Security Verification Method Using Scenario Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security verification methods, such as those using usernames and passwords or verification codes, are vulnerable to theft and interception, leading to weakened security as users find it difficult to memorize complex passwords and unauthorized users can steal verification codes through phishing attacks.
Innovation Solution
A security verification method that involves acquiring and prompting a first verification code describing scenario information, triggering a user to send a second verification code from their terminal, and verifying both the code and the terminal's ID to enhance security by preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a password composed of letters and digits is used for security verification, then the verification strength is improved, but the ease of memorization and resistance to interception is worsened
Solution Approach 1:
The patent changes the parameter of verification code composition from complex alphanumeric passwords to simple Chinese character phrases that describe scenario information. This transformation maintains security verification strength while dramatically improving ease of memorization and user understanding.
Solution Approach 2:
The patent uses disposable verification codes that are valid only for specific scenarios and time periods. Each verification code is tied to a particular operation context (e.g., payment, login) and becomes invalid after use or expiration, preventing reuse by unauthorized users.
2Measurement precision
If a verification code is sent to user terminal for security verification, then the verification accuracy is improved, but the vulnerability to phishing attacks and code theft is worsened
Solution Approach 1:
The patent applies local quality by making verification codes context-specific and location-specific. Each verification code is tied to a particular scenario (payment, login, etc.) and terminal device, so even if a code is stolen, it cannot be used in a different context or device. This prevents phishing attacks where attackers create fake websites to steal verification codes.
Solution Approach 2:
The patent performs preliminary binding between the user terminal ID and the verification code before the verification process. The system pre-establishes a relationship between the legitimate terminal and its authorized verification codes, allowing the server to verify not only the code itself but also whether it was sent to the correct terminal, thereby preventing interception and misuse.
3Reliability
If dual verification of code and terminal ID is performed, then the security verification reliability is improved, but the device complexity and verification process complexity is worsened
Solution Approach 1:
The patent merges the verification of the code and terminal ID into a single integrated verification process. Rather than treating them as separate steps, the system combines both verifications into one unified authentication flow, where the terminal ID verification is performed concurrently with or immediately following the code verification, reducing the perceived complexity for users.
Solution Approach 2:
The system performs automatic terminal ID verification without requiring user input. The terminal device automatically provides its identification information, and the server independently verifies this ID against the registered information, eliminating the need for users to manually enter or manage terminal identifiers and simplifying the user's interaction.
Data Source
AI summary
Disclosed are a security verification method, apparatus, and terminal. The method includes: acquiring a first verification code and prompting the first verification code, the content of the first verification code describing scenario information that is simple for a user to understand, and triggering the user to send a second verification code over a user terminal; receiving the second verification code, and acquiring an ID of the user terminal sending the second verification code; and obtaining a security verification result according to two verification results of the second verification code and the corresponding ID. A first verification code describing scenario information that is simple for a user to understand is displayed such that the user understands the scenario information corresponding to the first verification code and unauthorized users are prevented from stealing the verification codes using similar websites.


