[go: up one dir, main page]

CN101667915A - Method for generating dynamic password to execute remote security authentication and mobile communication device thereof - Google Patents

Method for generating dynamic password to execute remote security authentication and mobile communication device thereof Download PDF

Info

Publication number
CN101667915A
CN101667915A CN200810212103A CN200810212103A CN101667915A CN 101667915 A CN101667915 A CN 101667915A CN 200810212103 A CN200810212103 A CN 200810212103A CN 200810212103 A CN200810212103 A CN 200810212103A CN 101667915 A CN101667915 A CN 101667915A
Authority
CN
China
Prior art keywords
mobile communication
communication device
dynamic password
dynamic
generating
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN200810212103A
Other languages
Chinese (zh)
Inventor
林茂聪
张金平
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Todos Information Co ltd
Original Assignee
Todos Information Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Todos Information Co ltd filed Critical Todos Information Co ltd
Priority to CN200810212103A priority Critical patent/CN101667915A/en
Publication of CN101667915A publication Critical patent/CN101667915A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Telephonic Communication Services (AREA)

Abstract

A method for generating dynamic cipher to execute remote safety certification and its mobile communication device are disclosed, which is characterized by that a mobile communication device is electrically connected to an independent integrated circuit chip, a dynamic cipher generating module is set in the integrated circuit chip, and a remote server respectively generates a correspondent dynamic certification code, and said dynamic certification code is displayed on the display interface of the mobile communication device. The user reads the dynamic authentication code displayed on the display interface and transmits the dynamic authentication code back to the remote server for checking so as to perform remote security authentication. Therefore, the user only needs to carry out remote security authentication by the portable mobile communication device without carrying other identity verification tools additionally.

Description

产生动态密码执行远程安全认证的方法及其移动通信装置 Method for generating dynamic password to perform remote security authentication and mobile communication device thereof

技术领域 technical field

本发明涉及一种产生动态密码执行远程安全认证的方法及其装置,尤指一种基于行动通讯介面产生动态密码执行远程安全认证的方法以及产生动态密码执行远程安全认证的移动通信装置。The invention relates to a method and device for generating a dynamic password to perform remote security authentication, in particular to a method for generating a dynamic password to perform remote security authentication based on a mobile communication interface and a mobile communication device for generating a dynamic password to perform remote security authentication.

背景技术 Background technique

随着网络通讯的快速发展,新型态的电子商务交易模式因应而生。人们不须亲临银行或出门购物,即可通过网络进行银行业务的办理或商业交易。相较于传统交易方式,电子商务模式所提供的仿真交易环境确实提供极大的便利性。With the rapid development of network communication, a new type of e-commerce transaction mode has emerged accordingly. People do not need to go to the bank or go shopping in person, they can conduct banking business or business transactions through the Internet. Compared with traditional trading methods, the simulated trading environment provided by the e-commerce model does provide great convenience.

然而此种电子商务模式最为人所批评的是交易安全上的考虑,由于使用者必须将自身的金融数据或个人机密数据,如信用卡卡号、银行账户、密码、登入账号、交易明细等,通过网络传输到所欲交易的服务器上,此举提供了网络黑客或有心人士侧录或窃取数据的机会,遂造成个人或银行极大的损失。However, the most criticized aspect of this e-commerce model is the consideration of transaction security, because users must send their own financial data or personal confidential data, such as credit card numbers, bank accounts, passwords, login account numbers, transaction details, etc., through the network. It is transmitted to the desired transaction server, which provides opportunities for network hackers or interested persons to log or steal data, which will cause great losses to individuals or banks.

目前常见的解决方式是利用密码安全机制,来作为个人远程安全认证的手段;一般远程安全认证包含了使用者身份认证以及安全数据传输等。就传统的密码安全机制为例,使用者先于交易服务器内储存一静态密码,待日后欲进行交易行为时,将该静态密码输入至该服务器并加以核对后,来确定使用者身分以进行交易。然而,网络黑客很容易利用网络钓鱼(phishing)或者植入木马程序、间谍软件到使用者计算机中等方法,取得使用者的静态密码,再一次暴露出网络交易的安全问题。At present, a common solution is to use a password security mechanism as a means of personal remote security authentication; general remote security authentication includes user identity authentication and secure data transmission. Taking the traditional password security mechanism as an example, the user first stores a static password in the transaction server, and when he wants to conduct transactions in the future, he enters the static password into the server and checks it to determine the user's identity for the transaction . However, network hackers can easily use methods such as phishing or implanting Trojan horse programs and spyware into the user's computer to obtain the user's static password, which once again exposes the security problem of network transactions.

为能克服上述问题,开发出一种一次性密码(One-TimePassword,OTP)的技术,又称为动态密码技术,如中国台湾第I288554号专利案所示。OTP技术可以根据时间或事件(event)随机产生一次使用的密码,该密码同时仅为目标服务器以及个人所得知,当超过预定时间或将该动态密码使用后,本次密码随即失效。若欲进行下一次的密码输入,则必须产生不同的动态密码。于OTP技术中,每次所使用的动态密码皆不相同,且仅被使用者所得知,即使被网络黑客撷取本次的动态密码,该动态密码亦无法运用于下一次的交易。因此相较于传统静态密码的安全机制,具有较佳的安全性。In order to overcome the above-mentioned problems, a One-Time Password (OTP) technology, also known as a dynamic password technology, has been developed, as shown in Chinese Taiwan Patent No. I288554. OTP technology can randomly generate a once-used password according to time or event (event), and the password is only known to the target server and individuals at the same time. When the predetermined time is exceeded or the dynamic password is used, the password will become invalid immediately. If you want to enter the password next time, you must generate a different dynamic password. In OTP technology, the dynamic password used each time is different and only known by the user. Even if the dynamic password is captured by a network hacker, the dynamic password cannot be used in the next transaction. Therefore, compared with the security mechanism of the traditional static password, it has better security.

市面上常见的OTP技术须通过一独立的动态密码产生装置(Token)来产生动态密码,因此,若欲使用OTP功能时,必须随身携带动态密码产生装置,增加使用者携带上的负担。此外,每一家金融业者或交易公司所使用的动态密码产生装置皆不兼容,若欲与不同的交易对象进行交易时,则必须携带多个动态密码产生装置,在使用上相当不便。已知一中国台湾第I261451号专利案,揭露一种传送动态密码的交易确认方法及系统,主要利用一终端机读取芯片型卡片内的身分验证码,并传送至一远程服务器上,该远程服务器核对该身分验证码后产生一动态密码置一移动通信装置,使用者可凭该动态密码输入至该终端机进行比对并确认使用者身分。虽然于此一技术中,动态密码是由远程服务器所提供,避免传统动态密码产生装置的需要,但使用者必须倚赖终端机才能验证身分以及输入动态密码,仍有不便之处。The common OTP technology on the market needs to generate a dynamic password through an independent dynamic password generating device (Token). Therefore, if you want to use the OTP function, you must carry the dynamic password generating device with you, which increases the burden on the user. In addition, the dynamic password generating devices used by each financial industry or trading company are not compatible. If you want to conduct transactions with different trading partners, you must carry multiple dynamic password generating devices, which is quite inconvenient to use. A known Taiwan Patent No. I261451 discloses a transaction confirmation method and system for transmitting a dynamic password, which mainly uses a terminal to read the identity verification code in the chip-type card and transmits it to a remote server. After checking the identity verification code, the server generates a dynamic password and puts it in a mobile communication device. The user can input the dynamic password into the terminal for comparison and confirm the user's identity. Although in this technology, the dynamic password is provided by the remote server, avoiding the need of the traditional dynamic password generating device, but the user must rely on the terminal to verify the identity and input the dynamic password, which is still inconvenient.

发明内容 Contents of the invention

本发明的主要目的,在于让使用者仅需以一随身的移动通信装置即可与所欲交易的对象完成OTP身分确认。为达上述目的,本发明提供一种产生动态密码执行远程安全认证的方法,应用于一移动通信装置中,包括以下步骤:The main purpose of the present invention is to allow the user to complete the OTP identity confirmation with the desired transaction object only with a portable mobile communication device. In order to achieve the above object, the present invention provides a method for generating a dynamic password to perform remote security authentication, which is applied to a mobile communication device and includes the following steps:

a)建立该移动通信装置与一独立集成电路芯片之间的电连接关系,该集成电路芯片内设有一动态密码产生模组;a) establishing an electrical connection relationship between the mobile communication device and an independent integrated circuit chip, which is provided with a dynamic password generation module;

b)操作该移动通信装置以启动该动态密码产生模组,该动态密码产生模组与一远程服务器分别产生一相对应的动态认证码,且该动态认证码显示于该移动通信装置的显示介面;b) operate the mobile communication device to activate the dynamic password generation module, the dynamic password generation module and a remote server respectively generate a corresponding dynamic authentication code, and the dynamic authentication code is displayed on the display interface of the mobile communication device ;

c)通过一与该远程服务器相连的回传手段将该显示介面上的动态认证码输入至该远程服务器;以及c) inputting the dynamic authentication code on the display interface to the remote server through a return means connected to the remote server; and

d)该远程服务器核对所接收的动态认证码是否相符,以进行身分确认。d) The remote server checks whether the received dynamic authentication code matches, so as to confirm the identity.

其中,远程安全认证包含身份认证以及安全数据传输等。该动态密码产生模组产生对应多个远程服务器的动态认证码,因此,本发明中还可具有一选择所欲对应远程服务器的步骤。Among them, remote security authentication includes identity authentication and secure data transmission. The dynamic password generation module generates dynamic authentication codes corresponding to a plurality of remote servers. Therefore, the present invention may also include a step of selecting the desired corresponding remote server.

此外,为能增加本发明的安全性,本发明还可具有一输入个人识别码以及核对该个人识别码是否相符的步骤;该核对个人识别码是否相符的步骤是于该移动通信装置内进行。或者,具有一根据交易数据产生电子签章以及核对该电子签章是否相符的步骤;核对该电子签章于该远程服务器内进行。In addition, in order to increase the security of the present invention, the present invention also has a step of inputting a personal identification code and checking whether the personal identification code matches; the step of checking whether the personal identification code matches is carried out in the mobile communication device. Or, there is a step of generating an electronic signature according to the transaction data and checking whether the electronic signature is consistent; checking the electronic signature is performed in the remote server.

于本发明中,该集成电路芯片设置于一供用户识别模组卡插设的卡槽上。该回传手段则亦可通过因特网、行动通讯网络或固定电话系统传输至该远程服务器上;其中,该回传手段是通过简讯、GPRS、MMS、传真、语音、电子邮件等机制输入至该远程服务器。In the present invention, the integrated circuit chip is arranged on a card slot for inserting the user identification module card. The return means can also be transmitted to the remote server through the Internet, mobile communication network or fixed telephone system; wherein, the return means is input to the remote server through SMS, GPRS, MMS, fax, voice, email and other mechanisms. server.

此外,本发明还提供一种产生动态密码执行远程安全认证的移动通信装置,该移动通信装置电连接至一独立集成电路芯片,该集成电路芯片具有至少一动态密码产生模组,该动态密码产生模组可通过操作该移动通信装置而启动,并与一远程服务器产生一相对应的动态认证码,该动态认证码显示于该移动通信装置的显示介面,显示于该显示介面上的动态认证码经一连接于该远程服务器的密码回传手段传送至该远程服务器,且通过一设置于该远程服务器内的密码核对模组核来核对是否与该远程服务器内相对应的动态认证码相符,以进行远程安全认证。In addition, the present invention also provides a mobile communication device that generates a dynamic password to perform remote security authentication. The mobile communication device is electrically connected to an independent integrated circuit chip, and the integrated circuit chip has at least one dynamic password generation module. The dynamic password generates The module can be activated by operating the mobile communication device, and generates a corresponding dynamic authentication code with a remote server, the dynamic authentication code is displayed on the display interface of the mobile communication device, and the dynamic authentication code displayed on the display interface Send it to the remote server through a password return means connected to the remote server, and check whether it matches the corresponding dynamic authentication code in the remote server through a password checking module core set in the remote server, so as to Perform remote security authentication.

其中,远程安全认证包含身份认证以及安全数据传输等。该集成电路芯片可设置于一供用户识别模组卡插设的卡槽上。此外,该独立集成电路芯片内设有一储存单元。该储存单元中储存至少一用来对应于不同远程服务器的个人登录数据,该个人登录数据通过因特网或行动通讯网络传下载至该储存单元,或者于出厂时直接烧录于该储存单元内。储存于该储存单元内的个人登录数据可通过操作该移动通信装置的输入介面进行更改或删除。该回传手段则可通过因特网、行动通讯网络或固定电话系统传输至该远程服务器上。Among them, remote security authentication includes identity authentication and secure data transmission. The integrated circuit chip can be arranged on a card slot for inserting the user identification module card. In addition, a storage unit is arranged in the independent integrated circuit chip. The storage unit stores at least one personal login data corresponding to different remote servers, and the personal login data is downloaded to the storage unit through the Internet or a mobile communication network, or directly burned in the storage unit when leaving the factory. The personal registration data stored in the storage unit can be changed or deleted by operating the input interface of the mobile communication device. The return means can be transmitted to the remote server through the Internet, mobile communication network or fixed telephone system.

本发明产生动态密码执行远程安全认证的方法及其移动通信装置的特点在于:The present invention produces dynamic code and carries out the method for remote security authentication and its mobile communication device are characterized in that:

1.使用者仅需通过一随身所携带的移动通信装置即可与所欲交易的远程服务器进行一次性密码安全确认。1. The user only needs to carry out a one-time password security confirmation with the remote server to be traded through a portable mobile communication device.

2.本发明亦可利用下载扩充等方式,得以对应多个远程服务器进行远程安全认证。相较于传统一次性密码技术,本发明不需额外携带动态密码产生装置,且可于该移动通信装置内可储存多个交易的对象以获得不同动态密码,大幅提升使用上的便利性。2. The present invention can also use methods such as downloading and expansion to perform remote security authentication corresponding to multiple remote servers. Compared with the traditional one-time password technology, the present invention does not need to carry an additional dynamic password generating device, and can store multiple transaction objects in the mobile communication device to obtain different dynamic passwords, greatly improving the convenience of use.

3.本发明可将具有动态密码产生模组的集成电路芯片设置于行动电话上供用户识别模组卡(Subscriber Identity Module Card,SIM Card)插设的卡槽上,使用者可不通过行动通讯公司所提供的用户识别模组卡即可执行远程安全认证,有利于大众普及。3. The present invention can set the integrated circuit chip with the dynamic password generation module on the card slot on the mobile phone for the Subscriber Identity Module Card (SIM Card) to be inserted, and the user does not need to pass through the mobile communication company The provided user identification module card can perform remote security authentication, which is beneficial to popularization by the public.

附图说明 Description of drawings

图1是本发明一产生动态密码执行远程安全认证的移动通信装置优选实施例的系统架构示意图。FIG. 1 is a schematic diagram of the system architecture of a preferred embodiment of a mobile communication device for generating a dynamic password to perform remote security authentication according to the present invention.

图2是本发明中以计算机设备或固定电话作为回传手段实施例的系统架构示意图。FIG. 2 is a schematic diagram of the system architecture of the embodiment of the present invention using computer equipment or fixed telephones as the return means.

图3是本发明一产生动态密码执行远程安全认证的方法优选实施例的步骤流程示意图。FIG. 3 is a flow diagram of steps in a preferred embodiment of a method for generating a dynamic password to perform remote security authentication in the present invention.

图4是本发明方法中具有一输入个人识别码以及核对该个人识别码是否相符步骤实施例的步骤流程示意图。FIG. 4 is a schematic flowchart of an embodiment of the steps of inputting a personal identification code and checking whether the personal identification code matches in the method of the present invention.

图5是本发明方法中具有一根据交易数据产生电子签章以及核对该电子签章步骤实施例的步骤流程示意图。Fig. 5 is a schematic flow chart of an embodiment of the steps of generating an electronic signature according to transaction data and verifying the electronic signature in the method of the present invention.

具体实施方式 Detailed ways

有关本发明的详细说明及技术内容,现配合示意图说明如下:Relevant detailed description and technical content of the present invention, cooperate schematic diagram to illustrate as follows now:

请参阅图1所示,是本发明一优选实施例的系统架构示意图,如图所示:本发明揭露一种产生动态密码执行远程安全认证的移动通信装置10,该远程安全认证包含了使用者身份认证以及安全数据传输。该移动通信装置10包含有一供使用者输入指令信号或选择功能的输入介面11,以及一供使用者读取信息的显示介面12,该输入介面可为一键盘模组(keyboard module)或者为一触控面板(touch panel),而该显示介面可为一平板显示器(flat paneldisplay)。该移动通信装置10电连接一独立集成电路芯片30,该集成电路芯片30内设有至少一动态密码产生模组31。为了增加使用者的便利性,不必仅能通过行动通讯公司所提供的用户识别模组卡来扩充远程安全认证的方法,该集成电路芯片30可设置于一供用户识别模组卡(Subscriber Identity Module Card,SIM Card)插设的卡槽上。Please refer to FIG. 1, which is a schematic diagram of the system architecture of a preferred embodiment of the present invention. As shown in the figure: the present invention discloses a mobile communication device 10 that generates a dynamic password to perform remote security authentication. The remote security authentication includes user Authentication and secure data transmission. The mobile communication device 10 includes an input interface 11 for the user to input command signals or select functions, and a display interface 12 for the user to read information. The input interface can be a keyboard module (keyboard module) or a A touch panel (touch panel), and the display interface can be a flat panel display (flat panel display). The mobile communication device 10 is electrically connected to an independent integrated circuit chip 30 , and at least one dynamic password generating module 31 is disposed in the integrated circuit chip 30 . In order to increase the user's convenience, it is not necessary to expand the method of remote security authentication only through the Subscriber Identity Module card provided by the mobile communication company. The integrated circuit chip 30 can be arranged on a Subscriber Identity Module card Card, SIM Card) into the card slot.

该移动通信装置10通过操作该输入介面11而启动该动态密码产生模组31,使该动态密码产生模组31与一远程服务器20分别产生相对应的一动态认证码,该动态认证码显示于该移动通信装置10的显示介面12上。使用者通过读取该显示介面12而获得该动态认证码后,通过一密码回传手段将显示于该显示介面12上的动态认证码传送至该远程服务器20。使用者所采取的密码回传手段可为直接于该移动通信装置10上通过该输入介面11将该动态认证码输入后,经由因特网(Internet)或者行动通讯网络(Mobile CommunicationNetwork)传输至该远程服务器20,如图1所示。该行动通讯网络可为如GSM(Global System for Mobile Communication)系统、GPRS(General Packet Radio Service)系统或3G(3rd-Generatioln)系统等。或者,使用者得以读取该显示介面12的动态认证码后,利用其它与因特网相连的计算机设备40,如个人计算机或笔记本型计算机等,将该动态认证码输入至该远程服务器20上,如图2所示。该远程服务器20内具有一密码核对模组21,该密码核对模组21接收来自该密码回传手段所提供的动态认证码,进而核对所接收的动态认证码以进行远程安全认证的动作。甚者,使用者可以不利用图2所示的计算机设备,而改拨打固定电话50通过固定电话系统或公共电话交换网(Public Switched Telephone Network,PSTN),将显示于显示介面12上的动态认证码传输至该远程服务器20上。The mobile communication device 10 activates the dynamic password generation module 31 by operating the input interface 11, so that the dynamic password generation module 31 and a remote server 20 respectively generate a corresponding dynamic authentication code, and the dynamic authentication code is displayed on On the display interface 12 of the mobile communication device 10 . After the user obtains the dynamic authentication code by reading the display interface 12 , the dynamic authentication code displayed on the display interface 12 is sent to the remote server 20 through a password return means. The password return method adopted by the user can be to directly input the dynamic authentication code through the input interface 11 on the mobile communication device 10, and then transmit it to the remote server via the Internet (Internet) or mobile communication network (Mobile Communication Network) 20, as shown in Figure 1. The mobile communication network can be, for example, a GSM (Global System for Mobile Communication) system, a GPRS (General Packet Radio Service) system, or a 3G ( 3rd -Generation) system. Or, after the user can read the dynamic authentication code of the display interface 12, use other computer equipment 40 connected to the Internet, such as a personal computer or a notebook computer, etc., to input the dynamic authentication code into the remote server 20, such as Figure 2 shows. The remote server 20 has a password verification module 21 inside. The password verification module 21 receives the dynamic authentication code provided by the password return means, and then checks the received dynamic authentication code to perform remote security authentication. What's more, the user can not use the computer equipment shown in Figure 2, but instead dial the fixed telephone 50 through the fixed telephone system or the public switched telephone network (Public Switched Telephone Network, PSTN), the dynamic authentication will be displayed on the display interface 12 The code is transmitted to the remote server 20.

除此之外,为能使本发明得以应用于多个远程服务器20。该独立集成电路芯片30内设有一储存单元32。该储存单元32中储存多个用来对应于不同远程服务器20的个人登录数据,使用者可以选择不同的个人登录数据进而与一远程服务器20分别产生相对应动态认证码;该个人登录数据可由行动通讯网络或因特网下载至该储存单元32、或是出厂时直接烧录设定于该储存单元32。储存于该储存单元32内的个人登录数据可通过操作该移动通信装置10的输入介面进行更改或删除。Besides, in order to enable the present invention to be applied to a plurality of remote servers 20 . A storage unit 32 is disposed in the independent integrated circuit chip 30 . A plurality of personal login data corresponding to different remote servers 20 are stored in the storage unit 32, and the user can select different personal login data and then generate corresponding dynamic authentication codes with a remote server 20 respectively; The communication network or the Internet is downloaded to the storage unit 32 , or directly burned and set in the storage unit 32 when leaving the factory. The personal registration data stored in the storage unit 32 can be changed or deleted by operating the input interface of the mobile communication device 10 .

请参阅图3所示,是为本发明一优选实施例的步骤流程示意图,如图所示:本发明亦揭露一种产生动态密码执行远程安全认证的方法,远程安全认证包含身份认证以及安全数据传输等。该方法应用于一移动通信装置以及一远程服务器。首先,将该移动通信装置与一独立集成电路芯片之间建立电连接关系(S10),该集成电路芯片内设有至少一动态密码模组。该集成电路芯片可设置于一供用户识别模组卡插设的卡槽上。当建立好该移动通信装置与该集成电路芯片的连接关系后,使用者得以操作该移动通信装置以启动该动态密码产生模组,该动态密码产生模组与至少一远程服务器分别产生一相对应的动态认证码(S20),且该动态认证码显示于该移动通信装置的显示介面。该动态密码产生模组除了可以对应一远程服务器产生动态认证码之外,亦可对应多个远程服务器来产生动态认证码。由此,使用者可以使用单一移动通信装置得以对应多个服务器以达到扩大电子交易对象的目的。若该动态密码产生模组得以对应多个远程服务器而产生不同动态认证码,于本发明中,还具有一通过该移动通信装置的输入介面来选择所欲对应远程服务器的步骤(S21)。再者,当使用者通过该显示介面读取该动态认证码后,可通过一与该远程服务器相连的回传手段将该动态认证码输入至该远程服务器(S30)。使用者得以使用其它的计算机系统输入该动态认证码,该计算机系统与该远程服务器之间可通过一因特网相互连接,因此,该远程服务器得以接收由该计算机系统所输入的动态认证码。或者,使用者可以直接使用该移动通信装置上的输入介面输入该动态认证码,该移动通信装置可通过因特网或行动通讯网络与该远程服务器相互连接,而使该远程服务器接收该动态认证码。最后,于该远程服务器内核对由该回传手段所发出的动态认证码是否与该远程服务器内相对应动态认证码相符,来确定使用者的身分(S40)。若由该回传手段所发出的动态认证码与该远程服务器内相对应动态认证码相符,该远程服务器则发送一核对成功信息(S41);若由该回传手段所发出的动态认证码不符合该远程服务器内相对应动态认证码,该远程服务器则发送一核对失败信息(S42)。该核对成功信息以及该核对失败信息可根据所使用的回传手段,反向发送至该移动通信装置或该计算机系统中。Please refer to Figure 3, which is a schematic diagram of the steps of a preferred embodiment of the present invention. As shown in the figure: the present invention also discloses a method for generating a dynamic password to perform remote security authentication. Remote security authentication includes identity authentication and security data transmission etc. The method is applied to a mobile communication device and a remote server. Firstly, an electrical connection relationship is established between the mobile communication device and an independent integrated circuit chip (S10), and at least one dynamic password module is arranged in the integrated circuit chip. The integrated circuit chip can be arranged on a card slot for inserting the user identification module card. After the connection relationship between the mobile communication device and the integrated circuit chip is established, the user can operate the mobile communication device to activate the dynamic password generation module, and the dynamic password generation module and at least one remote server respectively generate a corresponding The dynamic authentication code (S20), and the dynamic authentication code is displayed on the display interface of the mobile communication device. In addition to generating dynamic authentication codes corresponding to one remote server, the dynamic password generation module can also generate dynamic authentication codes corresponding to multiple remote servers. Thus, the user can use a single mobile communication device to correspond to multiple servers to achieve the purpose of expanding electronic transaction objects. If the dynamic password generation module can generate different dynamic authentication codes corresponding to multiple remote servers, in the present invention, there is also a step of selecting the corresponding remote server through the input interface of the mobile communication device (S21). Furthermore, after the user reads the dynamic authentication code through the display interface, the dynamic authentication code can be input to the remote server through a return means connected to the remote server (S30). The user can use other computer systems to input the dynamic authentication code, and the computer system and the remote server can be connected to each other through an Internet, so the remote server can receive the dynamic authentication code input by the computer system. Alternatively, the user can directly use the input interface on the mobile communication device to input the dynamic authentication code, and the mobile communication device can be connected to the remote server through the Internet or mobile communication network, so that the remote server can receive the dynamic authentication code. Finally, the remote server kernel checks whether the dynamic authentication code sent by the return means matches the corresponding dynamic authentication code in the remote server to determine the identity of the user (S40). If the dynamic authentication code sent by the return means matches the corresponding dynamic authentication code in the remote server, the remote server sends a verification success message (S41); if the dynamic authentication code sent by the return means does not If it matches the corresponding dynamic authentication code in the remote server, the remote server sends a verification failure message (S42). The verification success information and the verification failure information can be sent back to the mobile communication device or the computer system according to the return means used.

请参阅图4所示,为了能加强整体远程安全认证的安全性,于前述方法中,还具有一输入个人识别码的步骤(S50)以及核对该个人识别码是否相符的步骤(S51)。于本实施例中,该输入个人识别码的步骤(S50)以及核对该个人识别码是否相符的步骤(S51)可置于启动动态密码产生模组并与一远程服务器分别产生相对应动态认证码的步骤(S20),以及通过一与该远程服务器相连的回传手段将该显示介面上的动态认证码输入至该远程服务器的步骤(S30)之间。当使用者所输入的个人识别码符合预先所储存的个人识别码,则可进行后续步骤;若不符合,则必须重新输入个人识别码。该个人识别码已预先设定于该移动通信装置内。或者使用者读取该动态认证码后,必须先于该移动通信装置中输入该个人识别码,所输入的个人识别码可于该移动通信装置内进行核对。若核对完成后,才能进行之后的步骤。该个人识别码可自行由使用者设定,如金钥、静态密码、金融账号、身分字号、电信号码等。Please refer to FIG. 4, in order to strengthen the security of the overall remote security authentication, in the aforementioned method, there is also a step of inputting a personal identification code (S50) and a step of checking whether the personal identification code matches (S51). In this embodiment, the step of inputting the personal identification code (S50) and the step of checking whether the personal identification code matches (S51) can be placed in activating the dynamic password generation module and generating corresponding dynamic authentication codes with a remote server between the step (S20) and the step (S30) of inputting the dynamic authentication code on the display interface to the remote server through a return means connected to the remote server. When the personal identification code input by the user matches the pre-stored personal identification code, the subsequent steps can be performed; if not, the personal identification code must be re-inputted. The personal identification code is preset in the mobile communication device. Or after the user reads the dynamic authentication code, he must first input the personal identification code in the mobile communication device, and the input personal identification code can be checked in the mobile communication device. After the verification is completed, the following steps can be carried out. The personal identification code can be set by the user, such as a key, a static password, a financial account number, an identity number, a telecommunication number, and the like.

除此之外,请参阅图5所示,为能确保交易安全,本发明亦可具有一根据交易数据产生电子签章以及核对该电子签章是否相符的步骤(S60)。以本实施例而言,使用者得以于发送一核对成功信息的步骤(S41)之后,进行电子交易。当确认电子交易内容之后,则可进行该根据交易数据产生电子签章以及核对该电子签章是否相符的步骤(S60)。该交易数据可为启用交易、金融交易种类、交易账户、交易金额、交易时间等。当使用者确定所欲进行的交易数据后,则进行一逻辑运算后产生该电子签章,使用者通过一回传手段将该电子签章传送至该远程服务器后并加以核对,若核对成功,则该远程服务器发送一交易成功的信息(S61),若核对失败,则该远程服务器发送一交易失败的信息(S62)。由此达到二次核对的程序,以增加安全可靠度。In addition, as shown in FIG. 5 , in order to ensure transaction security, the present invention may also include a step of generating an electronic signature according to the transaction data and checking whether the electronic signature is consistent ( S60 ). According to this embodiment, the user can conduct electronic transactions after the step of sending a verification success message ( S41 ). After the electronic transaction content is confirmed, the step of generating an electronic signature according to the transaction data and checking whether the electronic signature is consistent (S60) can be performed. The transaction data may be enabled transactions, types of financial transactions, transaction accounts, transaction amounts, transaction time, and the like. After the user confirms the desired transaction data, a logic operation is performed to generate the electronic signature. The user transmits the electronic signature to the remote server through a return method and checks it. If the verification is successful, Then the remote server sends a transaction success message (S61), if the verification fails, the remote server sends a transaction failure message (S62). In this way, the procedure of secondary checking is achieved, so as to increase the safety and reliability.

综上所述,通过本发明产生动态密码执行远程安全认证的方法及其移动通信装置,使用者与电子商家或银行进行电子交易时,可以利用一次性密码或动态性密码技术来确保身分的正确性。此外,使用者仅需配戴单一移动通信装置,即可与用于进行电子交易的远程服务器进行连结,以及远程安全认证。相较于传统需要额外携带一独立动态密码产生装置,或者必须通过终端机才可以进行动态性密码的取得以及核对,本发明确实提供一个较为方便的远程安全认证方式。还由于本发明亦可利用下载扩充等方式,得以对应多个远程服务器进行远程安全认证,因此大幅减少过去使用者可能为能够因应不同的交易对象而必须携带多种不同对应的动态密码产生装置,减轻使用者所需携带对象的负担,并增添使用上的便利性,还可以推广于大众使用。此外,于本发明中,具有动态密码产生模组的集成电路芯片可设置于一供用户识别模组卡插设的卡槽,相较于传统必须通过行动通讯公司所提供的用户识别模组卡才能进行扩充功能的方式,本发明可以适用于不同的行动通讯公司,有利于大众普及。In summary, through the method of generating a dynamic password to perform remote security authentication of the present invention and its mobile communication device, when a user conducts electronic transactions with an electronic merchant or a bank, the one-time password or dynamic password technology can be used to ensure the correctness of identity. sex. In addition, the user only needs to wear a single mobile communication device to connect with a remote server for electronic transactions and conduct remote security authentication. Compared with traditional methods that need to carry an additional independent dynamic password generating device, or obtain and verify dynamic passwords only through a terminal, the present invention does provide a more convenient remote security authentication method. Also, because the present invention can also use methods such as download expansion to perform remote security authentication corresponding to multiple remote servers, it greatly reduces the possibility that users in the past may have to carry a variety of different corresponding dynamic password generators in order to be able to respond to different transaction objects. It reduces the burden on the objects that users need to carry, increases the convenience of use, and can also be popularized for public use. In addition, in the present invention, the integrated circuit chip with the dynamic password generating module can be set in a card slot for inserting the user identification module card, compared with the traditional user identification module card that must be provided by the mobile communication company Only in the way of expanding functions, the present invention can be applied to different mobile communication companies, which is beneficial to the popularization of the public.

以上已将本发明做一详细说明,惟以上所述者,仅为本发明的一优选实施例而已,当不能限定本发明实施的范围。即凡依本发明权利要求所作的均等变化与修饰等,皆应仍属本发明的专利涵盖范围内。The present invention has been described in detail above, but what is described above is only a preferred embodiment of the present invention, and should not limit the implementation scope of the present invention. That is, all equivalent changes and modifications made according to the claims of the present invention should still fall within the scope of the patent of the present invention.

Claims (20)

1.一种产生动态密码执行远程安全认证的方法,应用于一移动通信装置(10)中,其特征在于,包括以下步骤:1. A method for generating a dynamic password to perform remote security authentication, applied in a mobile communication device (10), is characterized in that, comprising the following steps: 建立所述移动通信装置(10)与一独立集成电路芯片(30)之间的电连接关系,所述集成电路芯片(30)内设有一动态密码产生模组(31);Establishing an electrical connection relationship between the mobile communication device (10) and an independent integrated circuit chip (30), the integrated circuit chip (30) being provided with a dynamic password generation module (31); 操作所述移动通信装置(10)以启动所述动态密码产生模组(31),所述动态密码产生模组(31)与一远程服务器(20)分别产生一相对应的动态认证码,且所述动态认证码显示于所述移动通信装置(10)的显示介面(12);Operating the mobile communication device (10) to start the dynamic password generation module (31), the dynamic password generation module (31) and a remote server (20) respectively generate a corresponding dynamic authentication code, and The dynamic authentication code is displayed on the display interface (12) of the mobile communication device (10); 通过一与所述远程服务器(20)相连的回传工具将所述显示介面(12)上的动态认证码输入至所述远程服务器(20);以及inputting the dynamic authentication code on the display interface (12) to the remote server (20) through a return tool connected to the remote server (20); and 所述远程服务器(20)核对所接收的动态认证码是否相符,以进行远程安全认证。The remote server (20) checks whether the received dynamic authentication codes are consistent, so as to perform remote security authentication. 2.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,所述动态密码产生模组(31)产生对应多个远程服务器(20)的动态认证码。2. The method for generating a dynamic password to perform remote security authentication according to claim 1, characterized in that, the dynamic password generation module (31) generates dynamic authentication codes corresponding to a plurality of remote servers (20). 3.根据权利要求2所述的产生动态密码执行远程安全认证的方法,其特征在于,还包括一选择欲对应的远程服务器(20)的步骤。3. The method for generating a dynamic password to perform remote security authentication according to claim 2, further comprising a step of selecting a corresponding remote server (20). 4.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,还包括一输入个人识别码的步骤以及核对所述个人识别码是否相符的步骤。4. The method for generating a dynamic password for remote security authentication according to claim 1, further comprising a step of inputting a personal identification code and a step of checking whether the personal identification code matches. 5.根据权利要求4所述的产生动态密码执行远程安全认证的方法,其特征在于,所述核对个人识别码是否相符的步骤于所述移动通信装置(10)内进行。5. The method for generating a dynamic password to perform remote security authentication according to claim 4, characterized in that the step of checking whether the personal identification codes match is performed in the mobile communication device (10). 6.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,还包括一根据交易数据产生电子签章以及核对所述电子签章是否相符的步骤。6. The method for generating a dynamic password to perform remote security authentication according to claim 1, further comprising a step of generating an electronic signature according to the transaction data and checking whether the electronic signature matches. 7.根据权利要求6所述的产生动态密码执行远程安全认证的方法,其特征在于,核对所述电子签章于所述远程服务器(20)内进行。7. The method for generating a dynamic password to perform remote security authentication according to claim 6, characterized in that, verifying the electronic signature is performed in the remote server (20). 8.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,还包括一发送核对成功信息的步骤。8. The method for generating a dynamic password to perform remote security authentication according to claim 1, further comprising a step of sending verification success information. 9.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,还包括一发送核对失败信息的步骤。9. The method for generating a dynamic password to perform remote security authentication according to claim 1, further comprising a step of sending verification failure information. 10.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,所述集成电路芯片(30)设置于一供用户识别模组卡插设的卡槽上。10. The method for generating a dynamic password to perform remote security authentication according to claim 1, characterized in that the integrated circuit chip (30) is arranged on a card slot for insertion of a user identification module card. 11.根据权利要求1所述的产生动态密码执行远程安全认证的方法,其特征在于,所述回传手段通过因特网、行动通讯网络或固定电话系统输入至所述远程服务器(20)。11. The method for generating a dynamic password to perform remote security authentication according to claim 1, characterized in that the return means is input to the remote server (20) through the Internet, a mobile communication network or a fixed telephone system. 12.一种产生动态密码执行远程安全认证的移动通信装置,其特征在于:12. A mobile communication device that generates a dynamic password to perform remote security authentication, characterized in that: 所述移动通信装置(10)电连接于一独立集成电路芯片(30)内,所述集成电路芯片(30)具有至少一动态密码产生模组(31),所述动态密码产生模组(31)通过操作所述移动通信装置(10)而启动,并与一远程服务器(20)分别产生一相对应的动态认证码,所述动态认证码显示于所述移动通信装置(10)的显示介面(12),显示于所述显示介面(12)上的动态认证码经一连接于所述远程服务器(20)的密码回传手段传送至所述远程服务器(20),且通过一设置于所述远程服务器(20)内的密码核对模组(21)来核对是否与所述远程服务器(20)内相对应的动态认证码相符,以进行远程安全认证。13.根据权利要求12所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述集成电路芯片(30)设置于一供用户识别模组卡插设的卡槽上。The mobile communication device (10) is electrically connected in an independent integrated circuit chip (30), and the integrated circuit chip (30) has at least one dynamic password generation module (31), and the dynamic password generation module (31 ) is activated by operating the mobile communication device (10), and generates a corresponding dynamic authentication code with a remote server (20), and the dynamic authentication code is displayed on the display interface of the mobile communication device (10) (12), the dynamic authentication code displayed on the display interface (12) is sent to the remote server (20) through a password return means connected to the remote server (20), and through a The password checking module (21) in the remote server (20) checks whether it is consistent with the corresponding dynamic authentication code in the remote server (20), so as to perform remote security authentication. 13. The mobile communication device for generating a dynamic password for performing remote security authentication according to claim 12, characterized in that the integrated circuit chip (30) is arranged on a card slot for insertion of a subscriber identification module card. 14.根据权利要求12所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述移动通信装置(10)具有一输入介面(11)。14. The mobile communication device for generating a dynamic password to perform remote security authentication according to claim 12, characterized in that the mobile communication device (10) has an input interface (11). 15.根据权利要求12所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述显示介面(12)为一平板显示器。15. The mobile communication device for generating a dynamic password for performing remote security authentication according to claim 12, wherein the display interface (12) is a flat panel display. 16.根据权利要求12所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述独立集成电路芯片(30)内设有一储存单元(32)。16. The mobile communication device for generating a dynamic password for performing remote security authentication according to claim 12, characterized in that a storage unit (32) is arranged in the independent integrated circuit chip (30). 17.根据权利要求16所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述储存单元(32)中储存至少一用来对应于不同远程服务器(20)的个人登录数据。17. The mobile communication device generating a dynamic password according to claim 16 and performing remote security authentication, wherein at least one personal login data corresponding to different remote servers (20) is stored in the storage unit (32) . 18.根据权利要求17所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述个人登录数据由行动通讯网络或因特网下载至所述储存单元(32)。18. The mobile communication device for generating a dynamic password for remote security authentication according to claim 17, wherein the personal login data is downloaded to the storage unit (32) via a mobile communication network or the Internet. 19.根据权利要求17所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述个人登录数据于出厂时直接烧录至所述储存单元(32)内。19. The mobile communication device for generating a dynamic password for remote security authentication according to claim 17, wherein the personal login data is directly burned into the storage unit (32) when leaving the factory. 20.根据权利要求17所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,储存于所述储存单元(32)内的个人登录数据通过操作所述移动通信装置(10)进行更改或删除。20. The mobile communication device for generating a dynamic password according to claim 17 and performing remote security authentication, characterized in that the personal login data stored in the storage unit (32) is performed by operating the mobile communication device (10) change or delete. 21.根据权利要求12所述的产生动态密码执行远程安全认证的移动通信装置,其特征在于,所述密码回传手段通过因特网、行动通讯网络或固定电话系统传输至所述远程服务器(20)。21. The mobile communication device for generating a dynamic password to perform remote security authentication according to claim 12, characterized in that the password return means is transmitted to the remote server (20) through the Internet, a mobile communication network or a fixed telephone system .
CN200810212103A 2008-09-05 2008-09-05 Method for generating dynamic password to execute remote security authentication and mobile communication device thereof Pending CN101667915A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200810212103A CN101667915A (en) 2008-09-05 2008-09-05 Method for generating dynamic password to execute remote security authentication and mobile communication device thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN200810212103A CN101667915A (en) 2008-09-05 2008-09-05 Method for generating dynamic password to execute remote security authentication and mobile communication device thereof

Publications (1)

Publication Number Publication Date
CN101667915A true CN101667915A (en) 2010-03-10

Family

ID=41804370

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200810212103A Pending CN101667915A (en) 2008-09-05 2008-09-05 Method for generating dynamic password to execute remote security authentication and mobile communication device thereof

Country Status (1)

Country Link
CN (1) CN101667915A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104778384A (en) * 2014-01-13 2015-07-15 全宏科技股份有限公司 Authorization server, authorization method and computer program product
CN106415611A (en) * 2014-04-09 2017-02-15 凯帝仕系统有限公司 Self-authenticating chips
CN106656993A (en) * 2016-11-04 2017-05-10 中国银联股份有限公司 Dynamic verification code verifying method and apparatus

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104778384A (en) * 2014-01-13 2015-07-15 全宏科技股份有限公司 Authorization server, authorization method and computer program product
CN106415611A (en) * 2014-04-09 2017-02-15 凯帝仕系统有限公司 Self-authenticating chips
US10659455B2 (en) 2014-04-09 2020-05-19 Cardex Systems Inc. Self-authenticating chips
CN106415611B (en) * 2014-04-09 2020-11-27 凯帝仕系统有限公司 self-authentication chip
US11336642B2 (en) 2014-04-09 2022-05-17 Cardex Systems Inc. Self-authenticating chips
US12021863B2 (en) 2014-04-09 2024-06-25 Cardex Systems Inc. Self-authenticating chips
CN106656993A (en) * 2016-11-04 2017-05-10 中国银联股份有限公司 Dynamic verification code verifying method and apparatus
CN106656993B (en) * 2016-11-04 2019-12-06 中国银联股份有限公司 Dynamic verification code verification method and device

Similar Documents

Publication Publication Date Title
EP1807966B1 (en) Authentication method
US9344896B2 (en) Method and system for delivering a command to a mobile device
CN102542453B (en) Mobile payment identity verification method
KR100858144B1 (en) User authentication method and device in internet site using mobile communication terminal
US20110185181A1 (en) Network authentication method and device for implementing the same
CN101668288B (en) Identity authenticating method, identity authenticating system and terminal
CN101699892A (en) Method and device for generating dynamic passwords and network system
KR101297166B1 (en) Method and System for Providing User Authorization Service Using Bio Information and Mobile Communication Terminal for Transmitting Authorization Information Using Bio Information
WO2009048191A1 (en) Security authentication method and system
CN101184107A (en) Network transaction system and method for executing network transaction using the system
KR101125088B1 (en) System and Method for Authenticating User, Server for Authenticating User and Recording Medium
CN101667915A (en) Method for generating dynamic password to execute remote security authentication and mobile communication device thereof
KR20160137192A (en) User authentication server and method for authenticating user
JP2005182212A (en) Information processing method, information processing system, program and recording medium
JP2018036790A (en) Authentication device, identity confirmation method, and program
JP7223196B1 (en) Information processing device, information processing method, and program
KR20070076575A (en) How to handle customer authentication
KR20070076576A (en) Payment Approval Process
JP2008152612A (en) Authentication system and authentication method
TW201010371A (en) Authentication method by generating dynamic password over mobile communication interface, and mobile communication device generating dynamic password for authentication
TWI610195B (en) Identifying system, identifying method and a computer-readable media
KR20060102458A (en) Customer Authentication Method and System in Internet Banking, Server and Record Media for It
KR20100136047A (en) Seed combination type OTP operation method and system and recording medium
KR20070077481A (en) Customer Authentication Relay Server
KR20090006815A (en) How to handle customer authentication

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication

Open date: 20100310