Authentication method, authentication device, and authentication system

The authentication system optimizes biometric data collection based on device access and authentication states to balance convenience and security, efficiently verifying identities with reduced verification time.

JP2026066238APending Publication Date: 2026-04-16GHOST PASS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
GHOST PASS INC
Filing Date
2025-10-03
Publication Date
2026-04-16

AI Technical Summary

Technical Problem

Existing personal authentication systems face a challenge in balancing user convenience with high security, particularly in the efficient and secure collection and verification of biometric data.

Method used

An authentication method and system that selectively collects and verifies biometric data based on the access and authentication states of the device, omitting data collection when certain conditions are met to enhance security and reduce verification time.

Benefits of technology

The system provides enhanced user convenience while maintaining high security levels by optimizing the biometric data collection process, thereby reducing identity verification time and improving user satisfaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026066238000001_ABST
    Figure 2026066238000001_ABST
Patent Text Reader

Abstract

To provide a user authentication method, authentication device, and authentication system that enhance user convenience. [Solution] The user authentication method transmits an authentication signal to monitor the server, detects updates to the access status and authentication status of the user authentication device based on the monitoring of the server, collects biometric data of the authentication means based on whether the access status to the user authentication device corresponds to ON and the authentication status corresponds to OFF, and omits the collection of biometric data of the authentication means based on whether the access status to the user authentication device corresponds to ON and the authentication status corresponds to ON.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a personal authentication method, a personal authentication device, and a personal authentication system.

Background Art

[0002] In recent years, due to the development of smart device technology including smartphones and the development of network technology, it has become an experience that can be easily accessed to collect biometric information through common devices in daily life such as smart devices and KIOSKs, perform personal authentication through biometric information, and settle for goods or receive entry / exit permission.

[0003] On the other hand, since personal authentication is fundamentally a procedure for blocking identity theft, it can be said that security is the most important element in personal authentication technology.

[0004] As a result, there is a continuous demand for the development of personal authentication technology that can provide users with procedural convenience while maintaining high security.

Summary of the Invention

Problems to be Solved by the Invention

[0005] An object of the present disclosure is to provide a personal authentication method, a personal authentication device, and a personal authentication system. The problems to be solved by the present disclosure are not limited to the problems described above, and other problems and advantages of the present disclosure not mentioned can be understood from the following description and will be more clearly understood in the embodiments of the present disclosure. Furthermore, it will be understood that the problems and advantages to be solved by the present disclosure can be realized by the means and combinations thereof shown in the claims.

Means for Solving the Problems

[0006] A first aspect of this disclosure can provide an authentication method performed by an authentication request device, which includes the steps of: transmitting an authentication signal to monitor a server; detecting updates to the access state and authentication state of an authentication device based on the monitoring of the server; and collecting authentication means biometric data based on the access state to the authentication device corresponding to ON and the authentication state corresponding to OFF, and omitting the collection of authentication means biometric data based on the access state to the authentication device corresponding to ON and the authentication state corresponding to ON.

[0007] A second aspect of this disclosure provides an authentication request device comprising a memory storing at least one program and a processor that operates by executing the at least one program, wherein the processor transmits an authentication signal to monitor a server, detects updates to the access state to an authentication device and updates to the authentication state based on the monitoring of the server, collects authentication means biometric data based on whether the access state to the authentication device corresponds to ON and the authentication state corresponds to OFF, and omits the collection of authentication means biometric data based on whether the access state to the authentication device corresponds to ON and the authentication state corresponds to ON.

[0008] A third aspect of this disclosure can provide a computer-readable recording medium that contains a program for causing a computer to perform the method according to the first aspect. [Effects of the Invention]

[0009] According to various embodiments of this disclosure, it is possible to provide an authentication system that enhances user convenience while maintaining a high level of security.

[0010] In particular, it can significantly reduce the time required for identity verification and provide a high level of satisfaction to those who experience this verification system. [Brief explanation of the drawing]

[0011] Figure 1 is a block diagram illustrating an identity verification system according to one embodiment of the present disclosure. Figure 2 is a conceptual diagram showing an example of a user performing identity verification in an identity verification system according to one embodiment of this disclosure. Figure 3 is a flowchart illustrating an identity verification procedure according to one embodiment of this disclosure. Figure 4 is a flowchart illustrating an identity verification procedure according to another embodiment of this disclosure. Figure 5 is a flowchart illustrating an identity verification procedure according to another embodiment of this disclosure. Figure 6 is a flowchart of an identity verification method according to one embodiment of the present disclosure. Figure 7 is a block diagram of an apparatus according to one embodiment of the present disclosure. [Modes for carrying out the invention]

[0012] The advantages and features of the present invention, as well as methods for achieving them, will become clear with reference to the embodiments described in detail with the accompanying drawings. However, the present invention is not limited to the embodiments presented below and can be embodied in a variety of different forms, and should be understood to include all transformations, equivalents and substitutions that fall within the spirit and technical scope of the present invention. The embodiments presented below are provided to complete the disclosure of the present invention and to fully inform those who are ordinary skill in the art to which the present invention pertains. Where it is determined that a specific description of the relevant prior art would hinder the essence of the present invention, such detailed description will be omitted.

[0013] The terms used in this application are used solely to describe specific embodiments and are not intended to limit the invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as “includes” or “having” specify the presence of features, figures, steps, actions, components, parts, or combinations thereof described herein, and should be understood not to preemptively exclude the possibility of the presence or addition of one or more other features, figures, steps, actions, components, parts, or combinations thereof.

[0014] Some embodiments of this disclosure can be represented by functional block configurations and various processing steps. Some or all of such functional blocks can be embodied by various numbers of hardware and / or software configurations that perform a particular function. For example, a functional block of this disclosure can be embodied by one or more microprocessors or by a circuit configuration for a given function. Furthermore, for example, a functional block of this disclosure can be embodied by various programming or scripting languages. A functional block can be embodied by an algorithm that runs on one or more processors. Furthermore, this disclosure can employ prior art for electronic environment setup, signal processing and / or data processing, etc. Terms such as “mechanism,” “element,” “means,” and “configuration” can be used broadly and are not limited to mechanical and physical configurations.

[0015] Furthermore, the connecting lines or members between components shown in the drawings are merely illustrative examples of functional and / or physical or circuit connections. In actual devices, connections between components may be indicated by a variety of alternative or additional functional, physical, or circuit connections.

[0016] In this disclosure, “Identity Verification System” may mean a system established to ensure the security of specific procedures that are only accessible to authorized users. In this disclosure, users may use or access the Identity Verification System through an Identity Verification Device. To enable users to use or access the Identity Verification System in this disclosure, an Identity Verification Solution, such as an Identity Verification Application, may be provided to the user, and the provided Identity Verification Solution may be installed on the Identity Verification Device.

[0017] In this disclosure, “biometric data” can mean data relating to a user’s body or products generated by a user’s use of their body, which is used to identify the user. In this disclosure, biometric data may be of any type. For example, biometric data may be any one of any type of biometric data, such as a user’s fingerprints, pupils, irises, retinas, face, voice, veins, DNA, signature, handwriting, blinking patterns, skeletal structure, ear shape, palm print patterns, body temperature patterns, gait patterns, heart rate patterns, electrocardiogram patterns, lip morphology and movement, tongue morphology and movement, electroencephalogram patterns, finger joint morphology, skin patterns and textures, kinetic signature, neural network patterns, muscle patterns, blood flow patterns, tear composition, respiratory patterns, facial blood flow patterns, etc., or a combination of two or more of any types of biometric data.

[0018] In this disclosure, “authentication biometric data” can mean biometric data that serves as a means of authentication and biometric data collected for the purpose of authentication. That is, biometric data that a user attempting authentication has permitted to be entered or collected for the purpose of authentication, and may be used to refer to data collected by a particular device. Through authentication, a user attempting authentication may enter authentication biometric data for access to restricted procedures or permit the collection of authentication biometric data. The type of authentication biometric data may be pre-configured to be used for performing authentication by the user or system.

[0019] In this disclosure, “registered biometric data” may mean biometric data that a user has registered or stored in a device owned by the user, i.e., an authentication device. Registered biometric data may also be data that serves as a criterion for determining whether the authentication device biometric data matches the data of the user attempting authentication. The type of registered biometric data may be the same as the type of authentication device biometric data. If the authentication device biometric data matches the registered biometric data, authentication may be successfully performed and access to restricted procedures may be authorized.

[0020] In one embodiment, registered biometric data may be collected via an authentication device, a part of an authentication device, or a device electrically or communicatively connected to an authentication device, and stored in the authentication device. For example, a user can store registered biometric data in the authentication device by inputting their biometric data into a data input device provided in the authentication device, such as a camera or fingerprint input device.

[0021] In other embodiments, the registered biometric data may be collected via the personal authentication request device and stored in the personal authentication device. Specifically, the registered biometric data may be collected via the personal authentication request device, transmitted to the personal authentication device (or the personal authentication device via the server), and stored in the personal authentication device. The registered biometric data stored through this procedure may also be used to perform the personal authentication procedure by the system of the present disclosure hereinafter. For example, for the first authentication for the use of the personal authentication system, the personal authentication device can collect data as the "registered biometric data" of the user, and later when the user attempts to authenticate for the use of the personal authentication system, the personal authentication device can collect data as the "biometric data of the authentication means" of the user. Even if the types of the registered biometric data are the same (for example, face), the specifications of the sensors for collecting data may be different for each device. Therefore, according to this embodiment, the accuracy of the identity verification between the registered biometric data and the biometric data of the authentication means can be improved.

[0022] In one embodiment, in order for the registered biometric data to be stored in the personal authentication device, a user confirmation procedure can be executed. The user confirmation procedure is a procedure that must be accompanied in order to utilize the personal authentication system of the present disclosure and access the personal authentication system of the present disclosure, and can be understood as a kind of service registration procedure. In one embodiment, only the user who has executed the user confirmation procedure can store the registered biometric data in their own terminal, or only the terminal of the user who has executed the user confirmation procedure can store the registered biometric data.

[0023] In one embodiment, the user confirmation procedure can include an identity card verification procedure.

[0024] In one embodiment, the identity document verification procedure can include an identity document authenticity verification procedure. The identity document authenticity verification procedure may be a procedure for verifying whether the identity document held by the user is a forged identity document. The identity document authenticity verification procedure may be executed through image capture of the identity document via a camera or sensor of the user terminal. For example, image capture of the identity document and the identity document authenticity verification procedure may be executed through an identity verification solution such as a personal authentication application.

[0025] In one embodiment, the identity document verification procedure can include an identity document comparison procedure. The identity document comparison procedure may be a procedure for verifying whether the identity document held by the user is the user's identity document. The identity document comparison procedure may be executed through image capture of the user's face via a camera or sensor of the user terminal. For example, image capture of the user's face and the identity document comparison procedure may be executed through an identity verification solution such as a personal authentication application.

[0026] The authentication method of the present disclosure will be described below.

[0027] The personal authentication system of the present disclosure can be based on various authentication methods according to the subject that determines the presence or absence of matching of biometric data.

[0028] First, the identity verification system of this disclosure may be based on a user terminal authentication method (or an identity verification device authentication method). The user terminal authentication method may mean a method in which the user terminal, i.e., the identity verification device, determines whether or not the authentication means biometric data matches the registered biometric data. The user terminal can determine whether or not the authentication means biometric data matches the registered biometric data by comparing the registered biometric data stored in the user terminal with the authentication means biometric data received from another device. Here, the other device may be any one of the identity verification request device, the server, and the third device. The user terminal may also transmit the result value of the comparison to the other device (which may be the same device as the "other device" mentioned above), and the device that receives the result value may permit or deny access to restricted procedures based on the result value.

[0029] Next, the identity verification system of this disclosure may be based on an identity verification request device authentication scheme. An identity verification request device authentication scheme may mean a scheme in which the identity verification request device determines whether or not the authentication means biometric data matches the registered biometric data. The identity verification request device can determine whether or not the authentication means biometric data matches the registered biometric data by comparing the authentication means biometric data collected through the identity verification request device, a part of the identity verification request device, or a device electrically or communicatively connected to the identity verification request device with the registered biometric data received from another device. Here, the other device may be any one of the user terminal (i.e., the identity verification device), a server, and a third device. The identity verification request device may grant or deny access to restricted procedures based on the result value of the comparison, or it may transmit the result value of the comparison to another device (which may be the same device as the “other device” mentioned above), and the device that receives the result value may grant or deny access to restricted procedures based on the result value.

[0030] Next, the user authentication system of this disclosure may be based on a server authentication method. A server authentication method may mean a method in which a server determines whether or not the authentication means biometric data matches the registered biometric data. The server can determine whether or not the authentication means biometric data matches the registered biometric data by comparing the authentication means biometric data received from the user authentication request device with the registered biometric data from the user terminal (i.e., the user authentication device). The server may grant or deny access to restricted procedures based on the result of the comparison, or it may transmit the result of the comparison to another device, which may then grant or deny access to restricted procedures based on the result.

[0031] Furthermore, the identity verification system of this disclosure may be based on an identity verification device authentication method. An identity verification device authentication method may mean a method in which the identity verification device determines whether or not the authentication means biometric data matches the registered biometric data. The identity verification device may be a device provided separately from the user terminal (or identity verification device) or identity verification request device, and may not perform any other functions, but may be a device provided separately for the purpose of performing identity verification. The identity verification device can receive and store the registered biometric data from the user terminal, and thereafter determine whether or not the authentication means biometric data matches the registered biometric data by comparing the authentication means biometric data with the registered biometric data that is received. The identity verification device may transmit the result value of the comparison to another device, and the device that receives the result value may permit or deny access to restricted procedures based on the result value. Here, the other device may be any one of the user terminal, identity verification request device, server, and third device.

[0032] Figure 1 is a block diagram illustrating an identity verification system according to one embodiment of the present disclosure.

[0033] The identity verification system described herein may include an identity verification device 10 and an identity verification request device 20.

[0034] In this disclosure, the authentication device 10 may mean a device owned by the user performing the authentication. The authentication device 10 can be understood as a user terminal, where the user's terminal may include any type of device capable of storing registered biometric data or determining whether biometric data matches through comparison between biometric data. For example, the authentication device 10 may be, but is not limited to, a smartphone, mobile phone, tablet PC, PC, PDA (personal digital assistant), laptop, media player, GPS (global positioning system) device, smart glasses, smartwatch, camera or other device equipped with an input / output interface, and other mobile or non-mobile electronic devices.

[0035] In this disclosure, the user authentication request device 20 may mean a device that requests to perform user authentication. The user authentication request device 20 can detect a user who accesses the user authentication request device 20 (physically or electronically). The user authentication request device 20 can collect authentication means biometric data from the user. The user authentication request device 20 can transmit the authentication means biometric data to other devices or determine whether the biometric data matches through comparison between the biometric data. For example, the user authentication request device 20 may be, but is not limited to, a smartphone, mobile phone, tablet PC, PC, PDA, laptop, media player, GPS device, smart glasses, smartwatch, wearable device such as a hairband or ring with communication and data processing functions, a device equipped with an input / output interface such as a camera, and other mobile or non-mobile electronic devices.

[0036] In this disclosure, the authentication system may be used to grant access to procedures restricted to users who have successfully authenticated their identity, and the application of the authentication system, i.e., the procedures restricted by the authentication system, may be any procedures that require security compliance.

[0037] For example, the procedure restricted by the identity verification system may be "payment," and mobile payments may be automatically approved for users who have successfully verified their identity. For example, the procedure restricted by the identity verification system may be "entry and exit," and entry and exit may be permitted, such as opening an entry / exit gate, for users who have successfully verified their identity. For example, the procedure restricted by the identity verification system may be "vehicle control," and vehicle control may be permitted, such as allowing only users who have successfully verified their identity to start the vehicle's engine. For example, the procedure restricted by the identity verification system may be "purchase of items from a vending machine," and purchase of items may be permitted, such as allowing only users who have successfully verified their identity to select items from a vending machine. In addition to the examples given above, the identity verification system of this disclosure may be applied to any procedure for which security compliance is required.

[0038] In this disclosure, the user authentication request device 20 may be embodied in such a way as to be able to induce user authentication for access to restricted procedures through interaction with the user, such as an electronic kiosk. Thus, the user authentication request device 20 may be embodied in a variety of forms depending on the application of the user authentication system, i.e., where it is used.

[0039] For example, if the procedure restricted by the authentication system is "payment," the authentication request device 20 may be implemented in the form of a POS (point of sales) terminal. For example, if the procedure restricted by the authentication system is "entry and exit," the authentication request device 20 may be implemented in the form of an entry / exit gate or an electronic device provided together with an entry / exit gate. For example, if the procedure restricted by the authentication system is "vehicle control," the authentication request device 20 may be implemented in the form of an on-board computer installed in the vehicle. For example, if the procedure restricted by the authentication system is "purchase of goods from a vending machine," the authentication request device 20 may be implemented in the form of a vending machine.

[0040] In the user authentication system of this disclosure, the user authentication device 10 and the user authentication request device 20 can each transmit and receive data via the network 30. The network 30 may be a wired network such as a Local Area Network (LAN), Wide Area Network (WAN), or Value Added Network (VAN), or a wireless network such as a mobile radio communication network, Near Field Communication network, or satellite communication network. Furthermore, the network 30 is a comprehensive data communication network that enables each network component shown in Figure 1 to communicate smoothly with one another, and includes any type of wired internet, wireless internet, and mobile wireless communication network.

[0041] Although not shown in Figure 1, the user authentication system may include a server. The server can control the entire user authentication system, and the user authentication system may further include a server for reasons such as ease of data storage, data distribution, design limitations, and ease of design. In one embodiment, the user authentication device 10 or the user authentication request device 20 may send or receive some or all of the data to be sent or received via the server, rather than sending or receiving it directly to each other.

[0042] Figure 2 is a conceptual diagram showing an example of a user performing identity verification in an identity verification system according to one embodiment of this disclosure.

[0043] For convenience, the example shown in Figure 2 is explained as an example where the procedure restricted by the identity verification system is "entry and exit," but it is not limited to this.

[0044] Referring to Figure 2, User 1 may possess the personal authentication device 10. The personal authentication device 10 may store registered biometric data.

[0045] User 1 can access the personal authentication request device 20. For example, User 1 may access the personal authentication request device 20 in order to release the blockage of the entry / exit gate and pass through the entry / exit gate.

[0046] The user authentication request device 20 can detect access by user 1. For example, the user authentication request device 20 can detect access by user 1 through a camera or sensor mounted on or connected to the user authentication request device 20. For example, the user authentication request device 20 can detect access by transmitting specific data or signals (e.g., authentication signals described later).

[0047] The user authentication request device 20, upon detecting access by user 1, can collect user 1's authentication means biometric data. User 1 can input their own biometric data through a camera, sensor, or other input / output interface mounted on or connected to the user authentication request device 20.

[0048] If the user authentication system is based on a user terminal authentication method, the user authentication request device 20 can transmit the collected authentication means biometric data to the user authentication device 10. Upon receiving the authentication means biometric data, the user authentication device 10 can compare the received authentication means biometric data with the stored registered biometric data. The user authentication device 10 can then generate a result value for the comparison.

[0049] If the personal authentication system is based on the personal authentication request device authentication method, the personal authentication request device 20 can receive registered biometric data from the personal authentication device 10. The personal authentication request device 20 can send a signal to the personal authentication device 10 requesting the registered biometric data. Upon receiving the signal requesting the registered biometric data, the personal authentication device 10 can send the registered biometric data to the personal authentication request device 20. Upon receiving the registered biometric data, the personal authentication request device 20 can compare the received registered biometric data with the collected authentication means biometric data. The personal authentication request device 20 can generate a result value for the comparison.

[0050] In the example shown in Figure 2, the entry / exit status of user 1 may be determined by the generated result value. For example, if the generated result value corresponds to the two biometric data matching, the entry / exit gate may be deactivated for user 1. For example, if the generated result value corresponds to the two biometric data not matching, the entry / exit gate may remain deactivated for user 1.

[0051] On the other hand, the user authentication system may also require additional authentication procedures in addition to authentication through biometric data. For example, if the security level of the area the user is trying to enter or exit is higher than that of other areas, or if the amount the user is trying to pay is higher than a predetermined amount, the user authentication system may require the user to perform additional authentication procedures when necessary for security reasons. In one embodiment, additional authentication procedures may only be required if the registered biometric data and the authentication means biometric data match.

[0052] In one embodiment, the additional authentication procedure may include an identity verification procedure. The identity verification procedure may be a procedure for verifying whether the identity document held by the user is the user's identity document. The identity verification procedure may include capturing an image of the identity document through a camera or sensor of the identity authentication device 10 or identity authentication request device 20, capturing an image of the user's face, and comparing the image of the identity document with the image of the face.

[0053] On the other hand, in an identity authentication system, a problem may arise regarding how to identify the identity authentication device 10. In other words, a problem may arise regarding how the identity authentication request device 20 identifies the target to whom it requests the transmission of collected authentication biometric data or registered biometric data.

[0054] In one embodiment, the user authentication request device 20 can identify the user authentication device 10 based on identification information entered by the user 1. In this embodiment, the user authentication request device 20 may include an interface into which the user 1 can input device identification data, and can receive the input of device identification data from the user 1 through the interface. The device identification data may be data used to identify the user's terminal, i.e., the user authentication device. For example, the device identification data may include one or more of the following: a telephone number, a membership number, or a resident registration number.

[0055] In another embodiment, the user authentication request device 20 can identify the user authentication device 10 by detecting the nearest device. In this embodiment, the user authentication request device 20 can detect the nearest device through any suitable method. For example, the user authentication request device 20 may include a plurality of nodes or channels and can measure distance based on signals transmitted and received between the plurality of nodes or channels and the user authentication device. For example, the plurality of nodes or channels may be nodes or channels for transmitting and receiving beacon signals.

[0056] In another embodiment, the user authentication request device 20 can identify the user authentication device 10 based on a prearranged sound signal. In this embodiment, the prearranged sound signal can mean a sound signal that the user authentication device 10 can detect in the user authentication system. The user authentication device 10 can detect the sound signal and determine whether the detected sound signal is a prearranged sound signal transmitted by the user authentication request device 20. If the user authentication device 10 determines that the detected sound signal is a prearranged sound signal, it can transmit device identification data of the user authentication device 10 to the user authentication request device 20 or the server. The user authentication request device 20 can identify the user authentication device 10 based on the device identification data.

[0057] On the other hand, the various embodiment of the identity authentication system described below may include a plurality of identity authentication request devices, each performing identity authentication. Here, the plurality of identity authentication request devices may constitute a single overall identity authentication system, rather than each constituting an individual system. The plurality of identity authentication request devices may be understood as multiple devices when observed physically or externally, but may also be substantially a single device connected to each other by wire or wireless. For example, as will be described later, the first identity authentication request device 21, the second identity authentication request device 22, and the third identity authentication request device 23 may be understood as the aforementioned identity authentication request device 20 or as part of the identity authentication request device 20. The first identity authentication request device 21, the second identity authentication request device 22, and the third identity authentication request device 23 may be understood as separate entities for the convenience of describing their respective embodiments.

[0058] An authentication system according to one embodiment of this disclosure may include a primary authentication request device and a secondary authentication request device. The secondary authentication request device can perform authentication for users for whom primary authentication has not been successfully performed. Failure of primary authentication may include cases in which the user engages in fraudulent activity or procedural errors occur. This embodiment may be embodied through various embodiments of authentication systems described in this disclosure. This embodiment will be described in detail later.

[0059] An authentication system according to one embodiment of this disclosure may include a main authentication request device and one or more auxiliary authentication request devices. The main authentication request device is a device that performs the entire authentication procedure, and an auxiliary authentication request device may mean a device that performs the authentication procedure with some parts omitted for an authentication device that has performed authentication based on the main authentication request device. For example, as will be described later, the first authentication request device 21 is the main authentication request device, and the second authentication request device 22 and the third authentication request device 23 may each be an auxiliary authentication request device.

[0060] For example, the personal authentication system of this embodiment may be applied to an access-restricted area, where the main authentication request device corresponds to a main access-blocking gate, and each of the one or more auxiliary authentication request devices may correspond to one or more auxiliary access-blocking gates. The main authentication request device can control the operation of the corresponding main access-blocking gate, and the auxiliary authentication request devices can control the operation of the corresponding auxiliary access-blocking gates.

[0061] For example, the restricted access area may be a building containing one or more workplaces. In this example, the main access control gate may be located on the first floor of the building, and auxiliary access control gates may be located on each of the remaining floors. Workers working at the first workplace may only be able to enter and exit from the floor where the first workplace is located, and workers working at the second workplace may only be able to enter and exit from the floor where the second workplace is located. This may result in workers working at both the first and second workplaces being able to pass through the main access control gate, but being prevented from passing through the auxiliary access control gates on other floors that do not belong to their workplace.

[0062] For example, the restricted access area may be a residence containing one or more households, such as an apartment building. In this example, the main access gate may be located at the common entrance of the residence, and auxiliary access gates may be located for each household or for each remaining floor. Residents of the first household may be restricted to accessing only the first household or the floor corresponding to the first household, and residents of the second household may be restricted to accessing only the second household or the floor corresponding to the second household. This may be controlled so that residents of both the first and second households can pass through the main access gate, but cannot pass through the auxiliary access gates of other households or floors corresponding to other households.

[0063] Figure 3 is a flowchart illustrating an identity verification procedure according to one embodiment of this disclosure.

[0064] The user authentication procedure shown in Figure 3 may be performed by the first user authentication request device 21, the server 40, and the user authentication device 10. The first user authentication request device 21 may be understood as a user authentication request device corresponding to the place where the user first enters or exits the restricted access area, and may correspond to the main access control gate mentioned above.

[0065] In one embodiment, in step 301, the first personal authentication request device 21 can transmit an authentication signal and monitor the server 40.

[0066] In one embodiment, the first user authentication request device 21 may transmit an authentication signal to detect access from the user authentication device 10 or a user. The authentication signal may be configured so that the user authentication device 10 can perform a corresponding action upon receiving it. Here, the corresponding action may be the transmission of a status update request signal and an authentication status, as will be described later.

[0067] In one embodiment, the first user authentication request device 21 may monitor the server 40 in order to detect changes in specific data on the server 40. As will be described later, by monitoring the server 40, the first user authentication request device 21 can detect when the state of the user authentication device 10 is updated, and through this, it can detect that the user authentication device 10 or a user has accessed it.

[0068] In one embodiment, in step 302, the personal authentication device 10 can receive an authentication signal.

[0069] In one embodiment, the personal authentication device 10 can receive an authentication signal transmitted by the first personal authentication request device 21. The personal authentication device 10 may include an interface that can receive the authentication signal transmitted by the first personal authentication request device 21.

[0070] On the other hand, the authentication signals transmitted and received by the first personal authentication request device 21 and the personal authentication device 10 may be based on any communication method or of any type. For example, the authentication signals may be transmitted and received by beacons. As another example, the authentication signals may be based on near-field communication (NFC).

[0071] In this disclosure, with respect to the authentication signals transmitted and received by the first personal authentication request device 21 and the personal authentication device 10, the personal authentication device 10 may be implemented in such a way that merely transmitting and receiving the authentication signals means that the personal authentication device 10 is in close proximity to the first personal authentication request device 21, or the personal authentication device 10 may be implemented in such a way that the proximity to the first personal authentication request device 21 is calculated based on the strength and position of the transmitted and received authentication signals, the time required for transmitting and receiving the authentication signals, etc.

[0072] On the other hand, at this time, the authentication status of the personal authentication device 10 can correspond to OFF. In this disclosure, the authentication status may be a state relating to whether the corresponding personal authentication device 10 has successfully performed personal authentication in relation to the first personal authentication request device 21, or, as a specific example, whether the user of the personal authentication device 10 has passed through the main access control gate. The authentication status may be stored in the personal authentication device 10.

[0073] As shown in Figure 3, the authentication state value may be 0 ("Authentication state: 0") in the sense that the authentication state corresponds to OFF.

[0074] In one embodiment, in step 303, the user authentication device 10 can send an access status update request signal and an authentication status to the server 40.

[0075] In one embodiment, the user authentication device 10 may transmit an access status update request signal based on the reception of an authentication signal. The access status update request signal may be a signal to request the server 40 to update the access status of the user authentication device 10 by indicating that an authentication signal has been received. The user authentication device 10 may include an interface on which it can transmit the access status update request signal.

[0076] In one embodiment, the user authentication device 10 can trigger the first user authentication request device 21 to collect authentication means biometric data by transmitting an access status update request signal. As will be described later, the server 40 updates its access status in response to the access status update request signal transmitted by the user authentication device 10, and the user authentication request device 20 can detect the update of the server 40's access status.

[0077] In one embodiment, in step 304, the server 40 can update the access status and authentication status of the user authentication device 10.

[0078] In one embodiment, the server 40 can update the access state and authentication state corresponding to the user authentication device 10 based on receiving an access state update request signal and an authentication state from the user authentication device 10.

[0079] In the embodiment shown in Figure 3, the server 40 can update the access state to correspond to ON based on a request from the user authentication device 10. The server 40 can also update the authentication state in response to the authentication state transmitted by the user authentication device 10. Specifically, in the embodiment shown in Figure 3, since the authentication state of the user authentication device 10 corresponds to OFF, the server 40 can update the authentication state to correspond to OFF.

[0080] In one embodiment, in step 305, the first user authentication request device 21 can detect updates to the access status and authentication status.

[0081] As described above, the first personal authentication request device 21 can monitor the server 40 and detect changes in specific data on the server 40, where the changes in specific data may relate to the state of the personal authentication device 10 updated by the server 40, specifically the access state and authentication state of the personal authentication device 10.

[0082] In one embodiment, in step 306, the first personal authentication request device 21 can collect authentication means biometric data.

[0083] The first user authentication request device 21 can collect authentication biometric data based on detecting an update in the access state. In other words, the first user authentication request device 21 may be deemed to have accessed the system when it detects an update in the access state.

[0084] In one embodiment, in step 307, the first personal authentication request device 21 can transmit the collected authentication means biometric data to the server 40.

[0085] In one embodiment, the biometric data of the authentication means that the first personal authentication request device 21 transmits to the server 40 may be landmark data.

[0086] In one embodiment, the first personal authentication request device 21 can delete the authentication means biometric data based on the transmission of the collected authentication means biometric data.

[0087] In one embodiment, in step 308, the server 40 can send a message to the user authentication device 10.

[0088] In one embodiment, the server 40 can send a message to the authentication device 10 based on receiving authentication means biometric data from the first authentication request device 21.

[0089] In one embodiment, the message that the server 40 sends to the authentication device 10 may be a message relating to the collection of biometric data of the authentication means. The message that the server 40 sends to the authentication device 10 may also be a message instructing or guiding the authentication device 10 to download the biometric data of the authentication means from the server 40, as will be described later.

[0090] In one embodiment, the message that the server 40 sends to the authentication device 10 may be a push notification or a push message. The server 40 can send a message to the authentication device 10 based on any environment or service suitable for sending push notifications or push messages. For example, the server 40 can send a message to the authentication device 10 based on the FCM (firebase cloud messaging) service, but is not limited to this.

[0091] In one embodiment, in step 309, the personal authentication device 10 can download the authentication means biometric data.

[0092] In one embodiment, the user authentication device 10 can download authentication biometric data from the server 40 based on receiving a message from the server 40. Of course, the authentication biometric data downloaded by the user authentication device 10 may be the authentication biometric data that the first user authentication request device 21 sent to the server 40.

[0093] In one embodiment, in step 310, the personal authentication device 10 can compare the authentication means biometric data with the registered biometric data.

[0094] In one embodiment, the user authentication device 10 can compare the authentication means biometric data downloaded from the server 40 with the registered biometric data stored in the user authentication device 10. The user authentication device 10 may compare the authentication means biometric data with the registered biometric data in order to determine whether the authentication means biometric data and the registered biometric data match.

[0095] In one embodiment, the personal authentication device 10 can determine that the biometric data of the authentication means and the registered biometric data match if the matching rate between the biometric data of the authentication means and the registered biometric data is equal to or greater than a preset value, and can determine that the biometric data of the authentication means and the registered biometric data do not match if the matching rate between the biometric data of the authentication means and the registered biometric data is less than a preset value.

[0096] On the other hand, in one embodiment, the downloaded authentication biometric data may be deleted after step 310. That is, the downloaded authentication biometric data may be deleted immediately after being compared with the registered biometric data as one-time data.

[0097] In one embodiment, in step 311, the personal authentication device 10 can change the authentication state based on whether the biometric data of the authentication means matches the registered biometric data.

[0098] Specifically, the user authentication device 10 can change the authentication state to correspond to ON based on the successful execution of user authentication. As shown in Figure 3, the value of the authentication state may be 1 ("Authentication state: 1") in the sense that the authentication state corresponds to ON.

[0099] In one embodiment, in step 312, the user authentication device 10 can send the result value for the comparison to the server 40.

[0100] The result of the user authentication device 10 comparing the authentication means biometric data and the registered biometric data will be either a match or a mismatch, and the result value for the comparison may also correspond to either a match or a mismatch. However, according to step 311, since the authentication means biometric data and the registered biometric data match, in the embodiment shown in Figure 3, the result value for the comparison transmitted by the user authentication device 10 will be a value corresponding to a match.

[0101] In one embodiment, in step 313, the server 40 can update the result value.

[0102] In one embodiment, the server 40 can update the result value based on receiving the result value from the user authentication device 10.

[0103] In one embodiment, the server 40 can configure a data structure for updating the result value corresponding to the received authentication means biometric data based on receiving the authentication means biometric data from the first personal authentication request device 21 in step 307. Thereafter, in step 313, the result value can be updated based on the configured data structure based on receiving the result value for comparison from the personal authentication device 10.

[0104] In one embodiment, in step 314, the first user authentication request device 21 can detect the server's result value update.

[0105] After step 314, the user authentication request device 20 can decide whether to grant or deny access to the restricted procedure based on the updated result value.

[0106] Figure 4 is a flowchart illustrating an identity verification procedure according to another embodiment of this disclosure.

[0107] The user authentication procedure shown in Figure 4 may be performed by the second user authentication request device 22, the server 40, and the user authentication device 10. The second user authentication request device 22 may be understood as an additional user authentication request device provided after the user has entered or exited the restricted access area, and may correspond to the auxiliary access control gate mentioned above.

[0108] The authentication procedure shown in Figure 4 may be an authentication procedure performed on the authentication device 10 on which the authentication procedure shown in Figure 3 has been performed.

[0109] In one embodiment, in step 401, the second personal authentication request device 22 can transmit an authentication signal and monitor the server 40.

[0110] As described above with reference to Figure 3, in one embodiment, the second authentication request device 22 may transmit an authentication signal to detect access from the authentication device 10 or a user. The authentication signal may be configured such that the authentication device 10 can perform a corresponding action upon receiving it.

[0111] In one embodiment, the second user authentication request device 22 may monitor the server 40 in order to detect changes in specific data on the server 40. As will be described later, by monitoring the server 40, the second user authentication request device 22 can detect when the state of the user authentication device 10 is updated, and through this, it can detect that the user authentication device 10 or a user has accessed it.

[0112] In one embodiment, in step 402, the personal authentication device 10 can receive an authentication signal.

[0113] As described above with reference to Figure 3, in one embodiment, the personal authentication device 10 can receive an authentication signal transmitted by the second personal authentication request device 22. The personal authentication device 10 may include an interface that can receive the authentication signal transmitted by the second personal authentication request device 22.

[0114] A detailed explanation of the authentication signal has been given above, so it will be omitted here.

[0115] On the other hand, at this time, the authentication state of the personal authentication device 10 can correspond to ON. That is, the authentication state stored in the personal authentication device 10 can correspond to ON. This may be because, as mentioned above, the personal authentication procedure shown in Figure 4 is the personal authentication procedure that is executed on the personal authentication device 10 on which the personal authentication procedure shown in Figure 3 has been executed.

[0116] As shown in Figure 4, the authentication state value may be 1 ("Authentication state: 1") in the sense that the authentication state corresponds to ON.

[0117] A detailed explanation of the authentication status has been given above, so it will be omitted here.

[0118] In one embodiment, in step 403, the user authentication device 10 can send an access status update request signal and an authentication status to the server 40.

[0119] As described above with reference to Figure 3, in one embodiment, the user authentication device 10 can transmit an access status update request signal based on the receipt of an authentication signal.

[0120] A detailed explanation of the access status update request signal has been given above and will therefore be omitted here.

[0121] On the other hand, in Figure 4, since the authentication state of the user authentication device 10 corresponds to ON, the authentication state that the user authentication device 10 sends to the server 40 can also correspond to ON.

[0122] In one embodiment, in step 404, the server 40 can update the access status and authentication status of the user authentication device 10.

[0123] In one embodiment, the server 40 can update the access state and authentication state corresponding to the user authentication device 10 based on receiving an access state update request signal and an authentication state from the user authentication device 10.

[0124] In the embodiment shown in Figure 4, the server 40 can update the access state to correspond to ON based on a request from the user authentication device 10. The server 40 can also update the authentication state in response to the authentication state transmitted by the user authentication device 10. Specifically, in the embodiment shown in Figure 4, since the authentication state of the user authentication device 10 corresponds to ON, the server 40 can update the authentication state to correspond to ON.

[0125] In one embodiment, in step 405, the second user authentication request device 22 can detect updates to the access status and authentication status.

[0126] As described above, the second personal authentication request device 22 can monitor the server 40 and detect changes in specific data on the server 40, where the changes in specific data may be related to the state of the personal authentication device 10 updated by the server 40, specifically the access state and authentication state of the personal authentication device 10.

[0127] Here, since the authentication status of the personal authentication device 10 transmitted by the personal authentication device 10 corresponds to ON, the updated authentication status detected by the second personal authentication request device 22 can also correspond to ON.

[0128] In one embodiment, the second personal authentication request device 22 may omit the collection of authentication means biometric data based on the detected updated authentication state corresponding to ON. This may be because the authentication state of the personal authentication device 10 corresponding to ON means that personal authentication has already been performed on the personal authentication device 10 through comparison of authentication means biometric data.

[0129] In one embodiment, in step 406, the second user authentication request device 22 can view the user's privileges.

[0130] In one embodiment, the second user authentication request device 22 can determine, based on the updated access status, that a user of the user authentication device 10 has accessed the device, and can also determine, based on the updated authentication status, that a user of the user authentication device 10 has already performed authentication. Based on the determination that a user of the user authentication device 10 has accessed the device, and that a user of the user authentication device 10 has already performed authentication, the second user authentication request device 22 can view the user's privileges on the user authentication device 10. For example, the second user authentication request device 22 can view the user's privileges on the user authentication device 10 stored on the server 40. Viewing the user's privileges may be to determine whether the user has the privileges to access procedures restricted by the second user authentication request device 22.

[0131] In one embodiment, the second user authentication request device 22 can view the user's privileges by monitoring the server 40. In step 313 of Figure 3 described above, the server 40 can obtain the user's privileges, and the second user authentication request device 22 can view the obtained user privileges.

[0132] In one embodiment, in step 407, the second user authentication request device 22 may perform a procedure corresponding to the authentication status and user authority.

[0133] Specifically, the second user authentication request device 22 may, based on the authentication state being ON and the user having the authority to perform the procedure restricted by the second user authentication request device 22, omit the collection of biometric data from the authentication means and permit access to the restricted procedure. Conversely, the second user authentication request device 22 may, based on the authentication state being ON and the user not having the authority to perform the procedure restricted by the second user authentication request device 22, refrain from collecting biometric data from the authentication means but deny access to the restricted procedure.

[0134] Figure 5 is a flowchart illustrating an identity verification procedure according to another embodiment of this disclosure.

[0135] The user authentication procedure shown in Figure 5 may be performed by the third user authentication request device 23, the server 40, and the user authentication device 10. The third user authentication request device 23 may be understood as a user authentication request device installed in the area where the user exits the restricted access area after having entered or exited the restricted access area, and may correspond to the main access control gate or an auxiliary access control gate installed near the main access control gate.

[0136] The authentication procedure shown in Figure 5 may be an authentication procedure performed on the authentication device 10 on which the authentication procedure shown in Figure 3 has been performed.

[0137] In one embodiment, in step 501, the third user authentication request device 23 can transmit an authentication signal and monitor the server 40.

[0138] As described above with reference to Figures 3 and 4, in one embodiment, the third authentication request device 23 may transmit an authentication signal to detect access from the authentication device 10 or a user. The authentication signal may be configured such that the authentication device 10 can perform a corresponding action upon receiving it.

[0139] In one embodiment, the third user authentication request device 23 may monitor the server 40 in order to detect changes in specific data on the server 40. As will be described later, by monitoring the server 40, the third user authentication request device 23 can detect when the state of the user authentication device 10 is updated, and through this, it can detect that the user authentication device 10 or a user has accessed it.

[0140] In one embodiment, in step 502, the personal authentication device 10 can receive an authentication signal.

[0141] As described above with reference to Figures 3 and 4, in one embodiment, the personal authentication device 10 can receive an authentication signal transmitted by the third personal authentication request device 23. The personal authentication device 10 may include an interface that can receive the authentication signal transmitted by the third personal authentication request device 23.

[0142] A detailed explanation of the authentication signal has been given above, so it will be omitted here.

[0143] On the other hand, at this time, the authentication state of the personal authentication device 10 can correspond to ON. That is, the authentication state stored in the personal authentication device 10 can correspond to ON. This may be because, as mentioned above, the personal authentication procedure shown in Figure 5 is the personal authentication procedure that is executed on the personal authentication device 10 on which the personal authentication procedure shown in Figure 3 has been executed.

[0144] As shown in Figure 5, the authentication state value may be 1 ("Authentication state: 1") in the sense that the authentication state corresponds to ON.

[0145] A detailed explanation of the authentication status has been given above, so it will be omitted here.

[0146] In one embodiment, in step 503, the user authentication device 10 can send an access status update request signal and an authentication status to the server 40.

[0147] As described above with reference to Figures 3 and 4, in one embodiment, the user authentication device 10 can transmit an access status update request signal based on the receipt of an authentication signal.

[0148] A detailed explanation of the access status update request signal has been given above and will therefore be omitted here.

[0149] On the other hand, in Figure 5, since the authentication state of the user authentication device 10 corresponds to ON, the authentication state that the user authentication device 10 sends to the server 40 can also correspond to ON.

[0150] In one embodiment, in step 504, the server 40 can update the access status and authentication status of the user authentication device 10.

[0151] In one embodiment, the server 40 can update the access state and authentication state corresponding to the user authentication device 10 based on receiving an access state update request signal and an authentication state from the user authentication device 10.

[0152] In the embodiment shown in Figure 5, the server 40 can update the access status to correspond to ON based on a request from the user authentication device 10.

[0153] In one embodiment, in step 505, the third user authentication request device 23 can detect updates to the access status and authentication status. The server 40 can also update the authentication status in response to the authentication status transmitted by the user authentication device 10. Specifically, in the embodiment shown in Figure 5, since the authentication status of the user authentication device 10 corresponds to ON, the server 40 can update the authentication status to correspond to ON.

[0154] As described above, the third personal authentication request device 23 can monitor the server 40 and detect changes in specific data on the server 40, where the changes in specific data may relate to the state of the personal authentication device 10 updated by the server 40, specifically the access state and authentication state of the personal authentication device 10.

[0155] Here, since the authentication status of the personal authentication device 10 transmitted by the personal authentication device 10 corresponds to ON, the updated authentication status detected by the third personal authentication request device 23 can also correspond to ON.

[0156] In one embodiment, the third user authentication request device 23 may omit the collection of authentication means biometric data based on the detected updated authentication state corresponding to ON. This may be because the authentication state of the user authentication device 10 corresponding to ON means that user authentication has already been performed on the user authentication device 10 through comparison of authentication means biometric data.

[0157] In one embodiment, in step 506, the third user authentication request device 23 can view the user's privileges.

[0158] In one embodiment, the third user authentication request device 23 can determine that a user of the user authentication device 10 has accessed the device based on the updated access status, and can also determine that a user of the user authentication device 10 has already performed authentication based on the updated authentication status. Based on the determination that a user of the user authentication device 10 has accessed the device and that a user of the user authentication device 10 has already performed authentication, the third user authentication request device 23 can view the user's privileges on the user authentication device 10. For example, the third user authentication request device 23 can view the user's privileges on the user authentication device 10 stored on the server 40. Viewing the user's privileges may be to determine whether the user has the privilege to access a procedure restricted by the third user authentication request device 23. On the other hand, in the embodiment shown in Figure 5, the procedure restricted by the third user authentication request device 23 may be the user's exit.

[0159] In one embodiment, the third user authentication request device 23 can view the user's privileges by monitoring the server 40. In step 313 of Figure 3 described above, the server 40 can obtain the user's privileges, and the third user authentication request device 23 can view the obtained user privileges.

[0160] In one embodiment, in step 507, the third user authentication request device 23 may perform a procedure corresponding to the authentication status and user authority.

[0161] Specifically, the third user authentication request device 23 may, based on the authentication state being ON and the user having the authority to perform the procedure restricted by the third user authentication request device 23, omit the collection of biometric data from the authentication means and permit access to the restricted procedure. Conversely, the third user authentication request device 23 may, based on the authentication state being ON and the user not having the authority to perform the procedure restricted by the third user authentication request device 23, not perform the collection of biometric data from the authentication means but deny access to the restricted procedure. In other words, in the embodiment shown in Figure 5, the third user authentication request device 23 may deny the user from leaving.

[0162] In one embodiment, in step 508, the third user authentication request device 23 can send a user authentication expiration signal to the server 40.

[0163] In the embodiment shown in Figure 5, step 508 may be based on the premise that the third user authentication request device 23 permits the user to leave. Based on its decision to permit the user to leave, the third user authentication request device 23 may send a user authentication expiration signal to the server 40.

[0164] In one embodiment, in step 509, the server 40 can transmit a user authentication expiration signal to the user authentication device 10.

[0165] In one embodiment, the server 40 can transmit a user authentication expiration signal to the user authentication device 10 based on receiving a user authentication expiration signal from the third user authentication request device 23.

[0166] In one embodiment, the authentication expiration signal may be sent via a message, specifically a push notification or push message.

[0167] In other embodiments, instead of steps 508 and 509, the third user authentication request device 23 may directly transmit a user authentication expiration signal to the user authentication device 10.

[0168] In one embodiment, in step 510, the user authentication device 10 can change the authentication state.

[0169] Specifically, the user authentication device 10 can change the authentication state to correspond to OFF based on receiving a user authentication expiration signal. As shown in Figure 5, the value of the authentication state may be 0 ("Authentication state: 0") in the sense that the authentication state corresponds to OFF.

[0170] Thereafter, if a user of the authentication device 10 attempts to access the authentication system of this disclosure again, the authentication procedure shown in Figure 3 may be executed anew.

[0171] On the other hand, in Figures 3 to 5, the first personal authentication request device 21, the second personal authentication request device 22, and the third personal authentication request device 23 may be a single device connected by wire or wireless. For example, the first personal authentication request device 21, the second personal authentication request device 22, and the third personal authentication request device 23 may be understood as the aforementioned personal authentication request device 20 or as part of the personal authentication request device 20.

[0172] On the other hand, as described above, an identity authentication system according to one embodiment of this disclosure may include an identity authentication request device that performs primary authentication and an identity authentication request device that performs secondary authentication. The identity authentication request device that performs secondary authentication can perform identity authentication for users for whom primary authentication was not successfully performed. This embodiment is characterized by including a primary authentication request device and a secondary authentication request device, but does not include a main authentication request device and an auxiliary authentication request device, but may be implemented by utilizing the features of the identity authentication system described above with reference to Figures 3 to 5.

[0173] Specifically, in one embodiment, the secondary authentication request device can determine whether or not a user terminal has interacted with the primary authentication request device to perform identity authentication. In other words, the secondary authentication request device can detect user terminals that have interacted with the primary authentication request device to perform identity authentication and user terminals that have not interacted with the primary authentication request device to perform identity authentication.

[0174] Specifically, in one embodiment, the secondary authentication request device can detect a user terminal whose access status is ON but whose authentication status is OFF as a result of detecting the access status and authentication status update of the server 40, and identify it as a user terminal that has never interacted with the primary authentication request device to perform authentication. Conversely, in one embodiment, the secondary authentication request device can detect a user terminal whose access status is ON but whose authentication status is ON as a result of detecting the access status and authentication status update of the server 40, and identify it as a user terminal that has interacted with the primary authentication request device to perform authentication.

[0175] In one embodiment, the secondary authentication request device can perform user authentication if it detects a user terminal that has never interacted with the primary authentication request device to perform user authentication. Specifically, if the secondary authentication request device detects a user terminal that has never interacted with the primary authentication request device to perform user authentication, it can perform a subsequent procedure of collecting authentication means biometric data and transmitting the authentication means biometric data.

[0176] In one embodiment, when a secondary authentication request device interacts with a primary authentication request device to detect a user terminal for which authentication has been performed, it may omit the collection of biometric data from the authentication means and grant access to the restricted procedure.

[0177] According to this embodiment, by providing a primary authentication request device and a secondary authentication request device in combination, security can be improved without compromising user convenience.

[0178] Figure 6 is a flowchart of an identity verification method according to one embodiment of the present disclosure.

[0179] Each step of the user authentication method shown in Figure 6 may be performed by the user authentication request device 20 described above, specifically by the processor of the user authentication request device 20.

[0180] In step 610, the processor can send an authentication signal and monitor the server.

[0181] In step 620, the processor can detect updates to the access status and authentication status of the authentication device based on monitoring of the server.

[0182] In one embodiment, the update of the access status may be requested by the authentication device that received the authentication signal.

[0183] In one embodiment, the access state may be updated to correspond to ON based on a request from an authentication device that has received an authentication signal.

[0184] In step 630, the processor collects biometric data from the authentication means based on whether the access state to the authentication device is ON and the authentication state is OFF, and may omit the collection of biometric data from the authentication means based on whether the access state to the authentication device is ON and the authentication state is ON.

[0185] In one embodiment, the processor may further perform the step of transmitting the collected authentication biometric data to a server.

[0186] In one embodiment, the processor may further perform the step of detecting an update in the result value of a comparison between the authentication means biometric data and the registered biometric data stored in the personal authentication device, and deciding whether to permit or deny access to the restricted procedure based on the updated result value.

[0187] In one embodiment, the user authentication request device may be installed in an area with restricted access.

[0188] In one embodiment, the user authentication request device can control the operation of the access control gates included in the access restriction area.

[0189] In one embodiment, the access control gate may include a main access control gate and one or more auxiliary access control gates.

[0190] Figure 9 is a block diagram of an apparatus according to one embodiment of the present disclosure.

[0191] The device 700 shown in Figure 9 may be at least one of the aforementioned user authentication device 10, user authentication request device 20, and server 40.

[0192] Referring to Figure 9, the device 700 may include a communication unit 710, a processor 720, and a DB 730. Only components relating to the embodiment are illustrated in the device 700 in Figure 9. Therefore, a person of the art will understand that other general-purpose components may be included in addition to those shown in Figure 9.

[0193] The communication unit 710 may include one or more components that enable wired / wireless communication with an external server or external device. For example, the communication unit 710 may include at least one of a short-range communication unit (not shown), a mobile communication unit (not shown), and a broadcast receiving unit (not shown).

[0194] DB730 is hardware that stores various data processed within the device 700 and can store programs for processing and controlling the processor 720. DB730 can store payment information, user information, and the like.

[0195] The DB730 can include RAM (random access memory) such as DRAM (dynamic random access memory) and SRAM (static random access memory), ROM (read-only memory), EEPROM (electrically erasable programmable read-only memory), CD-ROM, Blu-ray or other optical disc storage, HDD (hard disk drive), SSD (solid state drive), or flash memory.

[0196] The processor 720 controls the overall operation of the device 700. For example, the processor 720 can control the input unit (not shown), display (not shown), communication unit 710, DB730, etc., by executing a program stored in DB730. The processor 720 can control the operation of the device 700 by executing a program stored in DB730.

[0197] The processor 720 can control at least some of the operations of the device 700 described above in Figures 1 to 6.

[0198] The processor 720 may be implemented using at least one of the following: ASICs (application-specific integrated circuits), DSPs (digital signal processors), DSPDs (digital signal processing devices), PLDs (programmable logic devices), FPGAs (field programmable gate arrays), controllers, microcontrollers, microprocessors, or other electrical units for performing functions.

[0199] In one embodiment, the device 700 may be a mobile electronic device. For example, the device 700 may be a smartphone, tablet PC, PC, smart TV, PDA (personal digital assistant), laptop, media player, navigation system, camera-equipped device, and other mobile electronic devices. Alternatively, the device 700 may be a wearable device such as a watch, glasses, headband, and ring equipped with communication and data processing functions.

[0200] Embodiments of the present invention can be embodied in the form of a computer program that can be executed on a computer via various components, and such a computer program may be recorded on a computer-readable medium. In this case, the medium may include magnetic media such as hard disks, floppy disks and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical recording media such as floptical disks, and hardware devices specially configured to store and execute program instructions, such as ROM, RAM, and flash memory.

[0201] On the other hand, the computer program may be specifically designed and configured for the present invention, or it may be publicly known and available to those skilled in the field of computer software. Examples of computer programs may include not only machine code, such as that produced by a compiler, but also high-level language code that can be executed by a computer using an interpreter or the like.

[0202] According to one embodiment, methods according to various embodiments of the present disclosure may be provided in a computer program product. The computer program product may be traded as a commodity between a seller and a buyer. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or online (e.g., downloaded or uploaded) via an application store (e.g., Play Store®), or directly between two user devices. In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily generated in a device-readable storage medium such as the memory of the manufacturer's server, the application store's server, or an intermediary server.

[0203] Unless otherwise stated, the steps constituting the method according to the present invention may be performed in any order that is appropriate. The present invention is not necessarily limited to the order in which the steps are described. In the present invention, the use of all examples or exemplary terms (e.g., ) is solely for the purpose of illustrating the present invention in detail, and the scope of the present invention is not limited by such examples or exemplary terms unless otherwise limited by the claims. Furthermore, those skilled in the art will understand that various modifications, combinations, and changes may be made to the scope of the claims or their equivalents, which may be composed of design conditions and factors.

[0204] Therefore, the concept of the present invention should not be limited to the embodiments described above. Not only the claims described later, but also all scopes equivalent to or equivalently modified from these claims fall within the scope of the concept of the present invention.

Claims

1. As an authentication method performed by an authentication request device, The steps include sending an authentication signal and monitoring the server, Based on monitoring of the server, the steps include detecting updates to the access status and authentication status of the authentication device, A step in which biometric data of the authentication means is collected based on the access state to the personal authentication device corresponding to ON and the authentication state corresponding to OFF, and a step in which the collection of biometric data of the authentication means is omitted based on the access state to the personal authentication device corresponding to ON and the authentication state corresponding to ON. Methods that include...

2. The method according to claim 1, further comprising the step of transmitting the collected authentication means biometric data to the server.

3. The steps include detecting an update to the result value of a comparison between the biometric data of the authentication means and the registered biometric data stored in the personal authentication device, The method according to claim 2, further comprising the step of determining whether to allow or deny access to a restricted procedure based on the updated result value.

4. The aforementioned update of the access status is: Requested by the personal authentication device that received the authentication signal, The aforementioned access status is, The method according to claim 1, wherein the authentication device is updated to correspond to ON based on a request from the user authentication device that has received the authentication signal.

5. The aforementioned authentication status is, The method according to claim 1, wherein the authentication device that receives the authentication signal transmits and updates in accordance with the transmitted authentication state.

6. The aforementioned personal authentication request device is The method according to claim 1, comprising a device installed in an access restriction area and controlling the operation of an access control gate included in the access restriction area.

7. As a device for requesting user authentication, Memory containing at least one program, A processor that operates by executing the aforementioned at least one program, The aforementioned processor, Send an authentication signal, monitor the server, Based on monitoring of the aforementioned server, updates to the access status and authentication status of the user authentication device are detected. A device that collects biometric data from an authentication means based on whether the access state to the personal authentication device corresponds to ON and the authentication state corresponds to OFF, and omits the collection of biometric data from the authentication means based on whether the access state to the personal authentication device corresponds to ON and the authentication state corresponds to ON.

8. A computer-readable recording medium containing a program for causing a computer to perform the method described in paragraph 1.