Electronic device and user authentication method using same
The electronic device and method enhance user authentication security and accuracy by using personalized data and statistical analysis to generate activity-based query sentences, ensuring only the user can correctly answer, thus improving authentication processes.
Patent Information
- Application Number
- PCT/KR2024/019739
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-22
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-12
AI Technical Summary
Existing user authentication methods lack sufficient security and accuracy, particularly in scenarios where personal information is accessed through electronic devices connected to external servers.
An electronic device and method that utilize personalized data and statistical data to generate query sentences for user authentication, enhancing security and accuracy by confirming user responses to activity-based queries.
The proposed solution improves user authentication security and accuracy by leveraging personalized data and statistical analysis to create tailored queries that only the user can accurately answer.
Smart Images

Figure KR2024019739_12062025_PF_FP_ABST
Abstract
Description
Electronic devices and user authentication methods using the same
[0001] An embodiment of the present disclosure relates to an electronic device and a user authentication method using the same.
[0002] With the recent advancement of digital technology, various types of electronic devices (user devices) capable of communication and personal information processing (e.g., mobile terminals, personal digital assistants (PDAs), electronic organizers, smartphones, tablets, personal computers (PCs), etc.) are being released. Electronic devices can communicate with external electronic devices (e.g., servers, cloud servers) using networks. Along with the advancement of electronic devices, demand for cloud computing is increasing. Through cloud computing, electronic devices can store user-related information on servers on the Internet (e.g., cloud servers), and the stored information can be accessed and used anytime, anywhere using the electronic device.
[0003] The above information may be provided as background art to aid in understanding the present disclosure. No claim or determination is made as to whether any of the above-described matters constitute prior art related to the present disclosure.
[0004] When using payment-related programs (e.g., shopping-related application programs, financial-related application programs), the electronic device may perform a user authentication procedure and store authentication information related to authentication and / or purchase history information on an external electronic device (e.g., server, cloud server).
[0005] In one embodiment, user authentication is becoming essential when using various services, and recently, two-factor authentication is being utilized to increase security related to personal information.
[0006] In one embodiment, when an authentication request is made to an individual (e.g., a user), the electronic device provides the user with a query sentence generated based on the individual's personal data to enhance security during the authentication process. The electronic device can determine whether user authentication is complete based on the user's response to the query sentence.
[0007] The technical tasks to be achieved in this document are not limited to the technical tasks mentioned above, and other technical tasks not mentioned can be clearly understood by a person having ordinary knowledge in the technical field to which this document belongs from the description below.
[0008] According to one embodiment, an electronic device includes a processor and a memory storing instructions, wherein the instructions, when executed by the processor, cause the electronic device to receive an authentication request for a user, and, in response to the authentication request, receive a plurality of personalized data corresponding to the user from an external electronic device. For example, the plurality of personalized data may include information related to an activity of the user and information on a time at which the activity of the user occurred. The instructions, when executed by the processor, cause the electronic device to determine a statistical distance between the plurality of personalized data and the statistical data based on the received plurality of personalized data and statistical data stored in the memory, select one personalized data from among the plurality of personalized data based on the determined statistical distance, and generate a first query for user authentication based on the selected personalized data.
[0009] According to one embodiment, a method for authenticating a user of an electronic device may include an operation of receiving an authentication request for a user, an operation of receiving a plurality of personalized data corresponding to the user from an external electronic device in response to the authentication request, an operation of confirming a statistical distance between the plurality of personalized data and the statistical data based on the received plurality of personalized data and statistical data stored in the memory, an operation of selecting one personalized data from among the plurality of personalized data based on the confirmed statistical distance, and an operation of generating a first query for user authentication based on the selected personalized data. The plurality of personalized data may include information related to an activity of the user and information on a time at which the activity of the user occurred.
[0010] According to one embodiment, a non-transitory computer-readable storage medium (or a computer program product) storing one or more programs for executing a user authentication method of an electronic device may be described. According to one embodiment, the one or more programs may include instructions that, when executed by a processor of the electronic device, perform the following operations: receiving an authentication request for a user; receiving, in response to the authentication request, a plurality of personalized data corresponding to the user from an external electronic device; determining a statistical distance between the plurality of personalized data and the statistical data based on the received plurality of personalized data and statistical data stored in the memory; selecting one personalized data from among the plurality of personalized data based on the determined statistical distance; and generating a first query for user authentication based on the selected personalized data. The plurality of personalized data may include information related to an activity of the user and information on the time at which the activity of the user occurred.
[0011] According to one embodiment, an electronic device and an external electronic device may be provided that perform additional user authentication based on personalized data stored in the electronic device and statistical data stored in an external electronic device (e.g., a server).
[0012] According to one embodiment, an electronic device may store multiple pieces of personalized data, including information related to a user's activities and information about the time at which the user's activities occurred. According to one embodiment, the electronic device may generate a first query (e.g., a query sentence related to the user's personal activities) for user authentication based on the multiple pieces of personalized data and statistical data, and may perform additional user authentication using the first query. According to one embodiment, by performing additional user authentication, the security of user authentication may be enhanced. By verifying the user's response to the first query generated based on the user's activities, the accuracy of user authentication may be enhanced.
[0013] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.
[0014] In connection with the description of the drawings, the same or similar reference numerals may be used for the same or similar components.
[0015] FIG. 1 is a block diagram of an electronic device within a network environment according to one embodiment of the present disclosure.
[0016] FIG. 2 is a diagram illustrating an embodiment in which an electronic device performs communication with a server in relation to user authentication according to one embodiment of the present disclosure.
[0017] FIG. 3 is a block diagram of an electronic device and a server according to one embodiment of the present disclosure.
[0018] FIG. 4A is a first flowchart illustrating a method of determining a statistical distance based on personal data and statistical data according to one embodiment of the present disclosure, generating a query based on the determined statistical distance, and performing user authentication using the generated query.
[0019] FIG. 4b is a second flowchart illustrating a method of determining a statistical distance based on personal data and statistical data according to one embodiment of the present disclosure, generating a query based on the determined statistical distance, and performing user authentication using the generated query.
[0020] FIG. 5 is a diagram illustrating an embodiment in which a statistical distance is determined based on personal data and statistical data according to one embodiment of the present disclosure.
[0021] FIG. 6 is a diagram illustrating operations performed in each of an electronic device and a server when performing user authentication according to one embodiment of the present disclosure.
[0022] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings so that those skilled in the art can easily implement the present disclosure. However, the present disclosure may be implemented in various different forms and is not limited to the embodiments described herein. In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Furthermore, in the drawings and related descriptions, descriptions of well-known functions and configurations may be omitted for clarity and conciseness.
[0023] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to various embodiments. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with the electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of the electronic device (104) or the server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).
[0024] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor)) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.
[0025] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, in the electronic device (101) itself where artificial intelligence is performed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.
[0026] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).
[0027] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).
[0028] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).
[0029] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.
[0030] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.
[0031] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).
[0032] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0033] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
[0034] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).
[0035] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
[0036] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.
[0037] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least a part of a power management integrated circuit (PMIC).
[0038] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.
[0039] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).
[0040] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.
[0041] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas by, for example, the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).
[0042] In one embodiment, the antenna module (197) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.
[0043] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).
[0044] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.
[0045] FIG. 2 is a diagram illustrating an embodiment in which an electronic device performs communication with a server in relation to user authentication according to one embodiment of the present disclosure.
[0046] The electronic device (210) of FIG. 2 may be at least partially similar to the electronic device (101) of FIG. 1, or may further include other embodiments of the electronic device (101). The server (310) of FIG. 2 may be at least partially similar to the server (108) of FIG. 1, or may further include other embodiments of the server (108). In one embodiment, the electronic device (210) and the server (310) may include at least partially similar components to the electronic device (101) of FIG. 1.
[0047] In one embodiment, the electronic device (210) may be operatively connected to a server (310) via a communication network and may transmit and receive data therebetween. For example, the electronic device (210) may transmit commands to at least partially control the server (310), and the server (312) may also transmit commands to at least partially control the electronic device (210).
[0048] Referring to FIG. 2, when a situation requiring user authentication is identified, the electronic device (210) can perform a user authentication function (211) based on an authentication-related application. For example, the electronic device (210) can obtain data related to user authentication from a server (310) and perform the user authentication function (211) based on the obtained data. The electronic device (210) can display a user interface according to the user authentication function (211) through a display (e.g., the display module (160) of FIG. 1).
[0049] According to one embodiment, the electronic device (210) may perform a user authentication function (211) when performing a payment-related function. For example, when performing the user authentication function (211), the electronic device (210) may receive authentication-related information and / or information related to the user's activity from the server (310). The electronic device (210) may perform a first user authentication function based on the authentication-related information, and additionally, may perform a second user authentication function using information related to the user's activity. For example, the electronic device (210) may provide the user with a first query generated based on information related to the user's activity, and may confirm the first user's answer to the first query. The electronic device (210) may enhance the security of user authentication by performing the second user authentication function using the first query. By confirming the user's answer to the first query generated based on the user's activity, the accuracy of user authentication may be enhanced.
[0050] FIG. 3 is a block diagram of an electronic device and a server according to one embodiment of the present disclosure.
[0051] The electronic device (210) of FIG. 3 may be at least partially similar to the electronic device (101) of FIG. 1, or may further include other embodiments of the electronic device (101). The server (310) of FIG. 3 may be at least partially similar to the server (108) of FIG. 1, or may further include other embodiments of the server (108). In one embodiment, the electronic device (210) and the server (310) may include at least partially similar components to the electronic device (101) of FIG. 1.
[0052] Referring to FIG. 3, the electronic device (210) may include a processor (220) (e.g., the processor (120) of FIG. 1), a memory (230) (e.g., the memory (130) of FIG. 1), and / or a communication circuit (290) (e.g., the communication module (190) of FIG. 1). Personalized data (231) corresponding to a user may be stored in the memory (230) of the electronic device (210). Referring to FIG. 3, the server (310) may include a processor (320), a memory (330), and / or a communication circuit (390). Statistical data (331) related to a plurality of users may be stored in the memory (330) of the server (310). For example, the electronic device (210) and the server (312) may include at least some similar components. According to one embodiment, the electronic device (210) and the server (310) may be operatively connected to each other through a communication network and may transmit and receive data between each other.
[0053] According to one embodiment, the processor (220) of the electronic device (210) may execute a program (e.g., program (140) of FIG. 1) stored in the memory (230) to control at least one other component (e.g., hardware or software component) and perform various data processing or operations. According to one embodiment, the processor (220) may be operatively, functionally, and / or electrically connected to the memory (230) and / or the communication circuit (290).
[0054] According to one embodiment, the memory (230) of the electronic device (210) may include a plurality of personalized data (231) related to the user of the electronic device (210). For example, the personalized data (231) may include information related to the user's activity and information on the time at which the user's activity occurred. For example, the information related to the user's activity may include at least one of purchase history information related to the purchase of goods, information related to the user (e.g., the user's personal information such as age, gender, occupation, address, height, and / or weight), activity information related to the installation program, and location-related information related to the purchase of goods. The purchase history information related to the purchase of goods may include at least one of the purchase time, purchase date, purchase time, purchase location, purchased goods, purchase price, category information of the purchased goods, image information of the purchased goods, discount information, and / or purchase method. The information related to the user may include personal information (e.g., age, gender, occupation, address) previously stored in the memory (230) by the user. Activity information related to the installation program may include purchase-related information (e.g., items purchased by executing the installation program, purchase time, purchase location, and / or purchase price) according to the execution of the installation program when purchasing an item using the installation program. Location-related information related to the purchase of an item may include location information where the item was purchased when the user executes a specific program to purchase an item. According to one embodiment, the electronic device (210) may store various information related to the user in the memory (230). When performing a user authentication function, the electronic device (210) may generate at least one query sentence based on personalized data (231) stored in the memory (230), and may perform user authentication using the generated at least one query sentence.For example, at least one query sentence may include a query sentence customized to the user in relation to the user's activity. The at least one query sentence may include a question related to the user's personal activity that only the user can accurately answer. The at least one query sentence may be generated based on information related to the user's activity (e.g., purchase history information, information related to the user, activity information related to the installed program, and / or location-related information) and information about the time at which the user's activity occurred. The at least one query sentence may be generated based on information actually experienced by the user using the electronic device (201) and information directly input by the user. For example, the correct answer to the at least one query sentence may be determined based on information related to the user's activity and information about the time at which the user's activity occurred, and may be stored in the memory (230). According to one embodiment, the processor (220) may request an answer to the at least one query sentence from the user, and may compare or analyze an answer input by the user with an answer stored in the memory (230). The processor (120) can determine whether the answer entered by the user is correct or incorrect.
[0055] According to one embodiment, the electronic device (210) may be connected to a server (310) based on a communication circuit (290) and may transmit and receive data with the server (312). For example, the processor (220) of the electronic device (210) may, in response to a request from the server (310), transmit personalized data (231) related to the user to the server (310). As another example, the processor (220) of the electronic device (210) may request statistical data stored in the memory (330) of the server (310) and obtain the statistical data from the server (310).
[0056] Referring to FIG. 3, the server (310) may include a processor (320), a memory (330), and / or a communication circuit (390). For example, if the electronic device (210) is a first electronic device, the server (310) may be interpreted as a second electronic device or an external electronic device. The communication circuit (290) of the electronic device (210) may be communicatively connected to the communication circuit (390) of the server (310), and data may be transmitted and received between the electronic device (210) and the server (310).
[0057] In one embodiment, the processor (320) of the server (310) may execute a program stored in the memory (330) to control at least one other component (e.g., hardware or software component) and perform various data processing or operations. In one embodiment, the processor (320) may be operatively, functionally, and / or electrically connected to the memory (330) and / or the communication circuit (390).
[0058] According to one embodiment, the memory (330) of the server (310) may include statistical data (331) related to a plurality of other users. For example, the statistical data (331) may include information related to activities of other users (e.g., aggregated data) and information about the time at which activities of other users occurred (e.g., aggregated time data). For example, the information related to activities of other users may include at least one of purchase history information related to purchases of goods, information related to a plurality of other users, activity information related to installation programs, and location-related information related to purchases of goods (e.g., purchases of goods by other users), and may include an average value for each piece of information.
[0059] Purchase history information related to the purchase of an item may include at least one of the purchase time, purchase date, purchase time, purchase location, purchased item, purchase price, category information of the purchased item, image information of the purchased item, discount information, and / or purchase method, which correspond to other users. For example, the purchase history information may include an average value of purchase history information for multiple other users. Information related to multiple other users may include personal information corresponding to the other users (e.g., age, gender, occupation, address of the other users). Activity information related to an installation program may include purchase-related information resulting from the execution of the installation program when an item is purchased using the installation program (e.g., items purchased by another user by executing the installation program, purchase time, purchase location, and / or purchase price). Location-related information related to the purchase of an item may include information on the location where the item was purchased when another user executes a specific program installed on another electronic device to purchase the item. According to one embodiment, the server (310) can manage various information related to multiple different users by organizing it into statistics, and can store statistical data (e.g., statistical data (331) of FIG. 3) calculated as an average value in the memory (330). The server (310) can obtain various information corresponding to multiple different users, respectively, from other electronic devices, and can organize and manage the various information obtained by organizing it into statistics. For example, the server (310) can classify purchase history information related to product purchases based on age, gender, occupation, address, height, and / or weight of multiple users, and can generate statistical data (331) based on the classified information and store the statistical data in the memory (330).
[0060] According to one embodiment, the server (310) may compare or analyze first purchase information about a user of the electronic device (201) and second purchase information about a plurality of other users of the same gender as the user. The server (310) may compare the first purchase information and the second purchase information to identify personalized data corresponding to the user, and may generate a first query for user authentication based on the personalized data.
[0061] According to one embodiment, the server (310) may be connected to the electronic device (210) based on the communication circuit (390) and may transmit and receive data with the electronic device (210). For example, when a user authentication request related to the user of the electronic device (210) is confirmed, the server (310) may request personalized data (231) related to the user from the electronic device (210) and obtain the personalized data (231) from the electronic device (210).
[0062] According to one embodiment, when a user authentication request is received from an electronic device (210), the server (310) may determine a statistical distance based on personalized data (231) obtained from the electronic device (210) and statistical data (331) stored in the memory (330). For example, the statistical distance may include an indicator indicating a similarity between personalized data (231) and statistical data (331). For example, a close statistical distance may mean that the similarity between personalized data (231) and statistical data (331) is relatively high. As another example, a far statistical distance may mean that the similarity between personalized data (231) and statistical data (331) is relatively low.
[0063] In one embodiment, personalized data (231) may be at least partially included in statistical data (331). For example, some portions of personalized data (231) may match statistical data (331), while other portions of personalized data (231) may not match statistical data (331). A discrepancy between personalized data (231) and statistical data (331) may indicate user-specific data.
[0064] According to one embodiment, the processor (320) of the server (310) may select one piece of information (e.g., data having a relatively long statistical distance, data having a relatively short statistical distance) from among various pieces of information included in the personalized data (231) based on the verified statistical distance, and may generate a first query based on the selected piece of information. For example, the first query may include a question corresponding to the user, a question from which only the user can infer an accurate answer.
[0065] According to one embodiment, an electronic device (310) may include a processor (320) and a memory (330) storing instructions. The instructions, when executed by the processor (320), may be configured to cause the electronic device (310) to receive an authentication request for a user, receive a plurality of personalized data (231) corresponding to the user from an external electronic device (210) in response to the authentication request, and, based on the received plurality of personalized data (231) and statistical data (331) stored in the memory (330), determine a statistical distance between the plurality of personalized data (231) and the statistical data (331), select one personalized data among the plurality of personalized data (231) based on the determined statistical distance, and generate a first query for user authentication based on the selected personalized data. The plurality of personalized data (231) may include information related to an activity of the user and information on a time when the activity of the user occurred.
[0066] According to one embodiment, the instructions, when executed by the processor (320), may be configured to cause the electronic device (310) to transmit the generated first query to the external electronic device (210), receive a first user answer to the first query from the external electronic device (210), determine whether the first user answer is correct based on the selected personalized data, and complete an authentication request for the user if the first user answer is correct.
[0067] According to one embodiment, the instructions, when executed by the processor (320), may be configured to cause the electronic device (310) to determine second time information different from the first time information corresponding to the selected personalized data, if the first user answer is not correct, select other personalized data based on the determined second time information, and generate a second query based on the selected other personalized data.
[0068] According to one embodiment, the first time information may be determined to be a point in the past relatively to the second time information.
[0069] According to one embodiment, the second time information may be determined to be a point in time relatively in the past compared to the first time information.
[0070] According to one embodiment, the information related to the user's activity may include at least one of purchase history information related to the purchase of goods, information related to the user, activity information related to the installation program, or location-related information related to the purchase of goods.
[0071] According to one embodiment, the purchase history information may include at least one of purchase time, purchase date, purchase time, purchase location, purchased item, purchase price, category information of purchased item, image information of purchased item, discount information, or purchase method.
[0072] According to one embodiment, the activity information related to the installation program may include at least one of application information with which account information is shared, content information in an application with which account information is shared, photo information, music information, information registered as a favorite, or location information.
[0073] According to one embodiment, the instructions, when executed by the processor (320), may be configured to cause the electronic device (310) to reflect the personalized data and the statistical data (331) in a similarity search method and determine the statistical distance based on the similarity search method.
[0074] According to one embodiment, the instructions, when executed by the processor (320), may be configured to cause the electronic device (310) to generate an authentication request for the user from the external electronic device in response to a situation in which lock screen authentication fails, user authentication based on an audio signal fails, or a purchase request exceeding a set purchase price occurs.
[0075] FIG. 4A is a first flowchart illustrating a method for determining a statistical distance based on personal data and statistical data, generating a first query based on the determined statistical distance, and performing user authentication using the generated first query according to one embodiment of the present disclosure. FIG. 4B is a second flowchart illustrating a method for determining a statistical distance based on personal data and statistical data, generating a first query based on the determined statistical distance, and performing user authentication using the generated first query according to one embodiment of the present disclosure.
[0076] The first flowchart of FIG. 4a is a flowchart illustrating a situation in which user authentication is completed based on a first query, and the second flowchart of FIG. 4b is a flowchart illustrating a situation in which a second query is generated and the user authentication is completed when user authentication is not completed based on the first query.
[0077] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.
[0078] According to one embodiment, operations 401 through 421 may be understood to be performed by a processor (e.g., processor 320 of FIG. 3 ) of a server (e.g., server (310) of FIG. 3 ), or may be understood to be performed by a processor (e.g., processor 220 of FIG. 3 ) of an electronic device (e.g., electronic device (210) of FIG. 3 ). The electronic device of FIGS. 4A and 4B may be at least partially similar to the server (310) of FIG. 3 , or may further include other embodiments of the server (310).
[0079] According to one embodiment, the processor (220) of the electronic device (210) may request authentication related to the user of the electronic device (210) from the server (310) when additional user authentication is required according to a set condition. For example, the set condition may include a situation where the user of the electronic device (210) is suspected to be someone other than the user. The set condition may include at least one of a situation where a password input fails while the lock screen is displayed on the electronic device (210), a situation where a user authentication process for an audio signal including the user's voice fails, a situation where a payment request exceeding a set amount occurs based on a payment-related program, and a situation where a payment request occurs at a location that the user has not visited before. For example, the set condition may include a situation where additional authentication for the user is required. According to one embodiment, the electronic device (210) may request authentication for the user from the server (310) when additional user authentication is required according to the set condition.
[0080] In operation 401, the server (310) can verify an authentication request for a user obtained from an electronic device (210). For example, the processor (320) of the server (310) can execute a program for performing user authentication and, based on the program, perform an authentication function for the user.
[0081] In operation 403, the processor (320) of the server (310) may receive a plurality of personalized data from an external electronic device (e.g., the electronic device (210)). For example, the plurality of personalized data may include at least one of information related to the user's personal information, information related to the user's use of the electronic device (210), information related to the user's activity, and / or information on the time at which the user's activity occurred.
[0082] In operation 405, the processor (320) of the server (310) can determine a statistical distance based on a plurality of personalized data (231) and statistical data (331) stored in the memory (330). For example, the statistical distance may include numerical information indicating a similarity between the plurality of personalized data (231) and the statistical data (331). A close statistical distance may mean that the similarity between the personalized data (231) and the statistical data (331) is relatively high. In operation 405, the processor (320) can determine the statistical distance by comparing or analyzing the plurality of personalized data (231) and the statistical data (331).
[0083] According to one embodiment, the server (310) may calculate a statistical distance (e.g., similarity) using a vector similarity search method. For example, the method for calculating the statistical distance may include at least one of a method based on a Euclidean distance, a method based on a Manhattan distance, a method based on a Minkowski distance, a method based on a Mahalanobis distance, and / or a method based on a cosine similarity. According to one embodiment, the server (310) may compare first vector data corresponding to personalized data (231) with second vector data corresponding to statistical data (331), and may numerically calculate the similarity between the two vectors. The server (310) can select at least one first personalized data based on a statistical distance calculated based on a plurality of personalized data (231) and statistical data (331).
[0084] In operation 407, the processor (320) of the server (310) may select first personalized data from among a plurality of personalized data (231) based on statistical distance. For example, the first personalized data may include data related to personal experiences that are at least partially different from the statistical data or that are not mapped to the statistical data. The first personalized data may include data specific to the user, specifically the user.
[0085] In operation 409, the processor (320) of the server (310) may generate a first query based on the first personalized data. For example, the first query may be generated based on the first personalized data (e.g., user-specific experience information). The first query may include a user-specific question to which only the user can provide an accurate answer.
[0086] In operation 411, the processor (320) of the server (310) may determine whether the first user's answer to the first query is correct. For example, the first query may be generated based on the selected first personalized data, and the correctness of the first user's answer may be determined based on the selected first personalized data. The correctness of the first user's answer may be determined based on information personally experienced by the user.
[0087] If the first user's answer to the first query is correct in operation 411, the processor (320) of the server (310) may complete an authentication request for the user in operation 413. In operation 413, the processor (320) may determine that the user authentication request requested by the electronic device (210) has been approved. The server (310) may transmit information indicating that the user authentication request has been completed (e.g., approved) to the electronic device (210). In response to the completion (e.g., approved) of the user authentication request, the processor (220) of the electronic device (210) may complete additional user authentication for the user.
[0088] If the first user's answer to the first query is not correct in operation 411, the processor (320) of the server (310) may select second personalized data having a different statistical distance from the first personalized data in operation 415. For example, the second personalized data may have a relatively longer or shorter statistical distance from the first personalized data. In one embodiment, if the second personalized data has a longer statistical distance from the first personalized data, a second query generated based on the second personalized data may require a more personalized answer than the first query. For example, the second query may be a question that is relatively more difficult for the user to answer than the first query. The second time point corresponding to the second query may be a relatively earlier time point than the first time point corresponding to the first query. According to one embodiment, the processor (320) may select second personalized data so that the user's answer difficulty level is relatively high when the first user answer is not correct.
[0089] In operation 417, the processor (320) of the server (310) may generate a second query based on the second personalized data. For example, the second query may be generated based on the second personalized data (e.g., user-specific experience information). The second query may include a question with a relatively higher difficulty level than the first query. For example, the second query may include a user-specific question to which only the user can provide an accurate answer.
[0090] In operation 419, the processor (320) of the server (310) may determine whether the second user's answer to the second query is correct. For example, the second query may be generated based on the selected second personalized data, and the second user's answer may be determined to be correct based on the selected second personalized data. The second user's answer may include a relatively more personalized answer than the first user's answer.
[0091] If the second user's answer to the second query is correct in operation 419, the processor (320) of the server (310) may complete an authentication request for the user in operation 413. In operation 413, the processor (320) may determine that the user authentication request requested by the electronic device (210) has been approved. The server (310) may transmit information indicating that the user authentication request has been completed (e.g., approved) to the electronic device (210). In response to the completion (e.g., approved) of the user authentication request, the processor (220) of the electronic device (210) may complete additional user authentication for the user.
[0092] If the second user's answer to the second query is not correct in operation 419, the processor (320) of the server (310) may determine that the authentication request for the user has failed in operation 415. According to one embodiment, the server (310) may perform a first additional authentication operation using a first query generated based on the first personalized data in response to the authentication request for the user, and if the first additional authentication operation fails, perform a second additional authentication operation using a second query generated based on the second personalized data. If both the first additional authentication operation and the second additional authentication operation fail, the processor (320) may determine that the authentication request for the user has failed.
[0093] According to one embodiment, when a user authentication request is confirmed, an electronic device (e.g., server (310)) may determine a statistical distance based on personalized data related to the user's activity and statistical data on the activities of multiple users. For example, the statistical distance may include information that numerically represents the similarity between the personalized data and the statistical data. Based on the statistical distance, the electronic device (e.g., server (310)) may select first personalized data corresponding to a specific activity of the user and generate a first query based on the first personalized data. In response to the user authentication request, the electronic device (e.g., server (310)) may generate a first query specialized for the user's activity and experience and provide the first query to the user, thereby performing user authentication. For example, since the first query requires a user answer based on the user's activity and experience, if the first answer to the first query is correct, the user authentication function may be determined to be completed.
[0094] According to one embodiment, the electronic device (210) may display a first query related to the purchase of Product A if the user purchased Product A approximately one day ago based on the current time. For example, the electronic device (210) may provide the user with a first query based on the user's experience, such as "What payment method did you use when purchasing Product A?", "What application did you use when purchasing Product A?", or "When did you purchase Product A?", and may obtain the user's answer to the first query. The electronic device (210) may determine whether the obtained user's answer is correct or incorrect.
[0095] According to one embodiment, if the first question provided to the user is determined to be incorrect, the electronic device (210) may provide the user with a second question based on a time point in the past relatively to the time point related to the first question. For example, if the first question was generated based on a user experience from about 1 day ago, the second question may be generated based on a user experience from about 7 days ago, which corresponds to a time point in the past relative to about 1 day ago. The second question may include questions that are relatively more difficult for the user than the first question. For example, if the user purchased product B about 7 days ago, the second question related to product B may be provided to the user. The electronic device (210) may determine whether the user's answer to the second question is correct or incorrect.
[0096] Referring to FIGS. 4A and 4B , operations 401 to 421 are described as being performed by the server (310), but are not limited thereto. According to another embodiment, the electronic device (210) may also perform operations 401 to 421 on its own.
[0097] FIG. 5 is a diagram illustrating an embodiment in which a statistical distance is determined based on personal data and statistical data according to one embodiment of the present disclosure.
[0098] Referring to FIG. 5, a statistical graph (500) that diagrams statistical distances is illustrated. The statistical graph (500) may include personalized data (510) based on a user's activities and experiences, and statistical data (520) generated by integrating the activities and experiences of multiple users. For example, the personalized data (510) may visually display the range of user activities within the statistical graph (500). The statistical data (520) may visually display the range of average activities of multiple users within the statistical graph (500). The personalized data (510) and statistical data (520) may be calculated based on various attribute information (e.g., time, store, product name, location, price, brand, category), and may visually provide numerical information according to each attribute information. The statistical graph (500) can be divided into a public area (531) where personalized data (510) and statistical data (520) at least partially overlap, and a private area (532) where the statistical data (520) is excluded based on the personalized data (510).
[0099] For example, suppose a user purchases and listens to music A during a set time interval. Assuming that there are approximately 20 other users who behave in the same way as the user on average per hour, and that the standard deviation is approximately 3, approximately 17-23 users can be identified as purchasing and listening to music A during the set time interval. If a user authentication request occurs at a specific time (T1), and approximately 2 people purchased music A during that specific time (e.g., approximately 18 people did not purchase music A during that specific time), the Mahalanobis distance (e.g., statistical distance) can be calculated to be approximately 6. For example, if the statistical distance is approximately 6, the situation can be understood as having approximately 6 times the scarcity value. High-scarcity activities can be understood as activities more specialized than the user's personal activities that are distinct from those of multiple users. For example, if other factors that distinguish the user from those of multiple users (e.g., purchase location, purchase price) are added, the user's activities can be further refined and distinguished. According to one embodiment, a server (e.g., server (310) of FIG. 3) may generate at least one query based on personalized data corresponding to the user's personal activities, and may perform additional user authentication using the generated at least one query. Since the server (310) utilizes queries tailored to the user's experiences and activities, the security associated with user authentication may be enhanced. The accuracy associated with user authentication may also be improved.
[0100] According to one embodiment, a processor (e.g., a processor (320) of FIG. 3) of a server (e.g., a server (310) of FIG. 3) may select personalized data (e.g., first personalized data (501) and second personalized data (502)) included in a personal area (532) based on personalized data (510) acquired from an electronic device (210) and statistical data (520) stored in a memory (e.g., a memory (330) of the server (310) of FIG. 3). For example, personalized data included in the personal area (532) may include data related to activities that other users have not statistically experienced. Personalized data included in the personal area (532) may include data related to activities personally experienced by the user (e.g., activities actually experienced by the user). For example, personalized data included in the personal area (532) may include activity data related to purchasing goods actually experienced by the user. The personalized data contained in the personal area (532) does not include average activity data related to product purchases experienced by multiple other users. In one embodiment, the personalized data contained in the personal area (532) may include all activity data actually experienced by the user, excluding activity data averaged across multiple other users. For example, the personalized data contained in the personal area (532) may include activity data specific to the user, but not experienced by multiple other users.
[0101] According to one embodiment, the processor (320) of the server (310) may select first personalized data (501) included in the personal area (532) from among the plurality of personalized data (510) and generate a first query based on the selected first personalized data (501). The first personalized data (501) may include data having a first statistical distance (541). For example, the first query may be a question related to an activity that statistically other users do not usually experience. The first query may be a question specialized for the user based on the user's activities and experiences. The processor (320) may perform a first additional user authentication using the first query generated based on the first personalized data (501).
[0102] According to one embodiment, if the first additional user authentication fails, the processor (320) of the server (310) may select second personalized data (502) included in the personal area (532) and generate a second query based on the selected second personalized data (502). The second personalized data (502) may include data having a second statistical distance (542). For example, the second personalized data (502) may include information having a relatively longer statistical distance than the first personalized data (501). The second personalized data (502) may include information more specific to the user's activities and experiences (e.g., relatively more private data) than the first personalized data (501). If the first additional user authentication fails, the processor (320) can perform a second additional user authentication using a second query generated based on the second personalized data (502).
[0103] According to one embodiment, in performing the first additional user authentication, the server (310) may generate a first query based on the first personalized data (501) of the first statistical distance (541), and determine whether the first additional user authentication is completed based on the first user's answer to the first query. If the first user's answer is incorrect, the server (310) may generate a second query based on the second personalized data (502) of the second statistical distance (542) that is different from the first statistical distance (541), and determine whether the second additional user authentication is completed based on the second user's answer to the second query. For example, the first query and the second query may include questions customized for the user based on the user's activities and / or experiences. The first statistical distance (541) corresponding to the first query may be relatively shorter than the second statistical distance (542) corresponding to the second query. This may be understood as the second query being a relatively more personal question to the user than the first query.
[0104] FIG. 6 is a diagram illustrating operations performed in each of an electronic device and a server when performing user authentication according to one embodiment of the present disclosure.
[0105] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.
[0106] Referring to FIG. 6, operations 601, 603, and 613 may be understood to be performed by a processor (e.g., processor (220) of FIG. 3) of an electronic device (e.g., electronic device (210) of FIG. 3). Operations 605 to 611 may be understood to be performed by a processor (e.g., processor (320) of FIG. 3) of a server (e.g., server (310) of FIG. 3).
[0107] Referring to FIG. 6, in operation 601, if user authentication is required according to set conditions, the processor (220) of the electronic device (210) may request authentication related to the user of the electronic device (210) from the server (310).
[0108] In operation 603, the electronic device (210) may provide personalized data related to the user's activity (e.g., personalized data (231) of FIG. 3) to the server (310) when requesting user authentication. For example, the personalized data (231) may be stored in the memory of the electronic device (210) (e.g., the memory (230) of the electronic device (210) of FIG. 3) and may include data generated and extracted based on the user's activity (e.g., activity information of the user using the electronic device (210). The personalized data (231) may be implemented in multiple pieces and may include at least one of information related to the user's personal information, information related to the user's use of the electronic device (210), information related to the user's activity, and / or information on the time when the user's activity occurred.
[0109] In operation 605, the processor (320) of the server (310) can check statistical data (e.g., statistical data (331) of FIG. 3, statistical data generated by integrating activities and experiences of multiple users, average data) stored in a memory (e.g., memory (330) of the server (310) of FIG. 3) in response to a user authentication request (601).
[0110] In operation 607, the processor (320) of the server (310) may determine a statistical distance based on personalized data (231) and / or statistical data (331) obtained from the electronic device (210). For example, the statistical distance may include numerical information indicating a similarity between the plurality of personalized data (231) and the statistical data (331). A close statistical distance may mean that the similarity between the personalized data (231) and the statistical data (331) is relatively high. In operation 405, the processor (320) may determine the statistical distance by comparing or analyzing the plurality of personalized data (231) and the statistical data (331).
[0111] In operation 609, the processor (320) of the server (310) may select at least one first personalized data (e.g., the first personalized data (501) of FIG. 5) based on the verified statistical distance, and may generate a first query based on the selected first personalized data (501). For example, the first personalized data (501) may include data related to personal experiences that do not overlap with statistical data (e.g., the statistical data (520) of FIG. 5). The first personalized data (501) may include data related to activities personally experienced by the user, and may include data specific to the user.
[0112] In operation 611, the processor (320) of the server (310) may provide information related to the first query to the electronic device (210). For example, the information related to the first query may include information related to the first query generated by the server (310) and the correct answer to the first query. The first query and the correct answer to the first query may be determined based on the selected first personalized data (50)1.
[0113] In operation 613, the processor (220) of the electronic device (210) may provide a first query to the user and confirm a first user answer to the first query. For example, the electronic device (210) may display the first query through a display and confirm the first user answer based on a user input for the first query. The electronic device (210) may determine whether the first user answer to the first query is correct. If the first user answer to the first query is correct, the electronic device (210) may complete the user authentication request in operation 601. For example, if the first user answer is correct, the electronic device (210) may determine that the user authentication has been approved.
[0114] In one embodiment, operation 613 may be performed via the server (310). The electronic device (210) may provide the first user's answer to the server (310), and the server (310) may determine whether the first user's answer is correct or not, and may obtain result information related to the completion of user authentication from the server (310). In one embodiment, the server (310) may independently perform operations related to user authentication.
[0115] In another embodiment, all of operations 601 to 613 may be performed by the electronic device (210) itself. For example, if statistical data is stored in the memory (230) of the electronic device (210), the electronic device (210) may independently process a user authentication process according to a user authentication request.
[0116] Referring to FIG. 6, when performing user authentication, the operations in the electronic device (210) and the operations in the server (310) are distinguished, but this may not be limited thereto. According to another embodiment, the electronic device (210) may independently perform operations 601 to 613.
[0117] According to one embodiment, the electronic device (210) may generate a first query specialized for the user's personal activity (e.g., first personalized data) and provide it to the user when performing user authentication, and may determine whether the user authentication is complete based on the first user response to the first query. The electronic device (210) may process the user authentication function based on the first query specialized for the user's personal activity and the first user response, thereby enhancing the security of user authentication. The accuracy of user authentication may be enhanced.
[0118] According to one embodiment, a user authentication method of an electronic device (310) may include an operation of receiving an authentication request for a user, an operation of receiving a plurality of personalized data (231) corresponding to the user from an external electronic device (210) in response to the authentication request, an operation of confirming a statistical distance between the plurality of personalized data (231) and the statistical data (331) based on the received plurality of personalized data (231) and statistical data (331) stored in the memory (330), an operation of selecting one personalized data among the plurality of personalized data (231) based on the confirmed statistical distance, and an operation of generating a first query for user authentication based on the selected personalized data. The plurality of personalized data (231) may include information related to an activity of the user and information on a time at which the activity of the user occurred.
[0119] A method according to one embodiment may further include an operation of transmitting the generated first query to the external electronic device (210), an operation of receiving a first user answer to the first query from the external electronic device (210), an operation of determining whether the first user answer is correct based on the selected personalized data, and an operation of completing an authentication request for the user if the first user answer is correct.
[0120] According to one embodiment, the method may further include, if the first user answer is not correct, an operation of determining second time information different from the first time information corresponding to the selected personalized data, an operation of selecting other personalized data based on the determined second time information, and an operation of generating a second query based on the selected other personalized data.
[0121] According to one embodiment, the first time information may be determined to be a point in the past relatively to the second time information.
[0122] According to one embodiment, the second time information may be determined to be a point in time relatively in the past compared to the first time information.
[0123] According to one embodiment, the information related to the user's activity may include at least one of purchase history information related to the purchase of goods, information related to the user, activity information related to the installation program, or location-related information related to the purchase of goods.
[0124] According to one embodiment, the purchase history information may include at least one of purchase time, purchase date, purchase time, purchase location, purchased item, purchase price, category information of purchased item, image information of purchased item, discount information, or purchase method.
[0125] According to one embodiment, the activity information related to the installation program may include at least one of application information with which account information is shared, content information in an application with which account information is shared, photo information, music information, information registered as a favorite, or location information.
[0126] The method according to one embodiment may further include an operation of reflecting the personalized data and the statistical data in a similarity search method, and an operation of determining the statistical distance based on the similarity search method.
[0127] An action of receiving an authentication request for a user according to one embodiment may include an action of generating an authentication request for the user from the external electronic device in response to a situation where lock screen authentication fails, user authentication based on an audio signal fails, or a purchase request exceeding a set purchase price occurs.
[0128] According to one embodiment, a non-transitory computer-readable storage medium (or a computer program product) storing one or more programs for executing a user authentication method of an electronic device may be described. According to one embodiment, the one or more programs may include instructions that, when executed by a processor of the electronic device, perform the following operations: receiving an authentication request for a user; receiving, in response to the authentication request, a plurality of personalized data corresponding to the user from an external electronic device; determining a statistical distance between the plurality of personalized data and the statistical data based on the received plurality of personalized data and statistical data stored in the memory; selecting one personalized data from among the plurality of personalized data based on the determined statistical distance; and generating a first query for user authentication based on the selected personalized data. The plurality of personalized data may include information related to an activity of the user and information on the time at which the activity of the user occurred.
[0129] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.
[0130] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.
[0131] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0132] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.
[0133] According to one embodiment, the method according to various embodiments disclosed in the present document may be provided as included in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smart phones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0134] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
Claims
1. In an electronic device (310), Processor (320); and A memory (330) for storing instructions; The above instructions, when executed by the processor (320), cause the electronic device (310) to: Receive an authentication request from a user, In response to the above authentication request, a plurality of personalized data (231) corresponding to the user is received from an external electronic device (210), and the plurality of personalized data (231) includes information related to the user's activity and information on the time at which the user's activity occurred. Based on the plurality of personalized data (231) received above and the statistical data (331) stored in the memory (330), the statistical distance between the plurality of personalized data (231) and the statistical data (331) is confirmed, Based on the statistical distance confirmed above, one personalized data among the plurality of personalized data (231) is selected, An electronic device that generates a first query for user authentication based on the above-mentioned selected personalized data.
2. In paragraph 1, When the above instructions are executed by the processor (320), the electronic device (310) causes: Transmitting the first query generated above to the external electronic device (210), Receive the first user response to the first query from the external electronic device (210), Based on the above selected personalized data, determine whether the first user's answer is correct or not, An electronic device that completes an authentication request for said user if the first user answer is correct.
3. In paragraph 2, When the above instructions are executed by the processor (320), the electronic device (310) causes: If the first user answer is not correct, determine second time information that is different from the first time information corresponding to the selected personalized data, Select other personalized data based on the second time information determined above, An electronic device that generates a second query based on the other selected personalized data.
4. In paragraph 3, An electronic device in which the first time information is determined to be a point in time relatively earlier than the second time information.
5. In paragraph 3, An electronic device in which the second time information is determined to be a point in time relatively earlier than the first time information.
6. In paragraph 1, An electronic device including at least one of information related to the user's activity, such as purchase history information related to purchase of goods, information related to the user, activity information related to the installation program, or location information related to purchase of goods.
7. In paragraph 6, The above purchase history information is an electronic device including at least one of purchase time, purchase date, purchase time, purchase location, purchased item, purchase price, category information of purchased item, image information of purchased item, discount information, or purchase method.
8. In paragraph 6, Activity information related to the above installation program is an electronic device including at least one of application information with which account information is shared, content information in an application with which account information is shared, photo information, music information, information registered as favorites, or location information.
9. In paragraph 1, When the above instructions are executed by the processor (320), the electronic device (310) causes: The above personalized data and the above statistical data (331) are reflected in the similarity search method, An electronic device for determining the statistical distance based on the above similarity search method.
10. In paragraph 1, When the above instructions are executed by the processor (320), the electronic device (310) causes: An electronic device that causes an authentication request to be generated for a user from said external electronic device in response to a failure in lock screen authentication, a failure in user authentication based on audio signals, or a purchase request exceeding a set purchase price.
11. In a user authentication method of an electronic device (310), The action of receiving an authentication request from a user; In response to the above authentication request, an action of receiving a plurality of personalized data (231) corresponding to the user from an external electronic device (210); An operation of checking a statistical distance between the plurality of personalized data (231) and the statistical data (331) based on the plurality of personalized data (231) received and the statistical data (331) stored in the memory (330); An operation of selecting one personalized data among the plurality of personalized data (231) based on the statistical distance confirmed above; and An operation of generating a first query for user authentication based on the selected personalized data; A method characterized in that the above plurality of personalized data (231) includes information related to the user's activity and information on the time at which the user's activity occurred.
12. In paragraph 11, An action of transmitting the generated first query to the external electronic device (210); An action of receiving a first user response to the first query from the external electronic device (210); An action of determining whether the first user's answer is correct based on the selected personalized data; and A method further comprising: completing an authentication request for the user if the first user answer is correct; 13. In paragraph 12, If the first user answer is not correct, an operation of determining second time information that is different from the first time information corresponding to the selected personalized data; An action of selecting other personalized data based on the second time information determined above; and A method further comprising: generating a second query based on the selected other personalized data; 14. In paragraph 13, A method characterized in that the first time information is determined to be a point in time relatively earlier than the second time information.
15. In paragraph 13, A method characterized in that the second time information is determined to be a point in time relatively earlier than the first time information.
Citation Information
Patent Citations
User authentication device and user authentication method
JP2014182549A
Authentication device, authentication method and authentication program
JP2017134750A
Server, authentication method, and computer program
JP2018147053A
Discrimination system, discrimination method, and computer program
JP2022065915A
Information processing apparatus, information processing method, and information processing program
JP2023159772A