Security authentication method for generating secure key by combining authentication elements of multi-users
View Patent ↗The present invention relates to a security authentication method for generating a secure key by combining authentication elements of multi-users, and more particularly, to a security authentication method for generating a secure key by combining authentication elements of multi-users so as to collect information from multi-users in a smart terminal-based security authentication environment and generate a secure key by combining the collected information of multi-users as authentication elements, in which a new secure key is generated by multi-dimensionally cross-combining randomly authentication elements of multi-users. According to the present invention, by applying identification information automatically collected by a smart terminal as authentication elements and generating a secure key by randomly multi-dimensional cross-combining the authentication elements, it is possible to provide a security service reinforced by multilateral cooperation, so that the provided security service is coupled with existing authentication and encryption technology to be applied to various applications.
1. A security authentication method for generating a secure key by combining authentication elements of multi-user, as the security authentication method using a security authentication system ( 100 ) which collects the authentication elements from a plurality of smart terminals by a request of a first user terminal ( 30 ) used by a user requesting a security authentication service to generate the secure key, the security authentication method comprising:
a first step of requesting, by a user requesting the security authentication service, any one service of approval of access authority, contents, information, financial services, and access authentication by accessing a service system ( 50 ) through a first user terminal ( 30 ) and requesting, by the first user terminal ( 30 ), the secure key for security authentication by accessing the security authentication system ( 100 );
a second step of requesting, by a collecting unit ( 104 ) included in the security authentication system ( 100 ), provision of the authentication elements to the first user terminal ( 30 ) and a second user terminal ( 40 ) used by a user without requesting the security authentication service;
a third step of storing, by the collecting unit ( 104 ), a plurality of authentication elements provided from the first user terminal ( 30 ) and the second user terminal ( 40 ) in an authentication element DB ( 116 );
a fourth step of randomly selecting a number of authentication elements to be extracted and randomly extracting the authentication elements, by the combining unit ( 106 ) included in the security authentication system ( 100 ), generating the secure key by multi-dimensionally cross-combining the plurality of extracted authentication elements, and providing the generated secure key to the first user terminal ( 30 );
a fifth step of converting, by the first user terminal ( 30 ), the secure key provided from the combining unit ( 106 ) into a hash value to transmit the converted hash value to security authentication system ( 100 ); and
a sixth step of notifying, by the security authentication system ( 100 ), to the service system ( 50 ) that the security authentication is normally processed, when the hash value transmitted from the first user terminal ( 30 ) is the same as a hash value of the secure key generated by the combining unit ( 106 ).
2. The security authentication method of claim 1 , wherein the authentication elements include
area detection information including information on an RFID tag, a WIFI SSID, a beacon, and a sensor value;
knowledge-based information including an email address, an ID, and a password of a user;
status information including a sensor, a universal unique identifier (UUID), status information, an MAC address; and
possession information including a phone number, an NFC tag, a QR code, and a barcode.
3. The security authentication method of claim 1 , wherein the secure key includes any one of a single-use secure key to be deleted or discarded after used for security authentication and a period-limited secure key to be deleted or discarded after a predetermined period.