산업예제 · 금융 · 핀테크USE CASES · FINANCE AND FINTECH

금융 인증Financial Authentication

“화면 너머의 그 사람이 본인이라는 것을, 지금 무엇으로 확신하십니까?”“The person on the other side of the screen — what exactly makes you certain it is them?”

비대면 계좌개설과 거래 승인은 제출된 사진 한 장에 기대어 있습니다. 딥페이크로 신분증과 영상 위조가 쉬워지면서 그 절차가 흔들리고 있습니다. 유니버스AI는 인증 엔진을 고객사 서버 안에 설치합니다 — 위조 여부를 판정하고 등록 명단과 대조하는 일이 조직 울타리 안에서 끝납니다.Remote account opening and transaction approval rest on a submitted image. Deepfakes have made forged documents and replayed video easy, and that procedure is now under strain. UniverseAI installs the authentication engine inside your own servers — spoof detection and matching against your enrolled population finish inside your perimeter.

인증 요건 보내기Send Your Requirements 라이브 데모 요청Request a Live Demo

금융 현장에서 실제로 벌어지는 일What actually happens at a financial institution

시장 규모나 성장률로 시작하지 않겠습니다. 담당자가 매번 겪는 세 장면입니다.We will not open with market size or growth rates. Here are the three scenes your team lives through every time.

장면 1 / 비대면 개설SCENE 1 / REMOTE ONBOARDING
신분증 사진과 얼굴이 같은 사람인지 확신이 안 섭니다You cannot be sure the ID photo and the face are the same person
비대면 계좌개설 화면에서 신분증과 셀피가 올라옵니다. 담당자가 눈으로 대조하지만, 화면을 다시 찍은 것인지 실제 사람 앞에서 찍은 것인지는 사진만으로 구분되지 않습니다.An ID document and a selfie arrive through the remote onboarding screen. A reviewer compares them by eye — but an image alone does not reveal whether it was captured from a live person or re-shot from a screen.
원인: 제출된 이미지가 살아 있는 사람 앞에서 촬영된 것인지 판정하는 단계가 절차 안에 없습니다.Cause: the procedure has no step that judges whether the submitted image came from a living person in front of the camera.
장면 2 / 사고 뒤의 요구SCENE 2 / AFTER AN INCIDENT
계정 탈취가 한 건 나면 요구가 계획 밖에서 내려옵니다One account takeover, and the mandate arrives outside your plan
탈취나 명의도용이 한 건 발생하면 인증을 강화하라는 요구가 즉시 내려옵니다. 연초에 잡아 둔 IT 예산과 무관하게, 이번 분기 안에 답을 내야 하는 일이 됩니다.A single takeover or identity-theft case triggers an immediate mandate to strengthen authentication. Regardless of the IT budget fixed at the start of the year, it becomes something you must answer within the quarter.
원인: 아이디 · 비밀번호와 문자 인증은 탈취되면 그대로 통과합니다. 사람 자체를 확인하는 단계가 없습니다.Cause: IDs, passwords and SMS codes pass straight through once stolen. Nothing in the chain verifies the person themselves.
장면 3 / 보안 검토SCENE 3 / SECURITY REVIEW
기술 검토는 끝났는데 데이터가 어디에 남느냐에서 멈춥니다The technical review passes, then stops at where the data lives
기능은 문제가 없다는 결론이 났습니다. 그런데 생체정보가 조직 밖 서버로 나가는 구조라는 점이 확인되면서 검토가 그 자리에서 멈춥니다.The functional review concludes without issue. Then it emerges that biometric data would travel to a server outside the organisation — and the review halts right there.
원인: 금융에서는 기능보다 데이터가 어디에 남는지가 먼저 판단됩니다. 밖으로 나가는 구조면 내부 심사를 통과하지 못하는 경우가 많습니다.Cause: in finance, where the data ends up is judged before what the product does. A design that sends it outside frequently fails internal review.
세 장면은 결국 한 줄로 이어집니다 — 사람 자체를 확인해야 하고(위조 판정 + 등록 명단 대조), 그 확인이 조직 안에서 끝나야 합니다(고객 서버 설치 + 원본 미저장). 뒤쪽이 성립하지 않으면 앞쪽은 검토 대상에도 오르지 못합니다. 그래서 저희는 설치 위치부터 먼저 말씀드립니다. The three scenes resolve into one line — you have to verify the person (spoof judgement plus a match against the enrolled population), and that verification has to finish inside the organisation (installed on your servers, originals not retained). If the second half does not hold, the first half never even reaches review. That is why we start with where it is installed.

이 자리는 GATE 하나로 성립합니다GATE alone covers this use case

제품을 여러 개 얹어 드리지 않습니다. 금융의 요건은 한 줄로 모입니다 — 인증이 고객 서버 안에서 끝나야 한다는 것입니다. 그 요건을 채우는 것은 서버에 설치되는 인증 엔진 하나입니다.We do not stack products here. The requirement in finance converges on a single line: authentication has to finish inside your servers. What satisfies it is one thing — an authentication engine installed on those servers.

고객 단말이 촬영한 얼굴 이미지가 고객 서버 안의 GATE로 전달되어 라이브니스 판정과 1:N 대조를 거친 뒤, 인증 결과만 고객 시스템으로 돌아가는 3단 구성도 단말은 고객 것, 인증은 고객 서버 안의 저희 엔진. The terminals are yours; the authentication runs on your own servers. 회색 = 고객이 이미 가진 것 / 파랑 = 고객 서버 안에 설치되는 것 Grey = what you already own / blue = what is installed inside your servers 고객이 이미 가진 것 Already yours 고객 서버 안 Inside your servers 고객이 이미 가진 것 Already yours 고객 단말 · 앱 Terminals and apps 모바일 앱 · ATM · 창구 Mobile app, ATM, branch 촬영만 담당 Capture only 하드웨어 교체 없음 No hardware swap GATE 고객 서버에 설치되는 인증 엔진 Authentication engine installed on your servers ① 라이브니스 — 위변조 탐지 1. Liveness — spoof detection ② 1:N 대조 — 등록 명단에서 확인 2. 1:N match — against the enrolled list 고객 시스템 Your systems 계좌개설 Account opening 거래 승인 Transaction approval 고객 시스템이 수행 Done by your systems 얼굴 이미지 Face image 인증 결과 Result only 생체정보는 고객 서버 밖으로 나가지 않습니다 (온프레미스 구성 기준) Biometric data does not leave your servers (under an on-premises configuration) 저장은 template-only — 대조용 특징 데이터만 남고 원본 이미지는 저장하지 않습니다 Storage is template-only — only the matching features remain; original images are not kept

저희가 납품하는 것은 엔진과 연동 규격입니다. ATM · 키오스크 · 창구 단말 · 모바일 앱은 쓰시던 것을 그대로 쓰십니다. 다만 단말이나 단말을 관리하는 시스템이 저희 서버를 호출하도록 연동 개발은 필요하며, 그 개발은 고객사 또는 고객사의 SI 파트너가 진행합니다.What we deliver is the engine and the integration specification. ATMs, kiosks, branch terminals and mobile apps stay exactly as they are. Integration work is still required so that your terminals or the systems managing them call our server, and that work is carried out by your team or your SI partner.

구성 요소Component맡는 일What it does
라이브니스Liveness인쇄 사진 · 화면 재생 영상 · 마스크 같은 대표적인 위조 시도를 걸러냅니다. RGB 패시브 방식이라 별도 적외선 카메라를 새로 다실 필요가 없고, 사용자가 눈을 깜빡이거나 고개를 돌릴 필요도 없습니다.Screens the common spoof attempts — printed photos, video replayed on a screen, masks. It is RGB passive, so no infrared camera has to be added and the user does not have to blink or turn their head.
1:N 대조1:N matching등록된 대규모 명단 가운데 이 사람이 누구인지 찾아냅니다. 1:1(이 계정의 주인이 맞는가)보다 어렵고, 회원 규모가 큰 금융에서 실제로 필요한 쪽입니다. KISA 인증 기준 99.97%, 응답 1초 미만 기준입니다.Finds who this person is within a large enrolled population. It is harder than a 1:1 check (is this the account owner?) and it is the one financial institutions with large memberships actually need. 99.97% under KISA certification testing, with a response designed for under one second.
얼굴 · 손바닥Face and palm얼굴만 쓰면 마스크 · 역광 · 외모 변화 같은 상황에서 그대로 멈춥니다. 손바닥을 함께 쓰면 얼굴이 막힌 자리를 대체하거나, 고액 거래에서 두 가지를 겹쳐 확인하실 수 있습니다.Relying on the face alone stops dead under masks, backlight or changed appearance. Adding the palm gives a second route where the face is blocked, or a second factor layered on top for high-value transactions.
저장 방식Storagetemplate-only. 대조에 필요한 특징 데이터만 저장하고 원본 사진은 남기지 않습니다. 온프레미스 설치와 겹치면 생체정보가 조직 울타리 밖으로 나가지 않는 구성이 성립합니다.Template-only. Only the feature data required for matching is stored; original photographs are not kept. Combined with on-premises installation, this is what makes it accurate to say biometric data never leaves your perimeter.
설치 · 이중화Deployment and redundancy고객 서버(온프레미스) · 클라우드 · 컨테이너(Docker · Kubernetes) 환경에 설치할 수 있습니다. Active-active 구성과 자동 페일오버를 지원합니다.Installs on your own servers (on-premises), in the cloud, or into container environments such as Docker and Kubernetes. Active-active configuration with automatic failover is supported.
연동IntegrationREST API. 연동 규격 문서를 드리고, 개발은 고객사 또는 SI 파트너가 진행합니다. 저희는 단말을 공급하지 않습니다.REST API. We supply the integration specification; development is carried out by your team or your SI partner. We do not supply terminals.
“다른 제품을 이 자리에 얹지 않는 이유입니다.”
저희에게는 영상 검색(VCA)과 엣지 압축(AI BOX)도 있습니다. 다만 그 둘이 푸는 문제는 이미 쌓인 영상을 되짚는 일영상이 지워지지 않게 하는 일입니다. 지금 이 문서를 읽고 계신 이유, 즉 계좌개설 화면 앞의 그 사람이 본인인가 하는 문제와는 다릅니다. 관제 영상 쪽 과제가 함께 있으시면 그때 별도로 말씀드립니다.
“Why we do not add other products here.”
We also build video search (VCA) and edge compression (AI BOX). But those two solve retracing footage that has already accumulated and keeping footage from being deleted. Neither is the question that brought you to this page — is the person in front of the onboarding screen really them. If you also have a surveillance-video problem, we address that separately.

도입은 네 걸음입니다Adoption takes four steps

요건 확인부터 배포까지, 각 걸음에서 무엇이 오가는지 미리 밝혀 둡니다.From confirming requirements to deployment — here is exactly what is exchanged at each step.

1
요건 확인Confirm requirements
인증 대상 인원 · 하루 인증 건수 · 단말 종류 · 설치 형태(온프레미스 또는 클라우드). 이 네 가지로 구성안을 정리해 회신드립니다. 보안 검토를 맡으신 부서와 함께 검토하시길 권합니다 — 데이터가 어디에 남는지는 기능 검토와 별개 항목으로 다뤄지는 경우가 많아, 나중에 다시 도는 일을 줄여 줍니다.Population to be authenticated, daily authentication volume, terminal types, and deployment form (on-premises or cloud). With those four we draft a configuration and reply. We recommend running this review together with whichever team owns security — where the data ends up is usually assessed separately from functionality, and involving them early avoids a second lap later.
2
라이브 데모Live demo
라이브니스 판정과 1:N 대조를 실제로 돌려 보여 드립니다. 인쇄 사진과 화면 재생 영상을 그 자리에서 넣어 보시는 것이 가장 빠릅니다.We run liveness judgement and 1:N matching live. The fastest way to judge it is to hand us a printed photo and a replayed video on the spot.
3
자체 환경 검증Verify in your environment
실제 조명 · 단말 · 등록 사진 품질로 확인하십니다. 인증 시험에서 측정된 값이 현장에서 그대로 나오지 않기 때문에, 쓰실 조건과 유사한 환경에서 검증하시는 것이 가장 정확합니다. 검증 항목을 어떻게 잡을지 요건을 주시면 정리해 드립니다.You verify with your real lighting, terminals and enrolment image quality. Figures measured in certification testing do not reproduce as-is in the field, so testing in conditions close to your actual use is the most accurate route. Send us your requirements and we will propose the verification criteria.
4
연동 개발과 배포Integration and rollout
REST API 연동 규격 문서를 드립니다. 개발은 고객사 내부 개발팀 또는 SI 파트너가 진행하고, 저희는 엔진과 규격 · 검증 지원을 맡습니다.We hand over the REST API integration specification. Development is carried out by your in-house team or your SI partner; we supply the engine, the specification and verification support.
연동 개발은 반드시 있습니다
단말 하드웨어를 교체할 필요는 없지만, 단말이나 단말을 관리하는 시스템이 저희 서버를 호출하도록 연동 개발은 반드시 필요합니다. 그 개발을 내부 개발팀이 맡으실지 SI 파트너가 맡으실지 초기에 정해 두시는 것이 전체 일정을 가장 크게 좌우합니다.
Integration work always exists
No terminal hardware has to be replaced, but integration development is always required so that your terminals or the systems managing them call our server. Deciding early whether your in-house team or an SI partner owns that work is what moves the overall schedule most.

무엇을 근거로 말씀드립니까What we base these claims on

측정된 것과 배치된 것만 적습니다. 그 뒤에 한계도 함께 적습니다.Only what has been measured and what has been deployed — followed by the limits, stated just as plainly.

99.97%
KISA 인증 기준 정확도Accuracy under KISA certification testing
1초 미만Under 1 sec
1:N 응답 기준(밀리초 보장 아님)1:N response target (no millisecond guarantee)
400M+
얼굴 DB 규모Face database scale
4종4
보유 인증 — KISA · iBeta · GS 1등급 · ISOCertifications: KISA, iBeta, GS 1st Grade, ISO
레퍼런스Reference

대규모 안면결제 서비스 운영 레퍼런스가 있습니다. 하루 단위로 대량의 본인 확인이 실제로 돌아간 환경이라는 뜻입니다. 고객사 이름은 밖에서 이야기하지 않습니다 — 귀사의 이름도 같은 원칙으로 지켜 드립니다.We hold a reference from operating a large-scale face payment service — an environment where a high daily volume of identity checks genuinely ran. We keep client names off the table outside, and yours is protected by the same rule.

원산 · 배포Origin and deployment

국내에서 개발한 비중국 벤더입니다. 내부 보안 정책이나 조달 규격에서 벤더 원산지를 요건으로 두시는 경우, 이는 성능 항목과 별개로 평가되는 자격 요건입니다. 관련 요건이 있으시면 확인 자료를 정리해 드립니다.A Korea-developed, non-Chinese vendor. Where your internal security policy or procurement specification treats vendor origin as a requirement, it is an eligibility criterion assessed separately from performance. If such a requirement applies, we prepare the supporting documentation.

먼저 말씀드립니다
  • 라이브니스가 인쇄 사진 · 화면 재생 영상 · 마스크 같은 위변조 시도를 걸러냅니다. 현장 성능은 단말 카메라 화질과 조명 조건을 타기 때문에, 그 조건에 맞춰 판정 기준을 조정해 드립니다.
  • 정확도 수치는 KISA 인증 시험에서 측정된 값이며 현장 조명 · 각도 · 등록 사진 품질에 따라 달라집니다. 실제 환경에서 먼저 검증해 보시길 권합니다.
  • 응답 시간은 1초 미만 기준으로 설계했습니다. 실제 값은 서버 사양 · DB 규모 · 네트워크 구간에서 정해지므로, 세 가지를 주시면 구성안을 잡아 실제 환경에서 측정해 보실 수 있게 준비해 드립니다.
  • 템플릿도 개인정보로 취급하는 규제가 있습니다. 법적 해석은 저희가 하지 않습니다 — 저장 방식이라는 사실만 정확히 전달드리고, 판단은 고객사 법무 · 컴플라이언스의 몫입니다.
  • 손바닥을 쓰시려면 고객 단말의 카메라가 손바닥을 제대로 촬영할 수 있어야 합니다. 촬영 거리 · 화각 · 조명 조건을 먼저 확인한 뒤 가능 여부를 정확히 답을 드립니다.
  • 단말은 고객사가 이미 가지고 계신 것을 그대로 쓰십니다. ATM · 키오스크 · 창구 단말 · 모바일 앱 — 저희가 드리는 것은 엔진과 연동 규격입니다.
Stated up front
  • Liveness screens spoof attempts such as printed photos, video replayed on a screen, and masks. Field performance tracks terminal camera quality and lighting, so we tune the decision thresholds to those conditions.
  • The accuracy figure was measured under KISA certification testing and shifts with on-site lighting, angle and enrolment image quality. We recommend verifying in your real environment first.
  • Response time is designed to the under one second mark. The actual figure is set by server specification, database size and the network segment, so send us those three and we will propose a configuration and prepare it so you can measure it in your own environment.
  • Some regulations treat templates as personal data too. We do not give legal interpretations — we state the storage method accurately, and the judgement belongs to your legal and compliance teams.
  • Using the palm requires that your terminal camera can actually capture it. We check capture distance, field of view and lighting first, then give you a definite answer.
  • Your existing terminals stay in place. ATMs, kiosks, branch terminals and mobile apps remain the ones you already own — what we supply is the engine and the integration specification.

자주 묻는 질문Frequently asked questions

금융 담당자분들이 실제로 가장 먼저 물으시는 아홉 가지입니다.The nine questions financial teams actually ask first.

생체정보가 외부로 나갑니까? 망 분리 환경입니다.Does biometric data leave our premises? We run a segregated network.
인증 엔진을 고객사 서버에 설치하는 온프레미스 구성이 가능하며, 그 구성에서는 데이터가 고객사 환경 안에 남습니다. 클라우드와 컨테이너(Docker · Kubernetes) 배포도 가능합니다. 정확한 데이터 흐름은 구축 형태를 확정한 뒤 문서로 정리해 드립니다.An on-premises configuration that installs the authentication engine on your own servers is supported, and in that configuration the data stays inside your environment. Cloud and container deployments (Docker, Kubernetes) are also possible. Once the deployment form is fixed, we document the exact data flow for you.
얼굴 사진 원본을 저장합니까?Do you store the original face photographs?
저장하지 않습니다. 대조에 필요한 특징 데이터(템플릿)만 저장하는 template-only 방식입니다. 다만 템플릿도 개인정보로 취급하는 규제가 있고, 그 해석은 저희가 하지 않습니다. 저장 방식이라는 사실만 정확히 전달드리고 판단은 고객사 법무 · 컴플라이언스에서 하십니다.We do not. Only the feature data (the template) required for matching is stored — a template-only approach. That said, some regulations treat templates as personal data as well, and we do not offer that interpretation. We state the storage method accurately; the judgement is made by your legal and compliance teams.
딥페이크나 화면 재생 영상으로 뚫리지 않습니까?Can it be defeated by a deepfake or by video replayed on a screen?
라이브니스가 인쇄 사진, 화면에 재생한 영상, 마스크 같은 대표적인 위조 시도를 걸러냅니다. 현장 성능은 단말 카메라 화질과 조명 조건을 타기 때문에, 그 조건에 맞춰 판정 기준을 조정해 드립니다. 데모에서 직접 시도해 보시는 것이 가장 정확한 판단 방법입니다.Liveness screens the common spoof attempts — printed photos, video replayed on a screen, masks. Field performance tracks terminal camera quality and lighting, so we tune the decision thresholds to those conditions. Trying it yourself in the demo is the most accurate way to judge.
쓰던 단말을 교체해야 합니까?Do we have to replace the terminals we already use?
하드웨어 교체는 없습니다. ATM · 키오스크 · 창구 단말 · 모바일 앱은 그대로 쓰십니다. 다만 단말이나 단말을 관리하는 시스템이 저희 서버를 호출하도록 연동 개발은 필요하며, 그 개발은 고객사 내부 개발팀 또는 SI 파트너가 진행합니다. 저희가 공급하는 것은 엔진과 연동 규격입니다.There is no hardware replacement. Your ATMs, kiosks, branch terminals and mobile apps stay as they are. Integration development is required, however, so that the terminals or the systems managing them call our server, and that work is done by your in-house team or your SI partner. What we supply is the engine and the integration specification.
1:1 확인이면 충분한데 왜 1:N이 필요합니까?A 1:1 check seems enough — why would we need 1:N?
1:1은 이 사람이 이 계정의 주인이 맞는지 확인하는 것이고, 1:N은 등록된 대규모 명단 가운데 이 사람이 누구인지 찾아내는 것입니다. 계정을 특정하지 않은 상태에서 본인을 확인해야 하거나, 한 사람이 여러 계정으로 중복 등록되는 것을 막아야 하는 경우에는 1:N이 필요합니다. 두 방식 모두 지원합니다.A 1:1 check confirms that this person owns this account; a 1:N search finds who this person is within a large enrolled population. You need 1:N when identity must be established before an account is specified, or when one person must be prevented from enrolling under multiple accounts. Both modes are supported.
얼굴이 잘 안 되는 사용자는 어떻게 합니까?What about users for whom the face does not work well?
얼굴과 손바닥을 함께 쓸 수 있습니다. 마스크 · 역광 · 외모가 크게 바뀐 경우처럼 얼굴이 막히는 상황을 손바닥이 대체하고, 고액 거래에서는 두 가지를 겹쳐 확인하실 수도 있습니다. 다만 손바닥을 쓰시려면 단말 카메라가 손바닥을 제대로 촬영할 수 있어야 하므로, 촬영 거리 · 화각 · 조명 조건을 먼저 확인드립니다.Face and palm can be used together. Where the face is blocked — masks, backlight, significantly changed appearance — the palm covers it, and for high-value transactions the two can be layered. Using the palm does require that your terminal camera can capture it properly, so we check capture distance, field of view and lighting first.
규제 요건에 맞는지 확인해 주실 수 있습니까?Can you confirm that this meets our regulatory requirements?
법적 해석은 저희가 하지 않습니다. 저희가 드릴 수 있는 것은 사실입니다 — 어디에 설치되는지, 무엇이 저장되고 무엇이 저장되지 않는지, 접근 권한과 감사 기록이 어떻게 남는지. 적용받으시는 규정과 내부 심사 항목을 알려주시면 필요한 확인 자료를 그 형식에 맞춰 정리해 회신드립니다.We do not provide legal interpretations. What we can provide are facts — where it is installed, what is stored and what is not, and how access rights and audit records are kept. Tell us which regulations apply and which internal review items you face, and we will prepare the supporting documentation in that format.
서버 부하와 이중화는 어떻게 됩니까?How are server load and redundancy handled?
Active-active 구성과 자동 페일오버를 지원합니다. 실제 구성은 등록 인원 · 하루 인증 건수 · 동시 처리량에 따라 달라지므로, 그 세 가지 숫자를 주시면 구성안을 검토해 회신드립니다. 가용률 보장 수준은 계약 조건으로 함께 정합니다.Active-active configuration with automatic failover is supported. The actual configuration depends on enrolled population, daily authentication volume and concurrency, so send us those three numbers and we will review a configuration and reply. Guaranteed availability levels are set together in the contract.
도입 비용은 어떻게 됩니까?What does adoption cost?
견적으로 회신드립니다. 산정에 필요한 것은 인증 대상 인원 규모, 고객사 서버에 설치하실지 클라우드로 하실지, 도입 목표 시점 세 가지입니다. 주시면 회신 일정을 바로 잡아 드립니다.We respond with a quotation. Three inputs are required: the size of the population to be authenticated, whether you will install on your own servers or in the cloud, and your target deployment date. Send those and we will confirm a reply date immediately.

관련 제품Related products

이 구성의 본체와, 엔진 자체를 직접 붙이시려는 경우의 접점입니다.The product at the centre of this configuration, and the entry point if you would rather build against the engine itself.

확인이 조직 안에서 끝나게So verification finishes inside your organisation

인증 대상 인원 · 하루 인증 건수 · 단말 종류 · 설치 형태 네 가지만 보내주시면, 구성안을 정리하고 데모 일정을 회신드립니다.Send us four things — population to be authenticated, daily authentication volume, terminal types and deployment form — and we will draft a configuration and respond with a demo schedule.

인증 요건 보내기Send Your Requirements