WO2017045253A1 - 电子账户的控制方法、系统及移动终端 - Google Patents
电子账户的控制方法、系统及移动终端 Download PDFInfo
- Publication number
- WO2017045253A1 WO2017045253A1 PCT/CN2015/093487 CN2015093487W WO2017045253A1 WO 2017045253 A1 WO2017045253 A1 WO 2017045253A1 CN 2015093487 W CN2015093487 W CN 2015093487W WO 2017045253 A1 WO2017045253 A1 WO 2017045253A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- operating system
- type
- address information
- user
- electronic account
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1483—Countermeasures against malicious traffic service impersonation, e.g. phishing, pharming or web spoofing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q30/00—Commerce
- G06Q30/018—Certifying business or products
- G06Q30/0185—Product, service or business identity fraud
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q30/00—Commerce
- G06Q30/06—Buying, selling or leasing transactions
- G06Q30/0601—Electronic shopping [e-shopping]
- G06Q30/0609—Qualifying participants for shopping transactions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q2220/00—Business processing using cryptography
Definitions
- the present invention relates to the field of terminal technologies, and in particular, to a method for controlling an electronic account, a control system for an electronic account, and a mobile terminal.
- the invention is based on at least one of the above technical problems, and proposes a new electronic account control scheme, which can encrypt the verification information before the user conducts the electronic account transaction, and then verify the information when determining to connect to the legal website.
- the decryption is performed to complete the electronic account transaction according to the decrypted verification information, thereby avoiding the occurrence of the user leaking the verification information to the phishing website when performing the electronic account transaction, thereby protecting the user's vital interests and improving the user experience.
- the present invention provides a method for controlling an electronic account, comprising: obtaining, by a first type of operating system, network address information of a target website to be electronically traded, the target website being used for online transactions; Decoding the network address information into the IP address information corresponding to the target website, and forwarding the IP address information to the second type of operating system; determining, by the second type of operating system, whether the IP address information is pre- Setting the IP address information to match; when the second type of operating system determines that the IP address information matches the preset IP address information, Decrypting the encrypted verification information according to the user instruction, and sending the decrypted verification information to the first type of operating system to determine the transaction authority of the first type of operating system to the electronic account at the target website .
- the network address information of the target website to be electronically traded is obtained and parsed by the first type of operating system, and the parsed IP (Internet Protocol) is determined by the second type of operating system.
- the encrypted verification information is decrypted according to the user instruction, and the decrypted verification information is sent to the first type of operating system to determine that the first type of operating system is
- the trading authority of the target website to the electronic account avoids the occurrence of the leakage of the verification information to the phishing website due to the user's accidental access to the phishing website due to the user clicking the unknown link, thereby ensuring the security of the transaction process of the entire electronic account. It protects the vital interests of users and enhances the user experience.
- the network address information of the target website to be electronically traded is obtained by the first type of operating system, and the target website is used for online transactions, and specifically includes: connecting the mobile terminal to the outside When the terminal is set, the network address information sent by the peripheral terminal is obtained by the first type of operating system.
- the network address information sent by the peripheral terminal is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing.
- the occurrence of the website is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing. The occurrence of the website.
- the network address information of the target website to be electronically traded is obtained by the first type of operating system, where the target website is used for online transactions, and specifically includes: A type of operating system obtains network address information of a target website input by a user.
- the user can also obtain the network address information of the target website input by the user through the first type of operating system, so that the user can perform the electronic account transaction through the mobile terminal, and can also prevent the user from leaking the verification information to the phishing website. The situation has happened.
- the network address information of the target website to be subjected to the electronic account transaction is obtained by using the first type of operating system, and the target website is used to perform the online transaction, and further includes: The second type of operating system pre-stores IP address information of a plurality of websites for conducting online transactions as the preset IP address information.
- the IP address information of a plurality of websites for performing online transactions is pre-stored in the second type of operating system, so as to provide preconditions for the subsequent users to decrypt the verification information according to the matching node.
- the network address information of the target website to be subjected to the electronic account transaction is obtained by using the first type of operating system, and the target website is used to perform the online transaction, and further includes:
- the first type of operating system receives the verification information to be encrypted
- the verification information to be encrypted is stored in the second type of operating system; and the second type of operating system is controlled to be encrypted according to the user instruction.
- the verification information is encrypted, wherein the user instruction includes a user touch instruction and biometric information, and the biometric information includes at least one of a fingerprint feature, an iris feature, a voiceprint feature, and a face image feature of the user.
- the user touch command includes touch operation information of the user and posture change information of the mobile terminal.
- the security level of the first type of operating system is lower than that of the second type of operating system, and the authentication information is obtained by the operating system with low security level in the mobile terminal, and the security level of the operating system with high security level in the mobile terminal is used.
- the low-level authentication information is stored in an encrypted manner, so that the encrypted authentication information is stored in a high-security operating system, so it is difficult for a virus such as a Trojan to invade a security-level operating system to steal authentication information, even if it is stolen and verified.
- Information, and the specific information content of the verification information cannot be obtained, thereby effectively ensuring the security of the verification information.
- the encrypted verification information is decrypted according to a user instruction, and
- the decrypted verification information is sent to the first type of operating system to determine the transaction authority of the first type of operating system to the electronic account at the target website, and the specific steps include: obtaining the user by using the first type of operating system. Sending a request for requesting an electronic account transaction, and forwarding the request instruction to the second type of operating system; determining, by the second type of operating system, whether the request instruction matches the user instruction; When the request instruction matches the user instruction, the second type of operating system is controlled to decrypt the encrypted verification information.
- the request instruction for the electronic account transaction is obtained by acquiring the request issued by the user, and the verification information is decrypted according to the matching result of the request instruction and the user instruction, if the If the match is not decrypted, the decryption information is not decrypted, so that the verification information can be obtained only when the website currently used for the electronic account transaction is legal, and the security of the verification information is ensured.
- a control system for an electronic account comprising: a first obtaining unit, configured to acquire network address information of a target website to be electronically traded through the first type of operating system, the target The website is configured to perform an online transaction; the parsing unit is configured to parse the network address information into IP address information corresponding to the target website; and the first forwarding unit is configured to forward the IP address information to the second class An operating system; the first matching unit is configured to determine, by the second type of operating system, whether the IP address information matches the preset IP address information; and the processing unit determines the IP address information in the second type of operating system When the preset IP address information is matched, the encrypted verification information is decrypted according to the user instruction, and the decrypted verification information is sent to the first type of operating system to determine that the first type of operating system is in the The trading authority of the target website to the electronic account.
- the network address information of the target website to be electronically traded is obtained and parsed by the first type of operating system, and the parsed IP (Internet Protocol) is determined by the second type of operating system.
- the encrypted verification information is decrypted according to the user instruction, and the decrypted verification information is sent to the first type of operating system to determine that the first type of operating system is
- the trading authority of the target website to the electronic account avoids the occurrence of the leakage of the verification information to the phishing website due to the user's accidental access to the phishing website due to the user clicking the unknown link, thereby ensuring the security of the transaction process of the entire electronic account. It protects the vital interests of users and enhances the user experience.
- the first obtaining unit is configured to: when the mobile terminal is connected to the peripheral terminal, acquire, by using the first type of operating system, network address information sent by the peripheral terminal .
- the network address information sent by the peripheral terminal is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing.
- the occurrence of the website is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing. The occurrence of the website.
- the first obtaining unit is configured to: obtain, by using the first type of operating system, network address information of a target website input by a user.
- the user can also obtain the network address information of the target website input by the user through the first type of operating system, so that the user can perform the electronic account transaction through the mobile terminal, and can also prevent the user from leaking the verification information to the phishing website. The situation has happened.
- the method further includes: a first storage unit, configured to pre-store, in the second type of operating system, IP address information of a plurality of websites for performing online transactions, as Preset IP address information.
- the IP address information of a plurality of websites for performing online transactions is pre-stored in the second type of operating system, so as to provide preconditions for the subsequent users to decrypt the verification information according to the matching node.
- the method further includes: a second storage unit, configured to: when the first type of operating system receives the verification information to be encrypted, store the verification information to be encrypted to the The second type of operating system; the encryption unit is configured to control the second type of operating system to encrypt the verification information to be encrypted according to the user instruction, wherein the user instruction includes a user touch instruction and a biometric feature And the biometric information includes at least one of a fingerprint feature, an iris feature, a voiceprint feature, and a face image feature of the user, where the user touch command includes touch operation information of the user and a posture of the mobile terminal. Change information.
- the security level of the first type of operating system is lower than that of the second type of operating system, and the authentication information is obtained by the operating system with low security level in the mobile terminal, and the security level of the operating system with high security level in the mobile terminal is used.
- the low-level authentication information is stored in an encrypted manner, so that the encrypted authentication information is stored in a high-security operating system, so it is difficult for a virus such as a Trojan to invade a security-level operating system to steal authentication information, even if it is stolen and verified.
- Information, and the specific information content of the verification information cannot be obtained, thereby effectively ensuring the security of the verification information.
- the processing unit includes: a second obtaining unit, configured to acquire, by using the first type of operating system, a request request sent by a user to perform an electronic account transaction; and a second forwarding unit
- the second matching unit is configured to determine, by the second type of operating system, whether the request instruction matches the user instruction, and the decryption unit uses Controlling the second type of operating system to solve the encrypted verification information when determining that the request instruction matches the user instruction dense.
- the request instruction of the electronic account transaction is obtained by acquiring a request sent by the user, and the verification information is decrypted according to the matching result of the request instruction matching the user instruction, and if the matching is performed, the verification information is decrypted, if not, the The decryption is performed so that the verification information can be obtained only when the website currently used for the electronic account transaction is legal, and the security of the verification information is ensured.
- a mobile terminal comprising: the control system of the electronic account according to any one of the above technical solutions. Therefore, the mobile terminal has the same technical effects as the control system of the electronic account described in any of the above technical solutions, and details are not described herein again.
- the verification information can be encrypted before the user conducts the electronic account transaction, and the verification information is decrypted when determining to connect to the legal website to complete the electronic account transaction according to the decrypted verification information, thereby avoiding the user being
- the occurrence of the leakage of verification information to the phishing website during the electronic account transaction protects the vital interests of the user and enhances the user experience.
- FIG. 1 shows a schematic flow chart of a method of controlling an electronic account according to an embodiment of the present invention
- FIG. 2 shows a schematic block diagram of a control system for an electronic account in accordance with an embodiment of the present invention
- FIG. 3 shows a schematic block diagram of a mobile terminal in accordance with one embodiment of the present invention
- FIG. 4 shows a schematic block diagram of a mobile terminal in accordance with another embodiment of the present invention.
- FIG. 1 shows a schematic flow chart of a method of controlling an electronic account in accordance with an embodiment of the present invention.
- a method for controlling an electronic account includes: Step 102: Obtain network address information of a target website to be electronically traded through a first type of operating system, where the target website is used. Performing an online transaction; step 104, parsing the network address information into IP address information corresponding to the target website, and forwarding the IP address information to the second type of operating system; and step 106, passing the second The operating system determines whether the IP address information matches the preset IP address information; and in step 108, when the second type of operating system determines that the IP address information matches the preset IP address information, the encrypted version is encrypted according to the user instruction.
- the verification information is decrypted, and the decrypted verification information is sent to the first type of operating system to determine the transaction authority of the first type of operating system to the electronic account at the target website.
- the network address information of the target website to be electronically traded is obtained and parsed by the first type of operating system, and the parsed IP (Internet Protocol) is determined by the second type of operating system.
- the encrypted verification information is decrypted according to the user instruction, and the decrypted verification information is sent to the first type of operating system to determine that the first type of operating system is
- the trading authority of the target website to the electronic account avoids the occurrence of the leakage of the verification information to the phishing website due to the user's accidental access to the phishing website due to the user clicking the unknown link, thereby ensuring the security of the transaction process of the entire electronic account. It protects the vital interests of users and enhances the user experience.
- the step 102 includes: acquiring, by the first type of operating system, network address information sent by the peripheral terminal when the mobile terminal is connected to the peripheral terminal.
- the network address information sent by the peripheral terminal is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing.
- the occurrence of the website is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing. The occurrence of the website.
- the step 102 further includes: obtaining, by using the first type of operating system, network address information of the target website input by the user.
- the user can also obtain the network address information of the target website input by the user through the first type of operating system, so that the user can perform the electronic account transaction through the mobile terminal, and can also prevent the user from leaking the verification information to the phishing website. The situation has happened.
- the method further includes: pre-storing, in the second type of operating system, IP address information of a plurality of websites for performing online transactions, as the pre- Set the IP address information.
- the IP address information of a plurality of websites for performing online transactions is pre-stored in the second type of operating system, so as to provide preconditions for the subsequent users to decrypt the verification information according to the matching node.
- the method further includes: when the first type of operating system receives the verification information to be encrypted, storing the verification information to be encrypted to the first
- the second type of operating system controls the second type of operating system to encrypt the verification information to be encrypted according to the user instruction, wherein the user instruction includes a user touch instruction and biometric information, and the biometric information
- the user touch instruction includes at least one of a user's fingerprint feature, an iris feature, a voiceprint feature, and a face image feature
- the user touch command includes the user's touch operation information and the posture change information of the mobile terminal.
- the security level of the first type of operating system is lower than that of the second type of operating system, and the authentication information is obtained by the operating system with low security level in the mobile terminal, and the security level of the operating system with high security level in the mobile terminal is used.
- the low-level authentication information is stored in an encrypted manner, so that the encrypted authentication information is stored in a high-security operating system, so it is difficult for a virus such as a Trojan to invade a security-level operating system to steal authentication information, even if it is stolen and verified.
- Information, and the specific information content of the verification information cannot be obtained, thereby effectively ensuring the security of the verification information.
- the step 108 includes: obtaining, by the first type of operating system, a request instruction issued by the user for performing an electronic account transaction, and forwarding the request instruction to the second class An operating system; determining, by the second type of operating system, whether the request instruction matches the user instruction; and when determining that the request instruction matches the user instruction, controlling the second type of operating system to the The encrypted authentication information is decrypted.
- a request for electronic account transaction is obtained by acquiring a request from a user.
- the instruction decrypts the verification information according to the matching result of the request instruction and the user instruction. If it matches, the verification information is decrypted. If it does not match, the decryption is not performed, so that only the website currently used for the electronic account transaction is legal. In order to obtain the verification information, the security of the verification information is guaranteed.
- FIG. 2 shows a schematic block diagram of a control system for an electronic account in accordance with an embodiment of the present invention.
- the electronic account control system 200 includes: a first obtaining unit 202, a parsing unit 204, a first matching unit 208, and a processing unit 210.
- the first obtaining unit 202 is configured to obtain, by using a first type of operating system, network address information of a target website to be electronically traded, the target website is used for online transactions, and the parsing unit 204 is configured to use the network.
- the address information is parsed into the IP address information corresponding to the target website;
- the first forwarding unit 206 is configured to forward the IP address information to the second type of operating system;
- the first matching unit 208 is configured to pass the first
- the second type of operating system determines whether the IP address information matches the preset IP address information; the processing unit 210, when the second type of operating system determines that the IP address information matches the preset IP address information, according to the user instruction
- the encrypted verification information is decrypted, and the decrypted verification information is sent to the first type of operating system to determine the transaction authority of the first type of operating system to the electronic account at the target website.
- the network address information of the target website to be electronically traded is obtained and parsed by the first type of operating system, and the parsed IP (Internet Protocol) is determined by the second type of operating system.
- the encrypted verification information is decrypted according to the user instruction, and the decrypted verification information is sent to the first type of operating system to determine that the first type of operating system is
- the trading authority of the target website to the electronic account avoids the occurrence of the leakage of the verification information to the phishing website due to the user's accidental access to the phishing website due to the user clicking the unknown link, thereby ensuring the security of the transaction process of the entire electronic account. It protects the vital interests of users and enhances the user experience.
- the first acquiring unit 202 is specifically configured to: when the mobile terminal is connected to the peripheral terminal, obtain the network address sent by the peripheral terminal by using the first type operating system. information.
- the network address information sent by the peripheral terminal is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing.
- the occurrence of the website is obtained by the first type of operating system, so that even if the user conducts an electronic account transaction through the peripheral terminal, the user can also be prevented from leaking the verification information to the fishing. The occurrence of the website.
- the first obtaining unit 202 is specifically configured to: obtain, by using the first type of operating system, network address information of a target website input by a user.
- the user can also obtain the network address information of the target website input by the user through the first type of operating system, so that the user can perform the electronic account transaction through the mobile terminal, and can also prevent the user from leaking the verification information to the phishing website. The situation has happened.
- the method further includes: a first storage unit 212, configured to pre-store, in the second type of operating system, IP address information of multiple websites for performing online transactions, as The preset IP address information.
- the IP address information of a plurality of websites for performing online transactions is pre-stored in the second type of operating system, so as to provide preconditions for the subsequent users to decrypt the verification information according to the matching node.
- the method further includes: a second storage unit 214 and an encryption unit 216.
- the second storage unit 214 is configured to: when the first type of operating system receives the verification information to be encrypted, store the verification information to be encrypted to the second type of operating system; the encryption unit 216, The second type of operating system is controlled to encrypt the verification information to be encrypted according to the user instruction, where the user instruction includes a user touch instruction and biometric information, and the biometric information includes a fingerprint of the user. At least one of a feature, an iris feature, a voiceprint feature, and a face image feature, the user touch command includes touch operation information of the user and posture change information of the mobile terminal.
- the security level of the first type of operating system is lower than that of the second type of operating system, and the authentication information is obtained by the operating system with low security level in the mobile terminal, and the security level of the operating system with high security level in the mobile terminal is used.
- the low-level authentication information is stored in an encrypted manner, so that the encrypted authentication information is stored in a high-security operating system, so it is difficult for a virus such as a Trojan to invade a security-level operating system to steal authentication information, even if it is stolen and verified.
- Information, and the specific information content of the verification information cannot be obtained, thereby effectively ensuring the security of the verification information. all.
- the processing unit 210 includes: a second obtaining unit 2102, a second forwarding unit 2104, a second matching unit 2106, and a decrypting unit 2108.
- the second obtaining unit 2102 is configured to obtain, by using the first type of operating system, a request for a request for electronic account transaction by a user, and a second forwarding unit 2104, configured to forward the request command to the second
- the second matching unit 2106 is configured to determine, by the second type of operating system, whether the request instruction matches the user instruction, and the decrypting unit 2108 is configured to determine the request instruction and the user instruction When matching, the second type of operating system is controlled to decrypt the encrypted verification information.
- the request instruction of the electronic account transaction is obtained by acquiring a request sent by the user, and the verification information is decrypted according to the matching result of the request instruction matching the user instruction, and if the matching is performed, the verification information is decrypted, if not, the The decryption is performed so that the verification information can be obtained only when the website currently used for the electronic account transaction is legal, and the security of the verification information is ensured.
- FIG. 3 shows a schematic block diagram of a mobile terminal in accordance with an embodiment of the present invention.
- a mobile terminal 300 includes a control system 200 of an electronic account as shown in FIG. 2. Therefore, the mobile terminal 300 has the same technical effects as the control system 200 of the electronic account shown in FIG. 2, and details are not described herein again.
- the mobile terminal includes two operating systems, namely, a read-only operating system A that does not support network connection and an operating system B that supports network connection, when the mobile terminal receives the dynamic code.
- a read-only operating system A that does not support network connection
- an operating system B that supports network connection
- the user's iris feature value, and/or fingerprint is entered into the read-only operating system A that does not support the network connection.
- the operating system B supporting the network connection receives the notification message of the dynamic code
- Read-only operating system A that supports network connection immediately adds dynamic code Secret storage (at this time, even if the Trojan steals, it is garbled without any value);
- the dynamic code can only be decrypted by the user himself. For example, if the iris feature value is used for encryption, the user needs to directly view the dynamic code to decrypt. If the fingerprint is encrypted, the user's fingerprint information needs to be input to decrypt.
- the most common problem for the user to go to the phishing website is to click on an unknown link, which is sometimes inevitable in the mobile terminal or the computer.
- the IP address of the website of the legal transaction platform is reserved in the read-only operating system A that does not support the network connection.
- the read-only operating system A that does not support the network connection makes a legal judgment on the newly established Socket (socket, which is used to describe the IP address and port) of the operating system B supporting the network connection, and only judges the pre-determination.
- Socket socketet, which is used to describe the IP address and port
- the Socket can establish a connection. Any other phishing website or other Sockets for non-online transactions are forbidden to be newly created.
- a online transaction can be up to several tens of seconds) without delaying the user's time.
- the corresponding decryption information is input according to the user initial setting to decrypt the dynamic code, and then the dynamic code is used to complete the electronic account transaction; or the user uses the computer and other terminals to access the Internet, and the computer must be used at this time.
- the computer is connected to the Internet via a mobile phone.
- the Socket link of a website that the user clicks on the computer must use the mobile phone as a modem (modem) to access the Internet.
- the website cannot be accessed.
- the user does not need to decrypt the dynamic code.
- the online transaction must also be under the protection of the operating system B that supports the network connection, otherwise the online transaction cannot be performed at all, and the user decrypts the dynamic code to force the use of the mobile phone to do the modem for the fund transaction, nor will it There is time to open a non-transaction Socket.
- the online transaction time is very short.
- the mobile Internet connection function can be disabled. The online transaction consumes very little traffic and does not occupy much mobile phone traffic. Therefore, it does not affect the user's online experience when not currently trading.
- the present invention proposes a new control scheme for an electronic account, which can encrypt the verification information before the user conducts the electronic account transaction, and then confirms the connection to the legitimate website.
- the verification information is decrypted to complete the electronic account transaction according to the decrypted verification information, thereby avoiding the occurrence of the user leaking the verification information to the phishing website when performing the electronic account transaction, thereby protecting the user's vital interests and improving the user's interests.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Finance (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Marketing (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Entrepreneurship & Innovation (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本发明提供了一种电子账户的控制方法、系统及移动终端,电子账户的控制方法包括:通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息;将网络地址信息解析为目标网站对应的IP地址信息,并将IP地址信息转发至第二类操作系统;通过第二类操作系统判断IP地址信息是否与预设IP地址信息匹配;在第二类操作系统判定IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至第一类操作系统。本发明的技术方案能够在用户进行网上交易前对验证信息进行加密,并在连接到合法网站时对验证信息进行解密以完成电子账户交易,从而避免了用户将验证信息泄漏给钓鱼网站,保护用户的切身利益。
Description
本发明涉及终端技术领域,具体而言,涉及一种电子账户的控制方法、一种电子账户的控制系统和一种移动终端。
目前用户无论是通过手机或者电脑进行网上交易时,都有可能因点击了不明链接而误入钓鱼网站,造成用户在毫无防备之下就泄漏了个人的敏感数据信息或验证信息,进而导致用户的财产损失,危害用户的切身利益,而针对此问题,目前还没有有效地方法可以解决。
因此,如何设计一种电子账户的控制方案以避免用户在进行电子账户交易时将验证信息泄漏给钓鱼网站成为亟待解决的技术问题。
发明内容
本发明正是基于上述技术问题至少之一,提出了一种新的电子账户的控制方案,能够在用户进行电子账户交易前对验证信息进行加密,并在确定连接到合法网站时再对验证信息进行解密以根据解密后的验证信息完成电子账户交易,从而避免了用户在进行电子账户交易时将验证信息泄漏给钓鱼网站的情况的发生,保护了用户的切身利益,提升了用户的使用体验。
有鉴于此,本发明提出了一种电子账户的控制方法,包括:通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易;将所述网络地址信息解析为所述目标网站对应的IP地址信息,并将所述IP地址信息转发至所述第二类操作系统;通过所述第二类操作系统判断所述IP地址信息是否与预设IP地址信息匹配;在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,
根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限。
在该技术方案中,通过第一类操作系统获取并解析待进行电子账户交易的目标网站的网络地址信息,并通过第二类操作系统在判定解析出的IP(Internet Protocol,网络之间的互联协议)地址信息和预设的IP地址信之后,再根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至第一类操作系统,以确定第一类操作系统在目标网站对电子账户的交易权限,避免了现有技术中因用户点击了不明链接而误登钓鱼网站导致将验证信息泄漏给钓鱼网站的情况的发生,保证了整个电子账户的交易过程的安全性,保护了用户的切身利益,提升了用户的使用体验。
在上述技术方案中,优选地,通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易,具体包括:在所述移动终端连接至外设终端时,通过所述第一类操作系统获取所述外设终端发送的网络地址信息。
在该技术方案中,通过所述第一类操作系统获取所述外设终端发送的网络地址信息,使得即便用户通过外设终端来进行电子账户交易,也同样能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易,具体还包括:通过所述第一类操作系统获取用户输入的目标网站的网络地址信息。
在该技术方案中,用户还可以通过第一类操作系统获取用户输入的目标网站的网络地址信息,使得用户在通过移动终端来进行电子账户交易,也能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,在通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易前,还包括:在所述第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以作为所述预设IP地址信息。
在该技术方案中,通过在第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以为后续用户根据匹配结过来解密验证信息提供前提保障。
在上述任一项技术方案中,优选地,在通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易前,还包括:在所述第一类操作系统接收到待加密的验证信息时,将所述待加密的验证信息存储至所述第二类操作系统;控制所述第二类操作系统根据所述用户指令对所述待加密的验证信息进行加密,其中,所述用户指令包括用户触控指令和生物特征信息,所述生物特征信息包括用户的指纹特征、虹膜特征、声纹特征和人脸图像特征中的至少一种,所述用户触控指令包括用户的触控操作信息和所述移动终端的姿态变化信息。
在该技术方案中,第一类操作系统的安全级别低于第二类操作系统,通过移动终端中安全级别低的操作系统获取验证信息,并利用移动终端中安全级别高的操作系统对安全级别低中的验证信息进行加密存储,使得因加密后的验证信息存储在安全级别高的操作系统中,所以木马等病毒很难侵入到安全级别高的操作系统来窃取验证信息,即便是窃取到验证信息,也无法获取验证信息的具体信息内容,从而有效地保证了验证信息的安全。
在上述任一项技术方案中,优选地,在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限,具体步骤包括:通过所述第一类操作系统获取用户发出的请求进行电子账户交易的请求指令,并将所述请求指令转发至所述第二类操作系统;通过所述第二类操作系统判断所述请求指令是否与所述用户指令匹配;在判定所述请求指令与所述用户指令匹配时,控制所述第二类操作系统对所述已加密的验证信息进行解密。
在该技术方案中,通过获取用户发出的请求进行电子账户交易的请求指令,并根据请求指令与用户指令匹配的匹配结果来解密验证信息,若匹
配,则解密验证信息,若不匹配,则不进行解密,使得只有在确保当前用于进行电子账户交易的网站是合法的时候,才能获取到验证信息,保证了验证信息的安全性。
根据本发明的第二方面,提出了一种电子账户的控制系统,包括:第一获取单元,用于通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易;解析单元,用于将所述网络地址信息解析为所述目标网站对应的IP地址信息;第一转发单元,用于将所述IP地址信息转发至所述第二类操作系统;第一匹配单元,用于通过所述第二类操作系统判断所述IP地址信息是否与预设IP地址信息匹配;处理单元,在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限。
在该技术方案中,通过第一类操作系统获取并解析待进行电子账户交易的目标网站的网络地址信息,并通过第二类操作系统在判定解析出的IP(Internet Protocol,网络之间的互联协议)地址信息和预设的IP地址信之后,再根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至第一类操作系统,以确定第一类操作系统在目标网站对电子账户的交易权限,避免了现有技术中因用户点击了不明链接而误登钓鱼网站导致将验证信息泄漏给钓鱼网站的情况的发生,保证了整个电子账户的交易过程的安全性,保护了用户的切身利益,提升了用户的使用体验。
在上述技术方案中,优选地,所述第一获取单元具体用于:在所述移动终端连接至外设终端时,通过所述第一类操作系统获取所述外设终端发送的网络地址信息。
在该技术方案中,通过所述第一类操作系统获取所述外设终端发送的网络地址信息,使得即便用户通过外设终端来进行电子账户交易,也同样能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,所述第一获取单元具体用于:通过所述第一类操作系统获取用户输入的目标网站的网络地址信息。
在该技术方案中,用户还可以通过第一类操作系统获取用户输入的目标网站的网络地址信息,使得用户在通过移动终端来进行电子账户交易,也能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,还包括:第一存储单元,用于在所述第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以作为所述预设IP地址信息。
在该技术方案中,通过在第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以为后续用户根据匹配结过来解密验证信息提供前提保障。
在上述任一项技术方案中,优选地,还包括:第二存储单元,用于在所述第一类操作系统接收到待加密的验证信息时,将所述待加密的验证信息存储至所述第二类操作系统;加密单元,用于控制所述第二类操作系统根据所述用户指令对所述待加密的验证信息进行加密,其中,所述用户指令包括用户触控指令和生物特征信息,所述生物特征信息包括用户的指纹特征、虹膜特征、声纹特征和人脸图像特征中的至少一种,所述用户触控指令包括用户的触控操作信息和所述移动终端的姿态变化信息。
在该技术方案中,第一类操作系统的安全级别低于第二类操作系统,通过移动终端中安全级别低的操作系统获取验证信息,并利用移动终端中安全级别高的操作系统对安全级别低中的验证信息进行加密存储,使得因加密后的验证信息存储在安全级别高的操作系统中,所以木马等病毒很难侵入到安全级别高的操作系统来窃取验证信息,即便是窃取到验证信息,也无法获取验证信息的具体信息内容,从而有效地保证了验证信息的安全。
在上述任一项技术方案中,优选地,所述处理单元包括:第二获取单元,用于通过所述第一类操作系统获取用户发出的请求进行电子账户交易的请求指令;第二转发单元,用于将所述请求指令转发至所述第二类操作系统;第二匹配单元,用于通过所述第二类操作系统判断所述请求指令是否与所述用户指令匹配;解密单元,用于在判定所述请求指令与所述用户指令匹配时,控制所述第二类操作系统对所述已加密的验证信息进行解
密。
在该技术方案中,通过获取用户发出的请求进行电子账户交易的请求指令,并根据请求指令与用户指令匹配的匹配结果来解密验证信息,若匹配,则解密验证信息,若不匹配,则不进行解密,使得只有在确保当前用于进行电子账户交易的网站是合法的时候,才能获取到验证信息,保证了验证信息的安全性。
根据本发明的第三方面,还提出了一种移动终端,包括:如上述任一项技术方案所述的电子账户的控制系统。因此,该移动终端具有与上述任一项技术方案中所述的电子账户的控制系统相同的技术效果,在此不再赘述。
通过以上技术方案,能够在用户进行电子账户交易前对验证信息进行加密,并在确定连接到合法网站时再对验证信息进行解密以根据解密后的验证信息完成电子账户交易,从而避免了用户在进行电子账户交易时将验证信息泄漏给钓鱼网站的情况的发生,保护了用户的切身利益,提升了用户的使用体验。
图1示出了根据本发明的实施例的电子账户的控制方法的示意流程图;
图2示出了根据本发明的实施例的电子账户的控制系统的示意框图;
图3示出了根据本发明的一个实施例的移动终端的示意框图;
图4示出了根据本发明的另一个实施例的移动终端的示意框图。
为了能够更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用其他不同于在此描述的其他方式来实施,因此,本发明
的保护范围并不受下面公开的具体实施例的限制。
图1示出了根据本发明的实施例的电子账户的控制方法的示意流程图。
如图1所示,根据本发明的实施例的电子账户的控制方法,包括:步骤102,通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易;步骤104,将所述网络地址信息解析为所述目标网站对应的IP地址信息,并将所述IP地址信息转发至所述第二类操作系统;步骤106,通过所述第二类操作系统判断所述IP地址信息是否与预设IP地址信息匹配;步骤108,在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限。
在该技术方案中,通过第一类操作系统获取并解析待进行电子账户交易的目标网站的网络地址信息,并通过第二类操作系统在判定解析出的IP(Internet Protocol,网络之间的互联协议)地址信息和预设的IP地址信之后,再根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至第一类操作系统,以确定第一类操作系统在目标网站对电子账户的交易权限,避免了现有技术中因用户点击了不明链接而误登钓鱼网站导致将验证信息泄漏给钓鱼网站的情况的发生,保证了整个电子账户的交易过程的安全性,保护了用户的切身利益,提升了用户的使用体验。
在上述技术方案中,优选地,步骤102具体包括:在所述移动终端连接至外设终端时,通过所述第一类操作系统获取所述外设终端发送的网络地址信息。
在该技术方案中,通过所述第一类操作系统获取所述外设终端发送的网络地址信息,使得即便用户通过外设终端来进行电子账户交易,也同样能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,步骤102具体还包括:通过所述第一类操作系统获取用户输入的目标网站的网络地址信息。
在该技术方案中,用户还可以通过第一类操作系统获取用户输入的目标网站的网络地址信息,使得用户在通过移动终端来进行电子账户交易,也能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,在步骤102前,还包括:在所述第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以作为所述预设IP地址信息。
在该技术方案中,通过在第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以为后续用户根据匹配结过来解密验证信息提供前提保障。
在上述任一项技术方案中,优选地,在步骤102前,还包括:在所述第一类操作系统接收到待加密的验证信息时,将所述待加密的验证信息存储至所述第二类操作系统;控制所述第二类操作系统根据所述用户指令对所述待加密的验证信息进行加密,其中,所述用户指令包括用户触控指令和生物特征信息,所述生物特征信息包括用户的指纹特征、虹膜特征、声纹特征和人脸图像特征中的至少一种,所述用户触控指令包括用户的触控操作信息和所述移动终端的姿态变化信息。
在该技术方案中,第一类操作系统的安全级别低于第二类操作系统,通过移动终端中安全级别低的操作系统获取验证信息,并利用移动终端中安全级别高的操作系统对安全级别低中的验证信息进行加密存储,使得因加密后的验证信息存储在安全级别高的操作系统中,所以木马等病毒很难侵入到安全级别高的操作系统来窃取验证信息,即便是窃取到验证信息,也无法获取验证信息的具体信息内容,从而有效地保证了验证信息的安全。
在上述任一项技术方案中,优选地,步骤108包括:通过所述第一类操作系统获取用户发出的请求进行电子账户交易的请求指令,并将所述请求指令转发至所述第二类操作系统;通过所述第二类操作系统判断所述请求指令是否与所述用户指令匹配;在判定所述请求指令与所述用户指令匹配时,控制所述第二类操作系统对所述已加密的验证信息进行解密。
在该技术方案中,通过获取用户发出的请求进行电子账户交易的请求
指令,并根据请求指令与用户指令匹配的匹配结果来解密验证信息,若匹配,则解密验证信息,若不匹配,则不进行解密,使得只有在确保当前用于进行电子账户交易的网站是合法的时候,才能获取到验证信息,保证了验证信息的安全性。
图2示出了根据本发明的实施例的电子账户的控制系统的示意框图。
如图2所示,根据本发明的实施例的电子账户的控制系统200,包括:第一获取单元202、解析单元204、第一匹配单元208及处理单元210。
其中,第一获取单元202,用于通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易;解析单元204,用于将所述网络地址信息解析为所述目标网站对应的IP地址信息;第一转发单元206,用于将所述IP地址信息转发至所述第二类操作系统;第一匹配单元208,用于通过所述第二类操作系统判断所述IP地址信息是否与预设IP地址信息匹配;处理单元210,在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限。
在该技术方案中,通过第一类操作系统获取并解析待进行电子账户交易的目标网站的网络地址信息,并通过第二类操作系统在判定解析出的IP(Internet Protocol,网络之间的互联协议)地址信息和预设的IP地址信之后,再根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至第一类操作系统,以确定第一类操作系统在目标网站对电子账户的交易权限,避免了现有技术中因用户点击了不明链接而误登钓鱼网站导致将验证信息泄漏给钓鱼网站的情况的发生,保证了整个电子账户的交易过程的安全性,保护了用户的切身利益,提升了用户的使用体验。
在上述技术方案中,优选地,所述第一获取单元202具体用于:在所述移动终端连接至外设终端时,通过所述第一类操作系统获取所述外设终端发送的网络地址信息。
在该技术方案中,通过所述第一类操作系统获取所述外设终端发送的网络地址信息,使得即便用户通过外设终端来进行电子账户交易,也同样能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,所述第一获取单元202具体用于:通过所述第一类操作系统获取用户输入的目标网站的网络地址信息。
在该技术方案中,用户还可以通过第一类操作系统获取用户输入的目标网站的网络地址信息,使得用户在通过移动终端来进行电子账户交易,也能避免用户将验证信息泄漏给钓鱼网站的情况的发生。
在上述任一项技术方案中,优选地,还包括:第一存储单元212,用于在所述第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以作为所述预设IP地址信息。
在该技术方案中,通过在第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以为后续用户根据匹配结过来解密验证信息提供前提保障。
在上述任一项技术方案中,优选地,还包括:第二存储单元214及加密单元216。
其中,第二存储单元214,用于在所述第一类操作系统接收到待加密的验证信息时,将所述待加密的验证信息存储至所述第二类操作系统;加密单元216,用于控制所述第二类操作系统根据所述用户指令对所述待加密的验证信息进行加密,其中,所述用户指令包括用户触控指令和生物特征信息,所述生物特征信息包括用户的指纹特征、虹膜特征、声纹特征和人脸图像特征中的至少一种,所述用户触控指令包括用户的触控操作信息和所述移动终端的姿态变化信息。
在该技术方案中,第一类操作系统的安全级别低于第二类操作系统,通过移动终端中安全级别低的操作系统获取验证信息,并利用移动终端中安全级别高的操作系统对安全级别低中的验证信息进行加密存储,使得因加密后的验证信息存储在安全级别高的操作系统中,所以木马等病毒很难侵入到安全级别高的操作系统来窃取验证信息,即便是窃取到验证信息,也无法获取验证信息的具体信息内容,从而有效地保证了验证信息的安
全。
在上述任一项技术方案中,优选地,所述处理单元210包括:第二获取单元2102、第二转发单元2104、第二匹配单元2106及解密单元2108。
其中,第二获取单元2102,用于通过所述第一类操作系统获取用户发出的请求进行电子账户交易的请求指令;第二转发单元2104,用于将所述请求指令转发至所述第二类操作系统;第二匹配单元2106,用于通过所述第二类操作系统判断所述请求指令是否与所述用户指令匹配;解密单元2108,用于在判定所述请求指令与所述用户指令匹配时,控制所述第二类操作系统对所述已加密的验证信息进行解密。
在该技术方案中,通过获取用户发出的请求进行电子账户交易的请求指令,并根据请求指令与用户指令匹配的匹配结果来解密验证信息,若匹配,则解密验证信息,若不匹配,则不进行解密,使得只有在确保当前用于进行电子账户交易的网站是合法的时候,才能获取到验证信息,保证了验证信息的安全性。
图3示出了根据本发明的实施例的移动终端的示意框图。
如图3所示,根据本发明的实施例的移动终端300,包括:如图2所示的电子账户的控制系统200。因此,该移动终端300具有与图2所示的电子账户的控制系统200相同的技术效果,在此不再赘述。
下面结合图4对本发明的技术方案进一步说明。
如图4所示,在本实施例中,移动终端包括两个操作系统,分别为不支持网络连接的只读操作系统A和支持网络连接的操作系统B,在该移动终端接收到动态码时,利用双系统的特点,防止用户登录钓鱼网站后,在无意中泄露动态码的情况,这个系统好处在于对动态码的保护不依赖与银行的系统的升级,所有的保护均可以用移动终端双系统本身搞定,极大的提高其灵活性。
具体地,在初始设置阶段,将用户的虹膜特征值,和/或指纹录入不支持网络连接的只读操作系统A中,当支持网络连接的操作系统B收到动态码的通知短信时,不支持网络连接的只读操作系统A立刻将动态码加
密存储(此时即使是木马窃取到,也是乱码没有任何价值);当接收查看动态码的指令时,会判断查看动态码的人是否是用户本人,因为移动终端上留有用户本人的虹膜特征值,或者指纹,那么动态码也只有用户本人才能解密,比如用虹膜特征值加密,则需用户本人直视动态码才能解密,若是指纹加密,则需输入用户本人的指纹信息才能解密。
而针对钓鱼网站窃取用户的验证信息的问题,在本实施例中,对于用户上了钓鱼网站的问题,最常见的就是点击了不明的链接,无论在手机端,或电脑等有时会无可避免的点击不明链接,为了保护用户的资金安全,就必须保护银行下发的动态码,绝对不能输入到钓鱼网站。
具体地,首先在不支持网络连接的只读操作系统A中预留合法交易平台的网站IP地址,当用户选择用支持网络连接的操作系统B上网,在用户需要进行电子账户交易解密动态码时,此时不支持网络连接的只读操作系统A对支持网络连接的操作系统B新建立的Socket(套接字,用于描述IP地址和端口)链接地址做合法性判断,只有判断出与预留的网站IP地址匹配时,Socket才能建立连接,其他不管任何是钓鱼网站,或者其他非在线交易用的Socket都被禁止新建,(一次在线交易最多几十秒)不会耽误用户的时间,并在与合法交易平台建立连接后,再根据用户初始化设置输入对应的解密信息来解密动态码,然后再利用动态码来完成电子账户交易;又或者用户使用电脑等终端来上网,此时须将电脑设置为仅能通过手机来上网的模式,比如可以通过USB口与手机连接,并将手机设置成一个热点,电脑通过手机来连接上网。用户在电脑上点击的某网站的Socket链接必须是使用手机做Modem(调制解调器)上网,否则无法访问该网站,在无法与网站建立连接时,用户也无需解密动态码。在用户使用电脑上网,其在线交易也要在支持网络连接的操作系统B的保护之下,否则根本无法进行在线交易,且用户解密动态码强制开启使用手机做Modem做资金交易时,也不会有空暇去开非交易的Socket,一般在线交易的时间很短,当用户不需要在线交易时,可以关闭强制使用手机上网连接功能,在线交易消耗流量极小,也不会占用多少手机的流量,从而不会影响到用户不进行在现交易时的上网体验。
以上结合附图详细说明了本发明的技术方案,本发明提出了一种新的电子账户的控制方案,能够在用户进行电子账户交易前对验证信息进行加密,并在确定连接到合法网站时再对验证信息进行解密以根据解密后的验证信息完成电子账户交易,从而避免了用户在进行电子账户交易时将验证信息泄漏给钓鱼网站的情况的发生,保护了用户的切身利益,提升了用户的使用体验。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
Claims (13)
- 一种电子账户的控制方法,适用于移动终端,所述移动终端运行有第一类操作系统和第二类操作系统,其特征在于,所述第一类操作系统可接入通信网络,所述第二类操作系统连接至所述第一类操作系统且隔离于所述通信网络,所述电子账户的控制方法包括:通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易;将所述网络地址信息解析为所述目标网站对应的IP地址信息,并将所述IP地址信息转发至所述第二类操作系统;通过所述第二类操作系统判断所述IP地址信息是否与预设IP地址信息匹配;在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限。
- 根据权利要求1所述的电子账户的控制方法,其特征在于,通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易,具体包括:在所述移动终端连接至外设终端时,通过所述第一类操作系统获取所述外设终端发送的网络地址信息。
- 根据权利要求1所述的电子账户的控制方法,其特征在于,通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易,具体还包括:通过所述第一类操作系统获取用户输入的目标网站的网络地址信息。
- 根据权利要求1所述的电子账户的控制方法,其特征在于,在通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易前,还包括:在所述第二类操作系统中预存储多个用于进行在线交易的网站的IP 地址信息,以作为所述预设IP地址信息。
- 根据权利要求1至4中任一项所述的电子账户的控制方法,其特征在于,在通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易前,还包括:在所述第一类操作系统接收到待加密的验证信息时,将所述待加密的验证信息存储至所述第二类操作系统;控制所述第二类操作系统根据所述用户指令对所述待加密的验证信息进行加密,其中,所述用户指令包括用户触控指令和生物特征信息,所述生物特征信息包括用户的指纹特征、虹膜特征、声纹特征和人脸图像特征中的至少一种,所述用户触控指令包括用户的触控操作信息和所述移动终端的姿态变化信息。
- 根据权利要求5所述的电子账户的控制方法,其特征在于,在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限,具体步骤包括:通过所述第一类操作系统获取用户发出的请求进行电子账户交易的请求指令,并将所述请求指令转发至所述第二类操作系统;通过所述第二类操作系统判断所述请求指令是否与所述用户指令匹配;在判定所述请求指令与所述用户指令匹配时,控制所述第二类操作系统对所述已加密的验证信息进行解密。
- 一种电子账户的控制系统,适用于移动终端,所述移动终端运行有第一类操作系统和第二类操作系统,其特征在于,所述第一类操作系统可接入通信网络,所述第二类操作系统连接至所述第一类操作系统且隔离于所述通信网络,所述电子账户的控制系统包括:第一获取单元,用于通过第一类操作系统获取待进行电子账户交易的目标网站的网络地址信息,所述目标网站用于进行在线交易;解析单元,用于将所述网络地址信息解析为所述目标网站对应的IP地址信息;第一转发单元,用于将所述IP地址信息转发至所述第二类操作系统;第一匹配单元,用于通过所述第二类操作系统判断所述IP地址信息是否与预设IP地址信息匹配;处理单元,在所述第二类操作系统判定所述IP地址信息与预设IP地址信息匹配时,根据用户指令对已加密的验证信息进行解密处理,并将解密后的验证信息发送至所述第一类操作系统,以确定所述第一类操作系统在所述目标网站对电子账户的交易权限。
- 根据权利要求7所述的电子账户的控制系统,其特征在于,所述第一获取单元具体用于:在所述移动终端连接至外设终端时,通过所述第一类操作系统获取所述外设终端发送的网络地址信息。
- 根据权利要求7所述的电子账户的控制系统,其特征在于,所述第一获取单元具体用于:通过所述第一类操作系统获取用户输入的目标网站的网络地址信息。
- 根据权利要求7所述的电子账户的控制系统,其特征在于,还包括:第一存储单元,用于在所述第二类操作系统中预存储多个用于进行在线交易的网站的IP地址信息,以作为所述预设IP地址信息。
- 根据权利要求7至10中任一项所述的电子账户的控制系统,其特征在于,还包括:第二存储单元,用于在所述第一类操作系统接收到待加密的验证信息时,将所述待加密的验证信息存储至所述第二类操作系统;加密单元,用于控制所述第二类操作系统根据所述用户指令对所述待加密的验证信息进行加密,其中,所述用户指令包括用户触控指令和生物特征信息,所述生物特征信息包括用户的指纹特征、虹膜特征、声纹特征和人脸图像特征中的至少一种,所述用户触控指令包括用户的触控操作信息和所述移动终端的姿 态变化信息。
- 根据权利要求11所述的电子账户的控制系统,其特征在于,所述处理单元包括:第二获取单元,用于通过所述第一类操作系统获取用户发出的请求进行电子账户交易的请求指令;第二转发单元,用于将所述请求指令转发至所述第二类操作系统;第二匹配单元,用于通过所述第二类操作系统判断所述请求指令是否与所述用户指令匹配;解密单元,用于在判定所述请求指令与所述用户指令匹配时,控制所述第二类操作系统对所述已加密的验证信息进行解密。
- 一种移动终端,其特征在于,包括:如权利要求7至12中任一项所述的电子账户的控制系统。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510590927.XA CN105141623B (zh) | 2015-09-16 | 2015-09-16 | 电子账户的控制方法、系统及移动终端 |
| CN201510590927.X | 2015-09-16 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017045253A1 true WO2017045253A1 (zh) | 2017-03-23 |
Family
ID=54726830
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2015/093487 Ceased WO2017045253A1 (zh) | 2015-09-16 | 2015-10-31 | 电子账户的控制方法、系统及移动终端 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105141623B (zh) |
| WO (1) | WO2017045253A1 (zh) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112437052B (zh) * | 2020-11-10 | 2022-06-28 | 北京字节跳动网络技术有限公司 | 用于处理信息的方法、装置、电子设备和计算机可读介质 |
| CN118521316B (zh) * | 2024-07-23 | 2024-10-22 | 江西裕民银行股份有限公司 | 银行电子账户交易权限控制方法、系统及其平台 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101459513A (zh) * | 2007-12-10 | 2009-06-17 | 联想(北京)有限公司 | 一种计算机和用于认证的安全信息的发送方法 |
| CN101753545A (zh) * | 2008-12-11 | 2010-06-23 | 北京奇虎科技有限公司 | 净盒技术 |
| CN103620613A (zh) * | 2011-03-28 | 2014-03-05 | 迈克菲股份有限公司 | 用于基于虚拟机监视器的反恶意软件安全的系统和方法 |
| CN104156658A (zh) * | 2014-07-30 | 2014-11-19 | 深圳市中兴移动通信有限公司 | 一种移动终端及其在双系统下访问数据的方法和装置 |
| CN104679558A (zh) * | 2015-02-09 | 2015-06-03 | 西安酷派软件科技有限公司 | 一种多系统间的切换方法和终端 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103475636A (zh) * | 2013-06-13 | 2013-12-25 | 深圳创维-Rgb电子有限公司 | 电子账户登录方法及智能终端、移动终端 |
-
2015
- 2015-09-16 CN CN201510590927.XA patent/CN105141623B/zh active Active
- 2015-10-31 WO PCT/CN2015/093487 patent/WO2017045253A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101459513A (zh) * | 2007-12-10 | 2009-06-17 | 联想(北京)有限公司 | 一种计算机和用于认证的安全信息的发送方法 |
| CN101753545A (zh) * | 2008-12-11 | 2010-06-23 | 北京奇虎科技有限公司 | 净盒技术 |
| CN103620613A (zh) * | 2011-03-28 | 2014-03-05 | 迈克菲股份有限公司 | 用于基于虚拟机监视器的反恶意软件安全的系统和方法 |
| CN104156658A (zh) * | 2014-07-30 | 2014-11-19 | 深圳市中兴移动通信有限公司 | 一种移动终端及其在双系统下访问数据的方法和装置 |
| CN104679558A (zh) * | 2015-02-09 | 2015-06-03 | 西安酷派软件科技有限公司 | 一种多系统间的切换方法和终端 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105141623B (zh) | 2018-10-26 |
| CN105141623A (zh) | 2015-12-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10897455B2 (en) | System and method for identity authentication | |
| US9875368B1 (en) | Remote authorization of usage of protected data in trusted execution environments | |
| US10057763B2 (en) | Soft token system | |
| US8370899B2 (en) | Disposable browser for commercial banking | |
| US9867043B2 (en) | Secure device service enrollment | |
| JP6498358B2 (ja) | 使い捨て乱数を利用して認証する統合認証システム | |
| US9547756B2 (en) | Registration of devices in a digital rights management environment | |
| US20150310427A1 (en) | Method, apparatus, and system for generating transaction-signing one-time password | |
| US20080134314A1 (en) | Automated security privilege setting for remote system users | |
| MX2011002423A (es) | Autorizacion de operaciones de servidor. | |
| CN106302332B (zh) | 用户数据的访问控制方法、装置及系统 | |
| US9332011B2 (en) | Secure authentication system with automatic cancellation of fraudulent operations | |
| US10333707B1 (en) | Systems and methods for user authentication | |
| US9871890B2 (en) | Network authentication method using a card device | |
| CN104410580B (zh) | 可信安全WiFi路由器及其数据处理方法 | |
| CN103368918A (zh) | 一种动态口令认证方法、装置及系统 | |
| CN108701202A (zh) | 数据泄漏检测系统 | |
| US20100146605A1 (en) | Method and system for providing secure online authentication | |
| WO2017045253A1 (zh) | 电子账户的控制方法、系统及移动终端 | |
| CN119722062A (zh) | 支付链接的生成方法、装置和非易失性存储介质 | |
| KR20140023085A (ko) | 사용자 인증 방법, 인증 서버 및 사용자 인증 시스템 | |
| Rivers et al. | A Study on Cyber Attacks and Vulnerabilities in Mobile Payment Applications | |
| US20080060060A1 (en) | Automated Security privilege setting for remote system users | |
| CN113434865A (zh) | 一种用于移动端的安全检测方法、装置、设备及存储介质 | |
| WO2018017019A1 (en) | Personal security device and method |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15903941 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15903941 Country of ref document: EP Kind code of ref document: A1 |