KR101706173B1 - 모바일 애플리케이션을 보안하기 위한 방법 및 장치 - Google Patents
모바일 애플리케이션을 보안하기 위한 방법 및 장치 Download PDFInfo
- Publication number
- KR101706173B1 KR101706173B1 KR1020167020999A KR20167020999A KR101706173B1 KR 101706173 B1 KR101706173 B1 KR 101706173B1 KR 1020167020999 A KR1020167020999 A KR 1020167020999A KR 20167020999 A KR20167020999 A KR 20167020999A KR 101706173 B1 KR101706173 B1 KR 101706173B1
- Authority
- KR
- South Korea
- Prior art keywords
- nfc
- dynamic
- authentication device
- user
- computer
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
- H04L63/0838—Network architectures or network communication protocols for network security for authentication of entities using passwords using one-time-passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
- H04L63/0846—Network architectures or network communication protocols for network security for authentication of entities using passwords using time-dependent-passwords, e.g. periodically changing passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0853—Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/068—Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H04W4/008—
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/80—Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Telephone Function (AREA)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US201361922215P | 2013-12-31 | 2013-12-31 | |
| US61/922,215 | 2013-12-31 | ||
| PCT/US2014/072102 WO2015103031A1 (en) | 2013-12-31 | 2014-12-23 | A method and apparatus for securing a mobile application |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| KR20160128997A KR20160128997A (ko) | 2016-11-08 |
| KR101706173B1 true KR101706173B1 (ko) | 2017-02-27 |
Family
ID=52350373
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR1020167020999A Active KR101706173B1 (ko) | 2013-12-31 | 2014-12-23 | 모바일 애플리케이션을 보안하기 위한 방법 및 장치 |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US9510192B2 (enExample) |
| EP (1) | EP3090521B1 (enExample) |
| JP (2) | JP6556145B2 (enExample) |
| KR (1) | KR101706173B1 (enExample) |
| CN (1) | CN106233689B (enExample) |
| WO (1) | WO2015103031A1 (enExample) |
Families Citing this family (32)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9954578B2 (en) * | 2011-09-08 | 2018-04-24 | Yubico Inc. | Devices and methods for identification, authentication and signing purposes |
| GB2516686B (en) * | 2013-07-30 | 2018-02-07 | Paxton Access Ltd | Communication method and system |
| EP3090521B1 (en) * | 2013-12-31 | 2020-04-01 | OneSpan International GmbH | A method and apparatus for securing a mobile application |
| US11328797B2 (en) * | 2014-11-19 | 2022-05-10 | Imprivata, Inc. | Location-based healthcare collaboration, data management and access control |
| US20160261588A1 (en) * | 2015-03-04 | 2016-09-08 | Tapcentive, Inc. | Secure nfc token supporting escalating authentication of nfc exchanges |
| KR200478493Y1 (ko) * | 2015-04-09 | 2015-10-14 | (주)예원조경건설 | 스마트 안내표지판 |
| US9998181B1 (en) * | 2015-04-09 | 2018-06-12 | Cellotape, Inc. | Method, system and apparatus for selectively accessing content at a device |
| EP3380976B1 (en) * | 2015-09-21 | 2020-11-18 | OneSpan International GmbH | A multi-user strong authentication token |
| US10817593B1 (en) * | 2015-12-29 | 2020-10-27 | Wells Fargo Bank, N.A. | User information gathering and distribution system |
| CN109075965B (zh) * | 2015-12-30 | 2022-02-15 | 万思伴国际有限公司 | 使用口令码验证的前向安全密码技术的方法、系统和装置 |
| SG10201600192TA (en) * | 2016-01-11 | 2017-08-30 | Mastercard Asia Pacific Pte Ltd | A Method For Dynamic Authentication Of An Object |
| FR3049414A1 (fr) * | 2016-03-25 | 2017-09-29 | Orange | Enregistrement de service dans un reseau local |
| CN105915541A (zh) * | 2016-06-07 | 2016-08-31 | 惠州Tcl移动通信有限公司 | 基于nfc的移动终端密码保存与恢复处理方法及系统 |
| US20230360023A1 (en) * | 2016-06-15 | 2023-11-09 | Capital One Services, Llc | Techniques to process contactless card functions in a multiple banking system environment |
| KR102526959B1 (ko) * | 2016-10-27 | 2023-05-02 | 삼성전자주식회사 | 전자 장치 및 그의 동작 방법 |
| JP2019067348A (ja) * | 2017-10-02 | 2019-04-25 | 聡子 荻原 | ワンタイムパスワード自動送信機 |
| EP3502998A1 (en) * | 2017-12-19 | 2019-06-26 | Mastercard International Incorporated | Access security system and method |
| CN108810836B (zh) | 2018-06-12 | 2020-06-16 | 飞天诚信科技股份有限公司 | 一种向用户提供近场通信设备信息的方法及系统 |
| EP3582166A1 (en) * | 2018-06-15 | 2019-12-18 | Thales Dis France SA | Method and system to create a trusted record or message and usage for a secure activation or strong customer authentication |
| EP3671498B1 (fr) * | 2018-12-20 | 2023-08-09 | EM Microelectronic-Marin SA | Procede d'authentification securisee d'un transpondeur en communication avec un serveur |
| DE102019108049A1 (de) * | 2019-03-28 | 2020-10-01 | Pilz Gmbh & Co. Kg | Zugriffssteuerungssystem zur Steuerung eines Zugriffs eines Nutzers auf eine oder mehrere Betriebsfunktionen einer technischen Anlage |
| US11521213B2 (en) * | 2019-07-18 | 2022-12-06 | Capital One Services, Llc | Continuous authentication for digital services based on contactless card positioning |
| US11455617B2 (en) * | 2019-10-04 | 2022-09-27 | Visa International Service Association | Type 4 NFC tags as protocol interface |
| US11432149B1 (en) | 2019-10-10 | 2022-08-30 | Wells Fargo Bank, N.A. | Self-sovereign identification via digital credentials for selected identity attributes |
| US10733283B1 (en) * | 2019-12-23 | 2020-08-04 | Capital One Services, Llc | Secure password generation and management using NFC and contactless smart cards |
| JP7669029B2 (ja) * | 2021-04-12 | 2025-04-28 | 株式会社アクアビットスパイラルズ | アクション制御システム、アクション制御サーバ及びアクション制御方法 |
| SE544638C2 (en) * | 2021-06-07 | 2022-10-04 | Total Security Stockholm Ab | System and method for taking an access control decision based on a virtual key |
| CN115695064A (zh) * | 2021-07-28 | 2023-02-03 | 佛山市顺德区美的电子科技有限公司 | 一种家电设备配网方法、配网装置和家电设备 |
| CN115278630A (zh) * | 2022-07-29 | 2022-11-01 | 上海千随信息技术有限公司 | 基于近场通信的信息交互方法、装置、系统及存储介质 |
| US20240346130A1 (en) * | 2023-04-11 | 2024-10-17 | Capital One Services, Llc | Random password generation and update for digital service authentication |
| US20240381080A1 (en) * | 2023-05-10 | 2024-11-14 | Capital One Services, Llc | Systems and methods for secure authentication information retrieval |
| TWI875546B (zh) * | 2024-03-28 | 2025-03-01 | 奧圖碼股份有限公司 | 顯示裝置、顯示系統及解除顯示裝置鎖定狀態的方法 |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013034681A1 (en) | 2011-09-08 | 2013-03-14 | Ehrensvaerd Jakob | Devices and methods for identification, authentication and signing purposes |
Family Cites Families (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7791451B2 (en) * | 2006-10-17 | 2010-09-07 | International Business Machines Corporation | Methods, systems, and computer program products for providing mutual authentication for radio frequency identification (RFID) security |
| US8494959B2 (en) * | 2007-08-17 | 2013-07-23 | Emc Corporation | Payment card with dynamic account number |
| WO2009039419A1 (en) * | 2007-09-21 | 2009-03-26 | Wireless Dynamics, Inc. | Wireless smart card and integrated personal area network, near field communication and contactless payment system |
| WO2009077664A1 (fr) * | 2007-09-27 | 2009-06-25 | Inside Contactless | Procédé et dispositif de gestion de données d'application dans un système nfc |
| WO2010043974A1 (en) | 2008-10-16 | 2010-04-22 | Christian Richard | System for secure contactless payment transactions |
| EP2369811B1 (en) * | 2008-11-04 | 2016-03-23 | SecureKey Technologies Inc. | System and methods for online authentication |
| US8412928B1 (en) * | 2010-03-31 | 2013-04-02 | Emc Corporation | One-time password authentication employing local testing of candidate passwords from one-time password server |
| US8453226B2 (en) * | 2010-07-16 | 2013-05-28 | Visa International Service Association | Token validation for advanced authorization |
| JP2012073955A (ja) * | 2010-09-29 | 2012-04-12 | Fujitsu Ltd | 送受信体及び認証システム |
| US20120167194A1 (en) * | 2010-12-22 | 2012-06-28 | Reese Kenneth W | Client hardware authenticated transactions |
| US8789146B2 (en) * | 2011-04-14 | 2014-07-22 | Yubico Inc. | Dual interface device for access control and a method therefor |
| EP2680526A1 (en) * | 2012-06-26 | 2014-01-01 | Certicom Corp. | Methods and devices for establishing trust on first use for close proximity communications |
| US9594896B2 (en) * | 2012-12-21 | 2017-03-14 | Blackberry Limited | Two factor authentication using near field communications |
| US9104853B2 (en) * | 2013-05-16 | 2015-08-11 | Symantec Corporation | Supporting proximity based security code transfer from mobile/tablet application to access device |
| EP3090521B1 (en) * | 2013-12-31 | 2020-04-01 | OneSpan International GmbH | A method and apparatus for securing a mobile application |
-
2014
- 2014-12-23 EP EP14827678.5A patent/EP3090521B1/en active Active
- 2014-12-23 US US14/580,438 patent/US9510192B2/en active Active
- 2014-12-23 WO PCT/US2014/072102 patent/WO2015103031A1/en not_active Ceased
- 2014-12-23 CN CN201480074247.6A patent/CN106233689B/zh active Active
- 2014-12-23 JP JP2016544601A patent/JP6556145B2/ja active Active
- 2014-12-23 KR KR1020167020999A patent/KR101706173B1/ko active Active
-
2018
- 2018-12-27 JP JP2018243834A patent/JP6629952B2/ja active Active
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013034681A1 (en) | 2011-09-08 | 2013-03-14 | Ehrensvaerd Jakob | Devices and methods for identification, authentication and signing purposes |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2015103031A1 (en) | 2015-07-09 |
| CN106233689B (zh) | 2019-09-20 |
| JP2019083536A (ja) | 2019-05-30 |
| JP2017503427A (ja) | 2017-01-26 |
| JP6629952B2 (ja) | 2020-01-15 |
| US9510192B2 (en) | 2016-11-29 |
| JP6556145B2 (ja) | 2019-08-07 |
| CN106233689A (zh) | 2016-12-14 |
| EP3090521A1 (en) | 2016-11-09 |
| EP3090521B1 (en) | 2020-04-01 |
| US20150189505A1 (en) | 2015-07-02 |
| KR20160128997A (ko) | 2016-11-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR101706173B1 (ko) | 모바일 애플리케이션을 보안하기 위한 방법 및 장치 | |
| CN106575416B (zh) | 用于向装置验证客户端的系统和方法 | |
| US9647840B2 (en) | Method for producing a soft token, computer program product and service computer system | |
| US11539399B2 (en) | System and method for smart card based hardware root of trust on mobile platforms using near field communications | |
| CN114746913B (zh) | 使用非接触式传统磁条数据的客户端设备认证 | |
| CN113474774A (zh) | 用于认可新验证器的系统和方法 | |
| US9495546B2 (en) | Electronic signing methods, systems, and apparatus | |
| US20140344160A1 (en) | Universal Authentication Token | |
| WO2016114841A1 (en) | A multi-user strong authentication token | |
| CN113711560A (zh) | 用于有效质询-响应验证的系统和方法 | |
| US10891599B2 (en) | Use of state objects in near field communication (NFC) transactions | |
| CN103210398B (zh) | 读取rfid令牌、rfid卡和电子设备的方法 | |
| EP3018607B1 (en) | Device and authentication system | |
| CN108322310A (zh) | 一种利用安全设备读卡登录方法及安全登录系统 | |
| CN108322440A (zh) | 一种利用安全设备读卡登录方法及安全登录系统 | |
| GB2495494A (en) | Identity verification | |
| CN108322907A (zh) | 一种开卡方法及终端 | |
| KR102854192B1 (ko) | 사용자의 신분을 증명해주기 위한 전자 장치 | |
| KR102172855B1 (ko) | 사용자의 휴대형 매체를 이용한 매체 분리 기반 서버형 일회용코드 제공 방법 | |
| KR20120080555A (ko) | 모바일 일회용코드를 이용한 거래 방법 | |
| CN108665267A (zh) | 安全认证装置及系统 | |
| KR101078953B1 (ko) | 공인 인증서 원격 폐기 중계처리 방법 및 시스템과 이를 위한 기록매체 | |
| HK40064425A (en) | System and method for efficient challenge-response authentication | |
| HK40060764A (en) | System and method for endorsing a new authenticator | |
| Kunning | Strong Authentication Protocol using PIV Card with Mobile Devices |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PA0105 | International application |
St.27 status event code: A-0-1-A10-A15-nap-PA0105 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| PG1501 | Laying open of application |
St.27 status event code: A-1-1-Q10-Q12-nap-PG1501 |
|
| A201 | Request for examination | ||
| A302 | Request for accelerated examination | ||
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| PA0201 | Request for examination |
St.27 status event code: A-1-2-D10-D11-exm-PA0201 |
|
| PA0302 | Request for accelerated examination |
St.27 status event code: A-1-2-D10-D17-exm-PA0302 St.27 status event code: A-1-2-D10-D16-exm-PA0302 |
|
| E701 | Decision to grant or registration of patent right | ||
| PE0701 | Decision of registration |
St.27 status event code: A-1-2-D10-D22-exm-PE0701 |
|
| GRNT | Written decision to grant | ||
| PR0701 | Registration of establishment |
St.27 status event code: A-2-4-F10-F11-exm-PR0701 |
|
| PR1002 | Payment of registration fee |
St.27 status event code: A-2-2-U10-U12-oth-PR1002 Fee payment year number: 1 |
|
| PG1601 | Publication of registration |
St.27 status event code: A-4-4-Q10-Q13-nap-PG1601 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-5-5-R10-R13-asn-PN2301 St.27 status event code: A-5-5-R10-R11-asn-PN2301 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| FPAY | Annual fee payment |
Payment date: 20200115 Year of fee payment: 4 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 4 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 5 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 6 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 7 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 8 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 9 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-5-5-R10-R11-asn-PN2301 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-5-5-R10-R14-asn-PN2301 |