A process for verifying identity, preventing phishing on the Internet, and removing dynamic passwords

A QR code and character selection process via USSD or voice call enhances security in electronic banking by preventing phishing attacks and reducing financial losses by eliminating dynamic passwords, ensuring secure user input confirmation.

IR112085BUndetermined Publication Date: 2023-12-22MOHAMMAD REZA NEJATI MOGHADDAM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
IR140250140003003658
Authority / Receiving Office
IR · IR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-08-20
Publication Date
2023-12-22
Estimated Expiration
2043-08-20

AI Technical Summary

Technical Problem

Existing security protocols, such as SSL technology and dynamic passwords, are ineffective against advanced phishing attacks that exploit SMS messages and manipulate users into revealing sensitive information, leading to financial losses and unauthorized access.

Method used

Implementing a QR code-based authentication method and a character selection process via USSD or voice call to confirm transactions, eliminating the need for dynamic passwords and making it difficult for hackers to intercept user inputs.

Benefits of technology

Enhances security by preventing phishing attacks, reducing financial losses, and maintaining account integrity by ensuring user inputs are not exposed to interception, thus improving overall security and trust in electronic banking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000010_0000
    Figure 00000010_0000
  • Figure 00000011_0000
    Figure 00000011_0000
  • Figure 00000012_0000
    Figure 00000012_0000
Patent Text Reader

Abstract

Considering the increasing use of electronic banking services and people's use of the Internet and mobile applications, paying attention to security issues is a very important and significant issue. Today, one of the most common attacks in the virtual space is phishing attacks. Of course, there are various attacks carried out by hackers in the world. In its most common form, the attacker creates a fake website similar to the original bank website or other pages and asks users for their customer numbers and passwords. This is when customers enter their customer number and password on a fake website, giving the attacker access to their online banking or other pages. Theft of information related to social networks, email services, currency exchanges, and individual identities are among the cases where user information is misused. Phishers use common methods to access their victims' information. The latest method of sending fake messages is a method used to exploit people, in which the fraudster sends a message to the victim with any title that appears to have a valid and important address. When the person opens their message and clicks on it, it means that the victim has full access to the phone information, which the phishers are looking for at a suitable time to read the dynamic password messages and empty the account. This type of attack will be the latest attack. Another current and important problem in the country that has arisen for banks and people is the dynamic password. Most hackers' main goal is to access the victim's phone messages. In this plan, we have solved this important problem by removing the dynamic password and implementing a process. We have also solved the excessive costs that people and banks pay for text messages, which are about several thousand billion tomans per year. By removing the dynamic password, we will see a reduction in costs.
Need to check novelty before this filing date? Find Prior Art

Description

Description of the invention Note: Items must be written only inside [ ], otherwise they will not be reviewed. Title of the invention (as stated in the declaration) A process for verifying identity, preventing phishing on the Internet, and removing dynamic passwords Technical background of the relevant invention Information Technology, Network Security Technical problem and stating the objectives of the invention Given the increasing use of electronic banking services and people's use of the Internet and mobile applications, compliance with security issues is a very important and significant issue. Today, one of the most common attacks in cyberspace is phishing attacks. Of course, there are various attacks carried out by hackers in the world. In its most common form, the attacker creates a fake website similar to the original bank website or other pages and requests users' customer numbers and passwords. At this time, customers enter their customer numbers and passwords on the fake website, which gives them access to the Internet banking login information or Other pages are at the attacker's disposal. Another attack, which is a newer type of phishing attack, is called "desktop phishing", in which the attacker first places his fake address on the victim's system by sending malware to the victim's system and manipulating his system. In this method, even though the victim has entered the correct address in his browser, he is redirected to the attacker's fake website. This method requires infecting the victim's system with malware specific to this type of attack. It is also possible for an attacker to use clever methods to trick a victim into clicking on links containing malicious malware. Hackers and scammers often use various methods to deliberately target different people and try to deceive them, steal information, and misuse it. Many fraudsters wait to steal user information at opportune times, such as when a new, popular service is being registered, by forging pages that look like the original service. In addition to direct theft of banking information, theft of information related to social networks, email services, exchanges, and individual identities are among the cases where user information is misused. Phishers use common methods to access their victims' information. The latest method of sending fake SMS messages is a method used to exploit people, in which the fraudster sends an SMS to the victim with any title that appears to have a valid and important address. When the person opens their SMS and clicks on it, it means the victim has full access to the phone's information, which the phishers are looking for at a suitable time to read the dynamic password SMS messages and drain the account. This type of attack will be the latest attack. Another current and important problem in the country that has arisen for banks and people is the dynamic password. Most hackers' main goal is to access the victim's SMS messages. In this plan, we have solved this important issue by removing the dynamic password and implementing a process. We also solve the excessive costs that people and banks pay for SMS messages, which are about several thousand billion Tomans per year. By removing the dynamic password, we will see a reduction in costs. A description of the state of the prior art and the history of developments related to the claimed invention. In the previous invention that we have done with registration number 101604, which we have disclosed various topics, we have examined one of the bugs in the infrastructure of all Internet pages such as payment gateways, online banking, login pages, authentication, applications and all pages that require customer authentication and presented a single and applicable plan. However, the previous invention only covered one type of attack, where phishers sought to perform operations on the home page by creating a fake page and simultaneously receiving information, which the invention has solved this problem. Of course, using SSL technology to increase the security factor in the communication between the bank and the Internet and customer pages is one of the solutions to increase security in this platform, but it has not been able to help, because the new methods that have been considered by hackers will almost certainly not have much effect in distinguishing the original and fake site. An example of one of the country's bank sites is that despite the security protocol available on this site, widespread attacks are carried out by hackers to obtain information and hack, and having this protocol will not be important for being safe against phishing attacks. But in the latest method, the phisher seeks access to text messages received on the victim's phone, which are sent by them in the form of text messages or deceptive messages on social networks. These links contain malware that is installed on your phone and steals your mobile banking account information and other personal information. Of course, this type of attack is considered a separate attack, and the hacker receives the information he needs due to full access to the person's phone. The abusers use the information obtained from the cards to transfer money to customers' accounts, making the victims themselves the accused. But in this plan, we have been able to upgrade the customer authentication process with newer knowledge and also, by removing the dynamic password, effectively cutting off the ultimate goal of phishers to access SMS messages. In this plan, an alternative method for SMS messages has been considered. Phishers have divided their victims into two categories: those who are redirected to fake pages and mistakenly enter their card information or username and password information, but the main operation is carried out by bots written by the hacker on the target sites. The second group are those who click on the link sent to their phone and give full access to the phishers. This group is considered another type of attack, and unlike the first group, the phishers themselves read or perform operations in this method. https: / / ipm.ssaa.ir / Search-Result?page=1&DecNo=139950140003000849&RN=101604 Providing a solution to an existing technical problem along with an accurate, sufficient, and integrated description of the invention First, we will mention payment gateways and their additional features. Of course, this section can also be implemented on other sites. After visiting the payment gateway or the desired page, the person can choose different methods for payment or verification. First method: Using QR code in internet banking and the country's payment gateway and login pages of sites. In this method, in the first step, the portals or sites are required to create a QR code platform and a plugin to read it in the application. People who have a smartphone can choose one of the methods with the QR code specified on the login pages, internet banking or even the payment gateway (which contains the acceptor's information, amount, acceptor's number, security code, etc.). This is a one-time barcode that the user can use without entering the information containing the bank card in the payment gateways or the information required on the login or internet banking pages. The method of use on the login pages of sites or internet banking will be as follows: after the person enters the desired page, the QR option will appear as one of the methods. After the customer enters the bank's application or the application of the site on his phone, by scanning it, he will be allowed to enter for confirmation and access. If the page is fake, a warning will appear stating that it is not valid.But in the online payment gateway, the person can select the desired payment application of that site after visiting the payment gateway. In the next step, the desired application is created in the payment gateway by creating a new extension in its application. After entering the application and selecting the extension, the user will be directed to the next step. In this step, the phone camera is activated and by placing the phone camera in front of the QR code of the payment gateway, all the available and necessary information in the payment gateway will be displayed on the user's phone. After viewing and confirming, the person is directed to the next step, in which step the person selects the card on his default card that he has previously entered information for his daily use and then is directed to the next step. And the code is automatically received and automatically selected by the software and placed in the confirmation box, and the final payment is made. If the payment is confirmed, the transaction information is saved on the phone and this transaction will also be visible from the portal.It is worth noting in this section that the user will not enter his card information after entering the portal. If the user connects to a fake portal, the barcode created will be disposable and specific to one portal, and the hacker cannot upload it to the victim's portal. In practice, this security protocol is difficult and difficult, and hacking it by a hacker will be inoperative. Of course, in the implementation method, instead of automatically receiving the code and automatically selecting it by the software and placing it, a table that is in the form of rows or columns or a matrix or irregular that can be in the form of characters or images and that we have discussed in the map can be displayed. The most important part of this invention can be referred to the elimination of SMS verification codes or dynamic passwords and instead of that, the customer chooses to either call or select the code confirmation via USSD method and if the subscriber is called, the desired number is read to him and the user selects the character in the table that will be placed randomly, which the user clicks on the desired number and confirms the payment or verification. In this table that we have mentioned, it can be with any character and any shape. For example, it can be in the form of a number and at least one 2-digit number or image or letter can be displayed, which will not be able to be modeled by the simulator software. But the second method, which prevents one of the most important attacks, is the same as the one mentioned above regarding phone access by phishers, and is also used for people who do not want to use barcodes or do not have a smartphone. In this method, after entering the payment gateway or internet banking or the login pages of the sites, the user enters the basic card information in the payment gateway or USERNAME in the box embedded in the login pages, which, in case of initial confirmation, will then be directed to the next step. This time, the same table with a specific algorithm that has been mentioned will be created in the payment gateway or the desired pages of the site. The user first selects the method of receiving the code, either through a call or a USSD code as the communication method. If he chooses to call, the call center number will be displayed for him to dial. For example, 5102-021, which he is asked to dial after calling, first select the number or any character that appears in the table (the same table mentioned) opposite and then dial it. If the correct choice is made, he will be directed to the final step.But if the customer selects the USSD code as the code confirmation, then the confirmation of this option will be displayed to him, where he first selects the desired number or character in the table opposite and then dials the USSD code. For example, #3562*730*, after which a message will be displayed to him as a description of the operation, asking him to re-enter the number announced in the message, and if this step is completed and confirmed, he will be directed to the final step to receive the password from it. Alternatively, you can select the character from the table and confirm that number in the bank application or application related to that site. This method does not require a call or USSD code. In this type of implementation method, which is considered the newest method, if customers are redirected to a fake page, the hacker's bots will be locked because the most important thing for the hacker is for customers to manually enter their details, but in this method, it will be in the form of a clicker. The next point is that if the customer's phone is hacked, since the selected code is in the form of a voice and a clicker, the robots will be locked in this area, will fail, and will become inoperable. Explanation of shapes, maps and diagrams General flowchart of the implementation method:. Map No. 1 - General flowchart for the implementation of this implementation method, which will be divided into two categories, and its general process in the existing diagram represents the implementation of this method. Description of the blog diagram of the first page of the map attachment: In the blog diagram attachment number 1 and 2, the subscriber will first enter the desired site, this site can be a banking site, a payment gateway, or a site that has a login and requires authentication. Then he selects the authentication method. If he selects QR, a one-time QR code that changes every 5 to 10 seconds will be displayed. Then the subscriber must install the application of that site (payment gateway, internet banking, etc.) on his phone and then authenticate his barcode by placing his phone against it. If he uses it as a payment, he can perform the payment steps on his phone after scanning, which is to enter the card number or select it, which is by default, and the steps to select the information must be entered to confirm the payment. In the same blog diagram, another method has been specified that does not have a smartphone, can enter the initial information after being present at the payment gateway or internet banking or login pages. This initial information can be the card number if it is in the payment gateway, and if it is in internet banking or login pages of other sites, he must enter his username information. Then, if the initial specifications are confirmed, an irregular table or matrix table or a vertical or horizontal table with any character will be displayed according to the second map. He must also choose the method of confirming the code, either by telephone or USSD code or through the application. If he chooses to call, he can call the desired number and confirm the code, or the call center will call the customer and announce the desired number for selection. The customer can also choose the application method to confirm the code, which the subscriber can then enter the application and enter the number in the embedded field after selecting from the table and confirm it. Similarly, in the last method, he can confirm the desired code by dialing the USSD code. A clear and precise statement of the advantages of the claimed invention over prior inventions.  Preventing e-banking security threats Preventing huge financial losses for bank customers Preventing access to banking information and theft and unauthorized withdrawals from bank accounts Improving the level of account security and reducing security risks in accordance with the development of science and technology, including the requirements of the banking sector. Standardization, security, improvement of service quality and increase of public trust Development of a new electronic payment service platform Reducing the prevention of cybercrime Description of at least one implementation method for implementing the invention In this executive protocol, in order to satisfy the people with financial transactions and providing services by creating a secure platform, this plan can be created in the portal, internet banking, login pages of sites and applications to create favorable conditions for people. In this executive method, sections have been considered for people with smartphones and for people who do not have smartphones, so that the person in question can determine his or her preferred payment method. Another important point in implementing this project is that the visible inputs will not be exposed to the hacker as much as possible. This means that the hacker will not be allowed to access this information by entering numbers using the victim's keyboard and virtual key. Explicit mention of the industrial application of the invention To increase the security of payment gateways or internet banking or login pages of sites to prevent theft of user information, with this invention and its exploitation, God willing, I will be able to implement this new protocol as a pilot in Iran and the countries requesting the implementation of the project under the title of supplementary invention.

Claims

Claim What is claimed: Claim 1: What is claimed in this invention is to prevent phishing and prevent the user from becoming a victim of hacking, this technique has innovative steps that include 3 main techniques that have been designed for the first time in the country and the world, which include several separate sections. The techniques used in this invention are separately capable of evaluation and validation. Claim 2: According to the documents of claim number 1, these three techniques include: Technique number 1) The first step is a security platform for transactions or customer authentication by creating a QR code protocol (Output of acceptor information) in payment gateways or login pages or internet banking. Technique number 2) The second step is creating an image code scanning protocol for identification in financial applications or specific to banks or sites and Technique number 3) The third step, which is the most important and main new step in creating payment security, is embedding and placing a table that is in the form of rows or columns or matrices or irregular. Claim 3: According to the documents of technique number 1 under claim number 2, creating a QR code protocol that includes (acceptor information, payment amount, acceptor number, etc.) is a unique payment method that is embedded in the payment gateway without disclosing the password and bank card information of the individual, for scanning and identification, which will be directed to payment in financial applications. In the payment gateway, by selecting the payment method via QR code, without disclosing the password and bank card information, the transaction will be carried out in the easiest and fastest way and with high security. According to claim number 3, the QR codes created in the payment gateway will only have one-time use capability. Using this technique, in addition to the acceptor's profile information included in this code for execution, one-time codes are also embedded in it, which will change every 20 seconds, so that hackers cannot copy and use it in their fake shell. It can also be used in internet banking or login pages to authenticate customers. Claim 4: According to the documents of technique number 2 under claim number 2, the next technique is to create an image code scanning protocol for identification in applications related to that site. By creating these new services in the application, payment from the internet portal in the application will be possible for users. In this step, by being in the application and selecting these services, they will be directed to the next step. In this step, the phone camera is activated and the user, by placing his phone camera in front of the QR code in the payment portal (according to claim 3), all the information in the payment portal for making a transaction is displayed on the phone, which the user will be directed to the next step after viewing and confirming it. In this step, a page is provided for users to enter the information containing the card. Selecting or entering the card information, which will then be directed to the next step created. If it is used for authentication in internet banking or login pages, all the above-mentioned steps must be taken, but after scanning, the confirmation will be sent to the server at the moment. Claim 5: According to the technique documents No. 3 under claim No. 2, in this step a table is formed. Initially, zero numbers are placed in this table. After selecting two characters, the user selects the new method and replaces the dynamic password either by calling or by using the USSD code, after which the bank will call the person in question. And the desired character must be selected in the random table opposite, the user clicks on the desired number and confirms the payment. If the selection is not made within 30 seconds, the position of the numbers in the table will change, and if it is not selected in the table within a certain period, the usage period will expire and a request for re-confirmation of the code must be made again. In case of payment and after payment, the transaction information is stored on the phone and this transaction can also be visible from the portal.An important point in this technique is that if the victim is connected to a fake portal, this table will not be displayed for him to view and select, while the main table will be displayed for the hacker to select, given that the information input will not be made by the victim. In this protocol, which has strict and difficult security, hacking it by the hacker will be inoperative. If this project is used in online banking or login pages, the subscriber must first enter his username, if approved, the mentioned table will be displayed to him and the above will happen, and the above actions must be performed by the subscriber, who, if approved, enters the password in the final stage. Claim 6: Based on claim 5, the mentioned table and the method of the technique are also embedded in the payment gateway.In this innovative table, people are considered to use the second payment method, i.e. direct payment from the portal, as well as people who do not have a smartphone. After entering the card information in the portal and being directed to the next step (the page created in claim 5), they will be shown the options for selection and final payment.