首页> 外国专利> SECURE USER TWO FACTOR AUTHENTICATION METHOD FROM PERSONAL INFOMATION LEAKING AND SMISHING

SECURE USER TWO FACTOR AUTHENTICATION METHOD FROM PERSONAL INFOMATION LEAKING AND SMISHING

机译:个人信息泄露和隐匿的安全用户两种因素认证方法

摘要

The present invention relates to a dual user authentication method and a dual user authentication system which can prevent the damage caused by hacking, smishing, and pharming through dual user authentication by using an international mobile subscriber identity (IMSI) and integrated circuit card identifier (ICCID) which is a unique identification number stored in a universal subscriber identity module (USIM) as well as a one-time password (OTP) or a password set by a user. The method of the present invention includes the steps of: having a service server receive subscriber information such as a mobile phone number for payment; having a payment server request user authentication to a communication company server when the service server requests the payment server to process payment; having the payment server request an authentication server to authenticate the user when the user is determined to be a valid subscriber according to a communication company authentication resu having an authentication server push an authentication application to the mobile phone of the corresponding subscriber to activate the authentication application in the users mobile phone, while the payment server transmits a message for OTP authentication to the users computer; having the authentication application extract unique information (ICCID) stored in the USIM to transmit the extracted information with the input OTP, and having the authentication server compare the transmitted ICCID to the ICCID of a corresponding pre-registered subscriber to authenticate the ICCID, and transmit the authentication result with the OTP to the payment server; and having the payment server execute the OTP authentication to approve the payment when the entire user authentication is successfully completed, and having the service server complete the payment process accordingly.
机译:本发明涉及一种双用户认证方法和双用户认证系统,该双用户认证方法和系统可以通过使用国际移动用户身份(IMSI)和集成电路卡标识符(ICCID)通过双用户认证来防止黑客入侵,欺骗和篡改所造成的损害。 ),它是存储在通用订户身份模块(USIM)中的唯一标识号以及一次性密码(OTP)或用户设置的密码。本发明的方法包括以下步骤:使服务服务器接收订户信息,例如用于支付的移动电话号码;以及当服务服务器请求支付服务器处理支付时,使支付服务器向通信公司服务器请求用户认证;当根据通信公司的认证结果确定用户为有效用户时,支付服务器请求认证服务器对用户进行认证;使认证服务器将认证应用推送到相应订户的手机上,以激活用户手机中的认证应用,同时支付服务器向用户计算机发送用于OTP认证的消息;使认证应用程序提取存储在USIM中的唯一信息(ICCID)以将提取的信息与输入的OTP一起发送,并使认证服务器将发送的ICCID与相应的预注册订户的ICCID进行比较以对ICCID进行认证,然后进行发送带OTP的认证结果到支付服务器;当整个用户认证成功完成时,使支付服务器执行OTP认证来批准支付,并由服务服务器相应地完成支付过程。

著录项

  • 公开/公告号KR20150124932A

    专利类型

  • 公开/公告日2015-11-06

    原文格式PDF

  • 申请/专利权人 LEE SUN HYOUNG;JANG DO HYUN;

    申请/专利号KR20150096109

  • 发明设计人 LEE SUN HYOUNG;JANG DO HYUN;

    申请日2015-07-06

  • 分类号G06Q20/38;G06Q20/32;

  • 国家 KR

  • 入库时间 2022-08-21 14:58:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号