauds that users have not customized, which affects the normal work and life of users. Spam messages not only impact the operators' networks, but also damage the interests of users. Bad social impact.
- a precautionary approach is that the operator system filters, identifies, and intercepts the content of the short message through the set identification rules.
- this method relies on the identification rule. After the scammer has some information, the identification rule can be bypassed. Anti-fraud means to scam, which results in poor recognition and interception of fraudulent SMS by the operator system. In addition, this method cannot prevent fraudulent text messages sent by fake base stations.
- Another prevention method is that the user can install a short message protection application on the mobile terminal, identify the received short message content and the sender information through the application, and intercept the identified fraudulent short message and the sender, but this The approach is also based on content and sender identification, and scammers can still scam through anti-fraud means.
- the content of the short message is private content, if the content of the short message is disclosed to Third-party applications will also come with security issues.
- the inventors of the present invention found that in the implementation of the existing fraud prevention, the fraudulent short message can not be effectively identified and intercepted. How to prevent fraudulent short message fraud and identify fraudulent short messages is a technical problem to be solved.
- an anti-forgery method for information is provided to solve the technical problem in the prior art that the user's interests are threatened because the fraudulent short message cannot be effectively recognized or the fraudulent short message is effectively prevented.
- the first aspect provides an anti-counterfeiting method for information, including:
- the constructing the additional information according to the retained information includes:
- the additional information is generated based on the retained information; or the retained information is directly used as additional information.
- the generating the additional information according to the retained information includes:
- Different levels of the additional information are generated based on the sensitivity level of the retained information.
- the retained information includes one or more of the following: one sentence or several sentences; one or several favorite hobbies; one or several favorite commodity categories; one or several favorite news Category; one or several favorite sports clubs; account information; identity information and passwords.
- the additional information includes one or more of the following: the retained information of the user; the related item that the user likes; the news that the user likes; the situation of the user's favorite sports club; the favorite poetic of the user; the user Account information; user identity information and user password.
- the information includes: a short message, a push notification, a phone call, a mail or a web page display.
- it also includes:
- the second aspect provides an information identification method, including:
- Receiving information sent by the website server the information including additional information, the additional information being constructed according to the retained information registered by the user on the website server;
- the additional information is presented to the user such that the user identifies the authenticity of the information based on the displayed content.
- the additional information includes one or more of the following:
- it also includes:
- the third aspect provides an information anti-counterfeiting device, comprising:
- An obtaining unit configured to obtain the retained information registered by the user on the website server
- a construction unit configured to construct additional information according to the retained information
- a sending unit configured to add the additional information to the information sent by the website server to the user, so that the user identifies the authenticity of the information according to the additional information.
- the constructing unit includes:
- a generating unit configured to generate the additional information according to the retained information; and/or;
- the generating unit includes:
- a first generating unit configured to generate, according to the content of the retained information, the additional information corresponding to the content
- a second generating unit configured to generate different levels of the additional information according to the sensitivity level of the retained information.
- the retention information acquired by the acquiring unit includes one or more of the following: one sentence or several sentences; one or several favorite hobbies; one or several favorite commodity categories; Several favorite news categories; one or several favorite sports clubs; account information; identity Information and password.
- the additional information constructed by the structural unit includes one or more of the following: retention information of the user; related products that the user likes; news that the user likes; the situation of the user's favorite sports club; and the user loves the poetry song. Assignment; user's account information; user's identity information and the user's password.
- the information sent by the sending unit includes: a short message, a push notification, a phone, a mail, or a web page display.
- it also includes:
- a notification unit configured to notify the user of the additional information after the construction unit constructs the additional information or before the sending unit sends the information.
- the fourth aspect provides an information identifying apparatus, including:
- a first receiving unit configured to receive information sent by a website server, where the information includes additional information, where the additional information is constructed according to the retained information registered by the user on the website server;
- the user presents the additional information to the user, so that the user identifies the authenticity of the information according to the displayed content.
- the additional information received by the first receiving unit includes one or more of the following:
- it also includes:
- the second receiving unit is configured to receive the additional information sent by the website server before the first receiving unit receives the information.
- the website server first constructs additional information for setting the authenticity according to the retained information of the user, and then adds the additional information to the information sent to the user, so that the user can
- the additional information identifies whether the information is forged fraudulent information, thereby improving the user's defense against fraudulent text messages and protecting their own interests.
- FIG. 1 is a flowchart of a method for preventing forgery of information according to an embodiment of the present invention
- FIG. 2 is a flowchart of an information identification method according to an embodiment of the present invention.
- FIG. 3 is a schematic structural diagram of an information anti-counterfeiting device according to an embodiment of the present invention.
- FIG. 4 is a schematic structural diagram of an information recognition apparatus according to an embodiment of the present invention.
- FIG. 5 is a schematic structural diagram of a website server according to an embodiment of the present invention.
- FIG. 6 is a schematic structural diagram of a user terminal according to an embodiment of the present disclosure.
- FIG. 7 is a schematic structural diagram of an application example of a website server according to an embodiment of the present invention.
- first, second, third, etc. may be used to describe various information in the embodiments of the present invention, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other.
- first information may also be referred to as the second information without departing from the scope of the embodiments of the invention, and does not necessarily require or imply any such actual relationship or order.
- second information may also be referred to as first information.
- the word “if” as used herein may be interpreted as “when” or “when” or “in response to a determination.”
- the term “comprises” or “comprises” or “comprises” or any other variations thereof is intended to encompass a non-exclusive inclusion, such that a process, method, article, or device that comprises a plurality of elements includes not only those elements but also Other elements, or elements that are inherent to such a process, method, item, or device.
- FIG. 1 is a flowchart of a method for preventing forgery of information according to an embodiment of the present invention. the method includes:
- Step 101 Acquire retention information registered by the user on the website server
- the user registers a retention information on the website server (that is, the server serving the website, or the network side device, etc.), and the retained information is commonly referred to as a secret number, that is, the website server obtains the retained information.
- the retained information includes but is not limited to one or more of the following: one sentence or several sentences; one or several favorite hobbies (or a poet or a certain poetry name, etc.); one or several Favorite merchandise category; one or several favorite news categories; one or several favorite sports clubs; account information; identity information and passwords, of course, the retained information is not limited to this, but also other users want to keep The information is not limited in this embodiment.
- Step 102 Construct additional information according to the retained information
- the website server constructs additional information according to the retained information, wherein there are two ways to construct:
- One way is to directly use the retained information as additional information
- the retained information can be directly used as additional information.
- the sentence or sentences can be used as additional information;
- the retained information of the user is account information, The account information may be used as additional information;
- the user's retained information is identity information, the identity information may be used as additional information;
- the user's retained information is a password, the password is used as the additional information.
- the retained information is not limited to this, and can also be adaptively modified according to the needs of the user.
- the corresponding additional information is also adaptively modified according to the retained retained information.
- the retained information is not limited to Therefore, the adaptive modification can also be performed according to the needs of the user.
- the generated additional information is also adaptively modified according to the retained retained information.
- the retained information in this manner may be one or more of the foregoing, and the corresponding additional information may also be one of the foregoing, or a combination of multiple.
- Another way is: generating the additional information according to the retained information
- the website server needs to generate additional information corresponding to the retained information according to the retained information of the user. For example, if the retained information of the user is a favorite product category, the corresponding additional information is generated as: the favorite product of the user. If the retained information of the user is a favorite news category, the corresponding additional information is generated: related news that the user likes; if the user retains the information as a favorite sports club, the corresponding additional information is generated: the favorite club of the user If the user's retained information is a hobby, the corresponding additional information is generated: the user's favorite poetry song.
- the retained information is not limited to this, and can be adaptively modified according to the needs of the user. When the user adaptively modifies the retained information, the generated additional information is also adaptively modified according to the retained retained information.
- the retained information in this manner may be one of the foregoing types, or a combination of multiple types; and the corresponding additional information may be generated by one or a combination of the foregoing.
- the generating the additional information according to the retained information also includes two ways:
- the website server generates the additional information corresponding to the content according to the content of the retained information
- the user's retained information is a favorite product category
- the corresponding additional information is generated as follows: the user's favorite product, of course, is not limited thereto, and is specifically shown in the above, and will not be described herein.
- the website server generates different levels of the additional information according to the sensitivity level of the retained information
- the web server keeps the user's retained information into three different levels according to the sensitivity level.
- the payment password and the like are the most sensitive information, which is called the first sensitive level;
- the retention level of the ID card is sensitive information, which is called the first
- the second sensitive level and the retained information such as the user name is not too sensitive information, which is called the third sensitive level, and vice versa.
- the embodiment of the present invention is not limited to the setting of the above-mentioned levels, and the division of more sensitive levels may be performed as needed, which is not limited in this embodiment.
- the additional information since the additional information has various characteristics, for example, when the additional information is a poetic, the user retains the information may be a hobby, or may be a poet or a poem set name, even if the scammer grasps by means of invasion or the like. The content of some SMS messages is still difficult to crack out the user's real retention information.
- Step 103 Add the additional information to the information sent by the website server to the user, so that the user identifies the authenticity of the information according to the additional information.
- the website server has information (herein referred to as information) to be sent to the user
- additional information constructed according to the retained information of the user is first added to the information, and then the information is sent to the user terminal (for example, the mobile phone, etc., and the user terminal presents the information including the additional information to the user, and the user can determine whether the information is forged false information or fraud information according to the additional information, that is, the user can Determine whether the information is False false information or fraud information, etc.
- the information may be a short message, a push notification, a phone, a mail, or a web page display.
- the related information includes, but is not limited to, a history of additional information display, optional additional information, an additional information feature table for disrupting the crack, or Other information used to construct additional information that is easier to understand and harder to crack.
- the website server first constructs additional information for setting the authenticity according to the retained information of the user, and then adds the additional information to the information sent to the user, so that the user can identify the information according to the additional information. Whether it is forged fraudulent information. That is to say, in the embodiment of the present invention, the fraudulent short message sent by the website is attached with obvious features that are difficult to forge and difficult to crack, thereby improving the user's prevention of fraudulent short messages and protecting their own interests.
- the embodiment is based on the foregoing embodiment, the method may further include: notifying the additional information after constructing the additional information or before the information To the user.
- the website server sends the information including the additional information to the user
- the constructed additional information that is easily recognized by the user and is difficult to forge is provided to the user, so that the user recognizes the received information. Whether it is forged fraudulent information to prevent fraud.
- FIG. 2 is a schematic diagram of an information identification method according to an embodiment of the present invention.
- the law includes:
- Step 201 Receive information sent by a website server, where the information includes additional information, where the additional information is constructed according to information retained by the user on the website server;
- the information may be a short message, a push notification, a phone call, a mail or a web page display, and the like.
- the purpose of using the secret number is to avoid leakage of more sensitive information, and at the same time provide sufficient clear information for the user to identify.
- the additional information may include one or more of the following: the user's retained information; the user's favorite related products; the user's favorite news; the user's favorite sports club's battle situation; the user's favorite poetry song assignment; the user's account information User's identity information and the user's password.
- the user's retained information may include one or more of the following: the user's retained information; the user's favorite related products; the user's favorite news; the user's favorite sports club's battle situation; the user's favorite poetry song assignment; the user's account information User's identity information and the user's password.
- the generated additional information is an item related to the user's favorite item; if the retained information is a user's favorite news category, then The generated additional information is news related to the favorite news category of the user; if the retained information is a sports club, the generated additional information is a battle situation of the sports club; if the retained information is Interests, the generated additional information is a poetry talent related to the hobby;
- the retained information may also be directly used as additional information.
- the retained information is one sentence or a few sentences retained by the user, one or a few sentences retained by the user are directly used as the additional information;
- the retained information is the account information of the user, the identity At least one of the information and the password, directly the account information and the identity letter of the user At least one of a message and a password is used as the additional information.
- different levels of the additional information may also be generated according to the sensitivity level of the retained information.
- the secret numbers of different sensitive levels are selectively disclosed.
- selecting to disclose different levels of retained information (the most sensitive retention information may be account information, identity information, password, etc.) to construct different levels of additional information to increase website information.
- the most sensitive retention information may be account information, identity information, password, etc.
- the configuration process of the additional information is the same as the configuration process of the additional information in the foregoing embodiment.
- the configuration process of the additional information is the same as the configuration process of the additional information in the foregoing embodiment.
- Step 202 Display the additional information to the user, so that the user identifies the authenticity of the information according to the displayed content.
- the user terminal (such as a mobile phone, a tablet, etc.) can directly display the retained information of the user in the additional information to the user, or the related product that the user likes; the news that the user likes; the battle situation of the user's favorite sports club; The poetry song is favored; the user's account information; one or more combinations of the user's identity information and the user's password are displayed to the user, so that the user can judge whether the received information is fraud information according to the additional information.
- the user terminal such as a mobile phone, a tablet, etc.
- the user terminal such as a mobile phone or the like
- the additional information is displayed to the user, and according to the additional information, whether the information is forged fraud information is identified. Thereby improving the user's identification of fraud information and protecting Self-interest.
- the embodiment is based on the foregoing embodiment, the method further includes: receiving the additional information sent by the website server before receiving the information.
- the website server notifies the user of the constructed additional information before transmitting the information including the additional information to the user, so that when the user receives the information, it is easy to recognize whether the information is forged fraud information.
- the additional information in the embodiment of the present invention is constructed according to the retained information registered by the user on the website server, so the scammer cannot forge a fraudulent short message for a specific user, and it is also difficult to forge a fraud covering a large range of users. Information, the effectiveness of its fraud information has dropped significantly.
- the embodiment of the present invention further provides an information anti-counterfeiting device, which is shown in FIG. 3, and the device includes: an obtaining unit 31, a constructing unit 32, and a sending unit 33, wherein ,
- the obtaining unit 31 is configured to acquire the retained information registered by the user on the website server, where the retained information includes one or more of the following: one sentence or several sentences; one or several favorite hobbies; Or a number of favorite merchandise categories; one or several favorite news categories; one or several favorite sports clubs; account information; identity information and passwords; but not limited to this.
- the constructing unit 32 is configured to construct additional information according to the retained information; wherein the additional information includes one or more of the following: retained information of the user; related products that the user likes; news that the user likes; and the user The battle situation of the favorite sports club; the user's favorite poetry song; the user's account information; the user's identity information and the user's password; but not limited to this.
- the sending unit 33 is configured to add the additional information to the information sent by the website server to the user, so that the user identifies the authenticity of the information according to the additional information.
- the information includes: short message, push notification, telephone, mail or webpage display, but is not limited thereto.
- the embodiment is based on the foregoing embodiment, where the constructing unit 32 includes: a generating unit and a constructing subunit (not shown), where
- the generating unit is configured to generate the additional information according to the retained information; and/or;
- the constructing subunit is configured to directly use the retained information as additional information.
- the embodiment is based on the foregoing embodiment, the generating unit includes: a first generating unit and a second generating unit, where
- the first generating unit is configured to generate, according to the content of the retained information, the additional information corresponding to the content;
- the second generating unit is configured to generate different levels of the additional information according to the sensitivity level of the retained information.
- the device may be integrated in the website server, or may be deployed independently. This embodiment is not limited.
- An embodiment of the present invention further provides an information identifying apparatus, and a schematic structural diagram thereof is shown in FIG.
- the device includes: a receiving unit 41 and a display unit 42, wherein
- the receiving unit 41 is configured to receive information sent by a website server, where the information includes additional information, where the additional information is constructed according to the retained information registered by the user on the website server;
- the retained information includes one or more of the following: one sentence or several sentences; one or several favorite hobbies; one or several favorite commodity categories; one or several favorite news categories; One or several favorite sports clubs; account information; identity information and passwords;
- the additional information includes one or more of the following: the retained information of the user; the related item that the user likes; the news that the user likes; the situation of the user's favorite sports club; the favorite poetic of the user; the user's Account information; user identity information and user password.
- the display unit 42 displays the additional information to the user, so that the user can identify the authenticity of the information according to the displayed content.
- the display unit 42 retains the user's information; the user's favorite related products; the user's favorite news; the user's favorite sports club's battle situation; the user's favorite poetry song; the user's account information; the user's identity information and the user's password One or more combinations are presented to the user so that the user can identify the authenticity of the information based on the additional information presented.
- FIG. 5 is a website server according to an embodiment of the present invention.
- the website server 5 includes: a transceiver 51 and a processor 52, where
- the transceiver 51 is configured to acquire the retained information registered by the user on the website server;
- the processor 52 is configured to construct additional information according to the retained information
- the transceiver 51 is further configured to add the additional information to the information sent by the website server to the user, so that the user identifies the authenticity of the information according to the additional information.
- the processor 52 is specifically configured to generate the additional information according to the retained information; or directly use the retained information as additional information.
- the processor 52 generates the additional information according to the retained information, including: generating the additional information related to the content according to content of the retained information; or according to a sensitivity level of the retained information. Generate different levels of the additional information.
- the retained information obtained by the transceiver 51 includes one or more of the following: one sentence or several sentences; one or several favorite hobbies; one or several favorite commodity categories; Or several favorite news categories; one or several favorite sports clubs; account information; identity information and passwords.
- the additional information configured by the processor 52 includes one or more of the following: retention information of the user; related products that the user likes; news that the user likes; the situation of the user's favorite sports club; Favorite poetry songs; user account information; user identity information and user password.
- the information sent by the transceiver 51 includes: a short message, a push notification, a phone, a mail, or a web page display.
- the transceiver 51 is further configured to notify the user of the additional information.
- the embodiment of the present invention further provides a user terminal, which is shown in FIG. 6.
- the user terminal 6 includes a transceiver 61 and a display 62.
- the transceiver 61 is configured to receive information sent by a website server, where the information includes additional information, where the additional information is constructed according to the retained information registered by the user on the website server;
- the display 62 is configured to display the additional information to the user, so that the user can identify the authenticity of the information according to the displayed content.
- the additional information received by the transceiver 61 includes one or more of the following: the user's retained information; the user's favorite related products; the user's favorite news; the user's favorite sports club's battle situation; User's favorite poetry song; user's account information; user's identity information and user's password.
- the transceiver 61 is further configured to receive the additional information sent by the website server before receiving the information.
- the user terminal may be a smart terminal or a mobile terminal, which is not limited in this embodiment.
- FIG. 7 is a schematic structural diagram of an application example of a website server according to an embodiment of the present invention.
- the website server 700 includes: a processor 710, a memory 720, a transceiver 730, and a bus 740.
- the processor 710, the memory 720, and the transceiver 730 are connected to each other through a bus 740; the bus 740 may be an ISA bus, a PCI bus, or an EISA bus.
- the bus can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 7, but it does not mean that there is only one bus or one type of bus.
- the memory 720 is configured to store a program.
- the program may include program code, the process
- the sequence code includes computer operating instructions.
- Memory 720 may include high speed RAM memory and may also include non-volatile memory, such as at least one disk memory.
- the transceiver 730 is used to connect to other devices and to communicate with other devices.
- the transceiver 530 may be configured to: acquire retained information registered by a user on a website server;
- the processor 710 executes the program code stored in the memory 720 for constructing additional information based on the retained information.
- the process of specifically constructing the additional information includes: generating the additional information according to the retained information; or directly using the retained information as additional information.
- the transceiver 730 is further configured to add the additional information to the information sent by the website server to the user, so that the user identifies the authenticity of the information according to the additional information.
- the retained information acquired by the transceiver 730 includes one or more of the following: one sentence or several sentences; one or several favorite hobbies; one or several favorite commodity categories; Several favorite news categories; one or several favorite sports clubs; account information; identity information and passwords.
- the additional information configured by the processor 710 includes one or more of the following: retention information of the user; related products that the user likes; news that the user likes; the situation of the user's favorite sports club; Favorite poetry songs; user account information; user identity information and user password.
- the information sent by the transceiver 730 includes: a short message, a push notification, a phone, a mail, or a web page display.
- the transceiver 730 is further configured to notify the user of the additional information after the processor 710 constructs the additional information and sends the information to the user.
- the website server first constructs additional information for setting the authenticity according to the retained information of the user, and then adds the additional information to the information sent to the user, so that the user can identify the information according to the additional information. Whether it is forged fraudulent information. That is to say, in the embodiment of the present invention, the fraudulent short message sent by the website is attached with obvious features that are difficult to forge and difficult to crack, thereby improving the user's prevention of fraudulent short messages and protecting their own interests.
- the techniques in the embodiments of the present invention can be implemented by means of software plus a necessary general hardware platform. Based on such understanding, the technical solution in the embodiments of the present invention may be embodied in the form of a software product in essence or in the form of a software product, which may be stored in a storage medium such as a ROM/RAM. , a disk, an optical disk, etc., including instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform the methods described in various embodiments of the present invention or portions of the embodiments.
- a computer device which may be a personal computer, server, or network device, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Information Transfer Between Computers (AREA)
Abstract
本发明实施例公开了一种信息的防伪造方法,信息识别方法及装置,所述信息的防伪造方法包括:获取用户在网站服务器上登记的留存信息;根据所述留存信息构造附加信息;将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。本发明实施例中,先根据用户的留存信息构造出用于设别真伪的附加信息,然后将该附加信息添加在发送给用户的信息中,以便于用户根据该附加信息识别出该信息是否为伪造的欺诈信息。从而提高用户对诈骗短信的防范,保护了自身利益。
Description
本发明涉及通信网络技术领域,特别涉及一种信息的防伪造方法、信息识别方法及装置。
随着移动终端的普及,和短信业务的迅速发展,越来越多的用户使用短信进行通信,然后,在用户享受快捷方便的通信手段时,伴随而来的是日趋泛滥的垃圾短信(包括诈骗短信);垃圾短信主要是指用户没有定制过的包括广告,诈骗等违法内容,影响用户的正常工作和生活,垃圾短信不但对运营商的网络产生冲击,而且,还损害了用户的利益,造成不良的社会影响。
特别是垃圾短信中的诈骗短信,诈骗者利用诈骗短信来骗取用户的金钱或财务。随着用户认知水平的提高,诈骗短信中的语言和内容也是日新月异,不断变化。基于此,现有技术中提出了针对诈骗短信的防范手段:
一种防范方式是,运营商系统通过设定的识别规则对短信的内容做过滤、识别和拦截,但是,这种方式依赖于识别规则,在诈骗者掌握一些信息后,可以绕开识别规则通过反欺诈手段来诈骗,从而导致运营商系统对诈骗短信的识别和拦截的效果不佳。另外,这种方式无法防范假基站发出的诈骗短信。
另一种防范方式是,用户可以在移动终端上安装短信防护应用,通过该应用对接收到的短信内容和发送者信息进行识别,对识别出的诈骗短信和发送者进行拦截,但是,这种方式同样也是基于内容和发送者的识别,诈骗者仍然可以通过反欺诈手段来诈骗。另外,短信内容为隐私内容,如果短信内容公开给
第三方应用,也会来带安全问题。
基于此,本发明的发明人发现,现有诈骗防范的实现方式中,都不能有效地对诈骗短信进行识别和拦截,如何防止诈骗短信的伪造以及识别诈骗短信是目前有待解决的技术问题。
发明内容
本发明实施例中提供了一种信息的防伪造方法、信息识别方法及装置,以解决现有技术中由于不能有效识别诈骗短信或有效防止诈骗短信的伪造,导致用户利益受到威胁的技术问题。
为了解决上述技术问题,本发明实施例公开了如下技术方案:
第一方面提供了一种信息的防伪造方法,包括:
获取用户在网站服务器上登记的留存信息;
根据所述留存信息构造附加信息;
将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
可选的,所述根据所述留存信息构造附加信息,包括:
根据所述留存信息生成所述附加信息;或者,直接将所述留存信息作为附加信息。
可选的,所述根据所述留存信息生成所述附加信息,包括:
根据所述留存信息的内容生成与所述内容相关的所述附加信息;或者
根据所述留存信息的敏感级别生成不同级别的所述附加信息。
可选的,所述留存信息包括下述的一种或多种:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码。
可选的,所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,所述信息包括:短信,推送通知,电话,邮件或网页展示。
可选的,还包括:
将所述附加信息通知给所述用户。
第二方面提供了一种信息识别方法,包括:
接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上登记的留存信息构造而成的;
将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
可选的,所述附加信息包括下述一种或多种包括:
用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,还包括:
在接收到所述信息前,接收所述网站服务器发送的附加信息。
第三方面提供了一种信息的防伪造装置,包括:
获取单元,用于获取用户在网站服务器上登记的留存信息;
构造单元,用于根据所述留存信息构造附加信息;
发送单元,用于将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
可选的,所述构造单元包括:
生成单元,用于根据所述留存信息生成所述附加信息;和/或;
构造子单元,用于直接将所述留存信息作为附加信息。
可选的,所述生成单元包括:
第一生成单元,用于根据所述留存信息的内容生成与所述内容相应的所述附加信息;
第二生成单元,用于根据所述留存信息的敏感级别生成不同级别的所述附加信息。
可选的,所述获取单元获取的所述留存信息包括下述的一个或多个:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份
信息以及密码。
可选的,所述构造单元构造的附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,所述发送单元发送的所述信息包括:短信,推送通知,电话,邮件或网页展示。
可选的,还包括:
通知单元,用于在所述构造单元构造所述附加信息后,或者在发送单元发送所述信息前,将所述附加信息通知给所述用户。
第四方面提供了一种信息识别装置,包括:
第一接收单元,用于接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上登记的留存信息构造而成的;
展示单元,用户将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
可选的,所述第一接收单元接收到的所述附加信息包括下述的一种或多种:
用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,还包括:
第二接收单元,用于在所述第一接收单元接收到所述信息前,接收所述网站服务器发送的附加信息。
由上述技术方案可知,本发明实施例中,网站服务器先根据用户的留存信息构造出用于设别真伪的附加信息,然后将该附加信息添加在发送给用户的信息中,以便于用户根据该附加信息识别出信息是否为伪造的欺诈信息,从而提高用户对诈骗短信的防范,保护了自身利益。
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的一种信息的防伪造方法的流程图;
图2为本发明实施例提供的一种信息识别方法的流程图;
图3为本发明实施例提供的一种信息的防伪造装置的结构示意图;
图4为本发明实施例提供的一种信息识别装置的结构示意图;
图5为本发明实施例提供的一种网站服务器的结构示意图;
图6为本发明实施例提供的一种用户终端的结构示意图;
图7为本发明实施例提供的一种网站服务器的一种应用实例的结构示意
图。
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整的描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
在本发明实施例中使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本发明。在本发明实施例和所附权利要求书中所使用的单数形式的“一种”、“所述”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本发明实施例中可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本发明实施例范围的情况下,第一信息也可以被称为第二信息,不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”可以被解释成为“在……时”或“当……时”或“响应于确定”。而且,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。
请参阅图1,图1为本发明实施例提供的一种信息的防伪造方法的流程图;所述方法包括:
步骤101:获取用户在网站服务器上登记的留存信息;
该步骤中,用户在网站服务器(即为网站服务的服务器,也可以是网络侧设备等)上登记一个留存信息,该留存信息俗称为暗号,即网站服务器获取到该留存信息。其中,该留存信息包括但不限于下述的一种或多种:一句或数句话;一个或数个喜爱的兴趣爱好(或者是某个诗人或某个诗集名等);一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码,当然,该留存信息并不限于此,还可以是其他用户想留存的信息,本实施例不作限制。
步骤102:根据所述留存信息构造附加信息;
该步骤中,网站服务器根据该留存信息构造附加信息,其中,构造的方式有两种:
一种方式是:直接将所述留存信息作为附加信息;
这种方式中,可以直接将留存信息作为附加信息,比如,如果用户的留存信息为一句或数句话,则可以将该一句或数句话作为附加信息;如果用户的留存信息为账户信息,则可以将该账户信息作为附加信息;如果用户的留存信息为身份信息,则可以将该身份信息作为附加信息;如果用户的留存信息为密码,则将该密码作为加信息。当然,留存信息并不限于此,还可以根据用户的需要进行适应性修改,当用户适应性修改留存信息后,对应的附加信息也会根据更改后的留存信息进行适应性修改。当然,留存信息并不限于
此,还可以根据用户的需要进行适应性修改,当用户适应性修改留存信息后,生成的附加信息也会根据更改后的留存信息进行适应性修改。
需要说明的是,这种方式中的留存信息可以是上述的一种或多种,而对应的附加信息也可以是上述的一种,或多种的组合。
另一种方式是:根据所述留存信息生成所述附加信息;
这种方式中,网站服务器需要根据用户的留存信息生成与该留存信息对应的附加信息,比如,如果用户的留存信息为喜爱的商品类目,则生成对应的附加信息为:该用户喜爱的商品;如果用户的留存信息为喜爱的新闻类目,则生成对应的附加信息为:用户喜爱的相关新闻;如果用户留存信息为喜爱的体育俱乐部,则生成对应的附加信息为:该用户喜爱的俱乐部的战况;如果用户的留存信息为兴趣爱好,则生成对应的附加信息为:用户喜欢的诗词歌赋。当然,留存信息并不限于此,还可以根据用户的需要进行适应性修改,当用户适应性修改留存信息后,生成的附加信息也会根据更改后的留存信息进行适应性修改。
需要说明的是,在该实施例中,这种方式中的留存信息可以是上述的一种,或多种的组合;则生成对应的附加信息也可以上述的一种,或多种的组合。
其中,该实施例中,所述根据所述留存信息生成所述附加信息也包括两种方式:
一种方式是:网站服务器根据所述留存信息的内容生成与所述内容相应的所述附加信息;
比如如果用户的留存信息为喜爱的商品类目,则生成对应的附加信息为:该用户喜爱的商品,当然,并不限于此,具体如上述在所示,在此不再赘述。
另一种方式是:网站服务器根据所述留存信息的敏感级别生成不同级别的所述附加信息;
网站服务器对用户的留存信息按照敏感级别划分为三种不同等级,比如,支付密码等类似留存信息为最敏感信息,称为第一敏感等级;身份证等留存等级为较敏感信息,称为第二敏感等级,而用户名等留存信息为不是太敏感信息,称为第三敏感等级,反之,也可以。当然,本发明实施例并不限于这几种等级的设置,也可以根据需要进行更多敏感等级的划分,本实施例不作限定。
该实施例中,由于附加信息有多方面特征,例如附加信息为诗词时,用户留存信息可能为兴趣爱好,也有可能为某个诗人或某个诗集名等,即使诈骗者通过入侵等手段掌握了部分短信的内容,依然难以破解出用户真正的留存信息。
步骤103:将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
该步骤中,当网站服务器有信息(本文称为信息)要发送给用户时,先将根据该用户的留存信息构造的附加信息添加在该信息中,然后,再将该信息发送给用户终端(比如手机等),而该用户终端再将包括该附加信息的信息展现给该用户,用户就可以根据该附加信息判断出该信息是否为伪造的虚假信息或诈骗信息等,也就是说,用户可以通过对暗号来判断出该信息是否为
伪造的虚假信息或诈骗信息等。
其中,该实施例中,所述信息可以是短信,推送通知,电话,邮件或网页展示等。
比如,在电话回访中,可以人工直接语音确认暗号。
该实施例中,由于网站服务器需要维护用户的留存信息及其相关信息,相关信息包括但不限于:附加信息展示的历史记录,备选的附加信息,用于扰乱破解的附加信息特征表,或用于构造更易理解和更难破解的附加信息的其他信息等。
本发明实施例中,网站服务器先根据用户的留存信息构造出用于设别真伪的附加信息,然后将该附加信息添加在发送给用户的信息中,以便于用户根据该附加信息识别出信息是否为伪造的欺诈信息。也就说,本发明实施例中,为网站发送的欺诈短信附加难以伪造、难以破解的明显特征,从而提高用户对诈骗短信的防范,保护了自身利益。
可选的,在另一实施例中,该实施例在上述实施例的基础上,所述方法还可以包括:在构造所述附加信息后,或者在所述信息前,将所述附加信息通知给所述用户。
也就是说,网站服务器在将包括附加信息的信息发送给用户前,将构造出的容易被用户清晰识别的、难以伪造的附加信息,提供给用户,以令该用户识别出接收到的该信息是否为伪造的诈骗信息,防止诈骗。
还请参阅图2,图2为本发明实施例提供的一种信息识别方法,所述方
法包括:
步骤201:接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上留存的信息构造而成的;
该步骤中,所述信息可以短信,推送通知,电话,邮件或网页展示等等。
比如在电话回访中,可以人工直接语音确认暗号,这也是最原始的暗号形式。其本实施例中,采用暗号的目的,就是尽量避免更为敏感的信息的泄露,同时也能提供足够明确的信息供用户识别。
所述附加信息可以包括下述一种或多种包括:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。但并不限于此,还可以根据需要进行适应性增加或删减等。
也就是说,如果所述留存信息是用户喜爱的商品类目,则生成的所述附加信息为与所述用户喜爱的商品相关的商品;如果所述留存信息是用户喜爱的新闻类目,则生成的所述附加信息为与所述用户喜爱的新闻类目相关的新闻;如果所述留存信息是体育俱乐部,则生成的所述附加信息为所述体育俱乐部的战况;如果所述留存信息是兴趣爱好,则生成的所述附加信息为与所述兴趣爱好相关的诗词才艺;
当然,在该实施例中,也可以所述直接将所述留存信息作为附加信息。比如,如果所述留存信息是用户留存的一句或数句话,则直接将所述用户留存的一句或数句话作为所述附加信息;如果所述留存信息是所述用户的账户信息,身份信息和密码的至少一种,则直接将所述用户的账户信息、身份信
息和密码的至少一种作为所述附加信息。
进一步,还可以根据所述留存信息的敏感级别生成不同级别的所述附加信息。
也即是说,根据所述留存信息的敏感级别,来选择性披露不同敏感级别的暗号。
本实施例中,根据用户操作的重要性,选择披露不同级别的留存信息(最敏感的留存信息可以是使账户信息、身份信息、密码等)来构造不同级别的附加信息,以增加网站信息的权威性,并减少关键敏感信息泄露的风险。
该实施例中,附加信息的构造过程,与上述实施例中附加信息的构造过程相同,具体详见上述实施例,在此不再赘述。
步骤202:将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
该实施例中,用户终端(比如手机,平板等)可以直接将附加信息中用户的留存信息展示给用户,也可以将用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;喜爱诗词歌赋;用户的账户信息;用户的身份信息以及用户逇密码的一种或多种组合展示给用户,以便于用户根据该附加信息判断接收到的信息是否为诈骗信息。
本发明实施例中,当用户终端(比如手机等)接收到网站服务器发送的包括附加信息的信息时,将该附加信息展示给用户,根据该附加信息识别出该信息是否为伪造的诈骗信息,从而提高了用户对诈骗信息的识别,保护了
自身利益。
可选的,在另一实施例中,该实施例在上述实施例的基础上,所述方法还包括:在接收到所述信息前,接收所述网站服务器发送的附加信息。
也就是说,网站服务器在将包括附加信息的信息发送给用户前,先将构造的附加信息通知给用户,以便于在用户接收到该信息时,轻易识别出该信息是否为伪造的诈骗信息。
需要说明的是,本发明实施例中的附加信息是根据用户在网站服务器上登记的留存信息而构造的,因此诈骗者无法针对特定用户伪造诈骗短信,也很难伪造出覆盖大范围用户的诈骗信息,其诈骗信息的有效性大大下降。
基于上述方法实施例的实现过程,本发明实施例还提供一种信息的防伪造装置,其结构示意图如图3所示,所述装置包括:获取单元31,构造单元32和发送单元33,其中,
所述获取单元31,用于获取用户在网站服务器上登记的留存信息;其中,所述留存信息包括下述的一个或多个:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码;但并不限于此。
所述构造单元32,用于根据所述留存信息构造附加信息;其中,所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码;但并不限于此。
所述发送单元33,用于将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
其中,所述信息包括:短信,推送通知,电话,邮件或网页展示等,但并不限于此。
可选的,在另一实施例中,该实施例在上述实施例的基础上,所述构造单元32包括:生成单元和构造子单元(图中未示),其中,
所述生成单元,用于根据所述留存信息生成所述附加信息;和/或;
所述构造子单元,用于直接将所述留存信息作为附加信息。
可选的,在另一实施例中,该实施例在上述实施例的基础上,所述生成单元包括:第一生成单元和第二生成单元,其中,
所述第一生成单元,用于根据所述留存信息的内容生成与所述内容相应的所述附加信息;
所述第二生成单元,用于根据所述留存信息的敏感级别生成不同级别的所述附加信息。
可选的,所述装置可以集成在网站服务器中,也可以独立部署,本实施例不作限制。
所述装置中各个单元的功能和作用的实现过程,详见上述方法中对应步骤的实现过程,在此不再赘述。
本发明实施例还提供一种信息识别装置,其结构示意图如图4所示,所
述装置包括:接收单元41和展示单元42,其中,
所述接收单元41,用于接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上登记的留存信息构造而成的;
其中,所述留存信息包括下述的一个或多个:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码;
相应的,所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
所述展示单元42,用户将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
所述展示单元42将用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码的一种或多种组合展示给用户,以便于所述用户根据展示的附加信息识别所述信息的真伪。
还请参阅图5,图5为本发明实施例提供的一种网站服务器,所述网站服务器5包括:收发器51和处理器52,其中,
所述收发器51,用于获取用户在网站服务器上登记的留存信息;
所述处理器52,用于根据所述留存信息构造附加信息;
所述收发器51,还用于将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
可选的,所述处理器52,具体用于根据所述留存信息生成所述附加信息;或者,直接将所述留存信息作为附加信息。
可选的,所述处理器52根据所述留存信息生成所述附加信息,包括:根据所述留存信息的内容生成与所述内容相关的所述附加信息;或者根据所述留存信息的敏感级别生成不同级别的所述附加信息。
可选的,所述收发器51获取到的留存信息包括下述的一种或多种:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码。
可选的,所述处理器52构造的所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,所述收发器51发送的所述信息包括:短信,推送通知,电话,邮件或网页展示。
可选的,所述收发器51,还用于将所述附加信息通知给所述用户。
本发明实施例还提供一种用户终端,其结构示意图如图6所示,所述用户终端6包括:收发器61和显示器62,其中,
所述收发器61,用于接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上登记的留存信息构造而成的;
所述显示器62,用于将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
可选的,所述收发器61接收到的所述附加信息包括下述一种或多种包括:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,所述收发器61还用于在接收到所述信息前,接收所述网站服务器发送的附加信息。
可选的,所述用户终端可以是智能终端,也可以是移动终端,本实施例不作限制。
还请参阅图7,图7为本发明实施例提供的一种网站服务器的一种应用实例的结构示意图,该网站服务器700包括:处理器710、存储器720、收发器730和总线740;
处理器710、存储器720、收发器730通过总线740相互连接;总线740可以是ISA总线、PCI总线或EISA总线等。所述总线可以分为地址总线、数据总线、控制总线等。为便于表示,图7中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。
存储器720,用于存放程序。具体地,程序可以包括程序代码,所述程
序代码包括计算机操作指令。存储器720可能包含高速RAM存储器,也可能还包括非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。
收发器730用于连接其他设备,并与其他设备进行通信。具体的所述收发器530可以用于:获取用户在网站服务器上登记的留存信息;
所述处理器710执行存储器720中存储的所述程序代码,用于根据所述留存信息构造附加信息。具体构造附加信息的过程包括:根据所述留存信息生成所述附加信息;或者,直接将所述留存信息作为附加信息。
所述收发器730,还用于将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
可选地,所述收发器730获取的留存信息包括下述的一种或多种:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码。
可选的,所述处理器710构造的所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
可选的,所述收发器730发送的所述信息包括:短信,推送通知,电话,邮件或网页展示。
可选的,所述收发器730还用于在所述处理器710构造所述附加信息后,以及向用户发送信息前,将所述附加信息通知给所述用户。
本发明实施例中,网站服务器先根据用户的留存信息构造出用于设别真伪的附加信息,然后将该附加信息添加在发送给用户的信息中,以便于用户根据该附加信息识别出信息是否为伪造的欺诈信息。也就说,本发明实施例中,为网站发送的欺诈短信附加难以伪造、难以破解的明显特征,从而提高用户对诈骗短信的防范,保护了自身利益。
本领域的技术人员可以清楚地了解到本发明实施例中的技术可借助软件加必需的通用硬件平台的方式来实现。基于这样的理解,本发明实施例中的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品可以存储在存储介质中,如ROM/RAM、磁碟、光盘等,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例或者实施例的某些部分所述的方法。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于系统实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
以上所述的本发明实施方式,并不构成对本发明保护范围的限定。任何在本发明的精神和原则之内所作的修改、等同替换和改进等,均应包含在本发明的保护范围之内。
Claims (20)
- 一种信息的防伪造方法,其特征在于,包括:获取用户在网站服务器上登记的留存信息;根据所述留存信息构造附加信息;将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
- 根据权利要求1所述的方法,其特征在于,所述根据所述留存信息构造附加信息,包括:根据所述留存信息生成所述附加信息;或者,直接将所述留存信息作为附加信息。
- 根据权利要求2所述的方法,其特征在于,所述根据所述留存信息生成所述附加信息,包括:根据所述留存信息的内容生成与所述内容相关的所述附加信息;或者根据所述留存信息的敏感级别生成不同级别的所述附加信息。
- 根据权利要求1至3任一项所述的方法,其特征在于,所述留存信息包括下述的一种或多种:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码。
- 根据权利要求1至3任一项所述的方法,其特征在于,所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
- 根据权利要求1至3任一项所述的方法,其特征在于,所述信息包 括:短信,推送通知,电话,邮件或网页展示。
- 根据权利要求1至3任一项所述的方法,其特征在于,还包括:将所述附加信息通知给所述用户。
- 一种信息识别方法,其特征在于,包括:接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上登记的留存信息构造而成的;将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
- 根据权利要求8所述的方法,其特征在于,所述附加信息包括下述一种或多种包括:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱的诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
- 根据权利要求8或9所述的方法,其特征在于,还包括:在接收到所述信息前,接收所述网站服务器发送的附加信息。
- 一种信息的防伪造装置,其特征在于,包括:获取单元,用于获取用户在网站服务器上登记的留存信息;构造单元,用于根据所述留存信息构造附加信息;发送单元,用于将所述附加信息添加在所述网站服务器发送给所述用户的信息中,以便于所述用户根据所述附加信息识别出所述信息的真伪。
- 根据权利要求11所述的装置,其特征在于,所述构造单元包括:生成单元,用于根据所述留存信息生成所述附加信息;和/或;构造子单元,用于直接将所述留存信息作为附加信息。
- 根据权利要求12所述的装置,其特征在于,所述生成单元包括:第一生成单元,用于根据所述留存信息的内容生成与所述内容相应的所述附加信息;第二生成单元,用于根据所述留存信息的敏感级别生成不同级别的所述附加信息。
- 根据权利要求11至13任一项所述的装置,其特征在于,所述获取单元获取的所述留存信息包括下述的一个或多个:一句或数句话;一个或数个喜爱的兴趣爱好;一个或数个喜爱的商品类目;一个或数个喜欢的新闻类目;一个或数个喜欢的体育俱乐部;账户信息;身份信息以及密码。
- 根据权利要求11至13任一项所述的装置,其特征在于,所述构造单元构造的附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
- 根据权利要求11至13任一项所述的装置,其特征在于,所述发送单元发送的所述信息包括:短信,推送通知,电话,邮件或网页展示。
- 根据权利要求11至13任一项所述的装置,其特征在于,还包括:通知单元,用于在所述构造单元构造所述附加信息后,或者在发送单元发送所述信息前,将所述附加信息通知给所述用户。
- 一种信息识别装置,其特征在于,包括:第一接收单元,用于接收网站服务器发送的信息,所述信息中包括附加信息,所述附加信息是依据用户在网站服务器上登记的留存信息构造而成的;展示单元,用户将所述附加信息展示给所述用户,以便于所述用户根据展示的内容识别所述信息的真伪。
- 根据权利要求18所述的装置,其特征在于,所述第一接收单元接收到的所述附加信息包括下述的一种或多种:用户的留存信息;用户喜爱的相关商品;用户喜爱的新闻;用户喜爱的体育俱乐部的战况;用户喜爱诗词歌赋;用户的账户信息;用户的身份信息以及用户的密码。
- 根据权利要求18或19所述的装置,其特征在于,还包括:第二接收单元,用于在所述第一接收单元接收到所述信息前,接收所述网站服务器发送的附加信息。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510103396.7A CN106034303B (zh) | 2015-03-10 | 2015-03-10 | 一种信息的防伪造方法、信息识别方法及装置 |
| CN201510103396.7 | 2015-03-10 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016141819A1 true WO2016141819A1 (zh) | 2016-09-15 |
Family
ID=56880012
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/075374 Ceased WO2016141819A1 (zh) | 2015-03-10 | 2016-03-02 | 一种信息的防伪造方法、信息识别方法及装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN106034303B (zh) |
| WO (1) | WO2016141819A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113709748A (zh) * | 2021-07-21 | 2021-11-26 | 中数通信息有限公司 | 一种基于发送行为和网址特征识别病毒短信的方法 |
| CN120935573A (zh) * | 2025-10-14 | 2025-11-11 | 上海助通信息科技有限公司 | 一种基于发送轨迹与内容识别的短信反欺诈方法及系统 |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107801163A (zh) * | 2016-09-06 | 2018-03-13 | 中国电信股份有限公司 | 用于识别伪基站短信的方法、用户终端和系统 |
| CN107071752A (zh) * | 2017-03-20 | 2017-08-18 | 唐承龙 | 行业短信反诈骗反泄露系统平台 |
| CN111131183B (zh) * | 2019-12-05 | 2022-05-31 | 任子行网络技术股份有限公司 | 网络安全监控方法、计算机设备及计算机可读存储介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1825352A (zh) * | 2006-03-31 | 2006-08-30 | 中国工商银行股份有限公司 | 网上预留信息验证方法 |
| CN103955998A (zh) * | 2014-04-27 | 2014-07-30 | 汪风珍 | 银行卡预留验证信息 |
| CN104144146A (zh) * | 2013-05-10 | 2014-11-12 | 中国电信股份有限公司 | 一种访问网站的方法和系统 |
| CN104639521A (zh) * | 2013-11-15 | 2015-05-20 | 腾讯科技(深圳)有限公司 | 一种应用安全验证方法、应用服务器、应用客户端及系统 |
-
2015
- 2015-03-10 CN CN201510103396.7A patent/CN106034303B/zh active Active
-
2016
- 2016-03-02 WO PCT/CN2016/075374 patent/WO2016141819A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1825352A (zh) * | 2006-03-31 | 2006-08-30 | 中国工商银行股份有限公司 | 网上预留信息验证方法 |
| CN104144146A (zh) * | 2013-05-10 | 2014-11-12 | 中国电信股份有限公司 | 一种访问网站的方法和系统 |
| CN104639521A (zh) * | 2013-11-15 | 2015-05-20 | 腾讯科技(深圳)有限公司 | 一种应用安全验证方法、应用服务器、应用客户端及系统 |
| CN103955998A (zh) * | 2014-04-27 | 2014-07-30 | 汪风珍 | 银行卡预留验证信息 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113709748A (zh) * | 2021-07-21 | 2021-11-26 | 中数通信息有限公司 | 一种基于发送行为和网址特征识别病毒短信的方法 |
| CN113709748B (zh) * | 2021-07-21 | 2023-11-14 | 中数通信息有限公司 | 一种基于发送行为和网址特征识别病毒短信的方法 |
| CN120935573A (zh) * | 2025-10-14 | 2025-11-11 | 上海助通信息科技有限公司 | 一种基于发送轨迹与内容识别的短信反欺诈方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN106034303A (zh) | 2016-10-19 |
| CN106034303B (zh) | 2018-10-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Omodunbi et al. | Cybercrimes in Nigeria: Analysis, detection and prevention | |
| Siadati et al. | Mind your SMSes: Mitigating social engineering in second factor authentication | |
| US8549594B2 (en) | Method of identity authentication and fraudulent phone call verification that utilizes an identification code of a communication device and a dynamic password | |
| WO2016141819A1 (zh) | 一种信息的防伪造方法、信息识别方法及装置 | |
| Furnell | Phishing: can we spot the signs? | |
| US20160142398A1 (en) | Method of network identity authentication by using an identification code of a communication device and a network operating password | |
| WO2017190436A1 (zh) | 一种数据处理方法及装置 | |
| CN105391860A (zh) | 用于处理通信请求的方法和装置 | |
| Blancaflor et al. | A case study on smishing: an assessment of threats against mobile devices | |
| US20210081962A1 (en) | Data analytics tool | |
| Speed et al. | Mobile security: How to secure, privatize and recover your devices | |
| Singh et al. | Phishing: A computer security threat | |
| CN106357912A (zh) | 一种来去电处理方法和装置 | |
| CN106453808A (zh) | 终端数据的处理方法及装置 | |
| TW201112720A (en) | Method of communication device recognition code and dynamic code for network identification and telephone fraud certification | |
| Faluyi et al. | Impact of ICT-facilitated fraud on Sustainable Socio-economic Development in Nigeria | |
| CN106332027A (zh) | 一种消息分析方法及可消息分析的智能终端 | |
| Gutmann et al. | Taken out of context: Security risks with security code autofill in ios & macos | |
| Sirawongphatsara et al. | Analyzing bank account information of nominees and scammers | |
| CN107094126A (zh) | 一种病毒短信的拦截方法、装置及系统 | |
| CN106657535B (zh) | 一种来去电处理方法和装置 | |
| KR101553177B1 (ko) | 사칭방지 서비스 시스템 및 사칭방지 방법 | |
| KR102156905B1 (ko) | 메신저 피싱 예방을 위한 사용자 확인 방법 | |
| KR101407593B1 (ko) | 사용자 단말기에서 불법 수신 메시지를 확인하는 방법 | |
| Mawere et al. | Profile impostoring: a use case on the rising social engineering attack on Facebook users |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16761046 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16761046 Country of ref document: EP Kind code of ref document: A1 |