Method And System Used For Handling Encoded Information
Abstract
The present invention relates to a method and system for handling encoded information. The method involves a first server, a second server, and a portable device, and includes: generating a verification information item for inclusion in an encoded information item, wherein the reference verification information item is stored on a first server device; the portable device executes Steps: Obtain the encoded information item; decode the encoded information from the encoded information item; transmit a first message to the first server device, the first message including the decoded information and identification The device or the first identifier of the user of the device; and the first server device receives the first message from the device; establishing the identity of the user of the device includes: using the first identifier to determine whether to A server device registers the user; in response to establishing the user's identity, authorizes the user to access the service; and sends a second message to the second server device.
Term
5.2 yearsto projected expiry
Projected expiry 25 November 2031, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
25 claims: 4 independent, 21 dependent
- 11· 一种用于处置编码后的信息的方法,涉及第一服务器、第二服务器和便携式装置,该 方法包括: 生成用于在编码后的信息项中包括的验证信息项,其中将参考验证信息项存储在第一 服务器设备上,并且包括该验证信息项的编码后的信息项要由便携式装置解码; 该便携式装置执行步骤: 获得所述编码后的信息项; 对来自所述编码后的信息项的编码后的信息进行解码;和 向该第一服务器设备传送第一消息,该第一消息包括解码后的信息和标识该装置或该 装置的用户的第一标识符;和 该第一服务器设备执行步骤: 从该装置接收该第一消息; 建立该装置的用户的身份,其中所述建立该装置的用户的身份的步骤包括:使用该第 一标识符来确定是否向该第一服务器设备注册该用户; 响应于建立用户的身份,授权用户访问服务;和 向第二服务器设备发送第二消息,该第二消息指示授权该用户访问该第二服务器设备 所提供的服务,该第二服务器设备通过经由该便携式装置向该用户或经由该第一服务器向 该便携式装置提供该服务,而对该第二消息的接收作出应答。
- 2—种用于处置编码后的信息的方法,涉及第一服务器、第二服务器、和便携式装置, 该方法包括: 生成用于在编码后的信息项中包括的验证信息项,其中将参考验证信息项存储在第一 服务器设备上,并且包括该验证信息项的编码后的信息项要由便携式装置获得; 该便携式装置执行步骤: 获得所述编码后的信息;和 向该第一服务器设备传送第一消息,该第一消息包括编码后的信息项和标识该装置或 该装置的用户的第一标识符;和 该第一服务器设备执行步骤: 从该装置接收该第一消息; 对来自所述编码后的信息项的编码后的信息进行解码; 建立该装置的用户的身份,其中所述建立该装置的用户的身份的步骤包括:使用该第 一标识符来确定是否向该第一服务器设备注册该用户; 响应于建立用户的身份,授权该用户访问服务;和 向第二服务器设备发送第二消息,该第二消息指示授权该用户访问该第二服务器设备 所提供的服务,该第二服务器设备通过经由该便携式装置向该用户或经由该第一服务器向 该便携式装置提供该服务,而对该第二消息的接收作出应答。
- 3根据权利要求1或权利要求2的方法,进一步包括该第一服务器设备执行步骤: 比较该第一消息中包括的该验证信息项和该参考验证信息项; 如果在该验证信息项和该参考验证信息项之间存在一致,则向该第二服务器设备发送 该第二消息;和 如果在该验证信息项和该参考验证信息项之间不存在一致,则在向该第二服务器设备 发送该第二消息之前,中止该方法。
- 4根据权利要求1或权利要求2的方法,其中所述编码后的信息包括确定第二标识符的 信息,该第二标识符标识该第二服务器设备。
- 5根据权利要求1或权利要求2的方法,其中所述编码后的信息包括第三标识符,该第 三标识符标识该第一服务器设备,并且其中基于该第三标识符将该第一消息传送到该第一 服务器设备。
- 6根据权利要求1或权利要求2的方法,包括: 该便携式装置执行步骤: 在传送该第一消息之前,接收用户输入; 比较接收的用户输入和存储的参考输入;和 当确定在接收的用户输入和存储的参考用户输入之间存在一致时,传送该第一消息。
- 7根据权利要求1或权利要求2的方法,其中所述使用该第一标识符来确定是否向该第 一服务器设备注册该用户的步骤包括: 基于该第一标识符启动与该装置的通信信道; 经由该通信信道从该装置接收用户提供的信息; 比较接收的用户提供的信息与存储的参考用户提供的信息;和 当确定在接收的用户提供的信息与参考用户提供的信息之间存在一致时,验证并由此 建立用户的身份。
- 8根据权利要求1或权利要求2的方法,其中所述编码后的信息项被显示为数字、字母 或符号的序列,并且包括: 该便携式装置: 在传送该第一消息之前,作为用户使用用户接口将该序列手动打字输入该便携式装置 的结果,获得编码后的信息项。
- 9根据权利要求1或权利要求2的方法,其中所述第一消息代表支付请求,该方法包括: 该第一服务器响应于从第二服务器接收到通知,使用第一或第二消息中包括的信息, 以授权从用户的账户向收款方支付。
- 10根据权利要求1或权利要求2的方法,其中所述第一消息代表支付请求,该方法包 括: 该第二服务器使用第二消息中包括的信息,以授权从用户的账户向收款方支付。 11·根据权利要求1或权利要求2的方法,其中供应所述编码后信息项作为编码后图形 信息项。
- 1112. 根据权利要求1或权利要求2的方法,其中供应所述编码后信息项作为编码后的可 听信息项。
- 1213. 根据权利要求1或权利要求2的方法,其中供应所述编码后信息项作为编码后的射 频信息项。
- 1314. 一种用于处置编码后的信息的系统,涉及第一服务器、第二服务器和便携式装置, 该系统包括: 生成用于在编码后的信息项中包括的验证信息项,其中将参考验证信息项存储在第一 服务器设备上,并且包括该验证信息项的编码后的信息项要由便携式装置获得并解码; 该便携式装置被配置为: 获得所述编码后的信息项; 对来自所述编码后的信息项的编码后的信息进行解码; 向该第一服务器设备传送第一消息,该第一消息包括解码后的信息和标识该装置或该 装置的用户的第一标识符;和 该第一服务器设备被配置为: 从该装置接收该第一消息; 建立该装置的用户的身份,其中所述建立该装置的用户的身份的步骤包括:使用该第 一标识符来确定是否向该第一服务器设备注册该用户; 响应于建立用户的身份,授权用户访问服务;和 向第二服务器设备发送第二消息,该第二消息指示授权该用户访问该第二服务器设备 所提供的服务,其中该系统进一步包括该第二服务器设备通过经由该便携式装置向该用户 或经由该第一服务器向该便携式装置提供该服务,而对该第二消息的接收作出应答。
- 1415. —种用于处置编码后的信息的系统,涉及第一服务器、第二服务器、和便携式装置, 该系统包括: 生成用于在编码后的信息项中包括的验证信息项,其中将参考验证信息项存储在第一 服务器设备上,并且包括该验证信息项的编码后的信息项要由便携式装置获得; 该便携式装置被配置为: 获得所述编码后的信息;和 向该第一服务器设备传送第一消息,该第一消息包括编码后的信息项和标识该装置或 该装置的用户的第一标识符;和 该第一服务器设备被配置为: 从该装置接收该第一消息; 对来自所述编码后的信息项的编码后的信息进行解码; 建立该装置的用户的身份,其中所述建立该装置的用户的身份的步骤包括:使用该第 一标识符来确定是否向该第一服务器设备注册该用户;和响应于建立用户的身份,授权该 用户访问服务;和 向第二服务器设备发送第二消息,该第二消息指示授权该用户访问该第二服务器设备 所提供的服务,其中该系统进一步包括该第二服务器设备,被配置为通过经由该便携式装 置向该用户或经由该第一服务器向该便携式装置提供该服务,而对该第二消息的接收作出 应答。
- 1516. 根据权利要求14或权利要求15的系统,该系统进一步包括该第一服务器设备,被配 置为: 比较该第一消息中包括的该验证信息项和该参考验证信息项; 如果在该验证信息项和该参考验证信息项之间存在一致,则基于所述解码的信息执行 动作;和 如果在该验证信息项和该参考验证信息项之间不存在一致,则在基于所述解码的信息 执行动作之前,中止该系统。
- 1617. 根据权利要求14或权利要求15的系统,其中所述编码后的信息包括第二标识符,该 第二标识符标识第二服务器设备。
- 1718. 根据权利要求14或权利要求15的系统,其中所述编码后的信息包括第三标识符,该 第三标识符标识该第一服务器设备,并且其中该装置被配置为基于该第三标识符将该第一 消息传送到该第一服务器设备。
- 1819. 根据权利要求14或权利要求15的系统,其中该装置被配置为: 在传送该第一消息之前,接收用户输入; 比较接收的用户输入和存储的参考输入;和 当确定在接收的用户输入和存储的参考用户输入之间存在一致时,传送该第一消息。
- 1920. 根据权利要求14或权利要求15的系统,其中当使用该第一标识符来确定是否向该 第一服务器设备注册该用户时,该第一服务器设备被配置为: 基于该第一标识符启动与该装置的通信信道; 经由该通信信道从该装置接收用户提供的信息; 比较接收的用户提供的信息与存储的参考用户提供的信息;和 当确定在接收的用户提供的信息与参考用户提供的信息之间存在一致时,验证并由此 建立用户的身份。
- 2021. 根据权利要求14或权利要求15的系统,其中所述编码后的信息项被显示为数字、字 母或符号的序列,并且包括: 该便携式装置: 在传送该第一消息之前,作为用户使用用户接口将该序列手动打字输入该便携式装置 的结果,获得编码后的信息项。
- 2122. 根据权利要求14或权利要求15的系统,其中所述第一消息代表支付请求,该系统包 括: 该第一服务器响应于从第二服务器接收到通知,使用第一或第二消息中包括的信息, 以授权从用户的账户向收款方支付。
- 2223. 根据权利要求14或权利要求15的系统,其中所述第一消息代表支付请求,该系统包 括: 该第二服务器使用第二消息中包括的信息,以授权从用户的账户向收款方支付。
- 2324. 根据权利要求14或权利要求15的系统,其中供应所述编码后信息项作为编码后图 形信息项。
- 2425. 根据权利要求14或权利要求15的系统,其中供应所述编码后信息项作为编码后的 可听信息项。
- 2526. 根据权利要求14或权利要求15的系统,其中供应所述编码后信息项作为编码后的 射频信息项。
Independent claims25
124 paragraphs, as filed
Method and system for processing encoded information
[0001] This patent application is a divisional application of the following invention patent applications:
[0002] Mediation No.: 201180064866.3
[0003] Application date: November 25, 2011
[0004] Title of Invention: Information Technology Field after Disposal of Encoding
[0005] The present invention relates to the handling of encoded information.
Background technique
[0006] Identity cloning is an increasingly common phenomenon. Fraudsters use various mechanisms for the purpose of identity cloning in order to elicit personal information such as username, password, date of birth and address. One such mechanism is that fraudsters provide spoofing (or cloning) of the website, which in the eyes of doubtful users is the same as the original. Believing that the website is the original, the user provides personal information such as login details or credit card details, which is recorded by the fraudster. A more complex scheme is a "man-in-the-middle attack", in which the fraudster provides a cloned website and records personal information, but also passes the personal information to the real website, which makes the user log in as normal. In this way, the user does not notice any difference, and the fraudster can obtain personal information without warning the user. The invention was made for the purpose of preventing these and other similar types of fraud.
Summary of the invention
[0007] According to the first aspect, this describes a method, including a device obtaining an encoded information item, decoding the encoded information from the encoded information item, and transmitting a first server device to a first server device. Message, the first message includes the decoded information and a first identifier that identifies the device or the user of the device; and the first server device receives the first message from the device and uses the first identifier to establish the device The users identity, and in response to establishing the users identity, perform actions based on the decoded information.
[0008] The encoded information may include a third identifier that identifies the first server device, and the first message may be transmitted to the first server device based on the third identifier.
[0009] According to a second aspect, the present invention describes a method, including a device obtaining an encoded information item, and transmitting a first message to a first server device, the first message including the encoded information item and identifying the device or The first identifier of the user of the device, and the first server device receives the first message from the device, decodes the encoded information from the encoded information item, and uses the first identifier to establish the The identity of the user of the device, and in response to establishing the identity of the user, perform actions based on the decoded information.
[0010] In the first or second aspect, the decoded information may include a verification information item, and the method may further include the first server device comparing the verification information item with a reference verification item, and if the verification information exists If there is agreement between the item and the reference verification item, the action is executed based on the decoded information, and if there is no agreement between the verification information item and the reference verification item, then the action is aborted before the action is executed based on the decoded information this method.
[0011] The decoded information may include a device identification information item for allowing it to be provided on, through, or close to it
The identification of the computing device of the encoded information object.
[0012] Performing an action may include sending a signal to the computing device based on the device identification information item. Performing an action may also include allowing the user to access the service, where the signal includes an indication that the user is allowed to access the service.
[0013] The encoded information may include a second identifier that identifies the second server device, and the step of performing an action based on the decoded information may include: sending a second message to the second server, which The second message includes authorization information related to the identified user. The decoded information may include a device identification information item for allowing the identification of the computing device on, through, or near to provide the encoded information object, the second message may include the device identification information item, and The method may further include the second server device responding to the reception of the second message by sending a signal to the computing device based on the device identification information item. The second server device may respond to the reception of the second message by allowing the user to access the service, and the signal may include an indication that the user is allowed to access the service.
[0014] According to a third aspect, the present invention describes a system, including a device, configured to: obtain an encoded information item, decode the encoded information from the encoded information item, and send it to the first The server device transmits a first message, the first message including the decoded information and a first identifier that identifies the device or the user of the device; and the first server device is configured to: receive the first message from the device, The first identifier is used to establish the identity of the user of the device, and in response to the establishment of the user's identity, an action is performed based on the decoded information.
[0015] According to a fourth aspect, the present invention describes a system including: an apparatus configured to obtain an encoded information item, and transmit a first message to a first server device, the first message including the encoded information item And a first identifier that identifies the device or a user of the device; and a first server device configured to receive the first message from the device, and decode the encoded information from the encoded information item, The first identifier is used to establish the identity of the user of the device, and in response to the establishment of the user's identity, an action is performed based on the decoded information.
[0016] The apparatus and the first server device can be configured as described above by means of one or more processors operating under the control of computer readable code (optionally stored on one or more memories) . The one or more memories may include one or more non-transitory storage media.
[0017] The present also describes a method, including a portable device to obtain a graphically encoded information item displayed on the display of a computing device, and decode the encoded information from the encoded information item; and A server device transmits a first message, the first message includes decoded information and a first identifier that identifies the device or a user of the device, wherein the decoded information includes a device identifier for allowing identification of the computing device Information item, and the first server device receives the first message from the device and establishes the identity of the user of the device, wherein the step of establishing the identity of the user includes: using the first identifier to determine whether to send the first message to the first The server device registers the user, in response to establishing the user's identity, authorizes the user to access the service, and uses the device identification information item to provide the service to the user via the computing device, or send a second message to the second server device. The message includes the device identification information item and instructs that the user is authorized to access the service provided by the second server device. The second server device provides the service to the user via the computing device using the device identification information item. Receipt of the second message responds.
[0018] The present invention also describes a method, including: the portable device obtains the graphically encoded information item displayed on the display of the computing device, and transmits a first message to the first server device, the first message including the encoded An information item and a first identifier identifying the device or a user of the device, and the first server device receives the first message from the device, and decodes the encoded information from the encoded information item, wherein The decoded information includes a device identification information item for allowing the identification of the computing device to establish the identity of the user of the device, wherein the step of establishing the identity of the user includes: using the first identifier to determine whether to The first server device registers the user,
In response to establishing the user's identity, authorizing the user to access the service, and using the device identification information item to provide the service to the user via the computing device, or to send a second message to the second server device, the second message including the device identification Information item and instruct the user to access the service provided by the second server device, the second server device provides the service to the user via the computing device by using the device identification information item, and the second message is received Respond.
[0019] The present invention also describes a system for performing the above method.
[0020] The present invention also describes computer-readable code, which is optionally stored on a non-transitory storage medium, which when run by a computing device, causes the computing device to perform any of the above methods.
[0021] The present invention also describes a method for handling encoded information, involving a first server, a second server, and a portable device. The method includes: generating a verification information item for inclusion in the encoded information item , Wherein the reference verification information item is stored on the first server device, and the encoded information item including the verification information item is to be decoded by the portable device; the portable device performs the steps of: obtaining the encoded information item; The encoded information of the encoded information item is decoded; a first message is transmitted to the first server device, the first message includes the decoded information and a first identifier that identifies the device or the user of the device; And the first server device to perform the steps: receiving the first message from the device; establishing the identity of the user of the device, wherein the step of establishing the identity of the user of the device includes: using the first identifier to determine whether to The first server device registers the user; in response to establishing the user's identity, authorizes the user to access the service; and sends a second message to the second server device, the second message indicating that the user is authorized to access the service provided by the second server device The second server device responds to the reception of the second message by providing the service to the user via the portable device or to the portable device via the first server.
[0022] The present invention also describes a method for handling encoded information, involving a first server, a second server, and a portable device, and the method includes: generating verification information for inclusion in the encoded information item Item, wherein the reference verification information item is stored on the first server device, and the encoded information item including the verification information item is to be obtained by a portable device; the portable device performs the steps of: obtaining the encoded information; and The first server device transmits a first message, the first message including the encoded information item and a first identifier that identifies the device or the user of the device; and the first server device performs the step of: receiving the first message from the device A message; decoding the encoded information from the encoded information item; establishing the identity of the user of the device, wherein the step of establishing the identity of the user of the device includes: using the first identifier to determine Whether to register the user with the first server device; in response to establishing the user's identity, authorize the user to access the service; and send a second message to the second server device, the second message indicating that the user is authorized to access the second server device To provide a service, the second server device responds to the reception of the second message by providing the service to the user via the portable device or to the portable device via the first server.
[0023] The present invention also describes a system for handling encoded information, involving a first server, a second server, and a portable device. The system includes: generating a verification information item for inclusion in the encoded information item , Wherein the reference verification information item is stored on the first server device, and the encoded information item including the verification information item is to be obtained and decoded by the portable device; the portable device is configured to: obtain the encoded information item Decode the encoded information from the encoded information item; transmit a first message to the first server device, the first message including the decoded information and the first identifying the device or the user of the device And the first server device is configured to: receive the first message from the device; establish the identity of the user of the device, wherein the establishment of the user of the device
The identity step includes: using the first identifier to determine whether to register the user with the first server device; in response to establishing the users identity, authorizing the user to access the service; and sending a second message to the second server device, the second The message indicates that the user is authorized to access the service provided by the second server device, wherein the system further includes the second server device by providing the service to the user via the portable device or to the portable device via the first server, and Receipt of the second message responds.
[0024] The present invention also describes a system for handling encoded information, involving a first server, a second server, and a portable device. The system includes: generating verification information for inclusion in the encoded information item Item, wherein the reference verification information item is stored on the first server device, and the encoded information item including the verification information item is to be obtained by a portable device; the portable device is configured to: obtain the encoded information; and Transmitting a first message to the first server device, the first message including an encoded information item and a first identifier identifying the device or a user of the device; and the first server device is configured to: receive from the device The first message; decoding the encoded information from the encoded information item; establishing the identity of the user of the device, wherein the step of establishing the identity of the user of the device includes: using the first identifier To determine whether to register the user with the first server device; and in response to establishing the user's identity, authorize the user to access the service; and send a second message to the second server device, the second message indicating that the user is authorized to access the second A service provided by a server device, wherein the system further includes the second server device configured to provide the service to the user via the portable device or to the portable device via the first server, and to provide information to the second message Receive an answer.
Description of the drawings
[0025] For a more comprehensive understanding of the exemplary embodiments of the present invention, reference is now made to the following description given in conjunction with the accompanying drawings, in which:
[0026] FIG. 1 is a schematic illustration of a system in which embodiments of the present invention can be implemented;
[0027] FIG. 2 is a schematic illustration of a method according to an embodiment of the present invention; and
[0028] FIG. 3 is a schematic illustration of a system and method according to an alternative embodiment of the present invention.
Detailed ways
[0029] In the drawings and the following description, the same reference numerals denote the same elements.
[0030] FIG. 1 is a schematic illustration of a system in which embodiments of the present invention can be implemented.
[0031] The system 1 includes a computing device 10, a mobile device 12, a first server device 14 and a second server device 16. The first and second server devices 14, 16 may be located in the cloud.
[0032] The mobile device 12 is operable to communicate wirelessly with the first server device 14. The wireless communication with the first server device is performed via the transceiver 124. The wireless communication with the first server device may be via a telephone network or a data network. The mobile device 12 includes a controller 120 and one or more memories 122. The controller 120 includes at least one processor 120A. The controller 120 may also include at least one application specific integrated circuit (ASIC) not shown. The at least one memory 122 may include any suitable type of fixed or removable storage medium, such as but not limited to ROM, RAM or EEPROM. The at least one memory 122 stores computer-readable instructions 122A thereon. The controller 120 is operable to read the computer-readable instructions 122A and operate under the control of the computer-readable instructions 122A. The controller 120 is operable to control other components of the mobile device 12.
[0033] The mobile device 12 includes an obtaining component 124 for obtaining coded information items external to the device 12. Acquisition Department
The component 124 may include a camera or scanner for obtaining graphical information, or any other type of components suitable for obtaining encoded information items.
[0034] The mobile device 12 also includes a user interface 126 for receiving user input. The mobile device may also include a display 128. In this example, the user interface 126 and the display 128 form a touch screen. However, it will be understood that the user interface 126 may be of any type. For example, it may include one or more of one or more hardware buttons, trackballs, touch pads, scroll wheels, and the like.
[0035] The first server device 14 is operable to communicate with the mobile device 12. The first server device 14 is also operable to communicate with the second server device 16. The first server device 14 includes a controller 140 and one or more memories 142. The controller 140 includes at least one processor 140A. The controller 140 may also include at least one application specific integrated circuit (ASIC) not shown. The at least one memory 142 may include any suitable type of fixed or removable storage medium, such as but not limited to ROM, RAM or EEPROM. The at least one memory 140 has stored thereon computer readable instructions 142A. The controller 140 is operable to read the computer-readable instructions 142A and operate under their control.
[0036] The first server device 14 also includes one or more transceivers 146 for communicating with the mobile device 12 and the second server device 16. The communication between the first and second server devices 14, 16 can be performed in any suitable manner.
[0037] The first server device 14 may be located at a single location, and may include one or more separate devices or machines. Alternatively, the first server device 14 may be distributed in multiple locations.
[0038] The second server device 16 is operable to communicate with the computing device 10 and the first server device 14 in any suitable manner. The second server device 16 includes one or more transceivers 164 for communicating with the computing device 10 and the first server device 14. The second server device 16 includes a controller 160 and one or more memories 162. The controller 160 includes at least one processor 160A. The controller 160 may also include at least one application specific integrated circuit (ASIC) not shown. The at least one memory 162 may include any suitable type of fixed or removable storage medium, such as but not limited to ROM, RAM or EEPROM. The at least one memory 160 stores computer-readable instructions 162A thereon. The controller 160 is operable to read the computer-readable instructions 162A and operate under their control. The controller 160 may also operate under the control of computer readable codes to control other components of the second server device 16.
[0039] The second server device 16 may be located at a single location, and may include one or more separate devices or machines. Alternatively, the second server device 16 may be distributed in multiple locations.
[0040] The computing device 10 is operable to receive a signal from the second server device 16 via the transceiver 106 to interpret the information included therein and display it on the display 104 for user consumption. The computing device 10 may also include a user interface 108, such as but not limited to a mouse, touch pad, or keyboard via which user input can be received. The computing device 10 includes a controller 100 and one or more memories 102. The controller 100 includes at least one processor 100A. The controller 100 may also include at least one application specific integrated circuit (ASIC) not shown. The at least one memory 102 may include any suitable type of fixed or removable storage medium, such as but not limited to ROM, RAM or EEPROM. The at least one memory 100 stores computer-readable instructions 102A thereon. The controller 100 is operable to read computer readable instructions 102A and operate under their control. The controller 100 can operate under the control of computer readable code to control other components such as the display 104 and the transceiver 106.
[0041] FIG. 2 is a schematic illustration of a method according to a first embodiment of the present invention.
[0042] In step S2-1, the second server device 16, which is a web server in this example, provides information to the computing device 10. In this example, the information is web page information. The provision of the web page information may be in response to a request received from the computing device 10 after the user input is received at the computing device 10.
[0043] In step S2-2, the computing device receives and displays web page information. In this example, the web page information includes the "login" page 110. The "Login" page 110 includes an area where the user can provide details (in this example, username and password). The second server device 16 is operable to verify these details and then allow the user to access the services and content provided in the web page.
[0044] The web page includes an encoded information item 112, and the encoded information item 112 includes encoded information. In this example, the encoded information item 112 is a graphical object (G0) (depicted as a "quick response" (QR) code in the figure). It will be understood that various other types of graphical objects may be used instead. Examples are barcodes, irregular patterns, and moving images.
[0045] G0 112 includes GO address information items. The GO address information item includes the address of the computing device 10 on which the GO 112 is displayed or through which the GO 112 is displayed. The GO address information item may include a code such as a numeric code or an alphanumeric code, which identifies the route or routes to the device. Examples of such codes are IP addresses, phone numbers, domain names, and BlackBerry®PIN» [0046] According to other embodiments, the GO address information item may not include the address information itself, but may instead include a code that allows to determine that G0 112 is displayed on it. Information about the address of the device. This can include, for example, a code or number, such as but not limited to a hardware serial number, which can be used to determine a route to a computing device (eg, IP address) from a lookup table.
[0047] In this example, the GO 112 also includes a second server identification (SSID) information item that allows the second server device 16 to be identified. The SSID information item may include the address of the second server device 16. Alternatively, the SSID information item may include information that allows the application of the mobile device 12 or the first server device 14 to be determined, for example, from a lookup table.
[0048] The G0 112 may also include a first server device (FSID) information item for allowing the mobile device 12 to identify the first server device 14 associated with the G0 112<sub>O</sub>The FSID information item may include the address of the first server device 14 or may instead include data items, such as a code that allows an application stored on the mobile device 12 (described in more detail below) to restore the address of the first server device 14 from the memory 122.
[0049] G0 112 may also include one or more verification information items for allowing verification of the image object to ensure that it is not fake.
[0050] The information required to display the G0 112 may be generated by the second server device 16. Alternatively, a part of the GO 112 information such as the SSID and FSID information items may be generated by the second server device 16 or the first server device 14, and other information such as the GO address information item may be generated by the computing device 10. One or more verification information items may be generated by the second server device 16, in which case a copy of the one or more verification items is transferred to and stored in the memory 142 of the first server device 14. Alternatively, the one or more verification items may be generated by the first server device 14 and transferred to the computing device 10 via the second server device 16.
[0051] According to some embodiments, GO 112 may be displayed by computer program code embedded in a web page. Alternatively, the GO 112 may be displayed by computer program code stored on the computing device 10, for example, during the registration process. The computer program code that is stored on the computer device 10 and generates G0 112 can directly communicate with the second server device 16 when it is run by the controller 100. If direct communication with the second server device 16 can be established, the computer program code can be configured such that only G0 112 is displayed. If direct communication is not possible, GO 112 is not displayed, and therefore GO 112 cannot be used to access the service. The computer program can determine whether it is in direct communication in any suitable manner. For example, the IP address of the second server device can be encoded in a computer program, and this can be used to determine whether to communicate with the second server device 16. If the proxy server is between the second server device 16 and the computer device 10, the computer program will recognize that the IP address of the server with which it is communicating (ie, the IP address of the proxy server) is not its expected IP address. The computer program thus determines that it is not communicating with the second server device 16 and does not display G0 112. Alternatively, the computer program may send a request for a token to the second server device, and the token should be stored in the storage of the second server device 16.
In the device.The proxy server will not have the token in the memory, and therefore will not be able to return it to the computer device 10. In this way, the computer device 10 can determine that it does not directly communicate with the second server device 16. Similarly, the computer program can send a request for evidence of the processing desired to run on the second server device 16. If the process is not running on the computer where the request arrives, the computer program determines that it is not communicating with the second server device 16. It will be understood that any suitable mechanism including, for example, PKI, SSL, or DNS pooling may be used to make this determination.
[0052] In step S2-3, G0 112 is obtained by the mobile device 12. This may involve the user of device 12 using the camera of device 12 to take a picture of G0 112. Alternatively, any other type of scanner can be used to obtain GO 112.
[0053] In step S2-4, the application decodes the encoded information from the obtained GO 112. This application is a dedicated part of the computer-readable code 122A stored in the memory 122 of the device that can decode the GO 112 and perform subsequent operations.
[0054] The application may have been stored on the mobile device 12 before, during, or after the registration process between the mobile device 12 and the first server device 14. In either way, the user of the apparatus 12 must register with the first server device 14 to allow the user to utilize the services provided by the first server device 14.
[0055] During the registration process, the first server device 14 may store a user identification (UID) information item related to the user in its memory 142. This can include, for example, a username or user number. Alternatively, the first server device 14 may store a device identification (DID) information item related to the mobile device 12. The DID information item may include, for example, the phone number of the device, the IP address of the device, or a device ID code such as a serial number. The DID or UID information item is stored in association with user registration information (such as name, address, etc.). Thus, the DID and UID information items can be used to allow the first server device 14 to identify the user. A copy of the DID or UID information item is stored in the memory 122 of the mobile device 12.
[0056] In step S2-5, after decoding the obtained GO 112, the application prepares a first message (in this example, a login request) 314, and transmits it to the first server device 14.
[0057] The first message 214 is sent to the first server device 14 using the address of the first server device 14. The application may be configured to work with only one first server device 14, and thus as long as G0 112 is obtained, the first message 214 is sent to the same first server device 14 using the address stored in the memory 122. Alternatively, in an embodiment where G0 112 includes the FSID information item, this can be used to send the first message 214 (when the FSID information item includes the address of the first server information item, send it directly, or by using the FSID information item Send indirectly by restoring the address from the memory 122). In other alternative embodiments, the first message 214 may be sent to an address selected by the user from among a plurality of addresses stored on the device 12.
[0058] The first message 214 includes a first information part, and the first information part includes DID information or UID information. The first message 214 also includes a second information part, and the second information part includes a G0 address information item. The first message 214 may also include an SSID information item.
[0059] In an embodiment in which there is a verification information item in G0 112, the application may check the verification information item against the reference information item received from the first server device 14 before preparing and sending the first message 214 to determine Whether G0 112 is real. If it is determined that G0 112 is not real, then the user of the device 12 is warned. If it is determined that the GO 112 is real, the application prepares the first message 214 and transmits it to the server device 14. After receiving the update message from the first server device 14, the reference information for which the verification object is checked may be periodically updated. According to an alternative embodiment, the application may not check the verification information item, but may include it in the first message 214 instead.
[0060] Before preparing and sending the first message, the application may request the user to enter security information via the user interface 124 of the device 12 to thereby allow verification of the user's identity. The security information may include a pin or password, a disguised pin or password, a one-time code that has been sent to the user, a pattern drawn on the device, biological information (such as face or fingerprint recognition), or can be passed through
Any other suitable mechanism to verify the identity of the user of the device.
[0061] Next, in step S2-6, the first server device 14 receives the first message 214 (login request), and uses the UID or DID information to establish the identity of the user of the apparatus 12. Establishing the user's identity includes using UID or DID information items to determine whether to register the user with the first server device 14. Thus, the first server device 14 can check UID or DID information against the information stored in the database of the registered user to establish the user's identity. After establishing the identity of the user, the first server device proceeds to step S2-7<sub>O</sub>
[0062] In the embodiment in which the first message 214 includes the verification information item, the first server device 14 may check the verification against the reference information item stored in the memory 142 before any one of steps S2-6 and S2-7. Information item. If there is a coincidence between the reference information item and the verification item, the first server device 14 proceeds to step S2-6 or S2-7 as appropriate. If there is no agreement, the first server can send a message to the mobile device 12 to warn the user that G0 112 is untrue, and the method can be subsequently aborted.
[0063] In step S2-7, the first server device 14 prepares a second message 216 and sends it to the second server device 16. In this example, the second message 216 includes authorization information for notifying the second server device 16 of the identity of the user and authorizing the user to access the service provided by the second server device 16. The second message 216 also includes a G0 address information item.
[0064] The second message 216 is sent based on the SSID information item, and is sent directly when the SSID information item is the address of the second server device 16, or when the SSID information item enables the first server device to restore the second server device 14 from the memory 142 Address time to send.
[0065] In step S2-8, once the second message 216 is received, the second server device 16 performs an action. In this example, the second server device 16 is a web server, and thus in response to receiving the authorization information, the second server device 16 causes the user to log in to their account, and then uses the G0 address information item to send instructions to the computing device 10 Its signal. [0066] In step S2-9, the computing device 10 displays the received information, which indicates that the user is now logged in to the website.
[0067] According to some embodiments, the step S2-6 in which the first server device 14 establishes the user's identity may include an additional step for verifying the user's identity. In the embodiment where the mobile device 12 is a mobile phone, these steps may include the first server device 14 responding to the reception of the first message 214 by initiating a voice call with the mobile device 12. During the voice call, the user is asked to provide information that can verify their identity. This information may include, for example, a PIN number sent via DTMF, or a verbal password, or any other information that allows the user's identity to be established and verified. The information from the user may be compared with the information stored in the memory 142 of the first server device 14 and associated with the user. The voice call can be made using IVR, human agent, or a combination of the two. In embodiments where the mobile device 12 does not have telephone capabilities, these steps may be performed using messages such as instant messages sent using Internet protocols.
[0068] FIG. 3 depicts an alternative system in which the invention can be implemented and illustrates a method according to the invention.
[0069] The example of FIG. 3 is similar to the examples of FIGS. 1 and 2, but the difference is that it does not include the second server device 16. Thus, the system includes a computing device 10, a mobile device 12, and a first server device 14.
[0070] In the system 3 of FIG. 3, the first server device 14 is a web server, and is thus operable to provide web page information to the computing device 10 for display for consumption by the user.
[0071] The method according to the present invention will now be described with reference to FIG. 3.
[0072] In step S3-1, the first server device 14 provides web page information to the computing device 10. The provision of the web page information may be in response to a request received from the computing device 10 after the user input is received at the computing device 10.
[0073] In step S3-2, the computing device 10 receives and displays web page information. In this example, the page information includes "Login
The "Login" page 110. The "Login" page 110 is as described with reference to Figure 2 and includes a coded information item 312, which in this example is a graphical object (G0), especially a "quick response" (QR) Code.
[0074] G0 312 includes GO address information items. The GO address information item includes the address of the computer device 10 on which the GO 312 is displayed or through which the GO 312 is displayed. The GO address information item may include a code such as a numeric code or an alphanumeric code, which identifies the route or routes to the computer device 10. Examples of such codes are IP addresses, phone numbers, domain names, and BlackBerry® PINO
[0075] According to other embodiments, the GO address information item may not include the address information itself, but may instead include information that allows determining the address of the device on which the GO 312 is displayed or through which the GO 312 is displayed. This can include, for example, a code or number, such as but not limited to a hardware serial number, which can be used to determine a route to a computing device (eg, IP address) from a lookup table.
[0076] The GO 312 may also include a first server device (FSID) information item for allowing the mobile device to identify the first server device 14 associated with the GO 312<sub>O</sub>The FSID information item may include the address of the first server device 14 or may instead include a data item that allows an application stored on the mobile device 12 to restore the address of the first server device 14 from the memory 122.
[0077] GO 312 may also include a verification information item for allowing verification of the graphic object to ensure that it is not fake.
[0078] The information required to display the G0 312 may all be generated by the first server device 14. Alternatively, part of the information of the GO 312 such as the SSID and FSID information items may be generated by the first server device 14, and other information such as the GO address information items may be generated by the computing device 10. One or more verification information items are generated by the first server device 14, and a copy of the one or more verification information items is retained in the memory 142 of the first server device 14.
[0079] According to some embodiments, GO 312 may be displayed by computer program code embedded in a web page. Alternatively, the GO 312 may be displayed by computer program code stored on the computing device 10, for example, during the registration process. The computer program code that is stored on the computer device 10 and generates G0 112 can directly communicate with the first server device 14 when it is run by the controller 20. If direct communication with the first server device 14 can be established, the computer program code can be configured such that only G0 312 is displayed. This can be determined in any suitable way, for example as described with reference to FIG. 2 with respect to the second server device 16.
[0080] In step S3-3, G0 312 is obtained by the mobile device 2. This may involve the user of device 12 using the camera of device 12 to take a picture of G0 312. Alternatively, any other type of scanner can be used to obtain GO 312.
[0081] In step S3-4, the application decodes the encoded information from the obtained GO 312. This application is a dedicated portion of the computer-readable code 122A stored in the memory 122 that can decode the GO 312 and perform subsequent operations.
[0082] The application may have been stored on the mobile device 12 before, during, or after the registration process between the mobile device 12 and the first server device 14. In either way, the user of the apparatus 12 must register with the first server device 14 to allow the user to utilize the services provided by the first server device 14. The registration to the first server device is described with reference to FIG. 2.
[0083] In step S3-5, after decoding the obtained GO 312, the application prepares the first message 314 and transmits it to the first server device 14.
[0084] The first message 314 is sent to the first server device 14 using the address of the first server device 14. The application may be configured to work with only one first server device 14 and thus as long as the G0 312 is obtained, the first message 314 is sent to the same first server device 14 using the address stored in the memory 122. Alternatively, in an embodiment where G0 312 includes an FSID information item, this can be used to send the first message 214 (when the FSID information item includes the address of the first server information item, send it directly, or by using the FSID information item Indirectly by restoring the address from the memory 122
send). In other alternative embodiments, the first message may be sent to an address selected by the user from among a plurality of addresses stored on the device 12.
[0085] The first message 314 includes a first information part, and the first information part includes a DID information item or a UID information item. The first message 214 also includes a second information part, and the second information part includes a G0 address information item.
[0086] The first message may also include a verification information item. Alternatively, the application may check the verification information item against the reference information item received from the first server device 14 before preparing and sending the first message 314 to determine whether the GO 312 is authentic. If it is determined that G0 112 is not real, then the user of the device 12 is warned. If it is determined that the GO 312 is real, the application prepares the first message 314 and transmits it to the server device 14.
[0087] Before preparing and sending the first message 314, the application may request the user to provide security information via the user interface 124 of the device 12 to thereby allow verification of the user's identity. The security information may include a pin or password, a fake pin or password, a one-time code that has been sent to the user, a pattern drawn on the device, biological information (such as face or fingerprint recognition), or the identity of the user through which the device can be verified. Any other suitable mechanism.
[0088] Next, in step S3-6, the first server device 14 receives the first message 314 and uses the UID or DID information item to establish the identity of the user of the apparatus 12. Establishing the user's identity includes using UID or DID information items to determine whether to register the user with the first server device 14. Thus, the first server device 14 can check UID or DID information against the information stored in the database of the registered user to establish the user's identity. After establishing the identity of the user, the first server device proceeds to step S3-7<sub>O</sub>
[0089] In an embodiment in which the first message 314 includes a verification information item, the first server device 14 may check the verification against the reference information item stored in the memory 142 before any one of steps S3-6 and S3-7. Information item. If there is agreement between the reference information item and the verification item, the first server device 14 proceeds to step S3-6 or S37 as appropriate. If there is no agreement, the first server can send a message to the mobile device 12, or warn the user that GO 312 is untrue, and the method can be aborted.
[0090] In step S3-7, the first server device 14 performs an action after establishing the user's identity. In this example, when the first server device 14 is a web server, the first server device 14 causes the user to log in to their account. The first server device 14 uses the GO address information item to send a signal indicating it to the computing device. In this example, the G0 address information includes the IP address of the computing device 10, and so the first server device 16 transmits to the computing device 10 information indicating the user who has logged in to their account.
[0091] In step S3-9, the computing device 10 displays the received information, which indicates that the user is now logged in to the website.
[0092] According to some embodiments, the step S3-6 in which the first server device 14 establishes the identity of the user may include an additional step for verifying the identity of the user. These steps may be those described above with reference to steps S2-6 in FIG. 2.
[0093] In the embodiment of FIGS. 2 and 3, the GO 112, 312 is displayed in combination with the area where the user name and password can be entered.<sub>O </sub>However, it will be understood that GO 112,312 can be displayed instead of the username and password fields.<sub>O</sub>Moreover, although in the embodiment described with reference to FIGS. 2 and 3, G0 112, 312 is used instead of the user name and password to allow the user to log in to the web page, it will be understood that it can be used in combination with the traditional login process using the user name and password area GO 112,312<sub>O</sub>This adds an extra layer of security for both the web server and the user.
[0094] It will be understood that the present invention may be implemented in systems other than the systems described above. The following briefly describes such an implementation. Although it is briefly described, it will be understood that the operation may be substantially the same as described above, and may include some or all of the same steps and features.
[0095] According to an alternative embodiment, the present invention may be implemented in a building security system. In such an embodiment, the computing device 10 may include an electronic door lock. The encoded information items 112, 312 such as the above-mentioned G0 may be displayed on a sign that is geographically close to the electronic door lock. Alternatively, GO 112,312 can be provided on an electronic display that is geographically close to the electronic door lock<sub>O</sub>In such an embodiment, after receiving a signal from the first server device 14 (or from the second server device 16 if the system is as shown in FIG. 2), the encoded information item may be periodically updated . G0 112,312 includes G0 address information that allows identification of electronic door locks. The encoded information items 112, 312 may also include the aforementioned FS ID information items. Once approaching the door, the user uses their mobile device 12 to obtain and decode the encoded information items 112, 312. Then, optionally after the user successfully provides security information to the mobile device, a first message is sent to the first server device 14 214,314 (including G0 address information objects and UID or DID information items). In this example, the first message 214, 314 includes an "entry request." In response to receiving the entry request 214, 314, the first server device 14 uses the UID or DID information item to establish the identity of the user. Next, if the system does not include the second server device, the first server device 14 (using the G0 address information item) transmits a signal authorizing the electronic door lock to open to the electronic door lock, and thereby allows the user to pass through the door. Alternatively, if the system does include the second server device 16, the first server device 14 transmits (using the G0 address information item) to the electronic door lock a signal authorizing the electronic door lock to open, and transmits to the second server device 16 that answers The second message 216 (including instructions to authorize the use Authorization information for the user to enter the door).
[0096] According to another alternative embodiment, the present invention may be implemented to enable customers to pay for their goods at the checkout device. In this embodiment, the computing device 10 is a checkout device. Once the goods to be purchased have been scanned through the checkout device, The checkout device 10 generates and displays the encoded information items 112, 312, in this example GO o G0 112, 312 including the GO address information item (as described above) that allows the checkout device to be identified, and the total price to be paid. The GO may also include an information item that identifies (or allows the identification through the application) the banking institution to which the currency is to be paid. Optionally, after the user provides the security information to the mobile device 12, the application of the mobile device 12 transmits the first message 214, 314 (payment request) to the first server device 14. The payment request 214, 312 includes a G0 address information item, a UID or DID information item (as previously described), price information, and an information item identifying the payee's banking institution. The first server device 14 uses the UID or DID information item to establish the identity of the user. In response to establishing the user's identity, for example, the first server device 14 that may be associated with a banking institution authorizes payment of the amount identified by the price information from the user's account to the payee banking institution. Next, if the system does not include the second server device, the first server device 14 (using the G0 address information item) transmits a signal indicating the paid balance to the checkout device. Alternatively, if the system does include the second server device 16, the first server device 14 transmits a signal indicating the paid balance to the checkout device (using the G0 address information item), and sends a signal to the second server device 16 that responds. (It may be associated with the payee's banking institution) transmits a second message 216 (instructing the user to be authorized to make the payment).
[0097] According to another alternative embodiment, the present invention may be implemented in an ATM system. In this embodiment, the computing device 10 is an ATM. The user requests to withdraw a certain amount of currency from the ATM. In response to this, the ATM generates and displays encoded information items 112, 312. In this example, GO o G0 112, 312 includes GO address information items that allow the ATM to be identified, and information indicating the amount of withdrawal. G0 112 may also include an SSID information item. After the user provides security information (such as a pin, etc.) to the mobile device 12, the application of the mobile device 12 transmits a first message 214 (withdrawal request) to the first server device 14. The withdrawal request 214 includes a G0 address information item, a UID or DID information item identifying the device or user, withdrawal amount information, and (if applicable) SSID information item. The users identity is established by the first server device 14 using UID or DID information items, and in response to the establishment of the users identity, the first server device 14 (associated with the banking institution in this example) authorizes withdrawals and sends to the user account Debit The amount indicated by the withdrawal amount information. Next, if the system does not include the second server device 16, the first server device 14 (using the G0 address information item) transmits to the ATM a signal authorizing the ATM to distribute the requested amount. Make
For selection, if the system does not include the second server device 16, the first server device 14 transmits to the ATM (using the GO address information item) a signal authorizing the ATM to distribute the requested quantity, and (using the SSID information item) to the response The second server device 16 (if it is different from the banking institution of the user, it can be associated with the banking institution that owns the ATM) transmits a second message 216.
[0098] According to another alternative embodiment, the present invention may be implemented in a self-service shopping environment. In such an embodiment, the encoded information item 112 may be provided on the smart label of the product for sale, in this example G0. The user uses their mobile device 14 to obtain G0 112. In this embodiment, the GO 112, 312 includes the GO address information item (as described above) that allows the smart tag to be identified, and the price of the product. G0 112,312 may also include information items that identify (or allow identification through its application) the banking institution to which the currency is to be paid. Optionally, after the user provides security information to the mobile device 12, the application of the mobile device transmits a first message 214 (purchase request) to the first server device, including a G0 address information item, a UID or DID information item, and price information . The identity of the user is established by the first server device 14 using UID or DID, And in response to establishing the user's identity, the first server device 14 authorizes payment of the amount identified by the price information. Next, the first server device 14 transmits a second message 216 to the second server device 16 (which may be an in-store security system). The second message 216 includes a GO address information item and authorization information indicating that the product has been paid. In response to receiving the second message 216, the second server device uses the GO address information item to transmit a signal to the smart tag to thereby disable the tag so that when the user attempts to leave the store, the alarm is not activated.
[0099] Although in the above embodiments, the encoded information items 112, 312 have been described as graphical objects, it will be understood that they can be replaced by different types of encoded information items. These may include, for example, encoded audible information items, which can be transmitted by the computing device 10 and recorded and decoded by the mobile device 12. Other types of encoded information items include encoded radio frequency (RF) information items.
[0100] In some embodiments, the encoded information items 112, 312 may include a sequence of numbers, letters, or symbols. In such an embodiment, as a result of the user manually typing the sequence into the device using the user interface 126, the device 12 may obtain an encoded information item. In other alternative embodiments, the encoded information item may be obtained via a wired connection between the apparatus 12 and the computing device 10.
[0101] In some embodiments, the encoded information items 112, 312 may be changed periodically, for example, by updating the verification items. In such an embodiment, when the verification item is not created by the same entity that is responsible for checking it, each time the verification item is updated, the verification item is transmitted to the inspection entity.
[0102] In the foregoing embodiment, before sending the first message 214 to the first server device 14, the device decodes the encoded information items 312, 112. However, in an alternative embodiment, the encoded information items 112, 312 may be transmitted in the first message 214 for decoding by the first server device 14. In such an embodiment, the apparatus 12 has pre-stored the address of the first server device. The application may be configured to send the first message 214 to that address every time the encoded information item 112.312 is obtained. Alternatively, the user can select the address to which the first message 214 is to be sent from a plurality of addresses stored in the device 12. In these embodiments where the first message includes an encoded information item, it will be understood that where the encoded information item includes a verification item, it will be verified by the first server device 14 and not by the device 12.
[0103] In FIGS. 2 and 3, the mobile device 12 is depicted as a mobile phone. However, it will be understood that it may be any type of device, including an obtaining component 124 that obtains the encoded information item in one or more of the foregoing ways. The obtaining component 124 may include, for example, a physical interface for receiving an encoded information item in the form of a computer-readable electrical signal from the computing device 10, a transceiver for receiving an RF-encoded information item as an RF signal, or for obtaining An audio receiver that can hear the encoded data items.
[0104] The mobile device 12 is depicted as a single unit in FIG. 1. However, it will be understood that it may instead include multiple separate units, such as webcams and laptop computers.
[0105] The present invention provides a novel and creative way of providing secure access to services. The provision of encoded information items reduces the possibility of so-called "man-in-the-middle attacks". The present invention is particularly effective in this respect in that, in the embodiment, the computer program code used to generate the encoded information item is stored on the computer device 10 and is configured to be established with the network server 14; When the application running on 16 communicates directly, only the encoded information items (ie, display, transmission, output, etc.) are provided. This is because if a proxy server is placed between the computer device 10 and the network server 14; 16 to intercept the communication between the two, the computer program code running on the computer device 10 and the application running on the network server cannot be established. Direct communication between the two, and therefore will not provide encoded information items. As a result, users cannot access the service, and therefore cannot disclose sensitive information to fraudsters operating the proxy server.
[0106] The use of the verification item (which can be changed periodically) through which the first server device can verify the encoded data item reduces the fraudster's ability to clone the encoded information item and thereby clone the service in order to illegally discover from the user Information opportunities. In addition, the use of the mechanism according to the present invention reduces the amount of personal information (such as a user name and password) that needs to be entered in the computing device 10, and the security of personal information can be threatened by the existence of viruses and the like.
[0107] The present invention also allows rapid login processing because the user may not need to spend time typing in password and user name information. Similarly, the present invention can eliminate the need for users to remember many passwords for many different services.
[0108] In some embodiments of the present invention where it is necessary to obtain encoded information items and to enter a password, an additional layer of security is introduced, and so the system is more secure for users.
[0109] The present invention also allows for the application of hierarchical verification strength based on risk, transaction value, and/or user profile. For example, for some websites, simply possessing the mobile device 12 and obtaining encoded data items may be sufficient to allow users to access the services provided by the website. For other implementations such as payment and bank implementations, a more complex set of authentication factors (for example, possession of the device and knowing the password) can be used. If the device 12 is lost or stolen, the network provider (if the device is a mobile phone) can ban the device, thereby preventing the thief or discoverer of the device from being able to use the device and the applications stored on the device to access The users website and the services they subscribe to, etc. Alternatively, the user can contact the owner or repairer of the first service device to order them to ensure that any request from the lost or stolen device is rejected. The new device can then be associated with the registration of the user at the first server device 14.
[0110] In some embodiments of the invention, users may only be allowed to register their devices with the first server 14 if they have a monthly contract with the mobile phone network provider. Such a contract (as opposed to the so-called "pay as you go" price list) involves strict identification processing, including proof of address and bank details provided by the user. Therefore, for services whose security is important (such as banking, etc.), if users have a monthly payment contract and therefore know their identities more surely, they may only register to log in through the encoded information items.
[0111] By using a separate device (that is, the mobile device 12 whose service is being accessed instead of the computer device 10) and the one configured to establish user identity (see steps S2-6 and S3-6 in Figures 2 and 3, respectively) The server device 14 communicates to achieve security advantages. By making the verification process "out of band" in this way, the complexity of the system is increased. It is quite difficult and expensive for fraudsters to detect, intercept or threaten multiple communication channels (bands) and/or server equipment. As a result, the system is more secure.
[0112] It should be recognized that the foregoing embodiments are not limiting. Once those skilled in the art have read this application, other changes and modifications will be obvious. In addition, the disclosure of this application should be understood to include any novel features or any novel combination of these features or any generalizations explicitly or implicitly disclosed herein, and during the litigation period of this application or any application derived therefrom, the new The claims may be expressly expressed as covering any such feature and/or combination of such features.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN109639553A | Cited by | China | – | Search report | – |
| CN111695100A | Cited by | China | – | Search report | – |
| CN1928907A | Cites | China | X | Search report | 说明书第7页第2段到第12页第4段 |
| US2009241175A1 | Cites | United States of America | A | Search report | 全文 |
| EP2166697A1 | Cites | European Patent Office (EPO) | A | Search report | 全文 |
57 members in 15 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 10200251 | United Kingdom | – | |
| 201020025 | United Kingdom | A | |
| 201020025 | United Kingdom | A | |
| 201180064866 | China | A | |
| 201180064866 | China | A | |
| 10200251 | – | – | – |
| 2011800648663 | – | – | – |
| CN20118064866 | – | – | – |
| CN2011864866 | – | – | – |
| GB20100020025 | – | – | – |
Members57
| Document | Office | Kind | |
|---|---|---|---|
| GB201020025D0 | United Kingdom | D0 | |
| GB2481663A | United Kingdom | A | |
| GB201205664D0 | United Kingdom | D0 | |
| CA2818972A1 | Canada | A1 | |
| WO2012069845A1 | World Intellectual Property Organization (WIPO) | A1 | |
| GB2481663B | United Kingdom | B | |
| GB2489332A | United Kingdom | A | |
| GB201215438D0 | United Kingdom | D0 | |
| GB2491514A | United Kingdom | A | |
| GB2489332B | United Kingdom | B | |
| AU2011333497A1 | Australia | A1 | |
| AU2011333497A8 | Australia | A8 | |
| CO6731100A2 | Colombia | A2 | |
| PH12013501067A1 | Philippines | A1 | |
| MX2013005908A | Mexico | A | |
| EP2643787A1 | European Patent Office (EPO) | A1 | |
| CN103403728A | China | A | |
| CL2013001484A1 | Chile | A1 | |
| JP2014502394A | Japan | A | |
| RU2013128748A | Russian Federation | A | |
| GB2491514B | United Kingdom | B | |
| US2015089591A1 | United States of America | A1 | |
| GB201503007D0 | United Kingdom | D0 | |
| GB2519876A | United Kingdom | A | |
| GB2519894A | United Kingdom | A | |
| GB2519876B | United Kingdom | B | |
| GB2519894B | United Kingdom | B | |
| GB2519876B8 | United Kingdom | B8 | |
| MX336021B | Mexico | B | |
| GB2519894A8 | United Kingdom | A8 | |
| GB2519894B8 | United Kingdom | B8 | |
| AU2011333497B2 | Australia | B2 | |
| CN103403728B | China | B | |
| AU2016225906A1 | Australia | A1 | |
| CN106127017A | China | A | |
| CN106295303AThis record | China | A | |
| RU2608002C2 | Russian Federation | C2 | |
| US9614849B2 | United States of America | B2 | |
| JP6141187B2 | Japan | B2 | |
| US2017180358A1 | United States of America | A1 | |
| BR112013013027A2 | Brazil | A2 | |
| JP2017157227A | Japan | A | |
| ZA201303812B | South Africa | B | |
| AU2016225906B2 | Australia | B2 | |
| JP6494686B2 | Japan | B2 | |
| GB2489332C | United Kingdom | C | |
| US10530769B2 | United States of America | B2 | |
| CN106127017B | China | B | |
| US2020396224A1 | United States of America | A1 | |
| RU2742910C1 | Russian Federation | C1 | |
| GB2489332C2 | United Kingdom | C2 | |
| US11146561B2 | United States of America | B2 | |
| US2022239652A1 | United States of America | A1 | |
| US2024187412A1 | United States of America | A1 | |
| EP2643787B1 | European Patent Office (EPO) | B1 | |
| EP2643787C0 | European Patent Office (EPO) | C0 | |
| US2025260693A1 | United States of America | A1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Rejection of invention patent application after publicationRJ01 | RJ01 | |
| Entry into substantive examinationC10 | C10 | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 106295303
- Publication, DOCDB
- 106295303
- Publication, EPODOC
- CN106295303
- Application
- 2016106435025
- Application, DOCDB
- 201610643502
- Application, EPODOC
- CN201610643502
Titles2
- Chinese
- 用于处置编码后的信息的方法和系统
- English
- Method and system for processing encoded information
Classification
- CPC, 18
- G06F21/34
- G06Q20/401
- G06Q20/00
- H04L63/10
- G06F21/35
- G06F21/36
- G06F21/43
- G06Q20/3276
- G06Q20/407
- H04L63/0853
- H04L63/18
- G06F16/9554
- H04L63/083
- H04L2463/082
- H04W12/77
- G07C9/38
- H04L9/32
- H04L63/08
- IPC, 7
- G06F21 34
- G06F21 35
- G06F21 36
- G06F21 43
- G06Q20 32
- G06Q20 40
- H04L29 06