WO2018199713A1 - 생체 정보를 보호하는 생체 정보 인증 방법 - Google Patents
생체 정보를 보호하는 생체 정보 인증 방법 Download PDFInfo
- Publication number
- WO2018199713A1 WO2018199713A1 PCT/KR2018/005012 KR2018005012W WO2018199713A1 WO 2018199713 A1 WO2018199713 A1 WO 2018199713A1 KR 2018005012 W KR2018005012 W KR 2018005012W WO 2018199713 A1 WO2018199713 A1 WO 2018199713A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- secret information
- secret
- authentication
- vector
- authentication server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/45—Structures or tools for the administration of authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/30—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
- H04L9/3006—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters
Definitions
- the present invention relates to a secret information authentication method, and more particularly to a biometric information authentication method.
- biometric information unique to each human being such as fingerprint and iris information. Since the biometric information is unique to each person, there is no hassle such as having to memorize a password and there is no fear of leakage.
- biometric authentication has a different feature from the existing authentication method.
- the biometric input information inputted for recognition varies slightly depending on the noise generated in the biometric information recognition process.
- authentication should be possible even in the presence of noise.
- An object of the present invention is to solve the above-mentioned problems of the prior art, and to provide a method for authenticating secret information, particularly biometric information, which has a short cipher text and is fast.
- a secret information authentication server is performed in an environment including a secret information registration terminal, a secret information authentication server, and a secret information authentication request terminal, and the secret information authentication server performs a secret information vector.
- matrix Is the product of Receiving and storing the secret information from the registration terminal;
- Secret authentication server authentication requested secret information vector about, Vector created to satisfy the relationship of Receiving a secret information authentication request terminal from the terminal;
- Secret authentication server Wow Calculating an inner product of the third product; Secret authentication server, And a fourth step of determining that the secret information authentication succeeds when this value is less than or equal to the predetermined value, and determining otherwise as the secret information authentication failure.
- a secret information authentication server is a secret information vector.
- matrix A first step of receiving a product of a secret information registration terminal; Secret authentication server, authentication requested secret information vector And error vector ( )about, Vector created to satisfy the relationship of Receiving a secret information authentication request terminal from the terminal; Secret authentication server, Wow Calculating an inner product of the third product; Secret authentication server, And a fourth step of determining that the secret information authentication succeeds when this value is less than or equal to the predetermined value, and determining otherwise as the secret information authentication failure.
- Matrix after the first step Can be deleted from the secret information registration terminal.
- At least one of them may be transmitted encrypted with a public key.
- the secret information is encrypted and transmitted to the authentication server, the secret information is not leaked even if it is exposed in the middle or the authentication server is attacked.
- it is possible to determine whether to authenticate the encrypted secret information that has been requested for authentication and the encrypted secret information that has been registered it is possible to fundamentally block the possibility that the secret information is leaked.
- secret information is determined based on the inner product of a ciphertext having a vector of length m, the efficiency is improved.
- FIG. 1 is a flow chart of a secret information authentication method according to the present invention.
- the information (data) transmission process performed in the present specification may be applied to encryption / decryption as necessary, and in this specification and the claims, the expressions describing the information (data) transmission process are all encrypted / decrypted even if not mentioned otherwise. It should also be interpreted to include cases.
- expressions of the form "transfer from A to B (transfer)" or "A receives from B” include those that are transmitted (transmitted) or received with other mediators in between, and directly from A to B. It does not represent only what is transmitted (delivered) or received.
- the order of each step is to be understood without limitation unless the preceding step is to be performed logically and temporally prior to the later step.
- the present invention is performed by an electronic computing device such as a computer capable of electronic operations, and the mathematical operations and calculations of the steps of the present invention described later are suitable for the known coding method and / or the present invention for performing the operations or calculations. It can be implemented by computer operation by means of coding designed to be.
- value is defined as a concept including not only a scalar value but also a vector and a matrix.
- the encryption method and the authentication method according to the present invention may include general secret information (for example, a password, a secret key, and personal sensitivity information). Etc.), and the scope of the right should not be limited as it applies to biometric information.
- the secret information authentication method according to the present invention is performed in an environment including a secret information registration terminal 10, a secret information authentication request terminal 20, and an authentication server 30.
- the secret information registration terminal 10 is a terminal for first registering the user's secret information in the authentication server 30, and the secret information authentication request terminal 20 registers the secret information recognized after registering the secret information in the authentication server 30. It is a terminal for authenticating secret information by sending it).
- the secret information registration terminal 10 and the secret information authentication request terminal 20 may be the same terminal or may be different terminals. In this specification, it is assumed that the terminal is different from each other.
- the secret information registered and requested for authentication may be, for example, fingerprint information.
- the terminal When the user inputs the secret information to be registered in the secret information registration terminal 10, the terminal stores the secret information vector as a vector of length n consisting of -1 and 1. To create. And m ⁇ n matrix Secret information received with Is the product of Calculate (100). procession The secret information may be deleted from the terminal 10 after a process of initially registering the secret information in the registration terminal 10. procession If you delete it after registering confidential information, you can eliminate the risk of later leakage.
- a user who wants to authenticate secret information reads or inputs his secret information to the secret information authentication request terminal 20 so that the secret information authentication request terminal 20 has a length of -1, 1 n secret information vector Create
- the secret information vector requested authentication about, Vector satisfying the relationship of Generate (130).
- vector For example may be generated by randomly selecting (mn) components to an arbitrary value, and then calculating the remaining n components to satisfy the above relationship.
- n is a dimension of secret information, and security is determined by m.
- n may be set to 2,000 and m may be set to 2,500 to set the k value to 500.
- the invention is not to be interpreted as limiting the scope of protection to such specific values.
- the Hamming distance of two vectors is the number of different elements when comparing two elements in the same position. For example, the Hamming distance between the vector 1100 and the vector 1000 is 1, and the Hamming distance between the vector 1111 and the vector 1100 is 2. In other words, if the secret information is expressed as a vector, the smaller the hamming distance, the more similar the secret information can be seen.
- the authentication server 30 registers the encrypted secret information.
- Vector with The inner product of is calculated (150). This dot product satisfies the following relationship.
- Secret information property vector by equation (1) And, secret information vector generated during secret information authentication Hamming distance of To It is calculated as (160). If the calculated hamming distance is within a predetermined range, it is determined that the secret information requesting authentication is legitimate, otherwise, it is determined as authentication failure (170). The authentication success or failure is transmitted to the authentication server 30 to the secret information authentication request terminal 20 (180).
- a vector created to satisfy the relationship You can also use vector Is It is a noise vector having a small magnitude in the LWE problem that is randomly selected from.
- the authentication server 30 Wow A secret information vector registered by Equation 1 from the inner product of Error value is added to the secret vector The Hamming distance is calculated to determine whether to authenticate according to Equation 1.
- Equation 3 Is a small error Having It can be seen as an approximation of. Therefore, it can be used for secret information authentication.
- the secret information is encrypted and transmitted to the authentication server, the secret information is not leaked even if it is exposed in the middle or the authentication server is attacked.
- the matrix Q As described above, it is possible to discriminate whether or not the secret information is leaked since it is possible to determine whether to authenticate without decrypting the encrypted secret information requested for authentication and the encrypted secret information registered. Can be.
- secret information is determined based on the inner product of a ciphertext having a vector of length m, the efficiency is improved.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Collating Specific Patterns (AREA)
Abstract
본 발명에 의한 비밀 정보 인증 방법은, 비밀 정보 인증 서버가, 제1 비밀 정보 벡터와 행렬(Q)의 곱을 비밀 정보 등록 단말기로부터 수신하고 저장하는 제1 단계와; 비밀 정보 인증 서버가, 인증 요청된 제2 비밀 정보 벡터에 대해서, 행렬의 전치행렬(QT)과 제3 벡터를 곱한 값이 제2 비밀 벡터가 되는 제3 벡터를 비밀 정보 인증 요청 단말기로부터 수신하는 제2 단계와; 비밀 정보 인증 서버가, 행렬과 제1 비밀 벡터의 곱과 제3 벡터의 내적값(inner product)을 산출하는 제3 단계와; 비밀 정보 인증 서버가,1/2(n - 내적값)을 산출하고, 이 값이 소정의 값보다 작거나 같은 경우에 비밀 정보 인증에 성공한 것으로 판별하고, 그 이외의 경우에는 비밀 정보 인증 실패로 판별하는 제4 단계를 포함한다.
Description
본 발명은 비밀 정보 인증 방법에 대한 것으로서 특히 생체 정보의 인증 방법에 대한 것이다.
최근에 지문, 홍채 정보 등과 같은 인간마다 고유하게 가지고 있는 생체 정보를 이용하여 인증 방법이 널리 개발되고 있다. 생체 정보는 사람마다 고유하기 때문에 비밀번호를 외워야 하는 등의 번거로움이 없고, 유출의 우려도 없는 장점이 있다.
그런데 생체 정보 인증은 기존의 인증 방법과 다른 특징을 가지고 있다. 첫째, 생체 정보 인식 과정에서 발생하는 노이즈에 의해서 인식을 위해 입력되는 생체 입력 정보가 조금씩 달라지는데 이처럼 노이즈가 있는 상태에서도 인증이 가능해야 한다. 둘째, 생체 정보가 노출되는 경우라고 해도, 비밀번호와 달리 생체 정보는 변경이 불가능하다. 따라서, 노출의 위험성을 원천적으로 차단해야 한다.
이와 같은 생체 정보 인증의 특성을 고려하여 Fuzzy extractor나 Inner product encryption 등의 암호화 방식이 연구되고 있다. 그러나 종래의 암호화 방식에 따른 인증은 속도가 느리거나 암호문의 크기가 크다는 단점이 존재한다.
본 발명은 전술한 종래 기술의 문제점을 해결하여, 암호문의 크기가 짧고 속도가 빠른 비밀 정보 특히 생체 정보 인증 방법을 제공하는 것을 목적으로 한다.
본 발명에 의한 비밀 정보 인증 방법은, 비밀 정보 등록 단말기와, 비밀 정보 인증 서버와, 비밀 정보 인증 요청 단말기를 포함하는 환경에서 비밀 정보 인증 서버가 수행되며, 비밀 정보 인증 서버가, 비밀 정보 벡터 와 행렬 의 곱인 를 비밀 정보 등록 단말기로부터 수신하고 저장하는 제1 단계와; 비밀 정보 인증 서버가, 인증 요청된 비밀 정보 벡터 에 대해서, 의 관계를 만족하도록 생성된 벡터 를 비밀 정보 인증 요청 단말기로부터 수신하는 제2 단계와; 비밀 정보 인증 서버가, 와 의 내적값(inner product)을 산출하는 제3 단계와; 비밀 정보 인증 서버가, 을 산출하고, 이 값이 소정의 값보다 작거나 같은 경우에 비밀 정보 인증에 성공한 것으로 판별하고, 그 이외의 경우에는 비밀 정보 인증 실패로 판별하는 제4 단계를 포함한다.
본 발명의 다른 실시형태에 의하면, 본 발명에 의한 인증 방법은, 비밀 정보 인증 서버가, 비밀 정보 벡터 와 행렬 의 곱을 비밀 정보 등록 단말기로부터 수신하는 제1 단계와; 비밀 정보 인증 서버가, 인증 요청된 비밀 정보 벡터 와 에러벡터()에 대해서, 의 관계를 만족하도록 생성된 벡터 를 비밀 정보 인증 요청 단말기로부터 수신하는 제2 단계와; 비밀 정보 인증 서버가, 와 의 내적값(inner product)을 산출하는 제3 단계와; 비밀 정보 인증 서버가, 을 산출하고, 이 값이 소정의 값보다 작거나 같은 경우에 비밀 정보 인증에 성공한 것으로 판별하고, 그 이외의 경우에는 비밀 정보 인증 실패로 판별하는 제4 단계를 포함한다.
본 발명에 의하면, 비밀 정보가 암호화되어 인증 서버로 전송되므로 도중에 노출되거나 인증 서버가 공격받더라도 비밀 정보는 누출되지 않는 효과가 있다. 그리고 인증 요청을 받은 암호화된 비밀 정보와 등록되어 있는 암호화된 비밀 정보를 복호화할 필요없이 인증 여부를 판별할 수 있기 때문에 비밀 정보가 누설될 가능성을 원천적으로 차단할 수 있다. 또한, 비밀 정보는 길이가 m인 벡터로 되어 있는 암호문의 내적값으로 인증 여부를 판별하기 때문에 기존의 방법에 비해 효율성도 고양된다.
도 1은 본 발명에 의한 비밀 정보 인증 방법의 흐름도.
이하에서는 첨부 도면을 참조하여 본 발명에 대해서 자세하게 설명한다.
본 명세서에서 수행되는 정보(데이터) 전송 과정은 필요에 따라서 암호화/복호화가 적용될 수 있으며, 본 명세서 및 특허청구범위에서 정보(데이터) 전송 과정을 설명하는 표현은 별도로 언급되지 않더라도 모두 암호화/복호화하는 경우도 포함하는 것으로 해석되어야 한다. 본 명세서에서 "A로부터 B로 전송(전달)" 또는 "A가 B로부터 수신"과 같은 형태의 표현은 중간에 다른 매개체가 포함되어 전송(전달) 또는 수신되는 것도 포함하며, A로부터 B까지 직접 전송(전달) 또는 수신되는 것만을 표현하는 것은 아니다. 본 발명의 설명에 있어서 각 단계의 순서는 선행 단계가 논리적 및 시간적으로 반드시 후행 단계에 앞서서 수행되어야 하는 경우가 아니라면 각 단계의 순서는 비제한적으로 이해되어야 한다. 즉 위와 같은 예외적인 경우를 제외하고는 후행 단계로 설명된 과정이 선행 단계로 설명된 과정보다 앞서서 수행되더라도 발명의 본질에는 영향이 없으며 권리범위 역시 단계의 순서에 관계없이 정의되어야 한다. 그리고 본 명세서에서 “A 또는 B”은 A와 B 중 어느 하나를 선택적으로 가리키는 것 뿐만 아니라 A와 B 모두를 포함하는 것도 의미하는 것으로 정의된다. 또한, 본 명세서에서 "포함"이라는 용어는 포함하는 것으로 나열된 요소 이외에 추가로 다른 구성요소를 더 포함하는 것도 포괄하는 의미를 가진다.
본 명세서에서는 본 발명의 설명에 필요한 필수적인 구성요소만을 설명하며, 본 발명의 본질과 관계가 없는 구성요소는 언급하지 아니한다. 그리고 언급되는 구성요소만을 포함하는 배타적인 의미로 해석되어서는 아니되며 다른 구성요소도 포함할 수 있는 비배타적인 의미로 해석되어야 한다.
본 발명은 전자적 연산이 가능한 컴퓨터 등의 전자적 연산 장치에 의해서 수행되며, 후술하는 본 발명의 각 단계의 수학적 연산 및 산출은 해당 연산 또는 산출을 하기 위해 공지되어 있는 코딩 방법 및/또는 본 발명에 적합하게 고안된 코딩에 의해서 컴퓨터 연산으로 구현될 수 있다.
그리고 본 명세서에서 "값"이라 함은 스칼라값 뿐만 아니라 벡터, 행렬도 포함하는 개념으로 정의된다.
본 명세서에서는 본 발명이 생체 정보인 비밀 정보에 적용되는 실시예에 대해서 주로 설명하지만, 본 발명에 의한 암호화 방법 및 인증 방법은 통상적인 비밀 정보(예를 들어, 비밀 번호와 비밀키, 개인민감 정보 등)에도 적용할 수 있으며, 생체 정보에 적용되는 것으로 권리범위가 제한되어서는 아니된다.
도 1에는 본 발명에 의한 비밀 정보 인증 방법이 수행되는 흐름도가 도시되어 있다. 본 발명에 의한 비밀 정보 인증 방법은, 비밀 정보 등록 단말기(10)와, 비밀 정보 인증 요청 단말기(20)와, 인증 서버(30)를 포함하는 환경에서 수행된다. 비밀 정보 등록 단말기(10)는, 최초에 사용자의 비밀 정보를 인증 서버(30)에 등록하기 위한 단말기이며, 비밀 정보 인증 요청 단말기(20)는 비밀 정보 등록 후 인식된 비밀 정보를 인증 서버(30)로 전송하여 비밀 정보를 인증받기 위한 단말기이다. 비밀 정보 등록 단말기(10)와 비밀 정보 인증 요청 단말기(20)는 서로 동일한 단말기일 수도 있고, 서로 다른 단말기일 수도 있다. 본 명세서에서는 서로 다른 단말기인 것으로 가정하고 설명하기로 한다. 등록되고 인증 요청되는 비밀 정보로는 예를 들어 지문 정보가 될 수 있다.
등록하고자 하는 비밀 정보를 사용자가 비밀 정보 등록 단말기(10)에 입력하면 단말기는 비밀 정보 벡터를 -1, 1 로 구성된 길이 n인 벡터 로 생성한다. 그리고 m×n 행렬 와 입력받은 비밀 정보 벡터 의 곱인 을 산출한다(100). 행렬 는 비밀 정보 등록 단말기(10)에서 최초에 비밀 정보를 등록하는 과정을 거친 후에 단말기(10)에서 삭제할 수 있다. 행렬 를 비밀 정보 등록 후에 삭제해 버리면 이후에 유출될 위험을 제거할 수 있다.
산출된 는 인증 서버(30)로 전송된다(110). 행렬 는 비밀 정보 등록 단말기(10)만 가지고 있는 값이기 때문에 인증 서버(30)로 전송되는 값은 일종의 비밀 정보 암호화 값이다. 인증 서버(30)는 전송받은 값을 비밀 정보의 암호화값으로 등록한다(120).
비밀 정보가 등록된 후에, 비밀 정보 인증을 받고자 하는 사용자는 비밀 정보 인증 요청 단말기(20)에 자신의 비밀 정보를 판독시키거나 입력하여 비밀 정보 인증 요청 단말기(20)가 -1, 1 로 구성된 길이 n인 비밀 정보 벡터 를 생성한다.
그리고 비밀 정보 인증 요청 단말기(20)는, 인증 요청된 비밀 정보 벡터 에 대해서, 의 관계를 만족하는 벡터 를 생성한다(130). 벡터 는 예를 들어, (m-n)개의 성분을 임의의 값으로 랜덤하게 선택한 후에, 나머지 n개 성분을 위 관계를 만족하도록 계산하여 생성할 수 있다.
m과 n의 관계는 인 것이 바람직하다. n은 비밀 정보의 차원이고, m에 의해서 보안성이 결정된다. m과 n의 차이인 k(= m-n)값이 중요한데 이는 후술하는 LWE 문제의 안전성을 담보한다. 소망하는 보안성의 정도와 다른 인수들에 따라서 차이는 있지만, 대략 k값은 500 내지 1,000을 취하는 것이 일반적이다. 예를 들어 홍채 인식의 경우 n을 2,000으로, m은 2,500으로 설정하여 k값을 500으로 할 수 있다. 물론, 본 발명은 그러한 구체적인 값에 보호범위가 제한되지 것으로 해석되지 않는다.
비밀 정보 등록시 사용한 비밀 정보 벡터 와, 비밀 정보 인증시 생성된 비밀 정보 벡터 가 이므로 와 의 해밍 거리(hamming distance) 는 다음과 같이 와 의 내적 계산을 통해서 산출이 가능하다.
두 벡터의 해밍 거리는 두 벡터의 같은 위치에 있는 원소를 비교했을 때 서로 다른 원소의 개수를 의미한다. 예를 들어, 벡터 1100과 벡터 1000의 해밍 거리는 1이고, 벡터 1111과 벡터 1100 사이의 해밍 거리는 2가 된다. 즉 비밀 정보를 벡터로 표현하면 해밍 거리가 작을수록 서로 비슷한 비밀 정보로 볼 수 있다.
수학식 1에 의해서 비밀 정보 등록 정보 벡터 와, 비밀 정보 인증시 생성된 비밀 정보 벡터 의 해밍 거리 를 으로 산출한다(160). 이렇게 산출된 해밍 거리가 미리 정한 범위 이내라면 인증을 요청한 비밀 정보가 정당한 것으로 판별하고, 그렇지 않으면 인증 실패로 판별한다(170). 인증 성공 여부는 인증 서버(30)가 비밀 정보 인증 요청 단말기(20)로 전송한다(180).
생체 정보가 아닌 비밀정보는 노이즈가 개입할 여지가 없으므로 해밍 거리가 0이 되어야 인증에 성공한 것으로 판단한다.
노이즈가 없는 비밀 정보의 경우에는 해밍 거리가 0인 경우에만 인증에 성공하는 것으로 할 수 있다.
본 발명의 다른 실시예에 의하면 ()의 관계를 만족하도록 생성된 벡터 를 사용할 수도 있다. 벡터 는 로부터 랜덤하게 선택되는 LWE 문제에 있어서의 크기가 작은 노이즈 벡터이다. 이 실시예에서는, 인증 서버(30)가 와 의 내적값을 산출하고, 그 내적값으로부터 수학식 1에 의해 등록된 비밀 정보 벡터 와 인증 요청을 받은 비밀 정보 벡터에 에러값이 더해진 의 해밍 거리를 산출하여 수학식 1에 따라서 인증 여부를 판단한다.
본 발명에 의하면, 비밀 정보가 암호화되어 인증 서버로 전송되므로 도중에 노출되거나 인증 서버가 공격받더라도 비밀 정보는 누출되지 않는 효과가 있다. 그리고 전술한 바와 같은 행렬 Q를 이용하여 암호화함으로써 인증 요청받은 암호화된 비밀 정보와 등록되어 있는 암호화된 비밀 정보를 복호화할 필요없이 인증 여부를 판별할 수 있기 때문에 비밀 정보가 누설될 가능성을 원천적으로 차단할 수 있다. 또한, 비밀 정보는 길이가 m인 벡터로 되어 있는 암호문의 내적값으로 인증 여부를 판별하기 때문에 기존의 방법에 비해 효율성도 고양된다.
이상 첨부 도면을 참고하여 본 발명에 대해서 설명하였지만 본 발명의 권리범위는 후술하는 특허청구범위에 의해 결정되며 전술한 실시예 및/또는 도면에 제한되는 것으로 해석되어서는 아니된다. 그리고 특허청구범위에 기재된 발명의, 당업자에게 자명한 개량, 변경 및 수정도 본 발명의 권리범위에 포함된다는 점이 명백하게 이해되어야 한다.
Claims (4)
- 비밀 정보 등록 단말기와, 비밀 정보 인증 서버와, 비밀 정보 인증 요청 단말기를 포함하는 환경에서 비밀 정보 인증 서버가 수행하는 비밀 정보 인증 방법에 있어서,비밀 정보 인증 서버가, 을 산출하고, 이 값이 소정의 값보다 작거나 같은 경우에 비밀 정보 인증에 성공한 것으로 판별하고, 그 이외의 경우에는 비밀 정보 인증 실패로 판별하는 제4 단계를 포함하는,비밀 정보 인증 방법.
- 비밀 정보 등록 단말기와, 비밀 정보 인증 서버와, 비밀 정보 인증 요청 단말기를 포함하는 환경에서 비밀 정보 인증 서버가 수행하는 비밀 정보 인증 방법에 있어서,비밀 정보 인증 서버가, 을 산출하고, 이 값이 소정의 값보다 작거나 같은 경우에 비밀 정보 인증에 성공한 것으로 판별하고, 그 이외의 경우에는 비밀 정보 인증 실패로 판별하는 제4 단계를 포함하는,비밀 정보 인증 방법.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/519,865 US11032273B2 (en) | 2017-04-29 | 2019-07-23 | Method for authenticating secret information which protects secret information |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020170055803A KR101838008B1 (ko) | 2017-04-29 | 2017-04-29 | 생체 정보를 보호하는 생체 정보 인증 방법 |
| KR10-2017-0055803 | 2017-04-29 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/519,865 Continuation-In-Part US11032273B2 (en) | 2017-04-29 | 2019-07-23 | Method for authenticating secret information which protects secret information |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018199713A1 true WO2018199713A1 (ko) | 2018-11-01 |
Family
ID=61660791
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2018/005012 Ceased WO2018199713A1 (ko) | 2017-04-29 | 2018-04-30 | 생체 정보를 보호하는 생체 정보 인증 방법 |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR101838008B1 (ko) |
| WO (1) | WO2018199713A1 (ko) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR102019388B1 (ko) * | 2018-07-26 | 2019-09-06 | 주식회사 크립토랩 | 생체정보를 보호하는 고속 인증방법 |
| US11032273B2 (en) | 2017-04-29 | 2021-06-08 | Crypto Lab Inc. | Method for authenticating secret information which protects secret information |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20090042143A (ko) * | 2007-10-24 | 2009-04-29 | 한국전자통신연구원 | 생체 인증 방법 |
| KR100911594B1 (ko) * | 2006-10-04 | 2009-08-07 | 가부시키가이샤 히타치세이사쿠쇼 | 생체 인증 시스템, 등록 단말기, 인증 단말기, 및 인증서버 |
| KR20100013486A (ko) * | 2008-07-31 | 2010-02-10 | 한국전자통신연구원 | 생체 인증 방법, 클라이언트 및 서버 |
| JP2012022507A (ja) * | 2010-07-14 | 2012-02-02 | Ntt Data Corp | 認証システム、認証方法、認証サーバ、認証プログラム |
| JP2013120580A (ja) * | 2011-12-09 | 2013-06-17 | Hitachi Ltd | 生体認証システム |
-
2017
- 2017-04-29 KR KR1020170055803A patent/KR101838008B1/ko active Active
-
2018
- 2018-04-30 WO PCT/KR2018/005012 patent/WO2018199713A1/ko not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR100911594B1 (ko) * | 2006-10-04 | 2009-08-07 | 가부시키가이샤 히타치세이사쿠쇼 | 생체 인증 시스템, 등록 단말기, 인증 단말기, 및 인증서버 |
| KR20090042143A (ko) * | 2007-10-24 | 2009-04-29 | 한국전자통신연구원 | 생체 인증 방법 |
| KR20100013486A (ko) * | 2008-07-31 | 2010-02-10 | 한국전자통신연구원 | 생체 인증 방법, 클라이언트 및 서버 |
| JP2012022507A (ja) * | 2010-07-14 | 2012-02-02 | Ntt Data Corp | 認証システム、認証方法、認証サーバ、認証プログラム |
| JP2013120580A (ja) * | 2011-12-09 | 2013-06-17 | Hitachi Ltd | 生体認証システム |
Also Published As
| Publication number | Publication date |
|---|---|
| KR101838008B1 (ko) | 2018-03-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10515204B2 (en) | Method and system for securing user access, data at rest and sensitive transactions using biometrics for mobile devices with protected, local templates | |
| EP3241146B1 (en) | System and method for obfuscating an identifier to protect the identifier from impermissible appropriation | |
| EP3320662B1 (en) | Method of securing authentication in electronic communication | |
| CN112035860B (zh) | 文件加密方法、终端、装置、设备及介质 | |
| US20050114686A1 (en) | System and method for multiple users to securely access encrypted data on computer system | |
| US11227037B2 (en) | Computer system, verification method of confidential information, and computer | |
| US12333056B2 (en) | Neural network cryptography coprocessor providing countermeasture against side-channel analysis | |
| KR20120007509A (ko) | 일종의 신분 인증 및 공유키 생성방법 | |
| US11968300B2 (en) | Data extraction system, data extraction method, registration apparatus, and program | |
| US20090064273A1 (en) | Methods and systems for secure data entry and maintenance | |
| EP3057029B1 (en) | Improved encryption and authentication method and apparatus | |
| WO2018199713A1 (ko) | 생체 정보를 보호하는 생체 정보 인증 방법 | |
| CN114282254A (zh) | 加密、解密方法及装置、电子设备 | |
| WO2017005230A1 (en) | Method of authenticating communication of an authentication device and at least one authentication server using local factor | |
| CN112532627B (zh) | 冷启动推荐方法、装置、计算机设备及存储介质 | |
| EP3534566A2 (en) | Transmission/reception system, transmission device, reception device, method, and computer program | |
| Adam et al. | Multilevel Authentication Scheme for Cloud Computing | |
| WO2016159538A1 (ko) | Pin 인증 시스템 및 방법 | |
| WO2020130297A1 (ko) | 서버에의 비밀 정보 저장 방법 및 복구 방법 | |
| KR102019388B1 (ko) | 생체정보를 보호하는 고속 인증방법 | |
| Smid et al. | A Token Based Access Control System for Computer Networks | |
| Pol et al. | Secure Data Transfer Using Cloud | |
| CN117473543A (zh) | 人脸识别认证中的隐私保护方法及系统 | |
| HK40014549A (en) | Transmission/reception system, transmission device, reception device, method, and computer program |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18791169 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18791169 Country of ref document: EP Kind code of ref document: A1 |
