Identity authentication method, identity authentication device and identity authentication system

By monitoring the access and authentication status of identity authentication devices and collecting or omitting biometric data, the balance between security and convenience in identity authentication technology is resolved, enabling a fast and secure identity authentication process and improving the user experience.

CN121808754APending Publication Date: 2026-04-07GHOST PASS CO
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-09
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing identity authentication technologies struggle to balance high security with user convenience, resulting in lengthy authentication processes and poor user experiences.

Method used

The authentication method and device send authentication signals and monitor the server to detect access and authentication status. Based on the status, biometric data can be collected or omitted to achieve high security and convenience.

Benefits of technology

Shorten identity authentication time, improve user satisfaction, and provide a highly secure and convenient identity authentication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121808754A_ABST
    Figure CN121808754A_ABST
Patent Text Reader

Abstract

The invention relates to an identity authentication method, an identity authentication device and an identity authentication system. An identity authentication method according to one embodiment of the present disclosure may comprise: a step of transmitting an authentication signal and monitoring a server; a step of detecting an update of an access state and an update of an authentication state of the identity authentication device on the basis of monitoring of the server; and acquiring authentication means biodata based on an access state to the identity authentication device corresponding to ON and an authentication state corresponding to OFF, and omitting acquisition of authentication means biodata based on the access state to the identity authentication device corresponding to ON and the authentication state corresponding to ON.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to an identity authentication method, an identity authentication device, and an identity authentication system. BACKGROUND

[0002] With the development of smart device technology including smart phones and network technology, it has become an experience that people can easily access to collect biological information through smart devices or self-service terminals (KIOSK) and other commonly used devices, and use the biological information for identity authentication to realize commodity payment or obtain access permissions.

[0003] On the other hand, identity authentication is a procedure that fundamentally prevents identity theft, and therefore in the identity authentication technology, security can be said to be the most important factor.

[0004] Therefore, it is necessary to continuously develop an identity authentication technology that can maintain high security and provide users with on-procedure convenience. SUMMARY

[0005] Problems to be solved by the invention The purpose of the present disclosure is to provide an identity authentication method, an identity authentication device, and an identity authentication system. The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems and advantages of the present disclosure not mentioned can be understood from the following description, and can be more clearly understood by embodiments of the present disclosure. In addition, the problems and advantages to be solved by the present disclosure can be achieved by the solutions described in the claims and combinations thereof.

[0006] Means for solving the problem The first aspect of the present disclosure can provide an identity authentication method performed by an identity authentication request device, the method comprising: a step of transmitting an authentication signal and monitoring a server; a step of detecting an update of an access state and an update of an authentication state of an identity authentication device based on the monitoring of the server; and a step of collecting authentication means biological data based on the access state of the identity authentication device corresponding to on and the authentication state corresponding to off, and omitting the collection of the authentication means biological data based on the access state of the identity authentication device corresponding to on and the authentication state corresponding to on.

[0007] A second aspect of the disclosure can provide an identity authentication request device including a memory storing at least one program and a processor operating by executing the at least one program. The processor can be configured to transmit an authentication signal and monitor a server, detect an update of an access state and an update of an authentication state of an identity authentication device based on the monitoring of the server, collect authentication means biometric data based on the access state of the identity authentication device corresponding to on and the authentication state corresponding to off, and omit the collection of the authentication means biometric data based on the access state of the identity authentication device corresponding to on and the authentication state corresponding to on.

[0008] A third aspect of the disclosure can provide a computer-readable storage medium having stored thereon a program for executing the method according to the first aspect on a computer.

[0009] Inventive Effects According to various embodiments of the disclosure, an identity authentication system that maintains high security while improving user convenience can be provided.

[0010] In particular, the time required for identity authentication can be significantly shortened, and a person experiencing the identity authentication system of the disclosure can be provided with a higher level of satisfaction. BRIEF DESCRIPTION OF DRAWINGS

[0011] Figure 1 FIG. 1 is a block diagram for explaining an identity authentication system according to an embodiment of the disclosure.

[0012] Figure 2 FIG. 2 is a conceptual diagram illustrating one example in which a user performs identity authentication in the identity authentication system according to an embodiment of the disclosure.

[0013] Figure 3 FIG. 3 is a flowchart for explaining an identity authentication procedure according to an embodiment of the disclosure.

[0014] Figure 4 FIG. 4 is a flowchart for explaining an identity authentication procedure according to another embodiment of the disclosure.

[0015] Figure 5 FIG. 5 is a flowchart for explaining an identity authentication procedure according to still another embodiment of the disclosure.

[0016] Figure 6 FIG. 6 is a flowchart of an identity authentication method according to an embodiment of the disclosure.

[0017] Figure 7 FIG. 7 is a block diagram of a device according to an embodiment of the disclosure. DETAILED DESCRIPTION

[0018] The advantages and features of the present application and methods of accomplishing the same will become apparent from the following detailed description with reference to the attached drawings. It is to be understood, however, that the present application is not limited to the embodiments described below, but can be implemented in various forms. The embodiments are presented to make the disclosure complete and to provide a full and enabling disclosure of the present application to those skilled in the art. In describing the present application, specific terminology is used for the sake of clarity. However, the use of particular terms is not intended to limit the present application to the particular forms described and it is to be understood that the present application includes all variations, equivalents and alternatives that fall within the spirit and scope of the present application. In describing the present application, if it is determined that a detailed description of related known technology may obscure the gist of the present application, the detailed description will be omitted.

[0019] The terms used in the present application are merely used to describe particular embodiments and are not intended to limit the present application. Singular expressions include plural expressions unless the context clearly dictates otherwise. In the present application, the terms "include" or "have" or the like are understood to designate the presence of features, numbers, steps, operations, elements, components or a combination thereof described in the specification, and do not preclude the presence or possibility of additional one or more other features, numbers, steps, operations, elements, components or a combination thereof.

[0020] Some embodiments of the present disclosure can be represented by functional blocks and various processing steps. Some or all of these functional blocks can be implemented in any number of hardware and / or software configurations to perform the specified functions. For example, the functional blocks of the present disclosure can be implemented by one or more microprocessors, or by circuitry configured to perform predetermined functions. In addition, for example, the functional blocks of the present disclosure can be implemented in various programming or scripting languages. The functional blocks can be implemented by algorithms running on one or more processors. Furthermore, the present disclosure can employ conventional techniques for electronic environment settings, signal processing, and / or data processing, etc. Terms such as "mechanism," "element," "means," and "configuration" can be used broadly and are not limited to mechanical and physical configurations.

[0021] In addition, the connection lines or connection members between the constituent elements shown in the drawings are merely illustrative of functional connection and / or physical or circuit connection. In actual devices, the connection between the plurality of constituent elements can be represented by various alternative or additional functional connections, physical connections, or circuit connections.

[0022] In the present disclosure, the "identity authentication system" can refer to a system configured to comply with security of a certain procedure, which allows only authorized users to access. In the present disclosure, a user can use or access the identity authentication system through an identity authentication device. In order for the user to be able to use or access the identity authentication system of the present disclosure, an identity authentication solution such as an identity authentication application program can be provided to the user, and the provided identity authentication solution can be installed on the identity authentication device.

[0023] In the present disclosure, "biological data" can refer to data of a user's body, or data of a product generated by a user's own body, and can refer to data used to identify a user. In the present disclosure, biological data can be any kind of biological data. For example, biological data can be any one of a user's fingerprint, pupil, iris, retina, face, voice, vein, DNA, signature, handwriting, blink pattern, skeletal structure, ear shape, palm texture, body temperature pattern, gait pattern, heart rate pattern, electrocardiogram pattern, shape and movement of lips, shape and movement of tongue, brain wave pattern, finger joint shape, skin pattern and texture, kinetic signature, neural network pattern, muscle pattern, blood flow pattern, tear composition, breathing pattern, facial blood flow pattern, or a combination of any two or more of the above.

[0024] In the present disclosure, "authentication means biological data" is biological data used as an identity authentication unit, and can refer to biological data collected for identity authentication. That is, it can refer to data input or collected for identity authentication by a user attempting identity authentication, and can be used to refer to data collected by a specific device. A user attempting identity authentication can be allowed to input authentication means biological data or collection of authentication means biological data through identity authentication for access to a restricted program. The type of authentication means biological data can be set in advance by the user or the system for performing identity authentication.

[0025] In the present disclosure, "registered biological data" can refer to biological data registered or stored by a user on a device owned by the user (identity authentication device). Registered biological data can be used as a reference to determine whether authentication means biological data matches data of a user attempting identity authentication. The type of registered biological data can be the same as the type of authentication means biological data. When authentication means biological data matches registered biological data, identity authentication will be successfully performed, and access to a restricted program can be approved.

[0026] In an embodiment, registered biological data can be collected by an identity authentication device, a part of an identity authentication device, or a device electrically or communicatively connected to an identity authentication device, and stored in the identity authentication device. For example, a user can input and store his or her own biological data through a data input device (e.g., a camera, a fingerprint input device, etc.) provided on an identity authentication device, thereby storing registered biological data in the identity authentication device.

[0027] In another embodiment, the registered biometric data can be collected by the identity authentication request device and stored in the identity authentication device. Specifically, the registered biometric data can be collected by the identity authentication request device and transmitted to the identity authentication device (or transmitted to the identity authentication device through a server) and stored in the identity authentication device. The registered biometric data stored through this procedure can also be used in subsequent identity authentication procedures according to the system of the present disclosure. For example, in order to perform the first authentication for using the identity authentication system, the identity authentication device can collect data as the "registered biometric data" of the user, and then, when the user attempts to perform identity authentication for using the identity authentication system, the identity authentication device can collect data as the "authentication means biometric data" of the user. Even if the types of registered biometric data are the same (for example, face), since there can be differences in the data collection sensor specifications of each device, according to the present embodiment, the accuracy of the same verification between the registered biometric data and the authentication means biometric data can be improved.

[0028] In an embodiment, in order to store the registered biometric data in the identity authentication device, a user confirmation procedure can be performed. The user confirmation procedure is a procedure for using the identity authentication system of the present disclosure and is a procedure that must be accompanied in order to access the identity authentication system of the present disclosure, that is, can be understood as a kind of service registration procedure. In an embodiment, only a user who has performed the user confirmation procedure can store the registered biometric data in his / her own terminal, or only a terminal of a user who has performed the user confirmation procedure can store the registered biometric data.

[0029] In an embodiment, the user confirmation procedure can include an identity card verification procedure.

[0030] In an embodiment, the identity card verification procedure can include an identity card authenticity verification procedure. The identity card authenticity verification procedure can be a procedure for verifying whether the identity card held by the user is a fake identity card. The identity card authenticity verification procedure can be performed by image capturing of the identity card by the camera or sensor of the user terminal. For example, the image capturing of the identity card and the identity card authenticity verification procedure can be performed through an identity authentication solution such as an identity authentication application program.

[0031] In an embodiment, the identity card verification procedure can include an identity card verification procedure. The identity card verification procedure can be a procedure for verifying whether the identity card held by the user is the identity card of the user. The identity card verification procedure can be performed by image capturing of the face of the user by the camera or sensor of the user terminal. For example, the image capturing of the face of the user and the identity card verification procedure can be performed through an identity authentication solution such as an identity authentication application program.

[0032] The authentication method of the present disclosure will be described below.

[0033] The identity authentication system of the present disclosure can be based on a plurality of authentication manners according to the subject determining whether the biological data matches.

[0034] First, the identity authentication system of the present disclosure can be based on a user terminal authentication manner (or an identity authentication device authentication manner). The user terminal authentication manner can refer to a manner in which a user terminal, i.e., an identity authentication device, determines whether authentication means biological data matches registered biological data. The user terminal can determine whether the authentication means biological data matches the registered biological data by comparing the registered biological data stored in the user terminal with the authentication means biological data received from another device. The other device can be any one of an identity authentication request device, a server, and a third device. The user terminal can transmit a result value of the comparison to another device (which can be the same device as the above-mentioned “other device”), and the device receiving the result value can allow or prohibit access to a restricted program based on the result value.

[0035] Next, the identity authentication system of the present disclosure can be based on an authentication manner of an identity authentication request device. The authentication manner of the identity authentication request device can refer to a manner in which the identity authentication request device determines whether authentication means biological data matches registered biological data. The identity authentication request device can compare the authentication means biological data collected by the identity authentication request device, a part of the identity authentication request device, or a device electrically connected or communicatively connected to the identity authentication request device, with the registered biological data received from another device, thereby determining whether the authentication means biological data matches the registered biological data. The other device can be any one of a user terminal (i.e., an identity authentication device), a server, and a third device. The identity authentication request device can allow or prohibit access to a restricted program based on a result value of the comparison, or transmit the result value of the comparison to another device (which can be the same device as the above-mentioned “other device”), and the device receiving the result value can allow or prohibit access to the restricted program based on the result value.

[0036] Next, the identity authentication system of the present disclosure can be based on a server authentication manner. The server authentication manner can refer to a manner in which a server determines whether authentication means biological data matches registered biological data. The server can determine whether the authentication means biological data matches the registered biological data by comparing the authentication means biological data received from an identity authentication request device with the registered biological data from a user terminal (i.e., an identity authentication device). The server can allow or prohibit access to a restricted program based on a result value of the comparison, or transmit the result value of the comparison to another device, and the device receiving the result value can allow or prohibit access to the restricted program based on the result value.

[0037] Additionally, the identity authentication system of the present disclosure can be based on an authentication method of an identity authentication dedicated device. The authentication method of the identity authentication dedicated device can mean a method of determining whether authentication means biological data matches registered biological data by the identity authentication dedicated device. The identity authentication dedicated device can be a device separately provided from a user terminal (or an identity authentication device) or an identity authentication request device, which can be a device separately provided for performing only identity authentication without performing other functions. The identity authentication dedicated device can receive and store registered biological data from the user terminal, and determine whether authentication means biological data matches the registered biological data by comparing the authentication means biological data subsequently received with the registered biological data. The identity authentication dedicated device can transmit a result value of the comparison to another device, and the device receiving the result value can allow or prohibit access to a restricted program based on the result value. The other device can be any one of the user terminal, the identity authentication request device, a server, and a third device.

[0038] Figure 1 is a block diagram for explaining an identity authentication system according to an embodiment of the present disclosure.

[0039] The identity authentication system of the present disclosure can include an identity authentication device 10 and an identity authentication request device 20.

[0040] In the present disclosure, the identity authentication device 10 can mean a device owned by a user for performing identity authentication. The identity authentication device 10 can be understood as a user terminal, wherein the user's terminal can include a device for storing registered biological data, or any kind of device for determining whether biological data matches by comparison between biological data. For example, the identity authentication device 10 can be a device (e.g., a smart phone, a mobile phone, a tablet, a personal computer (PC), a personal digital assistant (PDA), a notebook computer, a media player, a global positioning system (GPS) device, smart glasses, a smart watch, a camera) equipped with an input / output interface, and other mobile or non-mobile electronic devices, but is not limited thereto.

[0041] In the present disclosure, the identity authentication request device 20 can mean a device for requesting execution of identity authentication. The identity authentication request device 20 can detect a user who accesses (physically or electronically) the identity authentication request device 20. The identity authentication request device 20 can collect authentication means biological data from the user. The identity authentication request device 20 can transmit the authentication means biological data to another device, or determine whether the biological data match by comparison between the biological data. For example, the identity authentication request device 20 can be a device (e.g., a smartphone, a mobile phone, a tablet, a personal computer (PC), a personal digital assistant (PDA), a notebook, a media player, a global positioning system (GPS) device, smart glasses, a smart watch, a wearable device (e.g., a headband, a ring, etc.) having a communication function and a data processing function, a camera) equipped with an input / output interface, but is not limited thereto.

[0042] In the present disclosure, the identity authentication system can be used to allow access to a restricted program only for a user who successfully passes the identity authentication, and the application program of the identity authentication system, i.e., the program restricted by the identity authentication system, can be any program that needs to comply with security.

[0043] For example, the program restricted by the identity authentication system can be "payment", and mobile payment can be automatically approved for a user who successfully passes the identity authentication. For example, the program restricted by the identity authentication system can be "access", and access, e.g., opening of an access blocking gate, etc., can be allowed for a user who successfully passes the identity authentication. For example, when the program restricted by the identity authentication system can be "vehicle control", control of a vehicle, e.g., starting of the vehicle, etc., can be allowed only for a user who successfully passes the identity authentication. For example, when the program restricted by the identity authentication system is "purchase of automatic vending machine goods", purchase of goods, e.g., selection of goods of an automatic vending machine, etc., can be allowed only for a user who successfully passes the identity authentication. In addition to the above examples, the identity authentication system of the present disclosure can be applied to any program that needs to comply with security.

[0044] In the present disclosure, the identity authentication request device 20 can be implemented to guide identity authentication for access to a restricted program by interaction with a user (e.g., an electronic kiosk). Accordingly, the identity authentication request device 20 can be implemented in various forms according to the application program (use scenario) of the identity authentication system.

[0045] For example, when the program limited by the identity authentication system is "payment", the identity authentication request device 20 can be implemented in the form of a point of sales (POS) terminal. For example, when the program limited by the identity authentication system is "access", the identity authentication request device 20 can be implemented in the form of an access blocking gate, or an electronic device equipped with the access blocking gate. For example, when the program limited by the identity authentication system is "vehicle control", the identity authentication request device 20 can be implemented in the form of an on-board computer mounted on a vehicle. For example, when the program limited by the identity authentication system is "automatic vending machine article purchase", the identity authentication request device 20 can be implemented in the form of an automatic vending machine.

[0046] In the identity authentication system of the present disclosure, the identity authentication device 10 and the identity authentication request device 20 can perform data transmission and reception through the network 30. The network 30 can be implemented through a wired network (for example, a Local Area Network (LAN), a Wide Area Network (WAN), or a Value Added Network (VAN), etc.), or can also be implemented through a wireless network (for example, a mobile radio communication network, a Near Field Communication network, or a satellite communication network, etc.). In addition, the network 30 is a data communication network having a broad sense in order to enable the respective network constituting bodies shown in Figure 1

[0047] Although not shown in Figure 1 , the identity authentication system can include a server. The server can manage and control the entire identity authentication system, and the identity authentication system can also include a server for reasons of convenience of data storage, dispersion of data, design restrictions, and design convenience, etc. In an embodiment, the identity authentication device 10 or the identity authentication request device 20 can not directly transmit and receive data to each other for a part or all of the data to be transmitted and received, but can transmit and receive data through the server.

[0048] Figure 2 is a conceptual diagram showing an example in which a user performs identity authentication in the identity authentication system according to an embodiment of the present disclosure.

[0049] For convenience, Figure 2 the example shown in

[0050] Referring to​Figure 2 User 1 can carry an authentication device 10. The authentication device 10 can store registered biometric data.

[0051] User 1 can access the authentication request device 20. For example, User 1 may access the authentication request device 20 in order to bypass an access barrier gate and pass through the access barrier gate.

[0052] The authentication request device 20 can detect the access of user 1. For example, the authentication request device 20 can detect the access of user 1 by means of a camera or sensor mounted on or connected to the authentication request device 20. For example, the authentication request device 20 can detect the access of user 1 by transmitting specific data or signals (e.g., authentication signals described later).

[0053] The authentication request device 20, upon detecting user 1's access, can collect user 1's biometric data. User 1 can input their biometric data via a camera, sensor, or other input / output interface mounted on or connected to the authentication request device 20.

[0054] When the identity authentication system uses user terminal authentication, the identity authentication request device 20 can transmit the collected authentication means biometric data to the identity authentication device 10. Upon receiving the authentication means biometric data, the identity authentication device 10 can compare the received authentication means biometric data with stored registration biometric data. The identity authentication device 10 can generate a comparison result value.

[0055] When the authentication system is based on the authentication method of the authentication request device, the authentication request device 20 can receive registered biometric data from the authentication device 10. The authentication request device 20 can transmit a signal to the authentication device 10 requesting registered biometric data. Upon receiving the signal, the authentication device 10 can transmit the registered biometric data to the authentication request device 20. The authentication request device 20, upon receiving the registered biometric data, can compare the received registered biometric data with the collected authentication biometric data. The authentication request device 20 can generate a comparison result value.

[0056] exist Figure 2 In the example, the ability to allow user 1 to enter or exit can be determined based on the generated result value. For instance, if the generated result value corresponds to a match between two biometric data points, the access barrier can be lifted for user 1. Conversely, if the generated result value corresponds to a mismatch between two biometric data points, the access barrier can remain in place for user 1.

[0057] On the other hand, the identity authentication system can also require an additional authentication procedure other than the identity authentication based on the biometric data. For example, the identity authentication system can require the user to perform an additional authentication procedure when security is necessary (e.g., when the security level of an area that the user desires to enter is higher than that of other areas, or when the amount that the user desires to pay is higher than a preset amount). In an embodiment, the additional authentication procedure can be required to be performed only when the registered biometric data matches the biometric data of the authentication means.

[0058] In an embodiment, the additional authentication procedure can include an ID card check procedure. The ID card check procedure can be a procedure of verifying whether an ID card held by the user is the ID card of the user. The ID card check procedure can include image capturing of the ID card, image capturing of the face of the user, and comparison of the image of the ID card with the image of the face, by the camera or sensor of the identity authentication device 10 or the identity authentication request device 20.

[0059] On the other hand, in the identity authentication system, a scheme of designating the identity authentication device 10 can become an issue. That is, how to designate the object when the identity authentication request device 20 transmits the collected biometric data of the authentication means or requests transmission of the registered biometric data can become an issue.

[0060] In an embodiment, the identity authentication request device 20 can designate the identity authentication device 10 based on the identification information input by the user 1. In this embodiment, the identity authentication request device 20 can include an interface through which the user 1 can input device identification data, and can receive input of the device identification data of the user 1 through the interface. The device identification data can be data for identifying the terminal (i.e., the identity authentication device) of the user. For example, the device identification data can include one or more of a phone number, a membership number, and a resident registration number.

[0061] In another embodiment, the identity authentication request device 20 can designate the identity authentication device 10 by detecting the closest device. In this embodiment, the identity authentication request device 20 can detect the closest device by any appropriate method. For example, the identity authentication request device 20 can include a plurality of nodes or channels, and can measure distances based on signals transmitted and received between the plurality of nodes or channels and the identity authentication device. For example, the plurality of nodes or channels can be nodes or channels for transmitting and receiving a beacon signal.

[0062] In yet another embodiment, the identity authentication request device 20 can designate the identity authentication device 10 based on a prearranged sound signal. In this embodiment, the prearranged sound signal can refer to a sound signal that the identity authentication device 10 can detect in the identity authentication system. The identity authentication device 10 can detect the sound signal and determine whether the detected sound signal is the prearranged sound signal transmitted by the identity authentication request device 20. When the identity authentication device 10 determines that the detected sound signal is the prearranged sound signal, the device identification data of the identity authentication device 10 can be transmitted to the identity authentication request device 20 or a server. The identity authentication request device 20 can designate the identity authentication device 10 based on the device identification data.

[0063] On the other hand, the identity authentication system according to each of the embodiments described below can include a plurality of identity authentication request devices that each perform identity authentication. The plurality of identity authentication request devices can not constitute independent systems, but can constitute an overall identity authentication system. The plurality of identity authentication request devices can be understood as a plurality of devices in terms of physics or from an external perspective, but can also be a single device connected by wire or wirelessly. For example, as described later, the first identity authentication request device 21, the second identity authentication request device 22, and the third identity authentication request device 23 can be understood as the identity authentication request device 20 or a part of the identity authentication request device 20 described above. The first identity authentication request device 21, the second identity authentication request device 22, and the third identity authentication request device 23 can be understood as being distinguished for the convenience of explanation of the corresponding embodiments.

[0064] The identity authentication system according to an embodiment of the present disclosure can include a first authentication request device and a second authentication request device. The second authentication request device can perform identity authentication with respect to a user who has not normally completed the first authentication. The case in which the first authentication is not normally completed can include a case in which the user performs an improper action and a case in which a program error occurs, etc. This embodiment can be implemented by the identity authentication system according to various embodiments of the present disclosure. Regarding this embodiment, detailed descriptions will be given later.

[0065] The identity authentication system according to an embodiment of the present disclosure can include a main authentication request device and one or more auxiliary authentication request devices. The main authentication request device is a device that performs the entire identity authentication process, and the auxiliary authentication request device can refer to a device that performs a process after omitting part of the identity authentication process with respect to an identity authentication device whose identity authentication has been performed based on the main authentication request device. For example, as described later, the first identity authentication request device 21 can be the main authentication request device, and the second identity authentication request device 22 and the third identity authentication request device 23 can each be the auxiliary authentication request device.

[0066] For example, the identity authentication system of the present embodiment can be applied to a restricted access area, the primary authentication request device corresponds to a primary access barrier gate, and each of the one or more secondary authentication request devices corresponds to one or more secondary access barrier gates. The primary authentication request device can control the operation of the corresponding primary access barrier gate, and the secondary authentication request device can control the operation of the corresponding secondary access barrier gate.

[0067] For example, the restricted access area can be a building including one or more business sites. In this example, the primary access barrier gate is provided at the first floor of the building, and the secondary access barrier gates can be provided at the remaining floors. An employee working at a first business site can need to be restricted to access only the floor on which the first business site is located, and an employee working at a second business site can need to be restricted to access only the floor on which the second business site is located. Therefore, the employee working at the first business site and the employee working at the second business site can both pass through the primary access barrier gate, but need to be controlled not to pass through the secondary access barrier gates of the other floors of the business sites other than the business site of the employee.

[0068] For example, the restricted access area can be a residence, such as an apartment, including one or more households. In this example, the primary access barrier gate is provided at the common entrance of the residence, and the secondary access barrier gates can be provided at each household or the remaining floors. A resident living in a first household can need to be restricted to access only the first household or the floor corresponding to the first household, and a resident living in a second household can need to be restricted to access only the second household or the floor corresponding to the second household. Therefore, the resident living in the first household and the resident living in the second household can both need to be controlled to pass through the primary access barrier gate, but not to pass through the secondary access barrier gates of the other households or the corresponding floors other than the household or the floor of the resident.

[0069] Figure 3 is a flowchart for explaining an identity authentication procedure according to an embodiment of the present disclosure.

[0070] Figure 3 The illustrated identity authentication procedure can be performed by the first identity authentication request device 21, the server 40, and the identity authentication device 10. The first identity authentication request device 21 can be understood as an identity authentication request device corresponding to a site when a user first restricts an access area, and can correspond to the aforementioned primary access barrier gate.

[0071] In an embodiment, in step 301, the first identity authentication request device 21 can send an authentication signal and monitor the server 40.

[0072] In an embodiment, the authentication signal transmitted by the first identity authentication request device 21 can be for detecting access of the identity authentication device 10 or the user. The authentication signal can be a signal that, after being received by the identity authentication device 10, enables the identity authentication device 10 to perform a corresponding action. As described later, the corresponding action can be transmission of a status update request signal and authentication status.

[0073] In an embodiment, the monitoring of the server 40 by the first identity authentication request device 21 can be for detecting a change in specific data of the server 40. As described later, the first identity authentication request device 21 can detect that the status related to the identity authentication device 10 has been updated by monitoring the server 40, thereby enabling detection of access of the identity authentication device 10 or the user.

[0074] In an embodiment, in step 302, the identity authentication device 10 can receive the authentication signal.

[0075] In an embodiment, the identity authentication device 10 can receive the authentication signal transmitted by the first identity authentication request device 21. The identity authentication device 10 can include an interface that enables reception of the authentication signal transmitted by the first identity authentication request device 21.

[0076] On the other hand, the authentication signal transmitted and received between the first identity authentication request device 21 and the identity authentication device 10 can be based on any communication method or any type of signal. As one example, the authentication signal can be transmitted and received through a beacon. As another example, the authentication signal can be a signal based on near field communication (NFC).

[0077] In the present disclosure, with regard to the authentication signal transmitted and received between the first identity authentication request device 21 and the identity authentication device 10, it can be possible to simply implement that the identity authentication device 10 is in proximity to the first identity authentication request device 21 by transmitting and receiving the authentication signal, or it can be possible to calculate that the identity authentication device 10 is in proximity to the first identity authentication request device 21 based on the strength, position, and time required for transmitting and receiving the authentication signal, etc. of the transmitted and received authentication signal.

[0078] On the other hand, at this time, the authentication status of the identity authentication device 10 can correspond to OFF. In the present disclosure, the authentication status can refer to a status of whether the corresponding identity authentication device 10 has successfully performed authentication in relation to the first identity authentication request device 21, and as a specific example, can be a status regarding whether the user of the identity authentication device 10 has passed through the main access barrier gate. The authentication status can be stored in the identity authentication device 10.

[0079] As Figure 3As shown, in the case where the authentication state corresponds to OFF, the value of the authentication state can be 0 ("Authentication state: 0").

[0080] In an embodiment, in step 303, the identity authentication device 10 can transmit the access state update request signal and the authentication state to the server 40.

[0081] In an embodiment, the identity authentication device 10 can transmit the access state update request signal based on receiving the authentication signal. The access state update request signal can be a signal that requests the server 40 to update the access state of the identity authentication device 10 by notifying that the authentication signal has been received. The identity authentication device 10 can include an interface capable of transmitting the access state update request signal.

[0082] In an embodiment, the identity authentication device 10 can trigger the first identity authentication request device 21 to collect the authentication means biometric data by transmitting the access state update request signal. As described later, according to the access state update request signal transmitted by the identity authentication device 10, the server 40 can update the access state, and the identity authentication request device 20 can detect the update of the access state of the server 40.

[0083] In an embodiment, in step 304, the server 40 can update the access state and the authentication state of the identity authentication device 10.

[0084] In an embodiment, the server 40 can update the access state and the authentication state corresponding to the identity authentication device 10 based on receiving the access state update request signal and the authentication state from the identity authentication device 10.

[0085] In Figure 3 In the embodiment shown, the server 40 can update the access state to correspond to ON based on the request of the identity authentication device 10. In addition, the server 40 can update the authentication state according to the authentication state transmitted by the identity authentication device 10, specifically, in the embodiment shown, the authentication state can be updated to correspond to ON. Figure 3 In the embodiment shown, since the authentication state of the identity authentication device 10 corresponds to OFF, the authentication state can be updated to correspond to OFF.

[0086] In an embodiment, in step 305, the first identity authentication request device 21 can detect the update of the access state and the update of the authentication state.

[0087] As described above, the first identity authentication request device 21 can monitor the server 40 to detect the change of the specific data in the server 40, wherein the change of the specific data can relate to the state of the identity authentication device 10 updated by the server 40, specifically, the access state and the authentication state of the identity authentication device 10.

[0088] In an embodiment, in step 306, the first identity authentication requesting device 21 can collect the authentication means biometric data.

[0089] The first identity authentication requesting device 21 can collect the authentication means biometric data based on detecting the update of the access status. That is, when the first identity authentication requesting device 21 detects the update of the access status, it can be considered that the user has accessed.

[0090] In an embodiment, in step 307, the first identity authentication requesting device 21 can transmit the collected authentication means biometric data to the server 40.

[0091] In an embodiment, the authentication means biometric data transmitted by the first identity authentication requesting device 21 to the server 40 can be landmark data.

[0092] In an embodiment, the first identity authentication requesting device 21 can delete the authentication means biometric data based on transmitting the collected authentication means biometric data.

[0093] In an embodiment, in step 308, the server 40 can transmit a message to the identity authentication device 10.

[0094] In an embodiment, the server 40 can transmit the message to the identity authentication device 10 based on receiving the authentication means biometric data from the first identity authentication requesting device 21.

[0095] In an embodiment, the message transmitted by the server 40 to the identity authentication device 10 can be a message related to the collection of the authentication means biometric data. The message transmitted by the server 40 to the identity authentication device 10, as described below, can be a message instructing or guiding the identity authentication device 10 to download the authentication means biometric data from the server 40.

[0096] In an embodiment, the message transmitted by the server 40 to the identity authentication device 10 can be a push notification or a push message. The server 40 can transmit the message to the identity authentication device 10 based on any suitable environment or service suitable for transmitting the push notification or the push message. For example, the server 40 can transmit the message to the identity authentication device 10 based on the Firebase Cloud Messaging (FCM) service, but is not limited thereto.

[0097] In an embodiment, in step 309, the identity authentication device 10 can download the authentication means biometric data.

[0098] In one embodiment, the identity authentication device 10 can download the authentication means biometric data from the server 40 based on the reception of the message from the server 40. Of course, the authentication means biometric data downloaded by the identity authentication device 10 can be the authentication means biometric data transmitted to the server 40 by the first identity authentication request device 21.

[0099] In one embodiment, in step 310, the identity authentication device 10 can compare the authentication means biometric data with the registered biometric data.

[0100] In one embodiment, the identity authentication device 10 can compare the authentication means biometric data downloaded from the server 40 with the registered biometric data stored in the identity authentication device 10. The identity authentication device 10 compares the authentication means biometric data with the registered biometric data in order to determine whether the authentication means biometric data matches the registered biometric data.

[0101] In one embodiment, the identity authentication device 10 can determine that the authentication means biometric data matches the registered biometric data when a matching rate of the authentication means biometric data and the registered biometric data is equal to or greater than a predetermined value, and determine that the authentication means biometric data does not match the registered biometric data when the matching rate of the authentication means biometric data and the registered biometric data is less than the predetermined value.

[0102] On the other hand, in one embodiment, the downloaded authentication means biometric data can be deleted after step 310. That is, the downloaded authentication means biometric data can be deleted immediately after the comparison with the registered biometric data as one-time data.

[0103] In one embodiment, in step 311, the identity authentication device 10 can change the authentication state based on the matching of the authentication means biometric data and the registered biometric data.

[0104] Specifically, the identity authentication device 10 can change the authentication state to correspond to ON based on the success of the identity authentication. As shown in Figure 3 the authentication state can be 1 ("Authentication state: 1") when the authentication state corresponds to ON.

[0105] In one embodiment, in step 312, the identity authentication device 10 can transmit a comparison result value to the server 40.

[0106] The result of the comparison of the authentication means biometric data and the registered biometric data by the identity authentication device 10 can be either of matching and non-matching, and the comparison result value can also be a value corresponding to either of matching and non-matching. However, according to step 311, since the authentication means biometric data and the registered biometric data match, the comparison result value can be a value corresponding to matching. Figure 3In the illustrated embodiment, the result value of the comparison transmitted by the identity authentication device 10 will be the value corresponding to the match.

[0107] In an embodiment, the server 40 can update the result value in step 313.

[0108] In an embodiment, the server 40 can update the result value based on the reception of the result value from the identity authentication device 10.

[0109] In an embodiment, the server 40 can construct a data structure for updating the result value corresponding to the received authentication means biometric data based on the reception of the authentication means biometric data from the first identity authentication request device 21 in step 307. Thereafter, the result value can be updated based on the constructed data structure based on the reception of the result value of the comparison from the identity authentication device 10 in step 313.

[0110] In an embodiment, the first identity authentication request device 21 can detect the result value update of the server in step 314.

[0111] After step 314, the identity authentication request device 20 can determine whether to allow or prohibit access to the restricted program based on the updated result value.

[0112] Figure 4 is a flowchart for explaining an identity authentication program according to another embodiment of the present disclosure.

[0113] Figure 4 The illustrated identity authentication program can be executed by the second identity authentication request device 22, the server 40, and the identity authentication device 10. The second identity authentication request device 22 can be understood as an identity authentication request device additionally provided after a user initially restricts access to an area, and can correspond to the aforementioned auxiliary access blocking gate.

[0114] Figure 4 The illustrated identity authentication program can be an identity authentication program that can be executed with respect to Figure 3 The illustrated identity authentication program can be an identity authentication program that can be executed with respect to

[0115] In an embodiment, the second identity authentication request device 22 can transmit an authentication signal and monitor the server 40 in step 401.

[0116] As explained with reference to Figure 3 As explained above, in an embodiment, the second identity authentication request device 22 transmits an authentication signal, which can be for detecting access of the identity authentication device 10 or the user. The authentication signal can be a signal that, when received by the identity authentication device 10, causes the identity authentication device 10 to perform a corresponding action.

[0117] In an embodiment, the second identity authentication request device 22 can monitor the server 40 to detect a change in the specific data of the server 40. As described later, the second identity authentication request device 22 can detect that the status related to the identity authentication device 10 is updated by monitoring the server 40, and thus can detect the access of the identity authentication device 10 or the user.

[0118] In an embodiment, in step 402, the identity authentication device 10 can receive the authentication signal.

[0119] As described above with reference to Figure 3 , in an embodiment, the identity authentication device 10 can receive the authentication signal transmitted by the second identity authentication request device 22. The identity authentication device 10 can include an interface capable of receiving the authentication signal transmitted by the second identity authentication request device 22.

[0120] A detailed description of the authentication signal has been described above, and thus will be omitted.

[0121] On the other hand, at this time, the authentication status of the identity authentication device 10 can correspond to ON. That is, the authentication status stored in the identity authentication device 10 can correspond to ON. This is because, as described above, Figure 4 , the identity authentication procedure can be an identity authentication procedure performed with respect to the identity authentication device 10 that has performed the identity authentication procedure described above. Figure 3

[0122] As described above with reference to Figure 4 , in the case where the authentication status corresponds to ON, the value of the authentication status can be 1 ("Authentication state: 1").

[0123] A detailed description of the authentication status has been described above, and thus will be omitted.

[0124] In an embodiment, in step 403, the identity authentication device 10 can transmit the access status update request signal and the authentication status to the server 40.

[0125] As described above with reference to Figure 3 , in an embodiment, the identity authentication device 10 can transmit the access status update request signal based on the reception of the authentication signal.

[0126] A detailed description of the access status update request signal has been described above, and thus will be omitted.

[0127] On the other hand, in Figure 4 , since the authentication status of the identity authentication device 10 corresponds to ON, the authentication status transmitted by the identity authentication device 10 to the server 40 can also correspond to ON. ​

[0128] In an embodiment, in step 404, the server 40 can update the access state and the authentication state of the identity authentication device 10.

[0129] In an embodiment, the server 40 can update the access state and the authentication state corresponding to the identity authentication device 10 based on the access state update request signal and the authentication state received from the identity authentication device 10.

[0130] In Figure 4 In the embodiment shown in FIG. 4, the server 40 can update the access state to correspond to ON based on the request of the identity authentication device 10. In addition, the server 40 can update the authentication state according to the authentication state transmitted by the identity authentication device 10, specifically, in the embodiment shown in FIG. 4, since the authentication state of the identity authentication device 10 corresponds to ON, the authentication state can be updated to correspond to ON. Figure 4

[0131] In an embodiment, in step 405, the second identity authentication request device 22 can detect the update of the access state and the update of the authentication state.

[0132] As described above, the second identity authentication request device 22 can detect the change of the specific data in the server 40 by monitoring the server 40, wherein the change of the specific data can be the state of the identity authentication device 10 updated by the server 40, specifically, can be the access state and the authentication state about the identity authentication device 10.

[0133] In the embodiment shown in FIG. 4, since the authentication state of the identity authentication device 10 transmitted by the identity authentication device 10 corresponds to ON, the updated authentication state detected by the second identity authentication request device 22 can also correspond to ON.

[0134] In an embodiment, the second identity authentication request device 22 can omit the collection of the authentication means biological data based on the detected updated authentication state corresponding to ON. The authentication state of the identity authentication device 10 corresponding to ON can be because it indicates that the identity authentication has been performed for the identity authentication device 10 by comparing the authentication means biological data.

[0135] In an embodiment, in step 406, the second identity authentication request device 22 can refer to the user's authority.

[0136] ​In an embodiment, the second identity authentication request device 22 can determine that the user of the identity authentication device 10 has accessed based on the updated access status, and determine that the user of the identity authentication device 10 has performed identity authentication based on the updated authentication status. The second identity authentication request device 22 can refer to the authority of the user of the identity authentication device 10 based on the determination that the user of the identity authentication device 10 has accessed, and the user of the identity authentication device 10 has performed identity authentication. For example, the second identity authentication request device 22 can refer to the authority of the user of the identity authentication device 10 stored in the server 40. The authority of the user is referred to in order to determine whether the user has the authority to access the program restricted by the second identity authentication request device 22.

[0137] In an embodiment, the second identity authentication request device 22 can refer to the authority of the user by monitoring the server 40. In the foregoing Figure 3 In step 313, the server 40 can call the authority of the user, and the second identity authentication request device 22 can refer to the called authority of the user.

[0138] In an embodiment, in step 407, the second identity authentication request device 22 can execute the program corresponding to the authentication status and the authority of the user.

[0139] Specifically, the second identity authentication request device 22 can omit the collection of the biometric data of the authentication means and allow access to the restricted program based on the authentication status corresponding to ON and the user having the authority to the program restricted by the second identity authentication request device 22. The second identity authentication request device 22 can not perform the collection of the biometric data of the authentication means and not allow access to the restricted program based on the authentication status corresponding to ON and the user not having the authority to the program restricted by the second identity authentication request device 22.

[0140] Figure 5 is a flowchart for explaining an identity authentication program according to still another embodiment of the present disclosure.

[0141] Figure 5 The identity authentication program illustrated in FIG. 13 can be executed by the third identity authentication request device 23, the server 40, and the identity authentication device 10. The third identity authentication request device 23 can be understood as an identity authentication request device provided in a region from which the user exits the restricted access region after the user initially restricts the access region, and can correspond to the main access blocking gate or the auxiliary access blocking gate provided near the main access blocking gate described above.

[0142] Figure 5 The identity authentication program illustrated in FIG. 13 can be an identity authentication program that can be executed with respect to Figure 3 The identity authentication program illustrated in FIG. 13 can be an identity authentication program that can be executed with respect to

[0143] In one embodiment, in step 501, the third authentication request device 23 may send an authentication signal and monitor the server 40.

[0144] For reference Figure 3 and Figure 4 As described above, in one embodiment, the third authentication request device 23 sends an authentication signal, possibly to detect access from the authentication device 10 or the user. The authentication signal can be a signal that, upon being received by the authentication device 10, causes the authentication device 10 to perform a corresponding action.

[0145] In one embodiment, the third authentication request device 23 monitors the server 40 to detect changes in specific data on the server 40. As described below, the third authentication request device 23 can detect updates to the status associated with the authentication device 10 by monitoring the server 40, thereby detecting access to the authentication device 10 or a user.

[0146] In one embodiment, in step 502, the authentication device 10 may receive an authentication signal.

[0147] For reference Figure 3 and Figure 4 As described above, in one embodiment, the authentication device 10 can receive an authentication signal sent by the third authentication request device 23. The authentication device 10 may include an interface capable of receiving the authentication signal sent by the third authentication request device 23.

[0148] The detailed description of the authentication signal has been described above and will therefore be omitted.

[0149] On the other hand, at this time, the authentication state of the authentication device 10 can correspond to ON. That is, the authentication state stored in the authentication device 10 can correspond to ON. This is because, as mentioned above, Figure 5 The authentication process shown can be for those that have already been executed. Figure 3 The identity authentication procedure executed by the identity authentication device 10 shown in the identity authentication procedure.

[0150] like Figure 5 As shown, when the authentication state corresponds to ON, the value of the authentication state can be 1 ("Authentication state: 1").

[0151] The detailed explanation of the authentication status has been described above and will therefore be omitted.

[0152] In one embodiment, in step 503, the authentication device 10 may transmit an access status update request signal and authentication status to the server 40.

[0153] As previously described with reference to Figure 3 and Figure 4 As previously described, in an embodiment, the identity authentication device 10 can transmit an access status update request signal based on receiving the authentication signal.

[0154] Detailed description of the access status update request signal has been described above, and thus will be omitted.

[0155] On the other hand, in Figure 5 , since the authentication status of the identity authentication device 10 corresponds to ON, the authentication status transmitted by the identity authentication device 10 to the server 40 can also correspond to ON.

[0156] In an embodiment, in step 504, the server 40 can update the access status and the authentication status of the identity authentication device 10.

[0157] In an embodiment, the server 40 can update the access status and the authentication status corresponding to the identity authentication device 10 based on the access status update request signal and the authentication status received from the identity authentication device 10.

[0158] In Figure 5 , the server 40 can update the access status to correspond to ON based on the request of the identity authentication device 10.

[0159] In an embodiment, in step 505, the third identity authentication request device 23 can detect the update of the access status and the update of the authentication status. In addition, the server 40 can update the authentication status according to the authentication status transmitted by the identity authentication device 10, specifically, in Figure 5 , since the authentication status of the identity authentication device 10 corresponds to ON, the authentication status can be updated to correspond to ON.

[0160] As previously described, the third identity authentication request device 23 can detect the change of the specific data in the server 40 by monitoring the server 40, wherein the change of the specific data can be the status of the identity authentication device 10 updated by the server 40, specifically, can be the access status and the authentication status about the identity authentication device 10.

[0161] In which, since the authentication status of the identity authentication device 10 transmitted by the identity authentication device 10 corresponds to ON, the updated authentication status detected by the third identity authentication request device 23 can also correspond to ON.

[0162] In an embodiment, the third identity authentication request device 23 can omit the collection of the authentication means biometric data based on the detected updated authentication status corresponding to ON. The authentication status of the identity authentication device 10 corresponding to ON can be because the identity authentication has been performed for the identity authentication device 10 by the comparison of the authentication means biometric data.

[0163] In an embodiment, in step 506, the third identity authentication request device 23 can consult the user's rights.

[0164] In an embodiment, the third identity authentication request device 23 can determine that the user of the identity authentication device 10 has accessed based on the updated access status, and determine that the user of the identity authentication device 10 has performed identity authentication based on the updated authentication status. The third identity authentication request device 23 can consult the user's rights of the identity authentication device 10 based on the determination that the user of the identity authentication device 10 has accessed, and the determination that the user of the identity authentication device 10 has performed identity authentication. For example, the third identity authentication request device 23 can consult the user's rights of the identity authentication device 10 stored in the server 40. The consultation of the user's rights is to determine whether the user has the right to access the program restricted by the third identity authentication request device 23. On the other hand, in Figure 5 In the embodiment shown, the program restricted by the third identity authentication request device 23 can be the user's departure.

[0165] In an embodiment, the third identity authentication request device 23 can consult the user's rights by monitoring the server 40. In the aforementioned step 313, the server 40 can invoke the user's rights, and the third identity authentication request device 23 can consult the invoked user's rights. Figure 3

[0166] In an embodiment, in step 507, the third identity authentication request device 23 can execute the program corresponding to the authentication status and the user's rights.

[0167] Specifically, the third identity authentication request device 23 can omit the collection of the authentication means biometric data and allow access to the restricted program based on the authentication status corresponding to ON and the user having the right to the program restricted by the third identity authentication request device 23. The third identity authentication request device 23 can possibly not perform the collection of the authentication means biometric data and not allow access to the restricted program based on the authentication status corresponding to ON and the user not having the right to the program restricted by the third identity authentication request device 23. That is, in the embodiment shown, the user can not be allowed to leave by the third identity authentication request device 23. Figure 5

[0168] ​​In an embodiment, in step 508, the third identity authentication request device 23 can transmit the authentication expiration signal of the user to the server 40.

[0169] In Figure 5 In the embodiment shown, step 508 can be premised on the third identity authentication request device 23 allowing the user to leave. The third identity authentication request device 23 can transmit the authentication expiration signal of the user to the server 40 based on determining to allow the user to leave.

[0170] In an embodiment, in step 509, the server 40 can deliver the authentication expiration signal of the user to the identity authentication device 10.

[0171] In an embodiment, the server 40 can deliver the authentication expiration signal of the user to the identity authentication device 10 based on receiving the authentication expiration signal of the user from the third identity authentication request device 23.

[0172] In an embodiment, the authentication expiration signal can be transmitted by a message, specifically, a push notification or a push message.

[0173] In another embodiment, instead of steps 508 and 509, the third identity authentication request device 23 can also transmit the authentication expiration signal of the user directly to the identity authentication device 10.

[0174] In an embodiment, in step 510, the identity authentication device 10 can change the authentication state.

[0175] Specifically, the identity authentication device 10 can change the authentication state to correspond to OFF based on receiving the authentication expiration signal of the user. As Figure 5 shown, in the case where the authentication state corresponds to OFF, the value of the authentication state can be 0 (“Authentication state: 0”).

[0176] Subsequently, when the user of the identity authentication device 10 wants to access the identity authentication system of the present disclosure again, the identity authentication procedure as Figure 3 shown can be re-executed.

[0177] On the other hand, in Figures 3 to 5 , the first identity authentication request device 21, the second identity authentication request device 22, and the third identity authentication request device 23 can also be one device connected by wired or wireless means. For example, the first identity authentication request device 21, the second identity authentication request device 22, and the third identity authentication request device 23 can be understood as the aforementioned identity authentication request device 20 or a part of the identity authentication request device 20.

[0178] On the other hand, as described above, the identity authentication system according to an embodiment of the present disclosure can include an identity authentication request device performing a first authentication and an identity authentication request device performing a second authentication. The identity authentication request device performing the second authentication can perform identity authentication for a user who failed to normally complete the first authentication. The embodiment is characterized by not including the primary authentication request device and the secondary authentication request device, but including the first authentication request device and the second authentication request device, but can be implemented with reference to the identity authentication system described above. Figures 3 to 5 The identity authentication system described above.

[0179] Specifically, in an embodiment, the second authentication request device can determine whether a user terminal has performed identity authentication by interacting with the first authentication request device. In other words, the second authentication request device can detect a user terminal that has performed identity authentication by interacting with the first authentication request device and a user terminal that has not performed identity authentication by interacting with the first authentication request device.

[0180] Specifically, in an embodiment, the second authentication request device can detect, based on a result of updating the access state and the authentication state of the server 40, a user terminal for which the access state corresponds to ON but the authentication state corresponds to OFF as a user terminal that has not performed identity authentication by interacting with the first authentication request device. Conversely, in an embodiment, the second authentication request device can detect, based on a result of updating the access state and the authentication state of the server 40, a user terminal for which the access state corresponds to ON and the authentication state also corresponds to ON as a user terminal that has performed identity authentication by interacting with the first authentication request device.

[0181] In an embodiment, when the second authentication request device detects a user terminal that has not performed identity authentication by interacting with the first authentication request device, identity authentication can be performed. Specifically, when the second authentication request device detects a user terminal that has not performed identity authentication by interacting with the first authentication request device, authentication means biometric data can be collected, and a subsequent procedure of transmitting the authentication means biometric data can be performed.

[0182] In an embodiment, when the second authentication request device detects a user terminal that has performed identity authentication by interacting with the first authentication request device, collection of authentication means biometric data can be omitted, and an access-restricted procedure can be allowed.

[0183] According to the present embodiment, by combining the first authentication request device and the second authentication request device, it is possible to improve security without affecting user convenience.

[0184] Figure 6 is a flowchart of an identity authentication method according to an embodiment of the present disclosure.

[0185] Figure 6 Each step of the identity authentication method shown can be executed by the aforementioned identity authentication request device 20, specifically, by the processor of the identity authentication request device 20.

[0186] In step 610, the processor can send an authentication signal and monitor the server.

[0187] In step 620, the processor can detect an update of the access state and an update of the authentication state of the identity authentication device based on the monitoring of the server.

[0188] In an embodiment, the update of the access state can be requested by the identity authentication device receiving the authentication signal.

[0189] In an embodiment, the access state can be updated to correspond to ON based on the request of the identity authentication device receiving the authentication signal.

[0190] In step 630, the processor can execute: a step of collecting authentication means biological data based on the access state of the identity authentication device corresponding to ON and the authentication state corresponding to OFF; and a step of omitting the collection of the authentication means biological data based on the access state of the identity authentication device corresponding to ON and the authentication state corresponding to ON.

[0191] In an embodiment, the processor can further execute: a step of transmitting the collected authentication means biological data to the server.

[0192] In an embodiment, the processor can further execute: a step of detecting an update of a result value of the comparison of the authentication means biological data and the registered biological data stored in the identity authentication device, and determining whether to allow or prohibit the access to the restricted program based on the updated result value.

[0193] In an embodiment, the identity authentication request device can be arranged in a restricted access area.

[0194] In an embodiment, the identity authentication request device can control the action of an access blocking gate included in the restricted access area.

[0195] In an embodiment, the access blocking gate can include a main access blocking gate and one or more auxiliary access blocking gates.

[0196] Figure 7 is a block diagram of a device according to an embodiment of the present disclosure.

[0197] Figure 7 The device 700 shown can be at least one of the aforementioned identity authentication device 10, identity authentication request device 20, and server 40.

[0198] Referring toFigure 7 The device 700 can include a communication unit 710, a processor 720, and a database (DB) 730. Figure 7 The device 700 in FIG. 7 shows only the constituent elements related to the embodiments. Accordingly, it will be understood by those skilled in the art that other general constituent elements can be further included in addition to the constituent elements shown in FIG. 7. Figure 7 The device 700 in FIG. 7 shows only the constituent elements related to the embodiments. Accordingly, it will be understood by those skilled in the art that other general constituent elements can be further included in addition to the constituent elements shown in FIG. 7.

[0199] The communication unit 710 can include one or more constituent elements for wired / wireless communication with an external server or an external device. For example, the communication unit 710 can include at least one of a short-range communication unit (not shown), a mobile communication unit (not shown), and a broadcast receiving unit (not shown).

[0200] The database 730, as hardware for storing various data processed in the device 700, can store programs for processing and control of the processor 720. The database 730 can store payment information, user information, and the like.

[0201] The database 730 can include a random access memory (RAM) (e.g., dynamic random access memory (DRAM) and static random access memory (SRAM), etc.), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), an optical disc storage (e.g., CD-ROM, Blu-ray, or other optical disc storage, a hard disk drive (HDD), a solid state drive (SSD), or a flash memory.

[0202] The processor 720 controls the overall operation of the device 700. For example, the processor 720 can control the input unit (not shown), the display (not shown), the communication unit 710, the database 730, and the like, as a whole, by executing programs stored in the database 730. The processor 720 can control the operation of the device 700 by executing programs stored in the database 730.

[0203] The processor 720 can control at least a part of the operation of the device 700 described in the above. Figures 1 to 6

[0204] ​The processor 720 can be implemented with at least one of application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, micro-controllers, microprocessors, and other electric units for performing functions.

[0205] As an embodiment, the device 700 can be an electronic device having mobility. For example, the device 700 can be implemented as a smartphone, a tablet PC, a personal computer (PC), a smart TV, a personal digital assistant (PDA), a notebook, a media player, a navigation, a device equipped with a camera, and other mobile electronic devices. In addition, the device 700 can be implemented as a wearable device having a communication function and a data processing function, such as a watch, glasses, a headband, a ring, and the like.

[0206] Embodiments according to the present application can be implemented in the form of a computer program that can be executed by various constituent elements on a computer, and such a computer program can be stored in a computer-readable medium. At this time, the medium can include magnetic media such as a hard disk, a floppy disk, a magnetic tape, and the like; optical storage media such as CD-ROM and DVD; magneto-optical media such as a floptical disk; and hardware devices specially designed for storing and executing program instructions, such as ROM, RAM, a flash memory, and the like.

[0207] On the other hand, the computer program can be specifically designed and configured for the present application, or can be known and available to those skilled in the computer software field. Examples of the computer program can include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter and the like.

[0208] According to one embodiment, the method according to embodiments of the present disclosure can be provided in a computer program product. The computer program product can be traded as a commodity between a seller and a buyer. The computer program product can be in the form of a device readable storage medium (e.g., a compact disc read only memory (CD-ROM)) or be distributed over a network (e.g., an application store) or be directly downloaded or uploaded from a website (e.g., a manufacturer's website) or directly distributed from one user device to another (e.g., through a peer-to-peer distribution). In the case of online distribution, at least a portion of the computer program product can be temporarily stored or temporarily created in a machine readable storage medium such as a server of a manufacturer, a server of an application store, or a relay server memory.

[0209] The steps constituting the method according to the present application can be performed in any appropriate order, unless the order is explicitly stated or otherwise stated. The present application is not necessarily limited according to the order of recitation of the above steps. All examples or exemplary terms used in the present application (e.g., etc.) are merely for the purpose of detailed description of the present application, and the scope of the present application is not limited by the above examples or exemplary terms, unless limited by the claims. In addition, those skilled in the art can understand that various modifications, combinations, and changes can be made to the embodiments according to design conditions and various factors, without departing from the scope of the claims and equivalents thereof.

[0210] Therefore, the idea of the present application should not be limited to the above embodiments, and not only the appended claims, but also all ranges equivalent or equivalently modified to these claims belong to the scope of the idea of the present application.

Claims

1. An identity authentication method, executed by an identity authentication request device, characterized in that, The identity authentication method includes: The steps for sending authentication signals and monitoring the server are as follows: Based on monitoring of the server, the steps of detecting updates to the access status and authentication status of the authentication device, and... Based on the fact that the access state of the identity authentication device corresponds to being on and the authentication state corresponds to being off, biometric data of the authentication means is collected, and based on the fact that the access state of the identity authentication device corresponds to being on and the authentication state corresponds to being on, the step of collecting biometric data of the authentication means is omitted.

2. The identity authentication method according to claim 1, characterized in that, Also includes: The step of transmitting the collected biometric data of the authentication method to the server.

3. The identity authentication method according to claim 2, characterized in that, Also includes: The step of updating the result value of comparing the biometric data for the authentication method with the registered biometric data stored in the identity authentication device, and Based on the updated result value, the step of determining whether to allow or deny access to the restricted program.

4. The identity authentication method according to claim 1, characterized in that, The update of the access status is requested by the identity authentication device that receives the authentication signal. Based on the request from the identity authentication device that has received the authentication signal, the access status is updated to correspond to being enabled.

5. The identity authentication method according to claim 1, characterized in that, The authentication status is transmitted by the identity authentication device that receives the authentication signal and is updated according to the transmitted authentication status.

6. The identity authentication method according to claim 1, characterized in that, The identity authentication request device is located in the restricted access area and controls the operation of the access barrier gates included in the restricted access area.

7. An identity authentication request device, characterized in that, include: Memory, storing at least one program, and The processor runs by executing the at least one program; The processor is configured to: Send authentication signals and monitor the server. Based on monitoring of the server, updates to the access status and authentication status of the identity authentication device are detected. Based on the access state of the identity authentication device being on and the authentication state being off, biometric data of the authentication means are collected; and based on the access state of the identity authentication device being on and the authentication state being on, the collection of biometric data of the authentication means is omitted.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program for executing the authentication method according to claim 1 on a computer.