JPS6238964A - Security system by password - Google Patents
Security system by passwordInfo
- Publication number
- JPS6238964A JPS6238964A JP60178905A JP17890585A JPS6238964A JP S6238964 A JPS6238964 A JP S6238964A JP 60178905 A JP60178905 A JP 60178905A JP 17890585 A JP17890585 A JP 17890585A JP S6238964 A JPS6238964 A JP S6238964A
- Authority
- JP
- Japan
- Prior art keywords
- password
- user
- conversion
- input
- output interface
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000006243 chemical reaction Methods 0.000 claims abstract description 60
- 238000000034 method Methods 0.000 claims description 10
- 238000009877 rendering Methods 0.000 abstract 1
- 238000010586 diagram Methods 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 230000007774 longterm Effects 0.000 description 1
Abstract
Description
【発明の詳細な説明】
〔産業上の利用分野〕
本発明は、電子計算機システムを利用する利用者に対し
て利用の許否判定をパスワードによって行なう、パスワ
ードによる機密保護方式に関する。DETAILED DESCRIPTION OF THE INVENTION [Field of Industrial Application] The present invention relates to a password-based security protection system in which a password is used to determine whether a user of a computer system is allowed to use the computer system.
従来、この種の機密保護方式は、利用者が入力したパス
ワードとシステムに予め登録されているパスワードとが
完全に一致するか否かで許否判定するものであった。Conventionally, this type of security protection system has determined whether or not the password entered by the user completely matches the password registered in advance in the system.
上述した従来のパスワードによる機密保護方式は、利用
者が入力したパスワードとシステムに予め登録されてい
るパスワードとを単純に比較し、判定するものであるの
でシステムに静的に登録されている登録パスワードの漏
洩により、電子計算機システムへの不正利用者の侵入が
可能となり、また固定的な単一パスワードの長期使用は
パスワードの漏洩機会を増加させるという欠点がある。The conventional password-based security protection method described above simply compares and determines the password entered by the user and the password registered in advance in the system. If the password is leaked, it becomes possible for an unauthorized user to infiltrate the computer system, and the long-term use of a fixed, single password has the drawback of increasing the chances of the password being leaked.
これらを防止する方法として、登録パスワードを随時変
更する方法や、複数のパスワードを登録する方法等が考
えられるが、利用者の数に依存して変更作業や登録パス
ワードの格納容量が増大するという問題がある。Possible ways to prevent this include changing the registered password at any time or registering multiple passwords, but the problem is that the changing work and storage capacity for registered passwords increases depending on the number of users. There is.
本発明のパスワードによる機密保護方式は、利用者と電
子計算機システムとの間の入出力インタフェース部と利
用者名およびそのパスワードが登録されるパスワード登
録部と、入出力インタフェース部を介して入力された利
用者名およびそのパスワードをパスワード登録部に登録
するパスワード登録処理部と、入出力インタフェース部
を介して入力された前記パスワードを指定された全ての
変換情報を基にしてパスワード変換し、このようにして
得られた全ての変換パスワードを当該利用者に入出力イ
ンタフェース部を介して通知する処理をすべての利用者
について行ない、その後、利用者がシステムを利用する
ために入出力インタフェース部を介して利用者名および
パスワードを入力すると、当該利用者の登録パスワード
をパスワード登録部から入手して、前記登録パスワード
を前記変換情報のうち現在システムに運用されている変
換情報に基づいてパスワード変換する処理を行なうパス
ワード変換部と、利用者がシステムを利用するために利
用者名およびパスワードを入出力インタフェース部を介
して入力すると、該パスワードを、前記パスワード変換
処理部で登録パスワードをパスワード変換して得られた
変換パスワ一ドと照合して許可あるいは拒否の判定を行
なうパスワード判定部を有するパスワードによる機密保
護方式。The password-based security protection system of the present invention includes an input/output interface section between a user and a computer system, a password registration section in which a user name and its password are registered, and a password input/output interface section that A password registration processing unit that registers a user name and its password in a password registration unit, and a password conversion unit that converts the password inputted through the input/output interface unit based on all specified conversion information, and performs the following steps. The process of notifying all the converted passwords obtained through the system via the input/output interface section is performed for all users, and then the users use the system via the input/output interface section in order to use the system. When a user's name and password are entered, the registered password of the user is obtained from the password registration section, and the registered password is converted into a password based on the conversion information currently operated in the system among the conversion information. a password conversion unit; when a user inputs a user name and password to use the system through the input/output interface unit, the password is converted into a password obtained by converting the registered password in the password conversion processing unit; A password-based security protection system that includes a password judgment unit that compares the converted password to determine permission or denial.
このように、利用者がシステムに登録するパスワード、
これを変換するための変換情報およびパスワード変換方
式がそれぞれ単独では意味を持たない独立情報であり利
用者がシステムを利用することができるパスワードはシ
ステムに登録したパスワードではなく、パスワード登録
時に、予めシステムに用意された変換情報に基づいて変
換され、利用者に通知された複数の変換パスワードのう
ち現在、システムに運用されている変換情報に対応する
変換パスワードであるので、従来のようにパスワードの
変更作業や格納容量が増大することなく、より完全な電
子計算機システムの機密保護が実現される。In this way, the password that the user registers in the system,
The conversion information and password conversion method for converting this are independent information that has no meaning on their own, and the password that allows the user to use the system is not the password registered in the system. Among the multiple converted passwords that have been converted based on the conversion information prepared in More complete security protection for electronic computer systems can be achieved without increasing work or storage capacity.
次に、本発明の実施例について図面を参照して説明する
。Next, embodiments of the present invention will be described with reference to the drawings.
第1図は本発明のパスワードによる機密保護力4一 式の一実施例を示す構成図である。Figure 1 shows the security protection power of the password of the present invention. It is a block diagram which shows one example of a formula.
入出力インタフェース部2は利用者1(パスワード登録
時)、利用者7(システム利用時)と電子計算機システ
ムのインタフェース部である。パスワード登録部4には
利用者名U1 およびパスワードPが登録される。パス
ワード登録処理部8は入出力インタフェース部を介して
入力された利用者名Ul およびパスワードPをパスワ
ード登録部4に登録し、また後述する変換パスワードP
j を ゛入出力インタフェース部2を介して利
用者lに通知する。表1はパスワード登録部4に登録さ
れている利用者名U I (1=1.2.・・・ )と
登録パスワードPの一例を示している。The input/output interface unit 2 is an interface unit between the user 1 (when registering a password), the user 7 (when using the system), and the computer system. A user name U1 and a password P are registered in the password registration section 4. The password registration processing unit 8 registers the user name Ul and password P input through the input/output interface unit in the password registration unit 4, and also converts the converted password P to be described later.
j to the user l via the input/output interface section 2. Table 1 shows an example of the user name U I (1=1.2...) registered in the password registration section 4 and the registered password P.
パスワード変換部6はパスワード登録部4に登録された
パスワードPを表2に示す全ての変換情報1、、I、、
I、・・・・・・からなる変換情報すを基にしてパスワ
ード変換P・xj を行ない、このようにして得られ
た全ての変換パスワードΣP−IJ をパスワード登
録処理部8.入出力インタフェース部1を介して利用者
1に通知する。これは全ての利用者(利用者名U1 e
Ut 、U3 *・・・)について行なわれる。The password conversion unit 6 converts the password P registered in the password registration unit 4 into all conversion information 1, , I, shown in Table 2.
Password conversion P·xj is performed based on the conversion information S consisting of I, . The user 1 is notified via the input/output interface unit 1. This applies to all users (user name U1 e
Ut, U3*...).
表8は表1の各利用者の登録パスワードに対する変換情
報it(文字列置換方式で、置換文字およびその位置を
指示している)による変換パスワードを示しており、ま
た、表8は表1の利用者(利用者名U1)に対する表2
の各変換情報I、、 Ile Ice・・・による変換
パスワードを示している。パスワード登録時、利用者U
1にはこの全ての変換パスワードが通知される。Table 8 shows the converted password for each user's registered password in Table 1 using the conversion information it (character string replacement method, indicating the replacement character and its position). Table 2 for user (user name U1)
The conversion information I, , Ile Ice, . . . shows conversion passwords. When registering a password, user U
1 is notified of all the converted passwords.
表 2
表 8
表 4
パスワード変換部6はまた、パスワードの登録と変換パ
スワードの通知が全ての利用者について終った後、利用
者7がシステムを利用するために入出力インタフェース
部2を介して利用者名Uj とパスワードを入力する
と、利用者名UL を後述のパスワード判定部8を通し
て受取り、パスワード登録部4から当該利用者UL の
登録パスワードPを入手して、前記変換情報IIs I
、@ x、、・・・のうち〇 −
現在、システムに運用されている変換情報Ikに基づい
たパスワード変換P −Ikを行なう。Table 2 Table 8 Table 4 The password conversion unit 6 also allows the user 7 to use the system via the input/output interface unit 2 after password registration and notification of converted passwords have been completed for all users. When the user name Uj and password are input, the user name UL is received through the password determination section 8 (described later), the registered password P of the user UL is obtained from the password registration section 4, and the conversion information IIs I
, @x, . . . - Password conversion P-Ik is performed based on the conversion information Ik currently used in the system.
パスワード判定部8は、利用者7が入出力インタフェー
ス部2を介して利用者名UI とパスワードPj
を入力すると、利用者名Ui をパスワード変換部6
に通知し、パスワード変換部6がパスワード変換処理し
た変換パスワードP・Ikを受は取り、入力されたパス
ワードPj を変換パスワー、 ドP −Ik
と照合して許可あるいは拒否の判定を行なう。なお、
変換情報は、パスワード変換部6に対する変換方式の選
択や変換方法に対する指示′ 情報であり、この変
換情報単独では、何んら意味を持たないものである。The password determination unit 8 receives the user name UI and password Pj from the user 7 via the input/output interface unit 2.
When you enter the user name Ui, the password converter 6
The password conversion unit 6 receives the converted password P・Ik that has undergone password conversion processing, and converts the input password Pj into the converted password, dP-Ik.
A decision is made to permit or deny the request. In addition,
The conversion information is information that instructs the password conversion unit 6 to select a conversion method and how to perform the conversion, and this conversion information alone has no meaning.
次に、本実施例の動作について第2図、第8図8
のフローチャートを参照して説明する。Next, the operation of this embodiment will be explained in Figs. 2 and 8.
This will be explained with reference to the flowchart.
11) パスワード登録時(第2図)利用者名Ui
とパスワードPが入出力インタフェース部2を介して
入力されると、これらはパスワード登録処理部8により
パスワード登録部4に登録される(処理11)。次K、
このパスワー ドPと表2の変換情報月(j=1.2.
8.・・・ )を基にしてパスワード変換1’ −Ij
がパスワード変換部6により行なわれ(処理12
、1.8 ) 、指定されている全ての変換情報に対す
る処理終了判定が行なわれ(処理14)、終了すると、
このようにして得もれた全ての変換パスワードΣp−x
j がパスワード登録処理部8.入出力インタフェー
ス部2を介して利用者lに通知される。11) When registering a password (Figure 2) User name Ui
and password P are input through the input/output interface section 2, these are registered in the password registration section 4 by the password registration processing section 8 (processing 11). Next K,
This password P and the conversion information month in Table 2 (j=1.2.
8. ... ) based on password conversion 1' -Ij
is performed by the password conversion unit 6 (processing 12
, 1.8), the processing end determination is made for all the specified conversion information (processing 14), and when the processing is completed,
All converted passwords Σp−x obtained in this way
j is the password registration processing section 8. The user l is notified via the input/output interface section 2.
(2) パスワード判定時(第8図)
利用者7が入出力インタフェース部8を介して利用者名
U1 とパスワードpj を入力すると、利用者名
Ui がパスワード判定部8を通ってパスワード変換部
6に送られ、パスワード変換部6はパスワード登録部4
・から利用者名対応の登録パスワードPを入力しく処理
21)、システムの現在の運用規則に従った変換情報I
kに基づいてこの登録パスワードPをパスワード変換し
く処理22)。(2) When determining a password (FIG. 8) When the user 7 inputs the user name U1 and password pj via the input/output interface unit 8, the user name Ui passes through the password determining unit 8 and is sent to the password converting unit 6. The password conversion unit 6 sends the password to the password registration unit 4.
・Process to input the registration password P corresponding to the user name from 21), conversion information I according to the current operating rules of the system
This registered password P is converted into a password based on k (22).
この変換パスワードP・Ikはパスワード判定部8に送
られて、利用者が入力したパスワードpiが変換パスワ
ードP・Ikと照合され、許可(処理 −24)
あるいは拒否(処理′25)の判定がなされる。したが
って、利用者が通知されている変換パスワードΣP−I
j のうちシステムの現在の運用規則に従った変換情
報Ikに基づいた変換パスワードを入力すれば許可の判
定がなされる。This converted password P・Ik is sent to the password judgment unit 8, the password pi input by the user is checked against the converted password P・Ik, and permission is given (processing -24).
Alternatively, a determination of rejection (process '25) is made. Therefore, the conversion password ΣP-I that the user has been notified of
Permission is determined by inputting a conversion password based on conversion information Ik according to the current operating rules of the system.
以上説明したように本発明は、利用者がシステムを利用
することができるパスワードはシステムに登録したパス
ワードではなく、パスワード登録時に、予めシステムに
用意された変換情報に基づいて変換され、利用者に通知
された複数の変換パスワードのうち、現在システムに運
用されている変換情報に対応する変換パスワードである
ので、従来のようにパスワードの変更作業や格納容量が
増大することなく、より完全な電子計算機システムの機
密保護が実現され、さらに変換情報のみを変更すること
によりパスワード変更が容易であるというシステム運用
上の効果がある。As explained above, the present invention provides that the password that allows the user to use the system is not the password registered in the system, but is converted based on conversion information prepared in advance in the system at the time of password registration, and the password that allows the user to use the system is not the password registered in the system. Among the multiple conversion passwords notified, the conversion password corresponds to the conversion information currently being used in the system, so it can be used to create a more complete electronic computer without the need to change passwords or increase storage capacity as in the past. This has the effect of system operation in that system security is achieved and passwords can be easily changed by changing only the conversion information.
第1図は本発明のパスワードによる機密保護方式の一実
施例を示す構成図、第2図、第8図はそれぞれ第1図の
パスワードによる機密保護方式のパスワード登録時、パ
スワード判定時の動作を示すフローチャートである。
1.7・・・・・・利用者(同一人)。
2・・・・・・・・・入出力インタフェース部。
8・・・・・・・・・パスワード登録処理部・4・・・
・・・・・・パスワード登録部。
5・・・・・・・・・パスワード変換のための変換情報
・6・・・・・・・・・パスワード変換部。
8・・・・・・・・・パスワード判定部。FIG. 1 is a block diagram showing an embodiment of the password-based security protection method of the present invention, and FIGS. 2 and 8 show the operations at the time of password registration and password determination, respectively, of the password-based security protection method of FIG. 1. FIG. 1.7...User (same person). 2...Input/output interface section. 8...Password registration processing section・4...
...Password registration section. 5... Conversion information for password conversion 6... Password conversion section. 8...Password determination section.
Claims (1)
ース部と、 利用者名およびそのパスワードが登録されるパスワード
登録部と、 入出力インタフェース部を介して入力された利用者名お
よびそのパスワードをパスワード登録部に登録するパス
ワード登録処理部と、 入出力インタフェース部を介して入力された前記パスワ
ードを指定された全ての変換情報を基にしてパスワード
変換し、このようにして得られた全ての変換パスワード
を当該利用者に入出力インタフェース部を介して通知す
る処理をすべての利用者について行ない、その後、利用
者がシステムを利用するために入出力インタフェース部
を介して利用者名およびパスワードを入力すると、当該
利用者の登録パスワードをパスワード登録部から入手し
て、前記登録パスワードを前記変換情報のうち現在シス
テムに運用されている変換情報に基づいてパスワード変
換する処理を行なうパスワード変換部と、 利用者がシステムを利用するために利用者名およびパス
ワードを入出力インタフェース部を介して入力すると、
該パスワードを、前記パスワード変換処理部で登録パス
ワードをパスワード変換して得られた変換パスワードと
照合して許可あるいは拒否の判定を行なうパスワード判
定部を有するパスワードによる機密保護方式。[Claims] In a computer system, an input/output interface unit between a user and the computer system; a password registration unit in which a user name and its password are registered; a password registration processing unit that registers the user name and its password in the password registration unit; and a password registration processing unit that converts the password input via the input/output interface unit based on all specified conversion information, and converts the password into a password based on all specified conversion information. The process of notifying all the converted passwords obtained in this way to the relevant users via the input/output interface section is performed for all users, and then, in order to use the system, the users When a user name and password are entered, the registered password of the user is obtained from the password registration section, and the registered password is converted into a password based on the conversion information currently operated in the system among the conversion information. When a user enters a user name and password to use the system via an input/output interface section,
A security protection system using a password, which includes a password determining unit that compares the password with a converted password obtained by converting a registered password by the password conversion processing unit to determine permission or rejection.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP60178905A JPS6238964A (en) | 1985-08-13 | 1985-08-13 | Security system by password |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP60178905A JPS6238964A (en) | 1985-08-13 | 1985-08-13 | Security system by password |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JPS6238964A true JPS6238964A (en) | 1987-02-19 |
Family
ID=16056732
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP60178905A Pending JPS6238964A (en) | 1985-08-13 | 1985-08-13 | Security system by password |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPS6238964A (en) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH09139933A (en) * | 1995-11-15 | 1997-05-27 | Nec Corp | Information network system and navigation device |
| JPH09200732A (en) * | 1996-01-19 | 1997-07-31 | Nec Corp | Network data base system and navigation system |
| US6230325B1 (en) | 1995-10-05 | 2001-05-08 | Nec Corporation | Information network system making use of television or radio broadcasting and broadcast receiving user terminal |
| US7958657B2 (en) | 2005-09-20 | 2011-06-14 | Yanmar Co., Ltd. | Fixing structure of work machine |
-
1985
- 1985-08-13 JP JP60178905A patent/JPS6238964A/en active Pending
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6230325B1 (en) | 1995-10-05 | 2001-05-08 | Nec Corporation | Information network system making use of television or radio broadcasting and broadcast receiving user terminal |
| JPH09139933A (en) * | 1995-11-15 | 1997-05-27 | Nec Corp | Information network system and navigation device |
| JPH09200732A (en) * | 1996-01-19 | 1997-07-31 | Nec Corp | Network data base system and navigation system |
| US7958657B2 (en) | 2005-09-20 | 2011-06-14 | Yanmar Co., Ltd. | Fixing structure of work machine |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7506171B2 (en) | Method and systems for securely supporting password change | |
| CN101729551A (en) | Method and system for controlling access privilege for trusted network node | |
| US20040088563A1 (en) | Computer access authorization | |
| CN108597066A (en) | A kind of caller management method, device and computer readable storage medium | |
| JPS6238964A (en) | Security system by password | |
| MXPA04007410A (en) | Moving principals across security boundaries without service interruption. | |
| Jøsang | IAM—Identity and Access Management | |
| JP2002109172A (en) | RECORDING MEDIUM WHICH RECORDED PROGRAM FOR AUTHENTICATION AUTHORIZATION | |
| US11341268B2 (en) | System and method for storing digital data with enhanced privacy | |
| JPS62242273A (en) | Security management system | |
| JPH03156662A (en) | Password input/processing method | |
| CN113704812A (en) | Dynamic configuration method for user access browsing authority | |
| JPH05242037A (en) | Security method | |
| JPH0237456A (en) | Password exchange system | |
| JPH04320564A (en) | User certification system | |
| JP2004295493A (en) | Authentication device, its method and its program | |
| JPS6154562A (en) | Japanese input device | |
| KR20020017409A (en) | Limiting method for user working by password | |
| JPH03148744A (en) | Password checking system | |
| JPH0476657A (en) | Log-in restriction system | |
| JPS6375871A (en) | How to protect word processor security | |
| CN115758303A (en) | Authority control method, device, equipment and storage medium | |
| JPH01198849A (en) | Security protecting system for information | |
| JPH06259381A (en) | Password matching processor | |
| Ekundayo et al. | A TWO FACTOR AUTHENTICATION PROTECTIVE SYSTEM FOR MANAGING USER LOGIN CREDENTIALS |