WO2012121497A2 - Système et procédé d'authentification sur la base d'un identifiant distinct - Google Patents

Système et procédé d'authentification sur la base d'un identifiant distinct Download PDF

Info

Publication number
WO2012121497A2
WO2012121497A2 PCT/KR2012/001246 KR2012001246W WO2012121497A2 WO 2012121497 A2 WO2012121497 A2 WO 2012121497A2 KR 2012001246 W KR2012001246 W KR 2012001246W WO 2012121497 A2 WO2012121497 A2 WO 2012121497A2
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
unique identifier
computer device
mobile communication
communication terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2012/001246
Other languages
English (en)
Korean (ko)
Other versions
WO2012121497A3 (fr
Inventor
정영석
한형덕
황재연
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inca Internet Co Ltd
Original Assignee
Inca Internet Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from KR1020110019204A external-priority patent/KR101206854B1/ko
Application filed by Inca Internet Co Ltd filed Critical Inca Internet Co Ltd
Publication of WO2012121497A2 publication Critical patent/WO2012121497A2/fr
Publication of WO2012121497A3 publication Critical patent/WO2012121497A3/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/068Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys

Definitions

  • the present invention relates to an authentication system and method, and more particularly, a unique identifier-based authentication that compares a unique identifier of a primary authenticated computer device with a unique identifier of a computer device that attempts secondary authentication to perform user authentication.
  • System and method a unique identifier-based authentication that compares a unique identifier of a primary authenticated computer device with a unique identifier of a computer device that attempts secondary authentication to perform user authentication.
  • the most commonly used user authentication method is an authentication method using a user ID and password.
  • the user ID and password are registered, and when the user later tries to access the system, Enter the registered user ID and password to verify the identity of the user.
  • the authentication method using the ID and password is easy to steal or hack authentication information (user ID and password), there is a problem that can not block malicious access attempts when the authentication information is exposed.
  • This one-time authentication key-based authentication method usually proceeds with the following procedure.
  • the online service system performs a first authentication procedure (for example, checking a user ID and a password), and after the first authentication, requests the second authentication to the second authentication server.
  • the secondary authentication server sends a text message (SMS) including a one-time authentication key to the user's mobile communication terminal.
  • SMS text message
  • the online service system receives the one-time authentication key through the user's computer device and delivers it to the secondary authentication server.
  • the secondary authentication server verifies whether the one-time authentication key sent to the user's mobile communication terminal and the one-time authentication key input through the online service system are the same.
  • the one-time authentication key-based secondary authentication method can strengthen the security strength of the user authentication to some extent, there are still vulnerabilities due to the following long-range hacking or short-range hacking.
  • a remote hacking technique when a user sends a one-time authentication key to an online service system, the hacker intercepts the one-time authentication key through network spoofing, or the hacker installs a key logger on the user's computer device in advance and remotely sets the user's computer.
  • the authentication key may be extorted by monitoring and removing the one-time authentication key input to the device, or inducing a user to access a phishing site rather than an online service system and extorting the one-time authentication key input to the phishing site. For example, in July 2006, a US bank infiltrated a bank account with an authentication key stolen through a phishing site, a remote hacking technique.
  • a one-time authentication key transmitted to a user's mobile communication terminal may be identified and stolen through a technique such as shoulder surfing or social engineering near the user.
  • An object of the present invention which is designed to solve the problems of the prior art described above, is to remotely hack a user by comparing the unique identifier of the computer device for which primary authentication has been completed with the unique identifier of the computer device that attempts secondary authentication. It is to provide a unique identifier-based authentication system and method that can resist single-use authentication key exploitation through a technique or a near-field hacking technique.
  • the device registration unit for registering the end entity information necessary for the second authentication and the mobile communication terminal matching the end entity information;
  • a second authentication attempt for communicating with an online service system and attempting to perform second authentication with the terminal entity information with the unique identifier of the primary authentication computer device with the end entity information from the unique identifier of the computer device with the second authentication attempt computer device
  • a transmission / reception processing unit for receiving a one-time authentication key input;
  • a unique identifier verification unit for verifying whether the first authenticated computer device and the second authentication attempt computer device are identical by using the unique identifier of the first authenticated computer device and the unique identifier of the second authentication attempt computer device;
  • An authentication key issuing unit for issuing a one-time authentication key to the mobile communication terminal and transmitting it through the transmission / reception processing unit;
  • an authentication key verification unit for verifying whether the one-time authentication key issued by the authentication key issuing unit and the one-time authentication key input to the transmission / reception processing unit are the same
  • the unique identifier-based authentication method includes a device registration step of registering the terminal entity information necessary for secondary authentication and the mobile communication terminal matching the terminal entity information in the secondary authentication system;
  • the secondary authentication system issuing an authentication key issuing a one-time authentication key to the mobile communication terminal Wow;
  • the second authentication system communicates with the online service system to receive a unique identifier of the second authentication attempt computer device that attempts second authentication with the end entity information and a one-time authentication key input from the second authentication attempt computer device.
  • Second authentication attempt step The secondary authentication system verifies whether the primary authenticated computer device and the secondary authentication attempt computer device are the same by using a unique identifier of the first authenticated computer device and a unique identifier of the second authentication attempt computer device. Verifying a unique identifier;
  • the second authentication system includes an authentication key verification step of verifying whether the one-time authentication key issued in the authentication key issuing step and the one-time authentication key input in the second authentication attempt step are the same.
  • the mobile communication terminal comprises a first step of installing a security authentication module; A second step of connecting, by the mobile communication terminal to the secondary authentication system, terminal entity information required for the second authentication and system information of the mobile communication terminal; A third step of the mobile communication terminal accessing a push server to transmit a certificate of the security authentication module and unique information of the mobile communication terminal and request issuance of a device token; Transmitting, by the mobile communication terminal, the issued device token to the secondary authentication system when the device token is issued from the push server;
  • the mobile communication terminal is characterized in that it comprises a fifth step of receiving a one-time authentication key from the secondary authentication system by communicating with the secondary authentication system and outputs on the screen.
  • the unique identifier-based authentication method if the terminal entity information for the primary authentication is input from the user, the computer device comprises a first step of generating a unique identifier of the computer device; A second step of the computer device transmitting a unique identifier of the computer device generated in the first step and end entity information for the first authentication to an online service system; A third step of generating, by the computer device, a unique identifier of the computer device when a one-time authentication key for second authentication is input from a user; And the fourth step of the computer device transmitting the unique identifier of the computer device generated in the third step and the one-time authentication key for the second authentication to the online service system.
  • the user authentication is performed only when the unique identifier of the computer device in which the primary authentication is completed and the unique identifier of the computer device attempting the second authentication is the same, authentication security is further enhanced.
  • FIG. 1 is a schematic block diagram of a unique identifier based authentication system according to the present invention.
  • FIG. 2 is a detailed block diagram of a unique identifier based authentication system according to the present invention.
  • FIG. 3 is an operation flowchart illustrating an operation of a mobile communication terminal according to an embodiment of the present invention.
  • FIG. 4 is a flowchart illustrating an operation of collecting a unique identifier of the computer device by the security authentication module of the computer device according to the present invention.
  • FIG 5 is an operation flowchart showing the operation of the secondary authentication system according to the present invention.
  • FIG. 6 is an operation flowchart illustrating a process of renewing and issuing a one-time authentication key to an end entity by the secondary authentication system according to the present invention.
  • terminal entity 111 computer device
  • transmission and reception processing unit 142 encryption and decryption processing unit
  • the online service system provides online services to users who have passed both primary authentication based on ID and password and secondary authentication based on one-time authentication key. Is also evolving.
  • hacking target computer devices computer devices
  • hacking computer device the nearby computer device
  • a normal user first authenticates by entering an ID and password into an online service system using a hacking target computer device where a hacking program is installed, and receives a one-time authentication key from his mobile communication terminal, and attempts second authentication
  • the hacker can steal information entered during all this process through the hacking computer device.
  • the normal user completes the first authentication by entering the ID and password into the hacked computer device
  • the hacker completes the first authentication by entering the corresponding ID and password into the hacking computer device (duplicate login using the ID and password is performed. If the normal user inputs the one-time authentication key for the second authentication into the hacking target computer device, the hacker also steals the one-time authentication key and inputs it to the hacking computer device.
  • the one-time authentication key input by the normal user through the hacking target computer device is blocked in the process of being delivered to the online service system, and instead, the one-time authentication key input by the hacker through the hacking computer device is transmitted to the online service system.
  • the hacking target computer device which is being used by the normal user cannot be connected to the online service system, and the hacker computer device being used by the hacker is connected to the online service system. That is, the first authentication is performed at the hacking computer device, but the second authentication is performed at the hacking computer device and the hacking computer device is connected to the online service system.
  • the present invention proposes a method of performing stronger identity authentication in such a situation.
  • FIG. 1 is a schematic block diagram of a unique identifier based authentication system according to the present invention.
  • the end entity 110 is an end user using the authentication procedure through this invention.
  • the end entity 110 uses the authentication procedure according to the present invention to receive the online service from the online service system 120 through the communication network 100.
  • the terminal entity 110 is provided with an on-line service of the on-line service system 120 and a computer device 111 for performing first and second authentication according to the present invention through communication with the on-line service system 120; And a mobile communication terminal 112 for performing secondary authentication.
  • the computer device 111 includes various computer environments such as a desktop and a notebook.
  • the computer device 111 includes a security authentication module according to the present invention.
  • the security authentication module extracts unique identifiers of the corresponding computer device 111 during a first authentication process and a second authentication process. To the online service system 120.
  • the mobile communication terminal 112 includes a smartphone equipped with a general feature phone or an operating system (OS) and capable of installing and driving various applications (applications).
  • OS operating system
  • applications applications
  • the online service system 120 is a system on the web that provides an online service to a plurality of users through the communication network 100.
  • the online service system 120 performs primary authentication on the end entity 110.
  • the online service system 120 includes a login processing system 121, and performs the first authentication of the end entity 110 in the login processing system 121.
  • Primary authentication includes all forms of single factor authentication, such as knowledge-based authentication, ownership-based authentication, and entity-based authentication.
  • the online service system 120 transmits a unique identifier of the primary authorized computer device 111 to the secondary authentication system 140 and requests secondary authentication for the primary authenticated end entity.
  • the online service system 120 transmits the one-time authentication key inputted for the second authentication from the computer device 111 and the unique identifier of the computer device 111 to the second authentication system 140.
  • the second authentication system 140 When the second authentication system 140 requests a second authentication from the online service system 120 for any computer device on which the first authentication has been performed, the second authentication system 140 receives a unique identifier of the first authorized computer device and receives the first authentication. Issue a one-time authentication key to the mobile communication terminal 112 of the terminated entity.
  • the secondary authentication system 140 receives a unique identifier of the computer device through which the one-time authentication key and the one-time authentication key are input (second authentication attempt) through the online service system 120.
  • the second authentication system 140 verifies whether the first authenticated computer device and the second authentication attempt computer device are the same by using the unique identifier of the first authenticated computer device and the unique identifier of the second authentication attempt computer device, and terminates.
  • the one-time authentication key issued to the mobile communication terminal 112 of the entity 110 and the one-time authentication key input through the one-time authentication key input computer device are verified, and the verification result is notified to the online service system.
  • the secondary authentication system 140 issues a one-time authentication key to the corresponding mobile communication terminal through an SMS server. .
  • the secondary authentication system 140 issues a one-time authentication key to the corresponding mobile communication terminal using the push server 130. Since the secondary authentication system 140 issues a one-time authentication key to the mobile communication terminal through the SM server, a detailed description thereof will be omitted. In this specification, the secondary authentication system 140 will be described in detail for the process of issuing a one-time authentication key to the mobile communication terminal using a push server.
  • Push (PUSH) server is a service provided by the manufacturer of the mobile terminal of the terminal entity, when the mobile terminal wants to receive a push service for any application, first issue a device token corresponding to the application from the push server Receive. Then, the push server wakes up the mobile communication terminal by sending a push message to the mobile communication terminal (wakeup), and serves to activate the application (security authentication module of the mobile communication terminal of the present invention) corresponding to the token device.
  • PSH Push
  • the secondary authentication system 140 attempts to issue a one-time authentication key to the mobile communication terminal 111 of the terminal entity 110, the device token of the mobile communication terminal 111 of the secondary authentication system 140 is determined.
  • Push (PUSH) server 130 and then push (PUSH) server 130 outputs a push message to the mobile communication terminal 111, the mobile communication terminal 111 wakes up and the secondary authentication system 140 and Communicate.
  • iOS uses Apple Push Notification Service (APNs) provided by Apple as a push server
  • Android uses C2DM (Cloud To Device Messaging) provided by Google as a push server.
  • APIs Apple Push Notification Service
  • C2DM Cloud To Device Messaging
  • the security authentication module installed in the computer device extracts a unique identifier for each computer device.
  • the unique identifier is generated based on the Universally Unique Identifier (UUID) or the Globally Unique Identifier (GUD) designated as a standard by the Open Software Foundation (OSF), thereby uniquely identifying the computer device.
  • UUID Universally Unique Identifier
  • GUID Globally Unique Identifier
  • OSF Open Software Foundation
  • FIG. 2 is a detailed block diagram of a unique identifier based authentication system according to the present invention.
  • the computer device 111 of the terminal entity 110 includes an input / output unit 111A, a transceiver unit 111B, and a security authentication module 111C.
  • the input / output unit 111A is a typical keyboard, mouse, monitor, or the like, and performs an interface with a user.
  • the transceiver 111B is connected to the online service system 120 through a wired communication network.
  • the security authentication module 111C is a software installed and operated in the computer device 111, and encrypts the unique identifier collecting unit for collecting the unique identifier of the computer device and the collected unique identifier and outputs it through the transmitting and receiving unit 111B. It includes a processing unit.
  • the unique identifier collection unit generates a unique identifier of the computer device based on a universally unique identifier (UUID) or a globally unique identifier (GUID) designated as a standard by the Open Software Foundation (OSF). do.
  • UUID universally unique identifier
  • the mobile communication terminal 112 of the terminal entity 110 includes an input / output unit 112A, a transceiver unit 112B, and a security authentication module 112C.
  • the input / output unit 112A is a conventional touch pad or the like and performs an interface with a user.
  • the transceiver 112B communicates with the secondary authentication system 140 and the push server 130 according to the present invention through a mobile communication network.
  • the security authentication module 112C receives a device token corresponding to the security authentication module 112C from the push server 130, registers the issued device token in the secondary authentication system 140, and push server 130. If a one-time authentication key is received from the secondary authentication system 140 after the push message is delivered from the second message, the received one-time authentication key is output on the screen of the input / output unit 112A.
  • the online service system 120 stores the information necessary for the first authentication of the end entity 110, and the second authentication to the second authentication system 140 for the end entity 110 for which the first authentication is completed. Request and receive the result from the secondary authentication system 140. That is, the online service system 120 first authenticates the end entity 110, receives the one-time authentication key for the second authentication from the end entity 110, and delivers the one-time authentication key to the second authentication system 140. In addition, the online service system 120 transmits the unique identifier of the primary authenticated computer device of the end entity and the unique identifier of the secondary authentication attempt computer device to the secondary authentication system 140.
  • the secondary authentication system 140 encrypts or decrypts data transmitted and received with the transmission and reception processing unit 141 for data transmission and reception between the end entity 110 and the online service system 120 and the push server 130.
  • the transmission and reception processing unit 141 is a wired processing unit for communicating with the online service system 120 and the push server 130 and the SMS server (not shown) through a wired communication network, and a mobile communication terminal 110 through a wireless communication network. It includes a wireless processing unit for communicating with).
  • the device registration unit 143 includes a device registration processing unit for processing device registration for each mobile communication terminal, and a device number issuer for issuing a number for the registered mobile communication terminal.
  • the one-time authentication processing unit 144 stores a unique identifier of the computer device that has been firstly authenticated in a memory unit and a unique identifier verification unit that verifies the unique identifier of the computer device that attempts the second authentication, and an authentication key for generating a one-time authentication key.
  • a generation unit, an authentication key issuing unit for issuing the one-time authentication key to a mobile communication terminal matched to the terminal entity that has been firstly authenticated, and a one-time authentication key input to the second authentication attempt computer device are received through an online service system.
  • an authentication key verification unit for comparing and verifying the issued one-time authentication key and the input one-time authentication key.
  • the authentication key generation unit may generate a one-time authentication key based on the unique identifier of the computer device that has been firstly authenticated.
  • the one-time authentication key is generated in the authentication key generation unit, is activated in the authentication key issuing unit, is verified in the authentication key verification unit, and is destroyed when the second authentication is requested for the first authenticated end entity.
  • a new one-time authentication key is repeatedly issued.
  • a malicious hacker may intervene in the security certification procedure of the legitimate end entity and prevent the legitimate end entity from passing the second authentication.
  • the present invention in principle allows the one-time authentication processing unit 144 to proceed sequentially until the one-time authentication key generation, activation, and extinction, so that the one-time authentication key is not repeatedly issued for the same end entity.
  • the one-time-issued one that is issued when the same is compared with the terminal entity computer device that requested the initial one-time authentication key and the terminal entity computer device that requested the renewal of the authentication key. You can discard the authentication key and generate and activate a new one-time authentication key.
  • FIG. 3 is an operation flowchart illustrating an operation of a mobile communication terminal according to an embodiment of the present invention.
  • the security authentication module 112C of the mobile communication terminal 112 is an application program (application) that is manufactured based on an operating system mounted on the mobile communication terminal 112 and performs an authentication procedure according to the present invention.
  • 3 is a procedure required for a mobile communication terminal to receive a device token from a push server and receive a one-time authentication key using the device token.
  • the security authentication module 112C is installed in the mobile communication terminal of the end entity (S301).
  • the security authentication module 112C transmits the end entity information (user ID for accessing the online service system, system information of the mobile communication terminal, etc.) to perform the authentication to the secondary authentication system, whereby the secondary authentication system transmits the mobile communication.
  • the terminal entity information is collected through the terminal (S302).
  • the secondary authentication system checks the collected terminal entity information, performs real name authentication and identity authentication for the mobile communication terminal itself, and transmits the result to the mobile communication terminal, real name authentication and identity from the secondary authentication system. If an authentication failure result is received (S303), it is recognized as a device registration failure and ends (S304).
  • the security authentication module of the mobile communication terminal is connected to the push server certificate and the unique information of the mobile communication terminal Requests to issue the device token while transmitting to the push server (S305).
  • the security authentication module of the mobile communication terminal delivers the issued device token to the secondary authentication system (S307).
  • the secondary authentication system then registers the device token of the mobile communication terminal in the database along with the corresponding end entity information.
  • the security authentication module of the mobile communication terminal is activated to communicate with the secondary authentication system (S309).
  • the one-time authentication key is received from the secondary authentication system (S310)
  • the one-time authentication key is output on the screen of the input / output unit (S311).
  • the security authentication module of the computer device according to the present invention is an application program installed and driven in a computer device connected to an online service system.
  • UUIDs Universally Unique Identifiers
  • GUIDs Globally Unique Identifiers
  • OSF Open Software Foundation
  • the purpose of the universally unique identifier is to uniquely identify each computer device in a distributed system.
  • a universally unique identifier created for identification of an entity (computer device) is rarely the same as a universally unique identifier created for identification of another entity (computer device).
  • UUID-based unique identifier is almost impossible because the UUID of the first authorized computer device and the UUID of the hacker computer device attempting the second authentication are almost the same. Can be.
  • this UUID is applied and used according to the objective of this invention.
  • the component of the unique identifier of the computer device used in the present invention may be a timestamp providing a one-time unique identifier of the unique identifier, information of a service file providing an identification of an online service system, and a corresponding information of the computer device. It consists of unique information.
  • the unique information of the computer device includes a UUID and may additionally include unique information of the system hardware of the computer device.
  • the unique identifier collection unit When a unique identifier collection request occurs in the security authentication module of the end entity computer device, the unique identifier collection unit generates a time stamp based on Universal Time Clock (UTC) (S401), and a service file provided by the online service system. Collect the information (S402).
  • the service file information includes file information generated and processed, such as a message digest of the file, in addition to the basic file information.
  • the unique information of the terminal entity computer device is collected (S403).
  • the collected unique information of the computer device may be reprocessed according to whether the end entity agrees to provide the information. If the end entity agrees to deliver the collected unique information of the computer device to the secondary authentication system (S404), the timestamp calculated in step S401, the service file information of the online service system collected in step S402, and step S403.
  • the unique information of the terminal entity computer device collected in (S405) and generates a unique identifier (S405), and encrypts the generated unique identifier with a symmetric key encryption algorithm (S406).
  • the encryption key of the symmetric key encryption algorithm is shared with the secondary authentication system through various key sharing algorithms, and the encrypted unique identifier is transmitted to the secondary authentication system via the online service system (S407).
  • step 404 if the end entity does not want to provide the secondary authentication system with the unique information of the collected computer device, a hash value (HASH) value, which is a one-way encryption algorithm, is calculated from the unique information of the computer device collected in step S403. (S408), the collected unique information of the computer device is coped with the calculated hash value, and the information is provided to step S405 (S409).
  • HASH hash value
  • FIG 5 is an operation flowchart showing the operation of the secondary authentication system according to the present invention.
  • the online service system When the end entity computer device accesses the online service system, the online service system performs primary authentication on the end entity computer device. At this time, the computer device transmits the terminal entity information necessary for authentication and the unique identifier of the computer device generated through FIG. 4 to the online service system. If the primary authentication is successful, the online service system sends the secondary entity information and the unique identifier of the primary authorized computer device to the secondary authentication system and requests the secondary authentication.
  • the secondary authentication system inputs the terminal actual information and the unique identifier of the primary authenticated computer device from the online service system.
  • S501 When the secondary authentication is requested (S501), whether the mobile communication terminal corresponding to the received terminal entity information is registered. Check (S502). If the mobile communication terminal is registered (S503), a one-time authentication key is generated (S504), and the generated one-time authentication key is issued to the mobile communication terminal (S505).
  • the one-time authentication key of step S504 can be generated based on the unique identifier of the primary authenticated computer device, and other factors such as time / random number besides the primary authenticated unique identifier in order to lower the probability of overlapping the disposable authentication key. Can be generated based on more.
  • the generated one-time authentication key may be issued to the mobile communication terminal in the form of a text message containing the one-time authentication key through the SMS server in step S505, and the secondary authentication with the mobile communication terminal activated by the push server
  • the system may be issued to the corresponding mobile communication terminal through server / client communication.
  • the secondary authentication system transmits a message to the push server in communication with the device token of the corresponding mobile communication terminal and the mobile communication terminal. Then, the push server grasps the mobile communication terminal to deliver the push message from the device token received from the second authentication system, and delivers the push message to the mobile communication terminal to activate the mobile communication terminal and the security authentication module of the mobile communication terminal. Let's do it.
  • the activated security authentication module performs server / client communication with the secondary authentication system, and the secondary authentication system issues a one-time authentication key to the security authentication module.
  • the generated one-time authentication key is transmitted to the mobile communication terminal of the party end entity through the communication network and output to the screen.
  • the unique identifier of the second authentication attempt computer device is collected (S506).
  • step S506 the one-time authentication key input to the second authentication attempt computer and the unique identifier of the second authentication attempt computer device are transferred to the second authentication system via the online service system (S507).
  • the secondary authentication system compares the one-time authentication key issued in step S505 with the one-time authentication key received in step S507 (S508) and performs authentication on the one-time authentication key.
  • the second authentication attempt computer device compares the unique identifier of the first authorized computer device with the unique identifier of the second authentication attempt computer device (S509). Verify that it is the same as the primary certified computer device. If the two computer devices are the same (S509), the process is processed as an authentication approval (S510), and the result is transmitted to the online service system (S511).
  • step S503 if the mobile communication terminal is not registered in step S503 is processed by the unregistered mobile communication terminal (S512), and notifies the online service system that the unregistered mobile communication terminal (S511).
  • the one-time authentication key issued in step S508 and the received one-time authentication key do not match or the two computer devices do not match in step S509, authentication failure is processed (S513) and the result is notified to the online service system (S511). ).
  • FIG. 6 is an operation flowchart illustrating a process of renewing and issuing a one-time authentication key to an end entity by the secondary authentication system according to the present invention.
  • the end entity may need to renew the one-time authentication key issued during the second authentication. For example, if the one-time authentication key issued by the secondary authentication system is lost due to the failure of the communication network without being delivered to the mobile communication terminal, or the one-time authentication key issued due to the physical defect of the computer device to attempt the second authentication. If it cannot be entered, the one-time authentication key should be updated to another value.
  • the secondary authentication system determines whether the end entity that requested the issuance of a one-time authentication key renewal is a legitimate end entity or an end entity having a malicious purpose involved in the security authentication procedure. It is necessary to determine whether or not. Therefore, the secondary authentication system receives the unique request of the renewal request computer device together with the renewal request of the one-time authentication key via the online service system, and verifies whether the initial request computer device and the renewal request computer device of the one-time authentication key are the same. do. This will be described in detail.
  • the secondary authentication system receives the terminal entity information, the one-time authentication key update request, and the unique identifier from the update request computer device (S601). It is checked whether a one-time authentication key issued in the mobile communication terminal matching the received end entity information exists (S602). If there is a one-time authentication key issued by the mobile communication terminal (S603), the unique key of the authentication key issuing computer device issued the one-time authentication key is compared with the unique identifier of the update request computer device, and the authentication key issuing computer It is verified whether the device and the update request computer are the same (S604).
  • the one-time authentication key is renewed and reissued to the mobile communication terminal matched with the corresponding end entity information (S605), and waits until the corresponding one-time reissued authentication key is received from the online service system ( S606). If the one-time authentication key issued in step S603 does not exist or the two computer devices are not the same in step S604, it is determined that the one-time authentication key update failed and the log is collected (S607).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

L'invention concerne un système d'authentification sur la base d'un identifiant distinct comprenant : une unité d'enregistrement de dispositif qui permet d'enregistrer les informations sur l'entité finale requises pour la seconde authentification et un terminal de communication mobile apparié avec les informations sur l'entité finale ; une unité de traitement de transmission et de réception qui communique avec un système de service en ligne pour recevoir un identifiant distinct d'un dispositif informatique de première authentification avec les informations sur l'entité finale, un identifiant distinct d'un dispositif informatique de tentative de seconde authentification qui essaie une seconde authentification avec les informations sur l'entité finale, et une clé d'authentification jetable entrée par le dispositif informatique de tentative de seconde authentification ; une unité de vérification d'identifiant distinct qui vérifie si oui ou non le dispositif informatique de première authentification et le dispositif informatique de tentative de seconde authentification sont identiques au moyen de l'identifiant distinct du dispositif informatique de première authentification et de l'identifiant distinct du dispositif informatique de tentative de seconde authentification ; une unité d'émission de clé d'authentification qui émet et transmet une clé d'authentification jetable au terminal de communication mobile au moyen de l'unité de traitement de transmission et de réception ; et une unité de vérification de clé d'authentification qui vérifie si oui ou non la clé d'authentification jetable émise par l'unité d'émission de clé d'authentification et la clé d'authentification jetable entrée dans l'unité de traitement de transmission et de réception sont identiques.
PCT/KR2012/001246 2011-03-04 2012-02-20 Système et procédé d'authentification sur la base d'un identifiant distinct Ceased WO2012121497A2 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR10-2011-0019204 2011-03-04
KR1020110019204A KR101206854B1 (ko) 2011-01-19 2011-03-04 고유식별자 기반 인증시스템 및 방법

Publications (2)

Publication Number Publication Date
WO2012121497A2 true WO2012121497A2 (fr) 2012-09-13
WO2012121497A3 WO2012121497A3 (fr) 2012-12-20

Family

ID=46798863

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2012/001246 Ceased WO2012121497A2 (fr) 2011-03-04 2012-02-20 Système et procédé d'authentification sur la base d'un identifiant distinct

Country Status (1)

Country Link
WO (1) WO2012121497A2 (fr)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014171797A1 (fr) * 2013-04-18 2014-10-23 주식회사 페이스콘 Procédé de sécurité de fichier et appareil associé
KR20190118829A (ko) * 2018-04-11 2019-10-21 주식회사 수퍼블리 간편 로그인 서비스 방법과 시스템 및 이를 위한 장치

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100372683B1 (ko) * 2000-03-07 2003-02-17 주식회사 모비젠 개인 휴대단말기를 이용한 사용자 인증 처리 시스템 및 그방법
KR20050094303A (ko) * 2004-03-22 2005-09-27 삼성전자주식회사 암호 인증을 처리하는 장치 및 그 방법
KR100861675B1 (ko) * 2007-06-12 2008-10-06 어드밴텍테크놀로지스(주) 인터넷 금융거래를 위한 일회용 인증번호 처리 시스템

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014171797A1 (fr) * 2013-04-18 2014-10-23 주식회사 페이스콘 Procédé de sécurité de fichier et appareil associé
US10541980B2 (en) 2013-04-18 2020-01-21 Facecon Co., Ltd. File security method and apparatus for same
US11463419B2 (en) 2013-04-18 2022-10-04 Facecon Co., Ltd. File security method and apparatus for same
KR20190118829A (ko) * 2018-04-11 2019-10-21 주식회사 수퍼블리 간편 로그인 서비스 방법과 시스템 및 이를 위한 장치
KR102105110B1 (ko) 2018-04-11 2020-04-27 주식회사 수퍼블리 간편 로그인 서비스 방법과 시스템 및 이를 위한 장치

Also Published As

Publication number Publication date
WO2012121497A3 (fr) 2012-12-20

Similar Documents

Publication Publication Date Title
EP2332089B1 (fr) Autorisation d'opérations de serveur
KR102202547B1 (ko) 액세스 요청을 검증하기 위한 방법 및 시스템
US20090158033A1 (en) Method and apparatus for performing secure communication using one time password
JP2016063533A (ja) 電子取引用のネットワーク認証方法
JP2017507549A (ja) ブルートゥースインタフェースを備える認証装置
WO2013176491A1 (fr) Procédé d'authentification d'utilisateur de service web
US11424915B2 (en) Terminal registration system and terminal registration method with reduced number of communication operations
WO2018021708A1 (fr) Procédé et système d'authentification de service basée sur une clé publique
WO2015069018A1 (fr) Système d'ouverture de session sécurisée et procédé et appareil pour celui-ci
KR101206854B1 (ko) 고유식별자 기반 인증시스템 및 방법
US12107956B2 (en) Information processing device, information processing method, and non-transitory computer readable storage medium
KR101856530B1 (ko) 사용자 인지 기반 암호화 프로토콜을 제공하는 암호화 시스템 및 이를 이용하는 온라인 결제 처리 방법, 보안 장치 및 거래 승인 서버
WO2013073780A1 (fr) Procédé et serveur pour fournir une fonction de connexion automatique
WO2012128478A2 (fr) Système et procédé d'authentification sur base d'une image
JP5665592B2 (ja) サーバ装置並びにコンピュータシステムとそのログイン方法
CN114885326A (zh) 一种银行移动作业安全防护方法、装置和存储介质
WO2012121497A2 (fr) Système et procédé d'authentification sur la base d'un identifiant distinct
CN115146284A (zh) 数据处理方法、装置、电子设备和存储介质
KR101619928B1 (ko) 이동단말기의 원격제어시스템
CN115460017B (zh) 一种基于区块链的数字身份权限验证系统
JP5937545B2 (ja) 携帯端末、サーバ装置、情報端末、および共用端末管理システム
CN111709538B (zh) 用于认证飞行器的地面维护设备的系统和方法
WO2012115403A2 (fr) Système et procédé d'authentification basée sur des informations de localisation
WO2022060156A1 (fr) Procédé, appareil et programme de mise à jour d'un micrologiciel d'authentificateur
KR101368772B1 (ko) 키 입력 보호 방법과 이를 위한 키 보호 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12755270

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12755270

Country of ref document: EP

Kind code of ref document: A2