A method, device, computer device and storage medium for displaying verification codes
Through the terminal housekeeper application, query the sending agency of the verification code SMS and match it with the web page domain name, the problem of automatic filling of verification code to the phishing website is solved, and a safe verification code display is achieved.
Patent Information
- Application Number
- CN202110234201.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-03
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-03-03
AI Technical Summary
In the prior art, the automatic filling mechanism of verification code SMS cannot identify the authenticity of the input box, resulting in users that may fill the verification code on a phishing website, resulting in information leakage and fraud.
Get the verification code text message through the terminal housekeeper application, query the sending agency and match the domain name of the current web page. If the match is successful, the verification code will be displayed, otherwise it will be a phishing website.
It effectively reduces the probability that users will fill verification codes on phishing websites and prevents information leakage and fraud.
Smart Images

Figure CN113704644B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more particularly, to a verification code display method, device, computer device and storage medium. Background Art
[0002] With the development of Internet technology, in the interaction process of many terminals, due to considerations of interaction security, service providers will send verification codes to users' terminals in the form of text messages. In the prior art, when a user receives a verification code text message, the verification code of the current text message will be automatically displayed, and the user can easily fill the verification code into the verification code input box. However, if the current verification code input box comes from a fake phishing website, this convenience may cause the user to be scammed. Summary of the Invention
[0003] In view of this, to solve the above problems, the present invention provides a verification code display method, device, computer device and storage medium, which realizes the display of the verification code depending on the risk identification result of the source website of the verification code input box, and reduces the occurrence of the situation where the user wrongly fills the verification code into a phishing website. The technical solutions are as follows:
[0004] A verification code display method includes:
[0005] Obtaining the verification code text message received when performing a verification code obtaining operation on a web page;
[0006] Determining the target service provider that sends the verification code text message;
[0007] Determining whether the web page comes from the target service provider according to the website address of the web page;
[0008] If the web page comes from the target service provider, in response to a trigger operation on the verification code input box in the web page, displaying the verification code in the verification code text message;
[0009] If the web page does not come from the target service provider, in response to a trigger operation on the verification code input box in the web page, refusing to display the verification code in the verification code text message and sending a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risk website.
[0010] A verification code display device includes:
[0011] A short message verification code obtaining unit, configured to obtain the verification code text message received when performing a verification code obtaining operation on a web page;
[0012] A target service provider determining unit, configured to determine the target service provider that sends the verification code text message;
[0013] A source determination unit, configured to determine whether the web page comes from the target service provider according to the URL of the web page;
[0014] A first display unit, configured to, if the web page comes from the target service provider, in response to a trigger operation on the verification code input box in the web page, display the verification code in the verification code SMS;
[0015] A second display unit, configured to, if the web page does not come from the target service provider, in response to a trigger operation on the verification code input box in the web page, refuse to display the verification code in the verification code SMS and send a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risk website.
[0016] A computer device, including: a processor and a memory, where the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store a program, and the program is used to implement the verification code display method.
[0017] A computer-readable storage medium, on which a computer program is stored, and the computer program is loaded and executed by a processor to implement the steps of the verification code display method.
[0018] The present application provides a verification code display method, device, computer device and storage medium, which obtains a verification code SMS received by performing a verification code acquisition operation on a web page; determines a target service provider that sends the verification code SMS; if the web page comes from the target service provider, in response to a trigger operation on the verification code input box in the web page, displays the verification code in the verification code SMS; if the web page does not come from the target service provider, in response to a trigger operation on the verification code input box in the web page, refuses to display the verification code in the verification code SMS and sends a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risk website. The verification code display method provided by the present application controls the display of the verification code in the middle depending on the risk identification result of the website to which the web page belongs, effectively reducing the occurrence of the situation where a user incorrectly fills the verification code into a phishing website. Description of the Drawings
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0020] Figure 1 It is a schematic diagram of a short message verification code display provided by an embodiment of the present application;
[0021] Figure 2 It is an architecture diagram of a verification code display system provided by an embodiment of the present application;
[0022] Figure 3 It is another schematic diagram of SMS verification code display provided by an embodiment of the present application;
[0023] Figure 4 It is yet another schematic diagram of SMS verification code display provided by an embodiment of the present application;
[0024] Figure 5 It is a flowchart of a verification code display method provided by an embodiment of the present application;
[0025] Figure 6 It is another flowchart of a verification code display method provided by an embodiment of the present application;
[0026] Figure 7 It is a schematic diagram of a verification code display method provided by an embodiment of the present application;
[0027] Figure 8 It is a schematic diagram of an inquiry interface of a sending mechanism provided by an embodiment of the present application;
[0028] Figure 9 It is a schematic diagram of the content of a target SMS provided by an embodiment of the present application;
[0029] Figure 10 It is another schematic diagram of the content of a target SMS provided by an embodiment of the present application;
[0030] Figure 11 It is a schematic diagram of the structure of a verification code display device provided by an embodiment of the present application;
[0031] Figure 12 It is a hardware structure block diagram of a computer device to which a verification code display method provided by an embodiment of the present application is applicable. Detailed implementation manners
[0032] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0033] In the existing automatic filling technology for SMS verification codes, after obtaining the verification code SMS, the SMS verification code is automatically popped up (as Figure 1 shown in a schematic diagram of SMS verification code display provided by an embodiment of the present application), and the user can click on the verification code and automatically input it into the corresponding input box.
[0034] In the current interaction method, when a user receives a verification code text message, the verification code of the current text message will be automatically displayed. The user can easily click and automatically fill the verification code into the input box. However, if the current website is a phishing website, this convenience may cause the user to be scammed. The existing automatic filling mechanism for SMS verification codes cannot identify whether the input box to be automatically filled comes from the genuine website that sent the verification code or a fake phishing website. As a result, the user may mistakenly let the verification code be automatically filled into the phishing website, resulting in information leakage and financial losses.
[0035] By using a verification code display method provided by an embodiment of the present application, when a verification code text message is obtained, the terminal steward number database can be used to query the sending institution of the verification code, and then the domain name of the institution can be obtained. The domain name is used to match the web page address that the user is currently browsing. If the match is successful, the automatic filling mechanism for the SMS verification code will be applied; otherwise, the user will be prompted that they may be browsing a phishing website, reducing the risk of the user being scammed by a fraudulent website due to automatic SMS filling.
[0036] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0037] An embodiment of the present application provides a verification code display method applied to a verification code display system. Refer to Figure 2 the shown verification code display system architecture diagram. The verification code display system is composed of a terminal steward application, a SMS application, and a browser. Taking the terminal steward application, the SMS application, and the browser being located on the same terminal as an example, the user opens a web page on the browser of the terminal and performs a verification code acquisition operation on the web page. If the mobile phone number filled in when performing the verification code acquisition operation is the mobile phone number of this terminal, the SMS application on this terminal can receive the corresponding verification code text message. Correspondingly, the terminal steward application on this terminal can obtain the verification code text message from the SMS application, determine the target service provider that sent the verification code text message, and determine whether the web page comes from the target service provider to obtain the recognition result of the web page. In this way, when the browser responds to the user's trigger operation on the verification code input box on the web page and pops up the system keyboard, the terminal steward application can control the system keyboard to display the verification code in the verification code text message according to the recognition result of this web page.
[0038] Exemplarily, if the recognition result of the web page by the terminal steward application indicates that the website to which the web page belongs is not a phishing website, the terminal steward application will control the verification code in the verification code text message to be displayed in the target area of the popped-up system keyboard.
[0039] Exemplarily, if the recognition result of the terminal housekeeper for a web page indicates that the website to which the web page belongs is a phishing website, the terminal housekeeper application will control not to display the verification code in the verification code text message in the target area of the popped-up system keyboard. Moreover, the terminal housekeeper application will also control to display a risk prompt message, which indicates that the website to which the web page belongs is a risky website.
[0040] See Figure 3 Another schematic diagram of displaying a short message verification code as shown. If the recognition result of the terminal housekeeper application for a web page indicates that the website to which the web page belongs is a phishing website, when the browser responds to the user's trigger operation on the verification code input box on the web page and pops up the system keyboard, the terminal housekeeper application will not only control not to display the verification code in the verification code text message in the target area of the popped-up system keyboard, but also control to display a risk prompt message at the position of the web page URL in the browser. As Figure 3 shown, the content displayed in the target area of the system keyboard is empty, so as to achieve the purpose of not displaying the verification code in the verification code text message in the target area of the popped-up system keyboard. The risk prompt message displayed at the position of the web page URL is "Risky website!!".
[0041] See Figure 4 Another schematic diagram of displaying a short message verification code as shown. If the recognition result of the terminal housekeeper application for a web page indicates that the website to which the web page belongs is a phishing website, when the browser responds to the user's trigger operation on the verification code input box on the web page and pops up the system keyboard, the terminal housekeeper application can control not to display the verification code of the verification code text message in the target area of the popped-up system keyboard, but to control to display a risk prompt message in the target area of the popped-up system keyboard. As Figure 4 shown, the risk prompt message displayed in the target area of the system keyboard is "The website to which the current web page belongs is a risky website".
[0042] Figure 3 、 Figure 4 Only two preferred contents of the risk prompt message provided by the embodiments of the present application are shown. Regarding the specific content of the risk prompt message, those skilled in the art can set it according to their own needs and are not limited herein.
[0043] The above are only preferred ways of the display method of the risk prompt message provided by the embodiments of the present application. Regarding the specific display method of the risk prompt message, those skilled in the art can set it according to their own needs and are not limited herein.
[0044] Next, a verification code display method provided by the embodiments of the present application will be described in detail from the perspective of the terminal housekeeper application. Specifically, please refer to Figure 5 .
[0045] As Figure 5 shown, the method includes:
[0046] S501. Obtain the verification code SMS received when performing the verification code obtaining operation on the web page;
[0047] Exemplarily, when the user opens a web page on the browser of the terminal, if the web page is a web page that requires filling in the verification code, the user can enter the mobile phone number of the terminal on the web page and click the "Obtain Verification Code" button on the web page. The SMS application on the terminal can receive the corresponding verification code SMS, and then the terminal steward application on the terminal can obtain the verification code SMS from the SMS application.
[0048] S502. Determine the target service provider that sent the verification code SMS;
[0049] In the embodiment of the present application, a number library is pre-set in the terminal steward application. The number library can be the terminal steward number library. After the terminal steward application obtains the verification code SMS, it can determine the sending number of the verification code SMS, and then query the service provider that owns the sending number from the terminal steward number library. If the service provider that owns the sending number is queried from the terminal steward number library, the queried service provider can be determined as the target service provider that sent the verification code SMS; if the service provider that owns the sending number is not queried from the terminal steward number library, the target SMS content that conforms to the pre-set text format can be intercepted from the verification code SMS, and the service provider represented by the target SMS content can be determined as the target service provider that sent the verification code SMS.
[0050] Exemplarily, the pre-set text format can be [*], where * represents a string. Taking the pre-set text format of [*] as an example, the string that conforms to this text format can be intercepted from the verification code SMS. The leftmost character of the intercepted string is the "[" character, and the rightmost character of the intercepted string is the "]" character. The intercepted string can be considered as the target SMS content intercepted from the verification code SMS that conforms to the text format, and then the service provider indicated by the target SMS content can be determined as the target service provider that sent the verification code SMS.
[0051] Exemplarily, after intercepting the target SMS content that conforms to the text format from the verification code SMS, deleting the leftmost character and the rightmost character of the target SMS content can obtain the target information, and the service provider indicated by the target information can be considered as the target service provider that sent the verification code SMS.
[0052] Taking the verification code SMS "
Tencent Technology
Tencent Technology
[0053] It should be noted that the sending institution of the verification code SMS can be regarded as the service provider that sends the verification code SMS.
[0054] S503. Determine whether the web page comes from the target service provider according to the URL of the web page; if the web page comes from the target service provider, execute step S504; if the web page does not come from the target service provider, execute step S505;
[0055] In the embodiment of the present application, at least one domain name of the target service provider is obtained; it is determined whether there is a domain name in the at least one domain name that matches the URL of the web page; if there is a domain name in the at least one domain name that matches the URL of the web page, it is determined that the web page comes from the target service provider; if there is no domain name in the at least one domain name that matches the URL of the web page, it is determined that the web page does not come from the target service provider.
[0056] Exemplarily, at least one domain name of the target service provider includes all domain names owned by the target service provider. Among them, the way for the terminal housekeeper application on the terminal to obtain at least one domain name of the target service provider can be: detect whether the domain name information of the target service provider is cached locally on the terminal. If the domain name information of the target service provider is cached locally on the terminal, all domain names indicated by the domain name information of the target service provider cached locally on the terminal can be obtained, and all the obtained domain names can be regarded as at least one domain name of the target service provider obtained; if the domain name information of the target service provider is not cached locally on the terminal, the domain name information of the target service provider can be obtained from the background server of the terminal housekeeper application. After the terminal housekeeper application on the terminal obtains the domain name information of the target service provider, the domain name information can be cached locally on the terminal, and all domain names indicated by the obtained domain name information can be determined as at least one domain name of the target service provider obtained.
[0057] Exemplarily, taking a domain name as an example, if the top-level domain name in the domain name is the same as the top-level domain name in the website URL of the web page, and the second-level domain name in the domain name is the same as the second-level domain name in the website URL of the web page, it can be considered that the domain name matches the website URL of the web page; conversely, if the top-level domain name in the domain name is different from the top-level domain name in the website URL of the web page, or if the second-level domain name in the domain name is different from the second-level domain name in the website URL of the web page, it can be considered that the domain name does not match the website URL of the web page.
[0058] Exemplarily, a domain name consists of two or more words separated by dots. The rightmost word is called the top-level domain name, and the second-level domain name refers to the domain name under the top-level domain name. For example, the penultimate word can be regarded as the second-level domain name.
[0059] Exemplarily, the word after the last dot in the website URL can be regarded as the top-level domain name, and the word between the last dot and the penultimate dot in the website URL can be regarded as the second-level domain name.
[0060] A method for determining whether a domain name matches the website URL of a web page can be: determining whether the top-level domain name in the website URL of the web page is the same as the top-level domain name in the domain name; if the top-level domain name in the website URL of the web page is the same as the top-level domain name in the domain name, determining whether the second-level domain name in the website URL of the web page is the same as the second-level domain name in the domain name; if the second-level domain name in the website URL of the web page is the same as the second-level domain name in the domain name, determining that the website URL of the web page matches the domain name; if the top-level domain name in the website URL of the web page is different from the top-level domain name in the domain name, or if the second-level domain name in the website URL of the web page is different from the second-level domain name in the domain name, determining that the website URL of the web page does not match the domain name.
[0061] The above is only the preferred method for determining whether a domain name matches the website URL of a web page provided by the embodiments of the present application. Regarding the specific method for determining whether a domain name matches the website URL of a web page, those skilled in the art can set it according to their own needs and are not limited herein.
[0062] Exemplarily, if it is determined that the web page comes from the target service provider, it indicates that the website to which the web page belongs is provided by the target service provider, and the website to which the web page belongs is not a risky website, that is, the website to which the web page belongs is not a phishing website.
[0063] Exemplarily, if it is determined that the web page does not come from the target service provider, it indicates that the website to which the web page belongs is not provided by the target service provider, and the website to which the web page belongs is a risky website, that is, the website to which the web page belongs is a phishing website.
[0064] S504. In response to the triggering operation on the verification code input box in the web page, display the verification code in the verification code text message;
[0065] In an embodiment of the present application, when the terminal management application determines that the website to which the web page belongs is not a phishing website, if the user performs a triggering operation on the verification code input box in the web page of the browser, the browser can trigger the system keyboard to pop up, and at this time, the verification code in the verification code text message is displayed in the target area of the popped-up system keyboard.
[0066] Exemplarily, when the terminal management application determines that the website to which the web page belongs is not a phishing website, if the user performs a triggering operation on the verification code input box in the page of the browser, the terminal management application can control the verification code in the verification code text message to be displayed in the target area of the system keyboard triggered by the browser to pop up.
[0067] Exemplarily, the user can click on the verification code input box in the page of the browser to trigger the verification code input box and enter the verification code input state.
[0068] S505: In response to the triggering operation on the verification code input box in the web page, reject the display of the verification code in the verification code text message and send a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risky website.
[0069] In an embodiment of the present application, when the terminal management application determines that the website to which the web page belongs is a phishing website, if the user performs a triggering operation on the verification code input box in the web page of the browser, the browser can trigger the system keyboard to pop up, and at this time, the verification code in the verification code text message is not displayed in the target area of the popped-up system keyboard. Further, when the terminal management application determines that the website to which the web page belongs is a phishing website, if the user performs a triggering operation on the verification code input box in the web page of the browser, not only can a system keyboard without the displayed verification code be popped up, but also a risk prompt message related to the web page can be displayed, and the risk prompt message indicates that the website to which the web page belongs is a risky website.
[0070] Exemplarily, when the terminal management application determines that the website to which the web page belongs is a phishing website, if the user performs a triggering operation on the verification code input box in the page of the browser, the terminal management application can not only control the verification code not to be displayed in the target area of the system keyboard triggered by the browser to pop up, but also control the sending of a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a phishing website.
[0071] Further, the verification code has a time limit, and the verification code becomes invalid after a certain period of time. To avoid affecting the timeliness of the verification code, a verification code display method provided in an embodiment of the present application may further include the following process: If the target service provider for sending the verification code text message cannot be determined within the first preset duration, it can be considered that the determination of the target service provider for sending the verification code text message fails, and then it is directly determined that the website to which the web page belongs is not a phishing website.
[0072] Further, a verification code display method provided by an embodiment of the present application may further include: If at least one domain name of the target service provider is not obtained within the second preset duration, it can be considered that the acquisition of at least one domain name of the target service provider fails, and then it is directly determined that the website to which the web page belongs is not a phishing website.
[0073] Exemplarily, the first preset duration and the second preset duration may be the same or different, and are not limited herein.
[0074] An embodiment of the present application provides a verification code display method, which acquires a verification code SMS received when performing a verification code acquisition operation on a web page; determines a target service provider that sends the verification code SMS; if the web page is from the target service provider, in response to a trigger operation on a verification code input box in the web page, displays the verification code in the verification code SMS; if the web page is not from the target service provider, in response to a trigger operation on the verification code input box in the web page, refuses to display the verification code in the verification code SMS and issues a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risk website. The verification code display method provided by an embodiment of the present application controls the display of the verification code based on the risk identification result of the website to which the web page belongs, effectively reducing the occurrence of the situation where a user incorrectly fills the verification code into a phishing website.
[0075] Further, after the mobile phone management application determines whether the web page is a web page from the target service provider, it may also locally store the query result of the web page (the query result may also be referred to as a risk identification result) on the terminal. For example, after the mobile phone management application determines that the web page is a web page from the target service provider, the query result of the web page locally stored on the terminal indicates that the website to which the web page belongs is not a phishing website; after the mobile phone management application determines that the web page is not a web page from the target service provider, the query result of the web page locally stored on the terminal indicates that the website to which the web page belongs is a phishing website.
[0076] Based on this, another verification code display method is provided by an embodiment of the present application. For details, please refer to Figure 6 .
[0077] As Figure 6 shown, the method includes:
[0078] S601. Acquire a verification code SMS received when performing a verification code acquisition operation on a web page;
[0079] S602. Determine whether a query result of the web page is cached locally; if the query result of the web page is cached locally, execute step S603; if the query result of the web page is not cached locally, execute step S604;
[0080] Exemplarily, after the user performs a verification code acquisition operation on the web page displayed on the browser of the terminal, the mobile phone management application on the terminal can first determine whether the query result of the web page is cached locally on the terminal. If the query result of the web page is cached locally on the terminal, step S603 can be executed; if the query result of the web page is not cached locally on the terminal, step S604 can be executed.
[0081] S603. Determine whether the query result indicates that the website to which the web page belongs is a phishing website. If the query result indicates that the website to which the web page belongs is not a phishing website, execute step S606; if the query result indicates that the website to which the web page belongs is a phishing website, execute step S607.
[0082] S604. Determine the target service provider for sending the verification code SMS.
[0083] S605. Determine whether the web page comes from the target service provider according to the website URL of the web page. If the web page comes from the target service provider, execute step S606; if the web page does not come from the target service provider, execute step S607.
[0084] S606. In response to the trigger operation on the verification code input box in the web page, display the verification code in the verification code SMS.
[0085] S607. In response to the trigger operation on the verification code input box in the web page, reject displaying the verification code in the verification code SMS and issue a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risk website.
[0086] In the embodiment of the present application, by caching the query result of the web page, the recognition efficiency of whether the website to which the web page belongs is a phishing website can be improved, and the influence on the timeliness of the verification code can be effectively reduced.
[0087] The following Figure 7 shows a verification code display schematic diagram to further describe in detail a verification code display method provided by the embodiment of the present application.
[0088] Exemplarily, Figure 7 Taking the terminal housekeeper application as an example of the mobile phone housekeeper application for illustration. In the embodiment of the present application, when the device (terminal) obtains the SMS verification code, it will not extract the verification code and display it in the target area of the keyboard (the target area can be an autofill field) for the user to select immediately. Instead, it will first perform a query and filtering operation on the sending institution, and then determine whether the verification code should be displayed in the autofill field. The specific process is as follows:
[0089] 1. When receiving the SMS, obtain the sending number of the SMS, query the number using the number library of the mobile phone housekeeper, and obtain the sending institution of the verification code, such as Figure 8Taking the schematic diagram of the sending institution query interface shown as an example, the sending institution of this SMS can be obtained as: Tencent Technology (Shenzhen) Company Limited, and proceed to step [3] for query.
[0090] 2. If the sending institution of the number can be queried, proceed to step [3]. If no result can be queried, use regular expressions to match the SMS content and try to obtain the sending institution. Similarly, characters such as "[*]" can be matched, as shown below. Figure 9 - 10 as shown.
[0091] For such SMSs, the sending institution can be obtained, and proceed to step [3] for query. If the regular expression fails to obtain the result successfully, skip this SMS, display the SMS verification code in the auto-fill field of the keyboard, and end the query process.
[0092] 3. After obtaining the sending institution of the SMS, synchronize the institution name with the background server. A database of institution names and their affiliated domain names will be maintained in the background server. When the client provides the institution name, the background server will return the affiliated domain names of this institution to the client for subsequent operations by the client. For example, "Tencent Technology (Shenzhen) Company Limited" corresponds to domain names such as "qq.com" and "tencent.com".
[0093] 3.1 Since the verification code input is a relatively time-sensitive operation, the background query time should be as short as possible. In the present invention, the timeout for the background query will be set to 3 seconds. If no server result is returned after 3 seconds, the query is considered failed.
[0094] 3.2 Additionally, to shorten the query time, the results of the server query will be cached locally. When querying next time, the local cache can be preferentially used to return the results. At the same time, the local cache results also need to receive updates from the background regularly.
[0095] 3.3 After the query fails, end the query process and directly display the SMS verification code in the auto-fill field of the keyboard. If the query is successful, proceed to step [4].
[0096] 4. After obtaining the domain names affiliated with the sending structure of the SMS verification code, use regular expressions to match the domain names with the web page address that the user is currently browsing. For example:
[0097] 4.1 Assume that when the user logs in with the SMS verification code on "pay.qq.com", the domain name "qq.com" can be matched. Therefore, the SMS verification code can be displayed in the auto-fill field of the keyboard.
[0098] 4.2 Assume that when the user logs in with a verification code on "fake.qp.com", since the website cannot match the domain names of "qq.com" or "tencent.com", the verification code will not be displayed in the automatic fill field of the keyboard.
[0099] 4.3 Assume that when the user logs in with a verification code on "fake.fake.qq.fake.com", since the website cannot fully match the domain names of "qq.com" or "tencent.com", the verification code will not be displayed in the automatic fill field of the keyboard.
[0100] 5. When the match in step 【4】 is successful, that is, when it is considered that the website matches the domain name of the website under the verification code sending institution, the SMS verification code will be displayed in the automatic fill field for the user to select and fill. When the match is unsuccessful, the SMS verification code will not be displayed in the automatic fill field, and the user will be prompted that they may be browsing a risky website currently.
[0101] 6. After the query is completed, the corresponding number domain name and query result provided by the background will be saved locally and checked and updated regularly. When the query needs to be performed next time, the local cache can be used to accelerate the query process.
[0102] Through a verification code display method provided by an embodiment of the present application, when the user needs to fill in the SMS verification code on a suspected phishing website or other fraudulent websites, it only needs to not automatically fill and pop up a prompt box to prompt the user. When the user faces phishing websites or other fraudulent websites, the SMS verification code will not be preferentially displayed and automatically filled, which can reduce the probability of the user being scammed by phishing websites.
[0103] A verification code display method provided by an embodiment of the present application combines the mobile phone manager number library with the browser. When receiving the SMS verification code, it obtains the source of the verification code and requests the domain name under the source from the background server, and matches the domain name with the web page address that the user is currently browsing. Only after a successful match will it perform automatic filling, thus avoiding some phishing websites from impersonating and stealing the SMS verification code.
[0104] Figure 11 It is a schematic structural diagram of a verification code display device provided by an embodiment of the present application.
[0105] As Figure 11 shown, the device includes:
[0106] An SMS verification code acquisition unit 1101, which is used to acquire the verification code SMS received when performing a verification code acquisition operation on a web page;
[0107] A target service provider determination unit 1102, which is used to determine the target service provider that sends the verification code SMS;
[0108] A source determination unit 1103, configured to determine whether a web page comes from a target service provider according to the URL of the web page;
[0109] A first display unit 1104, configured to, if the web page comes from a target service provider, in response to a trigger operation on the verification code input box in the web page, display the verification code in the verification code SMS;
[0110] A second display unit 1105, configured to, if the web page does not come from a target service provider, in response to a trigger operation on the verification code input box in the web page, refuse to display the verification code in the verification code SMS and send out a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risky website.
[0111] In an embodiment of the present application, preferably, the target service provider determination unit includes:
[0112] A sending number determination unit, configured to determine the sending number of the verification code SMS;
[0113] A query unit, configured to query, from a pre-set number library, the service provider that owns the sending number;
[0114] A SMS content intercepting unit, configured to, if the service provider that owns the sending number is not queried from the number library, intercept the target SMS content that conforms to a pre-set text format from the verification code SMS;
[0115] A target service provider determination unit, configured to determine the service provider represented by the target SMS content.
[0116] In an embodiment of the present application, preferably, the source determination unit includes:
[0117] A domain name acquisition unit, configured to acquire at least one domain name of the target service provider;
[0118] A matching unit, configured to determine whether there is a domain name in the at least one domain name that matches the URL of the web page;
[0119] A first source determination unit, configured to, if there is a domain name in the at least one domain name that matches the URL of the web page, determine that the web page comes from a target service provider;
[0120] A second source determination unit, configured to, if there is no domain name in the at least one domain name that matches the URL of the web page, determine that the web page does not come from a target service provider.
[0121] In an embodiment of the present application, preferably, the matching unit for determining whether a domain name matches the URL of a web page includes:
[0122] A top-level domain name judgment unit, configured to judge whether the top-level domain name in the URL of the web page is the same as the top-level domain name in the domain name;
[0123] A second-level domain name judgment unit, configured to judge whether the second-level domain name in the web page URL is the same as the second-level domain name in the domain name if the top-level domain name in the web page URL is the same as the top-level domain name in the domain name;
[0124] A first determination unit, configured to determine that the web page URL and the domain name match if the second-level domain name in the web page URL is the same as the second-level domain name in the domain name;
[0125] A second determination unit, configured to determine that the web page URL and the domain name do not match if the top-level domain name in the web page URL is different from the top-level domain name in the domain name / the second-level domain name in the web page URL is different from the second-level domain name in the domain name.
[0126] In the embodiment of the present application, preferably, the domain name acquisition unit includes:
[0127] A domain name information detection unit, configured to detect whether the domain name information of the target service provider is cached locally;
[0128] An acquisition unit, configured to acquire each domain name indicated by the domain name information of the target service provider if the domain name information of the target service provider is cached locally;
[0129] A request sending unit, configured to send a domain name acquisition request to the background server if the domain name information of the target service provider is not cached locally, where the domain name acquisition request indicates the target service provider;
[0130] A caching unit, configured to receive and cache locally the domain name information of the target service provider returned by the background server.
[0131] In the embodiment of the present application, preferably, a first display unit for displaying the verification code in the verification code SMS in response to a trigger operation on the verification code input box in the web page is specifically configured to control the display of the verification code in the verification code SMS in the target area of the popped-up system keyboard in response to a trigger operation on the verification code input box in the web page.
[0132] In the embodiment of the present application, preferably, a second display unit for rejecting the display of the verification code in the verification code SMS and sending a risk prompt message in response to a trigger operation on the verification code input box in the web page is specifically configured to control the non-display of the verification code in the verification code SMS in the target area of the popped-up system keyboard and send a risk prompt message in response to a trigger operation on the verification code input box in the web page.
[0133] A verification code display method provided by an embodiment of the present application is applied to a computer device, and the computer device may be the above terminal. As Figure 12 shown, it is a structural diagram of an implementation manner of the computer device provided by an embodiment of the present application, and the computer device includes:
[0134] A memory 1201 for storing programs;
[0135] A processor 1202 for executing programs, and the programs are specifically used for:
[0136] Obtaining the verification code SMS received when performing a verification code obtaining operation on a web page;
[0137] Determining the target service provider that sent the verification code SMS;
[0138] Determining whether the web page is from the target service provider according to the URL of the web page;
[0139] If the web page is from the target service provider, in response to a trigger operation on the verification code input box in the web page, displaying the verification code in the verification code SMS;
[0140] If the web page is not from the target service provider, in response to a trigger operation on the verification code input box in the web page, refusing to display the verification code in the verification code SMS and sending out a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risky website.
[0141] The processor 1202 may be a central processing unit CPU or a specific integrated circuit ASIC (Application Specific Integrated Circuit).
[0142] The control device may further include a communication interface 1203 and a communication bus 1204. Among them, the memory 1201, the processor 1202, and the communication interface 1203 complete mutual communication through the communication bus 1204.
[0143] An embodiment of the present application also provides a readable storage medium, on which a computer program is stored. The computer program is loaded and executed by a processor to implement the steps of the above verification code display method. The specific implementation process may refer to the description of the corresponding part of the above embodiment, and this embodiment will not be elaborated.
[0144] The present application also proposes a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in various optional implementation manners in the above verification code display method aspect or the verification code display device aspect. The specific implementation process may refer to the description of the corresponding embodiment above and will not be elaborated.
[0145] An embodiment of the present application provides a verification code display method, device, computer device, and storage medium, which acquire a verification code SMS received upon performing a verification code acquisition operation on a web page; determine a target service provider that sends the verification code SMS; if the web page is from the target service provider, in response to a trigger operation on a verification code input box in the web page, display the verification code in the verification code SMS; if the web page is not from the target service provider, in response to a trigger operation on a verification code input box in the web page, reject displaying the verification code in the verification code SMS and issue a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risky website. The verification code display method provided by the embodiment of the present application controls the display of the verification code based on the risk identification result of the website to which the web page belongs, effectively reducing the occurrence of the situation where a user erroneously fills the verification code into a phishing website.
[0146] The above has introduced in detail a verification code display method, device, computer device, and storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
[0147] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0148] It should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device that includes a series of elements includes not only those elements but also other elements inherent to these process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device that includes the element.
[0149] The foregoing description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Thus, the present invention is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A verification code display method, characterized in that, Including: Obtain the verification code SMS received when performing a verification code obtaining operation on a web page; Determine the target service provider that sent the verification code SMS; Obtain at least one domain name of the target service provider; Judge whether there is a domain name in the at least one domain name that matches the URL of the web page; If there is a domain name in the at least one domain name that matches the URL of the web page, determine that the web page comes from the target service provider; If there is no domain name in the at least one domain name that matches the URL of the web page, determine that the web page does not come from the target service provider; If the web page comes from the target service provider, in response to a trigger operation on the verification code input box in the web page, display the verification code in the verification code SMS; If the web page does not come from the target service provider, in response to a trigger operation on the verification code input box in the web page, reject displaying the verification code in the verification code SMS and issue a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risk website.
2. The method according to claim 1, characterized in that, The determining the target service provider that sent the verification code SMS includes: Determine the sending number of the verification code SMS; Query from a pre-set number library the service provider that owns the sending number; If the service provider that owns the sending number is not queried from the number library, intercept the target SMS content that conforms to a pre-set text format from the verification code SMS; Determine the service provider represented by the target SMS content.
3. The method according to claim 1, characterized in that, The process of judging whether the domain name matches the URL of the web page includes: Judge whether the top-level domain name in the URL of the web page is the same as the top-level domain name in the domain name; If the top-level domain name in the URL of the web page is the same as the top-level domain name in the domain name, judge whether the second-level domain name in the URL of the web page is the same as the second-level domain name in the domain name; If the second-level domain name in the URL of the web page and the second-level domain name in the domain name are the same, determine that the URL of the web page and the domain name match; If the top-level domain name in the URL of the web page and the top-level domain name in the domain name are different / the second-level domain name in the URL of the web page and the second-level domain name in the domain name are different, determine that the URL of the web page and the domain name do not match.
4. The method according to claim 1, wherein The obtaining at least one domain name of the target service provider includes: Detect whether the domain name information of the target service provider is cached locally; If the domain name information of the target service provider is cached locally, obtain each domain name indicated by the domain name information of the target service provider; If the domain name information of the target service provider is not cached locally, send a domain name obtaining request to the background server, where the domain name obtaining request indicates the target service provider; Receive and cache locally the domain name information of the target service provider returned by the background server.
5. The method according to claim 1, characterized in that The responding to the trigger operation on the verification code input box in the web page and displaying the verification code in the verification code SMS includes: In response to the trigger operation on the verification code input box in the web page, control to display the verification code in the verification code SMS in the target area of the popped-up system keyboard.
6. The method according to claim 5, characterized in that, In response to the triggering operation on the verification code input box in the web page, rejecting the display of the verification code in the verification code SMS and sending a risk prompt message, including: In response to the triggering operation on the verification code input box in the web page, controlling not to display the verification code in the verification code SMS in the target area of the popped-up system keyboard, and sending a risk prompt message.
7. A verification code display device, characterized in that Including: A SMS verification code acquisition unit, configured to acquire the verification code SMS received upon performing a verification code acquisition operation on a web page; A target service provider determination unit, configured to determine the target service provider that sent the verification code SMS; A source judgment unit, configured to determine whether the web page comes from the target service provider according to the URL of the web page; A first display unit, configured to, if the web page comes from the target service provider, in response to the triggering operation on the verification code input box in the web page, display the verification code in the verification code SMS; A second display unit, configured to, if the web page does not come from the target service provider, in response to the triggering operation on the verification code input box in the web page, reject the display of the verification code in the verification code SMS and send a risk prompt message, where the risk prompt message indicates that the website to which the web page belongs is a risky website; Wherein, the source judgment unit includes: A domain name acquisition unit, configured to acquire at least one domain name of the target service provider; A matching unit, configured to determine whether there is a domain name in the at least one domain name that matches the URL of the web page; A first source determination unit, configured to, if there is a domain name in the at least one domain name that matches the URL of the web page, determine that the web page comes from the target service provider; A second source determination unit, configured to, if there is no domain name in the at least one domain name that matches the URL of the web page, determine that the web page does not come from the target service provider.
8. The device according to claim 7, characterized in that, The target service provider determination unit includes: A sending number determination unit, configured to determine the sending number of the verification code SMS; A query unit, configured to query from a pre-set number library the service provider that owns the sending number; A SMS content intercepting unit, configured to, if the service provider that owns the sending number is not queried from the number library, intercept the target SMS content that conforms to a pre-set text format from the verification code SMS; A target service provider determination unit, configured to determine the service provider represented by the target SMS content.
9. The device according to claim 7, characterized in that, The matching unit includes: A top-level domain name judgment unit, configured to judge whether the top-level domain name in the URL of the web page is the same as the top-level domain name in the domain name; A second-level domain name judgment unit, configured to, if the top-level domain name in the URL of the web page is the same as the top-level domain name in the domain name, judge whether the second-level domain name in the URL of the web page is the same as the second-level domain name in the domain name; A first determination unit, configured to, if the second-level domain name in the URL of the web page is the same as the second-level domain name in the domain name, determine that the URL of the web page and the domain name match; A second determination unit, configured to determine that the URL of the web page does not match the domain name if the top-level domain name in the URL of the web page is different from the top-level domain name in the domain name / the second-level domain name in the URL of the web page is different from the second-level domain name in the domain name.
10. The device according to claim 7, characterized in that, The domain name acquisition unit includes: A domain name information monitoring unit, configured to detect whether the domain name information of the target service provider is cached locally; An acquisition unit, configured to acquire each domain name indicated by the domain name information of the target service provider if the domain name information of the target service provider is cached locally; A request sending unit, configured to send a domain name acquisition request to the background server if the domain name information of the target service provider is not cached locally, where the domain name acquisition request indicates the target service provider; A caching unit, configured to receive and cache locally the domain name information of the target service provider returned by the background server.
11. The device according to claim 7, characterized in that The first display unit is specifically configured to: In response to a trigger operation on the verification code input box in the web page, control to display the verification code in the verification code SMS in the target area of the popped-up system keyboard.
12. The device according to claim 11, characterized in that, The second display unit is specifically configured to: In response to a trigger operation on the verification code input box in the web page, control not to display the verification code in the verification code SMS in the target area of the popped-up system keyboard, and issue a risk prompt message.
13. A computer device, characterized in that, It includes: A processor and a memory, where the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; The memory is configured to store a program, and the program is used to implement the verification code display method according to any one of claims 1-6.
14. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and the computer program is loaded and executed by a processor to implement the steps of the verification code display method according to any one of claims 1-6.
15. A computer program product, characterized in that, The computer program product includes computer instructions, and the processor of the computer device executes the computer instructions, so that the computer device executes the verification code display method according to any one of claims 1-6.
Citation Information
Patent Citations
Verification code short message processing method and terminal
CN107666469A