JP2008242585A - Service use identification creating device, service use identification creation system, service use identification creation method, and program - Google Patents

Service use identification creating device, service use identification creation system, service use identification creation method, and program Download PDF

Info

Publication number
JP2008242585A
JP2008242585A JP2007079016A JP2007079016A JP2008242585A JP 2008242585 A JP2008242585 A JP 2008242585A JP 2007079016 A JP2007079016 A JP 2007079016A JP 2007079016 A JP2007079016 A JP 2007079016A JP 2008242585 A JP2008242585 A JP 2008242585A
Authority
JP
Japan
Prior art keywords
service
information
user
identification information
providing server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP2007079016A
Other languages
Japanese (ja)
Other versions
JP4989996B2 (en
Inventor
Tatsu Watanabe
龍 渡辺
Ayumi Kubota
歩 窪田
Toshiaki Tanaka
俊昭 田中
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
KDDI Research Inc
Original Assignee
KDDI R&D Laboratories Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by KDDI R&D Laboratories Inc filed Critical KDDI R&D Laboratories Inc
Priority to JP2007079016A priority Critical patent/JP4989996B2/en
Publication of JP2008242585A publication Critical patent/JP2008242585A/en
Application granted granted Critical
Publication of JP4989996B2 publication Critical patent/JP4989996B2/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

<P>PROBLEM TO BE SOLVED: To obtain user information required in a state that the information is kept secret from a third party while suppressing a communication burden of a TTP (Trusted Third Party) and a service providing server. <P>SOLUTION: Additional information is given to received user log-in information, and information in which additional information is given to user log-in information is encrypted by a different encryption key for each service which the user receives. Then information about the user is given to the encrypted information, and the information which is given the information about the user to the encrypted information is encrypted by an encryption key unique to a service use identification creation device. <P>COPYRIGHT: (C)2009,JPO&INPIT

Description

本発明は、ユーザIDに対して付加的な情報および利用者に関する情報を付与するとともに、この情報を第三者に対して秘匿化するサービス利用識別情報生成装置、サービス利用識別情報生成システム、サービス利用識別情報生成方法およびプログラムに関する。   The present invention provides a service use identification information generating apparatus, a service use identification information generating system, a service, which gives additional information and information about a user to a user ID and conceals this information from a third party. The present invention relates to a usage identification information generation method and program.

従来、図7に示すように、インターネット上でサービス利用の利便性を向上させる技術として、ユーザ端末100と、信頼のおける第三者機関(TTP:Trusted Third Party)200と、サービス提供サーバ300とからなるシステムにおいて、このTTP200を利用したシングルサインオン(SSO:Single Sign On)と呼ばれる技術がある。   Conventionally, as shown in FIG. 7, as a technique for improving the convenience of service use on the Internet, a user terminal 100, a trusted third party (TTP) 200, a service providing server 300, There is a technology called Single Sign On (SSO) using the TTP 200.

このTTP200を利用するSSO技術では、その利用にあたり、ユーザのプライバシーを保護するために、ユーザが利用するサービス(サービス提供者)に対して、サービスごとにID(Identifier)を変更することが必要とされる。これは、異なるサービスに対して同じIDを利用させてしまうと、サービス提供側が結託した場合に、それぞれのサービスにおけるユーザの行動を付き合わせることができてしまうためである。   In the SSO technology using the TTP 200, in order to protect the user's privacy, it is necessary to change the ID (Identifier) for each service with respect to the service (service provider) used by the user. Is done. This is because if the same ID is used for different services, the user's actions in each service can be associated with each other when the service provider collaborates.

また、サービスごとにIDを変更することに加えて、接続ごとにもIDを変更することが必要とされている。すなわち、同じサービスであっても、常に同じIDで利用し続けた場合には、そのユーザの行動をトレースできてしまうためである。この場合、特定のユーザの行動をトレースできることを利用して、ショッピングサイトのように、お勧め商品の紹介(リコメンデーションサービスあるいは、パーソナライゼーションサービスと呼ぶ)を提供することも可能となるが、その一方で、ユーザによっては、このようにユーザ自身の行動が把握されることを嫌がる可能性もある。   In addition to changing the ID for each service, it is also necessary to change the ID for each connection. That is, even if the service is the same, if the user always uses the same ID, the user's action can be traced. In this case, it is possible to provide an introduction of recommended products (referred to as a recommendation service or personalization service) like a shopping site by using the ability to trace the behavior of a specific user. On the other hand, depending on the user, there is a possibility that the user's own behavior is not grasped in this way.

さらに、このような、TTP200を利用したSSO技術の利用にあたり、TTP200が本人の特定を実施できるよう、IDのユーザと本人(この場合は、TTP200へのログインID)との対応関係をTTP200が把握できることも併せて必要とされている。このため、TTP200でのサービス利用時のIDの管理にあたり、TTP200での管理コストを低減することを目的として、暗号化の技法を利用する手法が提案されている(例えば、特許文献1参照。)。   Furthermore, when using the SSO technology using the TTP 200, the TTP 200 grasps the correspondence between the ID user and the user (in this case, the login ID to the TTP 200) so that the TTP 200 can identify the user. What can be done is also needed. For this reason, a method using an encryption technique has been proposed for the purpose of reducing the management cost in the TTP 200 when managing the ID when using the service in the TTP 200 (see, for example, Patent Document 1). .

この従来のID管理手法では、TTP200へのログインIDに生成日時といった動的な情報や、固定のビット列などの静的な情報を付加した後に暗号化を施したものをサービス利用のためのIDとして生成している。このため、ユーザとIDとの関係を把握するには、新たに生成したサービス利用のためのIDを、生成の際に利用した暗号化鍵を用いて復号してやればよい。そのため、TTP200自身では、ユーザ(ユーザのTTP200へのログインID)と新たに生成したサービス利用のためのIDとの対応関係を保持する必要はなく、TTP200が管理すべき情報は、IDの生成に利用した鍵のみとなる。したがって、TTP200における管理コストを低減することができる。   In this conventional ID management method, a dynamic ID such as a generation date and a static information such as a fixed bit string are added to the login ID to the TTP 200, and then encryption is performed as an ID for using the service. Is generated. Therefore, in order to grasp the relationship between the user and the ID, the newly generated ID for using the service may be decrypted using the encryption key used at the time of generation. Therefore, the TTP 200 itself does not need to maintain the correspondence between the user (the user's login ID to the TTP 200) and the newly generated ID for using the service, and the information that the TTP 200 should manage is the ID generation. Only used keys. Therefore, the management cost in TTP200 can be reduced.

また、上記従来のID管理手法においては、ID生成に利用した鍵が漏洩した際のリスクを低減するために、サービスごとに利用する暗号化鍵を変更する手法が提案されている。そのため、鍵が漏洩した場合でも、その被害はそのサービスに限定でき、被害が他のサービスに波及することが防げるようになっている。
特開2006−244420号公報
In the conventional ID management method, a method of changing the encryption key used for each service has been proposed in order to reduce the risk when the key used for ID generation leaks. Therefore, even if the key is leaked, the damage can be limited to the service, and the damage can be prevented from spreading to other services.
JP 2006-244420 A

しかしながら、上記従来のID管理手法は、サービス提供者が、自身のサービスの利用者を識別するための手法であり、識別子に利用者に関する情報は付与されてはいない。このため、サービス提供者がユーザの情報を取得するためには、別途、サービス提供者とTTP(あるいは、ユーザの情報の管理元)とが通信を行なう必要があるという問題がある。また、別途、利用者の情報を証明するための属性証明書などを利用する方式も提案されているが、この場合も、識別子の取得とは別に、通信が発生するという問題がある。   However, the above-described conventional ID management technique is a technique for a service provider to identify a user of his / her service, and information on the user is not given to the identifier. For this reason, in order for the service provider to acquire the user information, there is a problem that the service provider and TTP (or the user information management source) need to communicate separately. In addition, a method of using an attribute certificate or the like for proving user information has been proposed. However, in this case, there is a problem that communication occurs separately from acquisition of an identifier.

そこで、本発明は、上記の課題に鑑みてなされたものであり、TTPおよびサービス提供サーバの通信負担を抑えつつ、第三者に秘匿した状態で必要な利用者情報を入手できるサービス利用識別情報生成装置、サービス利用識別情報生成システム、サービス利用識別情報生成方法およびプログラムを提供することを目的とする。   Therefore, the present invention has been made in view of the above problems, and service use identification information that can obtain necessary user information in a state that it is kept secret from a third party while suppressing the communication burden of the TTP and the service providing server. It is an object to provide a generation device, a service use identification information generation system, a service use identification information generation method, and a program.

本発明は、上述の課題を解決するために以下の事項を提案している。
(1)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)とにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置であって、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成装置を提案している。
The present invention proposes the following items in order to solve the above-described problems.
(1) The present invention connects a user terminal (for example, equivalent to the user terminal 100 in FIG. 1) and a service providing server (for example, equivalent to the service providing server 300 in FIG. 1) managed by the service provider via a network. A service usage identification information generating device for generating service usage identification information for identifying the user when the service providing server uses the service, and receiving means for receiving the login information of the user ( For example, it corresponds to the receiving unit 21 in FIG. 2) and an encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user ( For example, it is equivalent to the encryption unit 22 in FIG. 2), and information related to the user is added to the information encrypted by the encryption processing means. Service usage identification information generating means (for example, corresponding to the service usage identification information generating unit 24 in FIG. 2) that generates service usage identification information by encrypting with an encryption key, and the service providing server that generates the generated service usage identification information A service use identification information generating device characterized by comprising a transmission means (for example, corresponding to the transmission unit 25 in FIG. 2).

この発明によれば、受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、サービス利用識別情報生成装置が、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。   According to this invention, the receiving means receives the user's login information, and the encryption processing means adds additional information to the received user's login information, and uses an encryption key that differs for each service that the user receives. Encrypt. Then, the service usage identification information generating means adds information about the user to the information encrypted by the encryption processing means, encrypts it with an encryption key unique to the device, generates service usage identification information, and the transmission means The generated service use identification information is transmitted to the service providing server. Therefore, when the service use identification information generating device generates an ID using an encryption key that is different for each service, information related to the user is given to the generated ID itself, and the entire device is encrypted unique to the device. Since the information is encrypted with the key, the information about the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.

(2)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)と、信頼できる第三者機関が管理しユーザ認証を行うとともにユーザがサービスを利用するためのサービス利用識別情報を生成する管理サーバとからなるサービス利用識別情報生成システムであって、前記管理サーバが、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、信頼できる第三者機関固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成システムを提案している。   (2) The present invention is reliable with a user terminal (for example, equivalent to the user terminal 100 in FIG. 1), a service providing server managed by the service provider (for example, equivalent to the service providing server 300 in FIG. 1), A service usage identification information generation system comprising a management server that manages a user and authenticates a user and generates service usage identification information for the user to use the service, wherein the management server includes user login information. And receiving means (e.g., corresponding to the receiving unit 21 in FIG. 2), and adding the additional information to the received login information of the user, and encrypting with a different encryption key for each service provided by the user Encryption processing means (e.g., corresponding to the encryption unit 22 in FIG. 2), and information related to the user in the information encrypted by the encryption processing means. Service usage identification information generating means (for example, corresponding to the service usage identification information generating unit 24 in FIG. 2) that generates service usage identification information by encrypting with an encryption key unique to a trusted third party organization, Proposing a service usage identification information generation system comprising transmission means for transmitting the generated service usage identification information to the service providing server (for example, corresponding to the transmission unit 25 in FIG. 2). .

この発明によれば、管理サーバ内の受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、管理サーバが、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。また、サービス提供サーバは、自身が持つ秘密鍵により復号化を行い、サービス利用のためのIDと、利用者情報とを個別の通信を行うことなく取得することができる。   According to this invention, the receiving means in the management server receives the user's login information, and the encryption processing means gives additional information to the received user's login information, and varies depending on the service the user receives. Encrypt with encryption key. Then, the service usage identification information generating means adds information about the user to the information encrypted by the encryption processing means, encrypts it with an encryption key unique to the device, generates service usage identification information, and the transmission means The generated service use identification information is transmitted to the service providing server. Therefore, when the management server generates an ID using a different encryption key for each service, information on the user is given to the generated ID itself, and the whole is encrypted with a device-specific encryption key. Therefore, information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information. In addition, the service providing server can perform decryption using its own private key, and can acquire the ID for using the service and the user information without performing individual communication.

(3)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)とにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置であって、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバとの間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成装置を提案している。   (3) The present invention connects a user terminal (for example, equivalent to the user terminal 100 in FIG. 1) and a service providing server (for example, equivalent to the service providing server 300 in FIG. 1) managed by the service provider via a network. A service use identification information generating apparatus for generating service use identification information for identifying the user when the service providing server uses the service, and receiving means for receiving user login information ( For example, it corresponds to the receiving unit 21 in FIG. 2) and an encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user ( For example, it corresponds to the encryption unit 22 in FIG. 2), and information related to the user is added to the information encrypted by the encryption processing means, and the service Service usage identification information generating means (for example, corresponding to the service usage identification information generating unit 24 in FIG. 2) that generates service usage identification information by encrypting with an encryption key shared with the providing server, and the generated A service use identification information generating apparatus is provided, characterized in that it comprises transmission means for transmitting service use identification information to the service providing server (for example, corresponding to the transmission unit 25 in FIG. 2).

この発明によれば、受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、サービス提供サーバとの間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、サービス利用識別情報生成装置が、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバとの間で共有された暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。   According to this invention, the receiving means receives the user's login information, and the encryption processing means adds additional information to the received user's login information, and uses an encryption key that differs for each service that the user receives. Encrypt. Then, the service use identification information generating means gives the information about the user to the information encrypted by the encryption processing means, and encrypts it with the encryption key shared with the service providing server, so that the service use identification information And the service use identification information generated by the transmission means is transmitted to the service providing server. Therefore, when the service use identification information generating device generates an ID using an encryption key that is different for each service, the information about the user is given to the generated ID itself, and the whole is connected to the service providing server. Since the information is encrypted with the encryption key shared between the users, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.

(4)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)と、信頼できる第三者機関が管理しユーザ認証を行うとともにユーザがサービスを利用するためのサービス利用識別情報を生成する管理サーバとからなるサービス利用識別情報生成システムであって、前記管理サーバが、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバと前記信頼できる第三者機関との間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成システムを提案している。   (4) The present invention provides a user terminal (for example, equivalent to the user terminal 100 in FIG. 1), a service providing server managed by the service provider (for example, equivalent to the service providing server 300 in FIG. 1), and a reliable first. A service usage identification information generation system comprising a management server that manages a user and authenticates a user and generates service usage identification information for the user to use the service, wherein the management server includes user login information. And receiving means (e.g., corresponding to the receiving unit 21 in FIG. 2), and adding the additional information to the received login information of the user, and encrypting with a different encryption key for each service provided by the user Encryption processing means (e.g., corresponding to the encryption unit 22 in FIG. 2), and information related to the user in the information encrypted by the encryption processing means. Service usage identification information generating means for generating service usage identification information by encrypting with an encryption key shared between the service providing server and the trusted third party organization (for example, service usage in FIG. 2) And a transmission means (for example, corresponding to the transmission unit 25 in FIG. 2) for transmitting the generated service use identification information to the service providing server. A service usage identification information generation system is proposed.

この発明によれば、管理サーバ内の受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、サービス提供サーバと信頼できる第三者機関との間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、管理サーバが、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバと信頼できる第三者機関との間で共有された暗号化鍵で暗号化するため、利用者に関する情報を、IDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。また、サービス提供サーバは、サービス提供サーバと信頼できる第三者機関との間で共有された暗号化鍵により復号化を行い、サービス利用のためのIDと、利用者情報とを個別の通信を行うことなく取得することができる。   According to this invention, the receiving means in the management server receives the user's login information, and the encryption processing means gives additional information to the received user's login information, and varies depending on the service the user receives. Encrypt with encryption key. Then, the service use identification information generating means adds information about the user to the information encrypted by the encryption processing means, and uses an encryption key shared between the service providing server and a trusted third party. The service use identification information is generated by encryption, and the service use identification information generated by the transmission unit is transmitted to the service providing server. Therefore, when the management server generates an ID using an encryption key that is different for each service, information related to the user is given to the generated ID itself, and the whole is trusted by the service providing server. In order to encrypt with the encryption key shared with the institution, the information about the user is concealed from those other than the TTP that has generated the ID and the service provider server that receives the information. be able to. In addition, the service providing server performs decryption using an encryption key shared between the service providing server and a trusted third party, and individually communicates the ID for using the service and the user information. You can get it without doing it.

(5)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法であって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、を有することを特徴とするサービス利用識別情報生成方法を提案している。   (5) The present invention is connected to a user terminal and a service providing server managed by the service provider via a network, and the service providing server identifies the user when the service is used by the user. A service usage identification information generation method in a service usage identification information generation apparatus that generates identification information, which is a first step (for example, corresponding to steps S101 and S102 in FIG. 3) for adding additional information to the received user login information. ), And a second step (for example, corresponding to step S103 in FIG. 3) of encrypting information in which additional information is added to the login information of the user with a different encryption key for each service provided by the user, A third step of adding information about the user to the encrypted information (for example, step S10 in FIG. 3) And a fourth step (for example, corresponding to step S105 in FIG. 3) of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generating device And a service usage identification information generation method characterized by having

この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、この暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。   According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with an encryption key unique to the service use identification information generating apparatus. Therefore, when generating an ID using a different encryption key for each service, information on the user is given to the generated ID itself, and the whole is encrypted with an encryption key unique to the service use identification information generating device. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.

(6)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法であって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、を有することを特徴とするサービス利用識別情報生成方法を提案している。   (6) The present invention is connected to a user terminal and a service providing server managed by a service provider via a network, and the service providing server identifies the user when the service is used by the user. A service usage identification information generation method in a service usage identification information generation apparatus that generates identification information, which is a first step (for example, corresponding to steps S101 and S102 in FIG. 3) for adding additional information to the received user login information. ), And a second step (for example, corresponding to step S103 in FIG. 3) of encrypting information in which additional information is added to the login information of the user with a different encryption key for each service provided by the user, A third step of adding information about the user to the encrypted information (for example, step S10 in FIG. 3) And a fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key shared between the service providing server and the service use identification information generating device. (For example, corresponding to step S105 in FIG. 3) is proposed.

この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、暗号化された情報に利用者に関する情報を付与した情報をサービス提供サーバとの間で共有された暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバとの間で共有された暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。   According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with the encryption key shared with the service providing server. Therefore, when generating an ID using an encryption key that differs for each service, information about the user is given to the generated ID itself, and the entire encryption key is shared with the service providing server. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.

(7)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法をコンピュータに実行させるためのプログラムであって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、をコンピュータに実行させるためのプログラムを提案している。   (7) The present invention is connected to a user terminal and a service providing server managed by a service provider via a network, and the service providing server identifies the user when the service is used by the user. A program for causing a computer to execute a service usage identification information generation method in a service usage identification information generation apparatus for generating identification information, and a first step of adding additional information to received user login information (for example, FIG. And a second step (for example, FIG. 3) of encrypting information obtained by adding additional information to the login information of the user with a different encryption key for each service provided by the user. Step S103), and information about the user is added to the encrypted information. Step (for example, corresponding to step S104 in FIG. 3), and a fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generation device (For example, corresponding to step S105 in FIG. 3) is proposed.

この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。   According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with an encryption key unique to the service use identification information generating apparatus. Therefore, when generating an ID using a different encryption key for each service, information on the user is given to the generated ID itself, and the whole is encrypted with an encryption key unique to the service use identification information generating device. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.

(8)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法をコンピュータに実行させるためのプログラムであって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、をコンピュータに実行させるためのプログラムを提案している。   (8) The present invention is connected to a user terminal and a service providing server managed by a service provider via a network, and the service providing server identifies the user when the service is used by the user. A program for causing a computer to execute a service usage identification information generation method in a service usage identification information generation apparatus for generating identification information, and a first step of adding additional information to received user login information (for example, FIG. And a second step (for example, FIG. 3) of encrypting information obtained by adding additional information to the login information of the user with a different encryption key for each service provided by the user. Step S103), and information about the user is added to the encrypted information. (For example, corresponding to step S104 in FIG. 3), and information obtained by adding information about the user to the encrypted information is shared between the service providing server and the service use identification information generating device. A program for causing a computer to execute a fourth step (for example, corresponding to step S105 in FIG. 3) of encrypting with an encryption key is proposed.

この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、暗号化された情報に利用者に関する情報を付与した情報をサービス提供サーバとの間で共有された暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバとの間で共有された暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。   According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with the encryption key shared with the service providing server. Therefore, when generating an ID using an encryption key that differs for each service, information about the user is given to the generated ID itself, and the entire encryption key is shared with the service providing server. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.

本発明によれば、ID自身に情報を付与することができ、しかも、第三者にはその情報が理解できないという効果がある。また、ID自身に利用者の情報が付与されているので、サービス提供者とTTPの間で、利用者の情報取得に本来必要な通信を行なう必要がないという効果がある。   According to the present invention, information can be given to the ID itself, and there is an effect that the third party cannot understand the information. Further, since the user information is given to the ID itself, there is an effect that it is not necessary to perform communication originally necessary for acquiring the user information between the service provider and the TTP.

また、本発明によれば、付与した情報を隠蔽するための暗号化処理にあたり、サービス提供者の認証に利用する公開鍵証明書を添付した公開鍵を利用できるため、付加的情報を必要としないという効果がある。さらに、上記の公開鍵の利用の他に、TTPとサービス提供者間で事前に共有された共有鍵を利用することもできるが、この場合、必要な情報の増加量としては、サービスひとつに対して、暗号化のための鍵ひとつであるため、サービス提供者、TTP双方にとって大きな負担とはならないという効果がある。   In addition, according to the present invention, since the public key attached with the public key certificate used for authentication of the service provider can be used in the encryption process for concealing the assigned information, no additional information is required. There is an effect. Furthermore, in addition to the use of the public key described above, a shared key shared in advance between the TTP and the service provider can be used. In this case, the amount of necessary information is increased for one service. Since this is one key for encryption, there is an effect that it does not become a heavy burden on both the service provider and TTP.

以下、本発明の実施形態について、図面を用いて、詳細に説明する。
なお、本実施形態における構成要素は適宜、既存の構成要素等との置き換えが可能であり、また、他の既存の構成要素との組合せを含む様々なバリエーションが可能である。したがって、本実施形態の記載をもって、特許請求の範囲に記載された発明の内容を限定するものではない。
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
Note that the constituent elements in the present embodiment can be appropriately replaced with existing constituent elements and the like, and various variations including combinations with other existing constituent elements are possible. Therefore, the description of the present embodiment does not limit the contents of the invention described in the claims.

<サービス利用識別情報生成システムの構成>
本実施形態に係るサービス利用識別情報生成システムは、図1に示すように、ユーザ端末100と、サービス利用識別情報生成装置または管理サーバとしてのTTP200と、サービス提供サーバ300とから構成され、これらユーザ端末100、管理サーバとしてのTTP200、サービス提供サーバ300は、それぞれネットワークを介して接続されている。
<Configuration of service usage identification information generation system>
As shown in FIG. 1, the service usage identification information generation system according to the present embodiment includes a user terminal 100, a TTP 200 as a service usage identification information generation device or a management server, and a service providing server 300. The terminal 100, the TTP 200 as a management server, and the service providing server 300 are connected via a network.

ユーザ端末100は、サービス提供サーバ300に対する接続要求をサービス利用識別情報生成装置または管理サーバとしてのTTP200に送信する。また、サービスの提供をはじめて受ける場合には、サービス利用識別情報生成装置または管理サーバとしてのTTP200に対して、IDの生成要求を発行し、管理サーバとしてのTTP200から取得したサービス利用IDに基づき、サービス提供サーバ300によるサービスの提供を受ける。   The user terminal 100 transmits a connection request to the service providing server 300 to the TTP 200 serving as a service use identification information generating device or a management server. In addition, when receiving a service for the first time, an ID generation request is issued to the service use identification information generating device or the TTP 200 as the management server, and based on the service use ID acquired from the TTP 200 as the management server, The service is provided by the service providing server 300.

サービス利用識別情報生成装置または管理サーバとしてのTTP200は、信頼のおける第三者機関が管理するサーバであって、その詳細な構成については後述する。本実施形態においては、図2における受信部21が、ユーザ端末100からログイン情報を受信し、暗号化部22が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成部24が、暗号化部22において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成し、送信部25が生成したサービス利用識別情報をサービス提供サーバ300に送信する。   The TTP 200 as a service use identification information generating device or a management server is a server managed by a reliable third party organization, and the detailed configuration thereof will be described later. In the present embodiment, the receiving unit 21 in FIG. 2 receives login information from the user terminal 100, and the encryption unit 22 provides additional information to the received login information of the user so that the user can receive the service. Encryption is performed with a different encryption key for each. Then, the service use identification information generation unit 24 adds information about the user to the information encrypted by the encryption unit 22, generates service use identification information by encrypting with the device-specific encryption key, and transmits the transmission unit. The service use identification information generated by the server 25 is transmitted to the service providing server 300.

サービス提供サーバ300は、サービス利用識別情報生成装置または管理サーバとしてのTTP200から通知されたIDにより、ユーザを識別し、ユーザの管理を実行するとともに、利用者情報を取得する。   The service providing server 300 identifies the user based on the ID notified from the service use identification information generating apparatus or the TTP 200 as the management server, executes user management, and acquires user information.

<生成されるIDの構成>
次に、図4から図6を用いて、本実施形態において、生成されるIDの構成について説明する。
まず、図4に示すように、ユーザ端末100のそれぞれが有するサービス利用識別情報生成装置または管理サーバとしてのTTP200へのログインID(IDu)に所定の付加情報(Sinfo)を結合する。そして、この結合された情報をサービスごとに異なる暗号化鍵(Kn)で暗号化する。さらに、この情報に、利用者の情報を結合し、この結合された情報をサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PK)で暗号化して、これを利用者情報が付与されたユーザIDデータとする。なお、サービス提供サーバ300では、図6に示すように、TTP200から送信された利用者情報が付与されたユーザIDデータをサービス提供サーバ300が有する秘密鍵(SK)で復号して、それぞれIDとして、あるいは、ユーザの情報として利用する。
<Configuration of generated ID>
Next, the configuration of an ID generated in the present embodiment will be described with reference to FIGS.
First, as shown in FIG. 4, predetermined additional information (Sinfo) is combined with a login ID (IDu) to the TTP 200 as a service use identification information generating device or a management server that each user terminal 100 has. The combined information is encrypted with a different encryption key (Kn) for each service. Further, the information of the user is combined with this information, and the combined information is encrypted with the encryption key (PK S ) unique to the TTP 200 as the service use identification information generating device or the management server, and this is used by the user. It is assumed that the user ID data is given information. In the service providing server 300, as shown in FIG. 6, the user ID data to which the user information transmitted from the TTP 200 is added is decrypted with the secret key (SK S ) of the service providing server 300. Or as user information.

次に、図5の場合には、ユーザ端末100のそれぞれが有するサービス利用識別情報生成装置または管理サーバとしてのTTP200へのログインID(IDu)に所定の付加情報(Sinfo)を結合する。そして、この結合された情報をサービスごとに異なる暗号化鍵(Kn)で暗号化する。さらに、この情報に、利用者の情報を結合し、この結合された情報をサービス利用識別情報生成装置または管理サーバとしてのTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)で暗号化して、これを利用者情報が付与されたユーザIDデータとする。なお、サービス提供サーバ300では、TTP200から送信された利用者情報が付与されたユーザIDデータをサービス提供サーバ300が有する共有鍵(KS−TTP)で復号して、それぞれIDとして、あるいは、ユーザの情報として利用する。 Next, in the case of FIG. 5, predetermined additional information (Sinfo) is combined with a login ID (IDu) to the TTP 200 as a service use identification information generating device or a management server of each user terminal 100. The combined information is encrypted with a different encryption key (Kn) for each service. Further, the information of the user is combined with this information, and the combined information is combined with the encryption key (K S-TTP ) shared between the TTP 200 serving as the service use identification information generating device or the management server and the service providing server 300. This is encrypted as user ID data to which user information is assigned. In the service providing server 300, the user ID data to which the user information transmitted from the TTP 200 is added is decrypted with the shared key (K S-TTP ) possessed by the service providing server 300, and each is used as an ID or a user. Use as information.

したがって、サービス利用識別情報生成装置または管理サーバとしてのTTP200が、サービスごとに異なる暗号化鍵(Kn)を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PK)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)で暗号化するため、利用者に関する情報を第三者に対して秘匿化することができ、さらに、全体をひとつのIDとすることができる。 Therefore, when the TTP 200 serving as the service use identification information generation device or the management server generates an ID using an encryption key (Kn) that is different for each service, information about the user is given to the generated ID itself, In order to encrypt the whole with the encryption key (PK S ) unique to the TTP 200 as the service use identification information generating device or the management server, or the encryption key (K S-TTP ) shared by the TTP 200 and the service providing server 300. The information about the user can be concealed from a third party, and the whole can be set as one ID.

<サービス利用識別情報生成装置の構成>
本実施形態に係るサービス利用識別情報生成装置は、図2に示すように、受信部21と、暗号化部22と、鍵データベース23と、サービス利用識別情報生成部24と、送信部25とから構成されている。
<Configuration of Service Usage Identification Information Generation Device>
As shown in FIG. 2, the service usage identification information generation apparatus according to the present embodiment includes a reception unit 21, an encryption unit 22, a key database 23, a service usage identification information generation unit 24, and a transmission unit 25. It is configured.

受信部21は、ユーザ端末100からサービス提供サーバ300に対する接続要求を受信する。なお、この際、サービス利用識別情報生成装置または管理サーバとしてのTTP200に対するログインIDも併せて受信する。   The receiving unit 21 receives a connection request for the service providing server 300 from the user terminal 100. At this time, a login ID for the TTP 200 as the service use identification information generation device or the management server is also received.

暗号化部22は、受信部21が受信したユーザのログインID(IDu)に所定の付加情報(Sinfo)を結合するとともに、鍵データベース23内に格納されたサービスごとに異なる暗号化鍵(Kn)を用いて、上記結合した情報を暗号化する。なお、所定の付加情報(Sinfo)は、IDの生成時刻のように動的に変動するものでもよいし、固定のビット列でもよい。   The encryption unit 22 combines predetermined additional information (Sinfo) with the user's login ID (IDu) received by the reception unit 21, and different encryption keys (Kn) for each service stored in the key database 23. Is used to encrypt the combined information. The predetermined additional information (Sinfo) may be dynamically changed like the ID generation time, or may be a fixed bit string.

鍵データベース30は、サービスごとに異なる暗号化鍵(Kn)およびサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PK)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)を格納する。なお、データベースは、ハードディスク、RAM(Random Access Memory)であってもよく、また、単一のハードウェアで構成されている必要はなく、個別の記録部や専用装置であってもよい。 The key database 30 includes an encryption key (Kn) that is different for each service and an encryption key (PK S ) unique to the TTP 200 serving as a service use identification information generating device or a management server, or an encryption shared by the TTP 200 and the service providing server 300. Stores the key (K S-TTP ). The database may be a hard disk or a RAM (Random Access Memory), and may not be configured by a single piece of hardware, but may be an individual recording unit or a dedicated device.

サービス利用識別情報生成部24は、上記暗号化部22において暗号化された情報に利用者に関する情報を結合し、この結合した情報を鍵データベース23内に格納されたサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PK)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)でさらに暗号化して利用者情報が付与されたユーザIDデータを生成する。 The service usage identification information generation unit 24 combines information about the user with the information encrypted by the encryption unit 22, and combines the combined information with the service usage identification information generation device or management stored in the key database 23. Generate user ID data with user information by further encrypting with an encryption key (PK S ) unique to the TTP 200 as a server or an encryption key (K S-TTP ) shared by the TTP 200 and the service providing server 300 To do.

送信部25は、サービス利用識別情報生成部24において生成されたサービス利用識別情報をサービス提供サーバ300に送信する。   The transmission unit 25 transmits the service usage identification information generated by the service usage identification information generation unit 24 to the service providing server 300.

<サービス利用識別情報生成システムの処理>
次に、図3を用いて、本実施形態に係るサービス利用識別情報生成システムの処理について説明する。
<Processing of service use identification information generation system>
Next, processing of the service use identification information generation system according to the present embodiment will be described with reference to FIG.

まず、サービス利用識別情報生成装置の受信部21がユーザ端末100からサービス提供サーバ300への接続仲介要求を受信する(ステップS101)。なお、このとき、同時に、サービス利用識別情報生成装置または管理サーバとしてのTTP200に対するログインIDも併せて受信する。   First, the receiving unit 21 of the service use identification information generating apparatus receives a connection mediation request from the user terminal 100 to the service providing server 300 (step S101). At this time, a login ID for the TTP 200 as the service use identification information generation device or the management server is also received.

暗号化部22は、受信部21からユーザのログインID(IDu)を入力すると、これに、所定の付加情報(Sinfo)を結合するとともに(ステップS102)、鍵データベース23内に格納されたサービスごとに異なる暗号化鍵(Kn)を用いて、上記結合した情報を暗号化する(ステップS103)。   When the user's login ID (IDu) is input from the receiving unit 21, the encryption unit 22 combines predetermined additional information (Sinfo) with this (step S 102), and for each service stored in the key database 23. The combined information is encrypted using a different encryption key (Kn) (step S103).

サービス利用識別情報生成部24は、暗号化部22から暗号化された情報を入力すると、この情報に利用者に関する情報を結合し(ステップS104)、この結合した情報を鍵データベース23内に格納されたサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PK)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)でさらに暗号化して利用者情報が付与されたユーザIDデータを生成する(ステップS105)。 When the service use identification information generation unit 24 receives the encrypted information from the encryption unit 22, the service use identification information generation unit 24 combines the information about the user with this information (step S 104), and the combined information is stored in the key database 23. The user information is further encrypted with the encryption key (PK S ) unique to the TTP 200 as the service use identification information generating apparatus or the management server or the encryption key (K S-TTP ) shared by the TTP 200 and the service providing server 300. Is generated (step S105).

したがって、本実施形態によれば、サービス利用識別情報生成装置または管理サーバとしてのTTP200が、サービスごとに異なる暗号化鍵(Kn)を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PK)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)で暗号化するため、利用者に関する情報を第三者に対して秘匿化することができ、さらに、全体をひとつのIDとすることができる。 Therefore, according to the present embodiment, when the TTP 200 as the service use identification information generation device or the management server generates an ID using an encryption key (Kn) that is different for each service, the information about the user is generated. Further, the entire ID is assigned to the ID itself, and further, the entire encryption key (PK S ) unique to the TTP 200 as the service use identification information generating device or the management server, or the encryption key (K S− Since the information is encrypted with TTP ), information about the user can be kept secret from a third party, and the whole can be made into one ID.

なお、サービス利用識別情報生成装置およびサービス利用識別情報生成システムのそれぞれの処理をコンピュータ読み取り可能な記録媒体に記録し、この記録媒体に記録されたプログラムをサービス利用識別情報生成装置およびサービス利用識別情報生成システムに読み込ませ、実行することによって本発明のサービス利用識別情報生成装置およびサービス利用識別情報生成システムを実現することができる。ここでいうコンピュータシステムとは、OSや周辺装置等のハードウェアを含む。   Each process of the service usage identification information generation apparatus and the service usage identification information generation system is recorded on a computer-readable recording medium, and the program recorded on the recording medium is stored in the service usage identification information generation apparatus and the service usage identification information. The service use identification information generation apparatus and service use identification information generation system of the present invention can be realized by causing the generation system to read and execute. The computer system here includes an OS and hardware such as peripheral devices.

また、「コンピュータシステム」は、WWW(World Wide Web)システムを利用している場合であれば、ホームページ提供環境(あるいは表示環境)も含むものとする。また、上記プログラムは、このプログラムを記憶装置等に格納したコンピュータシステムから、伝送媒体を介して、あるいは、伝送媒体中の伝送波により他のコンピュータシステムに伝送されても良い。ここで、プログラムを伝送する「伝送媒体」は、インターネット等のネットワーク(通信網)や電話回線等の通信回線(通信線)のように情報を伝送する機能を有する媒体のことをいう。   Further, the “computer system” includes a homepage providing environment (or display environment) if a WWW (World Wide Web) system is used. The program may be transmitted from a computer system storing the program in a storage device or the like to another computer system via a transmission medium or by a transmission wave in the transmission medium. Here, the “transmission medium” for transmitting the program refers to a medium having a function of transmitting information, such as a network (communication network) such as the Internet or a communication line (communication line) such as a telephone line.

また、上記プログラムは、前述した機能の一部を実現するためのものであっても良い。さらに、前述した機能をコンピュータシステムにすでに記録されているプログラムとの組合せで実現できるもの、いわゆる差分ファイル(差分プログラム)であっても良い。   The program may be for realizing a part of the functions described above. Furthermore, what can implement | achieve the function mentioned above in combination with the program already recorded on the computer system, and what is called a difference file (difference program) may be sufficient.

以上、この発明の実施形態につき、図面を参照して詳述してきたが、具体的な構成はこの実施形態に限られるものではなく、この発明の要旨を逸脱しない範囲の設計等も含まれる。   The embodiment of the present invention has been described in detail with reference to the drawings. However, the specific configuration is not limited to this embodiment, and includes a design and the like within a scope not departing from the gist of the present invention.

本実施形態に係るサービス利用識別情報生成システムの構成図である。It is a block diagram of the service use identification information generation system which concerns on this embodiment. 本実施形態に係るサービス利用識別情報生成装置の構成図である。It is a block diagram of the service use identification information generation apparatus which concerns on this embodiment. 本実施形態に係るサービス利用識別情報生成システムの処理フローである。It is a processing flow of the service use identification information generation system which concerns on this embodiment. 本実施形態に係るサービス利用識別情報の構成を示す図である。It is a figure which shows the structure of the service use identification information which concerns on this embodiment. 本実施形態に係るサービス利用識別情報の構成を示す図である。It is a figure which shows the structure of the service use identification information which concerns on this embodiment. 本実施形態に係るサービス利用識別情報の複号化処理を示す図である。It is a figure which shows the decoding process of the service use identification information which concerns on this embodiment. 従来のシステム構成を示す図である。It is a figure which shows the conventional system configuration.

符号の説明Explanation of symbols

21・・・受信部
22・・・暗号化部
23・・・鍵データベース
24・・・サービス利用識別情報生成部
25・・・送信部
100・・・ユーザ端末
200・・・TTP
300・・・サービス提供サーバ
DESCRIPTION OF SYMBOLS 21 ... Reception part 22 ... Encryption part 23 ... Key database 24 ... Service use identification information generation part 25 ... Transmission part 100 ... User terminal 200 ... TTP
300 ... Service providing server

Claims (8)

ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置であって、
ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成装置。
Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. An identification information generating device,
Receiving means for receiving user login information;
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service usage identification information generating means for generating service usage identification information by giving information about a user to the information encrypted in the encryption processing means, and encrypting with a device-specific encryption key;
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generating device comprising:
ユーザ端末と、サービス提供者が管理するサービス提供サーバと、信頼できる第三者機関が管理しユーザ認証を行うとともにユーザがサービスを利用するためのサービス利用識別情報を生成する管理サーバとからなるサービス利用識別情報生成システムであって、
前記管理サーバが、ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、信頼できる第三者機関固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成システム。
A service comprising a user terminal, a service providing server managed by a service provider, and a management server that is managed by a trusted third party to perform user authentication and generate service use identification information for the user to use the service A usage identification information generation system,
The management server receives a user login information; and
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service usage identification information generating means for generating service usage identification information by giving information about the user to the information encrypted in the encryption processing means, and encrypting with an encryption key unique to a reliable third party organization;
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generation system comprising:
ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置であって、
ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバとの間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成装置。
Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. An identification information generating device,
Receiving means for receiving user login information;
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service use identification information generation for adding service information to the information encrypted by the encryption processing means and generating service use identification information by encrypting with an encryption key shared with the service providing server Means,
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generating device comprising:
ユーザ端末と、サービス提供者が管理するサービス提供サーバと、信頼できる第三者機関が管理しユーザ認証を行うとともにユーザがサービスを利用するためのサービス利用識別情報を生成する管理サーバとからなるサービス利用識別情報生成システムであって、
前記管理サーバが、ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバと前記信頼できる第三者機関との間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成システム。
A service comprising a user terminal, a service providing server managed by a service provider, and a management server that is managed by a trusted third party to perform user authentication and generate service use identification information for the user to use the service A usage identification information generation system,
The management server receives a user login information; and
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service usage identification information obtained by adding information about a user to the information encrypted by the encryption processing means and encrypting the information with an encryption key shared between the service providing server and the trusted third party organization. Service usage identification information generating means for generating
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generation system comprising:
ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法であって、
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップと、
を有することを特徴とするサービス利用識別情報生成方法。
Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generating device;
A service use identification information generation method characterized by comprising:
ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法であって、
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップと、
を有することを特徴とするサービス利用識別情報生成方法。
Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about a user to the encrypted information with an encryption key shared between the service providing server and the service use identification information generating device;
A service use identification information generation method characterized by comprising:
ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法をコンピュータに実行させるためのプログラムであって、
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップと、
をコンピュータに実行させるためのプログラム。
Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A program for causing a computer to execute a service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generating device;
A program that causes a computer to execute.
ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法をコンピュータに実行させるためのプログラムであって、
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップと、
をコンピュータに実行させるためのプログラム。
Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A program for causing a computer to execute a service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about a user to the encrypted information with an encryption key shared between the service providing server and the service use identification information generating device;
A program that causes a computer to execute.
JP2007079016A 2007-03-26 2007-03-26 Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program Expired - Fee Related JP4989996B2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP2007079016A JP4989996B2 (en) 2007-03-26 2007-03-26 Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP2007079016A JP4989996B2 (en) 2007-03-26 2007-03-26 Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program

Publications (2)

Publication Number Publication Date
JP2008242585A true JP2008242585A (en) 2008-10-09
JP4989996B2 JP4989996B2 (en) 2012-08-01

Family

ID=39913895

Family Applications (1)

Application Number Title Priority Date Filing Date
JP2007079016A Expired - Fee Related JP4989996B2 (en) 2007-03-26 2007-03-26 Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program

Country Status (1)

Country Link
JP (1) JP4989996B2 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2015519636A (en) * 2012-04-09 2015-07-09 ミディアム、アクセス、システムズ、プライベート、リミテッドMedium Access Systemsprivate Ltd. Method and system for providing secure transactions using cyber IDs

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005056393A (en) * 2003-07-24 2005-03-03 Ricoh Co Ltd User authentication method, image forming apparatus, and user authentication program
JP2005311904A (en) * 2004-04-23 2005-11-04 Ntt Docomo Inc Authentication system
JP2006244420A (en) * 2005-03-07 2006-09-14 Kddi R & D Laboratories Inc Identification information generation management device, and its system and program

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005056393A (en) * 2003-07-24 2005-03-03 Ricoh Co Ltd User authentication method, image forming apparatus, and user authentication program
JP2005311904A (en) * 2004-04-23 2005-11-04 Ntt Docomo Inc Authentication system
JP2006244420A (en) * 2005-03-07 2006-09-14 Kddi R & D Laboratories Inc Identification information generation management device, and its system and program

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2015519636A (en) * 2012-04-09 2015-07-09 ミディアム、アクセス、システムズ、プライベート、リミテッドMedium Access Systemsprivate Ltd. Method and system for providing secure transactions using cyber IDs

Also Published As

Publication number Publication date
JP4989996B2 (en) 2012-08-01

Similar Documents

Publication Publication Date Title
US11676133B2 (en) Method and system for mobile cryptocurrency wallet connectivity
JP5006817B2 (en) Authentication information generation system, authentication information generation method, client device, and program
US10735186B2 (en) Revocable stream ciphers for upgrading encryption in a shared resource environment
CN102571329B (en) Password key management
US9372987B1 (en) Apparatus and method for masking a real user controlling synthetic identities
CN105022966A (en) Database data encryption and decryption method and system
US10063655B2 (en) Information processing method, trusted server, and cloud server
US20090210720A1 (en) Method for generating one-time password
JP5404501B2 (en) Encrypted information expiration date extension system, expiration date extension method and program
Thilakanathan et al. Secure multiparty data sharing in the cloud using hardware-based TPM devices
JP5678150B2 (en) User terminal, key management system, and program
JP5494171B2 (en) File management system, storage server, client, file management method and program
CN113779629A (en) Key file sharing method, device, processor chip and server
JP5139045B2 (en) Content distribution system, content distribution method and program
JP4989996B2 (en) Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program
JP4637612B2 (en) Identification information generation management device, system, and program
JP2002077134A (en) Server / client system, data server, data client, data providing / using method, and recording medium
JP2007058487A (en) Login information management apparatus and method
CN116781400A (en) A method, system, device and electronic equipment for data processing on the blockchain
JP2009055428A (en) Information processing apparatus, server apparatus, information processing program, and method
JP4945265B2 (en) Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program
JP2006279269A (en) Information management apparatus, information management system, network system, user terminal, and programs thereof
JP4679934B2 (en) Identification information generation management device, system, and program
JP2016163198A (en) File management device, file management system, file management method, and file management program
Damsika et al. A novel mechanism for secure e-tendering in an open electronic network

Legal Events

Date Code Title Description
A621 Written request for application examination

Free format text: JAPANESE INTERMEDIATE CODE: A621

Effective date: 20090708

A977 Report on retrieval

Free format text: JAPANESE INTERMEDIATE CODE: A971007

Effective date: 20111207

A131 Notification of reasons for refusal

Free format text: JAPANESE INTERMEDIATE CODE: A131

Effective date: 20111220

A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20120214

TRDD Decision of grant or rejection written
A01 Written decision to grant a patent or to grant a registration (utility model)

Free format text: JAPANESE INTERMEDIATE CODE: A01

Effective date: 20120417

A01 Written decision to grant a patent or to grant a registration (utility model)

Free format text: JAPANESE INTERMEDIATE CODE: A01

A61 First payment of annual fees (during grant procedure)

Free format text: JAPANESE INTERMEDIATE CODE: A61

Effective date: 20120501

R150 Certificate of patent or registration of utility model

Free format text: JAPANESE INTERMEDIATE CODE: R150

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20150511

Year of fee payment: 3

S533 Written request for registration of change of name

Free format text: JAPANESE INTERMEDIATE CODE: R313533

R350 Written notification of registration of transfer

Free format text: JAPANESE INTERMEDIATE CODE: R350

LAPS Cancellation because of no payment of annual fees