首页> 外国专利> OTP An OTP registration method based on location authentication and session for preventing replication and multi-registration

OTP An OTP registration method based on location authentication and session for preventing replication and multi-registration

机译:OTP基于位置身份验证和会话的OTP注册方法,用于防止复制和多注册

摘要

The present invention relates to a location authentication and session information-based OTP registration method for preventing duplication and multiple registration, the method comprising: (a) storing, by the authentication server, registration area information for each user; (b) requesting, by the service server, OTP device registration for a connected user to the authentication server; (c) the authentication server generating a unique ID and secret key, setting a registration area, and registering in the OTP device list; (d) transmitting, by the authentication server, OTP device information including the unique ID, the secret key, and the registration area to the OTP client; (e) extracting, by the OTP client, a unique ID, a secret key, and a registration area from the OTP device information; (f) the OTP client obtaining a measured current location and verifying whether the current location is located within the registration area; and, (g) when the current location is located within the registration area, the OTP client creates an OTP device with a corresponding unique ID and secret key, and transmits a registration completion message to the authentication server. By allowing only one OTP device to be registered at a specified location through verification of the registration location and a single registration session by the above method, even if an attacker captures or streams the user's screen, it is possible to prevent duplication or registration of the OTP device. can
机译:本发明涉及一种用于防止复制和多重登记的基于位置认证和基于会话信息的OTP注册方法,该方法包括:(a)通过认证服务器,每个用户的登记区域信息存储; (b)通过服务服务器请求OTP设备对认证服务器的连接用户注册; (c)生成唯一ID和密钥的认证服务器,设置注册区域,并在OTP设备列表中注册; (d)通过身份验证服务器传输,OTP设备信息包括唯一ID,秘密密钥和注册区域到OTP客户端; (e)通过OTP客户端,唯一ID,秘密密钥和OTP设备信息的注册区域提取; (f)OTP客户端获取测量的当前位置并验证当前位置是否位于注册区域内;并且(g)当当前位置位于注册区域内时,OTP客户端用相应的唯一ID和密钥创建OTP设备,并将注册完成消息发送到认证服务器。通过仅通过上述方法验证登记位置和单个注册会话的指定位置仅在指定位置注册一个OTP设备,即使攻击者捕获或流传输用户的屏幕,也可以防止重复或注册OTP设备。能够

著录项

  • 公开/公告号KR102291919B1

    专利类型

  • 公开/公告日2021-08-23

    原文格式PDF

  • 申请/专利权人 에스지에이 주식회사;

    申请/专利号KR20190122998

  • 发明设计人 강봉호;

    申请日2019-10-04

  • 分类号H04L9/08;H04L9/32;

  • 国家 KR

  • 入库时间 2022-08-24 22:18:24

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号