DID System Using Browser-Based Secure PIN Authentication and Control Method Thereof
By storing credentials locally in the browser and combining cloud servers and blockchain repositories, the problems of cumbersome authentication compatibility and steps between browsers are solved, and efficient and secure distributed identifier verification is achieved.
Patent Information
- Application Number
- CN202180075918.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-10
- Filing Date
- 2021-09-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-09-06
AI Technical Summary
In the prior art, the centralized identity verification system has problems with personal information leakage and abuse, and there are problems with cumbersome authentication compatibility and steps between different browsers and when separate programs are not installed.
By storing credentials in the browser's local memory and using browser PIN authentication, combining cloud servers and blockchain repositories, the authentication process of distributed identifiers is simplified.
Implementing high-compatibility authentication between different browsers simplifies authentication steps, avoids the hassle of installing additional programs, and improves the convenience and security of authentication.
Smart Images

Figure CN116438531B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a decentralized identifiers (DID) system using browser-based secure personal identification number (PIN) authentication and a control method thereof, and more particularly, to a DID system and a control method thereof capable of performing verification on a browser using a credential received from a server. Background Art
[0002] With the development of Internet services, most people use a large number of online services such as government agencies, educational institutions, medical institutions, communication companies, financial companies, travel companies, asset management, credit information, portals, social network services (SNS), games, shopping, ticketing, express delivery, and electronic voting through the Internet.
[0003] Therefore, users who want to use such services need to join as members by inputting personal information including their real names, or authenticate registered users by inputting a specific account and password. However, since repeating such authentication steps on multiple websites is quite cumbersome, recently, a method called simple authentication that can more easily assist in logging in and facilitate financial transactions on the Internet is being developed.
[0004] In the past, user authentication was performed through a centralized ID (Identify) system. Representatively, a recognized authentication certificate and an Active X program for using it were set up, or a separate application (App) for performing authentication was set up, and authentication was performed through such a program or application.
[0005] However, in the case of a centralized authentication system, there are problems of personal information leakage and abuse.
[0006] In addition, when using the program or application to perform user authentication, there is a hassle of installing a separate program, and there are compatibility problems with existing applications or programs, so there is a problem that user authentication cannot be smoothly performed. Summary of the Invention
[0007] Technical Problem
[0008] The technical problem to be solved by the present invention is to provide a DID system and a control method thereof capable of authenticating a user based on a browser.
[0009] Another technical problem to be solved by the present invention is to provide a DID system capable of authenticating users even between different browsers and a control method thereof.
[0010] Yet another technical problem to be solved by the present invention is to provide a DID system capable of managing credentials for user authentication in an optimized manner using a cloud server and a control method thereof.
[0011] The technical problems to be solved by the present invention are not limited to the above-mentioned technical problems, and those skilled in the art can clearly understand other technical problems not mentioned through the following description.
[0012] Technical Solution
[0013] The DID system according to the present invention for solving the above technical problems is characterized in that it includes: a server that issues credentials capable of verifying a distributed identifier (DID); and a terminal that receives the credentials from the server and transmits the credentials to a verification device that requests verification of the distributed identifier, wherein the terminal performs the following operations: storing the credentials issued from the server in the local memory of the browser installed in the terminal; when an authentication is requested by the verification device during the provision of a specific service, running the browser and performing browser PIN authentication to access the credentials stored in the local memory of the running browser; when the browser PIN authentication is successful, transmitting the credentials to the verification device; receiving usage information requested by the verification device from the verification device and requesting the server to issue credentials corresponding to the usage information; receiving the credentials corresponding to the usage information from the server in a manner including the distributed identifier of the terminal and transmitting the credentials corresponding to the usage information to the verification device to perform verification of the identity and usage information of the terminal; registering the distributed identifier in a preset repository based on a blockchain, and deleting the credentials stored in the local memory of the browser according to a deletion request of the credentials, wherein the server extracts the distributed identifier registered in the repository according to an authentication request from the verification device.
[0014] At this time, it is characterized in that the running browser is a browser that stores credentials in the local memory or a browser that stores credentials corresponding to the usage information requested from the verification device in the local memory.
[0015] Further, it is characterized in that the server performs the following operations: when a credential for a distributed identifier registered in the repository is requested by the terminal, generate a credential including the distributed identifier and transmit the credential including the distributed identifier to the terminal.
[0016] Further, it is characterized in that the terminal encrypts the credential received from the server and stores it in the local memory of the browser.
[0017] Further, it is characterized in that the server issues a credential in a manner reflecting the use of the distributed identifier and transmits it to the terminal, and the verification device uses the credential received from the terminal to verify compliance with the use.
[0018] Further, a control method of a DID system including a server and a terminal according to the present invention is characterized by including the following steps: the server issues a credential capable of verifying a distributed identifier; and the terminal receives the credential from the server and transmits the credential to a verification device that requests verification of the distributed identifier, wherein the terminal performs the following operations: store the credential issued by the server in the local memory of the browser installed in the terminal, when requesting authentication from the verification device during the provision of a specific service, run the browser, and perform browser PIN authentication to access the credential stored in the local memory of the running browser, when the browser PIN authentication is successful, transmit the credential to the verification device, receive use information requested by the verification device from the verification device, and request the server to issue a credential corresponding to the use information, receive a credential corresponding to the use information from the server in a manner including the distributed identifier of the terminal, and transmit the credential corresponding to the use information to the verification device to perform verification of the identity and use information of the terminal, register the distributed identifier in a preset repository based on a blockchain, and delete the credential stored in the local memory of the browser according to a deletion request of the credential, wherein the server extracts the distributed identifier registered in the repository according to an authentication request from the verification device.
[0019] Other specific matters of the present invention are included in the detailed description and the drawings.
[0020] Advantageous Effects
[0021] Even without installing or using a separate program or application to verify the identity of a user, the present invention can perform DID authentication on a browser, thereby being able to solve compatibility problems between programs or applications.
[0022] Moreover, in the present invention, even during the process of using a browser that does not store credentials, credentials can be easily obtained through the cloud server, thus simplifying the steps of authentication.
[0023] In addition, in the present invention, a new control method can be provided as follows: in the case where an authentication request exists during the process of using a browser that does not store credentials, use the browser that stores credentials to perform authentication, or call the credentials from the browser that stores credentials to perform authentication, so that authentication can be performed even without an additional cloud server.
[0024] The effects of the present invention are not limited to the above-mentioned effects, and those skilled in the art can clearly understand other effects not mentioned through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 is a conceptual diagram for explaining the concept of the decentralized identifiers (DID) system of the present invention.
[0026] Figure 2 is a conceptual diagram for explaining the control method of the DID system according to an embodiment of the present invention.
[0027] Figure 3 、 Figure 4 and Figure 5 is a conceptual diagram for explaining the method of registering, authenticating, and deleting the DID-based user identity in the DID system of the present invention.
[0028] Figure 6 is a conceptual diagram for explaining the control method of the DID system according to another embodiment of the present invention.
[0029] Figure 7 、 Figure 8 and Figure 9 is a flowchart for explaining various embodiments based on whether a credential is stored in the local memory of the browser in the DID system of the present invention.
[0030] Figure 10 is a conceptual diagram for explaining the operation of the DID system according to an embodiment of the present invention.
[0031] Figure 11 and Figure 12 is a conceptual diagram for explaining the server and terminal included in the DID system of the present invention. DETAILED DESCRIPTION
[0032] Refer to the appendix Figure 1When the embodiments described in detail below are described, the advantages and features of the present invention and the methods for achieving these can be clarified. However, the present invention can be implemented in various different forms and is not limited to the embodiments disclosed below. Providing these embodiments only makes the disclosure of the present invention complete and serves to fully inform those of ordinary skill in the technical field to which the present invention pertains of the scope of the present invention. The present invention is only defined by the scope of the claims.
[0033] The terms used in this specification are terms for describing the embodiments and are not terms for limiting the present invention. In this specification, unless specifically mentioned in the sentence, the singular form also includes the plural form. The terms "comprises" and / or "comprising" used in the specification do not exclude the presence or addition of one or more other components in addition to the components mentioned. Throughout the specification, the same reference numerals refer to the same components, and "and / or" includes each and more than one holding combination of the components mentioned. Although "first", "second", etc. are used to describe various components, these components are obviously not limited to these terms. These terms are only used to distinguish one component from another. Therefore, the first component mentioned below can obviously also be the second component within the technical idea of the present invention.
[0034] Unless otherwise defined, the technical terms (including technical and scientific terms) used in this specification can be used with the meanings commonly understood by those of ordinary skill in the technical field to which the present invention pertains. Also, terms defined in a generally used dictionary cannot be ideally or excessively interpreted unless specifically and clearly defined.
[0035] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0036] Figure 1 It is a conceptual diagram for explaining the concept of the Decentralized IDentifiers (DID) system of the present invention.
[0037] According to an embodiment of the present invention, a DID (Decentralized IDentifiers) can represent a decentralized identifier.
[0038] The decentralized identifier described in this specification refers to a globally unique identifier that is registered in a distributed repository using distributed ledger technology or other distributed network technologies other than this, and thus does not require a registration authority such as a centralized server.
[0039] Identity is a set of multiple attributes that distinguish an entity in a certain domain. An identifier (id: identifier) refers to an identifier composed of a series of numbers, characters, symbols, etc. that uniquely represent the identity.
[0040] In the existing centralized identity management system, the service provider manages the digital identities of users centrally. It issues user IDs and credentials (such as passwords) for verifying them, and saves and manages user information such as usernames and addresses.
[0041] In this system, the user identity is entrusted to the central authority for management, and it is difficult for users to control their own identities, personal data, and related attribute information managed by the central authority.
[0042] On the contrary, in the DID system of the present invention, users can use distributed network technologies such as blockchain to manage their own identity information. Such a system is called a distributed identity management system, and the identifier used in it is called a decentralized identifier (DID).
[0043] The DID system according to an embodiment of the present invention may include a server 100 that acts as an issuer, a terminal 200 that acts as a holder, a verification device 300 that acts as a verifier, and a verifiable distributed data repository 400.
[0044] The server 100 can issue credentials that can implement the verification of a decentralized identifier (DID).
[0045] That is, the server 100, as an issuer, can issue credentials that can implement the verification of a specific user (i.e., the identity holder).
[0046] Here, a credential refers to a set of data presented as evidence of identity or qualification.
[0047] For example, a credential may include a password for proving that the holder is the identifier, a public key for proving the possession of a private key, a public key certificate issued by a trusted third party that can prove the connection between the public key and the holder, information of a third-party certification authority, etc.
[0048] The terminal 200 described in this specification may include a mobile terminal, a mobile phone, a smart phone, a laptop computer, a digital broadcast terminal, a personal digital assistant (PDA), a portable multimedia player (PMP), a navigator, a slate PC, a tablet PC, an ultrabook, a wearable device (e.g., a smart watch, a smart glass, a head-mounted display (HMD)), etc.
[0049] However, those skilled in the art will easily understand that, except for the case where it is only applicable to mobile terminals, the terminal 200 according to the embodiments described in this specification can be applied to fixed terminals such as digital TVs, desktop computers, digital signage, etc.
[0050] The terminal 200 may receive a credential from the server 100 and transmit (or issue) the credential (or a presentation as a set of credential information) to the verification device 300 that requests verification of the distributed identifier.
[0051] That is, as a holder, the terminal 200 receives a credential combined with a DID from an issuer (server 100) that can guarantee its own identity through a predetermined process, and provides it to a verifier (verification device 300) and utilizes services, etc. when necessary.
[0052] The verification device 300, as a verifier, may request a credential from the holder (terminal 200) and verify it when identity verification is required.
[0053] The repository 400 mainly uses a distributed ledger (e.g., a blockchain) as a mechanism for storing DIDs, but other types of distributed repositories may also be used.
[0054] For a blockchain, its composition is generally well-known, so specific descriptions are omitted in this specification.
[0055] A DID is an identifier for a specific entity, and the description of the entity is represented by a DID document (DOD: DID Document). The DID document includes information associated with the identity subject and methods for verifying the information (e.g., a set of public keys of the DID, a set of authentication protocols, a set of service endpoints (endpoints) that can communicate or interact with the corresponding individual, etc.).
[0056] As an example, in this specification, a DID document can be transmitted and received in association with a distributed identifier or a credential.
[0057] In addition, the DID system according to the present invention can register and verify the usage information of a distributed identifier.
[0058] For example, the terminal 200 and the server 100 issue and receive a credential in a manner that reflects the usage of the distributed identifier, and the verification device 300 can use the credential to verify whether it conforms to the usage.
[0059] Hereinafter, a specific control method of such a DID system will be described in more detail with reference to the accompanying drawings.
[0060] Figure 2 It is a conceptual diagram for explaining the control method of a DID system according to an embodiment of the present invention.
[0061] First, in the present invention, the following steps are performed: The server 100 issues a credential (S210) that can implement the verification of a distributed identifier.
[0062] The server 100 can issue a credential according to a credential issuance request received from the terminal 200.
[0063] At this time, the server 100 can issue a credential in a manner that includes the distributed identifier (DID) of the terminal 200.
[0064] The distributed identifier (DID) can be transmitted together when the terminal 200 transmits a credential issuance request to the server 100. If the terminal 200 has registered the distributed identifier (DID) in the repository 400 (for example, a blockchain), the server 100 can also extract (obtain) the distributed identifier from the repository 400 in response to the request.
[0065] As an example, the terminal 200 can generate a distributed identifier and register the distributed identifier in a blockchain-based repository.
[0066] When a request for a credential for the distributed identifier registered in the repository 400 is received from the terminal 200, the server 100 can generate a credential including the distributed identifier and transmit the credential including the distributed identifier to the terminal 200.
[0067] Thereafter, in the present invention, the following steps are performed: The terminal 200 receives a credential from the server 100 and transmits the credential (S220) to the verification device 300 that requests verification of the distributed identifier.
[0068] Here, a request for verification of the distributed identifier may mean a request for authentication of a terminal (or a user using the terminal).
[0069] Moreover, performing verification of the distributed identifier includes the meaning of performing authentication of the terminal 200 or the terminal user, and may represent transmitting a credential to the verification device 300.
[0070] The terminal 200 may receive a request for authentication from the verification device 300 providing a service during the use of any service or for the purpose of using any service. In this case, the terminal 200 may request a credential from the server 100 and transmit the received credential to the verification device 300 to perform authentication.
[0071] More specifically, the terminal 200 may receive the usage information requested by the verification device 300 from the verification device 300 and request the server 100 to issue a credential corresponding to (matching) the usage information.
[0072] Thereafter, the server 100 may issue a credential corresponding to the usage information in a manner including the distributed identifier (DID) of the terminal 200 (or in the name of the distributed identifier (DID)) and transmit it to the terminal 200.
[0073] The terminal 200 may transmit the credential to the verification device 300 to perform verification of the identity and usage information of the terminal.
[0074] At this time, the terminal 200 of the present invention may include at least one browser. Here, the browser refers to software that displays web page information on the Internet on the screen and may be basically installed in the terminal 200.
[0075] As an example, the browser may include various browsers such as IE (Internet Explorer), Chrome, Safari, Microsoft Edge, etc.
[0076] There is a local memory in each browser. The local memory refers to a space for storing data generated when using each browser.
[0077] A part of the memory of the terminal 200 may be allocated to the local memory of the browser.
[0078] In the present invention, the following steps are performed: The terminal 200 stores the credential issued by the server 100 in the local memory of the browser included in the terminal 200 (S230).
[0079] The terminal 200 can receive the credentials issued by the server 100 and store the received credentials in the local memory of the browser.
[0080] At this time, the terminal 200 can request credentials from the server 100 through a browser. If it receives the credentials from the server 100, it can store the credentials in the local memory of the browser that requested the credentials.
[0081] At this time, the terminal 200 can encrypt the credentials received from the server 100. That is, the terminal 200 can encrypt the credentials received from the server 100 and store them in the local memory of the browser.
[0082] In addition, in order to store credentials in the local memory of the browser that can implement the verification of distributed identifiers, the DID system of the present invention can enhance security.
[0083] To this end, the terminal 200 of the DID system of the present invention can perform browser personal identification number (PIN: Personal Identification Number) authentication through the browser in order to access the credentials.
[0084] The terminal 200 can be configured to access the credentials stored in the local memory of the browser according to the success of the browser PIN authentication.
[0085] In the case of accessing the encrypted credentials stored in the local memory of the browser through browser PIN authentication, the terminal 200 can decrypt the encrypted credentials and transmit the decrypted credentials to the verification device 300.
[0086] The terminal 200 can receive a request for authentication from the verification device 300 during the use of any service. Here, the any service can include all types of services that can be received through the terminal 200 and can include at least one of the Internet, games, shopping, payment, access to a specific web page, and content download.
[0087] And, the service can be executed through a browser, program, or application.
[0088] As an example, the verification device 300 can be a server or service providing device related to the company that provides the any service.
[0089] The terminal 200 can run the browser according to the request for authentication from the verification device 300 during the use of any service.
[0090] Here, the running browser may be a browser that stores credentials in a local memory or a browser that stores credentials corresponding to the usage information requested by the authentication device in a local memory.
[0091] Terminal 200 may perform browser PIN authentication by accessing credentials stored in a local memory of the browser.
[0092] Thereafter, the terminal 200 transmits the credential to the verification device 300 requesting identity verification according to the success of the PIN verification, thereby enabling identity verification to be performed.
[0093] As described above, when receiving the purpose information of using the distributed identifier from the verification device 300 , the terminal 200 may transmit the purpose information of using the distributed identifier to the server 100 .
[0094] The server 100 may issue a credential capable of performing verification on the usage information (ie, a credential corresponding to (or conforming to) the usage information or a credential reflecting the usage information) to the terminal 200 .
[0095] Obviously, the credential may include a distributed identifier.
[0096] The terminal 200 may transmit the received credential to the verification device 300 to perform verification for the distributed identifier and usage information.
[0097] In this way, the present invention stores the credentials in the local storage of the browser which is the basic software of the terminal, rather than performing identity authentication through a separate application or program, so that the browser with higher compatibility can be authenticated in any case, thereby significantly improving the convenience and speed of identity authentication.
[0098] Figure 3 , Figure 4 and Figure 5 This is a conceptual diagram used to illustrate the method of registering, authenticating and deleting a DID-based user identity in the DID system of the present invention.
[0099] Figure 3 This is a conceptual diagram used to illustrate the user identity registration process based on DID.
[0100] First, the terminal 200 may receive a DID registration request based on a user's request.
[0101] As an example, the DID registration request may represent a request to store (register) the credentials received from the server in the local storage of the browser.
[0102] To store (register) a credential that can implement the verification of a distributed identifier in the local storage of a browser, the terminal 200 can register a PIN code.
[0103] To register a PIN code, the terminal 200 can perform user authentication.
[0104] Upon completion of PIN code registration, the terminal 200 can store the credential received from the server 100 in at least one of the local storage of the browser and the cloud server 500.
[0105] The registered PIN code is used for browser PIN authentication performed to access the credential stored in the local storage of the browser. The registered PIN code can be encrypted and registered (stored) in the browser.
[0106] At this time, the terminal 200 can encrypt the credential and store (register) it in the local storage of the browser.
[0107] In addition, the terminal 200 can register at least one of the distributed identifier and the credential in the blockchain (repository) 400 or store it in the cloud server 500.
[0108] At this time, at least one of the distributed identifier and the credential transmitted to the repository 400 or the cloud server 500 can be encrypted.
[0109] Figure 4 It is a conceptual diagram for explaining the steps of DID-based user authentication.
[0110] Referring to Figure 4 , the terminal 200 can receive a DID verification request (i.e., a request for authentication) from the verification device 300 during the use of any service.
[0111] In this case, to access the credential stored in the local storage of the browser, the terminal 200 can perform browser PIN authentication.
[0112] Based on the success of the browser PIN authentication, the terminal 200 can access the local storage of the browser and can transmit the credential (DID verification request) to the verification device 300 that requested authentication.
[0113] Thereafter, the verification device 300 can use the credential received from the terminal 200 to perform verification of the distributed identifier stored in the blockchain-based repository 400.
[0114] Figure 5 It is a conceptual diagram for explaining the steps of DID-based user identity deletion.
[0115] As Figure 5As shown, after the terminal 200 accesses the credentials (user identity) stored in the local memory of the browser, the terminal 200 can delete the credentials stored in the local memory of the browser according to the user's credential deletion request.
[0116] Moreover, when the credentials are stored in the cloud server, the terminal 200 can request deletion of the credentials from the cloud server.
[0117] In addition, the present invention can provide a DID system and its control method that can perform optimized DID verification in the presence of multiple browsers.
[0118] Hereinafter, a method for performing verification of a distributed identifier using multiple browsers will be described in more detail with reference to the accompanying drawings.
[0119] Figure 6 It is a conceptual diagram for explaining a control method of a DID system according to another embodiment of the present invention.
[0120] First, as Figure 6 shown, in the present invention, the following steps are performed: The server 100 issues a credential that can implement verification of the distributed identifier DID (S610), the terminal 200 receives the credential from the server, and transmits the credential to the verification device 300 that requests verification of the distributed identifier (S620).
[0121] At this time, the terminal 200 may be equipped with multiple browsers.
[0122] In the present invention, the following steps are performed: The terminal 200 stores the credential in the local memory of the first browser among the multiple browsers (S630).
[0123] Thereafter, in the present invention, the following steps are performed: The terminal 200 uploads the credential to the cloud server 500 through the first browser so that the terminal 200 can use the credential to perform authentication in a second browser different from the first browser (S640).
[0124] When the terminal 200 is in a state of being equipped with (set with) multiple browsers and receives a credential that can implement verification of the distributed identifier from the server 100, it can be stored in the local memory of the first browser among the multiple browsers.
[0125] The first browser may be any one of the multiple browsers, the browser set as the default browser, or at least one of the browsers that request credentials from the server.
[0126] In the present invention, the following steps are performed: According to the request for authentication during the use of the second browser, the terminal 200 receives the credential from the cloud server 500 through the second browser (S650).
[0127] The terminal 200 can receive an authentication request from the authentication device 300 that provides a service during the process of using any service through a second browser (instead of the first browser that stores the credential).
[0128] In this case, in the present invention, the credential stored in the local memory of the first browser can be transmitted (registered) to the cloud server 500 so that the terminal 200 can perform authentication through the second browser.
[0129] Thereafter, the terminal 200 can download (receive) the credential from the cloud server 500 and store the downloaded credential in the local memory of the second browser (S660).
[0130] Thereafter, the terminal 200 can use the credential stored in the local memory of the second browser to perform the requested authentication (S670). That is, the terminal 200 can perform PIN authentication on the second browser in order to access the credential stored in the local memory of the second browser, and transmit the credential stored in the local memory of the second browser to the authentication device 300 that requests authentication.
[0131] The terminal 200 can encrypt the credential during the process of transmitting the credential to the cloud server 500, during the process of registering (storing) the credential in the local memory of the first browser, and during the process of registering (storing) the credential in the local memory of the second browser.
[0132] That is, the terminal 200 can encrypt the credential stored in the local memory of the first browser and transmit it to the cloud server 500.
[0133] Moreover, for the PIN authentication of the first browser and the second browser, the terminal 200 can register the PIN code through personal authentication, and the related content can be analogously applied in the same / similar manner as the content described in Figure 3 can be analogously applied in the same / similar manner as the content described in
[0134] In order to perform authentication, the terminal 200 can decrypt the encrypted credential stored in the memory.
[0135] That is, the terminal 200 can decrypt the encrypted credential received from the cloud server 500 through the second browser and perform authentication (that is, transmit the decrypted credential to the authentication device 300 that requests authentication). After the authentication is completed, the credential can be encrypted and stored (registered) in the local memory of the second browser.
[0136] In addition, the terminal 200 may be in a state where the credentials received from the server 100 are stored only in the local memory of the first browser among multiple browsers. At this time, when authentication is requested during the process of using a second browser different from the first browser, the terminal 200 may run the first browser to perform authentication using the credentials stored in the local memory of the first browser.
[0137] Thereafter, the terminal 200 may perform authentication using the credentials stored in the local memory of the first browser. That is, the terminal 200 may run the first browser, perform the secure PIN authentication of the first browser to access the credentials stored in the local memory of the first browser, and transmit the credentials stored in the local memory of the first browser to the authentication device to perform authentication.
[0138] Thereafter, when the authentication is completed, the terminal 200 may stop the first browser and return to the second browser.
[0139] That is, during the authentication performed through the first browser, the second browser may run in the background of the terminal 200. Thereafter, when the authentication is completed through the first browser, the terminal 200 may stop running the first browser and run the second browser running in the background in the foreground.
[0140] In addition, the DID system of the present invention may also directly copy (or move) the credentials stored in the local memory of the first browser to the local memory of the second browser without passing through the cloud server 500.
[0141] In this case, in a state where the terminal 200 is not running the first browser but only running the second browser, the credentials stored in the local memory of the first browser are copied and stored in the local memory of the second browser, and the credentials stored in the local memory of the second browser may be accessed through the secure PIN authentication of the second browser to perform authentication.
[0142] In addition, in the present invention, there may be a situation where the user loses the terminal 200 or has multiple terminals. In this case, the DID system of the present invention may further include a new terminal different from the terminal 200.
[0143] The new terminal may include at least one of the first browser and the second browser.
[0144] The new terminal may download the uploaded credentials to the cloud server 500 to perform authentication through at least one of the first browser and the second browser.
[0145] Thereafter, the new terminal can decrypt the encrypted credential received from the cloud server 500 and transmit the credential to the authentication device 300 that requests authentication.
[0146] Figure 7 , Figure 8 and Figure 9 are flowcharts for illustrating various embodiments based on whether a credential is stored in the local memory of the browser.
[0147] Referring to Figure 7 , in the present invention, the terminal 200 can determine whether a credential is stored in the local memory of the browser (S710). Here, the browser can be the browser being used when the authentication request is received.
[0148] Thereafter, in the case where no credential exists in the local memory of the browser, the terminal 200 can register the credential in the local memory of the browser (S720). The process of registering the credential can be analogously inferred and applied in the same / similar manner as Figure 3 the content described in
[0149] In addition, in the case where a credential exists in the local memory of the browser, the terminal 200 can access the credential through browser security PIN authentication (S730), and can use the credential to perform authentication (S740).
[0150] In addition, referring to Figure 8 , in the present invention, in order to register a credential in the cloud server 500, the terminal 200 performs self-authentication (810), registers browser PIN authentication (PIN code) (S820), and can encrypt the credential and store it in the local memory of the browser (S830).
[0151] Thereafter, after the terminal 200 inquires whether it is stored in the cloud server 500, it encrypts the credential and stores it in the cloud to be stored (S840), and can complete credential registration in the cloud server 500 (S850).
[0152] Thereafter, referring to Figure 9 , in the present invention, the terminal 200 determines whether a credential is stored in the local memory of the browser (S710). In the case where no credential is stored, it can receive the credential from the cloud server 500 (S920).
[0153] Thereafter, the terminal 200 can register (store) the credential received from the cloud server 500 in the local memory of the browser (S922).
[0154] Thereafter, in order to perform authentication, the terminal 200 can access the credential through browser security PIN authentication (S730), and can use the credential to perform authentication (S740).
[0155] Figure 10 It is a conceptual diagram for explaining the operation of a DID system according to an embodiment of the present invention.
[0156] Referring to Figure 10 , in the terminal 200 included in the DID system of the present invention, a browser authentication service program for providing a DID browser authentication service and a browser storage program may be installed.
[0157] The browser authentication service program is a program that provides and controls the entire process of performing authentication on a browser. As an example, it can execute functions such as displaying a DID certificate (credential) directory and managing a PIN code for accessing the local memory of the browser.
[0158] Furthermore, the browser repository program can execute the function of controlling the credentials stored in the local memory of the browser.
[0159] Moreover, in the DID system of the present invention, the DID cloud service program for providing a DID cloud service may be installed. As an example, it can be installed on a cloud server or a terminal.
[0160] The DID cloud service program can act as an administrator for transmitting and receiving data (such as credentials) between the terminal 200 and the cloud server 500.
[0161] The cloud server 500 can store credentials and distributed identifiers (or DID documents), etc.
[0162] Figure 11 and Figure 12 It is a conceptual diagram for explaining the server and the terminal included in the DID system of the present invention.
[0163] Figure 11 It is a block diagram schematically showing the internal configuration of a server 100 according to an embodiment. Figure 12 It is a block diagram schematically showing the internal configuration of a terminal 200 according to an embodiment.
[0164] Figure 11 and Figure 12 Only the configurations required to illustrate an embodiment of the present invention are shown in Figure 11 and Figure 12 , but it may also include various configurations such as a display device. And it is obvious to those of ordinary skill in the art to which the present invention pertains that even if it is omitted in the descriptions of Figures 1 to 10 , it may further include the configurations required to execute the method described in
[0165] Referring to Figure 11, according to an embodiment, the server 100 may include a processor 130, a memory 140, and a communication unit 150. The operation of the server 100 that performs simple authentication may be executed by the processor 130 executing a program stored in the memory 140.
[0166] The communication unit 150 may perform wireless or wired communication between the terminal 200 and another server or another external device. For example, the communication unit 150 may perform encrypted communication with the terminal 200 in an SSL manner and may transmit a public key and encrypted data.
[0167] Refer to Figure 12 , according to an embodiment, the terminal 200 may include a processor 230, a memory 240, a communication unit 250, and an input unit 260. The operation of the terminal 200 that performs simple authentication may be executed by the processor 230 running a program stored in the memory 240.
[0168] In addition, the above-mentioned server 100 and terminal 200 may include more than one processor 130, 230 and / or more than one memory 140, 240. And, the memories 140, 240 may include volatile and / or non-volatile memories. More than one memory 140, 240 may store instructions that, when executed by more than one processor 130, 230, cause more than one processor 130, 230 to perform operations. In the present invention, programs or instructions, as software stored in the memories 140, 240, may include an operating system for controlling the resources of the server 100, applications, and / or middleware that provides various functions to applications so that the applications can utilize the resources of the device, etc.
[0169] More than one processor 130, 230 may control at least one component of the server 100 and the terminal 200 connected to the processor 130, 230 by driving software (e.g., programs, commands). And, the processors 130, 230 may perform various operations related to the present disclosure, such as processing, data generation, and processing operations. And, the processors 130, 230 may load data, etc. from the memories 140, 240 or store data, etc. in the memories 140, 240.
[0170] In an embodiment, at least one of the components of the server 100 and the terminal 200 may be omitted, or other components may be added. And, additionally or alternatively, some components may be integrated and implemented, or may be implemented by a single or multiple individuals.
[0171] The above communication units 150 and 250 can perform wireless communication according to methods such as enhanced Mobile Broadband (eMBB), Ultra Reliable Low-Latency Communications (URLLC), Massive Machine Type Communications (MMTC), long-term evolution (LTE), LTE Advance (LTE-A), Universal Mobile Telecommunications System (UMTS), Global System for Mobile communications (GSM), code division multiple access (CDMA), wideband CDMA (WCDMA), Wireless Broadband (WiBro), wireless fidelity (WiFi), Bluetooth, near field communication (NFC), Global Positioning System (GPS), or global navigation satellite system (GNSS).
[0172] The above input unit 260 can include means such as a keyboard, mouse, touchpad, camera module, etc., for inputting simple authentication information (PIN code) of the user into the terminal 2000.
[0173] Even without installing or using a separate program or application to verify the user's identity, the present invention can perform DID authentication on a browser, thereby being able to solve the compatibility problems between programs or applications.
[0174] Moreover, in the present invention, even during the process of using a browser that does not store credentials, the credentials can be easily obtained through a cloud server, thereby simplifying the steps of authentication.
[0175] Also, in the present invention, a new control method can be provided as follows: in the case where an authentication request exists during the process of using a browser that does not store a credential, use a browser that stores a credential to perform authentication, or call a credential from a browser that stores a credential to perform authentication, so that authentication can be performed even without an additional cloud server.
[0176] The method according to an embodiment of the present invention described above can be implemented by a program (or application) for combination with and execution by a server as hardware and stored in a medium.
[0177] The steps of the method or algorithm described in connection with the embodiments of the present invention can be directly implemented by hardware, or implemented by a software module executed by hardware, or implemented by a combination thereof. The software module can reside in a RAM (Random Access Memory), ROM (Read Only Memory), erasable programmable read-only memory (EPROM: Erasable Programmable ROM), electrically erasable programmable read-only memory (EEPROM: Electrically Erasable Programmable ROM), flash memory, hard disk, removable disk, CD-ROM, or any form of computer-readable recording medium known in the technical field to which the present invention pertains.
[0178] The embodiments of the present invention have been described above with reference to the accompanying drawings, but those skilled in the art can understand that the present invention can be implemented in other specific forms without changing the technical idea or essential features of the present invention. Therefore, the embodiments described above should be understood as being exemplary in all respects and not restrictive.
Claims
1. A DID system using browser-based secure PIN authentication, characterized in that, including: a server that issues a credential capable of verifying a distributed identifier; and a terminal that receives the credential from the server and transmits the credential to a verification device that requests verification of the distributed identifier, wherein the terminal performs the following operations: stores the credential issued by the server in the local memory of a browser installed on the terminal, when requesting authentication from the verification device during the provision of a specific service, runs the browser and performs browser PIN authentication to access the credential stored in the local memory of the running browser, when the browser PIN authentication is successful, transmits the credential to the verification device, receives usage information requested by the verification device from the verification device, requests the server to issue a credential corresponding to the usage information, receives from the server a credential corresponding to the usage information in a manner including the distributed identifier of the terminal, and transmits the credential corresponding to the usage information to the verification device to perform verification of the identity and usage information of the terminal, registers the distributed identifier in a preset repository based on a blockchain, and deletes the credential stored in the local memory of the browser according to a deletion request of the credential, wherein the server extracts the distributed identifier registered in the repository according to an authentication request from the verification device.
2. The DID system using browser-based secure PIN authentication according to claim 1, wherein the running browser is a browser that stores a credential in the local memory or a browser that stores a credential corresponding to usage information requested from the verification device in the local memory.
3. The DID system using browser-based secure PIN authentication according to claim 1, wherein the server performs the following operations: when the terminal requests a credential for a distributed identifier registered in the repository, generates a credential including the distributed identifier and transmits the credential including the distributed identifier to the terminal.
4. The DID system using browser-based secure PIN authentication according to claim 1, wherein the terminal encrypts the credential received from the server and stores it in the local memory of the browser.
5. The DID system using browser-based secure PIN authentication according to claim 1, wherein the server issues a credential in a manner reflecting the usage of the distributed identifier and transmits it to the terminal, and the verification device uses the credential received from the terminal to verify compliance with the usage.
6. A control method of a DID system using browser-based secure PIN authentication, the control method being a control method of a DID system including a server and a terminal, the control method including the following steps: issuing, by the server, a credential capable of verifying a distributed identifier; and The terminal receives the credential from the server and transmits the credential to an authentication device that requests verification of the distributed identifier. Among them, The terminal performs the following operations: Stores the credential issued by the server in the local memory of the browser installed on the terminal. When requesting authentication from the authentication device during the provision of a specific service, runs the browser and performs browser PIN authentication to access the credential stored in the local memory of the running browser. If the browser PIN authentication is successful, transmits the credential to the authentication device, receives the usage information requested by the authentication device from the authentication device, requests the server to issue a credential corresponding to the usage information, receives from the server a credential corresponding to the usage information in a manner including the distributed identifier of the terminal, and transmits the credential corresponding to the usage information to the authentication device to perform verification of the identity and usage information of the terminal, registers the distributed identifier in a pre-set repository based on a blockchain, and deletes the credential stored in the local memory of the browser according to a deletion request for the credential. Wherein, the server extracts the distributed identifier registered in the repository according to an authentication request from the authentication device.
7. The control method of a DID system using browser-based secure PIN authentication according to claim 6, wherein The running browser is a browser that stores a credential in the local memory or a browser that stores a credential corresponding to the usage information requested from the authentication device in the local memory.
8. The control method of a DID system using browser-based secure PIN authentication according to claim 6, wherein The server performs the following operations: When a terminal requests a credential for a distributed identifier registered in the repository, generates a credential including the distributed identifier and transmits the credential including the distributed identifier to the terminal.
9. The control method of a DID system using browser-based secure PIN authentication according to claim 6, wherein The terminal encrypts the credential received from the server and stores it in the local memory of the browser.
10. The control method of a DID system using browser-based secure PIN authentication according to claim 6, wherein The server issues a credential in a manner reflecting the usage of the distributed identifier and transmits it to the terminal. The authentication device uses the credential received from the terminal to verify compliance with the usage.
Citation Information
Patent Citations
Automatic login method, system, apparatus and device of application program, and medium
CN108322461A
Resource account binding method and device based on block chain, equipment and medium
CN111881483A