Security Verification Method Using Scenario Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security verification methods, such as those using usernames and passwords or verification codes, are vulnerable to theft and interception, leading to weakened security as users find it difficult to memorize complex passwords and unauthorized users can steal verification codes through phishing attacks.

Innovation Solution

A security verification method that involves acquiring and prompting a first verification code describing scenario information, triggering a user to send a second verification code from their terminal, and verifying both the code and the terminal's ID to enhance security by preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a password composed of letters and digits is used for security verification, then the verification strength is improved, but the ease of memorization and resistance to interception is worsened

Engineering Contradiction:
Improvesecurity verification strengthVSAvoidease of memorization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the parameter of verification code composition from complex alphanumeric passwords to simple Chinese character phrases that describe scenario information. This transformation maintains security verification strength while dramatically improving ease of memorization and user understanding.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses disposable verification codes that are valid only for specific scenarios and time periods. Each verification code is tied to a particular operation context (e.g., payment, login) and becomes invalid after use or expiration, preventing reuse by unauthorized users.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Measurement precision

If a verification code is sent to user terminal for security verification, then the verification accuracy is improved, but the vulnerability to phishing attacks and code theft is worsened

Engineering Contradiction:
Improveverification accuracyVSAvoidphishing attack vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making verification codes context-specific and location-specific. Each verification code is tied to a particular scenario (payment, login, etc.) and terminal device, so even if a code is stolen, it cannot be used in a different context or device. This prevents phishing attacks where attackers create fake websites to steal verification codes.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary binding between the user terminal ID and the verification code before the verification process. The system pre-establishes a relationship between the legitimate terminal and its authorized verification codes, allowing the server to verify not only the code itself but also whether it was sent to the correct terminal, thereby preventing interception and misuse.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dual verification of code and terminal ID is performed, then the security verification reliability is improved, but the device complexity and verification process complexity is worsened

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the verification of the code and terminal ID into a single integrated verification process. Rather than treating them as separate steps, the system combines both verifications into one unified authentication flow, where the terminal ID verification is performed concurrently with or immediately following the code verification, reducing the perceived complexity for users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs automatic terminal ID verification without requiring user input. The terminal device automatically provides its identification information, and the server independently verifies this ID against the registered information, eliminating the need for users to manually enter or manage terminal identifiers and simplifying the user's interaction.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10097547B2Security verification method, apparatus and terminal
Publication Date: 2018.10.09 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US10097547B2 patent drawing
  • US10097547B2 patent drawing
  • US10097547B2 patent drawing

AI summary

Disclosed are a security verification method, apparatus, and terminal. The method includes: acquiring a first verification code and prompting the first verification code, the content of the first verification code describing scenario information that is simple for a user to understand, and triggering the user to send a second verification code over a user terminal; receiving the second verification code, and acquiring an ID of the user terminal sending the second verification code; and obtaining a security verification result according to two verification results of the second verification code and the corresponding ID. A first verification code describing scenario information that is simple for a user to understand is displayed such that the user understands the scenario information corresponding to the first verification code and unauthorized users are prevented from stealing the verification codes using similar websites.