Procedure approval device and method for a virtual authentication code infrastructure
The virtual authentication code infrastructure addresses user fatigue and security vulnerabilities by generating unique codes at intervals, authenticating users without repeated login, and enhancing security through biometric and card data integration.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- SSENSTONE INC
- Filing Date
- 2025-01-16
- Publication Date
- 2026-05-08
AI Technical Summary
Existing OTP authentication methods require users to log in each time for authentication, and remote corporate account openings via agents introduce security vulnerabilities and repetitive authentication procedures, leading to user fatigue and potential fraud.
A non-face-to-face procedure approval system using a virtual authentication code infrastructure that generates unique codes at specific intervals, authenticates users without repeated login, and approves procedures based on identification codes, incorporating biometric and card data for enhanced security.
Provides secure, user-friendly authentication by generating unique codes at each interval, confirming user identity without repeated login, preventing code leakage, and minimizing process changes for enhanced security.
Smart Images

Figure 0007855743000001 
Figure 0007855743000002 
Figure 0007855743000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a procedure approval device and method for a virtual authentication code infrastructure, and more particularly to a method and device for generating a virtual authentication code for each user, generated in a way that does not duplicate at each point in time, authenticating the user based on the virtual authentication code, and approving the procedure requested by the user. [Background technology]
[0002] OTP (One-Time Password) is a user authentication method that utilizes a randomly generated one-time password. This OTP authentication method is a system introduced to enhance security, and by generating a one-time password each time a user logs in and performing user authentication, it overcomes the security vulnerabilities that arise from the repeated use of the same password.
[0003] However, existing OTP authentication methods require users to log in by entering a password at the start of the process to determine who the user is. After that, an OTP is generated using an OTP function assigned to that user, and OTP authentication is completed through that OTP. This method has the disadvantage that users must log in each time they want to perform OTP authentication. Therefore, there is a need for an invention that can generate an OTP and perform user authentication without requiring the user to log in each time they request authentication.
[0004] On the other hand, since January 1, 2020, corporations have been able to open corporate accounts remotely through agents of their officers or employees. In other words, financial institutions can approve the opening of an account for a corporation if the corporate customer goes through a remote, real-name verification procedure via an agent. However, this new policy also has its drawbacks and security vulnerabilities. The representative of the corporation must entrust their official seal and documents to the agent. Therefore, there is concern about fraudulent use through the theft of the name, and if the agent forges the representative's signature or steals the name, it remains difficult to verify the transaction.
[0005] Therefore, a system is needed that generates identification information that can identify the representative and the agent authorized to manage the corporate bank account, and uses this identification information to identify each representative and agent and proceed with financial transactions. In particular, in the case of identification information, it is desirable to generate and provide a virtual code to prevent leakage to third parties. Furthermore, many financial transactions are currently conducted via computers and mobile terminals, but the repetitive authentication procedures for each financial transaction cause users to feel fatigued when using the program or application. Therefore, a system is needed that simplifies user authentication using only one piece of identification information generated based on user information.
[0006] Furthermore, the need for such measures is not limited to the aforementioned financial transactions. In certain companies, institutions, etc., when performing procedures that require approval from a supervisor, it is also possible to request approval or authorization for such procedures through a virtual code that can authenticate the supervisor.
[0007] However, to date, there has been no adequate authentication method, particularly one involving virtual codes, for various financial transactions and procedures, not just for opening corporate bank accounts as mentioned above. [Overview of the project] [Problems that the invention aims to solve]
[0008] The problem that this invention aims to solve is to provide a procedure approval device and method for a virtual authentication code infrastructure.
[0009] The problems that this invention aims to solve are not limited to those mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the following description. [Means for solving the problem]
[0010] A non-face-to-face procedure approval device and method for a virtual authentication code infrastructure, according to one aspect of the present invention for solving the aforementioned problems, is a method performed by a procedure approval server (hereinafter referred to as "server"), and includes the steps of: the server receiving a virtual authentication code (the virtual authentication code is generated by a virtual authentication code generation function in a user terminal) and being requested to approve a procedure; the server searching for a storage space for user authentication information relating to the user in a storage location search algorithm based on the virtual authentication code; the server extracting user authentication information stored in the storage location and authenticating the user based on the user authentication information; and approving the procedure once user authentication is complete. The procedure includes multiple types of procedures, each of which has an identification code already set for that procedure, the virtual authentication code is generated based on user identification information and the identification code, set at specific time intervals, and changed with each unit count that changes as the time interval elapses, and the procedure approval step approves only procedures that correspond to the identification code.
[0011] Alternatively, the virtual authentication code is generated by combining a first code and a second code, which are included in a plurality of detail codes, according to a specific rule, and although there is a correlation between the first code and the second code, the first code determines the search starting point related to the storage location on the server, and the second code determines the search path related to the storage location from the search starting point.
[0012] Alternatively, the validity period data for the virtual authentication code is set via the user terminal, and a third code, which is included in a plurality of detail codes, is further generated based on the validity period data, and the virtual authentication code is generated by combining the first code, the second code, and the third code according to a specific rule.
[0013] Alternatively, the virtual authentication code includes a virtual security code generated based on the time data at which the virtual authentication code was generated, or the time data at which the user terminal requested the procedure approval, and the server further verifies the virtual authentication code based on the virtual security code. Alternatively, the virtual authentication code is generated based on either the card data provided to the user terminal or the biometric data provided to the user terminal.
[0014] Alternatively, among the multiple procedure types, the virtual authentication code generated by the first procedure type includes a first virtual authentication code and a second virtual authentication code, wherein the first virtual authentication code is generated by a first virtual authentication code generation function in the first user terminal based on first user information, and the second virtual authentication code is generated by a second virtual authentication code generation function in the second user terminal based on second user information, and the stage in which procedure approval is requested involves receiving the first virtual authentication code and the second virtual authentication code and requesting procedure approval of the first type, and the procedure approval stage grants approval only if the procedure identification codes of the first virtual authentication code and the second virtual authentication code are the same.
[0015] Alternatively, the search step searches for a first storage location in the storage location search algorithm where the first user authentication information of the first user of the first user is stored, based on the first virtual authentication code, and searches for a second storage location in the storage location search algorithm where the second user authentication information of the second user is stored, based on the second virtual authentication code, provided that the first and second storage locations are set so as not to overlap by the unit count.
[0016] Alternatively, the server further includes a step of receiving second user information relating to the first type of procedure from the first user terminal, the first virtual authentication code being generated based on the second user information provided from the first user terminal, and the authentication step comparing the second user information provided from the first user terminal with the second user authentication information extracted from the second storage location searched based on the second virtual authentication code, to authenticate the second user relating to the first type of procedure.
[0017] A procedure approval device for a virtual authentication code infrastructure in another embodiment includes a communication unit that receives a virtual authentication code and is requested to approve the procedure, a detail code extraction unit that extracts one or more detail codes included in the virtual authentication code, a storage location search unit that searches for a storage location where user authentication information is registered in a storage location search algorithm based on the extracted detail code, a user verification unit that extracts the user authentication information and authenticates the user, and a procedure approval unit that approves the procedure once the user authentication is complete. However, the procedure includes multiple types of procedures, each of the multiple types of procedures already has an identification code corresponding to that procedure set, and the virtual authentication code is generated based on the identification code, set at specific time intervals, and changed with each unit count that changes as the time interval elapses.
[0018] In addition, other methods, other systems for embodying the present invention, and computer-readable recording media for recording computer programs for performing the said methods may be further provided. [Effect of the Invention]
[0019] According to the present invention as described above, it has the following various effects.
[0020] First, every time the user requests user authentication for procedure authentication, a virtual authentication code can be provided that is newly generated at a unit count interval without being repeatedly generated.
[0021] Second, by comparing the generation time of the virtual authentication code newly generated at a unit count interval by the virtual authentication code generation means with the reception time of the virtual authentication code received by the virtual authentication code verification device, it is possible to confirm whether the virtual authentication code generated by the virtual authentication code generation means is the code generated at the current time. That is, it is possible to determine whether the user requested user authentication for financial transaction approval using the virtual authentication code generated at the current time.
[0022] Third, the server can confirm who the authenticated user is without logging in each time a user authentication request is made by using the virtual authentication code to extract the user information stored in the server.
[0023] Fourth, for each unit count, by making it so that the virtual authentication code that is newly generated and repeated does not appear within the defined entire cycle, or by randomizing the procedure for generating the virtual authentication code from which the server can extract user information when the virtual authentication code leaks, it provides the effect that user information does not leak even when the virtual authentication code leaks.
[0024] Fifthly, a virtual authentication code generation function is stored in a virtual authentication code generation device (e.g., a user terminal) that generates a virtual authentication code. For a virtual authentication code verification device (e.g., a server, etc.) that uses the virtual authentication code to extract user information and verify whether the virtual authentication code is a normal code, an algorithm for virtual authentication code verification may be added. Therefore, it is possible to prevent the outflow of algorithms for generating and verifying virtual authentication codes.
[0025] Sixthly, according to the present invention, an algorithm for virtual authentication code generation and for searching user authentication information may be added, so that the existing process can be maintained as it is. Through this, in order to enhance security, the parts that must be changed within the existing process can be minimized, and users do not have to perform separate steps for security improvement.
[0026] The effects of the present invention are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the following description.
Brief Description of the Drawings
[0027] [Figure 1] It is a configuration diagram of a procedure approval system using a virtual authentication code according to an embodiment of the present invention. [Figure 2] It is a flowchart schematically showing a procedure approval method based on a virtual authentication code according to an embodiment of the present invention. [Figure 3] It is a configuration diagram of a virtual authentication code generation means according to an embodiment of the present invention. [Figure 4] It is an exemplary diagram showing a place where a financial transaction based on a virtual authentication code is performed according to an embodiment of the present invention. [Figure 5] It is a configuration diagram of a virtual authentication code verification device according to an embodiment of the present invention. [Figure 6] It is a diagram showing a method for a K - polygon storage position search algorithm to search for the storage position of user authentication information according to an embodiment of the present invention. [Figure 7] This is an illustrative diagram of a user authentication method relating to a first type of procedure according to one embodiment of the present invention. [Modes for carrying out the invention]
[0028] The advantages, features, and methods for achieving them of the present invention will become clearer with reference to the embodiments described in detail below, along with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below and can be embodied in a variety of other forms, and these embodiments are merely provided to complete the disclosure of the present invention and to fully inform those skilled in the art of the scope of the invention of the present invention, and the present invention is defined only by the scope of the claims.
[0029] The terms used herein are for illustrative purposes only and do not limit the present invention. In this specification, the singular form includes the plural form unless otherwise specified in the text. The terms “comprise” and / or “comprising” as used in the specification do not preclude the existence or addition of one or more other components in addition to the components mentioned. Throughout the specification, the same reference numeral refers to the same component, and “and / or” includes each of the components mentioned and all one or more combinations thereof. It goes without saying that even though terms such as “first,” “second,” etc., are used to describe various components, those components are not limited by those terms. Those terms are simply used to distinguish one component from another. Thus, it goes without saying that the first component mentioned below is also the second component within the technical concept of the present invention.
[0030] Unless otherwise defined, all terms used herein (including technical and scientific terms) are also used in a sense that can be commonly understood by those skilled in the art in which the present invention pertains. Furthermore, commonly used predefined terms are not to be interpreted ideally or excessively unless explicitly defined otherwise.
[0031] In this specification, “user authentication” means a procedure that authorizes a user to pass through online or offline areas where security is required, such as access, login, or financial transactions.
[0032] In this specification, "financial transaction" means a procedure conducted with a financial institution. "Financial transaction" includes card payments, deposits and withdrawals from bank accounts, and opening a bank account.
[0033] In this specification, “characters” are components that make up a code, and include all or part of uppercase letters, lowercase letters, numbers, and special characters.
[0034] In this specification, "code" means a string of characters arranged in a sequence.
[0035] In this specification, "virtual authentication code" means a number generated by the virtual card number generation means based on information provided by the user, and a code used by the virtual card number verification means to retrieve the user's authentication information. In other words, "virtual authentication code" means a temporary virtual code assigned to each unit count so that the user can be authenticated after the authentication information has been retrieved and extracted.
[0036] In this specification, “detailed code” means a part of the code included in the virtual card number.
[0037] In this specification, “unit count” is a unit defined to be set for a specific time interval and to change as the time interval elapses. For example, 1 count is also used when set for a specific time interval (e.g., 1.5 seconds).
[0038] In this specification, "virtual authentication code generation function" means a function used to generate a virtual authentication code.
[0039] In this specification, "rolling motion" means that an object undergoes translational motion while rotating. That is, "rolling motion" means moving while simultaneously performing rotational and translational motion, and that each point of the rotating object moves while sequentially touching the axis of movement.
[0040] In this specification, "storage location" means the point on the track (count) corresponding to the time when the user registers user authentication information with the server by the user, or the time when the user information is first received by the server by the virtual authentication code generation means.
[0041] The embodiments of the present invention will be described in detail below with reference to the attached drawings.
[0042] Figure 1 is a diagram illustrating the configuration of a procedure approval system using a virtual authentication code, according to one embodiment of the present invention.
[0043] As illustrated in Figure 1, the procedure approval system using a virtual authentication code includes a virtual authentication code generation means 10 and a virtual authentication code verification means 20.
[0044] In this specification, “authority” means the right or qualification required to authorize a procedure requested by the user in a particular field, procedure, or transaction. Authorization is performed through user authentication based on a virtual authentication code within that field.
[0045] Furthermore, a user's "procedure approval request" is a request for approval of a specific procedure in a particular technical or industrial field related to the user. For example, this could include requesting the server of a financial institution to approve financial transactions such as logging in, making account transfers, or deposits and withdrawals through applications or programs provided in the financial transaction field. Moreover, "procedure approval requests" can also be made offline. For example, if a user displays their virtual authentication code on a document and submits it in person to a financial institution, an employee of that financial institution will request authentication of the user and approval of the procedure related to the financial transaction corresponding to the document from the financial institution's server, and ultimately request procedure approval.
[0046] Furthermore, it will be obvious to those skilled in the art that "requests for procedural approval" are not limited to financial transactions. For example, this includes requests for "user verification" and "authority verification" necessary for approving specific procedures in business processes within a company or institution.
[0047] In this specification, in order to aid in understanding the invention, "procedural approval" is explained using "financial transactions" as an example. However, this is not intended to limit the scope of the present invention.
[0048] The virtual authentication code generation means 10 refers to a device that has a dedicated program or application (hereinafter referred to as the dedicated program) built in or installed for generating a virtual authentication code based on user information. The virtual authentication code generation means 10 generates a virtual authentication code that includes information that allows the virtual authentication code verification means 20, described later, to retrieve the user's authentication information. More specifically, the virtual authentication code is generated by a virtual authentication code generation function based on user information. For the purpose of understanding the present invention, the virtual authentication code generation means 10 will be described below using the user terminal 100 as an example.
[0049] The virtual authentication code verification means 20 searches for the storage location where the user's authentication information is registered, based on the virtual authentication code generated by the virtual authentication code generation means 10, and extracts the user authentication information stored at that location. Then, based on the extracted user authentication information, it performs user authentication for the financial transaction approval request.
[0050] Furthermore, the virtual authentication code verification means 20 verifies whether the virtual authentication code is a successfully generated code based on the time the virtual authentication code is received and the time the virtual authentication code is generated in the virtual code generation means 20, i.e., the user terminal 100. The virtual authentication code verification means 20 can store the same virtual authentication code generation function as the virtual authentication code generation means 10 in order to search for user authentication information from the virtual authentication code received from the virtual authentication code generation means 10. On the other hand, the method for verifying the virtual authentication code and performing user authentication will be described in detail later. Hereinafter, for the understanding of the present invention, the virtual authentication code verification means 20 will be described as a financial transaction settlement server 200 (hereinafter referred to as "server").
[0051] In one embodiment of the present invention, a program dedicated to virtual authentication codes is provided with user data from a user for generating virtual authentication codes.
[0052] In this embodiment, the virtual authentication code dedicated program is also a dedicated program or application provided by a specific financial institution server. Alternatively, it is also a dedicated program or application necessary for performing a specific procedure. For example, a user can register user information with the financial institution server via a dedicated program or application provided by the financial institution.
[0053] For example, if user information (such as resident registration number and mobile phone number) provided to a dedicated program for membership registration is provided to a financial company's server via that program or application, the financial company's server will store the user information in a specific account.
[0054] On the other hand, in one embodiment of the present invention, user information also includes the user's biometric information. For example, this includes the user's facial information and fingerprint information. This biometric information is registered in the financial company server 20 along with the user's other user information during the user's membership registration process, but it may also be registered separately during the additional setting process for the user authentication means. It goes without saying that even when registered through such an additional setting process, the biometric information is stored in the same count as other already stored user information.
[0055] On the other hand, in another embodiment of the present invention, the user information is also the card data of the user registered in the financial company server 200. For example, if a user tags a card issued by a specific financial company to a user terminal, the card data stored on the IC chip in the card is transmitted to the user terminal 100. At this time, the user terminal 100 generates a virtual authentication code based on the card data. This is not limited to the financial company server, but can also be done via a user's card issued by a specific company, corporation, or institution, whose data is registered in the server.
[0056] In one embodiment of the present invention, a dedicated program plays the role of generating a virtual authentication code for user authentication using user information provided by the user. The dedicated program includes a virtual authentication code generation function, which generates a virtual authentication code using all or part of a specific user information from among multiple user information.
[0057] For example, the dedicated program can use card data provided by the user as seed data for a virtual authentication code generation function to generate a virtual authentication code. Alternatively, the dedicated program can use a combined serial number, obtained by combining the card data and the dedicated program's serial number, as seed data for a virtual authentication code generation function.
[0058] Furthermore, in one embodiment, the dedicated program performs the role of registering user information with the server, as described above. That is, the user registers user information with the dedicated program built into or installed on the user terminal 100, and the dedicated program transmits and registers the user information with the server 200.
[0059] As a specific example, the dedicated program generates user information either by receiving user information from the user or based on the user's login information for the dedicated program. The dedicated program then transmits the user information to the server 200.
[0060] When server 200 registers user information in a specific count, the dedicated program receives a virtual authentication code generation function or configuration data for identifying the virtual authentication code generation function from server 200. Through this, the dedicated program also includes a virtual authentication code generation function that generates a virtual authentication code that enables the search for the specific count in which user information is registered within server 200.
[0061] Furthermore, the server 200 stores user information provided by the dedicated program, or user information already stored within the server 200, in a specific account upon request from the dedicated program. On the other hand, at least one user information from the aforementioned user information is registered with the server 200. This specific user information registered with the server is used for user authentication and will be described below as user authentication information.
[0062] Figure 2 is a flowchart illustrating a procedure approval method for a virtual authentication code infrastructure according to one embodiment of the present invention. Figure 3 is a configuration diagram of a virtual authentication code generation means according to one embodiment of the present invention.
[0063] Referring to Figure 2, the financial transaction settlement server 200 receives a virtual authentication code from the user terminal 100 and is requested to approve the procedure (S510).
[0064] In this embodiment, the virtual authentication code is generated by a virtual authentication code generation function in a user terminal 100, which is one of the virtual authentication code generation means 10. The method for generating the virtual authentication code will be described below with reference to Figure 3. Referring to Figure 3, the virtual authentication code generation means 10 includes a detail code generation unit 110, a virtual authentication code generation unit 120, a communication unit 130, and a memory 140.
[0065] In one embodiment, the virtual authentication code generation means 10 is also a user terminal 100 on which a program (i.e., an application) for generating virtual authentication codes for user authentication is installed.
[0066] The detail code generation unit 110 is responsible for generating one or more detail codes based on user information. The virtual authentication code generation function includes one or more detail code generation functions. For example, if the virtual authentication code includes multiple detail codes, the virtual authentication code generation function uses multiple detail code generation functions to generate multiple detail codes, and then uses a detail code combining function to combine the multiple detail codes to generate the virtual authentication code.
[0067] In this case, the virtual authentication code is generated for each unit count by the virtual authentication code generation means 10, that is, by a dedicated program built into or installed inside the user terminal 100, and a mobile OTP (mOTP: mobile one time password) may be an example of this.
[0068] In one embodiment of the present invention, the virtual authentication code generation means 10 can use the resident registration number from the user information as one of the seed data for the virtual authentication code generation function. As a specific example, the detail code generation unit 110 uses one detail code generation function and uses a combined serial number, which is a combination of the resident registration number stored in memory 140 and the serial number of a dedicated program built into or installed in the virtual authentication code generation device 100, as seed data for each detail code generation function to generate each detail code. At this time, the detail code generation unit 110 can also use the time when user authentication is requested by the user, or a count value, to generate each detail code.
[0069] More preferably, the virtual authentication code generation means 10 does not store user information in memory (not shown), but provides it to the user each time a virtual authentication code is generated. For example, the virtual authentication code of the aforementioned card data infrastructure may fall under this category. In order to generate the virtual authentication code, the virtual authentication code generation means 10 requests the user to provide card data. Then, based on the card data entered by the user, it generates the virtual authentication code.
[0070] In one embodiment, the detail code generation unit 110 includes a first function and a second function as detail code generation functions, and can generate a first code and a second code. In this case, the virtual authentication code generation means 10 includes only a first function for generating the first code and a second function for generating the second code as detail code generation functions in order to enhance security, but does not include data relating to the correlation between the first code and the second code.
[0071] The virtual authentication code generation unit 120 is responsible for generating a virtual authentication code by combining one or more detail codes using a virtual authentication code generation function. In one embodiment, the virtual authentication code is generated by combining multiple detail codes according to a specific rule. The virtual authentication code generation function includes a rule for combining multiple detail codes (i.e., a detail code combination function). That is, the virtual authentication code generation unit 120 can combine one or more detail codes using the detail code combination function included in the virtual authentication code generation function.
[0072] Various methods can be applied to combine multiple detail codes to generate a single virtual authentication code. As an example of a detail code combining function, the virtual authentication code generation unit 220 can generate a virtual authentication code by alternating between an N-digit first code and an N-digit second code. Another example is that the detail code combining function is a function that combines the second code after the first code. As the number of detail codes included in the virtual authentication code increases, various detail code combining functions can also be generated.
[0073] Furthermore, in one embodiment, if the virtual authentication code is generated by a combination of a first code and a second code according to a specific rule, the first code and the second code can each play a role in searching for the storage location of user authentication information within a storage location search algorithm where user information is stored. For example, the first code sets the starting point for the storage location search, and the second code sets the search path from the starting point to the storage location of the user authentication information using a specific search method. That is, if the virtual authentication code generation means 10 provides a successfully generated virtual authentication code for each unit count, the virtual authentication code verification means 20 determines that the point reached by moving along the search path corresponding to the second code from the search starting point corresponding to the first code included in the virtual authentication code is the location where user information is stored (i.e., the storage location of user authentication information). A specific method for searching for the storage location of user authentication information based on the first code and the second code constituting the virtual authentication code will be described later.
[0074] In one embodiment of the method by which the detail code generation unit 110 generates detail codes, the detail code generation unit 110 generates a new detail code for each unit count, and thereby the virtual authentication code generation means 10 generates a new virtual authentication code for each unit count. The virtual authentication codes newly generated for each unit count are not duplicated. Specifically, the detail code generation unit 110 can be configured so that the virtual authentication codes newly generated for each unit count are not duplicated for a specific user or a specific virtual authentication code generation means 10 for a predetermined period of time, and not only are they not duplicated for users belonging to a specific group.
[0075] As a specific embodiment to prevent duplicate generation of virtual authentication codes, when generating an N-digit first or second code using M characters, the detail code generation function included in the virtual authentication code generation function is M N Each code can be generated as either a first or second code, and each code is matched for each count from the initial point when the detailed code generation function is driven. For example, if the unit count is set to 1 second, a different M will be generated every second from the point when the detailed code generation function is first driven. N The code is matched. Then, the period during which a specific detail code generation function is used, or the usage period of the virtual authentication code generation means 10 (for example, the validity period of the user terminal on which the application for generating virtual authentication codes is installed) is set to M N The duration of time corresponding to a count (for example, if 1 count is 1 second, then M N If the time length is set to be shorter than a second, the first or second code will not be generated twice during the usage cycle. In other words, when the count increases over time, if a user accesses user authentication information at a specific point in time and requests the virtual authentication code generation means 10 to generate a virtual authentication code, the virtual authentication code generation means 10 can generate a code value that matches the count corresponding to that specific point in time as the first or second code.
[0076] Specifically, if the code can include uppercase letters of the alphabet and numbers from 0 to 9 (i.e., 36 characters are used), and 6 digits are assigned to the first code and the second code, the virtual authentication code generation means 10 will use 36 characters as the first code and the second code. 6 It can provide individual codes. In this case, the virtual authentication code generation means 10 can match each code with each count and provide a modified first code and a modified second code for each count.
[0077] As another specific embodiment for preventing duplicate generation of virtual authentication codes, once the usage cycle of the virtual authentication code generation means 10 has elapsed, the function that generates the first code or the second code (i.e., the first function or the second function) is changed, or the matching relationship between the first code and the second code is changed, so that a different virtual authentication code is generated than in the previous usage cycle. If the virtual authentication code is a combination of a first code generated by the first function and a second code generated by the second function, if the first code generation function or the second code generation function is changed, the virtual authentication code generation means 10 can apply a virtual authentication code generation function that generates a different virtual authentication code than in the previous cycle to the new usage cycle, because the procedure in which the first code or the second code appears is different from that of the previous usage cycle. Furthermore, the virtual authentication code generation means 10 can select the first function and the second function so that the same virtual authentication code used in a previous usage cycle does not appear as the virtual authentication code for each count in the new usage cycle (i.e., the matching relationship between the first code generated by the first function and the second code generated by the second function is not included in the matching relationships included in the previous usage cycle for all counts in the new usage cycle). N After a usage cycle in which each code can be applied once has elapsed, the virtual authentication code generation function can be adjusted or updated to apply a virtual authentication code generation function for a new usage cycle in which no virtual authentication codes overlapping with previous usage cycles are generated.
[0078] Furthermore, as yet another specific embodiment to prevent the duplicate generation of virtual authentication codes, in order to prevent the occurrence of duplicate virtual authentication codes unrelated to the user throughout the entire cycle, the first code is set as a code value corresponding to the time (or count) when a virtual authentication code generation request is made, from among the codes matched for each count from the initial point in time when the first function is driven, and the second code is set as a code value generated by reflecting values that always exist differently at the same time for each user authentication information 10 (i.e., the user's resident registration number, mobile phone number, set password, etc.), and the virtual authentication code can be used as a code value that is a combination of the first code and the second code. The first code will have a different code value for each count, and the second code will have a different code value for each virtual authentication code generation means 10 at the same time, and the virtual authentication code that is a combination of the first code and the second code will output a different code value for all users at all time points.
[0079] In another embodiment, the virtual authentication code generation function (or detailed code generation function) may be subject to one of a number of sorting rules for arranging M characters in ascending order. That is, the virtual authentication code generation means 10 can apply a variety of sorting rules for arranging M characters in ascending order to the detailed code generation function included within the virtual authentication code generation function. For example, the sorting rule for arranging uppercase letters in ascending order may be the general order A, B, C, ..., Z, or A, C, B, ..., Z. In the virtual authentication code generation function, different sorting rules result in different order in which codes are matched to each count from the initial point when the virtual authentication code generation function is driven.
[0080] Furthermore, in one embodiment of the present invention, the virtual authentication code further includes a virtual security code. For example, the virtual authentication code includes a plurality of detail codes and a virtual security code. The security code of the virtual authentication code is used to verify whether or not it is a valid virtual authentication code. For this purpose, although not clearly shown in the drawings, the virtual authentication code generation means also further includes a security code generation function. In this case, the security code generation function uses time data and user information as function values to generate a security code of a specific number of digits. The time data is the time when user authentication and financial transaction approval are requested from the user terminal. However, it is not limited to this. On the other hand, a method for verifying the virtual authentication code based on the virtual security code will be described in detail later.
[0081] In one embodiment of the present invention, the virtual authentication code generation means 10 can set the validity period data (time stamp) of the generated virtual authentication code. That is, it sets the validity period during which the generated virtual authentication code can be used for user authentication. In this case, the validity period data of the virtual authentication code can also be set to differ depending on the type of financial transaction described above.
[0082] Furthermore, in one embodiment of the present invention, the virtual authentication code generation means 10 further includes a third detail code generation function, and can apply the validity time data to the third detail code generation function to generate the third detail code. In this case, the first detail code, the second detail code, and the third detail code are combined according to specific rules by a detail code combination function. At this time, the virtual authentication code verification means 20 can apply the received virtual authentication code to the detail code combination function and extract the third detail code relating to the validity time data. The virtual authentication code verification means 20 then determines whether the time when the virtual authentication code was received from the user terminal 100, which is the virtual authentication code generation means 10 (the time when approval of the financial transaction was requested), falls within the validity time data. If the time when the virtual authentication code was received falls outside the validity time data, the financial transaction requested by the user terminal 100 is not approved. Through this, repeated reuse of the virtual authentication code is prevented, security is enhanced, and even if the virtual authentication code is leaked to a third party, its use can be prevented.
[0083] The virtual authentication code provision unit 130 provides the generated virtual authentication code to the virtual authentication code verification means 20 and requests user authentication. More precisely, it sends the virtual authentication code to the server 200 and requests approval for a specific financial transaction.
[0084] On the other hand, although not clearly shown in the drawings, the virtual authentication code providing unit 130 includes all or part of the wireless internet module, short-range communication module, IC chip, magnetic field generating unit, and display unit.
[0085] The wireless internet module refers to a module for wireless internet connectivity, which may be built into or mounted on the mobile terminal 100. Examples of wireless internet technologies that may be used include WLAN (wireless local area network) (Wi-Fi), Wibro (wireless broadband), WiMAX (world interoperability for microwave access), HSDPA (high-speed downlink packet access), LTE (long-term evolution), and LTE-A (long-term evolution-advanced). For example, if the virtual authentication code generation means 10 is a mobile terminal with an app card application installed, when purchasing goods from a shopping application or shopping website, the virtual authentication code generation means 10 can transmit a virtual authentication code to the financial settlement server 20 via wireless internet communication through a payment settlement service server (i.e., PG's server).
[0086] The term "short-range communication module" refers to a module for short-range communication. Short-range communication technologies that can be used include Bluetooth®, BLE (Bluetooth Low Energy), Beacon, RFID (Radio Frequency Identification), NFC (Near Field Communication), Infrared Data Association (IrDA), Ultra Wide Band (UWB), and ZigBee.
[0087] The display unit (not shown) also includes at least one of the following: liquid crystal display, thin film transistor-liquid crystal display, organic light-emitting diode, flexible display, or e-paper.
[0088] In one embodiment of the present invention, the virtual authentication code providing unit 130 outputs a virtual authentication code to an external source. For example, when a user makes a payment based on a virtual authentication code and user authentication is performed, the virtual authentication code is output to a display unit (not shown) so that the user can visually confirm or copy the virtual authentication code and embed it in another program or web page. That is, the user can embed the virtual authentication code output on the screen of the user terminal 100 into a program or web page and provide the virtual authentication code to the financial company server 200.
[0089] The display unit visually outputs the virtual authentication code generated by the virtual card number generation unit 120 to the outside.
[0090] Figure 4 is an illustrative diagram showing how a financial transaction is performed using a virtual authentication code infrastructure according to one embodiment of the present invention.
[0091] Referring to Figure 4, the user executes the financial institution's program using a device other than the user terminal 100, which is the virtual authentication code generation means 10. At this time, the user can request approval of the login procedure based on a virtual authentication code 310, in addition to existing authentication means such as an official certificate, UID (user identification), and password, as an authentication means for login. At this time, the user can request approval from the server 200 for login by entering the virtual authentication code, which is generated via the user terminal 100 and displayed on the display unit, into the device.
[0092] Existing user authentication methods, such as official certificates and user UIDs (user identification), have limited usage periods. Therefore, with official certificates, once the usage period expires, a renewed certificate must be registered, and with user UIDs, the password must be changed periodically. However, using virtual authentication codes allows for the generation of unique virtual authentication codes without such periodic updates or changes, thus providing user convenience.
[0093] In addition, virtual authentication codes can be used in a variety of other financial transactions. For example, a user can execute a transfer transaction to a third-party account while running a program of a specific banking institution via a user terminal 100. In this case, the server 200 will request the user to perform a user authentication procedure, and the user will enter a virtual authentication code generated from the user terminal 100, as in the method described above, and then request approval for the transfer transaction. In this way, the user can proceed with a rapid financial transaction based on a single virtual authentication code generated via the user terminal 100, which is the virtual authentication code generation means 10, without the need for repetitive authentication procedures.
[0094] In one embodiment of the present invention, each type of procedure may be assigned an identification code in advance. For example, each procedure such as login, account transfer, and account opening may be assigned an identification code that can identify the procedure.
[0095] In this embodiment, the virtual authentication code is also generated based on the identification code. Specifically, the virtual authentication code generation unit 120 can generate a virtual authentication code using card data provided by the user or an identification code related to the procedure type set via the user terminal as source data. Through this, the virtual authentication code generation means 10 can generate different virtual authentication codes depending on the procedure type, the user, and the time of virtual authentication code generation.
[0096] For example, in the case of financial transactions, a user may be assigned an identification code based on the type of procedure, such as the login process, the account transfer process, or the passbook opening process. In this case, it goes without saying that, in one embodiment of the present invention, the same identification code may be assigned to multiple procedures.
[0097] Although not clearly shown in the drawings, the procedure approval method using a virtual authentication code according to one embodiment of the present invention also further includes a step in which the server registers user information. Through this, the server 200 sets the storage location for each user authentication information by a count corresponding to the time of user information registration. At this time, the storage locations for each user authentication information are not set redundantly.
[0098] The user authentication information corresponds to the user information, and at least one of the user information entries entered via the program is stored on the server 200. This stored user information is then used in the user authentication process.
[0099] Server 200 can register user authentication information by searching for a specific user authentication information storage location within its storage location search algorithm based on the time when a user requests registration of user information, and by saving the user information for which registration was requested (i.e., user information that possesses user authentication information) to the searched user authentication information storage location.
[0100] In this case, the user information is information that is directly entered by the user via a user terminal on which a virtual authentication code generation program is built-in or installed, and is also information that is generated based on the user login information of the virtual authentication code generation program.
[0101] Figure 5 is a configuration diagram of a virtual authentication code verification device according to one embodiment of the present invention.
[0102] Referring again to Figure 2, the server searches for the storage space of user authentication information related to the user within the storage location search algorithm based on the virtual authentication code (S520).
[0103] As one embodiment of the present invention, although not clearly shown in the drawings, the server 200 can also identify a procedure type and perform a step of verifying a virtual authentication code based on the procedure type. This is because, depending on the procedure type, multiple virtual authentication codes may be required, or the procedure approval request based on the virtual authentication code must be made within a specific time period that has already been set from the time the virtual authentication code was generated.
[0104] The storage location search algorithm is matched to a virtual authentication code generation function contained within a dedicated program built into or installed on the virtual authentication code generation means 10 (i.e., the user terminal), and enables the search for the user authentication information storage location based on at least one detail code within the virtual authentication code. For example, if the virtual authentication code includes a first code that determines the starting point for searching for the storage location and a second code that indicates the direction to the storage location from the starting point, the storage location search algorithm is an algorithm that adjusts itself so that when the direction corresponding to the second code is indicated at the point corresponding to the first code, the storage location to which the registration time of the user authentication information is matched is located at that point.
[0105] The present invention utilizes a storage location search algorithm that matches a virtual authentication code generation function, enabling the virtual authentication code verification means 20 to search for the user authentication information storage location (i.e., the user authentication information registration count) and extract user information stored at that storage location, even if the first and second codes included in the virtual authentication code are changed. Various methods can be applied to the storage location search algorithm, and specific examples will be described later. However, the storage location search algorithm is not limited to the examples described later.
[0106] The following describes the methods for user authentication and financial transaction approval of the virtual authentication code verification device 20, with reference to Figures 2 and 5.
[0107] As illustrated in Figure 5, the virtual authentication code verification means 20 includes a communication unit 210, a detailed code extraction unit 220, a storage location search unit 230, a user verification unit 240, a virtual authentication code verification unit 250, and a procedure approval unit 260.
[0108] The communications unit 210 receives a virtual authentication code from the user terminal 100 and, along with user authentication, is requested to approve a specific procedure.
[0109] For example, in the case of financial transactions, approval for a bank transfer procedure may be requested via the user terminal. In this case, the communication unit 210 may be provided with a virtual authentication code generated by a dedicated program built into or installed on the user terminal, and may be requested to authenticate the user. The detail code extraction unit 220 is responsible for extracting one or more detail codes contained in the virtual authentication code.
[0110] In one embodiment, the detail code extraction unit 220 includes a detail code concatenation function included in the virtual authentication code generation function. Therefore, if the virtual authentication code includes multiple detail codes, the detail code extraction unit 220 can apply the detail code concatenation function to extract multiple detail codes from the virtual authentication code. For example, if the virtual authentication code generation means 10 generates a virtual authentication code in which two detail codes (i.e., a first code and a second code) are concatenated, the detail code extraction unit 220 can apply the detail code concatenation function to the character sequence of the virtual authentication code to separate the first code and the second code.
[0111] The storage location search unit 230 plays the role of searching for the storage location where the user's authentication information is registered, based on one or more extracted detail codes, within the storage location search algorithm. Various methods can be applied to the storage location search unit 230 to search for the storage location of the user's authentication information based on each detail code. In order for the storage location search unit 230 to search for a storage location based on multiple detail codes, the detail codes also have correlations with each other.
[0112] Here, the storage location refers to the point on the track (count) corresponding to the time when the user requests registration of user information via a dedicated program, as described above. In other words, within the server 200, if the track related to the user authentication information is driven and a specific user requests registration of specific user information at a specific time, the user authentication information will be registered at the count corresponding to that time (i.e., the count that has elapsed from the last time the track was driven until the time of registration).
[0113] When the virtual authentication code is composed of a first code and a second code, in one embodiment where there is a correlation between the detail codes, the storage location search unit 230 can determine a search starting point corresponding to the first code, and determine the location where the user authentication information is stored by moving along a search path corresponding to the second code from the search starting point. Since the virtual authentication code generation means 10 provides a new virtual authentication code for each unit count, the virtual authentication code verification means 20 can set a search starting point and a search path based on the first code and the second code which are changed for each count, and search for the storage location of the user authentication information (i.e., the location where the user authentication information is registered).
[0114] The user verification unit 240 extracts the user authentication information stored at the storage location searched by the storage location search unit 230 and completes user authentication. That is, the virtual authentication code verification means 20 stores each user authentication information at a count corresponding to the time when user authentication information was registered from each user within the storage location search algorithm. Therefore, the user verification unit 240 can extract specific user information that has been matched and stored at a specific user authentication information storage location within the storage location search algorithm. This makes it possible to confirm who the user requesting user authentication is without the need to log in separately each time a user is authenticated.
[0115] Figure 6 is a diagram illustrating how a K-shaped storage location search algorithm, according to one embodiment of the present invention, searches for the storage location of user authentication information.
[0116] For example, referring to Figure 6, the storage location search algorithm corresponds to M in the first code. N A k-sided polygon (where k is M) rolls along a track lined with individual codes. NThat is, when the vertices of the k-sided polygon move while corresponding to the points on the first code track where the codes are arranged, each vertex of the k-sided polygon is matched with the storage position of the user authentication information, and the point where the first code track (i.e., the first track) and the k-sided polygon correspond also becomes the starting point for searching the storage position corresponding to the first code. At this time, the storage position search unit 230 can apply a rolling movement to the k-sided polygon so that the vertices of the k-sided polygon touch the point corresponding to the first code extracted by the detailed code extraction unit 220. Through this, the storage position search unit 230, at the position on the first track where the k-sided polygon touches, by indicating the angle corresponding to the second code (for example, a specific angle obtained by dividing 180° into M N pieces), can search for the vertex of the k-sided polygon that is the storage position where the user authentication information corresponding to the virtual authentication code is stored.
[0117] Specifically, as shown in FIG. 6, the virtual authentication code verification means 20 rolls the k-sided polygon (i.e., moves while ensuring that each vertex of the k-sided polygon touches each point on the track in order) to the point corresponding to the first code. Then, the virtual authentication code verification means 20 indicates the angular direction corresponding to the second code and searches for the vertex corresponding to the storage position.
[0118] Also, as another example, when the k-sided polygon is in contact with the point corresponding to the first code on the first track, the server 200 divides the entire central angle (i.e., 360°) into M N pieces based on the center of the k-sided polygon and the contact point on the first track, and matches each angle with M N pieces of the second codes. At this time, the direction of the line obtained by moving a specific number of unit angles (i.e., 360° / M N ) from the line connecting the center of the k-sided polygon and the contact point on the first track becomes a specific vertex of the k-sided polygon. Therefore, if the second code corresponding to a specific angle is received, the server 200 can search for the vertex located in the direction of that angle.
[0119] Another example is that a specific digit of the second code can be used to determine the direction of angle calculation. That is, when generating the second code using N characters (where N is a natural number), the direction of angle measurement can be determined by a single digit. For example, when server 200 divides the total central angle (i.e., 360°) based on the center of the k-gon and the junction on the first track, and matches the second code to each angle, it can determine by a single digit whether the angle is measured to the left or to the right of the line connecting the center of the k-gon and the junction on the first track.
[0120] As an example, the storage location search algorithm assigns a different number of second codes to each vertex on the k-gon, depending on the angle measurement direction. That is, a single vertex can be matched with different second codes when reached at an interior angle and when reached at an exterior angle, and the storage locations of other user authentication information can be linked. As another example, if the storage location search algorithm uses N characters (where N is a natural number) to generate the second code, N-1 characters can be used to match for half of the total angle (for example, 360° when divided based on the central angle), and one digit can be used to determine the angle application direction to reach each vertex.
[0121] The methods for searching for storage locations in a k-gon based on the second code are not limited to those mentioned above. A variety of methods can be applied, such as a method that searches for storage locations at points that divide the space between a point on the k-gon corresponding to the second code and a junction on the first track into specific ratios.
[0122] In another embodiment, if the virtual authentication code includes a first code and a second code that change with each unit count, the first code is generated by the server 200 based on the unit count that has elapsed since the first time user authentication was performed based on the virtual authentication code, and the second code is generated based on the unit count that has elapsed since each user registered user information via a dedicated program installed on the user terminal 100. In this case, the unit count is set to a specific time interval and changes as the time interval elapses.
[0123] Specifically, if the virtual authentication code includes a first code based on a unit count that has elapsed since the initial point in time when the storage location search algorithm started, and a second code generated based on a unit count that has elapsed since the time when each user's user information was registered, as shown in Figure 6, the server 200 sets the count on the track to which the code value corresponding to the first code is matched as the search starting point, and then, for a count value corresponding to the second code, it moves back along the track from the search starting point to search for the point on the track at the time when the user information was registered with the server 200 (i.e., the user authentication information storage location).
[0124] For example, the server searches for the location (or count) where the first code in the virtual authentication code is assigned on the first code track, sets a starting point for the search, places a second code track in the reverse direction from the starting point, searches for the location (or count) where the second code in the virtual authentication code is assigned, and extracts the location (or count) where user authentication information is registered on the first code track.
[0125] Furthermore, for example, server 200 sets a starting point for the search based on the first code in the virtual authentication code, and then searches for a point corresponding to the time of user authentication information registration by regressing to a count value calculated by applying the inverse function of the second function to the second code in the virtual authentication code.
[0126] The virtual authentication code verification unit 250 compares the time when the communication unit 210 receives the virtual authentication code with the time when the virtual authentication code is generated by the virtual authentication code generation means (i.e., the user terminal) using the virtual authentication code generation function, and verifies the virtual authentication code.
[0127] In one embodiment, the virtual authentication code verification unit 250 compares the time when the virtual authentication code is received with the time when the virtual authentication code is generated using a virtual authentication code generation function in a dedicated program built into or installed on the user terminal. If the generation time falls within a pre-set error range from the time of reception, the unit can determine that the received virtual authentication code is a valid code.
[0128] For example, in the case of a financial transaction, let's assume that user terminal 100 generates a virtual authentication code at time t1, which is used for user authentication for a user's account transfer. If the financial transaction settlement server 200 receives this virtual authentication code at time t2 via the communication unit 140 of user terminal 100, the server 200 compares t1 and t2 to determine whether the received virtual authentication code is a valid code. If the difference between t1 and t2, or the difference between the first count value corresponding to t1 and the second count value corresponding to t2, falls outside the pre-set range, the server 200 determines that the virtual authentication code was not generated correctly. This prevents a third party from obtaining the user's virtual authentication code and subsequently stealing it.
[0129] Furthermore, in another embodiment relating to the method for verifying the virtual authentication code, the first code and the second code are also codes related to a base count that is added to a virtual security code (e.g., an OTP code) that is randomly generated by the user terminal 100 from the time when user authentication information is registered or when user authentication is requested (for example, when the user terminal receives user authentication information data from the user authentication information, or when the user terminal generates a virtual authentication code as user authentication information data).
[0130] In a specific embodiment, the virtual authentication code generation means 10 generates the virtual security code by reflecting it in the first and second codes without outputting it externally. The virtual authentication code generation means 20 (for example, a dedicated virtual authentication code generation program) generates a virtual security code value (for example, an OTP code) based on the serial number (i.e., a unique value) and a portion of the user information (e.g., card data, biometric data, etc.) within the virtual authentication code generation means (i.e., the user terminal 200), or a combination of the user information and the serial number of the dedicated program. It then generates a first code which is a count that includes the virtual security code value at the time of user authentication information registration, and generates a second code which is a count corresponding to the virtual security code value (i.e., generates the virtual security code itself as the second code).
[0131] In other words, the first and second codes are generated based on a count that has shifted by the virtual security code value from point A, when the user authentication information 10 was registered with the server 200 by the user terminal 100. The count that has shifted by the virtual security code value from point A can be both a previous count and a subsequent count for the count corresponding to the current point in time, depending on the generated virtual security code value.
[0132] The server, which is a virtual authentication code verification means, can apply the received first and second codes to a storage location search algorithm to search for the storage location (or registration location) of the user authentication information. Through this, it becomes impossible for others to verify the order in which the first and second codes constituting the virtual authentication code are provided, thereby potentially improving security.
[0133] In another embodiment, the server 200, which is a virtual authentication code verification means, extracts the virtual security code from the generated second code based on the virtual security code, and then checks whether there is a value that matches the virtual security code in the OTP number calculated by inputting a count within a specific range from the count that received the virtual authentication code into the virtual security code generation function (i.e., the OTP function). Then, the server 200, which is a virtual authentication code verification means, applies the inverse function of the second function to the second code to obtain the virtual security code value (i.e., the OTP function value) used to generate the second code, and calculates the count that calculates a value identical to the virtual security code value.
[0134] Due to the transmission time and delay of the virtual authentication code, there is a difference between the time the virtual security code is generated at the user terminal 100, which is the virtual authentication code generation means 10, and the time the server 200, which is the virtual authentication code verification means 20, receives the virtual security code. As a result, the count of virtual authentication codes received by the virtual authentication code verification means 20 does not match the count of OTP numbers corresponding to the virtual security code that were generated.
[0135] To this end, server 200 allows a margin of error in the count of received virtual authentication codes. Through this, server 200 can prevent performing user authentication with a previously generated virtual authentication code instead of a currently generated one, thereby improving security. Furthermore, when the user enters a virtual authentication code, server 200 can autonomously search for the virtual security code and verify the user, even if the user does not enter a specific number of digits of the virtual security code.
[0136] In another embodiment, the virtual authentication code generation means 10 can generate a first code corresponding to a count that is generated by adding a virtual security code value, which is generated using a combination of the serial number (i.e., unique value) in the user terminal or dedicated program and user information, or a part or a combination thereof, as seed data, at the time user authentication is requested. At this time, a second code is generated that is corresponding to a count that is the sum of the count difference between the time of user authentication information registration (time A) and the time of user authentication request (time B), and the virtual security code value. In other words, the formula by which the virtual authentication code generation program generates the first code and the second code is as follows. <Formula> 1st code = f1(B point count + virtual security code) Second code = f2(Count at point B - Count at point A + Virtual security code) (Time A: Count at the time of user authentication information registration, Time B: Count at the time of user procedure approval request, Virtual security code: OTP number)
[0137] The server 200, which is the virtual authentication code verification means 20, searches for the location where user information is stored based on the first and second codes in the received virtual authentication code, and extracts seed data (i.e., a combination serial number which is a combination of the serial number of the virtual authentication code generation program or user terminal, user information, the serial number of the virtual authentication code generation program, and the user information serial number, used when generating the virtual authentication code) stored together at that location. Based on the seed data, the server 200 generates a virtual security code (i.e., an OTP number) within a specific count range from the time the user authentication request is received.
[0138] Subsequently, the server 200 determines the user authentication information registration time (Time A) by searching for the location where user information is stored based on the first and second codes. From the user authentication information registration time (Time A), the server calculates a calculated value corresponding to the sum of the number of counts up to each count within a specific count range and the virtual security code (i.e., OTP number), based on the time of receipt of the user authentication request. The server then checks whether a count such as the count number corresponding to the second code (i.e., the value obtained by applying the inverse function of the second function to the second code) exists in each of the calculated values. Through this, the server can confirm whether or not the virtual authentication code was provided successfully.
[0139] The procedure approval unit 260, once the virtual authentication code verification unit 250 has completed the verification of the virtual authentication code, is responsible for approving the procedure requested by the user terminal 10.
[0140] In one embodiment, in the case of user authentication during a bank transfer, once user authentication is completed by the user verification unit 240 and verification is completed by the virtual authentication code verification unit 250 after the virtual authentication code has been successfully generated, the procedure approval unit 260 approves the bank transfer, which is the financial transaction requested by the user.
[0141] Furthermore, in one embodiment of the present invention, depending on the field in which the procedure is used, multiple user authentications may be required. For example, approving a single financial transaction may require multiple user authentication processes involving multiple virtual authentication codes. This is the case when conducting financial transactions through an agent.
[0142] According to one embodiment of the present invention, the type of financial transaction requiring an authentication process involving multiple users and a single procedural approval based on multiple virtual authentication codes can also be set up for the first type of financial transaction. For example, a request for procedural approval via an agent may fall under this category. However, it is not limited to this.
[0143] As previously explained, server 200 can identify the requested financial transaction type based on the virtual authentication code generated based on the identification code of the financial transaction type.
[0144] The virtual authentication code for the first type of financial transaction includes a first virtual authentication code and a second virtual authentication code. In this case, the first virtual authentication code is generated by a first virtual authentication code generation function in the first user terminal based on first user information, and the second virtual authentication code is generated by a second virtual authentication code generation function in the second user terminal based on second user information. At this time, the server receives the first virtual authentication code and the second virtual authentication code and is requested to approve the first type of financial transaction.
[0145] For example, a financial transaction involving the opening of a corporate bank account could fall into this category. In order to conduct such a financial transaction through a corporate officer or employee, authentication of the corporate representative and the specific officer or employee acting as their agent is required simultaneously. To this end, the server receives virtual authentication codes provided by each representative and agent and verifies them.
[0146] Furthermore, in one embodiment of the present invention, the approval stage for the first type of financial transaction can be performed only if the server confirms that the financial transaction identification codes for the first virtual authentication code and the second virtual authentication code are identical.
[0147] To further explain using the aforementioned example, the server can only approve a financial transaction if the type of financial transaction identified based on each authentication code is the same. In other words, even if user authentication for the corporate representative (first user) is completed based on the first virtual authentication code of the first user (corporate representative), and user authentication for the agent (second user) is completed based on the second virtual authentication code of the agent (second user), the financial transaction will not be approved. The server will approve the financial transaction only if the identification code related to the financial transaction identified through the first virtual authentication code and the second virtual authentication code is the same. This prevents the first virtual authentication code generated via the terminal of the corporate representative (first user) from being used for other financial transactions by the agent (second user), or from the corporate representative being misused.
[0148] In one embodiment of the present invention, in the case of a first type of financial transaction, the server searches for a first storage location in the storage location search algorithm where the first user authentication information of the first user is stored, based on a first virtual authentication code, and searches for a second storage location in the storage location search algorithm where the second user authentication information of the second user is stored, based on a second virtual authentication code. At this time, the first storage location and the second storage location may be set so as not to overlap by the unit count.
[0149] Specifically, according to the virtual authentication code infrastructure's method for providing non-face-to-face financial transactions, each user's information is stored in the corresponding count at the time each user requests user information registration. Therefore, as mentioned above, user information is not stored redundantly. In this case, even if multiple users request user information registration simultaneously at the same time, the server assigns a priority order for storage location allocation based on pre-configured criteria (e.g., user's UID, name, etc.) and stores each user's information in a different count.
[0150] Figure 7 is an illustrative diagram of a user authentication method for a Type 1 financial transaction according to one embodiment of the present invention.
[0151] Furthermore, referring to Figure 7, one embodiment of the present invention further includes a step in which a first user terminal provides second user information relating to a first type of financial transaction. It also further includes a second authentication step for the second user relating to the first type of financial transaction, based on the second user information provided by the first user terminal and the second user information extracted from a second storage location searched based on the second virtual authentication code.
[0152] On the other hand, second user information (e.g., agent's mobile phone number, UID, etc.) may be stored together with the first user information stored in the first storage location, but may also be stored in other storage locations linked to the first storage location. After the server 200 completes authentication for the first user using the first user information extracted from the first storage location searched based on the first virtual authentication code, it extracts the second user information from other storage locations linked to the first storage location. Then, after extracting the second user information from the second storage location searched based on the second virtual authentication code, it compares it with the second user information provided from the first user terminal. Only if they are identical is the server 200 authorized the first type of financial transaction.
[0153] Furthermore, the second user information may be stored by the server 200, which has received the first user information from the first user terminal, at the same time as the registration of the first user information. However, when generating virtual authentication codes related to the first type of financial transaction that requires the aforementioned multiple virtual authentication codes, the server may also request the first user terminal to provide the second user information.
[0154] In this embodiment, the first virtual authentication code is also generated based on the second user information provided from the first user terminal. That is, the second user information provided from the first user terminal can be used as source data for the virtual authentication code generation function. Through this, the server 200 can approve a financial transaction only if the second user information extracted from the first virtual authentication code and the second user authentication information extracted from the second storage location searched based on the second virtual authentication code are identical.
[0155] The procedure approval method for a virtual authentication code infrastructure according to one embodiment of the present invention described above is embodied in a program (or application) and stored on a medium, so that it may be executed in conjunction with a computer, which is hardware.
[0156] Through the embodiment of the present invention described above, a user can generate a different virtual authentication code at all times based on the type of procedure, time, and user information. Based on the virtual authentication code, which consists of different values, the server can extract user authentication information related to the user and perform user verification.
[0157] In particular, when the user themselves performs financial transactions, the virtual authentication code is something that the user performs, and it can serve as a substitute for a seal certificate or official certificate. In this case, the user can tag a card registered on the server to their terminal device and generate a unique virtual authentication code corresponding to the user. This is because seed data stored on the card is transmitted via NFC, and the code is generated based on the seed data in the dedicated program and the seed data transmitted from the card. Through this, the user can be authenticated with a virtual authentication code that can only be generated using the user's own card and user terminal device.
[0158] Furthermore, assuming that an employee of a corporation performs specific tasks on behalf of the representative, the employee can also authenticate that they have been granted legitimate power of attorney by the representative by entering a virtual authentication code corresponding to the representative, which is generated when the representative tags the representative's terminal (a terminal with a virtual authentication code generation module installed or included) with the representative's card, into the documents delegated by the representative. In addition, when a supervisor within the company or organization is absent and approval for specific tasks is required, the employee can be provided with a virtual authentication code generated at a specific time from the supervisor's card and the supervisor's terminal, and by entering this virtual authentication code into the electronic system, the task will be processed as having been approved by the supervisor.
[0159] The aforementioned program also includes code encoded in a computer language such as C, C++, Java®, Ruby, or machine language, which can be read by the computer's processor (CPU) via the computer's device interface, in order for the computer to read the program and execute the method embodied by the program. Such code includes functional code, such as functions that define the functions necessary to execute the aforementioned method, and execution procedure-related control code necessary for the computer's processor to execute the aforementioned functions in a predetermined procedure. Furthermore, such code also includes additional information necessary for the computer's processor to execute the aforementioned functions, and memory reference-related code relating to the location (address) in the computer's internal or external memory where the media must be referenced. Furthermore, if the computer's processor needs to communicate with other remote computers or servers to perform the aforementioned functions, the code may also include communication-related code that specifies how the computer's communication module should communicate with other remote computers or servers, and what information or media should be sent and received during communication.
[0160] The aforementioned storage medium refers not to a medium that stores data for a short period of time, such as a register, cache, or memory, but rather a medium that stores data semi-permanently and is readable by a machine. Specifically, examples of such storage media include, but are not limited to, ROM, RAM, CD-ROM, magnetic tape, floppy disk, and optical data storage devices. In other words, the program can also be stored on various recording media on various servers that the aforementioned computer can connect to, or on various recording media on the user's computer. Furthermore, the medium can be distributed across computer systems connected to a network, and computer-readable code can be stored in a distributed manner.
[0161] Embodiments of the present invention have been described above with reference to the attached drawings. However, those skilled in the art in the field to which the present invention belongs will understand that the present invention can be implemented in other specific forms without changing its technical idea or essential features. Therefore, the embodiments described above should be understood to be illustrative and not restrictive in all respects.
Claims
1. A method performed by a server, The server receives a virtual authentication code and a request for user authentication, The server extracts user authentication information used for user authentication based on at least one detail code contained in the virtual authentication code. Includes, The aforementioned virtual authentication code is generated by a virtual authentication code generation function within the user terminal without a separate communication connection with the server, and is generated by changing each unit count that changes as a specific time interval elapses. The user authentication information is transmitted to the server or the device that requested the user authentication from the server, and is used to verify the user's authority to perform a specific procedure. The authority to carry out the aforementioned procedure includes the authority to carry out at least one of several types of procedures. Procedure approval method for the virtual authentication code infrastructure.
2. The virtual authentication code is generated by combining a first code with a second code included in a plurality of detail codes according to a specific rule. The first code and the second code are correlated, The first code determines a search starting point related to the storage location where the user authentication information is stored on the server, The procedure approval method for a virtual authentication code infrastructure according to claim 1, characterized in that the second code determines a search path relating to the storage location from the search starting point.
3. The validity period data for the virtual authentication code is set via the user terminal. Based on the aforementioned validity time data, a third code included in the plurality of detail codes is further generated. The procedure approval method for a virtual authentication code infrastructure according to claim 2, characterized in that the virtual authentication code is generated by combining the first code, the second code, and the third code in accordance with specific rules.
4. The aforementioned virtual authentication code is Includes a virtual security code generated based on time data relating to when the virtual authentication code was generated, or time data relating to when the user authentication was requested. The procedure approval method for a virtual authentication code infrastructure according to claim 2, characterized in that the server further verifies the virtual authentication code based on the virtual security code.
5. The procedure approval method for a virtual authentication code infrastructure according to claim 1, characterized in that the virtual authentication code is generated based on either the card data provided to the user terminal or the biometric data provided to the user terminal.
6. Of the aforementioned multiple types, the virtual authentication code according to the first type includes the first virtual authentication code and the second virtual authentication code. The first virtual authentication code is generated by a first virtual authentication code generation function within the first user terminal, based on the first user information. The aforementioned second virtual authentication code is generated by a second virtual authentication code generation function within the second user terminal, based on the second user information. The stage in which the aforementioned request is received involves receiving the first virtual authentication code and the second virtual authentication code, thereby receiving the user authentication for the first type. The procedure approval method for a virtual authentication code infrastructure according to claim 2, characterized in that the authority to perform the aforementioned procedure can only be performed if the user identification codes corresponding to the respective authorities of the first virtual authentication code and the second virtual authentication code are identical to each other.
Citation Information
Patent Citations
Method and system for authengicating user using virtual code for authentication
KR1020200018228A
Information processing device and information processing method
WO2017056309A1
Virtual code-based financial transaction provision system, virtual code generation device, virtual code verification device, virtual code-based financial transaction provision method, and virtual code-based financial transaction provision program
WO2020032321A1