Method and apparatus for authentication of unknown user in social network service

Disclosed are a method and apparatus for authenticating an unknown user in a social network service. The disclosed method for authenticating an unknown user comprises the steps of: receiving, from a terminal device of an unknown user, an access request message including identification information of the unknown user and a friend list of the unknown user in a social network service; searching the same friend as a friend of the unknown user in the social network service in the friend list of the unknown user; transmitting, to a terminal of the same friend, an authentication request message including the identification information of the unknown user; receiving, from the terminal of the same friend, an authentication confirmation message as a response to the authentication request message; and authenticating the unknown user in response to the reception of the authentication confirmation message. [Reference numerals] (210) User A; (230) User F; (S400) Receive an access request message transmitted from a user U; (S402) Decode the access request message; (S404) Extract a friend list of the user U and a first cryptogram from the decoded access request message; (S406) Decode the first cryptogram; (S408) Determine whether friend lists are identical to each other; (S410) Search whether the same friend as a friend of the user A exists in the friend list of the user U; (S412) Transmit an authentication request message; (S414) Decode the authentication request message; (S416) Extract identification information of the user A, identification information of the user U, and a second cryptogram from the decoded authentication request message; (S418) Decode the second cryptogram; (S420) Determine whether the identification information of the users are identical to one another; (S422) Search whether the identification information of the user F exists in one's own friend list; (S424) Transmit an authentication confirmation message; (S426) Authenticate the user U