Abstract:
PURPOSE: A method for a user registration is provided to solve an inconvenience of a complex approval code use and prevent a member authentication fraud through other person by using living body information in public key infrastructure. CONSTITUTION: An authentication system receives a request of member register from a registration institution(S600) and checks confidentiality and integrity of user information(S602). If the user information is normal(S604), inherent living body information of a user is recognized. In addition, it is checked whether living body information identified with the inputted living body information exists in database storage of the registration institution(S606). If identical living body information does not exist(S608), the user is approved as a member, the user information and living body information are stored and registered in the database storage by linking with a corresponding user table(S610,S617).
Abstract:
PURPOSE: An apparatus and a method for verifying a modified certificate path including root key verification and CRL pre-verification are provided to enhance the reliability of a root key by verifying the root key in a process for verifying a certificate path. CONSTITUTION: An apparatus for verifying a modified certificate path including root key verification and CRL pre-verification includes a root key verification unit(210), a CRL pre-verification unit(220), and a general certificate path verification unit(230). The root key verification unit(210) verifies a root key of a certificate authority of the highest level. The CRL pre-verification unit(220) identifies abolishing states of certificates on a certificate path. The general certificate path verification unit(230) verifies general items of the certificates.
Abstract:
The present invention provides a method of validating a certificate by a certificate validation server using certificate policy and certificate policy mapping in a public key infrastructure (PKI). If the certificate validation server receives, from a client, an object certificate to be validated, a certificate of a certification authority which the client trusts, and a certificate policy which will be applied to validation of the object certificate, and receives a request for validation of the object certificate, the certificate validation server creates a certification path for the object certificate in response to the request. The certificate validation server validates the created certification path using a certificate policy mapping table if the validation of the object certificate is allowed, and then transmits a result message to the client according to the result of the validation of the certification path.
Abstract:
PURPOSE: A method for changing certificate right using biological information in a public key infrastructure authentication system is provided to perform right prohibition, right recovery and abolition of a certificate according to damage of a personal key through user authentication using biological information. CONSTITUTION: According to the method, it is accessed to a certificate authority server using login information of a user when there is a certificate right change request from the user registered in an authentication system as a member(S500). Biological information for user authentication is inputted through a biological information input device comprises in the user system. A certificate right change request message according to the request of the user is generated. Then, a certificate right change is requested through on-line by transmitting the biological information and the certificate right change request message to the above certificate authority.
Abstract:
PURPOSE: An authentication issue request/process apparatus and method in a wireless public key infrastructure, and an authentication issue system using the same are provided to issue an authentication in the wireless public key infrastructure by a message signature function like a wireless markup language script sign text. CONSTITUTION: An authentication issue request device(100) signs an authentication request message using a user' identification, password, a signature public key, and a signature authentication and transmits it to an authentication issue processor(200) through a wireless network. The authentication issue request device(100) includes an initial information input/generation and providing module(110), an authentication request message generating module(120), an authentication request message signature module(130), and an authentication request control module(140). The authentication issue processor(200) tests and processes the signed authentication request message of the authentication issue request device(100). The authentication issue processor(200) includes an authentication request message signature testing module(210) and an authentication request message process module(220).
Abstract:
본발명의다양한실시예들에따르면, 모바일인증을요청하는사용자의제1 단말, 모바일인증의요청에대응하여인증정보및 암호화용키를생성하고, 인증정보를키로암호화하고, 키를제1 정보와제2 정보로나누어, 제1 정보를제1 단말로전송하고, 제2 정보및 암호화된정보를제1 단말과다른사용자의제2 단말로전송하는서버와, 제1 단말로부터제1 정보를획득하고, 제1 정보및 제2 정보에기초하여키를생성하고, 생성된키를이용하여인증정보를획득하는사용자의제2 단말을포함하는모바일인증시스템및 방법을제공할수 있다.