首页> 外国专利> INTERMEDIATE PERSON ATTACK PROTECTION BY CAPTURING, ILLEGAL ACCOUNT SHARING BLACK LIST, AND SAFETY RATING METHOD

INTERMEDIATE PERSON ATTACK PROTECTION BY CAPTURING, ILLEGAL ACCOUNT SHARING BLACK LIST, AND SAFETY RATING METHOD

机译:通过捕获,非法帐户共享黑名单和安全评级方法进行中间人攻击保护

摘要

PROBLEM TO BE SOLVED: To eliminate the conventional necessity of distributing a token (random number list or one-time password) for protection from the illegal money transfer of network banking, particularly, an intermediate person attack.;SOLUTION: An inquiry is made about last transaction history at the time of logging-in (first authentication). For example, a method for (1) displaying and selecting nine pieces of transaction history and one dummy, (2) preparing and selecting a plurality of dummies, and (3) returning the sum of money of transaction history or transaction names is employed. When all questions fail, as a recovery measure, balance information may be accurately input (balance checking by ATM) or telephone authentication (Patent No. 3497799) may be utilized. After the logging-in, as an intermediate person attack countermeasure during transfer (second authentication), when a remittance is input, a server displays a remittee number sequence as a capture mage. Herein, an image difficult to be identified in OCR or the like is used. In addition, ten dummy images are prepared to be selected by a user. This operation may be performed several times. When a correct image is selected, money transfer is executed. In the case of those where the operation is not normally ended, considering that an intermediate person attack has been made, the server transmits a received account number as an illegal account number to a shared DB. Each bank server always checks this, detects money transfer to this account, and blocks illegal money transfer in advance. A ranking server always checks the safety of each bank, and evaluates safety ranking in real time. The evaluation value of the safety of each bank (illegal money transfer blocking rate or applied technology) is displayed together with an image file or the like on the top page of each bank.;COPYRIGHT: (C)2016,JPO&INPIT
机译:解决的问题:消除了分发令牌(随机号码列表或一次性密码)的常规必要性,以防止网络银行的非法汇款,特别是对中间人的攻击。登录时的最新交易历史记录(首次身份验证)。例如,采用以下方法:(1)显示并选择9个交易历史和一个假人;(2)准备并选择多个假人;(3)返回交易历史或交易名称的金额。当所有问题均未通过时,作为恢复措施,可以准确地输入余额信息(通过ATM进行余额检查),或者可以使用电话认证(专利号3497799)。登录后,作为转移(第二次身份验证)过程中的中间人攻击对策,当输入汇款时,服务器会显示汇款人号码序列作为捕获法师。在此,使用在OCR等中难以识别的图像。另外,准备十张伪图像以供用户选择。该操作可以执行几次。选择正确的图像后,将执行汇款。在那些操作没有正常结束的情况下,考虑到进行了中间人攻击,服务器将接收到的帐号作为非法帐号发送到共享数据库。每个银行服务器总是检查此情况,检测到该帐户的转账,并预先阻止非法转账。排名服务器始终检查每个银行的安全性,并实时评估安全性排名。在各银行的首页上显示各银行的安全性评价值(非法汇款阻断率或应用技术)以及图像文件等。版权所有:(C)2016,JPO&INPIT

著录项

  • 公开/公告号JP2016110599A

    专利类型

  • 公开/公告日2016-06-20

    原文格式PDF

  • 申请/专利权人 BANKGUARD CO LTD;

    申请/专利号JP20140267121

  • 发明设计人 FUJII HARUHIKO;

    申请日2014-12-09

  • 分类号G06Q20/40;G06Q20/10;

  • 国家 JP

  • 入库时间 2022-08-21 14:46:10

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号