IP Library Granted Patent US 10,999,321
Granted Patent B2
US 10,999,321 · App. 16/186,197 · Granted May 4, 2021

Processing method for preventing copy attack, and server and client

Inventor: Xiaofeng Li (Hangzhou, CN)
Assignee: Advanced New Technologies Co., Ltd.
H04L63/1475G06F12/1458G06F21/55H04L63/0428H04L63/08H04L67/42G06F2212/1052G06F2212/154
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,999,321
App. No.
16/186,197
Granted
May 4, 2021
Kind
B2
Abstract

Service data is received by a server and from a client computing device, where the service data includes a unique identifier and a variable identifier stored in a local secure storage of the client computing device. The server parses the service data to obtain the unique identifier and the variable identifier as parsed data. The server determines whether the unique identifier and the variable identifier in the parsed data are identical to a unique identifier and a variable identifier associated with the client computing device and recorded by the server as recorded data. If the result of the determination is not identical, the server indicates that the local secure storage of the client computing device is under a copy attack, and performing a predetermined response action. If the result of the determination is identical, the server transmits a new variable identifier to the client computing device.

Claims (62)

1. A computer-implemented method, comprising:

receiving, by a server and from a client computing device, service data, wherein the service data comprises a plurality of fields, wherein a first field of the plurality of fields comprises a unique identifier of the client computing device and a second field of the plurality of fields comprises a variable identifier of the client computing device, the unique identifier and the variable identifier being previously generated by the server and being stored in a local secure storage of the client computing device, and wherein the variable identifier of the client computing device is generated through successive integer accumulation and comprises a randomly generated integer comprising a plurality of digits, and wherein an asymmetric encryption or a symmetric encryption is used to exchange the unique identifier and the variable identifier between the client computing device and the server;

parsing, by the server, the service data to obtain the unique identifier and the variable identifier as parsed data;

determining, by the server, whether the unique identifier and the variable identifier in the parsed data are identical to a stored unique identifier and a stored variable identifier associated with the client computing device and recorded by the server as recorded data;

in response to determining that the unique identifier and the variable identifier in the parsed data are identical to the stored unique identifier and the stored variable identifier associated with the client computing device, generating, by the server, a new variable identifier by adding at least a digit to the stored variable identifier; and

transmitting, by the server and to the client computing device, the new variable identifier for storage.

2. The computer-implemented method of claim 1 , further comprising:

receiving, by the client computing device, the new variable identifier transmitted by the server; and

updating, by the client computing device, the local secure storage of the client computing device with the new variable identifier.

3. The computer-implemented method of claim 1 , further comprising:

transmitting, by the server and to the client computing device, a message that an identity authentication needs to be performed by the client computing device with respect to a user corresponding to the service data; and

after the identity authentication succeeds:

sending, to the client computing device associated with the user, a redistributed unique identifier and a redistributed variable identifier.

4. The computer-implemented method of claim 1 , further comprising:

when the local secure storage of the client computing device is initialized, storing, by the client computing device and as the service data, the unique identifier and the variable identifier that are transmitted by the server and received by the client computing device; and

transmitting, by the client computing device, the service data to the server.

5. The computer-implemented method of claim 1 , further comprising:

performing, by the client computing device, an identity authentication based on a message, received from the server, that an identity authentication needs to be performed by the client computing device with respect to a user corresponding to the service data; and

after the identity authentication succeeds:

initializing, by the client computing device, the local secure storage based on a redistributed unique identifier and a redistributed variable identifier transmitted to the client computing device by the server.

6. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, by a server and from a client computing device, service data, wherein the service data comprises a plurality of fields, wherein a first field of the plurality of fields comprises a unique identifier of the client computing device and a second field of the plurality of fields comprises a variable identifier of the client computing device, the unique identifier and the variable identifier being previously generated by the server and being stored in a local secure storage of the client computing device, and wherein the variable identifier of the client computing device is generated through successive integer accumulation and comprises a randomly generated integer comprising a plurality of digits, and wherein an asymmetric encryption or a symmetric encryption is used to exchange the unique identifier and the variable identifier between the client computing device and the server;

parsing, by the server, the service data to obtain the unique identifier and the variable identifier as parsed data;

determining, by the server, whether the unique identifier and the variable identifier in the parsed data are identical to a stored unique identifier and a stored variable identifier associated with the client computing device and recorded by the server as recorded data;

in response to determining that the unique identifier and the variable identifier in the parsed data are identical to the stored unique identifier and the stored variable identifier associated with the client computing device, generating, by the server, a new variable identifier by adding at least a digit to the stored variable identifier; and

transmitting, by the server and to the client computing device, the new variable identifier for storage.

7. The non-transitory, computer-readable medium of claim 6 , further comprising:

receiving, by the client computing device, the new variable identifier transmitted by the server; and

updating, by the client computing device, the local secure storage of the client computing device with the new variable identifier.

8. The non-transitory, computer-readable medium of claim 6 , further comprising:

transmitting, by the server and to the client computing device, a message that an identity authentication needs to be performed by the client computing device with respect to a user corresponding to the service data; and

after the identity authentication succeeds:

sending, to the client computing device associated with the user, a redistributed unique identifier and a redistributed variable identifier.

9. The non-transitory, computer-readable medium of claim 6 , further comprising:

when the local secure storage of the client computing device is initialized, storing, by the client computing device and as the service data, the unique identifier and the variable identifier that are transmitted by the server and received by the client computing device; and

transmitting, by the client computing device, the service data to the server.

10. The non-transitory, computer-readable medium of claim 6 , further comprising:

performing, by the client computing device, an identity authentication based on a message, received from the server, that an identity authentication needs to be performed by the client computing device with respect to a user corresponding to the service data; and

after the identity authentication succeeds:

initializing, by the client computing device, the local secure storage based on a redistributed unique identifier and a redistributed variable identifier transmitted to the client computing device by the server.

11. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

receiving, by a server and from a client computing device, service data, wherein the service data comprises a plurality of fields, wherein a first field of the plurality of fields comprises a unique identifier of the client computing device and a second field of the plurality of fields comprises a variable identifier of the client computing device, the unique identifier and the variable identifier being previously generated by the server and being stored in a local secure storage of the client computing device, and wherein the variable identifier of the client computing device is generated through successive integer accumulation and comprises a randomly generated integer comprising a plurality of digits, and wherein an asymmetric encryption or a symmetric encryption is used to exchange the unique identifier and the variable identifier between the client computing device and the server;

parsing, by the server, the service data to obtain the unique identifier and the variable identifier as parsed data;

determining, by the server, whether the unique identifier and the variable identifier in the parsed data are identical to a stored unique identifier and a stored variable identifier associated with the client computing device and recorded by the server as recorded data;

in response to determining that the unique identifier and the variable identifier in the parsed data are identical to the stored unique identifier and the stored variable identifier associated with the client computing device, generating, by the server, a new variable identifier by adding at least a digit to the stored variable identifier; and

transmitting, by the server and to the client computing device, the new variable identifier for storage.

12. The computer-implemented system of claim 11 , further comprising:

receiving, by the client computing device, the new variable identifier transmitted by the server; and

updating, by the client computing device, the local secure storage of the client computing device with the new variable identifier.

13. The computer-implemented system of claim 11 , further comprising:

transmitting, by the server and to the client computing device, a message that an identity authentication needs to be performed by the client computing device with respect to a user corresponding to the service data; and

after the identity authentication succeeds:

sending, to the client computing device associated with the user, a redistributed unique identifier and a redistributed variable identifier.

14. The computer-implemented system of claim 11 , further comprising:

when the local secure storage of the client computing device is initialized, storing, by the client computing device and as the service data, the unique identifier and the variable identifier that are transmitted by the server and received by the client computing device; and

transmitting, by the client computing device, the service data to the server.

15. The computer-implemented system of claim 11 , further comprising:

performing, by the client computing device, an identity authentication based on a message, received from the server, that an identity authentication needs to be performed by the client computing device with respect to a user corresponding to the service data; and

after the identity authentication succeeds:

initializing, by the client computing device, the local secure storage based on a redistributed unique identifier and a redistributed variable identifier transmitted to the client computing device by the server.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053754/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053743/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2019
From: LI, XIAOFENG
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 050454/0253 →