Method for providing non-face-to-face authentication service of unmanned digital apparatus using security module and mobile identification card, and computing apparatus using same
The method uses a security module and mobile ID card for secure authentication and integrity verification in unmanned digital devices, addressing vulnerabilities and ensuring secure non-face-to-face transactions by verifying software integrity and performing secure authentication.
Patent Information
- Application Number
- PCT/KR2024/016124
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-16
- Filing Date
- 2024-10-23
- Publication Date
- 2025-07-24
AI Technical Summary
Unmanned digital devices face security vulnerabilities that can lead to leakage of sensitive personal information and unauthorized access, with potential for malware attacks and hacking of national mobile ID systems, necessitating enhanced security measures for authentication and software integrity verification.
A method utilizing a security module and mobile ID card for non-face-to-face authentication, involving software integrity verification, device authentication, and user authentication through an authentication server using encryption/decryption session keys and a mobile ID blockchain network, ensuring secure communication and data protection.
Enhances security by verifying software integrity and performing secure authentication, preventing information leakage and unauthorized access, while ensuring secure communication and data protection in non-face-to-face transactions.
Smart Images

Figure KR2024016124_24072025_PF_FP_ABST
Abstract
Description
Method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card, and a computing device using the same
[0001] The present invention relates to a method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card, and to a computing device using the same.
[0002] With the spread of contactless culture, more and more stores are utilizing in-store unmanned digital devices, such as kiosks, to provide contactless services to consumers. To meet the needs of consumers who have become accustomed to face-to-face transactions and reduce operating costs, these devices are increasingly being used to provide contactless services. Meanwhile, some unmanned digital devices, which offer specific products and / or services to specific individuals, handle sensitive information, such as personal and payment information. However, if the security of these devices themselves is compromised, sensitive personal information about individuals may not be protected and could be leaked to third parties.
[0003] In addition, due to the security vulnerabilities of unmanned digital devices, there is a problem that third parties can falsify the SW (firmware) of unmanned digital devices and perform various malicious acts using illegal SW such as malware, ransomware, and botnets. In addition, there is a problem that the national mobile ID system can be hacked by accessing the national mobile ID server using unmanned digital devices.
[0004] Therefore, there is a need for technology that enhances security to prevent leakage of personal information and payment information in two-way communication between the authentication server that performs user authentication and the unmanned digital device, and to check for illegal forgery or alteration of the unmanned digital device.
[0005] The purpose of the present invention is to solve all of the above-described problems.
[0006] In addition, the present invention has another purpose in that a computing device controlling an unmanned digital device verifies the integrity of software for the operation of the unmanned digital device through a security module corresponding to the unmanned digital device, and, when the integrity of the software is verified, executes the software to control the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module.
[0007] In addition, the present invention has another purpose in that, when request information for provision of a specific product or a specific service from a user is obtained from an unmanned digital device, a computing device requests user authentication through the unmanned digital device, and when user authentication information is obtained from a user terminal corresponding to the user, the computing device encrypts the user authentication information using a first encryption / decryption session key through a security module and transmits the encrypted user authentication information to an authentication server, so that the authentication server decrypts the encrypted user authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the user authentication information, obtains a user VP from a relay server with reference to the user authentication information, and performs user authentication on the user through a mobile ID blockchain network corresponding to the user's mobile ID using the user VP.
[0008] In order to achieve the purpose of the present invention as described above and to realize the characteristic effects of the present invention described below, the characteristic configuration of the present invention is as follows.
[0009] According to one aspect of the present invention, there is provided a method for providing a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID, comprising: (a) when a power-on signal to an unmanned digital device is obtained or a drive control signal of software for the operation of the unmanned digital device is obtained, a computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, drives the software to control the unmanned digital device, and performs device authentication of the unmanned digital device through interaction with an authentication server using the security module;(b) When request information for provision of a specific product or a specific service from a user is obtained from the unmanned digital device, the computing device requests user authentication through the unmanned digital device, and when user authentication information from a user terminal corresponding to the user - the user authentication information including at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID, and location information of the user VP stored in the relay server - is obtained through the unmanned digital device, the security module transmits the encrypted user authentication information encrypted using a first encryption / decryption session key to the authentication server, causing the authentication server to decrypt the encrypted user authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the user authentication information, obtain the user VP from the relay server with reference to the user authentication information, and use the user VP to perform a mobile ID blockchain network corresponding to the user mobile ID. A method is disclosed, comprising: (a) performing the user authentication for the user; and (c) when the user authentication is performed by the authentication server, (d) providing the computing device with the specific product or specific service requested by the user through the unmanned digital device.
[0010] As an example, in the step (a), the computing device (i) obtains a security module ID stored in the security module and a first security module nonce generated in the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server authentication data obtained by encrypting the server ID and the first security module nonce with a server authentication key, and a first server nonce to the computing device, (ii) if the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module so that the security module decrypts the server authentication data using a security module authentication key corresponding to the server authentication key, thereby obtaining the server ID and the decrypted first security module nonce, and if the decrypted first security module nonce is transmitted to the first security module (iii) transmit the security module authentication data generated through the security module to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and confirm whether the decrypted first server nonce matches the first server nonce; (iv) cause the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce;A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key by using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key by using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key, and from the authentication server, the server authentication session key is generated by referencing the server authentication key, the first security module nonce, and the first server nonce, and a server integrity verification key is generated by referencing the server authentication session key and the first server nonce, and when an encrypted server integrity verification key that encrypts the server integrity verification key by using the server authentication session key is obtained, causing the security module to use the security module authentication session key to decrypt the encrypted server integrity verification key. A method is disclosed, characterized in that device authentication for the unmanned digital device is performed by performing a process of verifying the server integrity verification key by decrypting it.
[0011] As an example, in the step (b), the computing device (i) acquires the security module ID stored in the security module and the second security module nonce generated in the security module through interaction with the security module, transmits the security module ID and the second security module nonce to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits the server ID and the server encrypted data obtained by encrypting the second security module nonce with a server encryption key, and the second server nonce to the computing device, (ii) if the server encrypted data and the second server nonce are acquired from the authentication server, transmits the server encrypted data and the second server nonce to the security module so that the security module decrypts the server encrypted data using a security module encryption key corresponding to the server encryption key, thereby acquiring the server ID and the decrypted second security module nonce, and if the decrypted second security module nonce is used as the second A process for checking whether the second security module nonce matches the security module nonce, and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, generating security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key, (iii) transmitting the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and checking whether the decrypted second server nonce matches the second server nonce, (iv) causing the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce.And a method is disclosed characterized in that it performs a process for causing the authentication server to generate the second encryption / decryption session key by referring to the server encryption key, the second security module nonce, and the second server nonce when it is confirmed that the decrypted second server nonce and the second server nonce match.
[0012] As an example, in the step (b), the computing device performs the user authentication by causing the authentication server to obtain a user public key corresponding to the user DID from the mobile ID blockchain network using the user DID corresponding to the user VP, to decrypt the user VP using the user public key to obtain at least one user VC (Verifiable Credential), to obtain a mobile ID issuance server public key corresponding to the mobile ID issuance server DID from the mobile ID blockchain network using the mobile ID issuance server DID included in the user VC, and to verify the user VC by verifying the mobile ID issuance server signature value included in the user VC using the mobile ID issuance server public key.
[0013] As an example, in the step (b), a method is disclosed in which the computing device acquires a user DID corresponding to the user VP from the user terminal by adding the user authentication information through the unmanned digital device, or causes the user terminal to transmit the user DID to the relay server by adding the user VP to the user DID, thereby acquiring the user DID through the relay server.
[0014] As an example, in the step (b), a method is disclosed in which the computing device acquires the user authentication information by scanning a QR code corresponding to the user authentication information displayed on the user terminal through the unmanned digital device, or acquires the user authentication information through wireless communication with the user terminal through the unmanned digital device.
[0015] As an example, in step (a), a method is disclosed in which the computing device verifies the integrity of the software by confirming that a first hash value stored in the security module, the first hash value being a hash value of the software authenticated for the operation of the unmanned digital device, and a second hash value generated by hashing the software are identical.
[0016] As an example, a method is disclosed in which the security module is a hardware security module including at least some of a memory card, a processor card, a smart card, a SMD (Surface-Mount Device) type chip card, and an external storage device.
[0017] According to another aspect of the present invention, a computing device providing a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID card comprises: a memory storing instructions for providing the non-face-to-face authentication service of the unmanned digital device using the security module and the mobile ID card; And a processor for performing an operation for providing the non-face-to-face authentication service of the unmanned digital device using the security module and the mobile ID according to the instructions stored in the memory; wherein the processor comprises: (I) a process for verifying the integrity of the software through a security module corresponding to the unmanned digital device when a power-on signal to the unmanned digital device is obtained or a drive control signal of software for the operation of the unmanned digital device is obtained, and for performing control of the unmanned digital device by driving the software when the integrity of the software is verified, and for performing device authentication of the unmanned digital device through interaction with an authentication server using the security module; (II) a process for requesting user authentication through the unmanned digital device when request information for provision of a specific product or specific service from a user is obtained from the unmanned digital device, and for providing user authentication information from a user terminal corresponding to the user - the user authentication information includes a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID; And at least one of the location information of the user VP stored in the relay server - is obtained through the unmanned digital device, the encrypted user authentication information is encrypted using the first encryption / decryption session key through the security module, and the authentication server transmits the encrypted user authentication information to the authentication server, so that the authentication server can:A computing device is disclosed, characterized in that it performs a process of decrypting the encrypted user authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the user authentication information, obtaining the user VP from the relay server with reference to the user authentication information, and performing the user authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP, and (III) when the user authentication for the user is performed from the authentication server, it performs a process of providing the specific product or specific service requested by the user through the unmanned digital device.
[0018] As an example, the processor, in the (I) process, (i) obtains a security module ID stored in the security module and a first security module nonce generated in the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits server authentication data obtained by encrypting the server ID and the first security module nonce with a server authentication key, and a first server nonce to the computing device, and (ii) if the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module so that the security module decrypts the server authentication data using a security module authentication key corresponding to the server authentication key, thereby obtaining the server ID and the decrypted first security module nonce, and if the decrypted first security module nonce is used for the first To check whether the first security module nonce matches the security module nonce, and if it is confirmed that the decrypted first security module nonce matches the first security module nonce, to generate security module authentication data by encrypting the security module ID and the first server nonce using the security module authentication key, (iii) to transmit the security module authentication data generated through the security module to the authentication server, and to cause the authentication server to decrypt the security module authentication data using the server authentication key, thereby obtaining the security module ID and the decrypted first server nonce, and to confirm whether the decrypted first server nonce matches the first server nonce, (iv) to cause the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce,A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key by using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key by using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key, and from the authentication server, the server authentication session key is generated by referencing the server authentication key, the first security module nonce, and the first server nonce, and a server integrity verification key is generated by referencing the server authentication session key and the first server nonce, and when an encrypted server integrity verification key that encrypts the server integrity verification key by using the server authentication session key is obtained, causing the security module to use the security module authentication session key to decrypt the encrypted server integrity verification key. A computing device is disclosed, characterized in that it performs device authentication for the unmanned digital device by performing a process of verifying the server integrity verification key by decrypting it.
[0019] As an example, in the process (II), the processor (i) obtains the security module ID stored in the security module and the second security module nonce generated in the security module through interaction with the security module, transmits the security module ID and the second security module nonce to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, transmits the server ID and the server encrypted data obtained by encrypting the second security module nonce with a server encryption key, and the second server nonce to the computing device, and (ii) if the server encrypted data and the second server nonce are obtained from the authentication server, transmits the server encrypted data and the second server nonce to the security module so that the security module decrypts the server encrypted data using a security module encryption key corresponding to the server encryption key, thereby obtaining the server ID and the decrypted second security module nonce, and if the decrypted second security module nonce is used as the second A process for checking whether the second security module nonce matches the security module nonce, and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, generating security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key, (iii) transmitting the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and checking whether the decrypted second server nonce matches the second server nonce, (iv) causing the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce.And a computing device is disclosed characterized in that it performs a process for causing the authentication server to generate the second encryption / decryption session key by referring to the server encryption key, the second security module nonce, and the second server nonce when it is confirmed that the decrypted second server nonce and the second server nonce match.
[0020] As an example, the processor, in the process (II), causes the authentication server to obtain a user public key corresponding to the user DID from the mobile ID blockchain network using the user DID corresponding to the user VP, to decrypt the user VP using the user public key to obtain at least one user VC (Verifiable Credential), to obtain a mobile ID issuance server public key corresponding to the mobile ID issuance server DID from the mobile ID blockchain network using the mobile ID issuance server DID included in the user VC, and to verify the user VC by verifying the mobile ID issuance server signature value included in the user VC using the mobile ID issuance server public key, thereby performing the user authentication.
[0021] As an example, a computing device is disclosed, characterized in that, in the process (II), the processor acquires a user DID corresponding to the user VP from the user terminal by adding the user authentication information through the unmanned digital device, or causes the user terminal to transmit the user DID to the relay server by adding the user VP to the user DID, thereby acquiring the user DID through the relay server.
[0022] As an example, a computing device is disclosed in which the processor acquires the user authentication information by scanning a QR code corresponding to the user authentication information displayed on the user terminal through the unmanned digital device in the process (II), or acquires the user authentication information through wireless communication with the user terminal through the unmanned digital device.
[0023] As an example, a computing device is disclosed, characterized in that the processor verifies the integrity of the software by confirming that, in the process (I), a first hash value stored in the security module, the first hash value being a value obtained by hashing the software authenticated for the operation of the unmanned digital device, and a second hash value generated by hashing the software are identical.
[0024] As an example, a computing device is disclosed, characterized in that the security module is a hardware security module including at least some of a memory card, a processor card, a smart card, a SMD (Surface-Mount Device) type chip card, and an external storage device.
[0025] The present invention has the effect of a computing device controlling an unmanned digital device verifying the integrity of software for the operation of the unmanned digital device through a security module corresponding to the unmanned digital device, executing the software to control the unmanned digital device when the integrity of the software is verified, and performing device authentication of the unmanned digital device through interaction with an authentication server using the security module.
[0026] In addition, the present invention has the effect of when a request for provision of a specific product or a specific service from a user is obtained from an unmanned digital device, a computing device requests user authentication through the unmanned digital device, and when authentication information is obtained from a user terminal corresponding to the user, the computing device transmits encrypted authentication information encrypted using a first encryption / decryption session key through a security module to an authentication server, causing the authentication server to decrypt the encrypted authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the authentication information, obtain a user VP from a relay server with reference to the authentication information, and performs authentication of the user through a mobile ID blockchain network corresponding to the user's mobile ID using the user VP.
[0027] The drawings attached below for use in explaining embodiments of the present invention are only some of the embodiments of the present invention, and a person having ordinary knowledge in the technical field to which the present invention pertains (hereinafter “ordinary skilled in the art”) can obtain other drawings based on these drawings without performing an inventive work.
[0028] FIG. 1 schematically illustrates a computing device that provides a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to one embodiment of the present invention.
[0029] FIG. 2 is a flowchart for explaining the sequence of a method for providing a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID card according to one embodiment of the present invention.
[0030] FIGS. 3A and 3B schematically illustrate a series of processes for exchanging a security module ID, an authentication server ID, a first security module nonce, and a first server nonce between a security module and an authentication server according to one embodiment of the present invention, and a series of processes for performing device authentication for an unmanned digital device using a security module authentication session key, a security module integrity verification key, a server authentication session key, and a server integrity verification key.
[0031] FIG. 4 schematically illustrates a series of processes for generating a first encryption / decryption session key and a second encryption / decryption session key by exchanging a security module ID, an authentication server ID, a second security module nonce, and a second server nonce between a security module and an authentication server according to one embodiment of the present invention.
[0032] FIG. 5 schematically illustrates a process for verifying a DID-based mobile ID according to one embodiment of the present invention.
[0033] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be implemented in other embodiments without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each disclosed embodiment may be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not intended to be limiting, and the scope of the present invention is defined only by the appended claims, along with the full scope of equivalents to which such claims are entitled, if properly described. Like reference numerals in the drawings designate the same or similar functionality throughout the several aspects.
[0034] Hereinafter, in order to enable a person having ordinary skill in the art to easily practice the present invention, preferred embodiments of the present invention will be described in detail with reference to the attached drawings.
[0035] FIG. 1 schematically illustrates a computing device that provides a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card according to one embodiment of the present invention.
[0036] Referring to FIG. 1, a computing device (100) that provides a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID may include a memory (110) in which instructions for providing a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID are stored, and a processor (120) that performs operations for providing a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID according to the instructions stored in the memory. That is, the memory (110) of the computing device (100) may store instructions to be performed by the processor (120). Specifically, the instructions are codes generated for the purpose of causing the computing device (100) to function in a specific manner, and may be stored in a computer-available or computer-readable memory that may be directed to a computer or other programmable data processing equipment, and the instructions may perform processes for executing functions described in the specification of the present invention.
[0037] In addition, the processor (120) of the computing device (100) may include hardware configurations such as a Micro Processing Unit (MPU) or a Central Processing Unit (CPU), cache memory, and a data bus. In addition, the computing device (100) may further include a software configuration of an operating system and an application that performs a specific purpose.
[0038] In addition, although not shown in FIG. 1, a security module according to one embodiment of the present invention may be a hardware security module including at least some of a memory card, a processor card, a smart card, a SMD (Surface-Mount Device) type chip card, and an external storage device.
[0039] A method using a computing device (100) according to one embodiment of the present invention configured as described above is described below with reference to FIG. 2.
[0040] FIG. 2 is a flowchart illustrating the sequence of a method for providing a non-face-to-face authentication service of an unmanned digital device using a security module and a mobile ID card according to one embodiment of the present invention.
[0041] Referring to FIG. 2, when a power-on signal for an unmanned digital device is acquired or a control signal for operating software for the operation of the unmanned digital device is acquired, the computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, the computing device executes the software to control the unmanned digital device, and performs device authentication for the unmanned digital device through interaction with an authentication server using the security module (S201).
[0042] Here, the integrity verification of the software is performed by comparing the software hash value stored in the security module with the software hash value of the unmanned digital device. More specifically, the computing device (100) verifies the integrity of the software by confirming whether the first hash value stored in the security module (the first hash value is a hash value of the software certified for the operation of the unmanned digital device) and the second hash value generated by hashing the software are identical. At this time, if it is determined that the first hash value and the second hash value match, the software can be successfully operated, and the computing device (100) can control the unmanned digital device.
[0043] In addition, the computing device (100) can perform device authentication for an unmanned digital device through interaction with an authentication server using a security module. For a more specific explanation, this will be described herein with reference to FIGS. 3a and 3b.
[0044] FIGS. 3A and 3B schematically illustrate a series of processes for exchanging and verifying a security module ID, an authentication server ID, a first security module nonce, and a first server nonce between a security module (500) and an authentication server (600) according to one embodiment of the present invention, and a series of processes for generating a security module authentication session key, a security module integrity verification key, a server authentication session key, and a server integrity verification key and performing device authentication for an unmanned digital device using the same.
[0045] First, referring to FIG. 3A, the computing device (100) obtains the security module ID stored in the security module (500) and the first security module nonce generated in the security module (500) through interaction with the security module (500) (S11), and transmits the security module ID and the first security module nonce to the authentication server (600) (S12). Next, the computing device (100) causes the authentication server (600) to perform a security module ID validity verification process (S13) to confirm whether the security module ID is a registered valid ID. At this time, the security module ID may be registered in advance with the authentication server (600), and the authentication server (600) confirms whether the pre-registered security module ID and the security module ID obtained through the computing device (100) are identical. At this time, if it is confirmed that the security module ID registered in advance and the security module ID acquired through the computing device (100) are the same, the authentication server (600) encrypts the server ID and the first security module nonce with the server authentication key (S14), and transmits the encrypted server authentication data (here, the server authentication data includes the server ID encrypted with the server authentication key and the first security module nonce encrypted with the server authentication key) and the first server nonce to the computing device (100) (S15). Meanwhile, the server authentication key may be generated by inputting the security module ID and the first authentication master key stored in the authentication server (600) into a key derivation function, but is not limited thereto.
[0046] Next, the computing device (100) transmits the server authentication data and the first server nonce to the security module (500) (S16), so that the security module (500) decrypts the server authentication data using a security module authentication key corresponding to the server authentication key to obtain a server ID and a decrypted first security module nonce, and performs a first security module nonce verification process (S17) to confirm whether the decrypted first security module nonce matches the first security module nonce. At this time, if it is confirmed that the decrypted first security module nonce matches the first security module nonce, the computing device (100) causes the security module (500) to generate security module authentication data (here, the security module authentication data includes a security module ID encrypted with the security module authentication key and a first server nonce encrypted with the security module authentication key) (S18). Meanwhile, the security module authentication key may be generated by inputting the security module ID and the second authentication master key stored in the security module (500) into the key derivation function, but is not limited thereto. In addition, the first authentication master key stored in the authentication server (600) and the second authentication master key stored in the security module (500) may be formed of symmetric keys, but the present invention is not limited thereto, and the first authentication master key and the second authentication master key may be formed of asymmetric keys.
[0047] Next, the computing device (100) transmits the security module authentication data generated through the security module (500) to the authentication server (600) (S19), causing the authentication server (600) to decrypt the security module authentication data using the server authentication key to obtain a security module ID and a decrypted first server nonce, and performs a first server nonce verification process (S20) to confirm whether the decrypted first server nonce matches the first server nonce. At this time, if it is confirmed that the decrypted first server nonce matches the first server nonce, a device authentication process for performing device authentication for an unmanned digital device is performed. A more specific description of the device authentication process will be described with reference to FIG. 3b.
[0048] Referring to FIG. 3b, the computing device (100) can cause the security module (500) to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce, and to generate a security module integrity verification key by referencing the security module authentication session key and the first security module nonce (S21). Here, the security module authentication session key can be generated by inputting the security module authentication key and the first security module nonce into a key derivation function, and then re-inputting them into the key derivation function together with the first server nonce, but is not limited thereto, and the security module integrity verification key can be generated by using a symmetric key encryption algorithm, the security module authentication session key, and the first security module nonce, but is not limited thereto. Next, the computing device (100) causes the security module (500) to encrypt (S22) the security module integrity verification key using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module (500), the computing device transmits (S23) the encrypted security module integrity verification key to the authentication server (600).
[0049] At this time, the authentication server (600) can verify the security module integrity verification key by decrypting the encrypted security module integrity verification key using the server authentication session key corresponding to the security module authentication session key (S24). Here, the server authentication session key can be generated with reference to the server authentication key, the first security module nonce, and the first server nonce, and more specifically, it can be generated by inputting the server authentication key and the first security module nonce into a key derivation function, and then re-inputting them together with the first server nonce into the key derivation function, but is not limited thereto. Next, the authentication server (600) encrypts the server integrity verification key using the server authentication session key (S25), and transmits the encrypted security module integrity verification key to the security module (500) via the computing device (100) (S26). Here, the server integrity verification key can be generated using a symmetric key encryption algorithm, the server authentication session key, and the first server nonce, but is not limited thereto. Next, when the encrypted server integrity verification key is obtained, the security module (500) decrypts the encrypted server integrity verification key using the security module authentication session key and verifies the server integrity verification key (S27), thereby performing device authentication for the unmanned digital device. Meanwhile, the security module authentication session key and the server authentication session key may be formed of a symmetric key, but the present invention is not limited thereto, and the security module authentication session key and the server authentication session key may be formed of an asymmetric key. Next, the computing device (100) can perform user authentication for the unmanned digital device, and for a detailed explanation thereof, this will be described again with reference to FIG. 2.
[0050] Referring back to FIG. 2, when request information for provision of a specific product or a specific service from a user is obtained from an unmanned digital device, the computing device (100) requests user authentication through the unmanned digital device, and when user authentication information from a user terminal corresponding to the user (the user authentication information includes at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP corresponding to the user mobile ID, and location information of the user VP stored in the relay server) is obtained through the unmanned digital device, the security module (500) transmits encrypted user authentication information encrypted using a first encryption / decryption session key to an authentication server, so that the authentication server decrypts the encrypted user authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain user authentication information, obtains the user VP from the relay server with reference to the user authentication information, and performs user authentication on the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP. (S202).
[0051] At this time, when the user authentication information from the user terminal is obtained through an unmanned digital device, the computing device (100) can create an encrypted communication channel with the authentication server (600). For a more specific explanation, this will be described here with reference to FIG. 4.
[0052] FIG. 4 schematically illustrates a series of processes for generating a first encryption / decryption session key and a second encryption / decryption session key by exchanging a security module ID, an authentication server ID, a second security module nonce, and a second server nonce between a security module (500) and an authentication server (600) according to one embodiment of the present invention.
[0053] Referring to FIG. 4, the computing device (100) obtains a security module ID stored in the security module (500) and a second security module nonce generated in the security module (500) through interaction with the security module (500) (S31), and transmits the security module ID and the second security module nonce to the authentication server (600) (S32). Next, the computing device (100) causes the authentication server (600) to perform a security module ID validity verification process (S33) to confirm whether the security module ID is a registered valid ID. At this time, the security module ID may be registered in advance with the authentication server (600), and the authentication server (600) confirms whether the pre-registered security module ID and the security module ID obtained through the computing device (100) are identical. At this time, if it is confirmed that the security module ID registered in advance and the security module ID acquired through the computing device (100) are the same, the authentication server (600) encrypts the server ID and the second security module nonce with a server encryption key (S34), and transmits the encrypted server encryption data (here, the server encryption data includes the server ID encrypted with the server encryption key and the second security module nonce encrypted with the server encryption key) and the second server nonce to the computing device (100) (S35). Meanwhile, the server encryption key may be generated by inputting the security module ID and the first encryption master key stored in the authentication server (600) into a key derivation function, but is not limited thereto.
[0054] Next, the computing device (100) transmits the server encrypted data and the second server nonce to the security module (500) (S36), so that the security module (500) decrypts the server encrypted data using a security module encryption key corresponding to the server encryption key, thereby obtaining a server ID and a decrypted second security module nonce, and performs a second security module nonce verification process (S37) to confirm whether the decrypted second security module nonce matches the second security module nonce. At this time, if it is confirmed that the decrypted second security module nonce matches the second security module nonce, the computing device (100) causes the security module (500) to generate security module encrypted data (here, the security module encrypted data includes the security module ID encrypted with the security module encryption key and the second server nonce encrypted with the security module encryption key) (S38). Meanwhile, the security module encryption key may be generated by inputting the security module ID and the second encryption master key stored in the security module (500) into the key derivation function, but is not limited thereto. In addition, the first encryption master key stored in the authentication server (600) and the second encryption master key stored in the security module (500) may be formed of symmetric keys, but the present invention is not limited thereto, and the first encryption master key and the second encryption master key may be formed of asymmetric keys.
[0055] Next, the computing device (100) transmits the security module encrypted data generated through the security module (500) to the authentication server (600) (S39), causing the authentication server (600) to decrypt the security module encrypted data using the server encryption key to obtain a security module ID and a decrypted second server nonce, and performs a second server nonce verification process (S40) to confirm whether the decrypted second server nonce matches the second server nonce. At this time, if it is confirmed that the decrypted second server nonce matches the second server nonce, the computing device (100) can cause the security module (500) to generate a first encryption / decryption session key (S41) by referencing the security module encryption key, the second security module nonce, and the second server nonce, and can cause the authentication server (600) to generate a second encryption / decryption session key (S42) by referencing the server encryption key, the second security module nonce, and the second server nonce. Meanwhile, the first encryption / decryption session key can be generated by inputting the security module encryption key and the second security module nonce into a key derivation function, and then re-inputting them into the key derivation function together with the second server nonce, but is not limited thereto, and the second encryption / decryption session key can be generated by inputting the server encryption key and the second security module nonce into a key derivation function, and then re-inputting them into the key derivation function together with the second server nonce, but is not limited thereto.
[0056] In addition, the exchange of the second security module nonce and the second server nonce between the security module (500) and the authentication server (600) may be performed by the security module (500) directly transmitting the second security module nonce to the authentication server (600) via the computing device (100) or transmitting an encrypted second security module nonce encrypted with the security module encryption key to the authentication server (600), but is not limited thereto, and conversely, the exchange may be performed by the authentication server (600) directly transmitting the second server nonce to the security module (500) via the computing device (100) or transmitting an encrypted second server nonce encrypted with the server encryption key to the security module (500), but is not limited thereto. In addition, the first encryption / decryption session key and the second encryption / decryption session key may be formed of symmetric keys, but the present invention is not limited thereto, and the first encryption / decryption session key and the second encryption / decryption session key may be formed of asymmetric keys.
[0057] In this way, when an encrypted communication channel is created using the first encryption / decryption session key and the second encryption / decryption session key between the computing device (100), i.e., the security module (500) and the authentication server (600), the security module (500) can use the first encryption / decryption session key to encrypt the user authentication information to be transmitted to the authentication server (600), and the user authentication information encrypted by the first encryption / decryption session key can be transmitted to the authentication server (600) through the encrypted communication channel. At this time, the authentication server (600) can use the second encryption / decryption session key to decrypt the obtained encrypted user authentication information.
[0058] Meanwhile, the first encryption / decryption session key and the second encryption / decryption session key can encrypt and decrypt information other than user authentication information. For example, the authentication server (600) can use the second encryption / decryption session key to encrypt user authentication result information to be transmitted to the security module (500), and the user authentication result information encrypted by the second encryption / decryption session key can be transmitted to the security module (500) through an encrypted communication channel. At this time, the security module (500) can use the first encryption / decryption session key to decrypt the obtained encrypted user authentication result information.
[0059] That is, the computing device (100) transmits encrypted user authentication information encrypted using a first encryption / decryption session key to the authentication server (600) through an encrypted communication channel via the security module (500), causes the authentication server (600) to decrypt the encrypted user authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain user authentication information, obtain a user VP from a relay server with reference to the user authentication information, perform user authentication on the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP, and encrypt user authentication result information corresponding to the user authentication using the second encryption / decryption session key to obtain encrypted user authentication result information, and when the encrypted user authentication result information is obtained from the authentication server (600) through the encrypted communication channel, the computing device (100) causes the security module (500) to decrypt the encrypted user authentication result information using the first encryption / decryption session key. By obtaining decrypted user authentication result information, user authentication is completed. At this time, although the authentication server (600) was described above as obtaining the user VP from the relay server, the user VP can also be obtained through encrypted communication by creating an encrypted communication channel between the authentication server (600) and the relay server through a method similar to the encrypted communication channel between the authentication server (600) and the computing device (100).
[0060] Meanwhile, user authentication information can be obtained through unmanned digital devices in various ways. For example, user authentication information can be obtained by scanning a QR code corresponding to user authentication information displayed on a user terminal, or user authentication information can be obtained through wireless communication with a user terminal, but is not limited thereto.
[0061] Next, a method for a computing device (100) according to one embodiment of the present invention to obtain a user DID will be described.
[0062] First, based on a user interaction for creating a user DID, the user terminal requests the mobile ID blockchain network to create a user DID. Accordingly, the mobile ID blockchain network creates a user DID and registers a mobile ID DID corresponding to the user DID in the distributed ledger of the mobile ID blockchain network. At this time, the mobile ID DID may include a user DID, a user public key, user VC issuance information, etc. At this time, the user private key corresponding to the user public key may be stored in the user terminal.
[0063] Thereafter, when a request for provision of a specific product and / or a specific service from a user is obtained from an unmanned digital device, the computing device (100) may request a user DID from the user terminal. At this time, the user terminal may provide at least one user mobile identification VC required for user authentication, a user VP encrypted with a user private key, a user DID, and at least a portion of the user authentication information to the computing device (100) through the unmanned digital device. At this time, the computing device (100) may cause the authentication server (600) to perform user authentication on the user in response to the request for provision of a specific product and / or a specific service from the user terminal.
[0064] That is, the computing device (100) requests the user for at least a portion of the user VP, the user DID, and the user authentication information through an unmanned digital device, and when the user VP, the user DID, and the user authentication information are obtained from the user terminal, the computing device (100) can perform user authentication by having the authentication server (600) verify them.
[0065] For example, the computing device (100) can obtain a user DID corresponding to a user VP from a user terminal by adding the user authentication information through an unmanned digital device. In this case, the computing device (100) can cause the security module (500) to encrypt the user DID and the user authentication information with a first encryption / decryption session key, transmit the encrypted user DID and the encrypted user authentication information to the authentication server (600), and cause the authentication server (600) to decrypt the information with a second encryption / decryption session key, thereby obtaining the decrypted user DID and the decrypted user authentication information.
[0066] As another example, the computing device (100) can obtain the user DID through the relay server by causing the user terminal to transmit the user DID to the relay server in addition to the user VP. In this case, the authentication server (600) encrypts the user DID and the user VP with a second encryption / decryption session key, and then transmits the encrypted user DID and the encrypted user VP to the computing device (100). The computing device (100) can cause the security module (500) to decrypt the encrypted user DID and the encrypted user VP with the first encryption / decryption session key, thereby obtaining the decrypted user DID and the decrypted user VP.
[0067] Next, the computing device (100) can perform a mobile ID verification process for verifying a DID-based mobile ID, which will be described in detail with reference to FIG. 5.
[0068] FIG. 5 schematically illustrates a process for verifying a DID-based mobile ID according to one embodiment of the present invention.
[0069] Referring to FIG. 5, the computing device (100) causes the authentication server (600) to obtain a user public key corresponding to the user DID from the mobile ID blockchain network using the user DID corresponding to the user VP (S501). More specifically, the computing device (100) causes the authentication server (600) to access the relay server by referencing the relay server address obtained from the user authentication information decrypted by the second encryption / decryption session key, and to provide the location information of the user VP obtained from the decrypted user authentication information to the relay server, thereby obtaining the user VP from the relay server, and to obtain the user public key corresponding to the user DID from the mobile ID blockchain network using the user DID corresponding to the user VP.
[0070] At this time, the authentication server (600) can decrypt the user VP using the acquired user public key to obtain at least one user VC (Verifiable Credential) (S502).
[0071] In addition, the authentication server (600) can perform user authentication by obtaining a mobile ID issuance server public key corresponding to the mobile ID issuance server DID from the mobile ID blockchain network using the mobile ID issuance server DID included in the user VC (S503), and verifying the user VC by verifying the mobile ID issuance server signature value included in the user VC using the mobile ID issuance server public key (S504).
[0072] At this time, the authentication server (600) compares the hash value of the user VC stored in the mobile ID DID registered in the mobile ID blockchain network with the hash value of the user VC obtained from the user terminal, and if the comparison results match, it can be confirmed that the user VC was issued in correspondence with the user DID.
[0073] In this way, the computing device (100) according to one embodiment of the present invention may provide a user with a non-face-to-face authentication service of an unmanned digital device using a security module (500) and a mobile ID. That is, referring back to FIG. 2, when the user's identity is authenticated by the authentication server (600), the computing device (100) may provide a specific product or service requested by the user through the unmanned digital device (S203).
[0074] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be those specially designed and configured for the present invention or may be those known and available to those skilled in the art of computer software. Examples of the computer-readable recording medium include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. The hardware devices may be configured to operate as one or more software modules to perform processing according to the present invention, and vice versa.
[0075] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and variations from this description.
[0076] Therefore, the idea of the present invention should not be limited to the embodiments described above, and all things that are modified equally or equivalently to the following claims as well as the claims are considered to fall within the scope of the idea of the present invention.
Claims
1. A method for providing a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID card, (a) a step of, when a power-on signal to an unmanned digital device is acquired or a control signal for operating software for the operation of the unmanned digital device is acquired, a computing device controlling the unmanned digital device verifies the integrity of the software through a security module corresponding to the unmanned digital device, and, when the integrity of the software is verified, executes the software to control the unmanned digital device, and performs device authentication of the unmanned digital device through interaction with an authentication server using the security module; (b) When request information for provision of a specific product or specific service from a user is obtained from the unmanned digital device, the computing device requests user authentication through the unmanned digital device, and when user authentication information from a user terminal corresponding to the user - the user authentication information including at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to the user mobile ID, and location information of the user VP stored in the relay server - is obtained through the unmanned digital device, the security module transmits the encrypted user authentication information encrypted using a first encryption / decryption session key to the authentication server, causing the authentication server to decrypt the encrypted user authentication information using a second encryption / decryption session key corresponding to the first encryption / decryption session key to obtain the user authentication information, obtain the user VP from the relay server with reference to the user authentication information, and performs a mobile ID blockchain network corresponding to the user mobile ID using the user VP. A step for performing the above-mentioned user authentication; and (c) a step in which, when the user's identity is authenticated by the authentication server, the computing device provides the specific product or specific service requested by the user through the unmanned digital device; A method including:
2. In paragraph 1, In step (a) above, The computing device (i) obtains a security module ID stored in the security module and a first security module nonce generated in the security module through interaction with the security module, transmits the security module ID and the first security module nonce to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is verified as a valid ID, transmits server authentication data encrypted with a server authentication key, including the server ID and the first security module nonce, and a first server nonce, to the computing device, (ii) if the server authentication data and the first server nonce are obtained from the authentication server, transmits the server authentication data and the first server nonce to the security module so that the security module decrypts the server authentication data using a security module authentication key corresponding to the server authentication key, thereby obtaining the server ID and the decrypted first security module nonce, and verifies whether the decrypted first security module nonce matches the first security module nonce, If it is confirmed that the decrypted first security module nonce matches the first security module nonce, the security module authentication data is generated by encrypting the security module ID and the first server nonce using the security module authentication key, (iii) the security module authentication data generated through the security module is transmitted to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and it is confirmed whether the decrypted first server nonce matches the first server nonce, (iv) the security module is generated by referencing the security module authentication key, the first security module nonce, and the first server nonce to generate a security module authentication session key,A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key by using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key by using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key, and a process for generating the server authentication session key from the authentication server by referencing the server authentication key, the first security module nonce, and the first server nonce, and generating a server integrity verification key by referencing the server authentication session key and the first server nonce, and when an encrypted server integrity verification key that encrypts the server integrity verification key by using the server authentication session key is obtained, causing the security module to decrypt the encrypted server integrity verification key by using the security module authentication session key. A method characterized in that device authentication for the unmanned digital device is performed by performing a process of verifying the server integrity verification key by decrypting it.
3. In paragraph 1, In step (b) above, The computing device (i) obtains the security module ID stored in the security module and the second security module nonce generated in the security module through interaction with the security module, transmits the security module ID and the second security module nonce to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is verified as a valid ID, transmits the server ID and the server encrypted data encrypted with the second security module nonce using a server encryption key, and the second server nonce to the computing device, (ii) if the server encrypted data and the second server nonce are obtained from the authentication server, transmits the server encrypted data and the second server nonce to the security module so that the security module decrypts the server encrypted data using a security module encryption key corresponding to the server encryption key, thereby obtaining the server ID and the decrypted second security module nonce, and verifies whether the decrypted second security module nonce matches the second security module nonce, If it is confirmed that the decrypted second security module nonce matches the second security module nonce, a process is performed to generate security module encrypted data by encrypting the security module ID and the second server nonce using the security module encryption key, (iii) transmitting the security module encrypted data generated through the security module to the authentication server so that the authentication server decrypts the security module encrypted data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and confirming whether the decrypted second server nonce matches the second server nonce, (iv) causing the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce, and causing the authentication server toA method characterized in that it performs a process for generating the second encryption / decryption session key by referring to the server encryption key, the second security module nonce, and the second server nonce when it is confirmed that the decrypted second server nonce and the second server nonce match.
4. In paragraph 1, In step (b) above, The computing device is characterized in that the method performs the user authentication by causing the authentication server to obtain a user public key corresponding to the user DID from the mobile ID blockchain network using the user DID corresponding to the user VP, to decrypt the user VP using the user public key to obtain at least one user VC (Verifiable Credential), to obtain a mobile ID issuance server public key corresponding to the mobile ID issuance server DID from the mobile ID blockchain network using the mobile ID issuance server DID included in the user VC, and to verify the user VC by verifying the mobile ID issuance server signature value included in the user VC using the mobile ID issuance server public key.
5. In paragraph 1, In step (b) above, A method characterized in that the computing device acquires a user DID corresponding to the user VP from the user terminal by adding the user authentication information through the unmanned digital device, or causes the user terminal to transmit the user DID to the relay server by adding the user VP to the user DID, thereby acquiring the user DID through the relay server.
6. In paragraph 1, In step (b) above, A method characterized in that the computing device obtains the user authentication information by scanning a QR code corresponding to the user authentication information displayed on the user terminal through the unmanned digital device, or obtains the user authentication information through wireless communication with the user terminal through the unmanned digital device.
7. In paragraph 1, In step (a) above, A method characterized in that the computing device verifies the integrity of the software by confirming that the first hash value stored in the security module, the first hash value being a value obtained by hashing the software authenticated for the operation of the unmanned digital device, and the second hash value generated by hashing the software are identical.
8. In paragraph 1, A method characterized in that the above security module is a hardware security module including at least some of a memory card, a processor card, a smart card, a SMD (Surface-Mount Device) type chip card, and an external storage device.
9. In a computing device that provides a non-face-to-face authentication service for an unmanned digital device using a security module and a mobile ID, A memory storing instructions for providing the non-face-to-face authentication service of the unmanned digital device using the security module and the mobile ID; and A processor that performs an operation for providing the non-face-to-face authentication service of the unmanned digital device using the security module and the mobile ID card according to the instructions stored in the memory; Including, The processor, (I) when a power-on signal to the unmanned digital device is acquired or a drive control signal of software for the operation of the unmanned digital device is acquired, verifies the integrity of the software through a security module corresponding to the unmanned digital device, and when the integrity of the software is verified, drives the software to perform control of the unmanned digital device, and performs device authentication of the unmanned digital device through interaction with an authentication server using the security module, (II) when request information for provision of a specific product or specific service from a user is acquired from the unmanned digital device, requests user authentication to the user through the unmanned digital device, and when user authentication information from a user terminal corresponding to the user - the user authentication information including at least one of a relay server address corresponding to a relay server to which the user terminal corresponding to the user terminal transmitted a user VP (Verifiable Presentation) corresponding to a user mobile ID, and location information of the user VP stored in the relay server - is acquired through the unmanned digital device, the user authentication information is transmitted to the first A process of transmitting encrypted user authentication information encrypted using a session key for encryption and decryption to the authentication server, causing the authentication server to decrypt the encrypted user authentication information using a second session key for encryption and decryption corresponding to the first session key for encryption and decryption to obtain the user authentication information, obtaining the user VP from the relay server with reference to the user authentication information, and performing the user authentication for the user through a mobile ID blockchain network corresponding to the user mobile ID using the user VP, and (III) when the user authentication for the user is performed from the authentication server,A computing device characterized by performing a process of providing the specific product or specific service requested by the user through the unmanned digital device.
10. In paragraph 9, The above processor, In the above (I) process, (i) through interaction with the security module, a security module ID stored in the security module and a first security module nonce generated in the security module are acquired, and the security module ID and the first security module nonce are transmitted to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, server authentication data encrypted with a server authentication key, including the server ID and the first security module nonce, and the first server nonce are transmitted to the computing device, and (ii) if the server authentication data and the first server nonce are acquired from the authentication server, the server authentication data and the first server nonce are transmitted to the security module so that the security module decrypts the server authentication data using a security module authentication key corresponding to the server authentication key, thereby acquiring the server ID and the decrypted first security module nonce, and verifying whether the decrypted first security module nonce matches the first security module nonce. and if it is confirmed that the decrypted first security module nonce matches the first security module nonce, generate security module authentication data by encrypting the security module ID and the first server nonce using the security module authentication key, (iii) transmit the security module authentication data generated through the security module to the authentication server so that the authentication server decrypts the security module authentication data using the server authentication key to obtain the security module ID and the decrypted first server nonce, and confirm whether the decrypted first server nonce matches the first server nonce, (iv) cause the security module to generate a security module authentication session key by referencing the security module authentication key, the first security module nonce, and the first server nonce.A process for generating a security module integrity verification key by referencing the security module authentication session key and the first security module nonce, encrypting the security module integrity verification key by using the security module authentication session key, and when the encrypted security module integrity verification key is obtained from the security module, transmitting the encrypted security module integrity verification key to the authentication server, and causing the authentication server to decrypt the encrypted security module integrity verification key by using a server authentication session key corresponding to the security module authentication session key to verify the security module integrity verification key, and a process for generating the server authentication session key from the authentication server by referencing the server authentication key, the first security module nonce, and the first server nonce, and generating a server integrity verification key by referencing the server authentication session key and the first server nonce, and when an encrypted server integrity verification key that encrypts the server integrity verification key by using the server authentication session key is obtained, causing the security module to decrypt the encrypted server integrity verification key by using the security module authentication session key. A computing device characterized in that it performs device authentication for the unmanned digital device by performing a process of verifying the server integrity verification key by decrypting it.
11. In paragraph 9, The above processor, In the above (II) process, (i) through interaction with the security module, the security module ID stored in the security module and the second security module nonce generated in the security module are acquired, and the security module ID and the second security module nonce are transmitted to the authentication server so that the authentication server verifies whether the security module ID is a registered valid ID, and if the security module ID is confirmed to be a valid ID, the server encrypted data obtained by encrypting the server ID and the second security module nonce with a server encryption key, and the second server nonce are transmitted to the computing device, and (ii) if the server encrypted data and the second server nonce are acquired from the authentication server, the server encrypted data and the second server nonce are transmitted to the security module so that the security module decrypts the server encrypted data using a security module encryption key corresponding to the server encryption key, thereby acquiring the server ID and the decrypted second security module nonce, and verifying whether the decrypted second security module nonce matches the second security module nonce. and if it is confirmed that the decrypted second security module nonce matches the second security module nonce, a process is created to encrypt the security module ID and the second server nonce using the security module encryption key, (iii) transmit the security module encryption data generated through the security module to the authentication server so that the authentication server decrypts the security module encryption data using the server encryption key to obtain the security module ID and the decrypted second server nonce, and confirm whether the decrypted second server nonce matches the second server nonce, (iv) cause the security module to generate the first encryption / decryption session key by referencing the security module encryption key, the second security module nonce, and the second server nonce, and cause the authentication server to,A computing device characterized in that it performs a process for generating the second encryption / decryption session key by referencing the server encryption key, the second security module nonce, and the second server nonce when it is confirmed that the decrypted second server nonce and the second server nonce match.
12. In paragraph 9, The above processor, A computing device characterized in that, in the above (II) process, the authentication server obtains a user public key corresponding to the user DID from the mobile ID blockchain network using the user DID corresponding to the user VP, decrypts the user VP using the user public key to obtain at least one user VC (Verifiable Credential), obtains a mobile ID issuance server public key corresponding to the mobile ID issuance server DID from the mobile ID blockchain network using the mobile ID issuance server DID included in the user VC, and verifies the user VC by verifying the mobile ID issuance server signature value included in the user VC using the mobile ID issuance server public key, thereby performing the user authentication.
13. In paragraph 9, The above processor, A computing device characterized in that in the above (II) process, a user DID corresponding to the user VP is acquired from the user terminal by adding the user authentication information through the unmanned digital device, or the user DID is acquired through the relay server by causing the user terminal to transmit the user DID to the relay server by adding the user VP to the user terminal.
14. In paragraph 9, The above processor, A computing device characterized in that, in the above (II) process, the user authentication information is obtained by scanning a QR code corresponding to the user authentication information displayed on the user terminal through the unmanned digital device, or the user authentication information is obtained through wireless communication with the user terminal through the unmanned digital device.
15. In paragraph 9, The above processor, A computing device characterized in that, in the above (I) process, the integrity of the software is verified by confirming that the first hash value stored in the security module - the first hash value is a value obtained by hashing the software authenticated for the operation of the unmanned digital device - and the second hash value generated by hashing the software are identical.
16. In paragraph 9, A computing device characterized in that the above security module is a hardware security module including at least some of a memory card, a processor card, a smart card, a SMD (Surface-Mount Device) type chip card, and an external storage device.
Citation Information
Patent Citations
Photovoltaic power generation having ground voltage and leakage current function and method performing the same
KR102194384B1
Method and system for managing kiosk based on programmable logic controller
KR102361081B1
Hemostatic clip for endoscopy
KR102441389B1
Issue systme of mobile pass
KR102523599B1
System and method for user authentication at a kiosk from a mobile device
US20200084040A1