IP Library › Granted Patent US 12,002,041
Granted Patent B2
US 12,002,041 · App. 17/170,750 · Granted Jun 4, 2024

Method and system for user authentication using virtual code for authentication

Inventor: Chang Hun Yoo (Seoul, KR)
Assignee: SSENSTONE INC.
G06Q20/385G06F1/14G06F12/10G06F21/60G06Q20/341G06Q20/343G06Q20/352G06Q20/353G06Q20/38G06Q20/40G06Q20/401G06Q20/40145H04L63/0838H04L63/0853G06F2212/65G06K19/0701G06K19/0723
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,002,041
App. No.
17/170,750
Granted
Jun 4, 2024
Kind
B2
Abstract

A method and system for user authentication by using an authentication virtual code are provided. A user authentication method using an authentication virtual code includes receiving, by a server, the authentication virtual code, searching, by the server, for an authentication card storage location, at which the authentication card is registered, in a storage location search algorithm based on the authentication virtual code, identifying, by the server, a user by extracting user information stored after being matched with the found authentication card storage location, verifying, by the server, an authentication virtual code based on a time point at which the authentication virtual code is received, and approving, by the server, user authentication.

Claims (50)

1. A user authentication method using an authentication virtual code, the method comprising:

receiving, by a server, a user authentication request and the authentication virtual code, wherein the authentication virtual code is generated by an authentication virtual code generation function included in an authentication virtual code generation program based on authentication card data provided from an authentication card;

searching, by the server, for an authentication card storage location, at which the authentication card is registered, in a storage location search algorithm based on the authentication virtual code, wherein the storage location search algorithm is matched with the authentication virtual code generation function and searches for the authentication card storage location based on at least one detailed code in the authentication virtual code;

identifying, by the server, a user by extracting user information stored after being matched with the authentication card storage location that is searched by the server;

verifying, by the server, the authentication virtual code, by comparing a reception time point, at which the server receives the authentication virtual, with a generation time point, at which the authentication virtual code is generated by using the authentication virtual code generation function; and

approving, by the server, user authentication when the comparison result indicates that the generation time point is within an error range from the reception time point.

2. The method of claim 1 , wherein the authentication virtual code is generated based on time data at which the authentication card data included in the authentication card is provided to the authentication virtual code generation program, or time data at which the user authentication is requested by tagging the authentication card to the authentication virtual code generation program.

3. The method of claim 2 , wherein the authentication virtual code is generated based on a combination serial number obtained by combining an authentication card serial number included in the authentication card data and a serial number included in the authentication virtual code generation program.

4. The method of claim 1 , further comprising:

registering, by the server, the authentication card by using the authentication card data and user information of a user holding the authentication card,

wherein the registering of the authentication card includes:

searching, by the server, for a specific authentication card storage location within the storage location search algorithm based on an authentication card registration time point; and

storing the user information at the authentication card storage location that is searched by the server, to complete registration.

5. The method of claim 1 , wherein the authentication virtual code includes a first code and a second code that are changed for each unit count set to a specific time interval,

wherein the first code is generated based on a unit count elapsing from a first time point at which the server starts an issuance of the authentication card, and

wherein the second code is generated based on a unit count elapsing from a time point at which the authentication card of a specific user is registered.

6. A non-transitory computer-readable recording medium storing a computer program, and configured to be coupled to a computer hardware, the program includes instructions to execute the method of claim 1 .

7. An authentication virtual code verification device for user authentication, the authentication virtual code verification device comprising:

an authentication virtual code reception unit configured to receive an authentication virtual code and to receive a request for the user authentication;

a detailed code extraction unit configured to extract one or more detailed codes included in the authentication virtual code;

a storage location search unit configured to search for an authentication card storage location, at which an authentication card is registered in a storage location search algorithm, based on the extracted one or more detailed codes;

a user information extraction unit configured to identify a user by extracting user information stored after being matched with the authentication card storage location that is searched by the storage location search unit;

an authentication virtual code verification unit configured to compare a time point, at which the authentication virtual code reception unit receives the authentication virtual code, with a time point, at which the authentication virtual code is generated by using an authentication virtual code generation function by an authentication virtual code generation means, and to verify the authentication virtual code; and

a user authentication approval unit configured to approve the user authentication when verification of the authentication virtual code is completed,

wherein, when it is identified by the authentication virtual code verification unit that the generation time point is within an error range from the reception time point, and it is determined that the authentication virtual code is a normal code, the user authentication is approved by the user authentication approval unit, and

wherein the storage location search algorithm is matched with the authentication virtual code generation function.

8. The device of claim 7 , wherein the authentication virtual code is generated based on time data at which an authentication card data included in the authentication card is provided to an authentication virtual code generation program, or time data at which the user authentication is requested by tagging the authentication card to the authentication virtual code generation program.

9. The device of claim 8 , wherein the authentication virtual code is generated based on a combination serial number obtained by combining an authentication card serial number included in the authentication card data and a serial number included in the authentication virtual code generation program.

10. The device of claim 7 , wherein the authentication virtual code verification device is further configured to:

register the authentication card by using an authentication card data and user information of a user holding the authentication card,

search for a specific authentication card storage location within the storage location search algorithm based on an authentication card registration time point; and

store the user information at the authentication card storage location that is searched by a server, to complete registration.

11. The device of claim 7 , wherein the authentication virtual code includes a first code and a second code that are changed for each unit count set to a specific time interval,

wherein the first code is generated based on a unit count elapsing from a first time point at which a server starts an issuance of the authentication card, and

wherein the second code is generated based on a unit count elapsing from a time point at which the authentication card of a specific user is registered.

12. An authentication card device for user authentication, the authentication card device comprising:

an integrated circuit (IC) chip including authentication card data; and

a communication unit configured to provide the authentication card data to an authentication virtual code generation means through wireless communication,

wherein the authentication card data is specific data assigned to the authentication card device when the authentication card device is manufactured,

wherein the authentication virtual code generation means generates an authentication virtual code based on the provided authentication card data by using an authentication virtual code generation function and provides the generated authentication virtual code to a server,

wherein the server receives a user authentication request and the authentication virtual code, and searches for an authentication card storage location, at which the authentication card device is registered, in a storage location search algorithm matched with the authentication virtual code generation function based on the provided authentication virtual code, and extracts user information stored after being matched with the authentication card storage location to identify a user, and

wherein the server verifies the authentication virtual code, by comparing a reception time point, at which the server receives the authentication virtual code, with a generation time point, at which the authentication virtual code generation means generates the authentication virtual code, and approves the user authentication when the comparison result indicates that the generation time point is within an error range from the reception time point.

13. The device of claim 12 , further comprising:

a determination unit configured to distinguish between a tag for payments and a tag for the user authentication when the authentication card device includes a card for the payments,

wherein the communication unit provides a payment terminal with card information for the payments included in the IC chip when the tag for the payments is determined by the determination unit, and

wherein the communication unit provides the authentication virtual code generation means with the authentication card data for generating the authentication virtual code when the tag for the user authentication is determined by the determination unit.

14. The device of claim 12 , further comprising:

a determination unit configured to distinguish between a tag for access and a tag for the user authentication when the authentication card device is used as a card for access,

wherein the communication unit provides an access terminal with identification information for the access included in the IC chip when the tag for the access is determined by the determination unit, and

wherein the communication unit provides the authentication virtual code generation means with the authentication card data for generating the authentication virtual code when the tag for the user authentication is determined by the determination unit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2021
From: YOO, CHANG HUN
To: SSENSTONE INC.
Reel/Frame 055187/0508 →
Priority Claims (2)
KR 10-2018-0093349 · Aug 9, 2018 · national
KR 10-2019-0071944 · Jun 18, 2019 · national
Continuity (2)
Continuation PCTKR2019009696 · Aug 5, 2019
Related Publication 20210185034A1 · Jun 17, 2021