JP2008242585A - Service use identification creating device, service use identification creation system, service use identification creation method, and program - Google Patents
Service use identification creating device, service use identification creation system, service use identification creation method, and program Download PDFInfo
- Publication number
- JP2008242585A JP2008242585A JP2007079016A JP2007079016A JP2008242585A JP 2008242585 A JP2008242585 A JP 2008242585A JP 2007079016 A JP2007079016 A JP 2007079016A JP 2007079016 A JP2007079016 A JP 2007079016A JP 2008242585 A JP2008242585 A JP 2008242585A
- Authority
- JP
- Japan
- Prior art keywords
- service
- information
- user
- identification information
- providing server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Abstract
Description
本発明は、ユーザIDに対して付加的な情報および利用者に関する情報を付与するとともに、この情報を第三者に対して秘匿化するサービス利用識別情報生成装置、サービス利用識別情報生成システム、サービス利用識別情報生成方法およびプログラムに関する。 The present invention provides a service use identification information generating apparatus, a service use identification information generating system, a service, which gives additional information and information about a user to a user ID and conceals this information from a third party. The present invention relates to a usage identification information generation method and program.
従来、図7に示すように、インターネット上でサービス利用の利便性を向上させる技術として、ユーザ端末100と、信頼のおける第三者機関(TTP:Trusted Third Party)200と、サービス提供サーバ300とからなるシステムにおいて、このTTP200を利用したシングルサインオン(SSO:Single Sign On)と呼ばれる技術がある。 Conventionally, as shown in FIG. 7, as a technique for improving the convenience of service use on the Internet, a user terminal 100, a trusted third party (TTP) 200, a service providing server 300, There is a technology called Single Sign On (SSO) using the TTP 200.
このTTP200を利用するSSO技術では、その利用にあたり、ユーザのプライバシーを保護するために、ユーザが利用するサービス(サービス提供者)に対して、サービスごとにID(Identifier)を変更することが必要とされる。これは、異なるサービスに対して同じIDを利用させてしまうと、サービス提供側が結託した場合に、それぞれのサービスにおけるユーザの行動を付き合わせることができてしまうためである。 In the SSO technology using the TTP 200, in order to protect the user's privacy, it is necessary to change the ID (Identifier) for each service with respect to the service (service provider) used by the user. Is done. This is because if the same ID is used for different services, the user's actions in each service can be associated with each other when the service provider collaborates.
また、サービスごとにIDを変更することに加えて、接続ごとにもIDを変更することが必要とされている。すなわち、同じサービスであっても、常に同じIDで利用し続けた場合には、そのユーザの行動をトレースできてしまうためである。この場合、特定のユーザの行動をトレースできることを利用して、ショッピングサイトのように、お勧め商品の紹介(リコメンデーションサービスあるいは、パーソナライゼーションサービスと呼ぶ)を提供することも可能となるが、その一方で、ユーザによっては、このようにユーザ自身の行動が把握されることを嫌がる可能性もある。 In addition to changing the ID for each service, it is also necessary to change the ID for each connection. That is, even if the service is the same, if the user always uses the same ID, the user's action can be traced. In this case, it is possible to provide an introduction of recommended products (referred to as a recommendation service or personalization service) like a shopping site by using the ability to trace the behavior of a specific user. On the other hand, depending on the user, there is a possibility that the user's own behavior is not grasped in this way.
さらに、このような、TTP200を利用したSSO技術の利用にあたり、TTP200が本人の特定を実施できるよう、IDのユーザと本人(この場合は、TTP200へのログインID)との対応関係をTTP200が把握できることも併せて必要とされている。このため、TTP200でのサービス利用時のIDの管理にあたり、TTP200での管理コストを低減することを目的として、暗号化の技法を利用する手法が提案されている(例えば、特許文献1参照。)。 Furthermore, when using the SSO technology using the TTP 200, the TTP 200 grasps the correspondence between the ID user and the user (in this case, the login ID to the TTP 200) so that the TTP 200 can identify the user. What can be done is also needed. For this reason, a method using an encryption technique has been proposed for the purpose of reducing the management cost in the TTP 200 when managing the ID when using the service in the TTP 200 (see, for example, Patent Document 1). .
この従来のID管理手法では、TTP200へのログインIDに生成日時といった動的な情報や、固定のビット列などの静的な情報を付加した後に暗号化を施したものをサービス利用のためのIDとして生成している。このため、ユーザとIDとの関係を把握するには、新たに生成したサービス利用のためのIDを、生成の際に利用した暗号化鍵を用いて復号してやればよい。そのため、TTP200自身では、ユーザ(ユーザのTTP200へのログインID)と新たに生成したサービス利用のためのIDとの対応関係を保持する必要はなく、TTP200が管理すべき情報は、IDの生成に利用した鍵のみとなる。したがって、TTP200における管理コストを低減することができる。 In this conventional ID management method, a dynamic ID such as a generation date and a static information such as a fixed bit string are added to the login ID to the TTP 200, and then encryption is performed as an ID for using the service. Is generated. Therefore, in order to grasp the relationship between the user and the ID, the newly generated ID for using the service may be decrypted using the encryption key used at the time of generation. Therefore, the TTP 200 itself does not need to maintain the correspondence between the user (the user's login ID to the TTP 200) and the newly generated ID for using the service, and the information that the TTP 200 should manage is the ID generation. Only used keys. Therefore, the management cost in TTP200 can be reduced.
また、上記従来のID管理手法においては、ID生成に利用した鍵が漏洩した際のリスクを低減するために、サービスごとに利用する暗号化鍵を変更する手法が提案されている。そのため、鍵が漏洩した場合でも、その被害はそのサービスに限定でき、被害が他のサービスに波及することが防げるようになっている。
しかしながら、上記従来のID管理手法は、サービス提供者が、自身のサービスの利用者を識別するための手法であり、識別子に利用者に関する情報は付与されてはいない。このため、サービス提供者がユーザの情報を取得するためには、別途、サービス提供者とTTP(あるいは、ユーザの情報の管理元)とが通信を行なう必要があるという問題がある。また、別途、利用者の情報を証明するための属性証明書などを利用する方式も提案されているが、この場合も、識別子の取得とは別に、通信が発生するという問題がある。 However, the above-described conventional ID management technique is a technique for a service provider to identify a user of his / her service, and information on the user is not given to the identifier. For this reason, in order for the service provider to acquire the user information, there is a problem that the service provider and TTP (or the user information management source) need to communicate separately. In addition, a method of using an attribute certificate or the like for proving user information has been proposed. However, in this case, there is a problem that communication occurs separately from acquisition of an identifier.
そこで、本発明は、上記の課題に鑑みてなされたものであり、TTPおよびサービス提供サーバの通信負担を抑えつつ、第三者に秘匿した状態で必要な利用者情報を入手できるサービス利用識別情報生成装置、サービス利用識別情報生成システム、サービス利用識別情報生成方法およびプログラムを提供することを目的とする。 Therefore, the present invention has been made in view of the above problems, and service use identification information that can obtain necessary user information in a state that it is kept secret from a third party while suppressing the communication burden of the TTP and the service providing server. It is an object to provide a generation device, a service use identification information generation system, a service use identification information generation method, and a program.
本発明は、上述の課題を解決するために以下の事項を提案している。
(1)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)とにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置であって、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成装置を提案している。
The present invention proposes the following items in order to solve the above-described problems.
(1) The present invention connects a user terminal (for example, equivalent to the user terminal 100 in FIG. 1) and a service providing server (for example, equivalent to the service providing server 300 in FIG. 1) managed by the service provider via a network. A service usage identification information generating device for generating service usage identification information for identifying the user when the service providing server uses the service, and receiving means for receiving the login information of the user ( For example, it corresponds to the receiving
この発明によれば、受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、サービス利用識別情報生成装置が、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。 According to this invention, the receiving means receives the user's login information, and the encryption processing means adds additional information to the received user's login information, and uses an encryption key that differs for each service that the user receives. Encrypt. Then, the service usage identification information generating means adds information about the user to the information encrypted by the encryption processing means, encrypts it with an encryption key unique to the device, generates service usage identification information, and the transmission means The generated service use identification information is transmitted to the service providing server. Therefore, when the service use identification information generating device generates an ID using an encryption key that is different for each service, information related to the user is given to the generated ID itself, and the entire device is encrypted unique to the device. Since the information is encrypted with the key, the information about the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.
(2)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)と、信頼できる第三者機関が管理しユーザ認証を行うとともにユーザがサービスを利用するためのサービス利用識別情報を生成する管理サーバとからなるサービス利用識別情報生成システムであって、前記管理サーバが、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、信頼できる第三者機関固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成システムを提案している。
(2) The present invention is reliable with a user terminal (for example, equivalent to the user terminal 100 in FIG. 1), a service providing server managed by the service provider (for example, equivalent to the service providing server 300 in FIG. 1), A service usage identification information generation system comprising a management server that manages a user and authenticates a user and generates service usage identification information for the user to use the service, wherein the management server includes user login information. And receiving means (e.g., corresponding to the receiving
この発明によれば、管理サーバ内の受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、管理サーバが、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。また、サービス提供サーバは、自身が持つ秘密鍵により復号化を行い、サービス利用のためのIDと、利用者情報とを個別の通信を行うことなく取得することができる。 According to this invention, the receiving means in the management server receives the user's login information, and the encryption processing means gives additional information to the received user's login information, and varies depending on the service the user receives. Encrypt with encryption key. Then, the service usage identification information generating means adds information about the user to the information encrypted by the encryption processing means, encrypts it with an encryption key unique to the device, generates service usage identification information, and the transmission means The generated service use identification information is transmitted to the service providing server. Therefore, when the management server generates an ID using a different encryption key for each service, information on the user is given to the generated ID itself, and the whole is encrypted with a device-specific encryption key. Therefore, information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information. In addition, the service providing server can perform decryption using its own private key, and can acquire the ID for using the service and the user information without performing individual communication.
(3)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)とにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置であって、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバとの間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成装置を提案している。
(3) The present invention connects a user terminal (for example, equivalent to the user terminal 100 in FIG. 1) and a service providing server (for example, equivalent to the service providing server 300 in FIG. 1) managed by the service provider via a network. A service use identification information generating apparatus for generating service use identification information for identifying the user when the service providing server uses the service, and receiving means for receiving user login information ( For example, it corresponds to the receiving
この発明によれば、受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、サービス提供サーバとの間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、サービス利用識別情報生成装置が、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバとの間で共有された暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。 According to this invention, the receiving means receives the user's login information, and the encryption processing means adds additional information to the received user's login information, and uses an encryption key that differs for each service that the user receives. Encrypt. Then, the service use identification information generating means gives the information about the user to the information encrypted by the encryption processing means, and encrypts it with the encryption key shared with the service providing server, so that the service use identification information And the service use identification information generated by the transmission means is transmitted to the service providing server. Therefore, when the service use identification information generating device generates an ID using an encryption key that is different for each service, the information about the user is given to the generated ID itself, and the whole is connected to the service providing server. Since the information is encrypted with the encryption key shared between the users, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.
(4)本発明は、ユーザ端末(例えば、図1のユーザ端末100に相当)と、サービス提供者が管理するサービス提供サーバ(例えば、図1のサービス提供サーバ300に相当)と、信頼できる第三者機関が管理しユーザ認証を行うとともにユーザがサービスを利用するためのサービス利用識別情報を生成する管理サーバとからなるサービス利用識別情報生成システムであって、前記管理サーバが、ユーザのログイン情報を受信する受信手段(例えば、図2の受信部21に相当)と、該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段(例えば、図2の暗号化部22に相当)と、該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバと前記信頼できる第三者機関との間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段(例えば、図2のサービス利用識別情報生成部24に相当)と、該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段(例えば、図2の送信部25に相当)と、を備えたことを特徴とするサービス利用識別情報生成システムを提案している。
(4) The present invention provides a user terminal (for example, equivalent to the user terminal 100 in FIG. 1), a service providing server managed by the service provider (for example, equivalent to the service providing server 300 in FIG. 1), and a reliable first. A service usage identification information generation system comprising a management server that manages a user and authenticates a user and generates service usage identification information for the user to use the service, wherein the management server includes user login information. And receiving means (e.g., corresponding to the receiving
この発明によれば、管理サーバ内の受信手段がユーザのログイン情報を受信し、暗号化処理手段が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成手段が、暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、サービス提供サーバと信頼できる第三者機関との間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成し、送信手段が生成したサービス利用識別情報をサービス提供サーバに送信する。したがって、管理サーバが、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバと信頼できる第三者機関との間で共有された暗号化鍵で暗号化するため、利用者に関する情報を、IDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。また、サービス提供サーバは、サービス提供サーバと信頼できる第三者機関との間で共有された暗号化鍵により復号化を行い、サービス利用のためのIDと、利用者情報とを個別の通信を行うことなく取得することができる。 According to this invention, the receiving means in the management server receives the user's login information, and the encryption processing means gives additional information to the received user's login information, and varies depending on the service the user receives. Encrypt with encryption key. Then, the service use identification information generating means adds information about the user to the information encrypted by the encryption processing means, and uses an encryption key shared between the service providing server and a trusted third party. The service use identification information is generated by encryption, and the service use identification information generated by the transmission unit is transmitted to the service providing server. Therefore, when the management server generates an ID using an encryption key that is different for each service, information related to the user is given to the generated ID itself, and the whole is trusted by the service providing server. In order to encrypt with the encryption key shared with the institution, the information about the user is concealed from those other than the TTP that has generated the ID and the service provider server that receives the information. be able to. In addition, the service providing server performs decryption using an encryption key shared between the service providing server and a trusted third party, and individually communicates the ID for using the service and the user information. You can get it without doing it.
(5)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法であって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、を有することを特徴とするサービス利用識別情報生成方法を提案している。 (5) The present invention is connected to a user terminal and a service providing server managed by the service provider via a network, and the service providing server identifies the user when the service is used by the user. A service usage identification information generation method in a service usage identification information generation apparatus that generates identification information, which is a first step (for example, corresponding to steps S101 and S102 in FIG. 3) for adding additional information to the received user login information. ), And a second step (for example, corresponding to step S103 in FIG. 3) of encrypting information in which additional information is added to the login information of the user with a different encryption key for each service provided by the user, A third step of adding information about the user to the encrypted information (for example, step S10 in FIG. 3) And a fourth step (for example, corresponding to step S105 in FIG. 3) of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generating device And a service usage identification information generation method characterized by having
この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、この暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。 According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with an encryption key unique to the service use identification information generating apparatus. Therefore, when generating an ID using a different encryption key for each service, information on the user is given to the generated ID itself, and the whole is encrypted with an encryption key unique to the service use identification information generating device. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.
(6)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法であって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、を有することを特徴とするサービス利用識別情報生成方法を提案している。 (6) The present invention is connected to a user terminal and a service providing server managed by a service provider via a network, and the service providing server identifies the user when the service is used by the user. A service usage identification information generation method in a service usage identification information generation apparatus that generates identification information, which is a first step (for example, corresponding to steps S101 and S102 in FIG. 3) for adding additional information to the received user login information. ), And a second step (for example, corresponding to step S103 in FIG. 3) of encrypting information in which additional information is added to the login information of the user with a different encryption key for each service provided by the user, A third step of adding information about the user to the encrypted information (for example, step S10 in FIG. 3) And a fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key shared between the service providing server and the service use identification information generating device. (For example, corresponding to step S105 in FIG. 3) is proposed.
この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、暗号化された情報に利用者に関する情報を付与した情報をサービス提供サーバとの間で共有された暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバとの間で共有された暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。 According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with the encryption key shared with the service providing server. Therefore, when generating an ID using an encryption key that differs for each service, information about the user is given to the generated ID itself, and the entire encryption key is shared with the service providing server. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.
(7)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法をコンピュータに実行させるためのプログラムであって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、をコンピュータに実行させるためのプログラムを提案している。 (7) The present invention is connected to a user terminal and a service providing server managed by a service provider via a network, and the service providing server identifies the user when the service is used by the user. A program for causing a computer to execute a service usage identification information generation method in a service usage identification information generation apparatus for generating identification information, and a first step of adding additional information to received user login information (for example, FIG. And a second step (for example, FIG. 3) of encrypting information obtained by adding additional information to the login information of the user with a different encryption key for each service provided by the user. Step S103), and information about the user is added to the encrypted information. Step (for example, corresponding to step S104 in FIG. 3), and a fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generation device (For example, corresponding to step S105 in FIG. 3) is proposed.
この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置固有の暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。 According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with an encryption key unique to the service use identification information generating apparatus. Therefore, when generating an ID using a different encryption key for each service, information on the user is given to the generated ID itself, and the whole is encrypted with an encryption key unique to the service use identification information generating device. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.
(8)本発明は、ユーザ端末と、サービス提供者が管理するサービス提供サーバとにネットワークを介して接続され、ユーザによるサービス利用の際に、前記サービス提供サーバがユーザを識別するためのサービス利用識別情報を生成するサービス利用識別情報生成装置におけるサービス利用識別情報生成方法をコンピュータに実行させるためのプログラムであって、受信したユーザのログイン情報に付加情報を付与する第1のステップ(例えば、図3のステップS101、S102に相当)と、該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップ(例えば、図3のステップS103に相当)と、該暗号化された情報に利用者に関する情報を付与する第3のステップ(例えば、図3のステップS104に相当)と、該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップ(例えば、図3のステップS105に相当)と、をコンピュータに実行させるためのプログラムを提案している。 (8) The present invention is connected to a user terminal and a service providing server managed by a service provider via a network, and the service providing server identifies the user when the service is used by the user. A program for causing a computer to execute a service usage identification information generation method in a service usage identification information generation apparatus for generating identification information, and a first step of adding additional information to received user login information (for example, FIG. And a second step (for example, FIG. 3) of encrypting information obtained by adding additional information to the login information of the user with a different encryption key for each service provided by the user. Step S103), and information about the user is added to the encrypted information. (For example, corresponding to step S104 in FIG. 3), and information obtained by adding information about the user to the encrypted information is shared between the service providing server and the service use identification information generating device. A program for causing a computer to execute a fourth step (for example, corresponding to step S105 in FIG. 3) of encrypting with an encryption key is proposed.
この発明によれば、受信したユーザのログイン情報に付加情報を付与し、ユーザのログイン情報に付加情報を付与した情報をユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する。そして、暗号化された情報に利用者に関する情報を付与し、暗号化された情報に利用者に関する情報を付与した情報をサービス提供サーバとの間で共有された暗号化鍵で暗号化する。したがって、サービスごとに異なる暗号化鍵を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス提供サーバとの間で共有された暗号化鍵で暗号化するため、利用者に関する情報をIDの生成を行ったTTPおよび情報の提供を受けるサービス提供者サーバ以外の者に対して、秘匿化することができる。 According to the present invention, additional information is added to the received login information of the user, and the information provided with the additional information is encrypted with a different encryption key for each service provided by the user. Then, information about the user is added to the encrypted information, and the information to which the information about the user is added to the encrypted information is encrypted with the encryption key shared with the service providing server. Therefore, when generating an ID using an encryption key that differs for each service, information about the user is given to the generated ID itself, and the entire encryption key is shared with the service providing server. Therefore, the information related to the user can be concealed from a person other than the TTP that has generated the ID and the service provider server that receives the information.
本発明によれば、ID自身に情報を付与することができ、しかも、第三者にはその情報が理解できないという効果がある。また、ID自身に利用者の情報が付与されているので、サービス提供者とTTPの間で、利用者の情報取得に本来必要な通信を行なう必要がないという効果がある。 According to the present invention, information can be given to the ID itself, and there is an effect that the third party cannot understand the information. Further, since the user information is given to the ID itself, there is an effect that it is not necessary to perform communication originally necessary for acquiring the user information between the service provider and the TTP.
また、本発明によれば、付与した情報を隠蔽するための暗号化処理にあたり、サービス提供者の認証に利用する公開鍵証明書を添付した公開鍵を利用できるため、付加的情報を必要としないという効果がある。さらに、上記の公開鍵の利用の他に、TTPとサービス提供者間で事前に共有された共有鍵を利用することもできるが、この場合、必要な情報の増加量としては、サービスひとつに対して、暗号化のための鍵ひとつであるため、サービス提供者、TTP双方にとって大きな負担とはならないという効果がある。 In addition, according to the present invention, since the public key attached with the public key certificate used for authentication of the service provider can be used in the encryption process for concealing the assigned information, no additional information is required. There is an effect. Furthermore, in addition to the use of the public key described above, a shared key shared in advance between the TTP and the service provider can be used. In this case, the amount of necessary information is increased for one service. Since this is one key for encryption, there is an effect that it does not become a heavy burden on both the service provider and TTP.
以下、本発明の実施形態について、図面を用いて、詳細に説明する。
なお、本実施形態における構成要素は適宜、既存の構成要素等との置き換えが可能であり、また、他の既存の構成要素との組合せを含む様々なバリエーションが可能である。したがって、本実施形態の記載をもって、特許請求の範囲に記載された発明の内容を限定するものではない。
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
Note that the constituent elements in the present embodiment can be appropriately replaced with existing constituent elements and the like, and various variations including combinations with other existing constituent elements are possible. Therefore, the description of the present embodiment does not limit the contents of the invention described in the claims.
<サービス利用識別情報生成システムの構成>
本実施形態に係るサービス利用識別情報生成システムは、図1に示すように、ユーザ端末100と、サービス利用識別情報生成装置または管理サーバとしてのTTP200と、サービス提供サーバ300とから構成され、これらユーザ端末100、管理サーバとしてのTTP200、サービス提供サーバ300は、それぞれネットワークを介して接続されている。
<Configuration of service usage identification information generation system>
As shown in FIG. 1, the service usage identification information generation system according to the present embodiment includes a user terminal 100, a TTP 200 as a service usage identification information generation device or a management server, and a service providing server 300. The terminal 100, the TTP 200 as a management server, and the service providing server 300 are connected via a network.
ユーザ端末100は、サービス提供サーバ300に対する接続要求をサービス利用識別情報生成装置または管理サーバとしてのTTP200に送信する。また、サービスの提供をはじめて受ける場合には、サービス利用識別情報生成装置または管理サーバとしてのTTP200に対して、IDの生成要求を発行し、管理サーバとしてのTTP200から取得したサービス利用IDに基づき、サービス提供サーバ300によるサービスの提供を受ける。 The user terminal 100 transmits a connection request to the service providing server 300 to the TTP 200 serving as a service use identification information generating device or a management server. In addition, when receiving a service for the first time, an ID generation request is issued to the service use identification information generating device or the TTP 200 as the management server, and based on the service use ID acquired from the TTP 200 as the management server, The service is provided by the service providing server 300.
サービス利用識別情報生成装置または管理サーバとしてのTTP200は、信頼のおける第三者機関が管理するサーバであって、その詳細な構成については後述する。本実施形態においては、図2における受信部21が、ユーザ端末100からログイン情報を受信し、暗号化部22が、受信したユーザのログイン情報に付加情報を付与して、ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化を行う。そして、サービス利用識別情報生成部24が、暗号化部22において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成し、送信部25が生成したサービス利用識別情報をサービス提供サーバ300に送信する。
The TTP 200 as a service use identification information generating device or a management server is a server managed by a reliable third party organization, and the detailed configuration thereof will be described later. In the present embodiment, the receiving
サービス提供サーバ300は、サービス利用識別情報生成装置または管理サーバとしてのTTP200から通知されたIDにより、ユーザを識別し、ユーザの管理を実行するとともに、利用者情報を取得する。 The service providing server 300 identifies the user based on the ID notified from the service use identification information generating apparatus or the TTP 200 as the management server, executes user management, and acquires user information.
<生成されるIDの構成>
次に、図4から図6を用いて、本実施形態において、生成されるIDの構成について説明する。
まず、図4に示すように、ユーザ端末100のそれぞれが有するサービス利用識別情報生成装置または管理サーバとしてのTTP200へのログインID(IDu)に所定の付加情報(Sinfo)を結合する。そして、この結合された情報をサービスごとに異なる暗号化鍵(Kn)で暗号化する。さらに、この情報に、利用者の情報を結合し、この結合された情報をサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PKS)で暗号化して、これを利用者情報が付与されたユーザIDデータとする。なお、サービス提供サーバ300では、図6に示すように、TTP200から送信された利用者情報が付与されたユーザIDデータをサービス提供サーバ300が有する秘密鍵(SKS)で復号して、それぞれIDとして、あるいは、ユーザの情報として利用する。
<Configuration of generated ID>
Next, the configuration of an ID generated in the present embodiment will be described with reference to FIGS.
First, as shown in FIG. 4, predetermined additional information (Sinfo) is combined with a login ID (IDu) to the TTP 200 as a service use identification information generating device or a management server that each user terminal 100 has. The combined information is encrypted with a different encryption key (Kn) for each service. Further, the information of the user is combined with this information, and the combined information is encrypted with the encryption key (PK S ) unique to the TTP 200 as the service use identification information generating device or the management server, and this is used by the user. It is assumed that the user ID data is given information. In the service providing server 300, as shown in FIG. 6, the user ID data to which the user information transmitted from the TTP 200 is added is decrypted with the secret key (SK S ) of the service providing server 300. Or as user information.
次に、図5の場合には、ユーザ端末100のそれぞれが有するサービス利用識別情報生成装置または管理サーバとしてのTTP200へのログインID(IDu)に所定の付加情報(Sinfo)を結合する。そして、この結合された情報をサービスごとに異なる暗号化鍵(Kn)で暗号化する。さらに、この情報に、利用者の情報を結合し、この結合された情報をサービス利用識別情報生成装置または管理サーバとしてのTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)で暗号化して、これを利用者情報が付与されたユーザIDデータとする。なお、サービス提供サーバ300では、TTP200から送信された利用者情報が付与されたユーザIDデータをサービス提供サーバ300が有する共有鍵(KS−TTP)で復号して、それぞれIDとして、あるいは、ユーザの情報として利用する。 Next, in the case of FIG. 5, predetermined additional information (Sinfo) is combined with a login ID (IDu) to the TTP 200 as a service use identification information generating device or a management server of each user terminal 100. The combined information is encrypted with a different encryption key (Kn) for each service. Further, the information of the user is combined with this information, and the combined information is combined with the encryption key (K S-TTP ) shared between the TTP 200 serving as the service use identification information generating device or the management server and the service providing server 300. This is encrypted as user ID data to which user information is assigned. In the service providing server 300, the user ID data to which the user information transmitted from the TTP 200 is added is decrypted with the shared key (K S-TTP ) possessed by the service providing server 300, and each is used as an ID or a user. Use as information.
したがって、サービス利用識別情報生成装置または管理サーバとしてのTTP200が、サービスごとに異なる暗号化鍵(Kn)を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PKS)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)で暗号化するため、利用者に関する情報を第三者に対して秘匿化することができ、さらに、全体をひとつのIDとすることができる。 Therefore, when the TTP 200 serving as the service use identification information generation device or the management server generates an ID using an encryption key (Kn) that is different for each service, information about the user is given to the generated ID itself, In order to encrypt the whole with the encryption key (PK S ) unique to the TTP 200 as the service use identification information generating device or the management server, or the encryption key (K S-TTP ) shared by the TTP 200 and the service providing server 300. The information about the user can be concealed from a third party, and the whole can be set as one ID.
<サービス利用識別情報生成装置の構成>
本実施形態に係るサービス利用識別情報生成装置は、図2に示すように、受信部21と、暗号化部22と、鍵データベース23と、サービス利用識別情報生成部24と、送信部25とから構成されている。
<Configuration of Service Usage Identification Information Generation Device>
As shown in FIG. 2, the service usage identification information generation apparatus according to the present embodiment includes a
受信部21は、ユーザ端末100からサービス提供サーバ300に対する接続要求を受信する。なお、この際、サービス利用識別情報生成装置または管理サーバとしてのTTP200に対するログインIDも併せて受信する。
The receiving
暗号化部22は、受信部21が受信したユーザのログインID(IDu)に所定の付加情報(Sinfo)を結合するとともに、鍵データベース23内に格納されたサービスごとに異なる暗号化鍵(Kn)を用いて、上記結合した情報を暗号化する。なお、所定の付加情報(Sinfo)は、IDの生成時刻のように動的に変動するものでもよいし、固定のビット列でもよい。
The
鍵データベース30は、サービスごとに異なる暗号化鍵(Kn)およびサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PKS)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)を格納する。なお、データベースは、ハードディスク、RAM(Random Access Memory)であってもよく、また、単一のハードウェアで構成されている必要はなく、個別の記録部や専用装置であってもよい。 The key database 30 includes an encryption key (Kn) that is different for each service and an encryption key (PK S ) unique to the TTP 200 serving as a service use identification information generating device or a management server, or an encryption shared by the TTP 200 and the service providing server 300. Stores the key (K S-TTP ). The database may be a hard disk or a RAM (Random Access Memory), and may not be configured by a single piece of hardware, but may be an individual recording unit or a dedicated device.
サービス利用識別情報生成部24は、上記暗号化部22において暗号化された情報に利用者に関する情報を結合し、この結合した情報を鍵データベース23内に格納されたサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PKS)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)でさらに暗号化して利用者情報が付与されたユーザIDデータを生成する。
The service usage identification
送信部25は、サービス利用識別情報生成部24において生成されたサービス利用識別情報をサービス提供サーバ300に送信する。
The
<サービス利用識別情報生成システムの処理>
次に、図3を用いて、本実施形態に係るサービス利用識別情報生成システムの処理について説明する。
<Processing of service use identification information generation system>
Next, processing of the service use identification information generation system according to the present embodiment will be described with reference to FIG.
まず、サービス利用識別情報生成装置の受信部21がユーザ端末100からサービス提供サーバ300への接続仲介要求を受信する(ステップS101)。なお、このとき、同時に、サービス利用識別情報生成装置または管理サーバとしてのTTP200に対するログインIDも併せて受信する。
First, the receiving
暗号化部22は、受信部21からユーザのログインID(IDu)を入力すると、これに、所定の付加情報(Sinfo)を結合するとともに(ステップS102)、鍵データベース23内に格納されたサービスごとに異なる暗号化鍵(Kn)を用いて、上記結合した情報を暗号化する(ステップS103)。
When the user's login ID (IDu) is input from the receiving
サービス利用識別情報生成部24は、暗号化部22から暗号化された情報を入力すると、この情報に利用者に関する情報を結合し(ステップS104)、この結合した情報を鍵データベース23内に格納されたサービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PKS)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)でさらに暗号化して利用者情報が付与されたユーザIDデータを生成する(ステップS105)。
When the service use identification
したがって、本実施形態によれば、サービス利用識別情報生成装置または管理サーバとしてのTTP200が、サービスごとに異なる暗号化鍵(Kn)を用いてIDを生成するにあたり、利用者に関する情報を、生成したID自身に付与し、さらに、全体を、サービス利用識別情報生成装置または管理サーバとしてのTTP200固有の暗号化鍵(PKS)あるいはTTP200とサービス提供サーバ300とが共有する暗号化鍵(KS−TTP)で暗号化するため、利用者に関する情報を第三者に対して秘匿化することができ、さらに、全体をひとつのIDとすることができる。 Therefore, according to the present embodiment, when the TTP 200 as the service use identification information generation device or the management server generates an ID using an encryption key (Kn) that is different for each service, the information about the user is generated. Further, the entire ID is assigned to the ID itself, and further, the entire encryption key (PK S ) unique to the TTP 200 as the service use identification information generating device or the management server, or the encryption key (K S− Since the information is encrypted with TTP ), information about the user can be kept secret from a third party, and the whole can be made into one ID.
なお、サービス利用識別情報生成装置およびサービス利用識別情報生成システムのそれぞれの処理をコンピュータ読み取り可能な記録媒体に記録し、この記録媒体に記録されたプログラムをサービス利用識別情報生成装置およびサービス利用識別情報生成システムに読み込ませ、実行することによって本発明のサービス利用識別情報生成装置およびサービス利用識別情報生成システムを実現することができる。ここでいうコンピュータシステムとは、OSや周辺装置等のハードウェアを含む。 Each process of the service usage identification information generation apparatus and the service usage identification information generation system is recorded on a computer-readable recording medium, and the program recorded on the recording medium is stored in the service usage identification information generation apparatus and the service usage identification information. The service use identification information generation apparatus and service use identification information generation system of the present invention can be realized by causing the generation system to read and execute. The computer system here includes an OS and hardware such as peripheral devices.
また、「コンピュータシステム」は、WWW(World Wide Web)システムを利用している場合であれば、ホームページ提供環境(あるいは表示環境)も含むものとする。また、上記プログラムは、このプログラムを記憶装置等に格納したコンピュータシステムから、伝送媒体を介して、あるいは、伝送媒体中の伝送波により他のコンピュータシステムに伝送されても良い。ここで、プログラムを伝送する「伝送媒体」は、インターネット等のネットワーク(通信網)や電話回線等の通信回線(通信線)のように情報を伝送する機能を有する媒体のことをいう。 Further, the “computer system” includes a homepage providing environment (or display environment) if a WWW (World Wide Web) system is used. The program may be transmitted from a computer system storing the program in a storage device or the like to another computer system via a transmission medium or by a transmission wave in the transmission medium. Here, the “transmission medium” for transmitting the program refers to a medium having a function of transmitting information, such as a network (communication network) such as the Internet or a communication line (communication line) such as a telephone line.
また、上記プログラムは、前述した機能の一部を実現するためのものであっても良い。さらに、前述した機能をコンピュータシステムにすでに記録されているプログラムとの組合せで実現できるもの、いわゆる差分ファイル(差分プログラム)であっても良い。 The program may be for realizing a part of the functions described above. Furthermore, what can implement | achieve the function mentioned above in combination with the program already recorded on the computer system, and what is called a difference file (difference program) may be sufficient.
以上、この発明の実施形態につき、図面を参照して詳述してきたが、具体的な構成はこの実施形態に限られるものではなく、この発明の要旨を逸脱しない範囲の設計等も含まれる。 The embodiment of the present invention has been described in detail with reference to the drawings. However, the specific configuration is not limited to this embodiment, and includes a design and the like within a scope not departing from the gist of the present invention.
21・・・受信部
22・・・暗号化部
23・・・鍵データベース
24・・・サービス利用識別情報生成部
25・・・送信部
100・・・ユーザ端末
200・・・TTP
300・・・サービス提供サーバ
DESCRIPTION OF
300 ... Service providing server
Claims (8)
ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、装置固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成装置。 Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. An identification information generating device,
Receiving means for receiving user login information;
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service usage identification information generating means for generating service usage identification information by giving information about a user to the information encrypted in the encryption processing means, and encrypting with a device-specific encryption key;
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generating device comprising:
前記管理サーバが、ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、信頼できる第三者機関固有の暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成システム。 A service comprising a user terminal, a service providing server managed by a service provider, and a management server that is managed by a trusted third party to perform user authentication and generate service use identification information for the user to use the service A usage identification information generation system,
The management server receives a user login information; and
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service usage identification information generating means for generating service usage identification information by giving information about the user to the information encrypted in the encryption processing means, and encrypting with an encryption key unique to a reliable third party organization;
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generation system comprising:
ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバとの間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成したサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成装置。 Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. An identification information generating device,
Receiving means for receiving user login information;
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service use identification information generation for adding service information to the information encrypted by the encryption processing means and generating service use identification information by encrypting with an encryption key shared with the service providing server Means,
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generating device comprising:
前記管理サーバが、ユーザのログイン情報を受信する受信手段と、
該受信したユーザのログイン情報に付加情報を付与して、前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する暗号化処理手段と、
該暗号化処理手段において暗号化された情報に利用者に関する情報を付与し、前記サービス提供サーバと前記信頼できる第三者機関との間で共有された暗号化鍵で暗号化してサービス利用識別情報を生成するサービス利用識別情報生成手段と、
該生成されたサービス利用識別情報を前記サービス提供サーバに送信する送信手段と、
を備えたことを特徴とするサービス利用識別情報生成システム。 A service comprising a user terminal, a service providing server managed by a service provider, and a management server that is managed by a trusted third party to perform user authentication and generate service use identification information for the user to use the service A usage identification information generation system,
The management server receives a user login information; and
An encryption processing means for adding additional information to the received login information of the user and encrypting with a different encryption key for each service provided by the user;
Service usage identification information obtained by adding information about a user to the information encrypted by the encryption processing means and encrypting the information with an encryption key shared between the service providing server and the trusted third party organization. Service usage identification information generating means for generating
Transmitting means for transmitting the generated service use identification information to the service providing server;
A service use identification information generation system comprising:
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップと、
を有することを特徴とするサービス利用識別情報生成方法。 Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generating device;
A service use identification information generation method characterized by comprising:
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップと、
を有することを特徴とするサービス利用識別情報生成方法。 Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about a user to the encrypted information with an encryption key shared between the service providing server and the service use identification information generating device;
A service use identification information generation method characterized by comprising:
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報をサービス利用識別情報生成装置固有の暗号化鍵で暗号化する第4のステップと、
をコンピュータに実行させるためのプログラム。 Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A program for causing a computer to execute a service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about the user to the encrypted information with an encryption key unique to the service use identification information generating device;
A program that causes a computer to execute.
受信したユーザのログイン情報に付加情報を付与する第1のステップと、
該ユーザのログイン情報に付加情報を付与した情報を前記ユーザが提供を受けるサービスごとに異なる暗号化鍵で暗号化する第2のステップと、
該暗号化された情報に利用者に関する情報を付与する第3のステップと、
該暗号化された情報に利用者に関する情報を付与した情報を前記サービス提供サーバとサービス利用識別情報生成装置との間で共有された暗号化鍵で暗号化する第4のステップと、
をコンピュータに実行させるためのプログラム。 Service use connected to a user terminal and a service providing server managed by the service provider via a network, and when the user uses the service, the service providing server generates service use identification information for identifying the user. A program for causing a computer to execute a service use identification information generation method in an identification information generation apparatus,
A first step of adding additional information to the received login information of the user;
A second step of encrypting information obtained by adding additional information to the login information of the user with an encryption key that is different for each service that the user receives;
A third step of assigning information about the user to the encrypted information;
A fourth step of encrypting information obtained by adding information about a user to the encrypted information with an encryption key shared between the service providing server and the service use identification information generating device;
A program that causes a computer to execute.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2007079016A JP4989996B2 (en) | 2007-03-26 | 2007-03-26 | Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2007079016A JP4989996B2 (en) | 2007-03-26 | 2007-03-26 | Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JP2008242585A true JP2008242585A (en) | 2008-10-09 |
| JP4989996B2 JP4989996B2 (en) | 2012-08-01 |
Family
ID=39913895
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2007079016A Expired - Fee Related JP4989996B2 (en) | 2007-03-26 | 2007-03-26 | Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JP4989996B2 (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2015519636A (en) * | 2012-04-09 | 2015-07-09 | ミディアム、アクセス、システムズ、プライベート、リミテッドMedium Access Systemsprivate Ltd. | Method and system for providing secure transactions using cyber IDs |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2005056393A (en) * | 2003-07-24 | 2005-03-03 | Ricoh Co Ltd | User authentication method, image forming apparatus, and user authentication program |
| JP2005311904A (en) * | 2004-04-23 | 2005-11-04 | Ntt Docomo Inc | Authentication system |
| JP2006244420A (en) * | 2005-03-07 | 2006-09-14 | Kddi R & D Laboratories Inc | Identification information generation management device, and its system and program |
-
2007
- 2007-03-26 JP JP2007079016A patent/JP4989996B2/en not_active Expired - Fee Related
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2005056393A (en) * | 2003-07-24 | 2005-03-03 | Ricoh Co Ltd | User authentication method, image forming apparatus, and user authentication program |
| JP2005311904A (en) * | 2004-04-23 | 2005-11-04 | Ntt Docomo Inc | Authentication system |
| JP2006244420A (en) * | 2005-03-07 | 2006-09-14 | Kddi R & D Laboratories Inc | Identification information generation management device, and its system and program |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2015519636A (en) * | 2012-04-09 | 2015-07-09 | ミディアム、アクセス、システムズ、プライベート、リミテッドMedium Access Systemsprivate Ltd. | Method and system for providing secure transactions using cyber IDs |
Also Published As
| Publication number | Publication date |
|---|---|
| JP4989996B2 (en) | 2012-08-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11676133B2 (en) | Method and system for mobile cryptocurrency wallet connectivity | |
| JP5006817B2 (en) | Authentication information generation system, authentication information generation method, client device, and program | |
| US10735186B2 (en) | Revocable stream ciphers for upgrading encryption in a shared resource environment | |
| CN102571329B (en) | Password key management | |
| US9372987B1 (en) | Apparatus and method for masking a real user controlling synthetic identities | |
| CN105022966A (en) | Database data encryption and decryption method and system | |
| US10063655B2 (en) | Information processing method, trusted server, and cloud server | |
| US20090210720A1 (en) | Method for generating one-time password | |
| JP5404501B2 (en) | Encrypted information expiration date extension system, expiration date extension method and program | |
| Thilakanathan et al. | Secure multiparty data sharing in the cloud using hardware-based TPM devices | |
| JP5678150B2 (en) | User terminal, key management system, and program | |
| JP5494171B2 (en) | File management system, storage server, client, file management method and program | |
| CN113779629A (en) | Key file sharing method, device, processor chip and server | |
| JP5139045B2 (en) | Content distribution system, content distribution method and program | |
| JP4989996B2 (en) | Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program | |
| JP4637612B2 (en) | Identification information generation management device, system, and program | |
| JP2002077134A (en) | Server / client system, data server, data client, data providing / using method, and recording medium | |
| JP2007058487A (en) | Login information management apparatus and method | |
| CN116781400A (en) | A method, system, device and electronic equipment for data processing on the blockchain | |
| JP2009055428A (en) | Information processing apparatus, server apparatus, information processing program, and method | |
| JP4945265B2 (en) | Service use identification information generation apparatus, service use identification information generation system, service use identification information generation method, and program | |
| JP2006279269A (en) | Information management apparatus, information management system, network system, user terminal, and programs thereof | |
| JP4679934B2 (en) | Identification information generation management device, system, and program | |
| JP2016163198A (en) | File management device, file management system, file management method, and file management program | |
| Damsika et al. | A novel mechanism for secure e-tendering in an open electronic network |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20090708 |
|
| A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20111207 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20111220 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20120214 |
|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20120417 |
|
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20120501 |
|
| R150 | Certificate of patent or registration of utility model |
Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20150511 Year of fee payment: 3 |
|
| S533 | Written request for registration of change of name |
Free format text: JAPANESE INTERMEDIATE CODE: R313533 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| LAPS | Cancellation because of no payment of annual fees |