System for biometric authentication and operation method thereof
The system addresses the security vulnerability of devices lacking biometric authentication by enabling external devices to use biometric authentication through connected electronic devices with biometric modules, enhancing security and user experience.
Patent Information
- Application Number
- PCT/KR2024/019639
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-19
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-12
AI Technical Summary
Devices such as desktops and smart TVs lack biometric authentication capabilities, making them more vulnerable to security compared to smartphones, which have built-in biometric identification devices.
A system that includes an electronic device with a biometric module and an external device connected via wireless communication, where the electronic device provides a biometric data template to the external device, which stores and transmits a remote authentication template for verification, enabling biometric authentication for external devices without native biometric capabilities.
This solution enhances the security of devices without built-in biometric authentication by allowing them to utilize biometric authentication through connected electronic devices, providing a secure and user-friendly experience.
Smart Images

Figure KR2024019639_12062025_PF_FP_ABST
Abstract
Description
System for biometric authentication and its operating method
[0001] The present disclosure relates to a system for biometric authentication and a method of operating the same.
[0002] Recent mass-produced smartphones are equipped with biometric identification devices, such as fingerprint sensors, which are used for unlocking, purchasing and paying for high-security items, and for authentication services such as deposits, withdrawals, and remittances. For less secure situations, users can authenticate using numbers, codes, or patterns.
[0003] On the other hand, devices such as desktops or smart TVs generally do not have biometric authentication devices like smartphones, and only perform authentication using numbers, codes, or patterns. Therefore, despite providing smartphone-like functions, they are relatively vulnerable to security.
[0004] To solve this problem, one could consider performing authentication by connecting a biometric device to a desktop or smart TV, either wired or wirelessly. However, this would require the purchase of separate hardware and the installation of an additional application to ensure compatibility with the device.
[0005] According to one embodiment, a system includes an electronic device having a biometric module and an external device connected to the electronic device, wherein the electronic device provides a biometric data template acquired from the biometric module to the external device while the electronic device and the external device are connected via wireless communication, the external device stores a remote authentication template in which a plurality of attributes are assigned to the biometric data template, the external device transmits the remote authentication template to the electronic device in response to a user's request for execution of an application, the electronic device verifies the validity of the remote authentication template based on a comparison between the remote authentication template and the biometric data template, and the external device requests biometric authentication from the electronic device based on the validity verified from the electronic device, and executes the application based on a result of the biometric authentication of the electronic device.
[0006] An external device according to one embodiment may include a processor and a memory storing at least one instruction executable by the processor. The at least one instruction may cause the external device to: receive a biometric data template acquired from the biometric module from the electronic device, store a remote authentication template in which a plurality of attributes are assigned to the biometric data template, transmit the remote authentication template to the electronic device in response to a user's request to execute an application, receive a validation result of the remote authentication template from the electronic device based on a comparison between the remote authentication template and the biometric data template, request biometric authentication from the electronic device based on the validity, and execute the application based on the biometric authentication result of the electronic device.
[0007] According to one embodiment, a recording medium may be a non-transitory computer-readable recording medium storing instructions that, when executed by at least one processor, cause the at least one processor to perform set operations. The operations may include receiving a biometric data template acquired from the biometric module from the electronic device, storing a remote authentication template in which a plurality of attributes are assigned to the biometric data template, transmitting the remote authentication template to the electronic device in response to a user's request for execution of an application, receiving a result of a validation of the remote authentication template based on a comparison between the remote authentication template and the biometric data template from the electronic device, requesting biometric authentication to the electronic device based on the validity, and executing the application based on the result of the biometric authentication of the electronic device.
[0008] FIG. 1 is a control block diagram between an electronic device and an external device according to one embodiment.
[0009] FIG. 2 is a flowchart of a system including an electronic device and an external device according to one embodiment.
[0010] FIG. 3 is a signal flow diagram of a remote authentication template registration process of an external device according to one embodiment.
[0011] Figure 4 is a signal flow diagram of an authentication process of a system according to one embodiment.
[0012] FIG. 5 illustrates a system according to one embodiment when there are multiple electronic devices.
[0013] Figure 6 is a signal flow diagram of the operation performed in Figure 5.
[0014] Figure 7 illustrates a system according to one embodiment when there are multiple external devices.
[0015] Figure 8 is a signal flow diagram of the operation performed in Figure 7.
[0016] Figure 9 illustrates a case where a failure occurs in a system according to one embodiment.
[0017] Figure 10 illustrates a payment processing process in a system according to one embodiment.
[0018] Fig. 11 is a signal flow diagram of a payment system according to one embodiment.
[0019] Figure 12 is a signal flow diagram when an external device is a VST device in a system according to one embodiment.
[0020] FIG. 13 is a block diagram of an electronic device within a network environment according to one embodiment.
[0021] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the attached drawings. The advantages and features of the present invention, and methods for achieving them, will become clear with reference to the embodiments described in detail below together with the attached drawings. However, the present invention is not limited to the embodiments disclosed below, but can be implemented in various different forms. These embodiments are provided only to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined only by the scope of the claims. Like reference numerals refer to like elements throughout the specification.
[0022] Unless otherwise defined, all terms (including technical and scientific terms) used herein may be used in their common sense to those of ordinary skill in the art to which the present invention pertains. Furthermore, terms defined in commonly used dictionaries are not to be interpreted ideally or excessively unless explicitly and specifically defined otherwise. The terminology used herein is for the purpose of describing embodiments and is not intended to limit the present invention. In this specification, singular forms also include plural forms, unless specifically stated otherwise.
[0023] The terms "comprises" and / or "comprising" as used in the specification do not exclude the presence or addition of one or more other components, steps, operations and / or elements.
[0024] FIG. 1 is a control block diagram between an electronic device (100) and an external device (200) according to one embodiment.
[0025] The electronic device (100) used in this specification refers to a device that has its own biometric sensor (not shown), and the external device (200) refers to a device without a biometric sensor.
[0026] An electronic device (100) can receive biometric data input from a user through a biometric sensor. The electronic device (100) can authenticate the input biometric data based on a result obtained by inputting the received biometric data (hereinafter, “input biometric data”) into a designated statistical model or engine. The designated statistical model or engine may be a model or engine (hereinafter, “matching model”) stored in a memory of the electronic device (e.g., memory (120) of FIG. 1) and used for authentication of biometric data (e.g., confirming whether the input biometric data matches the stored biometric data). Authentication of biometric information according to one embodiment may be authenticated through an external server (e.g., FIDO, Fast Identity Online).
[0027] In one embodiment, the electronic device (100) may provide the user with the specific service requested to be executed when the input biometric data is authenticated (or when the input biometric data matches stored biometric data).
[0028] A biometric sensor according to one embodiment can obtain biometric information of a user. The biometric information of the user may include, for example, fingerprints, irises, facial images, voices, heartbeats, or blood pressure information. The electronic device (100) can obtain the biometric information of the user through the biometric sensor. For example, the electronic device (100) can obtain the fingerprint information of the user through a fingerprint sensor. Alternatively, the electronic device (100) can obtain the iris information of the user through a camera module (1380 of FIG. 13). The processor (110) connected to the biometric sensor can display a user interface (UI) for obtaining the biometric information of the user through a display (1360 of FIG. 13).
[0029] Meanwhile, an external device (200) according to one embodiment refers to a general device that is not equipped with a biometric sensor. For example, the external device (200) refers to all devices, such as desktops and TVs, that are not typically equipped with a fingerprint sensor or an iris sensor (not shown), or that are not equipped with a sensor such as a camera that cannot function as a biometric sensor. The external device (200) according to one embodiment may include home appliances such as a refrigerator, a washing machine, and an air conditioner. However, as an exception, an external device (200) that includes a biometric sensor may include an HMD (Head Mounted Display) device such as a Video-See-Through (VST). For example, if the external device (200) is a VST device, the VST device may not have a fingerprint sensor and may only include an iris sensor.
[0030] Referring to FIG. 2, the electronic device (100) may include a first processor (110) and a first memory (120).
[0031] The processor (110, first processor) may include, for example, a general environment (REE, rich execution environment) and / or a secure environment (TEE, trusted execution environment). The processor (110) may process data requiring a relatively high level of security through the secure environment (TEE). The general environment (REE) and the secure environment (TEE) may be implemented, for example, in a physically separated form, a software separated form, or a form utilizing both physical separation and software separation. The secure environment (TEE) may be connected to separate security hardware (not shown) through a secure channel, for example. For example, the security hardware may include an embedded secure element (eSE) and / or a Secure Processor.
[0032] The processor (110) may, for example, access secure hardware through a secure environment and / or a secure channel, rather than a general environment. The processor (110) may, for example, store or execute information or programs requiring a relatively high level of security in a secure circuit through the secure environment and a secure channel. The general environment may, for example, perform typical computational tasks that are not related to security. The general environment may include one or more of a central processing unit (CPU), an application processor (AP), or a communication processor (CP). The general environment may, for example, perform computations or data processing related to control and / or communication of at least one other component (e.g., memory, communication interface, etc.) of the electronic device (100).
[0033] The general environment may receive encrypted security programs and additional information related to the encrypted security programs from external devices (e.g., external servers, desktop PCs, laptops, or short-range wireless communication devices). The general environment may provide the encrypted security programs or additional information to the secure environment.
[0034] The generic environment (REE) may include a first application layer (111), a first framework layer (113), and a first kernel (115).
[0035] The first application layer (111) may include, for example, an operating system (OS) that controls resources related to an electronic device (e.g., electronic device (100)) and / or various applications running on the operating system.
[0036] The first framework layer (113) may, for example, process one or more task requests received from the application layer (111) according to priority. By processing the one or more task requests according to the priority, the framework layer (113) may perform scheduling or load balancing, etc. for the one or more task requests. In various embodiments, the framework layer (113) may include libraries necessary for operating a general environment.
[0037] The first kernel (115) may control or manage system resources (e.g., a bus, processor, or memory) used to execute operations or functions implemented in other programs (e.g., a framework layer or an application layer), for example. In various embodiments, the kernel (115) may include a driver for operating a secure environment.
[0038] The secure environment may be, for example, a trusted execution environment (TEE) for performing secure data communications. For example, the processor (110) may provide operations or security programs related to processing security-related data (e.g., payment information, etc.) to the security circuit. In various embodiments, the secure environment may have a secret key shared with the security circuit and use the secret key to form a channel for transmitting and receiving encrypted data with the security circuit.
[0039] Although all components of the electronic device (100) are illustrated as being included in a single electronic device, embodiments according to the present disclosure are not limited thereto. For example, depending on the role, function, or performance of the electronic device (100), at least some of the components of the electronic device (100) may be implemented in a distributed manner across the electronic device (100) and an external electronic device.
[0040] The external device (200) may include a second processor (210) and a second memory (220).
[0041] The second processor (210) may include a rich execution environment (REE). The second processor (210) may process data requiring a relatively low level of security through the rich execution environment (REE).
[0042] The general environment (REE) may include a second application layer (211), a second framework layer (213), a second kernel (215), and a second memory (220).
[0043] The second application layer (211) may include, for example, an operating system (OS) that controls resources related to an external device (200) and / or various applications running on the operating system.
[0044] The second framework layer (213) may, for example, process one or more task requests received from the second application layer (211) according to priority. By processing the one or more task requests according to the priority, the second framework layer (213) may perform scheduling or load balancing, etc. for the one or more task requests. In various embodiments, the second framework layer (213) may include libraries necessary for operating in a general environment.
[0045] The second kernel (215) may, for example, control or manage system resources (e.g., a bus, processor, or memory) used to execute operations or functions implemented in other programs (e.g., a framework layer or an application layer). In various embodiments, the kernel (215) may include a driver for operating a secure environment.
[0046] Meanwhile, the electronic device (100) and the external device (200) can be paired or connected wirelessly or wiredly using BT, BLE, WiFi, ZIGBEE, USB, IEE1394, etc. At this time, a protocol such as SDCP (Secure Device Connection Protocol) can be used for security when transmitting and receiving data between the electronic device (100) and the external device (200). According to one embodiment, the electronic device (100) can provide biometric data for registration and authentication to the external device (200).
[0047] According to one embodiment, the first memory (120) may temporarily store a biometric data template used for biometric data authentication to encrypt and decrypt the biometric data template. The biometric data template may refer to user biometric data (e.g., fingerprint image, iris image) input and stored by the user in the electronic device (100) prior to the authentication process, and may include biometric data input during biometric information registration and biometric data input during biometric authentication attempts.
[0048] An electronic device (100) according to one embodiment may provide a biometric data template acquired from a biometric module to an external device (200). The external device (200) according to one embodiment may convert the biometric data template into a new format, a remote authenticator template, and store the converted biometric data template in a second memory (220).
[0049] An external device (200) according to one embodiment may include a remote authentication daemon (Remote Authenticator Daemon, RA Daemon) at the level of a second application layer (211) or a second framework layer (213). The remote authentication daemon may store a remote authentication template in a second memory (220) to manage information and history included in a biometric data template received from an electronic device (100).
[0050] A remote authentication template according to one embodiment may include information (data) categorized into a plurality of attributes, such as device information of the electronic device (100) and / or information about a biometric data template received from the electronic device (100).
[0051] For example, the plurality of properties may include a Universally Unique Identifier (UUID), which is a unique value that distinguishes the electronic device (100), a DisplayName (e.g., S21 of user A) that allows the user to distinguish the electronic device (100) by the UUID, an Authenticator ID, which is a unique value that changes together whenever the biometric information of the electronic device (100) changes, and Enrollments, which indicates index information of the registered biometric data. The UUID is used to distinguish the electronic device (100) and may be provided in the form of DisplayName in a user-friendly manner in the electronic device (100) or the external device (200).
[0052] A remote authentication template according to one embodiment may include first data corresponding to a first attribute (UUID) that identifies an electronic device (100), second data corresponding to a second attribute (Authenticator ID) that indicates that a biometric data template registered in the electronic device (100) has been changed, and third data corresponding to a third attribute (Enrollments) that is index information of the registered biometric data template.
[0053] Authenticator Id is a unique value that changes whenever the biometric information (biometric data template) of the electronic device (100) changes. It is a value to deal with a situation where biometric data is changed regardless of the owner's intention, such as when someone else registers new biometric information (fingerprint or iris) without the owner's knowledge of the electronic device (100). In this case, the remote authentication daemon provided in the second application (211) or the second framework layer (213) according to one embodiment can verify the validity of the Authenticator Id to check whether there is a change in the biometric data (biometric data template) of the connected electronic device (100). For example, the Authenticator Id may be a value that changes whenever new biometric data is registered (it may not change if the biometric data is deleted), and may be set to 0 if there is no registered biometric data. The Authenticator Id may be a random combination of letters and / or numbers generated each time the biometric data is newly created or updated by a random number generation algorithm (e.g., Entropy-encoded random number).
[0054] Enrollments are values representing fingerprint (or iris) index information included in the biometric data template of the electronic device (100) and can be used when synchronizing biometric information (fingerprint or iris) of the electronic device (100) with an external device (200).
[0055] FIG. 2 is a flowchart of a system including an electronic device and an external device according to one embodiment.
[0056] Pairing is performed (201) between an electronic device (100) and an external device (200) according to one embodiment. In the embodiment according to Fig. 2, the embodiment is described based on a connection via Bluetooth, but a wireless connection can be established via other connection methods such as WiFi, ZIGBEE, USB, or IEE1394.
[0057] The above wireless connection can be performed automatically when the user runs an application requiring biometric authentication through an external device (200), or can be performed manually by the user's function settings.
[0058] An external device (200) according to one embodiment can check whether a remote authentication template previously stored in the external device (200) exists (203). The remote authentication template can include information (data) classified into a plurality of attributes, such as device information of the electronic device (100) and / or information about a biometric data template received from the electronic device (100).
[0059] If a remote authentication template does not exist within the external device (200) according to one embodiment, the electronic device (100) may perform a registration process by providing a biometric data template to the external device (200) (205). The registration process will be described later with reference to FIG. 3.
[0060] If a remote authentication template exists within an external device (200) according to one embodiment, the external device (200) may receive an application execution request from a user (207). The application receiving the execution request may include at least one function requiring user authentication. For example, the application may require fingerprint authentication for payment processing using a payment application (e.g., Samsung Pay).
[0061] According to one embodiment, an external device (200) can transmit a remote authentication template to an electronic device (100) (209). More specifically, when the external device (200) transmits information regarding the remote authentication template to the electronic device (100), the electronic device (100) can generate a remote authentication template based on the information regarding the remote authentication template. Specifically, the external device (200) can transmit the remote authentication template to the electronic device (100) in response to the execution request so that the electronic device (100) can verify the validity of the remote authentication template.
[0062] An electronic device (100) according to one embodiment can verify the validity of a remote authentication template (211). For example, the electronic device (100) can verify whether there is a change in biometric data within the electronic device (100) by comparing the Authenticator Id and / or Enrollments included in the remote authentication template with the biometric data template stored in the first memory (120, FIG. 1) of the electronic device (100).
[0063] According to one embodiment, the electronic device (100) may notify the external device (200) that biometric authentication is not possible if the remote authentication template is invalid (No of 213). At this time, the external device (200) may provide a message indicating that biometric authentication cannot be attempted through a UI such as a pop-up. In addition, if biometric authentication is not possible, the external device (200) according to one embodiment may provide a UI such as a pop-up that guides registration or update of the remote authentication template.
[0064] According to one embodiment, the electronic device (100) can perform biometric authentication (217) if the remote authentication template is valid (example of 213). At this time, the electronic device (100) can provide a UI that allows the user to input biometric data (fingerprint or iris).
[0065] According to one embodiment, the electronic device (100) can transmit a signal to the external device (200) to cause the application of the external device (200) to be executed when the user inputs biometric data and completes authentication by recognizing it through a biometric sensor. That is, the external device (200) without a biometric module can provide a user experience (UX) similar to that of the external device (200) performing biometric authentication by having the electronic device (100) perform biometric authentication.
[0066] According to one embodiment, an electronic device (100) may output a UI that allows a user to input biometric data if a remote authentication template is valid. While the UI is being output, the electronic device (100) may provide a command to an external device (200) that causes the UI to be output. For example, the external device (200) may receive the command and output a message saying, "Enter your fingerprint (iris) on the connected smartphone."
[0067] FIG. 3 is a signal flow diagram of a remote authentication template registration process of an external device according to one embodiment.
[0068] An electronic device (100) according to one embodiment may store a biometric data template (301). The biometric data template is biometric data that a user registers to perform biometric authentication on the electronic device (100). If the biometric data is fingerprint data, a biometric data template including an Authenticator Id, which is a value that changes whenever fingerprint information is changed during the fingerprint registration process, and Enrollments, which indicates an index of registered fingerprint information, may be stored on the electronic device (100). Here, the Authenticator Id may be composed of a 64-byte random number, and Enrollments may be generated as an int type array.
[0069] According to one embodiment, an electronic device (100) and an external device (200) can establish a wireless communication connection (303).
[0070] An external device (200) according to one embodiment may receive a user's registration request command (305) while being wirelessly connected to an electronic device (100). For example, a user may input a registration request command for storing a remote authentication template in the external device (200) through an interface provided by the external device (200).
[0071] According to one embodiment, an external device (200) may request a biometric data template, which is information for generating a remote authentication template, from an electronic device (100) (307). That is, the external device (200) may transmit a signal to the electronic device (100) to receive a biometric data template from the electronic device (100) in response to a user's registration request command, in order to generate a remote authentication template.
[0072] According to one embodiment, when an electronic device (100) receives a request from an external device (200), it can determine whether to provide a biometric data template. At this time, if provision of a biometric data template is permitted by the user's selection (309), the electronic device (100) can provide the biometric data template to the external device (200) (311).
[0073] An external device (200) according to one embodiment can convert and process a biometric data template to generate and store a remote authentication template (313).
[0074] An external device (200) according to one embodiment can complete the registration process by providing (315) a remote authentication template to an electronic device (100).
[0075] Through the above-described registration process, a remote authentication template is provided in the external device (200), and when linked with the electronic device (100), validity can be verified by comparing the remote authentication template with the biometric data template stored in the electronic device (100).
[0076] Figure 4 is a signal flow diagram of an authentication process of a system according to one embodiment.
[0077] The authentication process is a process of performing biometric authentication by checking whether the remote authentication template registered in the external device (200) matches the input biometric data input through the electronic device (100). The system according to one embodiment can ensure the up-to-dateness of the biometric data stored in the electronic device (100) by comparing the remote authentication template with the biometric data template stored in the electronic device (100) to confirm validity.
[0078] According to one embodiment, an electronic device (100) and an external device (200) can establish a wireless communication connection (401). In this embodiment, the wireless communication connection may be pairing for performing biometric authentication in the external device (200).
[0079] According to one embodiment, an external device (200) may receive a user authentication request command (403) while being wirelessly connected to an electronic device (100). For example, a user may input a command to perform a specific function (e.g., payment) on the external device (200) through an interface provided on the external device (200).
[0080] According to one embodiment, an external device (200) may request the electronic device (100) to verify the validity of a remote authentication template (405). At this time, the electronic device (100) may verify the validity of the remote authentication template (407).
[0081] Validation can be performed by comparing the Authenticator Id / Enrollments included in the remote authentication template received from the external device (200) with the Authenticator Id / Enrollments stored in the electronic device (100) to determine whether the registered biometric data currently held by the electronic device (100) is identical to the registered biometric data stored in the external device (200).
[0082] According to one embodiment, the electronic device (100) may provide a signal to the external device (200) to notify (411) that the authentication request is rejected if the remote authentication template is invalid (No of 409). This case may include a case where biometric data in the electronic device (100) is updated or a case where the user of the electronic device (100) and the user of the external device (200) do not match.
[0083] According to one embodiment, the electronic device (100) can perform biometric authentication (413) if the remote authentication template is valid (example of 409). Biometric authentication can be performed by a user inputting biometric data into the electronic device (100). According to one embodiment, the electronic device (100) can perform biometric authentication by checking whether the input biometric data matches the biometric data template.
[0084] According to one embodiment, the electronic device (100) may provide a signal to the external device (200) to notify that the biometric authentication has failed if the biometric authentication fails (NO of 415).
[0085] According to one embodiment, when biometric authentication is passed (example of 415), the electronic device (100) provides a signal to the external device (200) to notify that the biometric authentication is successful, and the external device (200) can execute a function of an application that the user wants to execute (419).
[0086] Meanwhile, an external device (200) according to one embodiment can implement an application shortcut by utilizing attribute information included in a remote authentication template. As described above, the remote authentication template includes a UUID, which is one of a plurality of attributes, and the UUID can include information that can distinguish a user of the electronic device (100). For example, when the electronic device (100) and the external device (200) are wirelessly connected and biometric authentication for unlocking is passed, a user-specific preference profile is acquired through the UUID, so that a specific application corresponding to the user-specific preference profile can be executed simultaneously with unlocking.
[0087] As described above, the remote authentication template includes a UUID that can distinguish the electronic device (100), enabling implementation of various scenarios in the relationship between a single external device and multiple electronic devices. Furthermore, various scenarios can also be implemented in the relationship between multiple external devices and a single electronic device. This will be described with reference to FIGS. 5 to 8.
[0088] FIG. 5 illustrates a system according to one embodiment when there are multiple electronic devices. FIG. 6 is a signal flow diagram of the operations performed in FIG. 5.
[0089] Referring to FIG. 5, an external device (200) can establish a wireless connection with a first electronic device (100-1) and a second electronic device (100-2). The external device (200) can store a first remote authentication template provided by the first electronic device (100-1) and a second remote authentication template provided by the second electronic device (100-2) together.
[0090] Referring to FIG. 6, an external device (200) according to one embodiment can establish a wireless communication connection with a first electronic device (100-1) (601-1) and establish a wireless communication connection with a second electronic device (100-2) (601-2).
[0091] According to one embodiment, an external device (200) may request validation from each of the first electronic device (100-1) and the second electronic device (100-2) while the first electronic device (100-1) and the second electronic device (100-2) are connected to each other via wireless communication (603-1, 603-2). The validation request may be performed simultaneously or at different times for the first electronic device (100-1) and the second electronic device (100-2). Each of the first electronic device (100-1) and the second electronic device (100-2) may verify the validity (605-1, 605-2). Specifically, the first electronic device (100-1) may receive a first remote authentication template from the external device (200) and verify the validity of the first remote authentication template. The second electronic device (100-2) can verify the validity of the second remote authentication template from the external device (200).
[0092] Validation can be performed by comparing the Authenticator Id / Enrollments included in the first and second remote authentication templates received from the external device (200) with the Authenticator Id / Enrollments stored in the electronic device (100) to determine whether the registered biometric data currently held by the first and second electronic devices (100-1, 100-2) is identical to the registered biometric data stored in the external device (200).
[0093] Each of the first electronic device (100-1) and the second electronic device (100-2) can transmit the validation result to the external device (200) (607-1, 607-2).
[0094] When the external device (200) according to one embodiment receives a validation result, it can transmit a biometric authentication request to at least one electronic device so that biometric authentication can proceed (609).
[0095] For example, if the external device (200) is only validated for the first remote authentication template among the first electronic device (100-1) and the second electronic device (100-2), it may transmit a signal requesting biometric authentication only to the first electronic device (100-1).
[0096] As another example, if the external device (200) recognizes the validity of the first remote authentication template and the second remote authentication template of both the first electronic device (100-1) and the second electronic device (100-2), it may transmit a signal requesting biometric authentication to the first electronic device (100-1) and the second electronic device (100-2). In this case, the external device (200) may provide the user with a UI that allows the user to select either the first electronic device (100-1) or the second electronic device (100-2) and perform biometric authentication.
[0097] The above-described embodiment prioritizes a valid electronic device among multiple electronic devices, or determines the electronic device used for biometric authentication based on user selection. In one embodiment, in addition to the remote authentication template attributes of UUID, DisplayName, Authenticator ID, and Enrollments, other attributes can be added to allow the user to perform various biometric authentications.
[0098] A remote authentication template according to one embodiment may further include attributes regarding the security level and authentication type (type) of an electronic device synchronized with an external device (200). The security level may be divided into multiple levels depending on the security importance of an application running on the external device (200). For example, the multiple levels may be divided into strong-weak, or into a first level (low), a second level (medium), and a third level (high). The authentication type may include strong level authentication types such as fingerprint authentication, face authentication, and iris authentication, and weak level authentication types such as passwords, PINs, and patterns.
[0099] For example, if an application running on an external device (200) includes a payment function and requires strong level authentication, the external device (200) can pop up a list of electronic devices that support fingerprint authentication, face authentication, and iris authentication and provide it to the user based on the authentication type, which is an attribute included in the remote authentication template. In this case, the validation process of operations 603 to 607 may also be additionally performed. This operation is impossible in the past because the server anonymously knows the client in the server-client structure, but the present invention is possible because the external device knows the information about the electronic device.
[0100] Figure 7 illustrates a system according to one embodiment when there are multiple external devices. Figure 8 is a signal flow diagram of the operations performed in Figure 7.
[0101] Referring to FIG. 7, the electronic device (100) can establish a wireless connection with a first external device (200-1) and a second external device (200-2). The first external device (200-1) and the second external device (200-2) can each store the same remote authentication template provided by the electronic device (100).
[0102] When the first external device (200-1) and the second external device (200-2) send authentication requests to the electronic device (100) at similar times, the electronic device (100) can perform biometric authentication for both the first external device (200-1) and the second external device (200-2). For example, when the electronic device (100) receives biometric authentication requests for the first external device (200-1) and the second external device (200-2), an input for selecting the first external device (200-1) and biometric authentication for the first external device (200-1) are possible, and an input for selecting the second external device (200-2) and biometric authentication for the second external device (200-2) are possible.
[0103] Referring to FIG. 7, an electronic device (100) according to one embodiment can establish a wireless communication connection with a first external device (200-1) (801-1) and establish a wireless communication connection with a second external device (200-2) (801-2).
[0104] According to one embodiment, an electronic device (100) can receive a biometric authentication request for a first external device (200-1) and a biometric authentication request for a second external device (200-2) while the first external device (200-1) and the second external device (200-2) are connected together via wireless communication (803-1, 803-2).
[0105] The electronic device (100) can verify the validity of a remote authentication template in response to a biometric authentication request (805).
[0106] The electronic device (100) can generate a biometric authentication push notification for at least one of the first external device (200-1) and the second external device (200-2). For example, when the electronic device (100) receives a biometric authentication request for the first external device (200-1) and the second external device (200-2), the electronic device (100) can provide the user with a UI that allows the user to receive an input for selecting the first external device (200-1) and / or an input for selecting the second external device (200-2).
[0107] The electronic device (100) can receive input biometric data from a user and perform biometric authentication (809).
[0108] Figure 9 illustrates a case where a failure occurs in a system according to one embodiment.
[0109] After a wireless communication connection is established between an electronic device (100) and an external device (200), there are cases where the wireless connection is disconnected before performing biometric authentication, or the biometric data template in the electronic device (100) is changed, resulting in invalidation. If the electronic device (100) and the external device (200) are in a 1:1 situation, the only solution is to retry the wireless connection or update the biometric data template. However, if the electronic device (100) and the external device (200) are in an N:1 situation, the above-described obstacle can be resolved by using the attribute information included in the remote authentication template.
[0110] For example, when a plurality of electronic devices (100-1 to 100-4) are in a state where a wireless connection is established with an external device (200), the electronic device (200) according to one embodiment can provide a UI according to FIG. 9.
[0111] (A) of FIG. 9 shows status information that the first electronic device (100-1) and the fourth electronic device (100-4) are validated and biometric authentication is possible, (B) of FIG. 9 shows status information that the third electronic device (100-3) is disconnected from wireless communication with the external device (200), and (C) of FIG. 9 shows status information that the biometric data template of the second electronic device (100-2) has been changed and re-registration is requested.
[0112] An external device (200) according to one embodiment can provide a UI including status information of a plurality of electronic devices (100-1 to 100-4), and a user can select an electronic device to input biometric data for biometric authentication by referring to the status information of the external device (200).
[0113] FIG. 10 illustrates a payment processing process in a system according to one embodiment, and FIG. 11 is a signal flow diagram of a payment system according to one embodiment.
[0114] For example, if the external device (200) is a desktop that does not have a fingerprint recognition module (or iris recognition module), the user inputs personal information (such as a mobile phone number) through the desktop to make a payment on the desktop, and the electronic device (100) receives an authentication request from the server, so that the user can complete the payment based on the entered personal information. In FIG. 10, process 1105 causes the server to generate a push message to the electronic device (100) so that the user can perform fingerprint authentication through the electronic device (100).
[0115] According to an embodiment according to the disclosure, an external device (200) can proceed with payment without having the server request authentication from the electronic device (100). For example, the external device (200) can proceed with biometric authentication for payment by requesting validation from the electronic device (100).
[0116] Referring to FIG. 11, an electronic device (100) and an external device (200) according to one embodiment can establish a wireless communication connection (1101).
[0117] According to one embodiment, an external device (200) may receive a first user input while being wirelessly connected to an electronic device (100). For example, the first user command may be a user input requesting payment processing from a payment application (e.g., Samsung Pay) on the external device (200). The external device (200) may process the payment request in response to the first user input (1103). The user may input a command to the external device (200) to perform a specific function (e.g., payment) on the external device (200) through an interface provided on the external device (200).
[0118] According to one embodiment, an external device (200) may request the electronic device (100) to verify the validity of a remote authentication template (1105). At this time, the electronic device (100) may verify the validity of the remote authentication template (1107), thereby confirming the up-to-dateness of the fingerprint data (or iris data) stored in the external device (200).
[0119] According to one embodiment, validation may be performed by comparing the Authenticator Id / Enrollments included in the remote authentication template received from the external device (200) with the Authenticator Id / Enrollments stored in the electronic device (100) to determine whether the registered fingerprint data currently held by the electronic device (100) is identical to the registered fingerprint data stored in the external device (200).
[0120] According to one embodiment, the electronic device (100) may provide a signal to the external device (200) to notify (1111) that the payment request has been rejected if the remote authentication template is invalid (No of 1109). This case may include a case where fingerprint data in the electronic device (100) is updated or a case where the user of the electronic device (100) and the user of the external device (200) do not match.
[0121] According to one embodiment, the electronic device (100) can perform biometric authentication (1113) if the remote authentication template is valid (example of 1109). Biometric authentication can be performed by a user inputting input biometric data, which is a second user input, into the electronic device (100). According to one embodiment, the electronic device (100) can perform biometric authentication by checking whether the input fingerprint data matches the biometric data template.
[0122] According to one embodiment, the electronic device (100) may provide a signal to the external device (200) to notify that the payment has failed (1117) if the biometric authentication fails (NO of 1115).
[0123] According to one embodiment, the electronic device (100) may provide a signal to the external device (200) to notify that payment has been completed when biometric authentication is passed (example of 1115) (1119, 1107 of FIG. 10).
[0124] Meanwhile, the biometric authentication process based on validation can also be applied when the external device (200) is a head-mounted display (HMD) such as a video-see-through (VST). In general, a VST device that does not have a fingerprint module and can only perform iris recognition may require a user other than the registered user to hand the VST device back to the registered user for authentication when the VST device is worn by another user. In this case, if the VST device and an electronic device are linked so that the registered user can perform biometric authentication (e.g., fingerprint authentication) through the electronic device, the cumbersome process of the other user having to hand the VST device over to the registered user can be omitted.
[0125] Figure 12 is a signal flow diagram when an external device is a VST device in a system according to one embodiment.
[0126] Referring to FIG. 12, an electronic device (100) and a VST device (210) according to one embodiment can establish a wireless communication connection (1201).
[0127] According to one embodiment, the VST device (210) can detect that a second user, other than the first user, is wearing the VST device (210) while being connected to the electronic device (100) via wireless communication (1203). Here, the first user is a user registered in the electronic device (100) and the VST device (210), and may correspond to a user who can pass biometric authentication in each device. The second user may correspond to a guest in the VST device (210) and a user who has not registered his / her biometric data in the VST device (210).
[0128] According to one embodiment, a VST device (210) may request the electronic device (100) to verify the validity of a remote authentication template (1205). At this time, the electronic device (100) may verify the validity of the remote authentication template (1207), thereby confirming the up-to-dateness of biometric data (fingerprint data or iris data) stored in the VST device (210).
[0129] According to one embodiment, validation may be performed by comparing the Authenticator Id / Enrollments included in the remote authentication template received from the VST device (210) with the Authenticator Id / Enrollments stored in the electronic device (100) to determine whether the registered biometric data currently held by the electronic device (100) is identical to the registered biometric data stored in the external device (200).
[0130] According to one embodiment, the electronic device (100) may provide a signal to the VST device (210) to notify (1211) that the authentication request is rejected if the remote authentication template is invalid (No of 1209). This case may include a case where biometric data in the electronic device (100) has been updated.
[0131] According to one embodiment, the electronic device (100) can perform biometric authentication (1213) if the remote authentication template is valid (example of 1209). Biometric authentication can be performed by a first user inputting biometric data (fingerprint data or iris data) into the electronic device (100). According to one embodiment, the electronic device (100) can perform biometric authentication by checking whether the input biometric data matches the biometric data template.
[0132] According to one embodiment, the electronic device (100) may provide a signal to the VST device (210) to notify that the authentication has failed (1217) if the biometric authentication fails (NO of 1215).
[0133] According to one embodiment, when biometric authentication is passed (example of 1215), the electronic device (100) may provide a signal to the VST device (210) to notify that authentication has been completed (1219). Then, the VST device (210) may provide content to the second user by executing VST content (1221).
[0134] FIG. 13 is a block diagram of an electronic device (1301) within a network environment (1300) according to various embodiments. Referring to FIG. 13 , in the network environment (1300), the electronic device (1301) may communicate with the electronic device (1302) via a first network (1398) (e.g., a short-range wireless communication network), or may communicate with at least one of the electronic device (1304) or the server (1308) via a second network (1399) (e.g., a long-range wireless communication network). In one embodiment, the electronic device (1301) may communicate with the electronic device (1304) via the server (1308). According to one embodiment, the electronic device (1301) may include a processor (1320), a memory (1330), an input module (1350), an audio output module (1355), a display module (1360), an audio module (1370), a sensor module (1376), an interface (1377), a connection terminal (1378), a haptic module (1379), a camera module (1380), a power management module (1388), a battery (1389), a communication module (1390), a subscriber identification module (1396), or an antenna module (1397). In some embodiments, the electronic device (1301) may omit at least one of these components (e.g., the connection terminal (1378)), or may have one or more other components added. In some embodiments, some of these components (e.g., sensor module (1376), camera module (1380), or antenna module (1397)) may be integrated into a single component (e.g., display module (1360)).
[0135] The processor (1320) may, for example, execute software (e.g., a program (1340)) to control at least one other component (e.g., a hardware or software component) of the electronic device (1301) connected to the processor (1320) and perform various data processing or operations. According to one embodiment, as at least a part of the data processing or operations, the processor (1320) may store commands or data received from other components (e.g., a sensor module (1376) or a communication module (1390)) in a volatile memory (1332), process the commands or data stored in the volatile memory (1332), and store result data in a non-volatile memory (1334). According to one embodiment, the processor (1320) may include a main processor (1321) (e.g., a central processing unit or an application processor) or an auxiliary processor (1323) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together with the main processor (1321). For example, when the electronic device (1301) includes the main processor (1321) and the auxiliary processor (1323), the auxiliary processor (1323) may be configured to use less power than the main processor (1321) or to be specialized for a given function. The auxiliary processor (1323) may be implemented separately from the main processor (1321) or as a part thereof.
[0136] The auxiliary processor (1323) may control at least a portion of functions or states associated with at least one component (e.g., the display module (1360), the sensor module (1376), or the communication module (1390)) of the electronic device (1301), for example, on behalf of the main processor (1321) while the main processor (1321) is in an inactive (e.g., sleep) state, or together with the main processor (1321) while the main processor (1321) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (1323) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (1380) or a communication module (1390)). In one embodiment, the auxiliary processor (1323) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (1301) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (1308)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.
[0137] The memory (1330) can store various data used by at least one component (e.g., the processor (1320) or the sensor module (1376)) of the electronic device (1301). The data can include, for example, software (e.g., the program (1340)) and input data or output data for commands related thereto. The memory (1330) can include volatile memory (1332) or non-volatile memory (1334).
[0138] The program (1340) may be stored as software in memory (1330) and may include, for example, an operating system (1342), middleware (1344), or an application (1346).
[0139] The input module (1350) can receive commands or data to be used in a component of the electronic device (1301) (e.g., a processor (1320)) from an external source (e.g., a user) of the electronic device (1301). The input module (1350) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).
[0140] The audio output module (1355) can output audio signals to the outside of the electronic device (1301). The audio output module (1355) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.
[0141] The display module (1360) can visually provide information to an external party (e.g., a user) of the electronic device (1301). The display module (1360) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (1360) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.
[0142] The audio module (1370) can convert sound into an electrical signal, or vice versa. According to one embodiment, the audio module (1370) can acquire sound through the input module (1350), output sound through the sound output module (1355), or an external electronic device (e.g., electronic device (1302)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (1301).
[0143] The sensor module (1376) can detect the operating status (e.g., power or temperature) of the electronic device (1301) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (1376) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0144] The interface (1377) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (1301) with an external electronic device (e.g., the electronic device (1302)). In one embodiment, the interface (1377) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
[0145] The connection terminal (1378) may include a connector through which the electronic device (1301) may be physically connected to an external electronic device (e.g., the electronic device (1302)). In one embodiment, the connection terminal (1378) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).
[0146] The haptic module (1379) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (1379) may include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
[0147] The camera module (1380) can capture still images and videos. In one embodiment, the camera module (1380) may include one or more lenses, image sensors, image signal processors, or flashes.
[0148] The power management module (1388) can manage the power supplied to the electronic device (1301). According to one embodiment, the power management module (1388) can be implemented as, for example, at least a part of a power management integrated circuit (PMIC).
[0149] A battery (1389) may power at least one component of the electronic device (1301). In one embodiment, the battery (1389) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.
[0150] The communication module (1390) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (1301) and an external electronic device (e.g., electronic device (1302), electronic device (1304), or server (1308)), and the performance of communication through the established communication channel. The communication module (1390) may operate independently from the processor (1320) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (1390) may include a wireless communication module (1392) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (1394) (e.g., a local area network (LAN) communication module, or a power line communication module). Any of these communication modules may communicate with an external electronic device (1304) via a first network (1398) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (1399) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a local area network or a wide area network)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (1392) may use subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (1396) to verify or authenticate the electronic device (1301) within a communication network such as the first network (1398) or the second network (1399).
[0151] The wireless communication module (1392) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency communications (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (1392) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (1392) may support various technologies for securing performance in high-frequency bands, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (1392) may support various requirements specified in the electronic device (1301), an external electronic device (e.g., the electronic device (1304)), or a network system (e.g., the second network (1399)). According to one embodiment, the wireless communication module (1392) may support a peak data rate (e.g., 20 Gbps or more) for eMBB implementation, a loss coverage (e.g., 164 dB or less) for mMTC implementation, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC implementation.
[0152] The antenna module (1397) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (1397) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (1397) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (1398) or the second network (1399), may be selected from the plurality of antennas by, for example, the communication module (1390). A signal or power may be transmitted or received between the communication module (1390) and an external electronic device via the at least one selected antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (1397).
[0153] According to various embodiments, the antenna module (1397) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high frequency band.
[0154] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).
[0155] According to one embodiment, commands or data may be transmitted or received between the electronic device (1301) and an external electronic device (1304) via a server (1308) connected to a second network (1399). Each of the external electronic devices (1302 or 1304) may be the same or a different type of device as the electronic device (1301). According to one embodiment, all or part of the operations executed in the electronic device (1301) may be executed in one or more of the external electronic devices (1302, 1304, or 1308). For example, when the electronic device (1301) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (1301) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (1301). The electronic device (1301) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (1301) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (1304) may include an Internet of Things (IoT) device. The server (1308) may be an intelligent server utilizing machine learning and / or a neural network.According to one embodiment, an external electronic device (1304) or server (1308) may be included within the second network (1399). The electronic device (1301) may be applied to intelligent services (e.g., smart homes, smart cities, smart cars, or healthcare) based on 5G communication technology and IoT-related technology.
[0156] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.
[0157] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.
[0158] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0159] Various embodiments of the present document may be implemented as software (e.g., a program (1340)) including one or more instructions stored in a storage medium (e.g., an internal memory (1336) or an external memory (1338)) readable by a machine (e.g., an electronic device (1301)). For example, a processor (e.g., a processor (1320)) of the machine (e.g., an electronic device (1301)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.
[0160] According to one embodiment, the method according to various embodiments disclosed in this document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0161] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
[0162] According to one embodiment, a system includes an electronic device having a biometric module and an external device connected to the electronic device, wherein the electronic device provides a biometric data template acquired from the biometric module to the external device while the electronic device and the external device are connected via wireless communication, the external device stores a remote authentication template in which a plurality of attributes are assigned to the biometric data template, the external device transmits the remote authentication template to the electronic device in response to a user's request for execution of an application, the electronic device verifies the validity of the remote authentication template based on a comparison between the remote authentication template and the biometric data template, and the external device requests biometric authentication from the electronic device based on the validity verified from the electronic device, and executes the application based on a result of the biometric authentication of the electronic device.
[0163] In a system according to one embodiment, the external device may generate a signal that causes the electronic device to perform biometric authentication if the remote authentication template is valid. In response to the signal, the electronic device according to one embodiment may output a user interface that receives input biometric data from a user.
[0164] In a system according to one embodiment, the external device may notify that the biometric authentication is not possible if the remote authentication template is invalid.
[0165] In a system according to one embodiment, the remote authentication template may include first data corresponding to a first attribute that distinguishes the electronic device, second data corresponding to a second attribute indicating that a biometric data template registered in the electronic device has been changed, and third data corresponding to a third attribute that is an index of the registered biometric data template.
[0166] In a system according to one embodiment, the electronic device can receive second data and third data of the remote authentication template, and verify validity based on a comparison of the biometric data template with each of the second data and the third data.
[0167] In a system according to one embodiment, the external device may be connected to a first electronic device having a first biometric data template stored therein and a second electronic device having a second biometric data template stored therein by wireless communication, and in response to a user's application execution request, transmit a first remote authentication template corresponding to the first biometric data template and a second remote authentication template corresponding to the second biometric data template to each of the first electronic device and the second electronic device, receive a validation result of each of the first electronic device and the second electronic device, and transmit a biometric authentication request to at least one of the first electronic device or the second electronic device so that biometric authentication is performed based on each validation result.
[0168] In a system according to one embodiment, when a first external device having a first remote authentication template stored therein and a second external device having a second remote authentication template stored therein are connected by wireless communication, the electronic device may receive a biometric authentication request from the first external device and the second external device, and output a biometric authentication push notification for at least one of the first external device and the second external device based on the validity of the first remote authentication template and the second remote authentication template.
[0169] In a system according to one embodiment, the remote authentication template may further include fourth data corresponding to a fourth attribute indicating the type of authentication type. In one embodiment, the external device, while wirelessly connected to the first electronic device and the second electronic device, may transmit a biometric authentication request to either the first electronic device or the second electronic device based on the security level of the application.
[0170] In a system according to one embodiment, the external device, in response to a user input requesting payment while a payment application is running, requests validation of the electronic device, and transmits a biometric authentication request signal requesting biometric authentication to the electronic device based on the validated validity from the electronic device, and the electronic device according to one embodiment can output a user interface for biometric authentication in response to the biometric authentication request signal.
[0171] In a system according to one embodiment, the electronic device may include a memory that stores a first biometric data template of a first user. In one embodiment, the external device may include a Video-See-Through (VST) device that stores a first remote authentication template corresponding to the first biometric data template. In response to detecting that a second user other than the first user is wearing the VST device while a VST application is running, the external device may request the electronic device to verify validity, and transmit a biometric authentication request signal from the electronic device to request biometric authentication to the electronic device based on the verified validity. In one embodiment, the electronic device may output a user interface for biometric authentication in response to the biometric authentication request signal.
[0172] An external device according to one embodiment may include a processor and a memory storing at least one instruction executable by the processor. The at least one instruction may cause the external device to: receive a biometric data template acquired from the biometric module from the electronic device, store a remote authentication template in which a plurality of attributes are assigned to the biometric data template, transmit the remote authentication template to the electronic device in response to a user's request to execute an application, receive a validation result of the remote authentication template from the electronic device based on a comparison between the remote authentication template and the biometric data template, request biometric authentication from the electronic device based on the validity, and execute the application based on the biometric authentication result of the electronic device.
[0173] At least one instruction according to one embodiment may cause the electronic device to generate a signal to perform biometric authentication if the remote authentication template is valid.
[0174] At least one instruction according to one embodiment may cause a signal to be generated notifying that the biometric authentication is not possible if the remote authentication template is invalid.
[0175] A remote authentication template according to one embodiment may include first data corresponding to a first attribute that distinguishes the electronic device, second data corresponding to a second attribute indicating that a biometric data template registered in the electronic device has been changed, and third data corresponding to a third attribute that is an index of the registered biometric data template.
[0176] At least one instruction according to one embodiment may be configured to receive second data and third data of the remote authentication template and to verify validity based on a comparison of the biometric data template with each of the second data and the third data.
[0177] According to one embodiment, at least one instruction may be configured to: in a state where a first electronic device having a first biometric data template stored therein and a second electronic device having a second biometric data template stored therein are wirelessly connected to each other; in response to a user's request for application execution, transmit a first remote authentication template corresponding to the first biometric data template and a second remote authentication template corresponding to the second biometric data template to each of the first electronic device and the second electronic device; receive a validation result of each of the first electronic device and the second electronic device; and transmit a biometric authentication request to at least one of the first electronic device or the second electronic device so that biometric authentication is performed based on the validity of each.
[0178] In one embodiment, an external device includes a first external device and a second external device, and at least one instruction according to one embodiment may control the electronic device to transmit a biometric authentication request to the electronic device, and output a biometric authentication push notification for at least one of the first external device and the second external device based on the validity of the first remote authentication template and the second remote authentication template, while the electronic device is wirelessly connected to the first external device having a first remote authentication template stored therein and the second external device having a second remote authentication template stored therein.
[0179] A remote authentication template according to one embodiment may further include fourth data corresponding to a fourth attribute indicating the type of authentication type. At least one instruction according to one embodiment may transmit a biometric authentication request to either the first electronic device or the second electronic device based on the security level of the application while the first electronic device and the second electronic device are connected to each other by wireless communication.
[0180] In one embodiment, the at least one instruction may cause, while the payment application is running, in response to a user input requesting payment, to request validation from the electronic device, and to transmit a biometric authentication request signal to the electronic device, requesting biometric authentication from the electronic device based on the validated validity.
[0181] According to one embodiment, a recording medium may be a non-transitory computer-readable recording medium storing instructions that, when executed by at least one processor, cause the at least one processor to perform set operations. The operations include receiving a biometric data template acquired from the biometric module from the electronic device, storing a remote authentication template in which a plurality of attributes are assigned to the biometric data template, transmitting the remote authentication template to the electronic device in response to a user's request for execution of an application, receiving a result of a validation of the remote authentication template based on a comparison between the remote authentication template and the biometric data template from the electronic device, requesting biometric authentication to the electronic device based on the validity, and executing the application based on the result of the biometric authentication of the electronic device.
Claims
1. A system including an electronic device equipped with a biometric recognition module and an external device connected to the electronic device, While the above electronic device and the above external device are connected via wireless communication: The electronic device provides a biometric data template obtained from the biometric module to the external device; The external device stores a remote authentication template in which a plurality of attributes are assigned to the biometric data template; The external device transmits the remote authentication template to the electronic device in response to a user's request to execute an application; The electronic device verifies the validity of the remote authentication template based on a comparison between the remote authentication template and the biometric data template; and A system in which the external device requests biometric authentication from the electronic device based on the verified validity from the electronic device and executes the application based on the biometric authentication result of the electronic device.
2. In paragraph 1, The above external device is, If the above remote authentication template is valid, generate a signal causing the electronic device to perform biometric authentication; The above electronic device, A system that outputs a user interface that receives input biometric data from a user in response to the above signal.
3. In paragraph 2, The above external device is, A system that notifies that the biometric authentication is not possible if the above remote authentication template is invalid.
4. In paragraph 1, The above remote authentication template is, A system comprising first data corresponding to a first attribute that distinguishes the electronic device, second data corresponding to a second attribute indicating that a biometric data template registered in the electronic device has been changed, and third data corresponding to a third attribute that is an index of the registered biometric data template.
5. In paragraph 4, The above electronic device, Receive the second data and the third data of the above remote authentication template, A system for verifying validity based on comparing the above biometric data template with each of the second data and the third data.
6. In paragraph 1, The above external device is, In a state where a first electronic device having a first biometric data template stored therein and a second electronic device having a second biometric data template stored therein are wirelessly connected to each other: In response to a user's request to execute an application, transmit a first remote authentication template corresponding to the first biometric data template and a second remote authentication template corresponding to the second biometric data template to each of the first electronic device and the second electronic device; Receiving validation results of each of the first electronic device and the second electronic device; A system for transmitting a biometric authentication request to at least one of the first electronic device or the second electronic device so that biometric authentication is performed based on each validity.
7. In paragraph 1, While being wirelessly connected to a first external device having a first remote authentication template stored and a second external device having a second remote authentication template stored: The above electronic device, Receiving a biometric authentication request from the first external device and the second external device, A system that outputs a biometric authentication push notification for at least one of the first external device and the second external device based on the validity of the first remote authentication template and the second remote authentication template.
8. In paragraph 4, The above remote authentication template is, Further including fourth data corresponding to the fourth attribute indicating the type of authentication type, The above external device is, While connected wirelessly to the first electronic device and the second electronic device: A system that transmits a biometric authentication request to either the first electronic device or the second electronic device based on the security level of the application.
9. In paragraph 1, The above external device is, While the payment application is running: In response to user input requesting payment, request validation from said electronic device; Transmitting a biometric authentication request signal requesting biometric authentication to the electronic device based on the verified validity from the electronic device, The above electronic device, A system that outputs a user interface for biometric authentication in response to the above biometric authentication request signal.
10. In paragraph 1, The above electronic device, Contains a memory storing a first biometric data template of a first user, The above external device is, Including a VST (Video-See-Through) device having a first remote authentication template corresponding to the first biometric data template stored therein, While the VST application is running: In response to detecting that a second user other than the first user is equipped with a VST device, requesting validation of the electronic device; Transmitting a biometric authentication request signal requesting biometric authentication to the electronic device based on the verified validity from the electronic device, The above electronic device, A system that outputs a user interface for biometric authentication in response to the above biometric authentication request signal.
11. In an electronic device equipped with a biometric recognition module and an external device capable of wireless communication, processor; and a memory storing at least one instruction executable by the processor; At least one of the above instructions causes the external device to: Receiving a biometric data template obtained from the biometric module from the electronic device; Store a remote authentication template having multiple attributes assigned to the above biometric data template; In response to a user's request to execute an application, transmit the remote authentication template to the electronic device; Receiving a validation result of the remote authentication template based on a comparison between the remote authentication template and the biometric data template from the electronic device; and An external device that requests biometric authentication from the electronic device based on the validity thereof and executes the application based on the biometric authentication result of the electronic device.
12. In paragraph 11, At least one of the above instructions, An external device that generates a signal causing the electronic device to perform biometric authentication if the above remote authentication template is valid.
13. In paragraph 12, At least one of the above instructions, An external device that generates a signal notifying that said biometric authentication is not possible if said remote authentication template is invalid.
14. In paragraph 11, The above remote authentication template is, An external device comprising first data corresponding to a first attribute that distinguishes the electronic device, second data corresponding to a second attribute indicating that a biometric data template registered in the electronic device has been changed, and third data corresponding to a third attribute that is an index of the registered biometric data template.
15. In paragraph 14, At least one of the above instructions, Receive the second data and the third data of the above remote authentication template, An external device that verifies validity based on comparing the above biometric data template with each of the second data and the third data.
Citation Information
Patent Citations
Lock device and method using iris image for high security
KR101182922B1
Mobile Fingerprint Input Apparatus, Entrance Control System Comprising the Fingerprint Input Apparatus and Control Method thereof
KR102087440B1
Method and system for user authentication via an authentication factor integrating fingerprints and personal identification numbers
US20230262054A1
Wearable device for authenticating payment transactions
WO2019209435A1
KR20220066420A