Sensitive operation verification method, terminal device, server, and verification system

US9703971B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9703971-B2
Application numberUS-201314443541-A
CountryUS
Kind codeB2
Filing dateNov 4, 2013
Priority dateNov 16, 2012
Publication dateJul 11, 2017
Grant dateJul 11, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure discloses a sensitive operation verification method, a terminal device, a server, and a verification system. The method includes: scanning, by a first terminal device, a two-dimensional code for initiating a sensitive operation, and obtaining information in the two-dimensional code, the information in the two-dimensional code being at least used to uniquely determine the sensitive operation; and sending, by the first terminal device, a first verification request to a verification server, the first verification request carrying verification information of the first terminal device and the information in the two-dimensional code.

First claim

Opening claim text (preview).

What is claimed is: 1. A sensitive operation verification method, comprising: sending, by a second terminal device, a sensitive operation request to a sensitive operation server, wherein the sensitive operation request at least carrying carries verification scenario information referring to information that indicates a source website of the sensitive operation and content of the sensitive operation, so that the sensitive operation server separately sends a second verification request to a two-dimensional code server and a verification server, the second verification request carrying the verification scenario information, so that the verification server sends a verification code to the two-dimensional code server, and then the two-dimensional code server generates a two-dimensional code according to the verification scenario information and the verification code; wherein after the sending, by a second terminal device, a sensitive operation request to a sensitive operation server, and receiving, by the second terminal device, a verification result returned by the verification server, and displaying a processing result of the sensitive operation on the first terminal device and/or the second terminal device according to the verification result. 2. The method according to claim 1 , wherein the sensitive operation request further carries organization information and service identification information. 3. The method according to claim 1 , wherein the information in the two-dimensional code comprises at least one of the following items: organization information, service identification information, verification scenario information, and two-dimensional code identification information. 4. The method according to claim 1 , wherein the information in the two-dimensional code comprises a URL link relevant or irrelevant to verification of the sensitive operation. 5. A sensitive operation verification method, comprising: receiving, by a sensitive operation server, a sensitive operation request sent by a second terminal device wherein, the sensitive operation request at least carrying carries verification scenario information referring to information that indicates a source website of the sensitive operation and content of the sensitive operation: and separately sending, by the sensitive operation server, a second verification request to a two-dimensional code server and a verification server, the second verification request carrying the verification scenario information, so that the verification server sends a verification code to the two-dimensional code server, and then the two-dimensional code server generates a two-dimensional code according to the verification scenario information and the verification code; wherein after the sending, by a second terminal device, a sensitive operation request to a sensitive operation server, and receiving, by the second terminal device, a verification result returned by the verification server, and displaying a processing result of the sensitive operation on the first terminal device and/or the second terminal device according to the verification result. 6. The method according to claim 5 , wherein the sensitive operation request further carries organization information and/or service identification information. 7. A sensitive operation verification method, comprising: receiving, by a verification server, a second verification request sent by a sensitive operation server, wherein the second verification request carrying verification scenario information referring to information that indicates a source website of the sensitive operation and content of the sensitive operation: sending, by the verification server, a verification code to the two-dimensional code server, so that the two-dimensional code server generates a two-dimensional code according to the verification scenario information and the verification code, information in the two-dimensional code being at least used to uniquely determine a sensitive operation; and performing, by the verification server after receiving a first verification request that is sent by a first terminal device and carries verification information of the first terminal device and the information in the two-dimensional code, verification according to the verification information of the first terminal device to determine whether the verification information of the first terminal device is bound with registered user identity information; and in response to determining that the verification information is bound with registered user identity information, allowing, the sensitive operation that is determined by the information in the two-dimensional code and corresponding to the registered user identity information and that is protected by the registered user information to proceed without a login operation of a user identified by the registered user identity information; wherein after the performing, by the verification server, verification according to the verification information of the first terminal device, and separately sending a verification result to the first terminal device and/or a second terminal device that initiates the sensitive operation, so that the first terminal device and the second terminal device that initiates the sensitive operation display a processing result of the sensitive operation according to the verification result. 8. The method according to claim 7 , wherein before the receiving, by a verification server, a second verification request sent by a sensitive operation server, the method further comprises: registering the user identity information and the verification information of the first terminal device, and determining a binding relationship between the user identity information and the verification information. 9. The method according to claim 7 , wherein the information in the two-dimensional code comprises at least one of the following items: organization information, service identification information, verification scenario information, and two-dimensional code identification information. 10. The method according to claim 9 , wherein the information in the two-dimensional code further comprises a URL link relevant or irrelevant to verification of the sensitive operation.

Assignees

Inventors

Classifications

  • Restricted operating environment · CPC title

  • by remotely controlling device operation · CPC title

  • One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key · CPC title

  • Physics · mapped topic

  • Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9703971B2 cover?
The present disclosure discloses a sensitive operation verification method, a terminal device, a server, and a verification system. The method includes: scanning, by a first terminal device, a two-dimensional code for initiating a sensitive operation, and obtaining information in the two-dimensional code, the information in the two-dimensional code being at least used to uniquely determine the …
Who is the assignee on this patent?
Tencent Tech Shenzhen Co Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/62. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 11 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).