KR20140103593A - System and method for user authentication - Google Patents
System and method for user authentication Download PDFInfo
- Publication number
- KR20140103593A KR20140103593A KR1020130017162A KR20130017162A KR20140103593A KR 20140103593 A KR20140103593 A KR 20140103593A KR 1020130017162 A KR1020130017162 A KR 1020130017162A KR 20130017162 A KR20130017162 A KR 20130017162A KR 20140103593 A KR20140103593 A KR 20140103593A
- Authority
- KR
- South Korea
- Prior art keywords
- authentication
- user
- birth
- date
- terminal number
- Prior art date
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
More particularly, the present invention relates to a user authentication system and method, and more particularly, to a method and system for authenticating a user using a user terminal, To a user authentication system that performs user authentication using the date of birth and terminal number included in the request message, and transmits an authentication response message including authentication result information to the user terminal.
Recently, as utilization of personal information has increased, management of personal information of users has become important. Such personal information is used in a wide range of fields, from simple everyday life to financial life through financial institutions. And the social security number, name, and cell phone number that help to identify the individual are often used online to provide anonymity.
For example, in order to join a web site, a name and a resident registration number are entered in order to register as a member, and a financial institution requests a resident registration number and a name for the purpose of inquiring the user's credit information online.
Therefore, if the individual's resident registration number and name are known, a problem arises that he / she can freely access important credit information for conducting economic life.
SUMMARY OF THE INVENTION The present invention has been made in order to solve the above problems, and an object of the present invention is to provide an information processing apparatus and a method for processing a user authentication by using a user's date of birth and a terminal number (mobile phone number) And can be used exclusively for user authentication.
Another object of the present invention is to provide a method and system for managing a user's personal information by comparing user information inputted by a user with subscriber information possessed by a communication service provider, And a user authentication system and method capable of preventing theft.
According to an aspect of the present invention, there is provided a communication system including a communication unit for communicating with a user terminal or a service apparatus through a communication network, an authentication request message including a user's date of birth and a terminal number from the service apparatus or the user terminal, A message processing unit for transmitting an authentication response message, an authentication processing unit for performing user authentication using the date of birth and the terminal number, and generating an authentication response message including authentication result information.
The authentication device further includes a user information database including user's terminal number and date of birth, and the authentication processor extracts a terminal number and a date of birth of the user from the user information database, It compares the date of birth with the terminal number and the date of birth included in the authentication request message and transmits an authentication completion message when they match and an authentication failure message if they do not match.
When the authentication request message is received, the authentication processing unit receives the user information of the user by transmitting a user authentication request to the communication company device associated with the user terminal, and transmits the user ID information including the date of birth and the terminal number included in the user information, It compares the included date of birth and the terminal number, and transmits an authentication completion message when they match and an authentication failure message if they do not match.
According to another aspect of the present invention, there is provided a method for transmitting an authentication request message including an authentication request message including a date of birth and a terminal number to an authentication device when a user authentication is required and receiving an authentication response message from the authentication device, And an authentication device for performing user authentication using the date of birth and the terminal number when the message is received and transmitting an authentication response message including authentication result information to the user terminal.
Wherein the user authentication system determines whether a user authentication is required for providing a requested service when receiving a service request from the user terminal, requests the user terminal to input authentication information when user authentication is required, And a service device for providing the requested service to the user terminal when the message is received.
According to another aspect of the present invention, there is provided a method of authenticating a user, the method comprising the steps of: (a) receiving an authentication request message including a user's date of birth and a terminal number; (b) And transmitting an authentication response message including the authentication result information to the user terminal.
Wherein the step (b) comprises the steps of: transmitting a user authentication request to a communication carrier apparatus associated with the user; receiving user information of the user from the communication carrier apparatus; Comparing the date of birth and the terminal number included in the authentication request message, and transmitting an authentication completion message if they match, and transmitting an authentication failure message if they do not match.
The step (b) may further include extracting a date of birth and a terminal number of the user from the provided user information database, comparing the extracted date of birth and terminal number with a date of birth and a terminal number included in the authentication request message, Transmitting an authentication completion message if there is a match, and transmitting an authentication failure message if the match is not matched.
According to another aspect of the present invention, there is provided a method for authenticating a user, comprising the steps of: (a) receiving an authentication request message including a user's date of birth and a terminal number; (b) And transmitting an authentication response message including authentication result information to the user terminal, wherein the user authentication method is recorded in a program and is readable in an electronic device.
According to another aspect of the present invention, a user terminal receives a birth date and a terminal number for user authentication when the user authentication is required for service use, receives an authentication request message including the inputted date of birth and terminal number, Comparing the date of birth and the terminal number of the user stored in the user information database or the terminal of the communication enterprise, the date of birth and the terminal number included in the authentication request message; And transmitting an authentication completion message to the user terminal if the authentication result is not identical to the user authentication result when the authentication result is identical to the user authentication result.
According to the present invention, user authentication is performed using a user's date of birth and a terminal number (mobile phone number) so that information input for user authentication is not used for other purposes but used exclusively for user authentication. Can be prevented.
Also, when the user authentication is required, the user information inputted by the user is compared with the subscriber information held by the communication company, and the user authentication is performed only when the user information matches, thereby enhancing the user authentication process have.
1 illustrates a user authentication system in accordance with an embodiment of the present invention.
2 is a block diagram schematically illustrating a configuration of a user terminal according to an embodiment of the present invention;
3 is a block diagram schematically showing a configuration of an authentication apparatus according to an embodiment of the present invention.
4 is a diagram illustrating a user authentication method by a mobile phone authentication method according to an embodiment of the present invention.
The foregoing and other objects, features, and advantages of the present invention will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which: FIG.
1 is a diagram illustrating a user authentication system according to an embodiment of the present invention.
Referring to FIG. 1, the user authentication system includes a
The
The
A detailed description of the
The
The
The
A detailed description of the
2 is a block diagram schematically illustrating a configuration of a user terminal according to an embodiment of the present invention.
Referring to FIG. 2, the
The
The input unit 120 is a means for receiving a user request for controlling the operation of the
The
The
The authentication
The authentication
3 is a block diagram schematically showing a configuration of an authentication apparatus according to an embodiment of the present invention.
3, the
The
The
Upon receiving the authentication request message, the authentication processing unit 330 controls the user authentication process based on the information of the user, finalizes the user authentication success, and then transmits the result.
When the authentication request message including the date of birth and the terminal number is received from the service device or the user terminal, the authentication processor 330 performs user authentication using the date of birth and the terminal number, and transmits an authentication response message including the authentication result information And transmits it to the
The authentication processing unit 330 may perform credit card authentication, IPIN (Internet Personal Identification Number) authentication, SMS authentication, and the like, in addition to mobile phone authentication using the date of birth and the terminal number. The authentication processing unit 330 includes a credit
The credit
The mobile
The
The
The
4 is a diagram illustrating a user authentication method using a mobile phone authentication method according to an embodiment of the present invention.
Referring to FIG. 4, a user accesses a service device that wants to provide a service through a user terminal and requests service use and service access (S402).
Upon receiving the service request from the user terminal, the service device determines whether user authentication is required to provide the requested service (S404). Here, examples of services requiring user authentication may include membership subscription service, financial transaction service, identity verification service, and the like.
If it is determined in step S404 that user authentication is required, the service device transmits an authentication information input request signal to the user terminal (S406).
An authentication method selection screen such as a credit card authentication, a mobile phone authentication, an SMS authentication, and an IPIN authentication is output to the user terminal (S408), and the user selects a desired authentication method through an authentication method selection screen (S410).
Hereinafter, a case where the mobile phone authentication method is selected will be described as an example.
When the user selects cell phone authentication, the user terminal displays a window for inputting the date of birth and the terminal number, and the user inputs his or her date of birth and terminal number (S412).
Then, the user terminal transmits an authentication request message including the entered date of birth and the terminal number to the authentication apparatus (S414).
The authentication device compares the date of birth and the terminal number included in the authentication request message with the pre-stored date of birth and the terminal number (S416), and determines whether or not they match (S418). That is, the authentication device compares the date of birth and the terminal number of the user stored in the user information database or the terminal of the communication service provider, which includes the date of birth and the terminal number included in the authentication request message, to determine whether the date of birth and the terminal number match .
If it is determined as a result of the determination in step S418, the authentication apparatus transmits the authentication completion message to the user terminal and the service apparatus (S420), and the service apparatus provides the service requested to the user terminal (S422).
If it is determined in step S418 that the date of birth and the terminal number included in the authentication request message do not coincide with each other, the authentication device transmits an authentication failure message to the user terminal and the service device (S424).
If it is determined in step S404 that user authentication is not required, the service device provides the corresponding service to the user terminal (S426).
According to another aspect of the present invention, there is provided a method for authenticating a user, comprising the steps of: (a) receiving an authentication request message including a user's date of birth and a terminal number; (b) And transmitting an authentication response message including authentication result information to the user terminal is provided as a program and a recording medium readable by an electronic apparatus.
Such a user authentication method can be written in a program, and the codes and code segments constituting the program can be easily deduced by a programmer in the field. Further, the program relating to the user authentication method may be stored in an information storage medium (Readable Media) readable by the electronic apparatus, and read and executed by the electronic apparatus.
Thus, those skilled in the art will appreciate that the present invention may be embodied in other specific forms without departing from the spirit or essential characteristics thereof. It is therefore to be understood that the embodiments described above are to be considered in all respects only as illustrative and not restrictive. The scope of the present invention is defined by the appended claims rather than the detailed description and all changes or modifications derived from the meaning and scope of the claims and their equivalents are to be construed as being included within the scope of the present invention do.
According to the present invention, when a user authentication is required, user authentication is performed only when the date of birth, the terminal number (mobile phone number) input by the user is compared with the subscriber information possessed by the communication service provider, The user authentication system and method can prevent the personal information from being stolen.
100:
120: input unit 130: output unit
140: storage unit 150: authentication request processing unit
200: service device 300: authentication device
320: message processing unit 330: authentication processing unit
340: User information DB
Claims (10)
A message processing unit for receiving an authentication request message including a user's date of birth and a terminal number from the service device or a user terminal and transmitting an authentication response message; And
An authentication processing unit for performing user authentication using the date of birth and the terminal number, and generating an authentication response message including authentication result information;
.
User information including user's terminal number and date of birth further includes a user information database,
The authentication processing unit extracts the terminal number and the date of birth of the user from the user information database, compares the extracted terminal number and the date of birth with the terminal number and the date of birth included in the authentication request message, And transmits an authentication failure message if it does not match.
When the authentication request message is received, the authentication processing unit receives the user information of the user by transmitting a user authentication request to the communication company device associated with the user terminal, and transmits the user ID information including the date of birth and the terminal number included in the user information, Comparing the included date of birth and the terminal number, and transmitting an authentication completion message when they match, and transmitting an authentication failure message if they do not match.
An authentication device that performs user authentication using the date of birth and the terminal number when the authentication request message is received from the user terminal and transmits an authentication response message including the authentication result information to the user terminal;
And a user authentication system.
The method includes determining whether a user authentication is required for providing a requested service when receiving a service request from the user terminal, requesting the user terminal to input authentication information when user authentication is required, And a service device for providing the requested service to the user terminal.
(a) receiving an authentication request message including a user's date of birth and a terminal number; And
(b) performing user authentication using the date of birth and terminal number, and transmitting an authentication response message including authentication result information to the user terminal;
And a user authentication method.
The step (b)
Sending a user authentication request to a carrier device associated with the user;
Receiving user information of the user from the communication service provider; And
Comparing the date of birth and the terminal number included in the user information with the date of birth and the terminal number included in the authentication request message and transmitting an authentication completion message if they match and transmitting an authentication failure message if they do not match; And a user authentication method.
The step (b)
Extracting the user's date of birth and terminal number from the provided user information database; And
Comparing the extracted date of birth and terminal number with the terminal number included in the authentication request message and transmitting an authentication completion message when they match and transmitting an authentication failure message if they do not match; User authentication method.
(a) receiving an authentication request message including a user's date of birth and a terminal number; And
(b) performing user authentication using the date of birth and the terminal number, and transmitting an authentication response message including authentication result information to the user terminal, wherein the user authentication method is recorded as a program, Possible recording medium.
Comparing the birth date and the terminal number included in the authentication request message with the user information database or the date of birth and the terminal number of the user stored in the communication company apparatus; And
The authentication device transmits an authentication completion message to the user terminal if the comparison result indicates that the date of birth and the terminal number match, and transmits an authentication failure message to the user terminal if the authentication result message does not match.
And a user authentication method.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020130017162A KR20140103593A (en) | 2013-02-18 | 2013-02-18 | System and method for user authentication |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020130017162A KR20140103593A (en) | 2013-02-18 | 2013-02-18 | System and method for user authentication |
Publications (1)
Publication Number | Publication Date |
---|---|
KR20140103593A true KR20140103593A (en) | 2014-08-27 |
Family
ID=51747829
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020130017162A KR20140103593A (en) | 2013-02-18 | 2013-02-18 | System and method for user authentication |
Country Status (1)
Country | Link |
---|---|
KR (1) | KR20140103593A (en) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101853350B1 (en) * | 2017-11-29 | 2018-04-30 | 한국과학기술정보연구원 | Method and apparatus for the world wide federated authentication |
KR102281580B1 (en) * | 2020-03-11 | 2021-07-26 | 오상영 | Authentication system and method of performing authentication in authentication system |
-
2013
- 2013-02-18 KR KR1020130017162A patent/KR20140103593A/en not_active Application Discontinuation
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101853350B1 (en) * | 2017-11-29 | 2018-04-30 | 한국과학기술정보연구원 | Method and apparatus for the world wide federated authentication |
KR102281580B1 (en) * | 2020-03-11 | 2021-07-26 | 오상영 | Authentication system and method of performing authentication in authentication system |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US9730065B1 (en) | Credential management | |
US10911455B2 (en) | Using third party information to improve predictive strength for authentications | |
CN111833507B (en) | Visitor authentication method, device, equipment and computer readable storage medium | |
US20140082748A1 (en) | User information management apparatus and user information management method | |
KR20140127987A (en) | System and method for public terminal security | |
US20190347441A1 (en) | Patient privacy de-identification in firewall switches forming VLAN segregation | |
CN112365258A (en) | Binding method and device of electronic money account and electronic equipment | |
KR101957186B1 (en) | An aggregator system having a platform for engaging mobile device users | |
KR101489259B1 (en) | System and method for providing user authentication service | |
JP2008276422A (en) | Credit card settlement system | |
KR20140103593A (en) | System and method for user authentication | |
JP7492545B2 (en) | Information processing device, information processing method, and information processing program | |
US8731195B2 (en) | Method and system for initiating secure transactions within a defined geographic region | |
KR102470713B1 (en) | Method and apparatus for providing certificate distribution service based on block chain decentralized identitifier | |
KR101103634B1 (en) | Method for attestating credit card company server and that server | |
KR20190119233A (en) | Member management service system using big data analysistem | |
CA3156390A1 (en) | Systems and methods for providing in-person status to a user device | |
KR101498380B1 (en) | Apparatus and method for managment authentication process | |
CN115917537A (en) | System and method for data access control to personal user data using short-range transceivers | |
JP2022178679A (en) | Terminal device, information processing method and information processing program | |
JP7525539B2 (en) | Information processing device, information processing method, and information processing program | |
JP7568673B2 (en) | Information processing device, information processing method, and information processing program | |
JP7490008B2 (en) | Information processing device, information processing method, and information processing program | |
KR102211064B1 (en) | Systems and methods for providing services for identifying foreigners' identity | |
JP7525534B2 (en) | Information processing device, information processing method, and information processing program |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A201 | Request for examination | ||
E902 | Notification of reason for refusal | ||
E601 | Decision to refuse application |