Communication and payment device and method for preventing telecommunication fraud
By using the ZAPP system and anti-fraud devices, combined with voice verification, video calls, and location verification, the problem of insufficient information communication in telecommunications fraud has been solved. It enables comprehensive verification of both the initiator and the recipient, improves the security of communication and payment, and reduces system costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANJING ZHENSHENG BIYING TECHNOLOGY DEVELOPMENT CO LTD
- Filing Date
- 2026-01-27
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies are insufficient to effectively prevent telecommunications fraud, especially fraudulent activities. Furthermore, the lack of cross-bank communication capabilities in communication and payment systems leads to inadequate information exchange, making it difficult to determine the identity and location of the initiator, thus increasing the success rate of fraud.
By adopting the ZAPP system, which combines client and APP, and using voice authentication, video calls, location verification and encryption technology, it can achieve comprehensive verification of the initiator and the payee. It also adds authentication agencies, uses anti-fraud devices and anti-fraud kiosks to verify the operator's location and identity, thereby improving the security of communication and payment.
It effectively prevents telecommunications fraud, reduces unauthorized transactions, improves the legality and authenticity of transactions, reduces the system's manufacturing and maintenance costs, and enhances the security of payment and communication.
Smart Images

Figure CN121908271A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a communication device and a corresponding payment method for preventing telecommunications fraud (hereinafter referred to as "telecom fraud"), and involves cryptographic technology, electronic technology, communication technology, etc. Background Technology
[0002] AI face-swapping and voice-swapping are becoming increasingly common, posing one of the biggest threats to artificial intelligence. OpenAI can now generate speech that is highly similar to the voice of the person recording the audio with just 15 seconds of audio clip, making it impossible to guarantee safety with previous technologies alone.
[0003] People are now accustomed to remotely operating devices directly via mobile phones, but many messages sent from afar are difficult to verify. IP addresses can also be easily modified, making it entirely possible to misidentify someone based solely on their IP address. Furthermore, QQ accounts can now be registered anonymously, and many apps allow anonymous registration and use; relying solely on a username may not be sufficient to determine the true owner's identity, and usernames are easily impersonated.
[0004] Traditionally, it's difficult to determine the caller's location when making phone calls. Theoretically, voice chat apps could also add location sharing functionality, but software that alters location information is now commonplace, so simply relying on the phone's location services is insufficient. Summary of the Invention
[0005] This invention aims to prevent telecommunications fraud by improving the security of communication and payment; in addition, it also reduces the manufacturing and maintenance costs of the system.
[0006] Many people believe that improving the security of payment technology is enough to prevent telecom fraud, but this is not the case. When someone acts as a third-party money transfer agent, their bank card number, name, ID card, social media accounts, and passwords are all their own. During verification, nothing seems amiss, making this type of behavior extremely difficult to prevent. This type of fraud, where the actual operator of the account is the same as the nominal owner, is referred to as "self-operated account behavior." Because the operator may not necessarily have the intent to commit fraud (being exploited), it is simply called "behavior." Self-operated account behavior is not uncommon in telecom fraud. Fraudulent behavior, where the actual operator of the account is different from the nominal owner, is referred to as "other-operated account behavior," which is even more common.
[0007] Traditional payment methods were designed for banks and payment platforms, so people only focused on improving payment security from the payment perspective, without considering ways to ensure security and prevent fraud outside of the payment process itself. However, while banks can accurately transfer money to criminals and prevent impersonation, solely relying on payment technology doesn't guarantee the legality and authenticity of the transaction itself. Improvements in communication methods can close this loophole.
[0008] Of course, if perpetrators use malware or similar methods to gain a thorough understanding of the facts related to the victim, they can create a more convincing scam. However, this is quite difficult and therefore not common. In the past, there have been some scams using counterfeit cultural relics, which involve physical objects, but these are less frequent, as scams involving physical objects are more difficult to execute. Therefore, as long as we reveal relatively "complete" relevant information, perpetrators will have virtually no chance of succeeding; this is one of the "essences" of our method.
[0009] Communication methods can effectively cut off the first link in telecommunications fraud, thus preventing the vast majority of scams. Moreover, many owners of second-level, third-level, and so on accounts are ordinary, even innocent, people, so communicating with them will yield truthful answers.
[0010] Previously, bank accounts, Alipay accounts, Douyin accounts, social media accounts, etc., were all referred to as "accounts." Generally speaking, they are all identifiers, but their functions and meanings differ. In this article, payment and communication are two distinct functions. To avoid confusion, the following will refer to bank accounts, bank card numbers, Alipay accounts, and other identifiers used for payment as "payment accounts," or simply "accounts." Meanwhile, social media accounts, phone numbers, and other identifiers used for communication will be referred to as "usernames," or simply "names," and not as "accounts."
[0011] Almost all successful scams are caused by victims not carefully verifying relevant information. Therefore, to effectively prevent telecommunications fraud, we need to improve the convenience of verification and identification, and also try to increase the automation of identification. However, there is still a lot of work to be done in this regard.
[0012] In the past, banks often only had some knowledge of the payer and payee in payment transactions, knowing very little about the organizers or their affiliated organizations. Relying solely on a single bank (executing payment instructions) was insufficient to effectively prevent telecom fraud. Inter-bank communication capabilities were necessary to achieve this. Therefore, we need a dedicated system for verifying the authenticity of transactions, possessing both social and payment functions. This system is hereinafter referred to as ZAPP (Z being the first letter of "dedicated" in Chinese pinyin). Its server is hereinafter referred to as the "platform"; dedicated software (hereinafter referred to as the "client," usually a PC) is installed on computers and other devices within organizations to complete operations, while a dedicated app is installed on individuals' mobile phones to complete operations. The user's username in the ZAPP system is hereinafter referred to as the "user's username in the system." ZAPP, simply put, is a "large-scale OA system," involving a very wide range of people, not just those within a single organization. Furthermore, it incorporates numerous security measures and utilizes many new technologies; previously, there was no such dedicated "OA system" for preventing telecom fraud.
[0013] In the past, many people believed that preventing telecom fraud only required improving payment technology. However, it's difficult for a single bank to determine the authenticity of a transaction. Many also believe that communication methods (using social media) don't play a crucial role in fraud prevention; phone calls and chats don't significantly impact payment security. This is incorrect. People have often underestimated the importance of communication methods in ensuring payment security. It's crucial to understand that the receiving account (the primary account) to which the perpetrator requests transfers is often the most critical. If the fraud is detected early, all subsequent methods (multiple transfers, withdrawals, etc.) become ineffective. Therefore, the receiving account used by perpetrators is often a legitimate business or personal account, usually one the perpetrator hasn't used before. Many assume that the direct recipient of the transfer (the nominal owner of the account, the cardholder) is the perpetrator, but this is often not the case. The victim and the owner of the primary account are usually able to communicate normally. This breaks with many people's perceptions. Previously, people often assumed that the owner of a Level 1 account (the cardholder) was a criminal, and that communicating with them would yield no truthful or reliable answers, thus discouraging such interactions. However, through normal communication, it's possible to uncover the truth and avoid being scammed. If the victim says they want to transfer money to a "safe account," the recipient might realize something is wrong. Such communication was often impossible in the past.
[0014] In the past, there was often a lack of communication between the parties involved in payment, which is one of the key reasons why fraud can succeed. It is short-sighted to only prevent fraud by focusing on payment technology. We should also find ways to prevent fraud by improving communication methods.
[0015] In every case, there are not only victims and recipients, but also usually organizers and initiators. In ZAPP, the initiator is required to fill in the information for every transaction, making it difficult for them to conceal their identity or the facts. If the initiator refuses to use ZAPP, it's almost certain they are a violator, and you can usually refuse directly. In previous payment methods, the initiator could go unrecorded. This lack of process gave violators an opportunity, while a robust communication method and processing procedure can close this loophole.
[0016] Verifying the authenticity of a transaction solely against the recipient is often insufficient; the initiator must also be investigated. Perpetrators rarely send part-time workers to make calls, as ordinary conversation is usually insufficient to entice the recipient to pay. There are many techniques and tricks involved. Information that exposes a scam typically only appears in conversations and communications with the initiator. These details may not be directly related to the payment process, and anomalies may not be detectable from payment information alone. This point (this pattern) is crucial, highlighting that one of the key aspects of preventing telecom fraud should be communication. Preventing fraud through communication primarily requires verifying communications with the initiator. Previously, the importance of verifying this aspect has not been recognized, and the crucial element has been missed. Strictly verifying only the recipient is insufficient and often misses the mark.
[0017] The reason given for the transfer should be clear enough for others to make an accurate judgment about the background and consequences of the transfer; otherwise, the effectiveness of the review will be greatly reduced.
[0018] Many people don't understand that verifying a message and verifying payment information are two different things. Payment information consists only of the amount and name, and it's often heavily encrypted. It can be verified using specific keys or other methods. If the verification passes and the account and name match, it can be considered genuine. Ordinary messages, on the other hand, contain more complex content and often cannot be verified through account and name alone; it's difficult to determine their authenticity based solely on the text. Even if ordinary messages are encrypted, they are usually simpler, making them more susceptible to forgery. Having the payer and payee verify the message (including through direct communication) is a simple and effective method.
[0019] Previously, measures such as real-name authentication were used to verify callers. However, these measures were only effective for tracing after a fraud occurred, making recovery difficult once losses were incurred. Preventing risks before payment is far more effective. While real-name authentication when purchasing phone cards certainly improves security, the final user of the phone card may not be the purchaser. Previously, there were no strict identity verification measures during calls. Even if the caller was the purchaser of the phone card, the other party would not receive the caller's name or other identity information; they would only see the phone number. Real-name authentication at the time of purchase has very limited security benefits; it is primarily a record-keeping method. The measures mentioned above (establishing a ZAPP verification system, asking random questions, verifying the initiator, verifying two reasons for the transaction, and verifying the receiving entity) are far more effective in ensuring security. Therefore, using ZAPP is a much safer communication method than making phone calls.
[0020] While it's difficult to prevent unauthorized account activity through identity verification, we are not without options. We can add an authentication agency. If users activate this service, the agency can verify the communication between the payer and the initiator, potentially detecting anomalies. This authentication agency is an official body that payers can trust; adding a regulatory body significantly restricts violators. If the initiator refuses to use such an authentication agency, the recipient can hang up immediately and refuse to cooperate, as this is clearly untrustworthy behavior. Legitimate organizations use ZAPP, which allows for simultaneous voice and text transcription, making it easy for authentication agencies to verify using computers. This involves not only recording but also text transcription; furthermore, this method will be referred to as voice authentication. This utilizes technologies like artificial intelligence, which has historically been difficult to monetize, but this presents a promising avenue for profit.
[0021] Another effective method is for users to contact each other via video call. During the call, a "display registered face" function can be added, which can display the initiator's registered face in real time. This way, users can not only check whether the face matches, but the initiator's identity will also be exposed, and they will never be able to escape legal punishment.
[0022] While self-identification cannot be directly prevented or stopped through identity verification, it can be traced and held accountable through identity confirmation, thus preventing it indirectly. However, if the initiator uses their own username to communicate with the payer from abroad, the above methods are ineffective; although we can confirm the initiator's identity, we cannot hold them accountable. Self-identification can be further categorized based on the object: initiator using their own username for communication, hereinafter referred to as initiator self-identification, which is usually more crucial. Payee using their own account, hereinafter referred to as payee self-identification, which includes receiving payments, transferring funds, etc.
[0023] In the past, those in the electronic payment field often only verified the payee and payee, neglecting to verify the initiator. People habitually believed that even verifying with the initiator was insufficient to determine authenticity. However, to effectively prevent fraud, we must broaden our perspective beyond the narrow focus on payees and payees. This shift in mindset will lead to a historic revolution in electronic payment technology. Payment technology will move from simply verifying the payee and payee to a more comprehensive verification process that also includes verifying the initiator and the reason for the transaction. These methods are unprecedented and fundamentally different from previous verification methods; they will be referred to as "authentication methods" below. For clarity, I will refer to this more comprehensive verification of the initiator, the reason for the transaction, and the content of the communication as "authenticated payment," while payment that only verifies the payee and payee will be referred to as "unauthenticated payment."
[0024] The aforementioned communication methods have proven effective in verifying the authenticity of business transactions, but they are far from sufficient. Previously, it was believed that accurate identity verification was sufficient to prevent telecommunications fraud; however, these methods are useless if perpetrators use their own names, bank cards, etc., to commit fraud.
[0025] Self-proclaimed accounts are quite common. Directly checking the receiving account, name, etc., may not reveal any issues. Even checking the phone number used by the initiator (organizer) or the WeChat nickname used to send messages might not uncover anything (the number could have been changed using number spoofing software, and the nickname could also have been altered). As identity verification technology advances, it becomes much harder for criminals to impersonate others, while using their own accounts makes it easier to pass verification, but this exposes their identity and makes them easier to trace.
[0026] In the past, it was difficult to determine the caller's location when making a phone call, and simply relying on the phone's location function was insufficient.
[0027] To address this, we can establish a device capable of verifying the operator's location, hereinafter referred to as an "anti-fraud device" or simply "anti-fraud device." This device also includes encryption, decryption, and communication functions. While traditional payment and communication devices often possess encryption and decryption capabilities, location verification is a previously uncommon feature. This type of communication and payment system capable of verifying the operator's location is collectively referred to as an "anti-fraud system," encompassing not only the anti-fraud device but also the platform and the operator's mobile phone. The aforementioned ZAPP, client applications, and apps can also incorporate location verification functionality to enhance security. Previously, people used methods such as password verification to confirm identity and encryption to ensure the immutability of transmitted text, but these methods are insufficient to completely prevent telecommunications fraud. Location verification significantly improves security.
[0028] The security requirements for anti-fraud devices used by employees of organizations and government agencies (hereinafter referred to as "customer service") differ from those for personal use. Organizational anti-fraud devices have higher security requirements, while personal anti-fraud devices have lower requirements. This is because individuals are less likely to defraud organizations, while organizations are more likely to defraud individuals. Therefore, organizational anti-fraud devices typically need to be more comprehensive, while personal anti-fraud devices can usually be simpler. To promote the use of anti-fraud devices, devices in ordinary locations can be simplified to reduce costs. For public convenience, public anti-fraud devices, hereinafter referred to as "anti-fraud kiosks," can also be set up. These kiosks not only have communication equipment and cameras but also gyroscopes, encryption devices, etc. Genuine ZAPP and other similar software can be installed on the devices (unauthorized software installation is not allowed), enabling calls and various electronic operations. Anti-fraud kiosks can also be equipped with security doors, so that if someone inside is identified as a criminal, the door will be locked, preventing escape. Anti-fraud devices can provide location information, which plays a crucial role in preventing telecommunications fraud. When dealing with important matters (such as calls involving large transfers or signing loan contracts), we can ask the other party to use the company's anti-fraud device for making and operating the call.
[0029] Location verification calls, hereinafter referred to as "location verification calls," are crucial for security. Verifying whether a caller is located abroad can prevent a significant portion of scams. Even domestically, location verification greatly enhances security. Verifying location during a call reliably identifies the caller. Dedicated verification devices can be installed in legitimate workplaces (specific locations) to accurately indicate location, preventing perpetrators from bypassing these verifications. Verifying the sending location of text messages and notifications also significantly improves security, as perpetrators cannot bypass these verifications—an importance previously unrecognized.
[0030] Location verification during payment is also crucial. This type of payment, hereinafter referred to as "location-verified payment," is a new payment method that doesn't typically use location as a verification condition. For individuals, we usually require setting a specific payment location for each bank card and payment account, usually at home or work. For businesses, the same applies; a specific payment location must be set for each bank card and payment account, usually at the office. Agreements must be made not only with the bank but also with the platform. If only with the bank, the platform cannot verify the location. Most individuals are comfortable with transactions at their workplace, home, or nearby anti-fraud kiosks, and a slight delay in receiving payment is usually acceptable. Workplaces usually have staff on-site, allowing for transactions to be completed there. In rare cases where the person is out of town, a colleague can handle the transaction, or the anti-fraud device can be remotely controlled; our methods are sufficient to ensure the security of communication and payment. Location verification is extremely important. First, if the platform detects that the user is operating the app from abroad, it can immediately terminate the payment process, as this strongly suggests that criminals are transferring illicit funds. Furthermore, if the verification device is located in the office or home, it is usually inaccessible to offenders; they cannot even enter the premises. Therefore, location verification can significantly improve the accuracy of identity verification and can also serve as supporting evidence. This type of payment operation requires manual connection of the mobile phone to a location tag. If an adversary approaches the location tag, they will be in close proximity to the genuine user, allowing the user to detect unauthorized operations against their will. Therefore, the security is very high.
[0031] In the past, the recipient did not need to confirm the payment. As long as the bank deemed the request made by the payer to be legitimate, the funds would be transferred to the recipient's account.
[0032] Anti-fraud devices may include the following components: a processing device (desktop computer, mobile phone, tablet computer, etc.), a device for detecting location or changes in location (hereinafter referred to as "location detection device"), a chip for verifying location (hereinafter referred to as "location transponder," or simply "transponder"), a communication device (including microphone, speaker, camera, display, etc.), and a protection component (a device to prevent escape by violators, such as a security door, which may not be included in ordinary anti-fraud devices). The device and system composed of the location detection device and transponder, hereinafter referred to as the location verification device (location verification system), is a system used to verify location, and its meaning is different from that of (GPS, BeiDou) positioning systems. To improve security, we have added a chip (hereinafter referred to as "mobile phone encryption card") during communication to provide the mobile phone with an encryption key. It is similar to a SIM card and can be inserted into another card slot in the mobile phone. It is issued by the platform to provide the mobile phone with the encryption key. A brief introduction follows.
[0033] The simplest method of location tracking is to install a client application on a desktop computer. Desktop computers are bulky, often connected to multiple cables, and cannot be carried around, especially on public transport like buses and subways. They are typically located in offices or homes, making them difficult for attackers to access. They are also not easily moved, and their location is usually fixed. Alternatively, location information can be provided by the user's smartphone. Although smartphone location information is unreliable and can be altered using emulation, it's better than nothing and is generally more secure, which is crucial for protecting the payer. For the payee, we usually require the use of more secure devices. For individuals receiving wages, they can operate at their workplace or at a nearby anti-fraud kiosk. If they must receive funds at home, they can use the same mobile phone to verify their location multiple times (at least three days) at the same location to prove it's their identity; it's difficult for others to be at the same location every day. Purchasing more secure location verification devices costs money and is not easy to widely promote initially. In this situation, using simple devices is very beneficial for protecting ordinary people. Although its security is not high, for ordinary people, having such protection is certainly better than nothing, and much better. Previous payment processes lacked location verification measures. The system can also display the type of location verification device used by the other party, such as showing that the other party is only verifying their location using a mobile phone. For cases where only a mobile phone is used, the system can also issue a warning: the other party's verification device is simple, the security risk is high, please verify the situation carefully. If the other party only uses a mobile phone to verify their location, it is obviously untrustworthy. Moreover, even if simulated location information is used, changing the location to the location of a certain unit, verification will still fail because we use a transponder to send a specific authentication code to indicate the location; simply submitting the location will not pass verification.
[0034] The above methods have poor reliability. The simplest positioning device determines whether the position has changed by checking the continuity of a detection circuit fixed to the anchor. This is referred to as a circuit breaker. The detection circuit is connected to a transponder, which performs the judgment. Anti-fraud kiosks can use this simpler positioning device, which is a positioning expansion pin (hereinafter referred to as a positioning expansion pin). It may contain one transponder and a detection circuit inside the expansion tube. A contact of this circuit protrudes from the end of the expansion tube. The circuit and the screw are connected to the transponder, which is located outside the expansion tube and screw. This expansion pin is directly installed on anchors such as the ground or wall. After installation, the detection circuit is active. If the circuit is active, the position is determined not to have changed. If someone attempts to remove the screw, the detection circuit will be interrupted. The transponder detects this interruption, determines that the position has changed, and stops working. See [link to relevant documentation]. Figure 1Of course, the transponder can also be installed in a computer or other device instead of inside the expansion pin. To improve security, a two-component hardening adhesive can be applied to the outside of the expansion tube during installation, making it impossible to remove later. Furthermore, there are various styles of location verification devices. The processing device can be the main unit of the anti-fraud kiosk, a desktop computer in the unit, or a user's mobile phone, etc., and is connected to the location verification device. During operation, the processing device sends a request to the transponder to verify the location (hereinafter referred to as "request"), and the transponder returns a certain key; the processing device uses the received key to generate an authentication code representing the location (hereinafter referred to as "location authentication code") and sends it to the platform. Such computers and mobile phones need to have dedicated client software or mobile apps installed for communication between customer service and users, and between users. To prevent face-swapping and voice-swapping fraud, microphones, cameras, etc., can be protected with casings to prevent perpetrators from replacing audio cables, video cables, etc.
[0035] In the past, people often focused on improving payment security by addressing the technology itself. However, communication technology is also closely related to telecom fraud. Victims often receive deceptive calls, text messages, and other malicious messages through unreliable communication methods before making electronic payments. Therefore, improving communication security is also a crucial means of preventing telecom fraud. Verification of the sender's location is referred to as "location verification message." Location verification devices are used for both calls and payments, playing a vital role in both processes. Furthermore, during the transaction verification process, we send payment-related messages. Ordinary communication methods are insufficient to determine whether the sender is located abroad, making location verification essential. Currently, perpetrators often use GOIP devices to disguise overseas calls as local calls. With anti-fraud devices, the caller needs to send a location verification code, preventing perpetrators from spoofing the sender's location.
[0036] Large organizations can install anti-fraud devices within their premises for operational convenience. For ordinary citizens, public anti-fraud devices can be installed (in places like banks). This ensures accurate location information (preventing location spoofing) and reliable communication facilities (effectively preventing AI face-swapping, voice-swapping, and fake apps). Large organizations should generally install anti-fraud devices. If someone claims they are out on business and cannot use the device to send messages, you can reply: "Have a colleague send it." Large organizations would not be without staff on-site; this excuse is invalid. If the other party cannot find anyone to send the message, their claim is false. Scams targeting "so-called large organizations" are a common type of fraud because small organizations are difficult to deceive. Furthermore, we have remote operation methods, such as remote use of transponders, rendering this excuse untenable. Elderly people often find it difficult to stop scams; reliable communication methods can be used to verify the purpose of transfers. Anti-fraud kiosks are very effective in preventing these scams, making their installation in banks worthwhile.
[0037] Some organizations (including customer service centers) have a large number of employees. If anti-fraud devices are used, operators must physically go to the location of the transponder, which is inefficient. To address this, a local area network (LAN) can be set up: the transponder is located at the server's location. Each employee can use their workstation (desktop computer) to send a request to the server via the LAN and then use the transponder to complete the operation. This way, each employee can operate the device without going to the transponder's location, improving efficiency. Furthermore, encrypted data transmission between the workstation and the server ensures security. Typically, one organization can use only one transponder; however, multiple transponders can be used when there are many employees or offices are far apart.
[0038] The following details the different positioning devices. Positioning devices can be integrated with processing devices (such as desktop computers), hereinafter referred to as "integrated positioning devices." For example, a positioning expansion pin connects to the computer, sending a position authentication key to the computer, which then generates a position authentication code and sends it to the platform. However, in this case, the processing device must operate continuously; otherwise, if an adversary moves the device while the device is off, the platform will not detect it. This not only wastes electricity but also risks damaging the computer. Alternatively, the positioning device can be separated from the processing device, hereinafter referred to as "separate positioning devices." In this case, a positioning expansion pin alone is insufficient; a device that maintains constant communication with the platform, hereinafter referred to as a "connector," is also required. This can be a standalone device, or in the future, it can be integrated with routers, optical modems, etc., to reduce overall costs. Even after the computer is off, the connector continues to operate, continuously sending signals to the platform (at a specific frequency); this saves electricity and extends the lifespan of the processing device. While integrated positioning devices require less initial investment, the total cost is higher in the long run. In the future, most users will likely use separate location verification devices. When a user makes a payment or makes a call, the device sends a request to the transponder (to prevent attacks, the request may include a specific password, which is common practice and will not be described further). After verifying the request, the transponder sends a location authentication key to the serving device, which then generates a location authentication code. When the user is not making a payment or making a call, the serving device may be powered off, and the transponder may not be able to generate a location authentication code from it. Therefore, the transponder should generate the location authentication code and send it to the platform. In a combined location verification device, the transponder can simply send the location authentication key, which is simpler, easier to design, and lower in cost. However, since separate location verification devices will be used in most cases in the future, for consistency, the transponder's function in a combined location verification device should also be consistent.
[0039] A location verification device may serve not just one device, but multiple devices. A location verification system that serves multiple devices is hereinafter referred to as a multi-device location verification system (device); while a location verification system that serves one device is hereinafter referred to as a single-device location verification device (system). The entirety of a multi-device location verification system and the devices it serves is hereinafter referred to as a "multi-device anti-fraud system," see [link to relevant documentation]. Figure 2 The standalone location verification device and the equipment it serves (servers, mobile phones, etc.) together form the "standalone anti-fraud system," see [link to documentation]. Figure 3The platform needs to serve multiple multi-machine and single-machine anti-fraud systems. Most multi-machine anti-fraud systems are in fixed locations, such as a customer service center with many customer service representatives. Installing an independent location verification device for each computer (workstation) is costly and inconvenient to manage. To address this, a local area network (LAN) (system) can be set up to monitor the movement of each desktop computer. This LAN includes not only the server and workstations but also a transponder (connected to the internet via a modem). The transponder is located at the server's location and connected to it. Its location verification system can serve multiple computers within the same area. Only the transponder is always powered on and continuously sends signals to the platform (indicating normal or abnormal operation) at a specific frequency, such as once per second. Each computer (including the server) can be shut down at any time, significantly reducing the overall cost of monitoring and saving electricity while protecting equipment. A single transponder can be installed (within the transponder), resulting in lower equipment costs and easier security assurance.
[0040] The simplest method is to drill holes in the casing (inside) of each workstation, install a detection device (such as a positioning expansion pin), fix the detection device to a desktop or other location, and then connect them in series to a communicator. The communicator continuously monitors for circuit interruptions. If a circuit interruption is detected, it sends a notification to the monitoring personnel and the monitoring system. Upon receiving the notification, the personnel check the situation and promptly stop the movement of equipment. However, this only indicates that equipment has shifted within the monitored area, but not its location. Checking each device individually would be labor-intensive, inefficient, and slow. To address this, a device (hereinafter referred to as a "notifier") can be installed on each detection device to report the detection results to the communicator. A communication line can be set up to connect the device to the communicator. Each "notifier" that detects shifting equipment at its location reports its location (which can be an IP address) to the communicator. Even if it does not detect shifting equipment at its location, it still needs to report the information. Otherwise, if the device malfunctions and cannot send a notification, the communicator may mistakenly assume that no abnormality has occurred. The communicator then reports to the platform, which, upon receiving the notification, suspends the device's usage license. If the computer is currently operating, the communicator can directly send a signal to the computer to stop the client from working; the communicator can also send a signal to the computer via the local area network to stop the client from working. Upon receiving the notification, on-duty personnel will check the location and promptly stop the relocation of the mobile device. The clients running on the server and workstations are different; for distinction, the client running on the server will be hereinafter referred to as the primary client, and the client running on the workstation will be hereinafter referred to as the secondary client. The client installed in the standalone anti-fraud system will be hereinafter referred to as the independent client. If an adversary steals a workstation from the local area network and installs a jump server in its original location, using the jump server to relay information, it may be possible to send information to the server from a distance. It is also possible to use other workstations (as jump servers) to send information to the server through other ports. Although this is more difficult, it is theoretically feasible.
[0041] In the past, people were accustomed to using surveillance systems to prevent theft, computer tampering, and other illegal activities. However, surveillance systems are expensive to install and maintain, and require human monitoring. Often, the personnel on duty are distracted, rendering the surveillance system ineffective in the short term. Furthermore, adversaries can attack surveillance systems by replacing video cables, inputting false video signals, or playing fake videos in front of cameras to deceive them. Installing location detection devices, on the other hand, offers low equipment and maintenance costs and allows for immediate response, making it a superior solution. With these devices, surveillance systems can be reduced or eliminated altogether. The transponder at the communicator in a multi-machine location detection device is a core component requiring careful protection, such as a dedicated protective shield. It also has a dedicated location detection device to check for position changes. While its function differs from the workstation's location detection device (though the structure can be similar), it determines the overall system position and is therefore crucial. If the location detection device at a workstation detects a change in position, it will only cause that workstation to stop working normally; however, if the location detection device at the connector detects a change in position, it will cause the server and all workstations to stop working normally. Furthermore, anti-fraud kiosks can also serve multiple people through multiple fixtures, and the situation is different there; see below.
[0042] Sometimes, workstations are used only to provide services to specific users, such as accountants working only in the accounting office. In these cases, the workstation and username have a fixed relationship, which can add restrictions to identity verification. If the location reported by the workstation's notification device changes, the workstation will stop working normally, and the username will also be unable to verify the location. The platform must also be notified that the workstation has stopped working normally. However, usually, for the convenience of users, the relationship between workstations and usernames can be flexible. Users can verify their location at any workstation, and the cessation of work at one workstation will not cause a username to be unable to verify its location.
[0043] The location authentication code sent by the server to the platform after receiving a legitimate request serves a different purpose than the location authentication code typically used by the liaison in normal messages. For clarity, the liaison sends a normal location authentication code (hereinafter referred to as the security location authentication code) to the platform when it has not detected a change in location indicated by a tracking device. The location authentication code sent by the server after receiving a legitimate request is referred to as the working location authentication code. The simplest method is to establish a specific flag to distinguish between the working and security location authentication codes. Even if all workstations cease normal operation, the server remains usable, so there is no need for the liaison to report its impending cessation of normal operation.
[0044] If the location verification device is fixed, it is easy to implement and ensure security, with low manufacturing and maintenance costs. However, if the location verification device is mobile, it is more difficult to implement and can be achieved using gyroscopes, satellite positioning chips, etc. (see below). Anti-fraud devices are divided into two categories based on whether the location detection device is fixed: fixed anti-fraud devices and mobile anti-fraud devices. Mobile anti-fraud devices have higher manufacturing and maintenance costs but can meet some special needs. The location detection function is the core function of an anti-fraud device, and there are various ways to implement it:
[0045] One type of scam involves perpetrators posing as employees to defraud victims. They might instruct the victim to go to a secluded location like a restaurant to prevent others from learning about the situation and to prevent relatives or others from blocking the transfer. For this type of scam, verifying the payer's location (their home or the agreed-upon payment location) is a very effective technical measure; the payment cannot be completed if the location is changed. However, it's impractical for ordinary people to purchase expensive anti-fraud devices. The easiest way to implement this is for them to install ZAPP on their mobile phones or desktop computers. Although inexpensive, this is very effective and can protect most people. Strict location verification is primarily for the recipient, who should typically use a more secure verification device.
[0046] Of course, users should be allowed to change their verification location due to relocation, hospitalization, or travel, but with corresponding restrictions. For example, moving to a hotel or similar location should be prohibited, and a reason for the change must be submitted, with an effective timeframe of at least one day, and supporting documents such as a property ownership certificate required. Changing employers requires an employment contract, which must match the employer's verification information. Friends and family should also be notified of the location change so they are aware if they are scammed. Furthermore, monitoring should be strengthened after a location change, with strict controls on transfers made in the short period following the change. In cases like hospitalization, friends or family can verify the location on behalf of the user, but only with the user's permission can someone else perform the verification. These measures can only be implemented after the technical measures for location verification are in place.
[0047] Positioning expansion pins use the continuity of electrical circuits to determine if the location has changed; they are essentially circuit-breaking devices, and there are many types of circuit-breaking devices. The transponder in an anti-fraud kiosk is sealed within the anti-fraud device itself, which is fixed to the ground using positioning expansion pins. The device continuously monitors its position for changes and whether its connection to the ground has been compromised. If the device's position remains unchanged and its connection to the ground is intact, the device operates normally and sends a message to the platform indicating normal operation. If the device's position changes and its connection to the ground is compromised, the device stops operating normally and sends a message to the platform indicating the change in position. When the device is operating normally, it uses the key provided by the transponder to encrypt transaction data and send it to the platform. It also uses the key provided by the transponder to generate a password and send it to the platform. This allows the platform to confirm that the anti-fraud device is operating normally, that the device has not moved, and that the corresponding transaction data was sent from the device at that location. Anti-fraud devices do not need to directly transmit their location information (such as coordinates) in plaintext or ciphertext. As long as the device indicates it is functioning normally, its location is definite. The platform stores the device's location information (such as coordinates) in advance, which is indirectly carried by the device's serial number. Theoretically, the transponder itself cannot guarantee accurate location information. If an adversary steals the transponder and uses it elsewhere, the system will have difficulty distinguishing its authenticity. However, the transponder is sealed within the device, making it difficult for an adversary to steal and move it. Therefore, offline methods can ensure accurate location information. This method of ensuring accurate location information has never been used before. While computers and mobile phones may be turned off and on daily, anti-fraud devices, unlike ordinary devices, typically require continuous monitoring. During periods when the device is off, it may be tampered with.
[0048] Many anti-fraud devices (anti-fraud kiosks, unit anti-fraud devices, etc.) are fixed. If they indicate their location to the platform, they directly send a "location authentication code," meaning the transponder sends the "location authentication code" to the client, and the client then forwards the location authentication code to the platform. This method is relatively simple, and criminals can easily intercept it and send it elsewhere (using another client). A more secure method is for the transponder to only send a key, which a specific client then uses to generate an authentication code. This key, hereinafter referred to as the "location authentication key," is the key used to generate the location authentication code. If the transponder detects that the detection circuit is conducting and is working normally, it returns one location authentication key to a legitimate request. If the detection circuit is not conducting, it stops working normally and does not return a location authentication key to a received request, or returns a response indicating an abnormal status. The same transponder may be used by multiple people. To distinguish users, a personal APP can be used to send a key to the client (hereinafter referred to as the "personal key," which can be generated first by the mobile phone encryption card and then encrypted by the APP) to generate the location authentication code. Unless direct mobile phone communication is used, it is not necessary to use a personal APP to upload the personal key to the client. This identification code also includes information about the transponder and the personal app, and it is dynamic, making it difficult for adversaries to counterfeit.
[0049] The transponder in an anti-fraud kiosk is enclosed within its outer shell, making security relatively easy. However, an organization's anti-fraud system might simply be used to secure and protect existing computers, without requiring a large space. To ensure security (preventing movement) while minimizing space usage and facilitating operation, the transponder needs to be fixed to the wall or floor using expansion bolts. These expansion bolts are hereinafter referred to as "embedded expansion bolts." See [link to documentation]. Figure 4 An embedded expansion pin transponder, located inside a screw or expansion tube, detects changes in the expansion pin's position. This transponder connects to the equipment it serves to send a signal. To prevent removal, two detection components (hereinafter referred to as detection plates) are located outside the screw and expansion tube, each containing a thin wire (easily broken under stress), connected to a chip inside the screw. During installation, holes are drilled, and a two-component hardening adhesive is applied to both the outside and inside of the expansion tube (i.e., outside the screw). The transponder is then inserted. After installation, the adhesive hardens. If someone attempts to pull out the expansion tube, the wire in the detection plate outside the expansion tube will break; if someone attempts to rotate the screw, the wire in the detection plate outside the screw will break. The transponder, detecting the broken wire in the detection plate, stops operating.
[0050] For companies that do not frequently communicate with individual consumers and have lower security requirements, a simpler positioning device (hereinafter referred to as "positioning sticker") can be used: it includes a mounting plate, a protective cover, and a transponder located on the mounting plate; the external interface of the transponder is located on the protective cover; there is a wiring connection between the transponder and the interface. Both the mounting plate and the protective cover have adhesive backing for attaching to walls or tables; to prevent damage from impacts, the protective cover is best secured to the wall or table using expansion bolts, screws, etc. See [link to relevant documentation]. Figure 5 To prevent people from moving the positioning sticker, the following detection circuit can be used (see...). Figure 6 It consists of multiple irregularly shaped and positioned wires that cross the edges between the fixing plate and the protective cover. These wires are thin and easily broken under stress. All wires are connected to the transponder. If someone moves the positioning sticker, the wires between the fixing plate and the protective cover will break, and the transponder will stop working upon detecting the broken wires. After the fixing plate and protective cover separate, many broken wire ends are left, making it difficult for people to reassemble them. Using only one wire would make reassembly much easier. The fixing plate can also be made of a less robust material, making it prone to breakage under stress and interrupting the detection circuit. The fixing plate and protective cover are not connected to each other to ensure protection. To make a payment, the mobile phone is connected to the positioning sticker to obtain a location authentication key, generate a location authentication code, and send it to the platform to complete the transaction.
[0051] Using positioning stickers often results in a lack of continuous power supply and signal transmission to the platform, preventing the platform from determining sticker displacement based on signal reception. Furthermore, the system can be integrated within the positioning verification system to prevent enemy movement. This can be achieved by installing a battery and having a transponder continuously monitor the current in the detection circuit. However, transponders consume significant power, necessitating a dedicated chip (hereinafter referred to as the interruption chip) to detect current changes (various methods exist, not limited here). When the detection circuit is damaged, the current drops to zero; the interruption chip detects this and records it. We can define a variable to indicate whether an interruption has occurred (hereinafter referred to as the interruption variable), where 0 indicates an interruption and 1 indicates no interruption. Directly sending 0 or 1 is easily counterfeited. To improve security, the interruption device can pre-set a key to generate dynamic verification values for 0 and 1, sending this to the platform to prevent hacker spoofing.
[0052] After the device is powered on, the transponder sends a query request to the interruption detection chip. The interruption detection chip responds based on the interruption variable. If the interruption detection chip returns a message indicating a previous current interruption (hereinafter referred to as the interruption notification), the transponder enters an abnormal working state; otherwise, it remains in a normal working state and reports a message (including the corresponding checksum) to the platform. This device used to check for current interruption is hereinafter referred to as the interruption detection device. Theoretically, the position detection device also checks for circuit interruptions, but the position detection device checks for current interruption, while the interruption detection device checks for previous interruptions. Typically, a query to the interruption detection device (to check for previous circuit interruptions) is performed during power-on, and a normal shutdown is reported before power-off. Monitoring with the position detection device during power-on is sufficient to ensure safety. If the platform does not receive a normal shutdown notification and does not receive a normal working notification for an extended period, it will consider the device to be in an abnormal state and suspend service. Of course, querying the interruption detection device every time the position is verified would increase security, but this is usually unnecessary. In theory, when conducting actual operations, using a positioning device to issue a verification value can reduce the frequency of issuing security location identification codes, thus lessening the system burden. However, issuing security location identification codes periodically is more reliable.
[0053] Positioning devices that do not have continuous power supply, such as positioning stickers, should typically include a fault detection device. However, positioning devices with continuous power supply can also include a fault detection device. If an adversary moves the positioning device along with the anchor point, the power supply will be interrupted, and the positioning device will lose contact with the platform. Furthermore, power supply may be unexpectedly interrupted. Therefore, the use of a fault detection device is necessary. Fault detection devices can be installed not only at the server but also at the workstation. The fault detection devices at the workstation and server have different functions and are independent of each other. It is possible that a workstation loses power while the server does not. This fault detection device communicates with the communicator via a notification device. If a workstation's fault detection device sends a message indicating a circuit interruption after power-on, the workstation will also report the abnormal information to the communicator. After detecting a circuit interruption, the fault detection device needs to be reset to continue operating and determine whether a power outage has occurred. Having the fault detection device record the time of multiple interruptions would increase costs and reduce reliability, and is therefore not advisable. Resets should not be performed solely by the user, as this makes it easy for adversaries to falsify the data. Relevant evidence should be submitted to the platform, and the platform should issue an authorization signal after review and approval.
[0054] The advantage of the above-mentioned device is its low cost, but adversaries might remove the expansion bolts along with the wall and carry them away. To improve security, the anti-fraud device should ideally use a gyroscope or similar device to detect changes in position. Gyroscopes are familiar to people, and their use for position detection is trusted, but they are expensive and consume more power. Another option is a device containing a sealed container with a certain amount of liquid. Water or alcohol, which are prone to evaporation, can be replaced with a non-volatile liquid such as silicone oil. A buoy, made of lightweight materials like foam plastic, floats on the liquid surface. The buoy's surface has a mirror that reflects light. A transmitter and receiver are mounted above the container, connected to a transponder. When the device is installed and properly adjusted, the transmitter and receiver are at a specific angle. When the container is horizontal and the liquid is still, the receiver can receive light. If the container moves, the buoy will shake, changing the direction of the reflected light, and the receiver will no longer receive light, thus detecting an anomaly. Upon detecting this, the anti-fraud device will report the situation and stop operating. This instrument is hereinafter referred to as a "buoy device." See [link to documentation]. Figure 7 It is even more sensitive than a gyroscope, and can detect even the slightest movement of the buoy. To ensure that the buoy usually stays in the center of the container, a magnet can be placed in the middle of the buoy, and an iron plate can be placed in the middle of the bottom of the container. The magnet and the iron plate have an attraction between them, so the buoy can usually stay in the center position.
[0055] Buoy devices are still relatively expensive; a cheaper alternative (hereinafter referred to as a spring device, see [link]) can be used. Figure 8 The following describes a detection circuit: A spring is installed inside the casing (usually at the bottom) of a device (such as a desktop computer). An inertia bar is attached to the upper end of the spring, and a contact ring is located outside the spring. The contact ring is fixed to the casing by a fixing rod. The spring and fixing rod are connected to a transponder, forming a detection circuit. After the spring is installed, the spring and contact ring are normally not in contact. When the casing moves, the inertia bar, due to inertia, will remain in its original position, causing the spring to contact the contact ring, thus activating the detection circuit. If the transponder detects this activation, it will report the situation and stop operating. The mass of the inertia bar cannot be too large, otherwise it may tip over and cause the spring to contact the contact ring; nor can it be too small, otherwise the instrument's sensitivity will be too low.
[0056] The aforementioned multi-device anti-fraud system serves multiple computers. If serving multiple mobile phones, the situation differs. To reduce costs, one anti-fraud kiosk (host) can serve multiple users in the vicinity, helping them verify their location. The host contains a positioning expansion pin, which should be fixed to an anchor during operation. Multiple temporary location-fixed verification devices (hereinafter referred to as fixers) can be installed around the host, each containing a positioning expansion pin. These fixers are connected to the host via wired or wireless means, allowing only one (kiosk's) transponder to indicate location. Connecting the user's mobile phone to the fixer is more costly. Alternatively, an openable / closable wristband can be used, locking onto the user's wrist after successful authentication. When the detection circuit in each positioning expansion pin is active and the wristband on the user's wrist is closed, the host processes the received location verification request normally; otherwise, it suspends location confirmation. The wristband can be directly connected to the fixer via a wire. After the user's mobile phone sends a request, the anti-fraud kiosk's transponder sends a location authentication key, etc., which is then processed by the anti-fraud kiosk. See [link to relevant documentation]. Figure 9 The wristband can also be directly connected to the main unit via a wire, which is low-cost but can easily trip people up and is inconvenient. The fixed device, on the other hand, can be moved along with the main unit and deployed in residential areas. This system, hereinafter referred to as the fixed device system, serves multiple users and is a multi-device anti-fraud system. However, the relationship between the mobile phone and the fixed device is not as close as that between a computer and a notification device.
[0057] If the anti-fraud device is fixed in location, security is easily guaranteed. However, a movable location can adapt to certain special needs. For example, determining the location of a fixed anti-fraud device during registration is a challenge. Relying on users to upload their own locations is unreliable. We can create a dedicated device to determine its location; this device will be referred to as an "anti-fraud registration device." Satellite positioning is typically used to determine the location. Simulating satellite signals and enabling the device to derive a specific location is technically very difficult and beyond the capabilities of ordinary users. Previous attempts to modify location information involved using simulated location information on ordinary mobile phones. Therefore, we can use a device that cannot use simulated location information to prevent location information from being modified. Of course, satellite signals can be modified (although this is difficult to achieve), and in indoor environments where there is no satellite signal, a gyroscope can be used for inertial navigation to verify the location in demanding situations. Having platform maintenance personnel personally perform the location calibration is labor-intensive and impractical. A courier can deliver the device, use it, and return it after use.
[0058] Remote fraud often involves fabricating reasons, frequently using documents or notices as pretexts. Therefore, we can improve and enhance the security of our notification system to expose scams. This presents a significant opportunity, as there is a substantial potential demand for verifying the authenticity of notifications. Meeting this demand will yield substantial benefits. We can establish a unified "notification system" capable of receiving not only official letters but also notifications from large companies. If tax authorities, water, electricity, gas, JD.com, SF Express, and other departments / companies operate independently, sending notifications separately to users, it will not only cause significant inconvenience but also compromise security. This would require users to download and install multiple apps and use multiple key systems, which is clearly impractical. We need to establish notification systems for each organization, allowing them to log in and upload materials; users can then download files from the system. Many people previously believed that notifications seen directly on mobile phones were unreliable, thus requiring more reliable devices to display notifications. Anti-fraud kiosks are suitable for this need. To enhance security, the anti-fraud kiosk sends a query request to the platform to verify its location. When submitting notices or inquiring about information, various organizations must verify the location to prevent impersonation by criminals. Initially, anti-fraud kiosks can be set up in places like banks, where they are more likely to gain people's trust. Software cannot be installed arbitrarily on the equipment of these anti-fraud kiosks.
[0059] Face-swapping and voice-swapping scams are one of the biggest threats posed by artificial intelligence, but they can actually be solved using encryption. If the platform automatically retrieves the corresponding key after verifying the sender's identity, and encrypts the message before sending it to the recipient, an adversary who successfully passes identity verification could impersonate the sender and commit fraud. Therefore, having the sender (who possesses the key) perform encryption increases security by one level. AI face-swapping and voice-swapping are often used to scam friends and family, and since the number of friends and family members an individual has is usually limited, the number of keys an individual possesses is also limited, making it easy to implement. After successfully adding friends, the platform can encrypt and send a secret value to both parties. Then, both parties use a transponder to generate a key based on this secret value for a video call. The sender generates ciphertext using this secret value and sends it to the recipient through the platform. The recipient then decrypts the plaintext using the secret value. During this process, no plaintext appears on the platform; the platform receives and sends only ciphertext. Even if the information is stolen by a hacker, they cannot decrypt it. Furthermore, the hacker does not possess the secret value and therefore cannot generate the correct ciphertext, making impersonation difficult. This encryption is implemented by the sender of the message, not the platform, making it much harder for hackers to attack. Previously, adding friends simply involved sending a confirmation message without any encryption measures. Even if someone creates a deepfake video, without the necessary key, they cannot forge legitimate ciphertext and will use an incorrect key, ultimately preventing the recipient from accessing the message. In the past, phone calls typically only transmitted audio, not images, making simple voice-changing scams relatively easy. However, with video calls, even a voice change is meaningless; the recipient can accurately determine if the caller is a friend or family member through the image. And against strangers, a voice change is ineffective.
[0060] When making small payments directly between buyers and sellers, buyers can scan the seller's QR code to verify the authenticity of both parties, which is convenient. However, while QR codes are now widely used, many have been malicious. A simple way to prevent malicious QR codes is to use encrypted ones: the applicant first applies to the platform, and after identity verification, the platform returns a specific password and encryption key; the applicant uses this encryption key to encrypt the QR code content, then adds their username and password to generate a QR code; the user scans the code, uploads their username and password to the platform, the platform verifies the username and password, and returns a decryption key (encrypted using a key agreed upon by the platform and the app), allowing the user to retrieve the QR code content. This method only verifies the applicant's identity, which allows finding the perpetrator if problems arise, but it doesn't verify the QR code content and remains unreliable. To address this, the platform can act as an intermediary: anyone wanting to publish a QR code must first apply to the platform, including a username, password, location verification code, and the QR code content. The platform verifies the username, password, and location authentication code, acknowledging the user's identity. It then checks the QR code content. Upon successful verification, the platform generates a unique serial number for the QR code and uses this serial number to generate a new QR code (containing a verification code, username, etc.), which is returned to the applicant. The applicant then posts this QR code. When a user scans the QR code, they upload the serial number to the platform. The platform returns the content corresponding to that serial number, along with a dynamic verification code matching the serial number and username. The app verifies the verification code before acknowledging that the received information genuinely came from the platform, thus preventing attackers from impersonating the platform to send fake messages. We can establish a dedicated app for interpreting platform-approved QR codes, refusing to open QR codes not approved by the platform, making it difficult for malicious QR codes to deceive users.
[0061] In the future, with advanced identity verification and communication technologies (using transponders to verify location and purpose), both traditional methods of impersonation and fraud will become increasingly difficult. Only hacker attacks will be truly effective in carrying out fraud, leading to a significant increase in such attacks. Therefore, preventing hacking will become a key focus. Faced with this threat, we must find effective ways to resist hacker attacks. Most hacker attacks involve impersonation; the attackers typically use someone else's name, and the nominal user and the actual operator are not the same person. Generally, no one would willingly do something harmful to themselves unless they are being scammed. When identity verification technologies are less advanced, hackers can steal verification information and complete fraud on other devices. They can also use other devices to issue payment instructions and messages in the victim's name, which is convenient. However, with advancements in identity verification technologies, verification devices will only be usable by the original user. Situations where a single computer can log into any QQ account will become increasingly rare, making such attacks more difficult. Therefore, hackers will be more inclined to implant malware on the original device to carry out fraud. For clarity, attacks where the attacker uses the same device as the nominal initiator of the payment instruction (e.g., the device actually owned by the attacker) are hereinafter referred to as "local attacks"; attacks where they do not are hereinafter referred to as "other-device attacks." This distinction is based on the device used. "Self-account" and "other-account" actions are distinguished from the operator's perspective, using different criteria. Generally speaking, fraud falls into three categories: local / personal; local / other-account; and other-device / other-account. Local / personal (i.e., self-account) actions are not carried out using hacking techniques and are not considered true "attacks."
[0062] While transponders offer reliable authentication, they cannot guarantee the security of transaction information, which hackers can still compromise. With frequent virus infections on mobile phones and computers, ensuring the security of transmitted information is increasingly crucial. Previously, USB tokens were the most secure payment method, encrypting transaction information. However, even USB tokens cannot completely guarantee the security of transaction information. Hackers can intercept the plaintext transaction information and even the password entered by the user through the USB token on their computer; they can even manipulate the transaction information, replacing it with their own fabricated text, resulting in legitimate ciphertext. Hackers can not only steal accounts and passwords to commit crimes directly, but also steal chat logs to fabricate lies. Preventing hackers from obtaining chat logs is essentially a communication issue; when hackers eavesdrop, the chat tool's verification of accounts and passwords is not flawed. Simply encrypting the information prevents hackers from obtaining useful information online, but they can still obtain plaintext through Trojans. Simple cryptographic methods are insufficient to resist such attacks; only improvements to the devices (software and hardware) can effectively prevent this.
[0063] To ensure the security of transmitted information, the lowest-cost method is to improve the operating system and establish a "mode that can only run specific text-editing related applications," hereinafter referred to as "standalone mode." Simultaneously, applications that can only run in this mode, hereinafter referred to as "standalone software," should be used. These should be limited in variety and can only be installed in a specific way to reduce the chance of virus infection. Applications that cannot run in this mode are hereinafter referred to as "non-standalone software." After exiting standalone mode, non-standalone software can run, but standalone software will not. This unprotected text operation mode is hereinafter referred to as "non-standalone mode." Of course, having the protector agree on a key with other devices can also prevent attacks, and its implementation cost is even lower.
[0064] In standalone mode, text can be edited and simple processing can be performed. In this mode, the keyboard and monitor are available, and the standalone software is downloaded and installed in a separate location (a specific location, separate from the download and installation locations of non-standalone software). Its runtime cache and memory space are also independent, as is its data storage space on the hard drive; non-standalone software cannot read this data. Furthermore, keyboard input in standalone mode is only accessible to the standalone software, and display information originates solely from it; non-standalone software cannot take screenshots. Thus, data related to the standalone software cannot be freely read, stored, or modified by various non-standalone software or apps. Sometimes, however, standalone software needs to output data to non-standalone software. For example, a user edits a piece of text, encrypts it, outputs it to WeChat, and then sends it to a friend. The storage space for this type of data is referred to as the standalone software output space. Users must specify the receiving software in standalone mode; unauthorized software cannot obtain the sent information. Standalone software can also receive data from non-standalone software, which can be either encrypted or plaintext. The storage space for this type of data is referred to as the standalone software read space. Only after the user has finished editing, saved the data, and completed processing (such as encryption), will they be able to revert to non-independent mode by clicking "Switch to Non-Independent Mode." Editing information in "Independent Mode" can prevent hacker attacks; hackers cannot arbitrarily transfer or input information, nor can they eavesdrop on or modify it.
[0065] The above methods alone are insufficient. If a user downloads infected system software, hackers can still launch attacks. Even if the original computer or mobile phone had a genuine operating system installed, hackers could secretly reinstall a Trojan-infected version. Furthermore, many computers and mobile phones use older operating systems without a "standalone mode." To address this, a device independent of the phone or computer's (CPU) for text protection can be used, hereinafter referred to as a "text protector," or simply "protector." Previously, people used USB tokens (U-shields) to protect payment security. U-shields are also independent of phones and computers, but they have several drawbacks, such as the possibility of input information being intercepted and tampered with by hackers. The protector has a Type-C plug, which can be plugged into a mobile phone or, with an adapter, into a computer; it can also have Bluetooth functionality, making connection with mobile phones easier; it also has a small screen or touchscreen, multiple buttons, and functions for encryption, decryption, and generating and verifying checksums. Each protector has a built-in unique key for synchronization with the platform. It can also have multiple ports for plugging in keyboard cables, charging mobile phones, etc.; it can also have a port for connecting to a monitor, so that it can use a larger monitor (even larger than the mobile phone screen). It can be used with a computer, which makes observation more convenient. If a separate protector is used when using a computer, it will increase the cost, while adding only a monitor is the most cost-effective option.
[0066] The protector and the USB key share many similarities. The USB key is also a device independent of the computer or mobile phone, with a display screen and buttons. However, the text is first edited on the computer and then sent to the USB key for confirmation. When editing text with the protector, users can look directly at the protector's screen without looking at the computer screen. Each character typed is displayed on the protector, allowing for individual character checking without needing to re-check all text after it's been typed. Our editing software sends information to the protector in real-time, while the USB key receives the information only after it's edited. If text is input to the protector via mobile phone or computer and then confirmed on the protector, the protector can be without a keyboard or input function, resulting in lower costs. While hackers typically cannot tamper with the unencrypted text, they might intercept the information. USB keys have traditionally been used with computers, so keyboards are readily available. We could release a model where the keyboard connects directly to the protector, which then connects to the computer; this would prevent hackers from intercepting the information. In the future, protectors could also use touchscreens for direct clicking, making operation more convenient, but the cost would be higher and difficult to implement initially. Protectors have pre-set keys and are for personal use only; therefore, with protectors, personal keys are not required. The function of protectors differs from that of transponders, but as mentioned earlier, using transponders can improve the reliability of authentication, significantly increasing the difficulty of hacker attacks; therefore, transponders are also essential. Encrypting text using only the protector's key is certainly not as secure as using keys provided by transponders, but since transponders do not have a direct interface with protectors, information should be transmitted in an independent mode to prevent viruses from stealing information. Tracking verification (see below) is even more complex.
[0067] Previously, USB token passwords were entered on computers and mobile phones, which created an opportunity for hackers. If a hacker could intercept the password and steal the USB token, they could use it freely. To mitigate this vulnerability, the protector has an "input protection mode" (making the protector a dynamic "password book"), although it can also be used for other information input. To reduce costs, the protector may not include a keyboard; information acquisition relies on external input. The most conceivable method is for the protector's display screen to show ciphertext, which the operator then converts. The display screen is marked with 0-9, and above each mark, the corresponding ciphertext is displayed sequentially (it changes randomly, making it difficult for hackers to predict). The user enters the corresponding ciphertext on their computer or mobile phone (e.g., instead of 4, they enter 7). The computer or mobile phone then sends the ciphertext to the protector, which decrypts it and displays the plaintext. After the user verifies the information and confirms, the protector encrypts the text and sends it back to the computer or mobile phone, which then forwards it to the platform.
[0068] The above method requires manual conversion, which is mentally taxing and prone to errors. A simpler method (hereinafter referred to as the array method, see [link]) can be used instead. Figure 10 ):
[0069] On the mobile phone and computer screens, two rectangular arrays are displayed. One array displays the position of each character in plaintext in each cell (hereinafter referred to as the plaintext array), and the cell containing the plaintext character to be entered by the user (the target cell after transformation) is referred to as the target cell. The other array is for user clicks (for manual input) and is referred to as the click array. The cell clicked by the user (by hand or mouse) is referred to as the selection cell. If the screen is small, these two arrays can be merged without conflicting display and input functions. A rectangular array (hereinafter referred to as the protector array) is also displayed on the screen showing the positional relationship between the target cell and the selection cell. The array can have 1, 2, or multiple rows, referred to as a single-row label, a two-row label, and a multi-row label, respectively. A 3x3 array with 9 cells is referred to as a 9-cell label. The plaintext character to be entered by the user is placed in the center of the array and can be marked with a + symbol. The position of the selection cell can be marked with a * or O symbol, and the markings are different.
[0070] First, the user locates the target cell containing the character they want to input based on the display on their phone or computer screen. Then, the protector screen identifies the positional relationship between the target cell and the selection cell. Based on this relationship, the user locates the selection cell on their phone or computer screen and clicks it. The phone or computer then sends the position of the selection cell to the protector. The protector, based on the position of the selection cell and the current transformation relationship, determines the target cell and then the character the user wants to input. The protector can then display the transformation result (the decrypted character) for the user to verify. As the user inputs the next character, the protector array and phone array can change to increase the difficulty of the attack. If a physical keyboard is used, the same method can be used to determine the key to be pressed. After the key is pressed, the computer (or phone) sends a message to the protector, which then determines the character the user wants to input.
[0071] The distance between the target cell and the selection cell, hereinafter referred to as the conversion distance (usually in units of cells), should generally not exceed 3; otherwise, it becomes difficult to distinguish with the naked eye. If the maximum conversion distance is 3, a single row of labels can have 7 choices, which is relatively few; a two-row label can have 14 choices, which is more numerous; and if there are more rows, there will be even more choices. This increases the randomness of the transformation, making it less vulnerable to being intercepted by malware. This method may encounter issues exceeding the limits, for example, if the target cell is on the far left of the array and the selection cell is offset 2 cells to the left. In this case, the corresponding click position can be found starting from the other boundary in that direction. This method allows users to find the click position simply by following the specified direction and distance (1-3 cells). It uses up, down, left, and right transformations instead of number (letter) transformations, making it simple, convenient, fast, and easily accepted. Previously, plaintext and ciphertext were often represented by characters; here, they are represented by positions, a different situation.
[0072] The array method allows for input entirely on the phone, or it can be done using only the keys on the protector without the phone. Current USB tokens have a maximum of 5 keys, which is relatively few, making it cumbersome to input letters and Chinese characters using only 5 keys. To utilize existing hardware, another method is to use the protector keyboard in conjunction with the phone and computer keyboards for input; this is referred to as the "separate keyboard method." See [link to relevant documentation]. Figure 11 , 12 Mobile phone and computer keyboards, hereinafter referred to as split keyboards. Previously, input methods did not utilize two keyboards simultaneously for input. With split keyboards, both keyboards can typically be pressed together, achieving an input speed equivalent to one click on a 26-key keyboard; if fingers are used for input, the speed may be even faster. Previous input methods only considered input speed, neglecting security; achieving a balance between security and convenience is not easy. Information entered using split keyboards may be intercepted by hackers; therefore, we should make the information entered using split keyboards less critical, minimizing the difficulty of attacks.
[0073] Inputting Chinese characters can be done by entering Pinyin letters. Pinyin letters are divided into 5 groups (each group contains 5 letters, excluding V, which is used very infrequently; to input V, use the separate keyboard and select "Other Characters" mode). The group of letters is referred to as the "group"; the selected key is the key within that group, referred to as the "key sequence." You can first enter the group (the grouping of letters and the corresponding key relationships are fixed, so a diagram can be displayed on a computer or mobile phone for guidance, or it can be displayed on the protector), then select the letter, and you can complete the input with two clicks. It should be that the protector inputs the group, and the separate keyboard selects the specific letter. This is because the group contains more information than the key sequence.
[0074] Previous T9 input methods used 8 keys to input letters (groups), but we only use 5 keys to input groups, a reduction of 3 (over 33%). This significantly increases the difficulty of deducing letter combinations through frequency, as each group contains a larger number of letters. Furthermore, mobile phone and computer keyboards can only determine the key sequence. Therefore, cracking plaintext by analyzing keyboard input is very difficult, making this method highly secure. The letter order and grouping rules are also fixed, making it easy to learn and operate, requiring little thought and offering convenient operation. While computer users now have physical keyboards, current keyboards lack interfaces for connecting to the protector. In this case, the keyboard can be connected to the computer, allowing for character input using both the keyboard and the protector's keys.
[0075] To increase the difficulty for hackers to crack plaintext based on information input from the keyboard, additional keys can be added to the keyboard for selecting letters. A key that cannot be used for character input can be randomly inserted into each group of keys; this is referred to as a "scrambling key." This makes the key used to input each letter unpredictable, thus increasing the randomness of the input. After selecting a group, the protector displays a large diagram showing the key (and scrambling key) used for that group of letters and the corresponding finger markings, allowing users to quickly and easily input characters. However, this method has a drawback: the finger used for each letter is uncertain, making the operation slightly more difficult. Since there are usually many keys available on the keyboard, it's also possible to insert 1-2 spaces in each group, only at the beginning or end, without inserting any in the middle. A total of 6 or more keys can be used, all located on the same row. This way, once the input position of the first letter is found, the input positions of the other letters can be determined sequentially, as their positions are connected and all are a certain distance forward or backward from the reference position, thus reducing the operational difficulty. Furthermore, the conversion distance used for each group of characters can be different, further increasing the difficulty of the attack.
[0076] To further enhance security when the text input by the user is important, the following method can be used to select letters: Use two rows of keys, three keys per row, for a total of six keys (the computer's numeric keypad can be used directly); one key is a scrambling key, its position is randomly determined, and the six keys are used to input five different letters, leaving one extra space to be filled, which also requires a scrambling key. Thus, the key used for inputting each letter is not fixed; for easy identification, the order of the letters represented by each key can be fixed; however, the position of the starting letter can change (forming a letter loop); the difference in security is minimal despite the variable letter order. The protector displays a small diagram of the letters represented by each key, with close spacing between cells, making it easy to observe and identify, thus making operation very convenient. In this method, when the group is fixed, each key's function (representing a letter and scrambling) may have six possible variations, exhibiting strong randomness. The rules can be changed with each input or over a certain period of time. I also considered other methods, such as using a 3x3 grid of 9 keys with 4 scrambling keys. Even with a letter ring, each key could represent 6 different letters. Overall, the method using 6 keys is better.
[0077] One method for inputting numbers is to divide them into two groups: 1-5; 6-0. After pressing one key on the sub-keypad, pressing another key on the same sub-keypad will directly identify the input as the first group of numbers, confirm the input, and proceed to the next number. To input the second group of numbers, a combination of two keys on the protector can be used. However, using the keys on the sub-keypad is more convenient, requiring only one key press without the need for a combination, thus minimizing information leakage and increasing security. Inputting punctuation marks, selecting input modes, and deleting can all be done using the sub-keypad, as these operations also minimize information leakage.
[0078] When inputting Chinese characters, there's a final character selection step. Previously, candidate characters and words were arranged based on frequency of use. If arranged in a fixed order, hackers could easily attack. However, if the characters and words on the protector screen are randomly arranged, it becomes much more difficult for hackers to attack. There can be 5 or 10 candidate characters and words. The order can be adjusted starting with the most frequently used group; scrolling down allows for adjusting the order of less frequently used groups, and so on. Scrambling the order of candidate characters increases the difficulty of an attack. Theoretically, using the protector's keyboard to select candidate characters and words is safer, as it doesn't change the display order. However, the protector's keyboard has fewer keys, making selection less convenient. A separate keyboard has more keys, and the keys for selecting letters and words can be separated, making selection easier and revealing less information, thus increasing the difficulty for hackers. Therefore, a separate keyboard is usually used for selecting candidate characters and words. After the user finishes inputting the text and checks it for errors, they press the "signature key" (which can be a combination key) on the protector, and the protector encrypts and sends the information.
[0079] The protector is independent of the computer (or phone), making it impossible for hackers to attack. Once the text leaves the protector, it exists in encrypted form, making it difficult to decipher even if eavesdropped on. This prevents information leakage at the source. Previously, a USB security token only needed to send a message to the bank, but the protector's message ultimately needs to reach the recipient. The protector has encryption capabilities; if the encrypted text is sent directly, while it's not vulnerable to hacker attacks, it cannot be directly decrypted. Therefore, the platform decrypts it and then encrypts it again using a key agreed upon with the recipient. The recipient can input the encrypted text into the protector (either by selecting a specific encrypted text in dedicated chat software and sending it to the protector), which decrypts it. The user can then view the plaintext on the protector, thus preventing leaks and ensuring the sender's identity is correct. Hackers, lacking the corresponding key, cannot generate legitimate encrypted text. This functionality is crucial; simply sending plaintext wouldn't achieve this. This ability to independently view specific plaintext is unprecedented. If each user's protector operates independently, this function is impossible; it requires a platform as a bridge. These functions, though simple, are crucial. Previously, Trojan infections were not common, so people often didn't prioritize Trojan prevention and didn't consider using protectors to defend against hackers during communication. Therefore, this area has seen limited development, leaving significant opportunities. In the future, it can also be used to protect voice and other information, but this would be costly and require new file formats, only becoming feasible after such products are widely accepted. While USB tokens are only used for payments, protectors can protect most types of text information, offering a much broader scope and fundamental protection for communication security. The protector's program is pre-installed and cannot be modified or upgraded by hackers; the types and formats of data input to and output from the protector are heavily restricted, making attacks extremely difficult for hackers.
[0080] Encrypting plaintext alone is insufficient for the protector. To prevent hackers from tampering with or transferring information, a verification code can be generated. This verification code can be generated not only from the text but also using parameters such as username, location, payment account, and amount. If these components are independent, hackers can easily transfer the information elsewhere to launch an attack. The format of information sent and received by the protector can be the sender's username, password, receiver's username, text number, encrypted text, and verification code. The password is required for the platform to verify the sender's identity and determine the corresponding key. Since it's difficult for the receiver to directly synchronize keys with the sender, the platform can decrypt the received ciphertext and then encrypt it again using the agreed-upon key before sending it to the receiver. After verifying the received verification code, the platform must generate and send another verification code to the receiver.
[0081] Hackers most want to steal passwords, which are often short and simple. However, verification information in other automated verification processes is often more complex ciphertext. The password input step is the most vulnerable and therefore the most dangerous, requiring careful protection. Previously, people didn't change their passwords daily, making them difficult to remember, and passwords were often the same across different platforms. Recording passwords in notebooks, computers, and mobile phones also made them easy to leak. Passwords are divided into two categories: offline passwords (used to unlock phones and computers) and online passwords (used to log in to websites). Offline passwords are usually fixed. Dynamic passwords are certainly more secure, but they cannot be changed manually. Protectors can be used to achieve this. Mobile phones need to be synchronized with protectors, and both require pre-set keys, which can be done when purchasing a new device or under secure conditions. Dynamic online passwords can be changed through platforms. However, agreeing on keys for different websites is not only cumbersome but also limits the number of websites that can agree on keys. We can also establish a dedicated online password mode, hereinafter referred to as "password mode," to distinguish it from the mode for inputting ordinary text. This ensures that the password generated by the protector is different each time, greatly improving security. The format of the information sent by the protector can include username, password, the platform number to be logged into, last login time, verification code, etc. The user (via mobile phone, etc.) first enters the protector's password (which can be encrypted using an array method). After the protector verifies the password, it then enters the encrypted dynamic password into the computer or mobile phone. The computer or mobile phone then forwards the encrypted password to the platform. After the platform verifies the password, it sends verification information to the corresponding software server. Once the server verifies the password, the user is logged in, truly achieving "one password for everything." This is implemented using a standalone device and is connected to the internet, making it more complex than previous login methods.
[0082] This protector only needs one confirmation button. When editing text, if there are errors, users can delete or backspace on their phone or computer to re-edit, so the protector doesn't need a dedicated delete or backspace button. The protector only processes the text once the button is pressed, preventing hackers from launching attacks. This feature also prevents hackers from modifying the text because users will view and confirm the information, eliminating the need for keyboard input, thus keeping costs very low.
[0083] Verifying a user's identity solely based on location is relatively rare. Identity verification is often related to a specific event, such as confirming the identity of the recipient of a payment instruction or the sender of a notification. Therefore, text encryption can often be combined with location verification. Determining the key based on location significantly increases the difficulty of attacks. This type of data source is unprecedented, especially for cryptographic chips, whose location varies greatly, has high randomness, and is therefore highly valuable. Ideally, protectors and transponders should transmit information in independent mode to avoid virus attacks. The specific method is as follows: When a user wants to send a message, they press the signature button on the protector, and the system switches to independent mode. The protector first sends a request to the transponder and the key chip. The transponder and the key chip generate a key based on the location and return it. After receiving the key returned by the transponder and the key chip, the protector combines the protector's key to encrypt the message and send it to the platform. The platform decrypts the message with the corresponding key, derives the ciphertext based on the recipient's protector key, and then sends it to the recipient. Upon receiving the message, the recipient returns a confirmation message. The platform then returns a confirmation message to the message sender. After receiving this confirmation message, the message sender exits independent mode.
[0084] The protector has a pre-set key and is for personal use only, so with the protector, you don't need to use a personal key.
[0085] If a user has a computer nearby, they can submit transaction information to the platform using the computer and then receive the platform's confirmation message on their mobile phone. This ensures that the message received by the platform has not been forged by hackers. This ensures an immediate response from the platform, using time to prove the authenticity of the information. We can stipulate a standard response time (e.g., 2 seconds). Messages within this standard are valid; those exceeding it are invalid. This needs to be determined considering potential network congestion. If genuine messages can be received normally, other fraudulent messages will have no opportunity to launch an attack; even if they are sent, anomalies will be detected. If a user receives a message but realizes they haven't sent it to the platform, they can click "deny" instead of "confirm." The message will not be confirmed or executed, and the system will investigate whether someone is committing fraud. Simultaneously implanting viruses on both a mobile phone and a computer is difficult; switching to a different terminal to receive information significantly increases the difficulty of an attack. It's easier for one person to cover up a lie, but much more difficult for two people to collude. Although hackers cannot tamper with the text after using the protector, they can prevent the sending of information and impersonation. Therefore, after a user sends a message, the platform should return a confirmation message. To prevent impersonation by hackers, a notification code (which is also a verification code) can be attached to the message. The protector must verify the verification code to effectively prevent impersonation.
[0086] To ensure the authenticity of information, it's best for the sender to verify it themselves. Previously, there wasn't a method for the same person to send a message from a computer and then confirm it via mobile phone, or vice versa; however, it's relatively easy for hackers to send messages via mobile phone and then confirm them via mobile phone. Verification after switching terminals is even more reliable. Having others verify the authenticity of information is much more difficult; self-verification is much easier and safer. This method of self-verification is hereinafter referred to as "source verification." We should strive to verify the accuracy of information ourselves when users send it; this principle is hereinafter referred to as the "source verification principle."
[0087] Having clarified the importance of "source verification," we understand that users should reconfirm the confirmation message received from the platform, hereinafter referred to as "information re-verification." The specific process is as follows: After the user presses the confirmation button (which can be a combination button) on the protector, the protector first sends the encrypted username, password, transaction information, and verification code 1 to the platform via computer or mobile phone. After successful verification, the platform generates "confirmation code 1" and forwards it to the protector via computer or mobile phone. It can also encrypt the decrypted plaintext using another key and send it to the protector for text verification. After successful verification, the protector generates confirmation code 2 and sends it to the platform via computer or mobile phone. Once the platform verifies the transaction information, confirming its authenticity and the absence of hacker-intercepted communication attacks, it sends the message to the recipient and executes the transaction. This effectively prevents hackers from blocking communication and making requests to the platform without the user's knowledge.
[0088] Previously, hackers could use the CPU to steal or block passwords, notifications, and other information, and also input or send forged messages. To prevent these attacks, it's necessary to establish a device independent of the CPU (for control), and a protector is such a device. Protectors can only be controlled offline, which hackers cannot attack, making them extremely important. Information verification may seem redundant and cumbersome, but each step plays a different and irreplaceable role. Information verification is one of the core functions of a protector and a key difference between it and a USB security token.
[0089] With the rise of scams targeting acquaintances, many people are hesitant to believe calls for help from familiar people, even though some are genuine. Ignoring these calls could lead to serious consequences. Therefore, we must not only guard against criminals but also ensure the security of legitimate communications. Verifying location can significantly improve the security of communication and payments. While requiring on-site location verification poses a significant challenge for criminals, it also inconveniences legitimate users. Providing remote verification methods is necessary. To ensure secure communication between acquaintances, both parties can pre-agree on random questions and answers, but this limits the number of questions that can be agreed upon and lacks sufficient security. Scams impersonating business owners are rampant, making it crucial for business owners to confirm large transfers. Relying solely on offline methods like USB tokens is inconvenient when business owners are traveling or away, forcing them to hand over the tokens to accountants or others. This inconvenience creates opportunities for criminals to commit crimes. Ensuring high security for remote operation and communication leverages its convenience, playing a vital role in protecting funds and eliminating opportunities for fraud. Almost all successful scams stem from a failure to carefully verify relevant information. People often believe that ease of operation doesn't change the essence of the matter, and that saying one more or one less word has limited impact on the outcome. This is not the case. The significant increase in the convenience of remote operation will drastically reduce the occurrence of scams. We should not reject remote operation simply because online operations are less secure, but rather strive to leverage its advantages. It can usually be combined with offline operations to compensate for each other's weaknesses.
[0090] Using fixed-location anti-fraud devices offline (to verify identity) is fundamentally different from using mobile anti-fraud devices. Anti-fraud devices at home or in the office have limited contact with many people, so their location can accurately identify the user, making it simple and reliable. However, the identities of people who can reach locations outside of home or work are highly uncertain, especially in public places where many people will be present. Even if the location information is accurate, it cannot prove identity solely through location. Many people can reach that location, and others can also send the same coordinates. Simply sending a location only allows identity to determine the location, not the other way around. So how can we verify identity through location? Under normal circumstances, the speed at which a user's location changes is within a certain range. It's impossible to be in Beijing one second and in Shanghai the next, even by plane. Therefore, we can set a standard for typical displacement speed. If this standard is exceeded, the system will mark the user's status as "abnormal," preventing payment authorization, etc. For faster travel such as by plane or train, a declaration can be submitted to the platform regarding the mode of travel to help determine the standard used. To prove authenticity, flight tickets, highway toll records, etc., can be submitted. Different people typically have different movement trajectories, and users can be effectively distinguished through these trajectories (continuous location records). Verifying a user's identity through these trajectories is referred to as trajectory verification. While a trajectory in geometry is a set of points that meet certain conditions, the "trajectory" discussed in this article is more complex, containing not only spatial but also temporal information. Clearly, a set containing temporal information is more difficult to imitate than a set containing only spatial information. The mobile phone can encrypt and send its current coordinates to the platform at regular intervals (e.g., every minute), allowing the platform to determine the user's trajectory. Trajectory verification is a completely different technology from traditional identity verification. Previously, people primarily identified identities through encryption, while trajectory verification targets the trajectory itself. If a person's previous position is accurate, their subsequent position must be adjacent to that position; they cannot suddenly jump to another location. This principle, referred to as "trajectory continuity," is the basis for the working principle of trajectory verification.
[0091] Tracking is difficult to imitate. Criminals and users often come from different places. If their tracks were completely identical, the user could see the criminal, potentially exposing them. This kind of imitation is impossible, unlike imitating usernames or passwords. Location and time are tangible things, difficult to replicate; names, on the other hand, are abstract and easily copied. Even if a criminal temporarily places themselves near the real user's verification location using a mobile anti-fraud device, they cannot create a completely identical tracking pattern. Even if an adversary cracks the app's (or the key to the security chip, see below) key, because users typically move slowly, it would take a long time and multiple attempts to change their location to match the impersonator's. This cannot be achieved quickly, making imitation difficult. This is a key difference between tracking imitation and imitation of other information.
[0092] While each person's trajectory is typically unique, comparing the trajectories of a large number of people involves an enormous amount of computation, making it difficult to implement. Usually, continuously monitoring the location of just one user, as long as the trajectory is consistent, is sufficient to indicate that the user is indeed using the anti-fraud device. To ensure security, during payment confirmation, the app can use a separate algorithm to generate an authentication code for the current coordinates (otherwise, an adversary could copy the information). The phone then sends this code to the platform, which verifies the location before confirming it. If the current location is adjacent to the user's previous location, the platform considers the user's identity authentic.
[0093] The username cannot be determined by the trajectory alone. To determine the username, the starting point of the trajectory must be found, and the username can be determined based on this. Therefore, the starting point is very important.
[0094] If a user's identity can be correctly confirmed at a previous moment, and the location of the same person (determined by the username claimed in their message to the platform) changes within a standard range at a subsequent moment, then the identity of the person at that location can be confirmed as that of the previous person, thus completing the identity verification relay. This method of identity verification is hereinafter referred to as "identity relay." However, once the trajectory is interrupted, this relay (continuous identity verification) will also be interrupted. If the user subsequently sends location information to the platform again, the platform cannot confirm their identity solely based on their location. It can only continue the identity verification relay after re-verifying their identity at a reliable location using a reliable device.
[0095] The primary problem with trajectory verification is that the location information provided by previous mobile phones is unreliable. Violators can use simulated location information to alter it. To ensure that mobile phones provide reliable coordinate information, the following three methods can be used: 1. Upgrade the mobile phone operating system to add the following function: The app can send a (specific, unified across various apps) location query request to the CPU; upon receiving the request, the CPU compares the coordinates provided by the positioning chip with the coordinates provided by the system; if the difference exceeds the standard range, the data is deemed invalid, and the CPU sends an "abnormal status" notification to the app; upon receiving this notification, the app does not use the coordinate data, cannot process normally, and displays a "location status abnormal" notification to the user. If the difference is within the standard range, the coordinate data provided by the system is accepted as genuine, and a "normal status" notification is returned to the app; upon receiving this notification, the app uses the coordinate data and processes normally. The app generates encrypted coordinates using its built-in key and continuously sends the encrypted coordinates to the platform. Normally, if no location query request is received, the system does not need to perform this comparison to improve processing speed. However, previous mobile phone operating systems did not allow this check. This method certainly improves security, but it is vulnerable to attack, although it is relatively inexpensive. Such a system with location verification capabilities will be referred to as a "system with location verification capabilities" below.
[0096] 2. Adversaries might also disrupt the wiring between the positioning chip and the CPU, adding extra wiring (or even installing unauthorized chips) to send incorrect coordinate data to the CPU. To counter this, we can add a separate chip to the phone, hereinafter referred to as the "location verification chip." This chip is independent of the CPU and positioning chip, but it is connected to both. When security requirements are low, the app can verify the location solely through the CPU, following the same process. When security requirements are high, the app can send a (specific) location verification request to the CPU (this request is different from the location query request). The CPU then forwards this request to the location verification chip. Upon receiving the request, the location verification chip uses the positioning chip to determine the current location. The CPU then inputs the system-determined location into the location verification chip. The location verification chip, after comparison, determines the data invalid if the discrepancy exceeds the standard range, does not issue an authorization message, and sends an "abnormal status" notification to the app via the CPU. If the app receives the "abnormal status" notification, it stops sending encrypted coordinate data to the platform. If the core chip finds that the difference between these two data points is within the standard range, it acknowledges the authenticity of the data and can issue authorization information.
[0097] If the app directly sends plaintext coordinates to the other party for authorization, it is easily spoofed. If the positioning chip returns a key to the app via the CPU, and the app uses this key to generate ciphertext coordinates, it can prevent direct coordinate spoofing. However, an adversary might intercept the key and use it to forge ciphertext for other locations. A better method is for the app to send a request to the positioning chip via the CPU to generate an authentication code (hereinafter referred to as the authentication request). Upon receiving the request, the positioning chip generates an authentication code for the current location, with the key changing according to the location. This authentication code is then sent to the app via the CPU, and the app encrypts it before sending it to the platform. The platform uses the same method to generate an authentication code for the coordinates decrypted from the ciphertext coordinates previously sent by the app. If the two match, the verification is successful. This method can utilize the phone's existing positioning chip and communication capabilities, resulting in lower costs. To prevent attacks, each positioning chip can have a unique built-in key. This method can also prevent attacks such as counterfeit labels, as adversaries do not possess the corresponding key, making counterfeiting difficult.
[0098] 3. Of course, even phones with location verification chips can be modified by adversaries. A more reliable method is to improve the location chip, giving it verification and encryption functions. This type of chip is hereinafter referred to as a verification / encryption location chip, or simply a location verification chip. When security requirements are low, the app can simply send a location query request to the CPU, with the processing method as described above. When security requirements are high, the app can also send a (specific) location verification request to the CPU. Upon receiving this request, the CPU sends a verification request to the location verification chip.
[0099] The process of the micro-position chip verifying the position is as follows: the micro-position chip compares the coordinate data it generates with the coordinates provided by the system; if the difference between the two is within the standard range, the coordinate data provided by the system is accepted as true.
[0100] The location verification frequency can usually be high (e.g., once per minute). If the previous location verifications have all passed, the location chip generates an authentication code for the current location. The key changes with the location. The authentication code is then sent to the APP via the CPU, and the APP encrypts it and sends it to the platform. The platform generates an authentication code in the same way for the coordinates decrypted from the ciphertext of the coordinates sent by the APP. If the two are consistent, the verification is successful.
[0101] In addition, the key chip can also provide a key to the protector, which is more secure. However, there is no interface between the key chip and the protector, so information should be transmitted in independent mode.
[0102] To improve processing speed, the location chip only outputs the authentication code when it receives a request to generate a location authentication code, rather than sending the authentication code every time the location is checked. The location chip, transponder, and protector are separate. Hackers may intercept information sent from the location chip and transponder to the protector. To counter this, a key can be agreed upon between the location chip, transponder, and protector, so that even if the information is intercepted, it cannot be used. The verification request issued by the location chip typically includes the serial number, encrypted coordinates, and authentication code. The platform's verification process is as follows: the platform determines the key based on the serial number and location, decrypts the encrypted text to obtain the plaintext coordinates, and then verifies the authentication code. If the authentication code verification passes, the authenticity of the information is acknowledged. For existing mobile phones, it is impossible to replace the positioning chip; therefore, an independent location verification device (hereinafter referred to as a location checker) can be used, which also has certain advantages.
[0103] In situations with high security requirements, when confirming payments, it's helpful to check how many people are at the current location. If there's more than one person, their previous movements can be traced until differences are found. If multiple people are traveling in a group, their movements might be identical, which could lead to errors in identifying the recipient (as an adversary could impersonate them). To resolve this, the person being authorized can be asked to leave the group and operate the payment independently, thus changing their movement and location.
[0104] In trajectory verification, the number of processing steps is relatively high. To reduce system load, the number of verification steps can be adjusted appropriately. Location verification and authentication code generation can be performed separately. Location verification by the location chip is relatively simple and fast; however, authentication code generation is more complex and slower. Typically, the frequency of location verification can be higher (e.g., once per minute), while the frequency of authentication code generation can be lower (e.g., once every 5 minutes). The APP can send an authentication request to the location chip via the CPU; if previous location verifications have passed, the verification can proceed. If the location chip only verifies the location at long intervals, security is low. Continuously verifying the location at a high frequency but issuing authentication codes at a low frequency results in faster processing speed and higher security, balancing both security and cost-effectiveness. If the location at all times is recorded and processed, not only will the amount of data be too large, but it will also add a lot of data that is not related to the current task. To perform trajectory verification, a "notification to start executing trajectory verification task" needs to be sent to the core chip and the locator chip at a certain time (such as when leaving home in the morning). After receiving the notification, the core chip and the locator chip enter the "trajectory verification" mode and then begin to perform relevant processing.
[0105] For location verification, people worry about privacy leaks. To address this, coordinates can be transmitted in encrypted form. This encryption can be achieved by embedding a key in the location chip. Ideally, each chip should have a different key to make it difficult to attack. The location chip also needs to output plaintext coordinates to serve various apps. The plaintext coordinates are referred to as "plaintext coordinates"; the encrypted coordinates are referred to as "encrypted coordinates". Previously, phones only had a "Location Service" switch (hereinafter referred to as the "plaintext coordinates" switch). We need to add a "encrypted coordinates (service)" switch, referred to as the "encrypted coordinates" switch, resulting in four modes for transmitting location information: encrypted coordinates on, plaintext on; encrypted coordinates on, plaintext on; encrypted coordinates off, plaintext off; encrypted coordinates off, plaintext on. Users should try to turn off the "plaintext coordinates" switch to reduce privacy leaks. This method not only prevents privacy leaks but also improves security. The encryption of location information by the location chip also helps prevent the use of simulated location information. If simulated location information is used, ZAPP will not function properly because ZAPP needs the correct encrypted coordinates to work correctly. However, for regular apps, enabling the "secret label" switch allows the simulated location information to still function normally, and app usage remains unaffected because it doesn't access real location information. Of course, if the secret label chip has a built-in key, location verification wouldn't be necessary, but this function can still be retained to provide services to regular apps.
[0106] To prevent plaintext coordinates from being intercepted, encrypted coordinates should be used whenever possible during storage and computation. To prevent the plaintext coordinates from being exposed, relative coordinates can be used with respect to a reference point, and the reference point's number can be stored in encrypted form.
[0107] When verifying identity, a single location is insufficient; multiple locations must be verified. However, examining multiple locations places a heavy burden on the system. To reduce this burden, a summary value can be generated for the trajectory. One method is to generate an identification code for the coordinates of the trajectory points with the largest and smallest values in the east, west, south, and north directions. This is referred to as the extreme value summary value, or simply summary value 1. This method is suitable for processing by the micro-bit chip itself. The micro-bit chip can determine the trajectory points to select based on the current situation, requiring less data storage and less computation. However, the selected trajectory points may not be highly representative.
[0108] People's trajectories might look like this: making three trips a day—from home to the breakfast shop, then from the breakfast shop back home; from home to work, then from work back home; then from home to the market, then from the market back home. These trajectories often have destinations, involving round trips between two points. (See...) Figure 13The destination is often a point where the direction of movement changes; it is an inflection point or a boundary between concave and convex points. Hereinafter, such points where the direction of movement changes are simply called "Mang Points." Therefore, to generate a trajectory summary value, it can also be done as follows: The user has visited several destinations (3 in total), and the destinations are (breakfast shop, workplace, market). This data generated from the number and location of destinations is called the Mang Point Summary Value, or simply Summary Value 2. Users usually do not input their destinations into the system; we can determine the destinations based on round-trip relationships. This method of generating trajectory summary values is relatively complex and difficult to implement with micro-bit chips, but it can be implemented by apps and platforms. The app can generate the summary value and send it to the platform. Typically, during trajectory verification (authorization), the micro-bit chip can issue one authentication code based on the extreme value summary value, and the app can issue another authentication code based on the Mang Point summary value. This authentication code is different from the authentication code used for uploading locations; it is used for authorization.
[0109] In the past, verification codes and passwords in apps could be copied and used on other phones. Assassins could use malware to intercept these codes and complete payments or grant authorizations without the user's knowledge on other devices. However, such attacks are ineffective in our system. The intercepted information is often not compatible with other phones.
[0110] Previously, people often used dynamic passwords to verify identity, which was certainly more reliable than static verification information. Dynamic passwords were typically generated using fixed keys, making them predictable. However, using a cryptographic chip for identity verification is different. While the chip also contains a built-in key, the generation of the authentication code includes location information. This significantly increases the randomness of the authentication code, making it difficult to forge—something absent in the generation of dynamic passwords. The added location information is beyond the control of adversaries, greatly enhancing security. The data provided to a phone by a Trojan horse can be determined by the hacker. However, the data source of the cryptographic chip is beyond the adversary's interference; it originates from satellites. The authentication code generated by the cryptographic chip is derived from coordinates, etc., and cannot be input by a human or provided by a Trojan horse.
[0111] The key used to generate the authentication code is built into the security chip, is not output, and is unique, making it impossible for an adversary to steal or obtain it. Therefore, the process of generating the authentication code is also beyond the control of an adversary. As long as the chip (phone) is not lost, an adversary cannot generate the correct authentication code.
[0112] Examining the continuity of the trajectory is crucial for trajectory verification. Adversaries might forge trajectory information to deceive the platform. To counter this, the location of the cipher chip can be compared with the app's location. If they match, the trajectory is continuous, as the chip's location information is inherently continuous. This is unless the device for forging location signals is readily available to the public, which the platform can prevent by examining the trajectory's continuity. Simply having the app input coordinates into the cipher chip is not feasible. The cipher chip itself cannot guarantee the accuracy of the input coordinates; coordinates directly input by the app might be forged, rendering this method worthless. A more feasible approach is for the cipher chip to generate an authentication code using its built-in key, which is then forwarded to the platform. The platform then verifies the location information based on the app's location data. Synchronization of keys between the platform and the chip is easier and more secure. Alternatively, the platform can indirectly send the authentication code to the cipher chip, allowing the chip to complete the verification.
[0113] The authentication code differs from the verification code. The verification code has an input window, which the user manually enters into their mobile phone or computer. However, the authentication code does not have an input window and cannot be manually entered into the user's mobile phone. We do not give violators the opportunity to intercept information and enter it into the system.
[0114] Previously, the parameters used in app-generated passwords included time and transaction information (such as transaction amount and number of transactions), all of which could be obtained by adversaries. Time could also be determined by others; transaction information could be intercepted by hackers. However, each user's location is inherently unique, unlike time. With the adoption of trajectory verification, the platform can distinguish users by location, making location information non-transferable. Coordinate data is information, an abstract concept, easily copied; location itself is a physical entity, difficult to replicate. Two people's locations cannot be identical; with sufficient positioning accuracy, differences can always be detected, making each person's location unique. Since each person's location is irreplaceable, a physical entity, the authentication code generated based on location is difficult to transfer to other phones. We can detect anomalies in location information through trajectory verification and other methods; this is one of the fundamental reasons why location-based chips can resist hacker attacks. The non-transferability of location information was a characteristic previously unknown. Of course, this was only achieved after the adoption of technologies such as location-based chips and trajectory verification.
[0115] The most terrifying Trojan viruses disguise themselves as legitimate apps on users' phones. They not only intercept notifications from platforms but also block messages users want to send to those platforms, making it impossible for users to detect any messages being sent. The disguise is so convincing that no one suspects anything. In this way, the Trojan requests an authentication code from the security chip, potentially enabling it to perform actions against the true user's will.
[0116] The data source of a location-based security chip is essentially just location data, not transaction data, and therefore can only be used for authorization. Completing a payment requires not only authorization but also identification of the target of the action, i.e., transaction information, which the location-based security chip cannot determine. Identifying transaction information requires other devices and methods. A location-based security chip alone cannot completely resist malware; an adversary can pre-store transaction information and substitute it during user operations. The data output by the location-based security chip is encrypted; the adversary does not possess the key and therefore cannot generate legitimate ciphertext for other coordinates. This also ensures the security of trajectory verification, making the location-based security chip crucial. The transponder, protector, and location-based security chip are the three most important devices in this paper; they constitute a complete security system, the topology of which can be found in [reference needed]. Figure 14 .
[0117] If a hacker makes a request to the security chip, the user may not be aware of it. To prevent this type of "completely undetectable" attack, the following measures can be taken: upgrade the operating system so that when the system makes a request to the security chip, it also displays a notification to the user, detailing the type of request and complete related information. This way, the hacker's attack cannot be hidden, and the hacker cannot substitute other forged messages. When the security chip generates an authentication code, relevant payment information can also be displayed to the user; after the platform verifies the request, it can also return the relevant payment information, thus preventing deception of the user.
[0118] Alternatively, a separate button can be added to the security chip. The chip only performs processing (encryption, generation of authentication code, verification of authentication code, etc.) when the user presses the button. This prevents malware from secretly sending requests to the security chip without the user's knowledge. The security chip can actually contain multiple keys: a key for encrypting coordinates, a key for generating authentication codes, etc.
[0119] With the use of cipher chips, perpetrators must navigate between the cipher chip and the platform. Relatively speaking, it's easier for perpetrators to deceive the platform because the platform has difficulty understanding the user's true situation; however, deceiving the chip is more difficult because the data source and key are hard to obtain; and getting both to pass verification is even more challenging. Those involved in electronic payments know that Trojan viruses are very difficult to prevent; in the past, they were the ultimate method of theft, with no way to resist them. Finding a way to prevent Trojan viruses is a lifelong dream for many. However, with the use of cipher chips as a signal source, simple virus attacks become ineffective. Using cipher chips greatly increases the difficulty of attacks; even if a Trojan virus has been implanted in a phone, it cannot achieve its goal. The data output by the cipher chip is encrypted and cannot be easily transferred elsewhere. Previously, as long as the app was compromised and a Trojan was implanted, impersonation could be achieved. Using cipher chip location verification to resist Trojan viruses is something I haven't encountered before. In the past, people believed that once a mobile phone was infected with a virus, there was no effective way to resist it. This situation has broken people's previous ideas. Therefore, the location chip and location verification are extremely important, and can even be said to be irreplaceable.
[0120] Previously, to ensure security, bank apps could only rely on facial recognition, a method with very low security compared to using a secure locator chip. This gives mobile payments with a locator chip an advantage over desktop payments. Desktop computers lack location chips and cannot confirm location. Of course, desktop computers can use other location methods, such as USB tokens, which also offer advantages. Combining both methods provides even greater security.
[0121] The cipher chip and protector can operate independently. The cipher chip sends encrypted location information to the CPU, which then forwards it to the protector. The protector combines this encrypted information with transaction information to generate a verification code (1), which is then sent to the platform via the mobile phone. However, this method is relatively simple, and the information sent by the cipher chip is relatively independent, making it vulnerable to manipulation by adversaries for theft. Of course, the information sent by the cipher chip contains an authentication code, making it difficult to port. A more secure method is to use a separate cipher chip (or positioning chip) independent of the mobile phone, integrating the cipher chip and protector. The cipher chip does not send information to the CPU, thus preventing hackers from stealing location information. This integrated unit is referred to as the "cipher chip processor." This also has the advantage of allowing the use of older positioning chips; the encryption of location and generation of location authentication codes can be performed by the cipher chip, making it resistant to the use of simulated location information by mobile phones and very low-cost (positioning chips are inexpensive). Moreover, replacing the positioning chip with a cipher chip in existing mobile phones is impractical; under current circumstances, using a cipher chip processor is the easiest option to implement.
[0122] If we only use the cipher chip to verify identity without using a protector, it would be necessary to set up a separate button for the cipher chip to prevent hacker attacks. However, when the cipher chip and protector are combined, it is sufficient to set up a separate button for the cipher chip.
[0123] Of course, in the future, the location chip and protector can be integrated into the phone, which will be referred to as a "location phone." This way, the protector can always be carried, which is not only convenient but also more powerful. An additional interface can be added to the phone for connecting to other devices. If transaction information and location information are processed separately, adversaries can easily transfer the information; however, combining transaction information and location information to generate an authentication code can prevent information transfer. These functions are entirely new and were not available in previous social media software such as WeChat and Meta. We should seize this opportunity and strive to gain a competitive advantage in social media during this period of technological transformation.
[0124] Protectors ensure text security, source authentication prevents hackers from intercepting or replacing information, and the use of transponders and cryptographic chips for location verification (encrypting location information outside the CPU) ensures secure identity verification and verification of the cause. These measures combined can usually resist various hacker attacks and ensure the security of transactions; none of them can be omitted.
[0125] Confirmation of payment by the payee is also necessary. The method of receiving payment can be similar to the payment process, using a protector to confirm payment information and a transponder and occupant chip to verify location.
[0126] However, sometimes it is indeed necessary to remit money overseas. Simply prohibiting overseas remittances is incorrect; we should enhance their security. This can be achieved by setting up anti-fraud devices overseas to receive funds. Furthermore, cooperation with overseas banks can be established to verify the authenticity of recipients. Attached Figure Description
[0127] Figure 1 Positioning expansion pins
[0128] Figure 2 Schematic diagram of multi-machine anti-fraud system
[0129] Figure 3 Schematic diagram of a standalone anti-fraud system
[0130] Figure 4 Embedded expansion pins
[0131] Figure 5 Cross-sectional view of the positioning sticker
[0132] Figure 6 Detection circuit for positioning stickers
[0133] Figure 7 buoy
[0134] Figure 8 Spring meter
[0135] Figure 9 System structure diagram using fixation devices
[0136] Figure 10 Array method (crosshair)
[0137] Figure 11 Group diagram
[0138] Figure 12 Key sequence diagram
[0139] Figure 13 Schematic diagram of trajectory summarization method
[0140] Figure 14 Security System Topology Diagram
[0141] Figure 15 Identification process example The components are as follows: 1. Location transponder; 2. Expansion tube; 3. Detection circuit; 4. Contact; 5. Screw; 6. Detection board; 7. Interface; 8. Protective cover; 9. Fixing plate; 10. Table; 11. Transmitter; 12. Receiver; 13. Container; 14. Liquid; 15. Mirror; 16. Buoy; 17. Magnet; 18. Iron sheet; 19. Inertia rod; 20. Spring; 21. Contact ring; 22. Fixing rod; 23. Housing; 24. Fixing device; 25. Anti-fraud kiosk; 26. Initiator initiates the process (including location authentication code); 27. Platform sends self-verification notification to the initiator's unit; 28. Initiator's unit sends random questions to the initiator; 29. Initiator returns the answer; 30. Initiator's unit sends authentication opinion code and location authentication code to the platform; 31. After platform verification, it sends notification to the payee's unit; 32. Payee's unit sends random questions to the payee; 33. Payee returns the answer; 34. Payee's unit returns authentication result and location authentication code to the platform. 35. The payee's organization sends a notification to the payee. 36. The platform sends an authentication request to the payee. 37. The payee returns the reason, authorization contract, location authentication code, etc. 38. The platform sends a payment notification to the payer. 39. Both parties communicate via the platform. 40. The payer sends confirmation information and a location authentication code to the platform. 41. The payer completes the bank's payment operation. 42. The platform sends a business confirmation letter to the bank of the payment account. 43. The payment instruction is executed. Detailed Implementation
[0142] Anti-fraud systems (communication and payment systems that can verify the operator's location) typically include a platform, the operator's mobile phone, a SIM card, a protector, a security chip, multiple multi-device anti-fraud systems, multiple single-device anti-fraud systems, and multiple fixed-device systems. The operator's mobile phone has a dedicated app installed. Single-device anti-fraud systems have independent client software installed on the device.
[0143] The multi-device anti-fraud system serves multiple devices, including but not limited to one server and multiple workstations; the server has the main client installed, and the workstations have the auxiliary client installed.
[0144] A multi-machine anti-fraud system can be either fixed-location or mobile. A fixed-location multi-machine anti-fraud system includes a communicator, a transponder, a location detection device connected to the transponder, multiple notification devices, and location detection devices connected to them. The transponder is located in the communicator and is connected to a location detection device and a disconnection detection device; the communicator is located at the server location and is connected to the server and also to a modem; the communicator is always powered on; the notification devices are located at each workstation and are connected to a location detection device, a disconnection detection device, the communicator, and the workstation.
[0145] If the transponder does not receive the overcurrent interruption message from the detection device during this power-on, it will continue to monitor the status of the detection device. If no change in its position is detected, the transponder is in normal working condition, can accept position verification requests, and sends a normal authentication code to the contactor at a specific frequency. The contactor then sends a normal authentication code to the platform at a specific frequency. The contactor also continuously reports to the server that it is in normal working condition. After receiving this report, the server remains in normal working condition. If a change in its position is detected, the transponder stops working normally, reports the change in position to the platform and the server, and stops working normally, and will not accept position verification requests.
[0146] The notifier continuously monitors the status of the connected positioning device. If no change in its position is detected, it remains in normal working condition, accepts requests for position verification, and notifies the contactor that it is in normal working condition. It also continuously notifies the connected workstation that it is in normal working condition. Upon receiving this notification, the workstation remains in normal working condition. If a change in its position is detected, the notifier stops normal operation, notifies the contactor and workstation that its position has changed and it has stopped normal operation, and does not accept requests for position verification.
[0147] A standalone anti-fraud system includes a location detection device, a disconnection detection device, and a transponder. It may or may not include a contactor, which is always powered on and sends signals to the platform at a specific frequency.
[0148] Our local area network (system) includes not only servers and workstations, but also a liaison. The liaison is always powered on and continuously sends a normal signal to the platform. The process is as follows: When an operator wants to indicate their location to the platform, they use their app to send a request to the client on their workstation, which includes a "personal key." The secondary client then sends a request to the primary client, which in turn sends a request to the liaison. If the anti-fraud system is functioning normally, and the liaison does not receive any abnormal information reported by the notification device at that location, it assumes that the location has not changed and sends a request to the responder at the location of the liaison. If it has received any abnormal information reported by the notification device at that location, it assumes that the location has changed, does not send a request to the responder, terminates the process, and only returns a response to the server indicating that "the device location has changed and has stopped working normally." However, the operation of clients on workstations at other locations is unaffected and can continue normally. After receiving a request from the contactor, the transponder checks the status of the location detection device at its location. If no location change is detected, the transponder sends its serial number and a dynamic location authentication key to the contactor. The contactor then forwards the transponder's serial number and location authentication key to the server. If the location detection device detects a location change, the transponder only returns a response to the contactor's request indicating that the location has changed and normal operation has stopped, without returning any other information. The main client combines the personal key, location authentication key, etc., to generate a location authentication code, and sends it to the platform along with the transponder's serial number and the operator's ZAPP username (along with the main client's serial number and a dynamic password to identify the user to the platform; this is a common practice and will not be described further below).
[0149] The following describes an example of an electronic payment process using a local area network (LAN) with authentication methods that can verify the operator's location. The process is discussed below for a more typical and complex scenario; see [link to relevant documentation]. Figure 15The initiator is not the payer or payee; the initiator has an affiliated organization. The payer and payee are individuals. The payee has an affiliated organization. In scams, the receiving accounts are mostly personal accounts because company accounts are harder to obtain, and legitimate company accounts are even harder to obtain. The specific process is as follows: a. First, the initiator (such as a distributor company leader) needs to log in to the auxiliary client (of the company's anti-fraud device) (entering username and password, and verifying successfully), and then use their APP to send a request to the auxiliary client (containing a "personal key" generated by a mobile phone encryption card) to initiate the process; the initiator first fills in the information (hereinafter referred to as "initiation information") on the protector, including the initiator's ZAPP username and the name of their company, the payment account (such as the distributor company's account) and the payer's ZAPP username, the receiving account (such as the supplier's account) and the payee's ZAPP username, the name of the payee's company, and the reason (if there is a notification, it needs to be attached, including the notification number, company name, and names of relevant personnel, etc.), etc., and the protector encrypts it and sends it to the auxiliary client (the same below); the auxiliary client then forwards the information to the server, and the server then forwards the information to the platform, also adding a location verification code, etc. It is crucial to contact the contact person of the payment account via ZAPP (using a specific username). Previously, bank cards typically had contact numbers, but perpetrators often lacked the contact person's ZAPP username, making impersonation impossible and rendering many acquired bank cards useless. The ZAPP username of a payment account's contact person can change, and the ZAPP username of a company's contact person might be a completely different username. For a large organization with numerous transactions, a single customer service representative might be insufficient, requiring multiple representatives. Therefore, the relationship between the payment account and the ZAPP username may not be fixed (hence the need to verify the identity of the recipient). This is an important point to note. b. After receiving the initiation information, the platform decrypts the plaintext and then verifies the initiator's identity and their relationship with their organization (if any) (this relationship must be verified beforehand), location authentication code, the recipient's relationship with their organization (if any) (this relationship must be verified beforehand), and the reason for the transaction. Once verified, a transaction serial number is assigned. If the initiation information includes notifications related to the business (which may have been previously sent to the platform by the initiator and forwarded to the payer and payee by the platform), the notification number, organization name, and notification content must be verified. The platform then sends a self-certification notification to the organization to which the initiator belongs, which includes the initiator's username, the reason for the transaction, and an authentication code generated by the platform indicating that the initiator's location verification has been successful (i.e., authentication pass code). This code can be encrypted against the contact's protector (the same applies below). When handling official business, the initiator should usually operate within the organization, and the process can often be initiated through a local area network.If the initiator initiates the process outside of their organization, the platform can suspend the process (not continue processing). If the initiator's information indicates they belong to the organization, but they do not actually belong to that organization, the platform can suspend the process (not continue processing) and notify relevant parties, as they are likely a violator. If the initiator's information indicates the payee belongs to an organization, but the payee does not actually belong to that organization, the platform can also suspend the process and notify relevant parties. c. The initiator's organization reviews the reason for the transaction and the authentication code. If the authentication code is verified and there are no objections to the reason for the transaction, a random question is sent to the initiator. d. The initiator returns the answer. e. The initiator's organization approves the answer and sends a location authentication code (generated using a location authentication key and a personal key) and a signal indicating the authentication opinion (whether there is any objection) to the platform using the main client, hereinafter referred to as the authentication opinion code. In this example, the initiator's organization's main client and the platform use a fixed key to synchronize the authentication opinion code and the location authentication code. Previously, there was no such signal indicating authentication opinion and location; verification codes were often used to identify the user. f. After the platform verifies the location authentication code and authentication opinion code, it sends a payment notification to the recipient's organization. The notification content is the same as what the initiator originally filled in, including the reason, payer's account, recipient's account, an authentication code indicating that the initiator and their organization's location verification is successful, and a password to identify the platform. If the notification to the recipient's organization were simply sent by the initiator, it would be easy to counterfeit (the initiator might change the content privately, and violators could easily impersonate the initiator). Therefore, we send the message indirectly to the recipient's organization through the platform. The message is encrypted (and then decrypted by ZAPP). The recipient's organization's ZAPP also verifies the platform's identity (through the password), making it difficult for violators to counterfeit. g. Upon receiving the notification, the recipient's organization reviews the reason, authentication code, etc. If approved, it sends a random question to the recipient. h. The recipient returns the answer. i. If the system is functioning normally, and the recipient's organization approves the answer, the organization will use the main client to return the authentication result to the platform, which includes one authentication opinion code and one location authentication code. The reason the recipient's organization confirms the transaction first, rather than the payer, is that the payer is often in a vulnerable position and requires special protection. When handling official business, the recipient should typically operate within the organization, either using a workstation to receive and send information via a local area network (LAN) or directly on the server. If the recipient initiates the process outside the organization, and the server detects that the received information originated from outside the LAN, the server can terminate the process (not continue processing) and notify the platform. If the recipient is indeed an individual, their identity and location do not need to be confirmed by their organization; the location authentication code can be generated from anti-fraud kiosks, location tags, etc.j. Simultaneously, the payee's organization sends a payment notification to the payee (the person or department handling the transaction), including the transaction serial number, reason, and payer's username. Sending the notification first to the payee's organization, which then forwards it to the payee (individual), prevents forgery. Otherwise, if the initiator directly sends the full text of the payment notification to the accomplice (payee), the accomplice can also respond correctly. k. After receiving the authentication opinion code and location authentication code from the payee's organization, if the platform verifies these codes, it sends an authentication request to the payee via the server (encrypted), containing only the transaction serial number. The reason for requiring confirmation from the payee after obtaining confirmation from the payee's organization is to prevent perpetrators from impersonating the payee or deceiving the payee. When sending the authentication request, the platform should not provide all information but should allow the payee to provide the details for verification. If everything is provided, perpetrators will agree to everything. Only the genuine initiator can send the correct encrypted message to the platform and pass identity verification; only the organization to which the genuine recipient belongs can receive the message from the platform and decrypt it correctly. Impersonating the recipient (or their organization) will not receive the corresponding authentication request or payment notification, nor can they decrypt the plaintext of the payment notification. l. After receiving the payment notification from their organization and the authentication request from the platform, if the authentication result is undisputed (indicating that the transaction is indeed within their scope), the recipient returns the reason, organization name, one authentication opinion code, and location authentication code to the platform through the main client. When handling official business, the recipient should usually operate within the organization, either directly on the server using the organization's responder to generate the corresponding key and then the location authentication code; or they can send information through the local area network for the server to process. If the recipient is indeed an individual, the location authentication code can be generated from a public anti-fraud kiosk or using location stickers. If the recipient is entrusted to collect or transfer funds for others, a prior entrustment contract must be signed with the entrusting party. When the recipient returns the reason for the transfer, if it's due to being entrusted to transfer funds to another person, a power of attorney must be submitted simultaneously. If the initiator entrusts another person to transfer funds, there should be a contract or agreement. This not only provides a record (making it traceable) but also exposes the crime to multiple people, preventing fraud in advance. Perpetrators may use "too much trouble" as an excuse to avoid signing contracts or agreements. Templates can be pre-set to automatically fill in the content, completing the process quickly and eliminating the excuse of "too much trouble." If the other party refuses to sign, they are likely the perpetrator. Usually, the recipient doesn't need to edit the reason before sending it to the platform; the reason can be obtained from the payment notification sent by their employer. If the verification result is undisputed, it can be directly forwarded (to the platform). The platform verifies the reason and location verification code returned by the recipient. If the reason matches the record and the location verification code passes verification, the platform sends an encrypted payment notification to the payer's app.This notification includes not only all the information initially filled in by the initiator, but also confirmation information about the recipient's organization, the recipient's explanation of the reason for the payment, the organization's name, and the identification results for each entity, material, and reason. If there is a power of attorney, it must also be attached. If there are textual differences in the reason for the payment, the person who made the modification needs to submit a modification explanation, and the payer will manually verify it. This payment notification can include a PDF file with an official seal, making it difficult for ordinary people to forge. Of course, criminals can still create such a file with some time, so we also use a dynamic identification code to indicate the identification opinion, making it difficult for adversaries to counterfeit. If the recipient and payer do not know each other, it is difficult for them to agree on a key, so it is difficult for the recipient and payer to synchronize the identification code. A platform is needed as an intermediary. The recipient first sends the identification code to the platform, and the platform verifies it before generating an identification code for the payer. If both parties know each other, they can directly agree on a key, which is more secure and prevents fraud involving relatives and friends. The payment notification also includes an authentication code indicating that the locations of the initiator, the initiator's organization, the payee, and the payee's organization have all been verified. After the payer's app verifies the authentication code and authentication pass code, it displays the notification content to the payer. The payer checks the notification and, if there are no objections, communicates with the payee (the responsible personnel or department) through the platform via a call (both parties must send location authentication codes, which can be achieved using an answering machine or an anti-fraud kiosk, etc.) to verify identity and transaction details. (We prioritize using voice messages or recorded calls for communication, rather than traditional non-recording phone calls, as this makes it easier to preserve evidence). By employing these communication methods, instances of perpetrators deceiving both the payer and payee will be significantly reduced. o. The payer confirms all information in the notification without objection and clicks "Confirm" on their client or app (or a public anti-fraud device, or even a mobile phone, if no company-provided anti-fraud device is available). The client or app then generates an authentication code and a location authentication code and sends them to the platform. If there is any objection, the payer clicks "Objection," the process is immediately stopped, and a "Statement of Objection" is uploaded. If the issue may involve criminal activity, the platform can immediately report it to the relevant authorities. p. The payer then uses their bank's app or a terminal at a bank branch to complete the payment. q. After verifying the authentication code and location authentication code sent by the payer, the platform generates a transaction confirmation letter (containing the transaction serial number, an authentication code, and an authentication pass code indicating successful location verification) and sends this confirmation letter to the bank of the payment account. If the user personally presents the authentication code sent by the platform to the bank, the bank will have difficulty verifying its authenticity (it is difficult for the bank and user to synchronize their keys). Therefore, the platform should send the transaction confirmation letter to the bank.r. The bank will execute the payment instruction only after the authentication opinion code in the confirmation letter and the authentication pass code sent by the platform to indicate the location of the payee have been verified. If the authentication opinion code and authentication pass code fail to be verified, the payment instruction will be rejected.
[0150] Location verification is a core function of the anti-fraud system, and it goes beyond simply verifying location authentication codes. Location verification is divided into three levels: low, medium, and high. Low-level location verification determines whether the user is abroad; medium-level location verification verifies whether the user's location falls within the agreed-upon range; and high-level location verification verifies whether the user's location matches the reason for their visit.
[0151] For casual chats, it's sufficient to determine if the user is located abroad. For important communications, the user should operate from the agreed-upon location. If the user is not at the agreed-upon location, they should ask a colleague or family member to complete the operation. For operations such as payments or signatures, it's also necessary to verify that the user's location matches the purpose. However, the relationship between the verification level and the type of operation is not fixed. Even in casual chats, the other party can request a higher verification level, as the importance of information in chats is often difficult to determine. However, the minimum verification level for each operation is usually fixed; for example, payments must be at the high level.
[0152] Location verification may include the following steps: After receiving a verification request, the platform first determines whether the user is located abroad. If the user uses a transponder to send the request, the platform examines the transponder's ID. If its registration location is in China, the platform verifies the location authentication code. If the verification passes, the process continues.
[0153] If the user has a cryptographic chip, they must also use it to send a verification request (adding verification information improves security, significantly increases the difficulty of attacks, and further confirms location). This request includes an authentication code, generated using the plaintext coordinates as the key. The platform decrypts the ciphertext to obtain the plaintext coordinates and then verifies the authentication code. If the authentication code verification passes, the platform examines whether the plaintext coordinates match the registered location of the transponder. If they match, the platform acknowledges the authenticity of the information and determines whether the user is located abroad based on the plaintext coordinates. If the user does not have a transponder and only uses a cryptographic chip to send a verification request, the platform verifies the authentication code based on the plaintext coordinates. If the authentication code verification passes, the platform acknowledges the authenticity of the information and determines whether the user is located abroad based on the plaintext coordinates. If the user is found to be located abroad, the platform sends a location authentication code indicating that the sender is abroad and immediately stops the process, notifying all relevant parties until the situation is verified.
[0154] If the verification level is high, and the registered location is in China, the platform will further examine whether the location falls within the agreed verification locations. If it does, the platform will verify the received transponder number, ZAPP username, etc. If the location does not fall within the agreed verification locations, or the transponder number does not match the ZAPP username, or the location authentication code is not received, the platform will send an authentication code to the other party indicating that the location verification of the sender has failed, and immediately suspend the process, notify all relevant parties, and take further action after verifying the situation.
[0155] If the location is among the user's agreed verification locations, the platform will then examine whether the submitted reason matches the work (enterprise, institution) scope of the unit at that location. If they match, the platform will send an authentication code to the other party indicating that the location verification is successful and the reason matches; if they do not match, the platform will send an authentication code to the other party indicating that the location verification is successful but the reason does not match.
[0156] The communication and payment process using trajectory verification can be as follows: The user first sends a notification to the platform at an appropriate time to begin the trajectory verification task and verifies their identity using a fixed anti-fraud device. After successful identity verification, the platform begins recording their trajectory. Simultaneously, the app also sends a notification to the location chip to begin the trajectory verification task. Upon receiving this notification, the location chip enters trajectory verification mode. Then, the chip sends encrypted location data to the platform via the app at a certain frequency, and also sends an authentication code to the platform via the app at another frequency. After decrypting the encrypted location data, the platform calculates the user's movement speed. If the speed is within a reasonable range, it checks whether the authentication code matches the location. If they match, the location is confirmed as authentic, and the user's identity remains valid. When a user sends a message or makes a payment request, they first edit and view the text of the communication content or payment information on the protector. After confirming that it is correct, they press the signature button. The protector then sends a query request to the key chip, requesting the return of summary value 1. The key chip generates summary value 1 based on the coordinates and time of the trajectory points with the largest and smallest values in the current east-west-north-south directions, and encrypts it with the current location before sending it to the protector. After decryption, the protector generates verification code 1 based on summary value 1, username, and text. The key of verification code 1 changes with the current location. This verification code is then encrypted and sent to the platform. After the platform verifies verification code 1, it generates confirmation code 1 based on the current location and text number, and encrypts the text before sending it to the protector. If the response time is within the specified standard, the protector generates confirmation code 1 in the same way. If confirmation code 1 is verified and the decrypted information text is correct, the protector sends a query request to the APP, requesting the return of summary value 2. If the response time exceeds the specified standard, the process is terminated and a notification is issued.
[0157] Upon receiving the request, the app generates a summary value 2 using the number, location, and time of currently visited destinations, encrypts it, and sends it to the protector. The protector decrypts the summary value and generates a confirmation code 2, which is then sent to the platform. If the user has a fixed anti-fraud device nearby, they can use it to send verification information. The transponder sends its ID and a key for generating an authentication code to the contactor; the contactor then forwards the ID and key to the server. The main client, combining its personal key and the key sent by the transponder, generates an authentication code; this authentication code, along with the transponder's ID and the user's username in the system, is then encrypted and sent to the platform. If the user does not have a fixed anti-fraud device nearby, they can send verification information without using one. Once the platform verifies the information, it sends the message and payment request to the recipient and the corresponding bank.
Claims
1. A communication and payment system capable of verifying the location of an operator, characterized in that, It includes a platform, an operator's mobile phone, a chip for providing encryption keys to the mobile phone, a device for protecting text, a positioning chip for encrypting location information, and an integral part of multiple systems and devices that provide location verification services for multiple devices, as well as an integral part of multiple systems and devices that provide location verification services for individual devices. The operator's mobile phone has a dedicated APP installed; On the separate device, a client specifically designed for that device is installed. The system for verifying location serves multiple devices, including computers and mobile phones. A system that provides location verification services for multiple computers, including but not limited to one server and multiple workstations; The server is equipped with a dedicated client application. The workstation is equipped with a dedicated client application. A system that provides location verification services for multiple computers is located in a fixed location; The system described above provides location verification services for multiple computers with fixed locations. It includes a device that maintains constant communication with the platform, a chip for verifying location, and a device connected to the chip for detecting changes in location. Multiple devices for reporting detection results to a device that is always in contact with the platform, and connected to it for detecting changes in position; The chip used for verifying the position is located in the device that is always in contact with the platform, and is connected to a device for detecting changes in position and a device for checking whether the circuit is interrupted. The device that maintains constant contact with the platform is located at the server's location and is connected to both the server and the modem. The device, which maintains constant contact with the platform, is always powered on; The device used to report test results to the device that maintains constant contact with the platform is located at each workstation and is connected to a device for detecting changes in position, a device for checking for circuit interruptions, a device that maintains constant contact with the platform, and the workstation. If the chip used to verify the position does not receive a message indicating an overcurrent interruption from the device used to check if the circuit is interrupted during this power-on, the status of the device used to detect changes in position will be continuously monitored. If no change in its position is detected, the chip used to verify the position is in normal working condition, can accept requests to verify the position, and sends a normal identification code for indicating the position to the device that is always in contact with the platform at a specific frequency. The device, which maintains constant communication with the platform, then sends a normal authentication code indicating its location to the platform at a specific frequency. The device that maintains constant contact with the platform also continuously reports to the server that it is in normal working condition; upon receiving this report, the server maintains its normal working condition. If a change in its location is detected, the chip used to verify the location will stop working normally, notify the platform and server that its location has changed and will stop working normally, and will not accept requests to verify the location. The device is used to report the test results to the device that is always in contact with the platform, and to continuously monitor the status of the device connected to it for detecting changes in position. If no change in its location is detected, and it remains in normal working condition, it can accept requests to verify its location and notify the device that is in constant contact with the platform that it is in normal working condition. It also continuously notifies the connected workstations that it is in normal working condition; upon receiving the notification, the workstation maintains its normal working condition. If a change in its location is detected, the device used to report the detection results to the device that maintains constant contact with the platform will stop working normally, report the change in its location to the device and workstation that maintain constant contact with the platform, and will not accept requests to verify the location. A system that provides location verification services for multiple mobile phones can be either fixed-location or non-fixed-location, including but not limited to: a host, multiple mobile phones, multiple temporary fixed-location verification devices, and multiple wristbands connected to the temporary fixed-location verification devices. The host and the temporary fixed-position verification device each have a device for detecting changes in position; The wristband connected to the verification device with a temporary fixed location can be turned on and off; In the system that provides location verification services for multiple mobile phones, if the host and the device for detecting location changes in each of the temporary location-fixed verification devices do not detect any location change, and the wristband on the user's wrist that is connected to the temporary location-fixed verification device is turned off, the server will process the received location verification request normally; otherwise, it will suspend location confirmation. The system that provides location verification services for individual devices includes a device for detecting location or detecting changes in location, a device for checking whether the circuit is interrupted, a chip for verifying location, and may or may not include a device that maintains constant communication with the platform. The device, which maintains constant contact with the platform, is always powered on and sends signals to the platform at a specific frequency.
2. The system according to claim 1, and a device for detecting position changes, characterized in that, It includes a detection circuit that is fixed to the anchor. The detection circuit is connected to the chip used for position verification; The chip used for verifying the location, if it detects that the detection circuit is turned on, determines that the location has not changed and is working normally. For a valid request to verify the location received, it returns a key for generating an authentication code representing the location. If the chip used for verifying the location detects that the detection circuit is not conducting, it determines that the location has changed, stops working normally, and does not return the key used to generate the authentication code representing the location to the received request for location verification, or returns a response indicating that the status is abnormal.
3. The system according to claim 1, and a device for detecting position changes, characterized in that, It contains a sealed container filled with a certain amount of liquid; A buoy containing lightweight material is placed on the surface of the liquid and floats on the liquid surface; the surface of the buoy has a mirror that can reflect light; a set of transmitters and receivers is installed above the container; the receiver is connected to the chip used to verify the position. A magnet is located in the middle of the buoy, and an iron plate is located in the middle of the bottom of the container; When the transmitter and receiver are positioned at a specific angle, and the container is horizontal and the liquid is still, the receiver can receive the light. If the chip used for verifying the location detects that the receiver has received light and is working normally, it will return a key for generating an authentication code representing the location in response to a valid request for location verification. If no valid request for location verification is received, it will emit an authentication code representing the location at a specific frequency. If the chip used for location verification detects that the receiver has not received light, it stops working normally, does not return the key for generating the authentication code representing the location to the received request for location verification, and returns a response indicating that the status is abnormal, and does not issue the authentication code representing the location.
4. The system according to claim 1, and a device for detecting position changes, characterized in that, A spring is installed at the bottom of the device housing, and an inertia rod is installed at the upper end of the spring. A contact ring is installed outside the spring, and the contact ring is fixed to the housing by a fixing rod. The spring and the fixing rod are respectively connected to the chip used to verify the position to form a detection circuit. After the device is installed, when the equipment is stationary, the spring and the contact ring do not contact each other. If the chip used to verify the position does not detect that the detection circuit is conducting, it will work normally and return a key for generating an authentication code representing the position to the received legitimate request to verify the position. If the chip used for location verification detects that the detection circuit is turned on, it will report the situation and stop working. It will not return the key used to generate the authentication code representing the location to the received request for location verification, and will respond that the status is abnormal.
5. The system according to claim 1, using the aforementioned device for protecting text, combined with a mobile phone and computer, and the method for inputting characters, is characterized by: On the mobile phone screen and computer screen, two rectangular arrays are displayed. In one rectangular array, each cell shows the position of each character in plain text. The other rectangular array is clickable by the user for manual input of information. On the screen of the device for protecting text, a rectangular array is displayed, showing the positional relationship between the cell containing the plaintext character to be entered by the user and the cell clicked by the user; the plaintext character to be entered by the user is set at the center of the array, and the center of the array and the cell clicked by the user are marked with different symbols; When a user wants to input a character, the system first locates the cell containing the plaintext of the character they want to input by referring to the array of positions of each character displayed on the mobile phone screen or computer screen. Then, on the screen of the device for protecting text, the positional relationship between the cell containing the plaintext character that the user is about to input and the cell that the user clicked is identified. Based on this location relationship, the user can then locate the cell on the mobile phone or computer screen where the character is to be entered, and then click on that cell. The mobile phone or computer then sends the location of the cell clicked by the user to the aforementioned device for protecting text; The device for protecting text then determines the cell containing the plaintext of the character the user wants to input, based on the position of the cell clicked by the user and the current transformation relationship, and then determines the character the user wants to input. The device for protecting the text described later displays the decrypted characters, allowing the user to verify the correctness of their input.
6. The system according to claim 1, A method for inputting Chinese characters into the text protection device using the keyboard on the aforementioned text protection device, and the keyboard on a computer or mobile phone, is characterized in that... First, enter the pinyin letters. The device for protecting text uses 5 keys, while the keyboard on a computer or mobile phone uses 2 rows of keys, with 3 keys in each row; The pinyin letters are divided into 5 groups, with 5 letters in each group, excluding the letter V; The keys on the device for protecting text are used to select the group of letters; The keys on a computer or mobile phone are used to select letters in each group; Of the keys on the computer or mobile phone used to select letters in each group, one cannot be used to input letters. Its position is randomly determined and changes, and is displayed in real time on the screen of the device used to protect the text. The key is used to input which letter, which is variable and is displayed in real time on the screen of the device used to protect the text. The user first presses keys on the keyboard of the device used to protect text to select the group containing the letters; Then, according to the rule that each key is used to input which letter, after pressing a key on a computer or mobile phone, the computer or mobile phone forwards the information sent from its keyboard to the device used to protect the text. The device for protecting text uses this information, and the information provided by the keyboard of the device for protecting text, to determine the letter selected by the user; The corresponding words are displayed on the screen of the device for protecting text. The order of the words and phrases changes randomly. Each word or phrase is marked to indicate which word or phrase to select. Following the prompts on the screen of the device for protecting text, the user enters the corresponding marks on the keyboard of a computer or mobile phone. The aforementioned device for protecting text determines the words that the user wants to input based on markers sent by a computer or mobile phone.
7. In the system according to claim 1, the process of a user sending a message is characterized by: When a user wants to send a message, after pressing the signature key on the device used to protect the text, the system switches to a mode that only allows the running of specific text-editing related applications. The device for protecting text first sends a request to the chip for verifying location and the positioning chip that can encrypt location information. The chip used for verifying location and the positioning chip that can encrypt location information generate a key based on the location and return it. The device for protecting text receives the key determined by the chip for verifying location and the positioning chip for encrypting location information based on the location, and then combines the key of the device for protecting text to encrypt the message and send it to the platform. After the platform decrypts the message with the corresponding key, it obtains the ciphertext based on the key of the device used to protect the text as described by the recipient, and then sends it back to the recipient. After receiving the message, the recipient returns a confirmation message; The platform then sends a confirmation message back to the message sender; After receiving the confirmation message, the sender's system exits the mode that only allows the running of specific text editing applications.
8. The system for providing location verification services for multiple devices at a fixed location, as described in claim 1, and the devices served by that system. When it is working properly, the characteristic of the process by which the user uses the workstation to issue an authentication code to indicate the location through the system is that... First, the user initiates the process by sending a request to the client specifically designed for the workstation using their APP. The request includes a key generated by a chip used to provide encryption keys to the mobile phone. The client, which is dedicated to the workstation, then sends a request to the client on the server, which includes a key generated by the chip used to provide encryption keys to the mobile phone; If the system providing location verification services for multiple devices and the devices providing those services are operating normally... After receiving the above request, the dedicated server client then sends a request to the device that maintains constant contact with the platform. The device that maintains constant contact with the platform then sends a request to the chip used for location verification located at the location of the device that maintains constant contact with the platform. The chip used for location verification then sends the chip's serial number and a key for generating an authentication code representing the location to a device that maintains constant contact with the platform. The device that maintains constant contact with the platform then forwards to the server the chip number used to verify the location and the key used to generate the authentication code representing the location; The dedicated server client, in conjunction with the key generated by the chip used to provide encryption keys to the mobile phone and the key used to generate the authentication code representing the location, generates an authentication code representing the location. The authentication code, along with the chip number used to verify the location and the user's username in the system, is then encrypted and sent to the platform.
9. The communication and payment system capable of verifying the operator's location as described in claim 1. If a user sends a message through the platform requiring verification of the sender's location, or sends a payment request to a bank or related party... The characteristics of the platform's location verification process are: The messages and payment requests sent by the user to the platform may include an authentication code for representing the location generated using the chip used to verify the location, and ciphertext of the location generated using the positioning chip that can encrypt the location information, as well as the authentication code for representing the location. After receiving the verification request, the platform first determines whether the user is located abroad. If the user sends a verification request using the chip described above for location verification, The platform examines the serial number of the chip used for location verification. If the registered location is overseas, the platform will send the other party an identification code indicating that the person who sent the information is overseas, and immediately suspend the process, notify all relevant parties, and take further action after verifying the situation. If its registration location is in China, the platform verifies the identification code generated by the chip used for location verification. If the verification is successful, the process continues. If the user has the aforementioned location-encrypting chip, the user also needs to use the aforementioned location-encrypting chip to generate ciphertext of the coordinates; and use the key provided by the aforementioned location-verifying chip, along with the authentication code generated by the aforementioned location-encrypting chip, to send to the platform. The platform decrypts the ciphertext of the coordinates to obtain the plaintext of the coordinates, and then verifies the authentication code. If the authentication code matches the plaintext of the coordinates, then examine whether the plaintext of the coordinates matches the location of the registered location of the chip used to verify the location. If they match, acknowledge the authenticity of the information and continue processing. If the location verification fails, the platform will send an authentication code to the other party. If the user does not have the chip for verifying location, the user can send a verification request using the positioning chip that can encrypt location information. The request includes an authentication code, which is generated using the plaintext of the coordinates as the key. After obtaining the plaintext coordinates, the platform verifies the authentication code. If the authentication code is verified, the platform acknowledges the authenticity of the information and determines whether the location is overseas based on the plaintext coordinates. If the sender is found to be abroad, the platform will send an authentication code indicating that the sender is abroad and immediately suspend the process, notify all relevant parties, and take further action after verifying the situation; if the sender is in China, the process will continue. If the level of verification is higher, it is also necessary to verify whether the user's location is included in the agreement and whether the user's location matches the reason for the investigation. If the chip used for location verification is registered in China, the platform will then examine whether that location falls within the user's agreed-upon verification locations. If it does, The platform then verifies the serial number of the chip used to verify the location, the username of the client used to authenticate the transaction, and the username used for payment. If the location is not among the agreed verification locations, or the chip number used for location verification does not match the username of the client used to verify the authenticity of the business and make payment, or the verification code used to indicate the location is not received, the platform will send an verification code to the other party indicating that the location verification of the sender has failed, and immediately suspend the process, notify the relevant parties, and take further action after verifying the situation. If the location is among the user's agreed verification locations, the platform will then examine whether the submitted reason matches the work scope of the unit at that location. If they match, the platform will send an authentication code to the other party indicating that the location verification is successful and the reason matches. If they do not match, send an authentication code to the other party indicating that the location verification passed but the reason does not match.
10. The communication and payment system capable of verifying the operator's location according to claim 1, characterized in that the system verifies the user's identity based on the user's movement trajectory and completes the communication and payment process, has the following features: Users need to send a notification to the platform via their APP at an appropriate time to start the trajectory verification task, and use the communication and payment device with a fixed verifiable location to verify their identity; the device sends the verification information to the platform, and after the identity verification is successful, the platform confirms the user's identity and begins to record the user's trajectory. At the same time, the APP also sends a notification to the location chip that can encrypt location information to start executing the trajectory verification task. After receiving the notification, the location chip that can encrypt location information enters the trajectory verification mode and begins to perform relevant processing. The chip then sends its location in encrypted form to the platform via the app at a certain frequency. It also sends an authentication code to the platform via the APP at another frequency to indicate its location; After decrypting the ciphertext of the location, the platform calculates its movement speed; If the speed is within a reasonable range, then check whether the authentication code used to represent the location matches the location; if they match, then confirm that the location is real and the identity remains valid. When a user sends a message or makes a payment request First, on the device used to protect the text, edit and view the text containing communication content or payment information. After confirming that everything is correct, press the signature button on the device used to protect the text. The device for protecting text sends a query request to the positioning chip, which is capable of encrypting location information, requesting a summary value of 1. The positioning chip that can encrypt location information generates a summary value of 1 based on the coordinates and time of the trajectory points with the largest and smallest values in the current east, west, south, and north directions, and encrypts it with the current location before sending it to the device for protecting text. After decryption, the device for protecting the text generates a verification code 1 based on the summary value 1, username, and text. The key changes depending on the current position. Then encrypt the username, password, message text, text number, and verification code 1 and send them to the platform; After the platform verifies the verification code 1, it generates confirmation code 1 based on the current location and the text number, and encrypts the text with another key, and sends it to the user's device for protecting the text via mobile phone or computer. If the response time is within the specified standard The device for protecting text also generates confirmation code 1 in the same way. If confirmation code 1 is verified and the decrypted information text is correct, a query request is sent to the APP to request the return of summary value 2. If the response time exceeds the specified standard, the process will be suspended and a notification will be issued; After receiving the request, the APP generates a summary value 2 using the number, location, and time of the destinations it has visited, and encrypts it before sending it to the device for protecting the text. The device for protecting the text decrypts the summary value 2 and generates a confirmation code 2, which is then sent to the platform. If a user has a communication or payment device with a fixed and verifiable location nearby, the user can use that device to send verification information. The chip used for location verification in the communication and payment device sends the chip's serial number and a key for generating an authentication code representing the location to a device that maintains constant contact with the platform. The device that maintains constant contact with the platform then forwards to the server the chip number used to verify the location and the key used to generate the authentication code representing the location; The dedicated server client, in conjunction with the key generated by the chip used to provide encryption keys to the mobile phone and the key used to generate the authentication code representing the location, generates an authentication code representing the location. The authentication code, along with the chip number used to verify the location and the user's username in the system, is then encrypted and sent to the platform. If the user does not have a communication or payment device with a fixed and verifiable location nearby, the verification information can be sent without using the communication or payment device with a fixed and verifiable location. Once the platform verifies the transaction, it will send the message and payment request to the recipient and the corresponding bank.