Device and method of removing security on content and logging into server
Abstract
A device for removing security on content using biometric information includes a memory configured to store content on which security has been set based on first biometric information of a user; and a controller configured to obtain second biometric information of the user, which is of a different type than the first biometric information, and remove the security on the content based on the second biometric information, in response to a user input for executing the content.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
15 claims: 10 independent, 5 dependent
- 1一種用於使用生物識別資訊移除內容保全的裝置,所述裝置包括: 記憶體,其經組態以儲存保全已基於使用者的第一生物識別資訊設定的內容;以及 控制器,其經組態以獲得類型不同於所述第一生物識別資訊的所述使用者的第二生物識別資訊,且回應於用於執行所述內容的使用者輸入,基於所述第二生物識別資訊移除對所述內容的所述保全。
- 2如申請專利範圍第1項所述的裝置,其中所述控制器經進一步組態以在使用所述第二生物識別資訊鑑認了所述使用者時使用密碼及解密密鑰中的至少一者移除對所述內容的所述保全。
- 3如申請專利範圍第2項所述的裝置,其中: 所述密碼為用於所述第一生物識別資訊及所述第二生物識別資訊兩者的共同密碼,或是對應於所述第二生物識別資訊的第二密碼中的至少一者;且 當對所述內容的所述保全經移除時,所述控制器經進一步組態以使用所述密碼移除關於對所述內容的存取的限制。
- 4如申請專利範圍第2項所述的裝置,其中: 所述解密密鑰為通常用於所述第一生物識別資訊及所述第二生物識別資訊兩者的共同解密密鑰,或是對應於所述第二生物識別資訊的第二解密密鑰中的至少一者;且 當對所述內容的所述保全經移除時,所述控制器經進一步組態以使用所述解密密鑰解密經加密的所述內容。
- 5如申請專利範圍第4項所述的裝置,其中,當所述解密密鑰為所述第二解密密鑰時,所述控制器經進一步組態以使用所述第二解密密鑰解密對應於所述第一生物識別資訊的經加密第一加密密鑰,且使用藉由解密所述經加密第一加密密鑰獲得的第一解密密鑰解密所述內容。
- 6如申請專利範圍第1項所述的裝置,其中對應於所述第二生物識別資訊的第二解密密鑰是使用用於使用者鑑認且預先儲存於所述記憶體中的基本第二生物識別資訊所產生。
- 7如申請專利範圍第1項所述的裝置,其中所述控制器經進一步組態以在所述第二生物識別資訊是經由用於選擇所述第一生物識別資訊及所述第二生物識別資訊中的一者的畫面選擇時,獲得所述第二生物識別資訊。
- 8如申請專利範圍第1項所述的裝置,其進一步包括通信器, 其中所述第二生物識別資訊是經由所述通信器自至少一個外部裝置獲得。
- 9如申請專利範圍第1項所述的裝置,其進一步包括至少一個生物識別技術感測器,其經組態以辨識所述使用者的生物識別資訊, 其中所述第二生物識別資訊是自所述至少一個生物識別技術感測器獲得。
- 10一種用於藉由使用生物識別資訊登入至伺服器的裝置,所述裝置包括: 通信器,其經組態以與位於所述裝置外的所述伺服器通信;以及 控制器,其經組態以基於使用者的第一生物識別資訊登入至所述伺服器,且在所述裝置自所述伺服器登出之後,獲得類型不同於所述第一生物識別資訊的所述使用者的第二生物識別資訊,經由所述通信器將與所述第二生物識別資訊相關的密碼傳輸至所述伺服器,且在使用所述密碼鑑認了所述使用者時重新登入至所述伺服器。
- 11一種使用生物識別資訊移除內容保全的方法,所述方法包括: 儲存基於使用者的第一生物識別資訊設定了保全的內容; 根據執行所述內容的請求,獲得類型不同於所述第一生物識別資訊的所述使用者的第二生物識別資訊;以及 基於所述第二生物識別資訊移除對所述內容的所述保全。
- 12如申請專利範圍第11項所述的方法,其中所述保全的所述移除包括,回應於使用所述第二生物識別資訊鑑認了所述使用者,使用密碼及解密密鑰中的至少一者移除對所述內容的所述保全。
- 13如申請專利範圍第12項所述的方法,其中: 所述密碼為通常用於所述第一生物識別資訊及所述第二生物識別資訊兩者的共同密碼,或是對應於所述第二生物識別資訊的第二密碼中的至少一者;且 所述保全的所述移除包括使用所述密碼移除關於對所述內容的存取的限制。
- 14如申請專利範圍第12項所述的方法,其中: 所述解密密鑰為通常用於所述第一生物識別資訊及所述第二生物識別資訊兩者的共同解密密鑰,或是對應於所述第二生物識別資訊的第二解密密鑰中的至少一者;且 所述保全的所述移除包括使用所述解密密鑰解密經加密的所述內容。
- 15一種使用生物識別資訊登入至伺服器的方法,所述方法包括: 基於使用者的第一生物識別資訊登入至所述伺服器; 當自所述伺服器登出時,獲得類型不同於所述第一生物識別資訊的所述使用者的第二生物識別資訊; 將與所述第二生物識別資訊相關的密碼傳輸至所述伺服器;以及 當使用傳輸至所述伺服器的所述密碼鑑認了所述使用者時,重新登入至所述伺服器。
Independent claims15
960 paragraphs in 1 section, as filed
Device and method for setting or removing content preservation
DEVICE AND METHOD OF SETTING OR REMOVING SECURITY ON CONTENT
Apparatus and methods that comply with one or more exemplary embodiments relate to devices and methods for setting or removing content security, and more specifically, to devices and methods for setting or removing content security by using biometric information .
Biometrics is an authentication method in which personal unique biometric information (such as fingerprints, voice, face, iris, sweat gland structure and blood vessels) is extracted and informationized. Personal characteristics (such as face shape, voice, fingerprints, and eyeballs) cannot be illegally used or copied by another person (as in the case of keys or passwords), and are rarely changed or lost. Therefore, these characteristics are widely used in the field of security.
Recently, a technology that uses biometric information for user authentication has been developed.
Therefore, there is a need to study methods for setting and removing content preservation by effectively using biometric information.
Aspects of one or more exemplary embodiments provide an apparatus and method for setting or removing content security by using multiple pieces of biometric information.
Additional aspects will be partly set forth in the following description, and partly will be obvious from the description, or can be learned by practicing the exemplary embodiments presented.
According to an aspect of an exemplary embodiment, an apparatus for removing content security using biometric information is provided, the device includes: a memory configured to store security settings based on the user's first biometric information And a controller configured to obtain second biometric information of the user whose type is different from the first biometric information, and respond to user input for executing the content, based on The second biometric information removes the preservation of the content.
The controller may be configured to use at least one of a password and a decryption key to remove the security of the content when the user is authenticated using the second biometric information.
The password may be a common password used for both the first biometric information and the second biometric information, or at least one of the second passwords corresponding to the second biometric information, and When the security of the content is removed, the controller may be configured to use the password to remove restrictions on access to the content.
The decryption key may be a common decryption key generally used for both the first biometric information and the second biometric information or the second decryption key corresponding to the second biometric information At least one, and when the security of the content is removed, the controller can be configured to decrypt the encrypted content using the decryption key.
When the decryption key is the second decryption key, the controller may be configured to use the second decryption key to decrypt the encrypted first encryption key corresponding to the first biometric information Key, and decrypt the content using the first decryption key obtained by decrypting the encrypted first encryption key.
The second decryption key corresponding to the second biometric information can be generated using basic second biometric information for user authentication and pre-stored in the memory.
The controller may be configured to obtain the first biometric information when the second biometric information is selected via a screen for selecting one of the first biometric information and the second biometric information 2. Biometric information.
The device may further include a communicator, wherein the second biometric information may be obtained from at least one external device via the communicator.
The device may further include at least one biometric technology sensor configured to recognize biometric information of the user, wherein the second biometric information is obtained from the at least one biometric technology sensor .
According to an aspect of another exemplary embodiment, there is provided a device for logging in to a server by using biometric information. The device includes a communicator configured to communicate with the device located outside the device. Server communication; and a controller configured to log in to the server based on the user's first biometric information, and after the device is logged out from the server, the acquisition type is different from the first The second biometric information of the user of a biometric information, the password related to the second biometric information is transmitted to the server via the communicator, and the password is used to authenticate all Log in to the server again when the user is mentioned.
According to an aspect of another exemplary embodiment, there is provided a method for removing content preservation using biometric information, the method comprising: storing content that is set to be preserved based on the user's first biometric information; The request for the content obtains second biometric information of the user whose type is different from the first biometric information; and removes the security of the content based on the second biometric information.
The removing of the security may include, in response to authenticating the user using the second biometric information, using at least one of a password and a decryption key to remove the security of the content .
The password may be a common password commonly used for both the first biometric information and the second biometric information, or at least one of the second passwords corresponding to the second biometric information, And the removal of the security includes using the password to remove the restriction on the access to the content.
The decryption key may be a common decryption key generally used for both the first biometric information and the second biometric information or the second decryption key corresponding to the second biometric information At least one, and the removal of the security may include decrypting the encrypted content using the decryption key.
When the decryption key is the second decryption key, the decryption of the content may include using the second decryption key to decrypt the encrypted first encryption key corresponding to the first biometric information And decrypt the content using a first decryption key obtained by decrypting the encrypted first encryption key.
The second decryption key corresponding to the second biometric information can be generated using the basic second biometric information for user authentication and pre-stored in the memory.
The obtaining of the second biometric information may include, when the second biometric information is selected via a screen for selecting one of the first biometric information and the second biometric information , To obtain the second biometric information.
The obtaining of the second biometric information may include obtaining the second biometric information from at least one external device.
The obtaining of the second biometric information may include obtaining the second biometric information from at least one biometric technology sensor configured to recognize the user's biometric information.
According to an aspect of another exemplary embodiment, there is provided a method for logging in to a server by using biometric information, the method comprising: logging in to the server based on a user's first biometric information; when When logging out from the server, obtain the second biometric information of the user whose type is different from the first biometric information; transmit the password related to the second biometric information to the server And when the user is authenticated using the password received by the server, re-login to the server.
According to an aspect of another exemplary embodiment, there is provided a method for managing the preservation of content stored on a first device, the method comprising: obtaining first biometric information; receiving second biometric information from a second device; And setting the security of the content based on the first biometric information and the second biometric information.
Setting the security of the content based on the first biometric information and the second biometric information may include: generating a first encryption key associated with the first biometric information; using the first biometric information An encryption key encrypts the content; receives a second encryption key associated with the second biometric information; and encrypts the encrypted content using the second encryption key.
Setting the security of the content based on the first biometric information and the second biometric information may include: generating a first encryption key associated with the first biometric information; receiving and A second encryption key associated with the second biometric information; generating a third encryption key by combining at least a part of the first encryption key and at least a part of the second encryption key; and using the The third encryption key encrypts the content.
According to an aspect of another exemplary embodiment, there is provided a method for managing the preservation of content stored on a first device. The method includes: obtaining first biometric information; The security of the content; receiving the second biometric information from the second device; and removing the content from the content based on the second biometric information. The security is based on the first biometric information. The security may include: generating a first encryption key associated with the first biometric information; encrypting the content using the first encryption key; generating a first decryption key corresponding to the first encryption key And using a second encryption key associated with the second biometric information to encrypt the first decryption key.
One or more exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, it should be understood that the exemplary embodiments may be embodied in many different forms, and should not be construed as being limited to the exemplary embodiments set forth herein; to be precise, these exemplary embodiments are provided to make the present disclosure The content will be thorough and complete, and fully convey the concept of one or more exemplary embodiments to those having ordinary knowledge in the art. In the following description, well-known functions or constructions are not described in detail, because the well-known functions or constructions will confuse one or more exemplary embodiments with unnecessary details, and similar reference numerals in the drawings indicate throughout Similar or similar elements of this specification.
By referring to the following detailed description of the exemplary embodiments and the accompanying drawings, it is easier to understand the advantages and features of one or more exemplary embodiments and methods for implementing the exemplary embodiments. In addition, when describing the one or more exemplary embodiments, detailed descriptions about related well-known functions or configurations that can impair the clarity of the gist of the present invention are omitted. It should be understood that although the terms "first", "second", etc. may be used herein to describe various components, these components should not be limited by these terms. These components are only used to distinguish one component from another.
Hereinafter, the device according to one or more exemplary embodiments will be described in detail with reference to accompanying drawings. Terms such as "module" or "unit" are only used for the purpose of facilitating the preparation of this specification, and therefore should be considered in a broad sense and not limited to any specific meaning or effect.
Examples of the devices described in this article include mobile phones, smart phones, tablet personal computers (PC), laptops, digital broadcasting terminals, personal digital assistants (PDAs), portable multimedia players Device (portable multimedia player; PMP) and navigation device. However, it will be obvious to those with ordinary knowledge in the art that the configuration according to one or more exemplary embodiments can also be applied to fixed terminals, such as digital television (TV) or desktop computers, except in the following cases: When the configuration can only be applied to mobile terminals.
In this specification, when a zone is "connected" to another zone, the zone can not only be "directly connected", but can also be "electrically connected" via another device between the zones. In addition, when a region "includes" an element, the region may further include another element, rather than not including other elements, or stated differently in other ways.
As used herein, the term "and/or" includes any and all combinations of one or more of the associated listed items. When preceding the component list, expressions such as "at least one of..." modify the entire component list and do not modify individual components of the list.
The terms used herein will first be described together with a brief description of one or more exemplary embodiments.
The device according to the exemplary embodiment can set content security by using biometric information. The device can set content security by using specific biometric information (first biometric information), and by using another biometric information that is different from the biometric information used to set security (the first biometric information) Identification information (second biometric information) to remove the security of the content.
Throughout the specification, biometric information can mean information used to identify each person, such as fingerprints or irises that can be detected from each person's body.
Examples of biometric information include fingerprints, voice, face, iris, palm print, vein distribution, retina, movement patterns (such as gait), electrocardiogram (ECG), and palm print patterns, but are not limited thereto.
Examples of content include text (for example, work-related documents, memos, emails, text messages, and e-books), still images (for example, photos and videos), moving images (for example, video on demand (VOD), TV programs, user-created content (UCC), YouTube videos, music videos, and movies), application executable files, voice files, and web pages, but not limited to these. For example, the content may be a group of certain files stored in the device, that is, a folder indicating the location where the files are classified and stored. The folder can contain another folder or file. In other words, the term "content" can have a broad meaning that includes specific data or files.
Throughout the specification, setting content preservation may mean that the access to the content is restricted, and removing content preservation may mean that the restriction on the access to the content is removed. Alternatively, the setting or removal of content preservation may mean that the content is encrypted or decrypted.
For example, restricting access to content may mean that when content preservation is set, at least one of execution, editing, copying, and deletion of content is restricted by using a password. In addition, removing restrictions on access to content can mean that when the password obtained when setting content security matches the password obtained when removing content security, the execution, editing, copying and copying of content are permitted. Delete at least one of them. Alternatively, restricting access to the content may mean that at least one of the reference information of the content, the file name of the content, the reference information of the folder containing the content, and the folder name is encrypted so that the content is not discovered . Here, the reference information may be information indicating the path or address (inode number or similar) used to access a certain file or folder in the file system.
As another example, encrypted content may mean that the content is converted into meaningless, for example, converted into encrypted text. Encrypted text is obtained by converting the content by using a certain algorithm for security. In detail, encryption means converting specific information into encrypted text by using an encryption key (such as a specific bit string), and decryption means recovering the converted information by using a decryption key. Throughout the specification, the encryption key can mean the data obtained by processing the biometric information (for example, a specific bit string) instead of the biometric information itself, and the encryption key is used to encrypt specific content.
The method of setting or removing content security by using biometric information will be described in detail later with reference to the drawings.
Throughout the specification, the possible type of the second biometric information that is different from the first biometric information is different from the first biometric information. For example, the first biometric information may be fingerprint information, and the second biometric information may be iris information. The second biometric information that is different from the first biometric information may be of the same type as the first biometric information. For example, both the first and second biometric information can be fingerprint information, but they can be fingerprint information obtained from different fingers of the same user or from fingers of different users. Alternatively, the second biometric information that is different from the first biometric information may be biometric information obtained from a biometric technology module installed in a different device. Alternatively, the second biometric information that is different from the first biometric information may be biometric information obtained from different biometric technology modules installed in one device. Alternatively, the second biometric information that is different from the first biometric information may be biometric information obtained from a biometric technology module installed in a device.
Throughout the specification, the biometric technology module can be a module that can obtain specific biometric information from a person's body. The biometric technology module may include a sensor for sensing the biometric information of the person. For example, the biometric technology module may include a fingerprint sensor or a palm pattern sensor, but it is not limited thereto.
For example, the biometric technology module may include a camera. The camera can take pictures of the person's face or the person's iris.
Alternatively, the biometric technology module may include a microphone for obtaining the voice of the person. The biometric technology module described above is only an example, and therefore is not limited thereto.
According to an exemplary embodiment, when a device sets security for specific content by using fingerprint information, the device can remove it by using not only fingerprint information but also iris information (which is different biometric information) The preservation of specific content.
Therefore, even if the device cannot obtain the fingerprint information used to set the security of the specific content (for example, the biometric technology module used to obtain the fingerprint information cannot be used due to theft, loss or malfunction), the security of the specific content is also It can be removed by using a biometric technology module used to obtain other biometric information (such as iris information).
In other words, according to an exemplary embodiment, even if the security is set to specific content by using fingerprint information, if the user loses or does not currently have a biometric module for obtaining fingerprint information, the user can still access the security Specific content that has been set.
One or more exemplary embodiments will now be described in detail with reference to the accompanying drawings.
Fig. 1 is a diagram for describing an apparatus 100 according to an exemplary embodiment.
1, a user may own multiple devices, such as a device 100 (for example, a smart phone), a watch-type wearable device 401, and a glasses-type wearable device 402. At this time, the watch-type wearable device 401 may include a module for obtaining fingerprint information 10. The glasses-type wearable device 402 may include a module for obtaining iris information 12. The device 100 can receive (which is a communication unit) fingerprint information 10 and iris information 12 from a watch-type wearable device 401 and a glasses-type wearable device 402 that are paired with the device 100.
In order to protect the content c10 (for example, an identification (ID) card) stored in the device 100, the user can set the security of the content c10 by using the fingerprint information 10.
The device 100 can store the content c10 after setting the security of the content c10 based on the fingerprint information 10 obtained from the watch-type wearable device 401, and can later remove the content c10 based on the fingerprint information 10 obtained from the watch-type wearable device 401 Of preservation.
However, the user may want to remove the security of the content c10 in a situation where the watch-type wearable device 401 is not available.
According to an exemplary embodiment, even when the user cannot use the watch-type wearable device 401 (for example, even when the watch-type wearable device 401 is stolen, lost, or malfunctions), the users access to the content can be removed. Security set by c10.
In other words, according to an exemplary embodiment, the security set for the content c10 can be removed by using the iris information 12 obtained from the glasses-type wearable device 402.
FIG. 2 is a conceptual diagram of the controller 130 for setting or removing content preservation according to an exemplary embodiment.
2, the controller 130 of the device 100 may include functional modules, such as a biometric information obtainer 131, a biometric information modifier 132, a feature information extractor 133, a feature information matcher 134, a content preserver 135, and biometrics Information requester 136. For the convenience of description, the functional modules according to an exemplary embodiment are classified, and therefore, at least one of the functional modules may be omitted or changed, and at least two of the functional modules may be combined. The functional module can be configured as hardware, software, or a combination of hardware and software. Alternatively, a part of the functional module may be configured as hardware, and another part of the functional module may be configured as software.
2, the controller 130 may be in a registration mode 201 for registering the user's biometric information, or in an authentication mode 202 for authenticating the user by using the registered biometric information.
According to an exemplary embodiment, when the controller 130 is in the registration mode 201, the biometric information obtainer 131 can use the sensing unit 140 of FIG. 102 or the audio-video of FIG. 102 to be described in more detail below. AV) The input unit 160 obtains the user's biometric information. Alternatively, the biometric information obtainer 131 may receive biometric information from the watch-type wearable device 401 and the glasses-type wearable device 402 via the communication unit 150 of FIG. 101 which will be described in more detail below.
According to an exemplary embodiment, the biometric information modifier 132 can obtain modified biometric information by modifying the obtained biometric information. For example, when it is determined that the biometric information (for example, fingerprint image, iris image, vein image, or facial image) has a distorted shape or a low-resolution area, the biometric information modifier 132 can be executed by using statistical data Image processor or image processing function to correct or restore distorted shapes or areas with low resolution. When the quality of the biometric information is excellent, the operation of the biometric information modifier 132 can be omitted.
According to an exemplary embodiment, the feature information extractor 133 can extract feature information from the corrected or uncorrected biometric information.
For example, when the biometric information is fingerprint information, the feature information extractor 133 can extract feature information including at least one feature point (referred to as a small pattern) from the fingerprint information. The small pattern may include feature points indicating the bifurcation point, the end point, the core, and the difference. In addition, the small pattern may include feature points indicating the direction or shape of the ridge line and the valley between the ridge line. In this case, the feature information can be a template in which the feature points are arranged in a preset format (or frame or bit string).
As another example, when the biometric information is iris information, the feature information extractor 133 can extract the unique pattern of the iris. In this case, the characteristic information may be an iris template configured with a template for the unique pattern of the iris. Alternatively, when the biometric information is vein information, the feature information extractor 133 may extract the unique pattern of the vein. In this case, the characteristic information may be a vein template configured with a template for the unique pattern of the vein.
According to an exemplary embodiment, the controller 130 may store the characteristic information extracted by the characteristic information extractor 133 in the memory 170 in order to use the characteristic information as the biometric information (which is the basis for user authentication) ). In the following, the basic biometric information will also be referred to as basic biometric information. In addition, the controller 130 can store fingerprint information, voice information, facial information, iris information, palmprint information, vein information, retina information, movement pattern information, and ECG information in the memory 170 to be used as basic biometric information. Feature information. The characteristic information of the biometric information stored in the memory 170 can be registered and used as the basic biometric information for user authentication.
When feature information of a plurality of pieces of basic biometric information is registered in the memory 170, the controller 130 may be in the authentication mode 202.
When the controller 130 is in the authentication mode 202, the biometric information obtainer 131 can obtain the user's biometric information from the sensing unit 140 or the AV input unit 160. Alternatively, the biometric information obtainer 131 may receive biometric information from the watch-type wearable device 401 and the glasses-type wearable device 402 via the communication unit 150.
According to an exemplary embodiment, the biometric information modifier 132 can obtain modified biometric information by modifying the obtained biometric information.
The feature information extractor 133 can extract feature information from the corrected or uncorrected biometric information. The feature information matcher 134 can match the feature information extracted by the feature information extractor 133 with the feature information of the basic biometric information stored in the memory 170 in advance. Then, the feature information matcher 134 may calculate a matching score indicating the degree to which the feature information of the two segments match each other as a matching result. The matching score can be calculated (for example) based on statistical data or probability function, taking into account the difference, direction, or configuration similarity between the feature points of the feature template of the obtained biometric information and the feature points of the basic biometric information. .
The feature information matcher 134 can compare the matching score with a specific threshold, and when the matching score is equal to or higher than the specific threshold, it can determine that the user authentication has been successful. Here, the specific threshold may be preset by the manufacturer of the device 100, the provider of the application installed in the device 100, or the provider of the operating system. Alternatively, the specific threshold value may be assigned by the user via the user interface (UI). At the same time, the user can set the threshold for each of the multiple pieces of biometric information.
When the user authentication is successful, the content preserver 135 can set or remove content preservation.
For example, the content access limiter/allower 135-1 of the content protector 135 can restrict or allow access to the content. In addition, the content encryptor/decryptor 135-2 of the content protector 135 can encrypt or decrypt the content. Alternatively, both the content access limiter/allower 135-1 and the content encryptor/decryptor can be used to set or remove content security.
According to an exemplary embodiment, when the user authentication fails, the biometric information requester 136 can request the user's biometric information again. For example, the controller 130 may transmit a signal requesting the user's biometric information to the watch-type wearable device 401 or the glasses-type wearable device 402. In response to the signal, the watch-type wearable device 401 or the glasses-type wearable device 402 may provide a notification screen for re-requesting biometric information. When the biometric information is input, the watch-type wearable device 401 or the glasses-type wearable device 402 can transmit the input biometric information to the device 100. Alternatively, in response to the signal, the watch-type wearable device 401 or the glasses-type wearable device 402 may transmit the previously input biometric information to the device 100 again. After receiving the biometric information again, the device 100 may try to authenticate the user by using the obtained biometric information.
3 is a flowchart of a method for setting and removing content preservation using different biometric information according to an exemplary embodiment.
3, in operation S301, the controller 130 according to an exemplary embodiment may set content preservation by using the first biometric information.
As shown in FIG. 1, the controller 100 according to an exemplary embodiment can set the security of the content c10 by using the fingerprint information 10 obtained by the watch-type wearable device 401. Here, the content c10 may be data related to the user's personal information (such as an ID card), but is not limited to this.
For example, the watch-type wearable device 401 may include a module for obtaining biometric information (hereinafter, referred to as a biometric technology module). For example, referring to FIG. 1, a watch-type wearable device 401 may include a module for recognizing fingerprints of a finger.
Referring back to FIG. 3, in operation S302, the controller 130 may remove the security setting of the content by using the second biometric information.
As shown in FIG. 1, the controller 130 may remove the security setting of the content c10 by using the iris information 12 obtained by the glasses-type wearable device 402. Therefore, the controller 130 can remove the security setting of the content by using the iris information 12 instead of the fingerprint information 10 for setting the security of the content c10.
The method of removing the preservation of the content by using the iris information 12 by the controller 130 will be described in detail later.
In FIG. 1, the device 10 obtains fingerprint information 10 and iris information 12 from a watch-type wearable device 401 and a glasses-type wearable device 402 (the wearable device is an external device), but according to another exemplary embodiment, the device 100 can obtain at least one of fingerprint information 10 and iris information 12 from at least one biometric technology module installed in the device 100. For example, the device 100 can obtain both the fingerprint information 10 and the iris information 12 from a biometric module provided in the device 10 instead of an external device.
Fig. 4 is a flowchart of a method for setting content preservation according to an exemplary embodiment.
In operation S401, the controller 130 may obtain the user's first biometric information.
In operation S402, the controller 130 may authenticate the user by using the first biometric information.
The user can be authenticated by matching the feature information of the first biometric information with the feature information of the basic first biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded.
However, if the user authentication fails, the controller 130 may, for example, display a notification screen notifying the failure on the display unit 121 of FIG. 102.
In operation S403, when the user authentication has succeeded, the controller 130 may set content security by using the security key.
The security key can be a password or an encryption key.
The password can be a common password or a password corresponding to biometric information. Common passwords can generally be used to restrict access to content regardless of the type of biometric information. The password corresponding to the biometric information can be used for specific types of biometric information. Therefore, according to an exemplary embodiment, when there are multiple pieces of biometric information for user authentication, there may be multiple passwords corresponding to the multiple pieces of biometric information.
The encryption key can be a common encryption key or an encryption key corresponding to biometric information. The common encryption key can generally be used to encode content regardless of the type of biometric information. The common encryption key can be generated by using feature information of multiple pieces of basic biometric information. The encryption key corresponding to the biometric information can be used for specific types of biometric information. Therefore, according to an exemplary embodiment, when there are multiple pieces of biometric information for user authentication, there may be multiple encryption keys corresponding to the multiple pieces of biometric information. The encryption key may be generated by using characteristic information of each of the plurality of pieces of biometric information.
According to an exemplary embodiment, when the security key is a password, the security key used to set the content security and the security key used to remove the content security may be the same.
According to an exemplary embodiment, the security key used to set content security and the security key used to remove content security may be different from each other. When the security key is an encryption key, the encryption key used to set content security and the decryption key used to remove content security may be different from each other.
When, for example, the value output by using a function and the factor value of the function (the value is used to generate the encryption key) is used as the decryption key, the encryption key and the decryption key may be the same.
When (for example) the public key and the private key are generated together to decrypt the content based on the output value (for example, the seed value) of the function when using a function and the factor value of the function (the value is used to encrypt the content), The encryption key and the decryption key may be different from each other. At this time, the public key can be used as an encryption key, and the private key can be used as a decryption key. In the current exemplary embodiment, both the security key used to set content security and the security key used to remove content security are generally called security keys, but it will be obvious to those with ordinary knowledge in the art. The security key for setting content security and the security key for removing content security may have different values according to exemplary embodiments.
The method of obtaining a security key (such as a password or an encryption key) will be described in detail later.
FIG. 5 is a flowchart of a method for restricting access to content in order to set security according to an exemplary embodiment.
In operation S501, the controller 130 may obtain the user's first biometric information.
According to an exemplary embodiment, the controller 130 may receive the first biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S502, the controller 130 may authenticate the user by using the first biometric information.
The user can be authenticated by matching the feature information of the first biometric information with the feature information of the basic first biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded.
When the user authentication fails, the controller 130 may display a notification screen notifying the failure on the display unit 121.
In operation S503, when the user authentication has succeeded, the controller 130 may obtain the common password. Common passwords can generally be used to restrict access to content regardless of the type of biometric information. For example, the common password may be a value obtained from a plurality of values stored in the memory 170 in advance. Alternatively, the common password may be a value randomly generated by the controller 130. Alternatively, the common password may be a value generated by the controller 130 by using at least one piece of basic biometric information. For example, the common password may be a value generated by using a logical operation or a combination result of the characteristic information of the basic biometric information as a factor of a specific function.
According to an exemplary embodiment, the common password can be generated after the user has been successfully authenticated. Alternatively, the common password can be generated before performing user authentication. For example, in the registration mode 201, when the feature information of the basic biometric information is stored in the memory 170, a common password using the feature information of the basic biometric information can be generated and stored in advance.
According to an exemplary embodiment, the common password may be stored in the memory 170, an external server, a wearable device, or a third device.
In operation S504, the controller 130 may restrict access to the content by using a common password.
Fig. 6 is a flowchart of a method for restricting access to content in order to set security according to another exemplary embodiment.
In operation S601, the controller 130 may obtain the user's first biometric information.
According to an exemplary embodiment, the controller 130 may receive the first biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S602, the controller 130 may authenticate the user by using the first biometric information.
In operation S603, when the user authentication has succeeded, the controller 130 may obtain a first password corresponding to the first biometric information. In addition, the controller 130 can obtain a second password corresponding to the second biometric information. The password corresponding to the biometric information may have different values according to the type of the biometric information. For example, the first password corresponding to the first biometric information and the second password corresponding to the second biometric information may have different values.
At the same time, when the user presets the biometric information to remove the content preservation, the controller 130 can obtain the password corresponding to the preset biometric information.
The password corresponding to the biometric information may be, for example, a value obtained by the controller 130 from a plurality of values stored in the memory 170 in advance. Alternatively, the password corresponding to the biometric information may be a value randomly generated by the controller 130. Alternatively, the password corresponding to the biometric information may be a value generated by the controller 130 by using pre-stored basic biometric information corresponding to the biometric information. For example, the password corresponding to the biometric information may be a value generated by using at least a part of the feature information of the basic biometric information stored in advance as a factor of a specific function.
According to an exemplary embodiment, the password corresponding to the biometric information can be generated after the user has successfully authenticated. Alternatively, the password corresponding to the biometric information can be generated before performing user authentication. For example, in the registration mode 201, when the feature information of the basic biometric information is stored in the memory 170, the password corresponding to the basic biometric information can be generated in advance by using the feature information of the basic biometric information.
According to an exemplary embodiment, the password corresponding to the biometric information can be stored in the memory 170, an external server, a wearable device, or a third device.
In operation S604, the controller 130 may restrict access to the content by using at least one of a first password corresponding to the first biometric information and a second password corresponding to the second biometric information.
Fig. 7 is a flowchart of a method for encrypting content for setting security according to an exemplary embodiment.
In operation S701, the controller 130 may obtain the user's first biometric information.
According to an exemplary embodiment, the controller 130 may receive the first biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S702, the controller 130 may authenticate the user by using the first biometric information.
The user can be authenticated by matching the feature information of the first biometric information with the feature information of the basic first biometric information stored in advance. When the matching score obtained as a matching result is equal to or higher than a certain threshold, the controller 130 may determine that the user authentication has succeeded.
According to an exemplary embodiment, when it is determined that the user authentication has failed, the controller 130 may display a notification screen indicating the failure on the display unit 121.
In operation S703, when the user authentication has succeeded, the controller 130 may obtain the common encryption key. The common encryption key can generally be used to encrypt content regardless of the type of biometric information. For example, the common encryption key may be a value generated by the controller 130 by using characteristic information of at least one segment of the basic biometric information from a plurality of segments. The common encryption key can be generated after the user has successfully authenticated. Alternatively, the common encryption key may be generated before performing user authentication. For example, in the registration mode 201, when the feature information of the basic biometric information is stored in the memory 170, a common encryption key can be generated in advance by using the feature information of the basic biometric information.
According to an exemplary embodiment, the method for the controller 130 to generate a common encryption key by using multiple pieces of basic biometric information may include the following operations.
The controller 130 may determine the value generated by using the feature information of the multiple pieces of basic biometric information as a factor of a specific function (for example, a cryptographic hash function) as an encryption key. Alternatively, some of the characteristic information may be used as factors of a specific function. However, the method of generating an encryption key by using basic biometric information is not limited to this and can be varied.
For example, a specific operation (for example, an exclusive OR operation) can be applied to the feature information by using a preset value of a specific length (for example, 128 bits), and only the value corresponding to the result value of the specific length can be Determined as the encryption key. Alternatively, a password-based key derivation function 2 (PBKDF2) may be used.
According to an exemplary embodiment, the result value of the function is different when the factor (characteristic information) of the function is different, and a function with a condition that the factor cannot be derived from the result value can be used as a function for generating an encryption key.
Next, in operation S704, the controller 130 may encrypt the content by using the common encryption key.
Fig. 8 is a flowchart of a method of encrypting content for setting security according to another exemplary embodiment.
In operation S801, the controller 130 may obtain the user's first biometric information.
According to an exemplary embodiment, the controller 130 may receive the first biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S802, the controller 130 may authenticate the user by using the first biometric information.
The user can be authenticated by matching the feature information of the first biometric information with the feature information of the basic first biometric information stored in advance. When the matching score obtained as a matching result is equal to or higher than a certain threshold, the controller 130 may determine that the user authentication has succeeded.
According to an exemplary embodiment, if it is determined that the user authentication has failed, the controller 130 may display, for example, a notification screen indicating the failure on the display unit 121.
In operation S803, when the user authentication has succeeded, the controller 130 may obtain a first encryption key corresponding to the first biometric information. In addition, the controller 130 may obtain a second encryption key corresponding to the second biometric information. The encryption key corresponding to the biometric information may be different according to the type of the biometric information. For example, the first encryption key corresponding to the first biometric information and the second encryption key corresponding to the second biometric information may have different values.
At the same time, when the user presets the biometric information to remove the content preservation, the controller 130 can obtain the password corresponding to the preset biometric information.
The encryption key corresponding to the biometric information may be a value generated by using the basic biometric information stored in the memory 170 in advance. The encryption key corresponding to the biometric information can be generated after the user has successfully authenticated. Alternatively, the encryption key corresponding to the biometric information may be generated before performing user authentication. For example, in the registration mode 201, when the feature information of the basic biometric information is stored in the memory 170, the encryption key corresponding to the basic biometric information can be generated in advance by using the feature information of the basic biometric information .
In detail, the controller 130 may determine that the value generated by using the characteristic information of the basic biometric information as a factor of a specific function (for example, a cryptographic hash function) is used as the encryption key. Alternatively, some of the characteristic information may be used as factors of a specific function. However, the method of generating an encryption key by using basic biometric information is not limited to this and can be varied.
Next, in operation S804, the controller 130 may encrypt the content by using at least one of a first encryption key corresponding to the first biometric information and a second encryption key corresponding to the second biometric information.
Fig. 9 is a flowchart of a method for encrypting content and an encryption key to set security according to an exemplary embodiment.
In operation S901, the controller 130 may obtain the user's first biometric information. According to an exemplary embodiment, the controller 130 may receive the first biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
According to an exemplary embodiment, the external device may be a wearable device including a biometric technology module. Examples of external devices include watch-type wearable devices, glasses-type wearable devices, head-mounted display devices, and band-type wearable devices, but are not limited thereto. The external device may include at least one of the following: a biometric technology module for obtaining fingerprint information, a biometric technology module for obtaining iris information, a biometric technology module for extracting facial information, and A biometric technology module for extracting retinal information, a biometric technology module for extracting voice information, a biometric technology module for measuring heart rate, and a biometric technology module for identifying gait patterns. However, the biometric technology module described herein is only an example, and therefore is not limited thereto.
In operation S902, the controller 130 may authenticate the user by using the first biometric information.
In operation S903, when the user authentication has succeeded, the controller 130 may obtain the first encryption key. Here, the first encryption key may be a value generated by using basic first biometric information stored in the memory 170 in advance . The first encryption key can be generated after the user has successfully authenticated. Alternatively, the first encryption key may be generated before performing user authentication. For example, in the registration mode 201, when the feature information of the basic first biometric information is stored in the memory 170, the first encryption key can be generated in advance by using the feature information of the basic first biometric information. Since the method of generating an encryption key by using biometric information has been described above, the details of the method will not be provided.
In operation S904, the controller 130 may encrypt the content by using the first encryption key obtained in operation S903.
In operation S905, the controller 130 may obtain a second encryption key. The second encryption key may be, for example, a value generated by using basic second biometric information stored in the memory 170 in advance. The second encryption key can be generated after the content is encrypted. Alternatively, the second encryption key may be generated before the content is encrypted.
In operation S906, the controller 130 may encrypt the first encryption key by using the second encryption key generated in operation S905.
10 to 13 illustrate examples of UIs provided to set content preservation.
As shown in S1010, when the user's finger f10 selects the button for locking the setting, the controller 130 may determine that the user input for setting the security of the content c10 is received.
According to an exemplary embodiment, when the user input is received, the controller 130 may display a screen 1002 for the lock setting using biometric information, and the user's finger f11 may select the lock setting using the biometric information, such as Shown in S1020. According to another exemplary embodiment, the controller 130 may display a locked menu screen (not shown) or an icon (not shown) for setting using biometric information on the display unit 121. In FIG. 10, the UI for setting the lock on the content c10 is explained, but the UI is not limited to this.
Next, as shown in FIG. 11A, the watch-type wearable device 401 obtains the fingerprint information 10 of the user and transmits the fingerprint information to the device 100. The device 100 can receive fingerprint information 10 from a watch-type wearable device 401. The controller 130 may display on the display unit 121 a notification screen 1101 indicating that the biometric information for setting the lock on the content c10 has been received. The notification screen 1101 is only an example of a UI for notifying the user that the content is locked after receiving the biometric information, and therefore is not limited to this. As another example, the controller 130 may display a screen indicating the type of received biometric information (for example, "fingerprint information") on the display unit 121.
Alternatively, as shown in FIG. 11B, the device 100 may obtain biometric information through a biometric technology module provided in the device 100. For example, the device 100 may include a module 405 for identifying fingerprints, and the fingerprint information 10 may be obtained when the user's finger f12 touches the module 405.
Referring to FIG. 12, the controller 130 may display a screen 1201 for setting biometric information of another segment used to remove the lock on the content c10 on the display unit 121.
FIG. 12 illustrates an example of a UI provided to the user, and the user can preset biometric information that is different from the biometric information used to set the lock on the content c10. Therefore, the user can later use the preset biometric information of another segment when removing the preservation of the content c10. In FIG. 12, if the user's finger f13 selects a button for additionally registering biometric information, the device 100 can determine that the user input for setting the security of the content c10 is received.
Referring to FIG. 13, the controller 130 can obtain the iris information 12 of the user from the glasses-type wearable device 402.
The controller 130 may display on the display unit 121 a screen 1301 for notifying the user that the biometric information is received and that the received biometric information is registered as biometric information for removing the lock on the content c10. FIG. 13 illustrates an example of a UI that notifies the user that the user can remove the lock on the content based on biometric information (for example, iris information 12) other than the biometric information used to encrypt the content (for example, fingerprint information 10) .
According to an exemplary embodiment, the procedure of providing a UI for setting another piece of biometric information used to remove the lock on the content as described above with reference to FIG. 12 and FIG. 13 may be omitted. In this case, the controller 130 may set the basic biometric information of at least one segment previously stored in the memory 130 as the biometric information of another segment used to remove the lock on the content.
14A to 14C are diagrams for describing an example of setting content preservation according to an exemplary embodiment.
Referring to FIG. 14A, when the user who uses the fingerprint information 10 is successfully authenticated, the controller 130 may generate a common password, a first password, or a second password. The controller 130 can restrict access to the content c10 by using at least one password p10 (for example, PW_A) from the common password, the first password, and the second password. In FIG. 14A, "P[content]PW_A" indicates that access to "content" is restricted by using "PW_A".
Alternatively, referring to FIG. 14B, when the user authentication using the fingerprint information 10 is successful, the controller 130 may generate a common encryption key, a first encryption key, or a second encryption key. The controller 130 may encrypt the content c10 by using at least one key k10 (for example, key_A) from the common encryption key, the first encryption key, and the second encryption key. In FIG. 14B, "E[content]key_A" indicates that "content" is encrypted by using "key_A".
14C, when the encryption key is encrypted to set content preservation, the controller 130 may generate a second encryption key k12 (for example, key_B) based on the iris information 12 obtained by the glasses-type wearable device 402. For example, when the user is authenticated by using the iris information 12, the controller 130 can generate the second encryption key k12 by using the basic second biometric information stored in the memory 170 in advance. Then, the controller 130 may obtain the encryption key k14 by encrypting the at least one key k10 by using the second encryption key k12. Here, "E[key_A]key_B" indicates that "key_A" is encrypted by using "key_B".
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 15 is a diagram of a database (DB) d1 according to an exemplary embodiment.
The device 100 according to an exemplary embodiment may include the DB d1. Alternatively, the DB d1 of FIG. 15 may be provided in the server 200 of FIG. 79 (described in more detail below).
DB d1 may include content DB d2 and key DB d3.
The content DB d2 can store the content that has been secured.
For example, the content DB d2 can store "P[content]PW_A". "P[content]PW_A" can indicate that the access to "content" is restricted by using the password "PW_A". In the following, "P[aaa]bbb" indicates that access to "aaa" is restricted by using the password "bbb", and therefore a description of the key is not provided.
Alternatively, the content DB d2 may store "E[content]key_A". "E[content]key_A" can indicate that "content" is encrypted by using the encryption key "key_A". In the following, "E[ccc]ddd" indicates that "ccc" is encrypted by using the encryption key "ddd", and therefore no description of the key is provided.
The key DB d3 can store the security key.
For example, the key DB d3 may store at least one of a password, an encryption key, and an encrypted encryption key (for example, "E[key_A]key_B").
According to an exemplary embodiment, the secured content and the security key may be stored in the content DB d2, respectively, and the key DB d3 may be stored in one DB instead.
According to an exemplary embodiment, when the device 100 transmits the content and the security key to the server 200 via the communication unit 150, the server 200 may store the content and the security key in the content DB d2 and the key DB d3, respectively.
According to another exemplary embodiment, when the server 200 encrypts content or encrypts the encryption key, the server 200 may store the encrypted content and the encrypted encryption key in the content DB d2 and the key DB d3, respectively. Alternatively, the server 200 may store the encrypted content and the encrypted encryption key in a DB. Alternatively, the secured content and the security key may be stored in a DB provided in any one of the server 200 and the device 100, respectively. For example, the secured content can be stored in the DB provided in the server 200 and the security key can be stored in the DB provided in the device 100, and vice versa.
According to an exemplary embodiment, the secured content and security key stored in the server 200 can be accessed by the device 100 or a device assigned a specific access authority.
Fig. 16 is a flowchart of a method for removing content preservation according to an exemplary embodiment.
Here, the method of removing content security by using the second biometric information according to an exemplary embodiment may mean that when the security is set by using the first biometric information to set the content, the method of removing the content by using the second biometric information In addition to content preservation methods.
In operation S1601, the controller 130 may obtain the user's second biometric information.
In operation S1602, the controller 130 may authenticate the user by using the second biometric information.
The user authentication can be performed by matching the feature information of the second biometric information with the feature information of the basic second biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded. According to an exemplary embodiment, when the user authentication is determined to have failed, the controller 130 may, for example, display a notification screen indicating the failure on the display unit 121.
In operation S1603, when the user authentication has succeeded, the controller 130 may remove the content security by using the security key. The security key can be a password or a decryption key.
For example, the controller 130 may allow access to content by using a password. Alternatively, the controller 130 may decrypt the content by using the decryption key.
The method of obtaining the password and the decryption key will be described in detail later.
FIG. 17 is a flowchart of a method for allowing access to content in order to remove security according to an exemplary embodiment.
In operation S1701, the controller 130 may obtain the user's second biometric information.
According to an exemplary embodiment, the controller 130 may receive the second biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
In operation S1702, the controller 130 may authenticate the user by using the second biometric information.
The user authentication can be performed by matching the feature information of the second biometric information with the feature information of the basic second biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded. According to an exemplary embodiment, when the user authentication is determined to have failed, the controller 130 may, for example, display a notification screen indicating the failure on the display unit 121.
In operation S1703, when the user authentication has succeeded, the controller 130 may obtain the common password. Common passwords can generally be used to restrict access to content regardless of the type of biometric information. The controller 130 may obtain the common password from, for example, the memory 170, an external server, a wearable device, or a third device.
Next, in operation S1704, the controller 130 may allow access to the content by using the common password.
FIG. 18 is a flowchart of a method for allowing access to content in order to remove security according to another exemplary embodiment.
In operation S1801, the controller 130 may obtain the user's second biometric information.
According to an exemplary embodiment, the controller 130 may receive the second biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
In operation S1802, the controller 130 may authenticate the user by using the second biometric information.
In operation S1803, when the user authentication has been successful, the controller 130 may obtain a second password corresponding to the second biometric information. When the security is set by using the first biometric information to set the content, the second password can be generated by the controller 130 corresponding to the second biometric information. The controller 130 may obtain the second password from, for example, the memory 170, an external server, a wearable device, or a third device.
Then, in operation S1804, the controller 130 may allow access to the content by using the second password.
Fig. 19 is a flowchart of a method of decrypting content to remove security according to an exemplary embodiment.
In operation S1901, the controller 130 may obtain second biometric information of the user.
According to an exemplary embodiment, the controller 130 may receive the second biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
In operation S1902, the controller 130 may authenticate the user by using the second biometric information.
In operation S1903, when the user authentication has succeeded, the controller 130 may generate a common decryption key. The common decryption key can generally be used to decrypt content regardless of the type of biometric information. For example, the common decryption key may be a value generated by using feature information of at least one piece of basic biometric information of multiple pieces. In detail, the controller 130 may determine a value generated by using feature information of a plurality of pieces of basic biometric information as a factor of a specific function as a decryption key. Alternatively, the controller 130 may use some of the characteristic information as factors of a specific function. However, the example of generating the decryption key by using the basic biometric information is not limited to this and may vary.
In operation S1904, the controller 130 may decrypt the encrypted content by using the common decryption key generated in operation S1903.
FIG. 20 is a flowchart of a method of decrypting content to remove security according to another exemplary embodiment.
In operation S2001, the controller 130 may obtain the user's second biometric information.
According to an exemplary embodiment, the controller 130 may receive the second biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
In operation S2002, the controller 130 may authenticate the user by using the second biometric information.
In operation S2003, when the user authentication is successful, the controller 130 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using the characteristic information of the basic second biometric information stored in the memory 170 in advance. In detail, the controller 130 may determine the value generated by using the characteristic information of the second biometric information as a factor of the specific function as the second decryption key. However, the method of generating the second decryption key by using the basic second biometric information is not limited to this and can be changed.
At the same time, the second decryption key and the second encryption key may be the same or different from each other.
When (for example) the value output by using a function and the factor value of the function (the value is used to generate the second encryption key) is used as the second decryption key, the second decryption key and the second encryption The keys are the same.
When (for example) the public key and the private key are generated based on the output value (for example, the seed value) of the function to decrypt the content when the function and the factor value of the function (the value is used to encrypt the content) are used to decrypt the content, encryption The key and the decryption key can be different from each other. At this time, the public key can be used as an encryption key, and the private key can be used as a decryption key. At this time, the public key can be used as the second encryption key, and the private key can be used as the second decryption key.
In operation S2004, the controller 130 may decrypt the encrypted content by using the second decryption key.
FIG. 21 is a flowchart of a method of decrypting content to remove security according to another exemplary embodiment.
In operation S2101, the controller 130 may obtain the user's second biometric information.
According to an exemplary embodiment, the controller 130 may receive the second biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
In operation S2102, the controller 130 may authenticate the user based on the second biometric information.
In operation S2103, when the user authentication has succeeded, the controller 130 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using the characteristic information of the basic second biometric information stored in the memory 170 in advance. In detail, the controller 130 may determine the value generated by using the characteristic information of the second biometric information as a factor of the specific function as the second decryption key. However, the method of generating the second decryption key by using the basic second biometric information is not limited to this and can be changed. At the same time, the second decryption key and the second encryption key may be the same or different from each other.
In operation S2104, the controller 130 may decrypt the first encryption key by using the second decryption key obtained in operation S2103 (refer to operation S906 of FIG. 9).
In operation S2105, the controller 130 may decrypt the content by using the first decryption key obtained by decrypting the first encryption key in operation S2104 (refer to operation S904 of FIG. 9).
22A to FIG. 23 illustrate an example of a UI provided to remove content preservation by using second biometric information according to an exemplary embodiment.
Referring to FIG. 22A, when the user's finger f22 selects to preserve the set content c10 (at S2210), the controller 130 may display a screen on the display unit 121 requesting the user to input biometric information to remove the preservation of the content c10 2201 (at S2220). The controller 130 may display on the display unit 121 a list of devices 2201-1 and 2201-2 capable of obtaining biometric information for removing the security of the content c10. According to an exemplary embodiment, the controller 130 may receive a user input of selecting the device 2201-2 (ie, "glasses") as a device for obtaining biometric information by the finger 23.
As another example, referring to FIG. 22B, when the user's finger f24 selects to preserve the set content c10 (at S2230), the controller 130 may display on the display unit 121 requesting the user to input biometric information to remove the content The saved screen 2202 of c10 (at S2240). The controller 130 may display the types 2202-1 and 2202-2 of the biometric information for removing the preservation of the content c10 on the display unit 121. According to an exemplary embodiment, the controller 130 may receive a user input of selecting the type 2202-2 (ie, "iris") by the finger f25.
FIG. 22B illustrates an example of a UI that requests the user to input biometric information for removing the security when the device 100 receives user input for accessing the secured content, but the UI is not limited to this. For example, the device 100 may not display a list of devices or types of biometric information used to remove content preservation, but may only display a screen requesting the user to input authentication information.
Referring to FIG. 23, the device 100 can receive the iris information 12 from the glasses-type wearable device 402. The controller 130 may display a screen 2301 on the display unit 121 indicating that the authentication information is received.
FIG. 23 illustrates an example of a screen for instructing the device 100 to receive authentication information from an external device, but the screen is not limited to this. For example, the controller 130 may display the type of the received biometric information (for example, "iris information") on the display unit 121. Alternatively, the controller 130 may display a device (for example, "glasses-type wearable device") that obtains biometric information on the display unit 121.
24A to 24D are diagrams for describing examples of setting content preservation according to other exemplary embodiments.
Referring to FIG. 24A, when the user is authenticated by using the user's second biometric information (for example, iris information), the controller 130 can obtain the common password p21. The controller 130 can allow access to the content by using the common password p21.
Alternatively, referring to FIG. 24B, when the user is authenticated by using the user's second biometric information (for example, iris information), the controller 130 can obtain the password p22 corresponding to the second biometric information. The controller 130 can allow access to the content by using the password p22.
Alternatively, referring to FIG. 24C, when authenticating the user by using the user's second biometric information (for example, iris information), the controller 130 may use the basic biometric information stored in the memory 170 in advance. The characteristic information of the information generates a common decryption key k21. The controller 130 decrypts the encrypted content by using the common decryption key k21.
Alternatively, referring to FIG. 24D, when the user is authenticated by using the user's second biometric information (for example, iris information), the controller 130 may use the basic second biometric information stored in the memory 170 in advance. The feature information of the biometric information generates a second decryption key k22 corresponding to the second biometric information. Then, the controller 130 can decrypt the encrypted content by using the second decryption key k22.
Alternatively, referring to FIG. 24E, when the user is authenticated by using the user's iris information 12, the controller 130 may generate a second decryption key by using the basic second biometric information stored in the memory 170 in advance. The key k23 (that is, key_B). The controller 130 can decrypt the encrypted first encryption key k24 (ie, E[Key_A]key_B) by using the second decryption key k23. The controller 130 decrypts the encrypted content by using the decrypted key k25 (ie, key_A).
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 25 is a table for describing a decryption method according to an exemplary embodiment.
The table of FIG. 25 is used to describe the method of decrypting the content after the content is encrypted.
The controller 130 may decrypt the content based on the second biometric information.
In detail, as shown in reference numeral 2501 in FIG. 25, when the user has successfully authenticated by using the second biometric information, the controller 130 can use the basic second biometric information stored in the memory 170 in advance. Identify the information to generate the decryption key (Key_B). The controller 130 may decrypt the encrypted first encryption key (ie, E[key_A]key_B) by using the decryption key. The controller 130 may decrypt the encrypted content (ie, E[content]key_A) by using the decrypted first encryption key (ie, Key_A).
Alternatively, the controller 130 may decrypt the content based on the first biometric information.
In detail, as shown in reference numeral 2502 in FIG. 25, the controller 130 can generate a decryption key (Key_A) by using basic first biometric information stored in the memory 170 in advance. The controller 130 may decrypt the encrypted content (E[content]key_A) by using the decryption key (Key_A).
FIG. 26 is a flowchart of a method for decrypting content to remove security by using first biometric information according to another exemplary embodiment. The method of decrypting the content by using the first biometric information may refer to the method of decrypting the content by using the biometric information used to encrypt the content.
Referring to FIG. 26, in operation S2601, the controller 130 may obtain the user's biometric information.
According to an exemplary embodiment, the controller 130 may receive biometric information from an external device via the communication unit 150. Alternatively, the controller 130 may obtain biometric information from a biometric technology module provided in the device 100.
In operation S2602, the controller 130 may authenticate the user by using biometric information.
In operation S2603, the controller 130 may determine whether the biometric information obtained in operation S2601 is the same as the biometric information used to encrypt the content.
When it is determined in operation S2603 that the biometric information is the same as the biometric information used to encrypt the content, in operation S2604, the controller 130 may obtain a decryption key corresponding to the biometric information to decrypt the content.
For example, the decryption key may be a value generated by the controller 130 by using the characteristic information of the basic first biometric information stored in the memory 170 in advance.
In detail, the controller 130 may determine the value generated by using the characteristic information of the first biometric information as the factor of the specific function as the decryption key. However, the method of generating the decryption key by using the basic first biometric information is not limited to this and can be changed.
In operation S2605, the controller 130 may decrypt the content by using the decryption key obtained in operation S2605.
For example, when the biometric information used to encrypt the content is the first biometric information (for example, fingerprint information), and the biometric information obtained in operation S2601 is also the first biometric information (fingerprint information) , The content can be decrypted by using the decryption key corresponding to the basic first biometric information stored in the memory 170 in advance.
When it is determined in operation S2603 that the biometric information is different from the biometric information used to encrypt the content, in operation S2606, the controller 130 may obtain a decryption key corresponding to the biometric information in order to decrypt the encryption key of the content.
For example, the decryption key corresponding to the biometric information may be a value generated by the controller 130 by using the characteristic information of the basic second biometric information stored in the memory 170 in advance.
In operation S2607, the controller 130 may decrypt the encryption key by using the decryption key. In operation S2608, the controller 130 may decrypt the content by using the decrypted encryption key.
For example, when the biometric information used to encrypt the content is the first biometric information (for example, fingerprint information), and the biometric information obtained in operation S2601 is the second biometric information (for example, iris information) At this time, the encryption key can be decrypted by using the decryption key obtained by using the basic second biometric information stored in the memory 170 in advance, and then the content can be decrypted by using the decrypted encryption key.
27A-28 illustrate an example of a UI provided to decrypt content by using first biometric information in order to remove security according to an exemplary embodiment.
As shown in FIG. 27A, when the user's finger f18-1 selects to preserve the set content c18 (at S2710), the controller 130 may display on the display unit 121 requesting the user to input biometric information to remove the content The saved screen 208 of c18 (at S2720). For example, the controller 130 may display a list of the external devices 209 and 210 for removing the security of the content c18 on the display unit 121. For example, the controller 130 may receive a user input of selecting an external device 210 (for example, a "watch") as a device for obtaining biometric information by a finger f20.
According to another exemplary embodiment, referring to FIG. 27B, when the user's finger f18-2 selects content c18 (at S2730), the controller 130 may display on the display unit 121 for requesting the user to input biometric information to move The screen 208-2 (at S2740) of the preservation of the content c18 is excluded. The controller 130 may display the types 209-2 and 210-2 of the biometric information for removing the preservation of the content c18 on the display unit 121.
For example, the controller 130 may receive a user input of selecting the type 210-2 (ie, fingerprint) as the type of biometric information by the finger f20-2.
27A and 27B illustrate an example of a UI that requests the user to input biometric information for removing the security when the device 100 receives a user input for accessing the secured content, but the UI is not limited to this. For example, the device 100 may only display a screen requesting the user to input authentication information instead of displaying a list of the types of devices or biometric information used to remove the security.
Referring to FIG. 28, the device 100 can receive fingerprint information 22 from a watch-type wearable device 401. The controller 130 may display a screen 212 on the display unit 121 indicating that the authentication information is received. FIG. 28 illustrates an example of a screen indicating that the authentication information is received from an external device, and the screen is not limited to this.
For example, the controller 130 may display the type of the received biometric information (for example, "fingerprint information") on the display unit 121. Alternatively, the controller 130 may display a device (for example, a "watch-type wearable device") that obtains biometric information on the display unit 121.
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 29 is a diagram for describing an example of sharing content by multiple users according to an exemplary embodiment. As shown in Figure 29, for example, when the first user User1 sets the security of the content c26 by using the biometric information of the first user User1, the second user User2 and the third user User3 can use the The biometric information of each of the second user User2 and the third user User3 is removed from the security.
According to an exemplary embodiment, the first user User1 may own the device 100 (such as a smart phone) and the glasses-type wearable device 801. The glasses-type wearable device 801 may include a biometric technology module for obtaining iris information 34. The device 100 can obtain the iris information 34 by receiving the iris information 34 from the glasses-type wearable device 801 paired with the device 100 via the communication unit.
The second user User2 may own a device 802, such as a watch-type wearable device. The device 802 may include a microphone for obtaining voice information. In addition, the third user User3 may own a device 803, such as a smart phone. The device 803 may include a biometric technology module for recognizing facial information.
According to an exemplary embodiment, in order for multiple users to work on the content c26 together, the multiple users may be able to remove the security set on the content c26. When the first user User1 generates the content c26, the first user User1 may wish to allow the second user User2 and the third user User3 to access the content c26. In this case, the first user User1 can set the security of the content C26 by using the biometric information of the first user User1, and then set the content C26 so that the security is by using the second user User2 and The biometric information of each user User3 is removed.
For example, the device 100 can set the security of the content c26 by using the iris information 34 and then set the content c26 so that the security is by using the voice information 36 of the second user User2 or the face of the third user User3 Information 38 to remove.
According to an exemplary embodiment, the encryption key corresponding to the iris information 34 may be encrypted by using the voice information 36, and then later decrypted by using the voice information 36. Then, the content c26 can be decrypted by using the decrypted encryption key.
Alternatively, the encryption key corresponding to the iris information 34 may be encrypted by using the facial information 38, and then later decrypted by using the facial information 38. Then, the content c26 can be decrypted by using the decrypted encryption key.
In FIG. 29, the device 100 obtains the biometric information of the first user User1 from the glasses-type wearable device 801 (ie, an external device), but the exemplary embodiment is not limited thereto. According to another exemplary embodiment, the device 100 can directly obtain the biometric information of the first user User1 from the biometric technology module included in the device 100.
The method of setting and removing security according to other exemplary embodiments will now be described in detail with reference to FIGS. 30 to 43.
FIG. 30 is a flowchart of a method for encrypting content and an encryption key to set security according to an exemplary embodiment.
In operation S3001, the device 100 of the first user may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S3002, the controller 130 of the device 100 may perform user authentication by using the first biometric information.
The user authentication can be performed by matching the characteristic information of the obtained first biometric information with the characteristic information of the basic first biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded.
In operation S3003, when the user authentication has succeeded, the controller 130 may obtain the first encryption key. Here, the first encryption key may be a value generated by using basic first biometric information stored in the memory 170 in advance. The first encryption key can be generated after the user authentication is successful or before the user authentication is performed. For example, in the registration mode 201 for registering the first biometric information, when the characteristic information of the basic first biometric information is stored in the memory 170, the first encryption key can be used by using the basic first biometric information. The characteristic information of the biometric information is generated and stored in advance. Since the method of generating an encryption key by using biometric information has been described above, the details of the method will not be provided.
In operation S3004, the controller 130 may encrypt the content by using the first encryption key.
In operation S3005, the device 802 of the second user can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 802 can obtain the second biometric information from the biometric technology module provided in the device 802.
In operation S3006, the device 802 may perform user authentication by using the second biometric information.
The user authentication can be performed by matching the obtained feature information of the second biometric information with the feature information of the basic second biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded.
In operation S3007, when the user authentication has succeeded, the device 802 can obtain the second encryption key. Here, the second encryption key may be a value generated by using basic second biometric information stored in the memory 170 in advance. The second encryption key can be generated after the user authentication is successful or before the user authentication is performed. For example, in the registration mode 201 for registering the second biometric information, when the characteristic information of the basic second biometric information is stored in the memory 170, the second encryption key can be used by using the basic second biometric information. The characteristic information of the biometric information is generated and stored in advance. Since the method of generating an encryption key by using biometric information has been described above, the details of the method will not be provided.
In operation S3009, the device 803 of the third user can obtain the third biometric information of the third user.
In operation S3010, the device 803 may perform user authentication by using the third biometric information.
The user authentication can be performed by matching the obtained feature information of the third biometric information with the feature information of the basic third biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded.
In operation S3011, when the user authentication has succeeded, the device 803 may obtain the third encryption key. Here, the third encryption key may be a value generated by using basic third biometric information stored in the memory 170 of the device 803 in advance.
According to an exemplary embodiment, since each operation performed in the device 803 corresponds to each operation pointed to in the device 802, the details of each operation are not repeated.
In operation S3008, the device 802 may transmit the second encryption key to the device 100.
In operation S3013, the device 100 may encrypt the first encryption key by using the second encryption key received from the device 802.
In addition, in operation S3012, the device 803 may transmit the third encryption key to the device 100.
In operation S3014, the device 100 may encrypt the first encryption key by using the third encryption key received from the device 803.
FIG. 31 and FIG. 32 illustrate an example of a UI provided to set content preservation.
Referring to S3110, the controller 130 of the device 100 may receive an input of selecting the button 228 for setting a lock on the content c27 (such as document data) by the user's finger f32.
When the input is received, the controller 130 may display a selection screen 230 for setting a lock on the content c27 by using the biometric information on the display unit 121 (at S3120).
As shown in FIG. 32, the device 100 may receive the iris information 40 of the first user User1 from an external device (such as the glasses-type wearable device 801 of the first user User1). The controller 130 of the device 100 may display a screen 232-1 on the display unit 121 indicating that the biometric information is received. The controller 130 may display a screen 232-2 indicating that the lock to the content has been set on the display unit 121. However, this example of the UI of a device that receives biometric information for setting content lock from an external device is not limited to this.
Referring to FIG. 33, the controller 130 of the device 100 may generate the first encryption key k26 (for example, Key_C) by using the iris information 42 obtained from the glasses-type wearable device 801. For example, when the first user User1 is authenticated by using the iris information 42, the controller 130 can generate the first encryption key k26 by using the basic iris information stored in the memory 170 in advance. The controller 130 can encrypt the content c28 by using the first encryption key k26. Here, "E[content]key_C" indicates that "content" is encrypted by using "key_C".
34 to 38 are diagrams for describing a method for sharing and preserving set content between the device 100 and another user according to an exemplary embodiment.
Referring to S3410, the device 100 may display a menu screen 234-1 for sharing settings of an execution screen regarding content (for example, document data). When the finger f36-1 selects the menu window 234-1 for sharing settings (in S3410), the device 100 may display the contact list 234-2 stored in the device 100, as shown in S3420. When the finger f36-2 selects a specific person from the contact list 234-2, the device 100 can determine that the content will be shared with the selected specific person.
The sharing setting using the contact list described above with reference to FIG. 34 is only an example, and the sharing setting is not limited to this. For example, the device 100 may set the content to be shared by using acquaintance information by extracting acquaintance information through facial recognition performed on a specific image. Alternatively, the device 100 may set the content to be shared with acquaintances via the recent call list.
As shown in FIG. 35, the device 100 of the first user User1 can receive the encryption key k28 (Key_D) corresponding to the voice information of the second user User2 from the device 802 of the second user User2. For example, when the second user User2 is authenticated by using voice information, the device 802 can generate the encryption key k28 by using the basic voice information pre-stored in the memory.
According to an exemplary embodiment, the controller 130 of the device 100 may display a screen 236-2 on the display unit 121 indicating that the content lock is set so that the second user User2 can remove the content lock. However, the screen 236-2 is only an example of the UI, and thus is not limited thereto.
FIG. 36 is a diagram for describing a procedure of encrypting the first encryption key k30 (key_C) by using the second encryption key k28 (key_D).
The controller 130 of the device 802 of the second user User2 can generate a second encryption key k28 (for example, key_D) corresponding to the voice information 48 of the second user User2. For example, when the second user User2 is authenticated by using the voice information 48, the controller 130 can generate the second encryption key k28 by using the basic voice information pre-stored in the memory.
The device 100 receives the second encryption key k28 from the device 802, and can encrypt the first encryption key k3 (key_C) by using the second encryption key k28. For example, "E[key_C]key_D" indicates that "key_C" is encrypted by using "key_D".
37A and 37B are diagrams for describing a procedure for sharing content with another user (the third user User3).
As shown in FIG. 37A, the device 100 of the first user User1 can receive the encryption key k32 (Key_E) corresponding to the facial information of the third user User3 from the device 803 of the third user User3. For example, when the third user User3 is authenticated by using the facial information of the third user User3, the device 803 can generate the encryption key k32 by using the basic facial information stored in the memory in advance. According to an exemplary embodiment, the controller 130 of the device 100 may display a screen 237-2 on the display unit 121 indicating that the content lock is set so that the content lock can be removed by the third user User3. However, the screen 237-2 is only an example of the UI, and thus is not limited thereto.
According to another exemplary embodiment, referring to FIG. 37B, the device 100 may extract facial information from image data pre-stored in the device 100. As shown in S3710, the device 100 can display the image 238 stored in the memory of the device 100 on the display unit 121. The device 100 can receive the user input of selecting the image 51 with the finger f37.
As shown in S3720, the controller 130 can extract the user's facial information 51-2 included in the image data 51-1.
As shown in S3730, the controller 130 may display a screen 238-1 on the display unit 121 indicating that the facial information of the third user User3 has been extracted.
In addition, the controller 130 may display a screen 238-2 on the display unit 121 indicating that the third user User3 is set to remove the content lock. FIG. 37 illustrates an example of the UI, but the UI is not limited to this.
FIG. 38 is a diagram for describing a procedure of encrypting the first encryption key k34 (key_C) by using the third encryption key k32 (key_E).
Referring to FIG. 38, the controller 130 of the device 803 of the third user User3 can generate a third encryption key k32 (Key_E) corresponding to the obtained facial information 52. For example, when the facial information 52 obtained by the third user User3 is authenticated, the controller 130 can generate the third encryption key k32 by using the basic facial information pre-stored in the memory.
The controller 130 of the device 100 of the first user User1 can encrypt the first encryption key k34 (Key_C) by using the third encryption key k32. For example, "E[key_C]key_E" indicates that "key_C" is encrypted by using "key_E".
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
39 and 40 are flowcharts of a method of decrypting content according to an exemplary embodiment.
Referring to FIG. 39, in operation S3901, the device 100 of the first user User1 may store encrypted content. In operation S3902, the device 100 may store the encrypted first encryption key. In FIG. 39, the device 100 stores the encrypted content and the encrypted first encryption key.
In operation S3903, the device 802 of the second user User2 may request content from the device 100. According to an exemplary embodiment, the device 802 that will access the encrypted content may request the encrypted content from the device 100 that stores the encrypted content.
In operation S3904, the device 100 may transmit the encrypted content to the device 802. In operation S3905, the device 100 may transmit the encrypted first encryption key to the device 802.
As described above, according to an exemplary embodiment, the data transmission between the transmitter and the receiver (for example, the transmission of content, the transmission of biometric information, the transmission of encryption keys, and the transmission of decryption keys) can be achieved by using Security channel execution. The secure channel means a channel with high security regarding the communication content between the transmitter and the receiver. In other words, the secure channel can be configured by using a protocol for securely transmitting data (such as secure sockets layer (SSL) or transport layer security (TLS)). For example, the secure channel may be a Hypertext Secure Transmission Protocol (https) configured by using a protocol such as SSL or TLS.
Referring back to FIG. 39, in operation S3906, the device 802 may obtain the second biometric information of the second user User2. According to an exemplary embodiment, the device 802 can obtain the second biometric information from the biometric technology module provided in the device 802.
In operation S3907, the device 802 may perform user authentication by using the second biometric information.
In operation S3908, when the user authentication has succeeded, the controller 130 of the second device 802 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by the controller 130 by using the characteristic information of the basic second biometric information stored in the memory in advance.
In operation S3909, the device 802 may decrypt the encrypted first encryption key by using the second decryption key.
In operation S3910, the device 802 may decrypt the encrypted content by using the decrypted first encryption key.
According to an exemplary embodiment, since the device 802 decrypts the encrypted content received from the device 100 by using the second biometric information, the content of the first user User1 can be shared.
FIG. 40 is a diagram for describing an exemplary embodiment in which the server 200 stores the encrypted content and the encrypted first encryption key.
Referring to FIG. 40, in operation S4001, the device 100 of the first user User1 according to an exemplary embodiment may transmit encrypted content to the server 200. In operation S4002, the device 100 may transmit the encrypted first encryption key to the server 200. In operation S4003, the server 200 according to an exemplary embodiment may store encrypted content. In operation S4004, the server 200 may store the encrypted first encryption key.
Meanwhile, in operation S4005, the device 802 of the second user User2 may request content from the server 200. According to an exemplary embodiment, the device 802 that will access the encrypted content may request the encrypted content from the server 200 storing the encrypted content.
In operation S4006, the server 200 may transmit the encrypted content to the device 802. In operation S4007, the server 200 may transmit the encrypted first encryption key to the device 802. In operation S4008, the device 802 can obtain the second biometric information of the second user User2. According to an exemplary embodiment, the device 802 can obtain the second biometric information from the biometric technology module provided in the device 802.
In operation S4009, the device 802 may perform user authentication by using the second biometric information.
In operation S4010, when the user authentication has been successful, the controller 130 of the second device 802 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by the controller 130 by using the characteristic information of the basic second biometric information stored in the memory in advance.
In operation S4011, the device 802 may decrypt the encrypted first encryption key by using the second decryption key. In operation S4012, the device 802 may decrypt the encrypted content by using the decrypted first encryption key.
According to an exemplary embodiment, since the device 802 decrypts the encrypted content received from the device 100 by using the second biometric information, the content of the first user User1 can be shared.
FIG. 41 is a table for describing a decryption method according to another exemplary embodiment.
FIG. 41 illustrates a table for describing a method of decrypting content after encrypting the content. The controller 130 may decrypt the content based on the second biometric information of the second user.
In detail, when the user has successfully authenticated by using the second biometric information, the controller 130 can generate the decryption key (Key_D) by using the basic second biometric information pre-stored in the memory. The controller 130 may decrypt the encrypted encryption key (ie, E[key_C]key_D) by using the decryption key. The controller 130 may decrypt the encrypted content (ie, E[content]key_C) by using the decrypted encryption key (ie, Key_C).
In addition, the controller 130 can decrypt the content by using the third biometric information of the third user.
In detail, when the user authentication has succeeded by using the third biometric information, the controller 130 can generate the decryption key (Key_E) by using the basic third biometric information pre-stored in the memory. The controller 130 may decrypt the encrypted encryption key (ie, E[key_C]key_E) by using the decryption key. The controller 130 may decrypt the encrypted content (ie, [content]key_C) by using the decrypted encryption key (ie, Key_C).
In addition, the controller 130 can decrypt the content by using the first biometric information of the first user.
In detail, the controller 130 may generate the decryption key (Key_C) by using the basic first biometric information pre-stored in the memory. The controller 130 may decrypt the encrypted content (ie, E[content]key_C) by using the decryption key.
Fig. 42 is a flowchart of a method for changing security settings according to an exemplary embodiment. FIG. 43 is a diagram for describing an example of changing security settings according to an exemplary embodiment.
For example, according to one or more exemplary embodiments described above with reference to FIGS. 29 to 41, after the first user encrypts the content, the first user can share with the second user and the third user The content. The first user can assign the authority to access the encrypted content to each of the second user and the third user.
In order to share content, the device of the first user may encrypt the second user by using an encryption key generated based on each of the second users second biometric information and the third users third biometric information. An encryption key (encryption key used to encrypt content).
At the same time, according to an exemplary embodiment, the first user can remove the permissions assigned to the second user and the third user.
In order to remove content sharing, the device of the first user can encrypt the content and store the content by using a new encryption key generated based on the new biometric information. In this case, even when the second user and the third user generate decryption keys based on the second and third biometric information and obtain the first encryption key by using the decryption key, the second user And the third user cannot decrypt the content encrypted by using the new encryption key.
Referring to FIG. 42, in operation S4201, the device 100 of the first user may store content encrypted by using the first encryption key. In operation S4202, the device 100 may store a first encryption key encrypted by using a second encryption key generated based on the second biometric information of the second user. In addition, in operation S4203, the device 100 may store the first encryption key encrypted by using the third encryption key generated based on the third biometric information of the third user.
By performing operations S4202 and S4203, the content can be shared with the second user and the third user.
For example, the second encryption key can be generated based on the second biometric information of the second user. The first encryption key can be decrypted by using the second encryption key, and the content can be decrypted by using the first encryption key.
In addition, the third encryption key can be generated based on the third biometric information of the third user. The first encryption key can be decrypted by using the third encryption key, and the content can be decrypted by using the first encryption key.
At the same time, in operation S4204, the device 100 can obtain the first biometric information of the first user.
According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S4205, the device 100 may perform user authentication by using the first biometric information.
In operation S4206, when the user authentication has been successful, the controller 130 may obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by the controller 130 by using the characteristic information of the basic first biometric information stored in the memory in advance.
In operation S4207, the device 100 may decrypt the encrypted content by using the first decryption key.
In operation S4208, the device 100 may delete the encrypted content by using the first encryption key. Therefore, the content sharing effect with the second user and the third user can be removed.
In addition, in operation S4209, the device 100 may obtain another biometric information of the first user, and the another biometric information type is different from the first biometric information. According to an exemplary embodiment, the device 100 can obtain another biometric information from a biometric technology module provided in the device 100.
In operation S4210, the device 100 may perform user authentication by using another biometric information.
In operation S4211, when the user authentication has been successful, the controller 130 of the device 100 may obtain an encryption key corresponding to another biometric information. Here, the encryption key may be a value generated by using basic biometric information stored in the memory 170 in advance.
In operation S4212, the controller 130 may encrypt the content by using an encryption key corresponding to another biometric information. Therefore, the encrypted content is not decrypted by the second and third encryption keys generated based on the second and third biometric information, and therefore the second and third users cannot decrypt the encrypted content.
In FIG. 42, the device 100 stores encrypted content, but according to another exemplary embodiment, the encrypted content can be stored in an external server, and operations S4204 to S4212 can request the encrypted content from the external server when the device 100 requests the encrypted content and Execute when receiving encrypted content from an external server.
In addition, in operation S4212, the device 100 may store the encrypted content. As another example, in operation S4212, the device 100 may transmit the encrypted content to an external server.
Referring to FIG. 43, in S4310, the controller 130 of the device 100 may receive a user input of selecting the button 240 for changing the lock setting of the set content c30 by the finger f38.
Referring to FIG. 43, in S4320, the controller 130 may display a screen 242 on the display unit 121 for requesting the user to input new biometric information to change the lock setting.
FIG. 43 illustrates an example of the UI, in which the content preservation is removed, and then the content preservation is reset by using new biometric information, and the UI is not limited to this.
Fig. 44 is a flowchart of a method for setting content preservation according to an exemplary embodiment.
In operation S4401, the device 100 may generate a content encryption key.
The content encryption key may be a key randomly generated by the system for encrypting content (ie, the device 100 of the first user).
In operation S4402, the device 100 may transmit the content encryption key to the device 1001 of the second user.
The content encryption key can be transmitted by using a secure channel. As described above, the secure channel means a channel with high security regarding the communication content between the transmitter and the receiver. In other words, a secure channel can be configured by using a protocol (such as SSL or TLS) for securely transmitting data. For example, the secure channel can be https configured by an application protocol (such as SSL or TLS).
Meanwhile, in operation S4403, the device 100 may encrypt content by using the content encryption key.
In operation S4404, the device 100 may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S4405, the controller 130 of the device 100 may perform user authentication by using the first biometric information.
In operation S4406, when the user authentication has been successful, the controller 130 may obtain the first encryption key corresponding to the first biometric information. Here, the first encryption key may be a value generated by using basic first biometric information stored in the memory 170 in advance.
In operation S4407, the device 100 may encrypt the content encryption key by using the first encryption key. In operation S4408, the device 100 may store the content encryption key encrypted by using the first encryption key.
Meanwhile, in operation S4402, the device 1001 may receive the content encryption key from the device 100.
In operation S4409, the device 1001 can obtain the second biometric information of the second user. For example, the device 1001 can obtain the second biometric information from the biometric technology module provided in the device 1001.
In operation S4410, the device 1001 may perform user authentication by using the second biometric information.
In operation S4411, when the user authentication has been successful, the controller 130 of the device 1001 may obtain a second encryption key corresponding to the second biometric information. Here, the second encryption key may be a value generated by using basic second biometric information stored in the memory 170 in advance.
In operation S4412, the device 1001 may encrypt the content encryption key by using the second encryption key. In operation S4413, the device 1001 may store the content encryption key encrypted by using the second encryption key.
Therefore, the device 1001 can decrypt the content encryption key based on the second biometric information, and then decrypt the content by using the decrypted content encryption key.
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
45 and 46 are flowcharts of methods for decrypting content according to other exemplary embodiments.
In operation S4501, the device 100 of the first user may store the encrypted content. In operation S4502, the device 100 may store the content encryption key encrypted by using the first encryption key.
Meanwhile, in operation S4503, the device 2001 of the second user may store the content encryption key encrypted by using the second encryption key.
In operation S4504, the device 2001 may request the device 100 for content. For example, the device 2001 that will access the encrypted content may request the encrypted content from the device 100.
In operation S4505, the device 100 may transmit the encrypted content to the device 2001.
In order to decrypt the encrypted content, in operation 4506, the device 2001 obtains the second biometric information of the second user. According to an exemplary embodiment, the device 2001 can obtain the second biometric information from the biometric technology module provided in the device 2001.
In operation S4507, the device 2001 may perform user authentication by using the second biometric information.
In operation S4508, when the user authentication is successful, the controller 130 of the device 2001 can obtain the second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S4509, the device 2001 may decrypt the content encryption key by using the second decryption key. In operation S4510, the device 2001 may decrypt the encrypted content by using the decrypted content encryption key.
FIG. 46 illustrates an exemplary embodiment in which encrypted content is stored in the server 200.
In operation S4601, the server 200 according to an exemplary embodiment may store encrypted content.
In addition, in operation S4602, the device 2001 may store the content encryption key encrypted by using the second encryption key.
In operation S4603, the device 2001 may request the server 200 for content. For example, the device 2001 that will access the encrypted content may request the server 200 for the encrypted content. In operation S4604, the server 200 may transmit the encrypted content to the device 2001.
In operation S4605, the device 2001 may obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2001 can obtain the second biometric information from the biometric technology module provided in the device 2001.
In operation S4606, the device 2001 may perform user authentication by using the second biometric information.
In operation S4607, when the user authentication has succeeded, the controller 130 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S4608, the device 2001 may decrypt the content encryption key by using the second decryption key. In operation S4609, the device 2001 may decrypt the encrypted content by using the decrypted content encryption key.
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 47 is a table for describing a decryption method according to another exemplary embodiment.
FIG. 47 is a table for describing a method of decrypting the content after the content is encrypted. The controller 130 can decrypt the content by using the first biometric information of the first user.
In detail, when the user authentication has succeeded by using the first biometric information, the controller 130 can generate the decryption key (Key_A) by using the basic first biometric information pre-stored in the memory. The controller 130 may decrypt the encrypted encryption key (ie, E[key_con]key_A) by using the decryption key (Key_A). The controller 130 may decrypt the encrypted content (ie, E[content]key_con) by using the decrypted encryption key (ie, Key_con).
In addition, the controller 130 can decrypt the content by using the second biometric information of the second user.
In detail, when the user has successfully authenticated by using the second biometric information, the controller 130 can generate the decryption key (Key_B) by using the basic second biometric information pre-stored in the memory. The controller 130 may decrypt the encrypted encryption key (ie, E[key_con]key_B) by using the decryption key (Key_B). The controller 130 may decrypt the encrypted content (ie, E[content]key_con) by using the decrypted encryption key (ie, Key_con).
48 to 50 are flowcharts of methods for setting content preservation according to other exemplary embodiments.
Referring to FIG. 48, in operation S4801, the device 100 according to an exemplary embodiment may obtain the user's first biometric information. According to an exemplary embodiment, the controller 130 of the device 100 can obtain the first biometric information from the biometric technology module provided in the device 100.
In operation S4802, the controller 130 may perform user authentication by using the first biometric information.
In operation S4803, when the user authentication has succeeded, the controller 130 may obtain the first encryption key corresponding to the first biometric information. Here, the first encryption key may be a value generated by using basic first biometric information stored in the memory 170 in advance.
In operation S4804, the device 100 may encrypt the content by using the first encryption key.
In operation S4805, the second device 2002 according to an exemplary embodiment may obtain second biometric information of the user. According to an exemplary embodiment, the controller 130 of the second device 2002 can obtain the second biometric information from the biometric technology module provided in the second device 2002.
In operation S4806, the controller 130 of the second device 2002 may perform user authentication by using the second biometric information.
In operation S4807, when the user authentication has succeeded, the controller 130 may obtain a second encryption key corresponding to the second biometric information. Here, the second encryption key may be a value generated by using basic second biometric information stored in the memory 170 in advance.
In operation S4808, the device 100 may receive the second encryption key from the second device 2002. In operation S4809, the device 100 may double-encrypt the encrypted content by using the second encryption key. In operation S4810, the device 100 may store the double-encrypted content.
According to an exemplary embodiment, the device 100 may double-encrypt the content by using the second biometric information after encrypting the content by using the first biometric information.
The device 100 and the second device 2002 can be used by the same user or different users.
In FIG. 49, the device 100 obtains the first biometric information from an external device (ie, the third device 2006).
Referring to FIG. 49, in operation S4901, the third device 2006 according to an exemplary embodiment may obtain the user's first biometric information. According to an exemplary embodiment, the third device 2006 can obtain the first biometric information from the biometric technology module provided in the third device 2006.
In operation S4902, the third device 2006 may perform user authentication by using the first biometric information.
In operation S4903, when the user authentication has been successful, the third device 2006 may obtain the first encryption key corresponding to the first biometric information. Here, the first encryption key may be a value generated by using basic first biometric information stored in the memory 170 in advance.
In operation S4904, the third device 2006 may transmit the first encryption key to the device 100.
In operation S4905, the device 100 may encrypt the content by using the first encryption key.
Meanwhile, in operation S4906, the second device 2002 according to an exemplary embodiment may obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module provided in the second device 200.
In operation S4907, the second device 2002 may perform user authentication by using the second biometric information.
In operation S4908, when the user authentication has been successful, the second device 2002 can obtain a second encryption key corresponding to the second biometric information. Here, the second encryption key may be a value generated by using basic second biometric information stored in the memory 170 in advance.
In operation S4909, the second device 2002 may transmit the second encryption key to the device 100.
In operation S4910, the device 100 may double-encrypt the encrypted content by using the second encryption key. In operation S4911, the device 100 may store the double-encrypted content.
According to an exemplary embodiment, the device 100 may double-encrypt the content by using the second biometric information after encrypting the content by using the first biometric information.
The device 100 and the second device 2002 can be used by the same user or different users.
According to another exemplary embodiment, in FIG. 50, the device 100 double-encrypts the content based on the biometric information of a plurality of segments.
In operation S5001, the device 100 according to an exemplary embodiment may obtain the user's first biometric information. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S5002, the device 100 may perform user authentication by using the first biometric information.
In operation S5003, when the user authentication has succeeded, the device 100 may obtain the first encryption key corresponding to the first biometric information. Here, the first encryption key may be a value generated by using basic first biometric information stored in the memory 170 in advance.
In operation S5004, the device 100 may encrypt the content by using the first encryption key.
In addition, in operation S5005, the device 100 can obtain the user's second biometric information. According to an exemplary embodiment, the device 100 can obtain the second biometric information from another biometric technology module provided in the device 100.
In operation S5006, the device 100 may perform user authentication by using the second biometric information.
In operation S5007, when the user authentication has been successful, the device 100 may obtain a second encryption key corresponding to the second biometric information. Here, the second encryption key may be a value generated by using basic second biometric information stored in the memory 170 in advance.
In operation S5008, the device 100 may double-encrypt the encrypted content by using the second encryption key. In operation S5009, the device 100 may store double-encrypted content.
51 to 53 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 51 is a flowchart of a decryption method corresponding to the encryption method described above with reference to FIG. 48.
According to an exemplary embodiment, the double-encrypted content can be decrypted through a decryption program using the first decryption key and a decryption program using the second decryption key.
In operation S5101, the device 100 according to an exemplary embodiment may store double-encrypted content.
In operation S5102, the device 100 can obtain the user's first biometric information. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S5103, the device 100 may perform user authentication by using the first biometric information.
In operation S5104, when the user authentication is successful, the device 100 can obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
Meanwhile, in operation S5105, in order to decrypt the double-encrypted content, the device 100 may send a request for the second decryption key to the second device 2002. In addition, in operation S5106, the second device 2002 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 200 can obtain the second biometric information from the biometric technology module provided in the second device 200.
In operation S5107, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5108, when the user authentication is successful, the second device 2002 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5109, the second device 2002 may transmit the second decryption key to the device 100. In operation S5110, the device 100 may decrypt the double-encrypted content by using the first and second decryption keys. For example, the device 100 can decrypt the double-encrypted content (eg, E[E[content]Key_A]Key_B by using the first decryption key (eg, Key_A) and the second decryption key (eg, Key_B) ).
FIG. 52 is a flowchart of a decryption method corresponding to the encryption method described above with reference to FIG. 49.
According to an exemplary embodiment, the double-encrypted content can be decrypted through a decryption program using the first decryption key and a decryption program using the second decryption key.
In operation S5201, the device 100 according to an exemplary embodiment may store double-encrypted content. In operation S5202, in order to decrypt the double-encrypted content, the device 100 may send a request for the first decryption key to the third device 2006.
At the same time, in operation S5203, the third device 2006 can obtain the user's first biometric information. According to an exemplary embodiment, the third device 2006 can obtain the first biometric information from the biometric technology module provided in the third device 2006.
In operation S5204, the third device 2006 may perform user authentication by using the first biometric information.
In operation S5205, when the user authentication is successful, the third device 2006 can obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S5206, the third device 2006 may transmit the first decryption key to the device 100.
Meanwhile, in operation S5207, in order to decrypt the double-encrypted content, the device 100 may send a request for the second decryption key to the second device 2002.
In operation S5208, the second device 2002 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module provided in the second device 200.
In operation S5209, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5210, when the user authentication has been successful, the second device 200 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5211, the second device 2002 may transmit the second decryption key to the device 100.
In operation S5212, after receiving the first and second decryption keys, the device 100 may decrypt the double-encrypted content by using the first and second decryption keys. For example, the device 100 can decrypt the double-encrypted content (eg, E[E[content]Key_A]Key_B by using the first decryption key (eg, Key_A) and the second decryption key (eg, Key_B) ).
In FIG. 53, the first device 100 requests the second device 2002 to decrypt the content.
According to an exemplary embodiment, the double-encrypted content can be decrypted through a decryption program using the first decryption key and a decryption program using the second decryption key.
In operation S5301, the device 100 according to an exemplary embodiment may store double-encrypted content.
In operation S5302, the device 100 may request the second device 2002 to decrypt the double-encrypted content while transmitting the double-encrypted content.
In operation S5303, the second device 2002 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module installed in the second device 2002.
In operation S5304, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5305, when the user authentication is successful, the second device 2002 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5306, the second device 2002 performs the first decryption on the double-encrypted content by using the second decryption key. For example, the second device 2002 may decrypt the double-encrypted content based on the second biometric information obtained by the second device 200.
In operation S5310, the second device 2002 may transmit the double-encrypted content on which the first decryption has been performed to the device 100.
At the same time, in operation S5307, the first device 100 can obtain the user's first biometric information. According to an exemplary embodiment, the device 100 can obtain the first biometric technology information from the biometric technology module provided in the device 100.
In operation S5308, the device 100 may perform user authentication by using the first biometric information.
In operation S5309, when the user authentication is successful, the first device 100 may obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S5311, the device 100 may perform a second decryption on the double-encrypted content on which the first encryption has been performed by using the first decryption key. For example, the device 100 may decrypt the double-encrypted content (for example, E[content]Key_A]) performed by the first decryption by using the first decryption key (for example, Key_A).
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 54 is a table for describing a decryption method according to another exemplary embodiment.
FIG. 54 is a table for describing a method of decrypting content after encrypting the content according to one or more exemplary embodiments described above with reference to FIGS. 48 to 53.
The controller 130 can decrypt the content by using the first biometric information and the second biometric information.
In detail, when the user authentication has succeeded by using the first biometric information, the controller 130 can generate the decryption key (Key_A) by using the basic first biometric information pre-stored in the memory. In addition, when the user has successfully authenticated by using the second biometric information, the controller 130 can generate the decryption key (Key_B) by using the basic second biometric information pre-stored in the memory.
The controller 130 can decrypt the double-encrypted content (E[E[content]key_A]Key_B) by using the decryption key (Key_B), and then decrypt the content (E[content ]key_A) to decrypt the double-encrypted content E[E[content]key_A]Key_B.
As another example, the double-encrypted content (E[E[content]Key_B]Key_A) can be decrypted by using the decryption key (Key_A), and then decrypted by using the decryption key (Key_B).
FIG. 55 and FIG. 56 are flowcharts of encryption methods for setting security according to other exemplary embodiments. In FIGS. 55 and 56, the content is encrypted by using an encryption key generated by combining multiple encryption keys based on multiple pieces of biometric information.
Referring to FIG. 55, in operation S5501, the device 100 may obtain the user's first biometric information. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S5502, the device 100 may perform user authentication by using the first biometric information.
In operation S5503, when the user authentication has succeeded, the device 100 may obtain the first encryption key corresponding to the first biometric information. For example, the first encryption key may be a value generated by using basic first biometric information stored in memory in advance.
At the same time, in operation S5504, the second device 2202 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module installed in the second device 2002.
In operation S5505, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5506, when the user authentication is successful, the second device 2002 can obtain a second encryption key corresponding to the second biometric information. For example, the second encryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5507, the second device 2002 may transmit the second encryption key to the device 100.
In operation S5508, the device 100 may generate a third encryption key by combining the first encryption key and the second encryption key.
In operation S5509, the device 100 may encrypt the content by using the third encryption key.
In operation S5510, the device 100 may store the encrypted content.
Referring to FIG. 56, the device 100 obtains the first biometric information from an external device (the third device 2006).
In operation S5601, the third device 2006 can obtain the user's first biometric information. According to an exemplary embodiment, the third device 2006 can obtain the first biometric information from the biometric technology module provided in the third device 2006.
In operation S5602, the third device 2006 may perform user authentication by using the first biometric information.
In operation S5603, when the user authentication has succeeded, the third device 2006 may obtain the first encryption key corresponding to the first biometric information. For example, the first encryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S5604, the third device 2006 may transmit the first encryption key to the device 100.
At the same time, in operation S5605, the second device 2202 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module installed in the second device 2002.
In operation S5606, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5607, when the user authentication has been successful, the second device 2002 can obtain a second encryption key corresponding to the second biometric information. For example, the second encryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5608, the second device 2002 may transmit the second encryption key to the device 100.
In operation S5609, the device 100 may generate a third encryption key by combining the first encryption key and the second encryption key. In operation S5610, the device 100 may encrypt content by using the third encryption key. In operation S56110. The device 100 can store encrypted content.
57 to 59 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 57 is a flowchart for describing a decryption method corresponding to the encryption method described above with reference to FIG. 55.
In operation S5701, the device 100 according to an exemplary embodiment may store encrypted content.
In operation S5702, the device 100 may obtain the user's first biometric information. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S5703, the device 100 may perform user authentication by using the first biometric information.
In operation S5704, when the user authentication is successful, the device 100 may obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S5705, the device 100 may send a request for the second decryption key to the second device 2002.
In operation S5706, the second device 2002 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module installed in the second device 2002.
In operation S5707, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5708, when the user authentication is successful, the second device 2002 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5709, the second device 2002 may transmit the second decryption key to the device 100.
In operation S5710, the device 100 may generate a third decryption key by combining the second decryption key received from the second device 2002 and the first decryption key obtained in operation S5704.
In operation S5711, the device 100 may decrypt the encrypted content by using the third decryption key.
FIG. 58 is a flowchart for describing a decryption method corresponding to the encryption method described above with reference to FIG. 56.
The device 100 according to an exemplary embodiment may receive the first decryption key corresponding to the user's first biometric information from the external device (the third device 2006).
In operation S5801, the device 100 according to an exemplary embodiment may store encrypted content.
In operation S5802, the device 100 may send a request for the first decryption key to the third device 2006.
In operation S5803, the third device 2006 can obtain the user's first biometric information. According to an exemplary embodiment, the third device 2006 can obtain the first biometric information from the biometric technology module provided in the third device 2006.
In operation S5804, the third device 2006 may perform user authentication by using the first biometric information.
In operation S5805, when the user authentication is successful, the third device 2006 can obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S5806, the third device 2006 may transmit the first decryption key to the device 100.
Meanwhile, in order to decrypt the encrypted content, the device 100 may send a request for the second decryption key to the second device 2002 in operation S5807. In operation S5808, the second device 2002 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module installed in the second device 2002.
In operation S5809, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5810, when the user authentication has been successful, the second device 2002 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5811, the second device 2002 may transmit the second decryption key to the device 100.
In operation S5812, the device 100 may generate a third decryption key by combining the first decryption key received in operation S5806 and the second decryption key received in operation S5811.
In operation S5813, the device 100 may decrypt the encrypted content by using the third decryption key.
In FIG. 59, the second device 2002 decrypts the encrypted content.
In operation S5901, the device 100 according to an exemplary embodiment may store encrypted content.
In operation S5902, the second device 2002 that will access the encrypted content may send a request for the encrypted content to the device 100.
In operation S5903, the device 100 may transmit the encrypted content to the second device 2002.
In addition, in order to decrypt the encrypted content, the second device 200 may send a request for the first decryption key to the device 100 in operation S5904.
In operation S5905, the device 100 can obtain the user's first biometric information. According to an exemplary embodiment, the device 100 can obtain the first biometric information from a biometric technology module provided in the device 100.
In operation S5906, the device 100 may perform user authentication by using the first biometric information.
In operation S5907, when the user authentication has succeeded, the device 100 may obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S5911, the device 100 may transmit the first decryption key to the second device 2002.
At the same time, in operation S5908, the second device 2002 can obtain the user's second biometric information. According to an exemplary embodiment, the second device 2002 can obtain the second biometric information from the biometric technology module installed in the second device 2002.
In operation S5909, the second device 2002 may perform user authentication by using the second biometric information.
In operation S5910, when the user authentication has been successful, the second device 2002 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S5912, the second device 2002 may generate a third decryption key by combining the first decryption key received in operation S5911 and the second decryption key obtained in operation S5910.
In operation S5913, the second device 2002 may decrypt the encrypted content by using the third decryption key.
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 60 is a table for describing a decryption method according to another exemplary embodiment.
In other words, FIG. 60 is a table for describing a method of decrypting content after encrypting the content according to the exemplary embodiment described above with reference to FIGS. 55 to 59.
The controller 130 can decrypt the content by using the first biometric information and the second biometric information.
In detail, when the user authentication has succeeded by using the first biometric information, the controller 130 can generate the decryption key (Key_A) by using the basic first biometric information pre-stored in the memory.
In addition, when the user has successfully authenticated by using the second biometric information, the controller 130 can generate the decryption key (Key_B) by using the basic second biometric information stored in the memory in advance.
The controller 130 may generate a combined decryption key by combining the decryption keys (ie, Key_A and Key_B). The controller 130 may decrypt the encrypted content by using the combined decryption key (ie, E[content]key_A+Key_B). Here, "E[content]Key_A+Key_B" indicates the content encrypted by using the encryption key generated by combining Key_A and Key_B.
61 and 62 are flowcharts of encryption methods for setting security according to other exemplary embodiments.
In FIGS. 61 and 62, when the content is encrypted by multiple users (for example, N users), the content can be encrypted by all of the multiple users (for example, the N users). ) Decrypt.
According to an exemplary embodiment, the device 2003 of the first user may encrypt content based on the first to third biometrics of the first to third users.
Referring to FIG. 61, in operation S6101, the device 2003 may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2003 can obtain the first biometric information from a biometric technology module installed in the device 2003.
In operation S6102, the device 2003 may perform user authentication by using the first biometric information.
In operation S6103, when the user authentication has been successful, the device 2003 can obtain the first encryption key corresponding to the first biometric information. For example, the first encryption key may be a value generated by using basic first biometric information stored in memory in advance.
At the same time, in operation S6104, the device 2004 of the second user can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2004 can obtain the second biometric information from a biometric technology module installed in the device 2004.
In operation S6105, the device 2004 may perform user authentication by using the second biometric information.
In operation S6106, when the user authentication is successful, the device 2004 can obtain an encryption key corresponding to the second biometric information. For example, the second encryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6110, the device 2004 may transmit the second encryption key to the device 2003.
In addition, in operation S6107, the device 2005 of the third user can obtain the third biometric information of the third user. According to an exemplary embodiment, the device 2005 can obtain the third biometric information from a biometric technology module installed in the device 2005.
In operation S6108, the device 2005 may perform user authentication by using the third biometric information.
In operation S6109, when the user authentication has been successful, the device 2005 may obtain a third encryption key corresponding to the third biometric information. For example, the third encryption key may be a value generated by using basic third biometric information stored in memory in advance.
In operation S6111, the device 2005 may transmit the third encryption key to the device 2003.
Meanwhile, in operation S6112, the device 2003 may generate by combining the first encryption key obtained in operation S6103, the second encryption key received in operation S6110, and the third encryption key received in operation S6111 The fourth encryption key.
In operation S6113, the device 2003 may encrypt the content by using the fourth encryption key. In operation S6114, the device 2003 may store the encrypted content.
In FIG. 62, the server 200 encrypts the content.
In operation S6201, the device 2003 can obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2003 can obtain the first biometric information from a biometric technology module installed in the device 2003.
In operation S6202, the device 2003 may perform user authentication by using the first biometric information.
In operation S6203, when the user authentication is successful, the device 2003 can obtain the first encryption key corresponding to the first biometric information. For example, the first encryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S6204, the device 2003 may transmit the first encryption key to the server 200.
At the same time, in operation S6205, the device 2004 may obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2004 can obtain the second biometric information from a biometric technology module installed in the device 2004.
In operation S6206, the device 2004 may perform user authentication by using the second biometric information.
In operation S6207, when the user authentication has succeeded, the device 2004 may obtain an encryption key corresponding to the second biometric information. For example, the second encryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6208, the device 2004 may transmit the second encryption key to the server 200.
In addition, in operation S6209, the device 2005 may obtain the third biometric information of the third user. According to an exemplary embodiment, the device 2005 can obtain the third biometric information from a biometric technology module installed in the device 2005.
In operation S6210, the device 2005 may perform user authentication by using the third biometric information.
In operation S6211, when the user authentication has been successful, the device 2005 can obtain a third encryption key corresponding to the third biometric information. For example, the third encryption key may be a value generated by using basic third biometric information stored in memory in advance.
In operation S6212, the device 2005 may transmit the third encryption key to the server 200.
Meanwhile, in operation S6213, the server 200 may combine the first encryption key received in operation S6204, the second encryption key received in operation S6208, and the third encryption key received in operation S6212. Generate a fourth encryption key. In operation S6214, the server 200 may encrypt the content by using the fourth encryption key. In operation S6215, the server 200 may store the encrypted content.
FIG. 63 and FIG. 64 are flowcharts of methods for decrypting content according to other exemplary embodiments.
Referring to Figure 63, the device 2003 decrypts the content.
In operation S6301, the device 2003 according to an exemplary embodiment may store encrypted content.
In operation S6302, the device 2003 may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2003 can obtain the first biometric information from a biometric technology module installed in the device 2003.
In operation S6303, the device 2003 may perform user authentication by using the first biometric information.
In operation S6304, when the user authentication is successful, the device 2003 can obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S6305, in order to decrypt the encrypted content, the device 2003 may send a request for the second decryption key to the device 2004.
In operation S6306, the device 2004 may obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2004 can obtain the second biometric information from a biometric technology module installed in the device 2004.
In operation S6307, the device 2004 may perform user authentication by using the second biometric information.
In operation S6308, when the user authentication is successful, the second device 2004 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6309, the device 2004 may transmit the second decryption key to the device 2003.
Meanwhile, in operation S6310, in order to decrypt the encrypted content, the device 2003 may send a request for the third decryption key to the device 2005. In operation S6311, the device 2005 may obtain the third biometric information of the third user. According to an exemplary embodiment, the device 2005 can obtain the third biometric information from a biometric technology module installed in the device 2005.
In operation S6312, the device 2005 may perform user authentication by using the third biometric information.
In operation S6313, when the user authentication has been successful, the device 2005 may obtain a third decryption key corresponding to the third biometric information. For example, the third decryption key may be a value generated by using basic third biometric information stored in memory in advance.
In operation S6314, the device 2005 may transmit the third decryption key to the device 2003.
In operation S6315, the device 2003 may generate a fourth decryption key by combining the first decryption key obtained in operation S6304, the second decryption key received in operation S6309, and the third decryption key received in operation S6314. Decryption key. In operation S6316, the device 2003 may decrypt the encrypted content by using the fourth decryption key.
Referring to FIG. 64, the server 200 decrypts the content.
In operation S6401, the server 200 according to an exemplary embodiment may store encrypted content. In operation S6402, in order to decrypt the encrypted content, the server 200 may send a request for the first decryption key to the device 2003.
In operation S6403, the device 2003 can obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2003 can obtain the first biometric information from a biometric technology module installed in the device 2003.
In operation S6404, the device 2003 may perform user authentication by using the first biometric information.
In operation S6405, when the user authentication is successful, the device 2003 can obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S6406, the device 2003 may transmit the first decryption key to the server 200.
Meanwhile, in operation S6407, in order to decrypt the encrypted content, the server 200 may send a request for the second decryption key to the device 2004. In operation S6408, the device 2004 can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2004 can obtain the second biometric information from a biometric technology module installed in the device 2004.
In operation S6409, the device 2004 may perform user authentication by using the second biometric information.
In operation S6410, when the user authentication has been successful, the second device 2004 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6411, the device 2004 may transmit the second decryption key to the server 200.
Meanwhile, in operation S6412, in order to decrypt the encrypted content, the server 200 may send a request for the third decryption key to the device 2005. In operation S6413, the device 2005 can obtain the third biometric information of the third user. According to an exemplary embodiment, the device 2005 can obtain the third biometric information from a biometric technology module installed in the device 2005.
In operation S6414, the device 2005 may perform user authentication by using the third biometric information.
In operation S6415, when the user authentication has been successful, the device 2005 may obtain a third decryption key corresponding to the third biometric information. For example, the third decryption key may be a value generated by using basic third biometric information stored in memory in advance.
In operation S6416, the device 2005 may transmit the third decryption key to the device 2003.
In operation S6417, the server 200 may generate the first decryption key received in operation S6406, the second decryption key received in operation S6411, and the third decryption key received in operation S6416. Four decryption keys.
In operation S6418, the server 200 may decrypt the encrypted content by using the fourth decryption key.
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
FIG. 65 is a table for describing a decryption method according to another exemplary embodiment.
In other words, FIG. 65 is a table for describing a method of decrypting content after encrypting the content according to one or more exemplary embodiments described above with reference to FIGS. 61 to 64.
The controller 130 can decrypt the content based on the biometric information of the first user, the biometric information of the second user, and the biometric information of the third user.
In detail, when the user authentication has succeeded by using the biometric information of the first user, the controller 130 can generate the decryption key by using the basic biometric information of the first user stored in the memory in advance. (Key_1).
When the user authentication has succeeded by using the second users biometric information, the controller 130 can generate a decryption key (Key_2) by using the second users basic biometric information pre-stored in the memory . In addition, when the user authentication has succeeded by using the third user's biometric information, the controller 130 can generate the decryption key by using the third user's basic biometric information pre-stored in the memory ( Key_3).
Then, the controller 130 can generate a decryption key (Key_4) by combining Key_1, Key_2, and Key_3.
The encrypted content (for example, E[content]Key_4) can be decrypted by using the decryption key (Key_4). Here, "E[content]Key_4" indicates the content encrypted by using "Key_4".
66 and 67 are flowcharts of encryption methods for setting security according to other exemplary embodiments.
In FIGS. 66 to 69, when the content is encrypted by multiple users (for example, N users), the content may be encrypted by some of the multiple users (for example, the N users). K users among users) decrypt.
Referring to FIG. 66, in operation S6601, the device 2007 of the first user may generate a content encryption key. The content encryption key may be a key randomly generated by the system (ie, the device 2007) used to encrypt the content.
In operation S6602, the device 2007 may encrypt the content by using the content encryption key.
In operation S6603, the device 2007 may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2007 can obtain the first biometric information from a biometric technology module installed in the device 2007.
In operation S6604, the device 2007 may perform user authentication by using the first biometric information.
In operation S6605, when the user authentication has been successful, the device 2007 may obtain the first encryption key corresponding to the first biometric information. For example, the first encryption key may be a value generated by using basic first biometric information stored in memory in advance.
At the same time, in operation S6606, the device 2008 of the second device can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2008 can obtain the second biometric information from the biometric technology module installed in the device 2008.
In operation S6607, the device 2007 may perform user authentication by using the second biometric information.
In operation S6608, when the user authentication is successful, the device 2008 can obtain a second encryption key corresponding to the second biometric information. For example, the second encryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6609, the device 2008 may transmit the second encryption key to the device 2007.
In addition, in operation S6610, the device 2009 of the third user can obtain the third biometric information of the third user. According to an exemplary embodiment, the device 2009 can obtain the third biometric information from the biometric technology module provided in the device 2009.
In operation S6611, the device 2009 may perform user authentication by using the third biometric information.
In operation S6612, when the user authentication has been successful, the device 2009 may obtain a third encryption key corresponding to the third biometric information. For example, the third encryption key may be a value generated by using basic third biometric information stored in memory in advance.
In operation S6613, the device 2009 may transmit the third encryption key to the device 2007.
In operation S6614, the device 2007 may generate a fourth encryption key by combining some of the first to third encryption keys. Can generate up to<sub>N</sub>C<sub>K</sub>The fourth encryption key for the number of combinations (the number of combinations selected from N).
For example, the device can set the content so that the content is encrypted by three users and decrypted by two users. In this case, can produce<sub>3</sub>C<sub>2</sub>An encryption key (fourth encryption key). For example, the encryption key of the first and second encryption key combination, the encryption key of the first and third encryption key combination, and the encryption key of the second and third encryption key combination can be generated.
In operation S6615, the device 2007 may encrypt the content encryption key by using the fourth encryption key. In operation S6616, the device 2007 may store the encrypted encryption key. In operation S6617, the device 2007 may store the encrypted content.
Referring to FIG. 67, the server 2000 generates a content encryption key and encrypts the content.
In operation S6701, the server 2000 according to an exemplary embodiment may generate a content encryption key. The content encryption key may be a key randomly generated by the system (ie, the server 2000) used to encrypt the content. In operation S6702, the server 2000 may encrypt the content by using the content encryption key.
In operation S6703, the device 2007 can obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2007 can obtain the first biometric information from a biometric technology module installed in the device 2007.
In operation S6704, the device 2007 may perform user authentication by using the first biometric information.
In operation S6705, when the user authentication is successful, the device 2007 can obtain the first encryption key corresponding to the first biometric information. For example, the first encryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S6706, the device 2008 may transmit the first encryption key to the server 2000.
At the same time, in operation S6707, the device 2008 can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2008 can obtain the second biometric information from the biometric technology module installed in the device 2008.
In operation S6708, the device 2007 may perform user authentication by using the second biometric information.
In operation S6709, when the user authentication has been successful, the device 2008 may obtain a second encryption key corresponding to the second biometric information. For example, the second encryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6710, the device 2008 may transmit the second encryption key to the server 2000.
In addition, in operation S6711, the device 2009 can obtain the third biometric information of the third user. According to an exemplary embodiment, the device 2009 can obtain the third biometric information from the biometric technology module provided in the device 2009.
In operation S6712, the device 2009 may perform user authentication by using the third biometric information.
In operation S6713, when the user authentication has been successful, the device 2009 may obtain a third encryption key corresponding to the third biometric information. For example, the third encryption key may be a value generated by using basic third biometric information stored in memory in advance.
In operation S6714, the device 2009 may transmit the third encryption key to the server 2000.
In operation S6715, the server 2000 may generate a fourth encryption key by combining some of the first to third encryption keys. Can generate up to<sub>N</sub>C<sub>K</sub>The fourth encryption key for the number of combinations (the number of combinations selected from N).
For example, the server can set the content so that the content is encrypted by three users and decrypted by two users. In this case, can produce<sub>3</sub>C<sub>2</sub>An encryption key (fourth encryption key). For example, the encryption key of the first and second encryption key combination, the encryption key of the first and third encryption key combination, and the encryption key of the second and third encryption key combination can be generated.
In operation S6716, the server 2000 may encrypt the content encryption key by using the fourth encryption key. In operation S6717, the server 2000 may store the encrypted encryption key. In operation S6718, the server 2000 may store the encrypted content.
FIG. 68 and FIG. 69 are flowcharts of methods for decrypting content according to other exemplary embodiments.
Referring to FIG. 68, the device 2007 decrypts the encrypted content.
In operation S6801, the device 2007 may store the encrypted content encryption key. In operation S6802, the device 2007 may store the encrypted content.
In operation S6803, the device 2007 may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2007 can obtain the first biometric information from a biometric technology module installed in the device 2007.
In operation S6804, the device 2007 may perform user authentication by using the first biometric information.
In operation S6805, when the user authentication is successful, the device 2007 can obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
Meanwhile, in operation S6806, in order to decrypt the encrypted content, the device 2007 may request the device 2008 for a second decryption key. In operation S6807, the device 2008 can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2008 can obtain the second biometric information from the biometric technology module installed in the device 2008.
In operation S6808, the device 2008 may perform user authentication by using the second biometric information.
In operation S6809, when the user authentication has been successful, the device 2008 may obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6810, the device 2008 may transmit the second decryption key to the device 2007.
In operation S6811, the device 2007 may generate a fourth decryption key by combining the first and second decryption keys. In operation S6812, the device 2007 may decrypt the encrypted content encryption key by using the fourth decryption key. In operation S6813, the device 2007 may decrypt the encrypted content by using the decrypted content encryption key.
In Figure 68 and Figure 69, the content is encrypted by three users and decrypted by two users. In FIG. 68, the device of the first user decrypts the content, but the exemplary embodiment is not limited thereto. In other words, the device of the second user or the third user can decrypt the content.
Referring to FIG. 69, the server 200 decrypts the encrypted content.
In operation S6901, the server 200 may store the encrypted content encryption key. In operation S6902, the server 200 may store the encrypted content.
In order to decrypt the encrypted content, the server 200 may send a request for the first decryption key to the device 2007 in operation S6903. In operation S6904, the device 2007 may obtain the first biometric information of the first user. According to an exemplary embodiment, the device 2007 can obtain the first biometric information from a biometric technology module installed in the device 2007.
In operation S6905, the device 2007 may perform user authentication by using the first biometric information.
In operation S6906, when the user authentication has been successful, the device 2007 may obtain the first decryption key corresponding to the first biometric information. For example, the first decryption key may be a value generated by using basic first biometric information stored in memory in advance.
In operation S6907, the device 2007 may transmit the first decryption key to the server 200.
Meanwhile, in operation S6908, in order to decrypt the encrypted content, the server 200 may send a request for the second decryption key to the device 2008. In operation S6909, the device 2008 can obtain the second biometric information of the second user. According to an exemplary embodiment, the device 2008 can obtain the second biometric information from the biometric technology module installed in the device 2008.
In operation S6910, the device 2008 may perform user authentication by using the second biometric information.
In operation S6911, when the user authentication has been successful, the device 2008 can obtain a second decryption key corresponding to the second biometric information. For example, the second decryption key may be a value generated by using basic second biometric information stored in memory in advance.
In operation S6912, the device 2008 may transmit the second decryption key to the server 200.
In operation S6913, the server 200 may generate a fourth decryption key by combining the first and second decryption keys. In operation S6914, the server 200 may decrypt the encrypted content encryption key by using the fourth decryption key. In operation S6915, the server 200 may decrypt the encrypted content by using the decrypted content encryption key.
FIG. 70 is a table for describing a decryption method according to another exemplary embodiment.
FIG. 70 is a table for describing a method of decrypting content after encrypting the content according to one or more exemplary embodiments described above with reference to FIG. 66 to FIG. 69.
The controller 130 can decrypt the content by using at least two fragments of the biometric information from the first user, the biometric information of the second user, and the biometric information of the third user.
In detail, when the user authentication has succeeded by using the biometric information of the first user, the controller 130 can generate the decryption key by using the basic biometric information of the first user stored in the memory in advance. (Key_1). In addition, when the user authentication has succeeded by using the biometric information of the second user, the controller 130 can generate the decryption key by using the basic biometric information of the second user pre-stored in the memory. (Key_2). Then, the controller 130 can generate a decryption key (Key_4') by combining Key_1 and Key_2.
In addition, when the user authentication has succeeded by using the third user's biometric information, the controller 130 can generate a decryption key by using the third user's basic biometric information pre-stored in the memory ( Key_3). Then, the controller 130 can generate a decryption key (Key_4") by combining Key_2 and Key_3.
In addition, the controller 130 can generate a decryption key (Key_4"') by combining Key_1 and Key_3.
The encrypted content encryption key (E[key_con]Key_4) can be decrypted by using Key_4', Key_4'' or Key_4'''. Here, "E[key_con]Key_4" indicates the content encryption key encrypted by using Key_4.
The encrypted content (E[content]Key_con) can be decrypted by using the decrypted content encryption key (key_con). Here, "E[content]Key_con" indicates the content encrypted by using the content encryption key.
FIG. 71 is a flowchart of a method for setting content preservation according to another exemplary embodiment.
In operation S7101, the controller 130 of the device 100 may obtain the user's first biometric information.
In operation S7102, the controller 130 may generate a first security key by using the first biometric information.
The first security key may be a key generated by using the characteristic information of the first biometric information, and may be a password or an encryption key.
The password or the encryption key may be a value generated by using at least a part of the characteristic information of the biometric information as a factor of a specific function.
The details about the method of generating the password or the encryption key are not described, because the specific function is based on an exemplary embodiment of generating the password or the encryption key by using the characteristic information of the basic biometric information stored in advance as the factors of the specific function. The factor of can be replaced by the feature information of the biometric information obtained in operation S7101. At the same time, the feature information of the biometric information used in the method can be rougher than the feature information of the basic biometric information. For example, when the biometric information is a fingerprint, the interval for extracting the feature points of the fingerprint obtained by the feature information extractor 133 may be wider than the interval for extracting the feature points of the basic biometric information.
Therefore, even when the basic biometric information is not used, the security key generated by using the biometric information obtained when the security is set and the security key generated by using the biometric information obtained when the security is removed It is also very possible to match each other. When the interval for extracting the feature points of the fingerprint obtained by the feature information extractor 133 increases, the probability that the values of the security keys match each other can increase. The interval for extracting feature points can be preset by the manufacturer of the device 100, the provider of the application installed in the device 100, or the provider of the operating system installed in the device 100. Alternatively, the interval may be assigned by the user via the UI. At the same time, the user can assign an interval for each of the multiple pieces of biometric information.
In operation S7103, the controller 130 may set content security by using the first security key. For example, when the first security key is a password, the first security key can be used to restrict access to the content. Alternatively, when the first security key is an encryption key, the first security key may be used to encrypt content.
In operation S7104, the controller 130 can obtain the user's second biometric information as another piece of biometric information.
In operation S7105, the controller 140 may generate a second security key by using the second biometric information.
The second security key may be a key generated by using the characteristic information of the second biometric information, and may be a password or an encryption key. Since the method of generating the password or encryption key has been described above with reference to operation S7102, the details of the method will not be repeated.
Then, in operation S7106, the controller 130 may set the security of the first security key by using the second security key. For example, when the second security key is a password, the second security key can be used to restrict access to the first security key. Alternatively, when the second security key is an encryption key, the second security key can be used to encrypt the first security key.
FIG. 72 is a flowchart of a method for removing content preservation according to another exemplary embodiment.
In operation S7201, the controller 130 of the device 100 may obtain the second biometric information of the user.
In operation S7202, the controller 130 may generate a second security key by using the second biometric information. The second security key may be a key generated by using the characteristic information of the second biometric information, and may be a password or an encryption key.
In operation S7203, the controller 130 may remove the security of the first security key by using the second security key. For example, when the second security key is a password, the second security key can be used to remove the restriction on access to the first security key. Alternatively, when the second security key is a decryption key, the second security key can be used to decrypt the first security key.
In operation S7204, the controller 130 may remove the content security by using the first security key. For example, when the first security key is a password, the first security key can be used to remove restrictions on access to content. Alternatively, when the first security key is a decryption key, the first security key can be used to decrypt the content.
FIGS. 73 to 78 are diagrams for describing an example of user input for executing content according to an exemplary embodiment.
According to an exemplary embodiment, when content is set to be secured based on the user's first biometric information, the controller 130 of the device 100 can obtain the user's 2. The biometric information (its type is different from the first biometric information), and the security is removed based on the second biometric information.
According to an exemplary embodiment, the user input for executing the content may be at least one of the user input received during the process from the screen change until the content is executed.
For example, referring to FIG. 73, the controller 130 may receive a user input to activate the display unit 121. For example, the controller 130 may receive a user input of selecting a button 7301 installed on one side of the device 100 by a finger f73. Here, the activation of the display unit 121 means that the closed state of the display unit 121 becomes the open state or the display unit 121 is no longer in the black screen.
When the user input for activating the display unit 121 is received, the controller 130 may display on the display unit 121 a notification screen for requesting the user to input the second biometric information for removing the security. Then, according to the signal for inputting the second biometric information, the controller 130 can receive the second biometric information from a biometric technology module installed in the device 100 or from an external device via the communication unit 150. When the second biometric information is obtained through the biometric technology module or the communication unit 150, the controller 130 may remove the security of the content based on the second biometric information.
Alternatively, when the user input is received, the controller 130 may display a lock screen 7401 on the display unit 121, as shown in FIG. 74. The lock screen 7401 can be a screen that requests the user to enter a pattern or password to remove the locked screen, requests input from the user (such as a drag gesture) to enter the main screen, or requests the user to enter biometric information to remove content Security screen.
When the lock screen 7401 is displayed on the display unit 121, the controller 130 may receive a user input for removing the lock screen 7401.
When the lock screen 7401 is a screen that requests the user to input the second biometric information to remove the security of the content, and the signal for inputting the second biometric information is input, the controller 130 can be set in the device 100. The biometric technology module may receive the second biometric information from an external device via the communication unit 150. After obtaining the second biometric information, the controller 130 may remove the security of the content based on the second biometric information.
At the same time, when the lock screen 7401 is a screen requesting the user to input a pattern or password, and the user input of the pattern or password input by the finger f74 is received, the controller 130 may display the main screen 7501 on the display unit 121, as shown in FIG. As shown in 75.
When the main screen 7501 is displayed on the display unit 121, the controller 130 may receive a user input of identification (ID) information 7501-1 for selecting an application program for executing the content by a finger f75. The application used to execute the content can be a gallery application, a video reproduction application, an image editing application, a search application, or any other type of application as necessary.
After receiving the user input for selecting the ID information 7501-1, the controller 130 may display on the display unit 121 a notification screen requesting the user to input the second biometric information to remove the security of the content. According to the signal used to input the user's biometric information, the controller 130 can obtain the second biometric information from the biometric technology module provided in the device 100. Alternatively, the controller 130 may receive the second biometric information from an external device via the communication unit 150. After obtaining the second biometric information, the controller 130 may remove the security of the content based on the second biometric information.
Alternatively, when a user input to select the ID information 7501-1 is received, the controller 130 may display an application execution screen 7601 on the display unit 121, as shown in FIG. 76.
When the application execution screen 7601 is displayed, the controller 130 may receive a user input of selecting a group 7601-1 (such as a folder or a layer) containing content by the finger f76.
After receiving the user input of the selection group 7601-1, the controller 130 may display a notification screen requesting the user to input the second biometric information to remove the security of the content on the display unit 121. According to the signal used to input the second biometric information of the user, the controller 130 can obtain the second biometric information from the biometric technology module provided in the device 100. Alternatively, the controller 130 may receive the second biometric information from an external device via the communication unit 150. After obtaining the second biometric information, the controller 130 may remove the security of the content based on the second biometric information.
Alternatively, when the user input to select the group 7601-1 is received, the controller 130 may display a screen 7701 containing the ID information 7701-1 on the display unit 121, as shown in FIG. 77. The ID information 7701-1 may include, for example, the file name of the content or a representative image of the content.
When the screen 7701 containing the ID information 7701-1 is displayed on the display unit 121, the controller 130 may receive the user input of selecting the ID information 7701-1 by the finger f77.
After receiving the user input for selecting the ID information 7701-1, the controller 130 may display on the display unit 121 a notification screen requesting the user to input the second biometric information for removing the security of the content. According to the signal used to input the second biometric information of the user, the controller 130 can obtain the second biometric information from the biometric technology module provided in the device 100. Alternatively, the controller 130 may receive the second biometric information from an external device via the communication unit 150. After obtaining the second biometric information, the controller 130 may remove the security of the content based on the second biometric information.
Alternatively, when a user input to select the ID information 7701-1 is received, the controller 130 may display the content 7801 on the display unit 121, as shown in FIG. 78.
FIG. 79 is a diagram for describing an example in which the device 100 logs in to the server 200 according to an exemplary embodiment.
Referring to FIG. 79, the device 100 (for example, a smart phone) can log in to the server 200. Here, when the device 100 logs in to the server 200, the device 100 may be able to receive information in a specific area (for example, a physical or logical space that provides the content of a specific website or a specific service) set by the server 200.
For example, the user can input login information through the device 100 to access a specific area of the server 200. The device 100 can transmit the login information to the server 200. When the user authentication has succeeded by using the login information, the device 100 can log in to the server 200.
According to an exemplary embodiment, the user can use biometric information as login information. Multiple pieces of biometric information can be used as login information. For example, the user can log in to the server 200 based on the first biometric information or the second biometric information. Alternatively, the user may log in to the server 200 based on both the first and second biometric information.
In detail, the controller 130 can obtain the fingerprint information 70 from the watch-type wearable device 701 as the first biometric information. When the user authentication has succeeded by using the first biometric information, the controller 130 can obtain the first password corresponding to the first biometric information.
The password corresponding to the biometric information may be a value obtained by the controller 130 from a plurality of values stored in the memory 170 in advance. Alternatively, the password corresponding to the biometric information may be a value randomly generated by the controller 130. Alternatively, the password corresponding to the biometric information may be a value generated by the controller 130 by using basic biometric information corresponding to the biometric information stored in the memory 170 in advance. For example, the password corresponding to the biometric information can be obtained by using at least a part of the characteristic information of the basic biometric information as a specific function (for example, a one-way hash function, such as secure hash algorithm-1 (SHA-1), SHA-256 or SHA-512). The password corresponding to the biometric information can be generated after the user authentication is successful or before the user authentication is performed. For example, in the registration mode 201 for registering biometric information, when the feature information of the basic biometric information is stored in the memory 170, it can be generated and stored in advance by using the feature information of the basic biometric information The password corresponding to the biometric information.
The password corresponding to the biometric information can be stored in the memory 170, an external server, a wearable device, or a third device.
Then, the device 100 may transmit the first password to the server 200. When the user authentication has succeeded by using the first password, the device 100 can receive the login acceptance information from the server 200 and log in to the server 200.
In addition, the controller 130 can obtain the iris information 72 from the glasses-type wearable device 702 as the second biometric information. When the user authentication has succeeded by using the second biometric information, the controller 130 can obtain a second password corresponding to the second biometric information. Since the method of obtaining the password corresponding to the biometric information by the controller 130 has been described above, the details of the method will not be provided.
Then, the device 100 may transmit the second password to the server 200. When the user authentication has succeeded by using the second password, the device 100 can receive the login acceptance information from the server 200 and log in to the server 200.
A method of logging in to the server according to an exemplary embodiment will now be described in detail with reference to FIGS. 80 to 97.
FIG. 80 is a flowchart of a method for registering biometric information in the server 200 by the device 100 according to an exemplary embodiment.
Referring to FIG. 80, in operation S8001, the device 100 may obtain the user's first biometric information (for example, fingerprint information).
For example, the controller 130 of the device 100 can obtain the first biometric information from the biometric technology module included in the device 100. As another example, the device 100 may obtain the first biometric information from an external device.
In operation S8002, the device 100 may obtain a first password corresponding to the first biometric information based on the first biometric information.
For example, when the user has successfully authenticated by using the first biometric information, the controller 130 can obtain the first password corresponding to the first biometric information. Since the method of obtaining the password corresponding to the biometric information by the controller 130 has been described above, the details of the method will not be provided.
In operation S8003, the device 100 may transmit the first password to the server 200. The device 100 can transmit the ID information of the device 100 or the user together with the first password, or before or after the first password is transmitted. The ID information of the device 100 may be a serial number or a media access control (MAC) address of the device 100. In addition, the user's ID information can be a login ID, email address, or user-specific management number.
In operation S8004, the server 200 may store the first password after mapping the first password to the ID information of the device 100 or the user. At the same time, the server 200 can obtain ID information from the third server. For example, when the first password includes the user's biometric information, the server 100 may transmit the first password to a third certificate authority that manages the biometric information, and obtain the user ID from the third certificate authority News.
In operation S8005, the device 100 may obtain the user's second biometric information (for example, iris information).
In operation S8006, the device 100 may obtain a second password corresponding to the second biometric information based on the second biometric information.
For example, when the user has successfully authenticated by using the second biometric information, the controller 130 of the device 100 can obtain the second password corresponding to the second biometric information.
In operation S8007, the device 100 may transmit the second password to the server 200. The device 100 can transmit the ID information of the device 100 or the user together with the second password, or before or after the second password is transmitted.
In operation S8008, the server 200 may store the second password after mapping the second password to the ID information of the device 100 or the user. At the same time, the server 200 can obtain ID information from the third server.
According to an exemplary embodiment, the first password mapped to the ID information of the device 100 or the user may be stored in the server 200 in advance. The server 200 may store the first and second passwords after mapping the first and second passwords to the ID information of the device 100 or the user.
FIG. 81 is a flowchart of a method for registering biometric information in the server 200 by the device 100 according to another exemplary embodiment.
Referring to FIG. 81, in operation S8101, the device 100 may obtain first biometric information (for example, fingerprint information) and second biometric information (for example, iris information) of the user.
In operation S8102, the device 100 may obtain the first and second passwords based on the first and second biometric information, respectively. Since the method of obtaining the first and second passwords has been described above with reference to FIG. 80, the details of the method are not provided.
In operation S8103, the device 100 may transmit the first and second passwords to the server 200. The device 100 can transmit the ID information of the device 100 or the user together with the first and second passwords, or before or after the first and second passwords are transmitted.
In operation S8104, the server 200 may store the first and second passwords after mapping the first and second passwords to the ID information of the device 100 or the user. Alternatively, the server 200 may obtain ID information from a third server, and map and store the first and second passwords and ID information.
FIGS. 82 to 85 are diagrams for describing an example of a UI provided to register biometric information in the server 200 according to an exemplary embodiment.
As shown in FIG. 82, when a user logs in to the server 200 to receive a specific service, the controller 130 may display a screen 8201 on the display unit 121 requesting the user to register as a member first. The controller 130 may display a notification screen 8202 on the display unit 121 asking the user whether to use the biometric information for login. Then, the controller 130 may receive the accept button 8202-1 on the selection notification screen 8202 for user input using biometric information. However, if the user selects the reject button 8202-2 on the notification screen 8202, the controller 130 may display a screen requesting the user to input text for setting a password on the display unit 121.
In response to the user input of selecting the accept button 8202-1, the controller 130 may obtain the fingerprint information 70 from the watch-type wearable device 701 as the first biometric information, as shown in FIG. 83. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
The controller 130 may transmit the first password obtained based on the first biometric information to the server 200. When the first password is stored in the server 200 after being mapped to the ID information, the controller 130 may display a notification screen 8301 informing the user that the first biometric information has been registered in the server 200 on the display unit 121.
According to an exemplary embodiment, as shown in FIG. 84, the controller 130 may display a notification screen 8401 on the controller 130 asking the user whether to additionally register biometric information for login. Then, the controller 130 may receive the user input of selecting the accept button 8401-1 on the notification screen 8401 to additionally register the biometric information. However, if the user selects the rejection button 8401-2 on the notification screen 8401, the controller 130 may end the registration of the logged-in biometric information, and display the next screen for member registration on the display unit 121.
In response to the user input of selecting the accept button 8401-1, the controller 130 may obtain the iris information 72 from the glasses-type wearable device 702 as the second biometric information, as shown in FIG. 85. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
Then, the controller 130 may display a notification screen 8501 informing the user that the second biometric information has been registered in the server 200 on the display unit 121.
86A and 86B are flowcharts of a method for logging in to the server 200 by the device 100 according to an exemplary embodiment.
Referring to FIG. 86A, in operation S8601, the server 200 may store the first and second passwords corresponding to the ID information of the device 100 or the user.
In this case, in operation S8602, the device 100 may display a login screen for accessing a specific service provided by the server 200.
In operation S8603, the device 100 can obtain the user's first biometric information. For example, the device 100 may provide a guide screen requesting the user to input the first biometric information, and obtain the first biometric information according to the user's consent. Alternatively, the device 100 may automatically obtain the first biometric information when the login screen is displayed.
In operation S8604, the device 100 may obtain a first password corresponding to the first biometric information based on the first biometric information.
For example, when the user has successfully authenticated by using the first biometric information, the device 100 can obtain the first password corresponding to the first biometric information. The user authentication can be performed by matching the feature information of the first biometric information with the feature information of the basic first biometric information stored in the memory 170 in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has been successful. When the first biometric information has been registered in the server 200, it corresponds to the first The first password of the biometric information can be obtained by the controller 130 corresponding to the first biometric information. The controller 130 can obtain the first password corresponding to the first biometric information from the memory 170, an external server, a wearable device, or a third device.
In operation S8605, the device 100 may transmit the first password corresponding to the first biometric information to the server 200. The device 100 can transmit the first password together with the ID information of the device 100 or the user, or before or after the first password is transmitted.
In operation S8606, the server 200 may determine whether the received first password matches the stored first password. In detail, the server 200 can obtain the stored first password corresponding to the first biometric information (which is mapped to the received ID information), and determine whether the received first password and the stored first password match each other.
When the received first password and the stored first password match each other, the server 200 may transmit the login acceptance information to the device 100 in operation S8607.
After receiving the login acceptance information, in operation S8608, the device 100 can access the specific service provided by the server 200. In other words, the device 100 and the server 200 can be connected to each other for transmitting and receiving content related to a specific service.
Referring to FIG. 86B, in operation S8609, the connection between the device 100 and the server 200 for transmitting and receiving content related to a specific service can be removed. For example, the connection may be released in response to a user input to remove login (ie, log out) via the device 100.
In operation S8610, after the connection is removed, the device 100 may display a login screen for accessing a specific service provided by the server 200 in response to a user input for logging in to the server 200 again.
In operation S8611, the device 100 may obtain second biometric information of a type different from the first biometric information obtained in operation S8603. For example, the device 100 may provide guidance information for requesting the user to select one of the first biometric information and the second biometric information, and may obtain the second biometric information based on the user input for selecting the second biometric information News. Alternatively, the device 100 may automatically obtain the second biometric information when the login screen is displayed.
In operation S8612, the device 100 may obtain a second password corresponding to the second biometric information based on the second biometric information. Since the method of obtaining the first and second passwords has been described above with reference to FIG. 79, the details of the method are not provided.
In operation S8613, the device 100 may transmit the second password corresponding to the second biometric information to the server 200. The device 100 can transmit the second password together with the ID information of the device 100 or the user, or before or after the second password is transmitted.
In operation S8614, the server 200 may determine whether the received second password and the stored second password match each other. In detail, the server 200 can obtain the stored second password corresponding to the second biometric information (which is mapped to the received ID information), and determine whether the received second password and the stored second password match each other.
When the received second password and the stored second password match each other, the server 200 may transmit the login acceptance information to the device 100 in operation S8615.
After receiving the login acceptance information, in operation S8616, the device 100 can access the specific service provided by the server 200. In other words, the device 100 and the server 200 can be reconnected to each other for transmitting and receiving content related to a specific service.
FIGS. 87 to 88B are diagrams for describing an example of a UI provided for the device 100 to log in to the server 200 according to an exemplary embodiment.
As shown at S8710 in FIG. 87, the controller 130 may display a login screen 8701 for accessing a specific service provided by the server 200 on the display unit 121. The controller 130 may display a notification screen 8702 on the display unit 121 asking the user whether to log in to the server 200 by using biometric information. The controller 130 may receive the user input of the accept button 8702-1 that agrees to use the biometric information for login by selecting the acceptance button 8702-1 on the notification screen 8702 with the finger f87. However, if the user selects the reject button 8702-2 on the notification screen 8702, the controller 130 may display on the display unit 121 a screen requesting the user to input a password for login.
In response to the user input of selecting the accept button 8701-1, the controller 130 may display a notification screen 8702 for selecting biometric information on the display unit 121, as shown in S8720 in FIG. 87. When the first biometric information (for example, fingerprint information) and the second biometric information (for example, iris information) exist as the biometric information for login, the controller 130 may receive the first biometric information selected by the finger f88 User input for information.
In response to the user input of selecting the first biometric information, the controller 130 may obtain the fingerprint information 70 from the watch-type wearable device 701 as the first biometric information, as shown in FIG. 88A. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
The controller 130 may obtain a first password corresponding to the first biometric information based on the first biometric information. For example, when the user has successfully authenticated by using the first biometric information, the controller 130 can obtain the first password corresponding to the first biometric information.
The controller 130 may transmit the first password to the server 200. After receiving the login acceptance information, the controller 130 may display on the display unit 121 a notification screen 8801 notifying the user that the server 200 has logged in by using the biometric information.
Meanwhile, in S8720 in FIG. 87, the controller 130 may receive a user input for selecting the second biometric information (for example, iris information).
In this case, as shown in FIG. 88B, the controller 130 may obtain the iris information 72 from the glasses-type wearable device 702 as the second biometric information. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
The controller 130 may obtain a second password corresponding to the second biometric information based on the second biometric information. For example, when the user has successfully authenticated by using the second biometric information, the controller 130 can obtain the second password corresponding to the second biometric information. The controller 130 may transmit the second password to the server 200. After receiving the login acceptance information, the controller 130 may display on the display unit 121 a notification screen 8802 notifying the user that the server 200 has logged in by using the biometric information.
FIG. 89 is a flowchart of a method for registering biometric information in the server 200 by the device 100 according to another exemplary embodiment.
Referring to FIG. 89, in operation S8901, the server 200 may store the ID information of the user who logs in to the device 100 and the password mapped to the ID information.
In operation S8902, the device 100 may receive the common password from the user via the biometric information management application to log in to the server 200. The common password may be a password generally used to log in to the server 200 regardless of the type of biometric information.
The device 100 can receive the ID information of the user or the device 100 together with the common password. Alternatively, the ID information of the user or device may be received before or after the common password is received.
In operation S8903, the device 100 may store the common password. When the controller 130 receives the ID information of the user or the device 100, the controller 130 may store the common password after mapping the common password to the ID information of the user or the device 100.
In operation S8904, the device 100 may obtain the first biometric information (for example, fingerprint information) and the second biometric information (for example, iris information) of the user.
In operation S8905, when the user has successfully authenticated by using the first biometric information, the device 100 may<u style="single">register</u>The first biometric information uses a common password. In addition, in operation S8906, when the user has successfully authenticated by using the second biometric information, the device 100 can<u style="single">register</u>The second biometric information uses a common password. The user authentication can be performed by matching the characteristic information of the obtained biometric information with the characteristic information of the basic biometric information stored in advance. When the matching score calculated as the matching result is equal to or higher than the specific threshold, the controller 130 may determine that the user authentication has succeeded.
According to an exemplary embodiment, the controller 130 may<u style="single">register</u>Information about biometric information using a common password. For example, the controller 130<u style="single">register</u>The first and second biometric information using a common password may mean that the biometric information using the common password is the first and second biometric information.
90 to 94 are diagrams for describing examples of UIs provided to register biometric information in the server 200 according to other exemplary embodiments.
As shown in S9010 in FIG. 90, the controller 130 may display a notification screen 9001 on the display unit 121 that asks the user whether to log in to a specific service (for example, a specific website) provided by the server 200 using biometric information. Then, the controller 130 may receive the user input of using the biometric information by selecting the accept button 9001-1 on the notification screen 9001 with the finger f90.
In response to the user input of selecting the accept button 9001-1, the controller 130 may display a screen 9002 on the display unit 121 requesting the user to input a common password for logging in to the server 200, as shown in S9020. When the common password is input by the user, the controller 130 may store the common password.
Then, as shown in FIG. 91, the controller 103 may display on the display unit 121 to ask the user whether<u style="single">register</u>The biometric information is used for the login notification screen 9101. Then, the controller 130 may receive the user input of registering the biometric information by selecting the accept button 9101-1 on the notification screen 9101 by the finger f91.
In response to the user input of selecting the accept button 9101-1, the controller 130 may obtain the fingerprint information 70 from the watch-type wearable device 701 as the first biometric information, as shown in FIG. 92. Alternatively, the controller 130 may receive the first biometric information from a biometric technology module provided in the device 100.
When the user authentication has succeeded by using the first biometric information, the controller 130 may<u style="single">register</u>The first biometric information uses a common password. The controller 130 may display a notification screen 9201 on the display unit 121 indicating that the first biometric information is registered to use the common password.
Next, as shown in FIG. 93, the controller 130 may display a notification screen 9301 on the display unit 121 that asks the user whether to additionally register biometric information for login. Then, the controller 130 may receive the user input of selecting the accept button 9301-1 on the notification screen 9301 by the finger f93 to additionally register the biometric information. At the same time, if the user selects the reject button 9301-2 on the notification screen 9301, the controller 130 may end the additional registration of the biometric information for login.
In response to the user input of selecting the accept button 9301-1, the controller 130 may obtain the iris information 72 from the glasses-type wearable device 702 as the second biometric information, as shown in FIG. 94. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
When the user authentication has succeeded by using the second biometric information, the controller 130 may<u style="single">register</u>The second biometric information uses a common password. The controller 130 may display a notification screen 9401 on the display unit 121 indicating that the second biometric information is registered to use the common password.
95A and 95B are flowcharts of a method for accessing the server 200 by the device 100 according to an exemplary embodiment.
Referring to FIG. 95A, in operation S9501, the device 100 may store the common password required to log in to the server 200 and information about the biometric information using the common password.
In addition, in operation S9502, the server 200 may store the ID information of the user or the device 100 and the password mapped to the ID information.
In operation S9503, the device 100 may display a login screen for accessing a specific service provided by the server 200.
In operation S9504, the device 100 can obtain the user's first biometric information. For example, the device 100 may provide a notification screen asking the user whether to use the biometric information to access the server 200 through a biometric information management application, and obtain the first biometric information according to the user's consent. Alternatively, the device 100 may automatically obtain the first biometric information from the user when the login screen is displayed.
In operation S9505, the device 100 may determine whether the first biometric information is registered to use the common password based on the first biometric information. For example, when the user authentication has succeeded by using the first biometric information, the device 100 can determine whether the first biometric information is registered as biometric information for using a common password. The user authentication can be performed by matching the obtained feature information of the first biometric information with the feature information of the basic first biometric information stored in advance.
When it is determined that the first biometric information is registered to use the common password, the device 100 may transmit the ID information of the user or the device 100 and the common password to the server 200 in operation S9506. Alternatively, the ID information of the user or the device 100 may be received before or after the common password is transmitted.
In operation S9507, the server 200 may determine whether the received ID information of the user or device 100 and the received common password match the stored ID information of the user or device 100 and the stored password. When the received ID information of the user or device 100 and the received common password match the stored ID information of the user or device 100 and the stored password, in operation S9508, the server 200 may transmit the login acceptance information to the device 100 .
After receiving the login acceptance information, in operation S9509, the device 100 can access the specific service provided by the server 200. In other words, the device 100 and the server 200 can be connected to each other for transmitting and receiving content related to a specific service.
Referring to FIG. 95B, in operation S9510, the connection between the device 100 and the server 200 for transmitting and receiving content related to a specific service can be removed. For example, the connection can be removed via the device 100 in response to a user input to remove login (ie, log out).
In operation S9511, after the connection is removed, in response to a user input for re-logging in to the server 200, the device 100 may display a login for accessing a specific service provided by the server 200 on the display unit 121 Picture.
In operation S9512, the device 100 may obtain the user's second biometric information, the type of which is different from the first biometric information obtained in operation S9504. For example, the device 100 may provide guidance information for requesting the user to select one of the first biometric information and the second biometric information, and obtain the second biometric information according to the user input for selecting the second biometric information . Alternatively, the device 100 may automatically obtain the second biometric information from the user when the login screen is displayed.
In operation S9513, the device 100 may determine whether the second biometric information is registered to use the common password based on the second biometric information. For example, when the user has successfully authenticated by using the second biometric information, the device 100 can determine whether the second biometric information is registered as biometric information for using a common password. The user authentication can be performed by matching the obtained feature information of the second biometric information with the feature information of the basic second biometric information stored in advance.
When it is determined that the second biometric information is registered to use the common password, the device 100 may transmit the ID information of the user or the device 100 and the common password to the server 200 in operation S9514.
In operation S9515, the server 200 may determine whether the received ID information of the user or device 100 and the received common password match the stored ID information of the user or device 100 and the stored password. When the received ID information of the user or device 100 and the received common password match the stored ID information of the user or device 100 and the stored password, in operation S9516, the server 200 may transmit the login acceptance information to the device 100 .
After receiving the login acceptance information, in operation S9517, the device 100 can access the specific service provided by the server 200. In other words, the device 100 and the server 200 can be reconnected to each other for transmitting and receiving content related to a specific service.
FIGS. 96 to 97B are diagrams for describing examples of UIs provided for the device 100 to log in to the server 200 according to other exemplary embodiments.
As shown at S9610 in FIG. 96, the controller 130 may display a login screen 9601 for accessing a specific service provided by the server 200 on the display unit 121.
According to an exemplary embodiment, when the biometric information management application manages the common password used to log in to the server 200. The controller 130 may display a biometric information login button 9602 for logging in using biometric information on the display unit 121. The controller 130 may receive a user input of selecting the biometric information login button 9602.
As shown in S9620, in response to the user input, the controller 130 displays a notification screen 9603 for selecting biometric information on the display unit 121. When there are first biometric information (for example, fingerprint information) and second biometric information (for example, iris information) as the biometric information for login, the controller 130 may receive the user who selects the first biometric information enter.
In response to the user input of selecting the first biometric information, the controller 130 may obtain the fingerprint information 71 from the watch-type wearable device 701 as the first biometric information, as shown in FIG. 97A. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
The controller 130 may obtain the common password based on the first biometric information. For example, when the user has successfully authenticated by using the first biometric information, the controller 130 can obtain the first password corresponding to the first biometric information through the biometric information management application.
Then, the controller 130 may transmit the first password to the server 200. After receiving the login acceptance information, the controller 130 may display a notification screen 9701 on the display unit 121 indicating that the server 200 has logged in by using the biometric information.
Alternatively, in S9620 in FIG. 96, the controller 130 may receive a user input for selecting the second biometric information. According to an exemplary embodiment, as shown in FIG. 97B, the controller 130 may obtain the iris information 72 from the glasses-type wearable device 702 as the second biometric information. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100.
The controller 130 may obtain the common password based on the second biometric information. For example, when the user has successfully authenticated by using the second biometric information, the controller 130 can obtain the common password through the biometric information management application. In addition, the controller 130 may transmit the common password to the server 200. After receiving the login acceptance information, the controller 130 may display a notification screen 9702 on the display unit 121 indicating that the server 200 has logged in by using the biometric information.
The one or more exemplary embodiments described above are only examples and therefore are not limited thereto. In addition, the order of operations of the methods described above is not limited, and according to one or more exemplary embodiments, at least one operation may be omitted, operations may be added to the method, or the order may be changed.
According to an exemplary embodiment, data transmission between the transmitter and the receiver (eg, content transmission, biometric information transmission, encryption key transmission, and decryption key transmission) can be performed by using a secure channel. The secure channel means a channel with high security regarding the communication content between the transmitter and the receiver. For example, the secure channel may be a protocol such as https.
In addition, the one or more exemplary embodiments described above are not limitedly applied to content, but can also be applied to the file name of the content, the reference information of the content, the segment group of the content, the reference information of the group, or the application Program.
For example, the controller 130 of the device 100 may use the first biometric information to set the security of a group containing multiple fragments of content. The security is to set the group by setting the security of the group or by setting the security of the content of each segment included in the group. According to an exemplary embodiment, the controller 130 may remove the security of the group by using the second biometric information.
As another example, the controller 130 can set application security by using the first biometric information. The security of the application is set by setting the security of the application ID, application reference information, or application execution file. According to an exemplary embodiment, the controller 130 can remove the security of the application by using the second biometric information.
In addition, one or more exemplary embodiments may be applied to a lock screen that restricts access to the main screen.
FIG. 98 illustrates an example provided to set the security of the lock screen according to an exemplary embodiment.
As shown in FIG. 98, the controller 130 of the device 100 may display a lock screen setting screen 9801 for restricting access to the home screen on the display unit 121. The lock screen setting screen 9801 may include an item 9801-1 for setting security based on the first biometric information (ie, fingerprint information) and an item 9801-1 for setting security based on the second biometric information (ie, iris information) Project 9802-2.
According to an exemplary embodiment, when the user input of the selection item 9801-1 is received, the controller 130 may obtain the first biometric information. The user authentication can be performed by matching the obtained feature information of the first biometric information with the feature information of the basic first biometric information stored in advance. When the user authentication is successful, the controller 130 can set a lock screen for restricting access to the home screen by using the first biometric information.
According to another exemplary embodiment, when the user input of the selection item 9801-2 is received, the controller 130 may obtain the second biometric information. The user authentication can be performed by matching the obtained feature information of the second biometric information with the feature information of the basic second biometric information stored in advance. When the user authentication is successful, the controller 130 can set a lock screen for restricting access to the main screen by using the second biometric information.
FIGS. 99 to 100B are diagrams for describing an example of a UI provided to remove the security of the lock screen according to an exemplary embodiment.
According to an exemplary embodiment, the controller 130 of the device 100 may receive a user input to activate the display unit 121.
After receiving the user input, the controller 130 may display a notification screen 9902 requesting the user to select biometric information to remove the lock screen 9901 on the display unit 121, as shown in FIG. 99. When there are first biometric information (for example, fingerprint information) and second biometric information (for example, iris information) for removing the lock screen 9901, the controller 130 may receive the first biometric information selected by the finger f99 User input.
In response to the user input of selecting the first biometric information, the controller 130 may obtain the fingerprint information 90 from the first external device 911 as the first biometric information, as shown in FIG. 100A. Alternatively, the controller 130 may obtain the first biometric information from a biometric technology module provided in the device 100.
The controller 130 may display the main screen 10001 based on the first biometric information. For example, the controller 130 may display the main screen 10001 on the display unit 121 after removing the lock screen when the user has successfully authenticated by using the first biometric information.
Alternatively, in FIG. 99, the controller 130 may receive a user input for selecting the second biometric information.
According to an exemplary embodiment, the controller 130 may receive the iris information 92 from the second external device 912 as the second biometric information, as shown in FIG. 100B. Alternatively, the controller 130 may obtain the second biometric information from a biometric technology module provided in the device 100. The controller 130 may display the main screen 10001 on the display unit 121 based on the second biometric information. For example, when the user has successfully authenticated by using the second biometric information, the controller 130 can remove the lock screen and display the main screen 10001 on the display unit 121.
FIG. 101 and FIG. 102 are block diagrams of an apparatus 100 according to an exemplary embodiment.
As shown in FIG. 101, the device 100 according to an exemplary embodiment may include a controller 130, a communicator 150, and a memory 170. However, not all illustrated components are essential. The device 100 may include more or fewer components than those shown in FIG. 101.
For example, as shown in FIG. 102, the device 100 according to an exemplary embodiment may further include a user input 110, an output 120, an AV input 160, and a memory 170, as well as a display 121, a sensor 140, and a communicationDevice150 and controller 130.
The components of the device 100 will now be described in detail.
The user input 110 is used by the user to input data for controlling the device 100. Examples of user input 110 include keypads, hemispherical switches, touch pads (touch capacitive type, pressure resistance film type, infrared light detection type, surface ultrasonic conduction type, overall tensile force measurement type, or piezoelectric effect type) ), jog wheel and jog switch, but not limited to this.
The user input 110 can be controlled by the controller 130 to receive user input. For example, the user input 110 may receive a user input for removing the lock on the device 100.
The output device 120 is controlled by the controller 130 to output audio signals, video signals, or vibration signals, and may include a display 121, an audio output 122, and a vibration motor 123.
The display 111 can be controlled by the controller 130 to display information processed by the device 100. The display unit 121 may display and change the UI for removing the lock of the device 100. In addition, the display 121 may display the home screen while removing the lock on the device 100.
At the same time, when the display 121 is configured as a touch screen by forming a layer structure with a touch pad, the display 121 can also be used as an input device and an output device. The display 121 may include at least one of the following: liquid crystal display (LCD), thin film transistor-liquid crystal display (TFT-LCD), organic light emitting diode (organic light-emitting diode; OLED), flexible displays, 3D displays, and electrophoretic displays. According to an exemplary embodiment of the device 100, the device 100 may include at least two displays 121. Here, at least two displays 121 may be arranged to face each other by using hinges.
The audio output unit 122 outputs audio data received from the communication unit 150 or stored in the memory 170. In addition, the sound output unit 122 outputs sound signals related to functions performed by the device 100, such as a call signal receiving sound, a message receiving sound, or an alarm sound. The sound output unit 122 may include a speaker or a buzzer.
The vibration motor 123 may output a vibration signal. For example, the vibration motor 123 may output a vibration signal corresponding to the output of audio data or video data, for example, call signal receiving sound or message receiving sound. In addition, the vibration motor 123 can output a vibration signal when the touch screen is touched.
The controller 130 generally controls the overall operation of the device 100. For example, the controller 130 can generally control the user input 110, the output 120, the sensor 140, the communicator 150, and the A/V input 160 by executing a program stored in the memory 170.
In detail, the controller 130 according to an exemplary embodiment can obtain the second biometric information of the user whose type is different from the first biometric information of the user according to the user input for executing the content, and is based on the second biometric information of the user. The identification information is used to remove the security set on the content by using the first biometric information.
In addition, when the security of the content will be removed based on the second biometric information, when the user authentication has succeeded by using the second biometric information, the controller 130 can use at least one of the password and the decryption key. One to remove the security.
The password can be a common password generally used for the first and second biometric information or a second password corresponding to the second biometric information, and when the security of the content is to be removed, the controller 130 can use the password To remove restrictions on access to content.
The decryption key can be a common decryption key usually used for the first biometric information and the second biometric information or a second decryption key corresponding to the second biometric information, and when the security of the content will be removed , The controller 130 can decrypt the encrypted content by using the decryption key.
When the decryption key is the second decryption key corresponding to the second biometric information, the controller 130 can decrypt the first encryption key corresponding to the first biometric information by using the second decryption key, and then The encrypted content is decrypted by using the first decryption key obtained by decrypting the first encryption key.
In addition, when the second biometric information is selected through the screen for selecting one of the first biometric information and the second biometric information, the controller 130 can obtain the second biometric information.
In addition, the controller 130 may obtain the second biometric information from at least one external device via the communication unit 150.
The device 100 according to an exemplary embodiment may further include at least one biometric technology module for recognizing the biometric information of the user, and the controller 130 may obtain a second biometric technology from the at least one biometric technology module News.
In addition, the controller 130 according to an exemplary embodiment may log in to the server 200 based on the user's first biometric information.
In addition, after the login to the server 200 is removed, the controller 130 can obtain the user's second biometric information (the type of which is different from the first biometric information).
In addition, the controller 130 can transmit the password related to the second biometric information to the server 200 via the communication unit 150.
In addition, when the user authentication has succeeded by using the password, the device 100 can log in to the server 200 again.
The sensor 140 can detect the state of the device 100 or the state around the device 100, and transmit the detected state to the controller 130. The sensor 140 may include a magnetic sensor 141, an acceleration sensor 142, a temperature/humidity sensor 143, an infrared sensor 144, a gyro sensor 145, such as a global positioning system (GPS) At least one of the position sensor 146, the atmosphere sensor 147, the proximity sensor 148, and the red-green-blue (RGB) sensor 149 such as an illuminance sensor, but included in the sensing unit 140 The components are not limited to this. Because a person with ordinary knowledge in the art can intuitively infer the function of each sensor based on the name of the sensor, the details of the sensor function are not described in this article.
In addition, the sensor 140 may include a sensor for detecting a touch input of an input tool and a sensor for detecting a touch input of a user. In this case, the sensor for detecting the user's touch input can be included in the touch screen or touch pad. In addition, the sensor for detecting the touch input of the input tool can be arranged under or in the touch screen or touch pad.
The communicator 150 may include at least one component that enables the device 100 to communicate with an external device or a server. For example, the communicator 150 may include a short-range wireless communicator 151, a mobile communicator 152, and a broadcast receiver 153.
The short-range wireless communicator 151 may include a Bluetooth communicator, a BLE communicator, an NFC communicator, a wireless local area network (WLAN) (Wi-Fi) communicator, a Zigbee communicator, and an infrared data association (infrared data association). association; IrDA) communicator, Wi-Fi direct (WFD) communicator, UWB communicator, and Ant+ communicator, but the components included in the short-range wireless communicator 141 are not limited thereto.
The mobile communicator 152 transmits wireless signals to at least one of a base station, an external terminal, and a server on the mobile communication network, and receives wireless signals from at least one of the base station, an external terminal, and the server. Here, the wireless signal may include data in various formats according to the transmission and reception of a voice call signal, a video phone call signal, or a text/multimedia message.
The broadcast receiver 153 receives broadcast signals and/or broadcast-related information from external sources via broadcast channels. Broadcast channels may include satellite channels or terrestrial broadcast channels. In some exemplary embodiments, the device 100 may not include the broadcast receiver 153.
The A/V input 160 is used to receive audio signals or video signals, and may include a camera 161 and a microphone 162. The camera 161 can obtain an image frame of a static image or a moving image through an image sensor in a video phone mode or a photography mode. The image captured by the image sensor can be processed by the controller 130 or a separate image processor (not shown).
The image frame processed by the camera 161 can be stored in the memory 170 or transmitted to an external device via the communicator 150. According to an exemplary embodiment of the device 100, the device 100 may include at least two cameras 161.
The microphone 162 receives external sound signals and processes the external sound signals into electric voice data. For example, the microphone 162 may receive sound signals from an external device or a reader. The microphone 162 can use any of various noise removal algorithms to remove noise generated when receiving external sound signals.
The memory 170 can store programs used for processing and control items of the controller 130, and can store input/output data.
The memory 170 may include at least storage media among the following: flash memory, hard disk, multimedia card micro memory, card type memory (for example, secure digital (SD) card or extreme digital ; XD card), random access memory (random access memory; RAM), static random access memory (SRAM), read-only memory (ROM), electronically erasable In addition to programmable read-only memory (electrically erasable programmable read-only memory; EEPROM), programmable read-only memory (programmable read-only memory; PROM), magnetic memory, magnetic disks and optical discs. In addition, the device 100 can operate a network storage server or a cloud server that performs the storage function of the memory 170 on the Internet.
The programs stored in the memory 170 can be classified into a plurality of modules based on functions, and can be classified into a UI module 171, a touch screen module 172, and a notification module 173.
According to an exemplary embodiment, the memory 170 may store the content that is set to be secured based on the user's first biometric information. In addition, the memory 170 may store a first encryption key encrypted by using a second encryption key generated based on the second biometric information.
In addition, the memory 170 can store templates for fingerprint information, voice information, facial information, iris information, palmprint information, vein information, retina information, movement pattern information, and ECG information, and the stored templates can be used as basic biometrics. The characteristic information of the information.
In addition, the memory 170 can store the feature information extracted by the feature information extractor 133 according to the control items of the controller 130, and the stored feature information can be used as the feature information of the basic biometric information for user authentication .
The UI module 171 can provide a specialized UI or GUI connected to the device 100 according to the application. The touch screen module 172 can detect the touch gesture of the user on the touch screen, and transmit information about the touch gesture to the controller. The touch screen module 172 according to an exemplary embodiment can recognize and analyze touch codes. The touch screen module 172 can be configured as a separate hardware including a controller.
Various sensors can be placed inside or around the touch screen to detect touches or proximity touches on the touch screen. Examples of sensors for detecting touches on the touch screen include tactile sensors. The tactile sensor detects contact that can be felt by a person on a specific object. The tactile sensor can detect various types of information, such as the roughness of the contact surface, the stiffness of the contact object, and the temperature of the touch point.
Another example of a sensor for detecting a touch on the touch screen includes a proximity sensor. The proximity sensor uses electromagnetic field force or infrared rays to detect the presence of an object approaching or near the predetermined detection surface without detecting mechanical contact. Examples of proximity sensors include transmission photoelectric sensors, direct reflection photoelectric sensors, specular reflection photoelectric sensors, high frequency oscillation proximity sensors, capacitive proximity sensors, magnetic proximity sensors, and infrared rays Proximity sensor. Examples of the user's touch gestures include clicking, touching and holding, double-clicking, dragging, horizontal movement, tapping, dragging and dropping, and swiping.
The notification module 173 can generate a signal for notifying the occurrence of an event in the device 100. Examples of events that occur in the device 100 include call signal reception, message reception, key signal input, and schedule notification. The notification module 173 can output the notification signal in a video signal format via the display 121, in an audio signal format via the sound output unit 122, or in a vibration signal format via the vibration motor 123.
FIG. 103 is a block diagram of the server 200 according to an exemplary embodiment.
As shown in FIG. 103, the server 200 according to an exemplary embodiment may include a controller 901, a communicator 903, and a database (DB) 905. The DB 905 may include a content DB 907 and a key DB 909. However, not all illustrated components are essential. The server 200 may include more or fewer components than those shown in FIG. 103.
The controller 901 generally controls the overall operation of the server 200.
In detail, the controller 901 may store the encrypted encryption key in the key DB 909. The controller 901 can store the encrypted content in the content DB 907.
The controller 901 can generate an encryption key based on the user's biometric information. In addition, the controller 901 can generate a decryption key based on the user's biometric information. In addition, the controller 901 can generate a decryption key by combining multiple decryption keys. In addition, the controller 901 can decrypt the encrypted content by using the decryption key.
The exemplary embodiments can also be implemented in the form of a computer-readable recording medium (such as a program module executed by a computer). The computer-readable recording medium may be any available medium that can be accessed by a computer, and examples of the computer-readable recording medium include all volatile and non-volatile media, and detachable and inseparable media. In addition, examples of computer-readable recording media may include computer storage media and communication media. Examples of computer storage media include all volatile and non-volatile media, as well as separable and inseparable media, which have been implemented by any method or technology to store computer-readable commands, data structures, program modules, and other Information about the data. Communication media usually include computer-readable commands, data structures, program modules, other data of modulated data signals, or another transmission mechanism, and examples of communication media include any information transmission media.
In addition, in this document, a "unit" may be a hardware component (such as a processor or a circuit) and/or a software component executed by a hardware component such as a processor.
Those having ordinary knowledge in the art will understand that various changes in form and details can be made to the present invention without departing from the spirit and scope of the present invention. Therefore, it will be understood that the above-described exemplary embodiments do not limit the scope of the present invention. For example, each component described in a single type can be executed in a distributed manner, and the components described in a distributed manner can also be executed in an integrated manner.
<p>10Fingerprint Information</p><p>12Iris Information</p><p>22Fingerprint Information</p><p>34Iris Information</p><p>36Sound information</p><p>38Facial Information</p><p>40Iris Information</p><p>42Iris Information</p><p>48Voice Information</p><p>51Image</p><p>51-1Image data</p><p>51-2Facial Information</p><p>52Facial Information</p><p>70Fingerprint Information</p><p>72Iris Information</p><p>90Fingerprint Information</p><p>92Iris Information</p><p>100Device/Controller</p><p>110User input</p><p>120Output device</p><p>121Display Unit/Display</p><p>122Sound output device</p><p>123Vibration motor</p><p>130Controller</p><p>131Biometric Information Obtainer</p><p>132Biometric Information Corrector</p><p>133Feature Information Extractor</p><p>134Feature Information Matcher</p><p>135Content Saver</p><p>135-1Content Access Limiter/Allower</p><p>135-2Content Encryptor/Decryptor</p><p>136Biometric Information Requester</p><p>140Sensing unit</p><p>141Magnetic sensor</p><p>142Acceleration Sensor</p><p>143Temperature/Humidity Sensor</p><p>144Infrared sensor</p><p>145Gyrograph sensor</p><p>146Position Sensor</p><p>147Atmospheric Sensor</p><p>148Proximity Sensor</p><p>149Red, Green and Blue (RGB) Sensor</p><p>150Communicator/Communication Unit</p><p>151Short-range wireless communicator</p><p>152Mobile Communicator</p><p>153Broadcast receiver</p><p>160Audio-Video (AV) input unit</p><p>161Camera</p><p>162Microphone</p><p>170Memory</p><p>171UI Module</p><p>172Touch Screen Module</p><p>173Notification Module</p><p>200Server</p><p>201Registration Mode</p><p>202Authentication Mode</p><p>208Screen</p><p>208-2Screen</p><p>209External device</p><p>209-2Types of biometric information</p><p>210External device</p><p>210-2Types of biometric information</p><p>212Screen</p><p>228Button</p><p>230Select screen</p><p>232-1Screen</p><p>232-2Screen</p><p>234-1Menu Screen/Menu Window</p><p>234-2Contact List</p><p>236-2Screen</p><p>237-2Screen</p><p>238Image</p><p>238-1Screen</p><p>238-2Screen</p><p>240Button</p><p>242Screen</p><p>401Watch type wearable device</p><p>402Glasses type wearable device</p><p>405Module for fingerprint recognition</p><p>701Watch type wearable device</p><p>702Glasses type wearable device</p><p>801Glasses type wearable device</p><p>802device</p><p>803device</p><p>901controller (processor)</p><p>903Communicator</p><p>905Database</p><p>907Content Database</p><p>909Key Database</p><p>911First external device</p><p>912Second external device</p><p>1001Second users device</p><p>1002Screen</p><p>1101Notification screen</p><p>1201Screen</p><p>1301Screen</p><p>2000Server</p><p>2001Second users device</p><p>2002Second device</p><p>2003First users device</p><p>2004Second users device</p><p>2005Third users device</p><p>2006The third device</p><p>2007First users device</p><p>2008Second users device</p><p>2009Third users device</p><p>2201Screen</p><p>2201-1device</p><p>2201-2device</p><p>2202Screen</p><p>2202-1Types of biometric information</p><p>2202-2Types of biometric information</p><p>2301Screen</p><p>7301 button</p><p>7401Lock screen</p><p>7501Main screen</p><p>7501-1Identification (ID) Information</p><p>7601-1Group</p><p>7701Screen</p><p>7701-1ID Information</p><p>7801Content</p><p>8202-2Reject button</p><p>8201Screen</p><p>8202Notification screen</p><p>8202-1Accept button</p><p>8301Notification screen</p><p>8401Notification screen</p><p>8401-1Accept button</p><p>8401-2Reject button</p><p>8501Notification screen</p><p>8701Login screen</p><p>8702Notification screen</p><p>8702-1Accept button</p><p>8702-2Reject button</p><p>8703Notification screen</p><p>8801Notification screen</p><p>8802Notification screen</p><p>9001Notification screen</p><p>9001-1Accept button</p><p>9002Screen</p><p>9101Notification screen</p><p>9101-1Accept button</p><p>9201Notification screen</p><p>9301Notification screen</p><p>9301-1Accept button</p><p>9301-2Reject button</p><p>9401Notification screen</p><p>9601Login screen</p><p>9602Biometric information login button</p><p>9603Notification screen</p><p>9701Notification screen</p><p>9702Notification screen</p><p>9801Lock screen setting screen</p><p>9801-1Project</p><p>9801-2Project</p><p>9901Lock screen</p><p>9902Notification screen</p><p>10001Main screen</p><p>c10Content</p><p>c18Content</p><p>c26Content</p><p>c27Content</p><p>c28Content</p><p>c30Content</p><p>d1Database (DB)</p><p>d2Content database</p><p>d3Key Database</p><p>f10finger</p><p>f11finger</p><p>f12finger</p><p>f13finger</p><p>f18-1finger</p><p>f18-2Finger</p><p>f20finger</p><p>f20-2Finger</p><p>f22finger</p><p>f23finger</p><p>f24Finger</p><p>f25finger</p><p>f32finger</p><p>f36-1Finger</p><p>f36-2Finger</p><p>f37finger</p><p>f38finger</p><p>f73finger</p><p>f74finger</p><p>f75finger</p><p>f76finger</p><p>f77finger</p><p>f87finger</p><p>f88Finger</p><p>f90finger</p><p>f91Finger</p><p>f93finger</p><p>f99finger</p><p>k10Key</p><p>k12Second encryption key</p><p>k14Encryption key</p><p>k21Common decryption key</p><p>k22Second decryption key</p><p>k23Second decryption key</p><p>k24Encoded first encryption key</p><p>k25Decrypted key</p><p>k26The first encryption key (Key_C)</p><p>k28Second encryption key (Key_D)</p><p>k30The first encryption key (key_C)</p><p>k32The third encryption key (Key_E)</p><p>k34The first encryption key (Key_C)</p><p>p10Password</p><p>p21Common password</p><p>p22Password</p><p>S301Operation</p><p>S302Operation</p><p>S401Operation</p><p>S402Operation</p><p>S403Operation</p><p>S501Operation</p><p>S502Operation</p><p>S503Operation</p><p>S504Operation</p><p>S601Operation</p><p>S602Operation</p><p>S603Operation</p><p>S604Operation</p><p>S701Operation</p><p>S702Operation</p><p>S703Operation</p><p>S704Operation</p><p>S801Operation</p><p>S802Operation</p><p>S803Operation</p><p>S804Operation</p><p>S901Operation</p><p>S902Operation</p><p>S903Operation</p><p>S904Operation</p><p>S905Operation</p><p>S906Operation</p><p>S1601Operation</p><p>S1602Operation</p><p>S1603Operation</p><p>S1701Operation</p><p>S1702Operation</p><p>S1703Operation</p><p>S1704Operation</p><p>S1801Operation</p><p>S1802Operation</p><p>S1803Operation</p><p>S1804Operation</p><p>S1901Operation</p><p>S1902Operation</p><p>S1903Operation</p><p>S1904Operation</p><p>S2001Operation</p><p>S2002Operation</p><p>S2003Operation</p><p>S2004Operation</p><p>S2101Operation</p><p>S2102Operation</p><p>S2103Operation</p><p>S2104Operation</p><p>S2105Operation</p><p>S2601Operation</p><p>S2602Operation</p><p>S2603Operation</p><p>S2604Operation</p><p>S2605Operation</p><p>S2606Operation</p><p>S2607Operation</p><p>S2608Operation</p><p>S3001Operation</p><p>S3002Operation</p><p>S3003Operation</p><p>S3004Operation</p><p>S3005Operation</p><p>S3006Operation</p><p>S3007Operation</p><p>S3008Operation</p><p>S3009Operation</p><p>S3010Operation</p><p>S3011Operation</p><p>S3012Operation</p><p>S3013Operation</p><p>S3014Operation</p><p>S3901Operation</p><p>S3902Operation</p><p>S3903Operation</p><p>S3904Operation</p><p>S3905Operation</p><p>S3906Operation</p><p>S3907Operation</p><p>S3908Operation</p><p>S3909Operation</p><p>S3910Operation</p><p>S4001Operation</p><p>S4002Operation</p><p>S4003Operation</p><p>S4004Operation</p><p>S4005Operation</p><p>S4006Operation</p><p>S4007Operation</p><p>S4008Operation</p><p>S4009Operation</p><p>S4010Operation</p><p>S4011Operation</p><p>S4012Operation</p><p>S4201Operation</p><p>S4202Operation</p><p>S4203Operation</p><p>S4204Operation</p><p>S4205Operation</p><p>S4206Operation</p><p>S4207Operation</p><p>S4208Operation</p><p>S4209Operation</p><p>S4210Operation</p><p>S4211Operation</p><p>S4212Operation</p><p>S4401Operation</p><p>S4402Operation</p><p>S4403Operation</p><p>S4404Operation</p><p>S4405Operation</p><p>S4406Operation</p><p>S4407Operation</p><p>S4408Operation</p><p>S4409Operation</p><p>S4410Operation</p><p>S4411Operation</p><p>S4412Operation</p><p>S4413Operation</p><p>S4501Operation</p><p>S4502Operation</p><p>S4503Operation</p><p>S4504Operation</p><p>S4505Operation</p><p>S4506Operation</p><p>S4507Operation</p><p>S4508Operation</p><p>S4509Operation</p><p>S4510Operation</p><p>S4601Operation</p><p>S4602Operation</p><p>S4603Operation</p><p>S4604Operation</p><p>S4605Operation</p><p>S4606Operation</p><p>S4607Operation</p><p>S4608Operation</p><p>S4609Operation</p><p>S4801Operation</p><p>S4802Operation</p><p>S4803Operation</p><p>S4804Operation</p><p>S4805Operation</p><p>S4806Operation</p><p>S4807Operation</p><p>S4808Operation</p><p>S4809Operation</p><p>S4810Operation</p><p>S4901Operation</p><p>S4902Operation</p><p>S4903Operation</p><p>S4904Operation</p><p>S4905Operation</p><p>S4906Operation</p><p>S4907Operation</p><p>S4908Operation</p><p>S4909Operation</p><p>S4910Operation</p><p>S4911Operation</p><p>S5001Operation</p><p>S5002Operation</p><p>S5003Operation</p><p>S5004Operation</p><p>S5005Operation</p><p>S5006Operation</p><p>S5007Operation</p><p>S5008Operation</p><p>S5009Operation</p><p>S5101Operation</p><p>S5102Operation</p><p>S5103Operation</p><p>S5104Operation</p><p>S5105Operation</p><p>S5106Operation</p><p>S5107Operation</p><p>S5108Operation</p><p>S5109Operation</p><p>S5110Operation</p><p>S5201Operation</p><p>S5202Operation</p><p>S5203Operation</p><p>S5204Operation</p><p>S5205Operation</p><p>S5206Operation</p><p>S5207Operation</p><p>S5208Operation</p><p>S5209Operation</p><p>S5210Operation</p><p>S5211Operation</p><p>S5212Operation</p><p>S5301Operation</p><p>S5302Operation</p><p>S5303Operation</p><p>S5304Operation</p><p>S5305Operation</p><p>S5306Operation</p><p>S5307Operation</p><p>S5308Operation</p><p>S5309Operation</p><p>S5310Operation</p><p>S5311Operation</p><p>S5501Operation</p><p>S5502Operation</p><p>S5503Operation</p><p>S5504Operation</p><p>S5505Operation</p><p>S5506Operation</p><p>S5507Operation</p><p>S5508Operation</p><p>S5509Operation</p><p>S5510Operation</p><p>S5601Operation</p><p>S5602Operation</p><p>S5603Operation</p><p>S5604Operation</p><p>S5605Operation</p><p>S5606Operation</p><p>S5607Operation</p><p>S5608Operation</p><p>S5609Operation</p><p>S5610Operation</p><p>S5611Operation</p><p>S5701Operation</p><p>S5702Operation</p><p>S5703Operation</p><p>S5704Operation</p><p>S5705Operation</p><p>S5706Operation</p><p>S5707Operation</p><p>S5708Operation</p><p>S5709Operation</p><p>S5710Operation</p><p>S5711Operation</p><p>S5801Operation</p><p>S5802Operation</p><p>S5803Operation</p><p>S5804Operation</p><p>S5805Operation</p><p>S5806Operation</p><p>S5807Operation</p><p>S5808Operation</p><p>S5809Operation</p><p>S5810Operation</p><p>S5811Operation</p><p>S5812Operation</p><p>S5813Operation</p><p>S5901Operation</p><p>S5902Operation</p><p>S5903Operation</p><p>S5904Operation</p><p>S5905Operation</p><p>S5906Operation</p><p>S5907Operation</p><p>S5908Operation</p><p>S5909Operation</p><p>S5910Operation</p><p>S5911Operation</p><p>S5912Operation</p><p>S5913Operation</p><p>S6101Operation</p><p>S6102Operation</p><p>S6103Operation</p><p>S6104Operation</p><p>S6105Operation</p><p>S6106Operation</p><p>S6107Operation</p><p>S6108Operation</p><p>S6109Operation</p><p>S6110Operation</p><p>S6111Operation</p><p>S6112Operation</p><p>S6113Operation</p><p>S6114Operation</p><p>S6201Operation</p><p>S6202Operation</p><p>S6203Operation</p><p>S6204Operation</p><p>S6205Operation</p><p>S6206Operation</p><p>S6207Operation</p><p>S6208Operation</p><p>S6209Operation</p><p>S6210Operation</p><p>S6211Operation</p><p>S6212Operation</p><p>S6213Operation</p><p>S6214Operation</p><p>S6215Operation</p><p>S6301Operation</p><p>S6302Operation</p><p>S6303Operation</p><p>S6304Operation</p><p>S6305Operation</p><p>S6306Operation</p><p>S6307Operation</p><p>S6308Operation</p><p>S6309Operation</p><p>S6310Operation</p><p>S6311Operation</p><p>S6312Operation</p><p>S6313Operation</p><p>S6314Operation</p><p>S6315Operation</p><p>S6316Operation</p><p>S6401Operation</p><p>S6402Operation</p><p>S6403Operation</p><p>S6404Operation</p><p>S6405Operation</p><p>S6406Operation</p><p>S6407Operation</p><p>S6408Operation</p><p>S6409Operation</p><p>S6410Operation</p><p>S6411Operation</p><p>S6412Operation</p><p>S6413Operation</p><p>S6414Operation</p><p>S6415Operation</p><p>S6416Operation</p><p>S6417Operation</p><p>S6418Operation</p><p>S6601Operation</p><p>S6602Operation</p><p>S6603Operation</p><p>S6604Operation</p><p>S6605Operation</p><p>S6606Operation</p><p>S6607Operation</p><p>S6608Operation</p><p>S6609Operation</p><p>S6610Operation</p><p>S6611Operation</p><p>S6612Operation</p><p>S6613Operation</p><p>S6614Operation</p><p>S6615Operation</p><p>S6616Operation</p><p>S6617Operation</p><p>S6701Operation</p><p>S6702Operation</p><p>S6703Operation</p><p>S6704Operation</p><p>S6705Operation</p><p>S6706Operation</p><p>S6707Operation</p><p>S6708Operation</p><p>S6709Operation</p><p>S6710Operation</p><p>S6711Operation</p><p>S6712Operation</p><p>S6713Operation</p><p>S6714Operation</p><p>S6715Operation</p><p>S6716Operation</p><p>S6717Operation</p><p>S6718Operation</p><p>S6801Operation</p><p>S6802Operation</p><p>S6803Operation</p><p>S6804Operation</p><p>S6805Operation</p><p>S6806Operation</p><p>S6807Operation</p><p>S6808Operation</p><p>S6809Operation</p><p>S6810Operation</p><p>S6811Operation</p><p>S6812Operation</p><p>S6813Operation</p><p>S6901Operation</p><p>S6902Operation</p><p>S6903Operation</p><p>S6904Operation</p><p>S6905Operation</p><p>S6906Operation</p><p>S6907Operation</p><p>S6908Operation</p><p>S6909Operation</p><p>S6910Operation</p><p>S6911Operation</p><p>S6912Operation</p><p>S6913Operation</p><p>S6914Operation</p><p>S6915Operation</p><p>S7101Operation</p><p>S7102Operation</p><p>S7103Operation</p><p>S7104Operation</p><p>S7105Operation</p><p>S7106Operation</p><p>S7201Operation</p><p>S7202Operation</p><p>S7203Operation</p><p>S7204Operation</p><p>S8001Operation</p><p>S8002Operation</p><p>S8003Operation</p><p>S8004Operation</p><p>S8005Operation</p><p>S8006Operation</p><p>S8007Operation</p><p>S8008Operation</p><p>S8101Operation</p><p>S8102Operation</p><p>S8103Operation</p><p>S8104Operation</p><p>S8601Operation</p><p>S8602Operation</p><p>S8603Operation</p><p>S8604Operation</p><p>S8605Operation</p><p>S8606Operation</p><p>S8607Operation</p><p>S8608Operation</p><p>S8609Operation</p><p>S8610Operation</p><p>S8611Operation</p><p>S8612Operation</p><p>S8613Operation</p><p>S8614Operation</p><p>S8615Operation</p><p>S8616Operation</p><p>S8901Operation</p><p>S8902Operation</p><p>S8903Operation</p><p>S8904Operation</p><p>S8905Operation</p><p>S8906Operation</p><p>S9501Operation</p><p>S9502Operation</p><p>S9503Operation</p><p>S9504Operation</p><p>S9505Operation</p><p>S9506Operation</p><p>S9507Operation</p><p>S9508Operation</p><p>S9509Operation</p><p>S9510Operation</p><p>S9511Operation</p><p>S9512Operation</p><p>S9513Operation</p><p>S9514Operation</p><p>S9515Operation</p><p>S9516Operation</p><p>S9517Operation</p>
These and/or other aspects will become obvious and easier to understand from the following description of the exemplary embodiment in conjunction with the accompanying drawings. In the accompanying drawings:
Fig. 1 is a diagram for describing an apparatus according to an exemplary embodiment.
Fig. 2 is a conceptual diagram of a controller for setting or removing content preservation according to an exemplary embodiment.
3 is a flowchart of a method for setting and removing content preservation using different biometric information according to an exemplary embodiment.
Fig. 4 is a flowchart of a method for setting content preservation according to an exemplary embodiment.
FIG. 5 is a flowchart of a method for restricting access to content in order to set security according to an exemplary embodiment.
Fig. 6 is a flowchart of a method for restricting access to content in order to set security according to another exemplary embodiment.
Fig. 7 is a flowchart of a method for encrypting content for setting security according to an exemplary embodiment.
Fig. 8 is a flowchart of a method of encrypting content for setting security according to another exemplary embodiment.
Fig. 9 is a flowchart of a method for encrypting content and an encryption key to set security according to an exemplary embodiment.
Figures 10 to 13 illustrate examples of user interfaces (UI) provided to set content preservation.
14A to 14C are diagrams for describing an example of setting content preservation according to an exemplary embodiment.
FIG. 15 is a diagram of a database according to an exemplary embodiment.
Fig. 16 is a flowchart of a method for removing content preservation according to an exemplary embodiment.
FIG. 17 is a flowchart of a method for allowing access to content in order to remove security according to an exemplary embodiment.
FIG. 18 is a flowchart of a method for allowing access to content in order to remove security according to another exemplary embodiment.
Fig. 19 is a flowchart of a method of decrypting content to remove security according to an exemplary embodiment.
FIG. 20 is a flowchart of a method of decrypting content to remove security according to another exemplary embodiment.
FIG. 21 is a flowchart of a method of decrypting content to remove security according to another exemplary embodiment.
22A to 23 illustrate an example of a UI provided to remove content preservation according to an exemplary embodiment.
24A to 24E are diagrams for describing examples of setting content preservation according to other exemplary embodiments.
FIG. 25 is a table for describing a decryption method according to an exemplary embodiment.
FIG. 26 is a flowchart of a method of decrypting content to remove security according to another exemplary embodiment.
27A to 28 illustrate an example of a UI provided to decrypt content in order to remove security according to an exemplary embodiment.
FIG. 29 is a diagram for describing an example of sharing content among multiple users according to an exemplary embodiment.
Fig. 30 is a flowchart of an encryption method for setting security according to an exemplary embodiment.
31 to 33 are diagrams for describing a method for encrypting content based on the biometric information of the first user according to an exemplary embodiment.
34 to 38 are diagrams for describing a method for sharing content by multiple users according to an exemplary embodiment.
39 and 40 are flowcharts of a method of decrypting content according to an exemplary embodiment.
FIG. 41 is a table for describing a decryption method according to another exemplary embodiment.
Fig. 42 is a flowchart of a method for changing security settings according to an exemplary embodiment.
FIG. 43 is a diagram for describing an example of changing security settings according to an exemplary embodiment.
FIG. 44 is a flowchart of an encryption method for setting security according to an exemplary embodiment.
45 and 46 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 47 is a table for describing a decryption method according to another exemplary embodiment.
48 to 50 are flowcharts of encryption methods for setting security according to other exemplary embodiments.
51 to 53 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 54 is a table for describing a decryption method according to another exemplary embodiment.
FIG. 55 and FIG. 56 are flowcharts of encryption methods for setting security according to other exemplary embodiments.
57 to 59 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 60 is a table for describing a decryption method according to another exemplary embodiment.
61 and 62 are flowcharts of encryption methods for setting security according to other exemplary embodiments.
FIG. 63 and FIG. 64 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 65 is a table for describing a decryption method according to another exemplary embodiment.
66 and 67 are flowcharts of encryption methods for setting security according to other exemplary embodiments.
FIG. 68 and FIG. 69 are flowcharts of methods for decrypting content according to other exemplary embodiments.
FIG. 70 is a table for describing a decryption method according to another exemplary embodiment.
FIG. 71 is a flowchart of a method for setting content preservation according to another exemplary embodiment.
FIG. 72 is a flowchart of a method for removing content preservation according to another exemplary embodiment.
FIGS. 73 to 78 are diagrams for describing an example of user input for executing content according to an exemplary embodiment.
FIG. 79 is a diagram for describing an example in which a device logs in to a server according to an exemplary embodiment.
FIG. 80 is a flowchart of a method for a device to register biometric information in a server according to an exemplary embodiment.
FIG. 81 is a flowchart of a method for registering biometric information in a server by a device according to another exemplary embodiment.
82 to 85 are diagrams for describing an example of a UI provided to register biometric information in a server according to an exemplary embodiment.
86A and 86B are flowcharts of a method for logging in to a server through a device according to an exemplary embodiment.
FIGS. 87 to 88B are diagrams for describing an example of a UI provided for a device to log in to a server according to an exemplary embodiment.
FIG. 89 is a flowchart of a method for a device to register biometric information in a server according to another exemplary embodiment.
90 to 94 are diagrams for describing examples of UIs provided to register biometric information in a server according to other exemplary embodiments.
95A and 95B are flowcharts of a method for accessing a server through a device according to an exemplary embodiment.
FIGS. 96 to 97B are diagrams for describing examples of UIs provided for devices to log in to the server according to other exemplary embodiments.
FIG. 98 illustrates an example provided to set the security of the lock screen according to an exemplary embodiment.
FIGS. 99 to 100B are diagrams for describing an example of a UI provided to remove the security of the lock screen according to an exemplary embodiment.
FIG. 101 and FIG. 102 are block diagrams of an apparatus according to an exemplary embodiment.
FIG. 103 is a block diagram of a server according to an exemplary embodiment.
<bio-deposit></bio-deposit>
<sequence-list-text></sequence-list-text>
36 members in 8 offices
Priority claims15
| Document | Office | Kind | Date |
|---|---|---|---|
| 1020140098588 | Republic of Korea | – | |
| 20140098588 | Republic of Korea | A | |
| 20140098588 | Republic of Korea | A | |
| 1020150015584 | Republic of Korea | – | |
| 20150015584 | Republic of Korea | A | |
| 20150015584 | Republic of Korea | A | |
| 1020150046861 | Republic of Korea | – | |
| 20150046861 | Republic of Korea | A | |
| 20150046861 | Republic of Korea | A | |
| 20140098588 | – | – | – |
| 20150015584 | – | – | – |
| 20150046861 | – | – | – |
| KR20140098588 | – | – | – |
| KR20150015584 | – | – | – |
| KR20150046861 | – | – | – |
Members36
| Document | Office | Kind | |
|---|---|---|---|
| EP2981115A2 | European Patent Office (EPO) | A2 | |
| US2016034708A1 | United States of America | A1 | |
| US2016036811A1 | United States of America | A1 | |
| WO2016018028A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN105323059A | China | A | |
| KR20160016522A | Republic of Korea | A | |
| KR20160016546A | Republic of Korea | A | |
| EP2981115A3 | European Patent Office (EPO) | A3 | |
| TW201617954AThis record | Taiwan Province of China | A | |
| AU2015297203A1 | Australia | A1 | |
| US9614842B2 | United States of America | B2 | |
| US2017193214A1 | United States of America | A1 | |
| US9852279B2 | United States of America | B2 | |
| AU2015297203B2 | Australia | B2 | |
| TWI613563B | Taiwan Province of China | B | |
| TW201812633A | Taiwan Province of China | A | |
| EP3321834A1 | European Patent Office (EPO) | A1 | |
| AU2018202889A1 | Australia | A1 | |
| US10003596B2 | United States of America | B2 | |
| RU2660617C1 | Russian Federation | C1 | |
| US2018270227A1 | United States of America | A1 | |
| CN105323059B | China | B | |
| US10193885B2 | United States of America | B2 | |
| RU2018122102A | Russian Federation | A | |
| RU2018122102A3 | Russian Federation | A3 | |
| CN109639626A | China | A | |
| CN109660987A | China | A | |
| RU2690219C2 | Russian Federation | C2 | |
| US2019173878A1 | United States of America | A1 | |
| AU2018202889B2 | Australia | B2 | |
| TWI671654B | Taiwan Province of China | B | |
| EP3321834B1 | European Patent Office (EPO) | B1 | |
| US11057378B2 | United States of America | B2 | |
| CN109639626B | China | B | |
| KR102304307B1 | Republic of Korea | B1 | |
| CN109660987B | China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- 201617954
- Publication, DOCDB
- 201617954
- Publication, EPODOC
- TW201617954
- Application
- 104124612
- Application, DOCDB
- 104124612
- Application, EPODOC
- TW20154124612
Titles5
- English
- DEVICE AND METHOD OF REMOVING SECURITY ON CONTENT AND LOGGING INTO SERVER
- Chinese
- 移除內容保全及登入至伺服器的裝置與方法
- Chinese
- 設定或移除內容保全的裝置與方法
- English
- DEVICE AND METHOD OF SETTING OR REMOVING SECURITY ON CONTENT
- English
- Device and method for setting or removing content preservation
Classification
- CPC, 14
- G06F21/32
- G06F21/10
- G06F21/45
- G06F21/6218
- H04L63/083
- H04L63/0861
- H04W12/02
- H04W12/06
- H04W12/50
- H04W88/02
- G06F3/0488
- H04W12/33
- G06F2221/2131
- G06F21/62
- IPC, 3
- G06F21 32
- G06F21 62
- H04W12 06