A method of preventing phishing attacks aimed at dynamic passwords

A dynamic password and phishing attack technology, which is applied in the field of network security, can solve the problems that online banks are vulnerable to phishing attacks, and achieve the effects of preventing phishing attacks, improving security, and avoiding harm

CN102307181BActive Publication Date: 2016-03-02DYNAMICODE
5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2016-03-02

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a method for preventing a phishing attack for a dynamic password. The method comprises the following steps of: obtaining a unique computer identifier (ID) according to the hardware information of a computer; and establishing an authentication strategy on an authentication server, transmitting the computer ID and the dynamic password together to the authentication server when the user performs dynamic password authentication, and authenticating correspondence between the computer ID and a dynamic token sequence number according to the authentication strategy by using the authentication server. By the method, the phishing attack of a hacker for the dynamic password can be effectively prevented, and the security of online trading can be greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to a network security technology, in particular to a method for preventing phishing attacks, in particular to a method for preventing anti-phishing attacks aimed at dynamic passwords. Background technique

[0002] A dynamic password is a one-time password, and each password can only be used once. The dynamic password can change with time, frequency and challenge information. The dynamic password is combined with the original static password to form a two-factor authentication, which is widely applicable to various information systems.

[0003] Phishing is a very common means of attack at present, mainly refers to hackers lure customers to visit fake websites (phishing websites) through emails, text messages, etc., and lure customers to enter account names, passwords, dynamic passwords, etc. To achieve the purpose of stealing accounts and passwords.

[0004] For a dynamic password, due to the existence of a time window, the dyna...

Examples

Embodiment Construction

[0028] In order to make the technical means, creative features, goals and effects achieved by the present invention easy to understand, the present invention will be further described below in conjunction with specific illustrations.

[0029] For the principle of existing phishing attacks, the method for preventing phishing attacks for dynamic passwords provided by the present invention comprises the following steps (see figure 2 ):

[0030] (1) The hardware information of the user computer (such as inherent information such as CPUID and MAC address) is encrypted to generate a unique computer ID, which is used as the unique identification information for the calculation.

[0031] (2) Establish an authentication strategy on the authentication server, which authentication strategy is used to manage which token serial numbers correspond to which computer IDs, and the update method of the corresponding relationship, and establish the authentication method adopted by the exceeding...