A digital authentication system

EP4643245A1Pending Publication Date: 2025-11-05KOBIL TEKNOLOJI LTD SIRKETI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023913201
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-11-05

AI Technical Summary

Technical Problem

Users face inefficiencies and increased workload due to the need to repeatedly perform security authentication processes across multiple sub-applications within a super application, even when the security sensitivity differs, leading to time loss and decreased user engagement.

Method used

A digital authentication system that manages authentication between a main application and sub-applications through a client device, utilizing a server with predefined authentication modules, a database for reference information, and a processor unit to streamline authentication processes, allowing for efficient comparison and recording of user inputs, and enabling direct access or denial based on matching reference information.

Benefits of technology

This system reduces user workload and time loss by eliminating the need for repetitive authentication across sub-applications, ensuring authentication steps are directed based on specific requirements, thereby enhancing user experience and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

It relates to a digital authentication system (10) for providing authentication service between a main application (200) entered through a client device (100) and a plurality of sub- applications (201) integrated into said main application (200).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] A DIGITAL AUTHENTICATION SYSTEM

[0003] TECHNICAL FIELD

[0004] The invention relates to a digital authentication system for providing security service between a main application entered through a client device and a plurality of sub-applications integrated into said main application.

[0005] BACKGROUND

[0006] Today, with the use of smartphones, many applications have become an indispensable part of life. According to research conducted by experts, 51% of the world, that is, approximately 3.8 billion people, use the internet. Smartphones are used as the primary internet access point for many people in the world. Increasing internet and smartphone users lead to the development of new trends and trends day by day. One of the new trends that has emerged in recent days is "Super Applications” called "Super Apps".

[0007] Super applications are platforms where independently developed mini applications are served to users on a common infrastructure. Super applications aim to highlight data sharing and provide services such as user authentication and payment that mini applications need from a single source. In this way, users can access all mini applications by logging in to a single account. Service providers can also avoid the burden of developing a separate application for each service they offer and add mini applications integrated into the same infrastructure on a single platform.

[0008] While some of the mini applications in the super application have medium / high security sensitivity (banking, shopping, finance, health, etc.), some have low security sensitivity (applications that do not require any identity information or payment transaction). In this case, the security modules determined as the basis for the super application in the super applications used today must be reapplied every time for each mini application. In this case, when entering the mini-application with low security sensitivity, it is necessary to perform the defined operations for the mini-application with medium / high security sensitivity every time. This creates a workload and loss of time for users. In addition, it causes a decrease in the desire of users to use the super application. In the application US2018343120A1 , a system for enabling the authentication of user credentials is mentioned. In the aforementioned system, it is explained that various authentication data about users are received over a blockchain network, and the user is given access permission accordingly. However, said application does not mention the authentication process between the super application and the mini application.

[0009] All the problems mentioned above have made it necessary to make an innovation in the relevant technical field as a result.

[0010] BRIEF DESCRIPTION OF THE INVENTION

[0011] The present invention relates to a digital authentication system in order to eliminate the above-mentioned disadvantages and to bring new advantages to the related technical field.

[0012] An object of the invention is to provide a digital authentication system that allows the loss of time and workload during the entry of super application users to mini applications.

[0013] The present invention is a digital authentication system for providing authentication service between a main application entered through a client device and a plurality of sub-applications integrated into said main application in order to realize all the objects that will emerge from the abovementioned and the following detailed description. Accordingly, a management unit comprising a processor unit that enables an access signal to be generated in the event that an access signal is logged into a sub-application via said client device, a server comprising at least one predetermined authentication module for logging into said sub-application; a database associated with said management unit comprising at least one predetermined reference information for completing at least one authentication step comprising at least one authentication module held on said server; a memory unit associated with said management unit for storing data; the processor unit is further configured to:

[0014] - ensure that an access signal is transmitted to the server in the event that the subapplication is logged in via the client device;

[0015] - enable the authentication steps contained in at least one predetermined authentication module for the sub-application to be transmitted to the client device through the server based on said access signal;

[0016] - ensure that the authentication processes entered from the client device are transmitted to the server in order to ensure that the authentication processes are compared with the reference information stored in the database; - enable reception of the signal to open a sub-application via the server in the event that the authentication processes are found to match the reference information,

[0017] - allow the application to be opened depending on the open sub-application received from the server;

[0018] - enable reception of the signal to not to open a sub-application via the server in the event that the authentication processes are found not to match the reference information,

[0019] - prevent the opening of the application depending on the signal to open the subapplication received from the server;

[0020] - enable the authentication processes entered from the client device to be recorded in the memory unit.

[0021] A possible embodiment of the invention is characterized in that management unit comprises the memory unit.

[0022] Another possible embodiment of the invention is characterized in that the management unit comprises the database unit.

[0023] Another possible embodiment of the invention is characterized in that the management unit comprises the processor unit, memory unit and database unit.

[0024] Another possible embodiment of the invention is characterized in that the processor unit is configured to enable data exchange with the server.

[0025] Another possible embodiment of the invention is characterized in that the authentication module comprises at least one authentication step that must be performed by the user.

[0026] Another possible embodiment of the invention is characterized in that the server comprises a plurality of authentication modules.

[0027] Another possible embodiment of the invention is characterized in that the authentication module is an identity card verification module.

[0028] Another possible embodiment of the invention is characterized in that the authentication module is the NFC reading module. Another possible embodiment of the invention is characterized in that the authentication module is a face authentication and vitality module.

[0029] Another possible embodiment of the invention is characterized in that the authentication module is a sound authentication and vitality module.

[0030] Another possible embodiment of the invention is characterized in that the authentication module is a fingerprint authentication module.

[0031] Another possible embodiment of the invention is characterized in that it is configured to ensure that a signal is transmitted to the processing unit that prevents the authentication steps applied for the first sub-application from being allowed to be re-applied for the second sub-application, in the event that the server determines that at least one authentication module applied for a first sub-application is identical to the authentication module applied for a second sub-application.

[0032] Another possible embodiment of the invention is characterized in that the processor unit is configured to:

[0033] - ensure that an access signal is transmitted to the server in the event that the subapplication is logged in via the client device;

[0034] - enable the authentication steps contained in at least one predetermined authentication module for the sub-application to be transmitted to the client device through the server based on said access signal;

[0035] - ensure that the authentication processes entered from the client device are transmitted to the server in order to ensure that the authentication processes are compared with the reference information stored in the database;

[0036] - enable reception of the signal to open a sub-application via the server in the event that the authentication processes are found to match the reference information,

[0037] - allow the application to be opened depending on the open sub-application received from the server;

[0038] - enable reception of the signal to not to open a sub-application via the server in the event that the authentication processes are found not to match the reference information,

[0039] - prevent the opening of the application depending on the signal to open the subapplication received from the server;

[0040] - enable the authentication processes entered from the client device to be recorded in the memory unit. BRIEF DESCRIPTION OF THE FIGURE

[0041] Figure 1 shows a representative view of the working scenario of a digital authentication system.

[0042] DETAILED DESCRIPTION OF THE INVENTION

[0043] In this detailed description, the subject matter of the invention is explained only by means of examples that will not have any limiting effect for a better understanding of the subject matter.

[0044] The invention relates to a digital authentication system (10) for providing authentication service between a main application (200) entered through a client device (100) and a plurality of sub-applications (201) integrated into said main application (200). In a possible embodiment of the invention, the said main application (200) is a super-application in the state of the art. In a possible embodiment of the invention, the sub-application (201) is a mini application in the state of the art. The user can enter the main application (200) and at least one sub-application (201) within the main application (200) through the client device (100). The client device (100) may be a mobile device such as a smartphone, a computer, a tablet, etc. in a possible embodiment of the invention.

[0045] Referring to Figure 1 , the digital authentication system (10) comprises a server (300) comprising at least one predefined authentication module for a user who has entered the main application (200) to enter at least one sub-application (201 ) within the main application (200). The at least one authentication module can be defined for a sub-application (201 ) in a possible embodiment of the invention. The authentication module for a sub-application (201) may not be defined in another possible embodiment of the invention. The authentication modules defined for each sub-application (201) within the main application (200) are stored within the server (300). Each authentication module comprises at least one authentication step that must be performed by the user. The server (300) comprises a plurality of authentication modules. The authentication module is an identity card recognition module in a possible embodiment of the invention. The authentication module is an NFC reading module in another possible embodiment of the invention. The authentication module is a face authentication and vitality module in another possible embodiment of the invention. The authentication module is a sound authentication and vitality module in another possible embodiment of the invention. The authentication module is the fingerprint authentication module in another possible embodiment of the invention.

[0046] The digital authentication system (10) comprises a management module to enable the authentication process to be performed between the main application (200) and the subapplication (201 ). The management module comprises a processor unit (403) that allows the user to generate an access signal in the event that a sub-application (201) is entered through the client device (100). The processor unit (403) enables the predetermined process steps to be performed. There are different predetermined authentication modules for each subapplication (201) within the main application (200). For example, the user may need to complete the steps of a fingerprint authentication module and the NFC reading module to enter the first sub-application (201), while the user may need to complete the steps of the identity card recognition module to enter the second sub-application (201). There may be at least one authentication module defined for at least one sub-application (201 ) within the main application (200). The sub-application (201) may not include any authentication module according to another embodiment of the invention. The predefined authentication modules for all sub-applications (201 ) within the main application (200) are kept on the server (300). The management unit (400) comprises a database (401) comprising at least one predetermined reference information so that at least one authentication step comprising at least one authentication module kept on the server (300) can be completed. The information kept in said database (401 ) comprises the reference information for comparing the authentication processes entered by the user. The reference information comprises the information that the user has previously defined to the client device (100). For example, the database (401) comprises the reference information necessary for the user-entered fingerprint to match the user's predefined fingerprint for the fingerprint authentication module. The management unit (400) comprises a memory unit (402) to enable the recording of the transactions entered through the client device (100) and the transactions made on the server (300).

[0047] The management unit (400) comprises the processor unit (403) in a possible embodiment of the invention. The management unit (400) comprises the memory unit (402) in an alternative embodiment of the invention. The management unit (400) comprises the database (401 ) in an alternative embodiment of the invention. The management unit (400) comprises the processor unit (403), the memory unit (402) and the database (401) in an alternative embodiment of the invention. The processor unit (403) is configured to enable data exchange with the database (401). The processor unit (403) is configured to enable data exchange with the memory unit (402). The processor unit (403) is configured to enable data exchange with the server (300).

[0048] The processor unit (403) allows an access signal to be transmitted to the server (300) in the event that a sub-application (201) is entered through the client device (100). The server (300) enables the authentication steps included in the predetermined authentication module for said sub-application (201) to be transmitted to the client device (100) through the processor unit (403) depending on the access signal received from the processor unit (403). It is ensured that the user enters the authentication processes for said authentication steps. The processor unit (403) allows the authentication processes entered through the client device (100) to be transmitted to the server (300). The server (300) enables the comparison of the reference information in the database (401) and the authentication processes received from the client device (100). If it is determined that the authentication processes match the reference information as a result of the comparison, the server (300) allows the transmission of a sub-application (201) signal to the processor unit (403). The processor unit (403) allows the application to be opened depending on the open sub-application (201) received from the server (300). If the server (300) detects that at least one of the authentication processes and the reference information do not match as a result of the comparison, it allows the signal to be transmitted to the processor unit (403) to open a sub-application (201 ). The processor unit (403) allows the application to be opened depending on the open sub-application (201) received from the server (300). The processor unit (403) allows the authentication processes entered from the client device (100) to be recorded in the memory unit (402). The processor unit (403) allows the transactions made on the server (300) to be recorded in the memory unit (402).

[0049] Referring to Figure 1 , the management unit (400) allows the data to be exchanged with the server (300) and the client device (100), allowing the user to perform the authentication steps specially defined for each sub-application (201) to enter the sub-applications (201) under the main application (200). The management unit (400) prevents the entry of the sub-application (201 ) if the server (300) detects that the information entered by the user and the reference information do not match. The management unit (400) allows the authentication processes made by the user to be recorded in the memory unit (402). The management unit (400) allows the transactions made through the server (300) to be recorded in the memory unit (402). Thus, it can be ensured that the data is recorded for later use. Thus, if the user enters the main application (200) once, they do not need to complete an authentication module for the first sub-application (201) again for a second sub-application (201). This prevents the loss of time for the user. Referring to Figure 1 , the processor unit (403) is configured to enable an access signal to be transmitted to the server (300) in the event that the sub-application (201 ) is entered through the client device (100); to enable the authentication steps included in at least one predetermined authentication module for the sub-application (201 ) to be transmitted to the client device (100) depending on said access signal through the server (300); to enable the authentication processes entered from the client device (100) to be compared with the reference information kept in the database (401); to enable the authentication processes and reference information to be transmitted to the server (300); to enable the receipt of a subapplication (201) open signal in the event that the authentication processes through the server (300) match the reference information, to open the application depending on the open sub-application (201) signal received from the server (300); to enable the receipt of a subapplication (201) open signal in the event that the authentication processes through the server (300) do not match the reference information, to prevent the application (201) opened depending on the opening signal from the sub-application (201) received from the server (300); to be stored in the memory unit (402) of the authentication processes entered from the client device (100).

[0050] In an exemplary operating scenario of the invention, a user enters a main application (200) comprising sub-applications (201) that can be used for the city. A bus sub-application (201) specially created for the institutions or organizations in the city within the city main application (200) includes sub-applications (201 ) such as a train sub-application (201 ), a tram sub-application (201), etc. In order for the user to enter the bus sub-application (201 ), it is necessary to complete the facial authentication and vitality module authentication steps defined on the server (300). In order for the user to enter the train sub-application (201), the face authentication and vitality module and the identity card recognition module defined in the management unit (400) must be completed. The user can enter the tram sub-application (201 ) without applying any authentication module step. If the user primarily enters the bus sub-application (201), the management unit (400) allows the face authentication and vitality module and the identity card recognition module authentication steps kept on the server (300) to be transmitted to the user through the mobile device. The identity card recognition module allows the user to enter the authentication processes first. The management unit (400) allows the authentication processes entered by the user and the previously learned and / or determined reference information kept in the database (401 ) to be transmitted to the server (300). The server (300) allows the comparison of the authentication process and the information in the database (401 ). If it is determined that the information entered by the user is the same as the reference information, it is ensured that the next face authentication and vitality module authentication steps are transmitted to the user. The user allows the face authentication and vitality module authentication processes to be entered. It is ensured that the authentication processes entered by the user are compared with the previously learned and / or determined reference information kept in the database (401). If it is determined that the information entered by the user is the same as the reference information, the bus subapplication (201) is opened.

[0051] In case the user then wants to log in to the train sub-application (201), the server (300) checks the authentication module defined for the train sub-application (201). In case the server (300) determines that the authentication module is the same as that of the bus subapplication (201), it allows the user to log in directly to the train sub-application (201).

[0052] In case the user finally wants to log in to the tram sub-application (201), the management unit (400) allows direct login.

[0053] Thus, the time loss is prevented by preventing the same operations for the sub-applications (201 ) provided within the main application (200) every time. In addition, thanks to the digital authentication system (10), it is ensured that the authentication steps are directed to the user according to the need of the sub-applications (201 ). This reduces the workload and loss of time for the user.

[0054] The protection scope of the invention is specified in the appended claims and cannot be strictly limited to those explained in this detailed description for illustrative purposes. It is evident that a person skilled in the art may exhibit similar embodiments in light of the foregoing without departing from the main theme of the invention.

[0055] REFERENCE NUMBERS GIVEN IN THE FIGURE

[0056] 10 Digital authentication system

[0057] 100 Client device 200 Main application

[0058] 201 Sub-application

[0059] 300 Server

[0060] 400 Management unit

[0061] 401 Database 402 Memory unit

[0062] 403 Processor unit

Claims

CLAIMS1. A digital authentication system (10) for providing an authentication service between a main application (200) logged in via a client device (100) and a plurality of subapplications (201 ) integrated into said main application (200), characterized in that it comprises a management unit (400) comprising a processor unit (403) for generating an access signal in the event of logging into a sub-application (201) via said client device (100), a server (300) comprising at least one predetermined authentication module for logging in to said sub-application (201); a database (401) associated with said management unit (400) comprising at least one predetermined reference information for completing at least one authentication step contained in at least one authentication module maintained on said server (300); a memory unit (402) associated with said management unit (400) for storing data; that the processor unit (403) is configured to:- ensure that an access signal is transmitted to the server (300) in the event that the sub-application (201 ) is logged in via the client device (100);- enable the authentication steps contained in at least one predetermined authentication module for the sub-application (201 ) to be transmitted to the client device (100) through the server (300) based on said access signal;- ensure that the authentication processes entered from the client device (100) are transmitted to the server (300) in order to ensure that the authentication processes are compared with the reference information stored in the database (401 );- enable reception of the signal to open a sub-application (201) via the server (300) in the event that the authentication processes are found to match the reference information,- allow the application to be opened depending on the open sub-application (201) received from the server (300);- enable reception of the signal to not to open a sub-application (201) via the server (300) in the event that the authentication processes are found not to match the reference information,- prevent the opening of the application depending on the signal to open the subapplication (201) received from the server (300);- enable the authentication processes entered from the client device (100) to be recorded in the memory unit (402).

2. A digital authentication system (10) according to claim 1 , characterized in that the management unit (400) comprises the memory unit (402).

3. A digital authentication system (10) according to claim 1 , characterized in that the management unit (400) comprises the database (401 ) unit.

4. A digital authentication system (10) according to claim 1 , characterized in that the management unit (400) comprises the processor unit (403), the memory unit (402) and the database (401) unit.

5. A digital authentication system (10) according to claim 1 , characterized in that the processor unit (403) is configured to enable data exchange with the server (300).

6. A digital authentication system (10) according to claim 1 , characterized in that the authentication module comprises at least one authentication step that must be performed by the user.

7. A digital authentication system (10) according to claim 1 , characterized in that the server (300) comprises a plurality of authentication modules.

8. A digital authentication system (10) according to claim 1 , characterized in that the authentication module is an identity card verification module.

9. A digital authentication system (10) according to claim 1 , characterized in that the authentication module is the NFC reading module.

10. A digital authentication system (10) according to claim 1 , characterized in that the authentication module is a face authentication and vitality module.

11. A digital authentication system (10) according to claim 1 , characterized in that the authentication module is a sound authentication and vitality module.

12. A digital authentication system (10) according to claim 1 , characterized in that the authentication module is a fingerprint authentication module.

13. A digital authentication system (10) according to claim 1 , characterized in that it is configured to ensure that a signal is transmitted to the processing unit (403) thatprevents the authentication steps applied for the first sub-application (201) from being allowed to be re-applied for the second sub-application (201), in the event that the server (300) determines that at least one authentication module applied for a first sub-application (201 ) is identical to the authentication module applied for a second sub-application (201).

14. A method for providing authentication between a main application (200) and the subapplication (201) according to claim 1 , characterized in that the processor unit (403) is configured to:- ensure that an access signal is transmitted to the server (300) in the event that the sub-application (201 ) is logged in via the client device (100);- enable the authentication steps contained in at least one predetermined authentication module for the sub-application (201 ) to be transmitted to the client device (100) through the server (300) based on said access signal;- ensure that the authentication processes entered from the client device (100) are transmitted to the server (300) in order to ensure that the authentication processes are compared with the reference information stored in the database (401 );- enable reception of the signal to open a sub-application (201) via the server (300) in the event that the authentication processes are found to match the reference information,- allow the application to be opened depending on the open sub-application (201) received from the server (300);- enable reception of the signal to not to open a sub-application (201) via the server (300) in the event that the authentication processes are found not to match the reference information,- prevent the opening of the application depending on the signal to open the subapplication (201) received from the server (300);- enable the authentication processes entered from the client device (100) to be recorded in the memory unit (402).