User authentication and signature device and method using user biometric identification data

By using touch panels and biometric identification data in user information equipment to generate user keys, combined with user specific photos and biometric data, user authentication and signatures without third-party authentication agencies are achieved, solving the problems of fragile security and relying on third-party agencies in the prior art, and achieving higher confidentiality and security.

CN113826096BActive Publication Date: 2025-06-06NIOBO CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980096095.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-05-23
Filing Date
2019-05-31
Publication Date
2025-06-06
Estimated Expiration
2039-05-31

AI Technical Summary

Technical Problem

The prior art has problems with fragile security in user authentication and digital signatures, which are prone to misappropriation and relying on third-party certification agencies, especially in IoT and cryptocurrency circulation platforms.

Method used

By using the touch panel and biometric identification data, user keys with low memory burden and high occultness are generated, and user authentication and signature are realized without the intervention of third-party authentication agencies.

Benefits of technology

Provides faster, simpler, and cost-effective user authentication and signature capabilities, improving confidentiality and security, and reducing the complexity and cost of key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113826096B_ABST
    Figure CN113826096B_ABST
Patent Text Reader

Abstract

The present invention relates to a user authentication and signature device and method that can be provided in various user information devices including information devices with touch panels such as smart phones or desktop computers, laptops, tablet computers, closed-circuit televisions, the Internet of Things, driverless cars, drones, and business services using the network. More specifically, the present invention relates to a key / password generation and verification system for user authentication that needs to be provided for various network-based and application-based services implemented on a specific platform that various information devices serve in a client-server or peer-to-peer network environment, and a user authentication and digital signature device and method that is simpler and can ensure confidentiality and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a user authentication and signature device and method that can be provided in various user information devices including information devices with touch panels such as smartphones, or desktop computers, laptops, tablet computers, closed-circuit televisions, the Internet of Things, driverless cars, drones, and business services using the network.

[0002] More specifically, the present invention relates to a key / password generation and verification system for user authentication that is required to be provided by various information devices for various web-based services and application-based services implemented on specific platforms in a client-server or peer-to-peer network environment, and a user authentication and digital signature device and method that is simpler and can ensure confidentiality and security. Background Art

[0003] The most important technical field in the future technologies such as the Internet of Things (IoT), self-driving cars, drones, and other devices, equipment, and service technologies is "security issues."

[0004] Security technology is particularly important in the Internet of Things, where many things are connected and processed. Among them, the core technology for user authentication, namely passwords, urgently needs a technology that can further enhance the convenience of concealment, confidentiality, security, and ease of use, while supporting digital signature functions.

[0005] Usually, the user / owner authentication method basically uses information such as account number (ID, IDentification) / password (PW, Password), personal identification number, etc. The ID / password method is low-cost, but the security is fragile. For example, the user / owner's password composed of text, numbers, symbols, etc. generally tends to be short and easy to remember. However, this kind of password is easy for others to predict and easy to be stolen. On the contrary, in order to prevent theft, the password generated by a combination of complex and long text, numbers, symbols, etc. is difficult for the user / owner to remember, and it needs to be backed up and stored on paper, USB or other storage media before use on demand. However, such means are also easy to be cracked or stolen, resulting in a high possibility of password theft.

[0006] According to recent reports (www.fidoalliance.org), the most commonly used password authentication method has serious problems. Specifically, according to recent reports, passwords are the root cause of over 80% of data breaches, more than 90% of users have online accounts, up to 51% of passwords are reused, 1 / 3 of online purchases abandoned due to forgotten passwords, and the average help desk labor cost for a single password reset is $70.

[0007] In addition, the so-called digital signature function refers to a technology that is implemented in order to detect whether the user authentication information or short message sent or received between the sender and the receiver of the user authentication information or short message is forged or altered by a third party, to detect whether the user authentication information or short message is intercepted due to the disguise of a third party, and to ensure the post-repudiation of the sending and receiving of the user authentication information or short message.

[0008] Moreover, human biometrics, i.e. fingerprint, iris, face, vein, and voice recognition technology, can be used to replace user authentication means or digital signature functions. That is, by adding the sender's biometric information to the sent user authentication information or short message, and comparing it with the sender's biometric information saved by the recipient, the sender's user authentication and signature functions can be realized at the same time. If a person's biometric information is used as user authentication or signature information, it is highly secure and easy to use. However, if the biometric information provided to a third party is stolen and leaked without any changes, it cannot be exchanged or changed, so the problem is more serious. Moreover, the provision of biometric information is subject to legal restrictions on the leakage of personal information, so it is not ideal for others, i.e. a third party, to manage biometric information. Because once biometric information is leaked, it cannot be issued again, and there is a high possibility of permanent malicious use.

[0009] In addition, the FIDO (Fast IDentity Online) Alliance is developing an international standard protocol technology for user authentication through the user's biometric data to change the existing password method. The role of the FIDO Alliance is to jointly build a more convenient and secure authentication system and develop technical standards for the authentication system. The alliance was formed in the summer of 2012, officially launched in February 2013, and released FIDO1.0 in December 2014. In 2019, the FIDO Alliance and W3C (World Wide Web Consortium) collaborated to set FIDO2.0 as an international standard and actively popularize it. Different from FIDO1.0, which is a biometrics authentication standard centered on mobile devices (APPs), FIDO2.0 is expanded to be used in various environments such as computers, IoT devices, etc. including mobile devices.

[0010] FIDO is a second-generation authentication technology that uses authentication devices such as smartphones (for example, fingerprint recognition devices) to collect information, generate an authentication result value through an authenticator, transmit it to a server, and then verify the authentication result value by the server.

[0011] FIDO1.0 and FIDO2.0 are implemented through two authentication standards: mobile-based UAF and Wab-based U2F. UAF (Universal Authentication Factor) is a mobile application-centric authentication method that uses user-specific biometric information such as fingerprints, voice, and facial recognition for authentication. After verifying the user using the biometric information of user terminals such as smartphones, an asymmetric key pair (private key, public key) is generated, and the public key is registered on the service provider server for remote authentication. U2F (Universal 2nd Factor) is a computer-centric authentication method that uses an ID and password to perform a primary authentication, and then uses a USB or smart card that stores a one-time security key for secondary authentication.

[0012] In addition, the most important thing in transactions based on cryptocurrencies such as Bitcoin is the setting and storage management of the private key, which must be completed by the owner of the cryptocurrency. In other words, if the private key is intercepted due to loss or cracking, the same private key cannot be generated again, and the ownership of the cryptocurrency is lost, and all the Bitcoin assets are lost forever. There is still a risk.

[0013] The private key is composed of a combination of randomly selected values ​​or text. The person who owns and controls the private key is the owner and controller of all funds associated with the cryptocurrency address. The private key is used to generate the signature of the cryptocurrency owner. The cryptocurrency funds must be signed to obtain the right to use the funds. Therefore, the technical architecture related to the private key of the cryptocurrency owner is the core technical element in the cryptocurrency architecture technology.

[0014] The digital signature technology widely used at present is based on a technology similar to the "public key encryption method". After sending the short message and digital signature to the recipient, the recipient uses the sender's public key to decrypt the ciphertext (signature). If the decrypted short message is consistent with the received short message, the "sender's authentication" and "sender's non-repudiation" can be confirmed, so the above-mentioned function is called the "digital signature method".

[0015] However, there are also problems with the digital signature method. That is, if the public key provided for decryption is inconsistent with the public key sent by the sender due to a third party's disguise, not only the sender's authentication but also the non-repudiation confirmation will fail. Therefore, a technology proposed to eliminate these hazards is the "digital certificate" method.

[0016] The so-called digital certificate or certificate method refers to a third party institution that establishes a so-called certification authority "CA: Certification Authority", registers its own private key or public key with the certification authority, and then entrusts the issuance of a certificate for its own private key or public key, and uses the issued certificate as the basic method for notarized information application of the private key or public key. This digital certificate or authentication method also requires the establishment and maintenance of a third certification authority, which has an economic burden and greatly reduces the efficiency of use for users / owners. Summary of the invention

[0017] Technical issues

[0018] The technical problem to be solved by the present invention is to provide user authentication and digital signature functions that can ensure confidentiality and security in all application services such as the Internet of Things and virtual currency circulation platforms described in the background technology, and to provide a password or key generation technology that is easy for users or owners to create and manage, and can generate a small memory burden. In addition, the user authentication and signature of the generated password or key are controlled as biometric information, thereby providing a device and method that can support faster and more cost-effective user authentication and signature functions.

[0019] The technical problem to be solved by the present invention is to provide a device and method for providing user authentication and digital signature simultaneously on a service device, which is faster and simpler than a user authentication and signature method based on FIDO standard specifications and protocols using user biometric identification data, and which can provide the user authentication and digital signature simultaneously on a service device without incurring the risk of theft when the biometric information of a person is used as user signature information in a network application service.

[0020] The technical problem to be solved by the present invention is to provide a digital signature device and method that can support digital signature and authentication functions that can be applied to various purposes, does not require the intervention or guarantee of a third-party organization such as a certification organization, can ensure confidentiality and security, and can be used economically.

[0021] Technical Solution

[0022] Usually, the user authentication and signature device must include means for registering the user's key and authenticating the registered key (key), and must have the device or means required for digital signature.

[0023] To solve the above-mentioned problem, in the user authentication and signature device of the present invention, which utilizes the user touch data of a touch panel and the user identification device through the user's biometric identification data, the device for setting and registering the user's key comprises: a user information device with a touch panel and a computing function; a user information device with a user biometric identification data identification processor which acquires the user's biometric identification data from the user by utilizing the user biometric input and output device on the user information device, stores the acquired and stored user biometric identification data in the user's information device memory, and identifies the user based on the acquired and stored user biometric identification data; a user image data management processor which stores and manages the specific image data required to be displayed on the touch panel of the user information device on the user information device; and a key registration box which displays on the touch panel of the user information device a key registration requesting the user's key. processor; responding to a user's key registration request, uploading image data selected by the user or the user image data management processor from the image data stored in the image memory of the user information device to a user registration key generation image upload processor displayed on the touch panel of the user information device; a user registration key generation data acquisition processor that acquires user registration key generation data by touching a pixel at a specific position in the image data displayed on the touch panel of the user information device by the user registration key generation image upload processor; a user registration key generation processor that encrypts the user's characteristic biometric data stored in the memory of the user information device acquired by the user using a biometric data input / output device or the user registration key generation data acquired by the user registration key generation data extraction processor, thereby generating a user registration key;

[0024] A user registration key generation data acquisition processor that acquires user registration key generation data by touching a pixel at a specific position in the image data displayed on the touch panel of the user information device through the user registration key generation image upload processor includes: (a) a user registration key generation data acquisition processor that acquires and processes the coordinate value and the color value of the touched pixel after the user re-acquires the user's biometric identification data through the biometric data input and output device, performs user identification processing by comparing the data with the acquired and stored user biometric identification data to confirm whether the user is the same user; or (b) at least one of the user registration key generation data acquisition processors that acquires the coordinate value and the color value of the touched pixel at the same time after the user re-acquires the user's biometric identification data through the biometric data input and output device, performs user identification processing by comparing the data with the acquired and stored user biometric identification data to confirm whether the user is the same user.

[0025] Furthermore, the user registration key generation processor for encrypting the user biometric identification data acquired by the user using the biometric identification data input / output device and stored in the user information device memory or the user registration key generation data acquired by the user registration key generation data acquisition processor to generate the user registration key comprises: (a) selecting at least one of the coordinate values ​​of the touch pixel, the color value of the touch pixel or the user biometric identification data acquired by the user using the biometric identification data input / output device and stored in the user information device memory, and then encrypting each of the encrypted data into one data, combining the one or more encrypted data and the unencrypted data. (a) a processor for generating a user registration key for the user registration key, which combines at least two data into one and then encrypts the data, combines the at least two data into one encrypted data and unencrypted data into one data, or generates one of the data by re-encrypting the combined data as the user registration key; and (b) a processor for generating a user registration key for the user registration key, which combines at least two data into one encrypted data and unencrypted data into one data, or generates one of the data by re-encrypting the combined data from the coordinate value of the touch pixel, the color value of the touch pixel, or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user information device memory.

[0026] Preferably, the user authentication and signature device comprises: a user information device with a touch panel and a computing function; a user information device with a user biometric identification data identification processor which acquires the user's biometric identification data from the user by using the user biometric input and output device on the user information device, stores the acquired and stored user biometric identification data in the user information device memory, and identifies the user based on the acquired and stored user biometric identification data; a user image data management processor which stores and manages the required specific image data on the touch panel of the user information device; a processor which displays an authentication key input box requiring user key authentication on the touch panel of the user information device; and a processor which responds to the user's key authentication request and sends the user or the user image data management processor from the user information device to the user information device. A user authentication key generation image uploading processor is configured to select image data for a user registration key from image data stored in an image memory and re-upload the image data to be displayed on a touch panel of the user information device; a user authentication key generation data acquisition processor is configured to acquire user authentication key generation data when a user touches a pixel at the same position designated when remembering to register a user key from the re-displayed image data; a user authentication key generation processor is configured to encrypt the user authentication key generation data acquired by the user authentication key generation data acquisition processor and then generate a user authentication key; a user registration key authentication processor is configured to compare and determine the key re-generated by the user authentication key generation processor with the key stored in the user information device or a device requesting user key authentication;

[0027] When a user touches a pixel at the same designated position when remembering to register a user key from the image data redisplayed by the user authentication key generation image upload processor and re-touches it, the user authentication key generation data acquisition processor acquires the user authentication key generation data, including: (a) a processor that acquires the coordinate value and the color value of the re-touched pixel when the user touches a pixel at the same designated position when remembering to register a user key and re-touches it through the biometric identification data input and output device, after comparing with the acquired and stored user biometric identification data to confirm that the same user is the same; or (b) a processor that acquires the coordinate value and the color value of the re-touched pixel when the user touches a pixel at the same designated position when remembering to register a user key from the redisplayed image data and re-touches it, compares and processes the same with the user biometric identification data stored by the user biometric identification data recognition processor, and simultaneously acquires the coordinate value and the color value of the re-touched pixel.

[0028] Furthermore, the user authentication key generation processor that encrypts the re-acquired user touch data with the stored user biometric identification data to generate the user authentication key includes: (a) a user authentication key generation processor that selects at least one of the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the user biometric identification data acquired by the user using the biometric identification data input and output device and stored in the user information device memory, and then generates the user authentication key from one of the data of combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data; (b) one of the user authentication key generation processors that generates the user authentication key from at least two of the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the user biometric identification data acquired by the user using the biometric identification data input and output device and stored in the user information device memory, and then encrypts the data; combines the encrypted data and unencrypted data into one, or re-encrypts the combined data.

[0029] Preferably, the user authentication and signature method comprises: a step of obtaining the user's biometric identification data through the biometric identification data input and output device of the user information device by the user, and then storing it in the memory device of the user biometric identification data processor of the user information device; a step of receiving a key (password) registration request from the user; a step of responding to the key registration request and uploading image data selected by the user or the image data processor from the image data stored in the image memory of the user information device to the touch panel of the user information device for display; a step of obtaining the coordinate value and color value of the touched pixel as data for generating a key for user registration when a pixel at a specific position in the image data displayed on the touch panel of the user information device is touched by the user; a step of encrypting the coordinate value and color value of the touched pixel or the user biometric identification data stored in the memory of the user's information device and generating a key for user registration;

[0030] When a pixel at a specific position in the image data displayed on the touch panel of the user information device is designated by the user's touch, the step of obtaining the coordinate value and the color value of the touch pixel as key generation data for user registration includes at least one of the following steps: (a) after the user uses a biometric identification data input and output device to re-acquire the user's biometric identification data, compare it with the acquired and stored user biometric identification data to confirm that the same user is used, and then obtain the coordinate value and the color value of the touch pixel; (b) after re-acquiring the user's biometric identification data and comparing it with the user biometric identification data stored by the user biometric identification data verification processor, and simultaneously obtaining the coordinate value and the pixel color value of the touch pixel.

[0031] Furthermore, the step of encrypting the coordinate value of the touch pixel and the color value of the touch pixel or the stored user biometric identification data and generating a user registration key includes any one of the following steps: (a) selecting at least one of the coordinate value of the touch pixel, the color value of the touch pixel or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user information device memory, and then generating the user registration key from any one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data; (b) selecting at least two of the coordinate value of the touch pixel, the color value of the touch pixel or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user information device memory, and then encrypting the encrypted data, combining the at least two or more data into one encrypted data and unencrypted data into one data, or re-encrypting the combined data, and generating the user registration key.

[0032] Preferably, the user authentication and signature method comprises: a step of receiving a registered user key authentication request; a step of responding to the user key authentication request and uploading image data selected by the user or the image data processor as the user registration key from the image data stored in the image memory of the user information device to the touch panel of the user information device for display; a step of obtaining user authentication key generation data when the user touches the pixel at the same position designated when the user remembers to register the user key from the redisplayed image data and touches it again; a step of encrypting the user authentication key generation data to generate the user authentication key; a step of comparing and determining the key regenerated by the user authentication key generation processor and the key registered in the user information device or the device requesting the user key authentication;

[0033] When the user recalls and touches the pixel at the same designated position that was touched when generating the user key in the redisplayed image data, the step of obtaining the key generation data for user authentication includes one of the following steps: (a) obtaining the user's biometric identification data by using the biometric identification data input and output device, and comparing it with the acquired and stored user biometric identification data to confirm that it is the same user, and then obtaining the coordinate value and color value of the re-touched pixel from the redisplayed image data when the user recalls and touches the pixel at the same designated position that was touched when generating the user key; or (b) obtaining the user's biometric identification data from the redisplayed image data, and comparing it with the user biometric identification data stored by the user biometric identification data recognition processor, and simultaneously obtaining the coordinate value and color value of the re-touched pixel.

[0034] Further, the step of re-encrypting the coordinate value of the re-touched pixel and the color value of the re-touched pixel or the stored user biometric identification data information to generate the user authentication key includes one of the following steps: (a) selecting at least one of the user's biometric identification data acquired by the biometric identification data input and output device and stored in the user information device memory, and then encrypting them separately, and then generating the user authentication key from one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data; (b) generating the user authentication key from the coordinate value of the re-touched pixel, the color value of the re-touched pixel or the user's biometric identification data acquired by the user by the biometric identification data input and output device and stored in the user's information device memory, and then combining at least two of the data into one and then encrypting them, combining the encrypted data and unencrypted data into one, or re-encrypting the combined data.

[0035] Preferably, the step of encrypting the acquired coordinate value of the touch pixel, the acquired color value of the touch pixel or the biometric identification data of the user to generate a key for the user registration can be performed by encrypting and keying using a one-way hash function or an elliptic curve equation.

[0036] Preferably, the step of re-encrypting the coordinate value of the representative pixel of the same touch point, the representative pixel color value or the stored user feature identification data to generate a key for user authentication is to encrypt and key it using a one-way hash function or an elliptic curve equation.

[0037] Beneficial Effects

[0038] According to the present invention, the beneficial effect is that it can provide a user authentication and signature device and method that is simpler, safer, and more confidential than the user authentication and signature device and method of the FID01.0 and FID02.0 standards and protocols as international standards.

[0039] According to the present invention, its beneficial effect is that a user authentication and signature system based on the three inherent authentication information of the user can be provided. Specifically, a user authentication and signature system based on user knowledge information, owned information and biometric identification information can be provided. Unlike the FIDO standard and protocol, there is no signature system, and the user's inherent personal information, that is, the user's biometric information, is provided to a third-party service device without the risk of being stolen. Moreover, even if the data is lost, it is useless to the third party, so the user authentication and signature device of the new ecosystem of the user's biometric information can be used with confidence.

[0040] According to the present invention, its beneficial effect is that it can provide a user authentication and signature method that does not require the key to be stored in other devices, and only requires remembering the key generation process, that is, using the same method, and safely using one password in multiple devices and services, which can be used at any time and conveniently.

[0041] According to the present invention, its beneficial effect lies in providing a user authentication and signature integration device that can use the user's specific photo / image to easily generate a user key with less memory burden and high anonymity, while using the user's biometric identification data to exert excellent confidentiality, security and reproducibility in the Internet of Things, cryptocurrency circulation or application services for various purposes.

[0042] According to the present invention, the beneficial effect is to provide an economical and effective user authentication and signature device which does not require other tools such as a random number generator to generate a key.

[0043] According to the present invention, its beneficial effect lies in that the user's image / photo is attached to the user authenticator of the existing FIDO standard method, that is, the user's biometric identification data, as a multimodal authenticator, which further improves the user's convenience, and by attaching a multimodal authenticator to the public key signature method, which is the digital signature method of the current FIDO standard, a more powerful user signature method can be provided without changing the FIDO standard. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is an example diagram of a network model in which user authentication and an apparatus according to an embodiment of the present invention are implemented;

[0045] Figure 2 is an example diagram showing the processing of a user's biometric data;

[0046] Figure 3 is an exemplary diagram of a user authentication and signature device according to an embodiment of the present invention;

[0047] Figure 4 is an embodiment of a user image data management processor according to an embodiment of the present invention;

[0048] Figure 5 is a flow chart of a process of logging in a user key through a user authentication and signature device according to an embodiment of the present invention;

[0049] Figure 6 This is an example of a key input box in a specific application that requires a logged-in user key;

[0050] Figure 7 An embodiment of uploading a user's image to a touch panel in response to a key login request;

[0051] Figure 8 is a schematic diagram showing an embodiment of acquiring touch pixel data from an image;

[0052] Fig. 9 is an example diagram of a user authentication password input request box displayed on a user's display panel for user authentication;

[0053] Fig.10 is a flow chart of a process for processing a process required for user authentication through a user authentication and signature device according to an embodiment of the present invention;

[0054] Fig.11 is an example diagram of multiple images displayed by a user authentication and signature device according to an embodiment of the present invention for logging in / authenticating a user key using multiple images;

[0055] Fig.12 is a schematic diagram showing the processing flow required for user login according to the FIDO standard method;

[0056] Fig.13 is a schematic diagram showing the processing flow required for user authentication according to the FIDO standard method;

[0057] Fig.14 This is a flowchart showing the functional relationship processed in the standard digital signature method. DETAILED DESCRIPTION

[0058] The technical solutions in the embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings, but the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Those skilled in the art can implement the present invention in various forms, but all other embodiments obtained without creative work are within the scope of protection of the present invention.

[0059] To facilitate understanding of the technology of the present invention, the technical terms used in this specification are explained below.

[0060] User authentication refers to a verification procedure implemented to grant users access rights when using a certain service or information. Furthermore, after the user registers, the user's account or password can be identified, and the account or password provided by the user is compared with the registered account or password to verify whether the user has access rights. In addition, the user signature device refers to a device that can support the detection of forgery and alteration of the user's account or password, the detection of third-party camouflage, and the prevention of subsequent denial.

[0061] The key in this specification is used in the same meaning as a general user password, private key or password. The key can be used in the same meaning as a private key and a public key in the field of cryptography. The key can represent a user key, a user registration key or a user authentication key according to the embodiment. If it is encrypted using a hash function, it can represent a hash value key. The user's biometrics information, i.e., fingerprint, iris, face, vein, voice data, etc., is expressed as the user's biometrics.

[0062] The confidentiality of a password / key in this specification refers to the entropy or randomness of the source that generates the password / key, which is large, and the length of the password / private key is sufficiently long, so that it is extremely difficult to decrypt the password / key even with a high-performance computer. The integrity of a password / key refers to the impossibility / possibility of forgery or alteration, that is, even if someone steals the password / key, they cannot replay or use it. The reproducibility of the password / key refers to the storage of the password / key only for the convenience of the user and easy to remember and replay.

[0063] The processor in this specification refers to computer software or hardware that executes specific means or functions.

[0064] The term "touch" in this manual refers to the gestures input by users using "hand grease", "pen", etc. on the display screen of a smartphone, or the gestures input by users using "hand grease", "pen", and "mouse" on the display screen of a desktop computer, etc.

[0065] Figure 1 This is an example diagram of a network model in which a user authentication and signature device according to an embodiment of the present invention is implemented.

[0066] Figure 1The present invention briefly shows a user authentication and signature device that can simultaneously support user authentication and signature functions, and a service environment in which the user authentication and signature device is used, according to an embodiment of the present invention.

[0067] according to Figure 1 a. The user authentication and signature device is provided and used in an environment of a user information device (101, 102 and 103) having a touch panel, an application providing server (105) providing a certain service, and a network 104 connecting the user information device (101, 102 and 103) and the application providing server (105).

[0068] For example, the user information device ( 101 , 102 , and 103 ) is a computing device such as a smart phone, a tablet computer, or a computer that has a touch panel, a CPU, a storage device, and a network interface.

[0069] The application providing server (105) may be provided with a user database (106) for registration and management of application service users. The user database (106) may store user accounts, passwords and other user-generated keys.

[0070] Figure 1 b is an embodiment showing that the user authentication and signature device of the present invention is provided and used in a P2P (Peer to Peer, peer-to-peer network) type network environment. Figure 1 b. Each node on the P2P network (111) provides a user information device (107, 108, 109 and 110), and the user authentication and signature device of the present invention can be built into each user information device.

[0071] In addition, the user authentication and signature device of the present invention is an application such as an Apple or Google retail store, which can be provided for use in a wireless link network or a network application, a hybrid mode mobile application network, and can also be provided on a closed private network consisting only of specific application participants.

[0072] The following user information equipment refers to Figure 1 Of course, any one of the multiple user information devices (101, 102, 103, 107, 108, 109 and 110) shown in the figure has the same function as the user information device (101).

[0073] Figure 2 is an example diagram showing the processing of a user's biometric data.

[0074] Specifically, Figure 2 a to Figure 2d is an embodiment showing the processing in the user biometric identification data recognition processor provided in the user information device (101) by the device for acquiring the user biometric identification data built into the user information device (101).

[0075] according to Figure 2 a. The user's fingerprint is scanned using a fingerprint recognition device (201) built into the user information device (101). Figure 2 b, then extract the biometric identification data (203) of the user that matches the fingerprint feature (202) and store it in the user device for identification of the user's fingerprint. Figure 2 b. The user's biometric feature identification data (203) is an example of obtaining numerical data related to the fingerprint feature (202) in bit units.

[0076] according to Figure 2 c. Usually, the user's iris, face, vein and other biometric identification data are obtained through a camera (204) built into the user information device (101). Figure 2 d. The user's voice data is acquired by using a microphone (205), and a processor for implementing a pattern matching algorithm for recognition is also provided internally.

[0077] The acquisition of user biometric identification data and the acquired user biometric identification data identification processor in the present invention directly use the device and program provided in the user information device (101).

[0078] Before providing the user authentication and signature device and method of the present invention, it is necessary to first ensure that a processor is provided that can obtain the user's biometric data from the user information device and can perform processing such as user biometric identification data recognition. Therefore, in this specification, the process of obtaining the user's user biometric identification data through the user's use of the biometric identification data input and output device, and storing the obtained user biometric identification data in the user's information device for identification is called a user's biometric identification data recognition processor. The user's biometric identification data recognition processor based on the user's biometric identification data in this specification is based on the premise that the data is pre-stored in the user information device. Therefore, the user biometric identification data recognition processor described in the present invention adopts a third party's publicly known technology, so the relevant content will not be elaborated in detail.

[0079] Figure 3 2 is an exemplary diagram of a user authentication and signature device according to an embodiment of the present invention.

[0080] according to Figure 3The user authentication and signature device includes: a user information device (300), a user image data management processor (301), a key registration / authentication input box display processor (302), a user registration / authentication key generation image upload processor (303), a user registration / authentication key generation data acquisition processor (304), a user registration / authentication key generation processor (305), an authentication processor for the user registration key (306) and a user biometric identification data recognition processor (307).

[0081] The user information device (300) has a touch panel and a computing function. Specifically, the user information device (300) is a device such as a smart phone, a tablet computer, a computer, etc., and is a computing device having a touch panel, a central processing unit, a storage, a network interface, etc.

[0082] The user image data management processor (301) stores and manages specific image data to be displayed on the touch panel of the user information device (300) in the user information device (300).

[0083] The key registration / authentication input box display processor (302) is a key registration box display processor or a key authentication input box display processor, and requires user key registration and authentication to be performed on the touch panel of the user information device (300).

[0084] The user registration / authentication key generation image upload processor (303) is a user registration encryption key generation image upload processor or a user authentication encryption key generation image upload processor, which responds to a user encryption key registration request or a user encryption key authentication request, and uploads the image data selected by the user or the user image data management processor (301) from the image data stored in the image memory of the user information device (300) to the touch panel of the user information device (300) for display.

[0085] The user registration / authentication key generation data acquisition processor (304) is a user registration encryption key generation data acquisition processor or a user authentication encryption key generation data acquisition processor. The user touches a specific pixel point on the image data displayed on the touch panel of the user information device (300) through the user registration / authentication key image upload processor (303) to acquire the user's registration / authentication encryption key data.

[0086] The user registration / authentication key generation processor (305) is a user registration key generation processor or a user authentication key generation processor, which encrypts the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user information device memory or the user registration key generation data or user authentication key generation data obtained by the user registration / authentication key generation data acquisition processor (304), and then generates a user registration key or a user authentication key.

[0087] The user biometric identification data identification processor (307) uses the user biometric input and output device on the user information device (300) to obtain the user's biometric identification data from the user, stores it in the user's information device memory, and identifies the user based on the obtained and stored user biometric identification data.

[0088] For example, the user biometric identification data identification processor (307) is set on the user information device (300) and uses Figure 2 After the user's biometric identification data input and output devices (204 and 205) shown in the figure obtain the user's biometric identification data (203), the obtained biometric identification data is stored in the memory of the user biometric identification data recognition processor (307) built into the user information device (300).

[0089] Figure 4 This is an embodiment of a user image data management processor according to an embodiment of the present invention.

[0090] Specifically, Figure 4 This is an example of image data (401 and 402) stored in the storage device of the user information device (300). In each image data (401 and 402), digital data storing a date, a description, and an image is stored in pixel units, and the image data (401 and 402) is organized into files.

[0091] The storage date 403, description, etc. added to each image data (401 and 402) can be used as an associative memory medium for the user to remember which image data to use when generating a user registration and authentication key when creating a key.

[0092] It can also have the function of allowing the user image data management processor (301) to identify whether it is a user registration key required in a specific application, automatically selecting a matching image with reference to the creation date or description of the image data (401 and 402), and uploading it to the touch panel of the user information device (300).

[0093] For example, by setting the system program, if it is a key registered on a specific date, an image associated with a specific date is selected, or if it is a key associated with a specific person, an image of a specific person is selected. In addition, an interface can be set so that the user can directly select the desired image data from the image file.

[0094] Figure 5 It is a flow chart of a process of registering a user key through a user authentication and signature device according to an embodiment of the present invention.

[0095] Combine the following Figure 5 Various embodiments of the processor of the present invention and the processing contents of each step are described.

[0096] according to Figure 5 After the user key (password) setting and registration request (S501) is displayed on the display panel of the user information device (300), the user image data management processor (301) responds to the key setting and registration request, opens the image data storage file (S502) of the user information device (300), uploads the stored multiple image data to the touch panel of the user information device (300) for display (S503), and the user selects the required image data. Alternatively, the user image data management processor (301) can automatically select the image data of the application program that meets the requirements for registering the user key and display it on the touch panel.

[0097] The user information device (300) may be provided with a processor that supports both functions, or may provide one of the functions. The automatic selection means may be provided by a program that automatically selects an image based on information of an application requiring a password as described above.

[0098] Then, the biometric data acquired and stored by the user biometric data recognition processor (307) is compared with the user's biometric data and when they are consistent (S504), the user registration / authentication key generation data acquisition processor (304) acquires the coordinate value and color value of the specific touch pixel on the specific image designated to be displayed for generating the user registration key (S505), and then the user registration / authentication key generation processor (305) generates the key (S506 and S507).

[0099] Specifically, the user registration / authentication key generation processor (305) is (a) selected from at least one of the coordinate value (801) of the touch pixel, the color value (802) of the touch pixel, or the user's biometric identification data (203) obtained by the user using the biometric identification data input and output device and stored in the user information device memory, and after encrypting them separately, it generates the said key generation processor (305) by combining the encrypted data into one data, combining one or more encrypted data and unencrypted data into one data, or re-encrypting the combined data. A user registration key (S506), or (b) from the coordinate value (801) of the touch pixel, the color value (802) of the touch pixel, or the user's biometric data (203) obtained by the user using a biometric data input and output device and stored in the user information device memory, at least two or more data are combined into one for encryption, and then the encrypted data, at least two or more data are combined into one encrypted data and unencrypted data are combined into one data, or one of the combined data is re-encrypted to generate the user registration key (S507).

[0100] Figure 6 is an example of a key input box on a specific application that requires registration of a user key.

[0101] according to Figure 6 In a specific application service, the service provider requires the user to log in with the user's password and displays a registration key input box (601) on the touch panel of the user information device to request the user to register the user key.

[0102] Figure 7 This is an embodiment of uploading a user's image to the touch panel in response to a user key registration request.

[0103] according to Figure 7 ,answer Figure 6 When the user touches the registration key input box (601), the user image data management processor (301) will Figure 4 The plurality of image data (401 and 402) shown in the figure are uploaded from the image storage file to the display panel of the user information device (300) for display, and when the user selects specific image data (701) from the displayed plurality of images, the selected image data (701) is displayed.

[0104] Figure 8 is a schematic diagram showing an embodiment of acquiring data of a touch pixel from an image;

[0105] Specifically, Figure 8The invention is a process for displaying pixel data of a user acquired from image data (701) when a user touches a designated specific location in image data (701) displayed on a display panel of a user information device (300).

[0106] according to Figure 8 When the user touches a specific position, the user biometric identification data recognition processor (307) is driven at the same time to re-enter the user's biometric identification data (203) stored in the user information device (300) to verify whether it is the same user.

[0107] When the pattern matching result of the user biometric identification data recognition processor (307) is judged to be the same user, the coordinate value (X, Y) (801) and the color value (RGB) (802) of the touch pixel are obtained by the user registration / authentication key data acquisition processor (304). In addition, the user biometric identification data authentication processing and the user's touch pixel data acquisition processing can also be performed simultaneously, and an optimized solution is provided on the user information device that can recognize fingerprints on the front of the display panel.

[0108] For example, installing the device of the present invention on a user information device such as a smartphone that supports a sensor display function for identifying user fingerprints, Samsung Electronics' Galaxy 10, etc., can provide an optimized solution for user authentication and application development that requires signatures.

[0109] The user biometric identification data recognition processor (307) built into the user information device (300) is processed separately according to the functions of the processor provided by the manufacturer of the user information device (300) or a third party.

[0110] Re-reference Figure 8 , Figure 8 The image data (701) shown in the figure is displayed on the touch panel of Samsung Electronics' Galaxy Note 3 (1080X1920). Figure 8 This is an example of a location touched by a user on image data (701), where the coordinate value (801) and the color value (802) of the touch pixel at the point touched by the user are (277, 948) and (253, 255, 254), respectively.

[0111] In addition, as mentioned above, the tool API (Application Program Interface) for obtaining the user's touch pixel data on the image data is public, so it is easy to implement and process, or it can be obtained by calculating the X and Y coordinate values ​​of the touch area. If it is authentication, the tool for obtaining the data value of the touch pixel is also easy to implement.

[0112] The multiple data of the user acquired as described above are stored in the storage device of the user information device (300). The multiple data stored may be encrypted by a one-way hash function or encryption program before storage, or may be compressed by a biometric feature recognition data compression program before storage.

[0113] The following describes an embodiment of a user registration key generation processor (305) that encrypts the coordinate value (801) and color value (802) of a touch pixel or the user's biometric identification data (203) to generate a user registration key or a user authentication key.

[0114] The following describes an embodiment of using a one-way hash function to encrypt the coordinate value (801) of a touch pixel, the color value (802) of a touch pixel, or the user's biometric identification data (203).

[0115] Specifically, the user registration key generation processor (305) is (a) to select at least one of the coordinate values ​​(801) of the touch pixel, the color value (802) of the touch pixel, or the user biometric identification data (203) obtained by the user using the biometric identification data input and output device and stored in the user information device memory, and then encrypt them separately, and then generate the user registration key from one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data, or (b) to select at least two of the coordinate values ​​(801) of the touch pixel, the color value (802) of the touch pixel, or the user biometric identification data (203) obtained by the user using the biometric identification data input and output device and stored in the user information device memory, and then encrypt them, and then generate the user registration key from one of the encrypted data, the data obtained by combining at least two or more data into one, the encrypted data obtained by combining at least two or more data into one, the unencrypted data obtained by combining into one, or the data re-encrypting the combined data.

[0116] First, an embodiment of using a hash value key encrypted using a one-way hash function for the coordinate value (801) of a touch pixel, the color value (802) of a touch pixel, and the user's biometric identification data (203) is described.

[0117] First, the hash value key (SHA256, SHA512) of the touch pixel coordinate value (801) is calculated as follows.

[0118] "SHA256(X,Y)=SHA256(277948)=D1CDDBB8DEE15A796E7E021A692C85D388F0A3399CEBB05F07484C3B2B3CCAE9"......(1)

[0119] "SHA512(X,Y)=SHA512(277948)=2C7DA404B69B2982D1B5806017FAACE19C9F7439296AD359B7 FCD61691EB64BC2B19D1807132D6CE712850AF6138182D2DE58C0EC550F401D563C21F54B1FAA9”

[0120] The hash value key (SHA256, SHA512) of the touch pixel color value (802) is calculated as follows.

[0121] "SHA256(RGB)=SHA256(253255254)=2314FA02267DC6CE8F5662A0DCFB0151D03B43CC93319770A4824AD15C67F348"......(2)

[0122] "SHA512(RGB)=SHA512(253255254)=7AE223525E3F3E5403639FB0E4DEA9487DCB63C75F51FC40E 80BA97B6870791B70956B14470DF659822BBC50416278928FEA98B9DA73388E85B76CE811A5CDB7”

[0123] The hash value key (SHA256, SHA512) of the user biometric identification data (203) is obtained as follows.

[0124] "SHA256(finger print)=4E418BF3D461CA0B4C49A0514ED7942A0E893D759DE369C89CF74BDD1D077B0A"......(3)

[0125] "SHA512(finger print)=A871544968DABC2D39005BB4CFF5FD0808D5C948292505CCFC3E624F7221108900D49BAA8349E7F8DF1A4D1890AC5ADCEB6E45679F281D717046E27CF7BD8AAB”

[0126] The three hash value keys (1), (2), and (3) are combined to obtain the re-hashed key (SHA256, SHA512) as follows.

[0127] "SHA256((1)(2)(3))=A81194F8D9E9E61E35E14C4F9D175AB527D15E66388CBDD7C808553F31D1BD6C"

[0128] "SHA512((1)(2)(3))=3A662BABE41EF25BDC3D69D0240A6C4D624A6C7301289AAEE7C09FB 6F17B5125847F9E76F200BA8F16D84D5D019E6F8BCE664F2FA4FF67850294C7FD423332D0”

[0129] The user registration key generation processor (305) can use a hash value key (SHA256 (1) (2) (3)), a hash value key (SHA512 (1) (2) (3)) or one of the keys (SHA256, SHA512) as the user registration key. The hash value key generated in this way is more secure because it is encrypted twice.

[0130] Second, an embodiment of a hash value key encrypted by a one-way hash function after combining the coordinate value (801) of the touch pixel of the user's touch point and the color value (802) of the touch pixel, and an embodiment of a hash value key encrypted by a one-way hash function after combining the hash value key with the user's biometric identification data (203) again.

[0131] The coordinate value (801) of the touch pixel and the color value (802) of the touch pixel are combined and then encrypted using a one-way hash function to obtain a hash value key (SHA256 (4), SHA512 (5)) as follows.

[0132] "SHA256(XYRGB)=E81FEC84259FDOD63166DC12141AA2E91B23FE573FD0F757907DA9810A44BB5B"......(4)

[0133] "SHA512(XYRGB)=750CD6979C15E5819507F9B03ED491237BE8C4160D6C2B56E960CB81E9A26 B6C14668FB27DB919D92F9C0D5DBCCA3A0EE5FA5CC84C449862DA191B9CACD5DB6F”……… (5)

[0135] The key is combined with the stored user biometric identification data and then re-encrypted using a one-way hash function to obtain a hash value key (SHA256 (6), SHA512 (7)) as follows.

[0136] "SHA256(XYRGB)(BIO)=F12055FD338D0DF679A1C3042272F9F36CD4FCAEAEC012E09AEE69A582C804F0"......(6)

[0137] "SHA512(XYRGB)(BIO)=9C9C8285F966486C3E8890B459885F3DC0147E0B0A24A1F894CF5BE5A041 21E7C6A4AF1ADD67A9B1893C781FE5CFE4416DBD92A72EBD470D162618B3CF8F5C89”......(7)

[0138] The user registration key generation processor (305) can use any one of the hash value key (SHA256 (XYRGB) (BIO)), the hash value key (SHA512 (XYRGB) (BIO)) or the hash value key (SHA256 (6), SHA512 (7)) as the user registration key.

[0139] Third, an embodiment of combining the user's touch pixel coordinate value (801), the touch pixel color value (802) and the user's biometric identification data (203) into one, and then encrypting the combined data with a hash value key (SHA256, SHA512) using a one-way hash function is described.

[0140] After the touch pixel coordinate value (801), the touch pixel color value (802) and the user's biometric identification data (203) are combined into one, the combined data is encrypted with a hash value key (SHA256, SHA512) using a one-way hash function as follows.

[0141] "SHA256(XYRGBBIO)=318905E1D4A463696BACD9AF8CD3132E4DEB4EC41C82E3950DA851DEC4DCC6C4"

[0142] "SHA512(XYRGBBIO)=9EF8627D42245B214ACE62E586DEFFCF2F8C9F3C7673DFCC0B10BF7 7D016549B030C7189AC14FE0AF33026DC0C1144ABD6480AC503CC64053A381BA43E1CA87A”

[0143] The user registration key generation processor (305) can use any one of the hash value key (SHA256 (XYRGBBIO)), the hash value key (SHA512 (XYRGBBIO)), or the hash value key (SHA256, SHA512) as the user registration key.

[0144] The following describes an embodiment of combining the touch pixel coordinate value (801), the touch pixel color value (802) and the user's biometric identification data (203) to obtain a hashed value as a key and using the public key encryption of the elliptic curve equation.

[0145] Elliptic curve encryption is a public key encryption technology. Public key encryption consists of a pair of public key and private key. The private key (private key) is an inherent key owned only by the user, and the public key is a key created (encrypted) using the user's private key or a key used to decrypt messages.

[0146] For example, the public key encryption technology used by Bitcoin for electronic signatures is the Elliptic Curve Digital Signature Algorithm (ECDSA). The public key is generated as shown in mathematical formula 1 in the Elliptic Curve Digital Signature Algorithm.

[0147] [Mathematical formula 1]

[0148] K=k*G

[0149] In mathematical formula 1, K is the public key, k is the private key, and G represents the generator point. The elliptic curve used in Bitcoin is the secp256k1 curve developed by the National Institute of Standards and Technology (NIST). The secp256k1 curve is that the value of the digit n of G is "n = 11579208923731619542357098500868790785837564279074904382605163141518161494337".

[0150] In mathematical formula 1, the (x, y) value of the reference point G is

[0151] "Gx=55066263022277343669578718895168534326250603453777594175500187360389116729240",

[0152] "Gy=32670510020758816978083085130507043184471273380659243275938904335757337482424".

[0153] Therefore, the obtained key is used as the user's private key, and each public key is calculated according to mathematical formula 1, then "K 1 =A0ED188C7B4415FD65DBA776475E71E5CFDEDFEA17399A0Bl1711A3980F6F17E*G”,K 2 =F12055FD338D0DF679A1C3042272F9F36CD4FCAEAEC012E09AEE69A582C804F0*G”, K 3 =318905E1D4A463696BACD9AF8CD3132E4DEB4EC41C82E3950DA851DEC4DCC6C*G" are obtained, and these values ​​become the public keys corresponding to the private keys.

[0154] As shown in the above multiple embodiments, the user's acquisition data and the user's biometric identification data are combined in various ways to generate a key (private key, public key) (i.e., hash value key). As shown in the above multiple embodiments, the coordinate value of the touch pixel, the color value of the touch pixel, and the user's biometric identification data are generated as a key in various combinations. The advantage of the present invention is that it can make it more difficult for a third party to speculate or infer how the generated key is generated, thereby further improving the security of the key.

[0155] The evaluation example (https: / / howsecureismypassword.net / ) of the security of the keys generated by the embodiments is as follows. The time taken by a computer to decrypt all the keys obtained by the embodiments is that the key of SHA256 requires SESVIGINTILLION YEARS, i.e. 1063 years, and the key of SHA512 requires 12,751,349,217,300,716,000,000,000,000QUINQUAGINTILLION YEARS, i.e. 10153 years, so the key security of the present invention can be guaranteed in theory.

[0156] Next, an embodiment of the authentication processor (306) for the user registration key, which is another function in the user authentication and signature device of the present invention, is described.

[0157] Fig. 9 This is a diagram showing an example of a user authentication password input request box displayed on a user display panel for user authentication.

[0158] according to Fig. 9 To authenticate a registered user, the key registration / authentication input box display processor (302) responds to a normal application request and displays the user's account or password input box (901) (i.e., the authentication key input box).

[0159] Fig.10 Flow chart of a process for processing the process required for authenticating a user through a user authentication and signature device according to an embodiment of the present invention.

[0160] Specifically, Fig.10 It is a flowchart showing the processing procedure of the authentication processor (306) for the user registration key of the present invention.

[0161] according to Fig.10 The steps include: displaying an authentication request input box (S1001) for a key on the display panel of the user information device (300); in response to the authentication request for the key of a registered user, the user touches the password input box (901); and then uploading the same image data selected by the user or the user registration / authentication key generation image upload processor (303) for generating the user key and displayed on the touch panel from the storage device to the touch panel for display (S1002 and S1003) by the user image data management processor (301) of the user information device (300).

[0162] At this time, if the user uses Figure 7 The image data (701) shown in the figure is generated and a key is set, then Figure 7The image data (701) shown in the figure is re-designated by the user directly or is re-displayed on the display panel of the user information device (300) based on the processing of the user image data management processor (301) and the user registration / authentication key generation image upload processor (303).

[0163] On the other hand, when the user remembers the same place where he / she touched when registering the user key on the same image data that is redisplayed, and touches the pixel at the same place again, the user needs to remember the place where he / she touched when registering the key. In this case, the number of times the user touches can be limited to prevent the third party from misappropriating the key.

[0164] The user's biometric identification data is then retrieved and compared with the stored user biometric identification data to confirm that it is the same user (S1004). The user remembers and touches the same point on the redisplayed image data that he touched when registering the user key, and the user can retrieve the re-touched pixel coordinate value (X, Y) of the re-touched location on the image and the color value (RGB) of the re-touched pixel value (S1005).

[0165] At this time, there is an implementation step of one of the following (a) steps or (b) steps that can support two predefined different functions. The selection of each step is implemented by the same processor (301, 302, 303, 304, 305, 306 and 307) used when the user registered the key, and the authentication key generation data is obtained through step (a) or step (b).

[0166] Specifically, one of the following steps is implemented: (a) when the user re-acquires the user's biometric identification data by using a biometric identification data input / output device, compares it with the user's biometric identification data that has been acquired and stored to confirm that it is the same user, and then, when the user re-touches the same designated location that he touched when he remembered to register the user key and touches it again in the re-displayed image data, the pixel coordinate value (X, Y) of the re-touched point and the color value (RGB) of the re-touched pixel are acquired; or (b) when the user re-touches the same designated location that he touched when he remembered to register the user key on the re-displayed image data, the user's biometric identification data is re-acquired and compared with the user's biometric identification data stored by a user identification processor using the user biometric identification data, and at the same time, representative coordinate values ​​(X, Y) of the re-touched location and representative pixel color values ​​(RGB) of the re-touched location are acquired in parallel (the step of acquiring the coordinate value of the re-touched pixel and the color value of the re-touched pixel).

[0167] In this case, the treatment of step (b) is more preferable among the treatments of step (a) and step (b).

[0168] A more specific example of generating the user authentication key is the same as the example of the registration key described above.

[0169] Specifically, the user registration / authentication key generation processor (305) (a) selects at least one of the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user's information device memory, and then encrypts them separately, and then generates a user authentication key (S1006) from one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data, or (b) selects at least two of the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user's information device memory, and then encrypts them, and then generates the user authentication key (S1007) from one of the encrypted data, the data obtained by combining the encrypted data and the unencrypted data into one, or the data re-encrypting the combined data.

[0170] The user authentication key generated as described above is automatically input into the authentication password input box (901), followed by a key authentication step (S1008) in which the regenerated user authentication key is compared and judged with the user information device (300) or the user registration key registered in the device requiring user key authentication. Fig.10 The various steps of the key authentication process illustrated in the figure are uniformly executed in the authentication processor (306) of the user registration key.

[0171] The key registration and authentication are performed by the user touching the user's image data once or twice, which is simpler than the existing password input such as text combination.

[0172] Fig.11 This is an example of multiple images displayed by the user authentication and signature device according to one embodiment of the present invention for registering / authenticating a user key using multiple images.

[0173] Specifically, Fig.11 The invention is an embodiment of the user authentication and signature device of the present invention, in which a plurality of image data are uploaded and displayed on the touch panel of the user information device (300).

[0174] according to Fig.11, displaying multiple images on a touch panel of a user information device (300), allowing a user to touch a designated specific pixel on each image to register and authenticate a key. When registering a key based on multiple specific touch pixels selected by a user using multiple image data, a key with stronger security than a key based on a specific touch pixel of a user in one image can be registered. A key registration and authentication means and method in the device using multiple image data and a method thereof Figures 1 to 10 The method described in , but it just needs to be processed by the same processor twice.

[0175] Specifically, a specific touch pixel is selected from the first image of the user and the coordinate value and color value of the specific touch pixel are obtained by touching 1101. Based on the obtained data and the user's biometric identification data (203) and using the processor processing method of the present invention, various keys (first keys) can be generated and registered. Then, a specific location is touched on another second image to obtain the coordinate value and color value of the touch pixel 1102, combined with the user's biometric identification data (203), and a key (second key) is generated using the user registration key generation processor of the present invention. Then, the first key and the second key are combined, and the encryption method of the present invention is reused to generate and register a more secure third key. Correspondingly, the authentication key can also be registered and authenticated using the same method and processor as described above.

[0176] The user authentication and signature device according to the present invention can also be used as a multi-signature device. That is, it can be applied to services that require multiple co-signatures. The composition of the co-signature device can be implemented in the same way as the present invention on the user information device (300) equipped with the user authentication and signature device of the present invention. In addition, the above-mentioned technical composition can also be directly applied to the generation registration technology such as OTP (One Time Password).

[0177] The following is an evaluation of the user registration, authentication, and signature means and methods of the user authentication and signature device of the present invention compared with the standard technology of FIDO.

[0178] User authentication and signature according to the FIDO standard is to provide a user authentication and signature device as described in the present invention, which is basically equipped with a user biometric identification data identification processor (307) based on user biometric identification data.

[0179] Fig.12 is a diagram showing the process flow required for user registration according to the FIDO standard. Fig.13 This is a diagram showing the process flow required for user authentication based on the FIDO standard.

[0180] according to Fig.12 The FIDO processing process corresponding to the key registration of the present invention is called "registration".

[0181] Specifically, registration is the process of registering the user's attestation (the signature value that proves the user's authentication information generated in a specific FIDO authentication device) and public key on the server. Fig.12 Provide explanation.

[0182] ① After the user requests the server (FIDO server) to register the user information (key / password), ② the server requests authentication information from the user device (FIDO client) and transmits relevant policies, ③ the user enters the biometric identification data through the user identification device, and the authenticator (Authenticator) in the user device uses the input biometric identification data to generate a pair of private key / public key, and transmits the generated public key and attestation (Attestation) to the server, ④ the server stores and manages the user's attestation and public key received from the user device, thereby completing the user registration.

[0183] During the FIDO registration process, the user inputs biometric data through the authentication device. The authenticator uses the input biometric data to generate a pair of private / public keys. The user is identified based on the user's biometric data. After the user is successfully identified, the private / public key is generated, and the private key is used to generate the user's certificate (a digital signature value that proves the user's authentication information generated on a specific FIDO authentication device). The role of the user's biometric data is to unlock the signature generator that generates the private / public key.

[0184] The function is as described in the present invention, and is consistent with the function of unlocking and driving the processor that obtains the touch data of the user's touch location after the user is successfully identified by the user's biometric identification data. That is, FIDO uses the successful identification result of the user's biometric identification data to drive the digital signature key generator to generate a private key / public key. In the present invention, the user identification result based on the biometric identification data has the function of driving the registration data acquisition processor (304) such as key generation and registration required user key.

[0185] The user authentication and signature device of the present invention is consistent with FIDO in that the user identification processor is used according to the biometric identification data, but the processing after the user is identified is different. Specifically, the user authentication and signature device of the present invention generates a key using the touch pixel coordinate value, color value or biometric identification data of the user's specific image, while the difference of FIDO is that the standard method of generating a digital signature, namely a private key and a public key, is used to generate the user's certificate.

[0186] according to Fig.13 The FIDO processing corresponding to the user authentication means and process of the present invention is called authentication or transaction confirmation, which is specifically described as follows.

[0187] Regarding authentication (login) or transaction confirmation, the process of receiving the digital signature of user authentication (login) or transaction content is as follows: ① the user device requests the server (FIDO server) for authentication / transaction confirmation, ② the server generates the authentication challenge (Challenge) required for verification and transmits it to the user device (FIDO client), ③ the user extracts the private key stored in the terminal through the registered biometric identification data identification information, and uses the private key to digitally sign the authentication challenge (or transaction metadata) received from the server. After the user device transmits the signed authentication challenge (or transaction metadata) to the server, ④ the server uses the user's public key to verify whether the user's certificate (the electronic signature value generated on a specific FIDO authentication device to prove the user's authentication information) received from the service device is false or altered.

[0188] As mentioned above, the present invention is fundamentally different from the authentication and signature system of FIDO. That is, the present invention does not have a separate signature method, but FIDO uses a standard signature method.

[0189] The standard digital signature method adopted by FIDO refers to that after a pair of public keys (verification keys) and private keys (signature keys) are specified on the user device, the message is encrypted with the private key, which is equivalent to the creation of the signature, and the ciphertext is decrypted with the public key, which is equivalent to the verification of the signature. The specific process is as follows Fig.14 shown.

[0190] Fig.14 This is a flowchart showing the functional relationship of processing in the standard digital signature method.

[0191] according to Fig.14 The sender uses the signature key (private key) (1402) and the digital signature algorithm (1403) to complete the digital signature (1404) of the message (1401) that requires signature, and then sends it together with the public key (1405) to the recipient. The recipient uses the algorithm for verifying the encrypted message (1406), that is, the public key, to decrypt it and then verify (1407) whether the message is forged or altered.

[0192] There are many algorithms for implementing the digital signature creation and verification method, typical ones are RSA, DSA, ECDSA (Ellipitic Curve Digital Signature Algorithm), EdDSA (Edward DSA), etc.

[0193] The efficiency of the standard signature method varies depending on the security of the user's key, that is, the possibility of forgery and alteration. In other words, the user may pretend that his or her key (private key, public key) is lost or stolen, and the user's key may actually be stolen. Therefore, in the digital signature method, the certification and issuance system for the public key (Public key infrastructure) will naturally cost money. The methods for creating signatures in standard digital signatures include the method of signing directly on the message and the method of signing on the hash value of the message. The method of signing directly on the message takes some time for encryption, so the method mainly adopts the method of using a one-way hash function to calculate the hash value and then encrypting the hash value with the private key.

[0194] In addition, the processing equivalent to the digital signature in the present invention is implemented on the user registration key generation processor (305) that generates the user registration key. That is, it is implemented by encrypting the user biometric data stored in the user's information device memory obtained by the user using the biometric data input and output device and the user registration key data obtained by the user key registration data acquisition processor.

[0195] In addition, corresponding to the certificate encrypted by the personal secret key in FIDO, the key generated by the user key generation processor of the present invention. The certificate of FIDO is to encrypt the user information with a private key after hashing it, and the key of the present invention is the hashed value of the data composed of the touch data on the specific image of the user and the user's biometric identification data. The user information constituting the certificate in FIDO is the data of an unspecified user, while the data constituting the key of the present invention directly contains the authentication element information with guaranteed confidentiality and security.

[0196] The three elements of authentication refer to the user's knowledge information, the user's possession information, and the user's biometric identification data information. The user's knowledge information refers to the user's specific image, the coordinates of the user's specific touch pixels on the image, and the color value of the touch pixels in the present invention. The user's possession information refers to the type of device and the image owned by the user. The user's biometric identification data is the stored user's biometric identification data. The information is inherent to each user and is different from each other. It can be used as information for authenticating users and signatures. Therefore, it can be said to be a more superior method than the public key / private key pair method, that is, the standard digital signature method.

[0197] Because the key of the present invention, which is composed of three-factor authentication information, cannot be regenerated or copied as long as the three authentication information are not leaked. In principle, the key of the present invention can realize the detection of forgery and alteration of the digital signature function, i.e. the key (text), and the detection of non-repudiation of the user without setting up a digital signature key generation device separately. In principle, any user who does not have the information of the three authentication elements cannot generate and register the key of the present invention. Therefore, the key generated according to the present invention contains the authentication information representing the owner of the user key (text), thereby ensuring the authenticity of the digital signature function, i.e. the user.

[0198] In summary, compared with the existing user authentication method using passwords composed of text, symbols, and digital strings, the method of the present invention does not require the burden of remembering a secure password, and has high reproducibility, and can use the same key on multiple different application services. Moreover, unlike the signature method of the FIDO standard, it does not have a private key for the digital signature method, and does not generate a public key digital signature processor, and can also provide a more simple, easy and cost-effective user authentication and signature device.

[0199] The existing encryption methods and the method of the present invention are evaluated below.

[0200] What standards are followed when making keys is a known issue. That is, the general principle for creating more secure keys or passwords is to ① use information that only you know, ② use multiple keys / passwords separately, and use key generation / management tools. ① Using information that only you know means that even if a third party steals the key, it cannot be inferred what it was created on, that is, the source of the key is relatively random and difficult for a third party to predict.

[0201] The main features of the key of the present invention are: first, based on the personal image of the user, a third party cannot make an analogy about what image it is based on, so the randomness is more prominent than other methods. Second, even if the image can be analogized, the specific location on the image selected by the user cannot be analogized. The third is the user's biometric identification data. Even if the user's biometric identification data can be analogized, it is not easy to fabricate the user's biometric identification data. The three data with greater difficulty in analogy as described above are combined to generate a key, so its security is better than any key generation method. Even if a third party wants to steal the user's key, it needs to unlock the three randomnesses, so the security of its key is more secure than other methods.

[0202] The use of multiple keys / passwords in the prior art means that if you want to divide them into multiple keys for use according to the purpose, the user's memory burden is too large. The key method of the prior art mainly uses longer combinations of text, numbers, symbols, etc., but depending on the situation, even if multiple keys are set up, there are many problems with the key memory or storage method. However, the present invention is not only safe, but also can use a flexible method to generate multiple keys for use according to the purpose. Because as mentioned above, according to the key method of the present invention, only the image and the specific touch pixels on the image are remembered, so multiple keys can be remembered anytime and anywhere, or there is no need to bear the burden of confidentiality, and it is obvious that they can be used as multiple keys in various application services.

[0203] As mentioned above, the longer the length of the source (or seed) for creating the key, the higher the security of the key, and vice versa, the more difficult it is to remember the key, keep and manage the key, etc. As mentioned above, there is a trade-off relationship between each other. Usually in applications such as cryptocurrency, in order to ensure the high security of the key, a random number generator or hardware method is used to generate the source of the key. The key source generated by the random number generator or hardware as described above is almost not reproducible, so in order to verify the key, the key source or key needs to be secretly stored in a secret place, and stored and managed so that it can be reproduced when verifying the key.

[0204] Due to the above reasons, various technologies for key storage management in cryptocurrency services have been developed. For example, software wallets (paper wallets) or hardware wallets dedicated to key storage are technologies for securely storing and managing keys or even private keys. However, the key storage management methods using software and hardware wallets will become useless if they are stolen or lost, because the method of reproducing the set keys will disappear.

[0205] Compared with the existing methods, the key storage and management method of the present invention is very safe and simple. The reason is that, first, the image as the key source is stored and managed in the user's information device. Even if it is stolen among many images, it is useless to the third party. Second, even if the image is specific, the user's specific touch point information is encrypted and stored in the secret storage device of the user's information device, and cannot be deceived and reproduced. Third, even if the two pieces of information, namely the data of the specific image and the specific touch pixel, are obtained, the key generation and verification of the present invention must be verified by the user's biometric identification data. Therefore, a third party cannot generate the same key at all. Fourth, the key of the present invention is not afraid of being lost or stolen. Because the key can be changed, replaced, and refreshed anytime and anywhere.

[0206] The length of the key is closely related to the length of the key source. Usually, the data used as the key source is called the private key. The important concept in the private key is the so-called key space. The key space means "the total number of available keys", which refers to the total number of keys that can be created using the private key. The size of the key space is expressed in the number of bits of the key. For example, if the length of the private key is 28 bits, 256 private keys can be created. Generally, the maximum known secure length of a private key is "2 512 =1.340780X10 154 The problem of calculating the private key in the maximum key space number would take hundreds of years to calculate using current supercomputers.

[0207] In addition, the length of the encrypted private key (source) corresponding to the private key of the present invention is as follows.

[0208] According to the present invention, the data used as the key source (corresponding to the private key) is generated by combining the coordinate value (X, Y) and color value (RGB) of the specific touch pixel on the image selected by the user. Therefore, a representative pixel coordinate value (X, Y) is different according to the definition (size) of the display panel. The pixel coordinate value (X, Y) is integer data. The storage size of the integer data in the computer is different according to the OS, but "2 16 -2 64 ", the color data of the pixel is "2 16 -2 32 " bits, so the password length generated by a user's touch of a specific touch pixel is a maximum of 2 98 , minimum 2 32 .

[0209] The user's biometric identification data is added together with the combined data. The user's biometric identification data is different in type, but Figure 2 The biometric data shown in the figure is 2 64 Therefore, when combined with the coordinate value and color value data, the minimum value is 2 112 Bit, up to 2 168 According to the present invention, the number of key spaces can be expanded by increasing the number of images or the number of specific touch points of the user, thereby flexibly creating more secure keys, and even if tools such as random number generators are not installed, secure keys can be generated and managed.

[0210] Currently, most smart phones are basically provided with user biometric identification data authentication devices. The user biometric identification authentication device in the user device is only used for user identification services in a relatively closed environment within the user information device. However, the user biometric identification data of the present invention can be combined with another authentication factor and hashed even if it is leaked outside, so it cannot be separated. Even if it is separated, if the three authentication data are incomplete, or there is no user identification result in the online state, the same key cannot be generated at all, so the user authenticity of the key is guaranteed, and there is no risk of leakage of user personal information. It can be effective under the operation of the user authentication and signature device services of various applications that are both open, stable and cost-effective.

[0211] According to the present invention, a user authentication and signature device and method that is simpler, safer, and more confidential can be provided compared to user authentication and signature devices and methods based on international standards, namely FIDO1.0 and FIDO2.0 standards and protocols.

[0212] In addition, according to the present invention, a user authentication and signature system based on three authentication information inherent to the user can be provided. Specifically, through the user authentication and signature system based on the user's knowledge information, possession information and biometric identification information, unlike the FIDO standard and protocol, there is no signature system, and even if the user's inherent personal information, that is, the user's biometric identification information, is provided to a third-party service device, there is no risk of theft, and even if it is lost, the data is useless to the third party, so a user authentication and signature device of a new ecosystem in which the user's biometric identification information can be used with confidence is provided.

[0213] According to the present invention, the key does not need to be stored in other devices. Only the key generation process needs to be remembered. The same method can be used to safely provide a simple and convenient user authentication and signing method at any time on various devices and services with one password.

[0214] According to the present invention, a user key with a small memory burden and strong anonymity can be easily generated by using the user's characteristic photo / image, and the user's biometric identification data can be used to provide a user authentication and signature integration device with outstanding confidentiality, security and reproducibility in the Internet of Things, cryptocurrency circulation or application services for various purposes.

[0215] According to the present invention, the generation of keys (private keys / public keys) does not require the provision of other tools such as random number generators, and thus a cost-effective user authentication and signature device can be provided.

[0216] According to the present invention, the user authenticator of the existing FIDO standard method, i.e., the user's biometric identification data, is attached with the user's image / photo as a multimodal authenticator, which can further improve the user's convenience. By attaching a multimodal authenticator to the current FIDO standard digital signature method, i.e., the public key signature method, there is no need to change the FIDO standard, and a more powerful user signature method can be provided.

[0217] As described above, the present invention is described based on specific matters such as specific constituent elements and limited embodiments and drawings, but the above embodiments are only used to illustrate the technical solutions of the present invention so as to further fully understand the present invention. The present invention is not limited to the above embodiments. Although the present invention is described in detail with reference to the aforementioned embodiments, ordinary technicians in this field should understand that they can still modify or change the technical solutions described in the aforementioned embodiments, or make equivalent substitutions, and these modifications or changes, equivalent substitutions do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions described in the embodiments of the present invention.

Claims

1. A user authentication and signature device , It is characterized in that Includes: user information equipment with touch panel and computing functions; A user information device having a user biometric identification data identification processor which acquires the user's biometric identification data from the user by using the user biometric identification input and output device on the user information device, stores the acquired and stored biometric identification data in the user's information device memory, and identifies the user based on the acquired and stored biometric identification data; A user image data management processor storing and managing specific image data required for display on the touch panel of the user information device on the user information device; a key registration frame display processor requesting user key registration on a touch panel of the user information device; In response to a key registration request from a user, uploading image data selected by a user or the user image data management processor from image data stored in an image memory of the user information device to a user registration key generation image upload processor displayed on a touch panel of the user information device; a user registration key generation data acquisition processor for acquiring user registration key generation data by causing a user to touch and designate a pixel at a specific position in the image data displayed on the touch panel of the user information device by the user registration key generation image upload processor; A user registration key generation processor that encrypts the user characteristic biometric data stored in the memory of the user information device obtained by the user using the biometric data input and output device or the user registration key generation data obtained by the user registration key generation data extraction processor to generate a user registration key; The user registration key generation data acquisition processor acquires the user registration key generation data by touching a pixel at a specific position in the image data displayed on the touch panel of the user information device through the user registration key generation image upload processor, and then acquires the user registration key generation data, including: (a) after the user utilizes the biometric data input / output device to reacquire the user's biometric identification data, and then compares it with the acquired and stored user biometric identification data to confirm whether it is the same user, a user registration key generation data acquisition processor is acquired and processed to obtain and process the coordinate values ​​and color values ​​of the touched pixels; or (b) after the user utilizes the biometric data input / output device to reacquire the user's biometric identification data, perform user identification processing on the data and compare it with the acquired and stored user biometric identification data to confirm whether it is the same user, and simultaneously acquire the coordinate value of the touch pixel and the color value of the touch pixel for user registration key generation data acquisition processor at least one processor.

2. The user authentication and signature device according to claim 1, It is characterized in that The user registration key generation processor encrypts the user biometric identification data acquired by the user using the biometric identification data input and output device and stored in the memory of the user information device or the user registration key generation data acquired by the user registration key generation data acquisition processor to generate the user registration key, and includes: (a) a user registration key generation processor for generating the user registration key from at least one of the coordinate value of the touch pixel, the color value of the touch pixel, or the user biometric identification data acquired by the user using the biometric identification data input / output device and stored in the memory of the user information device, and encrypting them respectively, and then generating the user registration key from one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data; (b) A processor in the user registration key generation processor that generates the user registration key by combining at least two data into one and then encrypting the encrypted data, combining the at least two data into one encrypted data and unencrypted data into one data, or re-encrypting the combined data from the coordinate value of the touch pixel, the color value of the touch pixel, or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the user information device memory.

3. The user authentication and signature device according to claim 1 or 2, It is characterized in that The user registration key is generated by encrypting the acquired touch pixel coordinate value, the acquired touch pixel color value or the user's biometric identification data, and encrypting and keying the encrypted data using a one-way hash function or an elliptic curve equation.

4. A user authentication and signature device , It is characterized in that Includes: user information equipment with touch panel and computing functions; A user information device having a user biometric identification data identification processor which acquires user biometric identification data from a user by using a user biometric input and output device on the user information device, stores the acquired and stored user biometric identification data in a memory of the user information device, and identifies the user based on the acquired and stored user biometric identification data; A user image data management processor storing and managing specific image data required for displaying on the touch panel of the user information device in the user information device; a processor for displaying an authentication key input box requiring user key authentication on a touch panel of the user information device; In response to a key authentication request from a user, the image data for a user registration key selected by the user or the user image data management processor from the image data stored in the image memory of the user information device is re-uploaded to a user authentication key generation image upload processor displayed on a touch panel of the user information device; A user authentication key generation data acquisition processor for acquiring user authentication key generation data when the user touches the pixel at the same position designated when remembering the registered user key from the re-displayed image data again; a user authentication key generation processor that encrypts the user authentication key generation data acquired by the user authentication key generation data acquisition processor to thereby generate a user authentication key; A user registration key authentication processor that compares and determines the key regenerated by the user authentication key generation processor with the key stored in the user information device or the device requesting user key authentication; When the user touches the pixel at the same position designated when the registered user key is recalled from the image data re-displayed by the user authentication key generation image upload processor, the user authentication key generation data acquisition processor that acquires the user authentication key generation data includes: (a) a processor reacquires the user's biometric identification data by using a biometric identification data input / output device, compares it with the acquired and stored user biometric identification data to confirm that the same user is present, and then, when the user remembers to remember and touches the same pixel at the same position designated when the user registered the user key in the re-displayed image data, obtains the coordinate value and color value of the re-touched pixel; or (b) When the user remembers to touch the pixel at the same designated position touched when registering the user key and touches it again from the redisplayed image data, the user's biometric identification data is obtained again, compared with the user's biometric identification data stored by the user biometric identification data identification processor, and one of the processors obtains the coordinate value of the re-touched pixel and the color value of the re-touched pixel at the same time.

5. The user authentication and signature device according to claim 4, It is characterized in that The user authentication key generation processor encrypts the re-acquired user touch data and the stored user biometric identification data to generate the user authentication key, including: (a) a user authentication key generation processor that selects at least one of the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the user biometric identification data obtained by the user using the biometric identification data input / output device and stored in the user information device memory, and then encrypts each of them separately, and then generates one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data as the user authentication key; (b) A processor for generating a user authentication key by combining at least two data into one and then encrypting the encrypted data, combining the encrypted data and the unencrypted data into one, or re-encrypting the combined data, from the coordinate value of the re-touch pixel, the color value of the re-touch pixel, or the user biometric data obtained by the user using the biometric data input / output device and stored in the memory of the user information device.

6. The user authentication and signature device according to claim 4 or 5, It is characterized in that The coordinate value of the representative pixel of the same touch point, the color value of the representative pixel or the stored user biometric identification data is re-encrypted to generate a key for user authentication, and is encrypted and keyed using a one-way hash function or an elliptic curve equation.

7. A user authentication and signature method , It is characterized in that The method comprises the steps of obtaining the user's biometric identification data by using the biometric identification data input and output device of the user information device, and storing the data in a memory device in a user biometric identification data processor of the user information device; The step of receiving a key (password) registration request from a user; In response to the key registration request, the step of uploading image data selected by a user or an image data processor from among image data stored in an image memory of the user information device to be displayed on a touch panel of the user information device; When a pixel at a specific position in the image data displayed on the touch panel of the user information device is touched by a user, the coordinate value and color value of the touched pixel are obtained as key generation data for user registration; The step of encrypting the coordinate value of the touch pixel and the color value of the touch pixel or the user biometric feature recognition data stored in the memory of the user's information device to generate a key for user registration; When a pixel at a specific position in the image data displayed on the touch panel of the user information device is touched and designated by the user, the step of obtaining the coordinate value of the touched pixel and the color value of the touched pixel as the key generation data for user registration includes at least one of the following steps: (a) after the user reacquires the biometric identification data of the user by using the biometric identification data input and output device, compares it with the acquired and stored user biometric identification data to confirm that the same user is the same user, and then obtains the coordinate value of the touch pixel and the color value of the touch pixel; (b) reacquiring the user's biometric identification data and comparing it with the user's biometric identification data stored by the user biometric identification data verification processor, and simultaneously acquiring the coordinate value and pixel color value of the touch pixel.

8. The user authentication and signature method according to claim 7, It is characterized in that The step of encrypting the coordinate value of the touch pixel and the color value of the touch pixel or the stored user biometric identification data and generating a user registration key includes any one of the following steps: (a) selecting at least one of the coordinate value of the touch pixel, the color value of the touch pixel, or the user biometric identification data obtained by the user using the biometric identification data input and output device and stored in the memory of the user information device, and then encrypting them separately, and then generating the user registration key from one of the data obtained by combining the encrypted data into one, combining one or more encrypted data and unencrypted data into one, or re-encrypting the combined data; (b) A step of generating a key for the user registration by combining at least two data into one and then encrypting the encrypted data, combining the at least two data into one encrypted data and unencrypted data into one data, or re-encrypting the combined data from the coordinate value of the touch pixel, the color value of the touch pixel, or the user biometric data obtained by the user using a biometric data input / output device and stored in the memory of the user's information device.

9. The user authentication and signature method according to claim 7 or 8, It is characterized in that The step of encrypting the acquired touch pixel coordinate value, the acquired touch pixel color value or the user's biometric identification data to generate the user registration key is to encrypt and key the acquired touch pixel coordinate value or the user's biometric identification data using a one-way hash function or an elliptic curve equation.

10. A user authentication and signature method, It is characterized in that include: The step of receiving a registered user key authentication request; In response to the user key authentication request, the step of uploading image data selected by the user or the image data processor as a user registration key from the image data stored in the image memory of the user information device to be displayed on the touch panel of the user information device; When the user touches the pixel at the same position designated when the user remembers the registered user key from the re-displayed image data, the step of acquiring the user authentication key generation data; The step of encrypting the user authentication key generation data to generate a user authentication key; A step of comparing and determining the key regenerated by the user authentication key generation processor with the key registered in the user information device or the device requesting user key authentication; In the re-displayed image data, when the user remembers to touch the pixel at the same position designated when generating the user key and touches it again, the step of obtaining the user authentication key generation data includes any one of the following steps: (a) the user reacquires the user's biometric identification data by using a biometric identification data input and output device, compares it with the acquired and stored user biometric identification data to confirm that the same user is the same user, and when the user remembers and touches the pixel at the same position designated when generating the user key in the re-displayed image data, obtains the coordinate value and color value of the re-touched pixel; or (b) When the user remembers to touch the pixel at the same designated position touched when registering the user key from the redisplayed image data and touches it again, the user's biometric identification data is reacquired and compared with the user biometric identification data stored by the user biometric identification data identification processor, and the coordinate value of the re-touched pixel and the color value of the re-touched pixel are simultaneously acquired.

11. The user authentication and signature method according to claim 10, It is characterized in that The step of re-encrypting the coordinate value of the re-touched pixel and the color value of the re-touched pixel or the stored user biometric identification data information to generate the user authentication key comprises one of the following steps: (a) selecting at least one of the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the biometric data of the user acquired by the user using a biometric data input / output device and stored in a memory of a user information device, and then encrypting each of the encrypted data, combining the encrypted data into one data, combining one or more encrypted data and unencrypted data into one data, or re-encrypting the combined data to generate the user authentication key; (b) A step of generating a key for user authentication by combining at least two data into one data which is then encrypted, combining the encrypted data and unencrypted data into one data, or re-encrypting the combined data from the coordinate value of the re-touched pixel, the color value of the re-touched pixel, or the user's biometric data obtained by the user using a biometric data input / output device and stored in a memory of the user's information device.

12. The user authentication and signature method according to claim 10 or 11, It is characterized in that The step of re-encrypting the coordinate value of the representative pixel of the same touch point, the representative pixel color value or the stored user feature identification data to generate a key for user authentication is to encrypt and key it using a one-way hash function or an elliptic curve equation.

Citation Information

Patent Citations

  • System And Method For Executing File By Using Biometric Information

    CN104933335A

  • A multiple certification method and system

    CN108777672A