Method and system for security protection of account information

US2016294867A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016294867-A1
Application numberUS-201615182638-A
CountryUS
Kind codeA1
Filing dateJun 15, 2016
Priority dateFeb 14, 2014
Publication dateOct 6, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for security protection of account information is provided, where the method includes: detecting an account input event on an accessed web page; determining, when the account input event is detected, whether a URL of the accessed web page exists in a preset secure URL list; calculating, if the URL of the accessed web page does not exist in the secure URL list, a page similarity between the accessed web page and a preset real web page according to the URL and/or web page content of the accessed web page; and determining, according to the page similarity, whether the accessed web page has a security risk, and if yes, displaying an account security risk alert. The method preventing a user from being induced by a malicious website to input an account and a password. A system for security protection of account information is further provided.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for security protection of account information, performed at a terminal computer having one or more processors and one or more memories for storing programs to be executed by one or more processors, comprising: detecting an account input event on an accessed web page; determining, when the account input event is detected, whether a URL of the accessed web page exists in a preset secure URL list; calculating, if the URL of the accessed web page does not exist in the secure URL list, a page similarity between the accessed web page and a preset real web page according to the URL and/or web page content of the accessed web page; and determining, according to the page similarity, whether the accessed web page has a security risk, and if yes, displaying an account security risk alert. 2 . The method according to claim 1 , wherein before the detecting an account input event on an accessed web page, the method further comprises: sending the URL of the accessed web page to a server; receiving risk information that is corresponding to the URL of the accessed web page and returned by the server; and wherein when risk information indicating that the accessed web page is a non-malicious web page is received, the step of detecting an account input event on an accessed web page is performed. 3 . The method according to claim 2 , wherein the receiving risk information that is corresponding to the URL of the accessed web page and returned by the server comprises: receiving, after the server finds risk information that is corresponding to the URL of the accessed web page and in a preset URL database, the risk information returned by the server; or, receiving, when the server does not find risk information that is corresponding to the URL of the accessed web page and in a preset URL database, risk information that is generated according to the web page content of the accessed web page and then returned by the server. 4 . The method according to claim 2 , further comprising: displaying an access risk alert when risk information indicating that the accessed web page is a malicious web page is received. 5 . The method according to claim 1 , wherein the determining, according to the page similarity, whether the accessed web page has a security risk, and if yes, displaying an account security risk alert comprises: determining a risk level of the accessed web page according to the page similarity; determining, according to the risk level, whether the accessed web page has a security risk, and if yes, displaying an account security risk alert corresponding to the risk level. 6 . The method according to claim 1 , wherein the method further comprises: detecting a password submission event on the accessed web page; and displaying a login security risk alert when the password submission event is detected, and when it is determined according to the page similarity that the accessed web page has the security risk. 7 . The method according to claim 1 , further comprising: correspondingly uploading the URL of the accessed web page having the security risk, and security risk information to a server. 8 . A system for security protection of account information, performed at a terminal computer having one or more processors and one or more memories for storing programs to be executed by one or more processors, comprising: an event detecting module, configured to detect an account input event on an accessed web page; an existence judging module, configured to determine, when the account input event is detected, whether a URL of the accessed web page exists in a preset secure URL list; a similarity calculating module, configured to calculate, if the URL of the accessed web page does not exist in the secure URL list, a page similarity between the accessed web page and a preset real web page according to the URL and/or web page content of the accessed web page; and an account security risk alert module, configured to determine, according to the page similarity, whether the accessed web page has a security risk, and if yes, display an account security risk alert. 9 . The system according to claim 8 , wherein the system further comprises a URL sending module and a risk information receiving module, wherein the URL sending module is configured to send the URL of the accessed web page to a server; the risk information receiving module is configured to receive risk information that is corresponding to the URL of the accessed web page and returned by the server; and the event detecting module is further configured to detect the account input event on the accessed web page when risk information indicating that the accessed web page is a non-malicious web page is received. 10 . The system according to claim 9 , wherein the risk information receiving module is further configured to receive, after the server finds risk information that is corresponding to the URL of the accessed web page and in a preset URL database, the risk information returned by the server; or the risk information receiving module is further configured to receive, when the server does not find risk information that is corresponding to the URL of the accessed web page and in a preset URL database, risk information that is generated according to the web page content of the accessed web page and then returned by the server. 11 . The system according to claim 9 , further comprising: an access risk alert module, configured to display an access risk alert when risk information indicating that the accessed web page is a malicious web page is received. 12 . The system according to claim 8 , wherein the account security risk alert module comprises: a risk level determining module, configured to determine a risk level of the accessed web page according to the page similarity; a security risk judging module, configured to determine, according to the risk level, whether the accessed web page has a security risk; and an alert displaying module, configured to display an account security risk alert corresponding to the risk level when the accessed web page has the security risk. 13 . The system according to claim 8 , wherein the event detecting module is further configured to detect a password submission event on the accessed web page; and the system further comprises a login security risk alert module, configured to display a login security risk alert when the password submission event is detected, and when it is determined according to the page similarity that the accessed web page has the security risk. 14 . The system according to claim 8 , wherein the system further comprises: an uploading module, configured to correspondingly upload the URL of the accessed web page having the security risk, and security risk information to a server.

Assignees

Inventors

Classifications

  • Event detection, e.g. attack signature detection · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title

  • for controlling access to devices or network resources · CPC title

  • during transmission, i.e. party's identity is protected against eavesdropping, e.g. by using temporary identifiers, but is known to the other party or parties involved in the communication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016294867A1 cover?
A method for security protection of account information is provided, where the method includes: detecting an account input event on an accessed web page; determining, when the account input event is detected, whether a URL of the accessed web page exists in a preset secure URL list; calculating, if the URL of the accessed web page does not exist in the secure URL list, a page similarity between…
Who is the assignee on this patent?
Tencent Tech Shenzhen Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/1483. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 06 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).