Apparatus and method for trustworthiness score based enhanced security using dynamic authentication

The reliability score-based dynamic authentication enhancement security device addresses the lack of dynamic verification in Zero Trust models by using an artificial neural network to calculate and act on a reliability score, ensuring real-time identification and adaptive authentication procedures.

KR102995674B1Active Publication Date: 2026-07-29M SECURE
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
M SECURE
Filing Date
2024-11-27
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Current Zero Trust models lack dynamic verification of identity and device state changes after authentication, and there are no actual cases of authentication enhancement based on trust levels or AI models trained on trust algorithms in domestic implementations.

Method used

A reliability score-based dynamic authentication enhancement security device and method that includes a hardware processor and storage unit, performing authentication procedures for multiple areas, generating abnormal behavior information, and calculating a reliability score using an artificial neural network model to perform dynamic authentication procedures based on the score.

Benefits of technology

The device provides real-time identification of abnormal behavior and performs immediate security measures, enhancing authentication by varying the complexity of the process based on the reliability score, thereby improving security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 112024131126880-PAT00002_ABST
    Figure 112024131126880-PAT00002_ABST
Patent Text Reader

Abstract

The present specification discloses a dynamic authentication enhancement security device and method based on a reliability score. The dynamic authentication enhancement security device according to the present specification comprises: a hardware processor; and a storage unit connected to the processor and configured to store at least one computer program configured to perform a dynamic authentication enhancement security method based on a reliability score. The dynamic authentication enhancement security method may include: (a) a step of performing an authentication procedure for a plurality of authentication areas when an authentication request signal is received from a user terminal; (b) a step of generating abnormal behavior information from log data collected from the user terminal and calculating a reliability score when authentication is approved; and (c) a step of performing any one of a plurality of dynamic authentication procedures based on the reliability score.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a dynamic authentication enhancement security device and method, and more specifically, to a reliability score-based dynamic authentication enhancement security device and method. Background Technology

[0002] The content described in this section merely provides background information regarding the embodiments described in this specification and does not necessarily constitute prior art.

[0003] After the document 'Zero Trust Architecture (NIST SP 800-207)' was released in the United States in 2020, Zero Trust Architecture was specified in President Biden's Executive Order OMB, M-22-09 in May 2021.

[0004] Zero Trust is a concept that assumes attackers can always exist inside or outside the network, and does not trust any users, devices, or networks until they have undergone a clear authentication process.

[0005] In the NIST (National Institute of Standards and Technology) concept, the Zero Trust approach performs authentication and authorization to allow access subjects to access resources through Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs).

[0006] In Korea, the Zero Trust Guidelines 1.0 were published by the Ministry of Science and ICT in 2023 to promote the spread of the Zero Trust model. The Zero Trust Guidelines define the core elements of a corporate network for the introduction of Zero Trust as (1) Identity & User, (2) Device & Endpoint, (3) Network, (4) System, (5) Application & Workload, and (6) Data.

[0007] However, current Zero Trust models lack dynamic verification of identity and device state changes after authentication, as well as an enhanced authentication system. Furthermore, while NIST and Zero Trust guidelines require the implementation of AI training, such as machine learning, for trust algorithms, there are no actual cases of authentication enhancement based on trust levels or AI models trained on trust algorithms in domestic Zero Trust implementations. Prior art literature

[0008] Published Patent Application No. 10-2015-0054485, May 20, 2015 The problem to be solved

[0009] The present specification aims to provide a security device and method for dynamic authentication enhancement based on a trust score.

[0010] This specification is not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by a person skilled in the art from the description below. means of solving the problem

[0011] A dynamic authentication enhancement security device according to the present specification for solving the above-described problem comprises: a hardware processor; and a storage unit connected to the processor and configured to store at least one computer program configured to perform a reliability score-based dynamic authentication enhancement security method. In the reliability score-based dynamic authentication enhancement security device, the dynamic authentication enhancement security method may include: (a) a step of performing an authentication procedure for a plurality of authentication areas when an authentication request signal is received from a user terminal; (b) a step of generating abnormal behavior information from log data collected from the user terminal and calculating a reliability score when authentication is approved; and (c) a step of performing any one of a plurality of dynamic authentication procedures based on the reliability score.

[0012] According to one embodiment of the present specification, the plurality of authentication areas may include a user account authentication area, a network authentication area, a terminal authentication area, and a dynamic authentication area.

[0013] According to one embodiment of the present specification, step (a) may be a step of further performing a facial authentication procedure when the user terminal connects to a preset system.

[0014] According to one embodiment of the present specification, the log data may be data related to at least one of an identifier and identity (Identity & User), a device and endpoint (Device & Endpoint), a network (Network), a system (System), an application and workload (Application & Workload), and data from the user terminal.

[0015] According to one embodiment of the present specification, the storage unit further stores an artificial neural network model that generates abnormal behavior information using the log data as an input value, and step (b) may be a step of calculating a reliability score based on the abnormal behavior information obtained by inputting the log data to the artificial neural network model.

[0016] According to one embodiment of the present specification, step (c) may further include blocking a session associated with the user terminal.

[0017] According to one embodiment of the present specification, step (c) may be a step of transmitting a request signal to the user terminal to select an authentication number displayed on another user terminal among at least one authentication number displayed on the user terminal according to the reliability score, and checking whether the selected authentication number is valid.

[0018] At this time, the above step (c) may include setting the number of authentication numbers displayed on the user terminal according to the reliability score range where the reliability score is located among a plurality of preset reliability score ranges.

[0019] At this time, the plurality of reliability score intervals may include a first interval in which the smallest number of authentication numbers are displayed on the user terminal, a second interval in which a relatively larger number of authentication numbers are displayed than in the first interval, and a third interval in which the largest number of authentication numbers are displayed.

[0020] According to another embodiment of the present specification, step (c) may be a step of transmitting a request signal to the user terminal to input at least one authentication number displayed on another user terminal according to the reliability score, and checking whether the input authentication number is valid.

[0021] At this time, the above step (c) may include setting the number of authentication numbers according to the reliability score range in which the reliability score is located among a plurality of preset reliability score ranges.

[0022] At this time, the plurality of reliability score intervals may include a first interval set to input the smallest number of authentication numbers, a second interval set to input a relatively larger number of authentication numbers than the first interval, and a third interval set to input the largest number of authentication numbers.

[0023] According to one embodiment of the present specification, step (c) may further include blocking access to a user account connected through the user terminal when the reliability score is located within a preset range.

[0024] A dynamic authentication enhancement security method according to one embodiment of the present specification may be implemented in the form of a computer program written to perform each step on a computer and recorded on a computer-readable recording medium.

[0025] Other specific details of the present invention are included in the detailed description and drawings. Effects of the invention

[0026] According to one aspect of the present specification, a dynamic authentication enhanced security device calculates a reliability score based on abnormal behavior using log data and can perform a dynamic authentication procedure based on the reliability score.

[0027] According to another aspect of the present specification, a dynamic authentication enhanced security device identifies whether abnormal behavior is occurring in real time using log data and can perform immediate security measures when abnormal behavior is identified.

[0028] The effects of the present invention are not limited to those mentioned above, and other unmentioned effects will be clearly understood by a person skilled in the art from the description below. Brief explanation of the drawing

[0029] FIG. 1 illustrates a schematic configuration of a dynamic authentication enhanced security device according to one embodiment of the present specification. FIG. 2 is a flowchart of a dynamic authentication enhancement security method according to one embodiment of the present specification. FIG. 3 is a diagram illustrating the process of a dynamic authentication procedure according to one embodiment of the present specification, and FIG. 4 is a diagram illustrating an example of an authentication step according to a reliability score. Figure 5 is a diagram illustrating another example of a certification step according to a reliability score. Specific details for implementing the invention

[0030] The advantages and features of the invention disclosed herein, and the methods for achieving them, will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, this specification is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided merely to ensure that the disclosure of this specification is complete and to fully inform those skilled in the art (hereinafter referred to as "skilled in the art") of the scope of this specification, and the scope of rights of this specification is defined only by the scope of the claims.

[0031] The terms used herein are for describing the embodiments and are not intended to limit the scope of the claims herein. In this specification, the singular form includes the plural form unless specifically stated otherwise in the text. As used herein, "comprises" and / or "comprising" do not exclude the presence or addition of one or more other components in addition to the components mentioned.

[0032] Throughout the specification, the same reference numerals refer to the same components, and "and / or" includes each of the mentioned components and all combinations of one or more thereof. Although terms such as "first," "second," etc., are used to describe various components, they are not limited by these terms. These terms are used merely to distinguish one component from another. Accordingly, the first component mentioned below may be the second component within the scope of the technical concept of the present invention.

[0033] Unless otherwise defined, all terms used herein (including technical and scientific terms) may be used in a meaning commonly understood by a person skilled in the art to which this specification pertains. Additionally, terms defined in commonly used dictionaries are not to be interpreted ideally or excessively unless explicitly and specifically defined otherwise.

[0034] An Artificial Neural Network (ANN) implements artificial intelligence by connecting artificial neurons that mathematically model the neurons constituting the human brain.

[0035] In this specification, the term "artificial neural network model" may consist of a set of interconnected computational units that may generally be referred to as nodes. These nodes may also be referred to as neurons. A neural network is composed of at least one node. The nodes (or neurons) constituting the neural networks may be interconnected by one or more links.

[0036] In a neural network, one or more nodes connected via links can form relative input and output node relationships. The concepts of input and output nodes are relative; any node in an output node relationship with respect to one node may be in an input node relationship with respect to another node, and vice versa. As described above, the input node versus output node relationship can be generated based on links. One or more output nodes may be connected to a single input node via links, and vice versa.

[0037] Initial input nodes may refer to one or more nodes within a neural network to which data is directly input without passing through links in their relationships with other nodes. Alternatively, in terms of link-based relationships between nodes within the neural network, they may refer to nodes that do not have other input nodes connected by links. Similarly, final output nodes may refer to one or more nodes within a neural network that do not have output nodes in their relationships with other nodes. Furthermore, hidden nodes may refer to nodes constituting the neural network that are neither initial input nodes nor final output nodes.

[0038] In this specification, "inputting" data into an artificial neural network model means that a value is input to the initial input node. In this specification, "obtaining a value," "outputting data," "obtaining information," etc., from the artificial neural network means that data is output from the final output node.

[0039] A deep neural network (DNN) may refer to a neural network that includes multiple hidden layers in addition to an input layer and an output layer. Deep neural networks may include convolutional neural networks (CNN), recurrent neural networks (RNN), autoencoders, Generative Adversarial Networks (GAN), restricted Boltzmann machines (RBM), deep belief networks (DBN), Q networks, U networks, Siamese networks, Generative Adversarial Networks (GAN), etc. The description of deep neural networks described above is merely illustrative and the present disclosure is not limited thereto.

[0040] Neural networks can be trained in at least one of supervised learning, unsupervised learning, semisupervised learning, or reinforcement learning. The training of a neural network may be the process of applying knowledge to the neural network to perform a specific action.

[0041] Neural networks can be trained to minimize the error in their output. The training process involves repeatedly inputting training data into the network, calculating the error between the network's output and the target for the training data, and updating the weights of each node by backpropagating the error from the output layer to the input layer in a direction that reduces the error. In supervised learning, training data is used where the correct answer is labeled for each data point (i.e., labeled training data), whereas in unsupervised learning, the correct answer may not be labeled for each training data point. For instance, in the case of supervised learning for data classification, the training data may consist of data where each training point is labeled with a category. The labeled training data is input into the neural network, and the error can be calculated by comparing the network's output (category) with the labels of the training data. As another example, in the case of unsupervised learning for data classification, the error can be calculated by comparing the input training data with the neural network's output. The calculated error is backpropagated in the neural network (i.e., from the output layer to the input layer), and through backpropagation, the connection weights of each node in each layer of the neural network can be updated. The amount of change in the connection weights of each node being updated can be determined by the learning rate. The neural network's calculation of the input data and the backpropagation of the error can constitute a learning cycle (epoch). The learning rate can be applied differently depending on the number of iterations of the neural network's learning cycle. For example, a high learning rate can be used in the early stages of training to quickly achieve a certain level of performance and increase efficiency, while a low learning rate can be used in the later stages to improve accuracy.

[0042] In this specification, "learning" of an artificial neural network model means that the neural network updates the connection weights of each node so that the error of the output is minimized, and "learning" according to this specification is not limited by a specific learning method.

[0043] In this specification, the term "processor" may be composed of one or more cores and may include a processor for data analysis and deep learning, such as a central processing unit (CPU), a general purpose graphics processing unit (GPGPU), or a tensor processing unit (TPU) of a computing device. The processor may read a computer program stored in memory and perform data processing for machine learning according to one embodiment of this specification. According to one embodiment of this specification, the processor may perform computations for training a neural network. The processor may perform computations for training a neural network, such as processing input data for training in deep learning (DL), extracting features from input data, calculating errors, and updating the weights of the neural network using backpropagation. At least one of the CPU, GPGPU, and TPU of the processor may process the training of a network function. For example, the CPU and GPGPU may together process the training of a network function and data classification using the network function. In addition, in one embodiment of the present specification, processors of a plurality of computing devices may be used together to process the learning of a network function and data classification using a network function. In addition, a computer program executed on a computing device according to one embodiment of the present specification may be a CPU, GPGPU, or TPU executable program.

[0044] Hereinafter, embodiments of the present invention will be described in detail with reference to the attached drawings.

[0045] A reliability score-based dynamic authentication enhancement security device according to one embodiment of the present specification may include a hardware processor and a storage unit connected to the processor. The storage unit may store at least one computer program configured to perform a reliability score-based dynamic authentication enhancement security method.

[0046] FIG. 1 illustrates a schematic configuration of a dynamic authentication enhanced security device according to one embodiment of the present specification.

[0047] Referring to FIG. 1, the dynamic authentication enhanced security device according to the present specification can apply security policies based on a Zero Trust security model. The Zero Trust security model can perform authentication procedures for multiple authentication areas through a Policy Decision Point (PDP) and a Policy Enforcement Point (PEP) to allow subjects to access a server's system and / or resources through a network.

[0048] The authentication process can be continuously performed on user accounts and / or user terminals, which are the subjects seeking to access the server's system and / or resources, etc., through the network.

[0049] The above access subject can correspond to (1) Identity & User and (2) Device & Endpoint among the core elements of an Enterprise Network listed in the Zero Trust Guidelines published by the Ministry of Science and ICT.

[0050] In this case, the authentication process may vary depending on the trust score of the accessing subject, and I will refer to this as dynamic authentication (enhanced authentication) and / or dynamic authentication procedure (enhanced authentication procedure).

[0051] For example, when the reliability score is high, the certification process can be relatively simpler than when the reliability score is low.

[0052] As another example, if the trust score decreases due to the actions of the accessing entity after connecting to the server, the dynamic authentication process can become relatively complex.

[0053] The dynamic authentication enhanced security device according to the present specification performs an authentication procedure for a plurality of pre-set authentication areas in the authentication portion of a PDP and can calculate a reliability score for dynamic policy determination and access control.

[0054] In addition, the policy execution points of the PEP may include the application layer (OSI Layer 7) and the network layer (OSI Layer 3).

[0055] For the application layer, PEP(Web) can be implemented as a proxy without an agent. PEP(Web) can execute security policies for (3) Network and (5) Application & Workload among the core elements mentioned above.

[0056] For the network layer, the PEP (Network) can be implemented in the form of a gateway that requires an agent. The PEP (Network) can execute security policies for the (3) network, (4) system, and (6) data among the core elements mentioned above.

[0057] Since the technology related to the authentication procedure of the above-mentioned PDP and the implementation of the PEP's security policy is widely known among those skilled in the art, a detailed explanation is omitted.

[0058] The dynamic authentication security device described above may be connected to a server device accessed by an accessing subject via a network. Alternatively, the dynamic authentication security device may be the server device accessed by the accessing subject.

[0059] The authentication procedure of the above PDP and the execution of the security policy of the PEP can be performed by the above processor.

[0060] FIG. 2 is a flowchart of a dynamic authentication enhancement security method according to one embodiment of the present specification.

[0061] Referring to FIG. 2, in step S10, when an authentication request signal for accessing a server is received from a user terminal, the processor can perform an authentication procedure for a plurality of authentication areas.

[0062] User terminals may include IoT (Internet of Things) devices, laptops, computers, smartphones, tablet computers, etc., and are not limited to specific devices.

[0063] According to one embodiment of the present specification, a plurality of authentication areas may include a user account authentication area, a network authentication area, and a terminal authentication area.

[0064] The above processor can perform authentication procedures for a user account in the user account authentication area. The above processor can implement consistent authentication by integrating multiple authentications for a user account. The above processor can perform authentication for a user account using Multi-Factor Authentication (MFA), including user authentication using ID / password, Public Key Infrastructure (PKI) authentication, One Time Password (One Time Password) authentication, and Fast Identity Online (FIDO) authentication.

[0065] The above processor can perform a network-level authentication procedure for an access subject connecting to a server in the network authentication area. The above processor can perform network-level authentication by utilizing Single Packet Authorization (SPA) technology. The above processor can generate information regarding authentication status by verifying information contained in a single packet received from a user terminal. The above Single Packet Authorization method is an example and is not limited thereto, and various network authentication methods such as IEEE 802.1X authentication, DHCP (Dynamic Host Configuration Protocol) snooping-based authentication, and IPSec (Internet Protocol Security)-based authentication may be used.

[0066] The above processor can perform an authentication procedure for a user terminal connecting to a server in the terminal authentication area. The above processor can identify whether the user terminal is a user terminal that has been registered in advance.

[0067] A user terminal may store in advance a digital certificate issued through a Certificate Authority and / or a digital certificate issued by a server device. Alternatively, the user terminal may store in advance a token issued by a server device. When the user terminal accesses the server, the processor may receive a single packet containing information regarding the digital certificate and / or token from the user terminal. The processor may generate information regarding authentication status by verifying the information regarding the digital certificate and / or token and user information contained in the single packet.

[0068] Alternatively, the processor may determine whether the terminal is registered with the server by using the ID and / or MAC address information of the user terminal included in a single packet.

[0069] Even after the authentication of the above user terminal is approved, the processor can continuously check the status of the above user terminal and perform an authentication procedure for the user terminal.

[0070] According to one embodiment of the present specification, when the user terminal connects to a pre-configured system, the processor may further perform a facial authentication procedure. The pre-configured system may correspond to a critical system that processes important data, such as personal information data, confidential information data, or financial information data. Since the critical system requires a higher level of security than other systems, the processor may enhance the security level by further performing a facial authentication procedure. At this time, an app for capturing the user's face may be executed in the background on the user terminal. The processor may receive the face image captured from the user terminal and continuously check whether it matches a pre-captured image of the user's face.

[0071] In step S11, if authentication is approved for the authentication request received from the user terminal, the processor may collect log data from the user terminal. Subsequently, the processor may generate abnormal behavior information based on the log data and calculate a reliability score.

[0072] According to one embodiment of the present specification, the log data may include content related to at least one of the core elements of the enterprise network: Identity & User, Device & Endpoint, Network, System, Application & Workload, and Data. Since the content related to the core elements is described in the Zero Trust Guidelines, a detailed description is omitted.

[0073] Log data related to identifiers and identities may include information regarding user account login / logout records, authentication attempt and result information, authentication failure and account confiscation records, mapping information between user accounts and devices, user behavior pattern information, etc.

[0074] Log data related to devices and endpoints may include information regarding the registration status and authentication records of user terminals, security information, network connection attempts and results, records of resources accessed by user terminals, and records of processes executed on user terminals.

[0075] Network-related log data may include information regarding network connection requests and approval status of user accounts and user terminals, network connection location information, traffic flow and usage information, abnormal traffic detection and blocking information, etc.

[0076] Log data related to the system may include information related to user accounts and user terminal connection information, a list of tasks executed by user terminals, information on executed processes, and information on external and internal networks to which the system is connected.

[0077] Log data related to applications and workloads may include information on applications executed on user terminals, information on access attempts and results to applications, information on environments and resources used during workload deployment, status information of workloads, information on abnormal requests or API calls, etc.

[0078] Log data related to data may include information on data accessed by users, information on network segments through which data was transmitted, and records of unauthorized data transmission attempts and blocking.

[0079] The types of log data described above are examples and are not limited thereto, and the log data may include all types of log information that can be generated between a user terminal and a server.

[0080] The processor can collect the log data in real time from a user terminal accessing the server. In this case, the processor can retrieve the log data from the user terminal using the Syslog protocol and / or a Rest API (REpresentational State Transfer Application Programming Interface). Additionally, the processor can directly collect log data stored in the file system of the user terminal.

[0081] The above processor can generate abnormal behavior information by analyzing patterns in collected log data.

[0082] For example, based on the patterns of existing log data, the time when a user account is logged in can be analyzed as being between 9 AM and 6 PM. If the user account is logged in at 10 PM, the processor can generate information indicating that abnormal behavior has occurred.

[0083] As another example, in the pattern of existing log data, the location where a user account is logged in may be the first country. If the said user account is logged in from a different second country, the processor may generate information indicating that abnormal behavior has occurred.

[0084] As another example, there may be no record in the patterns of existing log data of an accessing entity accessing confidential data with a high security level. If such an entity accesses the said confidential data, the processor may generate information indicating that abnormal behavior has occurred.

[0085] As described above, the processor can generate information indicating that abnormal behavior has occurred when an accessing entity performs an action different from the pattern of existing log data.

[0086] Alternatively, the processor may determine whether abnormal behavior has occurred based on statistical data derived from the log data.

[0087] For example, in the pattern of existing log data, the average value of the total data transmission amount transmitted and received between the user terminal and the server device may be 500 MB per hour. The processor may generate information indicating that abnormal behavior has occurred when the data transmission amount deviates from the average value by more than a preset threshold.

[0088] The above processor can calculate a reliability score based on abnormal behavior information. In this case, the processor can calculate the reliability score based on criteria for reliability scores according to preset types of abnormal behavior.

[0089] For example, a reliability score may be calculated relatively higher when the user account login time changes compared to when the user account login location changes. Additionally, a reliability score may be calculated relatively higher when the user account login location changes compared to when an access entity with no record of accessing confidential data accesses the confidential data.

[0090] In addition, the reliability score may vary depending on the degree of difference from the patterns of existing log data.

[0091] For example, in existing log data, the login time of a user account may be between 9:00 AM and 9:30 AM. When the user account logs in at 11:00 AM, the reliability score may be calculated to be relatively higher than when the user account logs in at 9:00 PM.

[0092] As another example, an access entity without a record of accessing confidential data may access it. When an access entity accesses confidential data with a lower security level, the reliability score may be calculated to be relatively higher than when the entity accesses confidential data with a higher security level.

[0093] According to one embodiment of the present specification, the storage unit may further store an artificial neural network model that generates abnormal behavior information using log data as an input value.

[0094] The artificial neural network model described above can be pre-trained to generate abnormal behavior information using log data generated in advance by the processor as training data. In this case, the artificial neural network model may be trained using only log data generated from a specific access subject as training data. Alternatively, the artificial neural network model may be trained using log data generated from multiple different access subjects as training data.

[0095] The above artificial neural network model can be trained using pre-labeled log data of normal patterns and log data of abnormal patterns. Alternatively, the above artificial neural network model can be trained using non-supervisory learning methods such as data clustering and anomaly detection.

[0096] The processor can train the artificial neural network model using various machine learning and / or deep learning learning methods so that the artificial neural network model detects abnormal patterns in a dataset.

[0097] The processor can obtain abnormal behavior information by inputting log data related to the accessing entity accessing the server into the artificial neural network model. The processor can calculate a confidence score based on the obtained abnormal behavior information.

[0098] In step S12, the processor may perform any one of a plurality of dynamic authentication procedures based on the reliability score.

[0099] At this time, the processor may perform a dynamic authentication procedure after blocking the session associated with the access subject. The processor may block the session by logging out the logged-in user account, which is an example, and may block the session using methods widely known among those skilled in the art, such as IP blocking, location blocking, and user terminal blocking.

[0100] The above dynamic authentication procedure may vary depending on the reliability score. When the reliability score is relatively high, the difficulty of the authentication procedure may be relatively lower than when the reliability score is relatively low.

[0101] According to one embodiment of the present specification, the processor transmits a request signal to a user terminal (hereinafter 'first user terminal') connected to a server according to the reliability score to input at least one authentication number displayed on another user terminal (hereinafter 'second user terminal'), and can perform a dynamic authentication procedure using a mutual authentication method that verifies the validity of the authentication number input to the first user terminal.

[0102] For example, when a user connects to a server using a smartphone, the processor may transmit at least one authentication number to another terminal of the user, such as another smartphone, computer, or tablet computer. Additionally, the processor may transmit a request signal to the smartphone connected to the server to input the authentication number displayed on the other terminal. The user may perform a dynamic authentication procedure by inputting at least one authentication number displayed on the other terminal into the smartphone connected to the server.

[0103] When a user accesses a server using a computer, the processor can perform a dynamic authentication procedure by transmitting at least one authentication number to other terminals, such as the user's smartphone, other computer, or tablet computer.

[0104] FIG. 3 is a diagram illustrating the process of a dynamic authentication procedure according to one embodiment of the present specification, and FIG. 4 is a diagram illustrating an example of an authentication step according to a reliability score.

[0105] Referring to FIGS. 3 and FIGS. 4, the processor can perform different dynamic authentication procedures depending on the reliability score.

[0106] According to one embodiment of the present specification, a plurality of reliability score intervals may be pre-set. The processor may set the difficulty of the dynamic authentication procedure according to the reliability score interval where the calculated reliability score is located. The processor may transmit one authentication number to the second user terminal. At this time, the processor may transmit at least one authentication number to the first user terminal according to the reliability score interval where the reliability score is located. The processor may transmit a request signal to the first user terminal to select the authentication number displayed on the second user terminal.

[0107] At this time, the reliability score interval may include a first to third interval. The first interval may be a interval with a reliability score of 70 to 100, the second interval may be a interval with a reliability score of 40 to 69, and the third interval may be a interval with a reliability score of 10 to 39.

[0108] If the calculated reliability score is located in the first interval mentioned above, the authentication level of the access subject may correspond to '1'. Authentication level 1 may mean that the reliability of the access subject is relatively the highest. When the authentication level of the access subject is 1, the processor may perform a dynamic authentication procedure of difficulty level 1. The dynamic authentication procedure of difficulty level 1 may have the lowest difficulty level. In the dynamic authentication procedure of difficulty level 1, the processor may transmit the smallest number of authentication numbers to the first user terminal. At this time, the processor may transmit one authentication number to the first user terminal, which is an example and is not limited by the number mentioned above. The processor may transmit a request signal to the first user terminal to select an authentication number displayed on the second user terminal. The user may perform mutual authentication by selecting the authentication number displayed on the second user terminal from the first user terminal.

[0109] If the calculated reliability score is located in the second interval mentioned above, the authentication level of the access subject may correspond to '2'. Authentication level 2 may mean that the reliability of the access subject is relatively lower than authentication level 1. If the authentication level of the access subject is 2, the processor may perform a dynamic authentication procedure of difficulty level 2. In the dynamic authentication procedure of difficulty level 2, the processor may transmit a relatively larger number of authentication numbers to the first user terminal than in the dynamic authentication procedure of difficulty level 1. At this time, the processor may transmit two authentication numbers to the first user terminal, which is an example and is not limited by the said number. The processor may transmit a request signal to the first user terminal to select an authentication number displayed on the second user terminal. The user may perform mutual authentication by selecting the authentication number displayed on the second user terminal from the first user terminal.

[0110] If the calculated reliability score is located in the third interval mentioned above, the authentication level of the access subject may correspond to '3'. Authentication level 3 may mean that the reliability of the access subject is relatively lower than authentication level 2. If the authentication level of the access subject is 3, the processor may perform a dynamic authentication procedure of difficulty level 3. In a dynamic authentication procedure of difficulty level 2, the processor may transmit a relatively larger number of authentication numbers to the first user terminal than in a dynamic authentication procedure of difficulty level 2. At this time, the processor may transmit three authentication numbers to the first user terminal, which is an example and is not limited by the said number. The processor may transmit a request signal to the first user terminal to select an authentication number displayed on the second user terminal. The user may perform mutual authentication by selecting the authentication number displayed on the second user terminal from the first user terminal.

[0111] At this time, the processor may transmit a request signal to the first user terminal to select an authentication number displayed on the second user terminal within a preset time.

[0112] As illustrated in FIG. 3(a), the authentication number '154 127' and the authentication time may be displayed on the screen of the second user terminal. The user may select the authentication number displayed on the second user terminal from the first user terminal.

[0113] As illustrated in FIG. 3(b), when the reliability score is located in the first interval, one authentication number may be displayed on the screen of the first user terminal. At this time, the one authentication number may be the same as the authentication number displayed on the screen of the second user terminal. The user may select the corresponding authentication number to perform mutual authentication.

[0114] When the reliability score is located in the second interval, two authentication numbers may be displayed on the screen of the first user terminal. The user may perform mutual authentication by selecting '154 127' displayed on the screen of the second user terminal from among the two authentication numbers.

[0115] When the reliability score is located in the third interval, three authentication numbers may be displayed on the screen of the first user terminal. The user may perform mutual authentication by selecting '154 127' displayed on the screen of the second user terminal from among the three authentication numbers.

[0116] The remaining authentication time may be displayed on the screen of the first user terminal in the form of a loading bar, which is an example and is not limited thereto.

[0117] Figure 5 is a diagram illustrating another example of a certification step according to a reliability score.

[0118] According to another embodiment of the present specification, a plurality of reliability score intervals may be pre-set. Referring to FIG. 5, the processor may set the difficulty of the dynamic authentication procedure according to the reliability score interval where the calculated reliability score is located. More specifically, the processor may set the number of authentication numbers according to the reliability score interval where the reliability score is located.

[0119] If the calculated reliability score is located in the first interval mentioned above, the authentication level of the access subject may correspond to '1'. Authentication level 1 may mean that the reliability of the access subject is relatively the highest. When the authentication level of the access subject is 1, the processor may perform a dynamic authentication procedure of difficulty level 1. The dynamic authentication procedure of difficulty level 1 may have the lowest difficulty level. In the dynamic authentication procedure of difficulty level 1, the processor may transmit the smallest number of authentication numbers to the second user terminal. At this time, the processor may transmit one authentication number to the second user terminal, which is an example and is not limited by the number mentioned above. The processor may transmit a request signal to the first user terminal to input the authentication number displayed on the second user terminal. The user may perform authentication by inputting the authentication number displayed on the second user terminal into the first user terminal.

[0120] If the calculated reliability score is located in the second interval mentioned above, the authentication level of the access subject may correspond to '2'. Authentication level 2 may mean that the reliability of the access subject is relatively lower than authentication level 1. If the authentication level of the access subject is 2, the processor may perform a dynamic authentication procedure of difficulty level 2. In the dynamic authentication procedure of difficulty level 2, the processor may transmit a relatively larger number of authentication numbers to the second user terminal than in the dynamic authentication procedure of difficulty level 1. At this time, the processor may transmit two authentication numbers to the second user terminal, which is an example and is not limited by the said number. The processor may transmit a request signal to the first user terminal to input the authentication number displayed on the second user terminal. The user may perform authentication by inputting the authentication number displayed on the second user terminal into the first user terminal.

[0121] If the calculated reliability score is located in the third interval mentioned above, the authentication level of the access subject may correspond to '3'. Authentication level 3 may mean that the reliability of the access subject is relatively lower than authentication level 2. If the authentication level of the access subject is 3, the processor may perform a dynamic authentication procedure of difficulty level 3. In a dynamic authentication procedure of difficulty level 2, the processor may transmit a relatively larger number of authentication numbers to the second user terminal than in a dynamic authentication procedure of difficulty level 2. At this time, the processor may transmit three authentication numbers to the second user terminal, which is an example and is not limited by the said number. The processor may transmit a request signal to the first user terminal to input the authentication number displayed on the second user terminal. The user may perform authentication by inputting the authentication number displayed on the second user terminal into the first user terminal.

[0122] At this time, the processor may transmit a request signal to the first user terminal to input an authentication number displayed on the second user terminal within a preset time.

[0123] When multiple authentication numbers exist in a dynamic authentication procedure, the processor may transmit a request signal to the first user terminal to input the authentication numbers in a predetermined order.

[0124] As shown in FIG. 5, a plurality of authentication numbers can be arranged vertically on the second user terminal.

[0125] The processor may transmit a request signal to the first user terminal to input the authentication numbers displayed on the second user terminal in order from top to bottom. For example, in a three-step dynamic authentication procedure, the processor may transmit a request signal to the first user terminal to input '395758', '154127', and '175238' in that order.

[0126] Alternatively, the processor may transmit a request signal to the first user terminal to input the authentication numbers displayed on the second user terminal in order from bottom to top. For example, in a three-step dynamic authentication procedure, the processor may transmit a request signal to the first user terminal to input '175238', '154127', and '395758' in that order.

[0127] Alternatively, the input order may be displayed along with the authentication number displayed on the second user terminal. The input order may differ from the order of the authentication number displayed on the second user terminal. The processor may transmit a request signal to the first user terminal to input the authentication number according to the displayed input order.

[0128] If the authentication number selected or entered on the first user terminal is the same as the authentication number displayed on the second user terminal, the processor can restore the blocked session.

[0129] If the authentication number selected or entered on the first user terminal is different from the authentication number displayed on the second user terminal, the processor may maintain the session in a blocked state.

[0130] According to one embodiment of the present specification, a plurality of reliability score intervals may further include a fourth interval. The fourth interval may correspond to an interval where the reliability score is 0 to 9. When the calculated reliability score is located in the fourth interval, the processor may block access to a user account connected to the server through a user terminal. More specifically, the processor may log out the user account connected to the server. Subsequently, if a login request signal for the user account is received, the processor may not allow login to the user account. In addition, the processor may block the terminal where the user account is logged in, the IP address assigned to the terminal, etc.

[0131] The processor can continuously generate abnormal behavior information using the log data. If a change occurs in the confidence score range based on the confidence score according to the abnormal behavior information, the processor can perform a dynamic authentication procedure that has changed according to the changed confidence score range.

[0132] For example, if abnormal behavior is detected after the dynamic authentication procedure of the first step is performed and the confidence score range is changed from the first range to the second range, the processor may perform the dynamic authentication procedure of the second step.

[0133] As another example, after the dynamic authentication procedure of the above-mentioned second stage is performed, log data may be collected that includes patterns related to other abnormal behaviors, excluding patterns related to existing abnormal behaviors. For example, the existing first log data may include a record of an accessing entity accessing confidential information that does not have a record of accessing confidential information. The second log data collected thereafter does not include a record of accessing confidential information, but the time at which the accessing entity recorded in the second log data connected to the server may differ from the previous record. In this case, the reliability score calculated based on the first log data may be located in the second segment, and the reliability score calculated based on the second log data may be located in the first segment. If the second log data is collected after the first log data has been collected and the dynamic authentication procedure of the above-mentioned second stage has been performed, the processor may perform the dynamic authentication procedure of the above-mentioned first stage.

[0134] As another example, if log data of a normal pattern is collected after the dynamic authentication procedure of the above two stages and the reliability score range changes from the above second range to the above first range, the processor may change the authentication level from '2' to '1'. In this case, since log data of a normal pattern has been collected, the processor may not perform the dynamic authentication procedure of the above first stage. At this time, the reliability score calculated from the log data of a normal pattern may be close to 100. For example, when the reliability score calculated from arbitrary log data is located within the top 10% of the above first range, the log data may correspond to log data of a normal pattern, which is an example and is not limited by the above range.

[0135] If there is no existing log data for a specific access subject for whom access approval has been completed in user account authentication, network authentication, terminal authentication, and / or facial authentication procedures (e.g., when the access subject accesses the server for the first time), the processor may perform a dynamic authentication procedure of any one of authentication levels 1 to 3 for the access subject.

[0136] A dynamic authentication enhancement security method may be implemented in the form of a computer program written to perform each step on a computer and recorded on a computer-readable recording medium. The aforementioned computer program may include code encoded in a computer language such as C / C++, C#, JAVA, Python, or machine language, which can be read by the computer's processor (CPU) through the computer's device interface, so that the computer reads the program and executes the methods implemented in the program. Such code may include functional code related to functions that define the necessary functions for executing the methods, and may include control code related to execution procedures necessary for the computer's processor to execute the functions according to a predetermined procedure. Furthermore, such code may further include memory reference code regarding where (address) additional information or media necessary for the computer's processor to execute the functions should be referenced in the computer's internal or external memory. In addition, if the processor of the computer needs to communicate with any other computer or server located remotely in order to execute the above functions, the code may further include communication-related code regarding how to communicate with any other computer or server located remotely using the communication module of the computer, and what information or media to transmit or receive during communication.

[0137] The above-mentioned storage medium refers to a medium that stores data semi-permanently and is readable by a device, rather than a medium that stores data for a short period of time, such as a register, cache, or memory. Specifically, examples of the above-mentioned storage medium include, but are not limited to, ROM, RAM, CD-ROM, magnetic tape, floppy disk, and optical data storage device. That is, the above-mentioned program may be stored on various recording media on various servers that the computer can access, or on various recording media on the user's computer. Additionally, the above-mentioned medium may be distributed across networked computer systems, and computer-readable code may be stored in a distributed manner.

[0138] Although embodiments of this specification have been described above with reference to the attached drawings, those skilled in the art to which this specification pertains will understand that the present invention may be implemented in other specific forms without altering its technical concept or essential features. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive.

Claims

Claim 1 A reliability score-based dynamic authentication enhancement security device comprising: a hardware processor; and a storage unit connected to the processor and configured to store at least one computer program configured to perform a reliability score-based dynamic authentication enhancement security method, wherein the dynamic authentication enhancement security method comprises: (a) a step of performing an authentication procedure for a plurality of authentication areas when an authentication request signal is received from a user terminal; (b) a step of generating abnormal behavior information from log data collected from the user terminal and calculating a reliability score when authentication is approved; and (c) a step of performing any one of a plurality of dynamic authentication procedures based on the reliability score; wherein step (c) is a step of transmitting a request signal to the user terminal to select an authentication number displayed on another user terminal among at least one authentication number displayed on the user terminal according to the reliability score, and verifying whether the selected authentication number is valid, and wherein the number of authentication numbers displayed on the user terminal is set according to the reliability score interval in which the reliability score is located among a plurality of preset reliability score intervals, and wherein the plurality of reliability score intervals include a first interval in which the smallest number of authentication numbers are displayed on the user terminal, a second interval in which a relatively larger number of authentication numbers are displayed than in the first interval, and a third interval in which the largest number of authentication numbers are displayed. Claim 2 A dynamic authentication enhanced security device according to claim 1, wherein the plurality of authentication areas include a user account authentication area, a network authentication area, a terminal authentication area, and a dynamic authentication area. Claim 3 A dynamic authentication enhanced security device according to claim 2, wherein step (a) is a step of further performing a facial authentication procedure when the user terminal connects to a preset system. Claim 4 A dynamic authentication enhanced security device according to claim 1, wherein the log data is associated with at least one of an identifier and identity (Identity & User), a device and endpoint (Device & Endpoint), a network (Network), a system (System), an application and workload (Application & Workload), and data. Claim 5 A dynamic authentication enhanced security device according to claim 1, wherein the storage unit further stores an artificial neural network model that generates abnormal behavior information using the log data as an input value, and the step (b) is a step of calculating a reliability score based on the abnormal behavior information obtained by inputting the log data to the artificial neural network model. Claim 6 A dynamic authentication enhanced security device according to claim 1, wherein step (c) further comprises blocking a session associated with the user terminal. Claim 7 delete Claim 8 delete Claim 9 delete Claim 10 delete Claim 11 delete Claim 12 delete Claim 13 A dynamic authentication enhanced security device according to claim 1, wherein step (c) further comprises blocking access to a user account accessed through the user terminal when the reliability score is located within a preset range. Claim 14 A computer program written to perform each step of the dynamic authentication enhancement security method according to any one of claims 1 to 6 and 13 on a computer and recorded on a computer-readable recording medium.