TWI648979B - Authentication method and system thereof - Google Patents
Authentication method and system thereof Download PDFInfo
- Publication number
- TWI648979B TWI648979B TW106126016A TW106126016A TWI648979B TW I648979 B TWI648979 B TW I648979B TW 106126016 A TW106126016 A TW 106126016A TW 106126016 A TW106126016 A TW 106126016A TW I648979 B TWI648979 B TW I648979B
- Authority
- TW
- Taiwan
- Prior art keywords
- authentication
- voice
- traffic
- authentication system
- time password
- Prior art date
Links
Landscapes
- Telephonic Communication Services (AREA)
Abstract
本發明提供一種認證方法及其系統。前述認證方法應用於認證系統,並包含下列步驟:首先,認證系統依據話號資訊並透過話務鏈路傳送具有一次性密碼的認證語音至外部話務裝置。接著,認證系統連接外部之認證裝置,以觸發認證裝置取得並上傳話務裝置所播放的認證語音。再者,認證系統對上傳之認證語音進行認證,並於通過認證碼後提供圖像化一次性密。本發明透過話務鏈路傳送具有一次性密碼的認證語音至話務裝置,並再經由認證裝置取得認證語音以及執行認證作業,得以有效的提升認證之安全性。 The present invention provides an authentication method and system thereof. The foregoing authentication method is applied to the authentication system and includes the following steps: First, the authentication system transmits the authentication voice having the one-time password to the external traffic device according to the message information and through the traffic link. Next, the authentication system is connected to an external authentication device to trigger the authentication device to acquire and upload the authentication voice played by the traffic device. Furthermore, the authentication system authenticates the uploaded authentication voice and provides an imaged one-time secret after passing the authentication code. The invention transmits the authentication voice with the one-time password to the traffic device through the traffic link, and then obtains the authentication voice and performs the authentication operation through the authentication device, thereby effectively improving the security of the authentication.
Description
本發明係一種認證方法及其系統,尤指一種透過認證語音來提昇認證安全性之認證方法及其系統。 The present invention relates to an authentication method and system thereof, and more particularly to an authentication method and system for improving authentication security by authenticating voice.
隨著網路技術快速的發展,許多的重要訊息傳送,或商業交易、金融服務…等商業活動多仰賴網路來提供服務,而為提高網路交易之安全性,使得用戶身份以及用戶裝置之認證作業日益重要。 With the rapid development of network technology, many important information transmission, or commercial transactions, financial services, etc., rely on the Internet to provide services, and to improve the security of online transactions, the user identity and user devices Certification operations are increasingly important.
現行網路服務端在收到用戶端的認證要求時,大多透過電子信箱或簡訊將用於認證的一次性密碼傳送給用戶端裝置。然而,當用戶端裝置被植入木馬等惡意軟體時,惡意第三方則能透過惡意軟體輕易的從用戶端裝置取得認證碼,而嚴重的影響網路服務之安全性。 When the current network server receives the authentication request from the client, most of the one-time password for authentication is transmitted to the client device through an electronic mail box or a short message. However, when the client device is implanted with a malicious software such as a Trojan, the malicious third party can easily obtain the authentication code from the client device through the malicious software, and seriously affects the security of the network service.
綜上所述,如何提供一種可解決前述問題之方案乃本領域亟需解決之技術問題。 In summary, how to provide a solution to the aforementioned problems is a technical problem that needs to be solved in the field.
為解決前揭之問題,本發明之目的係提供一種可有效提認證安全性之認證方案。 In order to solve the problems disclosed above, an object of the present invention is to provide an authentication scheme that can effectively improve authentication security.
為達上述目的,本發明提出一種認證方法。前述方法應用於認證系統,並包含下列步驟:首先,認證系統依據一話號資訊,並透過話 務鏈路傳送具有一次性密碼的認證語音至外部話務裝置。接著,認證系統連接外部之認證裝置,以觸發認證裝置取得並上傳話務裝置所播放的認證語音。再者,認證系統對上傳之認證語音進行認證,並於通過認證後提供圖像化一次性密碼。 To achieve the above object, the present invention proposes an authentication method. The foregoing method is applied to an authentication system and includes the following steps: First, the authentication system is based on a message number and The service link transmits the authenticated voice with a one-time password to the external traffic device. Next, the authentication system is connected to an external authentication device to trigger the authentication device to acquire and upload the authentication voice played by the traffic device. Furthermore, the authentication system authenticates the uploaded authentication voice and provides an imaged one-time password after passing the authentication.
為達上述目的,本發明提出一種認證系統。前述認證系統包含音訊密碼伺服器、認證網站伺服器、以及處理模組。前述音訊密碼伺服器經由話務鏈路連線外部之話務裝置。前述認證網站伺服器經由網路連線外部之認證裝置。前述處理模組連接音訊密碼伺服器以及認證網站伺服器,並經由音訊密碼伺服器傳送具有一次性密碼的認證語音至話務裝置,並經由認證網站伺服器觸發認證裝置取得並上傳話務裝置所播放的認證語音,並對上傳之認證語音進行認證,並於通過認證後提供圖像化一次性密碼。 To achieve the above object, the present invention proposes an authentication system. The aforementioned authentication system includes an audio cryptographic server, an authentication website server, and a processing module. The aforementioned audio cryptographic server is connected to an external traffic device via a traffic link. The aforementioned authentication website server connects the external authentication device via the network. The processing module is connected to the audio cryptographic server and the authentication website server, and transmits the authentication voice to the traffic device with the one-time password via the audio cryptographic server, and the authentication device is triggered by the authentication website server to acquire and upload the traffic device. The authenticated voice played, and the uploaded authentication voice is authenticated, and an imaged one-time password is provided after passing the authentication.
綜上所述,本發明之認證方法及其系統透過話務鏈路傳送具有一次性密碼的認證語音至話務裝置,並再經由認證裝置取得認證語音,而當認證語音通過驗證後再發送一次性密碼,得以有效的提升認證程序之安全。 In summary, the authentication method and system thereof of the present invention transmit an authentication voice with a one-time password to a traffic device through a traffic link, and then obtain an authentication voice through the authentication device, and then send the authentication voice once it passes the verification. Sex passwords can effectively improve the security of the certification process.
1‧‧‧認證系統 1‧‧‧Certificate system
11‧‧‧音訊密碼伺服器 11‧‧‧Optical password server
12‧‧‧認證網站伺服器 12‧‧‧Certified Website Server
13‧‧‧處理模組 13‧‧‧Processing module
2‧‧‧話務裝置 2‧‧‧Attendance device
3‧‧‧認證裝置 3‧‧‧Authorized device
4‧‧‧話務鏈路 4‧‧‧Traffic link
5‧‧‧網路鏈路 5‧‧‧Network link
圖1為本發明第一實施例認證方法之流程圖。 1 is a flow chart of an authentication method according to a first embodiment of the present invention.
圖2為本發明第二實施例認證系統之系統方塊圖。 2 is a system block diagram of an authentication system according to a second embodiment of the present invention.
以下將描述具體之實施例以說明本發明之實施態樣,惟其並非用以限制本發明所欲保護之範疇。 The specific embodiments are described below to illustrate the embodiments of the invention, but are not intended to limit the scope of the invention.
請參閱圖1,其為本發明第一實施例認證方法之流程圖。前述認證方法應用於認證系統,包含下列步驟: Please refer to FIG. 1, which is a flowchart of an authentication method according to a first embodiment of the present invention. The aforementioned authentication method is applied to the authentication system and includes the following steps:
S101:認證系統依據一話號資訊,並透過話務鏈路傳送具有一次性密碼(one time password,OPT)的認證語音至外部話務裝置。 S101: The authentication system transmits the authentication voice with one time password (OPT) to the external traffic device according to the one-voice information and transmits the one-time password (OPT) through the traffic link.
S102:認證系統連接外部之認證裝置,以觸發認證裝置取得並上傳話務裝置所播放的認證語音。 S102: The authentication system is connected to an external authentication device to trigger the authentication device to acquire and upload the authentication voice played by the traffic device.
S103:認證系統對上傳之認證語音進行認證,並於通過認證後提供圖像化一次性密碼。 S103: The authentication system authenticates the uploaded authentication voice, and provides an imaged one-time password after passing the authentication.
於另一實施例中,前述方法之認證系統或認證裝置係對認證語音之視覺化圖像以進行認證。 In another embodiment, the authentication system or authentication device of the aforementioned method authenticates the visualized image of the voice for authentication.
於另一實施例中,前述方法之視覺化圖像係為認證語音之訊號波形。於另一實施例中,前述方法之訊號波形進一步包含時域波形或頻域圖形。 In another embodiment, the visual image of the foregoing method is a signal waveform of the authentication voice. In another embodiment, the signal waveform of the foregoing method further includes a time domain waveform or a frequency domain pattern.
於另一實施例中,前述方法之認證系統係致能認證裝置之麥克風單元,以取得認證語音。 In another embodiment, the authentication system of the foregoing method enables the microphone unit of the authentication device to obtain the authentication voice.
請參閱圖2,其為本發明第二實施例認證系統1之系統方塊圖。前述認證系統1包含音訊密碼伺服器11、認證網站伺服器12、以及處理模組13。前述音訊密碼伺服器11經由話務鏈路4連線外部之話務裝置2。前述認證網站伺服器12經由網路連線外部之認證裝置3。前述處理模組13連接 音訊密碼伺服器11以及認證網站伺服器12,並經由音訊密碼伺服器11傳送具有一次性密碼的認證語音至話務裝置2,並經由認證網站伺服器12觸發認證裝置3取得並上傳話務裝置2所播放的認證語音,並對上傳之認證語音進行認證,並於通過認證後提供圖像化一次性密碼。 Please refer to FIG. 2, which is a system block diagram of an authentication system 1 according to a second embodiment of the present invention. The authentication system 1 includes an audio cryptographic server 11, an authentication website server 12, and a processing module 13. The aforementioned audio cryptographic server 11 is connected to the external traffic device 2 via the traffic link 4. The aforementioned authentication website server 12 connects the external authentication device 3 via the network. The foregoing processing module 13 is connected The audio cryptographic server 11 and the authentication website server 12 transmit the authentication voice with the one-time password to the traffic device 2 via the audio cryptographic server 11, and trigger the authentication device 3 to acquire and upload the traffic device via the authentication website server 12. 2 The authenticated voice played, and authenticates the uploaded authentication voice, and provides an imaged one-time password after passing the authentication.
於另一實施例中,前述認證系統1係對認證語音之視覺化圖像以進行認證。 In another embodiment, the aforementioned authentication system 1 authenticates the visualized image of the voice.
於另一實施例中,前述認證系統1之視覺化圖像係為認證語音之訊號波形。於另一實施例中,前述認證系統1訊號波形進一步包含時域波形或頻域圖形。 In another embodiment, the visualized image of the authentication system 1 is a signal waveform of the authentication voice. In another embodiment, the aforementioned authentication system 1 signal waveform further includes a time domain waveform or a frequency domain graphic.
於另一實施例中,前述認證系統1係致能認證裝置3之麥克風單元,以取得認證語音。 In another embodiment, the aforementioned authentication system 1 enables the microphone unit of the authentication device 3 to obtain the authentication voice.
以下本發明茲以第二實施例認證系統1進行範例說明,惟第一實施例認證方法亦具有相同或相似之技術功效。以小額付款之應用情境為例,話務裝置2為用戶端所持有的電話裝置(例如:智慧型手機),而認證裝置3為用戶端持有的可連網裝置,例如:電腦、虛擬實境裝置(VR)…等。當用戶端利用話務裝置2進行認證系統1,並輸入話號、證號並經由認證系統1之後端確認該用戶身份後,認證系統1會將認證語音傳至用戶語音密碼伺服器,前述的認證語音可隱藏OTP訊息,用戶不會直接聽到OTP碼(用戶聽到一般歡迎訊息,但OTP碼的聲頻隱藏於其中,需經接收端分解音頻、轉換後才可識別)。接著,用戶語音密碼伺服器透過話務鏈路4(例如:市話鏈路、行動通訊話務鏈路…等)將認證語音傳送到話務裝置2,此時用戶端將話務裝置2的揚聲器朝向認證裝置3的麥克風單元,並讓話務裝置2播放認證語 音,而認證裝置3經由麥克風單元取得認證語音後,會經由網路鏈路5(例如:行動網路鏈路、固網鏈路…等)將認證語音傳送至認證系統1的認證網站伺服器12,而當認證網站伺服器12完成驗證後,將會傳送圖像化一次性密碼至該認證裝置3,以讓用戶端取得此圖像化一次性密碼。 The following description of the present invention is exemplified by the authentication system 1 of the second embodiment, but the authentication method of the first embodiment also has the same or similar technical effects. Taking the application scenario of the micropayment as an example, the traffic device 2 is a telephone device (for example, a smart phone) held by the client, and the authentication device 3 is a networkable device held by the client, for example, a computer or a virtual device. Reality device (VR)...etc. When the client uses the traffic device 2 to perform the authentication system 1, and inputs the voice number, the license number, and confirms the identity of the user via the back end of the authentication system 1, the authentication system 1 transmits the authentication voice to the user voice password server, the foregoing The authentication voice can hide the OTP message, and the user does not directly hear the OTP code (the user hears the general welcome message, but the audio of the OTP code is hidden in it, and the audio is converted by the receiving end and can be recognized after being converted). Then, the user voice cryptographic server transmits the authentication voice to the traffic device 2 through the traffic link 4 (for example, a local telephone link, a mobile communication link, etc.), at which time the user terminal will use the traffic device 2 The speaker faces the microphone unit of the authentication device 3, and causes the traffic device 2 to play the authentication language After the authentication device 3 obtains the authentication voice via the microphone unit, the authentication voice is transmitted to the authentication website server of the authentication system 1 via the network link 5 (for example, a mobile network link, a fixed network link, etc.). 12. When the authentication website server 12 completes the verification, an imaged one-time password will be transmitted to the authentication device 3, so that the user can obtain the imaged one-time password.
由訊號合成理論可知,透過加總訊號之基頻波形以及諧波之波形可改變訊號波形(例如:由正弦波及其諧波可合成為方波),因此音訊密碼伺服器11可在認證語音中加入特定頻率之訊號及其諧波來改變認證語音之視覺化圖形(例如:脈寬、波峰、波谷…等訊號特徵)。而認證網站伺服器12在取得認證語音後,會對其視覺化圖形進行圖形化識別,進而對此認證語音完成認證。由於話務鏈路4以及話務裝置2中話務處理單元之機密性極高,因此惡意第三方難以透過安裝木馬等惡意程式來盜取認證語音(以Android系統為例,話務處理單元位於系統核心,因此不易被植入惡意程式),因此本案之認證方法及其系統可提高傳送認證資料期間之安全性。 According to the signal synthesis theory, the signal waveform can be changed by the fundamental frequency waveform of the summed signal and the waveform of the harmonics (for example, the sine wave and its harmonics can be combined into a square wave), so the audio cryptographic server 11 can be in the authentication voice. Add a signal of a specific frequency and its harmonics to change the visual pattern of the authentication voice (for example, signal characteristics such as pulse width, peak, trough, etc.). After the authentication website server 12 obtains the authentication voice, the visualized graphics are graphically recognized, and the authentication voice is authenticated. Since the confidentiality of the traffic processing unit in the traffic link 4 and the traffic device 2 is extremely high, it is difficult for a malicious third party to steal authentication voice by installing a malicious program such as a Trojan (in the case of the Android system, the traffic processing unit is located). The core of the system is therefore not easy to be implanted with malicious programs. Therefore, the authentication method and system of the present invention can improve the security during the transmission of the authentication data.
因應各種認證需求,本發明更提供四種語音認證類型,而前述之認證方法或系統1可依需求設定認證之強度: In view of various authentication requirements, the present invention further provides four types of voice authentication, and the foregoing authentication method or system 1 can set the strength of the authentication according to requirements:
第一類型:簡易語音認證。認證系統1經由簡訊傳送一般語音檔案,認證語音之音頻可識別出OTP碼以進行認證程序。 The first type: simple voice authentication. The authentication system 1 transmits a general voice file via the short message, and the voice of the authenticated voice can recognize the OTP code for the authentication process.
第二類型:傳送無法直接聽到OTP碼之認證語音。認證系統1傳送一般語音檔案,且語音檔案中的音頻無法識別出OTP碼,需由認證裝置3(例如:VR裝置或電腦)之認證頁面接收後,進行音頻轉換正確的OTP碼,以進行認證程序。 The second type: the authentication voice that cannot directly hear the OTP code. The authentication system 1 transmits the general voice file, and the audio in the voice file cannot recognize the OTP code. After receiving the authentication page of the authentication device 3 (for example, a VR device or a computer), the audio is converted into the correct OTP code for authentication. program.
第三類型:語音檔位於系統端語音信箱。用戶之話務裝置2連接語音信箱, 且認證語音之音頻無法識別出OTP碼,需由認證裝置3(例如:VR裝置或電腦)之認證頁面接收後,經由音頻轉換出正確的OTP碼,以進行認證程序。 The third type: the voice file is located in the system side voice mailbox. The user's traffic device 2 is connected to the voice mail box. Moreover, the audio of the authenticated voice cannot recognize the OTP code, and after receiving the authentication page of the authentication device 3 (for example, a VR device or a computer), the correct OTP code is converted via audio to perform the authentication procedure.
第四類型:用戶裝置2之語音信箱具認證時限。用戶裝置2之語音信箱接收認證語音後,需在期限內(例如:1分鐘內)輸入OTP以完成認證程序。如時限內未能完成,則該次OTP作廢。並會依系統設定決是否再產生新的OTP音訊於語音信箱,進而避免駭客木馬側錄後,轉發語音檔案並盜用。 The fourth type: the voicemail of the user device 2 has a time limit for authentication. After the voicemail of the user device 2 receives the authentication voice, it is necessary to input the OTP within the deadline (for example, within 1 minute) to complete the authentication procedure. If the time limit is not completed, the OTP will be void. According to the system settings, it will decide whether to generate new OTP audio in the voice mailbox, and then avoid the hacking Trojan to record the voice file and steal it.
上列詳細說明係針對本發明之一可行實施例之具體說明,惟該實施例並非用以限制本發明之專利範圍,凡未脫離本發明技藝精神所為之等效實施或變更,均應包含於本案之專利範圍中。 The detailed description of the preferred embodiments of the present invention is intended to be limited to the scope of the invention, and is not intended to limit the scope of the invention. The patent scope of this case.
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
TW106126016A TWI648979B (en) | 2017-08-02 | 2017-08-02 | Authentication method and system thereof |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
TW106126016A TWI648979B (en) | 2017-08-02 | 2017-08-02 | Authentication method and system thereof |
Publications (2)
Publication Number | Publication Date |
---|---|
TWI648979B true TWI648979B (en) | 2019-01-21 |
TW201911804A TW201911804A (en) | 2019-03-16 |
Family
ID=65804259
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
TW106126016A TWI648979B (en) | 2017-08-02 | 2017-08-02 | Authentication method and system thereof |
Country Status (1)
Country | Link |
---|---|
TW (1) | TWI648979B (en) |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
TW200404212A (en) * | 2002-04-18 | 2004-03-16 | Microsoft Corp | Methods and systems for authentication of components in a graphics system |
US20050180408A1 (en) * | 2004-02-18 | 2005-08-18 | Nec Corporation | VoIP wireless telephone system and method utilizing wireless LAN |
TW201305935A (en) * | 2011-07-20 | 2013-02-01 | F2Ware Inc | One time password generation and application method and system using the same |
CN104270354A (en) * | 2014-09-17 | 2015-01-07 | 宁波掌聘企业管理咨询有限公司 | User account security verification method and device |
CN106993030A (en) * | 2017-03-22 | 2017-07-28 | 北京百度网讯科技有限公司 | Information-pushing method and device based on artificial intelligence |
-
2017
- 2017-08-02 TW TW106126016A patent/TWI648979B/en not_active IP Right Cessation
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
TW200404212A (en) * | 2002-04-18 | 2004-03-16 | Microsoft Corp | Methods and systems for authentication of components in a graphics system |
US20050180408A1 (en) * | 2004-02-18 | 2005-08-18 | Nec Corporation | VoIP wireless telephone system and method utilizing wireless LAN |
TW201305935A (en) * | 2011-07-20 | 2013-02-01 | F2Ware Inc | One time password generation and application method and system using the same |
CN104270354A (en) * | 2014-09-17 | 2015-01-07 | 宁波掌聘企业管理咨询有限公司 | User account security verification method and device |
CN106993030A (en) * | 2017-03-22 | 2017-07-28 | 北京百度网讯科技有限公司 | Information-pushing method and device based on artificial intelligence |
Also Published As
Publication number | Publication date |
---|---|
TW201911804A (en) | 2019-03-16 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11663578B2 (en) | Login using QR code | |
US10348715B2 (en) | Computer-implemented systems and methods of device based, internet-centric, authentication | |
TWI719190B (en) | Offline payment method and device | |
CN111556006B (en) | Third-party application system login method, device, terminal and SSO service platform | |
CN109150548B (en) | Digital certificate signing and signature checking method and system and digital certificate system | |
US9838205B2 (en) | Network authentication method for secure electronic transactions | |
WO2017197974A1 (en) | Biometric characteristic-based security authentication method, device and electronic equipment | |
WO2016155497A1 (en) | User authentication method and device, and wearable device registration method and device | |
EP2999189A1 (en) | Network authentication method for secure electronic transactions | |
JP2018532301A (en) | User authentication method and apparatus | |
JP2016521899A (en) | Two-factor authentication | |
US9124571B1 (en) | Network authentication method for secure user identity verification | |
US20200196143A1 (en) | Public key-based service authentication method and system | |
WO2015180689A1 (en) | Method and apparatus for acquiring verification information | |
CN109412812A (en) | Data safe processing system, method, apparatus and storage medium | |
WO2020102974A1 (en) | Data access method, data access apparatus, and mobile terminal | |
CN111949958B (en) | Authorization authentication method and device in Oauth protocol | |
CA3029871C (en) | Authentication server, authentication system and method | |
KR101741917B1 (en) | Apparatus and method for authenticating using speech recognition | |
JP2011003100A (en) | Authentication request conversion apparatus, authentication request conversion method, and authentication request conversion program | |
CN111949959B (en) | Authorization authentication method and device in Oauth protocol | |
WO2015109958A1 (en) | Data processing method based on negotiation key, and mobile phone | |
TWI643086B (en) | Method for binding by scanning two-dimensional barcode | |
TWI648979B (en) | Authentication method and system thereof | |
CN113904774B (en) | Block chain address authentication method and device and computer equipment |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
MM4A | Annulment or lapse of patent due to non-payment of fees |