Login user authentication method and apparatus using distributed id-based identity verification

The two-factor authentication system using distributed ID-based identity verification strengthens PC terminal login security by requiring a second authentication factor from a mobile terminal, effectively mitigating the risks associated with one-factor authentication methods.

WO2025116077A1PCT designated stage expired Publication Date: 2025-06-05DREAMSECURITY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2023/019549
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-29
Filing Date
2023-11-30
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing user account-based login methods for PC terminals rely on one-factor authentication, making them vulnerable to theft through hacking or social engineering, leading to potential unauthorized access.

Method used

Implementing a two-factor authentication system using distributed ID-based identity verification, which involves executing a login control program, requesting identity verification through an intermediary server, and performing signature verification using public keys in distributed ID documents.

Benefits of technology

Enhances the security of PC terminal login by requiring a second authentication factor from a mobile terminal, significantly reducing the risk of external theft and ensuring only the legitimate user can access their account.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2023019549_05062025_PF_FP_ABST
    Figure KR2023019549_05062025_PF_FP_ABST
Patent Text Reader

Abstract

A login user authentication method using distributed ID-based identity verification according to one embodiment of the present invention comprises the steps of: executing a login control program on the basis of a login attempt of a user; requesting an identity verification authentication mediation server to submit identity verification by using a user phone number in a database; comparing an identity verification identifier in an identity verification submission document with an identifier in the database; retrieving a user distributed ID document by using a user distributed ID in the identity verification submission document; performing signature verification of the identity verification submission document by using a public key in the user distributed ID document; retrieving an issuer distributed ID document by using an issuer distributed ID; and performing user identity verification signature verification by using a public key in the issuer distributed ID document.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for user authentication using decentralized ID-based authentication

[0001] The present invention relates to a technology that supports login user authentication using a distributed ID-based identity verification.

[0002] Typical login authentication for PC terminals uses a user account login method based on an ID and password, and this method is frequently used by individuals and organizations. While user account-based login methods offer the advantage of simplicity, their primary authentication structure makes them vulnerable to theft of PC terminal information through technical theft, such as hacking, or through social engineering by insiders.

[0003] The present invention proposes a method for strengthening login authentication through a second authentication method when authenticating a user PC terminal login and enabling self-directed control of the authentication method.

[0004] The purpose of the present invention is to provide a strengthened authentication system by performing secondary authentication using a distributed ID-based identity verification when a user accesses a login terminal.

[0005] In addition, an object of the present invention is to provide an authentication method that is safe from external theft by enabling control of a second authentication means in a mobile terminal.

[0006] According to one embodiment of the present invention for achieving the above object, a login user authentication method using a distributed ID-based identity verification comprises the steps of: executing a login control program based on a user's login attempt; requesting an identity verification submission to an identity verification authentication intermediary server using a user's phone number in a database; comparing an identity verification identifier of an identity verification submission document with an identifier in the database; retrieving a user distributed ID document using a user distributed ID of the identity verification submission document; performing signature verification of an identity verification submission document using a public key in the user distributed ID document; retrieving an issuer distributed ID document using an issuer distributed ID; and performing signature verification of a user identity verification document using a public key in the issuer distributed ID document.

[0007] At this time, the database may include a user identification identifier, a user phone number, an operating system account, and an operating system password.

[0008] At this time, the above-mentioned identity verification submission document may be received by the above-mentioned identity verification authentication intermediary server from the above-mentioned user identity verification wallet.

[0009] At this time, the identity verification submission document is generated from the user identity verification wallet and may include user identity verification and user distributed ID information.

[0010] At this time, the above-mentioned identity verification submission document may be signed with the user's distributed ID private key in the user's identity verification wallet.

[0011] At this time, the step of searching for the issuer distributed ID document may include searching for the issuer distributed ID in the user identity certificate, and searching for the issuer distributed ID document using the issuer distributed ID.

[0012] At this time, the user identification may include a user identification identifier, an issuer distributed ID, and user personal information.

[0013] At this time, the user distributed ID document and the issuer distributed ID document can be stored in a distributed trust storage.

[0014]

[0015] In addition, a method for registering a login user using a distributed ID-based identity verification according to an embodiment of the present invention for achieving the above-described purpose includes the steps of: receiving user input information through a login control program; requesting an identity verification submission to an identity verification authentication intermediary server using a user phone number; searching a user distributed ID document using a user distributed ID of an identity verification submission document; performing signature verification of the identity verification submission document using a public key in the user distributed ID document; searching an issuer distributed ID document using an issuer distributed ID; performing signature verification of a user identity verification document using a public key in the issuer distributed ID document; and encrypting user login authentication information and storing it in a database.

[0016] At this time, the user input information may include a user phone number, an operating system account, and an operating system password.

[0017] At this time, the above-mentioned identity verification submission document may be received by the above-mentioned identity verification authentication intermediary server from the above-mentioned user identity verification wallet.

[0018] At this time, the identity verification submission document is generated from the user identity verification wallet and may include user identity verification and user distributed ID information.

[0019] At this time, the above-mentioned identity verification submission document can be signed with the user's distributed ID private key in the user's identity verification wallet.

[0020] At this time, the step of searching for the issuer distributed ID document may include searching for the issuer distributed ID in the user identity certificate, and searching for the issuer distributed ID document using the issuer distributed ID.

[0021] At this time, the user identification may include a user identification identifier, an issuer distributed ID, and user personal information.

[0022] At this time, the user distributed ID document and the issuer distributed ID document can be stored in a distributed trust storage.

[0023]

[0024] In addition, according to one embodiment of the present invention for achieving the above object, a login user authentication device using a distributed ID-based identity verification comprises one or more processors; and an execution memory storing at least one program executed by the one or more processors, wherein the at least one program includes instructions for performing the steps of: executing a login control program based on a user's login attempt; requesting an identity verification authentication intermediary server to submit an identity verification using a user phone number in a database; comparing an identity verification identifier of an identity verification submission document with an identifier in the database; retrieving a user distributed ID document using a user distributed ID in the identity verification submission document; performing signature verification of an identity verification submission document using a public key in the user distributed ID document; retrieving an issuer distributed ID document using an issuer distributed ID; and performing signature verification of a user identity verification using a public key in the issuer distributed ID document.

[0025] According to the present invention, a strengthened authentication system can be provided by performing secondary authentication using a distributed ID-based identity verification when accessing a login terminal.

[0026] In addition, the present invention can provide an authentication method that is safe from external theft by enabling control of a secondary authentication means in a mobile terminal.

[0027] Figure 1 shows the general configuration of a distributed ID system.

[0028] Figure 2 illustrates the flow of a verifiable credential-based identity management service.

[0029] Figures 3 and 4 conceptually illustrate symmetric key and asymmetric key encryption algorithms, respectively.

[0030] FIG. 5 is a flowchart illustrating a login user authentication method using distributed ID-based identity verification according to one embodiment of the present invention.

[0031] Figure 6 is a flowchart illustrating a login user registration method using distributed ID-based identity verification according to one embodiment of the present invention.

[0032] Figure 7 is a diagram showing a system configuration according to one embodiment of the present invention.

[0033] Figure 8 is a flowchart showing an identity verification issuance step in a method according to one embodiment of the present invention.

[0034] FIG. 9 and FIG. 10 are flowcharts showing an identity registration step in a method according to one embodiment of the present invention.

[0035] FIG. 11 and FIG. 12 are flowcharts showing an identity verification authentication step in a method according to one embodiment of the present invention.

[0036] Fig. 13 is a diagram showing the configuration of a computer system according to an embodiment.

[0037] The advantages and features of the present invention, and the methods for achieving them, will become clearer with reference to the embodiments described in detail below together with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below, but may be implemented in various different forms. These embodiments are provided only to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification.

[0038] Although "first" or "second" are used to describe various components, these components are not limited by such terms. Such terms may only be used to distinguish one component from another. Accordingly, a first component referred to below may also be a second component within the technical scope of the present invention.

[0039] The terminology used herein is for the purpose of describing embodiments and is not intended to limit the present invention. In this specification, the singular also includes the plural unless specifically stated otherwise. As used herein, the terms "comprises" or "comprising" imply that a stated component or step does not exclude the presence or addition of one or more other components or steps.

[0040] In this specification, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" may include any one of the items listed together in that phrase, or all possible combinations thereof.

[0041] Unless otherwise defined, all terms used herein are to be interpreted as having a meaning commonly understood by those of ordinary skill in the technical field to which the present invention pertains. Furthermore, terms defined in commonly used dictionaries are not to be interpreted ideally or excessively unless explicitly and specifically defined otherwise.

[0042] Hereinafter, embodiments of the present invention will be described in detail with reference to the attached drawings. When describing with reference to the drawings, identical or corresponding components are given the same drawing reference numerals, and redundant descriptions thereof will be omitted.

[0043] The present invention is an authentication technology for logging into a PC terminal using an identity verification, which is a verifiable credential in a distributed ID-based environment, so that even if a third party steals the user's PC terminal account information through a technical or social engineering method, only the owner of the distributed ID-based identity verification can log into his or her own PC terminal, thereby providing a self-directed PC login authentication function.

[0044] Figure 1 shows the general configuration of a distributed ID system.

[0045] Decentralized ID is a core technology for next-generation identity management. It allows users to proactively control their own identities, moving away from the centralized ID systems typically used in isolated or federated services. Decentralized ID systems enable self-directed authentication across various Internet services without the intervention of a centralized certification authority. Decentralized ID technology is currently a W3C standard.

[0046] The general structure of the decentralized ID system is as shown in Figure 1, and all users can register and manage their own decentralized IDs in a distributed trust store. A decentralized ID document containing a public key corresponding to the user's decentralized ID is registered in the distributed trust store. When users exchange requests / responses, the sender signs the message to be transmitted with the private key corresponding to their decentralized ID and then transmits it to the receiver to authenticate that the other user is a user registered in the decentralized trust store. The receiver can then look up the sender's decentralized ID document in the distributed trust store, obtain the public key corresponding to the sender's decentralized ID, and then verify the signed message sent by the sender. This allows for authentication that the sender is a valid user registered in the distributed trust store.

[0047] Figure 2 illustrates the flow of a verifiable credential-based identity management service.

[0048] Verifiable credentials are a standard for identity verification used in next-generation identity management. They are a decentralized technology that allows users to directly manage and control their own identity information. Verifiable credentials are based on decentralized IDs and enable self-authorized authentication for various Internet services without the intervention of a certification authority.

[0049] Verifiable credential technology is currently a W3C standard and is being used as an identity management technology in various industries, including mobile driver's licenses, vaccine certificates, and employment certificates. The basic flow of a verifiable credential-based identity management service is illustrated in Figure 2. The issuing agency issues an identity certificate to the user, the user manages the issued identity certificate, and the user submits the identity certificate to the desired service provider for verification. During this process, a distributed trust store stores a decentralized ID document containing the issuing agency, user, and verification agency's decentralized IDs, along with their respective public keys.

[0050] Figures 3 and 4 conceptually illustrate symmetric key and asymmetric key encryption algorithms, respectively.

[0051] Encryption is an essential security technology in today's information society. It protects sensitive information by converting it into a form that is difficult for others to read. It is primarily used to protect sensitive information from end-to-end transmission and reception over the Internet. The sensitive information in this case is called plaintext, and the encrypted version is called ciphertext. The process of reconstructing this ciphertext back into plaintext is called decryption.

[0052] Encryption / decryption processes require encryption keys, which are broadly categorized into symmetric and asymmetric key algorithms. Symmetric key algorithms use the same encryption key during encryption / decryption. While computationally fast, they offer limited security because only a single encryption key is shared between the sender and receiver.

[0053] Asymmetric key algorithms are algorithms that use different encryption keys during the encryption / decryption process. They are slow to operate and are less efficient for large data sets, but their security is stronger than that of symmetric keys because the encryption and decryption keys are different.

[0054] FIG. 5 is a flowchart illustrating a login user authentication method using distributed ID-based identity verification according to one embodiment of the present invention.

[0055] A login user authentication method using a distributed ID-based identity verification according to one embodiment of the present invention can be performed at a user terminal, and in particular, can be performed at a user login terminal such as a PC.

[0056] A login user authentication method using a distributed ID-based identity verification according to one embodiment of the present invention includes a step of executing a login control program based on a user's login attempt (S110), a step of requesting an identity verification submission to an identity verification authentication intermediary server using a user's phone number in a database (S120), a step of comparing an identity verification identifier of an identity verification submission document with an identifier in the database (S130), a step of searching a user distributed ID document using a user distributed ID of an identity verification submission document (S140), a step of performing identity verification of a signature of an identity verification submission document using a public key in the user distributed ID document (S150), a step of searching an issuer distributed ID document using an issuer distributed ID (S160), and a step of performing user identity verification of a signature using a public key in the issuer distributed ID document (S170).

[0057] At this time, the database may include a user identification identifier, a user phone number, an operating system account, and an operating system password.

[0058] At this time, the above-mentioned identity verification submission document may be received by the above-mentioned identity verification authentication intermediary server from the above-mentioned user identity verification wallet.

[0059] At this time, the identity verification submission document is generated from the user identity verification wallet and may include user identity verification and user distributed ID information.

[0060] At this time, the above-mentioned identity verification submission document may be signed with the user's distributed ID private key in the user's identity verification wallet.

[0061] At this time, the step (S160) of searching for the issuer distributed ID document may search for the issuer distributed ID in the user identification, and search for the issuer distributed ID document using the issuer distributed ID.

[0062] At this time, the user identification may include a user identification identifier, an issuer distributed ID, and user personal information.

[0063] At this time, the user distributed ID document and the issuer distributed ID document can be stored in a distributed trust storage.

[0064] Figure 6 is a flowchart illustrating a login user registration method using distributed ID-based identity verification according to one embodiment of the present invention.

[0065] A method for registering a login user using a distributed ID-based identity verification according to one embodiment of the present invention can be performed at a user terminal, and in particular, can be performed at a user login terminal such as a PC.

[0066] A login user registration method using a distributed ID-based identity verification according to one embodiment of the present invention includes a step of receiving user input information through a login control program (S210), a step of requesting an identity verification submission to an identity verification authentication intermediary server using a user phone number (S220), a step of searching a user distributed ID document using a user distributed ID of an identity verification submission document (S230), a step of performing identity verification signature verification using a public key in the user distributed ID document (S240), a step of searching an issuer distributed ID document using an issuer distributed ID (S250), a step of performing user identity verification signature verification using a public key in the issuer distributed ID document (S260), and a step of encrypting user login authentication information and storing it in a database (S270).

[0067] At this time, the user input information may include a user phone number, an operating system account, and an operating system password.

[0068] At this time, the above-mentioned identity verification submission document may be received by the above-mentioned identity verification authentication intermediary server from the above-mentioned user identity verification wallet.

[0069] At this time, the identity verification submission document is generated from the user identity verification wallet and may include user identity verification and user distributed ID information.

[0070] At this time, the above-mentioned identity verification submission document can be signed with the user's distributed ID private key in the user's identity verification wallet.

[0071] At this time, the step (S250) of searching for the issuer distributed ID document may search for the issuer distributed ID in the user identification, and search for the issuer distributed ID document using the issuer distributed ID.

[0072] At this time, the user identification may include a user identification identifier, an issuer distributed ID, and user personal information.

[0073] At this time, the user distributed ID document and the issuer distributed ID document can be stored in a distributed trust storage.

[0074] Figure 7 is a diagram showing a system configuration according to one embodiment of the present invention.

[0075] A user identity wallet is an entity that owns and controls the identity, and can store the user's decentralized ID, the private key corresponding to the user's decentralized ID, and the identity issued by the identity issuer server.

[0076] At this time, the user can log in to the user's PC and be identified as the owner of the ID card, who directly controls the user's ID wallet. The user's PC can correspond to the PC terminal the user is attempting to authenticate through.

[0077] A login control program is software installed on a user's PC terminal to perform user login. It connects to a local database and can perform PC terminal login information registration and authentication procedures. The local database can correspond to a repository that stores user authentication-based login information. When authenticating with authentication-based login, login information can be retrieved from the local database.

[0078] The identity certificate issuer server is an entity that issues identity certificates and can store the identity certificate issuer decentralized ID and the private key corresponding to the identity certificate issuer decentralized ID.

[0079] The identity verification authentication intermediary server may correspond to an entity that interfaces between the user's PC's login control program and the user's identity verification wallet.

[0080] A distributed trust storage is a space that stores and manages distributed ID document information. It generally uses blockchain technology and can also be configured in the form of a distributed ledger.

[0081] The process of the present invention can consist of identity issuance, identity registration, and identity authentication steps. Users can be company employees, and the identity issuing server can be the company itself. Each entity must register its own decentralized ID in a distributed trust store to verify its identity as a trusted entity based on decentralized IDs. Subsequently, all request / response messages can be signed and verified using the public key pair corresponding to each entity's decentralized ID.

[0082] Assuming the user's PC is running Windows, the user requests the company to issue an ID card for login authentication on their work PC terminal. The company can then issue an ID card to enable the user to authenticate login to their work PC terminal. To verify that the ID card was issued by the company, the ID card includes a value signed with the company's decentralized ID's private key. The issued ID card is stored in the user's mobile device's ID wallet and is under the sole control of the user.

[0083] Afterwards, the user can register their identity for PC login authentication. The user runs the login control program, enters their phone number, PC account, and password, and then clicks the [Register] button. The login control program then requests the user's mobile device to submit their identity via the phone number. This process is performed via the identity authentication intermediary server connected to the login control program. The identity authentication intermediary server must be provided by the entity that established the relevant identity management system. In this scenario, it is assumed to be provided by the company.

[0084] The user submits their identity in response to a request for identity submission sent from the login control program to the user's identity wallet. The login control program receives the response via the identity authentication intermediary server. The user's PC can verify the identity issuer's distributed ID document in the distributed trust store to confirm that the identity is issued by the company. The user can then verify the identity by verifying the signature with the corresponding public key. Upon verification, the user's PC can encrypt and store the information required for subsequent login authentication in a local database.

[0085] After registering an identity, a login control program is executed when a user attempts to log in to a PC terminal. The login control program decrypts the login authentication information encrypted in the local database, obtains the user's phone number, and then requests the user to submit an identity verification certificate via the phone number. The user submits the identity verification certificate in response to the identity verification submission request transmitted from the login control program to the user's identity verification wallet, and the login control program can receive the response through the identity verification authentication intermediary server. If the received identity verification certificate has previously been registered in the local database, the login control program decrypts the encrypted login authentication information in the local database, obtains the user's PC account and password, and transmits them to the Windows OS login system to complete the user PC login authentication.

[0086] Figure 8 is a flowchart showing an identity verification issuance step in a method according to one embodiment of the present invention.

[0087] The user identity verification wallet (200) and the identity verification issuer server (100) correspond to the owner and issuer, respectively, in a decentralized ID-based identity management system, and may correspond to entities that must have a decentralized ID. Prior to the identity verification issuance process, the user identity verification wallet (200) and the identity verification issuer server (100) each generate a decentralized ID and public key pair (S301, S302) and register a decentralized ID document containing a public key corresponding to the decentralized ID in a distributed trust storage (300) (S303, S304). Upon completion of the decentralized ID document registration process, the user identity verification wallet (200) and the identity verification issuer server (100) receive a decentralized ID registration response (S305).

[0088] The user identity verification wallet (200) generates a user identity verification issuance request containing the user decentralized ID to request the identity verification issuer server (100) to issue an identity verification and signs the identity verification issuance request with the user decentralized ID private key (S306). The user identity verification wallet (200) transmits the signed user identity verification issuance request to the identity verification issuer server (100) (S307), and the identity verification issuer server (100) obtains the user decentralized ID from the received user identity verification issuance request (S308).

[0089] The identity certificate issuer server (100) can retrieve a user decentralized ID document from the distributed trust storage (300) using the user decentralized ID obtained from the user identity certificate issuance request (S309, S310, S311). Next, after obtaining a public key from the user decentralized ID document, the identity certificate issuance request signed by the user can be verified by signature verification to verify whether the user is a user registered in the distributed trust storage (300) (S312).

[0090] Once signature verification is complete, the identity certificate issuer server (100) generates an identity certificate to be issued to the user, and this identity certificate complies with the W3C's Verifiable Credential standard (S313). The generated user identity certificate original text largely consists of an identity certificate identifier, an issuer distributed ID, and user personal information. After generating the user identity certificate original text, a value signed with the issuer's distributed ID private key is added to issue the identity certificate to the user (S314). The user identity certificate wallet (200) stores the issued user identity certificate in the wallet (S315).

[0091] FIG. 9 and FIG. 10 are flowcharts showing an identity registration step in a method according to one embodiment of the present invention.

[0092] According to one embodiment of the present invention, upon completion of the identity verification issuance step, a method performs an identity verification registration process for user PC login authentication. The user executes a login control program pre-installed on the user PC terminal (500) and, when a window for entering user information appears, enters the information (S401, S402). The information to be entered may include the user's phone number, Windows account information, and password information. After entering the information and clicking the register button, a request is made to submit user identity verification to a mobile terminal with the corresponding phone number to verify the identity of the user of the corresponding PC (S404, S405). The user wallet that receives the identity verification submission request creates an identity verification submission document (VP) and signs the identity verification submission document with the user's distributed ID private key (S406, S407). The user identity verification wallet (200) transmits the identity verification to the user PC (500) via the identity verification authentication intermediary server (400) (S408, S409).

[0093] That is, the identity verification authentication intermediary server (400) can mediate communication between the user identity verification wallet (200) and the user PC login control program (500). When the identity verification authentication intermediary server (400) requests submission of identity verification to the user identity verification wallet (200), the push method, rather than TCP, can be used.

[0094] The identity submission document can comply with the standard method (Verifiable Presentation) for submitting verifiable credentials of the W3C standard, and when the identity submission document containing the user identity and the user decentralized ID is created, the signed identity submission document is signed with the user decentralized ID private key and transmitted to the identity submission authentication intermediary server (400). The identity submission authentication intermediary server (400) transmits the identity submission document to the login control program (500) of the user PC, and the login control program (500) of the user PC obtains the user identity and the user decentralized ID from the transmitted identity submission document (S410). The login control program (500) requests a user decentralized ID document query to the distributed trust storage (300) to verify the signature of the identity submission document (S411), and receives a user decentralized ID document query response from the distributed trust storage (300) (S412, S413). The login control program (500) verifies the signature of the identity verification submission request using the public key in the received user distributed ID document (S414).

[0095] If it is confirmed through verification of the submission document of the identity verification that it is a submission document sent by the user, a request is made to the distributed trust storage (300) to look up the issuer decentralized ID contained in the obtained user identity verification to obtain an issuer decentralized ID document (S415, S416, S417, S418). The login control program (500) can verify the issuer signature value of the user identity verification submitted by the user through the public key in the obtained issuer decentralized ID document to confirm that the user identity verification was issued by the correct identity verification issuer server (100) (S419). Once the user identity verification is complete, the login control program registers a total of four pieces of information, including the identity verification identifier, user phone number, Windows account, and Windows password, in the local DB of the user PC, and the information can be used when the user authenticates the PC login in the future (S420). The PC login authentication information can be encrypted and stored in the local DB.

[0096] FIG. 11 and FIG. 12 are flowcharts showing an identity verification authentication step in a method according to one embodiment of the present invention.

[0097] Once user PC login authentication information, including an identity verification identifier, is registered, the user can then use the identity verification-based PC login authentication function. When a user attempts to log in to a locked PC terminal, the Windows OS calls a login control program (S501, S502). The login control program can decrypt encrypted information in the local database to obtain the user's phone number (S503, S504). The login control program (500) can request the submission of user identity verification from a mobile terminal with the phone number obtained through the identity verification authentication intermediary server (400) (S505, S506).

[0098] The user identity verification wallet (200) creates an identity verification submission form in response to the received identity verification submission request (S507). The user identity verification wallet (200) signs the identity verification submission form containing the user identity and the user decentralized ID with the user decentralized ID private key (S508), and transmits the signed identity verification submission form to the user PC (500) via the identity verification authentication intermediary server (400) (S509, S510).

[0099] At this time, the identity verification authentication intermediary server (400) may use a push method rather than TCP when requesting identity verification submission to the user identity verification wallet (200). At this time, the identity verification submission document may comply with the standard method (Verifiable Presentation) for submitting verifiable credentials of the W3C standard.

[0100] The login control program (500) obtains a user identity certificate and a user distributed ID from the received identity certificate submission document (S511). The login control program (500) can compare the identity certificate identifier among the decrypted information in the local DB with the identifier within the user identity certificate obtained from the identity certificate submission document to confirm that it is the identity certificate of a previously registered user (S512).

[0101] Once the identifier comparison verification is complete, the login control program verifies the signature of the identity submission document and the user identity within the submission document. The signature verification of the identity submission document can obtain a distributed ID from the identity submission document (S513) and request a distributed ID document search corresponding to the user's distributed ID from the distributed trust storage (300) (S514).

[0102] A user distributed ID document query response is received from a distributed trust storage (300) (S515, S516), and the signature of the identity proof submission request can be verified using the public key in the user distributed ID document (S517).

[0103] Additionally, the login control program can verify the issuer decentralized ID in the user authentication (S518), retrieve the issuer decentralized ID document, and receive an issuer decentralized ID document query response from the block trust storage (300) (S519, S520, S521). The user authentication signature is verified using the public key in the received decentralized ID document (S522).

[0104] When each signature verification is completed, the login control program (500) obtains the Window account and password from the decrypted information of the local DB and transmits them to the Window OS (S523), and the Window OS automatically enters the received Window account and password information into the login system7 to complete user PC login authentication (S524).

[0105] Fig. 13 is a diagram showing the configuration of a computer system according to an embodiment.

[0106] A user registration and authentication device using a distributed ID-based identity verification according to an embodiment can be implemented in a computer system (1000) such as a computer-readable recording medium.

[0107] The computer system (1000) may include one or more processors (1010), memory (1030), user interface input devices (1040), user interface output devices (1050), and storage (1060) that communicate with each other via a bus (1020). In addition, the computer system (1000) may further include a network interface (1070) connected to a network (1080). The processor (1010) may be a central processing unit or a semiconductor device that executes programs or processing instructions stored in the memory (1030) or storage (1060). The memory (1030) and storage (1060) may be storage media that include at least one of a volatile medium, a nonvolatile medium, a removable medium, a non-removable medium, a communication medium, or an information transmission medium. For example, the memory (1030) may include a ROM (1031) or a RAM (1032).

[0108] The specific implementations described in the present invention are exemplary and do not limit the scope of the present invention in any way. For the sake of brevity of the specification, descriptions of conventional electronic components, control systems, software, and other functional aspects of the systems may be omitted. In addition, the lines connecting or connecting members between components depicted in the drawings are merely representative of functional connections and / or physical or circuit connections, and may be replaced or represented as various additional functional connections, physical connections, or circuit connections in an actual device. In addition, unless specifically mentioned as “essential,” “important,” etc., a component may not be absolutely necessary for the application of the present invention.

[0109] Therefore, the idea of ​​the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of ​​the present invention.

Claims

1. In the identity verification authentication method performed on a user terminal, A step of executing a login control program based on a user's login attempt; A step of requesting submission of identity verification to an identity verification authentication intermediary server using a user phone number in the database; A step of comparing the identity verification identifier of the identity verification submission request with the identifier in the database; Step for searching user distributed ID document using user distributed ID of identity verification submission request; A step of performing signature verification of an identity proof submission document using a public key in the above user distributed ID document; Step for querying an issuer distributed ID document using the issuer distributed ID; and A step of performing user identity verification signature verification using the public key in the above issuer distributed ID document; A method for authenticating a login user using a distributed ID-based identity verification system including .

2. In claim 1, The above database is A login user authentication method using a distributed ID-based identity verification, characterized by including a user identity verification identifier, a user phone number, an operating system account, and an operating system password.

3. In claim 1, The above identification document must be submitted A login user authentication method using a distributed ID-based identity verification, characterized in that the identity verification authentication intermediary server receives the identity verification from the user identity verification wallet.

4. In claim 3, The above identification document must be submitted Generated from the above user authentication wallet, A login user authentication method using distributed ID-based identity verification, characterized by including user identity verification and user distributed ID information.

5. In claim 4, The above identification document must be submitted A login user authentication method using a decentralized ID-based identity verification, characterized in that the user's identity verification wallet is signed with the user's decentralized ID private key.

6. In claim 4, The steps to retrieve the above issuer distributed ID document are: A login user authentication method using a distributed ID-based identity verification, characterized by searching for an issuer distributed ID in the user identity verification and searching for an issuer distributed ID document using the issuer distributed ID.

7. In claim 4, The above user identification is A login user authentication method using a decentralized ID-based identity verification, characterized by including a user identity verification identifier, an issuer decentralized ID, and user personal information.

8. In claim 1, A login user authentication method using a distributed ID-based identity verification, characterized in that the user distributed ID document and the issuer distributed ID document are stored in a distributed trust storage.

9. In the method of registering identity verification performed on a user terminal, A step of receiving user input information through a login control program; A step of requesting submission of identity verification to an identity verification authentication intermediary server using the user's phone number; Step for searching user distributed ID document using user distributed ID of identity verification submission request; A step of performing signature verification of an identity proof submission document using a public key in the above user distributed ID document; Step for querying an issuer distributed ID document using the issuer distributed ID; A step of performing user identity verification signature verification using the public key in the above issuer distributed ID document; and Step of encrypting user login credentials and storing them in a database; A method for registering a login user using a distributed ID-based identity verification system including .

10. In claim 9, The above user input information A method for registering a login user using a distributed ID-based identity verification method, characterized by including a user phone number, an operating system account, and an operating system password.

11. In claim 9, The above identification document must be submitted A login user registration method using a distributed ID-based identity verification, characterized in that the identity verification authentication intermediary server receives the identity verification from the user identity verification wallet.

12. In claim 11, The above identification document must be submitted Generated from the above user authentication wallet, A method for registering a login user using a distributed ID-based identity verification, characterized by including user identity verification and user distributed ID information.

13. In claim 12, The above identification document must be submitted A method for registering a login user using a decentralized ID-based identity verification, characterized in that the user's identity verification wallet is signed with the user's decentralized ID private key.

14. In claim 12, The steps to retrieve the above issuer distributed ID document are: A login user registration method using a distributed ID-based identity verification, characterized by searching for an issuer distributed ID in the user identity verification and searching for an issuer distributed ID document using the issuer distributed ID.

15. In claim 12, The above user identification is A method for registering a login user using a decentralized ID-based identity verification, characterized by including a user identity verification identifier, an issuer decentralized ID, and user personal information.

16. In claim 9, A login user registration method using decentralized ID-based identity verification, characterized in that the user decentralized ID document and the issuer decentralized ID document are stored in a distributed trust storage.

17. One or more processors; and comprising an execution memory storing at least one program executed by said one or more processors; At least one of the above programs A step of executing a login control program based on a user's login attempt; A step of requesting submission of identity verification to an identity verification authentication intermediary server using a user phone number in the database; A step of comparing the identity verification identifier of the identity verification submission request with the identifier in the database; Step for searching user distributed ID document using user distributed ID of identity verification submission request; A step of performing signature verification of an identity proof submission document using a public key in the above user distributed ID document; Step for querying an issuer distributed ID document using the issuer distributed ID; and A step of performing user identity verification signature verification using the public key in the above issuer distributed ID document; A login user authentication device using a distributed ID-based identity verification including commands for performing the following.

Citation Information

Patent Citations

  • Massage apparatus for providing pulsed electro magnetic field and operation thereof

    KR1020220144756A

  • Allulose composition with excellent stability

    KR1020240002725A

  • Processing apparatus

    KR1020240064527A

  • Display device

    KR1020240112406A

  • Method and apparatus for verifying digital identity, device and storage medium

    US20210218574A1