Method and System for Authenticating Users
The method and system enhance non-face-to-face user authentication by capturing real-time user actions and identity documents to verify user identity securely, addressing fraud and ensuring reliable verification.
Patent Information
- Application Number
- JP2020209356
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-20
- Filing Date
- 2020-12-17
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-12-17
AI Technical Summary
Non-face-to-face real-name authentication methods face challenges in verifying the actual identity of users, as they are prone to fraud using images or hacked information, and existing systems struggle to ensure secure and reliable user verification.
A user authentication method and system that involves sending multiple instructions to a user terminal, capturing videos in real-time, analyzing user actions and identity documents, and authenticating users based on face and document information to ensure the user's presence and identity.
Prevents the use of printed photographs or hacked images for authentication, provides secure real-time user verification, and supports authentication through both applications and web browsers, enhancing the reliability of non-face-to-face identity verification.
Smart Images

Figure 0007708506000001 
Figure 0007708506000002 
Figure 0007708506000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a user authentication method and system, and specifically, to a method and system capable of receiving a video captured by a user terminal, analyzing the received video to determine whether a user exists in the video, and processing user authentication.
Background Art
[0002] Due to the spread of mobile devices such as smartphones and the development of the Internet, financial services and payment services using mobile devices have been widely used. In order to use such financial and payment services, real-name authentication of users may be required. However, since the number of users using such services has increased rapidly and the resources of institutions providing authentication services are limited, there may be limitations in providing real-name authentication services through in-person real-name authentication. As a result, services for authenticating users through non-face-to-face real-name authentication have been actively studied in the field of recent image processing / recognition. For example, the face information of a user extracted from an image captured using a camera can be used to authenticate the user.
[0003] However, such non-face-to-face real-name authentication is more difficult to confirm whether the person is the actual person than in-person real-name authentication, so there may be a side effect that a person who is not the actual person pretends to be the actual person. For example, there may be a problem that a photo or paper printed with the same person as someone else's identity card is used and judged to be the same person. Also, when non-face-to-face real-name authentication is performed on a client device, there may be a drawback that different real-name results are transmitted through cracking when transmitting the real-name authentication result processed by the client device to a system that requests real-name authentication. Furthermore, even when image recognition and processing for non-face-to-face real-name authentication are performed on a server device, there is a problem that the image transmitted from the client for non-face-to-face real-name authentication can be changed through eavesdropping and hacking of the transmitted and received information.
Prior Art Documents
Patent Document
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] The present disclosure provides a user authentication method, a computer program stored in a recording medium, and a system for solving the above problems.
[0006] A user authentication method and system are provided that respond to a plurality of instructions that induce a plurality of actions in a user, receive a video captured corresponding to the plurality of instructions from a user terminal, determine whether a user exists in the video, and authenticate the user based on the face of the user extracted from the video when it is determined that the user exists.
[0007] A user authentication method and system are provided in which a video captured via a camera is received in real time and continuously from a user terminal in a user authentication process.
Means for Solving the Problems
[0008] The present disclosure can be implemented in various ways including a computer-readable storage medium storing a method, a system, or a command.
[0009] A user authentication method according to an embodiment of the present disclosure includes transmitting a plurality of instructions that induce a plurality of actions in a user to a user terminal, receiving a video captured corresponding to the plurality of instructions from the user terminal, determining whether a user exists in the video, and authenticating the user based on the face of the user extracted from the video when it is determined that the user exists.
[0010] According to one embodiment, the step of receiving a video captured in response to a plurality of instructions from a user terminal includes the step of receiving the video in real time from the user terminal via a channel for communication with the user terminal.
[0011] According to one embodiment, the video is continuously received via a channel for communication with the user terminal.
[0012] According to one embodiment, the step of determining whether a user exists in the video includes the step of analyzing the video to determine whether the user performs a plurality of actions corresponding to a plurality of instructions in the video, and, when it is determined that the user performs a plurality of actions corresponding to a plurality of instructions, the step of determining that the user exists in the captured video.
[0013] According to one embodiment, the step of receiving a video captured in response to a plurality of instructions from a user terminal includes the step of receiving a face-related video captured in response to an instruction that induces the user terminal to capture the user's face, and the step of receiving an identity document-related video captured in response to an instruction that induces the user terminal to capture the user's identity document. The step of authenticating the user includes the step of extracting first information about the user's face from the face-related video, the step of extracting second information about the user's face from the identity document-related video, the step of comparing the extracted first information and the extracted second information, and the step of authenticating the user when the extracted first information and the extracted second information are similar.
[0014] According to one embodiment, the plurality of instructions includes an instruction that induces the user's front face to be captured.
[0015] According to an embodiment, the plurality of instructions includes an instruction for guiding the movement of the user's identity card. The step of receiving the identity card-related video includes the step of receiving, from the user terminal, a video in which the user's identity card is photographed based on the instruction. The step of authenticating the user includes the step of determining whether the user's identity card exists in the video based on the movement of the user's identity card obtained by analyzing the video.
[0016] According to an embodiment, the identity card-related video includes a video in which at least a part of the user and the user's identity card are photographed together. The step of receiving the identity card-related video includes the step of receiving, from the user terminal, an area including at least a part of the user on a first channel, and the step of receiving, from the user terminal, an area including the user's identity card on a second channel.
[0017] According to an embodiment, the step of sending a plurality of instructions for guiding a plurality of actions of the user to the user terminal includes the step of randomly selecting a plurality of instructions from a plurality of predetermined instruction candidates, and the step of sending the randomly selected plurality of instructions to the user terminal.
[0018] According to an embodiment, the step of sending a plurality of instructions for guiding a plurality of actions of the user to the user terminal includes the step of sending, to the user terminal, a first instruction for guiding the user to perform a first action. The step of receiving, from the user terminal, a video photographed corresponding to the plurality of instructions includes the step of receiving, from the user terminal, a video photographed corresponding to the first instruction. The step of determining whether the user exists in the video includes the step of analyzing the video photographed corresponding to the first instruction and determining whether the user performs the first action in response to the first instruction.
[0019] According to one embodiment, the step of sending a plurality of instructions for guiding a user to perform a plurality of actions to the user terminal further includes, when it is determined that the user has performed the first action, sending a second instruction for guiding the user to perform a second action to the user terminal. The step of receiving a video captured corresponding to the plurality of instructions from the user terminal includes receiving a video captured corresponding to the second instruction from the user terminal. The step of determining whether the user exists in the video includes analyzing the video captured corresponding to the second instruction and determining whether the user has performed the second action in response to the second instruction.
[0020] According to one embodiment, the step of sending a plurality of instructions for guiding a user to perform a plurality of actions to the user terminal includes, when it is determined that the user has not performed the first action, sending a third instruction for guiding the user to perform a third action to the user terminal. The third instruction is selected based on the difference between the user's action obtained from the analysis of the video captured corresponding to the first instruction and the first action.
[0021] According to one embodiment, when it is determined that the user has not performed the first action, it further includes the step of communicating with the user terminal using a channel different from the channel used for communication with the user terminal.
[0022] According to one embodiment, the step of sending a plurality of instructions for guiding a user to perform a plurality of actions to the user terminal includes sending information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions.
[0023] According to one embodiment, the plurality of resolutions corresponding to the plurality of instructions include the resolutions for each of the plurality of regions on the screen where the videos captured corresponding to the plurality of instructions are displayed.
[0024] According to one embodiment, the plurality of instructions includes an instruction to guide the photographing of at least a part of the user and the user's identification document together, and the resolution of the area guided to photograph the user's identification document is set higher than the resolution of the area guided to photograph at least a part of the user.
[0025] According to one embodiment, the step of transmitting a plurality of instructions for guiding a plurality of actions to the user terminal to the user terminal includes the step of transmitting information on the transfer speed corresponding to each of the plurality of instructions to the user terminal together with the plurality of instructions.
[0026] A computer program stored in a computer-readable recording medium for executing the above-described user authentication method according to an embodiment of the present disclosure on a computer is provided.
[0027] A user authentication system according to an embodiment of the present disclosure includes a communication module configured to transmit a plurality of instructions for guiding a plurality of actions to the user terminal to the user terminal and receive a video captured corresponding to the plurality of instructions from the user terminal, a memory, and at least one processor coupled to the memory and configured to execute computer-readable instructions included in the memory, the at least one processor being further configured to determine whether a user exists in the video and, if determined that the user exists, authenticate the user based on the face of the user extracted from the video.
[0028] According to one embodiment, the communication module is further configured to receive the video in real time from the user terminal via a channel for communication with the user terminal.
Effect of the Invention
[0029] According to an embodiment of the present disclosure, in order to analyze a video received from a user terminal to determine whether a user is present and perform user authentication when it is determined that the user is present, it is possible to prevent user authentication from being performed using a printed photograph or paper of the user.
[0030] According to an embodiment of the present disclosure, since a real-time received video is analyzed to provide a user authentication service, it is possible to solve the problem that images and videos used in the process of authenticating a user are forged.
[0031] According to an embodiment of the present disclosure, since a user authentication system analyzes a video received in real time from a user terminal to perform user authentication, it is possible to provide a user authentication service not only through an application that provides a user authentication service but also through a web browser.
[0032] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned are clearly understandable to those having ordinary knowledge in the technical field to which the present disclosure belongs (hereinafter referred to as "ordinary technicians") from the description of the claims.
Brief Description of the Drawings
[0033] Embodiments of the present disclosure will be described with reference to the accompanying drawings described below, where like reference numerals indicate like elements but are not limited thereto.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Best Mode for Carrying Out the Invention
[0034] Hereinafter, specific content for carrying out the present disclosure will be described in detail with reference to the attached drawings. However, in the following description, when there is a risk of unnecessarily obscuring the gist of the present disclosure, specific descriptions regarding widely known functions and configurations will be omitted.
[0035] In the attached drawings, the same or corresponding components are given the same reference numerals. Also, in the description of the following embodiments, the description of the same or corresponding components can be omitted from being repeated. However, even if the description of a component is omitted, it is not intended that such a component is not included in the embodiments in which it exists.
[0036] The advantages and features of the disclosed embodiments, and the methods for achieving them, will become clear by referring to the embodiments described later together with the attached drawings. However, the present disclosure is not limited to the embodiments disclosed below, and can be implemented in various different forms, and the present embodiments are merely provided to make the present disclosure complete and to fully inform those with ordinary knowledge in the technical field to which the present disclosure belongs of the scope of the invention.
[0037] The terms used in this specification will be briefly explained, and the disclosed embodiments will be specifically described. The terms used in this specification are selected as general terms that are currently widely used as much as possible while considering the functions in the present disclosure, but this can change depending on the intentions or precedents of those skilled in the relevant field, the emergence of new technologies, etc. Also, in certain cases, there are terms arbitrarily selected by the applicant, and in this case, the meaning will be described in detail in the explanatory part of the corresponding invention. Therefore, the terms used in the present disclosure should be defined based on the meaning of the terms and the overall content of the present disclosure, rather than simply by the name of the terms.
[0038] As used herein, the singular forms also include the plural forms unless the context clearly dictates otherwise. And the plural forms also include the singular form unless the context clearly dictates otherwise. When a portion of the specification states that a certain component "includes" something, this means that it can further include other components, rather than excluding other components, unless otherwise stated to the contrary.
[0039] Also, as used in the specification, the terms "module" or "section" mean software or hardware components, and the "module" or "section" performs a certain role. However, the "module" or "section" is not limited in meaning to software or hardware. The "module" or "section" can also be configured to be in an addressable storage medium or to cause one or more processors to execute. Thus, by way of example, the "module" or "section" can include components such as software components, object-oriented software components, class components, and task components, and at least one of processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, or variables. Components and "modules" or "sections" can be combined with a smaller number of components and "modules" or "sections", or further separated into additional components and "modules" or "sections".
[0040] According to one embodiment of the present disclosure, a "module" or "unit" can be implemented by a processor and a memory. The "processor" should be broadly interpreted to include a general-purpose processor, a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a controller, a microcontroller, a state machine, etc. In some environments, the "processor" can also refer to a custom semiconductor (ASIC), a programmable logic device (PLD), a field-programmable gate array (FPGA), etc. The "processor" can refer to a combination of processing devices, such as a combination of a DSP and a microprocessor, a combination of multiple microprocessors, a combination of one or more microprocessors coupled with a DSP core, or any other such configuration combination. Also, the "memory" should be broadly interpreted to include any electronic component capable of storing electronic information. The "memory" can refer to various types such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable PROM (EEPROM), flash memory, magnetic or optical data storage devices, processor-readable media such as registers, etc. If the processor can read information from the memory / or record information in the memory, the memory is said to be in an electronic communication state with the processor. The memory integrated with the processor is in an electronic communication state with the processor.
[0041] In the present disclosure, a "system" can include, but is not limited to, at least one device among a server device and a cloud device. For example, the system can be composed of one or more server devices. As another example, the system can be composed of one or more cloud devices. As yet another example, the system can be configured and operated with a server device and a cloud device together.
[0042] In the present disclosure, an "image" can include one or more images and can also refer to a video including a plurality of images.
[0043] In the present disclosure, a "video" includes a plurality of images captured by a camera and can refer to a video in which one or more objects in the images move. For example, the video can include all the images captured by a user terminal. As another example, the video can include images corresponding to and / or some of the frames extracted from the images captured by the user terminal. Here, the number of frames or images extracted from the video captured by the user terminal can be adjusted.
[0044] In the present disclosure, a "video in which a user's action is captured" includes a video in which an action performed by the user using his / her body and / or an object is captured. For example, his / her body can include a face, hands, arms, feet, etc. Also, an object can mean an object that the user can hold in his / her hand and take any action with, and can include, for example, but not limited to, an identity card.
[0045] In the present disclosure, "determining whether a user exists" can include determining whether the user actually exists in reality. For example, whether a user exists in a video captured corresponding to a plurality of instructions can refer to whether the user captured in the video actually exists in reality. Here, when an image, paper, video, etc. in which the user is imaged or captured rather than the actual user is captured by the user terminal, it can be determined that the user does not exist.
[0046] In the present disclosure, "receiving in real time" can refer to receiving data simultaneously with its generation. According to one embodiment, receiving a captured video in real time can refer to receiving the captured video immediately after it is captured by an image sensor. For example, a user authentication system receiving a video captured from a user terminal in real time can refer to the video being captured by the user terminal and immediately transmitted to the user authentication system, and the user authentication system receiving the video captured from the user terminal. Here, when the user terminal transmits to the user authentication system, there may be a video capture / processing time of the user terminal and / or a communication delay provided from the user terminal to the user authentication system. However, it can be determined that the video received after such a video capture / processing time and / or any communication delay time is also received in real time.
[0047] In the present disclosure, "identity document" can refer to a document or card that proves the personal or user's personal or identity information. For example, identity documents can include, but are not limited to, a resident registration card, a social security card, a driver's license, a passport, a student ID card, a disability certificate, etc.
[0048] In the present disclosure, "similar" can include all meanings of being the same or similar. For example, two pieces of information being similar can refer to the two pieces of information being the same or similar to each other.
[0049] In the present disclosure, "channel" can refer to a passage for mutually communicating any information and / or data between two devices. For example, the channel used for communication between a user authentication system and a user terminal can refer to a passage for mutually communicating any information and / or data between the user authentication system and the user terminal.
[0050] In the present disclosure, although "user" and "user terminal" are used separately, a user can refer to a user terminal, and conversely, a user terminal can also refer to a user.
[0051] FIG. 1 is an exemplary diagram showing a video in which the actions of a user (120) are imaged by a received command in a process of authenticating the user (120) according to an embodiment of the present disclosure. The user (120) can be requested to perform personal authentication or real-name authentication of the user (120) for the service he / she is using through the user terminal (100). Here, the service can include any service that the user terminal (100) can perform via a web browser and / or an application, and can include, for example, but not limited to, payment services, credit card services, banking services, virtual currency services, etc.
[0052] According to an embodiment, when the user (120) joins a system that provides the service he / she is using, or when he / she loses his / her ID and / or password, the user can be requested to perform such user authentication by the user authentication system. For example, such a user authentication system can be provided together with the system that provides the service. As another example, the user authentication system can be provided separately from the system that provides the service.
[0053] The user authentication system can be configured to receive a video in which at least a part of the user is photographed from the user terminal (100). Such a video can be captured or photographed via a camera attached to the user terminal (100) or connected by wire / wirelessly. According to one embodiment, as shown in the figure, the camera (110) can be provided attached to the front surface of the user terminal (100). In this case, the camera (110) can photograph the actions performed by the user looking at the front surface of the user terminal (100), and the photographed video can be transmitted to the user authentication system. For example, the user authentication system can receive in real time a video in which the user's actions are photographed from the user terminal (100).
[0054] The user authentication system can be configured to receive a video in which at least a part of the user is photographed from the user terminal (100) and determine whether the user exists in the received video. According to one embodiment, the user authentication system can transmit one or more instructions to the user terminal (100), and the one or more transmitted instructions can be output to the user terminal (100). For example, as shown in the figure, the user terminal (100) can receive an instruction "Please draw a V" from the user authentication system (300) and display such an instruction on the display of the user terminal (100). Here, the received instruction can be displayed in an area that is separated from the area where the photographed video is displayed.
[0055] In response to an instruction received by the user terminal (100), the user can perform the action induced by such an instruction, and such user action can be captured by the camera (110) and sent to the user authentication system. For example, as shown in the figure, the user (120) can act to draw a "V" using their right hand in response to the instruction "Please draw a V", and such an action can be captured by the camera (110). The video captured by the user terminal (100) can be sent to the user authentication system in real time. The user authentication system can determine whether a user exists in the video received in real time from the user terminal (100).
[0056] FIG. 2 is an exemplary diagram showing a video in which the action of the user is imaged by an instruction displayed on the user terminal (100) in the process of authenticating the user (120) according to another embodiment of the present disclosure. When it is determined that the user (120) exists, the user authentication system can send an instruction to the user terminal (100) asking to show the user's identity card to be captured by the camera (110). According to another embodiment, the user terminal (100) can receive an instruction asking to show such a user's identity card during the process of determining whether the user exists from the user authentication system (300). Such an instruction can be output to the user terminal (100), and for example, as shown in the figure, it can be displayed as an instruction "Please present your identity card (front side)" on the display of the user terminal (100). Here, the received instruction can be displayed in an area separated from the area where the captured video is displayed.
[0057] In response to such an instruction, the user (120) can hold up their ID card with their hand so that it can be photographed by the camera (110). The video of the user's (120) ID card being photographed can be sent to the user authentication system (300). For example, as shown in the illustration, in the process of photographing at least a part of the user (120), the user's ID card can be photographed together. Such a video can be sent to the user authentication system (300) immediately after being photographed by the camera, that is, in real time. In this embodiment, although the user's (120) face and ID card are shown being photographed together, it is not limited to this, and only the user's (120) ID card can be photographed by the camera (110) and provided to the user authentication system (300). The user authentication system can use the video of the ID card being photographed in this way for the authentication of the user (120).
[0058] FIG. 3 is a schematic diagram showing a configuration in which a user authentication system (300) is communicably connected to a plurality of user terminals (100_1, 100_2, 100_3) to provide a user authentication service according to an embodiment of the present disclosure. The user authentication system (300) can include a system capable of authenticating users of a plurality of user terminals via a network (310). According to one embodiment, the user authentication system (300) can include one or more server devices and / or databases capable of storing, providing, and executing computer-executable programs (e.g., downloadable applications) and data related to the user authentication service, or one or more distributed computing devices and / or distributed databases of a cloud computing service infrastructure. The user authentication service provided by the user authentication system (300) can be provided to the user via an application or a web browser, etc., for which the user authentication service installed on a plurality of user terminals (100_1, 100_2, 100_3) is required. Here, when a server managing such an application receives a user authentication request from a plurality of user terminals (100_1, 100_2, 100_3), it can request user authentication from the user authentication system (300). In this case, the user authentication system (300) and the plurality of user terminals (100_1, 100_2, 100_3) can be communicably connected to each other.
[0059] A plurality of user terminals (100_1, 100_2, 100_3) can communicate with a user authentication system (300) via a network (310) for user authentication. According to one embodiment, the plurality of user terminals (100_1, 100_2, 100_3) can send a video captured via an image sensor associated with the user terminals (100_1, 100_2, 100_3) to the user authentication system (300). Here, the captured video can include any information and / or data required for user authentication. For example, the captured video can include information about at least a part of the user (e.g., the user's face). As yet another example, the captured video can include information about the user's identity document.
[0060] A plurality of user terminals (100_1, 100_2, 100_3) can send in real time a video captured by an image sensor to a user authentication system (300) via a channel capable of any two-way communication for authenticating the user. According to one embodiment, the user authentication system (300) can receive a video captured by a plurality of user terminals (100_1, 100_2, 100_3) via a VoIP (Voice over Internet Protocol) channel with the user terminal (100). According to other embodiments, a video captured in this way can be received in real time from the user terminal (100) via a broadcast channel. Here, the broadcast channel can be generated through any method capable of two-way communication, and can be generated using, for example, but not limited to, WebRTC (Web Real-Time Communication).
[0061] The network (310) can be configured to enable communication between a plurality of user terminals (100_1, 100_2, 100_3) and the user authentication system (300). The network (310) can be composed of a wired network such as Ethernet (registered trademark), a wired home network (Power Line Communication), a telephone line communication device, and RS-serial communication, a mobile communication network, a WLAN (Wireless LAN), Wi-Fi (registered trademark), Bluetooth (registered trademark), and ZigBee (registered trademark) depending on the installation environment, or a combination thereof. That is, the communication method is not limited, and it includes not only a communication method that utilizes a communication network that the network (310) can include (for example, a mobile communication network, a wired Internet, a wireless Internet, a broadcast network, a satellite network, etc.), but also short-range wireless communication between user terminals. For example, the network (310) can include any one or more of networks such as a PAN (personal area network), a LAN (local area network), a CAN (campus area network), a MAN (metropolitan area network), a WAN (wide area network), a BBN (broadband network), and the Internet. Further, the network (310) can include any one or more of network topologies including a bus network, a star network, a ring network, a mesh network, a star-bus network, a tree, or a hierarchical network, but is not limited thereto.
[0062] In FIG. 3, a mobile phone terminal (100_1), a tablet terminal (100_2), and a PC terminal (100_3) are illustrated as examples of user terminals, but the present invention is not limited thereto. The user terminal can be any computing device capable of wired and / or wireless communication and having a user interface for receiving information for user authentication from a user. For example, the user terminal can include a smart phone, a mobile phone, a navigation device, a computer, a laptop, a digital broadcast terminal, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), a tablet PC, a game console, a wearable device, an IoT (internet of things) device, a VR (virtual reality) device, an AR (augmented reality) device, and the like. Further, in FIG. 3, three user terminals (100_1, 100_2, 100_3) are illustrated as communicating with a user authentication system (300) via a network (310), but the present invention is not limited thereto, and a different number of user terminals can be configured to communicate with the user authentication system (300) via the network (310).
[0063] The user authentication system (300) can receive user authentication requests from a plurality of user terminals (100_1, 100_2, 100_3) via the network (310). The received user authentication requests can be stored as user authentication information in a storage medium associated with the user authentication system (300). The user authentication requests can include user information that generated the user authentication requests, videos in which at least a part of the user is photographed, videos in which the user's identity card is photographed, and the like, and can be requested when the user needs to authenticate himself / herself for a specific service or product.
[0064] The user authentication system (300) can send a plurality of instructions to the user terminals (100_1, 100_2, 100_3) to induce the users of the plurality of user terminals (100_1, 100_2, 100_3) to perform a plurality of actions via the network (310). According to one embodiment, such a plurality of instructions can be sent to the plurality of user terminals (100_1, 100_2, 100_3) in real time. In response to each of such a plurality of instructions, the users of the plurality of user terminals (100_1, 100_2, 100_3) perform the action indicated by the corresponding instruction, and a video of the performed action being taken can be sent to the user authentication system (300) in real time. The video received in this way can be used to authenticate the users of the plurality of user terminals (100_1, 100_2, 100_3).
[0065] FIG. 4 is a block diagram showing the internal configuration of a user terminal (100) and a user authentication system (300) according to an embodiment of the present disclosure. The user terminal (100) can include a communication module (412), a processor (414), a memory (416), and an input / output interface (418). Similarly, the user authentication system (300) can include an input / output interface (432), a processor (434), a memory (436), and a communication module (438). As shown in FIG. 4, the user terminal (100) and the user authentication system (300) can be configured to communicate information and / or data via a network (310) using their respective communication modules (412, 438). Also, an input / output device (420) can be configured to input information and / or data to the user terminal (100) via the input / output interface (418) or output information and / or data generated from the user terminal (100). In FIG. 4, the communication module (412), the processor (414), the memory (416), and the input / output interface (418) are shown as the internal configuration of the user terminal (100), but other user terminals (e.g., the user terminals (100_1, 100_2, 100_3) in FIG. 3) can also include an internal configuration identical or similar to that of the user terminal (100).
[0066] The communication modules (412, 438) can provide a configuration or function for the user terminal (100) and the user authentication system (300) to communicate with each other via the network (310), and can also provide a configuration or function for the user terminal (100) and / or the user authentication system (300) to communicate with the terminals of other users or other systems (for example, a separate cloud system, a separate video receiving system). As an example, a request (for example, a user authentication request) generated by the processor (414) of the user terminal (100) based on program code stored in a recording device such as the memory (416) can be transmitted to the user authentication system (300) via the network (310) under the control of the communication module (412). Conversely, control signals and instructions (for example, instructions for guiding the user's actions) provided based on the control of the processor (434) of the user authentication system (300) can be received by the user terminal (100) through the communication module (412) of the user terminal (100) via the communication module (438) and the network (310). For example, the user terminal (100) can receive at least one of an instruction for guiding the user's actions from the user authentication system (300) through the communication module (412) or information about an image exemplifying such an instruction.
[0067] The memory (416, 436) can include any non-transitory computer-readable recording medium. According to one embodiment, the memory (416, 436) can include a permanent mass storage device such as a RAM (random access memory), ROM (read only memory), disk drive, SSD (solid state drive), flash memory, etc. As another example, a permanent mass storage device such as a ROM, SSD, flash memory, disk drive, etc. can be included in the user terminal (100) or the user authentication system (300) as a separate permanent storage device distinct from the memory (416, 436). Also, the memory (416, 436) can store an operating system and at least one program code (for example, code for a browser installed and driven on the user terminal (100) or a user authentication dedicated application installed on the user terminal (100) for providing a user authentication service or an application for providing a user authentication service, etc.). Differently, the memory (416, 436) can store program code required for user authentication provided via a web browser.
[0068] Such software components can be loaded from a computer-readable recording medium separate from the memories (416, 436). Such a separate computer-readable recording medium can include a recording medium directly connectable to such a user terminal (100) and user authentication system (300), and can include, for example, computer-readable recording media such as floppy drives, disks, tapes, DVD / CD-ROM drives, memory cards, etc. As another example, the software component can also be loaded into the memories (416, 436) via the communication modules (412, 438) rather than a computer-readable recording medium. For example, at least one program can be loaded into the memories (416, 436) based on a computer program (e.g., the above-described dedicated user authentication application or an application providing a user authentication service) installed by a file provided by a file distribution system that distributes developer or application installation files via the network (310). In contrast, at least one program can be loaded into the memories (416, 436) via a web browser.
[0069] The processors (414, 434) can be configured to process the instructions of a computer program by performing basic arithmetic, logic, and input / output operations. The instructions can be provided to the processors (414, 434) by the memories (416, 436) or the communication modules (412, 438). For example, the processors (414, 434) can be configured to execute instructions received based on program code stored in a recording device such as the memories (416, 436).
[0070] The input / output interface (418) can be means for interfacing with an input / output device (420). As an example, the input device can include devices such as a camera including an image sensor, a keyboard, a microphone, a mouse, etc., and the output device can include devices such as a display, a speaker, a haptic feedback device, etc. As another example, the input / output interface (418) can be means for interfacing with a device in which a configuration or function for performing input and output is integrated into one, such as a touch screen. For example, when the processor (414) of the user terminal (100) processes the instructions of the computer program loaded in the memory (416), a service screen or content configured using information and / or data provided by the user authentication system (300) and other user terminals can be displayed on the display via the input / output interface (418). In FIG. 4, although the input / output device (420) is illustrated as not being included in the user terminal (100), it is not limited thereto, and the input / output device (420) can be configured as one device with the user terminal (100). Also, the input / output interface (432) of the user authentication system (300) can be means for interfacing with a device (not shown) for input or output that can be connected to the user authentication system (300) or included in the user authentication system (300). In FIG. 4, although the input / output interfaces (418, 432) are illustrated as elements configured separately from the processors (414, 434), it is not limited thereto, and the input / output interfaces (418, 432) can be configured to be included in the processors (414, 434).
[0071] The user terminal (100) and the user authentication system (300) can include more components than those shown in FIG. 4. However, it is not necessary to clearly illustrate most of the components of the prior art. According to one embodiment, the user terminal (100) can be implemented to include at least a part of the input / output devices described above. In addition, the user terminal (100) can further include other components such as a transceiver, a GPS (Global Positioning System) module, one or more cameras including an image sensor, various sensors, a database, etc. For example, when the user terminal (100) is a smartphone, it can include the components generally included in a smartphone. For example, various components such as an acceleration sensor, a gyro sensor, a camera module, various physical buttons, buttons using a touch panel, input / output ports, and a vibrator for vibration can be implemented to be further included in the user terminal (100).
[0072] According to one embodiment, the processor (414) of the user terminal (100) can be configured to operate an application or a web browser that provides a user authentication service. At this time, the program code related to the corresponding application or web browser can be loaded into the memory (416) of the user terminal (100). While the application or web browser is operating, the processor (414) of the user terminal (100) can receive information and / or data provided from the input / output device (420) and / or receive information and / or data from the user authentication system (300) through the communication module (412) via the input / output interface (418), and can process the received information and / or data and store it in the memory (416). Also, such information and / or data can be provided to the user authentication system (300) through the communication module (412).
[0073] According to one embodiment, while an application or web browser that provides a user authentication service is operating, the processor (414) can receive information such as text and images via input devices such as a camera, touch screen, keyboard, etc. connected to the input / output interface. In addition to this, the processor (414) can store the received images, videos and / or text in the memory (416) or provide them to the user authentication system (300) via the communication module (412) and the network (310). For example, the processor (414) can receive information for generating a user authentication request via input devices such as a touch screen, keyboard, etc. Also, the processor (414) can receive information regarding a video in which a user's actions are captured via an input device such as a camera. The received information can be provided to the user authentication system (300) via the communication module (412) and the network (310).
[0074] The processor (414) can be configured to output processed information and / or data via output devices such as a display output-capable device (e.g., touch screen, display, etc.) and an audio output-capable device (e.g., speaker) of the user terminal (100). According to one embodiment, information and / or data provided by an application or web browser that provides a user authentication service (e.g., instructions for guiding a user's actions, exemplary images showing such actions, etc.) can be displayed via a display output-capable device or the like. According to other embodiments, information and / or data provided by an application or web browser that provides a user authentication service can be output via an audio output-capable device or the like. For example, instructions for guiding a user's actions can be output through the speaker and provided to the user via the user terminal.
[0075] The processor (434) of the user authentication system (300) can be configured to generate any information and / or data required for user authentication. According to one embodiment, the processor (434) can generate information and / or data (e.g., information for the channel with the user terminal) required for communication with the user terminal that requested user authentication. According to other embodiments, the processor (434) can be configured to generate information and / or data for a plurality of instructions that induce specific actions for the user. The information and / or data generated in this way can be stored in the memory (436) and further provided to the user terminal (100) via the communication module (438) and the network (310).
[0076] The processor (434) can be configured to manage, process, and / or store information and / or data received from a plurality of user terminals including the user terminal (100) and / or a plurality of external systems. The processor (434) can be configured to receive in real time a video captured via an image sensor from a plurality of user terminals. The video received in real time can be received continuously without interruption. Here, the video can refer to at least a video in which the user's actions are captured. For example, when the real-time reception of the video captured during the interruption of communication with the user terminal is stopped, the processor (434) can end user authentication or start a new user authentication after the communication is resumed.
[0077] The processor (434) can be configured to analyze the video received in real time to determine whether a user exists in the received video. If a user exists, the processor (434) can analyze the face of the user extracted from the video and authenticate the user based on the analyzed result. For example, the processor (434) can extract information about the user's face from the face-related video captured in response to an instruction to guide the capture of the user's face, and extract information about the user's face from the ID-related video captured in response to an instruction to guide the capture of the user's ID card. The information about the user's face extracted from both is compared, and if they are similar, the user can be authenticated. The authentication result for the user can be provided to the user terminal (100) via the communication module (438) and the network (310). Hereinafter, a specific method for providing a service for authenticating a user based on the video received by the processor (434) of the user authentication system (300) will be described in detail.
[0078] FIG. 5 is a block diagram showing the configuration of a user authentication system (300) according to an embodiment of the present disclosure. The processor (434) of the user authentication system (300) can be configured to include an instruction processing module (510), an image extraction module (520), an image analysis module (530), and an authentication module (540). In addition, the processor (434) can transmit and receive information and / or data to and from an external system through the communication module (438). In addition to this, the processor (434) can store information and / or data in the memory (436) or obtain information and / or data from the memory (436).
[0079] The command processing module (510) can be configured to generate a plurality of commands for user authentication. Here, each of the plurality of commands can include a command that guides the user's actions. Also, each of the plurality of commands can include an exemplary image that indicates such an action. For example, the plurality of commands can include any command used to determine whether a user is present. As yet another example, the plurality of commands can include a command that guides the user to present an identity document. The commands generated in this way can be stored in a storage medium (e.g., memory (416)) accessible by the processor (434).
[0080] The command processing module (510) can select one or more commands from among a plurality of pre-stored commands. According to one embodiment, the command processing module (510) can be configured to randomly select a plurality of commands from among a plurality of candidates of pre-stored commands. For example, the plurality of selected commands can include a command that guides the user to take a frontal face photo. As another example, the plurality of selected commands can include a command that guides the user to have an identity document photographed.
[0081] The command processing module (510) can transmit a plurality of selected commands to the user terminal (100) through the communication module (438). According to one embodiment, the command processing module (510) can transmit a plurality of selected commands to the user terminal (100) in a determined order. For example, if the plurality of commands includes a first command, a second command, and a third command, the first command can be transmitted to the user terminal (100) first. And if the analysis of the first command is completed by the image analysis module (530), the second command can be transmitted to the user terminal (100). When the analysis of the video received corresponding to the second command is completed, the command processing module (510) can transmit the third command to the user terminal (100). According to other embodiments, for a specific command, the command processing module (510) can provide the user terminal (100) with information about a plurality of channels through which videos taken in each of a plurality of regions on the screen of the user terminal are transmitted. For example, if the region where the user is photographed is separated from the region where the identity card is photographed, the videos taken in the two regions can be transmitted through different channels.
[0082] The command processing module (510) can transmit a plurality of commands to the user terminal (100) before user authentication is completed. According to one embodiment, the plurality of commands can include commands used to determine whether a user exists in the captured video. For example, such commands can include commands that induce the user to perform specific actions using their body (e.g., face, etc.) and / or objects (e.g., identity card, etc.). According to other embodiments, the plurality of commands can include commands used to authenticate the user in the captured video. For example, such commands can include commands that induce the user's face to be properly recognized (e.g., commands that induce the user's front face to be photographed) and commands that induce the user's identity card to be photographed.
[0083] The image extraction module (520) can receive videos in real time from the user terminal (100) through the communication module (438). When the user terminal (100) receives an instruction to induce a specific action from the instruction processing module (510), the user of the user terminal (100) can perform such an action. While such an action is being performed, the camera associated with the user terminal (100) can capture the user's action, and the user terminal (100) can transmit the video captured in response to the received instruction to the image extraction module (520) through the communication module (438). Immediately after the video is captured, the user terminal (100) can transmit the captured video to the image extraction module (520) in real time, and the image extraction module (520) can receive the captured video in real time. According to one embodiment, the image extraction module (520) can directly receive videos through the communication module (438) via the network (310). According to other embodiments, the video transmitted in real time from the user terminal (100) can be received by a separate server (e.g., a VoIP management server, a broadcast channel management server, etc.) that manages the channel between the user authentication system (300) and the user terminal (100), and can be provided to the image extraction module (520) via another server. According to still other embodiments, the image extraction module (520) can receive videos captured in multiple regions on the screen of the user terminal on multiple channels.
[0084] The image extraction module (520) can extract one or more images from the video received in real time for user authentication. According to one embodiment, the image extraction module (520) can be configured to extract one or more images included in the received video based on predetermined rules. For example, the image extraction module (520) can be configured to extract a plurality of images included in the received video at regular time intervals (e.g., extracted every 1 second). According to other embodiments, the image extraction module (520) can receive information regarding the instructions sent to the user from the instruction processing module (510), and adjust the speed of extracting images from the received video based on the received instructions. For example, in the case of an instruction that induces an action corresponding to a static state of the user (e.g., an action of looking at the face from the front, an action of reflecting the identity card), the instruction processing module (510) can extract images from the received video at a low image extraction speed. As yet another example, in the case of an instruction that induces an action corresponding to a dynamic state of the user (e.g., an action of moving the face, an action of moving the identity card), the instruction processing module (510) can extract images from the received video at a high image extraction speed. The images extracted in this way can be provided to the image analysis module (530).
[0085] The image extraction module (520) can determine a plurality of resolutions corresponding to a plurality of instructions. Here, the resolution can refer to the resolution applied when the user terminal (100) uses the camera for shooting corresponding to the instruction. According to one embodiment, the resolution can be determined to be different for each region in the video to be shot. For example, the region in the video to be shot where the user's identity card is located can be set to be shot at a high resolution. The resolution determined in this way can be stored in the memory (436) in association with the corresponding instruction.
[0086] The image extraction module (520) can determine the transfer speed corresponding to each of a plurality of instructions. Here, the transfer speed can refer to the transfer speed applied when the user terminal (100) transmits a video captured using a camera to the user authentication system (300). For example, the transfer speed can be indicated by the number of frames transmitted per second (fps). The transfer speed determined in this way can be stored in association with the corresponding instruction and the memory (436). According to one embodiment, the transfer speed can indicate the playback speed of a video captured by the camera of the user terminal (100). The user terminal (100) can transmit the captured video to the image extraction module (520) according to the playback speed corresponding to the transfer speed.
[0087] The instruction processing module (510) can transmit information regarding the resolution and / or transfer speed related to an instruction together when transmitting the instruction to the user terminal (100). Thereby, in response to the received instruction, the user terminal (100) can capture an image using the camera at the received resolution, and the captured video can be provided to the user authentication system (300) at the received transfer speed. For example, different resolutions can be received for a plurality of regions displayed on the screen of the captured video, and the user terminal (100) can apply the set resolutions for the plurality of regions to the camera during video capture.
[0088] The image analysis module (530) can be configured to receive one or more images extracted from the image extraction module (520) and analyze the extracted images. According to one embodiment, a library used to analyze whether a user performs the actions induced by each of a plurality of instructions can be stored in the memory (416). In such an environment, the image analysis module (530) can access the memory (416) and analyze the received images using the pre-stored library. According to other embodiments, an analysis model used to determine whether a user performs the actions induced by a plurality of instructions can be generated, and the generated analysis model can be stored in a storage medium (e.g., the memory (436)). The image analysis module (530) can analyze the extracted images using such an analysis model. Such an analysis model will be described in detail with reference to FIG. 7.
[0089] The image analysis module (530) can analyze the received one or more images to determine whether a user in the images performs the actions corresponding to a plurality of instructions.
[0090] According to one embodiment, when an instruction sent to the user terminal (100) is an instruction that induces the user to move a part of the body and / or an object, the image analysis module (530) can determine whether the user moves according to the sent instruction. According to other embodiments, when an instruction sent to the user terminal (100) is an instruction that induces the user to move the identity card, the image analysis module (530) can analyze the images extracted from the video received corresponding to such an instruction to determine whether the identity card moves. Information regarding whether a user performs the actions corresponding to a plurality of instructions can be provided to the authentication module (540).
[0091] According to an embodiment, the image analysis module (530) can extract information about the user's face from the received image. For example, the received image can include an image of the user's face (e.g., the user's frontal face), and the image analysis module (530) can extract first information about the user's face from such an image. As another example, the received image can include an image in which the user's identification card is imaged, and the image analysis module (530) can extract second information about the user's face from the image in which the user's identification card is imaged. The first information and the second information about the user extracted in this way can be provided to the authentication module (540).
[0092] According to an embodiment, after one or more instructions are sent to the user terminal (100) in a predetermined order, the image analysis module (530) can analyze an image extracted from a video received corresponding to each of the one or more instructions sent from the user terminal (100). For example, the image analysis module (530) can analyze the extracted image to determine whether the user performs the action induced by the instruction in response to the corresponding instruction. Under such a configuration, every time an analysis result corresponding to one instruction is generated, the generated analysis result can be provided to the authentication module (540).
[0093] The authentication module (540) can determine whether a user exists in the real-time received video based on the analysis result for the image extracted from the image analysis module (530). For example, such an analysis result can be received based on the order of the instructions sent to the user terminal. According to one embodiment, when it is determined that the user has completed all the actions corresponding to one or more instructions (e.g., three instructions) sent to the user terminal (100), the authentication module (540) can determine that the user exists in the received video. In contrast, when it is determined that the user has not completed the actions corresponding to one or more instructions sent to the user terminal, the authentication module (540) can determine that the user does not exist in the received video.
[0094] According to another embodiment, when the authentication module (540) determines that the user has not completed the action corresponding to the first instruction among a plurality of instructions sent to the user terminal (100), it can request the instruction processing module (510) to send a different second instruction to the user terminal (100). Here, the second instruction can be selected by the instruction processing module (510) based on the difference between the user's action obtained from the analysis of the video analyzed from the video received corresponding to the first instruction and the action corresponding to the first instruction. When the result of analyzing the image extracted from the video captured corresponding to the second instruction indicates that the user has completed the action corresponding to the second instruction, the authentication module (540) can determine that the user exists in the received video. In yet another embodiment, when the authentication module (540) receives an analysis result that the user has performed actions corresponding to a predetermined number of instructions among a plurality of instructions, it can determine that the user exists in the received video.
[0095] In yet another embodiment, when it is determined that the video received from the user terminal (100) is not continuous, the authentication module (540) can determine that there is no user in the received video. For example, when it is determined that the time difference between one or more consecutive frames included in the video does not correspond to the transfer speed indicated by the instruction processing module (510), it can be determined that there is no user in the received video.
[0096] In yet another embodiment, when the authentication module (540) determines that the user has not performed an action corresponding to a first instruction among a plurality of instructions sent by the user to the user terminal (100), it can instruct the communication module (438) to change the channel used for communication with the user terminal. According to one embodiment, the authentication module (540) can change the channel currently used for communication with the user terminal (100) to a different communication channel. Thereby, it is possible to prevent the user authentication from not being properly performed due to a communication channel problem. According to another embodiment, the authentication module (540) can instruct the communication module (438) to change the channel currently used in communication with the user terminal (100) to a communication channel connectable to the counselor. Thereby, when the user's action does not correspond to the action indicated by the sent instruction, the counselor can directly perform user authentication, and accurate authentication for the user can be provided.
[0097] The authentication module (540) can authenticate the user based on the analysis result for the extracted image. According to one embodiment, the authentication module (540) can be configured to authenticate the user when it is determined that there is a user in the received image. In another embodiment, when the authentication module (540) receives a video analysis result from the image analysis module (530) that the identity document is moving, it can determine that the identity document exists. Thereby, it can be configured that the user is authenticated when it is determined that the identity document exists.
[0098] The authentication module (540) can receive first information about the user's face extracted from a face-related video captured in response to an instruction to guide the capture of the user's face, and can receive second information about the user's face extracted from an ID-related video captured in response to an instruction to guide the capture of the user's ID card. Then, the first information about the user's face extracted and the second information about the user's face extracted can be compared with each other. Here, when the extracted first information and the extracted second information are similar, the authentication module (540) can authenticate the user. For example, when the similarity between the extracted first information and the extracted second information is equal to or greater than a predetermined similarity, it can be determined that the extracted first information and the extracted second information are similar. As yet another example, the authentication module (540) can determine the similarity and the related reliability between the extracted first information and the extracted second information, and can determine whether the extracted first information and the extracted second information are similar based on the determined similarity and reliability. Such similarity and / or reliability can be determined using any technique known in the field of image processing. For example, rule-based techniques, machine learning techniques, artificial neural network models, etc., configured to infer / output similarity and / or reliability based on information extracted from multiple images can be used, but are not limited thereto. The user authentication result determined by the authentication module (540) can be provided to the user terminal (100) or provided to a system related to the user authentication request.
[0099] In FIG. 5, the processor (434) is illustrated as including the instruction processing module (510), the image extraction module (520), the image analysis module (530), and the authentication module (540) as respective modules, but is not limited thereto, and two or more modules can be implemented by one module.
[0100] Figure 6 is a flowchart showing a user authentication method (600) according to an embodiment of the present disclosure. The user authentication method (600) can be performed by a user authentication system (300). As shown, the user authentication method (600) can start with the step (S610) of sending a plurality of instructions for guiding a plurality of actions to the user terminal to the user. For example, the plurality of actions can include actions required to determine whether the user is present, actions required to extract the user's face, actions required to photograph the user's identity card, and the like.
[0101] Then, in step (S620), a video taken in response to the plurality of instructions can be received from the user terminal. According to an embodiment, the user authentication system (300) can receive in real time a video taken in response to the plurality of instructions from the user terminal via a channel for communication with the user terminal. For this purpose, the user terminal can, in response to the plurality of instructions, photograph the actions of the user indicated by the instructions using a camera including an image sensor, and transmit the taken video to the user authentication system (300) in real time.
[0102] Next, in step (S630), the user authentication system (S630) can determine whether the user is present in the video. The video can capture the actions of the user performed in response to each of the plurality of instructions. For example, such actions can refer to actions that cause a part of the user's body (e.g., face, hand, arm, etc.) and / or an object (e.g., something that the user can hold in the hand) to move.
[0103] Finally, in step (S640), if the user authentication system (300) determines that the user exists, it can authenticate the user based on the face of the user extracted from the video. According to one embodiment, the user authentication system (300) can be configured to extract the faces of multiple users from the video. For example, the first information about the face of the user captured in the video can be extracted. In addition to this, the second information about the face of the user included in the user's identity card can be extracted from the video. Then, the user authentication system (300) compares the similarity between the first information and the second information about the extracted face of the user, and if the first information and the second information are similar, the user can be authenticated.
[0104] FIG. 7 is a diagram showing an image analysis model (720) configured to infer or output an action execution result (730) based on an image (710) according to an embodiment of the present disclosure. The image analysis model (720) can be generated through the processor (434) of the user authentication system (300), and the generated model (720) can be stored in a storage medium (e.g., memory (436)) accessible by the processor (434). The image (710) can include one or more images extracted from the video received by the user authentication system (300). For example, the image extraction module (520) can receive the video captured from the user terminal in real time and extract the image (710) from the received video based on a predetermined rule. The extracted image (710) is provided to the image analysis module (530), and the image analysis module (530) can be configured to input the extracted image (710) into the image analysis model (720) to infer or output the action execution result (730) by the user. For example, the action execution result can include information on whether the user performs actions corresponding to each of the multiple instructions. Here, the image analysis model (720) can include multiple models for analyzing multiple actions indicated by the multiple instructions.
[0105] According to one embodiment, the image analysis module (530) can provide a plurality of learning images in which the actions of a plurality of users are captured as input images to the image analysis model (720), and infer or output the result regarding whether the user performs a specific action within the image. For example, the image analysis model (720) can be configured to infer the result regarding whether the user performs a specific action through rule-based learning and prediction. As another example, the image analysis model (720) can be learned through known machine learning techniques and be configured to output the action execution result (730) through the input image. For example, the machine learning techniques can include the Find-S algorithm, the Version Space algorithm, and the Candidate Elimination algorithm. As yet another example, the image analysis model (720) can include an artificial neural network model generated using any neural network or the like.
[0106] FIG. 8 is a drawing showing an example of authenticating a user based on a video in which the actions of the user according to a plurality of instructions according to an embodiment of the present disclosure are captured. The user terminal (100) can request user authentication via the user authentication system (300). Correspondingly, the user authentication system (300) can generate a channel for communication with the user terminal. For example, when the user authentication system (300) and the user terminal communicate using webRTC, the user authentication system (300) can transmit information including a link (for example, a "user request start" button) to the user terminal. In response to this, when the user terminal clicks such a button, a channel for communication with the user can be generated. The user terminal (100) can transmit in real time the video captured by the camera connected to the user terminal to the user authentication system (300) via the generated channel.
[0107] The user terminal (100) can start real-time transmission of a video captured via a camera and can transmit the video captured until the end of transmission to the user authentication system (300) in real time (S810). The captured video can be transmitted in real time via a channel between the user authentication system (300) and the user terminal (100). Thereby, the user authentication system (300) can start real-time reception of the video captured by the user terminal (100) and can receive in real time the video captured until the reception is completed via the generated channel (S812). That is, the user authentication system (300) can receive in real time and continuously the video captured by the user terminal (100) while performing user authentication.
[0108] After the reception of the video captured by the user terminal (100) is started, the user authentication system (300) can transmit a plurality of instructions to the user terminal (100) in a predetermined order. For example, such a plurality of instructions can be randomly selected. In response thereto, the user performs actions corresponding to the plurality of instructions, and the user terminal (100) can transmit in real time the video in which the performed actions are captured to the user authentication system (300). The user authentication system (300) can analyze the video transmitted in real time and store the analyzed result. In addition to this, the user authentication system (300) can authenticate the user based on the video stored in real time and notify the authentication result to the user terminal (100).
[0109] First, the user authentication system (300) can send an instruction to "look at the face from the front" (S814). In response to this, the user (120) can act so that their face can be seen from the front on the screen being captured via the camera (S816). Such an action is captured via the camera, and the user terminal (100) can send the captured video to the user authentication system (300) in real time. The user authentication system (300) can analyze the video received in real time to determine whether the user has performed the action indicated by the sent instruction, that is, the action of looking at the face from the front, and can store the analysis result (S818).
[0110] Next, the user authentication system (300) can send an instruction to "shake the head from side to side" to the user terminal (100) (S820). In response to this, the user (120) can perform an action so that the action of shaking the head from side to side can be seen on the screen being captured via the camera (S822). The user terminal (100) can capture such an action via the camera and send the captured video to the user authentication system (300) in real time. The user authentication system (300) can analyze the video received in real time to determine whether the user has performed the action indicated by the sent instruction, that is, the action of shaking the head from side to side, and can store the analysis result (S824). In the present disclosure, since the user (120) has performed the actions induced by a plurality of instructions in response to the plurality of instructions, the user authentication system (300) can determine that the user is present in front of the camera during user authentication.
[0111] After it is determined that a user exists, the user authentication system (300) can request or transmit to the user terminal (100) an instruction to induce the identity card to be placed and photographed in a specific area (S826). For example, the specific area can correspond to a part of the area within each image or frame constituting the photographed video and can be displayed via the display of the user terminal. In response to this, the user can present the user's identity card in the specific area (S828). Such an identity card can be photographed via a camera associated with the user terminal (100), and the photographed video can be transmitted to the user authentication system (300) in real time. The user authentication system (300) analyzes the identity card-related video photographed in response to the instruction requesting the presentation of the identity card in the specific area to extract the user's face image, and can extract the user's face image from the face-related video photographed in response to the instruction requesting the user to look at the front of the face (S830). If the user authentication system (300) compares the extracted face images of both users and they are similar to each other, it can notify that the user authentication has been completed (S832). In response to such a notification, the user terminal (100) can stop the real-time transmission of the photographed video. As a result, the reception of the photographed video can also be stopped in the user authentication system (300).
[0112] FIG. 9 is a drawing showing an exemplary instruction information DB (900) according to an embodiment of the present disclosure. The instruction information DB (900) can be constructed as an arbitrary data structure in which a plurality of instructions, resolutions, transfer speeds, etc. are stored in association with each other. Here, the resolution can be set to be different for each area according to the instruction.
[0113] The resolution and transfer speed corresponding to multiple instructions can be determined by the processor (434), and the determined resolution and transfer speed can be stored in a storage medium (e.g., memory (436)) as an instruction information DB (900). According to one embodiment, a high resolution can be determined and stored for an instruction that induces the extraction of an image of a face used to authenticate a user. For example, as shown in the figure, since a video of the front face being captured can be received corresponding to Instruction 1, the resolution related to Instruction 1 (e.g., 720p) can be set higher than the resolution related to other instructions. As yet another example, a video of a face and an identity card (front) being captured can be received corresponding to Instruction 5, and the image of the face in the user's identity card can be used to authenticate the user. Thus, the resolution of Region 2 (e.g., 1024p) where the user's identity card is induced to be captured can be set higher than the resolution related to other instructions. At this time, the information for Region 1 and / or Region 2 can be stored in the storage medium of the instruction information DB (900) or the region information DB (e.g., memory (436)).
[0114] According to other embodiments, among multiple instructions used to determine whether a user exists, a relatively high resolution can be set for an instruction that induces the extraction of an image used to analyze the user's movement. For example, since a video of an action of moving the face to the left can be received corresponding to Instruction 2, the resolution related to Instruction 2 (e.g., 480p) can be set higher than the resolution related to an instruction showing the user's static movement. Also, the same can be set for Instruction 4. In contrast, an instruction showing the user's static movement can include, for example, Instruction 3 ("Please draw a V"), and the resolution related to Instruction 3 can be set to a relatively low 240p.
[0115] The processor (434) can determine different transfer speeds according to a plurality of instructions. According to one embodiment, a high transfer speed can be set for instructions that induce the extraction of images used to analyze the user's movement. For example, for instructions 2 and 4, since a video in which the user's movement behavior is captured can be received, a higher transfer speed (e.g., 5fps) can be set compared to other instructions. According to other embodiments, a relatively low transfer speed can be set for instructions related to the user's static movement. For example, instructions 1, 3, and 5 can be related to the user's static movement, and as shown, the transfer speed can be set to 1fps.
[0116] When the processor (434) transmits each instruction to the user terminal with reference to the instruction information DB (900) stored in the storage medium, it can transmit information regarding the resolution and / or transfer speed related to each instruction together. In response, when the user terminal captures a video via the camera corresponding to the received instruction, the received resolution can be applied to the camera, and the frames or images of the video captured at the received transfer speed can be transmitted to the user authentication system (300). Since the user terminal transmits the captured video to the user authentication system (300) at different transfer speeds based on the instructions, the data usage amount at the user terminal for user authentication can be minimized.
[0117] FIG. 10 is a drawing showing an example in which different instructions are selected according to whether the user's action is performed by the user authentication system (300) according to an embodiment of the present disclosure. As shown, the user authentication system (300) can select instruction 1 (“Please turn your face to the right”) (S1010). For example, such instruction 1 can be selected according to a predetermined rule. In the process of authenticating the user, the selected instruction 1 can be transmitted to the user terminal.
[0118] In response to the received command 1, the user terminal can use the camera to capture the user's actions and send the captured user actions to the user authentication system (300). The user authentication system (300) can analyze the received video to determine whether the user has performed command 1 (S1020). If it is determined that the user has performed command 1, command 2 ("Please blink") can be selected (S1030). Here, the action indicated by command 2 can be unrelated to the action indicated by command 1.
[0119] If it is determined that the user has not performed command 1, command 3 ("Please turn your face to the left") can be generated or selected (S1040). Here, command 3 can be selected based on the difference between the user's actions obtained from the analysis of the received video and the actions corresponding to command 1. For example, the actions related to command 3 can indicate actions similar to those related to command 1. Thus, if the actions of the user in the video captured in response to command 1 have not been verified, the actions of the user in the video captured in response to command 3, which indicates similar actions, can be analyzed to complement or re-verify the results analyzed corresponding to command 1.
[0120] Although not shown in FIG. 10, when it is determined that the user has not performed command 1, it is also possible to end the verification process or re-request the performance of command 1. At this time, the user authentication system (300) can send information regarding the determination that command 1 has not been performed to the user terminal.
[0121] On the one hand, the user terminal can perform a user authentication request by using an application or a web browser that provides a user authentication service. In response to this, a channel can be generated between the user terminal and the user authentication system that provides the user authentication service. The user terminal can communicate with the user authentication system by using the generated channel. The following FIGS. 11 to 15 show exemplary screens that capture how a user acts in response to an instruction in the process of using the user authentication service.
[0122] FIG. 11 is a drawing showing an example of a screen in which a user's action is captured in response to an instruction according to an embodiment of the present disclosure. According to an embodiment, the user terminal can receive an instruction "Please look at your face from the front" from the user authentication system (300). In response to such an instruction, the user can act so that their face is located in the area (1110) displayed on the screen that displays the video captured by using the camera. When such an action is performed, the video of the user's front face can be transmitted to the user authentication system (300) in real time. In response to this, the user authentication system (300) can analyze the video captured in a partial area (1110) within the video in the process of performing user authentication.
[0123] As shown, corresponding to the received instruction, information related to the received instruction can be displayed together on the screen of the user terminal that displays the video captured using the camera. According to one embodiment, the text (1130) indicating the received instruction, that is, "Please look at the face from the front", can be displayed together on the screen of the user terminal that displays the video being captured. In addition to this, the character image (1120) indicating the received instruction can also be displayed together on the screen of the user terminal. Referring to such text (1130) and / or character image (1120), the user can perform an action corresponding to the received instruction. The user authentication system (300) that receives the video of such an action in real time can determine whether the user exists in the video. Also, the user authentication system (300) can extract information about the user's face from the received video.
[0124] FIG. 12 is a drawing showing an example of a screen in which a user's action is captured corresponding to an instruction according to another embodiment of the present disclosure. According to this embodiment, the user terminal can receive an instruction "Please turn your face to the right" from the user authentication system (300). In response to such an instruction, the user can position their face in a specific area (1210) displayed on the screen captured using the camera and perform the action of turning to the right. When such an action of turning the face to the right is performed, the video of the action of turning the user's face to the right being captured can be transmitted to the user authentication system (300) in real time. In response to this, the user authentication system (300) can analyze the video captured in a partial area (1210) within the video in the process of performing user authentication.
[0125] As shown, corresponding to the received command, information related to the received command can be displayed together on the screen of the user terminal that displays the video captured using the camera. According to one embodiment, the text (1230) indicating the received command, that is, "Please turn your face to the right" can be displayed together on the screen of the user terminal that displays the video being captured. In addition to this, the character image (1220) indicating the received command can also be displayed together on the screen of the user terminal. By referring to such text (1230) and / or character image (1220), the user can perform the action corresponding to the received command, and the user authentication system (300) that receives the video of such an action captured in real time can determine whether the user exists in the video.
[0126] FIG. 13 is a drawing showing an example of a screen in which the user's action is captured in response to a command according to still another embodiment of the present disclosure. According to this embodiment, the user terminal can receive a command "Please close your eyes" from the user authentication system (300). In response to such a command, the user can position his / her face in the area (1310) displayed on the screen captured using the camera and perform the action of closing his / her eyes. When such an action is performed, the video of the user's action of closing his / her eyes being captured can be transmitted to the user authentication system in real time. In response to this, the user authentication system (300) can analyze the video captured in a partial area (1310) in the video in the process of performing user authentication.
[0127] In FIG. 13, in response to a received command, information related to the received command can be displayed together on the screen of a user terminal that displays a video captured using a camera. For example, text (1330) indicating the received command, i.e., "Please close your eyes", can be displayed together on the screen of the user terminal that displays the captured video. In addition to this, a character image (1320) indicating the received command can also be displayed together on the screen of the user terminal. By referring to such text (1330) and / or character image (1320), the user can perform an action corresponding to the received command, and the user authentication system (300) that receives the video of such an action in real time can determine whether the user exists in the video.
[0128] FIG. 14 is a drawing showing an example in which a user and the user's identity document are captured together in response to a command according to an embodiment of the present disclosure. According to this embodiment, the user terminal can receive a command "Show your identity document (front side) together with your face" from the user authentication system (300). In response to such a command, as shown in the figure, the user can act so that their face is located in the area (1410) displayed on the screen captured using the camera. At the same time, the user can act so that the identity document is located in the area (1440) displayed on the screen. When such an action is performed, a video of the user's face and identity document being captured can be transmitted to the user authentication system (300) in real time. In response to this, the user authentication system (300) can analyze the video captured in the area (1410) and / or area (1440) in the video in the process of performing user authentication.
[0129] As shown, in response to the received instruction, information related to the received instruction can be displayed together on the screen of the user terminal that displays the video captured using the camera. According to one embodiment, the text (1420) indicating the received instruction, that is, "Please show your identity card (front) together with your face", can be displayed together on the screen of the user terminal that displays the captured video. In addition to this, the image (1430) of the identity card indicating the received instruction can also be displayed together on the screen of the user terminal. Referring to the information thus displayed on the screen, the user can perform the actions corresponding to the received instruction, and the user authentication system (300) that receives the video capturing such actions can extract the user's face from the image of the identity card. The face image extracted from the video capturing the front face in FIG. 11 and the face image extracted from the video capturing the identity card can be compared with each other and used to authenticate the user.
[0130] According to one embodiment, different settings can be applied to the area (1410) where at least a part of the user (here, at least a part of the user including the user's face) is captured and the area (1440) where the identity card is captured. For example, different channels can be applied to the two areas, and the videos captured in the two areas can be transmitted to the user authentication system (300) with the set channels respectively. As another example, different resolutions can be applied to the two areas, and the videos captured in the two areas can be videos captured with different resolutions. Here, the resolution of the video captured in the area (1440) where the identity card is induced to be captured can be higher than the resolution of the area (1410) where at least a part of the user is induced to be captured.
[0131] FIG. 15 is a drawing showing an example of photographing the movement of an identity document in response to an instruction to determine whether an identity document of a user according to an embodiment of the present disclosure exists. According to one embodiment, a user terminal can receive an instruction "Please show your face and the identity document (front side) and move the identity document" from a user authentication system (300). In response to such an instruction, the user can act so that his / her face is located in an area (1510) displayed on a screen photographed using a camera. At the same time, the user can position the identity document in another area (1540) of the screen photographed using the camera and perform an action of moving the identity document. When such an action is performed, a video in which the actions of the user's face and the identity document moving are photographed can be transmitted in real time to the user authentication system (300). In response thereto, the user authentication system (300) can analyze the video photographed in the area (1510) and / or the area (1540) in the video in the process of performing user authentication.
[0132] In FIG. 15, in response to the received instruction, information related to the received instruction can be displayed together on the screen of the user terminal that displays the video photographed using the camera. For example, text (1520) indicating the received instruction, that is, "Please show your face and the identity document (front side) and move the identity document" can be displayed together on the screen of the user terminal that displays the video being photographed. In addition to this, an image (1530) of the identity document indicating the received instruction and the area (1540) of the identity document can also be displayed together on the screen of the user terminal. The user can use such information displayed on the screen to perform an action corresponding to the received instruction, and the user authentication system (300) that has received in real time a video of such an action can determine whether an identity document exists. For example, the user authentication system (300) can determine whether a user's identity document exists in the video based on the movement of the user's identity document obtained by analyzing the video. The user authentication system (300) can be configured to authenticate the user when an identity document exists.
[0133] The above-described user authentication method can also be implemented in a computer-readable code on a computer-readable recording medium. The computer-readable recording medium includes all types of recording devices in which data readable by a computer system is stored. Examples of the computer-readable recording medium include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, and the like. Further, the computer-readable recording medium can be distributed in a computer system connected by a network, and the computer-readable code can be stored and executed in a distributed manner. And the functional programs, codes, and code segments for implementing the above embodiments can be easily inferred by programmers in the technical field to which the present invention pertains.
[0134] The method, operation, or technique of the present disclosure can also be implemented by various means. For example, these techniques can be implemented by hardware, firmware, software, or a combination thereof. One of ordinary skill in the art will understand that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate such interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been generally described above in terms of their functionality. Whether such functionality is implemented as hardware or software will depend upon the particular application and design constraints imposed on the overall system. One of ordinary skill in the art may implement the described functionality in varying ways for each particular application, but such implementations should not be construed as departing from the scope of the present disclosure.
[0135] In a hardware implementation, the processing unit utilized to carry out the techniques can be implemented from one or more ASICs, DSPs, digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described in this disclosure, computers, or combinations thereof.
[0136] Accordingly, the various exemplary logic blocks, modules, and circuits described in conjunction with this disclosure can be implemented or performed in any combination of a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gates or transistor logic, discrete hardware components, or those designed to perform the functions described herein. A general-purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices, e.g., a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other configuration.
[0137] In a firmware and / or software implementation, the techniques can also be implemented with commands stored on a computer-readable medium such as a random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable PROM (EEPROM), flash memory, compact disc (CD), magnetic or optical data storage device, etc. The commands can also be executed by one or more processors and can cause the processors to perform particular aspects of the functions described in this disclosure.
[0138] When implemented in software, the techniques can also be stored on or transmitted across a computer-readable medium as one or more commands or code. A computer-readable medium includes both a computer storage medium and a communication medium including any medium that facilitates transfer of a computer program from one place to another. A storage medium can be any available medium that can be accessed by a computer. By way of example, and not limitation, these computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to transfer or store desired program code in the form of commands or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium.
[0139] For example, when software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, the coaxial cable, fiber optic cable, twisted pair, digital subscriber line, or wireless technologies such as infrared, radio, and microwave are included within the definition of the medium. As used herein, the terms "disk" and "disc" include CD, laser disk, optical disk, DVD (digital versatile disc), floppy disk, and Blu-ray disk, where "disks" typically reproduce data magnetically, while "discs" reproduce data optically using a laser. Such combinations should also be included within the scope of computer-readable media.
[0140] A software module can also reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other known form of storage medium. An exemplary storage medium can be coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium can be integrated into the processor. The processor and the storage medium can reside in an ASIC. The ASIC can reside in a user terminal. Alternatively, the processor and the storage medium can exist as discrete components in a user terminal.
[0141] Although the embodiments described above have been described as utilizing aspects of the presently disclosed subject matter in one or more stand-alone computer systems, the present disclosure is not so limited and can also be implemented in conjunction with any computing environment such as a network or a distributed computing environment. Further, aspects of the subject matter of the present disclosure can also be implemented in a plurality of processing chips or devices, and storage can similarly be affected across a plurality of devices. These devices can also include PCs, network servers, and handheld devices.
[0142] Although the present disclosure has been described in connection with some embodiments, various modifications and changes can be made without departing from the scope of the present disclosure that can be understood by those of ordinary skill in the art to which the invention of the present disclosure pertains. Also, such modifications and changes must be considered to fall within the scope of the claims appended hereto.
Explanation of Reference Numerals
[0143] 100, 100_1, 100_2, 100_3: User terminals 110: Camera 120: User 300: User authentication system 310: Network 412, 438: Communication modules 414, 434: Processors 416, 436: Memories 418, 432: Input / output interfaces 420: Input / output devices 510: Instruction processing module 520: Image extraction module 530: Image analysis module 540: Authentication module
Claims
A user authentication method executed by a user authentication system, comprising: a step in which a communication module of the user authentication system transmits a plurality of instructions for guiding a user to perform a plurality of actions to a user terminal; a step in which the communication module receives a video captured in response to the plurality of instructions from the user terminal; a step in which a processor of the user authentication system determines whether the user exists in the video; when it is determined that the user exists, a step in which the processor authenticates the user based on the face of the user extracted from the video; The step of transmitting the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal includes: a step in which the communication module transmits information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions; The step of transmitting the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal further includes: a step in which the processor randomly selects the plurality of instructions from among a plurality of predetermined instruction candidates; a step in which the communication module transmits the randomly selected plurality of instructions to the user terminal. A user authentication method.
2. The step of receiving the video captured in response to the plurality of instructions from the user terminal includes a step in which the communication module receives the video in real time from the user terminal via a channel for communication with the user terminal. The user authentication method according to claim 1.
3. The video is continuously received via a channel for communication with the user terminal. The user authentication method according to claim 2.
4. The step of determining whether the user exists in the video includes: a step in which the processor analyzes the video to determine whether the user performs a plurality of actions corresponding to the plurality of instructions in the video; when it is determined that the user performs the plurality of actions corresponding to the plurality of instructions, a step in which the processor determines that the user exists in the captured video. The user authentication method according to any one of claims 1 to 3. A user authentication method executed by a user authentication system, comprising: The communication module of the user authentication system transmits a plurality of instructions for guiding a user to perform a plurality of actions to the user terminal; The communication module receives a video captured corresponding to the plurality of instructions from the user terminal; The processor of the user authentication system determines whether the user exists in the video; When it is determined that the user exists, the processor authenticates the user based on the face of the user extracted from the video, The step of transmitting the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal includes the communication module transmitting information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions; The step of receiving a video captured corresponding to the plurality of instructions from the user terminal includes the communication module receiving a face-related video captured corresponding to an instruction for guiding the user terminal to capture the user's face; and the communication module receiving an identity document-related video captured corresponding to an instruction for guiding the user terminal to capture the user's identity document. The step of authenticating the user includes the processor extracting first information about the user's face from the face-related video; the processor extracting second information about the user's face from the identity document-related video; the processor comparing the extracted first information and the extracted second information; and when the extracted first information and the extracted second information are similar, the processor authenticating the user. A user authentication method.
6. The user authentication method according to claim 5, wherein the plurality of instructions include an instruction for guiding the user's front face to be captured.
7. The plurality of instructions include an instruction for guiding the user to move the identity document. The step of receiving the identity document-related video includes the communication module receiving a video of the user's identity document captured from the user terminal based on the instruction. The step of authenticating the user includes the step of the processor determining whether the user's identity document exists in the video based on the movement of the user's identity document obtained by analyzing the video, according to the user authentication method described in claim 5.
8. The identity document related video includes a video in which at least a part of the user and the user's identity document are photographed together. The step of receiving the identity document related video is the step of the communication module receiving, from the user terminal, an area including at least a part of the user on a first channel, and the step of the communication module receiving, from the user terminal, an area including the user's identity document on a second channel, according to the user authentication method described in claim 5 or 6.
9. The step of sending the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal is the step of the communication module sending a first instruction for guiding the user to perform a first action to the user terminal, and The step of receiving the video photographed corresponding to the plurality of instructions from the user terminal is the step of the communication module receiving the video photographed corresponding to the first instruction from the user terminal, and The step of determining whether the user exists in the video includes the step of the processor analyzing the video photographed corresponding to the first instruction and determining whether the user performs the first action in response to the first instruction, according to the user authentication method described in claim 1.
10. The step of sending the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal is when it is determined that the user performs the first action, further including the step of the communication module sending a second instruction for guiding the user to perform a second action to the user terminal, and The step of receiving the video photographed corresponding to the plurality of instructions from the user terminal is further including the step of the communication module receiving the video photographed corresponding to the second instruction from the user terminal. The step of determining whether the user exists in the video further includes the step of the processor analyzing the video captured in response to the second instruction and determining whether the user performs the second action in response to the second instruction. The user authentication method according to claim 9.
11. The step of sending the plurality of instructions for inducing a plurality of actions to the user terminal to the user includes: When it is determined that the user does not perform the first action, the communication module further includes the step of sending a third instruction for inducing a third action to the user terminal to the user. The third instruction is selected based on the difference between the user's action obtained from the analysis of the video captured in response to the first instruction and the first action. The user authentication method according to claim 9 or 10.
12. When it is determined that the user does not perform the first action, the communication module further includes the step of communicating with the user terminal using a channel different from the channel used for communication with the user terminal. The user authentication method according to claim 9.
13. A user authentication method executed by a user authentication system, The communication module of the user authentication system sending a plurality of instructions for inducing a plurality of actions to the user terminal to the user; The communication module receiving a video captured in response to the plurality of instructions from the user terminal; The processor of the user authentication system determining whether the user exists in the video; When it is determined that the user exists, the processor authenticating the user based on the face of the user extracted from the video. The step of sending the plurality of instructions for inducing a plurality of actions to the user terminal to the user includes: The communication module includes the step of sending information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions. The plurality of resolutions corresponding to the plurality of instructions include the resolutions for each of the plurality of regions on the screen where the video captured in response to the plurality of instructions is displayed. The user authentication method.
14. A user authentication method executed by a user authentication system, The communication module of the user authentication system transmits a plurality of instructions for guiding a user to perform a plurality of actions to the user terminal; The communication module receives a video captured in response to the plurality of instructions from the user terminal; The processor of the user authentication system determines whether the user exists in the video; When it is determined that the user exists, the processor authenticates the user based on the face of the user extracted from the video, The step of transmitting the plurality of instructions for guiding a user to perform a plurality of actions to the user terminal includes: The communication module transmits information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions; The plurality of instructions include an instruction for guiding at least a part of the user and the user's identity document to be captured together; A user authentication method, wherein the resolution of the area guided to capture the user's identity document is set higher than the resolution of the area guided to capture at least a part of the user.
15. A user authentication method executed by a user authentication system, comprising: The communication module of the user authentication system transmits a plurality of instructions for guiding a user to perform a plurality of actions to the user terminal; The communication module receives a video captured in response to the plurality of instructions from the user terminal; The processor of the user authentication system determines whether the user exists in the video; When it is determined that the user exists, the processor authenticates the user based on the face of the user extracted from the video; The step of transmitting the plurality of instructions for guiding a user to perform a plurality of actions to the user terminal includes: The communication module transmits information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions; The step of transmitting the plurality of instructions for guiding a user to perform a plurality of actions to the user terminal includes: A user authentication method, which includes transmitting information on the transfer rate corresponding to each of the plurality of instructions to the user terminal together with the plurality of instructions.
16. A computer program stored on a computer-readable recording medium for a computer to execute the user authentication method according to any one of claims 1 to 15.
17. A user authentication system, A communication module configured to send a plurality of instructions for guiding a user to perform a plurality of actions to a user terminal and receive a video captured corresponding to the plurality of instructions from the user terminal; A memory; Including at least one processor coupled to the memory and configured to execute computer-readable instructions included in the memory, The at least one processor, Determine whether the user exists in the video, When it is determined that the user exists, it is further configured to authenticate the user based on the face of the user extracted from the video, Sending the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal, Includes sending information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions, Sending the plurality of instructions for guiding the user's plurality of actions to the user terminal further includes, Randomly selecting the plurality of instructions from among a plurality of predetermined instruction candidates; And sending the randomly selected plurality of instructions to the user terminal. A user authentication system.
18. A user authentication system, A communication module configured to send a plurality of instructions for guiding a user to perform a plurality of actions to a user terminal and receive a video captured corresponding to the plurality of instructions from the user terminal; A memory; Including at least one processor coupled to the memory and configured to execute computer-readable instructions included in the memory, The at least one processor, Determine whether the user exists in the video, When it is determined that the user exists, it is further configured to authenticate the user based on the face of the user extracted from the video, Sending the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal, Includes sending information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions, Receiving a video captured in response to the plurality of instructions from the user terminal includes receiving a face-related video captured in response to an instruction for guiding the user terminal to capture the user's face, and receiving an identity document-related video captured in response to an instruction for guiding the user terminal to capture the user's identity document, Authenticating the user includes extracting first information about the user's face from the face-related video, extracting second information about the user's face from the identity document-related video, comparing the extracted first information and the extracted second information, and when the extracted first information and the extracted second information are similar, authenticating the user. A user authentication system. **Claim 19**: A user authentication system, comprising a communication module configured to send a plurality of instructions for guiding a user to perform a plurality of actions to a user terminal and receive a video captured in response to the plurality of instructions from the user terminal; a memory; and at least one processor coupled to the memory and configured to execute computer-readable instructions included in the memory, wherein the at least one processor is configured to determine whether the user exists in the video, and when it is determined that the user exists, further configured to authenticate the user based on the face of the user extracted from the video. Sending the plurality of instructions for guiding the user to perform a plurality of actions to the user terminal includes sending information about a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions. The plurality of resolutions corresponding to the plurality of instructions include resolutions for respective ones of a plurality of regions on a screen on which a video captured in response to the plurality of instructions is displayed. A user authentication system. **Claim 20**: A user authentication system, comprising a communication module configured to send a plurality of instructions for guiding a user to perform a plurality of actions to a user terminal and receive a video captured in response to the plurality of instructions from the user terminal; a memory; and at least one processor coupled to the memory and configured to execute computer-readable instructions included in the memory, The at least one processor is configured to determine whether the user is present in the video, and, if the user is determined to be present, further configured to authenticate the user based on the face of the user extracted from the video, sending the plurality of instructions for inducing a plurality of actions to the user terminal to the user terminal includes sending information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions, wherein the plurality of instructions includes an instruction for inducing at least a part of the user and the user's identity document to be photographed together, A user authentication system, wherein the resolution of the area induced to photograph the user's identity document is set higher than the resolution of the area induced to photograph at least a part of the user. **Claim 21** A user authentication system, comprising: a communication module configured to send a plurality of instructions for inducing a plurality of actions to a user terminal and receive a video captured corresponding to the plurality of instructions from the user terminal; a memory; at least one processor coupled to the memory and configured to execute computer-readable instructions included in the memory, wherein the at least one processor is configured to determine whether the user is present in the video, and, if the user is determined to be present, further configured to authenticate the user based on the face of the user extracted from the video, sending the plurality of instructions for inducing a plurality of actions to the user terminal to the user terminal includes sending information on a plurality of resolutions corresponding to the plurality of instructions to the user terminal together with the plurality of instructions, sending the plurality of instructions for inducing a plurality of actions to the user terminal to the user terminal includes sending information on a transfer rate corresponding to each of the plurality of instructions to the user terminal together with the plurality of instructions. **Claim 22** The user authentication system according to any one of claims 17 to 21, wherein the communication module is further configured to receive the video in real time from the user terminal via a channel for communication with the user terminal.
Citation Information
Patent Citations
Form attachment system
JP1989081074A
JPP6541140B
Computer and method for user recognition thereof
KR100597753B1
User authentication method and system
KR101861080B1
Networked video surveillance system
US20080303903A1