WO2011077512A1 - 本人認証方法、本人認証システム及び携行型通信端末 - Google Patents

本人認証方法、本人認証システム及び携行型通信端末 Download PDF

Info

Publication number
WO2011077512A1
WO2011077512A1 PCT/JP2009/071277 JP2009071277W WO2011077512A1 WO 2011077512 A1 WO2011077512 A1 WO 2011077512A1 JP 2009071277 W JP2009071277 W JP 2009071277W WO 2011077512 A1 WO2011077512 A1 WO 2011077512A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
information
authentication key
terminal
storage medium
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2009/071277
Other languages
English (en)
French (fr)
Inventor
杉中順子
古川義久
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Priority to KR1020127018923A priority Critical patent/KR20120099782A/ko
Priority to PCT/JP2009/071277 priority patent/WO2011077512A1/ja
Priority to JP2011547128A priority patent/JPWO2011077512A1/ja
Priority to US13/516,044 priority patent/US20120254955A1/en
Priority to CN2009801631145A priority patent/CN102667798A/zh
Priority to EP09852529A priority patent/EP2518659A1/en
Publication of WO2011077512A1 publication Critical patent/WO2011077512A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/42User authentication using separate channels for security data
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0866Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3234Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices

Definitions

  • the present invention relates to an authentication technology for authenticating the legitimacy of a person who uses an information processing terminal connected to a network.
  • Patent Document 1 describes an authentication technique that uses the presence location and authentication date and time obtained using a clock circuit and a GPS receiver in addition to the fingerprint data of the terminal user. Patent Document 1 describes that information that can identify a living body such as an iris or a vein can be used in addition to a fingerprint.
  • Patent Document 2 describes a network system that enables transactions from a personal computer (hereinafter referred to as a personal computer) at a destination via a network.
  • Patent Document 2 when a password is transmitted by e-mail from a center server to a user's mobile phone during a transaction, the user looks at the received password and enters a key in a password input field of a personal computer. To enter a password. Then, it is described that the entered information is transmitted to the center server and verified with the original password (paragraph numbers 500 to 502). As a result, procedure processing, login, and transaction processing can be performed safely on a personal computer other than the personal computer owned by the user. Note that Patent Document 2 describes that a user may return a mail received by a mobile phone to the center server (paragraph number 503).
  • Patent Document 1 While the authentication technique described in Patent Document 1 is superior in that it uses individual information called fingerprints, fingerprints and the like are easily forged and whether or not the fingerprint data to be authenticated is forged. It is not easy to identify.
  • the network system described in Patent Document 2 forces a user to perform a password input operation that is almost the same as a conventional password input operation to a personal computer while looking at the screen of a mobile phone. There is a high risk of being known to others.
  • the password may be obtained by wireless eavesdropping and may be used illegally.
  • Patent Document 2 if only the password input operation is cleared, the personal computer can be used illegally thereafter, which is not perfect.
  • An object of the present invention is to authenticate the portable storage medium in a mounted state and pass through the portable storage medium with respect to a portable storage medium that is attached to an information processing terminal and permits execution of predetermined information processing. It is an object of the present invention to provide a personal authentication method, a personal authentication system, and a portable communication terminal used in the system that can effectively prevent an unauthorized passing operation of the authentication process by performing personal authentication.
  • the personal authentication system is the personal authentication system for authenticating the presence or absence of a legitimate owner of a portable storage medium that allows execution of predetermined information processing by being attached to an information processing terminal connected to a network.
  • An authentication server connected to a network and authenticating whether or not the owner is authorized the portable storage medium includes an identification information storage unit for storing identification information, and a radio base station possessed by the authorized owner
  • a first short-range communication unit that performs short-range communication with a portable communication terminal capable of transmitting and receiving information via an information transmission system, wherein the authentication server identifies the portable storage medium In association with the information, the electronic information of the portable communication terminal possessed by the rightful owner of the portable storage medium, and a related information storage unit in which unique authentication key information is stored
  • the information processing terminal includes an authentication request processing unit that detects attachment of the portable storage medium, acquires the identification information, and transmits a signal including the acquired identification information to the authentication server; and the identification information After acquiring the authentication key information from the authentication server via the portable communication terminal and the portable storage
  • the personal authentication method is a personal authentication method for authenticating the presence or absence of a legitimate owner of a portable storage medium that is permitted to execute predetermined information processing by being attached to an information processing terminal connected to a network.
  • An authentication server that is connected to the network and authenticates whether or not it is the rightful owner, and the associated information storage unit of the authentication server is associated with the identification information of the portable storage medium in association with the portable storage medium
  • Electronic address information of the portable communication terminal possessed by the rightful owner of the medium and unique authentication key information are stored, and the authentication request processing means of the information processing terminal detects attachment of the portable storage medium Then, the identification information stored in the portable storage medium is acquired, a signal including the acquired identification information is transmitted to the authentication server, and authentication key information processing of the authentication server is performed.
  • the stage reads the authentication key information and electronic address information corresponding to the identification information included in the received signal including the identification information from the related information storage unit, and reads the read authentication key information.
  • a portable communication terminal capable of transmitting and receiving information via an information transmission system having a radio base station owned by the rightful owner.
  • the authentication key relay processing means of the information processing terminal authenticates from the authentication server via the portable communication terminal and the portable storage medium after transmitting a signal including the identification information.
  • key information is acquired, the acquired authentication key information is transmitted to the authentication server, and a determination unit of the authentication server transmits the authentication key information to the electronic address.
  • a determination unit of the authentication server transmits the authentication key information to the electronic address.
  • predetermined information processing when it is authenticated that the portable storage medium attached to the information processing terminal is possessed by the rightful owner, predetermined information processing can be executed via the network.
  • the network is connected to an authentication server that authenticates whether or not the owner is the rightful owner.
  • electronic address information for example, electronic
  • E-mail address E-mail address
  • unique authentication key information are stored.
  • the authentication request processing means of the information processing terminal detects attachment of the portable storage medium, acquires identification information stored in the portable storage medium, and a signal including the acquired identification information. Sent to the authentication server.
  • authentication key information and electronic address information corresponding to the identification information included in the received signal including the identification information are read from the related information storage unit by the authentication key information processing means of the authentication server, The read authentication key information is transmitted to the read electronic address.
  • a portable communication terminal capable of transmitting and receiving information via the information transmission system (for example, public telephone line) possessed by the rightful owner and possessed by the short-range communication unit of the portable storage medium.
  • the authentication key information is acquired via.
  • the authentication key relay processing means of the information processing terminal acquires the authentication key information from the authentication server via the portable communication terminal and the portable storage medium after transmitting the signal including the identification information.
  • the acquired authentication key information is transmitted to the authentication server.
  • the authentication key information processing unit transmits the authentication key information. It is determined whether or not the authentication key information is different.
  • a portable storage medium is given (including lending) to the terminal user, and the personal authentication is made possible by using the portable storage medium and the portable communication terminal possessed by the terminal user. That is, on the condition that the validity of the portable storage medium attached to the terminal is determined by the authentication server, the authentication key information is transferred from the authentication server to the portable communication terminal, for example, by e-mail.
  • the authentication key sent by the authentication server can be transmitted from the terminal wearing the portable storage medium to the authentication server via the network by short-range communication from the mobile terminal to the portable storage medium attached to the terminal. By verifying the received authentication key, personal authentication can be performed.
  • the authentication key transmitted by the e-mail is transmitted from the portable communication terminal to the portable storage medium by short-range communication, so that the terminal user can use his portable storage medium and his portable communication terminal.
  • the portable storage medium is stolen, an illegal slip-through operation of the personal authentication process is reliably prevented systematically.
  • the portable communication terminal is the portable communication terminal used in the personal authentication system, and is a second short-range communication that performs short-range communication with the first short-range communication unit. And a near field communication control means for transmitting the received authentication key information from the second near field communication unit to the first near field communication unit when receiving the authentication key information from the authentication server. ing.
  • the portable communication terminal since the portable communication terminal includes the second short-range communication unit and transmits the authentication key to the portable storage medium, the personal authentication process can be performed even if the portable storage medium is stolen. Unauthorized slip-through processing is reliably prevented.
  • the present invention it is possible to effectively prevent unauthorized slipping of the personal authentication process by interposing near field communication between the portable communication terminal and the portable storage medium.
  • FIG. 1 is a schematic configuration diagram of a network system to which a personal authentication system according to the present invention is applied.
  • FIG. 2 is a configuration diagram in which functions of the terminal 1, the USB memory 2, the authentication server 4, the mail system 5, and the mobile phone 6 are blocked.
  • FIG. 6 is a sequence diagram showing an outline of the flow of information related to personal authentication among the USB memory 2, the terminal 1, the authentication server 4, and the mobile phone 6.
  • 4 is a flowchart illustrating an example of a USB port state detection procedure executed by the CPU of the terminal 1. It is a flowchart which shows an example of the procedure of the authentication process I performed by CPU of the authentication server 4. It is a flowchart which shows an example of the procedure of the authentication process II performed by CPU of the authentication server 4.
  • 5 is a flowchart illustrating an example of a procedure of an authentication key creation process executed by a CPU of the authentication server 4.
  • 10 is a flowchart showing an example of a procedure of processing I executed by the CPU of the mobile phone 6.
  • 4 is a flowchart illustrating an example of a procedure of USB processing I executed by the CPU of the terminal 1.
  • 4 is a flowchart illustrating an example of a procedure of USB processing II executed by the CPU of the terminal 1.
  • 10 is a flowchart showing an example of a procedure of a process II executed by the CPU of the mobile phone 6;
  • FIG. 1 is a schematic configuration diagram of a network system to which a personal authentication system according to the present invention is applied.
  • the network system shown in FIG. 1 includes, for example, a terminal (information processing terminal) 1 that is a member, a consumer, a store, a company, or the like, and a terminal (information processing terminal) 1 arranged in one or more financial institutions that perform settlement. And a member server 3 disposed in a management organization that performs overall management and storage of information between the terminal 1 and the terminal 1.
  • Each terminal 1 and member server 3 are connected to a network 7 such as the Internet.
  • the terminal 1 is generally composed of a personal computer or the like with a built-in CPU (Central Processing Unit).
  • general information such as information creation, processing, storage, and transmission / reception of information using communication software using general document and graphic generation software is used.
  • a program file (referred to as general-purpose AP (application program)) for executing each process and a program file (referred to as specific AP) for performing processes related to execution of specific application software described later are stored.
  • the terminal 1 such as a consumer, a store, or a company that is a member performs the creation and communication of each document relating to the purchase and sale of goods and services, estimation or billing, and deposit / withdrawal as a specific AP.
  • Software and authentication processing software to be described later are installed.
  • the terminal 1 performs settlement in general commercial transactions, for example, issuance and receipt of invoices from a merchant store, and deposit (i.e., payment) instructions from the purchaser to the account of the contract financial institution that issued the invoice.
  • deposit i.e., payment
  • the terminal 1 can create various documents as electronic files in text format or binary format.
  • the electronic file is exchanged between the terminals 1 via the member server 3, for example.
  • Special application software that performs payment instruction processing (such as instructions for payment processing between financial institutions) in accordance with the financial payment document from the terminal 1 of the consumer or company is also installed in each financial institution terminal 1. ing.
  • the terminal 1 has a USB port to which a portable storage medium (member external storage medium), for example, a chip-shaped USB (Universal Serial Bus) memory 2 can be attached (connected).
  • the storage medium may be stick-like hardware using an IEEE 1394 port.
  • the USB memory 2 is given to members and has a storage unit (area) in which predetermined information can be stored as will be described later.
  • the USB memory 2 is provided with short-range communication means such as Bluetooth in an appropriate place such as the inside of a chip-shaped main body.
  • the short-range communication means is not limited to wireless (radio waves, light), but is preferably a wireless type in terms of operability.
  • the short-range communication method is not limited to Bluetooth, but may be wireless LAN (Local area network), RFID (Radio Frequency Identification) or the like.
  • the member server 3 stores appropriate information related to members, for example, member information such as a member's name, name, e-mail address, and address in units of members.
  • the member server 3 further includes a storage unit for storing the file transmission / reception history of each member and the files thereof for management.
  • the member server 3 includes a functional unit as the authentication server 4.
  • the authentication server 4 is connected to the network 7 and is in a state where a file exchanged between the member server 3 and the terminal 1, that is, a packet can be viewed.
  • the relationship between the member server 3 and the authentication server 4 may be a serial or parallel connection relationship, and the packet transmitted from the terminal 1 to the member server 3 realizes the authentication processing in the present invention. Any mode can be used as long as it can be browsed in a possible range.
  • this system creates and stores secret information, for example, information communication between a plurality of terminals 1 connected to a LAN in a corporate organization that is a public institution.
  • secret information for example, information communication between a plurality of terminals 1 connected to a LAN in a corporate organization that is a public institution.
  • the terminal 1 is connected to a network 7 via a provider (ISP) 8.
  • ISP provider
  • a plurality of terminals 1 are connected to the ISP 8.
  • an appropriate number of servers having Web sites that provide various types of information are connected to the ISP 8.
  • the terminal 1 connected to the ISP 8 includes a member-owned terminal 1 in which the specific AP is installed and a normal terminal 1 ′ in which the specific AP is not installed.
  • a part of the specific AP has a program for performing an authentication process, and controls whether or not to execute the specific AP according to the authentication result.
  • the legitimacy of the member who uses the USB memory 2 that is, a portable communication terminal that can carry out personal authentication, typically a mobile phone 6 that can send and receive e-mails is used.
  • a mail system 5 of a mobile phone company is used as a mechanism for sending and receiving e-mail.
  • the configurations of the mail system 5 and the mobile phone 6 will be described with reference to FIG.
  • the portable communication terminal 6 may be a PDA (Personal Digital Assistant) in addition to the mobile phone 6.
  • FIG. 2 shows a block diagram in which the functions of the terminal 1, the USB memory 2, the authentication server 4, the mail system 5, and the mobile phone 6 are respectively blocked.
  • the terminal 1 includes a control unit 11 configured by a CPU, and a ROM (Read Only Memory) 12 and a RAM (Random Access Memory) 13 are connected to the control unit 11.
  • the control unit 11 is connected to an operation unit 14 including a numeric keypad and a mouse, and a display unit 15 including an CRT, a liquid crystal display, a plasma display, or the like and displaying an image.
  • the ROM 12 includes at least an OS storage unit 121 that stores an OS (Operating System), a BIOS (Basic Input / Output System), and the like for starting the terminal 1 (boot processing) and reading application software.
  • OS Operating System
  • BIOS Basic Input / Output System
  • the RAM 13 includes a general-purpose AP storage unit 131 in which the above-described general application software is installed, and a specific AP storage unit 132 in which specific application software related to processing such as authentication, electronic commerce service, and administrative service is installed. And at least a creation file storage unit 133 for storing a text file or a file created by a binary code created by a general-purpose AP or a specific AP.
  • the files stored in the created file storage unit 133 include not only files created by the user but also transmitted and received files.
  • the specific AP is taken in via an external storage medium in advance or at a predetermined time. For example, it is installed from a predetermined server (may be the member server 3) on the network or from an external storage medium such as a hard disk at the time of member registration.
  • the control unit 11 is equipped with a USB communication processing unit 111 for communicating with the USB memory 2 and the USB memory 2 mounted on the USB port Po of the terminal 1 by executing a program stored in the ROM 12 and the RAM 13 by the CPU.
  • a mounting detection unit 112 that detects whether or not the USB memory 2 has been identified; a USBID acquisition unit 113 that acquires identification information (USBID) for identifying the USB memory 2 from the USB memory 2; and an authentication request processing unit that transmits an authentication request signal to the authentication server 4 114, an authentication key acquisition unit 115 that acquires authentication key information from the USB memory 2, an authentication result processing unit 116 that acquires authentication result information from the authentication server 4 and performs processing according to the authentication result, and a designated program.
  • Network communication processing for sending and receiving document files between the member server 3 and the authentication server 4, typically sending and receiving document files using packets formed in accordance with TCP / IP (transmission control protocol / internet protocol) rules It functions as the unit 118.
  • the network communication processing unit 118 returns the received packet to the original document file or replaces the transmission file with the packet and transmits the packet.
  • the header of each packet to be transmitted includes the terminal that is the transmission source. 1 global IP address, the global IP address of the other terminal that is the transmission destination and the member server 3, and the USB ID of the USB memory attached to the terminal 1 and at least the first authentication key are included. .
  • the USB memory 2 includes a configuration unit 20 in which information is stored and a short-range communication transmission / reception unit 21 that is a configuration unit that performs short-range communication.
  • the configuration unit 20 that stores information includes a USBID storage unit 201 in which a USBID for identifying the USB memory 2 is stored, information used in session processing to be described later (information for identifying itself “passkey: PIN (Personal IdentificationIdentNumber))
  • the information storage unit 202 stores information received in the session.
  • the near field communication transmitting / receiving unit 21 includes an antenna for transmitting and receiving electromagnetic waves in the above-described Bluetooth or the like, and performs near field communication with the mobile phone 6 and Bluetooth as described later.
  • the near field communication processing unit 203 controls the operation of the near field communication transmitting / receiving unit 21 by receiving a required signal from the terminal 1 or receiving a required control program while being attached to the terminal 1. And controls the session operation.
  • the attachment detection unit 112 of the terminal 1 detects whether or not the USB memory 2 is attached from the presence or absence of a response signal from the USB port Po in a predetermined handshake process.
  • the USBID acquisition unit 113 reads and acquires the USBID from the USBID storage unit 201 when the USB memory 2 is attached.
  • the authentication request processing unit 114 When the USB memory 2 is attached, the authentication request processing unit 114 generates an authentication request signal including a USB ID, converts the signal into a predetermined packet, and transmits the packet to the authentication server 4.
  • the authentication key acquisition unit 115 acquires the authentication key information from the USB memory 2 after transmitting the authentication request signal
  • the authentication key acquiring unit 115 converts the authentication key into a predetermined packet and transmits the packet to the authentication server 4.
  • the authentication result processing unit 116 receives the authentication result transmitted from the authentication server 4. If the authentication result is successful, the program execution processing unit 117 permits only the specific AP to execute, and is not successful (failed). In this case, a signal permitting the execution of only the general-purpose AP is output to the program effective processing unit 117.
  • the authentication server 4 performs file transmission / reception between the terminal 1 and the member server 3 by executing a specific AP (specifically, the member server 3 relays the other server 1 and the document It is continuously executed while file transmission / reception is performed.
  • a specific AP specifically, the member server 3 relays the other server 1 and the document It is continuously executed while file transmission / reception is performed.
  • the authentication server 4 includes a control unit 41 including a CPU, a ROM 42 in which an authentication processing program is stored, and a RAM 43 in which authentication information is stored.
  • the RAM 43 stores the USBID / portable electronic device in which the USBID of the USB memory 2 assigned to each member, the e-mail address of the mobile phone 6 possessed by each member, and the authentication key for personal authentication are stored in association with each other. It has a mail address / authentication key (hereinafter referred to as related information) storage unit 431.
  • the control unit 41 executes the program stored in the ROM 42 by the CPU, thereby determining the validity of the read USBID, the packet monitoring unit 411 that reads the USBID and the authentication key in the packet transmitted from the terminal 1
  • the USB validity determination unit 412 transmits the authentication key corresponding to the USBID determined to be valid by e-mail to the corresponding mobile e-mail address, and then the USBID source determined to be valid
  • a first authentication processing unit 413 that performs verification (initial authentication) with an authentication key received from a certain terminal 1. Every time a packet is received from the terminal 1 after the initial authentication, the USBID included in the received packet and the initial authentication are acquired.
  • the second authentication processing unit 414 for collating the difference with the USBID, and the authentication key at a predetermined timing
  • it functions as a mobile electronic mail communication processing unit 417 that converts authentication key information into an electronic mail packet and transmits it to a predetermined mobile phone 6 (via the mobile phone company mail system 5 described above).
  • the portable electronic mail communication processing unit 417 functions as a so-called mail server, and converts a transmission mail into, for example, an Internet mail format and transmits it.
  • the USB validity determination unit 412 compares the read USBID with a list of USBIDs that are the original information stored in advance in the related information storage unit 431, and determines that there is a validity if there is a matching USBID. Is. If the matching USBID cannot be found, the USB validity determination unit 412 does not need to perform authentication key authentication processing. Information indicating that the USB validity is not valid and the USB memory 2 is not valid. Is returned to the terminal 1 on which is mounted, and subsequent communication is interrupted.
  • the authentication process is continuously performed while the USB memory 2 is attached to the terminal 1. Specifically, when the USBID transmitted from the terminal 1 is valid, the first authentication processing unit 413 transmits the authentication key transmitted to the corresponding mobile phone 6 via the mobile phone 6, the USB memory 2, and the terminal 1. If the two authentication keys are matched and matched, the authentication success information is returned to the terminal 1. On the other hand, if the two authentication keys are collated and they do not match, information indicating that the terminal 1 cannot be authenticated (authentication failure) is returned. The information on the authentication failure can be used as a mode for guiding a retry (operation for remounting the USB memory 2) up to a predetermined number of times by counting the number of times with a built-in counter (not shown) or the like.
  • the process by the first authentication processing unit 413 is the first authentication process.
  • the second authentication processing unit 414 temporarily stores this initial authentication as a first time in, for example, an appropriate location in the RAM 43, and then stores a file, that is, a packet with the terminal 1. While transmission / reception is performed, it is verified whether or not the USBID included in the header in the packet received from the terminal 1 matches the USBID acquired during the initial authentication process. If the collation results match, the communication is continued assuming that the second and subsequent authentications are established, and conversely, in the authentication process at any stage after the second, It is assumed that the USB memory 2 has been replaced in the middle or that there has been other illegal acts, and communication with the terminal 1 is interrupted.
  • the authentication key creation unit 415 includes only the authentication key among the information corresponding to the USB ID after the USB memory 2 is attached to the terminal 1 and the required processing by the member is completed until it is attached next time. Is to change.
  • the authentication key may be changed in response to the USB memory 2 being attached to the terminal 1 and the USBID being read, and thereafter, at least the next time the USB memory 2 is connected to any terminal. What is necessary is just to change before mounting to 1.
  • the authentication key is preferably changed at random by using a random number generator or the like.
  • the authentication key is updated by rewriting the current authentication key corresponding to the corresponding USBID in the related information storage unit 431.
  • the mail system 5 functions as an information transmission system, is connected to the network 7 via the ISP 8, and includes an information processing unit 51 and a required number of wireless base stations 52.
  • the base station 52 is a transmission / reception unit that has an antenna and transmits / receives radio waves to / from the mobile phone 6.
  • a required number of mail systems 5 may be provided for load distribution. Similarly, as many base stations as necessary are provided for the purpose of expanding the call area.
  • the information processing unit 51 is a mail gateway that performs conversion between the format and protocol of the electronic mail transmitted / received by the mobile phone 6 and the format and protocol of the electronic mail transmitted over the Internet and transmitted / received to the authentication server 4. 511, a portable electronic mail server 512 that controls transmission and reception of electronic mail, and a mail box 513 that temporarily stores electronic mail to be transmitted and received.
  • the mobile phone 6 includes an antenna 60 that is provided in the main body and performs transmission and reception of radio waves, and a control unit 61 that is provided in the main body and includes a CPU.
  • the control unit 61 includes a ROM 62 that stores various control programs for short-distance session communication for personal authentication processing, authentication key reception, and session result reporting in addition to normal call processing and e-mail transmission / reception processing.
  • a RAM 63 is connected to store transmission information and reception information, and an e-mail address of the authentication server, a passkey and other information that is information for identifying the corresponding USB memory 2.
  • an operation unit 64 composed of various function keys such as a numeric keypad and a display unit 65 such as a liquid crystal panel for displaying processing information and reception information are disposed at appropriate positions on the main body surface of the cellular phone 6.
  • the near field communication transmitting / receiving unit 66 includes an antenna for transmitting / receiving electromagnetic waves in the above-described Bluetooth or the like, and performs near field communication with the USB memory 2 and Bluetooth as described later.
  • the control unit 61 controls the operation of the near field communication transmitting / receiving unit 66 by the control program stored in the ROM 62 being executed by the CPU, and controls the session operation, the near field communication processing unit 611, the USB connection It has a status monitoring unit 612, an authentication key acquisition unit 613, a portable electronic mail communication processing unit 614, and a timer 615 for timing.
  • the near field communication processing unit 611 Upon receiving the authentication key transmitted from the authentication server 4, the near field communication processing unit 611 transmits a signal for performing a predetermined session with the USB memory 2, and a response signal is received with respect to the transmitted signal. Then, a session is started, an authentication key is transmitted, and thereafter a signal for the session is continuously exchanged.
  • the short-range communication processing unit 611 and the short-range communication processing unit 203 when the USB memory 2 and the mobile phone 6 are within a short distance, for example, 1 m (meter), which is a communication range of each other, the USB memory 2 This is continued until the terminal 1 is disconnected.
  • the transmission / reception surfaces face each other and be disposed at a predetermined short distance.
  • the USB connection state monitoring unit 612 performs a predetermined session with the short-range communication processing unit 203 of the USB memory 2, so that the USB connection state monitoring unit 612 is in the vicinity of the USB memory 2 attached to the terminal 1. It is determined whether or not the mobile phone 6 exists. That is, the USB connection state monitoring unit 612 determines that the mobile phone 6 does not originally exist in the vicinity of the terminal 1 unless a session with the short-range communication transmitting / receiving unit 21 occurs, and if the session is interrupted in the middle. Then, it is determined that the mobile phone 6 has moved away from the terminal 1 on the way, and both are abnormally terminated as will be described later.
  • the USB connection state monitoring unit 612 determines that the mobile phone 6 has been in the vicinity of the terminal 1 until the end, and does not end abnormally.
  • the mobile phone 6 transmits a signal indicating a failure of the authentication process to the authentication server 4.
  • the monitoring (judgment) of the continuity of the session by the USB connection state monitoring unit 612 is executed by measuring a required interval within about ten seconds or one minute with the timer 615, for example.
  • the authentication key acquisition unit 613 receives an authentication key transmitted from the authentication server 4 via the electronic mail system 5 and passes it to the near field communication processing unit 611.
  • the portable electronic mail communication processing unit 614 transmits and receives authentication key information, information indicating session failure, and the like to and from the authentication server 4 in the form of electronic mail.
  • FIG. 3 is a sequence diagram showing an outline of the flow of information relating to personal authentication among the USB memory 2, the terminal 1, the authentication server 4, and the mobile phone 6.
  • the member attaches his / her USB memory 2 to the USB port Po of the target terminal 1. With this attachment, a handshake process is executed between the terminal 1 and the USB memory 2.
  • the USBID is read from the USB memory 2 to the terminal 1.
  • the terminal 1 generates an authentication request signal including the acquired USBID, converts it into a transmission packet, and transmits it to the authentication server 4. Thereby, the first authentication process is started.
  • the authentication server 4 checks the validity of the USBID, and if it is valid, sends an authentication key corresponding to the USBID to the corresponding mobile phone 6 by e-mail.
  • the mobile phone 6 transmits the received authentication key to the USB memory 2 by near field communication. Then, the authentication key received by the USB memory 2 is transmitted to the authentication server via the terminal 1.
  • the authentication server 4 determines the difference between the authentication key transmitted to the mobile phone 6 and the authentication key received from the terminal 1, and determines that the authentication is successful if they match, and determines that the authentication fails if they do not match. .
  • the authentication result is transmitted to the terminal 1. If the authentication result is an authentication failure, the fact is transmitted to the mobile phone 6 via the USB memory 2. Thereby, near field communication is cut off. In addition, the member can retry.
  • a required file is transferred into a packet between the terminal 1 and the authentication server 4 (specifically, between the terminal 1 and the member server 3 via the authentication server 4). Converted and sent / received. Therefore, the USBID of the USB memory 2 written in the header of the packet transmitted from the terminal 1 to the authentication server 4 is included so that the second and subsequent authentications are performed while the USB memory 2 is attached to the terminal 1. Processing is performed continuously.
  • the authentication server 4 monitors the header information of the packet transmitted from the terminal 1, and extracts the USBID from the header information. And the difference with USBID acquired from the terminal 1 at the time of the first authentication process is collated. Here, if the authentication fails, the fact is transmitted to the terminal 1.
  • the specific AP process that is activated by the success of the first authentication process includes simply document creation in addition to communication, but the second and subsequent authentications are interrupted during processes other than packet transmission / reception. Will be. Further, even during the interruption period, an authentication packet including the USBID may be created periodically or periodically and transmitted to the authentication server 4.
  • FIG. 4 is a flowchart showing an example of the USB port state detection procedure executed by the CPU of the terminal 1.
  • a handshake signal is periodically transmitted to the USB port Po, and the state of the USB port Po is determined (step S1).
  • a response signal is returned in response to the handshake signal.
  • the USB memory 2 is not attached, no response signal is returned. Exit this flow.
  • a specific AP in the specific AP is activated, assuming that some chip including the USB memory 2 is attached.
  • the dedicated AP activates communication application software for determining whether or not the mounted chip is the USB memory 2 and for executing processing for reading the internal information when the chip is the USB memory 2.
  • step S1 when there is a response from the USB memory 2, the USB ID is read from the USB ID storage unit 201 (step S3).
  • step S5 an authentication request signal (packet) including the USBID is created (step S5).
  • step S7 the created authentication request signal is transmitted to the authentication server 4 (step S7).
  • step S9 the process shifts to a standby mode waiting for reception of a packet from the authentication server 4 (step S9).
  • USB port state detection process may be performed by a general-purpose AP instead of the specific AP. Then, after the mounting of the chip is detected in the USB port Po, the processing may be transferred to the specific AP.
  • FIG. 5 is a flowchart showing an example of the procedure of the authentication process I executed by the CPU of the authentication server 4.
  • the authentication process I refers to an initial authentication process.
  • step # 1 it is determined whether or not an authentication request signal has been received from the terminal 1 (step # 1). If the authentication request signal has not been received, this flow is exited. On the other hand, if the authentication request signal is received, the USBID is read from the packet (step # 3). Next, the USBID list in the related information storage unit 431 is searched for whether or not there is the same information as the read USBID, and the presence or absence of validity is determined (step # 5). If there is the same information in the list, it is determined that the information is valid (Y in step # 7). On the other hand, if there is no identical information, it is determined that there is no legitimacy (N in step # 7), and this flow is exited.
  • the e-mail address of the mobile phone 6 corresponding to the USBID that is currently determined to be valid is extracted from the related information storage unit 431 (step # 9), and further, this USBID is supported.
  • the authentication key is extracted (step # 11). Then, the extracted authentication key is transmitted to the extracted e-mail address by the portable e-mail communication processing unit 417 of the authentication server 4 (step # 13).
  • the predetermined time is a time set slightly longer than the time required for the authentication key information output from the authentication server 4 in step # 13 to return via the mobile phone 6, the USB memory 2, and the terminal 1. Thus, the time is measured by a timer (not shown) in the control unit 11.
  • the authentication key is acquired (from the terminal 1 that is the transmission source of the authentication key) within a predetermined time (step # 17)
  • the authentication key transmitted in step # 13 is different from the authentication key received in step # 15. Are collated (step # 19).
  • an authentication failure signal is returned to the terminal 1 (step # 23).
  • This authentication failure signal is treated as prompting the authentication retry for the required number of times. That is, the member reconfirms that the USB memory 2 is correct, for example, by displaying an authentication failure signal on the display unit 15 of the terminal 1, and prompts the user to insert the USB port Po of the terminal 1 again.
  • the required number of times can be monitored by counting the authentication failure signal with a counter (not shown) and comparing the number with a set number value.
  • step # 21 if the transmitted authentication key matches the received authentication key, an authentication success signal is transmitted to the terminal 1 (step # 25), and further communication with the terminal 1 is permitted. Perform (step # 27).
  • FIG. 6 is a flowchart showing an example of the procedure of the authentication process II executed by the CPU of the authentication server 4.
  • the authentication process II refers to the authentication process for the second and subsequent times.
  • the USBID at that time is temporarily stored in a suitable place in the RAM 43 of the authentication server 4 in association with the terminal 1 (IP address), and the specific AP is executed, so that the terminal 1 Between the authentication server 4 and the authentication server 4 (specifically, the member server 3). Then, it is determined whether or not the packet transmitted from the terminal 1 has been received based on the IP address of the terminal 1 (step # 41).
  • step # 41 the USBID is read from the header of the packet (step # 43). Then, the USBID (referred to as the first USBID) used in the validity judgment at the time of the first authentication in the terminal 1 is compared with the USBID read from the current packet (step # 45). If the first USBID and the current USBID match, this flow is exited as a successful authentication. On the other hand, if the first USBID and the current USBID do not match, communication with the specific AP with the terminal 1 is blocked (step # 51), and an authentication failure signal is transmitted to the terminal 1 (step #). 53).
  • the first USBID and the current USBID do not match, communication with the specific AP with the terminal 1 is blocked (step # 51), and an authentication failure signal is transmitted to the terminal 1 (step #). 53).
  • step # 49 it is determined whether or not a session failure e-mail is received from the mobile phone 6 corresponding to the terminal 1 (step # 49). If no session failure e-mail has been received, this flow is exited. Conversely, if a session failure e-mail has been received, the process proceeds to step # 51.
  • FIG. 7 is a flowchart showing an example of the procedure of the authentication key creation process executed by the CPU of the authentication server 4.
  • the time when the authentication key is created is a period from when the USB memory 2 is removed from the terminal 1 until the next time the USB memory 2 is attached to the terminal 1 (regardless of whether it is different from the terminal 1 attached last time) and further removed. Of a certain preset time. For example, it may be when the first USBID is received from the terminal 1 by the authentication server 4 or when the USB memory 2 is removed from the terminal 1.
  • step # 63 the authentication key is randomly created.
  • step # 65 the created authentication key is associated with the corresponding USBID or portable e-mail address in the related information storage unit 431 and updated and stored. In this way, by changing the authentication key every time and at random like One time password, even if it is wiretapped, it can be made useless next time.
  • FIG. 8 is a flowchart showing an example of the procedure of the process I executed by the CPU of the mobile phone 6.
  • step T1 it is determined whether or not an authentication key has been received by e-mail from the authentication server 4 (step T1). If the authentication key has not been received, this flow is exited.
  • step T3 a connection command is transmitted to the USB memory 2 having the pass key prior to the session with the USB memory 2 (step T3). That is, the mobile phone 6 stores the e-mail address of the authentication server 4 and automatically receives a predetermined information from the e-mail address, that is, the authentication key information here, for the session. Transition to connection command transmission processing. Instead of automatically shifting to the session, instruction information for instructing the operation of starting the session by short-range communication may be transmitted to the holder of the mobile phone 6.
  • the pairing process is a session pre-process, and is a process of associating the mobile phone 6 and the USB memory 2 having a corresponding relationship with each other with predetermined information, for example, a passkey.
  • connection it is determined whether or not the connection is successful (step T5). If the connection is successful, a session is performed. For example, by using a GAP (Generic Access Profile) that is a profile for connecting / authenticating / encrypting a device, connection is performed using information of a passkey. When the connection is established, data transfer is performed using FTP (File Transfer Profile) which is a profile for performing data transfer.
  • GAP Generic Access Profile
  • FTP File Transfer Profile
  • step T7 session processing is started as described above, and an authentication key is first transmitted to the USB memory 2 of the pairing destination (step T7). Subsequently, it is determined whether or not a response signal has been received from the USB memory 2 (step T9). If it has been received, a given time within a predetermined time (for example, about ten seconds to one minute) is received. It is determined whether or not (time) has elapsed (step T11). When a certain time has elapsed, a response request signal is transmitted (step T13), and then it is determined whether or not a response signal is received from the USB memory 2 (step T15).
  • a predetermined time for example, about ten seconds to one minute
  • step T17 whether or not the USB memory 2 has been removed from the terminal 1 is determined, for example, based on whether or not a signal indicating that the USB memory 2 has been removed has been received. If the USB memory 2 has been removed from the terminal 1, this flow ends. On the other hand, if the USB memory 2 is not removed from the terminal 1, the process returns to step T11.
  • a session failure signal indicating a connection failure at the start of the session or a disconnection during the session is transmitted to the authentication server 4 by e-mail (step T19).
  • FIG. 9 is a flowchart showing an example of the procedure of the USB process I executed by the CPU of the terminal 1. Note that the USB processing I and the USB processing II described later may be executed in such a manner that the CPU is built in the USB memory 2 and the processing programs for the USB processing I and II are stored in the information storage unit 202.
  • step Q1 it is determined whether a signal for a session, here, the connection command is received from the mobile phone 6 (step Q1). If the command has not been received, the flow exits. On the other hand, if the signal is received, a passkey is returned as a response signal (step Q3). Subsequently, it is determined whether or not an authentication key has been received (step Q5). If no authentication key has been received, the process exits this flow. On the other hand, if the authentication key is received, the received authentication key is sent to the terminal 1 (step Q7).
  • step Q11 it is determined whether or not the USB memory 2 has been removed from the terminal 1 (step Q13). If it has not been removed, the process returns to step Q9 to determine whether or not a response request signal has been received. In this way, the session is continued until the USB memory 2 is removed from the terminal 1.
  • FIG. 10 is a flowchart illustrating an example of the procedure of the USB processing II executed by the CPU of the terminal 1.
  • FIG. 11 is a flowchart showing an example of the procedure of the process II executed by the CPU of the mobile phone 6.
  • step T31 it is determined whether an authentication failure signal has been received from the USB memory 2 (step T31). If the authentication failure signal is not received, the process exits this flow. On the other hand, if an authentication failure signal is received, a command for disconnecting near field communication with the USB memory 2 is issued (step T33). By this disconnection command, short-range communication between the mobile phone 6 that is the session partner and the USB memory 2 is blocked.
  • the specific application software stored in the specific AP storage unit 132 is stored in the member server 3 or the like and downloaded from the member server 3 and installed.
  • the specific AP installed in the terminal 1 can be executed by dividing the general-purpose AP.
  • the USB memory 2 may be configured to include a secondary battery for power supply inside, or may be operated by receiving power supply from the power supply of the terminal 1 while being attached (connected) to the terminal 1.
  • the authentication server 4 transmits an authentication failure signal to the terminal and prohibits the operation of the specific AP of the terminal 1 when the authentication server 4 determines that the authentication has failed in the comparison of the authentication keys.
  • the authentication server 4 may prohibit transmission / reception of packets with the terminal 1 by an authentication failure signal.
  • the authentication server 4 determines that the USBID received from the terminal 1 is valid (step # 7), the authentication server 4 transmits the authentication key to the corresponding mobile phone 6 by e-mail (step). # 13)
  • a required application service is provided between a mobile phone 6 compatible with i-mode (registered trademark) and a predetermined server (authentication server 4) on a network (information transmission system) such as i-appli (registered trademark).
  • the application program to be performed is downloaded in advance from the authentication server 4 or another predetermined site (or downloaded as necessary), and predetermined information is exchanged.
  • the program for executing the application service uses the standby function to transmit an authentication key transmission request signal to the authentication server 4 at a predetermined period of, for example, several seconds to several tens of seconds.
  • the authentication key transmitted from the authentication server 4 is received (assuming that the USBID has been received).
  • the authentication server 4 includes an information transmission / reception unit capable of handling i- ⁇ ppli (registered trademark) services.
  • the information transmission / reception unit receives an authentication key transmission request signal from the mobile phone 6, the information transmission / reception unit transmits an authentication key to the electronic address of the mobile phone 6 in response thereto.
  • the storage unit 431 stores each information of USBID / electronic address / authentication key of the mobile phone 6 in association with each other. Further, the authentication server 4 may determine the validity of the electronic address of the mobile phone 6 that is the transmission source of the authentication key transmission request signal by checking the USBID of the storage content of the storage unit 431. Good.
  • the following procedure may be performed.
  • the holder of the USB memory 2 performs a startup operation of the mobile phone 6 to a predetermined i- ⁇ ppli (registered trademark) mode (when always in this mode state, No startup operation is required).
  • the authentication server 4 determines that the USBID has been received, and then performs the above-described verification for the validity determination. If it is valid, the authentication server 4 sends the authentication key in response to the authentication key transmission request signal. Transmit to mobile phone 6.
  • the authentication server 4 transmits the authentication key once (subject to normal reception).
  • the mobile phone 6 may sleep in this mode to save power.
  • the authentication key transmission / reception process is not limited to an electronic mail, but can be performed using another application service according to a mobile phone company.
  • the present invention provides a personal authentication system that authenticates the presence or absence of a legitimate owner of a portable storage medium that is permitted to execute predetermined information processing by being attached to an information processing terminal connected to the network.
  • the portable storage medium includes an identification information storage unit for storing identification information, and a radio base station possessed by the rightful owner.
  • a first short-range communication unit that performs short-range communication with a portable communication terminal capable of transmitting and receiving information via an information transmission system, wherein the authentication server includes identification information of the portable storage medium
  • a related information storage unit in which electronic address information of the portable communication terminal possessed by the rightful owner of the portable storage medium and unique authentication key information are stored.
  • the physical terminal detects the attachment of the portable storage medium, acquires the identification information, and transmits an authentication request processing means for transmitting a signal including the acquired identification information to the authentication server; and a signal including the identification information
  • the authentication key relay processing means for transmitting the acquired authentication key information to the authentication server
  • the authentication server reads authentication key information and electronic address information corresponding to the identification information included in the received signal including the identification information from the related information storage unit, and reads the read authentication key information.
  • An authentication key information processing means for transmitting to an electronic address; and after the transmission of the authentication key information to the electronic address, through the information processing terminal Upon reception of the authentication key information preferably comprises a first determining means for determining difference between the authentication key and the authentication key information transmitted by the information processing means.
  • the authentication key information is transferred from the authentication server to the portable communication terminal, for example, by e-mail.
  • the authentication key transmitted by e-mail or the like is transmitted from the portable communication terminal to the portable storage medium by short-range communication, so that the terminal user can use his portable storage medium and his portable communication terminal. Both of them are possessed, and even if the portable storage medium is stolen, an illegal slipping operation of the personal authentication process is reliably prevented systematically.
  • the authentication server includes an identification information coincidence determining unit that determines a match between the identification information included in the received signal including the identification information and the identification information stored in the related information storage unit in advance. preferable. According to this configuration, since the legitimacy of the portable storage medium is determined, authentication for the portable storage medium can be ensured.
  • the authentication server includes a determination result processing unit that transmits the determination result to an information processing terminal that is a transmission source of the authentication key information.
  • the information processing terminal also handles the response to the authentication failure, for example, the transmission of information to the authentication server. It is possible to take measures such as prohibiting processing.
  • the information processing terminal includes a mounting monitoring unit that monitors a mounting state of the portable storage medium and stops communication with the authentication server when non-mounting is detected. According to this configuration, it is necessary to continuously mount the portable storage medium on the information processing terminal and clear the monitoring of the mounting state while performing predetermined information processing on the information processing terminal. Unauthorized use can be made difficult as compared with the case where it is only necessary to wear it at the time.
  • the information processing terminal is in a state in which the predetermined information processing can be executed while the portable storage medium is attached, and the authentication server receives the identification from the information processing terminal. Whether or not the signal including the information is received for the first time is monitored. In the second and subsequent times, whether or not the identification information included in the signal including the identification information matches the identification information received for the first time. It is preferable to include second determination means for determining According to this configuration, when the first person authentication succeeds, only the identification information needs to be checked after the second authentication. Therefore, the authentication key information is sent to the e-mail, the portable communication terminal every time the authentication operation is performed. Therefore, it is possible to save the trouble of passing through a portable storage medium and reduce the chance of eavesdropping.
  • an authentication key information creating unit that creates different authentication key information for each transmission of the authentication key information by the authentication key information processing unit is provided. According to this configuration, even if the authentication key information is eavesdropped, it becomes useless information when the information processing terminal is used next time, so that theft can be prevented.
  • the authentication key information creating means randomly creates the authentication key information. According to this configuration, since the changed information cannot be predicted from the authentication key information that has been wiretapped, the authentication key information is highly reliable.
  • the portable communication terminal is a mobile phone that transmits and receives the information to and from the radio base station through electromagnetic waves. According to this configuration, since the mobile phone is a tool possessed by many persons, the present invention can be made highly versatile.
  • the first short-range communication unit includes a wireless communication device that uses electromagnetic waves as a medium.
  • a wireless communication device that uses electromagnetic waves as a medium.
  • operations such as adjusting the orientation in order to match the transmitting / receiving surface of the mobile phone are not required as compared with a mode using light.
  • the portable communication terminal used in the personal authentication system according to any one of claims 1 to 8, wherein the second short-range communication is performed with the first short-range communication unit.
  • a short-distance communication control means for transmitting the received authentication key information from the second short-range communication unit to the first short-range communication unit when receiving the authentication key information from the authentication server; It is preferable to provide. According to this configuration, since the portable communication terminal includes the second short-range communication unit and transmits the authentication key to the portable storage medium, the personal authentication process can be performed even if the portable storage medium is stolen. Unauthorized slip-through processing is reliably prevented.
  • the short-range communication control means stores in advance a pass key for specifying a corresponding portable storage medium, and uses the pass key to store the authentication key information received from the authentication server in the corresponding portable storage medium. It is preferable to transmit to the first near field communication unit of the medium. According to this configuration, even if there are a plurality of portable storage media in the vicinity, the authentication key is transmitted to only one specified portable storage medium, so that high confidentiality can be maintained.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

 本人認証システムは、所定の情報処理が可能な端末(1)、電子メール機能を備えた携帯電話機(6)とブルーツースによる近距離通信が可能なUSBメモリ(2)、及び認証サーバ(4)を備える。USBメモリ(2)が端末(1)に装着されると、USBIDが読み取られ、端末(1)から認証サーバ(4)に送信される。認証サーバ(4)はUSBIDの認証を行い、正当であればUSBIDに対応する認証キーを対応する携帯電話機6に送信する。携帯電話機(6)は認証キーをブルーツースでUSBメモリ(2)に送信する。受信された認証キーはUSBメモリ(2)を経て端末(1)から認証サーバ(4)に送信される。認証サーバ(4)は送信した認証キーと受信した認証キーとの異同を比較することで本人認証を行う。

Description

本人認証方法、本人認証システム及び携行型通信端末
 本発明は、ネットワークに接続された情報処理端末を使用する者の正当性を認証する認証技術に関する。
 近年、インターネットを始めとした通信ネットワークの急激な進展により、種々の商取引等のサービスが、端末から通信ネットワークを介して行われるようになってきている。同様に、行政機関等に対する行政手続等のサービスも通信ネットワークを介して行われるようになってきている。かかるサービスの実行に際し、ネットワークを介して授受される情報には決済情報、取引情報を含む個人情報等が少なくない。一方で、他人になりすましてサーバやデータベース等に侵入し、かかる個人情報等を閲覧、盗用し、また改竄したりする不正行為が増大している。従って、端末を使用する者が本人か否かを判断する本人認証を行うことが重要である。
 ネットワーク上に設けられた認証局で行われる本人認証技術として、生体情報を利用したものが知られている。特許文献1には、端末利用者の指紋データの他、クロック回路及びGPS受信機を用いて得られる存在場所や認証日時を併用する認証技術が記載されている。また、特許文献1には、指紋の他、虹彩や静脈などの生体を識別できる情報が利用可能であることが記載されている。また、特許文献2には、出先のパーソナルコンピュータ(以下、パソコン)からネットワークを介して取引を可能にするネットシステムが記載されている。より詳細には、特許文献2には、取引に際して、ユーザの携帯電話機にセンターサーバからパスワードが電子メールで送信されると、ユーザは、受信したパスワードを目視しながら、パソコンのパスワード入力欄にキーを操作してパスワードを入力するものである。そして、入力された情報がセンターサーバに送信されて、元のパスワードと照合されることで、本人認証が行われることが記載されている(段落番号500~502)。これにより、ユーザが所有するパソコン以外のパソコンにて手続処理やログインや取引処理が安全に行えるようにしている。なお、特許文献2には、携帯電話機で受信したメールをユーザによってセンターサーバに返信するようにしてもよいことが記載されている(段落番号503)。
特開2009-104248号公報 特開2008-33571号公報
 特許文献1に記載の認証技術は、指紋という固体個々の情報を利用する点で優れている一方、指紋などは偽造され易い上に、認証対象となる指紋データが偽造されたものであるか否かを識別することは容易ではない。特許文献2に記載のネットシステムは、ユーザに、携帯電話機の画面を見ながらパソコンへの入力操作という、従来とほぼ同様のパスワード入力操作を強いることになり、キー操作の内容、すなわちパスワードを周囲の他人に知られる虞が高い。また、パスワードが無線傍受によって知得され、不正使用される可能性もある。さらに、特許文献2は、パスワードの入力操作のみクリアすれば、その後は、自由にパソコンを不正使用することも可能となり、万全ではない。一方、特許文献2に記載の、携帯電話機で受信したパスワードをユーザがセンターサーバに返信する態様では、ユーザとパソコンとの物理的な位置の一致が検証できないため、ユーザとパソコンとが同一の場所にいるという保証が取れず、本人認証に一定の限界があることになる。
 本発明の目的は、情報処理端末に装着して所定の情報処理の実行を許可する携行型記憶媒体に対して、装着状態で前記携行型記憶媒体の認証と、前記携行型記憶媒体を経由して本人認証を行うようにして、認証処理の不正なすり抜け操作等を効果的に阻止する本人認証方法、本人認証システム及び本システムに使用する携行型通信端末を提供することにある。
 本発明に係る本人認証システムは、ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証システムにおいて、前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、前記携行型記憶媒体は、識別情報を記憶する識別情報記憶部と、前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末との間で近距離通信を行う第1の近距離通信部とを備え、前記認証サーバは、前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶された関連情報記憶部を備え、前記情報処理端末は、前記携行型記憶媒体の装着を検出して前記識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信する認証要求処理手段と、前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信する認証キー中継処理手段とを備え、前記認証サーバは、受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信する認証キー情報処理手段と、前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定する第1の判定手段とを備えたことを特徴とするものである。
 また、本発明に係る本人認証方法は、ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証方法において、前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、前記認証サーバの関連情報記憶部には、前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶され、前記情報処理端末の認証要求処理手段が、前記携行型記憶媒体の装着を検出して、前記携行型記憶媒体に記憶されている識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信し、前記認証サーバの認証キー情報処理手段が、受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信し、前記携行型記憶媒体の近距離通信部が、前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末を介して前記認証キー情報を取得し、前記情報処理端末の認証キー中継処理手段が、前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信し、前記認証サーバの判定手段が、前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定することを特徴とするものである。
 これらの発明によれば、情報処理端末に装着された携行型記憶媒体が正当所有者によって所持されていることが認証されると、ネットワークを介して所定の情報処理の実行が可能となる。また、前記ネットワークには、前記正当所有者か否かを認証する認証サーバが接続されている。この認証サーバの関連情報記憶部には、前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報(例えば電子メールアドレス)、及び固有の認証キー情報が記憶されている。そして、前記情報処理端末の認証要求処理手段によって、前記携行型記憶媒体の装着が検出され、前記携行型記憶媒体に記憶されている識別情報が取得され、取得された前記識別情報を含む信号が前記認証サーバに送信される。次いで、前記認証サーバの認証キー情報処理手段によって、受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報が前記関連情報記憶部から読み出され、読み出された前記認証キー情報が、読み出された前記電子的なアドレスに送信される。次いで、前記携行型記憶媒体の近距離通信部によって、前記正当所有者の所持する、無線基地局を有する情報伝送系(例えば公衆電話回線)を経由して情報の送受信が可能な携行型通信端末を介して前記認証キー情報が取得される。次いで、前記情報処理端末の認証キー中継処理手段によって、前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報が取得されると、取得された前記認証キー情報が前記認証サーバに送信される。次いで、前記認証サーバの判定手段によって、前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報が受信されると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同が判定される。
 このように、端末使用者に携行型記憶媒体を付与(貸与を含む)し、この携行型記憶媒体及び端末使用者の所持する携行型通信端末を活用して本人認証が可能とされている。すなわち、認証サーバで、端末に装着された携行型記憶媒体の正当性が判定されたことを条件に、認証キー情報を、認証サーバから携行型通信端末へ、例えば電子メールで、携行型通信端末から端末に装着された携行型記憶媒体へ近距離通信で、そして携行型記憶媒体を装着している端末から認証サーバへネットワークを経由して送信することで、認証サーバで、送信した認証キーと受信した認証キーとを照合することで、本人認証が可能となる。従って、例えば前記電子メールで送信された認証キーが携行型通信端末から携行型記憶媒体に近距離通信によって送信されることで、端末使用者が自己の携行型記憶媒体と自己の携行型通信端末の両方を所持していることになり、携行型記憶媒体の盗用によっても、本人認証処理の不正なすり抜け操作等がシステム的に確実に阻止される。
 また、本発明に係る携行型通信端末は、本人認証システムに用いられる前記携帯型通信端末であって、前記第1の近距離通信部との間で近距離通信を行う第2の近距離通信部と、前記認証サーバから前記認証キー情報を受信すると、該受信した認証キー情報を前記第2の近距離通信部から前記第1の近距離通信部へ送信する近距離通信制御手段とを備えている。
 本発明によれば、携行型通信端末に、第2の近距離通信部を備え、認証キーを携行型記憶媒体に送信するようにしたので、携行型記憶媒体の盗用によっても、本人認証処理の不正なすり抜け処理が確実に阻止される。
 本発明によれば、携行型通信端末と携行型記憶媒体との間の近距離通信を介在させることで本人認証処理の不正なすり抜けを効果的に阻止できる。
本発明に係る本人認証システムが適用されるネットワークシステムの概略構成図である。 端末1、USBメモリ2、認証サーバ4、メールシステム5及び携帯電話機6の有する機能をそれぞれブロック化した構成図を示すものである。 USBメモリ2、端末1、認証サーバ4及び携帯電話機6間での本人認証に関する情報の流れの概要を示すシーケンス図である。 端末1のCPUによって実行されるUSBポート状態検出の手順の一例を示すフローチャートである。 認証サーバ4のCPUによって実行される認証処理Iの手順の一例を示すフローチャートである。 認証サーバ4のCPUによって実行される認証処理IIの手順の一例を示すフローチャートである。 認証サーバ4のCPUによって実行される認証キー作成処理の手順の一例を示すフローチャートである。 携帯電話機6のCPUによって実行される処理Iの手順の一例を示すフローチャートである。 端末1のCPUによって実行されるUSB処理Iの手順の一例を示すフローチャートである。 端末1のCPUによって実行されるUSB処理IIの手順の一例を示すフローチャートである。 携帯電話機6のCPUによって実行される処理IIの手順の一例を示すフローチャートである。
 図1は、本発明に係る本人認証システムが適用されるネットワークシステムの概略構成図である。図1に示すネットワークシステムは、例えば、会員である、消費者や商店乃至は企業等、更には決済を行う1又は複数の金融機関に配置される端末(情報処理端末)1と、これらの各端末1及び端末1間での情報の管理及び保管を統括的に行う管理機関に配設された会員サーバ3とを備える。各端末1及び会員サーバ3はインターネット等のネットワーク7に接続されている。
 端末1は、一般的にはCPU(Central Processing Unit)を内蔵するパーソナルコンピュータ等で構成されている。端末1内には、例えば、一般的な文書や図形の作成ソフトウエアを利用しての情報の作成、加工、記憶、更に通信用のソフトウエアを利用しての情報の送受信等の一般的な各処理を実行するプログラムファイル(汎用AP(application program)という)と、後述する特定のアプリケーションソフトウエアの実行に関連する処理を行うプログラムファイル(特定APという)とが記憶されている。より具体的には、会員間である消費者、商店及び企業等の端末1には、特定APとして、商品やサービスの売買、見積もり乃至は請求、入出金に関する各書類の作成と通信とを行うソフトウエア、及び後述する認証処理のソフトウエアがインストールされている。すなわち、端末1は、一般的な商取引における決済、例えば業者店舗からの請求書の発行、受領や、購買者側から請求書発行元の契約金融機関の口座への入金(すなわち支払い)指示書、その受領書の発行の他、電子決済の如何を問わず種々の電子書面での送受信処理を可能とするものである。端末1は、各種書類をテキスト形式の、またバイナリー形式の電子ファイルとして作成可能である。電子ファイルは、例えば会員サーバ3を中継して端末1間で授受される。各金融機関の端末1には、消費者や企業の端末1からの金融的な決済書面に従った決済指示処理(金融機関間での決済処理の指令等)を行う特別アプリケーションソフトウエアもインストールされている。
 また、端末1は、携行可能な記憶媒体(会員用外部記憶媒体)、例えばチップ状のUSB(Universal Serial Bus)メモリ2が装着(接続)可能なUSBポートを有する。記憶媒体としては、IEEE1394ポートを使用したスティック状のハードウエアでもよい。USBメモリ2は、会員に付与されるもので、後述するように所定の情報が記憶可能な記憶部(領域)を有する。また、USBメモリ2は、チップ状の本体の内部等の適所にブルーツース(Blue tooth)等の近距離通信手段を備えている。近距離通信手段は、無線(電波、光)に限定されないが、操作性から無線式が好ましい。近距離通信の方式としては、ブルーツースに限定されず、無線LAN(Local area network)、RFID(Radio Frequency Identification)等でもよい。
 会員サーバ3は、会員に関する適宜な情報、例えば会員の氏名、名称、メールアドレス、住所等の会員情報等を会員単位で記憶するものである。また、会員サーバ3は、さらに、各会員のファイル送受信履歴やそのファイル類等を管理用に記憶する記憶部を備えている。会員サーバ3は、認証サーバ4としての機能部を備えている。認証サーバ4は、ネットワーク7に接続されており、会員サーバ3と端末1との間で授受されるファイル、すなわちパケットが閲覧可能な状態にある。なお、会員サーバ3と認証サーバ4との関係は、シリアル的な他、パラレル的な接続関係にあってもよく、端末1から会員サーバ3に送信されるパケットが、本発明における認証処理が実現できる範囲において閲覧できる態様であればよい。
 また、本システムは、他の適用例として、秘密情報を作成、保管管理する、例えば公的機関である団体組織内のLANに接続された複数の端末1間での情報通信、さらに団体組織外にある端末との間における情報通信・管理体制に適用する例を挙げることができる。団体組織外にある端末との間における情報通信としては、例えば証明書の発行などが想定される。
 図1において、端末1はプロバイダ(ISP)8を介してネットワーク7に接続されている。ISP8には、通常、複数の端末1が接続されている。なお、図1には示されていないが、ISP8には、各種の情報を提供するWebサイトを有するサーバも、適宜の数だけ接続されている。また、ISP8に接続される端末1には、前述した特定APがインストールされている会員所有の端末1と、特定APがインストールされていない通常の端末1’とが存在する。特定APの一部は、認証処理を行うプログラムを有し、認証結果に従って特定APの実行許否及びその管理を行う。
 また、本ネットワークシステムでは、USBメモリ2を使用する会員の正当性、すなわち本人認証を可搬式の携行型通信端末、代表的には電子メールの送受信が可能な携帯電話機6を用いる。電子メールの送受を行うための仕組みとしては、携帯電話会社のメールシステム5が使用される。メールシステム5及び携帯電話機6の構成については、図2を用いて説明する。なお、携行型通信端末6は、携帯電話機6の他、PDA(Personal Digital Assistant)でもよい。
 図2は、端末1、USBメモリ2、認証サーバ4、メールシステム5及び携帯電話機6の有する機能をそれぞれブロック化した構成図を示すものである。図2において、端末1は、CPUから構成される制御部11を備え、制御部11にROM(Read Only Memory)12とRAM(Random Access Memory)13とが接続されている。制御部11には、テンキーやマウスなどからなる操作部14、及びCRT、液晶又はプラズマディスプレイ等からなり、画像を表示する表示部15が接続されている。
 ROM12は、端末1の起動(ブート処理)、アプリケーションソフトウエアの読み込みを実行するためのOS(Operating System)やBIOS(Basic Input/OutputSystem)等を記憶するOS等記憶部121を少なくとも備えている。
 RAM13は、前述した一般的なアプリケーションソフトウエアがインストールされた汎用AP記憶部131、前述した認証、電子商取引サービス、行政サービス等の処理に関連する特定アプリケーションソフトウエアがインストールされた特定AP記憶部132、汎用APや特定APで作成された、テキストファイルやバイナリーコードで作成されたファイルを格納する作成ファイル記憶部133を少なくとも備えている。作成ファイル記憶部133に記憶されるファイルには、自己が作成したファイルの他、送信、受信したファイルも含まれる。特定APは、予め又は所定の時点で外部記憶媒体を介して取り込まれる。例えば、会員登録する時点で、ネットワーク上の所定のサーバ(会員サーバ3でもよい)から、あるいはハードディスク等の外部記憶媒体からインストールされる。
 制御部11は、ROM12及びRAM13に記憶されているプログラムがCPUによって実行されることによって、USBメモリ2と通信を行うためのUSB通信処理部111、USBメモリ2が端末1のUSBポートPoへ装着されているか否かを検出する装着検出部112、USBメモリ2を識別する識別情報(USBID)をUSBメモリ2から取得するUSBID取得部113、認証サーバ4に認証要求信号を送信する認証要求処理部114、USBメモリ2から認証キー情報を取得する認証キー取得部115、認証サーバ4から認証結果の情報を取得し、認証結果に応じた処理を行う認証結果処理部116、指定されたプログラムである汎用AP及び特定APを実行させるプログラム実行処理部117、及びネットワーク7を介して会員サーバ3及び認証サーバ4との間で文書ファイルの送受信、代表的にはTCP/IP(transmission control protocol/internet protocol)規約に沿って形成されたパケットによって文書ファイルの送受信を行うネットワーク通信処理部118として機能する。なお、ネットワーク通信処理部118は、受信パケットを元の文書ファイルに戻したり、送信ファイルをパケットに置換して送信したりするもので、送信される各パケットのヘッダには、送信元である端末1のグローバルIPアドレス、送信先である他の端末及び会員サーバ3のグローバルIPアドレスが含まれ、更に端末1に装着されているUSBメモリのUSBIDや少なくとも初回における認証キーも含まれるようにしている。
 USBメモリ2は、情報が記憶される構成部20と、近距離通信を行う構成部である近距離通信送受信部21とを備えている。情報の記憶を行う構成部20は、USBメモリ2を識別するUSBIDが記憶されたUSBID記憶部201と、後述するセッション処理において使用される情報(自己を特定する情報「パスキー:PIN(PersonalIdentification Number)ともいう」)等が記憶され、また前記セッションで受信した情報が記憶される情報記憶部202とを有する。また、近距離通信送受信部21は、前述したブルーツース等における電磁波送受用のアンテナを含み、後述するように携帯電話機6とブルーツースによる近距離通信を行うものである。近距離通信処理部203は、端末1に装着された状態で、端末1から所要の信号を受信することで、あるいは所要の制御プログラムを受信することで、近距離通信送受信部21の動作を制御し、及び前記セッション動作を制御するものである。
 端末1の装着検出部112は、所定のハンドシェイク処理におけるUSBポートPoからの応答信号の有無から、USBメモリ2の装着の有無を検出するものである。USBID取得部113は、USBメモリ2が装着されている場合に、USBID記憶部201からUSBIDを読み出して取得するものである。認証要求処理部114は、USBメモリ2が装着された場合に、USBIDを含む認証要求信号を作成し、所定のパケットに変換してから認証サーバ4に送信するものである。
 認証キー取得部115は、認証要求信号を送信した後、USBメモリ2から認証キーの情報を取得すると、この認証キーを所定のパケットに変換して認証サーバ4に送信するものである。認証結果処理部116は、認証サーバ4から送信された認証結果を受信し、認証結果が、成功な場合にはプログラム実効処理部117による特定APのみの実行を許可し、成功でない(失敗の)場合には汎用APのみの実行を許可する信号をプログラム実効処理部117に出力する。認証サーバ4における認証処理は、後述するように、特定APの実行によって端末1と会員サーバ3との間でファイルの送受信(具体的には、会員サーバ3を中継して他の端末1と文書ファイルの送受信等)が行われている間、継続的に実行される。
 認証サーバ4は、CPUからなる制御部41、認証処理プログラムが記憶されたROM42、及び認証用情報が記憶されたRAM43を備えている。RAM43は、各会員に付与されたUSBメモリ2のUSBIDと、各会員の所持する携帯電話機6の電子メールアドレスと、本人認証のための認証キーが対応付けられて記憶された、USBID/携帯電子メールアドレス/認証キー(以下、関連情報という)記憶部431を有する。
 制御部41は、ROM42に記憶されているプログラムがCPUによって実行されることによって、端末1から送信されてくるパケット内のUSBIDや認証キーを読み取るパケット監視部411、読み取ったUSBIDの正当性を判定するUSB正当性判定部412、正当性ありと判定されたUSBIDに対応する認証キーを、対応する携帯電子メールアドレスに電子メールで送信し、その後、正当性ありと判定されたUSBIDの送信元である端末1から受信した認証キーとの照合(初回認証)を行う第1認証処理部413、初回認証後において端末1からパケットを受信する毎に、受信するパケットに含まれるUSBIDと初回認証時に取得したUSBIDとの異同を照合する第2認証処理部414、認証キーを所定のタイミングで変更する認証キー作成部415、ネットワーク7を介して端末1との間で文書ファイルの送受信、代表的にはTCP/IPプロトコルによって形成されたパケットによって文書ファイルの送受信を行うネットワーク通信処理部416、及び認証キー情報を電子メールのパケットに変換して所定の携帯電話機6に(前記した携帯電話会社のメールシステム5を経由して)送信する携帯電子メール通信処理部417として機能する。携帯電子メール通信処理部417は、いわゆるメールサーバとして機能するもので、送信メールを例えばインターネットメール形式に変換して送信する。
 USB正当性判定部412は、読み取ったUSBIDと関連情報記憶部431に予め記憶されている元情報であるUSBIDのリストとを照合を経て、一致したUSBIDがある場合に、正当性ありと判定するものである。USB正当性判定部412は、一致するUSBIDが発見できなかった場合は、認証キーの認証処理を経るまでもなく、正当なUSBメモリ2ではないとして、正当性なしの情報が、当該USBメモリ2が装着されている端末1に返信されて、以後の通信が遮断等される。
 本実施形態では、認証処理は、USBメモリ2が端末1に装着されている間、継続して行われる。具体的には、第1認証処理部413は、端末1から送信したUSBIDが正当である場合に、対応する携帯電話機6に送信された認証キーが携帯電話機6、USBメモリ2及び端末1を経由して受信されると両方の認証キーを照合して一致している場合には、当該端末1に認証成功の情報を返信する。一方、両方の認証キーを照合して不一致であった場合には、当該端末1に認証ができない(認証失敗)の情報を返信する。認証失敗の情報は、図略の内蔵カウンタ等で回数をカウントすることで、所定回数まで再トライ(USBメモリ2の装着し直し操作)をガイドする態様として活用し得る。第1認証処理部413による処理は初回の認証処理とされる。
 第2認証処理部414は、初回の認証処理で認証成功とされると、この初回認証を1回目として例えばRAM43の適所に一旦記憶し、その後において、端末1との間でファイル、すなわちパケットの送受信が行われている間に、当該端末1から受信したパケット内のヘッダに含まれるUSBIDが初回認証処理時に取得したUSBIDと一致しているか否かの照合を行うものである。照合の結果が一致していれば、2回目以降の認証が成立したとして、通信を継続させ、逆に、2回目以降のいずれかの段階での認証処理において、一致しなくなった場合には、USBメモリ2が途中で差し替えられたり、その他の不正行為があったりと見なして、当該端末1との通信を遮断する等する。
 認証キー作成部415は、USBメモリ2が端末1に装着されて会員による所要の処理が終了してから、次回に装着されるまでの間に、当該USBIDに対応する情報のうち、認証キーのみを変更するものである。認証キーの変更は、USBメモリ2が端末1に装着され、USBIDが読み取られたことに応答して変更してもよいし、その後であって、少なくとも次回に当該USBメモリ2がいずれかの端末1に装着されるまでの間に変更されればよい。認証キーの変更は、乱数発生器を利用する等して無作為に変更されるのが好ましい。認証キーの更新は、関連情報記憶部431の対応するUSBIDに対応する現認証キーを書き換えることで行われる。
 メールシステム5は、情報伝送系として機能するもので、ISP8を介してネットワーク7に接続されており、情報処理部51と、所要数の無線式の基地局52を有する。基地局52は、アンテナを有し、携帯電話機6との間で電波の送受信を行う送受信部である。メールシステム5は、負荷分散のため所要数台設けてもよい。同様に基地局も通話エリアを拡充する目的で所要数だけ配設されている。
 情報処理部51は、携帯電話機6で送受される電子メールのフォーマット及びプロトコルとインターネット上を伝送されて認証サーバ4に送受される電子メールのフォーマット及びプロトコルとの間でのそれぞれ変換を行うメールゲートウェイ511、電子メールの送受を制御する携帯電子メールサーバ512、及び送受する電子メールを一時的に保存するメールボックス513を有する。
 携帯電話機6は、本体に設けられ、電波の送受信を行うアンテナ60と、本体内に設けられ、CPUから構成された制御部61とを有する。制御部61には、通常の通話処理や電子メール送受信処理の他、本人認証処理のための近距離セッション通信、認証キー受信、セッション結果報告のための各種制御プログラムが記憶されたROM62、処理情報である送信情報及び受信情報、及び認証サーバの電子メールアドレス、対応するUSBメモリ2を特定する情報であるパスキーその他の情報が格納されるRAM63が接続されている。また、携帯電話機6の本体表面適所には、テンキー等各種機能キーから構成される操作部64と、処理情報や受信情報を表示する液晶パネル等の表示部65とが配設されている。近距離通信送受信部66は、前述したブルーツース等における電磁波送受用のアンテナを含み、後述するようにUSBメモリ2とブルーツースによる近距離通信を行うものである。
 制御部61は、ROM62に記憶されている制御プログラムがCPUによって実行されることによって、近距離通信送受信部66の動作を制御し、及び前記セッション動作を制御する近距離通信処理部611、USB接続状態監視部612、認証キー取得部613、携帯電子メール通信処理部614、及び計時用のタイマ615を有する。
 近距離通信処理部611は、認証サーバ4から送信された認証キーを受信すると、USBメモリ2との間で所定のセッションを行うための信号を送信し、送信した信号に対して返答信号が受信されると、セッションを開始して、認証キーを送信すると共に、その後はセッションのための信号を継続的にやり取りするものである。近距離通信処理部611及び近距離通信処理部203によるセッションは、USBメモリ2と携帯電話機6とが、互いの通信範囲である近距離、例えば1m(メートル)以内にある場合、USBメモリ2が端末1から抜かれるまで継続される。なお、光学式の場合は、互いに送受波面が対向し、かつ所定近距離に配置される必要がある。
 USB接続状態監視部612は、USBメモリ2の近距離通信処理部203との間で所定のセッションを行うことで、端末1に装着された状態のUSBメモリ2の近傍に、要するに端末1の近傍に携帯電話機6が存在するか否かを判断するものである。すなわち、USB接続状態監視部612は、近距離通信送受信部21との間のセッションが発生しなければ、端末1の近傍に元々携帯電話機6は存在しないと判断し、またセッションが途中で途切れたら、途中で携帯電話機6が端末1から遠ざかったと判断し、いずれも後述するように異常終了とする。一方、USB接続状態監視部612は、USBメモリ2が端末から抜かれてセッションが終了した場合には、携帯電話機6が最後まで端末1の近傍にあったと判断し、異常終了とはしない。セッションが最初から、あるいは途中で途切れた場合、携帯電話機6は、認証処理の失敗を示す信号を認証サーバ4に送信する。USB接続状態監視部612によるセッションの継続性の監視(判断)は、例えば十数秒乃至は1分程度の内の所要の間隔をタイマ615で計時することで実行される。
 認証キー取得部613は、認証サーバ4から電子メールシステム5を経由して送信される認証キーを受信し、近距離通信処理部611に渡すものである。携帯電子メール通信処理部614は、認証キーの情報やセッションの失敗を示す情報等を電子メールの形で認証サーバ4との間で送受信するものである。
 図3は、USBメモリ2、端末1、認証サーバ4及び携帯電話機6間での本人認証に関する情報の流れの概要を示すシーケンス図である。
 今、自己のUSBメモリ2及び自己の携帯電話機6を所持する会員が自宅の端末1で、あるいは他人、例えば公共設備や店舗に備え付けの端末1で、何らかの申請、あるいは商取引を行う場合を想定する。
 会員は、自己のUSBメモリ2を対象である端末1のUSBポートPoに装着する。この装着によって、端末1とUSBメモリ2との間でハンドシェイク処理が実行される。次いで、USBIDがUSBメモリ2から端末1へ読み取られる。端末1は取得したUSBIDを含む認証要求信号を生成し、送信用のパケットに変換して認証サーバ4に送信する。これにより、初回の認証処理が開始される。認証サーバ4は、USBIDの正当性をチェックし、正当であれば、USBIDに対応する認証キーを対応する携帯電話機6に電子メールで送信する。携帯電話機6は、受信した認証キーを近距離通信でUSBメモリ2に送信する。そして、USBメモリ2で受信された認証キーは端末1を介して認証サーバに送信される。ここで、認証サーバ4は、携帯電話機6に送信した認証キーと、端末1から受信した認証キーとの異同を判定し、一致すれば認証成功と判断し、一致しなければ認証失敗と判定する。認証結果は端末1に送信される、認証結果が認証失敗であった場合、その旨はUSBメモリ2を経て携帯電話機6に送信される。これにより、近距離通信が切断される。また、会員には、再トライが可能となる。
 初回の認証処理が成功すると、その後は、当該端末1と認証サーバ4との間で(具体的には認証サーバ4を介して端末1と会員サーバ3との間で)所要のファイルがパケットに変換されて送受される。そこで、端末1から認証サーバ4に送信されるパケットのヘッダ内に書き込まれているUSBメモリ2のUSBIDを含めるようにして、USBメモリ2が端末1に装着されている間、2回目以降の認証処理を継続的に行うようにしている。
 すなわち、認証サーバ4は、当該端末1から送信されるパケットのヘッダ情報を監視し、その中からUSBIDを抽出する。そして、初回の認証処理時に端末1から取得したUSBIDとの異同を照合する。ここで、認証が失敗すると、その旨が端末1に送信される。なお、初回の認証処理の成功によって稼働される特定APの処理には、通信以外にも、単に文書作成などがあるが、パケットの送受以外の処理の間は、2回目以降の認証は中断していることになる。また、この中断期間であっても、定期的乃至は周期的にUSBIDを含む認証用のパケットを作成し、認証サーバ4に送信する態様としてもよい。
 図4は、端末1のCPUによって実行されるUSBポート状態検出の手順の一例を示すフローチャートである。まず、USBポートPoに対して周期的にハンドシェイク信号の送信が行われて、USBポートPoの状態が判断される(ステップS1)。このとき、USBポートPoにUSBメモリ2が装着されていれば、ハンドシェイク信号に応答して、応答信号が返信される一方、USBメモリ2が装着されていなければ、応答信号は返信されず、本フローを抜ける。次いで、応答信号が返信されてくると、USBメモリ2を含む何らかのチップが装着されているとして、特定AP内の、ある専用APが起動される。専用APは、装着チップがUSBメモリ2であるか否かの判断と、USBメモリ2である場合に、内部の情報を読み出す処理を実行させる通信アプリケーションソフトウエアを起動させる。
 ステップS1において、USBメモリ2から応答があると、USBID記憶部201からUSBIDの読み取りが行われる(ステップS3)。USBIDが取得されると、USBIDを含む認証要求信号(パケット)が作成される(ステップS5)。次いで、作成された認証要求信号が認証サーバ4に送信される(ステップS7)。送信が終了すると、認証サーバ4からのパケットの受信を待つ待機モードに移行する(ステップS9)。
 なお、USBポート状態検出処理は、特定APに代えて、汎用APで行ってもよい。そして、USBポートPoにチップの装着が検出された後に、特定APへ処理を受け渡すようにしてもよい。
 図5は、認証サーバ4のCPUによって実行される認証処理Iの手順の一例を示すフローチャートである。認証処理Iとは、初回の認証の処理をいう。
 まず、端末1から認証要求信号が受信されたか否かが判断される(ステップ#1)。認証要求信号が受信されていなければ、本フローを抜ける。一方、認証要求信号が受信されたのであれば、パケット内からUSBIDが読み取られる(ステップ#3)。次いで、読み取られたUSBIDと同一の情報があるか否かについて関連情報記憶部431のUSBIDリストが検索され、正当性の有無が判断される(ステップ#5)。リスト中に同一の情報があれば、正当性ありと判断される(ステップ#7でY)。一方、同一の情報がなければ、正当性なしと判断されて(ステップ#7でN)、本フローを抜ける。
 正当性ありと判断された場合、関連情報記憶部431から、現に正当性ありと判断されたUSBIDに対応した、携帯電話機6の電子メールアドレスが抽出され(ステップ#9)、さらに当該USBIDに対応した認証キーが抽出される(ステップ#11)。そして、認証サーバ4の携帯電子メール通信処理部417によって、抽出された電子メールアドレスに、抽出された認証キーが送信される(ステップ#13)。
 次いで、所定時間内に、当該端末1からのパケットが受信されたか否かが判断される(ステップ#15)。所定時間とは、ステップ#13で認証サーバ4から出力された認証キーの情報が、携帯電話機6、USBメモリ2、端末1を経由して戻って来るに要する時間より多少大きめに設定された時間で、制御部11内の図略のタイマによって計時される。所定時間内に認証キーが(当該認証キーの送信元である端末1から)取得されると(ステップ#17)、ステップ#13で送信した認証キーとステップ#15で受信した認証キーとの異同の照合が行われる(ステップ#19)。
 ここで、送信した認証キーと受信した認証キーとが不一致であると(ステップ#21でN)、認証失敗信号が当該端末1に返信される(ステップ#23)。この認証失敗信号は、認証の再トライを所要回数だけ促すものとして扱われる。すなわち、会員は、認証失敗信号が当該端末1の表示部15に表示される等によって、正しいUSBメモリ2かを再確認し、かつ端末1のUSBポートPoに対して差し直し操作を促す。なお、所要回数は、認証失敗信号を図略のカウンタでカウントし、設定回数値と大小比較することで監視可能である。
 また、ステップ#21で、送信した認証キーと受信した認証キーとが一致している場合、認証成功信号が当該端末1に送信され(ステップ#25)、さらに当該端末1との通信の許可を行う(ステップ#27)。
 図6は、認証サーバ4のCPUによって実行される認証処理IIの手順の一例を示すフローチャートである。認証処理IIとは、2回目以降での認証の処理をいう。初回の認証処理が成功すると、そのときのUSBIDが、当該端末1(IPアドレス)と対応付けて認証サーバ4のRAM43の適所に一時的に保存され、さらに特定APが実行されて、当該端末1と認証サーバ4(具体的には会員サーバ3)間で、所要のパケットの授受が可能となる。そして、当該端末1から送信されたパケットが受信されたか否かの判断が、当該端末1のIPアドレスに基づいて行われる(ステップ#41)。
 ステップ#41においてパケットが受信されたのであれば、当該パケットのヘッダからUSBIDの読み取りが行われる(ステップ#43)。そして、当該端末1における初回の認証時における正当性判断で用いられたUSBID(最初のUSBIDという)と今回のパケットから読み出されたUSBIDとの異同の照合が行われる(ステップ#45)。最初のUSBIDと今回のUSBIDとが一致していると、認証成功として、本フローを抜ける。一方、最初のUSBIDと今回のUSBIDとが不一致である場合、当該端末1との特定APによる通信が遮断され(ステップ#51)、さらに、当該端末1に認証失敗信号が送信される(ステップ#53)。
 なお、ステップ#41で当該端末1からパケットが受信されていない場合、当該端末1に対応する携帯電話機6からセッション失敗の電子メールが受信されたか否かが判断される(ステップ#49)。セッション失敗の電子メールが受信されていなければ、本フローを抜け、逆にセッション失敗の電子メールが受信されていると、ステップ#51に進む。
 図7は、認証サーバ4のCPUによって実行される認証キー作成処理の手順の一例を示すフローチャートである。まず、認証キーの作成時点か否かが判断される(ステップ#61)。認証キーの作成時点とは、USBメモリ2が端末1から抜かれてから、次回にUSBメモリ2が端末1(前回装着された端末1との異同は問わない)に装着され、さらに抜かれるまで間の、ある予め設定された時点をいう。例えば、端末1から認証サーバ4に最初のUSBIDが受信された時点とか、USBメモリ2が端末1から抜かれた時点とかでもよい。
 認証キー作成時点でなければ、本フローを抜ける。一方、認証キー作成時点であれば、無作為に認証キーが作成される(ステップ#63)。次いで、関連情報記憶部431内の対応するUSBID又は携帯電子メールアドレスに対して、作成した認証キーが対応付けされて更新記憶される(ステップ#65)。このように、認証キーをOne time passwordと同様に毎回かつ無作為に変更することで、仮に盗聴されても次回では無用化できる。
 図8は、携帯電話機6のCPUによって実行される処理Iの手順の一例を示すフローチャートである。まず、認証サーバ4から認証キーが電子メールで受信されたか否かが判断され(ステップT1)、認証キーが受信されたのでなければ、本フローを抜ける。一方、認証キーが受信されたのであれば、USBメモリ2との間でのセッションに先だって接続コマンドが前記パスキーを有するUSBメモリ2に送信される(ステップT3)。すなわち、携帯電話機6は、認証サーバ4の電子メールアドレスを記憶しておき、当該電子メールアドレスから所定の情報、すなわち、ここでは認証キーの情報が受信されると、自動的にセッションのための接続コマンドの送信処理に移行する。なお、自動的にセッションに移行する態様に代えて、携帯電話機6の所持者に近距離通信によるセッション開始の操作を指示する指示情報を送信するようにしてもよい。
 また、携帯電話機6のRAM63には、対応するUSBメモリ2を特定するためのパスキーがペアリング処理によって予め記憶されている。ペアリング処理とは、セッションの事前処理であって、対応関係にある携帯電話機6とUSBメモリ2とを所定の情報、例えばパスキーで紐付けする処理である。
 次いで、接続が成功したか否かが判断され(ステップT5)、成功すると、セッションが行われることになる。例えば、機器の接続/認証/暗号化を行うためのプロファイルであるGAP(Generic Access Profile)を使用することで、パスキーの情報を利用して接続を行う。そして、接続されたら、データ転送を行うためのプロファイルであるFTP(File Transfer Profile)を使用してデータ転送を行う。
 次いで、上記のようにしてセッション処理が開始され、まず認証キーがペアリング先のUSBメモリ2に送信される(ステップT7)。続いて、当該USBメモリ2から応答信号が受信されたか否かが判断され(ステップT9)、受信されたのであれば、予め設定された一定時間(例えば十数秒~1分程度内の所与の時間)が経過したか否かが判断される(ステップT11)。一定時間が経過すると、応答要求信号が送信され(ステップT13)、次いで当該USBメモリ2から応答信号が受信されたか否かが判断される(ステップT15)。応答信号が受信されたのであれば、当該USBメモリ2が端末1から抜かれたか否かが、例えば抜かれた旨の信号の受信の有無によって判断される(ステップT17)。当該USBメモリ2が端末1から抜かれたのであれば、本フローを終了する。一方、当該USBメモリ2が端末1から抜かれていなければ、ステップT11に戻る。
 また、ステップT5でペアリング相手が発見できず、ステップT9,T15で応答信号が受信されなければ、USBメモリ2を装着する者が対応する携帯電話機6を所有しておらず、あるいは携帯電話機6がUSBメモリ2から所定の近距離以上離れたと見なすなどして、セッション開始での接続失敗又はセッション中での切断を示すセッション失敗信号が電子メールで認証サーバ4に送信される(ステップT19)。
 図9は、端末1のCPUによって実行されるUSB処理Iの手順の一例を示すフローチャートである。なお、USB処理I及び後述するUSB処理IIは、USBメモリ2内にCPUを内蔵し、USB処理I,IIの処理プログラムを情報記憶部202に記憶した態様で実行されるようにしてもよい。
 まず、携帯電話機6からセッションのための信号、ここでは前記接続コマンドが受信されたかどうかが判断される(ステップQ1)。前記コマンドが受信されていなければ、本フローを抜ける。一方、前記信号が受信されていると、パスキーが応答信号として返信される(ステップQ3)。続いて、認証キーの受信の有無が判断され(ステップQ5)、認証キーが受信されていなければ、本フローを抜ける。一方、認証キーが受信されていると、受信した認証キーが端末1に送出される(ステップQ7)。
 次いで、携帯電話機6から、セッションのための応答要求信号が受信されたか否かが判断される。信号が受信されていなければ、本フローを抜ける。一方、信号が受信されていると、応答信号が送信される(ステップQ11)。次いで、USBメモリ2が端末1から抜かれたか否かが判断され(ステップQ13)、抜かれていなければ、ステップQ9に戻って、応答要求信号の受信の有無が判断される。このようにして、USBメモリ2が端末1から抜かれるまで、セッションが継続される。
 図10は、端末1のCPUによって実行されるUSB処理IIの手順の一例を示すフローチャートである。まず、端末1から認証失敗信号が受信されたか否かが判断され(ステップQ21)、端末1から認証失敗信号が受信されていなければ、本フローを抜ける。一方、端末1から認証失敗信号が受信されていると、この信号に対応して認証失敗信号が携帯電話機6に送信される(ステップQ23)。
 図11は、携帯電話機6のCPUによって実行される処理IIの手順の一例を示すフローチャートである。まず、USBメモリ2から認証失敗信号を受信したか否かが判断される(ステップT31)。認証失敗信号が受信されなければ、本フローを抜ける。一方、認証失敗信号が受信されたのであれば、当該USBメモリ2との近距離通信の切断コマンドが発行される(ステップT33)。この切断コマンドによって、セッション相手である携帯電話機6とUSBメモリ2との近距離通信が遮断される。
 なお、本発明は、以下の態様が採用可能である。
(1)特定AP記憶部132に記憶される特定アプリケーションソフトウエアは会員サーバ3等に格納されており、会員サーバ3からダウンロードされ、インストールされる態様とすることが好ましい。これにより、端末1にインストールされる特定APを汎用APを分断して実行させることが可能となる。
(2)USBメモリ2は内部に電源用二次電池を備える構成でもよいし、あるいは端末1に装着(接続)された状態で端末1の電源から電源供給を受けて稼働する態様でもよい。
(3)認証サーバ4は、認証キーの異同の照合において認証失敗と判定した場合、当該端末に対して認証失敗信号を送信して、当該端末1の特定APの動作自体を禁止する等の態様を採用してもよいし、あるいは認証失敗信号によって認証サーバ4において当該端末1との間のパケットの送受信を禁止する態様でもよい。
(4)本実施形態では、認証サーバ4は、端末1から受信したUSBIDに対して正当性ありと判断すると(ステップ#7)、認証キーを対応する携帯電話機6に電子メールで送信する(ステップ#13)態様としたが、以下の態様でもよい。すなわち、例えばiモード(登録商標)対応の携帯電話機6にiアプリ(登録商標)のような、ネットワーク(情報伝送系)上の所定のサーバ(認証サーバ4)との間で所要のアプリケーションサービスを行う、アプリケーションプログラムを、認証サーバ4あるいは他の所定のサイトから、予めダウンロードしておき(あるいは必要に応じてその都度ダウンロードして)、所定の情報の授受を行う。また、このアプリケーションサービスを実行するプログラムは、待ち受け機能を利用して、例えば数秒~数十秒での所定周期で認証キー送信要求信号を認証サーバ4に送信すると共に、この認証キー送信要求信号に応答して、(USBIDの受信済みを前提として)認証サーバ4から送信されてきた認証キーを受信するようにする。一方、認証サーバ4は、iアプリ(登録商標)のサービスに対応可能な情報送受信部を備える。この情報送受信部は、携帯電話機6から認証キー送信要求信号を受信すると、それに応答して当該携帯電話機6の電子的なアドレスに認証キーを送信するようにしている。なお、この態様では、記憶部431は、USBID/携帯電話機6の電子的なアドレス/認証キーの各情報を関連付けて記憶しておく。また、認証サーバ4は、前記認証キー送信要求信号の送信元の携帯電話機6の電子的なアドレスの正当性を、前記記憶部431の記憶内容のUSBIDと照合することで判断するようにしてもよい。
 具体的には、以下の手順で行えばよい。USBメモリ2が端末1に装着されると、USBメモリ2の所持者は携帯電話機6を所定のiアプリ(登録商標)のモードへの起動操作を行う(常時このモード状態にある場合には、起動操作不要)。認証サーバ4は、USBIDを受信済みであることを判断し、次いで、前述の正当性判断のための照合を行った後、正当であれば、認証キー送信要求信号に応答して認証キーを当該携帯電話機6に送信する。認証サーバ4は、認証キーの送信を(正常受信を条件に)1回行う。携帯電話機6は、認証キーを受信すると、省電のために本モードをスリープするようにしてもよい。このように、認証キーの送受信処理は、電子メールに限らず、携帯電話会社に応じた他のアプリケーションサービスを利用しても可能である。
 以上のとおり、本発明は、ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証システムにおいて、前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、前記携行型記憶媒体は、識別情報を記憶する識別情報記憶部と、前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末との間で近距離通信を行う第1の近距離通信部とを備え、前記認証サーバは、前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶された関連情報記憶部を備え、前記情報処理端末は、前記携行型記憶媒体の装着を検出して前記識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信する認証要求処理手段と、前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信する認証キー中継処理手段とを備え、前記認証サーバは、受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信する認証キー情報処理手段と、前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定する第1の判定手段とを備えることが好ましい。
 この構成によれば、認証サーバで、端末に装着された携行型記憶媒体の正当性が判定されたことを条件に、認証キー情報を、認証サーバから携行型通信端末へ、例えば電子メールで、携行型通信端末から端末に装着された携行型記憶媒体へ近距離通信で、そして携行型記憶媒体を装着している端末から認証サーバへネットワークを経由して送信することで、認証サーバで、送信した認証キーと受信した認証キーとを照合することで、本人認証が可能となる。従って、電子メール等で送信された認証キーが携行型通信端末から携行型記憶媒体に近距離通信によって送信されることで、端末使用者が自己の携行型記憶媒体と自己の携行型通信端末の両方を所持していることになり、携行型記憶媒体の盗用によっても、本人認証処理の不正なすり抜け操作等がシステム的に確実に阻止される。
 また、前記認証サーバは、受信した前記識別情報を含む信号に含まれる前記識別情報と前記関連情報記憶部に予め記憶されている識別情報との一致を判定する識別情報一致判定手段を備えることが好ましい。この構成によれば、携行型記憶媒体の正当性が判定されるので、携行型記憶媒体に対する認証を確実なものとすることができる。
 また、前記認証サーバは、前記判定の結果を前記認証キー情報の送信元の情報処理端末に送信する判定結果処理手段を備えることが好ましい。この構成によれば、判定の結果、認証が失敗した場合には、その旨が情報処理端末に送信されるので、情報処理端末においても、認証失敗に対する対応処理、例えば認証サーバへの情報の送信処理等を禁止する等の対応が可能となる。
 また、前記情報処理端末は、前記携行型記憶媒体の装着状態を監視し、非装着が検知されると、前記認証サーバとの通信を中止する装着監視手段を備えることが好ましい。この構成によれば、情報処理端末での所定の情報処理を行う間、携行型記憶媒体を情報処理端末に継続して装着して、装着状態の監視をクリアする必要があるため、初回の認証時のみ装着すれば済む場合に比して、不正使用を困難なものとすることができる。
 また、前記情報処理端末は、前記携行型記憶媒体が装着されている間、前記所定の情報処理が実行可能な状態にされるものであり、前記認証サーバは、前記情報処理端末からの前記識別情報を含む信号の受信が初回か否かを監視し、前記2回目以降の場合、前記識別情報を含む信号に含まれる前記識別情報が1回目に受信された前記識別情報と一致するか否かを判断する第2の判定手段を備えることが好ましい。この構成によれば、初回の本人認証が成功した場合には、2回以降では識別情報のみのチェックで済ますようにしたので、認証キー情報を、認証動作の都度、電子メール、携行型通信端末、携行型記憶媒体を経由させるといった手間を省き、かつ盗聴機会を少なくすることができる。
 また、前記認証キー情報処理手段による前記認証キー情報の送信毎に異なる認証キー情報を作成する認証キー情報作成手段を備えることが好ましい。この構成によれば、仮に認証キー情報を盗聴されたとしても、次回の情報処理端末の使用に際しては無益な情報となるので、盗用が阻止できる。
 また、認証キー情報作成手段は、無作為に前記認証キー情報を作成することが好ましい。この構成によれば、盗聴された認証キー情報から変更後の情報を予想できないため、信頼性の高い認証キー情報となる。
 また、前記携行型通信端末は、前記携行型通信端末は、前記無線基地局との間で電磁波を媒介として前記情報の送受信を行う携帯電話機であることが好ましい。この構成によれば、携帯電話機は多数の者が所持しているツールであるため、本発明を汎用性の高いものとすることが可能となる。
 また、前記第1の近距離通信部は、電磁波を媒介とした無線通信装置を備えたものであることが好ましい。この構成によれば、電磁波であれば、例えば光を用いた態様に比して携帯電話機の送受光面を合わせるために向きを調整する等の操作が不要となる。
 また、請求項1~8のいずれかに記載の本人認証システムに用いられる前記携帯型通信端末であって、前記第1の近距離通信部との間で近距離通信を行う第2の近距離通信部と、前記認証サーバから前記認証キー情報を受信すると、該受信した認証キー情報を前記第2の近距離通信部から前記第1の近距離通信部へ送信する近距離通信制御手段とを備えることが好ましい。この構成によれば、携行型通信端末に、第2の近距離通信部を備え、認証キーを携行型記憶媒体に送信するようにしたので、携行型記憶媒体の盗用によっても、本人認証処理の不正なすり抜け処理が確実に阻止される。
 また、前記近距離通信制御手段は、対応する携行型記憶媒体を特定するパスキーが予め記憶されており、前記パスキーを用いて、前記認証サーバから受信した前記認証キー情報を前記対応する携行型記憶媒体の第1の近距離通信部へ送信することが好ましい。この構成によれば、仮に周囲に複数の携行型記憶媒体が存在していても、特定された1つの携行型記憶媒体にしか認証キーが送信されないため、高い秘匿性が保持できる。
 また、前記認証サーバの電子的なアドレスを記憶するアドレス記憶部と、前記第1の近距離通信部との間での近距離通信の状態を監視し、近距離通信が途絶えた場合、その旨の情報を前記認証サーバの電子的なアドレスに送信する近接通信監視手段とを備えることが好ましい。この構成によれば、携行型通信端末と携行型記憶媒体との距離が相対的に近距離範囲外となった場合に、認証サーバにその旨が連絡されるので、正当者でない可能性の高い場合には所定の情報処理を禁止する等の措置を採ることできる。
 1 端末(情報処理端末)
 11 制御部
 111 USB通信処理部
 112 装着検出部(装着監視手段)
 113 USBID取得部
 114 認証要求処理部(認証要求処理手段)
 115 認証キー取得部(認証キー中継処理手段、回数監視手段)
 116 認証結果処理部
 117 プログラム実行処理部
 118 ネットワーク通信処理部
 132 特定AP記憶部
 2 USBメモリ(携行型記憶媒体)
 201 USBID記憶部(識別情報記憶部)
 202 情報記憶部
 203 近距離通信処理部(第1の近距離通信部)
 21 近距離通信送受波部(第1の近距離通信部)
 3 会員サーバ
 4 認証サーバ
 41 制御部
 411 パケット監視部
 412 USB正当性判定部(識別情報一致判定手段)
 413 第1認証処理部(第1の判定手段、判定結果処理手段)
 414 第2認証処理部(第2の判定手段、判定結果処理手段)
 415 認証キー作成部(認証キー情報作成手段)
 416 ネットワーク通信処理部
 417 携帯電子メール通信処理部(認証キー情報処理手段)
 431 USBID/携帯電子メールアドレス/認証キー記憶部(関連情報記憶部)
 5 電子メールシステム(情報伝送系)
 6 携帯電話機(携行型通信端末)
 61 制御部
 611 近距離通信処理部(近距離通信制御手段)
 612 USB接続状態監視部(近接通信監視手段)
 613 認証キー取得部
 614 携帯電子メール通信処理部
 615 タイマ
 63 RAM(アドレス記憶部)
 66 近距離通信送受波部(第2の近距離通信部)
 7 ネットワーク

Claims (13)

  1. ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証システムにおいて、
     前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、
     前記携行型記憶媒体は、
     識別情報を記憶する識別情報記憶部と、
     前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末との間で近距離通信を行う第1の近距離通信部とを備え、
     前記認証サーバは、
     前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶された関連情報記憶部を備え、
     前記情報処理端末は、
     前記携行型記憶媒体の装着を検出して前記識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信する認証要求処理手段と、
     前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信する認証キー中継処理手段とを備え、
     前記認証サーバは、
     受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信する認証キー情報処理手段と、
     前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定する第1の判定手段とを備えたことを特徴とする本人認証システム。
  2. 前記認証サーバは、受信した前記識別情報を含む信号に含まれる前記識別情報と前記関連情報記憶部に予め記憶されている識別情報との一致を判定する識別情報一致判定手段を備えたことを特徴とする請求項1記載の本人認証システム。
  3. 前記認証サーバは、前記判定の結果を前記認証キー情報の送信元の情報処理端末に送信する判定結果処理手段を備えたことを特徴とする請求項1又は2に記載の本人認証システム。
  4. 前記情報処理端末は、前記携行型記憶媒体の装着状態を監視し、非装着が検知されると、前記認証サーバとの通信を中止する装着監視手段を備えたことを特徴とする請求項1~3のいずれかに記載の本人認証システム。
  5. 前記情報処理端末は、前記携行型記憶媒体が装着されている間、前記所定の情報処理が実行可能な状態にされるものであり、
     前記認証サーバは、
     前記情報処理端末からの前記識別情報を含む信号の受信が初回か否かを監視し、前記2回目以降の場合、前記識別情報を含む信号に含まれる前記識別情報が1回目に受信された前記識別情報と一致するか否かを判断する第2の判定手段を備えたことを特徴とする請求項1~4のいずれかに記載の本人認証システム。
  6. 前記認証キー情報処理手段による前記認証キー情報の送信毎に異なる認証キー情報を作成する認証キー情報作成手段を備えたことを特徴とする請求項1~5のいずれかに記載の本人認証システム。
  7. 認証キー情報作成手段は、無作為に前記認証キー情報を作成することを特徴とする請求項6に記載の本人認証システム。
  8. 前記携行型通信端末は、前記無線基地局との間で電磁波を媒介として前記情報の送受信を行う携帯電話機であることを特徴とする請求項1~7のいずれかに記載の本人認証システム。
  9. 前記第1の近距離通信部は、電磁波を媒介とした無線通信装置を備えたものであることを特徴とする請求項8に記載の本人認証システム。
  10. 請求項1~9のいずれかに記載の本人認証システムに用いられる前記携帯型通信端末であって、前記第1の近距離通信部との間で近距離通信を行う第2の近距離通信部と、
     前記認証サーバから前記認証キー情報を受信すると、該受信した認証キー情報を前記第2の近距離通信部から前記第1の近距離通信部へ送信する近距離通信制御手段とを備えることを特徴とする携帯型通信端末。
  11. 前記近距離通信制御手段は、対応する携行型記憶媒体を特定するパスキーが予め記憶されており、前記パスキーを用いて、前記認証サーバから受信した前記認証キー情報を前記対応する携行型記憶媒体の第1の近距離通信部へ送信するものであることを特徴とする請求項10に記載の携帯型通信端末。
  12. 前記認証サーバの電子的なアドレスを記憶するアドレス記憶部と、
     前記第1の近距離通信部との間での近距離通信の状態を監視し、近距離通信が途絶えた場合、その旨の情報を前記認証サーバの電子的なアドレスに送信する近接通信監視手段とを備えたことを特徴とする請求項10又は11に記載の携帯型通信端末。
  13. ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証方法において、
     前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、
     前記認証サーバの関連情報記憶部には、前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶され、
     前記情報処理端末の認証要求処理手段が、前記携行型記憶媒体の装着を検出して、前記携行型記憶媒体に記憶されている識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信し、
     前記認証サーバの認証キー情報処理手段が、受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信し、
     前記携行型記憶媒体の近距離通信部が、前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末を介して前記認証キー情報を取得し、
     前記情報処理端末の認証キー中継処理手段が、前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信し、
     前記認証サーバの判定手段が、前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定することを特徴とする本人認証方法。
PCT/JP2009/071277 2009-12-22 2009-12-22 本人認証方法、本人認証システム及び携行型通信端末 Ceased WO2011077512A1 (ja)

Priority Applications (6)

Application Number Priority Date Filing Date Title
KR1020127018923A KR20120099782A (ko) 2009-12-22 2009-12-22 본인 인증 방법, 본인 인증 시스템 및 휴대형 통신단말기
PCT/JP2009/071277 WO2011077512A1 (ja) 2009-12-22 2009-12-22 本人認証方法、本人認証システム及び携行型通信端末
JP2011547128A JPWO2011077512A1 (ja) 2009-12-22 2009-12-22 本人認証方法、本人認証システム及び携行型通信端末
US13/516,044 US20120254955A1 (en) 2009-12-22 2009-12-22 Personal authentication method, personal authentication system, and portable-type communication terminal
CN2009801631145A CN102667798A (zh) 2009-12-22 2009-12-22 本人认证方法、本人认证系统和便携式通信终端
EP09852529A EP2518659A1 (en) 2009-12-22 2009-12-22 User authentication method, user authentication system, and portable communications terminal

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2009/071277 WO2011077512A1 (ja) 2009-12-22 2009-12-22 本人認証方法、本人認証システム及び携行型通信端末

Publications (1)

Publication Number Publication Date
WO2011077512A1 true WO2011077512A1 (ja) 2011-06-30

Family

ID=44195075

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2009/071277 Ceased WO2011077512A1 (ja) 2009-12-22 2009-12-22 本人認証方法、本人認証システム及び携行型通信端末

Country Status (6)

Country Link
US (1) US20120254955A1 (ja)
EP (1) EP2518659A1 (ja)
JP (1) JPWO2011077512A1 (ja)
KR (1) KR20120099782A (ja)
CN (1) CN102667798A (ja)
WO (1) WO2011077512A1 (ja)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014191671A (ja) * 2013-03-28 2014-10-06 Mitsubishi Space Software Co Ltd セキュリティ記憶媒体、ファイル管理システムおよびファイル管理方法
JPWO2015068452A1 (ja) * 2013-11-06 2017-03-09 株式会社村田製作所 無線通信システム及びワンタイムパスワードの生成、認証方法
JP2019194863A (ja) * 2014-04-16 2019-11-07 ジェイエーエムエフ・ソフトウェア・エルエルシー 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること
JP2024544644A (ja) * 2021-11-30 2024-12-03 北京博衍思創信息科技有限公司 Usbデバイスアクセス制御の方法、装置及び電子機器

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8626921B2 (en) * 2010-04-22 2014-01-07 Cisco Technology, Inc. Device and service management based on layer 2 through layer 7 device attributes
US20120102324A1 (en) * 2010-10-21 2012-04-26 Mr. Lazaro Rodriguez Remote verification of user presence and identity
JP5817766B2 (ja) * 2013-03-21 2015-11-18 富士ゼロックス株式会社 情報処理装置、通信システム及びプログラム
CN103490902B (zh) * 2013-10-11 2017-11-24 北京握奇智能科技有限公司 一种实现用户身份认证的方法和装置
CN109040099B (zh) 2013-10-30 2021-06-22 创新先进技术有限公司 一种针对应用的验证方法、终端和系统
CN106169055A (zh) * 2015-05-21 2016-11-30 秦皇岛鸿大科技开发有限公司 基于指静脉识别的蓝牙移动存储器
CN110113153B (zh) * 2019-04-23 2022-05-13 深圳数字电视国家工程实验室股份有限公司 一种nfc密钥更新方法、终端及系统
JP7227086B2 (ja) * 2019-06-21 2023-02-21 ファナック株式会社 正当性確認機器
JP7276235B2 (ja) * 2020-04-20 2023-05-18 トヨタ自動車株式会社 認証システム
WO2022003796A1 (ja) * 2020-06-29 2022-01-06 日本電気株式会社 情報処理システム、情報処理方法及びプログラム
US11561917B2 (en) * 2020-09-23 2023-01-24 Hewlett Packard Enterprise Development Lp USB connection management

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001306806A (ja) * 2000-04-19 2001-11-02 Nec Corp カードの不正使用防止方法及びシステム並びに記録媒体
JP2006268682A (ja) * 2005-03-25 2006-10-05 Fujitsu Ltd 認証システム、その制御方法、情報処理システムおよび携帯型認証装置
JP2008033571A (ja) 2006-07-27 2008-02-14 Mieko Tsuyusaki ネットシステム
JP2008250923A (ja) * 2007-03-30 2008-10-16 Ntt Docomo Inc 認証処理システム、移動通信端末、及び認証処理方法
JP2009104248A (ja) 2007-10-19 2009-05-14 Dainippon Printing Co Ltd 認証情報入力モジュール

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
ATE339742T1 (de) * 2003-11-07 2006-10-15 Cit Alcatel Verfahren zur unterstützung bargeldloser zahlung
US8045961B2 (en) * 2009-06-22 2011-10-25 Mourad Ben Ayed Systems for wireless authentication based on bluetooth proximity

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001306806A (ja) * 2000-04-19 2001-11-02 Nec Corp カードの不正使用防止方法及びシステム並びに記録媒体
JP2006268682A (ja) * 2005-03-25 2006-10-05 Fujitsu Ltd 認証システム、その制御方法、情報処理システムおよび携帯型認証装置
JP2008033571A (ja) 2006-07-27 2008-02-14 Mieko Tsuyusaki ネットシステム
JP2008250923A (ja) * 2007-03-30 2008-10-16 Ntt Docomo Inc 認証処理システム、移動通信端末、及び認証処理方法
JP2009104248A (ja) 2007-10-19 2009-05-14 Dainippon Printing Co Ltd 認証情報入力モジュール

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014191671A (ja) * 2013-03-28 2014-10-06 Mitsubishi Space Software Co Ltd セキュリティ記憶媒体、ファイル管理システムおよびファイル管理方法
JPWO2015068452A1 (ja) * 2013-11-06 2017-03-09 株式会社村田製作所 無線通信システム及びワンタイムパスワードの生成、認証方法
JP2019194863A (ja) * 2014-04-16 2019-11-07 ジェイエーエムエフ・ソフトウェア・エルエルシー 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること
JP2021145365A (ja) * 2014-04-16 2021-09-24 ジェイエーエムエフ・ソフトウェア・エルエルシー 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること
JP7238015B2 (ja) 2014-04-16 2023-03-13 ジェイエーエムエフ・ソフトウェア・エルエルシー 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること
JP2024544644A (ja) * 2021-11-30 2024-12-03 北京博衍思創信息科技有限公司 Usbデバイスアクセス制御の方法、装置及び電子機器
JP7787612B2 (ja) 2021-11-30 2025-12-17 北京博衍思創信息科技有限公司 Usbデバイスアクセス制御の方法、装置及び電子機器

Also Published As

Publication number Publication date
US20120254955A1 (en) 2012-10-04
KR20120099782A (ko) 2012-09-11
JPWO2011077512A1 (ja) 2013-05-02
EP2518659A1 (en) 2012-10-31
CN102667798A (zh) 2012-09-12

Similar Documents

Publication Publication Date Title
JPWO2011077512A1 (ja) 本人認証方法、本人認証システム及び携行型通信端末
US11706212B2 (en) Method for securing electronic transactions
CN106991317B (zh) 安全验证方法、平台、装置和系统
EP3312750B1 (en) Information processing device, information processing system, and information processing method
EP3271885B1 (en) Multi-device transaction verification
CN110232568B (zh) 移动支付方法、装置、计算机设备及可读存储介质
US20240403863A1 (en) Multi-device authentication process and system utilizing cryptographic techniques
US20150333911A1 (en) Id system and program, and id method
US20110197267A1 (en) Secure authentication system and method
US7357329B2 (en) IC card, terminal device, and data communication method
KR20180108713A (ko) 이동 단말 p2p에 기초한 신용 지불 방법 및 장치
WO2011048645A1 (ja) 端末管理システム及び端末管理方法
WO2015161699A1 (zh) 数据安全交互方法和系统
WO2001082151A1 (fr) Dispositif externe et systeme d'authentification
WO2015161690A1 (zh) 数据安全交互方法和系统
JP2004220402A (ja) Eコマース認証システムおよび方法
KR101212510B1 (ko) 위치기반의 서비스 보안 시스템 및 그 방법
JPH10198636A (ja) 個人認証システムおよび個人認証方法
CN114253414B (zh) 用于非接触式pin输入的系统和方法
KR20070029537A (ko) 무선단말기와 연동한 개인별고유코드를 활용한인증시스템과 그 방법
KR20010067759A (ko) 일회용식별코드를 이용한 통합개인인증 방법
KR101700833B1 (ko) 카드 사용자 인증 시스템 및 그를 위한 인증서버와 휴대단말기
EP4250210B1 (en) Devices, methods and a system for secure electronic payment transactions
EP4250208B1 (en) Devices, methods and a system for secure electronic payment transactions
KR20130005635A (ko) 보안 모바일 결제 시스템 및 그 제공방법

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200980163114.5

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09852529

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2011547128

Country of ref document: JP

WWE Wipo information: entry into national phase

Ref document number: 13516044

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2009852529

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20127018923

Country of ref document: KR

Kind code of ref document: A