Method for providing untact authorizing service of unmanned digital device using security module and mobile identification card and computing device using the same

KR103013709B1Active Publication Date: 2026-09-02KOREA MINTING SECURITY PRINTING & ID CARD OPERATING CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
KR1020240007056
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-01-16
Publication Date
2026-09-02
Estimated Expiration
2044-01-16

Smart Images

  • Figure 112024006080745-PAT00002_ABST
    Figure 112024006080745-PAT00002_ABST
Patent Text Reader

Abstract

The present invention relates to a method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card, comprising: (a) when a power-on signal to the unmanned digital device is obtained or a control signal for operating software for the operation of the unmanned digital device is obtained, a computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, executes the software to perform control over the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module;(b) When information requesting the provision of a specific product or specific service from a user is obtained from the unmanned digital device, the computing device requests identity authentication from the user through the unmanned digital device, and when identity authentication information from a user terminal corresponding to the user—the identity authentication information includes at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID—is obtained through the unmanned digital device, the computing device requests identity authentication from the user terminal through the unmanned digital device, the computing device encrypts the identity authentication information using a first encryption / decryption session key, and transmits the encrypted identity authentication information to the authentication server through the security module, thereby causing the authentication server to decrypt the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the identity authentication information, obtain the user VP from the relay server by referring to the identity authentication information, and use the user VP to [determine] the user through a mobile ID blockchain network corresponding to the user mobile ID. The present invention relates to a method characterized by: a step of performing the above-mentioned identity authentication; and (c) when the above-mentioned identity authentication for the user is performed by the authentication server, the computing device provides the above-mentioned specific product or specific service requested by the user through the unmanned digital device.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID, and a computing device using the same. Background Technology

[0002] With the spread of non-face-to-face culture, an increasing number of stores are utilizing in-store unmanned digital devices, such as kiosks, to provide contactless services to consumers in order to satisfy the demands of consumers for whom non-face-to-face transactions have become commonplace and to reduce store operating costs. Meanwhile, in the case of some unmanned digital devices that provide specific products and / or specific services to specific individuals, sensitive information such as personal information and payment information regarding those individuals is handled. In this situation, if the security of the unmanned digital device itself is weak, there is a problem in that sensitive personal information regarding those individuals is not protected and is leaked to a third party.

[0003] In addition, due to security vulnerabilities in unmanned digital devices, there is a problem in that a third party can tamper with the software (firmware) of the unmanned digital device and perform various malicious acts using illegal software such as malware, ransomware, and botnets, and can also hack the national mobile ID system by accessing the national mobile ID server using the unmanned digital device.

[0004] Therefore, there is a need for technology that enhances security to prevent the leakage of personal and payment information during bidirectional communication between unmanned digital devices and an authentication server that verifies the illegality and tampering of the devices and performs identity verification. The problem to be solved

[0005] The present invention aims to solve all of the aforementioned problems.

[0006] In addition, the present invention has another objective in that a computing device for controlling an unmanned digital device verifies the integrity of software for the operation of the unmanned digital device through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, executes the software to perform control of the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module.

[0007] In addition, the present invention has another objective of, when information requesting the provision of a specific product or specific service from a user is obtained from an unmanned digital device, the computing device requests identity authentication from the user through the unmanned digital device, and when identity authentication information is obtained from a user terminal corresponding to the user, the encrypted identity authentication information, which is encrypted using a first encryption / decryption session key through a security module, is transmitted to an authentication server, thereby causing the authentication server to obtain identity authentication information by decrypting the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key, and by obtaining a user VP from a relay server by referring to the identity authentication information, and by performing identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP. means of solving the problem

[0008] The characteristic configuration of the present invention for achieving the objectives of the present invention as described above and realizing the characteristic effects of the present invention described below is as follows.

[0009] According to one aspect of the present invention, a method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card comprises: (a) when a power-on signal to the unmanned digital device is obtained or a control signal for operating software for the operation of the unmanned digital device is obtained, a computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, drives the software to perform control over the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module;(b) When information requesting the provision of a specific product or specific service from a user is obtained from the unmanned digital device, the computing device requests identity authentication from the user through the unmanned digital device, and when identity authentication information from a user terminal corresponding to the user—the identity authentication information includes at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID—is obtained through the unmanned digital device, the computing device requests identity authentication from the user terminal through the unmanned digital device, the computing device encrypts the identity authentication information using a first encryption / decryption session key, and transmits the encrypted identity authentication information to the authentication server through the security module, thereby causing the authentication server to decrypt the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the identity authentication information, obtain the user VP from the relay server by referring to the identity authentication information, and use the user VP to [determine] the user through a mobile ID blockchain network corresponding to the user mobile ID. A method is disclosed comprising: a step of performing the above-mentioned identity authentication; and (c) when the above-mentioned identity authentication for the user is performed by the authentication server, the computing device provides the above-mentioned specific product or specific service requested by the user through the unmanned digital device.

[0010] As an example, in step (a) above, the computing device (i) obtains a security module ID stored in the security module and a first security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server authentication data, which is obtained by encrypting the server ID and the first security module nonce with a server authentication key, and the first server nonce to the computing device, and (ii) when the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module to have the security module decrypt the server authentication data using a security module authentication key corresponding to the server authentication key to obtain the server ID and the decrypted first security module nonce, and the decrypted first security module nonce is the first security module nonce and (iii) verify whether they match, and if it is confirmed that the decrypted first security module nonce matches the first security module nonce, generate security module authentication data by encrypting the security module ID and the first server nonce using the security module authentication key; (iii) transmit the security module authentication data generated through the security module to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and verify whether the decrypted first server nonce matches the first server nonce; (iv) instruct the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce.A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key; and, from the authentication server, generating the server authentication session key by referencing the server authentication key, the first security module nonce, and the first server nonce, generating a server integrity verification key by referencing the server authentication session key and the first server nonce, and when the encrypted server integrity verification key obtained by encrypting the server integrity verification key using the server authentication session key is obtained, causing the security module to decrypt the encrypted server integrity verification key using the security module authentication session key. A method is disclosed characterized by performing device authentication for the unmanned digital device by performing a process to verify the server integrity verification key.

[0011] As an example, in step (b) above, the computing device (i) obtains the security module ID stored in the security module and the second security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the second security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server encrypted data obtained by encrypting the server ID and the second security module nonce with a server encryption key, and the second server nonce to the computing device, and (ii) if the server encrypted data and the second server nonce are obtained from the authentication server, transmits the server encrypted data and the second server nonce to the security module to have the security module decrypt the server encrypted data using a security module encryption key corresponding to the server encryption key to obtain the server ID and the decrypted second security module nonce, and the decrypted second security module nonce is the second security module nonce and A process for verifying whether they match, and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, generating security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key; (iii) transmitting the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and verifying whether the decrypted second server nonce matches the second server nonce; and (iv) causing the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce.A method is disclosed characterized by performing a process in which the authentication server generates the second encryption / decryption session key by referencing the server encryption key, the second security module nonce, and the second server nonce, as it is confirmed that the decrypted second server nonce matches the second server nonce.

[0012] As an example, in step (b) above, the computing device performs the identity authentication by causing the authentication server to obtain a user public key corresponding to the user DID from the mobile identity blockchain network using a user DID corresponding to the user VP, decrypt the user VP using the user public key to obtain at least one user VC (Verifiable Credential), obtain a mobile identity issuing server public key corresponding to the mobile identity issuing server DID from the mobile identity blockchain network using a mobile identity issuing server DID included in the user VC, and verify the user VC by confirming a mobile identity issuing server signature value included in the user VC using the mobile identity issuing server public key.

[0013] As an example, a method is disclosed in which, in step (b) above, the computing device obtains a user DID corresponding to the user VP by adding it to the personal authentication information from the user terminal through the unmanned digital device, or causes the user terminal to transmit the user DID by adding it to the user VP to the relay server and obtains the user DID through the relay server.

[0014] As an example, a method is disclosed in which, in step (b) above, the computing device obtains the identity authentication information by scanning a QR code corresponding to the identity authentication information displayed on the user terminal through the unmanned digital device, or obtains the identity authentication information through wireless communication with the user terminal through the unmanned digital device.

[0015] As an example, a method is disclosed in which, in step (a) above, the computing device verifies the integrity of the software by checking whether a first hash value stored in the security module—the first hash value is a value obtained by hashing the software authenticated for the operation of the unmanned digital device—and a second hash value generated by hashing the software are the same.

[0016] As an example, a method is disclosed in which the security module is a hardware security module comprising at least some of a memory card, a processor card, a smart card, a Surface-Mount Device (SMD) type chip card, and an external storage device.

[0017] According to another aspect of the present invention, a computing device for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card comprises: a memory storing instructions for providing the non-face-to-face authentication service for the unmanned digital device using the security module and the mobile ID card; and a processor that performs operations to provide the non-face-to-face authentication service of the unmanned digital device using the security module and the mobile ID card according to the instructions stored in the memory; wherein the processor comprises: (I) a process of verifying the integrity of the software through a security module corresponding to the unmanned digital device when a power-on signal to the unmanned digital device is obtained or a control signal for the operation of the software for the operation of the unmanned digital device is obtained, and when the integrity of the software is verified, running the software to perform control over the unmanned digital device, and performing device authentication for the unmanned digital device through interaction with an authentication server using the security module; (II) a process of requesting identity authentication from the user through the unmanned digital device when information requesting the provision of a specific product or specific service from the user is obtained from the unmanned digital device, and identity authentication information from a user terminal corresponding to the user - the identity authentication information is a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID card, and the Including at least one of the location information of the above-mentioned user VP stored in the relay server - when obtained through the above-mentioned unmanned digital device, the above-mentioned identity authentication information, encrypted using a first encryption / decryption session key, is transmitted to the above-mentioned authentication server through the security module, thereby causing the above-mentioned authentication server,A computing device is disclosed, characterized by a process of obtaining the identity authentication information by decrypting the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key, obtaining the user VP from the relay server by referring to the identity authentication information, and performing identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP, and (III) performing a process of providing the specific product or specific service requested by the user through the unmanned digital device when the identity authentication for the user is performed by the authentication server.

[0018] For example, in the process (I), the processor (i) obtains a security module ID stored in the security module and a first security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server authentication data, which is obtained by encrypting the server ID and the first security module nonce with a server authentication key, and the first server nonce to the computing device, and (ii) when the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module to have the security module decrypt the server authentication data using a security module authentication key corresponding to the server authentication key to obtain the server ID and the decrypted first security module nonce, and the decrypted first security module nonce is the first security module nonce and (iii) verify whether they match, and if it is confirmed that the decrypted first security module nonce matches the first security module nonce, generate security module authentication data by encrypting the security module ID and the first server nonce using the security module authentication key; (iii) transmit the security module authentication data generated through the security module to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and verify whether the decrypted first server nonce matches the first server nonce; (iv) instruct the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce.A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key; and, from the authentication server, generating the server authentication session key by referencing the server authentication key, the first security module nonce, and the first server nonce, generating a server integrity verification key by referencing the server authentication session key and the first server nonce, and when the encrypted server integrity verification key obtained by encrypting the server integrity verification key using the server authentication session key is obtained, causing the security module to decrypt the encrypted server integrity verification key using the security module authentication session key. A computing device is disclosed that performs device authentication for the unmanned digital device by performing a process to verify the server integrity verification key.

[0019] For example, in the process (II), the processor (i) obtains the security module ID stored in the security module and the second security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the second security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server encrypted data obtained by encrypting the server ID and the second security module nonce with a server encryption key, and the second server nonce to the computing device, and (ii) if the server encrypted data and the second server nonce are obtained from the authentication server, transmits the server encrypted data and the second server nonce to the security module to have the security module decrypt the server encrypted data using a security module encryption key corresponding to the server encryption key to obtain the server ID and the decrypted second security module nonce, and the decrypted second security module nonce is the second security module A process for verifying whether it matches the nonce, and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, generating security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key; (iii) transmitting the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and verifying whether the decrypted second server nonce matches the second server nonce; and (iv) causing the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce.A computing device is disclosed, characterized by performing a process in which the authentication server generates the second encryption / decryption session key by referencing the server encryption key, the second security module nonce, and the second server nonce as it is confirmed that the decrypted second server nonce matches the second server nonce.

[0020] As an example, a computing device is disclosed in which, in the process (II), the processor causes the authentication server to obtain a user public key corresponding to the user DID from the mobile ID blockchain network using a user DID corresponding to the user VP, decrypts the user VP using the user public key to obtain at least one user VC (Verifiable Credential), obtains a mobile ID issuing server public key corresponding to the mobile ID issuing server DID from the mobile ID blockchain network using a mobile ID issuing server DID included in the user VC, and verifies the user VC by confirming a mobile ID issuing server signature value included in the user VC using the mobile ID issuing server public key.

[0021] As an example, a computing device is disclosed in which, in the process (II), the processor obtains a user DID corresponding to the user VP by adding it to the personal authentication information from the user terminal through the unmanned digital device, or causes the user terminal to transmit the user DID by adding it to the user VP to the relay server and obtains the user DID through the relay server.

[0022] As an example, a computing device is disclosed in which the processor obtains the identity authentication information by scanning a QR code corresponding to the identity authentication information displayed on the user terminal through the unmanned digital device in the process (II), or obtains the identity authentication information through wireless communication with the user terminal through the unmanned digital device.

[0023] As an example, a computing device is disclosed in which the processor verifies the integrity of the software by checking whether, in the process (I), a first hash value stored in the security module—the first hash value is a value obtained by hashing the software authenticated for the operation of the unmanned digital device—and a second hash value generated by hashing the software are the same.

[0024] As an example, a computing device is disclosed in which the security module is a hardware security module comprising at least some of a memory card, a processor card, a smart card, a Surface-Mount Device (SMD) type chip card, and an external storage device. Effects of the invention

[0025] The present invention has the effect of a computing device for controlling an unmanned digital device, which verifies the integrity of software for the operation of the unmanned digital device through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, executes the software to control the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module.

[0026] In addition, the present invention has the effect of, when information requesting the provision of a specific product or specific service from a user is obtained from an unmanned digital device, a computing device requests identity authentication from the user through the unmanned digital device, and when identity authentication information is obtained from a user terminal corresponding to the user, the encrypted identity authentication information, which is encrypted using a first encryption / decryption session key through a security module, is transmitted to an authentication server, thereby causing the authentication server to obtain identity authentication information by decrypting the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key, and obtaining a user VP from a relay server by referring to the identity authentication information, and performing identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP. Brief explanation of the drawing

[0027] The drawings attached below for use in describing embodiments of the present invention are merely some of the embodiments of the present invention, and other drawings can be obtained based on these drawings without inventive work by a person skilled in the art to which the present invention pertains (hereinafter "person skilled in the art"). FIG. 1 schematically illustrates a computing device that provides a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to an embodiment of the present invention. FIG. 2 is a flowchart illustrating the sequence of a method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to an embodiment of the present invention, and FIGS. 3a and 3b schematically illustrate a series of processes for exchanging a security module ID, an authentication server ID, a first security module nonce, and a first server nonce between a security module and an authentication server according to an embodiment of the present invention, and a series of processes for performing device authentication for an unmanned digital device using a security module authentication session key, a security module integrity verification key, a server authentication session key, and a server integrity verification key. FIG. 4 schematically illustrates a series of processes for generating a first encryption / decryption session key and a second encryption / decryption session key by exchanging a security module ID, an authentication server ID, a second security module nonce, and a second server nonce between a security module and an authentication server according to an embodiment of the present invention. FIG. 5 schematically illustrates the process of verifying a DID-based mobile ID card according to one embodiment of the present invention. Specific details for implementing the invention

[0028] The following detailed description of the invention refers to the accompanying drawings, which illustrate specific embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention. It should be understood that various embodiments of the invention are different but need not be mutually exclusive. For example, specific shapes, structures, and characteristics described herein with respect to one embodiment may be implemented in other embodiments without departing from the spirit and scope of the invention. It should also be understood that the location or arrangement of individual components within each disclosed embodiment may be changed without departing from the spirit and scope of the invention. Accordingly, the following detailed description is not intended to be limiting, and the scope of the invention is limited only by the appended claims, including all equivalents to those claimed therein, provided appropriately described. Similar reference numerals in the drawings refer to the same or similar functions across various aspects.

[0029] Hereinafter, in order to enable a person skilled in the art to easily practice the present invention, preferred embodiments of the present invention will be described in detail with reference to the attached drawings.

[0030] FIG. 1 schematically illustrates a computing device that provides a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to an embodiment of the present invention.

[0031] Referring to FIG. 1, a computing device (100) providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card may include a memory (110) in which instructions for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card are stored, and a processor (120) that performs operations to provide a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to the instructions stored in the memory. That is, the memory (110) of the computing device (100) may store instructions to be performed by the processor (120). Specifically, the instructions are code generated for the purpose of causing the computing device (100) to function in a specific manner, and may be stored in a computer-readable or computer-accessible memory that may be directed toward a computer or other programmable data processing equipment, and the instructions may perform processes for executing functions described in the specification of the present invention.

[0032] Additionally, the processor (120) of the computing device (100) may include hardware configurations such as a Micro Processing Unit (MPU) or a Central Processing Unit (CPU), a cache memory, and a data bus. Additionally, the computing device (100) may further include software configurations such as an operating system and an application for a specific purpose.

[0033] In addition, although not illustrated in FIG. 1, a security module according to one embodiment of the present invention may be a hardware security module comprising at least some of a memory card, a processor card, a smart card, a Surface-Mount Device (SMD) type chip card, and an external storage device.

[0034] A method using a computing device (100) according to one embodiment of the present invention configured as described above is explained with reference to FIG. 2 as follows.

[0035] FIG. 2 is a flowchart illustrating the sequence of a method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to an embodiment of the present invention.

[0036] Referring to FIG. 2, when a power-on signal to an unmanned digital device is obtained or a control signal for operating software for the operation of an unmanned digital device is obtained, the computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, it executes the software to perform control of the unmanned digital device and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module (S201).

[0037] Here, the integrity of the software is verified by comparing the software hash value stored in the security module with the software hash value of the unmanned digital device. More specifically, the computing device (100) verifies the integrity of the software by checking whether the first hash value stored in the security module (the first hash value is the value obtained by hashing the software authenticated for the operation of the unmanned digital device) and the second hash value generated by hashing the software are identical. At this time, if it is determined that the first hash value and the second hash value match each other, the software can be successfully executed, and the computing device (100) can perform control over the unmanned digital device.

[0038] In addition, the computing device (100) can perform device authentication for an unmanned digital device through interaction with an authentication server using a security module, and for a more specific explanation, this will be explained with reference to FIGS. 3a and FIGS. 3b.

[0039] FIGS. 3a and 3b schematically illustrate a series of processes for exchanging a security module ID, an authentication server ID, a first security module nonce, and a first server nonce between a security module (500) and an authentication server (600) according to an embodiment of the present invention and verifying them, and a series of processes for generating a security module authentication session key, a security module integrity verification key, a server authentication session key, and a server integrity verification key and performing device authentication for an unmanned digital device using them.

[0040] First, referring to FIG. 3a, the computing device (100) obtains (S11) a security module ID stored in the security module (500) and a first security module nonce generated by the security module (500) through interaction with the security module (500), and transmits (S12) the security module ID and the first security module nonce to the authentication server (600). Next, the computing device (100) causes the authentication server (600) to perform a security module ID validity verification process (S13) to verify whether the security module ID is a registered valid ID. At this time, the security module ID may be registered with the authentication server (600) in advance, and the authentication server (600) verifies whether the security module ID registered in advance and the security module ID obtained through the computing device (100) are identical. At this time, if it is confirmed that the security module ID registered in advance and the security module ID obtained through the computing device (100) are identical, the authentication server (600) encrypts the server ID and the first security module nonce with the server authentication key (S14), and transmits the encrypted server authentication data (wherein the server authentication data includes the server ID encrypted with the server authentication key and the first security module nonce encrypted with the server authentication key) and the first server nonce to the computing device (100) (S15). Meanwhile, the server authentication key may be generated by inputting the security module ID and the first authentication master key stored in the authentication server (600) into a key derivation function, but is not limited thereto.

[0041] Next, the computing device (100) transmits the server authentication data and the first server nonce to the security module (500) (S16), causing the security module (500) to decrypt the server authentication data using a security module authentication key corresponding to the server authentication key to obtain the server ID and the decrypted first security module nonce, and performs a first security module nonce verification process (S17) to verify whether the decrypted first security module nonce matches the first security module nonce. At this time, if it is confirmed that the decrypted first security module nonce matches the first security module nonce, the security module (500) is caused to generate (S18) security module authentication data (wherein the security module authentication data includes the security module ID encrypted with the security module authentication key and the first server nonce encrypted with the security module authentication key). Meanwhile, the above security module authentication key may be generated by inputting the security module ID and the second authentication master key stored in the security module (500) into a key derivation function, but is not limited thereto. Additionally, the first authentication master key stored in the authentication server (600) and the second authentication master key stored in the security module (500) may be symmetric keys, but the present invention is not limited thereto, and the first authentication master key and the second authentication master key may be asymmetric keys.

[0042] Next, the computing device (100) transmits the security module authentication data generated through the security module (500) to the authentication server (600) (S19), causing the authentication server (600) to decrypt the security module authentication data using the server authentication key to obtain a security module ID and a decrypted first server nonce, and performs a first server nonce verification process (S20) to verify whether the decrypted first server nonce matches the first server nonce. At this time, if it is confirmed that the decrypted first server nonce matches the first server nonce, a device authentication process is performed to perform device authentication for an unmanned digital device. For a more detailed explanation of the device authentication process, I will explain it with reference to FIG. 3b.

[0043] Referring to FIG. 3b, the computing device (100) may cause the security module (500) to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce, and to generate a security module integrity verification key (S21) by referencing the security module authentication session key and the first security module nonce. Here, the security module authentication session key may be generated by inputting the security module authentication key and the first security module nonce into a key derivation function and then re-inputting them into the key derivation function together with the first server nonce, but is not limited thereto, and the security module integrity verification key may be generated using a symmetric key encryption algorithm, the security module authentication session key, and the first security module nonce, but is not limited thereto. Next, the computing device (100) causes the security module (500) to encrypt the security module integrity verification key (S22) using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module (500), the encrypted security module integrity verification key is transmitted to the authentication server (600) (S23).

[0044] At this time, the authentication server (600) can verify the security module integrity verification key (S24) by decrypting the encrypted security module integrity verification key using the server authentication session key corresponding to the security module authentication session key. Here, the server authentication session key can be generated by referencing the server authentication key, the first security module nonce, and the first server nonce. More specifically, it can be generated by inputting the server authentication key and the first security module nonce into a key derivation function, and then re-inputting them into the key derivation function together with the first server nonce, but is not limited thereto. Next, the authentication server (600) encrypts the server integrity verification key (S25) using the server authentication session key and transmits the encrypted security module integrity verification key to the security module (500) through the computing device (100) (S26). Here, the server integrity verification key can be generated using a symmetric key encryption algorithm, the server authentication session key, and the first server nonce, but is not limited thereto. Next, when the security module (500) obtains the encrypted server integrity verification key, it performs device authentication for the unmanned digital device by decrypting the encrypted server integrity verification key using the security module authentication session key and verifying the server integrity verification key (S27). Meanwhile, the security module authentication session key and the server authentication session key may be symmetric keys, but the present invention is not limited thereto, and the security module authentication session key and the server authentication session key may be asymmetric keys. Next, the computing device (100) can perform identity authentication for the user through the unmanned digital device, and for a detailed explanation of this, I will explain it again with reference to FIG. 2.

[0045] Referring again to FIG. 2, when information requesting the provision of a specific product or specific service from a user is obtained from an unmanned digital device, the computing device (100) requests identity authentication from the user through the unmanned digital device, and when identity authentication information from a user terminal corresponding to the user (identity authentication information includes at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted the user VP corresponding to the user mobile ID, and location information of the user VP stored in the relay server) is obtained through the unmanned digital device, the security module (500) encrypts the identity authentication information using a first encryption / decryption session key and transmits the encrypted identity authentication information to an authentication server, thereby causing the authentication server to obtain identity authentication information by decrypting the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key, and obtains the user VP from the relay server by referring to the identity authentication information, and performs identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP (S202).

[0046] At this time, when personal authentication information from a user terminal is obtained through an unmanned digital device, the computing device (100) can create an encrypted communication channel with the authentication server (600), and for a more specific explanation, this will be explained with reference to FIG. 4.

[0047] FIG. 4 schematically illustrates a series of processes for generating a first encryption / decryption session key and a second encryption / decryption session key by exchanging a security module ID, an authentication server ID, a second security module nonce, and a second server nonce between a security module (500) and an authentication server (600) according to an embodiment of the present invention.

[0048] Referring to FIG. 4, the computing device (100) obtains (S31) a security module ID stored in the security module (500) and a second security module nonce generated by the security module (500) through interaction with the security module (500), and transmits (S32) the security module ID and the second security module nonce to the authentication server (600). Next, the computing device (100) causes the authentication server (600) to perform a security module ID validity verification process (S33) to verify whether the security module ID is a registered valid ID. At this time, the security module ID may be registered with the authentication server (600) in advance, and the authentication server (600) verifies whether the security module ID registered in advance and the security module ID obtained through the computing device (100) are identical. At this time, if it is confirmed that the security module ID registered in advance and the security module ID obtained through the computing device (100) are identical, the authentication server (600) encrypts the server ID and the second security module nonce with the server encryption key (S34), and transmits the encrypted server encryption data (wherein the server encryption data includes the server ID encrypted with the server encryption key and the second security module nonce encrypted with the server encryption key) and the second server nonce to the computing device (100) (S35). Meanwhile, the server encryption key may be generated by inputting the security module ID and the first encryption master key stored in the authentication server (600) into a key derivation function, but is not limited thereto.

[0049] Next, the computing device (100) transmits the server encrypted data and the second server nonce to the security module (500) (S36), causing the security module (500) to decrypt the server encrypted data using a security module encryption key corresponding to the server encryption key to obtain a server ID and a decrypted second security module nonce, and performs a second security module nonce verification process (S37) to verify whether the decrypted second security module nonce matches the second security module nonce. At this time, if it is confirmed that the decrypted second security module nonce matches the second security module nonce, the security module (500) is caused to generate (S38) security module encrypted data (wherein the security module encrypted data includes a security module ID encrypted with the security module encryption key and a second server nonce encrypted with the security module encryption key) by encrypting the security module ID and the second server nonce using the security module encryption key. Meanwhile, the above security module encryption key may be generated by inputting the security module ID and the second encryption master key stored in the security module (500) into a key derivation function, but is not limited thereto. Additionally, the first encryption master key stored in the authentication server (600) and the second encryption master key stored in the security module (500) may be symmetric keys, but the present invention is not limited thereto, and the first encryption master key and the second encryption master key may be asymmetric keys.

[0050] Next, the computing device (100) transmits the security module encrypted data generated through the security module (500) to the authentication server (600) (S39), causing the authentication server (600) to decrypt the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and performs a second server nonce verification process (S40) to verify whether the decrypted second server nonce matches the second server nonce. At this time, if it is confirmed that the decrypted second server nonce matches the second server nonce, the computing device (100) may cause the security module (500) to generate a first encryption / decryption session key (S41) by referring to the security module encryption key, the second security module nonce, and the second server nonce, and may cause the authentication server (600) to generate a second encryption / decryption session key (S42) by referring to the server encryption key, the second security module nonce, and the second server nonce. Meanwhile, the first encryption / decryption session key may be generated by inputting the security module encryption key and the second security module nonce into the key derivation function, and then re-inputting them into the key derivation function together with the second server nonce, but is not limited thereto; and the second encryption / decryption session key may be generated by inputting the server encryption key and the second security module nonce into the key derivation function, and then re-inputting them into the key derivation function together with the second server nonce, but is not limited thereto.

[0051] Additionally, the exchange of the second security module nonce and the second server nonce between the security module (500) and the authentication server (600) may be achieved by the security module (500) directly transmitting the second security module nonce to the authentication server (600) through the computing device (100), or by transmitting the encrypted second security module nonce encrypted with the security module encryption key to the authentication server (600), but is not limited thereto. Conversely, the exchange may be achieved by the authentication server (600) directly transmitting the second server nonce to the security module (500) through the computing device (100), or by transmitting the encrypted second server nonce encrypted with the server encryption key to the security module (500), but is not limited thereto. Additionally, the first encryption / decryption session key and the second encryption / decryption session key may be symmetric keys, but the present invention is not limited thereto, and the first encryption / decryption session key and the second encryption / decryption session key may be asymmetric keys.

[0052] In this way, when a cryptographic communication channel is created between the computing device (100), that is, the security module (500) and the authentication server (600) using the first encryption / decryption session key and the second encryption / decryption session key, the security module (500) may use the first encryption / decryption session key to encrypt personal authentication information to be transmitted to the authentication server (600), and the personal authentication information encrypted by the first encryption / decryption session key may be transmitted to the authentication server (600) through the cryptographic communication channel. At this time, the authentication server (600) may use the second encryption / decryption session key to decrypt the acquired encrypted personal authentication information.

[0053] Meanwhile, the first encryption / decryption session key and the second encryption / decryption session key can also encrypt / decrypt information other than personal authentication information. For example, the authentication server (600) may use the second encryption / decryption session key to encrypt personal authentication result information to be transmitted to the security module (500), and the personal authentication result information encrypted by the second encryption / decryption session key may be transmitted to the security module (500) through an encrypted communication channel. At this time, the security module (500) may use the first encryption / decryption session key to decrypt the obtained encrypted personal authentication result information.

[0054] That is, the computing device (100) transmits the encrypted identity authentication information, which is encrypted using a first encryption / decryption session key, to the authentication server (600) through the security module (500) via the encryption communication channel, and causes the authentication server (600) to obtain the identity authentication information by decrypting the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key, and causes the authentication server (600) to obtain the user VP from the relay server by referring to the identity authentication information, and causes the authentication of the user to perform identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP, and causes the identity authentication result information corresponding to the identity authentication to be encrypted using the second encryption / decryption session key to obtain the encrypted identity authentication result information, and when the encrypted identity authentication result information is obtained from the authentication server (600) via the encryption communication channel, the computing device (100) causes the security module (500) to decrypt the identity authentication result information encrypted using the first encryption / decryption session key, and the decrypted The identity verification of the user is completed by obtaining the identity verification result information. At this time, although the above description explains that the authentication server (600) obtains the user VP from the relay server, the user VP may also be obtained through encrypted communication by creating an encrypted communication channel between the authentication server (600) and the relay server through a method similar to the encrypted communication channel between the authentication server (600) and the computing device (100).

[0055] Meanwhile, identity authentication information can be obtained through unmanned digital devices in various ways; for example, identity authentication information can be obtained by scanning a QR code corresponding to the identity authentication information displayed on a user terminal, or by wireless communication with the user terminal, but is not limited thereto.

[0056] Next, a method for a computing device (100) according to one embodiment of the present invention to acquire a user DID will be described.

[0057] First, based on a user's interaction for generating a user DID, the user terminal requests the generation of a user DID from the mobile ID blockchain network. Accordingly, the mobile ID blockchain network generates a user DID and can register the mobile ID DID corresponding to the user DID on the distributed ledger of the mobile ID blockchain network. At this time, the mobile ID DID may include the user DID, the user public key, user VC issuance information, etc. At this time, the user private key corresponding to the user public key may be stored on the user terminal.

[0058] Subsequently, when information regarding a request for the provision of a specific product and / or specific service from a user is obtained from an unmanned digital device, the computing device (100) may request a user DID from the user terminal. At this time, the user terminal may provide at least some of the user VP, user DID, and identity authentication information, which are obtained by encrypting at least one user mobile ID VC required for identity authentication with the user's private key, to the computing device (100) through the unmanned digital device. At this time, the computing device (100) may have the authentication server (600) perform identity authentication for the user in response to the information regarding the provision of a specific product and / or specific service from the user terminal.

[0059] That is, the computing device (100) requests at least some of the user VP, user DID, and personal authentication information from the user through an unmanned digital device, and when at least some of the user VP, user DID, and personal authentication information are obtained from the user terminal, the authentication server (600) can verify them to perform personal authentication for the user.

[0060] For example, the computing device (100) can obtain a user DID corresponding to a user VP from a user terminal by adding the user authentication information through an unmanned digital device. In this case, the computing device (100) can have the security module (500) encrypt the user DID and the user authentication information with a first encryption / decryption session key, then transmit the encrypted user DID and the encrypted user authentication information to the authentication server (600), and have the authentication server (600) decrypt them with a second encryption / decryption session key to obtain the decrypted user DID and the decrypted user authentication information.

[0061] As another example, the computing device (100) may obtain the user DID through the relay server by having the user terminal add the user DID to the user VP and transmit it to the relay server. In this case, the authentication server (600) encrypts the user DID and the user VP with a second encryption / decryption session key, then transmits the encrypted user DID and the encrypted user VP to the computing device (100), and the computing device (100) may obtain the decrypted user DID and the decrypted user VP by having the security module (500) decrypt them with a first encryption / decryption session key.

[0062] Next, the computing device (100) can perform a mobile ID verification process that verifies a DID-based mobile ID, and for a specific explanation of this, I will explain it with reference to FIG. 5.

[0063] FIG. 5 schematically illustrates the process of verifying a DID-based mobile ID card according to one embodiment of the present invention.

[0064] Referring to FIG. 5, the computing device (100) causes the authentication server (600) to obtain a user public key corresponding to the user DID from a mobile identity blockchain network using a user DID corresponding to the user VP (S501). More specifically, it is configured to connect to a relay server by referring to the relay server address obtained from the identity authentication information decrypted by the second encryption / decryption session key, and to obtain the user VP from the relay server by providing the location information of the user VP obtained from the decrypted identity authentication information to the relay server, and to obtain a user public key corresponding to the user DID from a mobile identity blockchain network using the user DID corresponding to the user VP.

[0065] At this time, the authentication server (600) can decrypt the user VP using the acquired user public key to obtain at least one user VC (Verifiable Credential) (S502).

[0066] Additionally, the authentication server (600) can perform identity authentication by obtaining a mobile ID issuance server public key corresponding to the mobile ID issuance server DID from a mobile ID blockchain network using the mobile ID issuance server DID included in the user VC (S503), and verifying the user VC by checking the mobile ID issuance server signature value included in the user VC using the mobile ID issuance server public key (S504).

[0067] At this time, the authentication server (600) compares the hash value of the user VC stored in the mobile ID DID registered in the mobile ID blockchain network with the value of the user VC obtained from the user terminal converted into a hash value, and if the comparison result matches, it can confirm that the user VC was issued corresponding to the user DID.

[0068] In this way, a computing device (100) according to one embodiment of the present invention may provide a non-face-to-face authentication service for an unmanned digital device using a security module (500) and a mobile ID card to a user. That is, referring again to FIG. 2, when the user's identity is authenticated by the authentication server (600), the computing device (100) may provide a specific product or specific service requested by the user through the unmanned digital device (S203).

[0069] The embodiments according to the present invention described above may be implemented in the form of program instructions that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, etc., either alone or in combination. The program instructions recorded on the computer-readable recording medium may be those specifically designed and configured for the present invention, or they may be those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc. The hardware device may be configured to operate as one or more software modules to perform processing according to the present invention, and vice versa.

[0070] Although the present invention has been described above with specific details such as specific components, limited embodiments, and drawings, this is provided only to aid in a more comprehensive understanding of the invention, and the invention is not limited to the above embodiments, and a person skilled in the art to which the invention belongs can make various modifications and variations from this description.

[0071] Accordingly, the scope of the present invention should not be limited to the embodiments described above, and all modifications equivalent to or equivalent to the claims set forth below, as well as the claims described below, shall be considered to fall within the scope of the concept of the present invention.

Claims

Claim 1 A method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card, comprising: (a) when a power-on signal to the unmanned digital device is obtained or a control signal for the operation of software for the operation of the unmanned digital device is obtained, a computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, executes the software to perform control over the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module; (b) when information requesting the provision of a specific product or specific service from a user is obtained from the unmanned digital device, the computing device requests identity authentication from the user through the unmanned digital device, and identity authentication information from a user terminal corresponding to the user - the identity authentication information is at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID card, and location information of the user VP stored in the relay server. Including - a step in which, when obtained through the above-mentioned unmanned digital device, the encrypted identity authentication information, which is encrypted using a first encryption / decryption session key through the security module, is transmitted to the authentication server, thereby causing the authentication server to decrypt the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the identity authentication information, and to obtain the user VP from the relay server by referring to the identity authentication information, and to perform identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP;and (c) when the user is authenticated by the authentication server, the computing device provides the specific product or specific service requested by the user through the unmanned digital device; a method comprising; Claim 2 In claim 1, in step (a) above, the computing device (i) obtains a security module ID stored in the security module and a first security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server authentication data, which is obtained by encrypting the server ID and the first security module nonce with a server authentication key, and the first server nonce to the computing device, and (ii) if the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module to have the security module decrypt the server authentication data using a security module authentication key corresponding to the server authentication key to obtain the server ID and the decrypted first security module nonce, and the decrypted first security module nonce is the first security module nonce and (iii) verify whether they match, and if it is confirmed that the decrypted first security module nonce matches the first security module nonce, generate security module authentication data by encrypting the security module ID and the first server nonce using the security module authentication key; (iii) transmit the security module authentication data generated through the security module to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and verify whether the decrypted first server nonce matches the first server nonce; (iv) instruct the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce.A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key; and, from the authentication server, generating the server authentication session key by referencing the server authentication key, the first security module nonce, and the first server nonce, generating a server integrity verification key by referencing the server authentication session key and the first server nonce, and when the encrypted server integrity verification key obtained by encrypting the server integrity verification key using the server authentication session key is obtained, causing the security module to decrypt the encrypted server integrity verification key using the security module authentication session key. A method characterized by performing device authentication for the unmanned digital device by performing a process to verify the server integrity verification key. Claim 3 In claim 1, in step (b), the computing device (i) obtains a security module ID stored in the security module and a second security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the second security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server encrypted data obtained by encrypting the server ID and the second security module nonce with a server encryption key, and the second server nonce to the computing device, and (ii) if the server encrypted data and the second server nonce are obtained from the authentication server, transmits the server encrypted data and the second server nonce to the security module to have the security module decrypt the server encrypted data using a security module encryption key corresponding to the server encryption key to obtain the server ID and the decrypted second security module nonce, and the decrypted second security module nonce is the second security module nonce and (iii) verify whether they match, and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, generate security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key; (iii) transmit the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and verify whether the decrypted second server nonce matches the second server nonce; (iv) cause the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce; and cause the authentication server,A method characterized by performing a process of generating a second encryption / decryption session key by referencing the server encryption key, the second security module nonce, and the second server nonce, as it is confirmed that the decrypted second server nonce matches the second server nonce. Claim 4 A method according to claim 1, wherein in step (b), the computing device performs identity authentication by causing the authentication server to obtain a user public key corresponding to the user DID from the mobile identity blockchain network using a user DID corresponding to the user VP, decrypt the user VP using the user public key to obtain at least one user VC (Verifiable Credential), obtain a mobile identity issuance server public key corresponding to the mobile identity issuance server DID from the mobile identity blockchain network using a mobile identity issuance server DID included in the user VC, and verify the user VC by confirming a mobile identity issuance server signature value included in the user VC using the mobile identity issuance server public key. Claim 5 A method according to claim 1, wherein in step (b), the computing device obtains a user DID corresponding to the user VP by adding it to the identity authentication information from the user terminal through the unmanned digital device, or causes the user terminal to transmit the user DID by adding it to the user VP to the relay server and obtains the user DID through the relay server. Claim 6 A method according to claim 1, wherein in step (b), the computing device obtains the identity authentication information by scanning a QR code corresponding to the identity authentication information displayed on the user terminal through the unmanned digital device, or obtains the identity authentication information through wireless communication with the user terminal through the unmanned digital device. Claim 7 A method according to claim 1, wherein in step (a), the computing device verifies the integrity of the software by confirming whether the first hash value stored in the security module—the first hash value is a value obtained by hashing the software authenticated for the operation of the unmanned digital device—and the second hash value generated by hashing the software are the same. Claim 8 A method according to claim 1, wherein the security module is a hardware security module comprising at least some of a memory card, a processor card, a smart card, a Surface-Mount Device (SMD) type chip card, and an external storage device. Claim 9 A computing device that provides a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card, comprising: a memory in which instructions for providing the non-face-to-face authentication service for the unmanned digital device using the security module and the mobile ID card are stored; and a processor that performs operations to provide the non-face-to-face authentication service of the unmanned digital device using the security module and the mobile ID card according to the instructions stored in the memory; wherein the processor comprises: (I) a process of verifying the integrity of the software through a security module corresponding to the unmanned digital device when a power-on signal to the unmanned digital device is obtained or a control signal for the operation of the software for the operation of the unmanned digital device is obtained, and when the integrity of the software is verified, running the software to perform control over the unmanned digital device, and performing device authentication for the unmanned digital device through interaction with an authentication server using the security module; (II) a process of requesting identity authentication from the user through the unmanned digital device when information requesting the provision of a specific product or specific service from the user is obtained from the unmanned digital device, and identity authentication information from a user terminal corresponding to the user - the identity authentication information is a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID card, and the Including at least one of the location information of the above-mentioned user VP stored in the relay server - when obtained through the above-mentioned unmanned digital device, the above-mentioned identity authentication information, encrypted using a first encryption / decryption session key, is transmitted to the above-mentioned authentication server through the security module, thereby causing the above-mentioned authentication server,A computing device characterized by: (III) a process of obtaining the identity authentication information by decrypting the encrypted identity authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key, obtaining the user VP from the relay server by referring to the identity authentication information, and performing identity authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP; and (III) a process of providing the specific product or specific service requested by the user through the unmanned digital device when the identity authentication for the user is performed by the authentication server. Claim 10 In claim 9, the processor, in the process (I), (i) obtains a security module ID stored in the security module and a first security module nonce generated by the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server authentication data, which is obtained by encrypting the server ID and the first security module nonce with a server authentication key, and the first server nonce to the computing device, and (ii) if the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module to have the security module decrypt the server authentication data using a security module authentication key corresponding to the server authentication key to obtain the server ID and the decrypted first security module nonce, and the decrypted first security module nonce is the first security module (iii) verify whether it matches the nonce, and if it is confirmed that the decrypted first security module nonce matches the first security module nonce, generate security module authentication data by encrypting the security module ID and the first server nonce using the security module authentication key; (iii) transmit the security module authentication data generated through the security module to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and verify whether the decrypted first server nonce matches the first server nonce; (iv) instruct the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce.A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key; and, from the authentication server, generating the server authentication session key by referencing the server authentication key, the first security module nonce, and the first server nonce, generating a server integrity verification key by referencing the server authentication session key and the first server nonce, and when the encrypted server integrity verification key obtained by encrypting the server integrity verification key using the server authentication session key is obtained, causing the security module to decrypt the encrypted server integrity verification key using the security module authentication session key. A computing device characterized by performing device authentication for the unmanned digital device by performing a process to verify the server integrity verification key. Claim 11 In claim 9, the processor, in the process (II), (i) obtains a security module ID stored in the security module and a second security module nonce generated by the security module through interaction with the security module, and transmits the security module ID and the second security module nonce to the authentication server to have the authentication server verify whether the security module ID is a registered valid ID; if the security module ID is confirmed to be a valid ID, transmits server encrypted data, obtained by encrypting the server ID and the second security module nonce with a server encryption key, and the second server nonce to the computing device; and (ii) when the server encrypted data and the second server nonce are obtained from the authentication server, transmits the server encrypted data and the second server nonce to the security module to have the security module decrypt the server encrypted data using a security module encryption key corresponding to the server encryption key to obtain the server ID and the decrypted second security module nonce, and the decrypted second security module nonce is the second security module A process for verifying whether it matches the nonce, and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, generating security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key; (iii) transmitting the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and verifying whether the decrypted second server nonce matches the second server nonce; and (iv) causing the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce.A computing device characterized by performing a process in which the authentication server generates the second encryption / decryption session key by referencing the server encryption key, the second security module nonce, and the second server nonce as it is confirmed that the decrypted second server nonce matches the second server nonce. Claim 12 A computing device according to claim 9, wherein, in the process (II), the processor causes the authentication server to obtain a user public key corresponding to the user DID from the mobile ID blockchain network using a user DID corresponding to the user VP, decrypts the user VP using the user public key to obtain at least one user VC (Verifiable Credential), obtains a mobile ID issuing server public key corresponding to the mobile ID issuing server DID from the mobile ID blockchain network using a mobile ID issuing server DID included in the user VC, and verifies the user VC by confirming a mobile ID issuing server signature value included in the user VC using the mobile ID issuing server public key. Claim 13 A computing device according to claim 9, wherein the processor, in the process (II), obtains a user DID corresponding to the user VP by adding it to the identity authentication information from the user terminal through the unmanned digital device, or causes the user terminal to transmit the user DID by adding it to the user VP to the relay server and obtains the user DID through the relay server. Claim 14 A computing device according to claim 9, wherein the processor, in the process (II), obtains the identity authentication information by scanning a QR code corresponding to the identity authentication information displayed on the user terminal through the unmanned digital device, or obtains the identity authentication information through wireless communication with the user terminal through the unmanned digital device. Claim 15 A computing device according to claim 9, wherein the processor verifies the integrity of the software by checking whether, in the process (I), the first hash value stored in the security module—the first hash value is a value obtained by hashing the software authenticated for the operation of the unmanned digital device—and the second hash value generated by hashing the software are the same. Claim 16 A computing device according to claim 9, wherein the security module is a hardware security module comprising at least some of a memory card, a processor card, a smart card, a Surface-Mount Device (SMD) type chip card, and an external storage device.

Citation Information

Patent Citations

  • Method and apparatus for providing service using kiosk

    KR1020200088740A

  • Method for mobile identification card authentication service using decentralized identifier based on blockchain networks and user device executing mobile identification card authentication service

    KR1020220028870A

  • Method and system for managing kiosk based on programmable logic controller

    KR102361081B1

  • System and method for user authentication at a kiosk from a mobile device

    US20200084040A1