WO2014137063A1 - 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치 - Google Patents

어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치 Download PDF

Info

Publication number
WO2014137063A1
WO2014137063A1 PCT/KR2013/012060 KR2013012060W WO2014137063A1 WO 2014137063 A1 WO2014137063 A1 WO 2014137063A1 KR 2013012060 W KR2013012060 W KR 2013012060W WO 2014137063 A1 WO2014137063 A1 WO 2014137063A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
token
reliability
service
authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2013/012060
Other languages
English (en)
French (fr)
Inventor
고경완
주재영
엄봉수
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
SK Planet Co Ltd
Original Assignee
SK Planet Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from KR1020130025077A external-priority patent/KR102139162B1/ko
Priority claimed from KR1020130030488A external-priority patent/KR20140115660A/ko
Application filed by SK Planet Co Ltd filed Critical SK Planet Co Ltd
Publication of WO2014137063A1 publication Critical patent/WO2014137063A1/ko
Priority to US14/848,255 priority Critical patent/US10135809B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0815Network architectures or network communication protocols for network security for authentication of entities providing single-sign-on or federations
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present invention relates to an authentication method using an application, a system and an apparatus therefor, and more particularly, an integrated ID can be used by obtaining a trust relationship between a plurality of applications installed in one terminal, or a plurality of installed in one terminal.
  • An authentication method using an application for performing authentication of another application by sharing authentication information using a representative application among applications, and a system and apparatus therefor.
  • user ID integration includes flexibility to accommodate various member policies (membership / scope, member verification method, etc.) for each service, operational stability, service maintainability, and future scalability. Should be considered.
  • a separate integrated authentication server can be built to Authentication can be performed through an integrated server, or single sign-on (SSO) technology to pass authentication information from a specific application or service to another service or authentication server, eliminating the need for users to log in again.
  • SSO single sign-on
  • Related technologies can be divided into methods using cookies, sessions, authentication tokens, tickets, etc., depending on how authentication information is transmitted.
  • each application in one device can recognize that each other is installed in the same device, there is a problem in obtaining a trust relationship because it cannot be connected to each other.
  • the authentication method for using content in a general application is performed by simply accessing an Internet site that provides each application, or by providing a personal information such as a subscription and an application through any procedure required by the site.
  • a method of generating a unique ID for execution of an ID and authenticating to fully use the content provided by the application is used only when the ID is accessed using the ID.
  • an object of the present invention can recognize that each application in one device is installed in the same device, but can not be connected to each other problems in obtaining a trust relationship Since it may occur, to obtain a trust relationship between a plurality of applications installed in one terminal using a reliability token, and to provide an authentication method using an application that can use an integrated ID based on the trust relationship, and provides a system and apparatus therefor. I would like to.
  • Another object of the present invention is to solve the problem of having to create a unique ID and password for each of the numerous applications, when accessing each Internet site providing an application for the conventional application authentication, and using the content
  • An object of the present invention is to provide an authentication method using an application capable of performing authentication of another application by sharing authentication information using a representative application among a plurality of applications installed in one terminal, and a system and apparatus for the same.
  • Integrated authentication apparatus for achieving the above object is a service communication unit for transmitting and receiving data for obtaining a trust relationship between a plurality of applications by communicating with at least one terminal and the service providing device, Receiving a signal requesting a reliability check between the first application and the second application according to the request, generates a reliability token for obtaining a trust relationship between the first application and the second application, and transmits the generated reliability token to the terminal
  • the device may include a reliability token verification unit for verifying the reliability token and transmitting the verification result to the service providing apparatus.
  • a token for user authentication is generated according to a login request including service identification information from a representative application installed in one or more terminals, or the token is checked when a token for user authentication is received.
  • a user authentication unit for performing user verification and a token for verifying the reliability of a service application corresponding to the service identification information based on the information authenticated through the user authentication unit and providing the token to the corresponding terminal, and a service corresponding to the service identification information When the token confirmation is requested from the service providing device for providing a, the token provided from the service providing device is verified, and further includes a reliability authentication unit for providing a verification result for the verified token to the service providing device.
  • the reliability token generator is characterized in that for generating a one-time token for obtaining a trust relationship between the first application and the second application.
  • the reliability token verification unit is characterized in confirming the reliability token received from the service providing device, and discards the confirmed reliability token.
  • the integrated authentication apparatus characterized in that it further comprises an integrated ID management unit for integrating and managing IDs between a plurality of applications.
  • the user authentication unit is characterized in that for storing the integrated ID for each user and the authentication token generated for each user.
  • the reliability authentication unit is characterized by storing a reliability token for verifying the reliability of the service application, and deletes the once verified token.
  • the terminal communicates with the integrated authentication device and the service providing device to the communication unit for transmitting and receiving data for obtaining a trust relationship between a plurality of applications and the event requesting the trust relationship between the first application and the second application Detects, requests a credential confirmation between the first application and the second application to the integrated authentication device according to an event occurrence, and when a credential token is received from the integrated authentication device, a credential token check for driving the second application to the service providing device. And a controller configured to control a request to drive a second application provided through the service providing device according to a reliability token check result and to establish a trust relationship between the first application and the second application.
  • the terminal characterized in that it further comprises a storage for storing the representative application for the integrated authentication and one or more service applications.
  • control unit executes the representative application in response to the login request from the specific service application, through the representative application to the authentication information of the user and the service identification information corresponding to the specific service application to the integrated authentication device; Request for authentication, and in response to the request to receive the authentication token and the reliability token from the integrated authentication device, the specific service application provides the service token to the specific service application so that the service providing device can verify the authentication using the reliability token It characterized in that the transmission to.
  • the representative application is characterized in that one of a plurality of service applications.
  • the controller when the representative application is in the login state, transmits the previously received authentication token and service identification information of the specific service application to the integrated authentication device to request authentication verification, and from the integrated authentication device. And control to receive only an authentication result and a trust token.
  • An authentication system using an application detects an event requesting a trust relationship acquisition between a first application and a second application, and checks the reliability between the first application and the second application with the integrated authentication device according to the occurrence of the event.
  • Request and when a reliability token is received from the integrated authentication device, request a verification token confirmation to the service providing device for driving the second application, and drive the second application provided through the service providing device according to the verification token.
  • the terminal executes the representative application in response to the login request from the specific service application, and through the representative application to provide the user authentication information and service identification information corresponding to the specific service application.
  • a request for authentication by sending to an integrated authentication device, an authentication token and a reliability token from the integrated authentication device in response to a request, and a reliability token of a specific service application so that the corresponding service providing device can verify the authentication using the reliability token. It is characterized in that for transmitting to the service providing apparatus.
  • the integrated authentication device generates an authentication token for user authentication or an authentication token for user authentication according to a login request including service identification information from a representative application installed in a terminal.
  • the user performs verification by verifying an authentication token, generates a reliability token for verifying the reliability of a service application corresponding to the service identification information based on the authenticated information, and provides the corresponding token to the corresponding terminal, and corresponds to the service identification information.
  • the token confirmation is requested from the service providing device for providing a service
  • the reliability token provided from the service providing device is verified, and the verification result for the reliability token is provided to the service providing device.
  • An authentication method using an application includes the steps of: detecting, by a terminal, an event for requesting to obtain a trust relationship between a first application and a second application; Requesting a reliability confirmation between the second applications, and when the terminal receives the reliability token from the integrated authentication device, requesting the service token providing the device to verify the reliability token for driving the second application; And driving the second application provided through the service providing apparatus and establishing a trust relationship between the first application and the second application.
  • the reliability token is a one-time token issued by the integrated authentication device to obtain a trust relationship between the first application and the second application, the request for the service providing device in the integrated authentication device. It is characterized in that it is discarded after confirmation of the token to be performed.
  • the detecting may include: detecting, by a terminal, an occurrence of an event related to obtaining reliability with a first application; Requesting to obtain a trust relationship with the second application.
  • the step of establishing the terminal establishes a trust relationship with the second application in the mobile environment through the first application that is the representative application, at least for authentication of the second application It is characterized by applying one authentication method.
  • An authentication method using an application includes the steps of receiving, by the integrated authentication device, a request for verifying reliability between a first application and a second application according to a request of at least one terminal, Generating a trust token for acquiring a trust relationship between the first application and the second application, transmitting the generated trust token to the terminal by the integrated authentication device, and requesting verification of the trust token from the service providing device by the integrated authentication device; Receiving a signal, confirming the received trust token by the integrated authentication device, and transmitting the verification result of the trust token to the service providing device by the integrated authentication device.
  • the generating step is characterized in that the integrated authentication device generates a one-time token for obtaining a trust relationship between the first application and the second application.
  • the step of verifying includes the step of the authentication unit has confirmed the trust token received from the service providing device and the integrated authentication device discards the verified trust token It is characterized by.
  • the terminal detects a login event of a specific service application, and if a login event is detected, the representative application transmits service identification information of the specific service application to the integrated authentication device. Requesting a login; and, upon request, the representative application receiving login result information including a reliability token generated in response to the service identification information from the integrated authentication device, and the representative application providing the reliability token to the specific service application. And a specific service application providing a reliability token to the service providing device to request a reliability confirmation, and executing the specific service application according to the reliability confirmation result.
  • the step of requesting the login may include checking whether the representative application is logged in, and if the representative application is not logged in, a user ID and password for logging in the representative application. And receiving the input and transmitting the input user ID and password to the integrated authentication device together with the service identification information of the specific service application, and requesting a login.
  • the login result information may further include an authentication token generated according to authentication of a user ID and a password.
  • the authentication token previously received by the representative application together with the service identification information is transmitted to the integrated authentication device to log in. It further comprises the step of requesting.
  • An authentication method using an application includes the steps of performing, by the integrated authentication device, a user authentication according to a login request including service identification information from a representative application installed in one or more terminals, and the integrated authentication device authenticated information.
  • Generating a reliability token for verifying the reliability of the service application corresponding to the service identification information transmitting the login result including the reliability token to the terminal by the integrated authentication device, and the service identification information by the integrated authentication device; Verifying the reliability token provided from the service providing apparatus when the verification token is requested from the service providing apparatus providing the service corresponding to the request; and providing the verification result of the reliability token to the service providing apparatus by the integrated authentication apparatus.
  • the integrated authentication device before performing the step, the integrated authentication device, if the representative application is logged in, receiving an authentication token previously received by the representative application from the terminal together with the service identification information; It characterized in that it further comprises.
  • the representative application is not logged in before the step of performing, together with the service identification information of the service application, a user ID and password for logging in the representative application from the terminal. It further comprises the step of receiving.
  • a computer readable recording medium having recorded thereon a program for executing a second application and establishing a trust relationship between the first and second applications is provided.
  • receiving a signal requesting a reliability check between the first application and the second application in response to a request of at least one terminal, and the trust relationship between the first application and the second application Generating a reliability token for obtaining, transmitting the generated reliability token to the terminal, receiving a signal requesting verification of the reliability token from the service providing apparatus, checking the received reliability token, and authenticity
  • a computer readable recording medium having recorded thereon a program for executing a step of transmitting a result of verifying a token to a service providing device is provided.
  • detecting a login event of a specific service application detecting a login event of a specific service application, and if a login event is detected, the representative application sends a service identification information of the specific service application to the integrated authentication device to request a login. And, upon request, the representative application receiving login result information including a reliability token generated in response to the service identification information from the integrated authentication device, and the representative application providing the reliability token to the specific service application.
  • the step of performing the user authentication according to the login request including the service identification information from the representative application installed in one or more terminals, and corresponding to the service identification information based on the authenticated information Generating a reliability token for verifying the reliability of the service application, transmitting a login result including the reliability token to the terminal, and verifying the reliability token from a service providing device that provides a service corresponding to the service identification information
  • the present invention provides a computer-readable recording medium having recorded thereon a program for executing a step of verifying a reliability token provided from a service providing device and providing a result of verification of the reliability token to the service providing device.
  • the present invention means that the account registration with reference to the representative application, through which the implementation of the SSO (Single Sing On) authentication scheme is possible in the mobile environment.
  • SSO Single Sing On
  • the representative application can be executed by reference only between applications without an internal browser, which is not limited by various operating systems.
  • SSO authentication can increase management transparency, reliability, reduce costs, and increase efficiency.
  • increase the efficiency of user ID or password management use other system without separate login, support authentication, reduce administrator's password inquiry, reduce re-entry for user login / shutdown / reconnection, and provide reporting function of user's access information. This is possible.
  • authentication information may be shared in one device through a representative application on the assumption that trust relationships between applications are established.
  • FIG. 1 is a diagram illustrating a configuration of an authentication system using an application according to an exemplary embodiment of the present invention.
  • FIG. 2 is a block diagram showing the configuration of a terminal according to the present invention.
  • FIG. 3 is a block diagram showing the configuration of the integrated authentication device according to the present invention.
  • FIG. 4 is a data flowchart illustrating a process of obtaining a trust relationship between applications according to the present invention.
  • FIG. 5 is a data flowchart illustrating an integrated authentication process using a representative application according to the present invention.
  • FIG. 6 is a data flow diagram illustrating an integrated authentication process using a representative application according to another embodiment of the present invention.
  • FIG. 7 is a flowchart illustrating a method of operating a terminal according to an exemplary embodiment of the present invention.
  • FIG. 8 is a flowchart illustrating a method of operating an integrated authentication device according to an embodiment of the present invention.
  • FIG. 9 is a flowchart illustrating a method of operating a terminal according to another embodiment of the present invention.
  • FIG. 10 is a flowchart illustrating a method of operating a terminal according to another embodiment of the present invention.
  • FIG. 11 is a flowchart illustrating a method of operating an integrated authentication device according to another embodiment of the present invention.
  • FIG. 12 is a flowchart illustrating a method of operating an integrated authentication device according to another embodiment of the present invention.
  • a terminal may be connected to a communication network to execute various types of applications, to execute an application using an integrated ID, and to transmit and receive data for obtaining a trust relationship between applications, or to a communication network.
  • a mobile communication terminal connected to execute an application using an integrated ID and to transmit and receive data for authentication of a service application using a representative application will be described as a representative example, but the terminal is not limited to the mobile communication terminal. It can be applied to various terminals such as all information communication devices, multimedia terminals, wired / wireless terminals, fixed terminals, and IP (Internet Protocol) terminals.
  • the terminal may be a mobile phone, a portable multimedia player (PMP), a mobile internet device (MID), a smart phone, a desktop, a tablet computer, a notebook, a net book. It may be advantageously used when the mobile terminal having various mobile communication specifications such as a server, a server, and an information communication device.
  • PMP portable multimedia player
  • MID mobile internet device
  • smart phone a desktop, a tablet computer, a notebook, a net book. It may be advantageously used when the mobile terminal having various mobile communication specifications such as a server, a server, and an information communication device.
  • the first application and the second application represent a representative application as a first application and a service application as a second application for convenience of description, and are limited to the first or second presented. It can be described in various ways.
  • the representative application is an application that is logged in with an integrated ID and may be used for obtaining a trust relationship with a service application that requires a login with the integrated ID, and is responsible for an integrated ID and authentication for obtaining a trust relationship between a plurality of applications.
  • the reliability token provided from the integrated identity management device may be applied.
  • the present invention will be described a trust relationship acquisition system between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device has already been established.
  • the integrated authentication device may pre-store login information (ID, password, etc.), user information, and the like for the representative application.
  • the application according to an embodiment of the present invention describes a mobile application as a representative example, the application is not limited to a mobile application, but also an applet (Applet), which is a communication program made of Java inserted into a homepage source of the Internet. It can be an application.
  • Applet a communication program made of Java inserted into a homepage source of the Internet. It can be an application.
  • the login method for application authentication will be described as a typical example of the ID (ID) and password, but the login method is not limited thereto, and a login method using an authorized authentication method, an i-pin, etc. may also be applied.
  • FIG. 1 is a diagram illustrating a configuration of an authentication system using an application according to an exemplary embodiment of the present invention.
  • the authentication system 100 using an application according to the present invention includes a terminal 10, an integrated authentication device 20, a service providing device 30, and a communication network 40.
  • the communication network 40 performs a series of data transmission and reception operations for data transmission and information exchange between the terminal 10 and the integrated authentication device 20.
  • the communication network 40 may be used in various forms of communication networks, for example, wireless LAN (WLAN, Wireless LAN), Wi-Fi (Wi-Fi), Wibro (Wimax), high-speed downlink packet connection ( Wireless communication methods such as HSDPA, High Speed Downlink Packet Access (HSDPA) or Ethernet, xDSL (ADSL, VDSL), Hybrid Fiber Coax (HFC), Fiber to The Curb (FTTC), and Fiber To The Home (FTTH) Wired communication can be used.
  • the communication network 40 is not limited to the above-described communication method, and may include all other communication methods in addition to the above-mentioned communication method well-known or to be developed in the future.
  • the terminal 10 is connected to the integrated authentication device 20 through the communication network 40 to transmit and receive all data for obtaining a trust relationship between applications.
  • the terminal 10 detects an event for requesting a trust relationship between the representative application and the service application, and requests the integrated authentication device 20 to confirm the reliability between the representative application and the service application according to the occurrence of the event.
  • the terminal 10 When the terminal 10 receives a trust token from the integrated authentication device 20, the terminal 10 requests the service providing device 30 to confirm the trust token for driving the service application. In addition, the terminal 10 drives a service application provided through the service providing device 30 according to the result of confirming the reliability token, and establishes a trust relationship between the representative application and the service application.
  • the terminal 10 is connected to the integrated authentication device 20 through the communication network 40 to transmit and receive all data for performing application authentication using the integrated ID.
  • the terminal 10 executes the representative application according to the login request from the specific service application, and transmits the authentication information of the user and the service identification information corresponding to the specific service application to the integrated authentication device 20 through the representative application. Request authentication.
  • the terminal 10 receives the authentication token and the reliability token from the integrated authentication device 20 in response to the request, and the reliability token of the specific service application so that the corresponding service providing device 30 may verify the authentication using the reliability token. To the service providing device 30.
  • the integrated authentication device 20 receives a signal for requesting confirmation of reliability between the representative application and the service application according to the request of the terminal 10. In addition, the integrated authentication device 20 generates a trust token for obtaining a trust relationship between the representative application and the service application, and transmits the generated trust token to the terminal 10.
  • the integrated authentication device 20 receives a signal for requesting confirmation of the reliability token from the service providing device, the integrated authentication device 20 confirms the reliability token and transmits the confirmation result to the service providing device 30.
  • the SSO authentication scheme may be applied in a mobile environment in which account registration of a service application is performed with reference to a representative application.
  • the SSO authentication method is classified into a basic authentication method, an ID federation authentication method, and an assertion authentication method.
  • the ID federation authentication method is used to use the existing user information as there is an authentication information management server for each service provider. Therefore, there is no integrated authentication information in the integrated authentication information management server, but it has an authentication information map (Map) to know whether to log in to centrally manage the login.
  • the Assertion authentication method is suitable when the authentication information used in the existing service provider and the integrated authentication information are used together.
  • the service provider has a login page, and the login service is forced to the central authentication server after the login processing by the service provider. Do At this time, since authentication information coexists, authentication information synchronization is also required.
  • the integrated authentication device 20 performs a reliability check between the representative application and the service application at the request of the terminal 10, and transmits and receives data for application authentication using the integrated ID.
  • the integrated authentication device 20 generates an authentication token for user authentication according to a login request including service identification information from a representative application installed in the terminal 10.
  • the integrated authentication device 20 verifies the authentication token to perform user verification, and a reliability token for verifying the reliability of the service application corresponding to the service identification information based on the authenticated information. It generates and provides to the terminal 10.
  • the integrated authentication device 20 verifies the reliability token provided from the service providing device 30 when the token verification is requested from the service providing device 30 providing the service corresponding to the service identification information, and verifies the reliability token. To the service providing device 30.
  • a processor mounted in the terminal 10 or the integrated authentication apparatus 20 according to the present invention may process a program command for executing the method according to the present invention.
  • this processor may be a single-threaded processor, and in other implementations, the processor may be a multi-threaded processor.
  • the processor is capable of processing instructions stored on memory or storage devices.
  • FIG. 2 is a block diagram showing the configuration of a terminal according to the present invention.
  • the terminal 10 includes a control unit 11, an input unit 12, a display unit 13, a storage unit 14, and a communication unit 15.
  • the control unit 11 includes an application execution module 11a and a trust relationship acquisition module 11b
  • the storage unit 14 includes a representative application 14a and a plurality of service applications 14b.
  • the input unit 12 receives various information such as numeric and text information, and transmits a signal input in connection with setting various functions and controlling functions of the terminal 10 to the control unit 11.
  • the input unit 12 may include at least one of a keypad and a touch pad generating an input signal according to a user's touch or manipulation.
  • the input unit 12 may be configured in the form of a single touch panel (or touch screen) together with the display unit 13 to simultaneously perform input and display functions.
  • the input unit 12 may be any type of input means that can be developed in the future, in addition to input devices such as a keyboard, a keypad, a mouse, a joystick, and the like.
  • the display unit 13 displays information on a series of operation states and operation results generated during the functioning of the terminal 10.
  • the display unit 13 may display a menu of the terminal 10 and user data input by the user.
  • the display unit 13 includes a liquid crystal display (LCD), an ultra-thin liquid crystal display (TFT-LCD, thin film transistor LCD), a light emitting diode (LED), an organic light emitting diode (OLED, Organic) LED), an active organic light emitting diode (AMOLED, Active Matrix OLED), a Retina display, a flexible display, and a three-dimensional display.
  • the display unit 13 may perform some or all of the functions of the input unit 12.
  • the storage unit 14 is a device for storing data.
  • the storage unit 14 includes a main memory device and an auxiliary memory device, and stores an application program necessary for a functional operation of the terminal 10.
  • the storage unit 14 may largely include a program area and a data area.
  • the terminal 10 when the terminal 10 activates each function in response to a user's request, the terminal 10 executes corresponding application programs under the control of the controller 11 to provide each function.
  • the storage unit 14 according to the present invention includes an operating system for booting the terminal 10, a program for executing an application, a program for obtaining a trust relationship between a plurality of applications, a program for performing application authentication using an integrated ID, and the like. Save it.
  • the storage unit 14 stores applications of various kinds, and the applications may be divided into a representative application 14a and a plurality of service applications 14b.
  • the communication unit 15 performs a function for transmitting and receiving data through the communication network 40 with the integrated authentication device 20 and the service providing device 30.
  • the communication unit 15 includes RF transmitting means for upconverting and amplifying the frequency of the transmitted signal, and RF receiving means for low noise amplifying and downconverting the received signal, and the like.
  • the communication unit 15 may include at least one of a wireless communication module (not shown) and a wired communication module (not shown).
  • the wireless communication module is configured to transmit and receive data according to a wireless communication method.
  • any one of a wireless network communication module, a wireless LAN communication module, and a wireless fan communication module may be used. Data may be transmitted and received to the integrated authentication device 20.
  • the wired communication module is for transmitting and receiving data by wire.
  • the wired communication module may be connected to the communication network 40 through a wire, and may transmit and receive data to the integrated authentication device 20. That is, the terminal 10 may be connected to the communication network 40 by using a wireless communication module or a wired communication module, and may transmit and receive data with the integrated authentication device 20 through the communication network 40.
  • the communication unit 15 according to the present invention communicates with the integrated authentication device 20 and the service providing device 30 to transmit and receive data for obtaining a trust relationship between a plurality of applications.
  • the communication unit 15 communicates with the integrated authentication device 20 and the service providing device 30 to apply the integrated ID to transmit and receive data related to the integrated authentication using the representative application.
  • the control unit 11 may be a process device that drives an operating system (OS) and each component.
  • OS operating system
  • the control unit 11 detects an event requesting to obtain a trust relationship between the representative application and the service application.
  • the control unit 11 detects the occurrence of an event related to the acquisition of reliability with the representative application from the service application, and requests the representative application to acquire a trust relationship with the service application according to the occurrence of the event.
  • the controller 11 requests the integrated authentication device 20 to check the reliability between the representative application and the service application according to the occurrence of the event.
  • the controller 11 requests the service providing device 30 to confirm the reliability token for driving the service application.
  • the reliability token is a one-time token issued by the integrated authentication device 30 to obtain a trust relationship between the representative application and the service application, and the token verification performed at the request of the service providing device 30 in the integrated authentication device 20 is performed. It is discarded later.
  • the control unit 11 drives a service application provided through the service providing device 30 according to the result of verifying the reliability token, and establishes a trust relationship between the representative application and the service application.
  • the control unit 11 may establish a trust relationship with the service application in the mobile environment through the representative application, and may apply an authentication method for authentication of the service application.
  • control unit 11 detects a login event of a specific service application.
  • the controller 11 detects a signal for requesting login by the representative application transmitting service identification information of a specific service application to the integrated authentication device 20.
  • the controller 11 checks whether the representative application is logged in. If the representative application is not logged in, the controller 11 receives a user ID and password for logging in the representative application.
  • the controller 11 transmits the input user ID and password to the integrated authentication device 20 together with the service identification information of the specific service application and requests a login.
  • the control unit 11 transmits the authentication token previously received by the representative application together with the service identification information to the integrated authentication device 20, and requests a login.
  • the authentication token is a token that is regenerated only when the terminal 10 logs in, and the login result value is stored.
  • the control unit 11 receives the login result information including the reliability token generated in response to the service identification information from the integrated authentication device 20 in response to the login request.
  • the login result information includes an authentication token generated according to authentication of the user ID and password.
  • the reliability token is a one-time token issued by the integrated authentication device 20 to confirm the trust relationship between the representative application and the service application, which is discarded after the token confirmation performed by the service providing device in the integrated authentication device 20. Token.
  • the control unit 11 detects a signal that the representative application provides the reliability token to the specific service application. That is, the specific service application provides the reliability token to the service providing device 30 to request the reliability confirmation. Then, according to the reliability confirmation result, the specific service application is executed.
  • the control unit 11 includes an application execution module 11a and a trust relationship acquisition module 11b.
  • the application execution module 11a performs a function related to the execution of various kinds of applications. At this time, the application execution module 11a performs all functions related to the execution of the representative application or the service application based on the integration ID.
  • the application execution module 11a performs a function related to the execution of various kinds of applications. At this time, the application execution module 11a performs all functions related to the execution of the representative application or the service application based on the integration ID.
  • the trust relationship obtaining module 11b performs a function for obtaining a trust relationship between a plurality of applications (a representative application and a service application). That is, the trust relationship obtaining module 11b establishes trust relationship acquisition between applications using the trust token received from the integrated authentication device 20.
  • FIG. 3 is a block diagram showing the configuration of the integrated authentication device according to the present invention.
  • the integrated authentication apparatus 20 includes a trust token generator 21a, a trust token checker 21b, an integrated ID manager 21c, a service store 22, and a service communication unit ( 23).
  • the service storage unit 22 includes integrated ID information 22a, token information 22b, and integrated authentication information 22c.
  • the reliability token generation unit 21a, the reliability token confirmation unit 21b, the integrated ID management unit 21c, the user authentication unit 21d and the reliability authentication unit 21e of the present invention are independently modulated as respective devices. It may be configured to perform the function of the integrated authentication device 20 for obtaining a trust relationship between applications.
  • the service communication unit 23 communicates with the terminal 10 and the service providing device 30 to transmit and receive data for obtaining a trust relationship between a plurality of applications.
  • the service communication unit 23 communicates with the terminal 10 and the service providing apparatus 30 to apply an integrated ID between a plurality of applications, and transmit and receive data related to integrated authentication using a representative application.
  • the service storage unit 22 stores programs and data for performing the functions of the integrated authentication device 20.
  • the service storage unit 22 generates a program for generating a trust token to obtain a trust relationship between applications, a program for checking a trust token, a program for managing an integrated ID, and an authentication token for application authentication using an integrated ID. Save the program to run.
  • the service storage unit 22 stores the integrated ID information 22a for acquiring the trust relationship between the applications and using the integrated ID, and the token information 22b for storing the trust token used for acquiring the trust relationship.
  • the service storage unit 22 is integrated authentication information 22c for using an integrated ID based on a trust relationship between applications, and token information for storing an authentication token and a reliability token applied to application authentication using the integrated ID. (22b).
  • the reliability token generator 21a receives a signal for requesting confirmation of reliability between the representative application and the service application according to the request of the terminal 10. In addition, the reliability token generation unit 21a generates a reliability token for obtaining a trust relationship between the representative application and the service application. At this time, the reliability token generator 21a generates a one-time token for obtaining a trust relationship between the representative application and the service application. Thereafter, the reliability token generator 21a transmits the generated reliability token to the terminal 10.
  • the reliability token confirmation unit 21b determines whether a signal for requesting confirmation of the reliability token is received from the service providing device 30. When confirmation of the reliability token is requested, the reliability token verification unit 21b confirms the received reliability token. At this time, the reliability token verification unit 21b confirms the reliability token received from the service providing device 30 and discards the verified reliability token. Then, the reliability token verification unit 21b transmits the verification result of the reliability token to the service providing device 30.
  • the integrated ID manager 21c performs a function for integrating and managing IDs among applications.
  • the integrated ID management unit 21c may apply the SSO authentication method. Accordingly, the present invention can be equally applied to SSO in a mobile environment.
  • the user authentication unit 21d may generate a token for user authentication according to a login request including service identification information from a representative application installed in the terminal 10, or, if a token for user authentication is received, verify the token to verify the user. To perform. At this time, the user authentication unit 21d stores the integrated ID for each user and the authentication token generated for each user.
  • the user authentication unit 21d receives an authentication token previously received by the representative application from the terminal 10 together with the service identification information. Meanwhile, when the representative application is not logged in, the user authentication unit 21d receives, from the terminal 10, a user ID and a password for logging in the representative application together with service identification information of the service application.
  • the user authentication unit 21d generates a token for authenticating the representative application. At this time, the user authentication unit 21d is regenerated only when the terminal 10 logs in, and generates an authentication token that stores the login result value.
  • the user authentication unit 21d uses the integrated ID according to the request of the terminal 10, and checks the login result based on the token generated according to a signal for requesting confirmation of the login status of the representative application in order to log in the service application. , And transmits the confirmed result to the terminal 10.
  • the user authentication unit 21d performs a function for integrating and managing IDs among applications. To this end, the user authentication unit 21d may apply the SSO authentication method. Accordingly, the present invention can be equally applied to SSO in a mobile environment.
  • the reliability authenticator 21e generates a token for verifying the reliability of the service application corresponding to the service identification information based on the information authenticated by the user authenticator 21d and provides the token to the corresponding terminal 10.
  • the reliability authentication unit 21e verifies the token provided from the service providing apparatus 30 and verifies the verified token. To the service providing device 30.
  • the reliability authentication unit 21e receives a signal for requesting confirmation of reliability between the representative application and the service application according to the request of the terminal 10. In addition, the reliability authentication unit 21e generates a reliability token for verifying a trust relationship between the representative application and the service application. At this time, the reliability authentication unit 21e generates a one-time token for checking the trust relationship between the representative application and the service application. Thereafter, the reliability authenticator 21e transmits the generated reliability token to the terminal 10.
  • the reliability authenticator 21e determines whether a signal for requesting verification of a reliability token is received from the service providing apparatus 30. When confirmation of the reliability token is requested, the reliability authenticator 21e confirms the received reliability token. At this time, the reliability authentication unit 21e checks the reliability token received from the service providing device 30 and discards the verified reliability token. Then, the reliability authenticator 21e transmits the verification result of the reliability token to the service providing device 30.
  • the integrated authentication device 20 configured as described above may be implemented as one or more servers operating in a server-based computing-based method or a cloud method.
  • data for obtaining a trust relationship between applications using a cloud computing device may be provided through a cloud computing function that may be permanently stored in a cloud computing device on the Internet.
  • cloud computing utilizes Internet technologies in digital terminals such as desktops, tablet computers, laptops, netbooks, and smartphones to virtualize information technology (IT) resources such as hardware (servers, storage, networks, etc.) and software. It refers to a technology that provides services on demand (database, security, web server, etc.), services, and data.
  • FIG. 4 is a data flowchart illustrating a process of obtaining a trust relationship between applications according to the present invention.
  • the present invention will be described a process of establishing a trust relationship between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device 20 is already established.
  • the terminal 10 detects an event for requesting to acquire a trust relationship between a representative application and a service application. That is, the terminal 10 detects occurrence of an event related to obtaining reliability with the representative application from the service application in step S11. In operation S13, the terminal 10 requests a representative application to acquire a trust relationship with the service application according to the occurrence of the event.
  • step S15 the terminal 10 requests the integrated authentication device 30 to confirm the reliability between the representative application and the service application.
  • the integrated authentication device 20 In accordance with a signal for requesting reliability confirmation, the integrated authentication device 20 generates a trust token for acquiring a trust relationship between the representative application and the service application in step S17.
  • the integrated authentication device 20 At this time, the integrated authentication device 20 generates a one-time token for obtaining a trust relationship between the representative application and the service application. Then, the integrated authentication device 20 transmits the trust token generated in step S19 to the terminal 10.
  • the terminal 10 transmits the reliability token received from the integrated authentication device 20 to the service application through the representative application to drive the service application in step S21. That is, the terminal 10 transmits the reliability token received in response to the reliability confirmation request in step S15 to the service providing apparatus 30. In operation S23, the terminal 10 transmits a reliability token confirmation for driving the service application to the service providing apparatus 30 through the service application.
  • the service providing device 30 requests the integrated authentication device 20 to verify the reliability token in step S25.
  • the integrated authentication device 20 confirms the reliability token according to a signal for requesting confirmation of the reliability token transmitted from the service providing device 30 in step S27.
  • the integrated authentication device 20 confirms the reliability token received from the service providing device 30, and discards the confirmed reliability token.
  • the integrated authentication device 20 transmits the verification result of the trust token to the service providing device 30 in step S29.
  • the service providing apparatus 30 drives a service application of the terminal 10 in step S31 and performs a corresponding service. That is, the terminal 10 drives a service application provided through the service providing device 30 according to the result of verifying the reliability token.
  • the terminal 10 establishes a trust relationship between the representative application and the service application in step S33.
  • FIG. 5 is a data flowchart illustrating an integrated authentication process using a representative application according to the present invention.
  • the present invention will be described a process of establishing a trust relationship between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device 20 is already established.
  • the terminal 10 detects an event occurrence for logging in with the integrated ID, and requests login confirmation of the representative application (S41 to S43). That is, the terminal 10 uses the integrated ID and detects an event for logging in the service application according to the login state of the representative application.
  • the terminal 10 checks whether the representative application is logged in according to the occurrence of the event in step S45. In this case, when the representative application is logged in, the terminal 10 transmits an authentication token and service identification information to request the verification of the login status of the representative application to the integrated authentication device 20 in step S47.
  • the integrated authentication device 20 performs user authentication through an authentication token verification process according to a login request including service identification information from a representative application installed in the terminal 10 in step S49.
  • the integrated authentication device 20 generates a trust token for confirming a trust relationship between the representative application and the service application.
  • the integrated authentication device 20 generates a one-time token for checking the trust relationship between the representative application and the service application.
  • the integrated authentication device 20 checks the login result based on the token generated in step S53.
  • the integrated authentication device 20 transmits the login result and the reliability token confirmed in step S55 to the terminal 10.
  • the terminal 10 transmits a confirmation of the reliability token for driving the S57 service application to the service providing apparatus 30. That is, when the login result is received from the integrated authentication device 20, the terminal 10 requests the service providing device 30 to confirm the reliability token for driving the service application in step S59.
  • the service providing device 30 requests the integrated authentication device 20 to verify the reliability token in step S61.
  • the integrated authentication device 20 confirms the reliability token according to a signal for requesting confirmation of the reliability token transmitted from the service providing device 30.
  • the integrated authentication device 20 confirms the reliability token received from the service providing device 30, and discards the confirmed reliability token.
  • the integrated authentication device 20 transmits the verification result of the token to the service providing device 30 in step S65.
  • the service providing device 30 drives a service application of the terminal 10 in step S67 and performs a corresponding service. That is, the terminal 10 drives a service application provided through the service providing device 30 according to the result of verifying the reliability token.
  • FIG. 6 is a data flow diagram illustrating an integrated authentication process using a representative application according to another embodiment of the present invention.
  • the terminal 10 detects an event occurrence for logging in with the integrated ID, and requests login confirmation of the representative application (S71 to S73). That is, the terminal 10 uses the integrated ID and detects an event for logging in the service application according to the login state of the representative application. Thereafter, the terminal 10 checks whether the representative application is logged in as the event occurs.
  • the terminal 10 receives a user ID and password for logging in the representative application in step S75.
  • the terminal 10 transmits an input user ID, a password, and service identification information to the integrated authentication device 20 to request the confirmation of the login status of the representative application.
  • the integrated authentication device 20 generates an authentication token according to a login request including service identification information from the representative application installed in the terminal 10 in step S79. That is, the integrated authentication device 20 generates an authentication token to which the integrated ID can be applied using a user ID and a password.
  • the terminal 10 stores an integrated ID for each user and an authentication token generated for each user.
  • the integrated authentication device 20 generates a trust token for checking the trust relationship between the representative application and the service application in step S81.
  • the integrated authentication device 20 generates a one-time token for checking the trust relationship between the representative application and the service application.
  • the integrated authentication device 20 checks the login result based on the token generated in step S83. Thereafter, the integrated authentication device 20 transmits the authentication token and the reliability token to the terminal 10 as a result of the login confirmed in step S85.
  • the terminal 10 When the terminal 10 receives the login result, the authentication token and the reliability token of the representative application, the terminal 10 transmits a confirmation of the reliability token for driving the S87 service application to the service providing apparatus 30. That is, when the login result is received from the integrated authentication device 20, the terminal 10 requests the service providing device 30 to confirm the reliability token for driving the service application in operation S89.
  • the service providing device 30 requests the integrated authentication device 20 to verify the reliability token in step S91.
  • the integrated authentication device 20 confirms the reliability token according to a signal for requesting confirmation of the reliability token transmitted from the service providing device 30.
  • the integrated authentication device 20 confirms the reliability token received from the service providing device 30, and discards the confirmed reliability token.
  • the integrated authentication device 20 transmits the verification result of the token to the service providing device 30 in step S95.
  • the service providing device 30 drives a service application of the terminal 10 in step S97 and performs a corresponding service. That is, the terminal 10 drives a service application provided through the service providing device 30 according to the result of verifying the reliability token.
  • FIG. 7 is a flowchart illustrating a method of operating a terminal according to the present invention.
  • the present invention will be described the operation of the terminal 10 for establishing a trust relationship between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device 20 has already been established.
  • step S101 the terminal 10 detects an event for requesting to acquire a trust relationship between a representative application and a service application.
  • the terminal 10 detects an occurrence of an event related to obtaining reliability from the service application from the service application, and requests the representative application to acquire a trust relationship with the service application according to the event occurrence.
  • step S103 the terminal 10 requests the integrated authentication device 30 to confirm reliability between the representative application and the service application.
  • the terminal 10 determines whether a reliability token is received in step S105.
  • the terminal 10 transmits the trust token confirmation to the service providing apparatus 30 in step S107.
  • the terminal 10 drives a service application provided through the service providing device 30 according to the result of the verification of the reliability token in step S109.
  • step S111 the terminal 10 establishes a trust relationship between the representative application and the service application.
  • FIG. 8 is a flowchart illustrating a method of operating an integrated authentication device according to the present invention.
  • the present invention will be described the operation of the integrated authentication device 20 for establishing a trust relationship between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device 20 has already been established.
  • step S121 the integrated authentication device 20 receives a signal for requesting a reliability check between a representative application and a service application according to a request of the terminal 10.
  • the integrated authentication device 20 generates a trust token for acquiring a trust relationship between the representative application and the service application in step S123. At this time, the integrated authentication device 20 generates a one-time token for obtaining a trust relationship between the representative application and the service application.
  • the integrated authentication device 20 transmits the reliability token generated in step S125 to the terminal 10.
  • the integrated authentication device 20 determines whether a signal for requesting confirmation of the reliability token is received from the service providing device 30. When confirmation of the reliability token is requested, the integrated authentication device 20 confirms the reliability token received in step S129. At this time, the integrated authentication device 20 confirms the reliability token received from the service providing device 30, and discards the confirmed reliability token. Then, the integrated authentication device 20 transmits the verification result of the trust token to the service providing device 30 in step S131.
  • the service when a trust relationship is acquired between the representative application and the service application, that is, when the representative application and the service application are logged in through the integrated ID, the service can be used immediately without the inconvenience of having to log in again.
  • FIG. 9 is a flowchart illustrating a method of operating a terminal according to another embodiment of the present invention.
  • the present invention will be described the operation of the terminal 10 for establishing a trust relationship between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device 20 has already been established.
  • the terminal 10 detects an event for logging in with an integrated ID in step S141.
  • the terminal 10 checks whether the representative application is logged in. That is, the terminal 10 uses the integrated ID and detects an event for logging in the service application according to the login state of the representative application.
  • the terminal 10 transmits an authentication token and service identification information to request the verification of the login status of the representative application to the integrated authentication device 20 in step S145.
  • the terminal 10 checks whether a login result and a reliability token of the representative application are received from the integrated authentication device 20.
  • the terminal 10 transmits a confirmation of the reliability token for driving the S149 service application to the service providing apparatus 30. Thereafter, the terminal 10 drives the service application according to the result of the verification of the reliability token in step S151 and performs the corresponding service. Accordingly, the terminal 10 may establish a trust relationship with the service application in the mobile environment through the representative application, and apply an authentication method for authentication of the service application.
  • FIG. 10 is a flowchart illustrating a method of operating a terminal according to another embodiment of the present invention.
  • the terminal 10 when the representative application is not logged in in the integrated authentication process using the representative application according to another exemplary embodiment of the present disclosure, the terminal 10 provides a user ID and password for logging in the representative application in step S161. Take input. In operation S163, the terminal 10 transmits the input user ID, password, and service identification information to the integrated authentication device 20 to request the confirmation of the login status of the representative application.
  • the terminal 10 checks whether the authentication token and the reliability are received as a result of the login of the representative application from the integrated authentication device 20 in step S165.
  • the terminal 10 transmits a confirmation of the reliability token for driving the service application to the service providing apparatus 30.
  • the terminal 10 drives the service application according to the result of the verification of the reliability token, and performs the corresponding service. Accordingly, the terminal 10 may establish a trust relationship with the service application in the mobile environment through the representative application, and apply an authentication method for authentication of the service application.
  • FIG. 11 is a flowchart illustrating a method of operating an integrated authentication device according to another embodiment of the present invention.
  • the present invention will be described the operation of the integrated authentication device 20 for establishing a trust relationship between the following applications on the premise that a trust relationship between the representative application and the integrated authentication device 20 has already been established.
  • the integrated authentication device 20 uses the integrated ID according to the request of the terminal 10 in operation S171, and an authentication token and a service for logging in a representative application to log in a service application. Receive identification information.
  • the representative application will be described on the assumption that the login.
  • the integrated authentication device 20 verifies the authentication token for authentication for the representative application in step S173. Accordingly, the integrated authentication device 20 performs user authentication.
  • the integrated authentication device 20 is regenerated only when the terminal 10 logs in, and is an integrated ID for each user and a token generated for each user.
  • the integrated authentication device 20 generates a trust token for verifying a trust relationship between the representative application and the service application. That is, the integrated authentication device 20 generates a one-time token for checking the trust relationship between the representative application and the service application.
  • the reliability token is a one-time token for confirming the trust relationship between the representative application and the service application.
  • the integrated authentication device 20 checks the login result based on the token generated in step S177. In addition, the integrated authentication device 20 transmits the login result and the reliability token confirmed in step S179 to the terminal 10.
  • the integrated authentication device 20 checks whether a signal for requesting confirmation of the reliability token is received from the service providing device 30 in step S181. When a signal for requesting the reliability token confirmation is received, the integrated authentication device 20 confirms the reliability token according to the reliability token confirmation request in step S183. At this time, the integrated authentication device 20 confirms the reliability token received from the service providing device 30, and discards the confirmed reliability token. Then, the integrated authentication device 20 transmits the verification result for the trust token to the service providing device 30 in step S185.
  • FIG. 12 is a flowchart illustrating a method of operating an integrated authentication device according to another embodiment of the present invention.
  • the integrated authentication device 20 uses the integrated ID according to the request of the terminal 10 in step S191, and identifies a user ID, a password, and a service of a representative application to log in a service application. Receive information. At this time, it will be described on the assumption that the representative application is not logged in.
  • the integrated authentication device 20 generates an authentication token for authenticating the representative application in step S193. Accordingly, the integrated authentication device 20 performs user authentication. Here, the integrated authentication device 20 is regenerated only when the terminal 10 logs in, and is an integrated ID for each user and a token generated for each user. In operation S195, the integrated authentication device 20 generates a trust token for confirming a trust relationship between the representative application and the service application. That is, the integrated authentication device 20 generates a one-time token for checking the trust relationship between the representative application and the service application. The reliability token is a one-time token for confirming the trust relationship between the representative application and the service application.
  • the integrated authentication device 20 checks the login result based on the token generated in step S197.
  • the integrated authentication device 20 transmits the authentication token and the reliability token to the terminal 10 as a result of the login confirmed in step S199.
  • the integrated authentication device 20 checks whether a signal for requesting confirmation of the reliability token is received from the service providing device 30 in step S201. When a signal for requesting the reliability token confirmation is received, the integrated authentication device 20 confirms the reliability token according to the reliability token confirmation request in step S203. At this time, the integrated authentication device 20 confirms the reliability token received from the service providing device 30, and discards the confirmed reliability token. Then, the integrated authentication device 20 transmits the verification result for the trust token to the service providing device 30 in step S205.
  • the memory mounted in the terminal 10 or the integrated authentication device 20 stores information in the device.
  • the memory is a computer readable medium.
  • the memory may be a volatile memory unit, and for other implementations, the memory may be a nonvolatile memory unit.
  • the storage device is a computer readable medium.
  • the storage device may include, for example, a hard disk device, an optical disk device, or some other mass storage device.
  • the specification and drawings describe exemplary device configurations, the functional operations and subject matter implementations described herein may be embodied in other types of digital electronic circuitry, or modified from the structures and structural equivalents disclosed herein. It may be implemented in computer software, firmware or hardware, including, or a combination of one or more of them. Implementations of the subject matter described herein relate to one or more computer program products, ie computer program instructions encoded on a program storage medium of tangible type for controlling or by the operation of an apparatus according to the invention. It may be implemented as the above module.
  • the computer readable medium may be a machine readable storage device, a machine readable storage substrate, a memory device, a composition of materials affecting a machine readable propagated signal, or a combination of one or more thereof.
  • Computer-readable media suitable for storing computer program instructions and data include, for example, magnetic media such as hard disks, floppy disks, and magnetic tape, such as magnetic disks, compact disk read only memory (CD-ROM), and DVDs.
  • Optical Media such as Digital Video Disk, Magnetic-Optical Media such as Floppy Disk, and Read Only Memory, RAM, Random Semiconductor memories such as access memory (EPM), flash memory, erasable programmable ROM (EPROM), and electrically erasable programmable ROM (EEPROM).
  • the processor and memory can be supplemented by or integrated with special purpose logic circuitry.
  • Examples of program instructions may include high-level language code that can be executed by a computer using an interpreter as well as machine code such as produced by a compiler.
  • Such hardware devices may be configured to operate as one or more software modules to perform the operations of the present invention, and vice versa.
  • the present invention can use the integrated ID by obtaining a trust relationship between a plurality of applications installed in one terminal, or can perform authentication of another application by sharing authentication information using a representative application among a plurality of applications installed in one terminal.
  • it refers to registering an account with reference to the representative application, through which SSO authentication can be implemented in a mobile environment.
  • the representative application can be executed by reference only between applications without an internal browser, which is not limited by various operating systems.
  • SSO authentication can increase management transparency, reliability, reduce costs, and increase efficiency.
  • authentication information may be shared in one device through a representative application on the assumption that trust relationships between applications are established. This has industrial applicability because it is not only sufficient marketable or business possibility, but also practically evident.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Telephonic Communication Services (AREA)

Abstract

본 발명은 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치에 관한 것으로, 특히, 하나의 단말기에 설치된 복수의 어플리케이션 간의 신뢰관계를 획득하여 통합 아이디를 이용할 수 있거나, 하나의 단말기에 설치된 복수의 어플리케이션 중 대표 어플리케이션을 이용한 인증 정보를 공유하여 다른 어플리케이션의 인증을 수행할 수 있도록 함으로써, 대표 어플리케이션을 참조하여 계정 등록을 하는 것을 의미하며, 이를 통해 모바일 환경에서도 SSO(Single Sing On) 인증 방식의 구현이 가능하다. 또한, 대표 어플리케이션을 통해 내부 브라우저 없이 어플리케이션 간 참조만으로 이를 실행할 수 있으며, 이는 다양한 운영체제의 제약을 받지 않는다. 또한, SSO 인증 방식을 통해 관리의 투명성과 신뢰성을 높이고, 비용을 절감하고, 효율성을 높일 수 있다. 즉, 사용자 아이디나 비밀번호 관리의 효율 증가, 별도 로그인 없이 다른 시스템 이용, 인증 지원, 관리자의 비밀번호 문의 감소, 사용자의 로그인/종료/재접속을 위한 재입력 감소, 사용자의 접속정보에 대한 리포팅 기능 제공 등이 가능하다. 또한, 어플리케이션들 간의 신뢰관계가 설정되어 있다는 가정하에, 대표 어플리케이션을 통해 하나의 디바이스 내에서 인증 정보를 공유할 수 있다.

Description

어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치
본 발명은 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치에 관한 것으로, 더욱 상세하게는 하나의 단말기에 설치된 복수의 어플리케이션 간의 신뢰관계를 획득하여 통합 아이디를 이용할 수 있거나, 하나의 단말기에 설치된 복수의 어플리케이션 중 대표 어플리케이션을 이용한 인증 정보를 공유하여 다른 어플리케이션의 인증을 수행할 수 있도록 하는 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치에 관한 것이다.
이동통신망의 발달과 통신 기술의 발달에 따라서, 유무선 통신망을 기반으로 다양한 서비스들이 제공되고 있으나, 다양한 서비스 별로 사용자 ID(Identification) 체계가 분산 관리되고 있기 때문에, 고객의 편의성 저하, 정보 보안 및 법규 준수의 어려움, 신규 서비스의 도입과 서비스간 연계 저해 등의 문제가 발생하고, 다양한 서비스의 사용자 ID에 대한 통합의 필요성이 대두되고 있으며, 이에 하나의 통합된 ID를 관리하는 통합 인증 시스템(가칭)에 대한 개발이 이루어지고 있다.
이러한, 통합 인증 시스템의 구축에 있어서, 사용자 ID 통합은 서비스 별로 다양한 회원 정책(회원 자격/범위, 회원 확인 방식 등)을 수용할 수 있는 융통성, 운영 안정성, 서비스 유지 가능성, 및 향후 확장성 등이 고려되어야 한다.
특히, 여러 웹 서비스 혹은 여러 어플리케이션에서의 인증(Authentication)을 통합하여 한번의 인증으로 다수의 웹 서비스나 여러 어플리케이션을 이용할 수 있도록 하기 위하여, 별도의 통합 인증 서버를 구축하여 서로 다른 여러 서비스 혹은 어플리케이션의 인증을 통합 서버를 통해 수행하거나, 단일 인증(SSO: Single Sign on) 기술을 통해서 특정 어플리케이션 또는 서비스에서의 인증 정보를 다른 서비스 혹은 인증 서버로 전달하여, 사용자가 다시 로그인할 필요가 없도록 한다. 이와 관련된 기술은 인증 정보를 전달하는 방식에 따라서, 쿠키, 세션, 인증 토큰, 티겟 등을 이용하는 방식으로 구분 가능하며, 통합 대상에 따라서, 웹 서비스간의 단일 인증, 어플리케이션 간의 단일 인증, 네트워크 접속과 서비스 간 단일 인증 등으로 구분될 수 있다.
하지만, 하나의 디바이스 내에 있는 각각의 어플리케이션들은 서로가 동일한 디바이스 내에 설치되어 있다는 사실을 인지할 수 있지만, 서로 간의 연결이 될 수 없어 신뢰관계 획득에 문제가 있다.
또한, 일반적인 어플리케이션에서의 컨텐츠 사용을 위한 인증하는 방법에는 각각의 어플리케이션을 제공하는 인터넷 사이트에 접속하는 것만으로 인증이 수행되는 되거나, 회원가입이라는 개인정보 제공 및 그 사이트에서 요구하는 어떠한 절차를 통한 어플리케이션의 실행을 위한 고유의 아이디를 생성하고, 그 아이디를 이용하여 접속했을 경우에만, 어플리케이션에서 제공하는 컨텐츠를 완전하게 사용하도록 인증하는 방법이 이용되고 있다.
이와 같은 인증방법에 따라 어플리케이션을 제공하는 인터넷 사이트에서 컨텐츠를 이용할 때에는 각각의 수많은 어플리케이션 마다 고유의 아이디와 비밀번호를 생성해야 하고, 이를 기억 해야 하는 문제점들이 발생하고 있다. 부가적으로, 회원가입 시 똑같은 개인정보를 반복적으로 입력해야 한다는 점과, 개인정보의 변경 시 회원으로 가입된 수많은 어플리케이션에 접속하여 다시금 개인정보를 변경해주어야 한다는 문제점이 발생하게 되다.
이러한 종래의 문제점을 해결하기 위하여, 본 발명의 목적은 하나의 디바이스 내에 있는 각각의 어플리케이션들은 서로가 동일한 디바이스 내에 설치되어 있다는 사실을 인지할 수 있지만, 서로 간의 연결이 될 수 없어 신뢰관계 획득에 문제가 발생할 수 있기 때문에, 하나의 단말기에 설치된 복수의 어플리케이션 간의 신뢰관계를 신뢰성 토큰을 이용하여 획득하고, 신뢰관계를 기반으로 통합 아이디를 이용할 수 있는 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치를 제공하고자 한다.
또한, 본 발명의 다른 목적은 종래의 어플리케이션 인증을 위하여 어플리케이션을 제공하는 각각의 인터넷 사이트에 접속하고, 컨텐츠를 이용할 경우, 각각의 수많은 어플리케이션 마다 고유의 아이디와 비밀번호를 생성해야 하는 문제점을 해결하기 위한 것으로, 하나의 단말기에 설치된 복수의 어플리케이션 중 대표 어플리케이션을 이용한 인증 정보를 공유하여 다른 어플리케이션의 인증을 수행할 수 있는 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치를 제공하고자 한다.
상술한 바와 같은 목적을 달성하기 위한 본 발명의 실시 예에 따른 통합 인증 장치는 적어도 하나의 단말기 및 서비스 제공 장치와 통신하여 복수의 어플리케이션 간의 신뢰관계 획득을 위한 데이터를 송수신하는 서비스통신부와, 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하고, 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하고, 생성된 신뢰성 토큰을 단말기로 전송하는 신뢰성 토큰 생성부 및 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되면, 신뢰성 토큰을 확인한 후, 확인 결과를 서비스 제공 장치로 전송하는 신뢰성 토큰 확인부를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 통합 인증 장치에 있어서, 하나 이상의 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 위한 토큰을 생성하거나, 사용자 인증을 위한 토큰이 수신되면 토큰을 확인하여 사용자 검증을 수행하는 사용자 인증부 및 사용자 인증부를 통해 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 토큰을 생성하여 해당 단말기로 제공하고, 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 토큰 확인이 요청되면, 서비스 제공 장치로부터 제공된 토큰을 검증하여, 검증된 토큰에 대한 검증 결과를 서비스 제공 장치로 제공하는 신뢰성 인증부를 더 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 통합 인증 장치에 있어서, 신뢰성 토큰 생성부는 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성하는 것을 특징으로 한다.
또한, 본 발명에 따른 통합 인증 장치에 있어서, 신뢰성 토큰 확인부는 서비스 제공 장치로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기하는 것을 특징으로 한다.
또한, 본 발명에 따른 통합 인증 장치에 있어서, 다수의 어플리케이션들 간의 ID를 통합하여 관리하는 통합 ID 관리부를 더 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 통합 인증 장치에 있어서, 사용자 인증부는 사용자 별 통합 ID 및 사용자 별로 생성된 인증 토큰을 저장하는 것을 특징으로 한다.
또한, 본 발명에 따른 통합 인증 장치에 있어서, 신뢰성 인증부는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 저장하고, 한번 검증된 신뢰성 토큰을 삭제하는 것을 특징으로 한다.
본 발명의 실시 예에 따른 단말기는 통합 인증 장치 및 서비스 제공 장치와 통신하여 복수의 어플리케이션 간의 신뢰관계 획득을 위한 데이터를 송수신하는 통신부 및 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하고, 이벤트 발생에 따라 통합 인증 장치로 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하고, 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하고, 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하고, 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하도록 제어하는 제어부를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 단말기에 있어서, 통합 인증을 위한 대표 어플리케이션 및 하나 이상의 서비스 어플리케이션을 저장하는 저장부를 더 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 단말기에 있어서, 제어부는 특정 서비스 어플리케이션으로부터의 로그인 요청에 따라서 대표 어플리케이션을 실행하여, 대표 어플리케이션을 통하여 사용자의 인증 정보 및 특정 서비스 어플리케이션에 대응하는 서비스 식별 정보를 통합 인증 장치로 전송하여 인증을 요청하고, 요청에 대응하여 통합 인증 장치로부터 인증 토큰 및 신뢰성 토큰을 수신하고, 해당 서비스 제공 장치가 신뢰성 토큰을 이용하여 인증 여부를 확인할 수 있도록 특정 서비스 어플리케이션이 신뢰성 토큰을 서비스 제공 장치로 전송하는 것을 특징으로 한다.
또한, 본 발명에 따른 단말기에 있어서, 대표 어플리케이션은 다수의 서비스 어플리케이션 중 하나 인 것을 특징으로 한다.
또한, 본 발명에 따른 단말기에 있어서, 제어부는 대표 어플리케이션이 로그인 상태인 경우, 기 수신된 인증 토큰 및 특정 서비스 어플리케이션의 서비스 식별 정보를 통합 인증 장치로 전송하여 인증 검증을 요청하고, 통합 인증 장치로부터 인증 결과 및 신뢰성 토큰만을 수신하도록 제어하는 것을 특징으로 한다.
본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 시스템은 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하고, 이벤트 발생에 따라 통합 인증 장치로 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하고, 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하고, 신뢰성 토큰 확인에 따라 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하고, 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하는 단말기 및 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하고, 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하고, 생성된 신뢰성 토큰을 단말기로 전송하고, 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되면, 신뢰성 토큰을 확인한 후, 확인 결과를 서비스 제공 장치로 전송하는 통합 인증 장치를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 시스템에 있어서, 단말기는 특정 서비스 어플리케이션으로부터의 로그인 요청에 따라서 대표 어플리케이션을 실행하여, 대표 어플리케이션을 통하여 사용자의 인증 정보 및 특정 서비스 어플리케이션에 대응하는 서비스 식별 정보를 통합 인증 장치로 전송하여 인증을 요청하고, 요청에 대응하여 통합 인증 장치로부터 인증 토큰 및 신뢰성 토큰을 수신하고, 해당 서비스 제공 장치가 신뢰성 토큰을 이용하여 인증 여부를 확인할 수 있도록 특정 서비스 어플리케이션의 신뢰성 토큰을 서비스 제공 장치로 전송하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 시스템에 있어서, 통합 인증 장치는 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 위한 인증 토큰을 생성하거나, 사용자 인증을 위한 인증 토큰이 수신되면 인증 토큰을 확인하여 사용자 검증을 수행하고, 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하여 해당 단말기로 제공하고, 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 토큰 확인이 요청되면, 서비스 제공 장치로부터 제공된 신뢰성 토큰을 검증하여, 신뢰성 토큰에 대한 검증 결과를 서비스 제공 장치로 제공하는 것을 특징으로 한다.
본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 방법은 단말기가 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하는 단계와, 단말기가 이벤트 발생에 따라 통합 인증 장치로 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 단계와, 단말기가 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하는 단계와, 단말기가 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하는 단계 및 단말기가 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하는 단계를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 신뢰성 토큰은 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위해 통합 인증 장치에서 발급되는 일회용 토큰으로서, 통합 인증 장치에서 서비스 제공 장치의 요청에 따라 수행되는 토큰 확인 후에 폐기되는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 감지하는 단계는 단말기가 제2 어플리케이션으로부터 제1 어플리케이션과의 신뢰성 획득과 관련된 이벤트 발생을 감지하는 단계 및 단말기가 이벤트 발생에 따라 제1 어플리케이션으로 제2 어플리케이션과의 신뢰관계 획득을 요청하는 단계를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 구축하는 단계는 단말기가 대표 어플리케이션인 제1 어플리케이션을 통해 모바일 환경에서 제2 어플리케이션과의 신뢰관계를 구축하고, 제2 어플리케이션의 인증을 위한 적어도 하나의 인증방식을 적용하는 것을 특징으로 한다.
본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 방법은 통합 인증 장치가 적어도 하나의 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하는 단계와, 통합 인증 장치가 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하는 단계와, 통합 인증 장치가 생성된 신뢰성 토큰을 단말기로 전송하는 단계와, 통합 인증 장치가 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호를 수신하는 단계와, 통합 인증 장치가 수신된 신뢰성 토큰을 확인하는 단계 및 통합 인증 장치가 신뢰성 토큰의 확인 결과를 서비스 제공 장치로 전송하는 단계를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 생성하는 단계는 통합 인증 장치가 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 확인하는 단계는 통합 인증 장치가 서비스 제공 장치로부터 수신된 신뢰성 토큰을 확인하는 단계 및 통합 인증 장치가 확인된 신뢰성 토큰을 폐기하는 단계를 포함하는 것을 특징으로 한다.
본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 방법은 단말기가 특정 서비스 어플리케이션의 로그인 이벤트를 감지하는 단계와, 로그인 이벤트가 감지되면, 대표 어플리케이션이 특정 서비스 어플리케이션의 서비스 식별 정보를 통합 인증 장치로 전송하여 로그인을 요청하는 단계와, 요청에 따라 대표 어플리케이션이 통합 인증 장치로부터 서비스 식별 정보에 대응하여 생성된 신뢰성 토큰을 포함하는 로그인 결과 정보를 수신하는 단계와, 대표 어플리케이션이 신뢰성 토큰을 특정 서비스 어플리케이션으로 제공하는 단계와, 특정 서비스 어플리케이션이 신뢰성 토큰을 서비스 제공 장치로 제공하여 신뢰성 확인을 요청하는 단계 및 신뢰성 확인 결과에 따라서, 특정 서비스 어플리케이션이 실행되는 단계를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 로그인을 요청하는 단계는 대표 어플리케이션의 로그인 여부를 확인하는 단계와, 대표 어플리케이션이 로그인 되지 않은 경우, 대표 어플리케이션의 로그인을 위한 사용자 ID 및 비밀번호를 입력받는 단계 및 특정 서비스 어플리케이션의 서비스 식별 정보와 함께, 입력된 사용자 ID 및 비밀번호를 통합 인증 장치로 전송하여, 로그인을 요청하는 단계를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 로그인 결과 정보는 사용자 ID 및 비밀번호의 인증에 따라서 생성되는 인증 토큰을 더 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 로그인을 요청하는 단계는 대표 어플리케이션이 로그인 된 경우, 서비스 식별 정보와 함께 대표 어플리케이션이 기 수신한 인증 토큰을 통합 인증 장치로 전송하여, 로그인을 요청하는 단계를 더 포함하는 것을 특징으로 한다.
본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 방법은 통합 인증 장치가 하나 이상의 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 수행하는 단계와, 통합 인증 장치가 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하는 단계와, 통합 인증 장치가 신뢰성 토큰을 포함하는 로그인 결과를 단말기로 전송하는 단계와, 통합 인증 장치가 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 신뢰성 토큰 확인이 요청되면, 서비스 제공 장치로부터 제공된 신뢰성 토큰을 검증하는 단계 및 통합 인증 장치가 신뢰성 토큰에 대한 검증 결과를 서비스 제공 장치로 제공하는 단계를 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 수행하는 단계 이전에, 통합 인증 장치가 대표 어플리케이션이 로그인 된 경우, 서비스 식별 정보와 함께 대표 어플리케이션이 기 수신한 인증 토큰을 단말기로부터 수신하는 단계를 더 포함하는 것을 특징으로 한다.
또한, 본 발명에 따른 어플리케이션을 이용한 인증 방법에 있어서, 수행하는 단계 이전에, 대표 어플리케이션이 로그인 되지 않은 경우, 서비스 어플리케이션의 서비스 식별 정보와 함께, 대표 어플리케이션을 로그인하기 위한 사용자 ID 및 비밀번호를 단말기로부터 수신하는 단계를 더 포함하는 것을 특징으로 한다.
본 발명의 과제 해결을 위한 또 다른 수단으로서, 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하는 단계와, 이벤트 발생에 따라 통합 인증 장치로 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 단계와, 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하는 단계와, 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하는 단계 및 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체를 제공한다.
본 발명의 과제 해결을 위한 또 다른 수단으로서, 적어도 하나의 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하는 단계와, 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하는 단계와, 생성된 신뢰성 토큰을 단말기로 전송하는 단계와, 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호를 수신하는 단계와, 수신된 신뢰성 토큰을 확인하는 단계 및 신뢰성 토큰의 확인 결과를 서비스 제공 장치로 전송하는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체를 제공한다.
본 발명의 과제 해결을 위한 또 다른 수단으로서, 특정 서비스 어플리케이션의 로그인 이벤트를 감지하는 단계와, 로그인 이벤트가 감지되면, 대표 어플리케이션이 특정 서비스 어플리케이션의 서비스 식별 정보를 통합 인증 장치로 전송하여 로그인을 요청하는 단계와, 요청에 따라 대표 어플리케이션이 통합 인증 장치로부터 서비스 식별 정보에 대응하여 생성된 신뢰성 토큰을 포함하는 로그인 결과 정보를 수신하는 단계와, 대표 어플리케이션이 신뢰성 토큰을 특정 서비스 어플리케이션으로 제공하는 단계와, 특정 서비스 어플리케이션이 신뢰성 토큰을 서비스 제공 장치로 제공하여 신뢰성 확인을 요청하는 단계 및 신뢰성 확인 결과에 따라서, 특정 서비스 어플리케이션이 실행되는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체를 제공한다.
본 발명의 과제 해결을 위한 또 다른 수단으로서, 하나 이상의 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 수행하는 단계와, 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하는 단계와, 신뢰성 토큰을 포함하는 로그인 결과를 단말기로 전송하는 단계와, 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 신뢰성 토큰 확인이 요청되면, 서비스 제공 장치로부터 제공된 신뢰성 토큰을 검증하는 단계 및 신뢰성 토큰에 대한 검증 결과를 서비스 제공 장치로 제공하는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체를 제공한다.
본 발명에 따르면, 대표 어플리케이션을 참조하여 계정 등록을 하는 것을 의미하며, 이를 통해 모바일 환경에서도 SSO(Single Sing On) 인증 방식의 구현이 가능하다.
또한, 대표 어플리케이션을 통해 내부 브라우저 없이 어플리케이션 간 참조만으로 이를 실행할 수 있으며, 이는 다양한 운영체제의 제약을 받지 않는다.
또한, SSO 인증 방식을 통해 관리의 투명성과 신뢰성을 높이고, 비용을 절감하고, 효율성을 높일 수 있다. 즉, 사용자 아이디나 비밀번호 관리의 효율 증가, 별도 로그인 없이 다른 시스템 이용, 인증 지원, 관리자의 비밀번호 문의 감소, 사용자의 로그인/종료/재접속을 위한 재입력 감소, 사용자의 접속정보에 대한 리포팅 기능 제공 등이 가능하다.
또한, 어플리케이션들 간의 신뢰관계가 설정되어 있다는 가정하에, 대표 어플리케이션을 통해 하나의 디바이스 내에서 인증 정보를 공유할 수 있다.
도 1은 본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 시스템의 구성을 나타내는 도면이다.
도 2는 본 발명에 따른 단말기의 구성을 나타내는 블록도 이다.
도 3은 본 발명에 따른 통합 인증 장치의 구성을 나타내는 블록도 이다.
도 4는 본 발명에 따른 어플리케이션 간의 신뢰관계 획득 과정을 설명하기 위한 데이터 흐름도이다.
도 5는 본 발명에 따른 대표 어플리케이션을 이용한 통합 인증 과정을 설명하기 위한 데이터 흐름도이다.
도 6은 본 발명의 다른 실시 예에 따른 대표 어플리케이션을 이용한 통합 인증 과정을 설명하기 위한 데이터 흐름도이다.
도 7은 본 발명의 실시 예에 따른 단말기의 동작 방법을 설명하기 위한 흐름도이다.
도 8은 본 발명의 실시 예에 따른 통합 인증 장치의 동작 방법을 설명하기 위한 흐름도이다.
도 9는 본 발명의 다른 실시 예에 따른 단말기의 동작 방법을 설명하기 위한 흐름도이다.
도 10은 본 발명의 또 다른 실시 예에 따른 단말기의 동작 방법을 설명하기 위한 흐름도이다.
도 11은 본 발명의 다른 실시 예에 따른 통합 인증 장치의 동작 방법을 설명하기 위한 흐름도이다.
도 12는 본 발명의 또 다른 실시 예에 따른 통합 인증 장치의 동작 방법을 설명하기 위한 흐름도이다.
이하 본 발명의 바람직한 실시 예를 첨부한 도면을 참조하여 상세히 설명한다. 다만, 하기의 설명 및 첨부된 도면에서 본 발명의 요지를 흐릴 수 있는 공지 기능 또는 구성에 대한 상세한 설명은 생략한다. 또한, 도면 전체에 걸쳐 동일한 구성 요소들은 가능한 한 동일한 도면 부호로 나타내고 있음에 유의하여야 한다.
이하에서 설명되는 본 명세서 및 청구범위에 사용된 용어나 단어는 통상적이거나 사전적인 의미로 한정해서 해석되어서는 아니 되며, 발명자는 그 자신의 발명을 가장 최선의 방법으로 설명하기 위한 용어의 개념으로 적절하게 정의할 수 있다는 원칙에 입각하여 본 발명의 기술적 사상에 부합하는 의미와 개념으로 해석되어야만 한다. 따라서 본 명세서에 기재된 실시 예와 도면에 도시된 구성은 본 발명의 가장 바람직한 일 실시 예에 불과할 뿐이고, 본 발명의 기술적 사상을 모두 대변하는 것은 아니므로, 본 출원시점에 있어서 이들을 대체할 수 있는 다양한 균등물과 변형 예들이 있을 수 있음을 이해하여야 한다.
이하에서는 본 발명의 실시 예에 따른 단말기는 통신망에 연결되어 다양한 종류의 어플리케이션을 실행하고, 통합 아이디를 이용하여 어플리케이션을 실행하고, 어플리케이션들 간의 신뢰관계 획득을 위한 데이터를 송수신할 수 있거나, 통신망에 연결되어 통합 ID를 이용하여 어플리케이션을 실행하고, 대표 어플리케이션을 이용하여 서비스 어플리케이션의 인증을 수행하기 위한 데이터를 송수신할 수 있는 이동통신단말기를 대표적인 예로서 설명하지만 단말기는 이동통신단말기에 한정된 것이 아니고, 모든 정보통신기기, 멀티미디어 단말기, 유선/무선 단말기, 고정형 단말기 및 IP(Internet Protocol) 단말기 등의 다양한 단말기에 적용될 수 있다. 특히, 어플리케이션 간 데이터 조회가 불가능한 운영체제에 적용 가능하며, 운영체제로는 iOS, 안드로이드(Android), 심비안(Symbian), 바다(Bada) 등의 모바일 운영체제가 포함될 수 있고, 이러한 조건들을 합쳐서 모바일 환경이 형성될 수 있다. 또한, 단말기는 휴대폰, PMP(Portable Multimedia Player), MID(Mobile Internet Device), 스마트폰(Smart Phone), 데스크톱(Desktop), 태블릿컴퓨터(Tablet PC), 노트북(Note book), 넷북(Net book), 서버(Server) 및 정보통신 기기 등과 같은 다양한 이동통신 사양을 갖는 모바일(Mobile) 단말기일 때 유리하게 활용될 수 있다.
한편, 본 발명의 실시 예에 따른 제1 어플리케이션과 제2 어플리케이션은 설명의 편의를 위하여 대표 어플리케이션을 제1 어플리케이션으로 표현하고, 서비스 어플리케이션을 제2 어플리케이션으로 표현한 것으로, 제시된 제1 또는 제2 에 한정된 것이 아니며, 다양한 방식으로 기재될 수 있다. 여기서, 대표 어플리케이션은 통합 아이디로 로그인 되어 있는 어플리케이션으로 통합 아이디로의 로그인이 필요한 서비스 어플리케이션과의 신뢰관계 획득을 위해 이용될 수 있으며, 복수의 어플리케이션 간의 신뢰관계 획득을 위하여 통합 아이디 및 인증을 담당하는 통합 아이디 관리장치로부터 제공되는 신뢰성 토큰이 적용될 수 있다.
이하, 본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 시스템에 대하여 설명한다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 획득 시스템을 설명하기로 한다. 이때, 통합 인증 장치는 대표 어플리케이션에 대한 로그인 정보(아이디, 비밀번호 등), 사용자 정보 등을 기 저장하고 있을 수 있다.
또한, 본 발명의 실시 예에 따른 어플리케이션은 모바일 어플리케이션을 대표적인 예로 설명하기만, 어플리케이션은 모바일 어플리케이션에 한정된 것이 아니고, 인터넷의 홈페이지 소스에 삽입되는 자바(Java)로 만든 통신 프로그램인 애플릿(Applet)도 어플리케이션이 될 수 있다.
또한, 본 발명에 따른 어플리케이션 인증을 위한 로그인 방법으로 아이디(ID)와 비밀번호를 대표적인 예로 설명하지만, 로그인 방법은 이에 한정된 것이 아니고, 공인인증 방법, 아이핀 등을 이용한 로그인 방법도 적용될 수 있다.
도 1은 본 발명의 실시 예에 따른 어플리케이션을 이용한 인증 시스템의 구성을 나타내는 도면이다.
도 1을 참조하면, 본 발명에 따른 어플리케이션을 이용한 인증 시스템(100)은 단말기(10), 통합 인증 장치(20), 서비스 제공 장치(30) 및 통신망(40)으로 구성된다.
통신망(40)은 단말기(10) 및 통합 인증 장치(20) 사이의 데이터 전송 및 정보 교환을 위한 일련의 데이터 송수신 동작을 수행한다. 특히, 통신망(40)은 다양한 형태의 통신망이 이용될 수 있으며, 예컨대, 무선랜(WLAN, Wireless LAN), 와이파이(Wi-Fi), 와이브로(Wibro), 와이맥스(Wimax), 고속하향패킷접속(HSDPA, High Speed Downlink Packet Access) 등의 무선 통신방식 또는 이더넷(Ethernet), xDSL(ADSL, VDSL), HFC(Hybrid Fiber Coax), FTTC(Fiber to The Curb), FTTH(Fiber To The Home) 등의 유선 통신방식이 이용될 수 있다. 한편, 통신망(40)은 상기에 제시된 통신방식에 한정되는 것은 아니며, 상술한 통신 방식 이외에도 기타 널리 공지되었거나 향후 개발될 모든 형태의 통신 방식을 포함할 수 있다.
단말기(10)는 통신망(40)을 통해 통합 인증 장치(20)와 연결되어 어플리케이션 간의 신뢰관계 획득을 위한 모든 데이터를 송수신한다. 특히, 단말기(10)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하고, 이벤트 발생에 따라 통합 인증 장치(20)로 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청한다.
단말기(10)는 통합 인증 장치(20)로부터 신뢰성 토큰이 수신되면, 서비스 어플리케이션의 구동을 위한 신뢰성 토큰의 확인을 서비스 제공 장치(30)로 요청한다. 그리고, 단말기(10)는 신뢰성 토큰의 확인 결과에 따라 서비스 제공 장치(30)를 통해 제공되는 서비스 어플리케이션을 구동하고, 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계를 구축한다.
또한, 본 발명의 다른 실시 예에 따른 단말기(10)는 통신망(40)을 통해 통합 인증 장치(20)와 연결되어 통합 ID를 이용한 어플리케이션 인증을 수행하기 위한 모든 데이터를 송수신한다. 특히, 단말기(10)는 특정 서비스 어플리케이션으로부터의 로그인 요청에 따라서 대표 어플리케이션을 실행하고, 대표 어플리케이션을 통하여 사용자의 인증 정보 및 특정 서비스 어플리케이션에 대응하는 서비스 식별 정보를 통합 인증 장치(20)로 전송하여 인증을 요청한다.
단말기(10)는 요청에 대응하여 통합 인증 장치(20)로부터 인증 토큰 및 신뢰성 토큰을 수신하고, 해당 서비스 제공 장치(30)가 신뢰성 토큰을 이용하여 인증 여부를 확인할 수 있도록 특정 서비스 어플리케이션의 신뢰성 토큰을 서비스 제공 장치(30)로 전송한다.
통합 인증 장치(20)는 단말기(10)의 요청에 따라 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신한다. 그리고, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하고, 생성된 신뢰성 토큰을 단말기(10)로 전송한다.
이후, 통합 인증 장치(20)는 서비스 제공 장치로부터 신뢰성 토큰의 확인을 요청하는 신호가 수신되면, 신뢰성 토큰을 확인한 후, 확인 결과를 서비스 제공 장치(30)로 전송한다.
본 발명에 따르면, 대표 어플리케이션을 참조하여 서비스 어플리케이션의 계정 등록을 수행하는 모바일 환경에서도 SSO 인증 방식이 적용될 수 있다. 여기서, SSO(Single Sign On) 인증방식은 기본 인증방식, ID 연합(Federation) 인증방식, Assertion 인증방식으로 구분된다.
첫째로, 기본 인증방식은 주로 신규로 시스템을 구축하는 경우나, 사용자 정보를 통합하는 경우에 많이 사용된다. 따라서, 통합 인증 정보 및 통합 로그인 페이지를 중앙 인증 서버에 포함한다. 둘째로, ID 연합 인증방식은 서비스 제공자들 별로 인증정보 관리서버가 존재하여 기존 사용중인 사용자 정보를 그대로 이용하기 위해 사용된다. 따라서, 통합 인증정보 관리서버에는 통합 인증정보가 존재하기 않으며, 다만, 로그인 여부를 중앙 관리하기 위하여 로그인 여부를 알 수 있는 인증 정보 맵(Map)을 가지고 있다. 셋째로, Assertion 인증 방식은 기존 서비스 제공자에 사용중인 인증정보와 통합 인증정보를 같이 사용할 경우에 적합한 방식으로서, 로그인 페이지를 서비스 제공자가 가지고 있으며, 서비스 제공자에서 로그인 처리 후에 중앙 인증 서버로 강제 로그인 처리를 한다. 이때, 인증 정보가 공존하므로, 인증정보 동기화 작업도 필요하다.
또한, 본 발명의 다른 실시 예에 따른 통합 인증 장치(20)는 단말기(10)의 요청에 따라 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 수행하고, 통합 ID를 이용한 어플리케이션 인증을 위한 데이터를 송수신한다. 특히, 통합 인증 장치(20)는 단말기(10)에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 위한 인증 토큰을 생성한다. 또한, 통합 인증 장치(20)는 사용자 인증을 위한 인증 토큰이 수신되면 인증 토큰을 확인하여 사용자 검증을 수행하고, 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하여 해당 단말기(10)로 제공한다.
통합 인증 장치(20)는 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치(30)로부터 토큰 확인이 요청되면, 서비스 제공 장치(30)로부터 제공된 신뢰성 토큰을 검증하여, 신뢰성 토큰에 대한 검증 결과를 서비스 제공 장치(30)로 제공한다.
또한, 본 발명에 따른 단말기(10)나 통합 인증 장치(20)에 탑재되는 프로세서는 본 발명에 따른 방법을 실행하기 위한 프로그램 명령을 처리할 수 있다. 일 구현 예에서, 이 프로세서는 싱글 쓰레드(Single-threaded) 프로세서일 수 있으며, 다른 구현 예에서 본 프로세서는 멀티 쓰레드(Multi-threaded) 프로세서일 수 있다. 나아가 본 프로세서는 메모리 혹은 저장 장치 상에 저장된 명령을 처리하는 것이 가능하다.
도 2는 본 발명에 따른 단말기의 구성을 나타내는 블록도 이다.
도 2를 참조하면, 본 발명에 따른 단말기(10)는 제어부(11), 입력부(12), 표시부(13), 저장부(14) 및 통신부(15)를 포함한다. 여기서, 제어부(11)는 어플리케이션 실행모듈(11a)과 신뢰관계 획득모듈(11b)을 포함하고, 저장부(14)는 대표 어플리케이션(14a)과 다수의 서비스 어플리케이션(14b)를 포함한다.
입력부(12)는 숫자 및 문자 정보 등의 다양한 정보를 입력 받고, 각종 기능을 설정 및 단말기(10)의 기능 제어와 관련하여 입력되는 신호를 제어부(11)로 전달한다. 또한, 입력부(12)는 사용자의 터치 또는 조작에 따른 입력 신호를 발생하는 키패드와 터치패드 중 적어도 하나를 포함하여 구성될 수 있다. 이때, 입력부(12)는 표시부(13)와 함께 하나의 터치패널(또는 터치스크린(touch screen))의 형태로 구성되어 입력과 표시 기능을 동시에 수행할 수 있다. 또한, 입력부(12)는 키보드, 키패드, 마우스, 조이스틱 등과 같은 입력 장치 외에도 향후 개발될 수 있는 모든 형태의 입력 수단이 사용될 수 있다.
표시부(13)는 단말기(10)의 기능 수행 중에 발생하는 일련의 동작상태 및 동작결과 등에 대한 정보를 표시한다. 또한, 표시부(13)는 단말기(10)의 메뉴 및 사용자가 입력한 사용자 데이터 등을 표시할 수 있다. 여기서, 표시부(13)는 액정표시장치(LCD, Liquid Crystal Display), 초박막 액정표시장치(TFT-LCD, Thin Film Transistor LCD), 발광다이오드(LED, Light Emitting Diode), 유기 발광다이오드(OLED, Organic LED), 능동형 유기발광다이오드(AMOLED, Active Matrix OLED), 레티나 디스플레이(Retina Display), 플렉시블 디스플레이(Flexible display) 및 3차원(3 Dimension) 디스플레이 등으로 구성될 수 있다. 이때, 표시부(13)가 터치스크린(Touch screen) 형태로 구성된 경우, 표시부(13)는 입력부(12)의 기능 중 일부 또는 전부를 수행할 수 있다.
저장부(14)는 데이터를 저장하기 위한 장치로, 주 기억 장치 및 보조 기억 장치를 포함하고, 단말기(10)의 기능 동작에 필요한 응용 프로그램을 저장한다. 이러한 저장부(14)는 크게 프로그램 영역과 데이터 영역을 포함할 수 있다. 여기서, 단말기(10)는 사용자의 요청에 상응하여 각 기능을 활성화하는 경우, 제어부(11)의 제어 하에 해당 응용 프로그램들을 실행하여 각 기능을 제공하게 된다. 특히, 본 발명에 따른 저장부(14)는 단말기(10)를 부팅시키는 운영체제, 어플리케이션을 실행하는 프로그램, 복수의 어플리케이션 간의 신뢰관계를 획득하는 프로그램, 통합 ID를 이용하여 어플리케이션 인증을 수행하는 프로그램 등을 저장한다. 또한, 저장부(14)는 다양한 종류의 어플리케이션이 어플리케이션이 저장되며, 상기 어플리케이션들은 대표 어플리케이션(14a) 및 다수의 서비스 어플리케이션(14b)으로 구분될 수 있다.
통신부(15)는 통합 인증 장치(20) 및 서비스 제공 장치(30)와 통신망(40)을 통해 데이터를 송수신하기 위한 기능을 수행한다. 여기서, 통신부(15)는 송신되는 신호의 주파수를 상승 변환 및 증폭하는 RF 송신 수단과 수신되는 신호를 저잡음 증폭하고 주파수를 하강 변환하는 RF 수신 수단 등을 포함한다. 이러한 통신부(15)는 무선통신 모듈(미도시) 및 유선통신 모듈(미도시) 중 적어도 하나를 포함할 수 있다. 그리고, 무선통신 모듈은 무선 통신 방법에 따라 데이터를 송수신하기 위한 구성이며, 단말기(10)가 무선 통신을 이용하는 경우, 무선망 통신 모듈, 무선랜 통신 모듈 및 무선팬 통신 모듈 중 어느 하나를 이용하여 데이터를 통합 인증 장치(20)로 송수신할 수 있다. 또한, 유선통신 모듈은 유선으로 데이터를 송수신하기 위한 것이다. 유선통신 모듈은 유선을 통해 통신망(40)에 접속하여, 통합 인증 장치(20)에 데이터를 송수신할 수 있다. 즉, 단말기(10)는 무선통신 모듈 또는 유선통신 모듈을 이용하여 통신망(40)에 접속하며, 통신망(40)을 통해 통합 인증 장치(20)와 데이터를 송수신할 수 있다. 특히, 본 발명에 따른 통신부(15)는 통합 인증 장치(20) 및 서비스 제공 장치(30)와 통신하여 복수의 어플리케이션 간의 신뢰관계 획득을 위한 데이터를 송수신한다. 또한, 통신부(15)는 통합 인증 장치(20) 및 서비스 제공 장치(30)와 통신하여 통합 ID를 적용하여 대표 어플리케이션을 이용한 통합 인증과 관련된 데이터를 송수신한다.
제어부(11)는 운영 체제(OS, Operation System) 및 각 구성을 구동시키는 프로세스 장치가 될 수 있다. 특히, 본 발명에 따른 제어부(11)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지한다. 이때, 제어부(11)는 서비스 어플리케이션으로부터 대표 어플리케이션과의 신뢰성 획득과 관련된 이벤트 발생을 감지하고, 이벤트 발생에 따라 대표 어플리케이션으로 서비스 어플리케이션과의 신뢰관계 획득을 요청한다.
제어부(11)는 이벤트 발생에 따라 통합 인증 장치(20)로 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청한다. 그리고, 제어부(11)는 통합 인증 장치(20)로부터 신뢰성 토큰이 수신되면, 서비스 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 요청한다. 여기서, 신뢰성 토큰은 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위해 통합 인증 장치(30)에서 발급되는 일회용 토큰으로서, 통합 인증 장치(20)에서 서비스 제공 장치(30)의 요청에 따라 수행되는 토큰 확인 후에 폐기된다.
제어부(11)는 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치(30)를 통해 제공되는 서비스 어플리케이션을 구동하고, 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰 관계를 구축한다. 이때, 제어부(11)는 대표 어플리케이션을 통해 모바일 환경에서 서비스 어플리케이션과의 신뢰관계를 구축하고, 서비스 어플리케이션의 인증을 위한 인증방식을 적용할 수 있다.
또한, 본 발명의 다른 실시 예에 따른 제어부(11)는 특정 서비스 어플리케이션의 로그인 이벤트를 감지한다. 로그인 이벤트가 감지되면, 제어부(11)는 대표 어플리케이션이 특정 서비스 어플리케이션의 서비스 식별 정보를 통합 인증 장치(20)로 전송하여 로그인을 요청하는 신호를 감지한다. 이때, 제어부(11)는 대표 어플리케이션의 로그인 여부를 확인한다. 만약, 대표 어플리케이션이 로그인 되지 않은 경우, 제어부(11)는 대표 어플리케이션의 로그인을 위한 사용자 ID 및 비밀번호를 입력 받는다. 그리고, 제어부(11)는 특정 서비스 어플리케이션의 서비스 식별 정보와 함께, 입력된 사용자 ID 및 비밀번호를 통합 인증 장치(20)로 전송하여, 로그인을 요청한다.
한편, 대표 어플리케이션이 로그인 된 경우, 제어부(11)는 서비스 식별 정보와 함께 대표 어플리케이션이 기 수신한 인증 토큰을 통합 인증 장치(20)로 전송하여, 로그인을 요청한다. 이때, 인증 토큰은 단말기(10)의 로그인 시에만 재 생성되고, 로그인 결과 값이 저장되는 토큰이다.
제어부(11)는 로그인 요청에 따라 대표 어플리케이션이 통합 인증 장치(20)로부터 서비스 식별 정보에 대응하여 생성된 신뢰성 토큰을 포함하는 로그인 결과 정보를 수신한다. 여기서, 로그인 결과 정보는 사용자 ID 및 비밀번호의 인증에 따라서 생성되는 인증 토큰을 포함한다. 또한, 신뢰성 토큰은 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위해 통합 인증 장치(20)에서 발급되는 일회용 토큰으로서, 통합 인증 장치(20)에서 서비스 제공 장치의 요청에 따라 수행되는 토큰 확인 후에 폐기되는 토큰이다.
제어부(11)는 대표 어플리케이션이 신뢰성 토큰을 특정 서비스 어플리케이션으로 제공하는 신호를 감지한다. 즉, 특정 서비스 어플리케이션이 신뢰성 토큰을 서비스 제공 장치(30)로 제공하여 신뢰성 확인을 요청한다. 그리고, 신뢰성 확인 결과에 따라서, 특정 서비스 어플리케이션이 실행된다.
이와 같은 단말기(10)의 기능을 보다 효과적으로 수행하기 위하여, 제어부(11)는 어플리케이션 실행모듈(11a)과, 신뢰관계 획득모듈(11b)을 포함한다. 특히, 어플리케이션 실행모듈(11a)은 다양한 종류의 어플리케이션의 실행과 관련된 기능을 수행한다. 이때, 어플리케이션 실행모듈(11a)은 통합 ID를 기반으로 대표 어플리케이션 또는 서비스 어플리케이션의 실행과 관련된 모든 기능을 수행한다. 또한, 어플리케이션 실행모듈(11a)은 다양한 종류의 어플리케이션의 실행과 관련된 기능을 수행한다. 이때, 어플리케이션 실행모듈(11a)은 통합 ID를 기반으로 대표 어플리케이션 또는 서비스 어플리케이션의 실행과 관련된 모든 기능을 수행한다.
또한, 신뢰관계 획득모듈(11b)은 복수의 어플리케이션(대표 어플리케이션 및 서비스 어플리케이션) 간의 신뢰관계 획득을 위한 기능을 수행한다. 즉, 신뢰관계 획득모듈(11b)은 통합 인증 장치(20)로부터 수신되는 신뢰성 토큰을 이용하여 어플리케이션들 간의 신뢰관계 획득을 구축한다.
도 3은 본 발명에 따른 통합 인증 장치의 구성을 나타내는 블록도 이다.
도 3을 참조하면, 본 발명에 따른 통합 인증 장치(20)는 신뢰성 토큰 생성부(21a), 신뢰성 토큰 확인부(21b) 및 통합 ID 관리부(21c), 서비스저장부(22) 및 서비스통신부(23)로 구성된다. 여기서, 서비스저장부(22)는 통합 ID 정보(22a), 토큰 정보(22b) 및 통합 인증 정보(22c)를 포함한다. 특히, 본 발명의 신뢰성 토큰 생성부(21a), 신뢰성 토큰 확인부(21b), 통합 ID 관리부(21c), 사용자 인증부(21d) 및 신뢰성 인증부(21e)는 각각의 장치로서 독립적으로 모듈로 구성되어, 어플리케이션 간의 신뢰관계 획득을 위한 통합 인증 장치(20)의 기능을 수행할 수 있다.
서비스통신부(23)는 단말기(10) 및 서비스 제공 장치(30)와 통신하여 복수의 어플리케이션 간의 신뢰관계 획득을 위한 데이터를 송수신한다. 또한, 서비스통신부(23)는 단말기(10) 및 서비스 제공 장치(30)와 통신하여 복수의 어플리케이션 간의 통합 ID를 적용하고, 대표 어플리케이션을 이용한 통합 인증과 관련된 데이터를 송수신한다.
서비스저장부(22)는 통합 인증 장치(20)의 기능을 수행하기 위한 프로그램 및 데이터가 저장된다. 특히, 서비스저장부(22)는 어플리케이션들 간의 신뢰관계 획득을 위해 신뢰성 토큰을 생성하는 프로그램, 신뢰성 토큰을 확인하는 프로그램, 통합 ID를 관리하는 프로그램 및 통합 ID를 이용한 어플리케이션 인증을 위한 인증 토큰을 생성하는 프로그램 등을 저장한다. 또한, 서비스저장부(22)는 어플리케이션들 간의 신뢰관계를 획득하여 통합 ID를 이용하기 위한 통합 ID 정보(22a)와, 신뢰관계 획득 시 이용되는 신뢰성 토큰이 저장되는 토큰 정보(22b)가 저장된다. 또한, 서비스저장부(22)는 어플리케이션들 간의 신뢰관계를 기반으로 통합 ID를 이용하기 위한 통합 인증 정보(22c)와, 통합 ID를 이용한 어플리케이션 인증에 적용되는 인증 토큰 및 신뢰성 토큰이 저장되는 토큰 정보(22b)를 포함한다.
신뢰성 토큰 생성부(21a)는 단말기(10)의 요청에 따라 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신한다. 그리고, 신뢰성 토큰 생성부(21a)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성한다. 이때, 신뢰성 토큰 생성부(21a)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성한다. 이후, 신뢰성 토큰 생성부(21a)는 생성된 신뢰성 토큰을 단말기(10)로 전송한다.
신뢰성 토큰 확인부(21b)는 서비스 제공 장치(30)로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되는지 판단한다. 신뢰성 토큰의 확인이 요청되면, 신뢰성 토큰 확인부(21b)는 수신된 신뢰성 토큰을 확인한다. 이때, 신뢰성 토큰 확인부(21b)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 신뢰성 토큰 확인부(21b)는 신뢰성 토큰의 확인 결과를 서비스 제공 장치(30)로 전송한다.
또한, 본 발명에 따른 통합 ID 관리부(21c)은 어플리케이션들 간의 ID를 통합하여 관리하기 위한 기능을 수행한다. 이를 위해, 통합 ID 관리부(21c)은 SSO 인증 방식을 적용할 수 있다. 이에 따라, 본 발명은 모바일 환경의 SSO에도 동일하게 적용될 수 있다.
사용자 인증부(21d)는 단말기(10)에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 위한 토큰을 생성하거나, 사용자 인증을 위한 토큰이 수신되면 토큰을 확인하여 사용자 검증을 수행한다. 이때, 사용자 인증부(21d)는 사용자 별 통합 ID 및 사용자 별로 생성된 인증 토큰을 저장한다.
특히, 사용자 인증부(21d)는 대표 어플리케이션이 로그인 된 경우, 서비스 식별 정보와 함께 대표 어플리케이션이 기 수신한 인증 토큰을 단말기(10)로부터 수신한다. 한편, 사용자 인증부(21d)는 대표 어플리케이션이 로그인 되지 않은 경우, 서비스 어플리케이션의 서비스 식별 정보와 함께, 대표 어플리케이션을 로그인하기 위한 사용자 ID 및 비밀번호를 단말기(10)로부터 수신한다.
사용자 인증부(21d)는 대표 어플리케이션에 대한 인증을 위한 토큰을 생성한다. 이때, 사용자 인증부(21d)는 단말기(10)의 로그인 시에만 재 생성되고, 로그인 결과 값을 저장하는 인증 토큰을 생성한다.
사용자 인증부(21d)는 단말기(10)의 요청에 따라 통합 ID를 이용하며, 서비스 어플리케이션을 로그인하기 위하여 대표 어플리케이션의 로그인 상태 확인을 요청하는 신호에 따라 생성된 토큰을 기반으로 로그인 결과를 확인하고, 확인된 결과를 단말기(10)로 전송한다.
사용자 인증부(21d)는 어플리케이션들 간의 ID를 통합하여 관리하기 위한 기능을 수행한다. 이를 위해, 사용자 인증부(21d)는 SSO 인증 방식을 적용할 수 있다. 이에 따라, 본 발명은 모바일 환경의 SSO에도 동일하게 적용될 수 있다.
신뢰성 인증부(21e)는 사용자 인증부(21d)를 통해 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 토큰을 생성하여 해당 단말기(10)로 제공한다.
신뢰성 인증부(21e)는 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치(30)로부터 토큰 확인이 요청되면, 서비스 제공 장치(30)로부터 제공된 토큰을 검증하여, 검증된 토큰에 대한 검증 결과를 서비스 제공 장치(30)로 제공한다.
신뢰성 인증부(21e)는 단말기(10)의 요청에 따라 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신한다. 그리고, 신뢰성 인증부(21e)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 신뢰성 토큰을 생성한다. 이때, 신뢰성 인증부(21e)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰을 생성한다. 이후, 신뢰성 인증부(21e)는 생성된 신뢰성 토큰을 단말기(10)로 전송한다.
신뢰성 인증부(21e)는 서비스 제공 장치(30)로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되는지 판단한다. 신뢰성 토큰의 확인이 요청되면, 신뢰성 인증부(21e)는 수신된 신뢰성 토큰을 확인한다. 이때, 신뢰성 인증부(21e)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 신뢰성 인증부(21e)는 신뢰성 토큰의 확인 결과를 서비스 제공 장치(30)로 전송한다.
또한, 상술한 바와 같이 구성되는 통합 인증 장치(20)는 서버 기반 컴퓨팅 기반 방식 또는 클라우드 방식으로 동작하는 하나 이상의 서버로 구현될 수 있다. 특히, 클라우드 컴퓨팅 장치를 이용하여 어플리케이션 간의 신뢰관계 획득을 위한 데이터는 인터넷 상의 클라우드 컴퓨팅 장치에 영구적으로 저장될 수 있는 클라우드 컴퓨팅(Cloud Computing) 기능을 통해 제공될 수 있다. 여기서, 클라우드 컴퓨팅은 데스크톱, 태블릿 컴퓨터, 노트북, 넷북 및 스마트폰 등의 디지털 단말기에 인터넷 기술을 활용하여 가상화된 IT(Information Technology) 자원, 예를 들어, 하드웨어(서버, 스토리지, 네트워크 등), 소프트웨어(데이터베이스, 보안, 웹 서버 등), 서비스, 데이터 등을 온 디맨드(On demand) 방식으로 서비스하는 기술을 의미한다.
도 4는 본 발명에 따른 어플리케이션 간의 신뢰관계 획득 과정을 설명하기 위한 데이터 흐름도이다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치(20) 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 구축 과정을 설명하기로 한다.
도 4를 참조하면, 본 발명에 따른 어플리케이션 간의 신뢰관계 획득을 위하여 단말기(10)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지한다. 즉, 단말기(10)는 S11 단계에서 서비스 어플리케이션으로부터 대표 어플리케이션과의 신뢰성 획득과 관련된 이벤트 발생을 감지한다. 그리고, 단말기(10)는 S13 단계에서 이벤트 발생에 따라 대표 어플리케이션으로 서비스 어플리케이션과의 신뢰관계 획득을 요청한다.
단말기(10)는 S15 단계에서 이벤트 발생에 따라 통합 인증 장치(30)로 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청한다. 신뢰성 확인을 요청하는 신호에 따라 통합 인증 장치(20)는 S17 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성한다. 이때, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성한다. 그리고 나서, 통합 인증 장치(20)는 S19 단계에서 생성된 신뢰성 토큰을 단말기(10)로 전송한다.
단말기(10)는 S21 단계에서 서비스 어플리케이션 구동을 위하여 대표 어플리케이션을 통해 통합 인증 장치(20)로부터 수신된 신뢰성 토큰을 서비스 어플리케이션으로 전달한다. 즉, 단말기(10)는 상기 S15 단계의 신뢰성 확인 요청에 대한 응답으로 수신되는 신뢰성 토큰을 서비스 제공 장치(30)로 전달한다. 그리고, 단말기(10)는 S23 단계에서 서비스 어플리케이션을 통해 서비스 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 전달한다.
서비스 제공 장치(30)는 S25 단계에서 신뢰성 토큰 확인을 통합 인증 장치(20)로 요청한다. 그리고, 통합 인증 장치(20)는 S27 단계에서 서비스 제공 장치(30)로부터 전송되는 신뢰성 토큰 확인을 요청하는 신호에 따라 신뢰성 토큰을 확인한다. 이때, 통합 인증 장치(20)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 통합 인증 장치(20)는 S29 단계에서 신뢰성 토큰의 확인 결과를 서비스 제공 장치(30)로 전송한다.
서비스 제공 장치(30)는 S31 단계에서 단말기(10)의 서비스 어플리케이션을 구동하고, 해당 서비스를 수행한다. 즉, 단말기(10)는 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치(30)를 통해 제공되는 서비스 어플리케이션을 구동한다.
이에 따라, 단말기(10)는 S33 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰 관계를 구축한다.
도 5는 본 발명에 따른 대표 어플리케이션을 이용한 통합 인증 과정을 설명하기 위한 데이터 흐름도이다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치(20) 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 구축 과정을 설명하기로 한다.
도 5를 참조하면, 본 발명에 따른 통합 ID를 이용한 어플리케이션 인증을 위하여 단말기(10)는 통합 ID로 로그인 하기 위한 이벤트 발생을 감지하고, 대표 어플리케이션의 로그인 확인을 요청한다(S41 내지 S43). 즉, 단말기(10)는 통합 ID를 이용하며, 대표 어플리케이션의 로그인 상태에 따라 서비스 어플리케이션을 로그인하기 위한 이벤트를 감지한다.
단말기(10)는 S45 단계에서 이벤트 발생에 따라 대표 어플리케이션의 로그인 여부를 확인한다. 여기서, 대표 어플리케이션이 로그인 되어 있는 경우, 단말기(10)는 S47 단계에서 통합 인증 장치(20)로 대표 어플리케이션의 로그인 상태 확인을 요청하기 위하여 인증 토큰 및 서비스 식별정보를 전송한다.
통합 인증 장치(20)는 S49 단계에서 단말기(10)에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 인증 토큰 검증과정을 통해 사용자 인증을 수행한다. 그리고, 통합 인증 장치(20)는 S51 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 신뢰성 토큰을 생성한다. 여기서, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰을 생성한다.
통합 인증 장치(20)는 S53 단계에서 생성된 토큰을 기반으로 로그인 결과를 확인한다. 그리고, 통합 인증 장치(20)는 S55 단계에서 확인된 로그인 결과 및 신뢰성 토큰을 단말기(10)로 전송한다.
단말기(10)는 대표 어플리케이션의 로그인 결과 및 신뢰성 토큰이 수신되면, S57 서비스 어플리케이션 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 전달한다. 즉, 단말기(10)는 통합 인증 장치(20)로부터 로그인 결과가 수신되면, S59 단계에서 서비스 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 요청한다.
서비스 제공 장치(30)는 S61 단계에서 신뢰성 토큰 확인을 통합 인증 장치(20)로 요청한다. 그리고, 통합 인증 장치(20)는 S63 단계에서 서비스 제공 장치(30)로부터 전송되는 신뢰성 토큰 확인을 요청하는 신호에 따라 신뢰성 토큰을 확인한다. 이때, 통합 인증 장치(20)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 통합 인증 장치(20)는 S65 단계에서 토큰의 확인 결과를 서비스 제공 장치(30)로 전송한다.
서비스 제공 장치(30)는 S67 단계에서 단말기(10)의 서비스 어플리케이션을 구동하고, 해당 서비스를 수행한다. 즉, 단말기(10)는 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치(30)를 통해 제공되는 서비스 어플리케이션을 구동한다.
도 6은 본 발명의 다른 실시 예에 따른 대표 어플리케이션을 이용한 통합 인증 과정을 설명하기 위한 데이터 흐름도이다.
도 6을 참조하면, 본 발명에 따른 통합 ID를 이용한 어플리케이션 인증을 위하여 단말기(10)는 통합 ID로 로그인 하기 위한 이벤트 발생을 감지하고, 대표 어플리케이션의 로그인 확인을 요청한다(S71 내지 S73). 즉, 단말기(10)는 통합 ID를 이용하며, 대표 어플리케이션의 로그인 상태에 따라 서비스 어플리케이션을 로그인하기 위한 이벤트를 감지한다. 이후, 단말기(10)는 이벤트 발생에 따라 대표 어플리케이션의 로그인 여부를 확인한다.
대표 어플리케이션이 로그인 되어 있지 않은 경우, 단말기(10)는 S75 단계에서 대표 어플리케이션의 로그인을 위한 사용자 ID 및 비밀번호를 입력 받는다. 그리고, 단말기(10)는 S77 단계에서 통합 인증 장치(20)로 대표 어플리케이션의 로그인 상태 확인을 요청하기 위하여 입력된 사용자 ID, 비밀번호 및 서비스 식별정보를 전송한다.
통합 인증 장치(20)는 S79 단계에서 단말기(10)에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 인증 토큰을 생성한다. 즉, 통합 인증 장치(20)는 사용자 아이디 및 비밀번호를 이용하여 통합 ID를 적용할 수 있는 인증 토큰을 생성한다. 그리고, 단말기(10)는 사용자 별 통합 ID 및 사용자 별로 생성된 인증 토큰을 저장한다.
통합 인증 장치(20)는 S81 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 신뢰성 토큰을 생성한다. 여기서, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰을 생성한다. 그리고, 통합 인증 장치(20)는 S83 단계에서 생성된 토큰을 기반으로 로그인 결과를 확인한다. 이후, 통합 인증 장치(20)는 S85 단계에서 확인된 로그인 결과, 인증 토큰 및 신뢰성 토큰을 단말기(10)로 전송한다.
단말기(10)는 대표 어플리케이션의 로그인 결과, 인증 토큰 및 신뢰성 토큰이 수신되면, S87 서비스 어플리케이션 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 전달한다. 즉, 단말기(10)는 통합 인증 장치(20)로부터 로그인 결과가 수신되면, S89 단계에서 서비스 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 요청한다.
서비스 제공 장치(30)는 S91 단계에서 신뢰성 토큰 확인을 통합 인증 장치(20)로 요청한다. 그리고, 통합 인증 장치(20)는 S93 단계에서 서비스 제공 장치(30)로부터 전송되는 신뢰성 토큰 확인을 요청하는 신호에 따라 신뢰성 토큰을 확인한다. 이때, 통합 인증 장치(20)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 통합 인증 장치(20)는 S95 단계에서 토큰의 확인 결과를 서비스 제공 장치(30)로 전송한다.
서비스 제공 장치(30)는 S97 단계에서 단말기(10)의 서비스 어플리케이션을 구동하고, 해당 서비스를 수행한다. 즉, 단말기(10)는 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치(30)를 통해 제공되는 서비스 어플리케이션을 구동한다.
도 7은 본 발명에 따른 단말기의 동작 방법을 설명하기 위한 흐름도이다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치(20) 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 구축을 위한 단말기(10)의 동작을 설명하기로 한다.
도 7을 참조하면, 본 발명에 따른 단말기(10)는 S101 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지한다. 여기서, 단말기(10)는 서비스 어플리케이션으로부터 대표 어플리케이션과의 신뢰성 획득과 관련된 이벤트 발생을 감지하고, 이벤트 발생에 따라 대표 어플리케이션으로 서비스 어플리케이션과의 신뢰관계 획득을 요청한다.
단말기(10)는 S103 단계에서 이벤트 발생에 따라 통합 인증 장치(30)로 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청한다. 그리고, 단말기(10)는 S105 단계에서 신뢰성 토큰이 수신되는지 판단한다. 신뢰성 토큰이 수신되면, 단말기(10)는 S107 단계에서 신뢰성 토큰 확인을 서비스 제공 장치(30)로 전달한다. 이후, 단말기(10)는 S109 단계에서 신뢰성 토큰 확인 결과에 따라 서비스 제공 장치(30)를 통해 제공되는 서비스 어플리케이션을 구동한다.
단말기(10)는 S111 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰 관계를 구축한다.
도 8은 본 발명에 따른 통합 인증 장치의 동작 방법을 설명하기 위한 흐름도이다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치(20) 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 구축을 위한 통합 인증 장치(20)의 동작을 설명하기로 한다.
도 8을 참조하면, 본 발명에 따른 통합 인증 장치(20)는 S121 단계에서 단말기(10)의 요청에 따라 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신한다.
통합 인증 장치(20)는 S123 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성한다. 이때, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성한다.
통합 인증 장치(20)는 S125 단계에서 생성된 신뢰성 토큰을 단말기(10)로 전송한다. 그리고, 통합 인증 장치(20)는 S127 단계에서 서비스 제공 장치(30)로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되는지 판단한다. 신뢰성 토큰의 확인이 요청되면, 통합 인증 장치(20)는 S129 단계에서 수신된 신뢰성 토큰을 확인한다. 이때, 통합 인증 장치(20)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 통합 인증 장치(20)는 S131 단계에서 신뢰성 토큰의 확인 결과를 서비스 제공 장치(30)로 전송한다.
본 발명에 따르면, 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 획득이 구축되면, 즉, 통합 아이디를 통해 대표 어플리케이션과 서비스 어플리케이션이 로그인 되는 경우, 다시 로그인 해야 하는 불편한 점이 없이 바로 서비스 이용이 가능하다.
도 9는 본 발명의 다른 실시 예에 따른 단말기의 동작 방법을 설명하기 위한 흐름도이다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치(20) 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 구축을 위한 단말기(10)의 동작을 설명하기로 한다.
도 9을 참조하면, 본 발명에 따른 단말기(10)는 S141 단계에서 통합 ID로 로그인 하기 위한 이벤트 발생을 감지한다. 그리고, 단말기(10)는 S143 단계에서 대표 어플리케이션의 로그인 여부를 확인한다. 즉, 단말기(10)는 통합 ID를 이용하며, 대표 어플리케이션의 로그인 상태에 따라 서비스 어플리케이션을 로그인하기 위한 이벤트를 감지한다.
대표 어플리케이션이 로그인 되어 있는 경우, 단말기(10)는 S145 단계에서 통합 인증 장치(20)로 대표 어플리케이션의 로그인 상태 확인을 요청하기 위하여 인증 토큰 및 서비스 식별정보를 전송한다.
그리고, 단말기(10)는 S147 단계에서 통합 인증 장치(20)로부터 대표 어플리케이션의 로그인 결과 및 신뢰성 토큰이 수신되는지 확인한다.
대표 어플리케이션의 로그인 결과 및 신뢰성 토큰이 수신되면, 단말기(10)는 S149 서비스 어플리케이션 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 전달한다. 이후, 단말기(10)는 S151 단계에서 신뢰성 토큰 확인 결과에 따라 서비스 어플리케이션을 구동하고, 해당 서비스를 수행한다. 이에 따라, 단말기(10)는 대표 어플리케이션을 통해 모바일 환경에서 서비스 어플리케이션과의 신뢰관계를 구축하고, 서비스 어플리케이션의 인증을 위한 인증방식을 적용할 수 있다.
도 10은 본 발명의 또 다른 실시 예에 따른 단말기의 동작 방법을 설명하기 위한 흐름도이다.
도 10을 참조하면, 본 발명의 다른 실시 예에 따른 대표 어플리케이션을 이용한 통합 인증 과정에서 대표 어플리케이션이 로그인 되어 있지 않는 경우, 단말기(10)는 S161 단계에서 대표 어플리케이션의 로그인을 위한 사용자 ID 및 비밀번호를 입력 받는다. 그리고, 단말기(10)는 S163 단계에서 통합 인증 장치(20)로 대표 어플리케이션의 로그인 상태 확인을 요청하기 위하여 입력된 사용자 ID, 비밀번호 및 서비스 식별정보를 전송한다.
이후, 단말기(10)는 S165 단계에서 통합 인증 장치(20)로부터 대표 어플리케이션의 로그인 결과, 인증 토큰 및 신뢰성 수신되는지 확인한다.
대표 어플리케이션의 로그인 결과, 인증 토큰 및 신뢰성 토큰이 수신되면, 단말기(10)는 서비스 어플리케이션 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치(30)로 전달한다. 그리고, 단말기(10)는 신뢰성 토큰 확인 결과에 따라 서비스 어플리케이션을 구동하고, 해당 서비스를 수행한다. 이에 따라, 단말기(10)는 대표 어플리케이션을 통해 모바일 환경에서 서비스 어플리케이션과의 신뢰관계를 구축하고, 서비스 어플리케이션의 인증을 위한 인증방식을 적용할 수 있다.
도 11은 본 발명의 다른 실시 예에 따른 통합 인증 장치의 동작 방법을 설명하기 위한 흐름도이다. 특히, 본 발명은 대표 어플리케이션과 통합 인증 장치(20) 간의 신뢰관계가 이미 구축되어 있다는 전제로 다음의 어플리케이션 간의 신뢰관계 구축을 위한 통합 인증 장치(20)의 동작을 설명하기로 한다.
도 11을 참조하면, 본 발명에 따른 통합 인증 장치(20)는 S171 단계에서 단말기(10)의 요청에 따라 통합 ID를 이용하며, 서비스 어플리케이션을 로그인하기 위하여 대표 어플리케이션의 로그인에 대한 인증 토큰 및 서비스 식별정보를 수신한다. 이때, 대표 어플리케이션은 로그인 되어 있는 경우를 가정하여 설명한다.
통합 인증 장치(20)는 S173 단계에서 대표 어플리케이션에 대한 인증을 위한 인증 토큰을 검증한다. 이에 따라, 통합 인증 장치(20)는 사용자 인증을 수행한다. 여기서, 통합 인증 장치(20)는 단말기(10)의 로그인 시에만 재 생성되며, 사용자 별 통합 ID 및 사용자 별로 생성된 토큰이다. 그리고, 통합 인증 장치(20)는 S175 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 신뢰성 토큰을 생성한다. 즉, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰을 생성한다. 신뢰성 토큰은 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰이다.
통합 인증 장치(20)는 S177 단계에서 생성된 토큰을 기반으로 로그인 결과를 확인한다. 그리고, 통합 인증 장치(20)는 S179 단계에서 확인된 로그인 결과 및 신뢰성 토큰을 단말기(10)로 전송한다.
통합 인증 장치(20)는 S181 단계에서 서비스 제공 장치(30)로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되는지 확인한다. 신뢰성 토큰 확인을 요청하는 신호가 수신되면, 통합 인증 장치(20)는 S183 단계에서 신뢰성 토큰 확인 요청에 따라 신뢰성 토큰을 확인한다. 이때, 통합 인증 장치(20)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 통합 인증 장치(20)는 S185 단계에서 신뢰성 토큰에 대한 확인 결과를 서비스 제공 장치(30)로 전송한다.
도 12는 본 발명의 또 다른 실시 예에 따른 통합 인증 장치의 동작 방법을 설명하기 위한 흐름도이다.
도 12를 참조하면, 본 발명에 따른 통합 인증 장치(20)는 S191 단계에서 단말기(10)의 요청에 따라 통합 ID를 이용하며, 서비스 어플리케이션을 로그인하기 위하여 대표 어플리케이션의 사용자 ID, 비밀번호 및 서비스 식별정보를 수신한다. 이때, 대표 어플리케이션은 로그인 되어 있지 않은 경우를 가정하여 설명한다.
통합 인증 장치(20)는 S193 단계에서 대표 어플리케이션에 대한 인증을 위한 인증 토큰을 생성한다. 이에 따라, 통합 인증 장치(20)는 사용자 인증을 수행한다. 여기서, 통합 인증 장치(20)는 단말기(10)의 로그인 시에만 재 생성되며, 사용자 별 통합 ID 및 사용자 별로 생성된 토큰이다. 그리고, 통합 인증 장치(20)는 S195 단계에서 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 신뢰성 토큰을 생성한다. 즉, 통합 인증 장치(20)는 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰을 생성한다. 신뢰성 토큰은 대표 어플리케이션과 서비스 어플리케이션 간의 신뢰관계 확인을 위한 일회용 토큰이다.
통합 인증 장치(20)는 S197 단계에서 생성된 토큰을 기반으로 로그인 결과를 확인한다. 그리고, 통합 인증 장치(20)는 S199 단계에서 확인된 로그인 결과, 인증 토큰 및 신뢰성 토큰을 단말기(10)로 전송한다.
통합 인증 장치(20)는 S201 단계에서 서비스 제공 장치(30)로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되는지 확인한다. 신뢰성 토큰 확인을 요청하는 신호가 수신되면, 통합 인증 장치(20)는 S203 단계에서 신뢰성 토큰 확인 요청에 따라 신뢰성 토큰을 확인한다. 이때, 통합 인증 장치(20)는 서비스 제공 장치(30)로부터 수신된 신뢰성 토큰을 확인하고, 확인된 신뢰성 토큰을 폐기한다. 그리고 나서, 통합 인증 장치(20)는 S205 단계에서 신뢰성 토큰에 대한 확인 결과를 서비스 제공 장치(30)로 전송한다.
한편, 단말기(10)나 통합 인증 장치(20)에 탑재되는 메모리는 그 장치 내에서 정보를 저장한다. 일 구현예의 경우, 메모리는 컴퓨터로 판독 가능한 매체이다. 일 구현 예에서, 메모리는 휘발성 메모리 유닛 일 수 있으며, 다른 구현예의 경우, 메모리는 비휘발성 메모리 유닛 일 수도 있다. 일 구현예의 경우, 저장장치는 컴퓨터로 판독 가능한 매체이다. 다양한 서로 다른 구현 예에서, 저장장치는 예컨대 하드디스크 장치, 광학디스크 장치, 혹은 어떤 다른 대용량 저장장치를 포함할 수도 있다.
비록 본 명세서와 도면에서는 예시적인 장치 구성을 기술하고 있지만, 본 명세서에서 설명하는 기능적인 동작과 주제의 구현물들은 다른 유형의 디지털 전자 회로로 구현되거나, 본 명세서에서 개시하는 구조 및 그 구조적인 등가물들을 포함하는 컴퓨터 소프트웨어, 펌웨어 혹은 하드웨어로 구현되거나, 이들 중 하나 이상의 결합으로 구현 가능하다. 본 명세서에서 설명하는 주제의 구현물들은 하나 이상의 컴퓨터 프로그램 제품, 다시 말해 본 발명에 따른 장치의 동작을 제어하기 위하여 혹은 이것에 의한 실행을 위하여 유형의 프로그램 저장매체 상에 인코딩된 컴퓨터 프로그램 명령에 관한 하나 이상의 모듈로서 구현될 수 있다. 컴퓨터로 판독 가능한 매체는 기계로 판독 가능한 저장 장치, 기계로 판독 가능한 저장 기판, 메모리 장치, 기계로 판독 가능한 전파형 신호에 영향을 미치는 물질의 조성물 혹은 이들 중 하나 이상의 조합일 수 있다.
컴퓨터 프로그램 명령어와 데이터를 저장하기에 적합한 컴퓨터로 판독 가능한 매체는, 예컨대 기록매체는 하드 디스크, 플로피 디스크 및 자기 테이프와 같은 자기 매체(Magnetic Media), CD-ROM(Compact Disk Read Only Memory), DVD(Digital Video Disk)와 같은 광 기록 매체(Optical Media), 플롭티컬 디스크(Floptical Disk)와 같은 자기-광 매체(Magneto-Optical Media), 및 롬(ROM, Read Only Memory), 램(RAM, Random Access Memory), 플래시 메모리, EPROM(Erasable Programmable ROM), EEPROM(Electrically Erasable Programmable ROM)과 같은 반도체 메모리를 포함한다. 프로세서와 메모리는 특수 목적의 논리 회로에 의해 보충되거나, 그것에 통합될 수 있다. 프로그램 명령의 예에는 컴파일러에 의해 만들어지는 것과 같은 기계어 코드뿐만 아니라 인터프리터 등을 사용해서 컴퓨터에 의해서 실행될 수 있는 고급 언어 코드를 포함할 수 있다. 이러한 하드웨어 장치는 본 발명의 동작을 수행하기 위해 하나 이상의 소프트웨어 모듈로서 작동하도록 구성될 수 있으며, 그 역도 마찬가지이다.
본 명세서는 다수의 특정한 구현물의 세부사항들을 포함하지만, 이들은 어떠한 발명이나 청구 가능한 것의 범위에 대해서도 제한적인 것으로서 이해되어서는 안되며, 오히려 특정한 발명의 특정한 실시형태에 특유할 수 있는 특징들에 대한 설명으로서 이해되어야 한다. 개별적인 실시형태의 문맥에서 본 명세서에 기술된 특정한 특징들은 단일 실시형태에서 조합하여 구현될 수도 있다. 반대로, 단일 실시형태의 문맥에서 기술한 다양한 특징들 역시 개별적으로 혹은 어떠한 적절한 하위 조합으로도 복수의 실시형태에서 구현 가능하다. 나아가, 특징들이 특정한 조합으로 동작하고 초기에 그와 같이 청구된 바와 같이 묘사될 수 있지만, 청구된 조합으로부터의 하나 이상의 특징들은 일부 경우에 그 조합으로부터 배제될 수 있으며, 그 청구된 조합은 하위 조합이나 하위 조합의 변형물로 변경될 수 있다.
마찬가지로, 특정한 순서로 도면에서 동작들을 묘사하고 있지만, 이는 바람직한 결과를 얻기 위하여 도시된 그 특정한 순서나 순차적인 순서대로 그러한 동작들을 수행하여야 한다거나 모든 도시된 동작들이 수행되어야 하는 것으로 이해되어서는 안 된다. 특정한 경우, 멀티태스킹과 병렬 프로세싱이 유리할 수 있다. 또한, 상술한 실시형태의 다양한 시스템 컴포넌트의 분리는 그러한 분리를 모든 실시형태에서 요구하는 것으로 이해되어서는 안되며, 설명한 프로그램 컴포넌트와 시스템들은 일반적으로 단일의 소프트웨어 제품으로 함께 통합되거나 다중 소프트웨어 제품에 패키징 될 수 있다는 점을 이해하여야 한다.
한편, 본 명세서와 도면에 개시된 본 발명의 실시 예들은 이해를 돕기 위해 특정 예를 제시한 것에 지나지 않으며, 본 발명의 범위를 한정하고자 하는 것은 아니다. 여기에 개시된 실시 예들 이외에도 본 발명의 기술적 사상에 바탕을 둔 다른 변형 예들이 실시 가능하다는 것은, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 자명한 것이다.
본 발명은 하나의 단말기에 설치된 복수의 어플리케이션 간의 신뢰관계를 획득하여 통합 아이디를 이용할 수 있거나, 하나의 단말기에 설치된 복수의 어플리케이션 중 대표 어플리케이션을 이용한 인증 정보를 공유하여 다른 어플리케이션의 인증을 수행할 수 있으며, 대표 어플리케이션을 참조하여 계정 등록을 하는 것을 의미하며, 이를 통해 모바일 환경에서도 SSO 인증 방식의 구현이 가능하다. 또한, 대표 어플리케이션을 통해 내부 브라우저 없이 어플리케이션 간 참조만으로 이를 실행할 수 있으며, 이는 다양한 운영체제의 제약을 받지 않는다. 또한, SSO 인증 방식을 통해 관리의 투명성과 신뢰성을 높이고, 비용을 절감하고, 효율성을 높일 수 있다. 즉, 사용자 아이디나 비밀번호 관리의 효율 증가, 별도 로그인 없이 다른 시스템 이용, 인증 지원, 관리자의 비밀번호 문의 감소, 사용자의 로그인/종료/재접속을 위한 재입력 감소, 사용자의 접속정보에 대한 리포팅 기능 제공 등이 가능하다. 또한, 어플리케이션들 간의 신뢰관계가 설정되어 있다는 가정하에, 대표 어플리케이션을 통해 하나의 디바이스 내에서 인증 정보를 공유할 수 있다. 이는 시판 또는 영업의 가능성이 충분할 뿐만 아니라 현실적으로 명백하게 실시할 수 있는 정도이므로 산업상 이용가능성이 있다.

Claims (33)

  1. 적어도 하나의 단말기 및 서비스 제공 장치와 통신하여 복수의 어플리케이션 간의 신뢰관계 획득을 위한 데이터를 송수신하는 서비스통신부;
    상기 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하고, 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하고, 상기 생성된 신뢰성 토큰을 상기 단말기로 전송하는 신뢰성 토큰 생성부; 및
    상기 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되면, 상기 신뢰성 토큰을 확인한 후, 확인 결과를 상기 서비스 제공 장치로 전송하는 신뢰성 토큰 확인부;
    를 포함하는 것을 특징으로 하는 통합 인증 장치.
  2. 제1항에 있어서,
    하나 이상의 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 위한 토큰을 생성하거나, 사용자 인증을 위한 토큰이 수신되면 상기 토큰을 확인하여 사용자 검증을 수행하는 사용자 인증부; 및
    상기 사용자 인증부를 통해 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 토큰을 생성하여 해당 단말기로 제공하고, 상기 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 토큰 확인이 요청되면, 상기 서비스 제공 장치로부터 제공된 토큰을 검증하여, 상기 검증된 토큰에 대한 검증 결과를 상기 서비스 제공 장치로 제공하는 신뢰성 인증부;
    를 더 포함하는 것을 특징으로 하는 통합 인증 장치.
  3. 제1항에 있어서, 상기 신뢰성 토큰 생성부는
    상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성하는 것을 특징으로 하는 통합 인증 장치.
  4. 제1항에 있어서, 상기 신뢰성 토큰 확인부는
    상기 서비스 제공 장치로부터 수신된 신뢰성 토큰을 확인하고, 상기 확인된 신뢰성 토큰을 폐기하는 것을 특징으로 하는 통합 인증 장치.
  5. 제1항에 있어서,
    다수의 어플리케이션들 간의 ID를 통합하여 관리하는 통합 ID 관리부;
    를 더 포함하는 것을 특징으로 하는 통합 인증 장치.
  6. 제2항에 있어서, 상기 사용자 인증부는
    사용자 별 통합 ID 및 상기 사용자 별로 생성된 인증 토큰을 저장하는 것을 특징으로 하는 통합 인증 장치.
  7. 제2항에 있어서, 상기 신뢰성 인증부는
    상기 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 저장하고, 한번 검증된 신뢰성 토큰을 삭제하는 것을 특징으로 하는 통합 인증 장치.
  8. 통합 인증 장치 및 서비스 제공 장치와 통신하여 복수의 어플리케이션 간의 신뢰관계 획득을 위한 데이터를 송수신하는 통신부; 및
    제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하고, 상기 이벤트 발생에 따라 상기 통합 인증 장치로 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하고, 상기 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 상기 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하고, 신뢰성 토큰 확인 결과에 따라 상기 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하고, 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하도록 제어하는 제어부;
    를 포함하는 것을 특징으로 하는 단말기.
  9. 제8항에 있어서,
    통합 인증을 위한 대표 어플리케이션 및 하나 이상의 서비스 어플리케이션을 저장하는 저장부;
    를 더 포함하는 것을 특징으로 하는 단말기.
  10. 제8항에 있어서, 상기 제어부는
    특정 서비스 어플리케이션으로부터의 로그인 요청에 따라서 상기 대표 어플리케이션을 실행하여, 상기 대표 어플리케이션을 통하여 사용자의 인증 정보 및 상기 특정 서비스 어플리케이션에 대응하는 서비스 식별 정보를 상기 통합 인증 장치로 전송하여 인증을 요청하고, 상기 요청에 대응하여 통합 인증 장치로부터 인증 토큰 및 신뢰성 토큰을 수신하고, 해당 서비스 제공 장치가 상기 신뢰성 토큰을 이용하여 인증 여부를 확인할 수 있도록 특정 서비스 어플리케이션이 상기 신뢰성 토큰을 서비스 제공 장치로 전송하는 것을 특징으로 하는 단말기.
  11. 제10항에 있어서, 상기 대표 어플리케이션은
    다수의 서비스 어플리케이션 중 하나 인 것을 특징으로 하는 단말기.
  12. 제10항에 있어서, 상기 제어부는
    상기 대표 어플리케이션이 로그인 상태인 경우, 기 수신된 인증 토큰 및 상기 특정 서비스 어플리케이션의 서비스 식별 정보를 상기 통합 인증 장치로 전송하여 인증 검증을 요청하고, 통합 인증 장치로부터 인증 결과 및 신뢰성 토큰만을 수신하도록 제어하는 것을 특징으로 하는 단말기.
  13. 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하고, 상기 이벤트 발생에 따라 상기 통합 인증 장치로 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하고, 상기 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 상기 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하고, 신뢰성 토큰 확인에 따라 상기 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하고, 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하는 단말기; 및
    상기 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하고, 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하고, 상기 생성된 신뢰성 토큰을 상기 단말기로 전송하고, 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호가 수신되면, 상기 신뢰성 토큰을 확인한 후, 확인 결과를 상기 서비스 제공 장치로 전송하는 통합 인증 장치;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 시스템.
  14. 제13항에 있어서, 상기 단말기는
    특정 서비스 어플리케이션으로부터의 로그인 요청에 따라서 상기 대표 어플리케이션을 실행하여, 상기 대표 어플리케이션을 통하여 사용자의 인증 정보 및 상기 특정 서비스 어플리케이션에 대응하는 서비스 식별 정보를 상기 통합 인증 장치로 전송하여 인증을 요청하고, 상기 요청에 대응하여 통합 인증 장치로부터 인증 토큰 및 신뢰성 토큰을 수신하고, 해당 서비스 제공 장치가 상기 신뢰성 토큰을 이용하여 인증 여부를 확인할 수 있도록 특정 서비스 어플리케이션의 상기 신뢰성 토큰을 서비스 제공 장치로 전송하는 것을 특징으로 하는 어플리케이션을 이용한 인증 시스템.
  15. 제13항에 있어서, 상기 통합 인증 장치는
    상기 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 위한 인증 토큰을 생성하거나, 사용자 인증을 위한 인증 토큰이 수신되면 상기 인증 토큰을 확인하여 사용자 검증을 수행하고, 상기 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하여 해당 단말기로 제공하고, 상기 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 토큰 확인이 요청되면, 상기 서비스 제공 장치로부터 제공된 신뢰성 토큰을 검증하여, 상기 신뢰성 토큰에 대한 검증 결과를 상기 서비스 제공 장치로 제공하는 것을 특징으로 하는 어플리케이션을 이용한 인증 시스템.
  16. 단말기가 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하는 단계;
    상기 단말기가 상기 이벤트 발생에 따라 통합 인증 장치로 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 단계;
    상기 단말기가 상기 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 상기 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하는 단계;
    상기 단말기가 신뢰성 토큰 확인 결과에 따라 상기 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하는 단계; 및
    상기 단말기가 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  17. 제16항에 있어서, 상기 신뢰성 토큰은
    상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위해 상기 통합 인증 장치에서 발급되는 일회용 토큰으로서, 상기 통합 인증 장치에서 상기 서비스 제공 장치의 요청에 따라 수행되는 토큰 확인 후에 폐기되는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  18. 제16항에 있어서, 상기 감지하는 단계는
    상기 단말기가 상기 제2 어플리케이션으로부터 제1 어플리케이션과의 신뢰성 획득과 관련된 이벤트 발생을 감지하는 단계; 및
    상기 단말기가 상기 이벤트 발생에 따라 상기 제1 어플리케이션으로 상기 제2 어플리케이션과의 신뢰관계 획득을 요청하는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  19. 제16항에 있어서, 상기 구축하는 단계는
    상기 단말기가 대표 어플리케이션인 제1 어플리케이션을 통해 모바일 환경에서 제2 어플리케이션과의 신뢰관계를 구축하고, 상기 제2 어플리케이션의 인증을 위한 적어도 하나의 인증방식을 적용하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  20. 통합 인증 장치가 적어도 하나의 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하는 단계;
    상기 통합 인증 장치가 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하는 단계;
    상기 통합 인증 장치가 상기 생성된 신뢰성 토큰을 상기 단말기로 전송하는 단계;
    상기 통합 인증 장치가 서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호를 수신하는 단계;
    상기 통합 인증 장치가 상기 수신된 신뢰성 토큰을 확인하는 단계; 및
    상기 통합 인증 장치가 상기 신뢰성 토큰의 확인 결과를 상기 서비스 제공 장치로 전송하는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  21. 제20항에 있어서, 상기 생성하는 단계는
    상기 통합 인증 장치가 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 일회용 토큰을 생성하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  22. 제20항에 있어서, 상기 확인하는 단계는
    상기 통합 인증 장치가 상기 서비스 제공 장치로부터 수신된 신뢰성 토큰을 확인하는 단계; 및
    상기 통합 인증 장치가 상기 확인된 신뢰성 토큰을 폐기하는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  23. 단말기가,
    특정 서비스 어플리케이션의 로그인 이벤트를 감지하는 단계;
    상기 로그인 이벤트가 감지되면, 대표 어플리케이션이 상기 특정 서비스 어플리케이션의 서비스 식별 정보를 통합 인증 장치로 전송하여 로그인을 요청하는 단계;
    상기 요청에 따라 상기 대표 어플리케이션이 통합 인증 장치로부터 상기 서비스 식별 정보에 대응하여 생성된 신뢰성 토큰을 포함하는 로그인 결과 정보를 수신하는 단계;
    상기 대표 어플리케이션이 상기 신뢰성 토큰을 상기 특정 서비스 어플리케이션으로 제공하는 단계;
    상기 특정 서비스 어플리케이션이 상기 신뢰성 토큰을 서비스 제공 장치로 제공하여 신뢰성 확인을 요청하는 단계; 및
    신뢰성 확인 결과에 따라서, 상기 특정 서비스 어플리케이션이 실행되는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  24. 제23항에 있어서, 상기 로그인을 요청하는 단계는
    상기 대표 어플리케이션의 로그인 여부를 확인하는 단계;
    상기 대표 어플리케이션이 로그인 되지 않은 경우, 상기 대표 어플리케이션의 로그인을 위한 사용자 ID 및 비밀번호를 입력받는 단계; 및
    상기 특정 서비스 어플리케이션의 서비스 식별 정보와 함께, 상기 입력된 사용자 ID 및 비밀번호를 통합 인증 장치로 전송하여, 로그인을 요청하는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  25. 제23항에 있어서, 상기 로그인 결과 정보는
    상기 사용자 ID 및 비밀번호의 인증에 따라서 생성되는 인증 토큰을 더 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  26. 제23항에 있어서, 상기 로그인을 요청하는 단계는
    상기 대표 어플리케이션이 로그인 된 경우, 상기 서비스 식별 정보와 함께 상기 대표 어플리케이션이 기 수신한 인증 토큰을 상기 통합 인증 장치로 전송하여, 로그인을 요청하는 단계;
    를 더 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  27. 통합 인증 장치가 하나 이상의 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 수행하는 단계;
    상기 통합 인증 장치가 상기 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하는 단계;
    상기 통합 인증 장치가 상기 신뢰성 토큰을 포함하는 로그인 결과를 상기 단말기로 전송하는 단계;
    상기 통합 인증 장치가 상기 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 신뢰성 토큰 확인이 요청되면, 상기 서비스 제공 장치로부터 제공된 신뢰성 토큰을 검증하는 단계; 및
    상기 통합 인증 장치가 상기 신뢰성 토큰에 대한 검증 결과를 상기 서비스 제공 장치로 제공하는 단계;
    를 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  28. 제27항에 있어서, 상기 수행하는 단계 이전에,
    상기 통합 인증 장치가 상기 대표 어플리케이션이 로그인 된 경우, 상기 서비스 식별 정보와 함께 상기 대표 어플리케이션이 기 수신한 인증 토큰을 상기 단말기로부터 수신하는 단계;
    를 더 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  29. 제27항에 있어서, 상기 수행하는 단계 이전에,
    상기 대표 어플리케이션이 로그인 되지 않은 경우, 상기 서비스 어플리케이션의 서비스 식별 정보와 함께, 상기 대표 어플리케이션을 로그인하기 위한 사용자 ID 및 비밀번호를 상기 단말기로부터 수신하는 단계;
    를 더 포함하는 것을 특징으로 하는 어플리케이션을 이용한 인증 방법.
  30. 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 요청하는 이벤트를 감지하는 단계;
    상기 이벤트 발생에 따라 통합 인증 장치로 상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 단계;
    상기 통합 인증 장치로부터 신뢰성 토큰이 수신되면, 상기 제2 어플리케이션의 구동을 위한 신뢰성 토큰 확인을 서비스 제공 장치로 요청하는 단계;
    신뢰성 토큰 확인 결과에 따라 상기 서비스 제공 장치를 통해 제공되는 제2 어플리케이션을 구동하는 단계; 및
    상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰 관계를 구축하는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체.
  31. 적어도 하나의 단말기의 요청에 따라 제1 어플리케이션과 제2 어플리케이션 간의 신뢰성 확인을 요청하는 신호를 수신하는 단계;
    상기 제1 어플리케이션과 제2 어플리케이션 간의 신뢰관계 획득을 위한 신뢰성 토큰을 생성하는 단계;
    상기 생성된 신뢰성 토큰을 상기 단말기로 전송하는 단계;
    서비스 제공 장치로부터 신뢰성 토큰 확인을 요청하는 신호를 수신하는 단계;
    상기 수신된 신뢰성 토큰을 확인하는 단계; 및
    상기 신뢰성 토큰의 확인 결과를 상기 서비스 제공 장치로 전송하는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체.
  32. 특정 서비스 어플리케이션의 로그인 이벤트를 감지하는 단계;
    상기 로그인 이벤트가 감지되면, 대표 어플리케이션이 상기 특정 서비스 어플리케이션의 서비스 식별 정보를 통합 인증 장치로 전송하여 로그인을 요청하는 단계;
    상기 요청에 따라 상기 대표 어플리케이션이 통합 인증 장치로부터 상기 서비스 식별 정보에 대응하여 생성된 신뢰성 토큰을 포함하는 로그인 결과 정보를 수신하는 단계;
    상기 대표 어플리케이션이 상기 신뢰성 토큰을 상기 특정 서비스 어플리케이션으로 제공하는 단계;
    상기 특정 서비스 어플리케이션이 상기 신뢰성 토큰을 서비스 제공 장치로 제공하여 신뢰성 확인을 요청하는 단계; 및
    신뢰성 확인 결과에 따라서, 상기 특정 서비스 어플리케이션이 실행되는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체.
  33. 하나 이상의 단말기에 설치된 대표 어플리케이션으로부터 서비스 식별 정보를 포함하는 로그인 요청에 따라 사용자 인증을 수행하는 단계;
    상기 인증된 정보를 기반으로 서비스 식별 정보에 대응하는 서비스 어플리케이션의 신뢰성 확인을 위한 신뢰성 토큰을 생성하는 단계;
    상기 신뢰성 토큰을 포함하는 로그인 결과를 상기 단말기로 전송하는 단계;
    상기 서비스 식별 정보에 대응하는 서비스를 제공하는 서비스 제공 장치로부터 신뢰성 토큰 확인이 요청되면, 상기 서비스 제공 장치로부터 제공된 신뢰성 토큰을 검증하는 단계; 및
    상기 신뢰성 토큰에 대한 검증 결과를 상기 서비스 제공 장치로 제공하는 단계를 실행하는 프로그램을 기록한 컴퓨터 판독 가능한 기록매체.
PCT/KR2013/012060 2013-03-08 2013-12-24 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치 Ceased WO2014137063A1 (ko)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US14/848,255 US10135809B2 (en) 2013-03-08 2015-09-08 Method, system and apparatus for authentication using application

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
KR10-2013-0025077 2013-03-08
KR1020130025077A KR102139162B1 (ko) 2013-03-08 2013-03-08 어플리케이션 간의 신뢰관계 획득 방법, 이를 위한 시스템 및 장치
KR1020130030488A KR20140115660A (ko) 2013-03-21 2013-03-21 대표 어플리케이션을 이용한 통합 인증 방법, 이를 위한 시스템 및 장치
KR10-2013-0030488 2013-03-21

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/848,255 Continuation US10135809B2 (en) 2013-03-08 2015-09-08 Method, system and apparatus for authentication using application

Publications (1)

Publication Number Publication Date
WO2014137063A1 true WO2014137063A1 (ko) 2014-09-12

Family

ID=51491544

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2013/012060 Ceased WO2014137063A1 (ko) 2013-03-08 2013-12-24 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치

Country Status (2)

Country Link
US (1) US10135809B2 (ko)
WO (1) WO2014137063A1 (ko)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109547460A (zh) * 2018-12-12 2019-03-29 重庆邮电大学 面向身份联盟的多粒度联合身份认证方法

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11089028B1 (en) * 2016-12-21 2021-08-10 Amazon Technologies, Inc. Tokenization federation service
US11657136B2 (en) 2017-12-21 2023-05-23 Bitstrata Systems Inc. Secure association of an installed application instance with a service
JP7033944B2 (ja) * 2018-02-08 2022-03-11 Line株式会社 ログイン支援プログラム、ログイン支援方法、情報処理端末、及び、ログイン支援システム
CN110278187B (zh) * 2019-05-13 2021-11-16 网宿科技股份有限公司 多终端单点登录方法、系统、同步服务器及介质
US20230093470A1 (en) * 2021-09-17 2023-03-23 Salesforce, Inc. Account authorization mapping

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003345751A (ja) * 2002-05-22 2003-12-05 Nippon Telegr & Teleph Corp <Ntt> プラットフォーム制御方法、プラットフォーム制御装置、プラットフォーム制御プログラムおよびそのプログラムを格納した記憶媒体
JP2006065712A (ja) * 2004-08-30 2006-03-09 Yokogawa Electric Corp 統合認証方法、統合認証装置および統合認証のためのプログラム
KR20080041220A (ko) * 2005-08-22 2008-05-09 마이크로소프트 코포레이션 분산된 단일 서명 서비스 방법
US20100077469A1 (en) * 2008-09-19 2010-03-25 Michael Furman Single Sign On Infrastructure
US20120291114A1 (en) * 2011-05-13 2012-11-15 Cch Incorporated Single sign-on between applications

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101453557B1 (ko) * 2007-11-08 2014-10-21 삼성전자주식회사 통신 시스템에서 단말기의 데이터 송수신 방법 및 그 통신시스템

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003345751A (ja) * 2002-05-22 2003-12-05 Nippon Telegr & Teleph Corp <Ntt> プラットフォーム制御方法、プラットフォーム制御装置、プラットフォーム制御プログラムおよびそのプログラムを格納した記憶媒体
JP2006065712A (ja) * 2004-08-30 2006-03-09 Yokogawa Electric Corp 統合認証方法、統合認証装置および統合認証のためのプログラム
KR20080041220A (ko) * 2005-08-22 2008-05-09 마이크로소프트 코포레이션 분산된 단일 서명 서비스 방법
US20100077469A1 (en) * 2008-09-19 2010-03-25 Michael Furman Single Sign On Infrastructure
US20120291114A1 (en) * 2011-05-13 2012-11-15 Cch Incorporated Single sign-on between applications

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109547460A (zh) * 2018-12-12 2019-03-29 重庆邮电大学 面向身份联盟的多粒度联合身份认证方法
CN109547460B (zh) * 2018-12-12 2020-12-04 重庆邮电大学 面向身份联盟的多粒度联合身份认证方法

Also Published As

Publication number Publication date
US10135809B2 (en) 2018-11-20
US20150381605A1 (en) 2015-12-31

Similar Documents

Publication Publication Date Title
WO2019127973A1 (zh) 镜像仓库的权限认证方法、系统、设备及存储介质
WO2022102930A1 (ko) 브라우저 기반 보안 pin 인증을 이용한 did 시스템 및 그것의 제어방법
CN103621009B (zh) 用于基于可信平台认证开放式标识的方法、装置和系统
CN108293045B (zh) 本地和远程系统之间的单点登录身份管理
WO2016137307A1 (en) Attestation by proxy
EP2919435B1 (en) Communication terminal and secure log-in method and program
WO2020189926A1 (ko) 블록체인 네트워크를 이용하여 사용자의 아이덴티티를 관리하는 방법 및 서버, 그리고, 블록체인 네트워크 기반의 사용자 아이덴티티를 이용하여 사용자를 인증하는 방법 및 단말
WO2014137063A1 (ko) 어플리케이션을 이용한 인증 방법, 이를 위한 시스템 및 장치
WO2014196708A1 (ko) 보안토큰을 이용한 인증 방법, 이를 위한 시스템 및 장치
WO2019072039A1 (zh) 一种业务证书管理方法、终端及服务器
WO2018192472A1 (zh) 访问认证的方法及服务器、智能终端和存储装置
WO2018030707A1 (ko) 인증 시스템 및 방법과 이를 수행하기 위한 사용자 단말, 인증 서버 및 서비스 서버
WO2013183814A1 (ko) 개선된 보안 기능 기반의 클라우드 서비스 시스템 및 이를 지원하는 방법
WO2014007516A1 (ko) 단일 인증 서비스 시스템 및 이의 운용 방법
WO2015020360A1 (ko) 무선 통신 시스템에서 기기 등록 및 인증을 수행하는 방법 및 장치
WO2019225921A1 (ko) 디지털 키를 저장하기 위한 방법 및 전자 디바이스
WO2015069018A1 (ko) 보안 로그인 시스템, 방법 및 장치
WO2020189927A1 (ko) 블록체인 네트워크를 이용하여 사용자의 아이덴티티를 관리하는 방법 및 서버, 그리고, 블록체인 네트워크 기반의 사용자 아이덴티티를 이용하여 사용자를 인증하는 방법 및 단말
WO2018151480A1 (ko) 인증 관리 방법 및 시스템
WO2020062644A1 (zh) Json劫持漏洞的检测方法、装置、设备及存储介质
WO2020141782A1 (ko) 블록체인 네트워크를 이용하여 사용자의 아이덴티티를 관리하는 방법 및 서버, 그리고, 블록체인 네트워크 기반의 사용자 아이덴티티를 이용하여 사용자를 인증하는 방법 및 단말
WO2023090755A1 (ko) 가상화 인스턴스의 네트워크 접속을 제어하기 위한 시스템 및 그에 관한 방법
WO2012074275A2 (ko) 인터넷 보안을 위한 본인인증 장치, 그 방법 및 이를 기록한 기록매체
WO2019017544A1 (ko) 사용자 인증 서비스 제공 방법, 웹 서버 및 사용자 단말
WO2021020918A1 (ko) 논리적 내부 네트워크를 제공하는 방법, 이를 구현하는 모바일 단말 및 어플리케이션

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13877213

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13877213

Country of ref document: EP

Kind code of ref document: A1