Message verification method and system

The message verification method and system address the issue of smishing by allowing users to verify the authenticity of messages through a matching process between first and second verification messages, effectively preventing malicious interactions and data breaches.

WO2025105748A1PCT designated stage expired Publication Date: 2025-05-22ATON INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/017135
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-13
Filing Date
2024-11-04
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

The increasing prevalence of smishing, which involves sending malicious text messages to smartphone users, poses a significant threat as users are often unaware of the authenticity of incoming messages, leading to potential data breaches and financial losses.

Method used

A message verification method and system that involves receiving a first verification message and a second verification message, determining whether they match, and providing a determination result to the user terminal, thereby allowing users to verify the authenticity of messages without directly interacting with potentially malicious links or contacts.

Benefits of technology

This solution effectively prevents users from falling victim to smishing by allowing them to verify the authenticity of messages without exposing themselves to potential threats, thereby minimizing data leakage and financial losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024017135_22052025_PF_FP_ABST
    Figure KR2024017135_22052025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention provides a message verification method and system, the method being performed by a verification intermediary system. The message verification method may comprise the steps of: receiving a first verification message including at least a portion of a first message transmitted by a message processing system; receiving a second verification message including at least a portion of a second message received by a user terminal; and determining whether the received first verification message and the received second verification message match.
Need to check novelty before this filing date? Find Prior Art

Description

Message Verification Method and System

[0001] The present disclosure relates to a message verification method and system, and more particularly, to a method and system for verifying messages to prevent smishing.

[0002]

[0003] The recent increase in smartphone adoption and technological advancements have led to a rise in smartphone-related crimes. In particular, smishing, a combination of phishing and text messaging (SMS), is becoming increasingly prevalent. Smishing refers to a criminal technique whereby a text message is sent to a smartphone user to download or install a viral application or malware onto the user's device, thereby collecting personal information or encouraging mobile payments. As the use of text messages for information transmission increases, the damage caused by smishing is also on the rise.

[0004] The only way for recipients to verify the authenticity of a message sent by the sender is to contact the sender directly or access a link included in the message. If recipients make a phone call or access a link to verify the contact information or link, they are exposed to smishing.

[0005]

[0006] The present disclosure provides a message verification method, a computer program stored in a recording medium, and a system (device) for solving the above-described problems.

[0007]

[0008] The present disclosure can be implemented in various ways, including a method, a device (system), and / or a computer program stored in a computer-readable storage medium, and a computer-readable storage medium having a computer program stored therein.

[0009] According to one embodiment of the present disclosure, a message verification method performed by a verification intermediary system may include the steps of: receiving a first verification message including at least a portion of a first message transmitted by a message processing system; receiving a second verification message including at least a portion of a second message received from a user terminal; and determining whether the received first verification message and the received second verification message match.

[0010] According to one embodiment of the present disclosure, the message verification method may further include, in response to determining whether the first verification message and the second verification message match, providing a determination result indicating one of a message match determination or a message mismatch determination to the user terminal.

[0011] According to one embodiment of the present disclosure, the step of determining whether the received first verification message and the received second verification message match includes the step of transmitting the first verification message to a user terminal, and the message verification method can determine whether the transmitted first verification message and the second verification message match by a verification application operating on the user terminal.

[0012] According to one embodiment of the present disclosure, the message verification method further includes a step of providing a determination result indicating a message matching determination to a message processing system, and in response to receiving the determination result indicating a message matching determination, message details associated with information included in the first message may be provided from the message processing system to a user terminal.

[0013] According to one embodiment of the present disclosure, the second verification message can be generated by extracting information indicating or characterizing an entity operating a message processing system from the second message by a verification application of the user terminal.

[0014] According to one embodiment of the present disclosure, the first verification message may include a message in which anonymization processing is performed on sensitive information included in the first message by a message processing system.

[0015] According to one embodiment of the present disclosure, the second verification message may include a message in which anonymization processing is performed on sensitive information included in the second message by a verification application of the user terminal.

[0016] According to one embodiment of the present disclosure, the first verification message further includes first identification information associated with the first message, the second verification message further includes second identification information associated with the second message, and the step of determining whether the received first verification message matches the received second verification message may include the step of determining whether the first verification message matches the second verification message by determining whether the first identification information and the second identification information match.

[0017] According to one embodiment of the present disclosure, a message verification method operated by a verification application of a user terminal may include a step of receiving information indicating or characterizing an entity operating a message processing system, a step of receiving a message from the message processing system, a step of receiving a verification message from a verification intermediary system, a step of extracting information corresponding to received information from the received message, and a step of determining whether the received message matches the received verification message if the extracted information matches the received information.

[0018] A computer program stored in a computer-readable recording medium may be provided to execute a method according to one embodiment of the present disclosure on a computer.

[0019] According to one embodiment of the present disclosure, a verification intermediary system comprises a communication module, a memory, and at least one processor connected to the memory and configured to execute at least one computer-readable program contained in the memory, wherein the at least one program may include instructions for receiving a first verification message including at least a portion of a first message transmitted by a message processing system, receiving a second verification message including at least a portion of a second message received at a user terminal, and determining whether the received first verification message matches the received second verification message.

[0020]

[0021] According to some embodiments of the present disclosure, a user can verify the sender of a message without performing any additional actions on the information contained in the message. Furthermore, the invention according to the present disclosure can prevent users from being targeted by smishing by screening out smishing messages among received messages.

[0022] According to some embodiments of the present disclosure, the authenticity of all messages received by a user terminal is not verified, and the authenticity of messages containing pre-entered information can be selectively determined. In other words, the authenticity of messages regarding a specific entity operating the message processing system can be selectively determined.

[0023] According to some embodiments of the present disclosure, if communication between the verification intermediary system and the user terminal is difficult or the verification intermediary system's response is delayed, the verification intermediary system may be delayed in determining whether the first and second verification messages match. The invention according to the present disclosure can resolve this issue by determining whether the first and second verification messages match at the user terminal. Furthermore, if the message contains sensitive information, the message content is not provided to external systems, such as the user terminal, thereby minimizing the leakage of sensitive information.

[0024] According to some embodiments of the present disclosure, a verification message generated based on an anonymized message may not contain sensitive information. Since sensitive information is not transmitted to the user terminal and / or external systems of the message processing system, personal information may be prevented from being leaked.

[0025] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs (referred to as “one skilled in the art”) from the description of the claims.

[0026]

[0027] Embodiments of the present disclosure will be described below with reference to the accompanying drawings, wherein like reference numerals represent similar elements, but are not limited thereto.

[0028] FIG. 1 is a diagram showing an example of a user terminal receiving a message according to one embodiment of the present disclosure.

[0029] FIG. 2 is a schematic diagram showing a configuration connected to enable communication between a message processing system, a verification intermediary system, and multiple user terminals for message verification according to one embodiment of the present disclosure.

[0030] FIG. 3 is a block diagram showing the internal configuration of a computing device according to one embodiment of the present disclosure.

[0031] FIG. 4 is a flowchart illustrating an example of a message verification method according to one embodiment of the present disclosure.

[0032] FIG. 5 is a flowchart illustrating an example of a message verification method according to one embodiment of the present disclosure.

[0033] FIG. 6 is a diagram showing an example of performing anonymization processing of sensitive information according to one embodiment of the present disclosure.

[0034] FIG. 7 is a flowchart illustrating an example of a message verification method according to one embodiment of the present disclosure.

[0035]

[0036] Hereinafter, specific details for implementing the present disclosure will be described in detail with reference to the attached drawings. However, in the following description, specific descriptions of widely known functions or configurations will be omitted if they may unnecessarily obscure the gist of the present disclosure.

[0037] In the attached drawings, identical or corresponding components are assigned the same reference numerals. Furthermore, in the description of the embodiments below, duplicate descriptions of identical or corresponding components may be omitted. However, even if a description of a component is omitted, it is not intended that such component is not included in any embodiment.

[0038] The advantages and features of the disclosed embodiments, and methods for achieving them, will become clearer with reference to the embodiments described below, along with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure the completeness of the disclosure and to fully inform those skilled in the art of the scope of the invention.

[0039] The terms used in this specification will be briefly explained, followed by a detailed description of the disclosed embodiments. The terms used in this specification have been selected from widely used, current terms, taking into account the functions of the present disclosure. However, these terms may vary depending on the intentions of engineers working in the relevant field, precedents, the emergence of new technologies, etc. Furthermore, in certain cases, terms may be arbitrarily selected by the applicant, and in such cases, their meanings will be described in detail in the relevant description of the invention. Therefore, the terms used in this disclosure should not be defined simply as names of terms, but rather based on their meanings and the overall content of the present disclosure.

[0040] In this specification, singular expressions include plural expressions unless the context clearly indicates otherwise. Furthermore, plural expressions include singular expressions unless the context clearly indicates otherwise. When a part of the specification is said to include a component, this does not exclude other components, but rather implies that other components may be included, unless otherwise specifically stated.

[0041] Also, the term 'module' or 'part' used in the specification means a software or hardware component, and the 'module' or 'part' performs certain roles. However, the 'module' or 'part' is not limited to software or hardware. The 'module' or 'part' may be configured to reside on an addressable storage medium and may be configured to execute one or more processors. Thus, as an example, the 'module' or 'part' may include at least one of components such as software components, object-oriented software components, class components, and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, or variables. The functionality provided within the components and 'modules' or 'parts' may be combined into a smaller number of components and 'modules' or 'parts', or further separated into additional components and 'modules' or 'parts'.

[0042] According to one embodiment of the present disclosure, a 'module' or 'unit' may be implemented as a processor and a memory. 'Processor' should be broadly construed to include a general-purpose processor, a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a controller, a microcontroller, a state machine, and the like. In some circumstances, a 'processor' may also refer to an application-specific integrated circuit (ASIC), a programmable logic device (PLD), a field-programmable gate array (FPGA), and the like. A 'processor' may also refer to a combination of processing devices, such as, for example, a combination of a DSP and a microprocessor, a combination of multiple microprocessors, a combination of one or more microprocessors in conjunction with a DSP core, or any other such combination of configurations. In addition, 'memory' should be broadly construed to include any electronic component capable of storing electronic information. 'Memory' may refer to various types of processor-readable media, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable PROM (EEPROM), flash memory, magnetic or optical data storage, registers, etc. Memory is said to be in electronic communication with the processor if the processor can read information from, and / or write information to, the memory. Memory integrated in a processor is in electronic communication with the processor.

[0043] In addition, terms such as first, second, A, B, (a), (b), etc. used in the following embodiments are only used to distinguish certain components from other components, and the nature, order, or sequence of the components are not limited by the terms.

[0044] Additionally, in the embodiments below, when it is described that a component is 'connected', 'coupled' or 'connected' to another component, it should be understood that the component may be directly connected or connected to the other component, but another component may also be 'connected', 'coupled' or 'connected' between each component.

[0045] In the present disclosure, 'each of the plurality of As' may refer to each of all components included in the plurality of As, or may refer to each of some components included in the plurality of As.

[0046] Additionally, the terms 'comprises' and / or 'comprising' used in the following embodiments do not exclude the presence or addition of one or more other components, steps, operations and / or elements.

[0047] In this disclosure, "sensitive information" may refer to information that, if disclosed to unauthorized parties, could pose a risk to an individual (or organization, system, etc.), such as a privacy breach or security threat. For example, sensitive information may include a name, resident registration number, information that can identify a specific individual, or information that, even if not identifiable, can be easily combined with other information to identify a specific individual. Specifically, sensitive information related to financial products may include product names and various information related to the product (e.g., the customer's account number, the customer's subscription date, etc.).

[0048] In the present disclosure, "identification information" may refer to information for determining the authenticity of a message within a message processing system, a verification intermediary system, and / or a user terminal. Specifically, the identification information may include information generated by combining at least a portion of a message with information about the entity sending / receiving the message. For example, the identification information may include a serial number generated by combining text information included in the message (e.g., information indicating or characterizing the entity operating the message processing system), information about the entity sending the message (e.g., account information of the message processing system), and / or information about the entity receiving the sent message (e.g., account information of a verification application).

[0049] In the present disclosure, a "verification message" may refer to a message used to determine the authenticity of a message within a message processing system, a verification intermediary system, and / or a user terminal. Specifically, the verification message may include at least a portion of the message. Additionally, the verification message may be generated by including identification information. Furthermore, within the verification intermediary system and / or the verification application of the user terminal, the verification messages may be mutually verified for consistency to determine the authenticity of the message.

[0050] FIG. 1 is a diagram illustrating an example of a user terminal (120) receiving a message according to one embodiment of the present disclosure. Referring to FIG. 1 , the user terminal (120) can receive a message (132). At this time, the user (110) can confirm the received message (132) through the user interface (130).

[0051] In one embodiment, the message (132) may output text information contained in the message (132) through the user interface (130). Here, the message (132) may include text, electronic documents, etc. transmitted through communication and data transmission functions of a telecommunications company or an Internet service provider. For example, the message (132) may be a message in the form of an SMS (Short Message Service) or an MMS (Multimedia Messaging System). Additionally, the message (132) may be an instant message (IM, Instant Message) generated in an instant messaging application.

[0052] In one embodiment, the message (132) may include information sent to its customers by a well-known company, financial institution, or public institution. For example, the message (132) may include information about products held by the financial institution, link information to the financial institution's website, contact information for the financial institution, information about financial institution employees, etc. Here, the user (110) can check financial information related to the user (110) or financial information related to the financial institution through the financial information included in the message (132).

[0053] In one embodiment, if the message (132) is sent from an entity impersonating the entity operating the message processing system, the message (132) may contain information associated with smishing. Specifically, the message (132) may include links and contact information that could trigger smishing. For example, if a user (110) accesses a link that could trigger smishing, sensitive information contained in the user terminal (120) may be leaked.

[0054] In one embodiment, a user terminal (120) may receive a message (132) sent by a message processing system. The entity operating the message processing system may be a well-known corporation, financial institution, or public institution. The message processing system is described in detail later in FIGS. 2 and 3 . In another embodiment, the user terminal (120) may receive a message (132) sent by an entity impersonating the entity operating the message processing system. Referring to FIG. 1 , the user terminal (120) may receive a message (132) sent by an entity impersonating Bank A.

[0055] In one embodiment, the message (132) may include sensitive information about the user (110) and / or information identifying or characterizing the entity operating the message processing system (hereinafter referred to as “operating entity characteristic information”). Specifically, the operating entity characteristic information may include information identifying the entity operating the message processing system or, when combined with other information, information that can identify the entity operating the message processing system. For example, the operating entity characteristic information may include the name of the entity operating the message processing system, a link to the website of the entity operating the message processing system, contact information associated with the entity operating the message processing system, product names owned by the entity operating the message processing system, etc.

[0056] In one embodiment, the user terminal (120) may receive characteristic information of a first operating entity. Here, the characteristic information of the first operating entity may be information indicating or characterizing an entity requiring message verification. In addition, the user terminal (120) may generate characteristic information of a second operating entity associated with the message (132) by extracting the characteristic information of the operating entity of the message (132). The user terminal (120) may determine whether the characteristic information of the first operating entity and the characteristic information of the second operating entity match. In addition, if the characteristic information of the first operating entity and the characteristic information of the second operating entity do not match, the user terminal (120) may not generate a second verification message based on the message (132). By this configuration, the authenticity of all messages (132) received by the user terminal (120) is not verified, and the authenticity of messages (132) including pre-input information (e.g., characteristic information of the first operating entity) can be selectively determined. That is, the authenticity of a message (132) regarding a specific entity operating a message processing system can be selectively determined.

[0057] In one embodiment, the user terminal (120) may receive a first verification message from the verification intermediary system. Here, the first verification message may be a verification message that serves as a basis for determining whether the verification message matches. Furthermore, the user terminal (120) may generate a second verification message based on the message (132). Here, the second verification message may be a verification message that serves as a target for determining whether the verification message matches. Thereafter, the user terminal (120) may determine whether the first verification message and the second verification message match.

[0058] In another embodiment, the user terminal (120) may generate a second verification message based on the message (132). Furthermore, the user terminal (120) may provide the second verification message to a verification intermediary system. The verification intermediary system may then determine whether the first verification message matches the provided second verification message. Here, the verification intermediary system may receive the first verification message from the message processing system prior to or concurrently with receiving the second verification message. The detailed generation process for each of the first and second verification messages, as well as the detailed process for determining whether the first and second verification messages match, will be described below.

[0059] In one embodiment, at least one of the verification intermediary system or the user terminal (120) may determine whether the first verification message matches the second verification message. In response to determining whether the first verification message matches the second verification message, the processor may generate a determination result indicating either a message match determination or a message inconsistency determination. Here, if the determination result is generated by the verification intermediary system, the determination result may be provided to the user terminal (120). Thereafter, the user terminal (120) may output the determination result. Specifically, in response to the determination result, the user terminal (120) may output visual, tactile, or auditory signals. For example, in response to the message match determination result, the user terminal (120) may output information corresponding to the message match determination result through the user interface (130). As another example, referring to FIG. 1, in response to the message mismatch determination result, the user terminal (120) can output information corresponding to the message mismatch determination result (e.g., 'The text message just sent is a smishing text message.') by outputting a notification window (134) on the user interface (130).

[0060] In one embodiment, a series of processes performed on the user terminal (120) may be performed by a verification application operating on the user terminal (120). Alternatively, the message verification service may be provided through an application provided by the entity operating the message processing system. However, this is not limited to this, and the message verification service may be provided to the user (110) in various forms.

[0061] This configuration allows the user (110) to verify the sender of a message without having to directly perform any additional actions on the information contained in the message. Furthermore, the invention according to the present disclosure can prevent smishing of the user (110) by selecting smishing messages from among received messages.

[0062] FIG. 2 is a schematic diagram illustrating a configuration in which a message processing system (230), a verification brokerage system (240), and a plurality of user terminals (210_1, 210_2, 210_3) are connected to enable communication between them for message verification according to one embodiment of the present disclosure. As illustrated, the plurality of user terminals (210_1, 210_2, 210_3) may be connected to the message processing system (230) and the verification brokerage system (240) that can provide a message verification service via a network (220). Here, the plurality of user terminals (210_1, 210_2, 210_3) may include terminals of users who receive the message verification service.

[0063] According to one embodiment, the message processing system (230) may include one or more server devices and / or databases capable of storing, providing, and executing computer-executable programs (e.g., downloadable applications) and data associated with providing message verification services, or one or more distributed computing devices and / or distributed databases based on cloud computing services.

[0064] According to one embodiment, the verification brokerage system (240) may include one or more server devices and / or databases capable of storing, providing, and executing computer executable programs (e.g., downloadable applications) and data associated with providing message verification services, or one or more distributed computing devices and / or distributed databases based on cloud computing services.

[0065] The message verification service provided by the verification brokerage system (240) may be provided to users through a message verification service application, a web browser, a web browser extension program, etc. installed on each of a plurality of user terminals (210_1, 210_2, 210_3) and / or a message processing system (230). For example, the verification brokerage system (240) may provide information corresponding to a message verification request received from a user terminal (210_1, 210_2, 210_3) and / or a message processing system (230) or perform corresponding processing through a message verification service application, etc.

[0066] A plurality of user terminals (210_1, 210_2, 210_3) can communicate with a verification mediation system (240) and a message processing system (230) via a network (220). The network (220) can be configured to enable communication among the plurality of user terminals (210_1, 210_2, 210_3), the message processing system (230), and the verification mediation system (240). Depending on the installation environment, the network (220) can be configured as a wired network such as Ethernet, a wired home network (Power Line Communication), a telephone line communication device, and RS-serial communication, a mobile communication network, a wireless network such as WLAN (Wireless LAN), Wi-Fi, Bluetooth, and ZigBee, or a combination thereof. As another example, the network (220) can include a communication network configured by a communication company. At this time, the message and / or verification message can be communicated between the user terminals (210_1, 210_2, 210_3), the message processing system (230), and the verification mediation system (240) via the network (220). The communication method is not limited, and may include not only a communication method utilizing a communication network (e.g., a mobile communication network, a wired Internet, a wireless Internet, a broadcasting network, a satellite network, etc.) that the network (220) may include, but also short-range wireless communication between the user terminals (210_1, 210_2, 210_3).

[0067] In FIG. 2, a mobile phone terminal (210_1), a tablet terminal (210_2), and a PC terminal (210_3) are illustrated as examples of user terminals, but are not limited thereto, and the user terminals (210_1, 210_2, 210_3) may be any computing device capable of wired and / or wireless communication and capable of installing and executing a message verification application or web browser, etc. For example, the user terminal may include an AI speaker, a smartphone, a mobile phone, a navigation device, a computer, a laptop, a digital broadcasting terminal, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), a tablet PC, a game console, a wearable device, an IoT (Internet of Things) device, a VR (virtual reality) device, an AR (augmented reality) device, a set-top box, etc. In addition, although FIG. 2 illustrates three user terminals (210_1, 210_2, 210_3) communicating with a message processing system (230) and a verification intermediary system (240) through a network (220), the present invention is not limited thereto, and a different number of user terminals may be configured to communicate with the message processing system (230) and the verification intermediary system (240) through the network (220).

[0068] In FIG. 2, a configuration in which a user's request is transmitted to a message processing system (230) and / or a verification intermediary system (240) through a user terminal (210_1, 210_2, 210_3) is exemplarily illustrated, but the present invention is not limited thereto, and the user's request may be provided to the message processing system (230) and / or the verification intermediary system (240) through an input device associated with the message processing system (230) and / or the verification intermediary system (240) without passing through the user terminal (210_1, 210_2, 210_3), and the result of processing the user's request may be provided to the user through an output device (e.g., a display, etc.) associated with the message processing system (230) and / or the verification intermediary system (240).

[0069] FIG. 3 is a block diagram illustrating the internal configuration of a computing device (310) according to one embodiment of the present disclosure. The computing device (310) may include a memory (312), a processor (314), a communication module (316), and an input / output interface (318). As illustrated in FIG. 3, the computing device (310) may be configured to communicate information and / or data via a network using the communication module (316). In addition, each of the user terminal (210), message processing system (230), or verification mediation system (240) described above in FIG. 2 may correspond to one or more computing devices (310) or may include one or more computing devices (310).

[0070] The memory (312) may include any non-transitory computer-readable recording medium. According to one embodiment, the memory (312) may include a non-permanent mass storage device such as a random access memory (RAM), a read only memory (ROM), a disk drive, a solid state drive (SSD), a flash memory, etc. As another example, a non-permanent mass storage device such as a ROM, an SSD, a flash memory, a disk drive, etc. may be included in the computing device (310) as a separate permanent storage device distinct from the memory. In addition, the memory (312) may store an operating system and at least one program code (e.g., code for generating a verification message, generating identification information, determining whether a first verification message and a second verification message match, extracting characteristic information of an operating entity, etc. that is installed and operated in the computing device (310).

[0071] These software components may be loaded from a computer-readable recording medium separate from the memory (312). This separate computer-readable recording medium may include a recording medium directly connectable to the computing device (310), for example, a computer-readable recording medium such as a floppy drive, a disk, a tape, a DVD / CD-ROM drive, a memory card, etc. As another example, the software components may be loaded into the memory (312) through a communication module (316) other than a computer-readable recording medium. For example, at least one program may be loaded into the memory (312) based on a computer program (e.g., a program for generating a verification message, generating identification information, determining whether a first verification message matches a second verification message, extracting characteristic information of an operating entity, etc.) that is installed by files provided by developers or a file distribution system that distributes installation files of applications through the communication module (316).

[0072] The processor (314) may be configured to process instructions of a computer program by performing basic arithmetic, logic, and input / output operations. The instructions may be provided to a user terminal (not shown) or another external system via the memory (312) or the communication module (316). For example, the processor (314) may determine whether the first verification message and the second verification message match. In this case, in response to determining whether the first verification message and the second verification message match, the determination result may be provided to the user terminal.

[0073] The communication module (316) may provide a configuration or function for a user terminal (not shown) and a computing device (310) to communicate with each other via a network, and may provide a configuration or function for the computing device (310) to communicate with an external system (e.g., a separate cloud system, etc.). For example, control signals, commands, data, etc. provided under the control of the processor (314) of the computing device (310) may be transmitted to the user terminal and / or the external system via the communication module (316) and the network via the communication module of the user terminal and / or the external system.

[0074] Additionally, the input / output interface (318) of the computing device (310) may be a means for interfacing with a device (not shown) for input or output that is connected to the computing device (310) or that the computing device (310) may include. In FIG. 3, the input / output interface (318) is illustrated as an element configured separately from the processor (314), but is not limited thereto, and the input / output interface (318) may be configured to be included in the processor (314). The computing device (310) may include more components than those illustrated in FIG. 3. However, there is no need to explicitly illustrate most of the conventional components.

[0075] The processor (314) of the computing device (310) may be configured to manage, process, and / or store information and / or data received from multiple user terminals and / or multiple external systems. According to one embodiment, the processor (314) may receive a second verification message. Thereafter, the processor (314) may determine whether the first verification message stored in the memory (312) of the computing device (310) matches the second verification message.

[0076] FIG. 4 is a flowchart illustrating an example of a message verification method according to one embodiment of the present disclosure. Referring to FIG. 4 , a message processing system (230) may receive a first message (S412). At this time, the first message may be input by the entity operating the message processing system. Furthermore, the first message may include information that the entity operating the message processing system wishes to provide to the user terminal (210). Thereafter, the message processing system (230) may provide the first message to the user terminal (210) via a network (S410).

[0077] In one embodiment, the message processing system (230) may generate first identification information associated with the first message (S422). For example, the first identification information may be generated by combining at least some information included in the first message with account information of the message processing system (230). Additionally or alternatively, the first identification information may include account information of the user terminal that wishes to provide the first message. In this case, the first identification information may be in the form of a unique identification number.

[0078] The message processing system (230) may generate a first verification message (S424). Here, the first verification message may include at least a portion of the first message and / or first identification information. At this time, the first verification message may be generated by de-identifying sensitive information included in the first message. The de-identification of sensitive information is described in detail later in FIG. 6. Thereafter, the message processing system (230) may provide the first verification message to the verification intermediary system (240) via a network (S420). At this time, the verification intermediary system (240) may separately store and manage the provided first verification message.

[0079] The user terminal (210) may receive a second message (S430). Here, the second message may be the same message as the first message transmitted through step S410 from the message processing system (230). Alternatively, the second message may be an arbitrary smishing message impersonating the message processing system (230), rather than a message transmitted from the message processing system (230).

[0080] The second message may be a message associated with the characteristic information of the second operating entity that matches the characteristic information of the first operating entity described above in FIG. 1 among all messages received by the user terminal (210). In one embodiment, the user terminal (210) may generate second identification information associated with the second message (S442). For example, the second identification information may be generated by combining at least some information included in the first message with account information of the user terminal (210). Additionally, the second identification information may be in the form of a unique identification number.

[0081] The user terminal (210) may generate a second verification message (S444). Here, the second verification message may include at least a portion of the second message and / or second identification information. The second verification message may be generated by de-identifying sensitive information included in the second message. Thereafter, the user terminal (210) may provide the second verification message to the verification intermediary system (240) via the network (S440).

[0082] The verification intermediary system (240) can determine whether the first verification message and the second verification message match (S452). In one embodiment, the consistency of the first verification message and the second verification message can be determined by determining whether the text regarding the first message included in the first verification message and the text regarding the second message included in the second verification message are completely identical. In another embodiment, the consistency of the first verification message and the second verification message can be determined by determining whether the pattern regarding the first message included in the first verification message and the pattern regarding the second message included in the second verification message are identical. In yet another embodiment, the consistency of the first verification message and the second verification message can be determined by determining whether the first identification information included in the first verification message and the second identification information included in the second verification message are identical.

[0083] The verification intermediary system (240) can provide the user terminal (210) with the result of determining whether the first and second verification messages match (S450). The user terminal (210) can output the provided determination result. With this configuration, the user terminal (210) can verify the second message, thereby providing the user with information about the authenticity of the second message.

[0084] In one embodiment, the verification intermediary system (240) can verify whether the verification message match determination result is a message match determination (S462). Here, the message match determination may mean a determination that the first verification message and the second verification message match. If the verification message match determination result corresponds to a message match determination, the verification intermediary system (240) can provide the determination result indicating the message match determination to the message processing system (230) (S460). In response to receiving the determination result indicating the message match determination, the message processing system (230) can provide message details related to the information included in the first message to the user terminal (210) (S470). For example, if the first message includes summarized information regarding financial product information, the message details may include detailed information about the financial product (e.g., product maturity, product yield, product terms and conditions, etc.) or a link that can provide detailed information about the financial product. Thereafter, the user terminal (210) can output the provided message details and provide them to the user.

[0085] FIG. 5 is a flowchart illustrating an example of a message verification method according to one embodiment of the present disclosure. The steps from the message processing system (230) inputting a first message (S512) to the user terminal (210) generating a second verification message (S544) may be identical to those described in FIG. 4 . In FIG. 5 , descriptions of components that overlap with those depicted in FIG. 4 are omitted.

[0086] In one embodiment, the verification intermediary system (240) may provide the first verification message received from the message processing system (230) to the user terminal (210) (S540). Thereafter, the user terminal (210) may determine whether the first verification message and the second verification message match (S552). The process of determining whether the first verification message and the second verification message match may be identical to that described above in FIG. 4, except that it is performed by the user terminal (210) rather than the verification intermediary system (240).

[0087] In one embodiment, the user terminal (210) can verify whether the verification message match determination result is a message match determination (S554). Here, the message match determination may mean a determination that the first verification message and the second verification message match. If the verification message match determination result corresponds to a message match determination, the user terminal (210) can provide the determination result indicating the message match determination to the message processing system (230) (S550). In response to receiving the determination result indicating the message match determination, the message processing system (230) can provide the user terminal (210) with message details associated with the information included in the first message (S560).

[0088] By this configuration, whether the first verification message and the second verification message match can be determined at the user terminal (210) rather than at the verification intermediary system (240). If communication between the verification intermediary system (240) and the user terminal (210) is difficult or the response of the verification intermediary system (240) is delayed, there may be a problem in that the verification intermediary system (240) is delayed in determining whether the first verification message and the second verification message match. The invention according to the present disclosure can solve this problem by determining whether the first verification message and the second verification message match at the user terminal (210). In addition, if the message includes sensitive information, the message content is not provided to an external system of the user terminal (210), thereby minimizing the leakage of sensitive information. By minimizing the leakage of sensitive information, personal information leakage can be prevented.

[0089] FIG. 6 is a diagram illustrating an example of performing anonymization processing of sensitive information (614) according to one embodiment of the present disclosure. Referring to FIG. 6 , the first example (610) may represent a user interface on which a message (612) received by a user terminal is output. In one example, the message (612) may include information about a financial product (e.g., product name, product expiration date, link to the financial institution's homepage, contact information for the financial institution, etc.).

[0090] In one embodiment, the message (612) may include characteristic information (616) of the operating entity. For example, the characteristic information (616) of the operating entity may include the name of the financial institution (e.g., 'Bank A'), a product name, a homepage link indicating the financial institution, and contact information. The user terminal may extract the characteristic information (616) of the operating entity from the message (612) and determine whether the extracted characteristic information (616) of the operating entity matches the previously received characteristic information of the operating entity. If a result of determining that the extracted characteristic information (616) of the operating entity matches the previously received characteristic information of the operating entity is inconsistent, the message verification method for the corresponding message (612) may be terminated.

[0091] In one embodiment, message (612) may include sensitive information (614). For example, sensitive information (614) may include the name of a financial institution customer, the name of a product subscribed to by the customer, etc. In this case, message (612) may be anonymized for the sensitive information (614). Referring to FIG. 6 , a second example (620) may use a de-identification area (622, e.g., black box processing) to represent the sensitive information (614) contained in message (612) in anonymized form. However, the present invention is not limited thereto, and the de-identification of sensitive information (614) may be performed in various ways. Thereafter, a verification message may be generated based on the anonymized message. In this case, the verification message may include at least a portion of the anonymized message and identification information associated with message (612).

[0092] While Figure 6 focuses on the case where a user terminal receives a message, the same principle can be applied to the case where a message processing system sends a message. For example, if a verification message is generated based on a message sent by the message processing system, sensitive information contained in the sent message can be de-identified. A verification message can then be generated based on the de-identified message.

[0093] By this configuration, verification messages generated based on de-identified messages may not contain sensitive information. Since sensitive information (614) is not transmitted to user terminals and / or external systems of the message processing system, personal information may not be leaked.

[0094] FIG. 7 is a flowchart illustrating an example of a message verification method (700) according to one embodiment of the present disclosure. According to one embodiment, the message verification method (700) may be performed by at least one processor (e.g., at least one processor of a computing device) of a user terminal, a message processing system, and / or a verification brokerage system. The message verification method (700) may be initiated by the verification brokerage system receiving a first verification message including at least a portion of a first message transmitted by the message processing system (S710). Here, the first verification message may include a message in which sensitive information included in the first message has been de-identified by the message processing system.

[0095] In one embodiment, the verification intermediary system may receive a second verification message comprising at least a portion of a second message received from a user terminal (S720). The second verification message may include a message in which sensitive information contained in the second message has been de-identified by the verification application of the user terminal. Furthermore, the second verification message may be generated by the verification application of the user terminal extracting information from the second message that identifies or characterizes the entity operating the message processing system.

[0096] In one embodiment, the verification intermediary system may determine whether the received first verification message matches the received second verification message (S730). Specifically, in response to determining whether the first verification message matches the second verification message, the verification intermediary system may provide the user terminal with a determination result indicating either a message match determination or a message mismatch determination. Additionally or alternatively, the verification intermediary system may transmit the first verification message to the user terminal, and whether the transmitted first verification message matches the second verification message may be determined by a verification application running on the user terminal.

[0097] Additionally, the first verification message further includes first identification information associated with the first message, the second verification message further includes second identification information associated with the second message, and the verification intermediary system can determine whether the first verification message and the second verification message match by determining whether the first identification information and the second identification information match.

[0098] In one embodiment, the verification intermediary system provides a determination result indicating a message matching determination to the message processing system, and in response to receiving the determination result indicating a message matching determination, message details associated with information included in the first message may be provided from the message processing system to the user terminal.

[0099] In one embodiment, a user terminal may receive information indicating or characterizing an entity operating a message processing system. Furthermore, the user terminal may receive a message from the message processing system. Subsequently, the user terminal may receive a verification message from a verification intermediary system. Furthermore, the user terminal may extract information corresponding to the received information from the received message. Subsequently, if the extracted information matches the received information, the user terminal may determine whether the received message matches the received verification message. Here, the user terminal may be operated by a verification application.

[0100] The above-described method may be provided as a computer program stored on a computer-readable recording medium for execution on a computer. The medium may be one that continuously stores a computer-executable program or one that temporarily stores it for execution or download. In addition, the medium may be various recording means or storage means in the form of a single or multiple hardware combinations, and is not limited to a medium directly connected to a computer system, but may also be distributed over a network. Examples of the medium may include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and those configured to store program instructions, including ROM, RAM, and flash memory. In addition, examples of other media may include recording or storage media managed by app stores that distribute applications, sites that supply or distribute various software, servers, etc.

[0101] The methods, operations, or techniques of the present disclosure may be implemented by various means. For example, these techniques may be implemented in hardware, firmware, software, or a combination thereof. Those skilled in the art will appreciate that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software will depend on the particular application and the design requirements imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but such implementations should not be construed as departing from the scope of the present disclosure.

[0102] In a hardware implementation, the processing units used to perform the techniques may be implemented within one or more ASICs, DSPs, digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described herein, a computer, or a combination thereof.

[0103] Accordingly, the various exemplary logical blocks, modules, and circuits described in connection with the present disclosure may be implemented or performed by any combination of a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or those designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0104] In a firmware and / or software implementation, the techniques may be implemented as instructions stored on a computer-readable medium, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable PROM (EEPROM), flash memory, a compact disc (CD), a magnetic or optical data storage device, etc. The instructions may be executable by one or more processors and may cause the processor(s) to perform certain aspects of the functionality described herein.

[0105] When implemented in software, the techniques described above may be stored on or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media includes both computer storage media and communication media, including any medium that facilitates transfer of a computer program from one place to another. Storage media may be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium.

[0106] For example, if the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, digital subscriber line, or wireless technologies such as infrared, radio, and microwave are included within the definition of media. Disk and disc, as used herein, includes compact discs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks usually reproduce data magnetically, whereas discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0107] A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium may be coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. Alternatively, the processor and the storage medium may reside as discrete components in the user terminal.

[0108] While the embodiments described above have been described as utilizing aspects of the presently disclosed subject matter in one or more standalone computer systems, the present disclosure is not limited thereto and may be implemented in conjunction with any computing environment, such as a network or distributed computing environment. Furthermore, aspects of the present disclosure may be implemented in multiple processing chips or devices, and storage may be similarly affected across multiple devices. Such devices may include personal computers, network servers, and portable devices.

[0109] While the present disclosure has been described in connection with certain embodiments herein, various modifications and variations may be made without departing from the scope of the present disclosure, which would be apparent to those skilled in the art. Furthermore, such modifications and variations are intended to fall within the scope of the claims appended to this specification.

Claims

1. A message verification method performed by a verification intermediary system, A step of receiving a first verification message comprising at least a portion of a first message transmitted by a message processing system; receiving a second verification message comprising at least a portion of a second message received at a user terminal; and A step for determining whether the received first verification message and the received second verification message match each other A message verification method comprising:

2. In paragraph 1, In response to determining whether the first verification message and the second verification message match, a step of providing a determination result indicating one of a message match determination or a message mismatch determination to the user terminal A message verification method further comprising:

3. In paragraph 1, The step of determining whether the received first verification message and the received second verification message match is: Comprising a step of transmitting the first verification message to the user terminal, A message verification method, wherein whether the first verification message transmitted above matches the second verification message is determined by a verification application operating on the user terminal.

4. In paragraph 2, Further comprising a step of providing a judgment result indicating the message matching judgment to the message processing system; A message verification method, wherein, in response to receiving a judgment result indicating a message matching judgment, message details associated with information included in the first message are provided from the message processing system to the user terminal.

5. In paragraph 1, A message verification method, wherein the second verification message is generated by extracting information indicating or characterizing an entity operating the message processing system from the second message by the verification application of the user terminal.

6. In paragraph 1, The first verification message includes a message in which anonymization processing is performed on sensitive information included in the first message by the message processing system, A message verification method, wherein the second verification message includes a message in which anonymization processing is performed on sensitive information included in the second message by the verification application of the user terminal.

7. In paragraph 1, The first verification message further includes first identification information associated with the first message, The second verification message further includes second identification information associated with the second message, The step of determining whether the received first verification message and the received second verification message match is: A message verification method, comprising the step of determining whether the first verification message and the second verification message match by determining whether the first identification information and the second identification information match.

8. In a message verification method operated by a verification application of a user terminal, A step of receiving information identifying or characterizing an entity operating a message processing system; A step of receiving a message from the above message processing system; A step of receiving a verification message from a verification brokerage system; A step of extracting information corresponding to the received information from the received message; and If the extracted information and the received information match, a step of determining whether the received message and the received verification message match A method of verifying a message, including 9. A computer program stored on a computer-readable recording medium for executing the method according to any one of clauses 1 to 8 on a computer.

10. As a verification intermediary system, Communication module; memory; and At least one processor connected to said memory and configured to execute at least one computer-readable program contained in said memory Including, At least one of the above programs, Receiving a first verification message comprising at least a portion of a first message transmitted by a message processing system; Receive a second verification message including at least a portion of a second message received at the user terminal, A verification brokerage system comprising commands for determining whether the received first verification message and the received second verification message match.

Citation Information

Patent Citations

  • System for detecting and blocking phishing character of banking and method for detecting and blocking phishing character of banking

    KR1020140099389A

  • Method of blocking smishing, server performing the same and storage media storing the same

    KR1020150065017A

  • Method and apparatus for notifying smishing

    KR1020160003399A

  • Companion animal shower and dry room

    KR1020240019457A

  • System for providing phishing warning service using contents based blocking

    KR102531661B1