A method of preventing phishing attacks aimed at dynamic passwords
A dynamic password and phishing attack technology, which is applied in the field of network security, can solve the problems that online banks are vulnerable to phishing attacks, and achieve the effects of preventing phishing attacks, improving security, and avoiding harm
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2016-03-02
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to a network security technology, in particular to a method for preventing phishing attacks, in particular to a method for preventing anti-phishing attacks aimed at dynamic passwords. Background technique
[0002] A dynamic password is a one-time password, and each password can only be used once. The dynamic password can change with time, frequency and challenge information. The dynamic password is combined with the original static password to form a two-factor authentication, which is widely applicable to various information systems.
[0003] Phishing is a very common means of attack at present, mainly refers to hackers lure customers to visit fake websites (phishing websites) through emails, text messages, etc., and lure customers to enter account names, passwords, dynamic passwords, etc. To achieve the purpose of stealing accounts and passwords.
[0004] For a dynamic password, due to the existence of a time window, the dyna...
Examples
Embodiment Construction
[0028] In order to make the technical means, creative features, goals and effects achieved by the present invention easy to understand, the present invention will be further described below in conjunction with specific illustrations.
[0029] For the principle of existing phishing attacks, the method for preventing phishing attacks for dynamic passwords provided by the present invention comprises the following steps (see figure 2 ):
[0030] (1) The hardware information of the user computer (such as inherent information such as CPUID and MAC address) is encrypted to generate a unique computer ID, which is used as the unique identification information for the calculation.
[0031] (2) Establish an authentication strategy on the authentication server, which authentication strategy is used to manage which token serial numbers correspond to which computer IDs, and the update method of the corresponding relationship, and establish the authentication method adopted by the exceeding...