Method and system for trusted qr service
Patent Information
- Application Number
- KR1020250099319
- Authority / Receiving Office
- KR · KR
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-28
- Filing Date
- 2025-07-22
- Publication Date
- 2026-09-04
Smart Images

Figure PAT00001_ABST
Abstract
Description
Technology Field
[0001] The present invention relates to a secure QR service method and system capable of detecting and blocking Qshing, which is a form of hacking that occurs during the process of a terminal accessing a website of a link obtained by scanning a QR (Quick Response) code. Background Technology
[0002] Qshing is a portmanteau of QR (Quick Response) code and phishing, referring to hacking using QR codes. Qshing is a method in which hackers induce users to scan malicious QR codes they have created, thereby causing damages such as stealing personal or financial information, remotely controlling mobile devices, or inducing micropayments by causing users to install malicious apps or access illegal websites.
[0003] Currently, there is no fundamental technology available to prevent QR phishing other than avoiding scanning QR codes from unknown sources and checking the link (Uniform Resource Locator, URL) connected upon scanning to avoid accessing it if it appears suspicious. The problem to be solved
[0004] The present disclosure relates to a method and apparatus for providing a secure QR service that detects queuing, which is hacking occurring during the process of accessing a website corresponding to link information obtained by scanning a QR code, and abnormal situations occurring during the scanning process of a QR code, and allows access only to trusted connections.
[0005] The present disclosure relates to a method and apparatus for providing a safe QR service that determines a queshing detection type of link information obtained by a terminal scanning a QR code through a dedicated app among a plurality of queshing types set based on the type and severity of queshing, and generates and provides differentiated queshing detection information according to the determined queshing detection type to the terminal. means of solving the problem
[0006] According to one feature, a method of operation for detecting queshing in a terminal comprises the steps of: obtaining link information contained in a QR code through a QR (Quick Response) code scan; transmitting a queshing verification request containing the link information to a queshing detection server; receiving a queshing verification response to the queshing verification request from the queshing detection server; and displaying the queshing verification response, wherein the queshing verification response includes queshing detection information specified for the queshing detection type of the link information among a plurality of queshing detection types set based on the type of queshing and the severity of queshing.
[0007] The above cushing detection information includes a warning message according to each cushing detection type and a website access request corresponding to the link information, and the website access request may be optionally included only for some cushing detection types.
[0008] The queshing detection type of the above link information is obtained by the queshing detection server by searching a queshing detection type database, and the queshing detection type database can store at least one link information mapped to each queshing detection type for each of the plurality of queshing detection types.
[0009] The above queshing detection type database may include at least one of link information identified as a safe link type verified as safe, link information identified as a smishing type, link information identified as a spam type, and link information identified as a suspicious type.
[0010] Prior to the step of receiving the above queshing verification response, if an abnormal situation of the QR code scan or the queshing verification request is detected during the process of performing the above QR code scan, the method may further include a step of displaying abnormal situation detection information.
[0011] The step of displaying the above abnormal situation detection information may display abnormal situation detection information requesting a QR code rescan by determining it as a rescan type when an abnormal operation of the QR code scan, including at least one of an optical issue or QR code non-recognition, is detected.
[0012] The step of displaying the above abnormal situation detection information may display abnormal situation detection information including a notification of inability to connect by determining it as an invalid link type if the link information does not satisfy a pre-set valid link format.
[0013] The step of displaying the above abnormal situation detection information may display abnormal situation detection information including retry request information by determining it as a network error type when the attempt to transmit the above queshing verification request fails or when an abnormal response is received from the above queshing detection server.
[0014] The step of displaying the abnormal situation detection information above involves transmitting the queshing verification request to the queshing detection server and waiting for a response; if a response is not received for a set period of time, it is determined to be a timeout type, and abnormal situation detection information including retry request information can be displayed.
[0015] Prior to the above acquisition step, the method may further include a step of running a dedicated app for queshing detection that interacts with the queshing detection server connected via a network.
[0016] The above-mentioned app dedicated to queshing detection performs the function for queshing detection and may include at least one of an app installed by default on the terminal or an app related to a carrier service.
[0017] According to another feature, the queshing detection system includes a queshing detection type database that stores link information mapped to each queshing detection type for a plurality of queshing detection types set based on queshing type and queshing severity, and a queshing detection server that receives a queshing verification request from a terminal, searches the queshing detection type database to identify a queshing detection type mapped to the link information included in the queshing verification request, generates queshing detection information assigned to the queshing detection type, and transmits it to the terminal.
[0018] The above queshing detection type database includes at least one of link information of a safe type verified as safe, link information identified as a smishing type, link information identified as a spam type, and link information identified as a suspected queshing type. The queshing detection server can generate and transmit queshing detection information including information that guides access to a website corresponding to the link information according to the queshing detection type and user selection when the link information included in the queshing verification request is identified as a verified safe type or a suspected queshing type, and when the link information included in the queshing verification request is identified as a smishing type or a spam type, it can generate and transmit queshing detection information including a queshing detection type and a warning message.
[0019] The above queshing detection server can acquire link information by queshing detection type in real time by linking with the National Police Agency or an external agency server that provides cyber threat-related information, and update the above queshing detection type database based on the acquired information.
[0020] The above queshing detection server is implemented in a server linkage structure in which a plurality of servers are linked, and the plurality of servers may include: a dedicated app server that is connected via a network to a dedicated queshing detection app installed on the terminal, receives a queshing detection request from the dedicated queshing detection app, and transmits the queshing detection information to the dedicated queshing detection app; a queshing determination server that performs the creation and update of the queshing detection type database and determines the queshing detection type; an intermediary server that executes a predefined queshing detection API (Application Programming Interface) to transmit the queshing detection request to the queshing determination server and obtains queshing determination information from the queshing determination server and transmits it to the dedicated app server; and an API link gateway located between the dedicated app server and the intermediary server, which determines whether the queshing detection request received from the dedicated app server is valid, and if valid, transmits the queshing detection request to the intermediary server and transmits the queshing determination information to the dedicated app server. Effects of the invention
[0021] According to the present disclosure, when a user scans a QR code through a dedicated app, the queshing detection type is determined to determine whether the link information embedded in the QR code is a safe link, a spam link, or a smishing link, and by providing the user with differentiated queshing detection information based on the determined queshing detection type, access to a malicious website can be blocked in advance, thereby effectively preventing queshing.
[0022] In addition, various abnormal situations occurring during the QR code scanning process are identified by type and configured to provide an abnormal situation detection screen. By having the server receive feedback on the types of abnormal situations from the terminal's dedicated app and manage them, users can clearly understand and respond to abnormal situations, and the server-side operator can improve the app system through the feedback. Brief explanation of the drawing
[0023] FIG. 1 is a configuration diagram of a secure QR service system according to the present disclosure. Figure 2 shows an example of the distributed structure of the queshing detection server of Figure 1. FIG. 3 is a flowchart illustrating the operation of a secure QR service of a terminal according to the present disclosure. FIG. 4 is a flowchart illustrating the safe QR service operation of a querying detection server according to the present disclosure. FIG. 5 is an example of a secure QR service procedure according to the present disclosure. FIG. 6 is an example of an abnormal situation detection screen of a safety QR service according to the present disclosure. FIG. 7 is an example of a querying detection screen of a secure QR service according to the present disclosure. Specific details for implementing the invention
[0024] Embodiments of the present disclosure are described below with reference to the attached drawings so that those skilled in the art can easily implement them. However, the present disclosure may be embodied in various different forms and is not limited to the embodiments described herein. Furthermore, in order to clearly explain the present disclosure in the drawings, parts unrelated to the explanation have been omitted, and similar parts throughout the specification are denoted by similar reference numerals.
[0025] Throughout the specification, when a part is described as "including" a certain component, this means that, unless specifically stated otherwise, it does not exclude other components but may include additional components.
[0026] Additionally, terms such as “…part,” “…unit,” and “…module” described in the specification refer to a unit that processes at least one function or operation, and this may be implemented in hardware, software, or a combination of hardware and software.
[0027] The devices described in the present invention are composed of hardware including at least one processor, a memory device, a communication device, etc., and a program that is executed in combination with the hardware is stored in a designated location. The hardware has a configuration and performance capable of executing the method of the present invention. The program includes instructions that implement the method of operation of the present invention described with reference to the drawings, and executes the present invention in combination with hardware such as a processor and a memory device.
[0028] In this specification, "transmission or provision" may include not only direct transmission or provision but also indirect transmission or provision through another device or by using an alternative route.
[0029] Expressions described in the singular in this specification may be interpreted as singular or plural unless explicit expressions such as "one" or "single" are used.
[0030] In this specification, the same reference numeral refers to the same component regardless of the drawing, and "and / or" includes each of the mentioned components and all combinations of one or more.
[0031] In this specification, terms including ordinal numbers, such as first, second, etc., may be used to describe various components, but said components are not limited by said terms. Such terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the present disclosure, the first component may be named the second component, and similarly, the second component may be named the first component.
[0032] In the flowchart described with reference to the drawings in this specification, the order of operations may be changed, several operations may be merged or some operations may be divided, and certain operations may not be performed.
[0034] FIG. 1 is a configuration diagram of a secure QR (Quick Response) service system according to the present disclosure.
[0035] Referring to FIG. 1, the safety QR service system may include a terminal (100), a Qshing detection server (200), and a Qshing type database (300).
[0036] The terminal (100) is connected to and operates with the queshing detection server (200) through a network (400) including a wired and wireless network.
[0037] "Qshing" is a portmanteau of "QR" (Quick Response) and "phishing," referring to a hacking technique that utilizes QR codes. Qshing occurs when a user scans a QR code and the website accessed via a link within the code turns out to be a malicious website, or when the QR code itself connects the device to a malicious server, thereby executing hacking actions.
[0038] The link may contain a Uniform Resource Locator (URL) designed to induce access to a malicious website or to induce a connection to a malicious server.
[0039] The terminal (100) includes a dedicated app (101) for querying detection. The user can perform a QR code scan by running the dedicated app (101) and activating the camera function of the dedicated app (101).
[0040] The terminal (100) is an electronic device comprising components capable of scanning a QR code and connecting to a network, and may include, for example, a smartphone, a tablet PC, a laptop, a computer, an IoT (Internet of Things) device, etc.
[0041] The dedicated app (101) operates by connecting to the queshing detection server (200) via the network (400). The dedicated app (101) may be a newly developed app for queshing detection. The dedicated app (101) may be an app that is installed by default on the terminal (100), or it may be an app related to a carrier service with a queshing detection function added.
[0042] While the terminal (100) is running a dedicated app (101), it performs a QR code scan and transmits a queshing verification request containing link information obtained to a queshing detection server (200), and receives and outputs queshing detection information corresponding to a queshing detection type mapped to the link information among a plurality of queshing detection types from the queshing detection server (200).
[0043] Qshing detection information includes warning messages and link information for each type of qshing detection, and requests to access websites corresponding to those links. Requests to access websites may be optionally included for some types of qshing detection.
[0044] When the terminal (100) detects an abnormal situation during the QR code scanning or queshing verification request process, it can generate and output abnormal situation detection information containing information according to the type of abnormal situation detected.
[0045] Types of abnormal situations can be defined as shown in Table 1.
[0046] category explanation example Time out If response and call are delayed When calling the queshing detection server from the dedicated app's native area, if there is no response for a specific time (10 seconds on Android, 30 seconds on iOS) Network error If network connection is unavailable 1. When network connection is not possible using the OS (Operating System) network module (Android: ConnectManager, iOS: AFNetwork) 2. When the response code value is abnormal after connecting to the server Reshoot When QR code recognition is impossible due to optical issues such as light reflection or lack of clarity If QR code recognition is not possible Invalid link In case of an inaccessible link If the link information set within the QR code does not start with the 'http' or 'https' string
[0047] The queshing detection server (200) receives a queshing verification request from the terminal (100), searches the queshing type database (300) to identify a queshing detection type that maps to the link information included in the queshing verification request, generates queshing detection information corresponding to the queshing detection type, and transmits it to the terminal (100).
[0048] The queshing detection server (200) can generate queshing detection information based on the queshing type database (300), and transmit it to the terminal (100), if the link information included in the queshing verification request is determined to be a link type verified as safe or suspected of queshing, the queshing detection information including information guiding access to a website corresponding to the link information according to the queshing detection type and user selection.
[0049] If the link information included in the queshing verification request is determined to be smishing or spam, the queshing detection server (200) can generate queshing detection information including a queshing detection type and a warning message and transmit it to the terminal (100).
[0050] The queshing type database (300) stores link information mapped to each queshing detection type for each of the multiple queshing detection types set based on the queshing type and queshing severity.
[0051] The queshing detection server (200) can be linked with the National Police Agency or an external agency server that provides cyber threat-related information (e.g., KISA, SANDSLab, Kaspersky, etc.) to obtain link information by queshing detection type in real time and update the queshing type database (300) based on the obtained information.
[0052] Multiple queshing types can be defined as shown in Table 2.
[0053] category explanation smishing Links where personal information theft and financial crimes have occurred or are expected to occur (e.g., smishing, malware, malicious code, C&C, etc.) Spam Links containing harmful, illegal, or content that may cause discomfort to users (e.g., adult, gambling, drug sites, etc.) Doubt Links that have not undergone sufficient verification steps and are not classified safe Links deemed to have a significantly low risk of financial crime (e.g., portal sites, official websites, news / media, business / economics, etc.)
[0054] Figure 2 shows an example of the distributed structure of the queshing detection server of Figure 1.
[0055] Referring to FIG. 2, the queshing detection server (200) can be implemented as a server linkage structure in which multiple servers are linked, for example, a server linkage structure including a dedicated app server (210), an API (Application Programming Interface) link gateway (220), an intermediary server (230), and a queshing determination server (240).
[0056] The dedicated app server (210) operates in conjunction with the dedicated app (101). That is, when the QR code is scanned in the dedicated app (101) for queshing detection, the dedicated app (101) connects to the dedicated app server (210) and sends a queshing detection request containing link information obtained through the QR code scan to the dedicated app server (210).
[0057] The dedicated app server (210) transmits the queshing detection request received from the dedicated app (101) to the API link gateway (220).
[0058] The API link gateway (220) is a physical server for mediation that provides gateway functions for linking with the dedicated app server (210) and external systems.
[0059] The API link gateway (220) determines whether a queshing detection request received from the dedicated app server (210) is valid, and if it is determined to be valid, it can transmit the queshing detection request to the intermediary server (230). At this time, the queshing detection request may include an authentication key or identifier proving that the queshing detection type is valid, and the authentication key or identifier may be included in the dedicated app (101).
[0060] The API link gateway (220) transmits a valid queshing detection request to the intermediary server (230), receives queshing detection information from the intermediary server (230), and transmits it to the dedicated app server (210). Then, the dedicated app server (210) transmits the queshing detection information to the dedicated app (101) of the terminal (100).
[0061] The intermediary server (230) executes a predefined queshing detection API to transmit a queshing detection request transmitted from the API link gateway (220) to the queshing determination server (240), obtains queshing determination information from the queshing determination server (240), and transmits it to the API link gateway (220).
[0062] The queshing determination server (240) performs the creation and update of the queshing type database (300) by linking with an external agency server.
[0063] The queshing detection server (240) performs the operation of the queshing detection server (200) described in FIG. 1, that is, receiving a queshing detection request from a terminal (100), determining the queshing detection type of the link information included in the queshing detection request by referring to the queshing type database (300), and generating differentiated queshing detection information according to the determined queshing detection type and transmitting it to the terminal (100).
[0065] The operation of the secure QR service is described below in conjunction with the configuration described in Figures 1 and 2.
[0066] FIG. 3 is a flowchart illustrating the operation of a secure QR service of a terminal according to the present disclosure.
[0067] Referring to FIG. 3, the terminal (100) performs a QR code scan (S101) while connected to the queshing detection server (200) by running a dedicated app (101).
[0068] The terminal (100) determines whether an abnormal operation of the QR code scan is detected (S102).
[0069] When the terminal (100) determines that an abnormal operation is detected in S102, it determines that the abnormal situation type is a re-shooting type among the abnormal situation types, and outputs abnormal situation detection information including a request to rescan a QR code and specifying the re-shooting type (S103).
[0070] If the terminal (100) determines that there is no abnormal operation detection in S102, it determines whether the link information obtained through QR code scanning satisfies a pre-set valid link format (S104).
[0071] If the terminal (100) determines that the valid link type is not satisfied in S104, it determines that the link type is invalid among the abnormal situation types and outputs abnormal situation detection information including a notification of inability to connect, which specifies the type (S105).
[0072] If the terminal (100) determines that it satisfies a valid link format in S104, it sends a queshing detection request containing link information obtained through QR code scanning to the queshing detection server (200) (S106).
[0073] The terminal (100) determines whether it fails to transmit a queshing detection request or receives an abnormal response from the queshing detection server (200) (S107).
[0074] If the terminal (100) determines that it failed to transmit a queshing detection request in S107 or received an abnormal response from the queshing detection server (200), it determines that the abnormal situation type is a network error type among the abnormal situation types and outputs abnormal situation detection information that specifies the network error type and guides the attempt to retransmit the queshing detection request (S108).
[0075] If the terminal (100) succeeds in transmitting a queshing detection request in S107, it determines whether a response is received from the queshing detection server for a set period of time (S109).
[0076] If the terminal (100) determines that no response is received for a set period of time in S109, it determines that the abnormal situation type is a timeout type among the abnormal situation types and outputs abnormal situation detection information that specifies the timeout error type and guides the attempt to retransmit the queshing detection request (S110).
[0077] When the terminal (100) determines that a response is received for a set time in S109, it receives and outputs queshing detection information corresponding to a queshing type mapped to the link information of the queshing detection request from the queshing detection server (200) (S111).
[0079] FIG. 4 is a flowchart illustrating the safe QR service operation of a querying detection server according to the present disclosure.
[0080] Referring to FIG. 4, the queshing detection server (200) creates a queshing type database (300) that stores link information mapped to each queshing type for a plurality of queshing types set based on the queshing type and queshing severity (S201).
[0081] The queshing detection server (200) links with the National Police Agency or an external agency server that provides cyber threat-related information to obtain link information by queshing type in real time and updates the queshing type database (300) based on the obtained information (S202).
[0082] The queshing detection server (200) receives a queshing verification request from the terminal (100) (S203).
[0083] The queshing detection server (200) searches the queshing type database (300) to identify the queshing type that maps to the link information included in the queshing verification request (S204).
[0084] When the queshing detection server (200) determines that the queshing type identified in S204 is a safe link type or a suspected queshing type (S205), it generates queshing detection information that includes information specifying the safe link type or suspected queshing type and guiding the user to access a website corresponding to the link information according to the user's selection, and transmits this information to the terminal (100) (S206).
[0085] If the qshing detection server (200) determines in S204 that it is a smishing type or a spam type, it generates qshing detection information including a warning message and specifies the smishing type or spam type, and transmits it to the terminal (100) (S207).
[0087] FIG. 5 is an example of a safe QR service procedure according to the present disclosure, FIG. 6 is an example of an abnormal situation detection screen of a safe QR service according to the present disclosure, and FIG. 7 is an example of a querying detection screen of a safe QR service according to the present disclosure.
[0088] Here, the queshing detection screen displays queshing detection information mapped to a queshing detection type received from the queshing detection server (200). The abnormal situation detection screen displays abnormal situation detection information corresponding to an abnormal situation detection type.
[0089] Referring to FIG. 5, when a QR code scan request occurs while a dedicated app (101) is running on the terminal (100), a QR code scan guide screen (P1) is displayed. Subsequently, when the user scans the QR code, a screen (P2) indicating that the QR code scan is in progress is displayed. Next, the terminal (100) pops up a screen showing an abnormal situation detected during the QR code scanning process or a screen showing a queshing detection received from the queshing detection server (200) (P3).
[0090] Referring to Fig. 6, an example of an abnormal situation detection screen detected during the QR code scanning process is shown.
[0091] Referring to Fig. 6(a), the abnormal situation detection screen, which is a retake type, may display abnormal situation detection information indicating that the QR code cannot be recognized due to optical issues such as light reflection or lack of clarity, and that retake is required because the QR code cannot be recognized.
[0092] Referring to Fig. 6(b), the abnormal situation detection screen, which is an 'invalid link type,' can display abnormal situation detection information indicating that the format of the QR code link is invalid and providing a notification that the QR code cannot be accessed, along with instructions to retake the photo.
[0093] Referring to Fig. 6 (c), an abnormal situation detection screen that is a 'network error type' or 'timeout type' can display abnormal situation detection information including a warning message to reconfirm data settings because it is an abnormal situation.
[0094] Referring to FIG. 7, an example of a queshing detection screen received from a queshing detection server (200) is shown.
[0095] Referring to Fig. 7(a), the queshing detection screen of the safe link type can display queshing detection information that indicates that the link information of the QR code is of a safe type and guides the attempt to access the link of the QR code.
[0096] Referring to Fig. 7(b), the suspicious type of queshing detection screen may display queshing detection information that indicates that the link information of the QR code is not judged to be safe but is not a type corresponding to spam or smishing, and guides the user to selectively attempt to access the link of the QR code.
[0097] Referring to Fig. 7 (c), the phishing detection screen of the phishing type can display phishing detection information that specifies that the link information of the QR code is of the phishing type and blocks access to the link of the QR code.
[0098] Referring to Fig. 7(d), the spam-type queshing detection information can display the link information of the QR code specifying the spam type and blocking the link access of the QR code.
[0100] The embodiments of the present invention described above are not implemented only through devices and methods, but may also be implemented through a program that realizes a function corresponding to the configuration of the embodiments of the present invention or a recording medium on which such program is recorded.
[0101] Although embodiments of the present invention have been described in detail above, the scope of the present invention is not limited thereto, and various modifications and improvements by those skilled in the art using the basic concept of the present invention as defined in the following claims also fall within the scope of the present invention.
Claims
Claim 1 A method for operating to detect queshing in a terminal, comprising the steps of: obtaining link information contained in a QR code through scanning a QR (Quick Response) code; transmitting a queshing verification request containing the link information to a queshing detection server; receiving a queshing verification response to the queshing verification request from the queshing detection server; and displaying the queshing verification response, wherein the queshing verification response includes queshing detection information specified for a queshing detection type of the link information among a plurality of queshing detection types set based on the type of queshing and the severity of queshing. Claim 2 A method according to claim 1, wherein the cushing detection information includes a warning message according to each cushing detection type and a website access request corresponding to the link information, and the website access request is optionally included only for some cushing detection types. Claim 3 In paragraph 2, the queshing detection type of the link information is obtained by searching a queshing detection type database by the queshing detection server, and the queshing detection type database stores at least one link information mapped to each queshing detection type for each of the plurality of queshing detection types. Claim 4 In paragraph 3, the above-mentioned qshing detection type database comprises at least one of link information identified as a safe link type verified as safe, link information identified as a smishing type, link information identified as a spam type, and link information identified as a suspicious type. Claim 5 A method according to claim 1, further comprising the step of displaying abnormal situation detection information if an abnormal situation of the QR code scan or the queshing verification request is detected during the process of performing the QR code scan, prior to the step of receiving the queshing verification response. Claim 6 In claim 5, the step of displaying the abnormal situation detection information is a method of displaying abnormal situation detection information that requests a QR code rescan by determining it as a rescan type when an abnormal operation of the QR code scan, including at least one of an optical issue or QR code non-recognition, is detected. Claim 7 In paragraph 5, the step of displaying the abnormal situation detection information is a method in which, if the link information does not satisfy a pre-set valid link format, it is determined to be an invalid link type and the abnormal situation detection information including a notification of inability to connect is displayed. Claim 8 In claim 5, the step of displaying the abnormal situation detection information is a method of determining a network error type and displaying abnormal situation detection information including retry request information when the attempt to transmit the queshing verification request fails or an abnormal response is received from the queshing detection server. Claim 9 In claim 5, the step of displaying the abnormal situation detection information comprises: transmitting the queshing verification request to the queshing detection server and waiting for a response; and if a response is not received for a set period of time, determining it as a timeout type and displaying the abnormal situation detection information including retry request information. Claim 10 A method according to claim 5, further comprising the step of executing a dedicated app for queshing detection that interacts with the queshing detection server connected via a network prior to the above-mentioned acquisition step. Claim 11 In claim 10, the above-mentioned app dedicated to queshing detection performs the function for queshing detection and includes at least one of an app installed by default on the terminal or an app related to a carrier service. Claim 12 A queshing detection system comprising: a queshing detection type database storing link information mapped to each queshing detection type for a plurality of queshing detection types set based on queshing type and queshing severity; and a queshing detection server that receives a queshing verification request from a terminal, searches the queshing detection type database to identify a queshing detection type mapped to the link information included in the queshing verification request, generates queshing detection information specified for the queshing detection type, and transmits it to the terminal. Claim 13 In claim 12, the above-mentioned queshing detection type database includes at least one of link information of a safe type verified as safe, link information identified as a smishing type, link information identified as a spam type, and link information identified as a suspected queshing type; and the above-mentioned queshing detection server generates and transmits queshing detection information including information guiding access to a website corresponding to the link information according to the queshing detection type and user selection when the link information included in the queshing verification request is identified as a verified safe type or a suspected queshing type, and generates and transmits queshing detection information including the queshing detection type and a warning message when the link information included in the queshing verification request is identified as a smishing type or a spam type. Claim 14 In Paragraph 13, the above-mentioned queshing detection server is a queshing detection system that links with the National Police Agency or an external agency server providing cyber threat-related information to acquire link information by queshing detection type in real time and updates the above-mentioned queshing detection type database based on the acquired information. Claim 15 In claim 12, the queshing detection server is implemented in a server linkage structure in which a plurality of servers are linked, and the plurality of servers include: a dedicated app server that is connected via a network to a dedicated queshing detection app installed on the terminal, receives a queshing detection request from the dedicated queshing detection app, and transmits the queshing detection information to the dedicated queshing detection app; a queshing determination server that performs the creation and update of the queshing detection type database and determines the queshing detection type; an intermediary server that executes a predefined queshing detection API (Application Programming Interface) to transmit the queshing detection request to the queshing determination server and obtains queshing determination information from the queshing determination server and transmits it to the dedicated app server; and an API link gateway located between the dedicated app server and the intermediary server, which determines whether the queshing detection request received from the dedicated app server is valid, and if valid, transmits the queshing detection request to the intermediary server and transmits the queshing determination information to the dedicated app server.