Electronic device and electronic device control method

The electronic device improves user authentication security by managing biometric data in groups and ensuring correct matching for access, thus reducing the risk of unauthorized access and user inconvenience.

WO2025136057A1PCT designated stage expired Publication Date: 2025-06-26SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/097138
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-18
Filing Date
2024-12-18
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

User authentication systems using biometric information face security risks due to potential personal information leakage if biometric data is compromised, and conventional methods to mitigate this, such as deactivating biometric authentication, cause user inconvenience.

Method used

An electronic device with a processor that manages authentication data divided into groups, allowing access to applications only when the user's biometric information is correctly matched to the assigned group, and providing a message to set the corresponding group upon initial access attempt.

Benefits of technology

Enhances security by ensuring that only authorized biometric information is used for application access, reducing the risk of unauthorized access while minimizing user inconvenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024097138_26062025_PF_FP_ABST
    Figure KR2024097138_26062025_PF_FP_ABST
Patent Text Reader

Abstract

An electronic device and an electronic device control method are disclosed. Particularly, the electronic device may comprise: a memory for storing authentication data divided into a plurality of groups; and a processor for receiving a user authentication request made by a first application, identifying whether first biometric information is included in the authentication data when the first biometric information of a user is acquired for the request, identifying a first group corresponding to a first application from among the plurality of groups stored in the memory if the first biometric information is included in the authentication data, permitting access of user to the first application if the first group is identified and the first biometric information corresponds to the authentication data included in the first group, and providing a message for requesting to set a group corresponding to the first application if the first group is not identified.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic devices and methods for controlling electronic devices

[0001] The present disclosure relates to an electronic device and a method for controlling the electronic device, and more particularly, to an electronic device and a method for controlling the same that can improve the security of user authentication using biometric information.

[0002] Recently, with the advancement of technologies related to communications, artificial intelligence, and the Internet of Things, user authentication technology using biometrics has been continuously developing and being innovatively applied in various fields.

[0003] However, while user authentication technology using biometrics has advantages such as utilizing the uniqueness of each user, providing a high level of security due to its high recognition rate, and enabling fast and convenient user authentication, it also has the problem that it can cause serious personal information leakage if biometric information is stolen by a third party who is not the legitimate user of the electronic device.

[0004] In particular, once a third party has figured out the password for the lock screen of an electronic device and has added his or her biometric information to the electronic device, the third party can illegally obtain the user's personal information by logging in or accessing various applications where biometric authentication is enabled.

[0005] To address these issues, prior art uses a method of providing a message to notify the user that new biometric information has been added to an electronic device and disabling biometric authentication for the application.

[0006] However, the conventional technology has the limitation that, whenever new biometric information is added, biometric authentication for the application is disabled, and the user must endure the inconvenience of reactivating the disabled biometric authentication by entering the user account password or other methods. In addition, if appropriate measures are not taken when new biometric information is added to the electronic device, it can cause serious security problems.

[0007] The present disclosure is intended to solve the problems of the prior art as described above, and the purpose of the present disclosure is to provide an electronic device and a control method thereof that can improve the security of user authentication using biometric information.

[0008] According to one embodiment of the present disclosure for achieving the above-described object, an electronic device includes a memory storing authentication data divided into a plurality of groups and a processor for receiving a request for user authentication by a first application, and when first biometric information of a user is acquired in response to the request, identifying whether the first biometric information is included in the authentication data, and if the first biometric information is included in the authentication data, identifying a first group corresponding to the first application among the plurality of groups stored in the memory, and if the first group is identified and the first biometric information corresponds to authentication data included in the first group, allowing the user's access to the first application, and if the first group is not identified, providing a message for requesting setting a group corresponding to the first application.

[0009] Meanwhile, the processor may receive a user input from the user in response to the message, and when a second group is selected from the plurality of groups based on the user input, set the second group as a group corresponding to the first application, assign the first biometric information to the second group, and allow the user's access to the first application.

[0010] Meanwhile, if the processor assigns second biometric information different from the first biometric information to the second group, and if the second group is selected according to the user input, the processor may perform first additional user authentication based on the second biometric information, and if the first additional user authentication is successful, set the second group as a group corresponding to the first application, and if the first additional user authentication fails, set a third group different from the second group as a group corresponding to the first application.

[0011] Meanwhile, if at least one group among the plurality of groups is not selected by the user, the processor may set a fourth group designated in advance to perform user authentication for all applications among the plurality of groups as a group corresponding to the first application.

[0012] Meanwhile, if the first biometric information is not included in the authentication data, the processor may block the user's access to the first application and provide a message indicating that user authentication for the first application has failed.

[0013] Meanwhile, if the first biometric information does not correspond to authentication data included in the identified first group, the processor may block the user's access to the first application and provide a message indicating that user authentication for the first application has failed.

[0014] Meanwhile, when a user input for deleting the first biometric information is received after the first biometric information is assigned to the second group, the processor may identify whether second biometric information different from the first biometric information is assigned to the second group, and if the second biometric information is assigned to the second group, the processor may delete the first biometric information while maintaining the second group and the second biometric information in the authentication data, and if the second biometric information is not assigned to the second group, the processor may delete information about the second group together with the first biometric information from the authentication data.

[0015] Meanwhile, the processor may set a fifth group for an application for which there is no biometric information capable of performing user authentication when the second group is deleted, as a group corresponding to the first application.

[0016] Meanwhile, when the first biometric information is assigned to the second group and data for the first application is deleted, the processor may delete information indicating that the second group is set to perform user authentication for the first application from the authentication data.

[0017] Meanwhile, if the first group is identified and the first biometric information corresponds to authentication data included in the first group, the processor may compare a first time at which the request is received and a second time at which the first biometric information is input, and if the second time is later than the first time, the processor may block the user's access to the first application.

[0018] Meanwhile, when a user input for assigning the first biometric information to a third group different from the second group is received after the first biometric information is assigned to the second group, the processor may perform a second additional user authentication based on at least one biometric information included in the third group, and if the second additional user authentication is successful, assign the first biometric information to the third group, and if the second additional user authentication fails, may not assign the first biometric information to the third group.

[0019] According to one embodiment of the present disclosure for achieving the above-described object, a control method of an electronic device includes the steps of: receiving a request for user authentication by a first application; when first biometric information of a user in response to the request is acquired, identifying whether the first biometric information is included in authentication data divided into a plurality of groups; when the first biometric information is included in the authentication data, identifying a first group corresponding to the first application among the plurality of groups; when the first group is identified and the first biometric information corresponds to authentication data included in the first group, allowing the user's access to the first application; and when the first group is not identified, providing a message for requesting setting a group corresponding to the first application.

[0020] Meanwhile, the control method of the electronic device may further include a step of receiving a user input of the user in response to the message, and a step of setting the second group as a group corresponding to the first application when a second group among the plurality of groups is selected based on the user input, assigning the first biometric information to the second group, and allowing the user's access to the first application.

[0021] Meanwhile, the control method of the electronic device may further include, when second biometric information different from the first biometric information is assigned to the second group, if the second group is selected according to the user input, performing first additional user authentication based on the second biometric information; when the first additional user authentication is successful, setting the second group as a group corresponding to the first application; and when the first additional user authentication fails, setting a third group different from the second group as a group corresponding to the first application.

[0022] Meanwhile, the control method of the electronic device may further include a step of setting a fourth group, which is pre-designated to perform user authentication for all applications among the plurality of groups, as a group corresponding to the first application, if at least one group among the plurality of groups is not selected by the user.

[0023] Meanwhile, the control method of the electronic device may further include a step of blocking the user's access to the first application and providing a message indicating that user authentication for the first application has failed, if the first biometric information is not included in the authentication data.

[0024] Meanwhile, the control method of the electronic device may further include a step of blocking the user's access to the first application and providing a message indicating that user authentication for the first application has failed, if the first biometric information does not correspond to authentication data included in the identified first group.

[0025] Meanwhile, the control method of the electronic device may further include, when a user input for deleting the first biometric information is received after the first biometric information is assigned to the second group, a step of identifying whether second biometric information different from the first biometric information is assigned to the second group; a step of deleting the first biometric information while maintaining the second group and the second biometric information in the authentication data if the second biometric information is assigned to the second group; and a step of deleting information about the second group together with the first biometric information from the authentication data if the second biometric information is not assigned to the second group.

[0026] Meanwhile, the control method of the electronic device can set a fifth group for an application for which there is no biometric information capable of performing user authentication as a group corresponding to the first application when the second group is deleted.

[0027] According to one embodiment of the present disclosure for achieving the above-described object, there is provided a non-transitory computer-readable recording medium including a program for executing a method for controlling an electronic device, the method comprising: receiving a request for user authentication by a first application; identifying, when first biometric information of a user is acquired in response to the request, whether the first biometric information is included in authentication data divided into a plurality of groups; identifying, when the first biometric information is included in the authentication data, a first group corresponding to the first application among the plurality of groups; allowing the user's access to the first application when the first group is identified and the first biometric information corresponds to authentication data included in the first group; and providing, when the first group is not identified, a message for requesting setting a group corresponding to the first application.

[0028] FIG. 1 is a flowchart briefly illustrating a method for controlling an electronic device according to one or more embodiments of the present disclosure;

[0029] FIG. 2 is a diagram illustrating a structure of authentication data according to one or more embodiments of the present disclosure;

[0030] FIG. 3 is a flowchart illustrating one or more embodiments related to setting up a group corresponding to a first application;

[0031] FIG. 4 is a flowchart illustrating one or more embodiments related to deleting first biometric information after the first biometric information is assigned to a second group;

[0032] FIG. 5 is a diagram illustrating one or more embodiments related to assigning first biometric information to a third group after first biometric information is assigned to a second group;

[0033] FIG. 6 is a schematic diagram illustrating a configuration of an electronic device according to one or more embodiments of the present disclosure, and

[0034] FIG. 7 is a drawing detailing the configuration of an electronic device according to one or more embodiments of the present disclosure.

[0035] The present embodiments may be modified and have various embodiments. Specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the scope to specific embodiments, but should be understood to encompass various modifications, equivalents, and / or alternatives of the embodiments of the present disclosure. In connection with the description of the drawings, similar reference numerals may be used for similar components.

[0036] In describing the present disclosure, if it is determined that a specific description of a related known function or configuration may unnecessarily obscure the gist of the present disclosure, a detailed description thereof will be omitted.

[0037] Additionally, the following embodiments may be modified in various other forms, and the scope of the technical concepts of the present disclosure is not limited to the following embodiments. Rather, these embodiments are provided to further faithfully and completely convey the technical concepts of the present disclosure to those skilled in the art.

[0038] The terminology used in this disclosure is for the purpose of describing specific embodiments only and is not intended to limit the scope of the rights. Singular expressions include plural expressions unless the context clearly dictates otherwise.

[0039] In this disclosure, expressions such as “has,” “can have,” “includes,” or “may include” indicate the presence of a corresponding feature (e.g., a component such as a number, function, operation, or part), and do not exclude the presence of additional features.

[0040] In this disclosure, expressions such as “A or B,” “at least one of A and / or B,” or “one or more of A or / and B” can include all possible combinations of the listed items. For example, “A or B,” “at least one of A and B,” or “at least one of A or B” can all refer to (1) including at least one A, (2) including at least one B, or (3) including both at least one A and at least one B.

[0041] The expressions “first,” “second,” “first,” or “second,” etc., used in this disclosure can describe various components, regardless of order and / or importance, and are only used to distinguish one component from another, but do not limit the components.

[0042] When it is said that a component (e.g., a first component) is “(operatively or communicatively) coupled with / to” or “connected to” another component (e.g., a second component), it should be understood that said component may be directly coupled to said other component, or may be coupled via another component (e.g., a third component).

[0043] On the other hand, when it is said that a component (e.g., a first component) is "directly connected" or "directly connected" to another component (e.g., a second component), it can be understood that no other component (e.g., a third component) exists between said component and said other component.

[0044] The expression "configured to" as used in the present disclosure may be used interchangeably with, for example, "suitable for," "having the capacity to," "designed to," "adapted to," "made to," or "capable of." The term "configured to" may not necessarily mean only "specifically designed to" in terms of hardware.

[0045] Instead, in some contexts, the phrase "a device configured to" may mean that the device, in conjunction with other devices or components, is "capable of" performing A, B, and C. For example, the phrase "a processor configured (or set) to perform A, B, and C" may refer to a dedicated processor (e.g., an embedded processor) for performing those operations, or a general-purpose processor (e.g., a CPU or application processor) that can perform those operations by executing one or more software programs stored in a memory device.

[0046] In the embodiments, a 'module' or 'part' performs at least one function or operation, and may be implemented as hardware or software, or as a combination of hardware and software. Furthermore, a plurality of 'modules' or 'parts' may be integrated into at least one module and implemented as at least one processor, except for a 'module' or 'part' that needs to be implemented as a specific hardware.

[0047] Meanwhile, the various elements and areas in the drawings are schematically drawn. Therefore, the technical concept of the present invention is not limited by the relative sizes or spacing depicted in the attached drawings.

[0048] Hereinafter, with reference to the attached drawings, embodiments according to the present disclosure will be described in detail so that a person having ordinary knowledge in the technical field to which the present disclosure pertains can easily implement the present disclosure.

[0049]

[0050] FIG. 1 is a flowchart briefly illustrating a control method of an electronic device (100) according to one or more embodiments of the present disclosure, and FIG. 2 is a diagram illustrating a structure of authentication data according to one or more embodiments of the present disclosure.

[0051] As illustrated in FIG. 1, the electronic device (100) may receive a request for user authentication from a first application (S110). For example, the request for user authentication from the first application may be received based on the occurrence of an event, such as the execution of the first application, or may be received based on user input, such as a user's touch input for making a payment using the first application.

[0052] "User authentication" refers to the process of verifying a user's identity when accessing various functions, information, or services provided by an electronic device (100). In particular, user authentication may refer to the process of determining whether to allow a user access to various functions, information, or services provided by a specific application.

[0053] The term "first application" is intended to specify one application among multiple applications that may be provided by the electronic device (100), and does not impose any particular limitations on the type of first application. Furthermore, terms such as "second application" and "third application" may also be used, like the term "first application," to distinguish a specific application from other applications.

[0054] The electronic device (100) can obtain the user's first biometric information in response to a user authentication request (S120). Specifically, when a user authentication request is received by the first application, the user can input the user's first biometric information in response to the user authentication request, thereby allowing the electronic device (100) to obtain the user's first biometric information.

[0055] The term "biometric information" collectively refers to information related to a user's biological characteristics that can be used to identify the user. For example, biometric information may be information that identifies an individual based on unique biological characteristics, such as a user's fingerprint, iris, or voice. There are no specific limitations on the types of biometric information used in the present disclosure. The term "biometric information" may be replaced with terms such as "biometric identification information" or "biometric authentication information."

[0056] "First biometric information" is a term used to specify a single biometric information, and terms such as "second biometric information" and "third biometric information" can also be used, like the term "first biometric information," to refer to specific biometric information and distinguish it from other biometric information. For example, the first biometric information may be a single fingerprint information entered by the user, the second biometric information may be another fingerprint information entered by the user, and the third biometric information may be iris information entered by the user.

[0057] When the first biometric information is acquired, the electronic device (100) can identify whether the first biometric information is included in the authentication data (S130). Here, "authentication data" refers to data constructed for user authentication and may be replaced with terms such as "authentication database." In particular, the authentication data according to the present disclosure may be data divided into multiple groups. Specifically, the authentication data may be data in which different biometric information is divided into multiple groups.

[0058] Specifically, whenever a user's biometric information is acquired, the electronic device (100) can construct the acquired biometric information as authentication data and store it in the memory (110) of the electronic device (100). In addition, when new biometric information (first biometric information of FIG. 1) is acquired, the electronic device (100) can identify whether the new biometric information is included in the previously constructed authentication data.

[0059] Referring to Figure 2, authentication data may include group identification information, biometric information, and application setting information. Biometric information has been previously defined, and each biometric information may be assigned to at least one of multiple groups.

[0060] In this disclosure, the term "group" is used to refer to a collection of biometric information used for user authentication. Specifically, each biometric information may be assigned a specific group, and each group may correspond to at least one biometric information. The term "group" may be replaced with terms such as "biometric information group" or "collection of biometric information."

[0061] 'Group classification information' refers to information that distinguishes multiple groups, and more specifically, refers to information for managing each biometric information by assigning it to at least one group among the multiple groups. For example, as in the example of Fig. 2, group classification information may indicate that biometric information A has been assigned to group X, and biometric information B and biometric information C have been assigned to group Y. Meanwhile, the term 'allocate' may be replaced with terms such as 'designate', 'assign', and 'place'.

[0062] "Application configuration information" refers to information that identifies the group corresponding to each application in the authentication data. Specifically, application configuration information refers to information indicating the group configured for performing user authentication for each application.

[0063] In the description of the present disclosure, a group set up to perform user authentication for a specific application may be referred to as a 'group corresponding to the application', and may also be briefly referred to as a 'dedicated group', a 'designated group', a 'target group', an 'allocated group', etc.

[0064] Specifically, when only a specific group is set as a group corresponding to the first application, the electronic device (100) can use at least one of the biometric information assigned to the specific group during the user authentication process for the first application, and cannot use biometric information assigned to another group.

[0065] For example, as in the example of FIG. 2, the application setting information indicates that group X is set as a group corresponding to application K, and group Y is set as a group corresponding to application L and application M. Meanwhile, group ALL in FIG. 2 indicates that all groups (i.e., group X and group Y in the example of FIG. 2) are set as groups corresponding to application N, and group NONE in FIG. 2 indicates that no group is set as a group corresponding to application O. Meanwhile, the term 'set' may be replaced with terms such as 'select', 'designate', 'assign', etc.

[0066] Hereinafter, a group that is preset to correspond to a first application among multiple groups may be referred to as a "first group." In other words, the first group refers to a group that is preset to correspond to the first application before a user authentication request is received.

[0067] If the first biometric information is included in the authentication data (S130-Y), the electronic device (100) can identify a first group corresponding to the first application among the plurality of groups (S140). Specifically, the electronic device (100) can not complete user authentication simply by including the first biometric information in the authentication data, but can additionally perform a process of identifying whether a first group set to perform user authentication for the first application among the plurality of groups exists.

[0068] If the first biometric information is included in the authentication data and a first group corresponding to the first application is identified (S140-Y), the electronic device (100) can identify whether the first biometric information corresponds to the authentication data included in the first group (S150). Then, if the first biometric information corresponds to the authentication data included in the first group (S150-Y), the electronic device (100) can allow the user's access to the first application (S160).

[0069] Here, the first biometric information corresponding to the authentication data included in the first group means that the first biometric information is identical or similar to at least one biometric information corresponding to the first group. The first biometric information being similar to the biometric information included in the first group means that, although the characteristics of the first biometric information and the characteristics of the biometric information included in the first group are not identical, the difference is within a threshold level.

[0070] In other words, if a group for performing user authentication for the first application is pre-configured and the first biometric information is identical to the biometric information pre-assigned to the configured group, the electronic device (100) may determine that the user authentication is successful and allow the user access to the first application.

[0071] For example, if biometric information A is acquired in response to a request for user authentication by application K in a state where authentication data is constructed as in the example of FIG. 2, biometric information A is included in the authentication data, and since biometric information A is biometric information assigned to group X, which is a group corresponding to application K, the electronic device (100) can allow the user's access to application K.

[0072] Meanwhile, if the first biometric information is included in the authentication data (S130-Y), but the first group corresponding to the first application is not identified (S140-N), the electronic device (100) may provide a message to request setting a group corresponding to the first application (S170).

[0073] In other words, if the first biometric information is included in the authentication data, but the group corresponding to the first application has not yet been set, the electronic device (100) may provide a message requesting the setting of the group corresponding to the first application.

[0074] For example, when biometric information A is acquired in response to a request for user authentication by application O in a state where authentication data is constructed as in the example of FIG. 2, since biometric information A is included in the authentication data but before a group corresponding to application K is assigned, the electronic device (100) may provide a message for requesting to set a group corresponding to application K before determining whether to allow the user's access to application K. The process of setting a group corresponding to a specific application after a message for requesting to set a group corresponding to a specific application is provided will be described in more detail with reference to FIG. 3.

[0075] Meanwhile, the above description describes a case where the first biometric information is included in the authentication data (S130-Y), but if the first biometric information is not included in the authentication data (S130-N), the electronic device (100) may determine that user authentication has failed.

[0076] Specifically, if the first biometric information is not included in the authentication data, the electronic device (100) may block the user's access to the first application (S180) and provide a message indicating that user authentication for the first application has failed. For example, the electronic device (100) may provide a message including information indicating that the first biometric information is not included in the authentication data.

[0077] For example, if biometric information D is acquired in response to a request for user authentication by application K in a state where authentication data is constructed as in the example of FIG. 2, since biometric information D is not included in the authentication data, the electronic device (100) can block the user's access to application K.

[0078] Meanwhile, the process of performing user authentication after receiving a request for user authentication from the first application has been described above. However, separately from this, the electronic device (100) may perform a process of registering new user biometric information. Here, "registration" refers to storing the user's biometric information by including it in the authentication data. In particular, the biometric information registration process according to the present disclosure may include a process of updating the authentication data by assigning biometric information to at least one of a plurality of groups.

[0079] Specifically, when a user input for registering first biometric information is received, the electronic device (100) can acquire the first biometric information and assign the biometric information of the first user to at least one group among a plurality of groups.

[0080] For example, if there is no biometric information other than the first biometric information in the authentication data, the electronic device (100) can assign a new group, a second group, to the first biometric information. On the other hand, if there is second biometric information other than the acquired biometric information in the authentication data, the electronic device (100) can not only assign a new group, a second group, to the first biometric information, but can also assign a third group, an existing group corresponding to the second biometric information. In particular, the electronic device (100) can assign the first biometric information to the third group only when user authentication is successful based on the second biometric information corresponding to the third group.

[0081] Meanwhile, the above description describes a case where the first biometric information corresponds to authentication data included in the first group (S130-Y, S140-Y, S150-Y), but if it does not correspond to authentication data included in the first group (S150-N), the electronic device (100) may determine that user authentication has failed.

[0082] Specifically, if a first group for a first application is identified, but the first biometric information does not correspond to authentication data included in the first group, the electronic device (100) may block the user's access to the first application (S180) and provide a message indicating that user authentication for the first application has failed. In other words, if the first biometric information is not biometric information assigned to the group corresponding to the first application, the electronic device (100) may determine that the user authentication has failed and provide a message including information that the first biometric information is not biometric information assigned to the group corresponding to the first application.

[0083] For example, when biometric information B is acquired in response to a request for user authentication by application K in a state where authentication data is constructed as in the example of FIG. 2, if biometric information B is included in the authentication data and group X is assigned as a group corresponding to application K, but biometric information B is assigned only to group Y and not to group X, the electronic device (100) can block the user's access to application K.

[0084] Meanwhile, in the above, an embodiment was described in which, when the first biometric information corresponds to authentication data included in the first group (S130-Y, S140-Y, S150-Y), the user authentication is immediately determined to be successful and the user's access to the first application is permitted. However, the electronic device (100) may also perform an additional process even when the first biometric information corresponds to authentication data included in the first group.

[0085] If a first group corresponding to a first application is identified and the first biometric information corresponds to authentication data included in the first group, the electronic device (100) may perform user authentication based on comparing a first time at which a request for user authentication by the first application is received and a second time at which the first biometric information is input. Specifically, if the second time is later than the first time, the electronic device (100) may block the user's access to the first application, and if the second time is earlier than the first time or the first time and the second time are the same, the electronic device (100) may allow the user's access to the first application.

[0086] According to the embodiment described above with reference to FIGS. 1 and 2, the electronic device (100) assigns a group to registered biometric information, and when performing user authentication for an application, only biometric information corresponding to a dedicated group for the application can be used to verify the user's identity.

[0087] Accordingly, the electronic device (100) can prevent a third party from accessing an application provided by the electronic device (100) by registering his / her own biometric information, thereby improving the security of user authentication using biometric information without using a method that causes inconvenience to the user, such as disabling biometric authentication for the application.

[0088]

[0089] FIG. 3 is a flowchart illustrating one or more embodiments related to setting up a group corresponding to a first application.

[0090] As illustrated in FIG. 3, the electronic device (100) may provide a message requesting the setting of a group corresponding to the first application (S310). Specifically, as described above with reference to FIG. 1, if the first biometric information is included in the authentication data (S130-Y) but the first group is not identified (S140-N), the electronic device (100) may provide a message requesting the setting of a group corresponding to the first application (S170).

[0091] That is, FIG. 3 is intended to explain a step that can be performed after step S170 of FIG. 1, assuming that the first biometric information is included in the authentication data, but the corresponding group for the first application is not identified.

[0092] The electronic device (100) may receive a user input for selecting a second group from among a plurality of groups (S320). Here, the term "second group" is used to refer to a group selected from among the plurality of groups as corresponding to the first application according to the user's selection. In other words, the second group refers to a group selected as corresponding to the first application according to the user's selection when the first group, which is preset as corresponding to the first application, is not identified.

[0093] Specifically, the electronic device (100) may receive a user input in response to a message requesting the setting of a group corresponding to a first application. Then, if a second group is selected from among a plurality of groups based on the user input, the electronic device (100) may set the second group as the group corresponding to the first application, assign the first biometric information to the second group, and allow the user access to the first application.

[0094] That is, if a second group is selected from among multiple groups based on user input, the electronic device (100) may set the second group as the group corresponding to the first application without any additional process. However, if a second group is selected from among multiple groups based on user input, the electronic device (100) may set the group corresponding to the first application by performing an additional process as described below.

[0095] Meanwhile, the second group may be a group that already exists in the authentication data or a new group. That is, if the user input is to select a second group, which is one of the groups existing in the authentication data, the electronic device (100) may set the second group that already exists in the authentication data as the group corresponding to the first application. On the other hand, if the user input is to select a second group, which is a new group that does not exist in the authentication data, the electronic device (100) may create a second group in the authentication data and set the newly created second group as the group corresponding to the first application.

[0096] The electronic device (100) can identify whether second biometric information different from the first biometric information is assigned to the second group (S330). If second biometric information different from the first biometric information is assigned to the second group, the electronic device (100) can perform first additional user authentication based on the second biometric information (S340).

[0097] "First additional user authentication" refers to an authentication process performed during a user authentication process based on first biometric information to determine whether to assign the first biometric information to a second group along with the second biometric information. The first additional user authentication process may be performed based on whether the user enters biometric information identical to the second biometric information.

[0098] Specifically, if second biometric information that is different from the first biometric information is assigned to the second group, the electronic device (100) may request the user to input the second biometric information to determine whether to assign the first biometric information to the second group together with the second biometric information.

[0099] For example, when biometric information D is acquired in response to a request for user authentication by application K in a state where authentication data is constructed as in the example of FIG. 2, the electronic device (100) may perform a first additional user authentication based on biometric information A, which is biometric information assigned to group X, which is a group corresponding to application L, and determine whether to assign biometric information D to group X together with biometric information A.

[0100] If the first additional user authentication is successful (S350-Y), the electronic device (100) can set the second group as the group corresponding to the first application (S360). On the other hand, if the first additional user authentication fails (S350-N), the electronic device (100) can set a third group, different from the second group, as the group corresponding to the first application (S370).

[0101] Specifically, after the electronic device (100) requests the user to input second biometric information, if the user inputs biometric information identical to the second biometric information, the electronic device (100) may determine that the first additional user authentication is successful, set the second group as a group corresponding to the first application, and assign the first biometric information to the second group. Accordingly, both the first biometric information and the second biometric information corresponding to the second group can be used for user authentication for the first application.

[0102] On the other hand, if the electronic device (100) requests the user to input second biometric information and the user does not input biometric information identical to the second biometric information, the electronic device (100) may determine that the first additional user authentication has failed, set a new group, a third group, other than the second group, as the group corresponding to the first application, and assign the first biometric information to the third group. Accordingly, the second biometric information corresponding to the second group cannot be used for user authentication for the first application, and only the first biometric information corresponding to the third group can be used for user authentication for the first application.

[0103] Meanwhile, if one or more groups among the plurality of groups are not selected by the user, the electronic device (100) may set a fourth group (e.g., group ALL of FIG. 2) designated to perform user authentication for all applications among the plurality of groups as the group corresponding to the first application.

[0104] According to the embodiment described above with reference to FIG. 3, when setting a group corresponding to an application, the electronic device (100) can effectively prevent a third party from registering his / her own biometric information and accessing the application by assigning new biometric information to the group corresponding to the application only when user authentication is possible with already registered biometric information.

[0105]

[0106] FIG. 4 is a flowchart illustrating one or more embodiments related to deleting first biometric information after the first biometric information is assigned to a second group.

[0107] The electronic device (100) can assign the first biometric information to the second group (S410). That is, the description of FIG. 4 assumes that the first biometric information is assigned to the second group.

[0108] After the first biometric information is assigned to the second group, the electronic device (100) may receive a user input for deleting the first biometric information (S420). The user input for deleting the first biometric information may include a user input for deleting the previously registered first biometric information from the authentication data so that it is not used for user authentication.

[0109] When a user input for deleting the first biometric information is received, the electronic device (100) can identify whether second biometric information different from the first biometric information is assigned to the second group (S430).

[0110] If the second biometric information is assigned to the second group (S430-Y), the electronic device (100) can delete the first biometric information while maintaining the second group and the second biometric information in the authentication data (S440). On the other hand, if the second biometric information is not assigned to the second group (S430-N), the electronic device (100) can delete the information about the second group together with the first biometric information from the authentication data (S450).

[0111] For example, when a user input for deleting biometric information B is received in a state where authentication data is constructed as in the example of FIG. 2, the electronic device (100) can identify whether biometric information other than biometric information B is assigned to group Y assigned to biometric information B.

[0112] In the example of FIG. 2, since group Y is assigned biometric information B and other biometric information C, the electronic device (100) can update the authentication data to delete only biometric information B while maintaining group Y and biometric information C. On the other hand, unlike the example of FIG. 2, if group Y is not assigned biometric information B and other biometric information, there is no practical benefit in maintaining group Y, and therefore the electronic device (100) can update the authentication data to delete group Y together with biometric information B.

[0113] Meanwhile, if the second group is deleted while the second group is set as the group corresponding to the first application, the electronic device (100) can set the fifth group (e.g., group NONE of FIG. 2) for an application for which there is no biometric information capable of performing user authentication as the group corresponding to the first application.

[0114] Meanwhile, the above description assumes that a user input for deleting the first biometric information is received. However, the electronic device (100) can also receive a user input for deleting the second group. When a user input for deleting the second group is received, the electronic device (100) can delete the second group and all biometric information included in the second group from the authentication data.

[0115] Meanwhile, if the data for the first application is deleted after the first biometric information is assigned to the second group, the electronic device (100) may delete information indicating that the second group is set to perform user authentication for the first application from the authentication data. Here, the deletion of the data for the first application may include cases where the first application is removed (i.e., uninstalled) or data for various settings for the first application are deleted.

[0116] According to the embodiment described above with reference to FIG. 4, when deleting biometric information, the electronic device (100) can ensure reliability in managing biometric information by preventing other biometric information assigned to the same group as the biometric information to be deleted from being deleted.

[0117]

[0118] FIG. 5 is a diagram illustrating one or more embodiments related to assigning first biometric information to a third group after the first biometric information is assigned to a second group.

[0119] The electronic device (100) can assign the first biometric information to the second group (S510). That is, the description of FIG. 5 assumes that the first biometric information is assigned to the second group.

[0120] The electronic device (100) may receive a user input for assigning the first biometric information to a third group different from the second group (S520). The user input for assigning the first biometric information to a third group different from the second group may include a user input for assigning the first biometric information to the third group while maintaining the first biometric information's assignment to the second group, and a user input for assigning the first biometric information to the third group while canceling the first biometric information's assignment to the second group.

[0121] When a user input is received to assign the first biometric information to a third group different from the second group, the electronic device (100) can perform a second additional user authentication based on at least one biometric information included in the third group (S530).

[0122] "Second additional user authentication" refers to an authentication process performed based on at least one biometric information included in a third group, based on a user input for assigning the first biometric information to a third group different from the second group. That is, the second additional user authentication can be distinguished from the first additional user authentication (see FIG. 3) performed during the user authentication process based on the first biometric information in that it is performed based on a user input for assigning the first biometric information to a third group different from the second group.

[0123] Specifically, if the third group includes at least one biometric information, the electronic device (100) may request the user to input at least one biometric information included in the third group to determine whether to assign the first biometric information to the third group.

[0124] For example, when a user input for assigning biometric information A to group Y is received in a state where authentication data is constructed as in the example of FIG. 2, the electronic device (100) may perform a second additional user authentication based on at least one of biometric information B and biometric information C included in group Y, thereby determining whether to assign biometric information A to group Y together with biometric information B and biometric information C.

[0125] If the second additional user authentication is successful (S540-Y), the first biometric information may be assigned to the third group (S550). Conversely, if the second additional user authentication fails (S540-N), the first biometric information may not be assigned to the third group (S560).

[0126] Specifically, after the electronic device (100) requests input of at least one biometric information included in the third group, if the user inputs biometric information identical to at least one biometric information included in the third group, the electronic device (100) may determine that the second additional user authentication is successful and may assign the first biometric information to the third group. Accordingly, both the first biometric information and the at least one biometric information included in the third group may be used for user authentication for an application corresponding to the third group.

[0127] On the other hand, if the electronic device (100) requests input of at least one biometric information included in the third group, and the user does not input biometric information identical to at least one biometric information included in the third group, the electronic device (100) may determine that the second additional user authentication has failed and may not assign the first biometric information to the third group. Accordingly, the first biometric information may still be used only for user authentication for the first application, and may not be used for user authentication for applications corresponding to the third group.

[0128] According to the embodiment described above with reference to FIG. 5, when adding or changing a group corresponding to a specific application, the electronic device (100) allows addition or change of a group corresponding to the specific application only when user authentication is possible with biometric information already assigned to the group corresponding to the specific application, thereby effectively preventing a third party from registering his or her own biometric information to access the application.

[0129]

[0130] FIG. 6 is a diagram briefly showing the configuration of an electronic device (100) according to one or more embodiments of the present disclosure, and FIG. 7 is a diagram showing the configuration of an electronic device (100) according to one or more embodiments of the present disclosure in detail.

[0131] As illustrated in FIG. 6, the electronic device (100) according to the present disclosure includes a memory (110) and a processor (120). In addition, as illustrated in FIG. 7, the electronic device (100) according to the present disclosure may further include a communication unit (130), an input unit (140), and an output unit (150). However, the configurations illustrated in FIGS. 6 and 7 are merely exemplary, and it is to be understood that new configurations may be added or some configurations may be omitted in addition to the configurations illustrated in FIGS. 6 and 7 when implementing the present disclosure.

[0132] At least one instruction regarding the electronic device (100) may be stored in the memory (110). In addition, an O / S (Operating System) for driving the electronic device (100) may be stored in the memory (110). In addition, various software programs or applications for operating the electronic device (100) according to various embodiments of the present disclosure may be stored in the memory (110). In addition, the memory (110) may include a semiconductor memory such as a flash memory or a magnetic storage medium such as a hard disk.

[0133] Specifically, the memory (110) may store various software modules for operating the electronic device (100) according to various embodiments of the present disclosure, and the processor (120) may control the operation of the electronic device (100) by executing the various software modules stored in the memory (110). That is, the memory (110) is accessed by the processor (120), and data reading / recording / modifying / deleting / updating, etc., may be performed by the processor (120).

[0134] Meanwhile, in the present disclosure, the term memory (110) may be used to mean a memory (110), a ROM, a RAM in a processor (120), or a memory card (e.g., a micro SD card, a memory stick) mounted in an electronic device (100).

[0135] In particular, in one or more embodiments, the memory (110) may store authentication data in which different biometric information is divided into multiple groups. Specifically, the memory (110) may store authentication data including group division information, biometric information, and application setting information. In addition, the memory (110) may store information regarding a message requesting the setting of a group corresponding to a specific application, information regarding a message indicating that user authentication has failed, information regarding the time at which user authentication is requested by the application, information regarding the time at which biometric information is input, and the like.

[0136] In addition, various information necessary within the scope of achieving the purpose of the present disclosure may be stored in the memory (110), and the information stored in the memory (110) may be updated as received from an external device or input by a user.

[0137] The processor (120) controls the overall operation of the electronic device (100). Specifically, the processor (120) is connected to the configuration of the electronic device (100) including a memory (110), a communication unit (130), an input unit (140), and an output unit (150), and can control the overall operation of the electronic device (100) by executing at least one instruction stored in the memory (110) as described above.

[0138] The processor (120) may be implemented in various ways. For example, the processor (120) may be implemented as at least one of an application specific integrated circuit (ASIC), an embedded processor, a microprocessor, hardware control logic, a hardware finite state machine (FSM), and a digital signal processor (DSP). Meanwhile, the term "processor (120)" in the present disclosure may be used to mean a central processing unit (CPU), a graphic processing unit (GPU), and a microprocessor unit (MPU).

[0139] In particular, in one or more embodiments, the processor (120) may receive a request for user authentication by a first application. When the user's first biometric information is acquired in response to the request for user authentication by the first application, the processor (120) may identify whether the first biometric information is included in the authentication data.

[0140] When the first biometric information is included in the authentication data, the processor (120) can identify a first group corresponding to the first application among the multiple groups stored in the memory (110). Here, the multiple groups stored in the memory specifically refer to multiple groups that distinguish the authentication data stored in the memory.

[0141] Specifically, the electronic device (100) can perform a process of identifying whether a group corresponding to the first application exists among a plurality of groups, without completing user authentication simply by including the first biometric information in the authentication data.

[0142] If the first group is identified and the first biometric information corresponds to the authentication data included in the first group, the processor (120) may allow the user access to the first application. If the first group is not identified, the processor (120) may provide a message requesting the establishment of a group corresponding to the first application.

[0143] In one or more embodiments, the processor (120) may receive a user input in response to a message requesting the establishment of a group corresponding to the first application. If a second group is selected from among the plurality of groups based on the user input, the processor (120) may establish the second group as the group corresponding to the first application, assign the first biometric information to the second group, and allow the user access to the first application.

[0144] In one or more embodiments, if a second biometric information different from the first biometric information is assigned to the second group, and the second group is selected based on a user input, the processor (120) may perform a first additional user authentication based on the second biometric information. If the first additional user authentication is successful as a result of performing the first additional user authentication, the processor (120) may set the second group as a group corresponding to the first application. In addition, if the first additional user authentication fails, the processor (120) may set a third group different from the second group as a group corresponding to the first application.

[0145] In one or more embodiments, if the first biometric information is not included in the authentication data, the processor (120) may block the user's access to the first application and provide a message indicating that user authentication for the first application has failed.

[0146] In one or more embodiments, if the first biometric information does not correspond to authentication data included in the identified first group, the processor (120) may block the user's access to the first application and provide a message indicating that user authentication for the first application has failed.

[0147] Various embodiments according to the present disclosure based on the control of other processors (120) have been described above with reference to FIGS. 1 to 5, so a duplicate description of the same content will be omitted.

[0148] The communication unit (130) includes a circuit and can perform communication with an external device. Specifically, the processor (120) can receive various data or information from an external device connected via the communication unit (130) and can also transmit various data or information to the external device.

[0149] The communication unit (130) may include at least one of a WiFi module, a Bluetooth module, a wireless communication module, an NFC module, and a UWB (Ultra-Wide Band) module. Specifically, the WiFi module and the Bluetooth module may each perform communication in the WiFi or Bluetooth manner. When using a WiFi module or a Bluetooth module, various connection information, such as an SSID, may be first transmitted and received, and then communication may be established using this, after which various pieces of information may be transmitted and received.

[0150] In addition, the wireless communication module can perform communication according to various communication standards such as IEEE, Zigbee, 3G (3rd Generation), 3GPP (3rd Generation Partnership Project), LTE (Long Term Evolution), 5G (5th Generation), etc. And, the NFC module can perform communication in the NFC (Near Field Communication) method using the 13.56MHz band among various RF-ID frequency bands such as 135kHz, 13.56MHz, 433MHz, 860~960MHz, 2.45GHz, etc. In addition, the UWB module can accurately measure ToA (Time of Arrival), which is the time it takes for a pulse to reach a target, and AoA (Ange of Arrival), which is the pulse arrival angle at the transmitting device, through communication between UWB antennas, and accordingly, precise distance and location recognition is possible within an error range of several tens of centimeters indoors.

[0151] In particular, in one or more embodiments, the processor (120) may receive at least a portion of authentication data from an external device via the communication unit (130). In addition, the processor (120) may control the communication unit (130) to transmit information about a message for requesting the setting of a group corresponding to a specific application, information about a message indicating that user authentication has failed, and the like to an external device (e.g., another device having the same user as the electronic device (100)).

[0152] The input unit (140) includes a circuit, and the processor (120) can receive a user command to control the operation of the electronic device (100) through the input unit (140). Specifically, the input unit (140) can be configured with components such as a microphone, a camera, and a remote control signal receiving unit. In addition, the input unit (140) can also be implemented in a form included in a display as a touch screen. In particular, the microphone can receive a voice signal and convert the received voice signal into an electrical signal.

[0153] In particular, in one or more embodiments, the processor (120) may receive various user inputs, such as a user input for registering biometric information through the input unit (140), a user input for selecting a group corresponding to a plurality of group applications, a user input for deleting biometric information, a user input for assigning biometric information to another group, etc.

[0154] The output unit (150) includes a circuit, and the processor (120) can output various functions that the electronic device (100) can perform through the output unit (150). In addition, the output unit (150) can include at least one of a display, a speaker, and an indicator.

[0155] The display can output image data under the control of the processor (120). Specifically, the display can output an image previously stored in the memory (110) under the control of the processor (120). In particular, the display according to an embodiment of the present disclosure can also display a user interface stored in the memory (110). The display can be implemented as an LCD (Liquid Crystal Display Panel), an OLED (Organic Light Emitting Diodes), etc., and in some cases, the display can also be implemented as a flexible display, a transparent display, etc. However, the display according to the present disclosure is not limited to a specific type.

[0156] The speaker can output audio data under the control of the processor (120). The indicator can be turned on under the control of the processor (120). Specifically, the indicator can be turned on in various colors under the control of the processor (120). For example, the indicator can be implemented using a light emitting diode (LED), a liquid crystal display panel (LCD), a vacuum fluorescent display (VFD), etc., but is not limited thereto.

[0157] In particular, in one or more embodiments, the processor (120) may control the output unit (150) to output a message requesting to set a group corresponding to a specific application, a message indicating that user authentication has failed, etc. For example, the message requesting to set a group corresponding to a specific application, the message indicating that user authentication has failed, etc. may be output through a display in the form of a user interface including images and text, or may be output through a speaker in the form of voice.

[0158] Meanwhile, the control method of the electronic device (100) according to the above-described embodiments may be implemented as a program and provided to the electronic device (100). In particular, the program including the control method of the electronic device (100) may be stored and provided in a non-transitory computer readable medium.

[0159] Specifically, in a non-transitory computer-readable recording medium including a program for executing a method for controlling an electronic device (100), the method for controlling an electronic device (100) may include the steps of: receiving a request for user authentication by a first application; identifying, when first biometric information of a user in response to the request is acquired, whether the first biometric information is included in authentication data divided into a plurality of groups; identifying, when the first biometric information is included in the authentication data, a first group corresponding to the first application among the plurality of groups; allowing the user's access to the first application when the first group is identified and corresponds to the authentication data included in the first group; and providing a message for requesting setting a group corresponding to the first application when the first group is not identified.

[0160] In the above, a method for controlling an electronic device (100) and a computer-readable recording medium including a program for executing the method for controlling an electronic device (100) have been briefly described, but this is only to omit redundant descriptions, and it goes without saying that various embodiments of the electronic device (100) can also be applied to a method for controlling an electronic device (100) and a computer-readable recording medium including a program for executing the method for controlling an electronic device (100).

[0161] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, the term "non-transitory storage medium" simply means a tangible device that does not contain signals (e.g., electromagnetic waves). This term does not distinguish between cases where data is permanently stored in the storage medium and cases where data is temporarily stored. For example, a "non-transitory storage medium" may include a buffer in which data is temporarily stored.

[0162] According to one embodiment, the method according to various embodiments disclosed in the present document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smartphones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product (e.g., downloadable app) may be at least temporarily stored or temporarily created in a device-readable storage medium, such as a memory (110) of a manufacturer's server, an application store's server, or an intermediary server.

[0163] Each of the components (e.g., modules or programs) according to the various embodiments of the present disclosure as described above may be composed of a single or multiple entities, and some of the sub-components described above may be omitted, or other sub-components may be further included in the various embodiments. Alternatively or additionally, some components (e.g., modules or programs) may be integrated into a single entity, which may perform the same or similar functions as those performed by each of the respective components prior to integration.

[0164] According to various embodiments, operations performed by a module, program or other component may be executed sequentially, in parallel, iteratively or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.

[0165] Meanwhile, the terms "part" or "module" used in the present disclosure include units composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A "part" or "module" may be an integrally composed component, a minimum unit performing one or more functions, or a portion thereof. For example, a module may be composed of an application-specific integrated circuit (ASIC).

[0166] Various embodiments of the present disclosure may be implemented as software including instructions stored in a machine-readable storage medium that can be read by a machine (e.g., a computer). The device may include an electronic device (e.g., an electronic device (100)) according to the disclosed embodiments, which is a device capable of calling instructions stored in the storage medium and operating according to the called instructions.

[0167] When the above instruction is executed by the processor, the processor may perform the function corresponding to the instruction directly or by using other components under the control of the processor. The instruction may include code generated or executed by a compiler or interpreter.

[0168] Although the preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above, and various modifications may be made by a person having ordinary skill in the art to which the present disclosure pertains without departing from the gist of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical idea or prospect of the present disclosure.

Claims

1. In electronic devices, A memory for storing authentication data divided into multiple groups; and Receive a request for user authentication by the first application, When the user's first biometric information is obtained for the above request, it is identified whether the first biometric information is included in the authentication data, If the first biometric information is included in the authentication data, the first group corresponding to the first application among the plurality of groups stored in the memory is identified, If the first group is identified and the first biometric information corresponds to authentication data included in the first group, then the user's access to the first application is permitted, An electronic device comprising a processor for providing a message to request setting up a group corresponding to the first application if the first group is not identified.

2. In paragraph 1, The above processor, In response to the above message, receive user input from the user, An electronic device that, when a second group from among the plurality of groups is selected according to the user input, sets the second group as a group corresponding to the first application, assigns the first biometric information to the second group, and allows the user's access to the first application.

3. In paragraph 2, The above processor, If the second biometric information different from the first biometric information is assigned to the second group, and if the second group is selected according to the user input, the first additional user authentication is performed based on the second biometric information, If the above first additional user authentication is successful, the second group is set as a group corresponding to the first application, An electronic device that sets a third group, different from the second group, as a group corresponding to the first application if the first additional user authentication fails.

4. In paragraph 3, The above processor, An electronic device for setting a fourth group, which is pre-designated to perform user authentication for all applications among the plurality of groups, as a group corresponding to the first application if one or more groups among the plurality of groups are not selected by the user.

5. In paragraph 1, The above processor, An electronic device that blocks the user's access to the first application and provides a message indicating that user authentication for the first application has failed if the first biometric information is not included in the authentication data.

6. In paragraph 1, The above processor, An electronic device that blocks the user's access to the first application and provides a message indicating that user authentication for the first application has failed if the first biometric information does not correspond to authentication data included in the identified first group.

7. In paragraph 2, The above processor, When a user input for deleting the first biometric information is received after the first biometric information is assigned to the second group, it is identified whether second biometric information different from the first biometric information is assigned to the second group, If the second biometric information is assigned to the second group, the first biometric information is deleted while maintaining the second group and the second biometric information in the authentication data. An electronic device that deletes information about the second group together with the first biometric information from the authentication data if the second biometric information is not assigned to the second group.

8. In paragraph 7, The above processor, An electronic device that sets a fifth group for an application for which there is no biometric information capable of performing user authentication as a group corresponding to the first application when the second group is deleted.

9. In paragraph 2, The above processor, An electronic device that deletes information indicating that the second group is set to perform user authentication for the first application from the authentication data when the data for the first application is deleted after the first biometric information is assigned to the second group.

10. In paragraph 1, The above processor, If the first group is identified and the first biometric information corresponds to the authentication data included in the first group, the first time at which the request was received and the second time at which the first biometric information was entered are compared, An electronic device that blocks the user's access to the first application if the second time is later than the first time.

11. In paragraph 2, The above processor, After the first biometric information is assigned to the second group, when a user input is received to assign the first biometric information to a third group different from the second group, a second additional user authentication is performed based on at least one biometric information included in the third group, If the above second additional user authentication is successful, the first biometric information is assigned to the third group, An electronic device that does not assign the first biometric information to the third group if the second additional user authentication fails.

12. In a method for controlling an electronic device, A step of receiving a request for user authentication by a first application; When the user's first biometric information for the above request is acquired, a step of identifying whether the first biometric information is included in authentication data divided into a plurality of groups; If the first biometric information is included in the authentication data, a step of identifying a first group corresponding to the first application among the plurality of groups; If the first group is identified and the first biometric information corresponds to authentication data included in the first group, a step of allowing the user access to the first application; and A method of controlling an electronic device, comprising: providing a message for requesting to set a group corresponding to the first application if the first group is not identified; 13. In paragraph 12, The method of controlling the above electronic device is: receiving user input from the user in response to the above message; and A method for controlling an electronic device, further comprising: when a second group from among the plurality of groups is selected according to the user input, setting the second group as a group corresponding to the first application, assigning the first biometric information to the second group, and allowing the user's access to the first application; 14. In paragraph 13, The method of controlling the above electronic device is: When the second group is assigned second biometric information that is different from the first biometric information, a step of performing first additional user authentication based on the second biometric information when the second group is selected according to the user input; If the above first additional user authentication is successful, a step of setting the second group as a group corresponding to the first application; and A control method of an electronic device further comprising: if the first additional user authentication fails, setting a third group different from the second group as a group corresponding to the first application; 15. In paragraph 14, The method of controlling the above electronic device is: A control method of an electronic device further comprising: a step of setting a fourth group, which is pre-designated to perform user authentication for all applications among the plurality of groups, as a group corresponding to the first application if at least one group among the plurality of groups is not selected by the user;

Citation Information

Patent Citations

  • Permission management method and device of application program and electronic equipment

    CN112765582A

  • Fingerprint authenticating device and authenticating system

    JP2003085149A

  • Data-processing device and data-processing program with bio-authorization function

    KR1020110118829A

  • Antenna Device Using Metal Frame

    KR1020200144686A

  • Community biometric authentication on a smartphone

    US20150358316A1