WO2022092582A1 - Dispositif électronique et procédé permettant de fournir un document d'identification mobile au moyen d'un dispositif électronique - Google Patents
Dispositif électronique et procédé permettant de fournir un document d'identification mobile au moyen d'un dispositif électronique Download PDFInfo
- Publication number
- WO2022092582A1 WO2022092582A1 PCT/KR2021/013137 KR2021013137W WO2022092582A1 WO 2022092582 A1 WO2022092582 A1 WO 2022092582A1 KR 2021013137 W KR2021013137 W KR 2021013137W WO 2022092582 A1 WO2022092582 A1 WO 2022092582A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- mobile
- electronic device
- user
- photo
- image
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 57
- 238000004891 communication Methods 0.000 claims abstract description 107
- 230000006870 function Effects 0.000 claims description 26
- 238000012795 verification Methods 0.000 claims description 20
- 230000009471 action Effects 0.000 claims description 3
- 230000003213 activating effect Effects 0.000 claims description 2
- 230000004044 response Effects 0.000 abstract description 10
- 230000001815 facial effect Effects 0.000 description 17
- 238000010586 diagram Methods 0.000 description 16
- 238000005516 engineering process Methods 0.000 description 13
- 238000000605 extraction Methods 0.000 description 9
- 238000012546 transfer Methods 0.000 description 9
- 238000013528 artificial neural network Methods 0.000 description 8
- 239000000284 extract Substances 0.000 description 8
- 238000012545 processing Methods 0.000 description 8
- 238000013473 artificial intelligence Methods 0.000 description 5
- 238000004590 computer program Methods 0.000 description 5
- 230000008569 process Effects 0.000 description 4
- 230000001413 cellular effect Effects 0.000 description 3
- 230000008859 change Effects 0.000 description 3
- 238000012986 modification Methods 0.000 description 3
- 230000004048 modification Effects 0.000 description 3
- 238000012015 optical character recognition Methods 0.000 description 3
- 238000013527 convolutional neural network Methods 0.000 description 2
- 238000012937 correction Methods 0.000 description 2
- 230000036541 health Effects 0.000 description 2
- 238000010801 machine learning Methods 0.000 description 2
- 238000011017 operating method Methods 0.000 description 2
- 230000002093 peripheral effect Effects 0.000 description 2
- 230000000306 recurrent effect Effects 0.000 description 2
- 210000003462 vein Anatomy 0.000 description 2
- 230000001133 acceleration Effects 0.000 description 1
- 230000008901 benefit Effects 0.000 description 1
- 230000002457 bidirectional effect Effects 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 230000010267 cellular communication Effects 0.000 description 1
- 238000010835 comparative analysis Methods 0.000 description 1
- 239000004020 conductor Substances 0.000 description 1
- 238000012790 confirmation Methods 0.000 description 1
- 239000013256 coordination polymer Substances 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000007613 environmental effect Effects 0.000 description 1
- 210000004709 eyebrow Anatomy 0.000 description 1
- 210000000887 face Anatomy 0.000 description 1
- 239000000446 fuel Substances 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
- 230000003155 kinesthetic effect Effects 0.000 description 1
- 239000004973 liquid crystal related substance Substances 0.000 description 1
- 238000013507 mapping Methods 0.000 description 1
- 239000011159 matrix material Substances 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 230000000737 periodic effect Effects 0.000 description 1
- 230000002787 reinforcement Effects 0.000 description 1
- 230000005236 sound signal Effects 0.000 description 1
- 230000000638 stimulation Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
- 239000000758 substrate Substances 0.000 description 1
- 230000000007 visual effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/16—Human faces, e.g. facial parts, sketches or expressions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
Definitions
- Various embodiments of the present disclosure disclose a method and apparatus for providing a mobile identification document using an electronic device.
- PDAs personal digital assistants
- smart phones smart phones
- tablet PCs personal computers
- wearable devices are widely used.
- a hardware part and/or a software part of the electronic device are continuously being developed.
- An identification card may represent a document, such as an identification card, driver's license, and/or passport, maintained by a state authority and capable of authenticating a user (eg, identification).
- an identification card to prove identification information exists in the form of a plastic card and may need to be carried at all times.
- various physical cards are replaced by mobile devices, such as payment services using electronic devices, requirements are increasing so that an identification card capable of proving a user's identity can be stored and used in an electronic device.
- a standard specification is being established so that an identification card issued by a government agency can be issued and used in an electronic device.
- ISO 18013-5 may represent a standard specification defined by ISO for a mobile driver's license (mDL).
- the user may store the user's driver's license in the electronic device and, if necessary, show the mobile driver's license using the electronic device even if the user does not carry the current plastic driver's license.
- a mobile ID by exposing only necessary information through personal authentication, problems of illegal use, counterfeiting, and/or duplication can be prevented, and the mobile ID has various advantages that can be easily authenticated using an electronic device As such, discussions about mobile ID are actively underway.
- the electronic device After the electronic device completes the personal authentication operation for the mobile ID, the user's latest photo (eg, a recently taken selfie photo) is updated on the mobile ID, so that the identification can be performed more intuitively.
- the user's latest photo eg, a recently taken selfie photo
- Various embodiments are disclosed with respect to a method and apparatus capable of electronically verifying a mobile identity card and the face of a mobile identity presenter (eg, a user) by an electronic device.
- An electronic device includes a communication module, a memory, a display module, and a processor operatively connected to the communication module, the memory, and the display module, wherein the processor is for a mobile ID service Execute the application, obtain ID information based on a user input, display the ID information through the display module, obtain an image for an ID photo of a mobile ID based on a photo update request, and add the ID information to the image based on the face matching, and based on the result of the face matching, through the communication module, transmits a message requesting issuance of a mobile ID based on the image to the server, and through the communication module, the server Receive a mobile ID including an identification photo corresponding to the image from the mobile ID, and store the mobile ID in a secure area of the memory.
- An operating method of an electronic device includes an operation of executing an application for a mobile identification service, an operation of acquiring identification information based on a user input, an operation of displaying the identification information through a display module; Based on the photo update request, the operation of obtaining an image for the ID photo of the mobile ID, the operation of performing face matching based on the image, the operation of performing face matching based on the result of the face matching, through the communication module, based on the image transmitting a message requesting issuance of a mobile ID to the server, receiving a mobile ID including an ID photo corresponding to the image from the server through the communication module, and storing the mobile ID in the memory It may include an operation of saving to a secure area.
- a computer-readable recording medium recording a program for executing the method in a processor may be included.
- a photo of a mobile ID capable of proving a user's identity is updated with the user's latest photo (eg, a recently taken selfie photo) using the electronic device.
- the user's latest photo eg, a recently taken selfie photo
- the mobile ID and the face of the ID presenter may be electronically verified by the electronic device, thereby increasing the objectivity of self-authentication.
- FIG. 1 is a block diagram of an electronic device in a network environment according to various embodiments of the present disclosure
- FIG. 2 is a diagram illustrating an example of a system structure including an electronic device, a server, and a reader device according to various embodiments of the present disclosure
- FIG. 3 is a diagram schematically illustrating a configuration of an electronic device according to various embodiments of the present disclosure
- FIG. 4 is a diagram illustrating an operation scenario of issuing a mobile ID between an electronic device and a server according to various embodiments of the present disclosure
- FIG. 5 is a flowchart illustrating an operation of an electronic device according to various embodiments of the present disclosure
- FIG. 6 is a flowchart illustrating an operation of receiving a mobile ID from an electronic device according to various embodiments of the present disclosure
- FIG. 7 is a diagram for explaining an example of a user interface provided by an electronic device according to various embodiments of the present disclosure.
- FIG. 8 is a flowchart illustrating an operation of updating an ID photo of a mobile ID in an electronic device according to various embodiments of the present disclosure
- 9A and 9B are diagrams for explaining an example of a user interface provided by an electronic device according to various embodiments of the present disclosure.
- FIG. 10 is a diagram for describing a face matching method in an electronic device according to various embodiments of the present disclosure.
- FIG. 11 is a diagram illustrating an operation scenario of using a mobile ID electronically between an electronic device and a reader device according to various embodiments of the present disclosure
- FIG. 1 is a block diagram of an electronic device 101 in a network environment 100 according to various embodiments of the present disclosure.
- an electronic device 101 communicates with an electronic device 102 through a first network 198 (eg, a short-range wireless communication network) or a second network 199 . It may communicate with the electronic device 104 or the server 108 through (eg, a long-distance wireless communication network). According to an embodiment, the electronic device 101 may communicate with the electronic device 104 through the server 108 .
- a first network 198 eg, a short-range wireless communication network
- a second network 199 e.g., a second network 199 . It may communicate with the electronic device 104 or the server 108 through (eg, a long-distance wireless communication network). According to an embodiment, the electronic device 101 may communicate with the electronic device 104 through the server 108 .
- the electronic device 101 includes a processor 120 , a memory 130 , an input module 150 , a sound output module 155 , a display module 160 , an audio module 170 , and a sensor module ( 176), interface 177, connection terminal 178, haptic module 179, camera module 180, power management module 188, battery 189, communication module 190, subscriber identification module 196 , or an antenna module 197 may be included.
- at least one of these components eg, the connection terminal 178
- may be omitted or one or more other components may be added to the electronic device 101 .
- some of these components are integrated into one component (eg, display module 160 ). can be
- the processor 120 for example, executes software (eg, a program 140) to execute at least one other component (eg, a hardware or software component) of the electronic device 101 connected to the processor 120 . It can control and perform various data processing or operations. According to one embodiment, as at least part of data processing or operation, the processor 120 converts commands or data received from other components (eg, the sensor module 176 or the communication module 190 ) to the volatile memory 132 . may be stored in the volatile memory 132 , and may process commands or data stored in the volatile memory 132 , and store the result data in the non-volatile memory 134 .
- software eg, a program 140
- the processor 120 converts commands or data received from other components (eg, the sensor module 176 or the communication module 190 ) to the volatile memory 132 .
- the volatile memory 132 may be stored in the volatile memory 132 , and may process commands or data stored in the volatile memory 132 , and store the result data in the non-volatile memory 134 .
- the processor 120 is a main processor 121 (eg, a central processing unit (CPU) or an application processor (AP)) or an auxiliary processor capable of operating independently or together with it ( 123) (eg, graphic processing unit (GPU), neural network processing unit (NPU), image signal processor (ISP), sensor hub processor, or communication processor (CP, communication processor)) may be included.
- main processor 121 eg, a central processing unit (CPU) or an application processor (AP)
- auxiliary processor capable of operating independently or together with it eg, graphic processing unit (GPU), neural network processing unit (NPU), image signal processor (ISP), sensor hub processor, or communication processor (CP, communication processor)
- the main processor 121 may use less power than the main processor 121 or may be set to be specialized for a specified function.
- the auxiliary processor 123 may be implemented separately from or as a part of the main processor 121 .
- the auxiliary processor 123 is, for example, on behalf of the main processor 121 while the main processor 121 is in an inactive (eg, sleep) state, or the main processor 121 is At least one of the components of the electronic device 101 (eg, the display module 160 , the sensor module 176 , or At least some of functions or states related to the communication module 190 may be controlled.
- the coprocessor 123 eg, an image signal processor or a communication processor
- the auxiliary processor 123 may include a hardware structure specialized for processing an artificial intelligence model.
- Artificial intelligence models can be created through machine learning. Such learning may be performed, for example, in the electronic device 101 itself on which artificial intelligence is performed, or may be performed through a separate server (eg, the server 108).
- the learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but in the above example not limited
- the artificial intelligence model may include a plurality of artificial neural network layers.
- Artificial neural networks include deep neural networks (DNNs), convolutional neural networks (CNNs), recurrent neural networks (RNNs), restricted boltzmann machines (RBMs), deep belief networks (DBNs), bidirectional recurrent deep neural networks (BRDNNs), It may be one of deep Q-networks or a combination of two or more of the above, but is not limited to the above example.
- the artificial intelligence model may include, in addition to, or alternatively, a software structure in addition to the hardware structure.
- the memory 130 may store various data used by at least one component of the electronic device 101 (eg, the processor 120 or the sensor module 176 ).
- the data may include, for example, input data or output data for software (eg, the program 140 ) and instructions related thereto.
- the memory 130 may include a volatile memory 132 or a non-volatile memory 134 .
- the program 140 may be stored as software in the memory 130 , and may include, for example, an operating system (OS) 142 , middleware 144 , or an application 146 . there is.
- OS operating system
- middleware middleware
- application application
- the input module 150 may receive a command or data to be used in a component (eg, the processor 120 ) of the electronic device 101 from the outside (eg, a user) of the electronic device 101 .
- the input module 150 may include, for example, a microphone, a mouse, a keyboard, a key (eg, a button), or a digital pen (eg, a stylus pen).
- the sound output module 155 may output a sound signal to the outside of the electronic device 101 .
- the sound output module 155 may include, for example, a speaker or a receiver.
- the speaker can be used for general purposes such as multimedia playback or recording playback.
- the receiver may be used to receive an incoming call. According to one embodiment, the receiver may be implemented separately from or as part of the speaker.
- the display module 160 may visually provide information to the outside (eg, a user) of the electronic device 101 .
- the display module 160 may include, for example, a control circuit for controlling a display, a hologram device, or a projector and a corresponding device.
- the display module 160 may include a touch sensor configured to sense a touch or a pressure sensor configured to measure the intensity of a force generated by the touch.
- the audio module 170 may convert a sound into an electric signal or, conversely, convert an electric signal into a sound. According to an embodiment, the audio module 170 acquires a sound through the input module 150 or an external electronic device (eg, a sound output module 155 ) directly or wirelessly connected to the electronic device 101 . A sound may be output through the electronic device 102 (eg, a speaker or headphones).
- an external electronic device eg, a sound output module 155
- a sound may be output through the electronic device 102 (eg, a speaker or headphones).
- the sensor module 176 detects an operating state (eg, power or temperature) of the electronic device 101 or an external environmental state (eg, user state), and generates an electrical signal or data value corresponding to the sensed state. can do.
- the sensor module 176 may include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, It may include a temperature sensor, a humidity sensor, or an illuminance sensor.
- the interface 177 may support one or more designated protocols that may be used by the electronic device 101 to directly or wirelessly connect with an external electronic device (eg, the electronic device 102 ).
- the interface 177 may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, a secure digital (SD) card interface, or an audio interface.
- HDMI high definition multimedia interface
- USB universal serial bus
- SD secure digital
- the connection terminal 178 may include a connector through which the electronic device 101 can be physically connected to an external electronic device (eg, the electronic device 102 ).
- the connection terminal 178 may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (eg, a headphone connector).
- the haptic module 179 may convert an electrical signal into a mechanical stimulus (eg, vibration or movement) or an electrical stimulus that the user can perceive through tactile or kinesthetic sense.
- the haptic module 179 may include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
- the camera module 180 may capture still images and moving images. According to an embodiment, the camera module 180 may include one or more lenses, image sensors, image signal processors, or flashes.
- the power management module 188 may manage power supplied to the electronic device 101 .
- the power management module 188 may be implemented as, for example, at least a part of a power management integrated circuit (PMIC).
- PMIC power management integrated circuit
- the battery 189 may supply power to at least one component of the electronic device 101 .
- battery 189 may include, for example, a non-rechargeable primary cell, a rechargeable secondary cell, or a fuel cell.
- the communication module 190 is a direct (eg, wired) communication channel or a wireless communication channel between the electronic device 101 and an external electronic device (eg, the electronic device 102, the electronic device 104, or the server 108). It can support establishment and communication performance through the established communication channel.
- the communication module 190 may include one or more communication processors that operate independently of the processor 120 (eg, an application processor) and support direct (eg, wired) communication or wireless communication.
- the communication module 190 is a wireless communication module 192 (eg, a cellular communication module, a short-range communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module 194 (eg, : It may include a LAN (local area network) communication module, or a power line communication module).
- GNSS global navigation satellite system
- a corresponding communication module among these communication modules is a first network 198 (eg, a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network 199 (eg, legacy It may communicate with the external electronic device 104 through a cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (eg, a telecommunication network such as a LAN or a wide area network (WAN)).
- a first network 198 eg, a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)
- a second network 199 eg, legacy It may communicate with the external electronic device 104 through a cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (eg, a telecommunication network such as a LAN or a wide area network (WAN)).
- the wireless communication module 192 uses the subscriber information (eg, International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module 196 within a communication network such as the first network 198 or the second network 199 .
- the electronic device 101 may be identified or authenticated.
- the wireless communication module 192 may support a 5G network after a 4G network and a next-generation communication technology, for example, a new radio access technology (NR).
- NR access technology is a high-speed transmission of high-capacity data (eMBB, enhanced mobile broadband), minimization of terminal power and access to multiple terminals (mMTC, massive machine type communications), or high reliability and low latency (URLLC, ultra-reliable and low-latency). communications) can be supported.
- the wireless communication module 192 may support a high frequency band (eg, mmWave band) to achieve a high data rate, for example.
- a high frequency band eg, mmWave band
- the wireless communication module 192 includes various technologies for securing performance in a high-frequency band, for example, beamforming, massive multiple-input and multiple-output (MIMO), all-dimensional multiplexing. It may support technologies such as input/output (FD-MIMO, full dimensional MIMO), an array antenna, analog beam-forming, or a large scale antenna.
- the wireless communication module 192 may support various requirements specified in the electronic device 101 , an external electronic device (eg, the electronic device 104 ), or a network system (eg, the second network 199 ).
- the wireless communication module 192 may include a peak data rate (eg, 20 Gbps or more) for realizing eMBB, loss coverage (eg, 164 dB or less) for realizing mMTC, or U-plane latency for realizing URLLC ( Example: downlink (DL) and uplink (UL) each 0.5 ms or less, or round trip 1 ms or less).
- a peak data rate eg, 20 Gbps or more
- loss coverage eg, 164 dB or less
- U-plane latency for realizing URLLC
- the antenna module 197 may transmit or receive a signal or power to the outside (eg, an external electronic device).
- the antenna module 197 may include an antenna including a conductor formed on a substrate (eg, a PCB) or a radiator formed of a conductive pattern.
- the antenna module 197 may include a plurality of antennas (eg, an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network such as the first network 198 or the second network 199 is connected from the plurality of antennas by, for example, the communication module 190 . can be selected. A signal or power may be transmitted or received between the communication module 190 and an external electronic device through the selected at least one antenna.
- other components eg, a radio frequency integrated circuit (RFIC)
- RFIC radio frequency integrated circuit
- the antenna module 197 may form a mmWave antenna module.
- the mmWave antenna module comprises a printed circuit board, an RFIC disposed on or adjacent to a first side (eg, bottom side) of the printed circuit board and capable of supporting a designated high frequency band (eg, mmWave band); and a plurality of antennas (eg, an array antenna) disposed on or adjacent to a second side (eg, top or side) of the printed circuit board and capable of transmitting or receiving signals of the designated high frequency band. can do.
- peripheral devices eg, a bus, general purpose input and output (GPIO), serial peripheral interface (SPI), or mobile industry processor interface (MIPI)
- GPIO general purpose input and output
- SPI serial peripheral interface
- MIPI mobile industry processor interface
- the command or data may be transmitted or received between the electronic device 101 and the external electronic device 104 through the server 108 connected to the second network 199 .
- Each of the external electronic devices 102 or 104 may be the same as or different from the electronic device 101 .
- all or a part of operations executed in the electronic device 101 may be executed in one or more external electronic devices 102 , 104 , or 108 .
- the electronic device 101 may perform the function or service itself instead of executing the function or service itself.
- one or more external electronic devices may be requested to perform at least a part of the function or the service.
- One or more external electronic devices that have received the request may execute at least a part of the requested function or service, or an additional function or service related to the request, and transmit a result of the execution to the electronic device 101 .
- the electronic device 101 may process the result as it is or additionally and provide it as at least a part of a response to the request.
- cloud computing distributed computing, mobile edge computing (MEC), or client-server computing technology may be used.
- the electronic device 101 may provide an ultra-low latency service using, for example, distributed computing or mobile edge computing.
- the external electronic device 104 may include an Internet of things (IoT) device.
- Server 108 may be an intelligent server using machine learning and/or neural networks.
- the external electronic device 104 or the server 108 may be included in the second network 199 .
- the electronic device 101 may be applied to an intelligent service (eg, smart home, smart city, smart car, or health care) based on 5G communication technology and IoT-related technology.
- the electronic device may have various types of devices.
- the electronic device may include, for example, a portable communication device (eg, a smart phone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a home appliance device.
- a portable communication device eg, a smart phone
- a computer device e.g., a smart phone
- a portable multimedia device e.g., a portable medical device
- a camera e.g., a portable medical device
- a camera e.g., a portable medical device
- a camera e.g., a portable medical device
- a wearable device e.g., a smart bracelet
- a home appliance device e.g., a home appliance
- first”, “second”, or “first” or “second” may simply be used to distinguish the component from other components in question, and may refer to components in other aspects (e.g., importance or order) is not limited. It is said that one (eg, first) component is “coupled” or “connected” to another (eg, second) component, with or without the terms “functionally” or “communicatively”. When referenced, it means that one component can be connected to the other component directly (eg by wire), wirelessly, or through a third component.
- module used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and is interchangeable with terms such as, for example, logic, logic block, component, or circuit.
- a module may be an integrally formed part or a minimum unit or a part of the part that performs one or more functions.
- the module may be implemented in the form of an application-specific integrated circuit (ASIC).
- ASIC application-specific integrated circuit
- one or more instructions stored in a storage medium may be implemented as software (eg, the program 140) including
- a processor eg, processor 120
- a device eg, electronic device 101
- the one or more instructions may include code generated by a compiler or code executable by an interpreter.
- the device-readable storage medium may be provided in the form of a non-transitory storage medium.
- 'non-transitory' only means that the storage medium is a tangible device and does not include a signal (eg, electromagnetic wave), and this term is used in cases where data is semi-permanently stored in the storage medium and It does not distinguish between temporary storage cases.
- a signal eg, electromagnetic wave
- the method according to various embodiments disclosed in this document may be included in a computer program product (computer program product) and provided.
- Computer program products may be traded between sellers and buyers as commodities.
- the computer program product is distributed in the form of a machine-readable storage medium (eg compact disc read only memory (CD-ROM)), or via an application store (eg Play Store TM ) or on two user devices ( It can be distributed online (eg download or upload), directly between smartphones (eg smartphones).
- a part of the computer program product may be temporarily stored or temporarily generated in a machine-readable storage medium such as a memory of a server of a manufacturer, a server of an application store, or a relay server.
- each component (eg, module or program) of the above-described components may include a singular or a plurality of entities, and some of the plurality of entities may be separately disposed in other components. there is.
- one or more components or operations among the above-described corresponding components may be omitted, or one or more other components or operations may be added.
- a plurality of components eg, a module or a program
- the integrated component may perform one or more functions of each component of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. .
- operations performed by a module, program, or other component are executed sequentially, in parallel, repetitively, or heuristically, or one or more of the operations are executed in a different order. , may be omitted, or one or more other operations may be added.
- FIG. 2 is a diagram illustrating an example of a system structure including an electronic device, a server, and a reader device according to various embodiments of the present disclosure
- the example of FIG. 2 may represent an example of a system architecture for a mobile ID (or mobile ID service).
- the identity card is a certificate (or identity card) managed by a national authority and capable of authenticating a user (eg, identification), such as an identification card, driver's license, and/or passport. real-name verification certificate) may be included.
- the mobile ID card or mobile ID service may include a service for using the physical ID as described above through the electronic device 101 (or mobile).
- a system structure for a mobile ID may include a server 201 , a reader device 301 , and an electronic device 101 .
- the server 201 may include, for example, a server of an issuing authority (IA) of a mobile ID.
- the server 201 may store and manage identification information of a physical ID.
- identification information corresponding to a driver's license acquired by a user eg, a licensee
- the identification information may include, for example, the user's personal information such as user name, identification photo (eg, face image), date of birth, and/or gender, the user's signature, identification number (eg, license number). ), the issuing authority, and/or identification information associated with the user's acquired ID, such as renewal period.
- identification information on the driver's license obtained by the user and personal information of the user may be registered in the server 201 .
- the reader device 301 is a device of a verifier (eg, as a user's identity verifier, for example, a police officer or a seller of a store), and obtains at least some information included in the mobile ID from the electronic device 101 , A device for verifying the user identity based on the identity card may be included.
- a verifier eg, as a user's identity verifier, for example, a police officer or a seller of a store
- a device for verifying the user identity based on the identity card may be included.
- the electronic device 101 wirelessly communicates with the server 201 through a first network (eg, Wi-Fi network and/or cellular network), and a reader device (eg, out of band (OOB) network) through a second network (eg, out of band (OOB) network).
- a first network eg, Wi-Fi network and/or cellular network
- a reader device eg, out of band (OOB) network
- a second network eg, out of band (OOB) network
- 301 may include various types of devices including a function of providing data related to a mobile ID to the server 201 and/or the reader device 301 .
- the electronic device 101 may include a mobile device such as a smart phone, a tablet personal computer (PC), and/or a wearable device.
- the electronic device 101 receives a mobile ID from the server 201 in the mobile ID system, stores it in a secure area (eg, TA and/or eSE), and uses the mobile ID in an environment (eg, offline).
- a secure area eg, TA and/or eSE
- online (online) mode) may indicate a holder that provides (eg, displays or transmits) at least some information of the mobile ID.
- the security region may be a memory (eg, a space (or region) included in a partial region of the memory 130 of FIG. 1 , or a separate chip physically separated from the memory 130 .
- the electronic device 101 may verify whether the identity information for the mobile ID matches the identity information for the mobile ID while interacting with the server 201.
- the electronic device 101 may include the reader device 301 . and at least some information of the mobile ID through a specified authentication protocol.
- the mobile ID service is provided while the mobile ID (or mobile ID data) is directly issued from the server 201 (eg, issuing organization) from the server 201 .
- the server 201 eg, issuing organization
- the operation according to the offline mode of the electronic device 101 may include, for example, a device engagement operation and a data transfer (offline) operation.
- the device engagement operation may include a pre-operation of connecting to perform data transfer between the electronic device 101 and the reader device 301 offline.
- the electronic device 101 is a parameter to be set with the reader device 301 for data transfer through an identification code (eg, QR code and/or barcode) or OOB communication (eg, NFC, near field communication).
- the (parameter) value may be included in the device engagement data, and the reader device 301 may read the device engagement data through an identification code or OOB communication connection.
- the electronic device 101 may generate an ephemeral public key for end-to-end encrypted communication and include it in device engagement data.
- the reader device 301 requests the electronic device 101 for desired mobile identification data (or data element) offline, and the electronic device 101 receives the data from the reader device 301 . It may include providing the requested mobile identification data offline.
- the reader device 301 generates an ephemeral key and encrypts it with a session key to request mobile ID data, and the electronic device 101 encrypts the mobile ID data with the session key ID data may be provided (eg end-to-end encrypted communication).
- the data transfer operation is performed between the electronic device 101 and the reader device 301 for OOB communication (eg, BLE, NFC, ultra-wide band (UWB), Zigbee, and/or Wi-Fi 2.4).
- OOB communication eg, BLE, NFC, ultra-wide band (UWB), Zigbee, and/or Wi-Fi 2.4.
- the online mode of the electronic device 101 represents an example in which the electronic device 101 provides a mobile ID service in a state in which a mobile ID (or mobile ID data) is not issued from the server 201 .
- the operation according to the online mode of the electronic device 101 may include, for example, a device engagement operation and a data transfer (offline) operation.
- the device engagement action may include a pre-action for the electronic device 101 to transmit the mobile identification data to the reader device 301 online.
- the electronic device 101 may generate address information (eg, URL) and a one-time token of the server 201 and include it in the device engagement data
- the reader device 301 may include an identification code (eg, : Device engagement data can be read via QR code and/or barcode) or OOB (eg NFC) communication.
- the reader device 301 accesses the server 201 according to address information of the server 201 included in the device engagement data of the electronic device 101, and the electronic device 101 ) may include an operation of online requesting the mobile ID data including the token delivered to the server 201 .
- the server 201 may check the token obtained from the reader device 301 , and transmit the mobile ID data requested by the reader device 301 to the reader device 301 online.
- the communication channel for online communication between the server 201 and the reader device 301 may be protected by encrypted communication using HTTPS (hypertext transfer protocol secure).
- An embodiment of the present disclosure may include an example of operation in an offline mode in which the electronic device 101 operates in a state in which the mobile ID is directly issued from the server 201 in a system structure for a mobile ID service.
- a user may be issued a mobile ID using the electronic device 101 , and register an ID photo used in the mobile ID to correspond to the real ID in the server 201 . It is possible to update the photo selected by the user, not the photo that has been edited.
- FIG. 3 is a diagram schematically illustrating a configuration of an electronic device according to various embodiments of the present disclosure
- the electronic device 101 may include a communication module 192 , a display module 160 , a camera module 180 , a memory 130 , and a processor 120 . .
- the communication module 192 may support a legacy network (eg, a 3G network and/or a 4G network), a 5G network, an out of band (OOB), and/or a next-generation communication technology (eg, a new radio (NR) technology). According to an embodiment, the communication module 192 may correspond to the wireless communication module 192 as illustrated in FIG. 1 .
- the communication module 192 according to an embodiment includes a first communication module configured to support wireless communication of the electronic device 101 through a first network (eg, a cellular network), and an OOB (eg, NFC, BLE, and/or Alternatively, it may include a second communication module configured to support wireless communication of the electronic device 101 based on wireless fidelity (Wi-Fi) 2.4 GHz.
- a first network eg, a cellular network
- OOB eg, NFC, BLE
- the electronic device 101 may communicate with the server 201 through the first network using the first communication module.
- the electronic device 101 uses a second communication module to communicate with a second network different from the first network (eg, short-range communication such as Bluetooth, NFC, Wi-Fi direct, or infrared data association (IrDA)). network) to communicate with the reader device 301 .
- short-range communication such as Bluetooth, NFC, Wi-Fi direct, or infrared data association (IrDA)
- IrDA infrared data association
- the display module 160 may visually provide information (eg, a mobile ID) to the outside (eg, a user) of the electronic device 101 .
- the display module 160 includes a touch sensing circuit (or a touch sensor) (not shown), a pressure sensor capable of measuring the intensity of a touch, and/or a touch panel for detecting a magnetic field type stylus pen (eg, : a digitizer), and based on a touch sensing circuit, a pressure sensor and/or a touch panel, a signal for a specific position of the display module 160 (eg, voltage, light quantity, resistance, electromagnetic signal and/or electric charge quantity) A touch input and/or a hovering input (or a proximity input) may be sensed by measuring a change in .
- the display module 160 may be configured as a liquid crystal display (LCD), an organic light emitted diode (OLED), an active matrix organic light emitted diode (AMOLED), or a flexible display.
- LCD liquid crystal display
- OLED organic light
- the display module 160 under the control of the processor 120, provides a variety of information (eg, a mobile identification layout), an image object and/or a code object (eg, a capture layout) corresponding to a mobile identification request from a user or reader device 301 . : QR code and/or barcode)) can be provided visually.
- the display module 160 may display related information corresponding to the mobile ID on the execution screen of the service application 330 , the mobile ID data stored in the memory 130 , or the execution screen of the service application 330 . can
- the camera module 180 may capture still images and moving images. According to an embodiment, the camera module 180 may support photographing (eg, taking a selfie) for an ID photo to be used in a mobile ID while executing the service application 330 under the control of the processor 120 .
- photographing eg, taking a selfie
- the memory 130 may correspond to the memory 130 as described in the description with reference to FIG. 1 .
- the memory 130 may store various data used by the electronic device 101 .
- the data may include, for example, input data or output data for the service application 330 (eg, the program 140 of FIG. 1 ) and a command related thereto.
- the memory 130 may store instructions that cause the processor 120 to operate when executed.
- the service application 330 may be stored as software (eg, the program 140 of FIG. 1 ) on the memory 130 , and may be executable by the processor 120 .
- the service application 330 may be an application that can use the mobile ID service (eg, a mobile ID application), and may include a fast identity online (FIDO) authentication function for user authentication.
- a mobile ID application e.g., a mobile ID application
- FIDO fast identity online
- the memory 130 may include a security area 340 .
- the security area 340 may store personal information included in the mobile ID, identification information, and/or encryption key.
- the mobile ID may represent, for example, a mobile electronic ID (eg, eID, electronic identification), and the electronic ID may include a national ID card, driver's license, health insurance card, and/or may be used to encompass all identification cards such as electronic passports.
- the electronic device 101 may separately set the security area 340 in the memory 130 to enhance the security of the mobile ID, and the security area 340 may include a built-in security chip or a built-in security area ( For example, eSE, embedded secure element) may be implemented.
- the processor 120 may control each of the server 201 or the reader device 301 and a related operation for providing a mobile ID service. According to an embodiment, the processor 120 may control an operation related to updating the ID photo of the mobile ID when the electronic device 101 issues the mobile ID from the server 201 or in a state in which it is issued. According to an embodiment, the processor 120 includes a service module 310 (or service means) that can use the mobile ID service and a security module 320 that can control a security-related operation when using the mobile ID service ( or security means). For example, the service module 310 may process a function corresponding to the service application 330 , and the security module 320 may process a function corresponding to the security area 340 .
- the components (eg, the service module 310 and the security module 320 ) included in the processor 120 may be understood as, for example, a hardware module (eg, circuitry). However, various embodiments are not limited thereto.
- components included in the processor 120 eg, the service module 310 and the security module 320
- the components (eg, the service module 310 and the security module 320 ) included in the processor 120 are a storage medium (eg, a storage medium readable by the processor 120 ). It may be implemented as software (eg, the service application 330 and the security area 340) including one or more instructions stored in the memory 130).
- the operations performed by the processor 120 may be stored in the memory 130 and, when executed, may be executed by instructions that cause the processor 120 to operate.
- the electronic device 101 includes a communication module (eg, the communication module 192 of FIG. 1 ), a memory (eg, the memory 130 of FIG. 1 ), and a display module (eg, the display module of FIG. 1 ). a display module 160), and a processor operatively connected to the communication module, the memory, and the display module (eg, the processor 120 in FIG.
- a communication module eg, the communication module 192 of FIG. 1
- a memory eg, the memory 130 of FIG. 1
- a display module eg, the display module of FIG. 1
- a display module 160 operatively connected to the communication module, the memory, and the display module (eg, the processor 120 in FIG.
- the processor 120 provides a mobile ID service for executing an application for, obtaining ID information based on a user input, displaying the ID information through the display module, and obtaining an image for an ID photo of a mobile ID based on a photo update request, and the image performs face matching based on , and based on the result of the face matching, transmits a message requesting issuance of a mobile ID based on the image to the server through the communication module, and through the communication module, the Receive a mobile ID including an ID photo corresponding to the image from the server, and store the mobile ID in a secure area of the memory.
- the processor 120 when the application is executed, the processor 120 performs user authentication for releasing a security function related to the execution of the application, and based on the result of the user authentication, the execution of the application It is set to display a screen, and the user authentication may include biometric authentication and/or password authentication based on a fast identity online (FIDO) authentication method.
- FIDO fast identity online
- the processor 120 detects a user input requesting issuance of a mobile ID from a user, and based on the user input, a user for determining suitability of a user requesting issuance of the mobile ID It is configured to perform authentication and provide an interface related to obtaining the identification information based on the result of the user authentication, and the user authentication for determining the suitability may include a public certificate authentication and/or text message authentication. .
- the processor 120 may acquire the ID information through a user input, photographing a physical ID, contacting a physical ID, and/or interacting with a server.
- the processor 120 detects an input for updating the picture based on a specified object for updating the picture, activates a camera module based on the input, and performs a preview. It can be provided to provide guidelines related to photography.
- the processor 120 may perform face verification based on matching between the image and the image stored in the secure area of the memory.
- the processor 120 determines whether the face matching succeeds, and when the face matching fails, provides a guide related to re-photography, and when the face matching succeeds,
- the message including the ID information, the image, and photo update request information for requesting to correct the photo of the mobile ID using the image may be transmitted to the server.
- the processor 120 may manage an expiration period related to the mobile ID.
- the processor 120 may guide the update of the mobile ID based on a predetermined time point specified in the expiration period.
- the processor 120 may provide a related notice to the user to update the mobile ID and/or renew the physical ID at a predetermined time specified in the expiration period.
- Operations performed by the electronic device 101 to be described below may be executed by the processor 120 including at least one processing circuitry of the electronic device 101 .
- the operations performed by the electronic device 101 may be stored in the memory 130 and, when executed, may be executed by instructions that cause the processor 120 to operate.
- FIG. 4 is a diagram illustrating an operation scenario of issuing a mobile ID between an electronic device and a server according to various embodiments of the present disclosure
- the electronic device 101 matches (or verifies) various biometric information (eg, face authentication data and/or fingerprint authentication data) for a user to use various security services of the electronic device 101 .
- biometric information eg, face authentication data and/or fingerprint authentication data
- FIG. 4 may show an example of first issuing a mobile ID to the electronic device 101 through wireless communication between the electronic device 101 and the server 201 .
- the electronic device 101 may perform user authentication.
- the electronic device 101 determines whether the user is an actual user (or owner) of the electronic device 101 for issuance of the mobile ID (eg, a user requesting mobile ID issuance).
- user authentication which is a binding operation, may be performed.
- the electronic device 101 may perform user authentication through at least one designated authentication method such as biometric authentication (eg, face authentication or fingerprint authentication), password authentication, public certificate authentication, and/or text message authentication.
- biometric authentication eg, face authentication or fingerprint authentication
- password authentication eg., password authentication, public certificate authentication, and/or text message authentication.
- the electronic device 101 may obtain identification information.
- the electronic device 101 may acquire the user's real ID or ID information from the server 201 based on a user input.
- the electronic device 101 provides the user with a guide for obtaining ID information (eg, a guide related to direct input, ID photo taking, contact with a physical ID, and/or receiving ID information from a server) to the user, You can have them enter your ID information from
- the user may directly input information on the physical identification card according to a guide to input information on the physical identification card, and the electronic device 101 may obtain identification information based on information input from the user. .
- the user may photograph the physical ID using the camera module 180 according to a guide to photograph the physical ID, and the electronic device 101 performs optical character recognition (OCR) and/or ID information may be obtained based on image recognition.
- OCR optical character recognition
- the user may contact the physical ID at a designated location of the electronic device 101 according to a guide to contact the physical ID with the electronic device 101 , and the electronic device 101 detects the touch of the physical ID Based on this, information stored in the real ID may be acquired using the communication module 192 through the IC chip or RFID included in the ID.
- the electronic device 101 requests the user's ID information from the server 201 after user authentication to the server 201 storing the user's ID information in order to obtain the ID information. ID information can be obtained.
- the electronic device 101 may provide (eg, display) a list of photos stored in the memory 130 and acquire an image based on a user's selection.
- the electronic device 101 may obtain a picture of the user. According to an embodiment, the electronic device 101 may display the obtained identification information through the display module 160 . According to an embodiment, the user may selectively perform whether to update a photo (eg, an ID photo) to be used for a mobile ID using the displayed ID information.
- a photo eg, an ID photo
- the mobile ID that can be issued to the user in the current state may be a mobile ID having the same photo (eg, ID photo) included in the physical ID (eg, driver's license) issued as a real thing.
- the user may wish to update the photo at the time of issuance of the physical ID to the photo of the user's face at the current time.
- the electronic device 101 may selectively provide a guide for a photo update operation according to a setting of the electronic device 101 when obtaining identification information in an operation for issuing a mobile ID, Based on the user's selection, the user's photo may be acquired from the user's selfie or from a photo pre-stored in the memory 130 of the electronic device 101 .
- the electronic device 101 may activate the camera module 180 of the electronic device 101 to update a photo, and may take a photo (eg, take a selfie) from the user.
- the electronic device 101 may additionally provide a condition and/or a guide for taking a picture having a standard suitable for a mobile ID in a picture taking operation. An operation of guiding photo taking corresponding to the standard of a mobile ID card will be described with reference to the drawings to be described later.
- the electronic device 101 may perform face information matching (or verification). According to an embodiment, the electronic device 101 compares the face image of the captured photo and the face image of the photo stored in the electronic device 101 to determine whether the captured photo is a photo of the user of the electronic device 101 .
- User authentication can be performed by matching.
- the electronic device 101 may use the face authentication model stored in the memory 130 (eg, the security area 340 ) of the electronic device 101 to determine whether the photographed picture is of the user.
- the electronic device 101 may request the user to retake the picture when the taken picture and the stored picture do not match, and if the failure is repeated more than a specified number of times, a step before updating the picture (eg: ID information acquisition operation), or may end (or initialize) the mobile ID issuance operation.
- a step before updating the picture eg: ID information acquisition operation
- the electronic device 101 may request the server 201 to issue a mobile ID with an updated photo of the ID based on the captured picture. For example, the electronic device 101 may transmit a mobile ID issuance request including a photographed photo to the server 201 .
- the electronic device 101 determines that the captured photo is the face data of the real user, and uses the face data (eg, the captured photo) to display the photo of the mobile ID. It may be requested to the server 201 to issue a modified mobile ID.
- identification information of the electronic device 101 eg, a device identifier of the electronic device 101 and/or a phone number of the electronic device 101
- at least some information of the identification information obtained in operation 403 may be provided to the server 201 .
- the server 201 may verify the electronic device 101 based on receiving the update request from the electronic device 101 .
- the server 201 may verify whether the electronic device 101 is a device suitable for a mobile ID request by interacting with the electronic device 101 .
- the server 201 may determine whether or not the identification information obtained from the electronic device 101 matches the identification information previously stored (or registered) in the server 201 related to the electronic device 101 . there is.
- the server 201 may update (or change) the photo data related to the user ID of the electronic device 101 registered in the server 201 with the photo data received from the electronic device 101 .
- the server 201 may set a period during which the updated photo can be used (eg, photo expiration period) and manage the expiration period for the updated photo.
- the expiration period may be set for a policy or security issue of the server 201 .
- the server 201 may generate a mobile ID using the updated photo data.
- the server 201 may apply (or replace) a photo of a pre-registered physical ID with an updated photo, and may generate a mobile ID for issuing to the electronic device 101 .
- the server 201 may transmit the mobile ID to the electronic device 101 .
- the server 201 may transmit the mobile ID to the electronic device 101 to issue the mobile ID to the electronic device 101 .
- the server 201 may transmit information on an expiration period related to an updated photo together and store it in the security area 340 of the electronic device 101 .
- the expiration period may be managed by the server 201 and may also be managed by the electronic device 101 .
- the electronic device 101 may receive the mobile ID from the server 201 , and store the mobile ID in the secure area 340 of the memory 130 .
- the electronic device 101 may store the mobile ID and the expiration period in the security area 340 by mapping (or relating to) the expiration period.
- the electronic device 101 may provide a notice to the user based on the expiration period. For example, the electronic device 101 may request the user to update the photo of the mobile ID through a notification before the expiration period is reached or at a specified point in time (eg, one week before the expiration, one month, or one day before the expiration). , after the expiration period, the use of the corresponding photo in the mobile ID may be restricted, and the use of the mobile ID may also be restricted.
- FIG. 5 is a flowchart illustrating a method of operating an electronic device according to various embodiments of the present disclosure
- an ID photo to be used in the mobile ID is updated, and the mobile ID with the ID photo updated is updated. It can represent the operation of receiving and saving.
- the processor 120 of the electronic device 101 may execute an application (eg, a service application 330 or a mobile identification application).
- the processor 120 may control the display module 160 to execute a specified application for the mobile ID and display an execution screen of the application based on a user input.
- the processor 120 may perform user authentication.
- the processor 120 may receive a user input requesting issuance of a mobile ID through an application, and perform an operation for user authentication based on the user input.
- the processor 120 performs biometric authentication (eg, face authentication, User authentication may be performed through at least one designated authentication method such as iris authentication or fingerprint authentication), password authentication, public certificate authentication, and/or text message authentication.
- the processor 120 may obtain identification information.
- the processor 120 may acquire the user's real ID or ID information from the server based on the user input.
- the processor 120 provides the user with a guide for obtaining ID information (eg, a guide related to direct input, ID photo taking, physical ID contact, and/or receiving ID information from a server) to the user, You can select a method for entering identification information from
- the user directly inputs information on the physical ID, takes a picture of the physical ID, contacts the physical ID with a designated location of the electronic device 101 to perform data communication, or receives the user's ID information.
- ID information may be input based on an input for requesting and receiving the user's ID information from the stored server 201 .
- the processor 120 may acquire identification information corresponding to the real identification card in an automatic or manual method based on any one method according to a user input.
- the processor 120 may display the obtained identification information.
- the processor 120 may control the display module 160 to display the obtained identification information through the execution screen of the application. An example thereof will be described with reference to FIG. 7 to be described later.
- the processor 120 may acquire an image (eg, a face image) based on the photo update request.
- the user may selectively perform whether or not to update the photo to be used for the mobile ID by using the displayed ID information.
- the processor 120 may acquire an image from a user's selfie taking or a picture pre-stored in the memory 130 of the electronic device 101 based on the user's selection.
- the processor 120 activates the camera module 180 of the electronic device 101 based on the user's input for updating a photo (eg, taking a selfie), and taking a picture from the user (eg, taking a selfie) can be performed.
- the processor 120 may additionally provide a condition and/or a guide for taking a picture having a standard suitable for a mobile ID in a picture taking operation. According to an embodiment, an operation of guiding photo taking corresponding to the standard of a mobile ID will be described with reference to the drawings to be described later.
- the processor 120 may perform face matching (or face verification).
- the processor 120 matches an image (eg, a face image) obtained by taking a photo (eg, taking a selfie) with an image (eg, a face image) stored in the electronic device 101 to authenticate the user can be performed.
- the processor 120 compares and analyzes the image of the face authentication model stored in the memory 130 (eg, the security area 340 ) of the electronic device 101 and the acquired image, and the acquired image is the user. It is possible to identify whether it is an image of According to an embodiment, a face matching operation will be described with reference to drawings to be described later.
- the processor 120 may request the server 201 to issue a mobile ID.
- the processor 120 may request the server 201 to issue a mobile ID based on the acquired image.
- the processor 120 may transmit a mobile ID issuance request message including ID information, acquired image, and photo update request information to the server 201 through the communication module 192 .
- the processor 120 may request the server 201 to correct and issue a photo of the mobile ID using the acquired image.
- the processor 120 may receive the mobile ID from the server 201 .
- the processor 120 may receive, from the server 201 , a mobile ID including a photo according to the acquired image through the communication module 192 .
- the processor 120 may store the mobile ID. According to an embodiment, when the mobile ID is received, the processor 120 may store the received mobile ID in the secure area 340 of the memory 130 . According to some embodiments, the processor 120 may store the personal information included in the mobile ID and the associated encryption key in the secure area 340 .
- FIG. 6 is a flowchart illustrating an operation of receiving a mobile ID from an electronic device according to various embodiments of the present disclosure
- the processor 120 of the electronic device 101 may execute an application (eg, a service application 330 or a mobile identification application) that can use a mobile ID service.
- the processor 120 may execute a designated application for the mobile ID based on a user input.
- the processor 120 displays an authentication screen related to user authentication or displays the execution screen of the application, depending on whether the application policy or security is set. can be controlled
- the user's personal information may be included, a security function (or lock function) may be set for security, and the user authenticates the user to release the security function related to the execution of the application You can use the application later.
- the processor 120 may perform user authentication (eg, first user authentication). According to an embodiment, when detecting the execution of the application, the processor 120 may perform user authentication according to the security setting of the application. For example, the processor 120 may perform user authentication to identify whether the user has access to the usage right of the application.
- user authentication eg, first user authentication
- user authentication related to application execution may include, for example, biometric authentication (eg, fingerprint, iris, face recognition, voice, and/or vein authentication) based on a fast identity online (FIDO) authentication method and/or or password authentication.
- biometric authentication eg, fingerprint, iris, face recognition, voice, and/or vein authentication
- FIDO fast identity online
- the processor 120 may control the display module 160 to display an execution screen of an application.
- the user authentication operation in operation 603 may be integrally performed after operation 605 according to the setting of the electronic device 101 .
- the processor 120 may detect a mobile ID issuance request.
- the processor 120 may receive a user input requesting issuance of a mobile ID through a designated menu of the application (eg, a mobile ID issuance menu).
- the processor 120 may perform user authentication (eg, second user authentication) for determining suitability of a user requesting issuance of a mobile ID based on a user input requesting issuance of a mobile ID. there is.
- the processor 120 may be configured separately from the first user authentication (or Additionally), user authentication may be performed through at least one designated authentication method such as public certificate authentication and/or text message authentication.
- the processor 120 may obtain identification information.
- the processor 120 when user authentication is completed, the processor 120 provides an interface for obtaining identification information, and based on the interface, user input, physical identification photographing, physical identification contact, and/or server ID information can be obtained by interacting with For example, the processor 120 provides the user with a guide for obtaining ID information (eg, a guide related to direct input, ID photo taking, physical ID contact, and/or receiving ID information from a server) to the user, You can select a method for entering identification information from a guide for obtaining ID information (eg, a guide related to direct input, ID photo taking, physical ID contact, and/or receiving ID information from a server) to the user, You can select a method for entering identification information from a guide for obtaining ID information (eg, a guide related to direct input, ID photo taking, physical ID contact, and/or receiving ID information from a server) to the user, You can select a method for entering identification information from a guide for obtaining ID information (eg, a guide related to direct input
- the user directly inputs information on the physical ID, takes a picture of the physical ID, contacts the physical ID with a designated location of the electronic device 101 to perform data communication, or receives the user's ID information.
- ID information may be input based on an input for requesting and receiving the user's ID information from the stored server 201 (eg, ID issuing server).
- the electronic device 101 obtains identification information corresponding to the real ID in an automatic (eg, acquisition by photographing or communication) or manual (eg, by direct input) method based on any one method according to a user input. can be obtained
- the processor 120 may display the obtained identification information.
- the processor 120 may control the display module 160 to display the obtained identification information through the execution screen of the application. An example thereof will be described with reference to FIG. 7 to be described later.
- the processor 120 may determine whether to update the photo. According to an embodiment, after displaying the identification information, the processor 120 may determine whether there is a user input for selecting a specified object (eg, the object 730 of FIG. 7 ) for photo update from the user. For example, the user may selectively update the photo to be used for the mobile ID based on the displayed ID information (eg, image information corresponding to the ID photo of the physical ID).
- a specified object eg, the object 730 of FIG. 7
- the user may selectively update the photo to be used for the mobile ID based on the displayed ID information (eg, image information corresponding to the ID photo of the physical ID).
- the processor 120 may request the server 201 to issue a mobile ID.
- the processor 120 transmits ID information to the server 201 in response to a user input for selecting a designated object (eg, the object 750 in FIG. 7 ) for issuing a mobile ID without a photo update request. may be provided (eg, transmitted) to the server 201 to issue a mobile ID corresponding to the ID information.
- the processor 120 may activate the camera module 180 .
- the processor 120 activates the camera module 180 of the electronic device 101 based on the user's input for updating a photo (eg, taking a selfie), and taking a picture from the user (eg, taking a selfie) shooting) can be performed.
- the processor 120 may additionally provide a condition and/or a guide for taking a picture having a standard suitable for a mobile ID in a picture taking operation. According to an embodiment, an operation of guiding photo taking corresponding to the standard of a mobile ID will be described with reference to the drawings to be described later.
- the processor 120 may provide (eg, display) a photo list stored in the memory 130 of the electronic device 101 .
- the processor 120 displays a list of photos stored in the memory 130 of the electronic device 101 through the display module 160 based on the user's input for updating photos (eg, selecting a saved photo), and , may receive an input for a photo from the user.
- the processor 120 may provide an option to take a photo or select a photo in response to a photo update selection, and may acquire an image from a photo taken or a stored photo according to the user's selection. .
- the processor 120 displays at least one photo (eg, a recent photo within a specified period (eg, one week or one month)) designated based on the captured (acquired) date from among the stored photo list. It may be displayed through the module 160 , and an input for a photo may be received from the user. According to an embodiment, the processor 120 displays, through the display module 160, at least one photo that meets the specifications of the mobile ID from among at least one designated photo based on the captured date, and receives an input for the photo from the user. can receive According to another embodiment, the processor 120 may display, through the display module 160, at least one picture that meets the specifications of the mobile ID from among the stored picture list, and may receive an input for the picture from the user.
- a photo eg, a recent photo within a specified period (eg, one week or one month)
- the processor 120 displays, through the display module 160, at least one photo that meets the specifications of the mobile ID from among at least one designated photo based on the captured date, and receives an input for the
- the processor 120 may acquire an image.
- the processor 120 may acquire an image (eg, a face image) from the camera module 180 based on photographing.
- the processor 120 may acquire an image selected by the user based on the photo list.
- the processor 120 may display the acquired image through the display module 160 based on the image acquisition, and may include an operation of deactivating the camera module 180 .
- the processor 120 may perform face matching (or face verification).
- the processor 120 matches an image (eg, a face image) obtained by taking a photo (eg, taking a selfie) with an image (eg, a face image) stored in the electronic device 101 to authenticate the user can be performed.
- the processor 120 compares and analyzes the image of the face authentication model stored in the memory 130 (eg, the security area 340 ) of the electronic device 101 and the acquired image, and the acquired image is the user. It can be identified whether it is an image of According to an embodiment, an operation of matching a face will be described with reference to drawings to be described later.
- the processor 120 may determine whether face matching is successful based on the result of face matching. According to an embodiment, when the processor 120 identifies the same user (eg, a user's face) based on the acquired image and the stored image, the processor 120 may determine the success of face matching. According to another embodiment, when the processor 120 identifies that the user is not the same user (eg, user face) based on the acquired image and the stored image, the processor 120 may determine that the face matching fails.
- the processor 120 may provide a guide related to re-photographing.
- the processor 120 may control the display module 160 to display a guide to failure and a guide to requesting retake of a photo to the user.
- the processor 120 may proceed to operation 615 based on a user input in response to re-taking a photo and perform operations 615 and subsequent operations. According to some embodiments, if the processor 120 fails to match the face more than a specified number of times, it may proceed to an operation prior to photo update (eg, an operation to obtain identification information) or terminate (or initialize) the operation of issuing a mobile identification card. there is.
- an operation prior to photo update eg, an operation to obtain identification information
- the processor 120 may request the server 201 to issue a mobile ID.
- the processor 120 responds to a user input for selecting an object (eg, the object 720 in FIG. 7 ) for issuing a mobile ID after image acquisition (eg, taking a picture for updating a picture),
- the ID information and the acquired image may be provided (eg, transmitted) to the server 201 , and the server 201 may be requested to issue a mobile ID corresponding to the ID information and the acquired image.
- the processor 120 may transmit a mobile ID issuance request message including ID information, acquired image, and photo update request information to the server 201 through the communication module 192 .
- the processor 120 corrects the ID photo of the mobile ID using the acquired image (eg, replaces the ID photo of the physical ID with another acquired image-based photo). It may request the server 201 to issue.
- the processor 120 may receive the mobile ID from the server 201 .
- the processor 120 may receive, from the server 201 , a mobile ID including a photo according to the acquired image through the communication module 192 .
- the processor 120 may store the mobile ID. According to an embodiment, when the mobile ID is received, the processor 120 may store the received mobile ID in the secure area 340 of the memory 130 . According to some embodiments, the processor 120 may store the personal information included in the mobile ID and the associated encryption key in the secure area 340 .
- FIG. 7 is a diagram for explaining an example of a user interface provided by an electronic device according to various embodiments of the present disclosure.
- FIG. 7 may show an example of a user interface in a state verified by input of ID information for issuance of a mobile ID and verification by the server after the execution of the application.
- FIG. 7 may show an example of a user interface (eg, an example screen) of a mobile ID that can be provided in an operation of issuing a mobile ID in the electronic device 101 .
- a user interface eg, an example screen
- the user interface for issuing a mobile identity may be implemented in various forms (eg, different arrangement positions of each information, a display form of each information, and/or a structure of each information) depending on the implementation.
- the user interface displays a card image 710 , identification information 720 , a photo update object 730 , a correction object 740 , and/or a registration object 750 corresponding to the real thing of the physical ID.
- the card image 710 may be an image of a physical ID or may include an image generated based on identification information input by a user.
- the photo image (eg, ID photo) displayed through the card image 710 in the mobile ID issuance operation may be an image corresponding to the ID photo of the physical ID.
- the identification information 720 may include information directly input by the user based on a physical ID, or information extracted and automatically inputted based on character recognition (eg, OCR) from a photographed image. there is.
- the user interface may include a camera object (eg, the camera object 900 of FIG. 9A ) for supporting photo taking for updating an ID photo (eg, updating a photo) used in the mobile ID.
- a camera object eg, the camera object 900 of FIG. 9A
- the electronic device 101 displays input (or generated) information related to the mobile ID based on the user interface, based on the user input selecting the photo update object 730
- the camera module 180 may be activated, and an execution screen related to picture taking for photo update may be displayed by overlaying it on the user interface, or the user interface may be switched to an execution screen related to picture taking and provided.
- the user may correct erroneously input information based on the selection of the correction object 740 or register the mobile ID based on information input based on the selection of the registration object 750 .
- the electronic device 101 may transmit the input information to the server 201 to request issuance of the mobile ID.
- the electronic device 101 uses the same photo (eg, a photo before performing the update) among the mobile IDs stored in the security area 340 . You can also change the photo on your mobile ID. For example, when the first photo of the first mobile ID is updated to the second photo among the mobile IDs stored in the memory 130 (eg, the security area 340) of the electronic device 101, the electronic device 101 , it is possible to identify at least one second mobile ID including the same photo as the first photo from among the stored mobile IDs.
- the electronic device 101 may update the photo of at least one second mobile ID identified from among the stored mobile IDs to the second photo. According to an embodiment, the electronic device 101 may propose to the user whether to update the photo of at least one second mobile ID (eg, provide an interface for requesting confirmation of whether to update the photo of another mobile ID).
- the electronic device 101 may receive one or more different types of mobile IDs for each server 201 (eg, an ID issuing server), and when executing a mobile ID, the electronic device 101 may be issued from the same issuing server. It is also possible to obtain updated update information from other mobile IDs, and update information of the executed mobile IDs based on the obtained update information.
- server 201 e.g, an ID issuing server
- FIG. 8 is a flowchart illustrating an operation of updating an ID photo of a mobile ID in an electronic device according to various embodiments of the present disclosure
- FIG. 8 an operation of updating (eg, updating a photo) an identification photo of a mobile ID (eg, mobile driver's license) issued by the server 201 in the electronic device 101 may be illustrated.
- updating eg, updating a photo
- a mobile ID eg, mobile driver's license
- the processor 120 of the electronic device 101 may execute an application (eg, a service application 330 or a mobile identification application) that can use a mobile ID service.
- the processor 120 may execute a designated application for the mobile ID based on a user input.
- the processor 120 displays an authentication screen related to user authentication or displays the execution screen of the application, depending on whether the application policy or security is set. can be controlled
- the application may include the user's personal information, a security function (or lock function) may be set for security, and the user may use the application after user authentication to release the security function there is.
- the processor 120 may perform user authentication (eg, first user authentication). According to an embodiment, when detecting the execution of the application, the processor 120 may perform user authentication according to the security setting of the application. For example, the processor 120 may perform user authentication to identify whether the user has access to the usage right of the application.
- user authentication eg, first user authentication
- user authentication related to application execution includes, for example, biometric authentication (eg, fingerprint, iris, facial recognition, voice, and/or vein authentication) and/or password authentication based on a FIDO authentication method. can do.
- biometric authentication eg, fingerprint, iris, facial recognition, voice, and/or vein authentication
- password authentication based on a FIDO authentication method.
- the processor 120 may control the display module 160 to display an execution screen of an application.
- the user authentication operation in operation 803 may be integrally performed after operation 805 according to the setting of the electronic device 101 .
- the processor 120 may call and display the mobile ID.
- the processor 120 may receive a user input requesting a mobile ID through an application.
- the processor 120 may call the mobile ID stored in the secure area 340 of the memory 130 and display it through the display module 160 based on a user input.
- the processor 120 may call the mobile ID stored in the secure area 340 and control the display module 160 to display the called mobile ID through the execution screen of the application.
- An exemplary screen on which a mobile identification card is displayed according to an embodiment will be described with reference to the drawings to be described later.
- the processor 120 may detect a photo update request. According to an embodiment, after displaying the mobile ID, the processor 120 may determine whether there is a user input for selecting a designated object for photo update (eg, the object 900 of FIG. 9A ) from the user. For example, the user may check the ID photo from the displayed mobile ID, and selectively update the ID picture used in the mobile ID.
- a designated object for photo update eg, the object 900 of FIG. 9A
- the processor 120 may perform user authentication (eg, second user authentication) based on a user input requesting a photo update of the mobile ID. For example, in order to additionally confirm whether the current user who requests the photo update of the mobile ID and the actual user (or owner) of the electronic device 101 are the same user, the processor 120 may separate from the first user authentication. (or additionally), user authentication may be performed through at least one designated authentication method such as public certificate authentication and/or text message authentication.
- user authentication may be performed through at least one designated authentication method such as public certificate authentication and/or text message authentication.
- the processor 120 may activate the camera module 180 (eg, a front camera module) of the electronic device 101 .
- the processor 120 may activate the camera module 180 of the electronic device 101 based on a user's input for updating a photo, and may take a photo (eg, take a selfie) from the user. there is.
- the processor 120 may additionally provide a condition and/or a guide for taking a picture having a standard suitable for a mobile ID in a picture taking operation. According to an embodiment, an operation of guiding photo taking corresponding to the standard of a mobile ID will be described with reference to the drawings to be described later.
- the processor 120 may provide (eg, display) a photo list stored in the memory 130 of the electronic device 101 .
- the processor 120 displays a list of photos stored in the memory 130 of the electronic device 101 through the display module 160 based on the user's input for updating photos (eg, selecting a saved photo), and , may receive an input for selecting a photo from the user.
- the processor 120 may provide an option to take a photo or select a photo in response to a photo update selection, and may acquire an image from a photo taken or a stored photo according to the user's selection. .
- the processor 120 may acquire an image.
- the processor 120 may acquire an image (eg, a face image) from the camera module 180 based on photographing.
- the processor 120 may acquire an image selected by the user based on the photo list.
- the processor 120 may display the acquired image through the display module 160 based on the image acquisition, and may include an operation of deactivating the camera module 180 .
- the processor 120 may perform face matching (or face verification).
- the processor 120 matches an image (eg, a face image) obtained by taking a photo (eg, taking a selfie) with an image (eg, a face image) stored in the electronic device 101 to authenticate the user can be performed.
- the processor 120 compares and analyzes the image of the face authentication model stored in the memory 130 (eg, the security area 340 ) of the electronic device 101 and the acquired image, and the acquired image is the user. It can be identified whether it is an image of According to an embodiment, an operation of matching a face will be described with reference to drawings to be described later.
- the processor 120 may determine whether face matching is successful based on the result of face matching. According to an embodiment, when the processor 120 identifies the same user (eg, a user's face) based on the acquired image and the stored image, the processor 120 may determine the success of face matching. According to another embodiment, when the processor 120 identifies that the user is not the same user (eg, user face) based on the acquired image and the stored image, the processor 120 may determine that the face matching fails.
- the processor 120 may provide a guide related to re-photographing.
- the processor 120 may control the display module 160 to display a guide to failure and a guide to requesting retake of a photo to the user.
- the processor 120 may proceed to operation 809 based on a user input in response to re-taking a photo and perform operations 809 and subsequent operations.
- face matching or face verification
- the processor 120 may proceed to an operation prior to photo update (eg, an operation for displaying a mobile ID or an operation for executing an application).
- the processor 120 requests the server 201 to update a photo of the ID photo of the mobile ID and issuance of the mobile ID (eg, 'Yes' in operation 815 ). : reissue) can be requested.
- the processor 120 provides (eg, transmits) the acquired image to the server 201 in response to a user input or automatically after acquiring the image (eg, taking a picture for updating a picture), and acquiring The server 201 may be requested to issue a modified mobile ID (eg, update the ID photo and reissue it) using the image.
- ID information previously stored in the security area 340 and/or designated identification information capable of identifying the electronic device 101 eg: A mobile ID reissuance request message including the device identifier of the electronic device 101 and/or the phone number of the electronic device 101 that has been issued the mobile ID, and the acquired image and photo update request information through the communication module 192 It can be transmitted to the server 201 .
- the processor 120 may request the server 201 to correct and issue an ID photo of the mobile ID using the acquired image.
- the processor 120 may receive the mobile ID from the server 201 .
- the processor 120 may receive, from the server 201 , a mobile ID including a photo according to the acquired image through the communication module 192 .
- the processor 120 may update (or store) the mobile ID.
- the processor 120 may store the received mobile ID in the secure area 340 of the memory 130 .
- the processor 120 may delete the mobile ID previously stored in the security area 340 and update (eg, replace) the mobile ID with the received mobile ID.
- the electronic device 101 receives the mobile ID including the updated photo, the previously issued (or stored) mobile ID may be deleted from the security area or use may be restricted.
- the electronic device 101 and/or the server 201 may set a period (eg, photo expiration period) during which the updated ID photo can be used, and update the ID photo.
- a period eg, photo expiration period
- the expiration period may be set for a policy or security issue of the server 201 , may be managed by the server 201 , or may be managed by the electronic device 101 .
- the electronic device 101 and/or the server 201 may provide a notice to the user based on the expiration period. For example, before the expiration period is reached, the electronic device 101 requests the user to update the photo of the mobile ID through a notification at a specified point in time (eg, one week before, one month, or one day before the expiration) to prove You can guide the periodic update of photos. As another example, the server 201 may transmit the related notice to the electronic device 101 at a predetermined time specified in the expiration period, and the electronic device 101 may receive the related notice and provide it to the user.
- a specified point in time eg, one week before, one month, or one day before the expiration
- the electronic device 101 and/or the server 201 may manage the renewal period (or expiration period) of the mobile ID (eg, corresponding to the actual renewal period of the physical ID), and at a specified point in time They may guide you to renew your physical ID.
- 9A and 9B are diagrams for explaining an example of a user interface provided by an electronic device according to various embodiments of the present disclosure.
- FIGS. 9A and 9B may show an example of a user interface (eg, an example screen) of a mobile ID that can be provided by the electronic device 101 .
- a user interface eg, an example screen
- the user interface for the mobile ID may be implemented in various forms (eg, different arrangement positions of each information, a display form of each information, and/or a structure of each information) depending on implementation. .
- FIG. 9A may show an example of a first user interface that provides information of a mobile ID based on text and an identification code
- FIG. 9B shows a mobile ID in the form of a physical ID (eg: An example of the second user interface provided in the form of a card) may be shown.
- the first user interface and the second user interface may be toggled between (or switched) based on a user input (eg, toggle input).
- the first user interface includes an image 910 corresponding to an ID photo, an identification code 920 (eg, a QR code and/or a barcode), and valid (or count) time information for displaying the identification code. 930 , and/or a toggle object 940 for toggling between user interfaces.
- the first user interface may include a camera object 900 for supporting photo taking for an ID photo update (eg, photo update) used in a mobile ID.
- the electronic device 101 executes an application to easily recognize the mobile ID and some information included in the mobile ID based on the first user interface (eg, a QR code and/or barcode) may be provided, for example, the first user interface may be provided in a portrait mode.
- the second user interface may provide the mobile ID in the form of a card corresponding to the actual ID of the physical ID, and a card image 950 and/or a toggle object 960 for toggle between the user interfaces. ) may be included.
- the second user interface of the card image 950 may provide, in the card image 950 , an image corresponding to an identification photo and text of some identification information included in the mobile ID.
- the second user interface may include a camera object 900 for supporting photo taking for an ID photo update (eg, photo update) used in a mobile ID.
- the electronic device 101 may execute an application to provide the mobile ID card in the form of an intuitively recognizable card based on the first user interface, for example, the second user interface may Can be provided in landscape mode.
- the first user interface and the second user interface may be provided by switching the first user interface in the portrait mode and the second user interface in the landscape mode according to a user selection using the toggle objects 940 and 960 .
- the camera module 180 may be activated, and an execution screen related to picture taking for photo update may be displayed overlaid on the user interface, or the user interface may be switched to an execution screen related to picture taking and provided.
- FIG. 10 is a diagram for describing a face matching method in an electronic device according to various embodiments of the present disclosure.
- FIG. 10 examples of various algorithms (or modules) 1000 for a guide method during a photo taking operation in the electronic device 101 and a face matching method for user verification during a face recognition operation are shown.
- the electronic device 101 may provide the user with a photo taking when a photo update of the mobile ID is requested, and update the ID photo used in the mobile ID.
- the electronic device 101 may acquire an image by operating the camera module 180 to take a picture so that the entire outline of the user's face is revealed.
- the electronic device 101 provides guide lines (eg, positions of shoulders, eyes, nose, and input) through a preview so that the entire contour of the user's face can be captured to the user. It can induce you to take an image suitable for use as an ID photo for your mobile ID.
- the electronic device 101 may perform face matching (or face recognition) for user verification based on the obtained image to verify the obtained image.
- 10 may show an example of the algorithm 1000 for taking a picture and matching a face, and the algorithm 1000 may be implemented as a hardware structure or a software structure by a related module (or means).
- the electronic device 101 extracts a person and a background 1010 , an image determination 1020 , a face region extraction 1030 , a facial landmark extraction 1040 , and liveness ) determination 1050 , facial feature point extraction 1060 , and/or facial similarity determination 1070 , or each module capable of executing these algorithms 1000 .
- the electronic device 101 may extract a person and a background based on an image obtained after taking a picture. According to an embodiment, the electronic device 101 may extract the background and the person area from the acquired image by using the person and background extraction module. According to an embodiment, when the background and the person area are not extracted from the obtained image, the electronic device 101 may induce the user to take a picture again.
- the electronic device 101 may perform image discrimination on the acquired image in block 1020 .
- the electronic device 101 uses the image identification module to determine the background color of the picture, the overall brightness of the person (or object) area, and the location of the person area (eg, whether the face area is located in the center of the image). , and/or the size of the person area (eg, whether the face is not small in the photo) may be determined to confirm whether the obtained image is an image that can be used as an ID photo in the mobile ID.
- the electronic device 101 may induce the user to take a photo again.
- the electronic device 101 may extract a face region from the acquired image in block 1030 .
- the electronic device 101 may extract a face region from the person region of the obtained image by using the face region extraction module.
- the electronic device 101 detects elements such as darkness of the face region, sunglasses, eyes closed or blindfolded, and/or wearing a hat through image determination with respect to the extracted face region, the user You can induce them to take pictures again.
- facial landmarks eg, eyes, nose, and / or region of the mouth.
- the electronic device 101 may search for an eye, nose, and/or mouth region in the face region of the acquired image by using the facial landmark extraction module.
- a landmark eg, an area of the eyes, nose, and/or mouth
- the electronic device 101 may induce the user to take a picture again.
- the electronic device 101 may determine whether it is lively. According to an embodiment, the electronic device 101 may perform face recognition (or face recognition) for liveness detection in a face region using the liveness determination module. According to an embodiment, the electronic device 101 may determine whether or not liveness (eg, face recognition or face recognition) is performed based on the extraction of facial feature points.
- the liveness determination module may include a facial feature point extraction module.
- the electronic device 101 may extract a face landmark based on the face region of the obtained image.
- the electronic device 101 may extract facial feature points based on landmarks (eg, eyes, nose, mouth, eyebrows, and/or face shape) of a face region using the facial feature point extraction module.
- landmarks eg, eyes, nose, mouth, eyebrows, and/or face shape
- the facial feature points are indicated by dotted points for each specific part of the face (eg, eyes, nose, mouth, and/or mouth), for example, a certain number of points using point markup.
- a face (or face) can be recognized by extracting facial features from points.
- the electronic device 101 may determine the degree of facial similarity between the acquired image and the stored image based on the extracted facial feature points. According to an embodiment, the electronic device 101 may determine the face similarity between the acquired image and the image stored in the security area 340 using the face similarity determining module.
- the electronic device 101 measures the similarity between the acquired image and the stored image, and when the similarity score is, for example, lower than a face recognition threshold (eg, a reference similarity score), the image is returned to the user It can induce you to take pictures.
- the electronic device 101 determines the similarity between the acquired image and the stored image, and when the similarity score is, for example, higher than a face recognition threshold, the acquired image is related to the same user as the stored image. image can be considered.
- the face recognition threshold can be adjusted according to the setting of the electronic device 101 , and the security level can be increased by setting the high threshold value when matching a face for a mobile ID.
- FIG. 11 is a diagram illustrating an operation scenario of using a mobile ID electronically between an electronic device and a reader device according to various embodiments of the present disclosure
- the electronic device 101 may be in a state in which the mobile ID issued from the server 201 is stored in the security area 340 .
- at least some information (or information required for user verification) of the mobile ID stored in the electronic device 101 is selected through OOB communication between the electronic device 101 and the reader device 301 and the reader
- an operation example of verifying a user identity by a verifier using the reader device 301 may be indicated.
- the reader device 301 may request a mobile ID from the electronic device 101 .
- the reader device 301 searches for a connectable electronic device 101 using OOB (eg, NFC, BLE, and/or Wi-Fi 2.4GHz) communication, and the found electronic device 101 ) to send a connection request for a mobile ID.
- OOB eg, NFC, BLE, and/or Wi-Fi 2.4GHz
- the electronic device 101 may check request information based on the connection request of the reader device 301 .
- the electronic device 101 may determine what information the reader device 301 requests based on detecting a connection request from the reader device 301 .
- the electronic device 101 may determine whether the reader device 301 requests a mobile ID.
- the electronic device 101 checks the type of mobile ID requested by the reader device 301 (eg, resident registration card, driver's license, passport), and loads the ID requested by the reader device 301 . ) can be prepared.
- the electronic device 101 may verify the reader device 301 .
- the electronic device 101 is based on identifying that the reader device 301 requests a mobile ID, through a specified authentication protocol between the electronic device 101 and the reader device 301, the reader device ( 301) can verify whether the device is suitable for information transfer.
- the electronic device 101 may load a mobile ID.
- the electronic device 101 executes an application for a mobile ID based on verifying that the reader device 301 is a suitable device, and calls and displays the mobile ID stored in the secure area 340 . It can be displayed through the module 160 .
- the electronic device 101 may provide the mobile ID to the reader device 301 .
- the verifier may read the identification code (eg, QR code or barcode) of the mobile ID displayed on the electronic device 101 using the reader device 301 , and the electronic device 101 provides at least some of the personal information included in the mobile identification code (eg, identification information (eg, name, identification information (or license information) and/or photo image)) to the reader device 301 based on the identification code can do.
- the electronic device 101 may provide identification information of the mobile ID to the reader device 301 using OOB (eg, NFC, BLE, and/or Wi-Fi 2.4GHz) communication. .
- OOB eg, NFC, BLE, and/or Wi-Fi 2.4GHz
- the reader device 301 may display the mobile ID received from the electronic device 101 through the display module. According to an embodiment, the reader device 301 may display the mobile ID from the electronic device 101 based on some information (eg, identification information) included in the mobile ID, for example, in FIG. 9A or The mobile ID may be displayed as a user interface corresponding to the user interface illustrated in 9b.
- some information eg, identification information
- the reader device 301 may acquire an image.
- the reader device 301 may activate a camera module based on an input of a verifier requesting to take a photo, and acquire an image (eg, a face image of a user) captured through the camera module.
- the reader device 301 may verify the mobile ID received from the electronic device 101 . According to an embodiment, the reader device 301 may identify whether the received mobile ID is forged or altered by performing integrity verification of the received mobile ID. According to an embodiment, the reader device 301 may identify whether identification information (eg, name, license information) of the mobile ID is normal information. According to an embodiment, the reader device 301 may verify the integrity through an information inquiry according to the identification information (eg, an identification information inquiry request through the server 201 ).
- identification information eg, name, license information
- the reader device 301 may perform face matching (or face verification) based on verifying that the mobile ID is normal information. According to an embodiment, the reader device 301 may verify the mobile ID based on comparative analysis (eg, face matching) between a photo image and an image obtained through photo taking among the identification information of the mobile ID. According to an embodiment, the reader device 301 may perform verification between the photo image and the obtained image based on at least one verification method of comparing facial feature points between the photo image and the obtained image and/or determining the degree of facial similarity. .
- the reader device 301 may provide a verification result to the verifier.
- the reader device 301 may provide a result of whether the mobile ID is authentic or not in a specified manner, based on the results of the integrity verification and face matching of the mobile ID.
- the reader device 301 may notify the verifier of the result information based at least on visual, auditory and/or tactile information.
- An operation method performed by the electronic device 101 includes an operation of executing an application for a mobile identification service, an operation of acquiring identification information based on a user input, and an operation of displaying the identification information through a display module. Based on the display operation, the operation of obtaining an image for the ID photo of the mobile ID based on the photo update request, the operation of performing face matching based on the image, the operation of performing face matching based on the result of the face matching, through a communication module, Transmitting a message requesting issuance of a mobile ID based on the image to a server, receiving a mobile ID including an ID photo corresponding to the image from the server through the communication module, and the mobile ID may include the operation of storing in the secure area of the memory.
- the operation of executing the application includes, when the application is executed, performing user authentication for releasing a security function related to the execution of the application, based on a result of the user authentication, and displaying an execution screen of , wherein the user authentication may include biometric authentication and/or password authentication based on a fast identity online (FIDO) authentication method.
- FIDO fast identity online
- the obtaining of the ID information includes detecting a user input requesting issuance of a mobile ID from a user, and determining suitability of a user requesting issuance of the mobile ID based on the user input
- An operation of performing user authentication for and an operation of providing an interface related to obtaining the identification information based on the result of the user authentication, wherein the user authentication for determining the suitability is a public certificate authentication and/or a text message May include authentication.
- the operation of acquiring the identification information may include acquiring the identification information through a user input, photographing a physical identification, contacting the physical identification, and/or interacting with a server.
- the operation of acquiring the image includes an operation of detecting an input for updating a picture based on a specified object for updating a picture, an operation of activating a camera module based on the input, and a preview ( preview) may include an operation of providing guidelines related to photo taking.
- the performing of face matching may include performing face verification based on matching between the image and an image stored in a security area of a memory.
- the operation of performing the face matching includes an operation of determining whether the face matching is successful, an operation of providing a guide related to re-photography when the face matching fails, and the face matching If successful, the method may include transmitting the message including the ID information, the image, and photo update request information requesting to modify a photo of the mobile ID using the image to the server.
- the operating method performed by the electronic device 101 may include managing an expiration period related to the mobile ID.
- the operation of managing the expiration period may include an operation of guiding the update of the mobile ID based on a predetermined time point specified in the expiration period.
- the operation of managing the expiration period includes the operation of providing a related notice to the user so as to update the mobile ID and/or renew the physical identification at a predetermined time specified in the expiration period.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computing Systems (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Biomedical Technology (AREA)
- Oral & Maxillofacial Surgery (AREA)
- Human Computer Interaction (AREA)
- Multimedia (AREA)
- Telephone Function (AREA)
Abstract
Divers modes de réalisation concernent un procédé et un dispositif permettant de fournir un document d'identification mobile au moyen d'un dispositif électronique. Selon divers modes de réalisation, un dispositif électronique peut comprendre un module de communication, une mémoire, un module d'affichage et un processeur, le processeur étant configuré pour : exécuter une application pour un service de document d'identification mobile ; acquérir des informations de document d'identification d'après une entrée d'utilisateur ; afficher les informations du document d'identification au moyen du module d'affichage ; acquérir une image pour une photo d'identification pour un document d'identification mobile en réponse à une demande de mise à jour de photo ; effectuer une mise en correspondance de visages d'après l'image ; en fonction d'un résultat de la mise en correspondance de visages, transmettre, à un serveur par le biais du module de communication, un message pour demander d'émettre le document d'identification mobile d'après l'image ; recevoir, du serveur, le document d'identification mobile comprenant la photo d'identification correspondant à l'image par le biais du module de communication ; et stocker le document d'identification mobile dans une zone sécurisée de la mémoire. Divers modes de réalisation sont possibles.
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR10-2020-0142323 | 2020-10-29 | ||
KR1020200142323A KR20220057254A (ko) | 2020-10-29 | 2020-10-29 | 전자 장치 및 전자 장치에서 모바일 신분증 제공 방법 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2022092582A1 true WO2022092582A1 (fr) | 2022-05-05 |
Family
ID=81384212
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/KR2021/013137 WO2022092582A1 (fr) | 2020-10-29 | 2021-09-27 | Dispositif électronique et procédé permettant de fournir un document d'identification mobile au moyen d'un dispositif électronique |
Country Status (2)
Country | Link |
---|---|
KR (1) | KR20220057254A (fr) |
WO (1) | WO2022092582A1 (fr) |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101096175B1 (ko) * | 2010-10-08 | 2011-12-22 | 비씨카드(주) | 모바일 신분증 관리 시스템 및 이것의 모바일 신분증 관리 방법 |
KR20140126976A (ko) * | 2013-04-24 | 2014-11-03 | 에스케이플래닛 주식회사 | 모바일 신분증 관리 장치 및 사용자 단말기 |
KR101657534B1 (ko) * | 2016-01-21 | 2016-09-20 | 임철수 | 스마트폰을 통한 사진첨부의 신분증발급시스템 및 방법 |
KR20180042788A (ko) * | 2016-10-18 | 2018-04-26 | 장양호 | 모바일 여권 및 이를 생성하기 위한 모바일 여권 생성시스템과 모바일 여권 인증 방법 |
KR20200098765A (ko) * | 2019-02-11 | 2020-08-21 | 경운대학교 산학협력단 | 모바일을 통한 신분증 인증시스템 |
-
2020
- 2020-10-29 KR KR1020200142323A patent/KR20220057254A/ko active Search and Examination
-
2021
- 2021-09-27 WO PCT/KR2021/013137 patent/WO2022092582A1/fr active Application Filing
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101096175B1 (ko) * | 2010-10-08 | 2011-12-22 | 비씨카드(주) | 모바일 신분증 관리 시스템 및 이것의 모바일 신분증 관리 방법 |
KR20140126976A (ko) * | 2013-04-24 | 2014-11-03 | 에스케이플래닛 주식회사 | 모바일 신분증 관리 장치 및 사용자 단말기 |
KR101657534B1 (ko) * | 2016-01-21 | 2016-09-20 | 임철수 | 스마트폰을 통한 사진첨부의 신분증발급시스템 및 방법 |
KR20180042788A (ko) * | 2016-10-18 | 2018-04-26 | 장양호 | 모바일 여권 및 이를 생성하기 위한 모바일 여권 생성시스템과 모바일 여권 인증 방법 |
KR20200098765A (ko) * | 2019-02-11 | 2020-08-21 | 경운대학교 산학협력단 | 모바일을 통한 신분증 인증시스템 |
Also Published As
Publication number | Publication date |
---|---|
KR20220057254A (ko) | 2022-05-09 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2019216499A1 (fr) | Dispositif électronique et procédé de commande associé | |
WO2020017706A1 (fr) | Dispositif électronique et procédé pour le commander | |
WO2015030500A1 (fr) | Dispositif électronique et procédé de traitement de signature saisie de dispositif électronique | |
WO2020032510A1 (fr) | Dispositif électronique comprenant un stylo électronique et procédé de commande de connexion de communication entre un dispositif électronique et un stylo électronique | |
WO2019124811A1 (fr) | Procédé de vérification d'empreinte digitale et dispositif électronique permettant la mise en œuvre de celui-ci | |
WO2022010088A1 (fr) | Dispositif électronique prenant en charge un paiement mobile, son procédé de fonctionnement, et support de stockage associé | |
WO2020159200A1 (fr) | Procédé de fourniture de données associées à des données originales et dispositif électronique et support de stockage associés | |
WO2020171516A1 (fr) | Dispositif électronique permettant d'authentifier des informations biométriques et son procédé de fonctionnement | |
WO2022146026A1 (fr) | Procédé de traitement de données protégées et dispositif électronique le prenant en charge | |
WO2020189827A1 (fr) | Dispositif électronique et procédé de commande associé | |
WO2019172610A1 (fr) | Dispositif électronique et procédé pour réaliser un paiement à l'aide d'un module audio | |
WO2019107975A1 (fr) | Dispositif électronique de prise d'image et procédé d'affichage d'image | |
WO2023085588A1 (fr) | Dispositif électronique et procédé de commande de véhicule sur la base d'une authentification de conducteur | |
WO2022092582A1 (fr) | Dispositif électronique et procédé permettant de fournir un document d'identification mobile au moyen d'un dispositif électronique | |
WO2022035034A1 (fr) | Dispositif électronique comportant un capteur d'empreinte digitale et procédé de commande de celui-ci | |
WO2021101316A1 (fr) | Dispositif électronique et procédé de reconnaissance d'empreinte digitale par celui-ci | |
WO2020096399A1 (fr) | Dispositif électronique pour mettre en oeuvre une opération sur la base de types de couvercles identifiés et son procédé de fonctionnement | |
WO2022177138A1 (fr) | Dispositif électronique permettant d'afficher une image de sécurité et son procédé de fonctionnement | |
WO2023027292A1 (fr) | Dispositif électronique et procédé de mise en place d'un guide de reconnaissance d'empreintes digitales l'utilisant | |
WO2023054839A1 (fr) | Dispositif électronique et procédé pour la fourniture adaptative d'un processus d'authentification de service en fonction d'une situation, et support de stockage lisible par ordinateur non transitoire | |
WO2022177206A2 (fr) | Appareil électronique et procédé de fonctionnement d'appareil électronique | |
WO2023080338A1 (fr) | Dispositif électronique et procédé pour effectuer une authentification faciale au moyen d'une pluralité de caméras | |
WO2024025254A1 (fr) | Procédé et dispositif électronique pour empêcher un vol d'empreinte digitale à l'aide d'un dispositif externe | |
WO2022014873A1 (fr) | Procédé d'exécution d'authentification et dispositif électronique prenant en charge ledit procédé | |
WO2022103069A1 (fr) | Procédé d'authentification d'utilisateur et dispositif électronique associé |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 21886576 Country of ref document: EP Kind code of ref document: A1 |