Security protection of association between user equipment and user
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- VISA INTERNATIONAL SERVICE ASSOCIATION
- Filing Date
- 2021-01-04
- Publication Date
- 2026-05-22
AI Technical Summary
Existing technologies are insufficient to prevent SIM swapping attacks on user devices, leading to the leakage of user information and fraudulent losses, especially in IoT devices where current systems lack effective verification mechanisms.
By introducing three communication paths into the computing system—the communication path between the service provider and the computing system, the communication path between the user equipment and the computing system, and the communication path between the user and the computing system—and combining an authentication module and a storage device, the system verifies whether the user equipment's identifier is activated by a legitimate user, thus preventing SIM swapping attacks.
It effectively detects and prevents SIM swapping attacks, protects user information security, and reduces fraud risks, especially in IoT devices, improving the security of the connection between user devices and users.
Smart Images

Figure CN113065117B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims priority to U.S. Provisional Application No. 62 / 956,432, filed January 2, 2020, the entire disclosure of which is incorporated herein by reference. Technical Field
[0003] This application relates to a security protection. More specifically, this application relates to a security protection for the association between user equipment and the user. Background Technology
[0004] A network (e.g., a computer network, communication network, or data network) comprises a collection of components (e.g., terminal nodes or computing devices, computing systems, switches, routers) connected by links to enable communication between terminals, computing devices, or systems. Networks are widely used worldwide to connect individuals and organizations, enabling e-commerce. Users can communicate with the computing systems of other user devices or organizations using computing devices (e.g., user equipment) through communication networks operated by various service providers. Service providers can identify users by user identifiers, user equipment by user equipment identifiers, and can also associate user identifiers with user equipment identifiers. Communication security refers to rules that prevent unauthorized interception of access to computer systems or communication networks while still delivering content to the intended recipient or user. With the widespread use of the Internet, e-commerce, and other applications, network security or communication security faces increasing challenges. For example, an attacker might attempt to use a user equipment to perform an Account To-Do (ATO) attack, potentially causing millions in fraud and losses for the user. Summary of the Invention
[0005] The embodiments disclosed herein include a computer-implemented method for communicating to perform security protection of the association between a user equipment and a user. The method includes receiving, by a processor of a computing system, a notification from a service provider that a user equipment identifier has been activated in a user equipment to be associated with the user identifier, replacing the existing identifier of the user equipment associated with the user identifier. This notification can be received via a first communication path between the service provider and the computing system. The user equipment identifier is a hardware-based network identifier of the user equipment, and the user identifier is the service provider's identifier for the user. The method further includes storing the user's user identifier in a storage device coupled to the processor to indicate that the existing identifier of the user equipment associated with the user identifier has been changed. Furthermore, the method includes receiving, by the processor, a request from the user equipment for information associated with the user identifier to be sent to the user equipment associated with the user equipment identifier. The request for the information associated with the user identifier is received via a second communication path between the user equipment and the computing system. The method further includes searching the storage device for the user identifier, and, when the user identifier is found in the storage device, verifying that the user equipment identifier has been activated by the user through additional authentication of the user. The user equipment identifier being activated by the user can be verified via a third communication path between the user and the computing system.
[0006] The embodiments disclosed herein include a computing system comprising one or more processors, a storage device coupled to the one or more processors, application software to be operated by the one or more processors, and an authentication module to be operated by the one or more processors. The one or more processors are configured to receive a notification from a service provider that a user device identifier has been activated in a user device to be associated with the user identifier, replacing the existing identifier of the user device associated with the user identifier. The notification is received via a first communication path between the service provider and the computing system. The user device identifier is a hardware-based network identifier of the user device, and the user identifier is the service provider's identifier for the user. The storage device is configured to store the user's user identifier to indicate that the existing identifier of the user device associated with the user identifier has been changed. The application software is used to receive from the user device a request for information associated with the user identifier to be sent to the user device associated with the user device identifier. The request is received via a second communication path between the user device and the computing system, and the information associated with the user identifier is used by the user to operate the application software. The authentication module is used to search the storage device for the user identifier, and when the user identifier is found in the storage device, to send to the user a request for authentication information different from the user's user identifier. The request for the authentication information is sent via a third communication path between the user and the computing system. In addition, the authentication module is used to receive response messages from users requesting authentication information, and to authenticate users based on the response messages and rule sets.
[0007] The embodiments disclosed herein include an executable software product stored on a non-transitory computer-readable medium containing program instructions that cause a processor of a computing system to perform various operations. For example, in response to the processor executing the instructions, the computing system receives a notification that a user equipment identifier has been activated in a user equipment to be associated with the user identifier, replacing the existing identifier of the user equipment associated with the user identifier. The notification is received from the service provider via a first communication path between the service provider and the computing system. This notification occurs when a SIM swap occurs, preferably before a login attempt. The user equipment identifier is a hardware-based network identifier for the user equipment, and the user identifier is the identifier of the user by the service provider. In response to the processor executing the instructions, the computing system also stores the user's user identifier in a storage device coupled to the processor to indicate that the existing identifier of the user equipment associated with the user identifier has been changed. Furthermore, in response to the processor executing the instructions, the computing system receives, via the processor, a request for information associated with the user identifier to be sent to the user equipment associated with the user equipment identifier. The request for the information is received from the user equipment via a second communication path between the user equipment and the computing system. Furthermore, in response to the processor executing this instruction, the computing system will search the storage device for the user identifier, and when the user identifier is found in the storage device, will send a request to the user for authentication information that is different from the user's user identifier. The request for authentication information is sent via a third communication path between the user and the computing system. Additionally, in response to the processor executing this instruction, the computing system will receive a response message from the user regarding the authentication information request, and will authenticate the user based on the response message and a set of rules. Attached Figure Description
[0008] The embodiments will be readily understood from the following detailed description taken in conjunction with the accompanying drawings. For ease of description, similar reference numerals refer to similar structural elements. The embodiments are shown in the figures by way of example rather than limitation.
[0009] Figure 1 A computing system for verifying that a user equipment identifier has been activated by the user to replace the existing identifier of the user equipment associated with the user identifier is shown, according to various embodiments.
[0010] Figure 2 An example process is shown, according to various implementations, for verifying that an identifier of a user device has been activated by the user to replace an existing identifier of the user device associated with the user identifier.
[0011] Figure 3 Example devices, according to various embodiments, suitable for practicing various aspects of this disclosure are shown. Detailed Implementation
[0012] The following description is provided to enable those skilled in the art to make and use the embodiments, and is offered in the context of the patent application and its claims. Various modifications to the exemplary embodiments and the general principles and features described herein will be readily apparent. Exemplary embodiments are described primarily based on the specific methods and systems provided in particular implementations. However, methods and systems will function effectively in other implementations. Phrases such as “exemplary embodiment,” “one embodiment,” and “another embodiment” may refer to the same or different embodiments. Embodiments will be described with respect to systems and / or devices having certain components. However, systems and / or devices may include more or fewer components than those shown, and the arrangement and type of components may be changed without departing from the scope of this disclosure. Various embodiments will also be described in the context of specific methods having certain steps. However, other methods and systems with different steps and / or additional steps and different sequences of steps will function effectively, wherein these steps do not contradict the proposed embodiments. Therefore, this disclosure is not intended to limit itself to the embodiments shown, but rather to accord the broadest scope consistent with the principles and features described herein.
[0013] Users can use computing devices (e.g., user equipment) to communicate with the computing systems of other user equipment or institutions via communication networks operated by various service providers. Service providers or network operators can identify users by user identifiers (such as phone numbers or email addresses) and user equipment by hardware-based network identifiers (such as subscriber identification module (SIM) cards or user equipment media access control (MAC) addresses). Furthermore, user identifiers can be associated with identifiers of user equipment. Such associations between user identifiers and user equipment identifiers can be used in various applications. For example, a one-time password (OTP) used by a user to operate an application can be sent from the system running the application to the user equipment (e.g., a telephone) associated with the user's phone number. OTPs have become a common way to authenticate or recover user accounts, meaning that a phone number or user identifier represents the user. Attackers have attempted to perform account theft (ATO) by stealing a user's phone number. This type of attack is known as SIM swapping. SIM swapping (also known as SIM hijacking) is a type of ATO attack in which malicious threat actors use various techniques (often social engineering) to transfer the victim's phone number to their own SIM card. SIM swapping attacks have resulted in millions of frauds and losses. Current technology struggles to prevent such SIM swapping. Telecommunications network companies may not adequately verify SIM cards before swapping them, and victims and targeted financial institutions lack control over the flow of SIM swapping. With the increasing number of Internet of Things (IoT) devices (e.g., cars, watches, etc.) that come with SIM cards and are integrated to independently execute financial transactions, preventing SIM swapping attacks is crucial for both current and future systems.
[0014] In SIM swapping, an attacker alters the association between a user equipment (UE) and a user, causing security information related to that user to be sent to a UE that may not belong to that user. The implementation described herein relates to implementing security protections for the association between a UE and a user. The implementation verifies that the UE's identifier has been activated by the user to replace the existing identifier of the UE associated with the user's identifier. Specifically, the implementation can protect the user from SIM swapping attacks by using a telephone network provider (such as AT&T, Verizon, etc.) to track the user's SIM card details and phone number or IoT device as a service. When the SIM card is swapped and the new SIM is detected by the service provider, a flag is triggered that prevents authentication to the UE via telephone OTP or IoT OTP unless verification from other devices confirms that the telephone (IoT) / SIM change originates from a legitimate user.
[0015] Figure 1A computing system 104, according to various embodiments, is shown for verifying that an identifier 108 of user equipment 101 has been activated by user 102 to replace the existing identifier of user equipment 101 associated with user identifier 111. In some embodiments, user identifier 111 is used by service provider 103 to identify user 102. For example, a telephone company uses user identifier 111, which is a telephone number, to identify user 102.
[0016] In this implementation, user equipment 101 is used to communicate with service provider 103 and computing system 104. User equipment 101 includes an identifier 108 and application software 106 running on user equipment 101. Computing system 104 includes one or more processors (e.g., processor 105), a storage device 110 coupled to the one or more processors, application software 107 to be operated by the one or more processors, and an authentication module 109 to be operated by the one or more processors. Storage device 110 may store user identifier 111 and rule set 113. Many other components, not shown, may be present within user equipment 101 or computing system 104. For example, multiple processors may be present within computing system 104.
[0017] In this implementation, the identifier 108 of user equipment 101 may be a hardware-based network identifier for the user equipment, and may include a SIM card identifier or the MAC address of user equipment 101. For example, identifier 108 may include various information, such as the International Mobile Subscriber Identity (IMSI) and authentication key for verifying the IMSI, Integrated Circuit Card Identifier (ICCID), SIM card issuer, user account identifier, or parity number. User equipment 101 may be a wireless phone, cellular phone, satellite phone, VoIP phone, smartphone, laptop, tablet, personal computer, point-of-sale (POS) terminal, transaction terminal, IoT device, or handheld computer. Service provider 103 may be a telephone service provider (e.g., or The user identifier 111 is used by the service provider 103 to identify the user 102 and can be a telephone number or email address. The computing system 104 can be a computing system for e-commerce merchants or financial institutions and may include one or more independent computing devices connected together. The application software 106 on the user device 101 and the application software 107 on the computing system 104 can be a pair of network software working together to achieve the desired functionality. For example, the application software 106 can be an application (e.g., The client software is the application software 107, and the application software 107 can be the server software of the same application.
[0018] In one implementation, the identifier 108 of user equipment 101 may be activated for user 102 by service provider 103 via communication path 121 and network 131. Identifier 108 may be activated by user 102 or by an attacker posing as user 102. If identifier 108 is activated by an attacker posing as user 102 and identifier 108 is a SIM card, a SIM swap may have occurred. However, service provider 103 may not be able to detect such a SIM swap using current technology. Service provider 103 may notify computing system 104 that identifier 108 of user equipment 101 has been activated for user identifier 111 to replace the existing identifier of the user equipment associated with user identifier 111. In some implementations, user equipment 101 may be the same as the existing user equipment associated with user identifier 111, but with identifier 108 changed. In other implementations, both identifier 108 and user equipment 101 may be changed compared to the previous device and identifier associated with user identifier 111. The notification from service provider 103 may only include the change in the state of identifier 108 to be associated with user identifier 111. The notification from service provider 103 may not include details or complete information about identifier 108.
[0019] In one implementation, computing system 104 (e.g., processor 105) is configured to receive a notification from service provider 103 that identifier 108 of user equipment 101 has been activated in user equipment 101 to be associated with user identifier 111, replacing the existing identifier of user equipment 101 associated with user identifier 111. This notification may be received by processor 105 via communication path 123 and network 133 between service provider 103 and computing system 104. Storage device 110 may be configured to store user identifier 111 of user 102 to indicate that the existing identifier of the user equipment associated with user identifier 111 has been changed. Alternatively, a public ledger or public database (single source of fact) may exist, where multiple service providers participate in a linked ledger of phone number-to-SIM card mappings over time (similar to a blockchain, but users are not anonymous). Read / write API keys are provided only to service providers, so only service providers can update phone-SIM information. Companies that need this information can automatically read it from this ledger or database using their own API keys. A shared ledger or database provides a system based on valid proof to track SIM cards to phone numbers. It also provides a global log for cybercrime investigations and prevents conflicts in phone-SIM mappings, as only a one-to-one phone-SIM mapping can exist at any given time.
[0020] In some implementations, application software 106 will be operated by user 102 or an attacker on user device 101. For example, application software 106 may send a request from user device 101 for information associated with user identifier 111, requesting information to be sent to user device 101. The requested information associated with user identifier 111 can be used by user 102 to operate the application software, for example, for logging into an OTP (On-Phase Access Point) of application software 106. The request for information associated with user identifier 111 can be sent via communication path 125 and network 135 between user device 101 and computing system 104. In some implementations, communication path 125 may differ from communication path 123. In some implementations, the request for information associated with user identifier 111 to be sent to user device 101 may be a request for user 102's OTP.
[0021] In one implementation, the computing system 104 receives a request from the user equipment 101 via a communication path 125 between the user equipment 101 and the computing system 104 for information associated with user identifier 111 to be sent to the user equipment 101 associated with identifier 108. Application software 107, operable by the processor 105, receives the request for the information associated with user identifier 111. The information associated with user identifier 111 can be used by the user 102 to operate application software 107 or application software 106.
[0022] In this implementation, the authentication module 109 may be operated by one or more processors (e.g., processor 105) to perform various operations to secure the association between user equipment 101 and user 102 or user identifier 111. Specifically, before sending the requested information associated with user identifier 111 to user equipment 101 associated with identifier 108, the authentication module 109 searches storage device 110 to look up user identifier 111 to determine whether the existing identifier of user equipment 101 associated with user identifier 111 has been altered. By performing the search and determining that the existing identifier of user equipment 101 associated with user identifier 111 has been altered, the authentication module 109 may stop sending any information associated with user identifier 111 to user equipment 101 associated with identifier 108, thus preventing SIM swapping if identifier 108 is activated by an attacker. Therefore, the authentication module 109 performs functions that are not typically performed by computing system 104 and improves the functionality of conventional computing systems used to operate application software 107.
[0023] In this implementation, when user identifier 111 is found in storage device 110, authentication module 109 can perform additional authentication on user 102 to verify that identifier 108 of user device 101 has been activated by user 102. This additional authentication can be performed via communication path 127 between user 102 and computing system 104 and network 137. After verifying that identifier 108 of user device 101 has been successfully activated by user 102, authentication module 109 or application software 107 can send the requested information associated with user identifier 111 to user device 101 via communication path 125.
[0024] In some implementations, authentication module 109 can perform additional authentication of user 102 through various operations. Specifically, authentication module 109 can send a request to user 102 via communication path 127 for authentication information different from the user identifier 111 of user 101. Communication path 127 is the communication path between computing system 104 and user 102, which may be different from communication path 125 between user device 101 and computing system 104. For example, communication path 127 may include computing devices accessible to user 102, but different from user device 101. In some other implementations, communication path 127 may include the same user device 101, but via a software application that operates on user device 101, but different from application software 106. Furthermore, in some implementations, communication path 127 may include additional steps to be operated by application software 106 or application software 107.
[0025] In this way, authentication module 109 can detect whether a change to the identifier 108 of user equipment 101 was performed or authorized by user 102. An attacker could use a fake identifier 108 of user equipment 101, but might find it difficult to directly access different communication paths of user 102. Authentication information requested from user 102 may include information that user 102 knows, information that user 102 possesses, information about what user 102 is, information about where user 102 is, or information about what user 102 does.
[0026] In this implementation, the use of three communication paths (communication path 123 between service provider 103 and computing system 104, communication path 125 between user equipment 101 and computing system 104, and communication path 127 between user 102 and computing system 104) is a specific implementation on a particular machine architecture to integrate security protection for the association between user equipment 101 and user 102 or user identifier 111. Furthermore, the use of the three communication paths (communication path 123, communication path 125, and communication path 127) represents specific features that cannot be used in the current system to prevent SIM swapping. For example, the use of communication path 127 between user 102 and computing system 104 can effectively verify whether the identifier 108 of user equipment 101 is activated by user 102 or by an attacker, a detection that conventional computing systems cannot perform.
[0027] The authentication module 109 can receive a response message from user 101 requesting authentication information, and also authenticate user 102 based on the response message and rule set 113. The rule set 113 for authenticating user 102 may include rules regarding limits on the number of requests for information associated with a user identifier to be sent to the user device associated with that identifier, rules regarding limits on the number of identifiers associated with the user device, rules regarding limits on the number of user identifiers associated with the user device identifier, rules regarding constraints on the user device provider, or rules providing an authentication scheme corresponding to the user device identifier. After successfully authenticating user 102, the authentication module 109 can update memory 110 to associate the identifier 108 of user device 101 with the user identifier 111 of user 102, wherein the association between the identifier 108 of user device 101 and the user identifier 111 can be saved as item 112 to mark user identifier 111 as verified. The generation of item 112, which marks user identifier 111 as verified, affects the transition of a specific item (e.g., storage device 110 or user identifier 111) to a different state (e.g., verified state).
[0028] Figure 2 Example process 200, according to various embodiments, for verifying that an identifier of a user device has been activated by the user to replace an existing identifier of the user device associated with the user identifier. Figure 1 As shown, process 200 can be executed by computing system 104.
[0029] In one implementation, at interaction 201, computing system 104 or processor 105 within computing system 104 receives a notification from a service provider stating that a user equipment identifier has been activated in the user equipment to be associated with the user identifier, replacing the existing identifier of the user equipment associated with the user identifier. This notification is received via a first communication path between the service provider and the computing system. The user equipment identifier is a hardware-based network identifier for the user equipment, and the user identifier is the service provider's identifier for the user. For example, computing system 104 or processor 105 receives a notification from service provider 103 stating that an identifier 108 for user equipment 101 has been activated in the user equipment 101 to be associated with user identifier 111, replacing the existing identifier of the user equipment 101 associated with user identifier 111. This notification is received via communication path 123 between service provider 103 and computing system 104.
[0030] In one implementation, at interaction 203, computing system 104 or processor 105 within computing system 104 stores a user's user identifier in a storage device to indicate that the existing identifier of the user device associated with the user identifier has been changed. For example, computing system 104 or processor 105 stores user identifier 111 of user 102 in storage device 110 to indicate that the existing identifier of user device 101 associated with user identifier 111 has been changed.
[0031] In one implementation, at interaction 205, computing system 104 or processor 105 within computing system 104 receives from user equipment a request for information associated with a user identifier to be sent to the user equipment associated with the user equipment's identifier. This request is received via a second communication path between the user equipment and the computing system. For example, computing system 104 or processor 105 receives from user equipment 101 a request for information associated with user identifier 111 to be sent to user equipment 101 associated with identifier 108. This request is received via communication path 125 between user equipment 101 and computing system 104.
[0032] In one implementation, at interaction 207, computing system 104 or processor 105 within computing system 104 searches storage device for a user identifier to determine whether the existing identifier of the user device associated with the user identifier has been changed. For example, computing system 104 or processor 105 within computing system 104 searches storage device 110 for a user identifier 111 to check whether the existing identifier of the user device 101 associated with user identifier 111 has been changed.
[0033] In this implementation, at interaction 209, when a user identifier is found in the storage device, the computing system 104 or the processor 105 within the computing system 104 verifies that the user device identifier has been activated by the user through additional authentication of the user. The computing system 104 or the processor 105 verifies that the user device identifier has been activated by the user through a third communication path between the user and the computing system. For example, when user identifier 111 is found in the storage device, the computing system 104 or the processor 105 verifies that the identifier 108 of user device 101 has been activated by user 102 through additional authentication of user 102. The computing system 104 or the processor 105 verifies that the identifier 108 of user device 101 has been activated through communication path 127 between user 102 and the computing system 104.
[0034] Figure 3 Example devices, according to various embodiments and suitable for practicing various aspects of this disclosure, are shown. Although Figure 3 Various components of a computer system are shown, but are not intended to represent any particular architecture or manner of interconnecting the components. One implementation may use components with... Figure 3 Other systems shown have fewer or more components.
[0035] exist Figure 3 In this system, data processing system 370 includes a connector 371 (e.g., a bus and system core logic) that interconnects a microprocessor 373, a memory 367, and input / output (I / O) devices 375 via an I / O controller 377. The microprocessor 373 is coupled to a cache memory 379. I / O devices 375 may include display devices and / or peripherals such as a mouse, keyboard, modem, network interface, printer, scanner, camera, and other devices known in the art. In one embodiment, when the data processing system is a server system, some of the I / O devices 375, such as printers, scanners, mice, and / or keyboards, are optional.
[0036] In one embodiment, the connector 371 includes one or more buses interconnected with each other via various bridges, controllers, and / or adapters. In one embodiment, the I / O controller 377 includes a USB (Universal Serial Bus) adapter for controlling USB peripherals and / or an IEEE-1394 bus adapter for controlling IEEE-1394 peripherals.
[0037] In one implementation, memory 367 includes one or more of the following: ROM (Read-Only Memory), volatile RAM (Random Access Memory), and non-volatile memory (such as hard disk drives, flash memory, etc.). Volatile RAM is typically implemented as dynamic RAM (DRAM) that requires continuous power to refresh or maintain data in the memory. Non-volatile memory is typically a magnetic hard disk drive, magneto-optical drive, optical drive (e.g., DVD RAM), or other type of memory system that retains data even after power is removed from the system. Non-volatile memory can also be random access memory. Non-volatile memory can be a local device directly connected to the rest of the data processing system. Alternatively, non-volatile memory remote from the system can be used (e.g., a network storage device connected to the data processing system via a network interface (such as a modem or Ethernet interface).
[0038] In this specification, for the sake of simplicity, some functions and operations are described as being executed by or caused by software code. That is, in response to the processor (such as a microprocessor) of a computer system or other data processing system executing a sequence of instructions contained in memory (such as ROM, volatile RAM, non-volatile memory, cache, or remote storage device), the technology can be executed in the computer system or other data processing system.
[0039] Alternatively or in combination, the functions and operations described herein may be implemented using dedicated circuitry with or without software instructions (such as using application-specific integrated circuits (ASICs) or field-programmable gate arrays (FPGAs)). Implementations may also be implemented using hard-wired circuitry without software instructions or in combination with software instructions. Therefore, the technique is neither limited to any specific combination of hardware circuitry and software, nor to any particular source of instructions executed by the data processing system.
[0040] While one implementation can be carried out on a fully functional computer and computer system, various implementations can be deployed as computing products in various forms and can be applied without regard to the specific type of machine or computer-readable medium used to actually affect the deployment.
[0041] In implementation methods, depending on the specific implementation, the storage medium may store information for practical reference. Figures 1 to 2The instructions for the described method. For example, a non-transitory computer-readable storage medium may include a plurality of programming instructions. The programming instructions may be configured to enable a device (e.g., device 370) to perform various operations, such as performing security protection associated with the association between user device 101 and user 102, verifying that identifier 108 of user device 101 has been activated by user 102 to replace the existing identifier of user device 101 associated with user identifier 111, the operations described in process 200, or other operations described herein.
[0042] Routines executed to implement an implementation may be part of an operating system or a specific application, component, program, object, module, or sequence of instructions referred to as a "computer program." A computer program typically includes one or more instructions set at various times in various memories and storage devices within a computer, and when one or more instructions are read and executed by one or more processors in the computer, cause the computer to perform operations necessary to perform elements relating to various aspects.
[0043] Non-transitory computer-readable storage media can be used to store software and data that, when executed by a data processing system, cause the system to perform various methods. Executable software and data can be stored in various locations, including, for example, ROM, volatile RAM, non-volatile memory, and / or cache. A portion of the software and / or data can be stored in any of these storage devices. Furthermore, data and instructions can be obtained from a centralized server or a peer-to-peer network. Different portions of the data and instructions can be obtained at different times and in different communication sessions or within the same communication session from different centralized servers and / or peer-to-peer networks. Data and instructions can be obtained entirely before application execution. Alternatively, portions of data and instructions can be dynamically obtained in a timely manner when execution is required. Therefore, it is not necessary for all data and instructions to be on the machine-readable medium at a specific point in time.
[0044] Examples of computer-readable media include, but are not limited to, media of recordable and non-recordable types, such as volatile and non-volatile memory devices, read-only memory (ROM), random access memory (RAM), flash memory devices, floppy disks and other removable disks, disk storage media, optical storage media (e.g., optical disc read-only memory (CD-ROM), digital versatile disk (DVD), etc.). Computer-readable media can store instructions.
[0045] Instructions can also be embodied in digital and analog communication links used for electrical, optical, acoustic, or other forms of propagated signals (such as carrier waves, infrared signals, digital signals, etc.). However, propagated signals such as carrier waves, infrared signals, digital signals, etc., are not tangible machine-readable media and are not configured to store instructions.
[0046] Generally, machine-readable media include any mechanism that provides (i.e., stores and / or transmits) information in a form accessible to a machine (e.g., a computer, network device, personal digital assistant, manufacturing tool, any device having one or more processors, etc.).
[0047] In various implementations, hard-wired circuitry can be combined with software instructions to implement the technology. Therefore, the technology is neither limited to any specific combination of hardware circuitry and software, nor to any particular source of instructions executed by the data processing system.
[0048] The specification and accompanying drawings are illustrative and should not be construed as restrictive. This disclosure illustrates features disclosed to enable those skilled in the art to make and use these techniques. The various features described herein should be used in accordance with all current and future rules, laws, and regulations relating to privacy, security, licensing, consent, authorization, etc. Numerous specific details are described to provide a thorough understanding. However, in some instances, well-known or conventional details have not been described to avoid obscuring the description. References to one embodiment or embodiments in this disclosure are not necessarily references to the same embodiment; and such references imply reference to at least one embodiment.
Claims
1. Computer-implemented communication methods, including: The processor of the computing system receives a notification from the service provider via a first communication path between the service provider and the computing system. The notification states that a user equipment identifier has been activated in a user equipment to be associated with the user identifier, replacing the existing identifier of the user equipment associated with the user identifier. The user equipment identifier is a hardware-based network identifier of the user equipment, and the user identifier is the service provider's identifier for the user. The user's user identifier is stored in a storage device connected to the processor to indicate that the existing identifier of the user device associated with the user identifier has been changed; The processor receives a request from the user equipment via a second communication path between the user equipment and the computing system. The request is for requesting information associated with the user identifier to be sent to a user equipment associated with that user identifier; searching the storage device to locate the user identifier; and... When the user identifier is found in the storage device, the user device's identifier is verified to have been activated by the user through additional authentication via a third communication path between the user and the computing system.
2. The computer-implemented communication method according to claim 1, wherein, Verifying that the identifier of the user device has been activated by the user through the user's additional authentication includes: A request for authentication information different from the user's user identifier is sent to the user through the third communication path between the user and the computing system. Receive a response message from the user in response to a request for the authentication information; and The user is authenticated based on the response message and the rule set.
3. The computer-implemented communication method according to claim 1 further includes: After successfully verifying that the identifier of the user equipment has been activated by the user, the requested information associated with the user identifier is sent to the user equipment associated with the identifier of the user equipment through the second communication path.
4. The computer-implemented communication method according to claim 1 further includes: Update the storage device to associate the user device identifier with the user identifier.
5. The computer-implemented communication method according to claim 1, wherein, Requests for information associated with the user identifier to be sent to the user equipment include requests for the user's one-time password.
6. The computer-implemented communication method according to claim 1, wherein, The application software operating on the user device receives a request for information associated with the user identifier to be sent to the user device, and the information associated with the user identifier is for the user to operate the application software.
7. The computer-implemented communication method according to claim 1, wherein, The identifier of the user equipment includes an identifier for the subscriber identification module card or the media access control address of the user equipment.
8. The computer-implemented communication method according to claim 1, wherein, The user equipment includes wireless phones, cellular phones, satellite phones, VoIP phones, smartphones, laptops, tablets, personal computers, point-of-sale terminals, transaction terminals, or handheld computers.
9. The computer-implemented communication method according to claim 1, wherein, The service provider includes a telephone service provider or an internet service provider, and the user identifier includes a telephone number or an email address.
10. The computer-implemented communication method according to claim 2, wherein, Sending a request to the user for authentication information that is different from the user's user identifier includes sending the request to the user via a third communication path that is different from the second communication path.
11. The computer-implemented communication method according to claim 2, wherein, The authentication information includes information that the user knows, information that the user possesses, information about what the user is, information about where the user is, or information about what the user does.
12. The computer-implemented communication method according to claim 2, wherein, The rule set used to authenticate the user based on the response message includes: Rules regarding the limitation on the number of requests for information associated with the user identifier to be sent to the user device associated with the user device identifier; or Rules regarding the limitation on the number of identifiers for user devices associated with the user identifier; or Rules regarding the limitation on the number of user identifiers associated with the identifier of the user equipment; or Rules relating to constraints on the providers of the user equipment; or Rules for providing authentication schemes corresponding to the identifiers of the user equipment.
13. A computing system, including: One or more processors, wherein the one or more processors are configured to receive a notification from the service provider via a first communication path between the service provider and the computing system, the notification being: a user equipment identifier has been activated in a user equipment to be associated with the user identifier to replace the existing identifier of the user equipment associated with the user identifier, wherein the user equipment identifier is a hardware-based network identifier of the user equipment, and the user identifier is the service provider's identifier for the user; A storage device, coupled to the one or more processors, wherein the storage device is configured to store the user's user identifier to indicate that an existing identifier of the user device associated with the user identifier has been changed; Application software, operated by the one or more processors, wherein the application software receives a request from the user equipment via a second communication path between the user equipment and the computing system, the request being for requesting information associated with the user identifier to be sent to the user equipment associated with the user identifier, and the information associated with the user identifier being used by the user to operate the application software; and The authentication module will be operated by the one or more processors, wherein the authentication module will: Search the storage device to locate the user identifier; When the user identifier is found in the storage device, a request for authentication information different from the user's user identifier is sent to the user through a third communication path between the user and the computing system. Receive a response message from the user in response to a request for the authentication information; and The user is authenticated based on the response message and the rule set.
14. The computing system according to claim 13, wherein, The application software is also used to send the requested information associated with the user identifier to the user device associated with the identifier of the user device via the second communication path after successfully authenticating the user based on the response message.
15. The computing system according to claim 13, wherein, The authentication module is also used to update the storage device to associate the user device identifier with the user identifier.
16. The computing system according to claim 13, wherein, The third communication path is different from the second communication path.
17. The computing system according to claim 13, wherein, Requests for information associated with the user identifier to be sent to the user equipment include requests for the user's one-time password.
18. An executable software product stored on a non-transitory computer-readable medium containing program instructions, said program instructions causing a processor of a computing system to execute the instructions in response to the processor, so as to: A notification is received from the service provider via a first communication path between the service provider and the computing system, the notification stating that a user device identifier is activated in the user device to be associated with the user identifier, replacing the existing identifier of the user device associated with the user identifier, wherein... The identifier of the user equipment is a hardware-based network identifier of the user equipment, and the user identifier is the service provider's identifier for the user; The user's user identifier is stored in a storage device connected to the processor to indicate that the existing identifier of the user device associated with the user identifier has been changed; The processor receives a request from the user equipment via a second communication path between the user equipment and the computing system. The request is for requesting information associated with the user identifier to be sent to the user equipment associated with the user equipment identifier. Search the storage device to locate the user identifier; When the user identifier is found in the storage device, a request for authentication information different from the user's user identifier is sent to the user through a third communication path between the user and the computing system. Receive a response message from the user in response to a request for the authentication information; as well as The user is authenticated based on the response message and the rule set.
19. The executable software product according to claim 18, wherein, The program instructions also cause the processor to: After successfully authenticating the user based on the response message, the requested information associated with the user identifier is sent to the user device associated with the identifier of the user device through the second communication path; as well as Update the storage device to associate the user device identifier with the user identifier.
20. The executable software product according to claim 18, wherein, The third communication path is different from the second communication path, and Requests for information associated with the user identifier to be sent to the user equipment include requests for the user's one-time password.