WO2011077512A1 - 本人認証方法、本人認証システム及び携行型通信端末 - Google Patents
本人認証方法、本人認証システム及び携行型通信端末 Download PDFInfo
- Publication number
- WO2011077512A1 WO2011077512A1 PCT/JP2009/071277 JP2009071277W WO2011077512A1 WO 2011077512 A1 WO2011077512 A1 WO 2011077512A1 JP 2009071277 W JP2009071277 W JP 2009071277W WO 2011077512 A1 WO2011077512 A1 WO 2011077512A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- information
- authentication key
- terminal
- storage medium
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/42—User authentication using separate channels for security data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/34—User authentication involving the use of external additional devices, e.g. dongles or smart cards
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/02—Terminal devices
Definitions
- the present invention relates to an authentication technology for authenticating the legitimacy of a person who uses an information processing terminal connected to a network.
- Patent Document 1 describes an authentication technique that uses the presence location and authentication date and time obtained using a clock circuit and a GPS receiver in addition to the fingerprint data of the terminal user. Patent Document 1 describes that information that can identify a living body such as an iris or a vein can be used in addition to a fingerprint.
- Patent Document 2 describes a network system that enables transactions from a personal computer (hereinafter referred to as a personal computer) at a destination via a network.
- Patent Document 2 when a password is transmitted by e-mail from a center server to a user's mobile phone during a transaction, the user looks at the received password and enters a key in a password input field of a personal computer. To enter a password. Then, it is described that the entered information is transmitted to the center server and verified with the original password (paragraph numbers 500 to 502). As a result, procedure processing, login, and transaction processing can be performed safely on a personal computer other than the personal computer owned by the user. Note that Patent Document 2 describes that a user may return a mail received by a mobile phone to the center server (paragraph number 503).
- Patent Document 1 While the authentication technique described in Patent Document 1 is superior in that it uses individual information called fingerprints, fingerprints and the like are easily forged and whether or not the fingerprint data to be authenticated is forged. It is not easy to identify.
- the network system described in Patent Document 2 forces a user to perform a password input operation that is almost the same as a conventional password input operation to a personal computer while looking at the screen of a mobile phone. There is a high risk of being known to others.
- the password may be obtained by wireless eavesdropping and may be used illegally.
- Patent Document 2 if only the password input operation is cleared, the personal computer can be used illegally thereafter, which is not perfect.
- An object of the present invention is to authenticate the portable storage medium in a mounted state and pass through the portable storage medium with respect to a portable storage medium that is attached to an information processing terminal and permits execution of predetermined information processing. It is an object of the present invention to provide a personal authentication method, a personal authentication system, and a portable communication terminal used in the system that can effectively prevent an unauthorized passing operation of the authentication process by performing personal authentication.
- the personal authentication system is the personal authentication system for authenticating the presence or absence of a legitimate owner of a portable storage medium that allows execution of predetermined information processing by being attached to an information processing terminal connected to a network.
- An authentication server connected to a network and authenticating whether or not the owner is authorized the portable storage medium includes an identification information storage unit for storing identification information, and a radio base station possessed by the authorized owner
- a first short-range communication unit that performs short-range communication with a portable communication terminal capable of transmitting and receiving information via an information transmission system, wherein the authentication server identifies the portable storage medium In association with the information, the electronic information of the portable communication terminal possessed by the rightful owner of the portable storage medium, and a related information storage unit in which unique authentication key information is stored
- the information processing terminal includes an authentication request processing unit that detects attachment of the portable storage medium, acquires the identification information, and transmits a signal including the acquired identification information to the authentication server; and the identification information After acquiring the authentication key information from the authentication server via the portable communication terminal and the portable storage
- the personal authentication method is a personal authentication method for authenticating the presence or absence of a legitimate owner of a portable storage medium that is permitted to execute predetermined information processing by being attached to an information processing terminal connected to a network.
- An authentication server that is connected to the network and authenticates whether or not it is the rightful owner, and the associated information storage unit of the authentication server is associated with the identification information of the portable storage medium in association with the portable storage medium
- Electronic address information of the portable communication terminal possessed by the rightful owner of the medium and unique authentication key information are stored, and the authentication request processing means of the information processing terminal detects attachment of the portable storage medium Then, the identification information stored in the portable storage medium is acquired, a signal including the acquired identification information is transmitted to the authentication server, and authentication key information processing of the authentication server is performed.
- the stage reads the authentication key information and electronic address information corresponding to the identification information included in the received signal including the identification information from the related information storage unit, and reads the read authentication key information.
- a portable communication terminal capable of transmitting and receiving information via an information transmission system having a radio base station owned by the rightful owner.
- the authentication key relay processing means of the information processing terminal authenticates from the authentication server via the portable communication terminal and the portable storage medium after transmitting a signal including the identification information.
- key information is acquired, the acquired authentication key information is transmitted to the authentication server, and a determination unit of the authentication server transmits the authentication key information to the electronic address.
- a determination unit of the authentication server transmits the authentication key information to the electronic address.
- predetermined information processing when it is authenticated that the portable storage medium attached to the information processing terminal is possessed by the rightful owner, predetermined information processing can be executed via the network.
- the network is connected to an authentication server that authenticates whether or not the owner is the rightful owner.
- electronic address information for example, electronic
- E-mail address E-mail address
- unique authentication key information are stored.
- the authentication request processing means of the information processing terminal detects attachment of the portable storage medium, acquires identification information stored in the portable storage medium, and a signal including the acquired identification information. Sent to the authentication server.
- authentication key information and electronic address information corresponding to the identification information included in the received signal including the identification information are read from the related information storage unit by the authentication key information processing means of the authentication server, The read authentication key information is transmitted to the read electronic address.
- a portable communication terminal capable of transmitting and receiving information via the information transmission system (for example, public telephone line) possessed by the rightful owner and possessed by the short-range communication unit of the portable storage medium.
- the authentication key information is acquired via.
- the authentication key relay processing means of the information processing terminal acquires the authentication key information from the authentication server via the portable communication terminal and the portable storage medium after transmitting the signal including the identification information.
- the acquired authentication key information is transmitted to the authentication server.
- the authentication key information processing unit transmits the authentication key information. It is determined whether or not the authentication key information is different.
- a portable storage medium is given (including lending) to the terminal user, and the personal authentication is made possible by using the portable storage medium and the portable communication terminal possessed by the terminal user. That is, on the condition that the validity of the portable storage medium attached to the terminal is determined by the authentication server, the authentication key information is transferred from the authentication server to the portable communication terminal, for example, by e-mail.
- the authentication key sent by the authentication server can be transmitted from the terminal wearing the portable storage medium to the authentication server via the network by short-range communication from the mobile terminal to the portable storage medium attached to the terminal. By verifying the received authentication key, personal authentication can be performed.
- the authentication key transmitted by the e-mail is transmitted from the portable communication terminal to the portable storage medium by short-range communication, so that the terminal user can use his portable storage medium and his portable communication terminal.
- the portable storage medium is stolen, an illegal slip-through operation of the personal authentication process is reliably prevented systematically.
- the portable communication terminal is the portable communication terminal used in the personal authentication system, and is a second short-range communication that performs short-range communication with the first short-range communication unit. And a near field communication control means for transmitting the received authentication key information from the second near field communication unit to the first near field communication unit when receiving the authentication key information from the authentication server. ing.
- the portable communication terminal since the portable communication terminal includes the second short-range communication unit and transmits the authentication key to the portable storage medium, the personal authentication process can be performed even if the portable storage medium is stolen. Unauthorized slip-through processing is reliably prevented.
- the present invention it is possible to effectively prevent unauthorized slipping of the personal authentication process by interposing near field communication between the portable communication terminal and the portable storage medium.
- FIG. 1 is a schematic configuration diagram of a network system to which a personal authentication system according to the present invention is applied.
- FIG. 2 is a configuration diagram in which functions of the terminal 1, the USB memory 2, the authentication server 4, the mail system 5, and the mobile phone 6 are blocked.
- FIG. 6 is a sequence diagram showing an outline of the flow of information related to personal authentication among the USB memory 2, the terminal 1, the authentication server 4, and the mobile phone 6.
- 4 is a flowchart illustrating an example of a USB port state detection procedure executed by the CPU of the terminal 1. It is a flowchart which shows an example of the procedure of the authentication process I performed by CPU of the authentication server 4. It is a flowchart which shows an example of the procedure of the authentication process II performed by CPU of the authentication server 4.
- 5 is a flowchart illustrating an example of a procedure of an authentication key creation process executed by a CPU of the authentication server 4.
- 10 is a flowchart showing an example of a procedure of processing I executed by the CPU of the mobile phone 6.
- 4 is a flowchart illustrating an example of a procedure of USB processing I executed by the CPU of the terminal 1.
- 4 is a flowchart illustrating an example of a procedure of USB processing II executed by the CPU of the terminal 1.
- 10 is a flowchart showing an example of a procedure of a process II executed by the CPU of the mobile phone 6;
- FIG. 1 is a schematic configuration diagram of a network system to which a personal authentication system according to the present invention is applied.
- the network system shown in FIG. 1 includes, for example, a terminal (information processing terminal) 1 that is a member, a consumer, a store, a company, or the like, and a terminal (information processing terminal) 1 arranged in one or more financial institutions that perform settlement. And a member server 3 disposed in a management organization that performs overall management and storage of information between the terminal 1 and the terminal 1.
- Each terminal 1 and member server 3 are connected to a network 7 such as the Internet.
- the terminal 1 is generally composed of a personal computer or the like with a built-in CPU (Central Processing Unit).
- general information such as information creation, processing, storage, and transmission / reception of information using communication software using general document and graphic generation software is used.
- a program file (referred to as general-purpose AP (application program)) for executing each process and a program file (referred to as specific AP) for performing processes related to execution of specific application software described later are stored.
- the terminal 1 such as a consumer, a store, or a company that is a member performs the creation and communication of each document relating to the purchase and sale of goods and services, estimation or billing, and deposit / withdrawal as a specific AP.
- Software and authentication processing software to be described later are installed.
- the terminal 1 performs settlement in general commercial transactions, for example, issuance and receipt of invoices from a merchant store, and deposit (i.e., payment) instructions from the purchaser to the account of the contract financial institution that issued the invoice.
- deposit i.e., payment
- the terminal 1 can create various documents as electronic files in text format or binary format.
- the electronic file is exchanged between the terminals 1 via the member server 3, for example.
- Special application software that performs payment instruction processing (such as instructions for payment processing between financial institutions) in accordance with the financial payment document from the terminal 1 of the consumer or company is also installed in each financial institution terminal 1. ing.
- the terminal 1 has a USB port to which a portable storage medium (member external storage medium), for example, a chip-shaped USB (Universal Serial Bus) memory 2 can be attached (connected).
- the storage medium may be stick-like hardware using an IEEE 1394 port.
- the USB memory 2 is given to members and has a storage unit (area) in which predetermined information can be stored as will be described later.
- the USB memory 2 is provided with short-range communication means such as Bluetooth in an appropriate place such as the inside of a chip-shaped main body.
- the short-range communication means is not limited to wireless (radio waves, light), but is preferably a wireless type in terms of operability.
- the short-range communication method is not limited to Bluetooth, but may be wireless LAN (Local area network), RFID (Radio Frequency Identification) or the like.
- the member server 3 stores appropriate information related to members, for example, member information such as a member's name, name, e-mail address, and address in units of members.
- the member server 3 further includes a storage unit for storing the file transmission / reception history of each member and the files thereof for management.
- the member server 3 includes a functional unit as the authentication server 4.
- the authentication server 4 is connected to the network 7 and is in a state where a file exchanged between the member server 3 and the terminal 1, that is, a packet can be viewed.
- the relationship between the member server 3 and the authentication server 4 may be a serial or parallel connection relationship, and the packet transmitted from the terminal 1 to the member server 3 realizes the authentication processing in the present invention. Any mode can be used as long as it can be browsed in a possible range.
- this system creates and stores secret information, for example, information communication between a plurality of terminals 1 connected to a LAN in a corporate organization that is a public institution.
- secret information for example, information communication between a plurality of terminals 1 connected to a LAN in a corporate organization that is a public institution.
- the terminal 1 is connected to a network 7 via a provider (ISP) 8.
- ISP provider
- a plurality of terminals 1 are connected to the ISP 8.
- an appropriate number of servers having Web sites that provide various types of information are connected to the ISP 8.
- the terminal 1 connected to the ISP 8 includes a member-owned terminal 1 in which the specific AP is installed and a normal terminal 1 ′ in which the specific AP is not installed.
- a part of the specific AP has a program for performing an authentication process, and controls whether or not to execute the specific AP according to the authentication result.
- the legitimacy of the member who uses the USB memory 2 that is, a portable communication terminal that can carry out personal authentication, typically a mobile phone 6 that can send and receive e-mails is used.
- a mail system 5 of a mobile phone company is used as a mechanism for sending and receiving e-mail.
- the configurations of the mail system 5 and the mobile phone 6 will be described with reference to FIG.
- the portable communication terminal 6 may be a PDA (Personal Digital Assistant) in addition to the mobile phone 6.
- FIG. 2 shows a block diagram in which the functions of the terminal 1, the USB memory 2, the authentication server 4, the mail system 5, and the mobile phone 6 are respectively blocked.
- the terminal 1 includes a control unit 11 configured by a CPU, and a ROM (Read Only Memory) 12 and a RAM (Random Access Memory) 13 are connected to the control unit 11.
- the control unit 11 is connected to an operation unit 14 including a numeric keypad and a mouse, and a display unit 15 including an CRT, a liquid crystal display, a plasma display, or the like and displaying an image.
- the ROM 12 includes at least an OS storage unit 121 that stores an OS (Operating System), a BIOS (Basic Input / Output System), and the like for starting the terminal 1 (boot processing) and reading application software.
- OS Operating System
- BIOS Basic Input / Output System
- the RAM 13 includes a general-purpose AP storage unit 131 in which the above-described general application software is installed, and a specific AP storage unit 132 in which specific application software related to processing such as authentication, electronic commerce service, and administrative service is installed. And at least a creation file storage unit 133 for storing a text file or a file created by a binary code created by a general-purpose AP or a specific AP.
- the files stored in the created file storage unit 133 include not only files created by the user but also transmitted and received files.
- the specific AP is taken in via an external storage medium in advance or at a predetermined time. For example, it is installed from a predetermined server (may be the member server 3) on the network or from an external storage medium such as a hard disk at the time of member registration.
- the control unit 11 is equipped with a USB communication processing unit 111 for communicating with the USB memory 2 and the USB memory 2 mounted on the USB port Po of the terminal 1 by executing a program stored in the ROM 12 and the RAM 13 by the CPU.
- a mounting detection unit 112 that detects whether or not the USB memory 2 has been identified; a USBID acquisition unit 113 that acquires identification information (USBID) for identifying the USB memory 2 from the USB memory 2; and an authentication request processing unit that transmits an authentication request signal to the authentication server 4 114, an authentication key acquisition unit 115 that acquires authentication key information from the USB memory 2, an authentication result processing unit 116 that acquires authentication result information from the authentication server 4 and performs processing according to the authentication result, and a designated program.
- Network communication processing for sending and receiving document files between the member server 3 and the authentication server 4, typically sending and receiving document files using packets formed in accordance with TCP / IP (transmission control protocol / internet protocol) rules It functions as the unit 118.
- the network communication processing unit 118 returns the received packet to the original document file or replaces the transmission file with the packet and transmits the packet.
- the header of each packet to be transmitted includes the terminal that is the transmission source. 1 global IP address, the global IP address of the other terminal that is the transmission destination and the member server 3, and the USB ID of the USB memory attached to the terminal 1 and at least the first authentication key are included. .
- the USB memory 2 includes a configuration unit 20 in which information is stored and a short-range communication transmission / reception unit 21 that is a configuration unit that performs short-range communication.
- the configuration unit 20 that stores information includes a USBID storage unit 201 in which a USBID for identifying the USB memory 2 is stored, information used in session processing to be described later (information for identifying itself “passkey: PIN (Personal IdentificationIdentNumber))
- the information storage unit 202 stores information received in the session.
- the near field communication transmitting / receiving unit 21 includes an antenna for transmitting and receiving electromagnetic waves in the above-described Bluetooth or the like, and performs near field communication with the mobile phone 6 and Bluetooth as described later.
- the near field communication processing unit 203 controls the operation of the near field communication transmitting / receiving unit 21 by receiving a required signal from the terminal 1 or receiving a required control program while being attached to the terminal 1. And controls the session operation.
- the attachment detection unit 112 of the terminal 1 detects whether or not the USB memory 2 is attached from the presence or absence of a response signal from the USB port Po in a predetermined handshake process.
- the USBID acquisition unit 113 reads and acquires the USBID from the USBID storage unit 201 when the USB memory 2 is attached.
- the authentication request processing unit 114 When the USB memory 2 is attached, the authentication request processing unit 114 generates an authentication request signal including a USB ID, converts the signal into a predetermined packet, and transmits the packet to the authentication server 4.
- the authentication key acquisition unit 115 acquires the authentication key information from the USB memory 2 after transmitting the authentication request signal
- the authentication key acquiring unit 115 converts the authentication key into a predetermined packet and transmits the packet to the authentication server 4.
- the authentication result processing unit 116 receives the authentication result transmitted from the authentication server 4. If the authentication result is successful, the program execution processing unit 117 permits only the specific AP to execute, and is not successful (failed). In this case, a signal permitting the execution of only the general-purpose AP is output to the program effective processing unit 117.
- the authentication server 4 performs file transmission / reception between the terminal 1 and the member server 3 by executing a specific AP (specifically, the member server 3 relays the other server 1 and the document It is continuously executed while file transmission / reception is performed.
- a specific AP specifically, the member server 3 relays the other server 1 and the document It is continuously executed while file transmission / reception is performed.
- the authentication server 4 includes a control unit 41 including a CPU, a ROM 42 in which an authentication processing program is stored, and a RAM 43 in which authentication information is stored.
- the RAM 43 stores the USBID / portable electronic device in which the USBID of the USB memory 2 assigned to each member, the e-mail address of the mobile phone 6 possessed by each member, and the authentication key for personal authentication are stored in association with each other. It has a mail address / authentication key (hereinafter referred to as related information) storage unit 431.
- the control unit 41 executes the program stored in the ROM 42 by the CPU, thereby determining the validity of the read USBID, the packet monitoring unit 411 that reads the USBID and the authentication key in the packet transmitted from the terminal 1
- the USB validity determination unit 412 transmits the authentication key corresponding to the USBID determined to be valid by e-mail to the corresponding mobile e-mail address, and then the USBID source determined to be valid
- a first authentication processing unit 413 that performs verification (initial authentication) with an authentication key received from a certain terminal 1. Every time a packet is received from the terminal 1 after the initial authentication, the USBID included in the received packet and the initial authentication are acquired.
- the second authentication processing unit 414 for collating the difference with the USBID, and the authentication key at a predetermined timing
- it functions as a mobile electronic mail communication processing unit 417 that converts authentication key information into an electronic mail packet and transmits it to a predetermined mobile phone 6 (via the mobile phone company mail system 5 described above).
- the portable electronic mail communication processing unit 417 functions as a so-called mail server, and converts a transmission mail into, for example, an Internet mail format and transmits it.
- the USB validity determination unit 412 compares the read USBID with a list of USBIDs that are the original information stored in advance in the related information storage unit 431, and determines that there is a validity if there is a matching USBID. Is. If the matching USBID cannot be found, the USB validity determination unit 412 does not need to perform authentication key authentication processing. Information indicating that the USB validity is not valid and the USB memory 2 is not valid. Is returned to the terminal 1 on which is mounted, and subsequent communication is interrupted.
- the authentication process is continuously performed while the USB memory 2 is attached to the terminal 1. Specifically, when the USBID transmitted from the terminal 1 is valid, the first authentication processing unit 413 transmits the authentication key transmitted to the corresponding mobile phone 6 via the mobile phone 6, the USB memory 2, and the terminal 1. If the two authentication keys are matched and matched, the authentication success information is returned to the terminal 1. On the other hand, if the two authentication keys are collated and they do not match, information indicating that the terminal 1 cannot be authenticated (authentication failure) is returned. The information on the authentication failure can be used as a mode for guiding a retry (operation for remounting the USB memory 2) up to a predetermined number of times by counting the number of times with a built-in counter (not shown) or the like.
- the process by the first authentication processing unit 413 is the first authentication process.
- the second authentication processing unit 414 temporarily stores this initial authentication as a first time in, for example, an appropriate location in the RAM 43, and then stores a file, that is, a packet with the terminal 1. While transmission / reception is performed, it is verified whether or not the USBID included in the header in the packet received from the terminal 1 matches the USBID acquired during the initial authentication process. If the collation results match, the communication is continued assuming that the second and subsequent authentications are established, and conversely, in the authentication process at any stage after the second, It is assumed that the USB memory 2 has been replaced in the middle or that there has been other illegal acts, and communication with the terminal 1 is interrupted.
- the authentication key creation unit 415 includes only the authentication key among the information corresponding to the USB ID after the USB memory 2 is attached to the terminal 1 and the required processing by the member is completed until it is attached next time. Is to change.
- the authentication key may be changed in response to the USB memory 2 being attached to the terminal 1 and the USBID being read, and thereafter, at least the next time the USB memory 2 is connected to any terminal. What is necessary is just to change before mounting to 1.
- the authentication key is preferably changed at random by using a random number generator or the like.
- the authentication key is updated by rewriting the current authentication key corresponding to the corresponding USBID in the related information storage unit 431.
- the mail system 5 functions as an information transmission system, is connected to the network 7 via the ISP 8, and includes an information processing unit 51 and a required number of wireless base stations 52.
- the base station 52 is a transmission / reception unit that has an antenna and transmits / receives radio waves to / from the mobile phone 6.
- a required number of mail systems 5 may be provided for load distribution. Similarly, as many base stations as necessary are provided for the purpose of expanding the call area.
- the information processing unit 51 is a mail gateway that performs conversion between the format and protocol of the electronic mail transmitted / received by the mobile phone 6 and the format and protocol of the electronic mail transmitted over the Internet and transmitted / received to the authentication server 4. 511, a portable electronic mail server 512 that controls transmission and reception of electronic mail, and a mail box 513 that temporarily stores electronic mail to be transmitted and received.
- the mobile phone 6 includes an antenna 60 that is provided in the main body and performs transmission and reception of radio waves, and a control unit 61 that is provided in the main body and includes a CPU.
- the control unit 61 includes a ROM 62 that stores various control programs for short-distance session communication for personal authentication processing, authentication key reception, and session result reporting in addition to normal call processing and e-mail transmission / reception processing.
- a RAM 63 is connected to store transmission information and reception information, and an e-mail address of the authentication server, a passkey and other information that is information for identifying the corresponding USB memory 2.
- an operation unit 64 composed of various function keys such as a numeric keypad and a display unit 65 such as a liquid crystal panel for displaying processing information and reception information are disposed at appropriate positions on the main body surface of the cellular phone 6.
- the near field communication transmitting / receiving unit 66 includes an antenna for transmitting / receiving electromagnetic waves in the above-described Bluetooth or the like, and performs near field communication with the USB memory 2 and Bluetooth as described later.
- the control unit 61 controls the operation of the near field communication transmitting / receiving unit 66 by the control program stored in the ROM 62 being executed by the CPU, and controls the session operation, the near field communication processing unit 611, the USB connection It has a status monitoring unit 612, an authentication key acquisition unit 613, a portable electronic mail communication processing unit 614, and a timer 615 for timing.
- the near field communication processing unit 611 Upon receiving the authentication key transmitted from the authentication server 4, the near field communication processing unit 611 transmits a signal for performing a predetermined session with the USB memory 2, and a response signal is received with respect to the transmitted signal. Then, a session is started, an authentication key is transmitted, and thereafter a signal for the session is continuously exchanged.
- the short-range communication processing unit 611 and the short-range communication processing unit 203 when the USB memory 2 and the mobile phone 6 are within a short distance, for example, 1 m (meter), which is a communication range of each other, the USB memory 2 This is continued until the terminal 1 is disconnected.
- the transmission / reception surfaces face each other and be disposed at a predetermined short distance.
- the USB connection state monitoring unit 612 performs a predetermined session with the short-range communication processing unit 203 of the USB memory 2, so that the USB connection state monitoring unit 612 is in the vicinity of the USB memory 2 attached to the terminal 1. It is determined whether or not the mobile phone 6 exists. That is, the USB connection state monitoring unit 612 determines that the mobile phone 6 does not originally exist in the vicinity of the terminal 1 unless a session with the short-range communication transmitting / receiving unit 21 occurs, and if the session is interrupted in the middle. Then, it is determined that the mobile phone 6 has moved away from the terminal 1 on the way, and both are abnormally terminated as will be described later.
- the USB connection state monitoring unit 612 determines that the mobile phone 6 has been in the vicinity of the terminal 1 until the end, and does not end abnormally.
- the mobile phone 6 transmits a signal indicating a failure of the authentication process to the authentication server 4.
- the monitoring (judgment) of the continuity of the session by the USB connection state monitoring unit 612 is executed by measuring a required interval within about ten seconds or one minute with the timer 615, for example.
- the authentication key acquisition unit 613 receives an authentication key transmitted from the authentication server 4 via the electronic mail system 5 and passes it to the near field communication processing unit 611.
- the portable electronic mail communication processing unit 614 transmits and receives authentication key information, information indicating session failure, and the like to and from the authentication server 4 in the form of electronic mail.
- FIG. 3 is a sequence diagram showing an outline of the flow of information relating to personal authentication among the USB memory 2, the terminal 1, the authentication server 4, and the mobile phone 6.
- the member attaches his / her USB memory 2 to the USB port Po of the target terminal 1. With this attachment, a handshake process is executed between the terminal 1 and the USB memory 2.
- the USBID is read from the USB memory 2 to the terminal 1.
- the terminal 1 generates an authentication request signal including the acquired USBID, converts it into a transmission packet, and transmits it to the authentication server 4. Thereby, the first authentication process is started.
- the authentication server 4 checks the validity of the USBID, and if it is valid, sends an authentication key corresponding to the USBID to the corresponding mobile phone 6 by e-mail.
- the mobile phone 6 transmits the received authentication key to the USB memory 2 by near field communication. Then, the authentication key received by the USB memory 2 is transmitted to the authentication server via the terminal 1.
- the authentication server 4 determines the difference between the authentication key transmitted to the mobile phone 6 and the authentication key received from the terminal 1, and determines that the authentication is successful if they match, and determines that the authentication fails if they do not match. .
- the authentication result is transmitted to the terminal 1. If the authentication result is an authentication failure, the fact is transmitted to the mobile phone 6 via the USB memory 2. Thereby, near field communication is cut off. In addition, the member can retry.
- a required file is transferred into a packet between the terminal 1 and the authentication server 4 (specifically, between the terminal 1 and the member server 3 via the authentication server 4). Converted and sent / received. Therefore, the USBID of the USB memory 2 written in the header of the packet transmitted from the terminal 1 to the authentication server 4 is included so that the second and subsequent authentications are performed while the USB memory 2 is attached to the terminal 1. Processing is performed continuously.
- the authentication server 4 monitors the header information of the packet transmitted from the terminal 1, and extracts the USBID from the header information. And the difference with USBID acquired from the terminal 1 at the time of the first authentication process is collated. Here, if the authentication fails, the fact is transmitted to the terminal 1.
- the specific AP process that is activated by the success of the first authentication process includes simply document creation in addition to communication, but the second and subsequent authentications are interrupted during processes other than packet transmission / reception. Will be. Further, even during the interruption period, an authentication packet including the USBID may be created periodically or periodically and transmitted to the authentication server 4.
- FIG. 4 is a flowchart showing an example of the USB port state detection procedure executed by the CPU of the terminal 1.
- a handshake signal is periodically transmitted to the USB port Po, and the state of the USB port Po is determined (step S1).
- a response signal is returned in response to the handshake signal.
- the USB memory 2 is not attached, no response signal is returned. Exit this flow.
- a specific AP in the specific AP is activated, assuming that some chip including the USB memory 2 is attached.
- the dedicated AP activates communication application software for determining whether or not the mounted chip is the USB memory 2 and for executing processing for reading the internal information when the chip is the USB memory 2.
- step S1 when there is a response from the USB memory 2, the USB ID is read from the USB ID storage unit 201 (step S3).
- step S5 an authentication request signal (packet) including the USBID is created (step S5).
- step S7 the created authentication request signal is transmitted to the authentication server 4 (step S7).
- step S9 the process shifts to a standby mode waiting for reception of a packet from the authentication server 4 (step S9).
- USB port state detection process may be performed by a general-purpose AP instead of the specific AP. Then, after the mounting of the chip is detected in the USB port Po, the processing may be transferred to the specific AP.
- FIG. 5 is a flowchart showing an example of the procedure of the authentication process I executed by the CPU of the authentication server 4.
- the authentication process I refers to an initial authentication process.
- step # 1 it is determined whether or not an authentication request signal has been received from the terminal 1 (step # 1). If the authentication request signal has not been received, this flow is exited. On the other hand, if the authentication request signal is received, the USBID is read from the packet (step # 3). Next, the USBID list in the related information storage unit 431 is searched for whether or not there is the same information as the read USBID, and the presence or absence of validity is determined (step # 5). If there is the same information in the list, it is determined that the information is valid (Y in step # 7). On the other hand, if there is no identical information, it is determined that there is no legitimacy (N in step # 7), and this flow is exited.
- the e-mail address of the mobile phone 6 corresponding to the USBID that is currently determined to be valid is extracted from the related information storage unit 431 (step # 9), and further, this USBID is supported.
- the authentication key is extracted (step # 11). Then, the extracted authentication key is transmitted to the extracted e-mail address by the portable e-mail communication processing unit 417 of the authentication server 4 (step # 13).
- the predetermined time is a time set slightly longer than the time required for the authentication key information output from the authentication server 4 in step # 13 to return via the mobile phone 6, the USB memory 2, and the terminal 1. Thus, the time is measured by a timer (not shown) in the control unit 11.
- the authentication key is acquired (from the terminal 1 that is the transmission source of the authentication key) within a predetermined time (step # 17)
- the authentication key transmitted in step # 13 is different from the authentication key received in step # 15. Are collated (step # 19).
- an authentication failure signal is returned to the terminal 1 (step # 23).
- This authentication failure signal is treated as prompting the authentication retry for the required number of times. That is, the member reconfirms that the USB memory 2 is correct, for example, by displaying an authentication failure signal on the display unit 15 of the terminal 1, and prompts the user to insert the USB port Po of the terminal 1 again.
- the required number of times can be monitored by counting the authentication failure signal with a counter (not shown) and comparing the number with a set number value.
- step # 21 if the transmitted authentication key matches the received authentication key, an authentication success signal is transmitted to the terminal 1 (step # 25), and further communication with the terminal 1 is permitted. Perform (step # 27).
- FIG. 6 is a flowchart showing an example of the procedure of the authentication process II executed by the CPU of the authentication server 4.
- the authentication process II refers to the authentication process for the second and subsequent times.
- the USBID at that time is temporarily stored in a suitable place in the RAM 43 of the authentication server 4 in association with the terminal 1 (IP address), and the specific AP is executed, so that the terminal 1 Between the authentication server 4 and the authentication server 4 (specifically, the member server 3). Then, it is determined whether or not the packet transmitted from the terminal 1 has been received based on the IP address of the terminal 1 (step # 41).
- step # 41 the USBID is read from the header of the packet (step # 43). Then, the USBID (referred to as the first USBID) used in the validity judgment at the time of the first authentication in the terminal 1 is compared with the USBID read from the current packet (step # 45). If the first USBID and the current USBID match, this flow is exited as a successful authentication. On the other hand, if the first USBID and the current USBID do not match, communication with the specific AP with the terminal 1 is blocked (step # 51), and an authentication failure signal is transmitted to the terminal 1 (step #). 53).
- the first USBID and the current USBID do not match, communication with the specific AP with the terminal 1 is blocked (step # 51), and an authentication failure signal is transmitted to the terminal 1 (step #). 53).
- step # 49 it is determined whether or not a session failure e-mail is received from the mobile phone 6 corresponding to the terminal 1 (step # 49). If no session failure e-mail has been received, this flow is exited. Conversely, if a session failure e-mail has been received, the process proceeds to step # 51.
- FIG. 7 is a flowchart showing an example of the procedure of the authentication key creation process executed by the CPU of the authentication server 4.
- the time when the authentication key is created is a period from when the USB memory 2 is removed from the terminal 1 until the next time the USB memory 2 is attached to the terminal 1 (regardless of whether it is different from the terminal 1 attached last time) and further removed. Of a certain preset time. For example, it may be when the first USBID is received from the terminal 1 by the authentication server 4 or when the USB memory 2 is removed from the terminal 1.
- step # 63 the authentication key is randomly created.
- step # 65 the created authentication key is associated with the corresponding USBID or portable e-mail address in the related information storage unit 431 and updated and stored. In this way, by changing the authentication key every time and at random like One time password, even if it is wiretapped, it can be made useless next time.
- FIG. 8 is a flowchart showing an example of the procedure of the process I executed by the CPU of the mobile phone 6.
- step T1 it is determined whether or not an authentication key has been received by e-mail from the authentication server 4 (step T1). If the authentication key has not been received, this flow is exited.
- step T3 a connection command is transmitted to the USB memory 2 having the pass key prior to the session with the USB memory 2 (step T3). That is, the mobile phone 6 stores the e-mail address of the authentication server 4 and automatically receives a predetermined information from the e-mail address, that is, the authentication key information here, for the session. Transition to connection command transmission processing. Instead of automatically shifting to the session, instruction information for instructing the operation of starting the session by short-range communication may be transmitted to the holder of the mobile phone 6.
- the pairing process is a session pre-process, and is a process of associating the mobile phone 6 and the USB memory 2 having a corresponding relationship with each other with predetermined information, for example, a passkey.
- connection it is determined whether or not the connection is successful (step T5). If the connection is successful, a session is performed. For example, by using a GAP (Generic Access Profile) that is a profile for connecting / authenticating / encrypting a device, connection is performed using information of a passkey. When the connection is established, data transfer is performed using FTP (File Transfer Profile) which is a profile for performing data transfer.
- GAP Generic Access Profile
- FTP File Transfer Profile
- step T7 session processing is started as described above, and an authentication key is first transmitted to the USB memory 2 of the pairing destination (step T7). Subsequently, it is determined whether or not a response signal has been received from the USB memory 2 (step T9). If it has been received, a given time within a predetermined time (for example, about ten seconds to one minute) is received. It is determined whether or not (time) has elapsed (step T11). When a certain time has elapsed, a response request signal is transmitted (step T13), and then it is determined whether or not a response signal is received from the USB memory 2 (step T15).
- a predetermined time for example, about ten seconds to one minute
- step T17 whether or not the USB memory 2 has been removed from the terminal 1 is determined, for example, based on whether or not a signal indicating that the USB memory 2 has been removed has been received. If the USB memory 2 has been removed from the terminal 1, this flow ends. On the other hand, if the USB memory 2 is not removed from the terminal 1, the process returns to step T11.
- a session failure signal indicating a connection failure at the start of the session or a disconnection during the session is transmitted to the authentication server 4 by e-mail (step T19).
- FIG. 9 is a flowchart showing an example of the procedure of the USB process I executed by the CPU of the terminal 1. Note that the USB processing I and the USB processing II described later may be executed in such a manner that the CPU is built in the USB memory 2 and the processing programs for the USB processing I and II are stored in the information storage unit 202.
- step Q1 it is determined whether a signal for a session, here, the connection command is received from the mobile phone 6 (step Q1). If the command has not been received, the flow exits. On the other hand, if the signal is received, a passkey is returned as a response signal (step Q3). Subsequently, it is determined whether or not an authentication key has been received (step Q5). If no authentication key has been received, the process exits this flow. On the other hand, if the authentication key is received, the received authentication key is sent to the terminal 1 (step Q7).
- step Q11 it is determined whether or not the USB memory 2 has been removed from the terminal 1 (step Q13). If it has not been removed, the process returns to step Q9 to determine whether or not a response request signal has been received. In this way, the session is continued until the USB memory 2 is removed from the terminal 1.
- FIG. 10 is a flowchart illustrating an example of the procedure of the USB processing II executed by the CPU of the terminal 1.
- FIG. 11 is a flowchart showing an example of the procedure of the process II executed by the CPU of the mobile phone 6.
- step T31 it is determined whether an authentication failure signal has been received from the USB memory 2 (step T31). If the authentication failure signal is not received, the process exits this flow. On the other hand, if an authentication failure signal is received, a command for disconnecting near field communication with the USB memory 2 is issued (step T33). By this disconnection command, short-range communication between the mobile phone 6 that is the session partner and the USB memory 2 is blocked.
- the specific application software stored in the specific AP storage unit 132 is stored in the member server 3 or the like and downloaded from the member server 3 and installed.
- the specific AP installed in the terminal 1 can be executed by dividing the general-purpose AP.
- the USB memory 2 may be configured to include a secondary battery for power supply inside, or may be operated by receiving power supply from the power supply of the terminal 1 while being attached (connected) to the terminal 1.
- the authentication server 4 transmits an authentication failure signal to the terminal and prohibits the operation of the specific AP of the terminal 1 when the authentication server 4 determines that the authentication has failed in the comparison of the authentication keys.
- the authentication server 4 may prohibit transmission / reception of packets with the terminal 1 by an authentication failure signal.
- the authentication server 4 determines that the USBID received from the terminal 1 is valid (step # 7), the authentication server 4 transmits the authentication key to the corresponding mobile phone 6 by e-mail (step). # 13)
- a required application service is provided between a mobile phone 6 compatible with i-mode (registered trademark) and a predetermined server (authentication server 4) on a network (information transmission system) such as i-appli (registered trademark).
- the application program to be performed is downloaded in advance from the authentication server 4 or another predetermined site (or downloaded as necessary), and predetermined information is exchanged.
- the program for executing the application service uses the standby function to transmit an authentication key transmission request signal to the authentication server 4 at a predetermined period of, for example, several seconds to several tens of seconds.
- the authentication key transmitted from the authentication server 4 is received (assuming that the USBID has been received).
- the authentication server 4 includes an information transmission / reception unit capable of handling i- ⁇ ppli (registered trademark) services.
- the information transmission / reception unit receives an authentication key transmission request signal from the mobile phone 6, the information transmission / reception unit transmits an authentication key to the electronic address of the mobile phone 6 in response thereto.
- the storage unit 431 stores each information of USBID / electronic address / authentication key of the mobile phone 6 in association with each other. Further, the authentication server 4 may determine the validity of the electronic address of the mobile phone 6 that is the transmission source of the authentication key transmission request signal by checking the USBID of the storage content of the storage unit 431. Good.
- the following procedure may be performed.
- the holder of the USB memory 2 performs a startup operation of the mobile phone 6 to a predetermined i- ⁇ ppli (registered trademark) mode (when always in this mode state, No startup operation is required).
- the authentication server 4 determines that the USBID has been received, and then performs the above-described verification for the validity determination. If it is valid, the authentication server 4 sends the authentication key in response to the authentication key transmission request signal. Transmit to mobile phone 6.
- the authentication server 4 transmits the authentication key once (subject to normal reception).
- the mobile phone 6 may sleep in this mode to save power.
- the authentication key transmission / reception process is not limited to an electronic mail, but can be performed using another application service according to a mobile phone company.
- the present invention provides a personal authentication system that authenticates the presence or absence of a legitimate owner of a portable storage medium that is permitted to execute predetermined information processing by being attached to an information processing terminal connected to the network.
- the portable storage medium includes an identification information storage unit for storing identification information, and a radio base station possessed by the rightful owner.
- a first short-range communication unit that performs short-range communication with a portable communication terminal capable of transmitting and receiving information via an information transmission system, wherein the authentication server includes identification information of the portable storage medium
- a related information storage unit in which electronic address information of the portable communication terminal possessed by the rightful owner of the portable storage medium and unique authentication key information are stored.
- the physical terminal detects the attachment of the portable storage medium, acquires the identification information, and transmits an authentication request processing means for transmitting a signal including the acquired identification information to the authentication server; and a signal including the identification information
- the authentication key relay processing means for transmitting the acquired authentication key information to the authentication server
- the authentication server reads authentication key information and electronic address information corresponding to the identification information included in the received signal including the identification information from the related information storage unit, and reads the read authentication key information.
- An authentication key information processing means for transmitting to an electronic address; and after the transmission of the authentication key information to the electronic address, through the information processing terminal Upon reception of the authentication key information preferably comprises a first determining means for determining difference between the authentication key and the authentication key information transmitted by the information processing means.
- the authentication key information is transferred from the authentication server to the portable communication terminal, for example, by e-mail.
- the authentication key transmitted by e-mail or the like is transmitted from the portable communication terminal to the portable storage medium by short-range communication, so that the terminal user can use his portable storage medium and his portable communication terminal. Both of them are possessed, and even if the portable storage medium is stolen, an illegal slipping operation of the personal authentication process is reliably prevented systematically.
- the authentication server includes an identification information coincidence determining unit that determines a match between the identification information included in the received signal including the identification information and the identification information stored in the related information storage unit in advance. preferable. According to this configuration, since the legitimacy of the portable storage medium is determined, authentication for the portable storage medium can be ensured.
- the authentication server includes a determination result processing unit that transmits the determination result to an information processing terminal that is a transmission source of the authentication key information.
- the information processing terminal also handles the response to the authentication failure, for example, the transmission of information to the authentication server. It is possible to take measures such as prohibiting processing.
- the information processing terminal includes a mounting monitoring unit that monitors a mounting state of the portable storage medium and stops communication with the authentication server when non-mounting is detected. According to this configuration, it is necessary to continuously mount the portable storage medium on the information processing terminal and clear the monitoring of the mounting state while performing predetermined information processing on the information processing terminal. Unauthorized use can be made difficult as compared with the case where it is only necessary to wear it at the time.
- the information processing terminal is in a state in which the predetermined information processing can be executed while the portable storage medium is attached, and the authentication server receives the identification from the information processing terminal. Whether or not the signal including the information is received for the first time is monitored. In the second and subsequent times, whether or not the identification information included in the signal including the identification information matches the identification information received for the first time. It is preferable to include second determination means for determining According to this configuration, when the first person authentication succeeds, only the identification information needs to be checked after the second authentication. Therefore, the authentication key information is sent to the e-mail, the portable communication terminal every time the authentication operation is performed. Therefore, it is possible to save the trouble of passing through a portable storage medium and reduce the chance of eavesdropping.
- an authentication key information creating unit that creates different authentication key information for each transmission of the authentication key information by the authentication key information processing unit is provided. According to this configuration, even if the authentication key information is eavesdropped, it becomes useless information when the information processing terminal is used next time, so that theft can be prevented.
- the authentication key information creating means randomly creates the authentication key information. According to this configuration, since the changed information cannot be predicted from the authentication key information that has been wiretapped, the authentication key information is highly reliable.
- the portable communication terminal is a mobile phone that transmits and receives the information to and from the radio base station through electromagnetic waves. According to this configuration, since the mobile phone is a tool possessed by many persons, the present invention can be made highly versatile.
- the first short-range communication unit includes a wireless communication device that uses electromagnetic waves as a medium.
- a wireless communication device that uses electromagnetic waves as a medium.
- operations such as adjusting the orientation in order to match the transmitting / receiving surface of the mobile phone are not required as compared with a mode using light.
- the portable communication terminal used in the personal authentication system according to any one of claims 1 to 8, wherein the second short-range communication is performed with the first short-range communication unit.
- a short-distance communication control means for transmitting the received authentication key information from the second short-range communication unit to the first short-range communication unit when receiving the authentication key information from the authentication server; It is preferable to provide. According to this configuration, since the portable communication terminal includes the second short-range communication unit and transmits the authentication key to the portable storage medium, the personal authentication process can be performed even if the portable storage medium is stolen. Unauthorized slip-through processing is reliably prevented.
- the short-range communication control means stores in advance a pass key for specifying a corresponding portable storage medium, and uses the pass key to store the authentication key information received from the authentication server in the corresponding portable storage medium. It is preferable to transmit to the first near field communication unit of the medium. According to this configuration, even if there are a plurality of portable storage media in the vicinity, the authentication key is transmitted to only one specified portable storage medium, so that high confidentiality can be maintained.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Telephonic Communication Services (AREA)
- Information Transfer Between Computers (AREA)
Abstract
Description
11 制御部
111 USB通信処理部
112 装着検出部(装着監視手段)
113 USBID取得部
114 認証要求処理部(認証要求処理手段)
115 認証キー取得部(認証キー中継処理手段、回数監視手段)
116 認証結果処理部
117 プログラム実行処理部
118 ネットワーク通信処理部
132 特定AP記憶部
2 USBメモリ(携行型記憶媒体)
201 USBID記憶部(識別情報記憶部)
202 情報記憶部
203 近距離通信処理部(第1の近距離通信部)
21 近距離通信送受波部(第1の近距離通信部)
3 会員サーバ
4 認証サーバ
41 制御部
411 パケット監視部
412 USB正当性判定部(識別情報一致判定手段)
413 第1認証処理部(第1の判定手段、判定結果処理手段)
414 第2認証処理部(第2の判定手段、判定結果処理手段)
415 認証キー作成部(認証キー情報作成手段)
416 ネットワーク通信処理部
417 携帯電子メール通信処理部(認証キー情報処理手段)
431 USBID/携帯電子メールアドレス/認証キー記憶部(関連情報記憶部)
5 電子メールシステム(情報伝送系)
6 携帯電話機(携行型通信端末)
61 制御部
611 近距離通信処理部(近距離通信制御手段)
612 USB接続状態監視部(近接通信監視手段)
613 認証キー取得部
614 携帯電子メール通信処理部
615 タイマ
63 RAM(アドレス記憶部)
66 近距離通信送受波部(第2の近距離通信部)
7 ネットワーク
Claims (13)
- ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証システムにおいて、
前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、
前記携行型記憶媒体は、
識別情報を記憶する識別情報記憶部と、
前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末との間で近距離通信を行う第1の近距離通信部とを備え、
前記認証サーバは、
前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶された関連情報記憶部を備え、
前記情報処理端末は、
前記携行型記憶媒体の装着を検出して前記識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信する認証要求処理手段と、
前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信する認証キー中継処理手段とを備え、
前記認証サーバは、
受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信する認証キー情報処理手段と、
前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定する第1の判定手段とを備えたことを特徴とする本人認証システム。 - 前記認証サーバは、受信した前記識別情報を含む信号に含まれる前記識別情報と前記関連情報記憶部に予め記憶されている識別情報との一致を判定する識別情報一致判定手段を備えたことを特徴とする請求項1記載の本人認証システム。
- 前記認証サーバは、前記判定の結果を前記認証キー情報の送信元の情報処理端末に送信する判定結果処理手段を備えたことを特徴とする請求項1又は2に記載の本人認証システム。
- 前記情報処理端末は、前記携行型記憶媒体の装着状態を監視し、非装着が検知されると、前記認証サーバとの通信を中止する装着監視手段を備えたことを特徴とする請求項1~3のいずれかに記載の本人認証システム。
- 前記情報処理端末は、前記携行型記憶媒体が装着されている間、前記所定の情報処理が実行可能な状態にされるものであり、
前記認証サーバは、
前記情報処理端末からの前記識別情報を含む信号の受信が初回か否かを監視し、前記2回目以降の場合、前記識別情報を含む信号に含まれる前記識別情報が1回目に受信された前記識別情報と一致するか否かを判断する第2の判定手段を備えたことを特徴とする請求項1~4のいずれかに記載の本人認証システム。 - 前記認証キー情報処理手段による前記認証キー情報の送信毎に異なる認証キー情報を作成する認証キー情報作成手段を備えたことを特徴とする請求項1~5のいずれかに記載の本人認証システム。
- 認証キー情報作成手段は、無作為に前記認証キー情報を作成することを特徴とする請求項6に記載の本人認証システム。
- 前記携行型通信端末は、前記無線基地局との間で電磁波を媒介として前記情報の送受信を行う携帯電話機であることを特徴とする請求項1~7のいずれかに記載の本人認証システム。
- 前記第1の近距離通信部は、電磁波を媒介とした無線通信装置を備えたものであることを特徴とする請求項8に記載の本人認証システム。
- 請求項1~9のいずれかに記載の本人認証システムに用いられる前記携帯型通信端末であって、前記第1の近距離通信部との間で近距離通信を行う第2の近距離通信部と、
前記認証サーバから前記認証キー情報を受信すると、該受信した認証キー情報を前記第2の近距離通信部から前記第1の近距離通信部へ送信する近距離通信制御手段とを備えることを特徴とする携帯型通信端末。 - 前記近距離通信制御手段は、対応する携行型記憶媒体を特定するパスキーが予め記憶されており、前記パスキーを用いて、前記認証サーバから受信した前記認証キー情報を前記対応する携行型記憶媒体の第1の近距離通信部へ送信するものであることを特徴とする請求項10に記載の携帯型通信端末。
- 前記認証サーバの電子的なアドレスを記憶するアドレス記憶部と、
前記第1の近距離通信部との間での近距離通信の状態を監視し、近距離通信が途絶えた場合、その旨の情報を前記認証サーバの電子的なアドレスに送信する近接通信監視手段とを備えたことを特徴とする請求項10又は11に記載の携帯型通信端末。 - ネットワークに接続された情報処理端末に装着することで所定の情報処理の実行を許可する携行型記憶媒体の正当所有者の有無を認証する本人認証方法において、
前記ネットワークに接続され、前記正当所有者か否かを認証する認証サーバを備え、
前記認証サーバの関連情報記憶部には、前記携行型記憶媒体の識別情報に対応付けて、前記携行型記憶媒体の正当所有者の所持する前記携行型通信端末の電子的なアドレス情報、及び固有の認証キー情報が記憶され、
前記情報処理端末の認証要求処理手段が、前記携行型記憶媒体の装着を検出して、前記携行型記憶媒体に記憶されている識別情報を取得し、取得した前記識別情報を含む信号を前記認証サーバに送信し、
前記認証サーバの認証キー情報処理手段が、受信した前記識別情報を含む信号に含まれる前記識別情報に対応する認証キー情報及び電子的なアドレス情報を前記関連情報記憶部から読み出し、読み出した前記認証キー情報を読み出した前記電子的なアドレスに送信し、
前記携行型記憶媒体の近距離通信部が、前記正当所有者の所持する、無線基地局を有する情報伝送系を経由して情報の送受信が可能な携行型通信端末を介して前記認証キー情報を取得し、
前記情報処理端末の認証キー中継処理手段が、前記識別情報を含む信号の送信後、前記携行型通信端末及び前記携行型記憶媒体を介して前記認証サーバから認証キー情報を取得すると、取得した前記認証キー情報を前記認証サーバに送信し、
前記認証サーバの判定手段が、前記認証キー情報の前記電子的なアドレスへの送信後、前記情報処理端末を介して前記認証キー情報を受信すると、前記認証キー情報処理手段によって送信された前記認証キー情報との異同を判定することを特徴とする本人認証方法。
Priority Applications (6)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020127018923A KR20120099782A (ko) | 2009-12-22 | 2009-12-22 | 본인 인증 방법, 본인 인증 시스템 및 휴대형 통신단말기 |
| PCT/JP2009/071277 WO2011077512A1 (ja) | 2009-12-22 | 2009-12-22 | 本人認証方法、本人認証システム及び携行型通信端末 |
| JP2011547128A JPWO2011077512A1 (ja) | 2009-12-22 | 2009-12-22 | 本人認証方法、本人認証システム及び携行型通信端末 |
| US13/516,044 US20120254955A1 (en) | 2009-12-22 | 2009-12-22 | Personal authentication method, personal authentication system, and portable-type communication terminal |
| CN2009801631145A CN102667798A (zh) | 2009-12-22 | 2009-12-22 | 本人认证方法、本人认证系统和便携式通信终端 |
| EP09852529A EP2518659A1 (en) | 2009-12-22 | 2009-12-22 | User authentication method, user authentication system, and portable communications terminal |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2009/071277 WO2011077512A1 (ja) | 2009-12-22 | 2009-12-22 | 本人認証方法、本人認証システム及び携行型通信端末 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2011077512A1 true WO2011077512A1 (ja) | 2011-06-30 |
Family
ID=44195075
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2009/071277 Ceased WO2011077512A1 (ja) | 2009-12-22 | 2009-12-22 | 本人認証方法、本人認証システム及び携行型通信端末 |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US20120254955A1 (ja) |
| EP (1) | EP2518659A1 (ja) |
| JP (1) | JPWO2011077512A1 (ja) |
| KR (1) | KR20120099782A (ja) |
| CN (1) | CN102667798A (ja) |
| WO (1) | WO2011077512A1 (ja) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2014191671A (ja) * | 2013-03-28 | 2014-10-06 | Mitsubishi Space Software Co Ltd | セキュリティ記憶媒体、ファイル管理システムおよびファイル管理方法 |
| JPWO2015068452A1 (ja) * | 2013-11-06 | 2017-03-09 | 株式会社村田製作所 | 無線通信システム及びワンタイムパスワードの生成、認証方法 |
| JP2019194863A (ja) * | 2014-04-16 | 2019-11-07 | ジェイエーエムエフ・ソフトウェア・エルエルシー | 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること |
| JP2024544644A (ja) * | 2021-11-30 | 2024-12-03 | 北京博衍思創信息科技有限公司 | Usbデバイスアクセス制御の方法、装置及び電子機器 |
Families Citing this family (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8626921B2 (en) * | 2010-04-22 | 2014-01-07 | Cisco Technology, Inc. | Device and service management based on layer 2 through layer 7 device attributes |
| US20120102324A1 (en) * | 2010-10-21 | 2012-04-26 | Mr. Lazaro Rodriguez | Remote verification of user presence and identity |
| JP5817766B2 (ja) * | 2013-03-21 | 2015-11-18 | 富士ゼロックス株式会社 | 情報処理装置、通信システム及びプログラム |
| CN103490902B (zh) * | 2013-10-11 | 2017-11-24 | 北京握奇智能科技有限公司 | 一种实现用户身份认证的方法和装置 |
| CN109040099B (zh) | 2013-10-30 | 2021-06-22 | 创新先进技术有限公司 | 一种针对应用的验证方法、终端和系统 |
| CN106169055A (zh) * | 2015-05-21 | 2016-11-30 | 秦皇岛鸿大科技开发有限公司 | 基于指静脉识别的蓝牙移动存储器 |
| CN110113153B (zh) * | 2019-04-23 | 2022-05-13 | 深圳数字电视国家工程实验室股份有限公司 | 一种nfc密钥更新方法、终端及系统 |
| JP7227086B2 (ja) * | 2019-06-21 | 2023-02-21 | ファナック株式会社 | 正当性確認機器 |
| JP7276235B2 (ja) * | 2020-04-20 | 2023-05-18 | トヨタ自動車株式会社 | 認証システム |
| WO2022003796A1 (ja) * | 2020-06-29 | 2022-01-06 | 日本電気株式会社 | 情報処理システム、情報処理方法及びプログラム |
| US11561917B2 (en) * | 2020-09-23 | 2023-01-24 | Hewlett Packard Enterprise Development Lp | USB connection management |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001306806A (ja) * | 2000-04-19 | 2001-11-02 | Nec Corp | カードの不正使用防止方法及びシステム並びに記録媒体 |
| JP2006268682A (ja) * | 2005-03-25 | 2006-10-05 | Fujitsu Ltd | 認証システム、その制御方法、情報処理システムおよび携帯型認証装置 |
| JP2008033571A (ja) | 2006-07-27 | 2008-02-14 | Mieko Tsuyusaki | ネットシステム |
| JP2008250923A (ja) * | 2007-03-30 | 2008-10-16 | Ntt Docomo Inc | 認証処理システム、移動通信端末、及び認証処理方法 |
| JP2009104248A (ja) | 2007-10-19 | 2009-05-14 | Dainippon Printing Co Ltd | 認証情報入力モジュール |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| ATE339742T1 (de) * | 2003-11-07 | 2006-10-15 | Cit Alcatel | Verfahren zur unterstützung bargeldloser zahlung |
| US8045961B2 (en) * | 2009-06-22 | 2011-10-25 | Mourad Ben Ayed | Systems for wireless authentication based on bluetooth proximity |
-
2009
- 2009-12-22 EP EP09852529A patent/EP2518659A1/en not_active Withdrawn
- 2009-12-22 US US13/516,044 patent/US20120254955A1/en not_active Abandoned
- 2009-12-22 JP JP2011547128A patent/JPWO2011077512A1/ja not_active Ceased
- 2009-12-22 WO PCT/JP2009/071277 patent/WO2011077512A1/ja not_active Ceased
- 2009-12-22 KR KR1020127018923A patent/KR20120099782A/ko not_active Abandoned
- 2009-12-22 CN CN2009801631145A patent/CN102667798A/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001306806A (ja) * | 2000-04-19 | 2001-11-02 | Nec Corp | カードの不正使用防止方法及びシステム並びに記録媒体 |
| JP2006268682A (ja) * | 2005-03-25 | 2006-10-05 | Fujitsu Ltd | 認証システム、その制御方法、情報処理システムおよび携帯型認証装置 |
| JP2008033571A (ja) | 2006-07-27 | 2008-02-14 | Mieko Tsuyusaki | ネットシステム |
| JP2008250923A (ja) * | 2007-03-30 | 2008-10-16 | Ntt Docomo Inc | 認証処理システム、移動通信端末、及び認証処理方法 |
| JP2009104248A (ja) | 2007-10-19 | 2009-05-14 | Dainippon Printing Co Ltd | 認証情報入力モジュール |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2014191671A (ja) * | 2013-03-28 | 2014-10-06 | Mitsubishi Space Software Co Ltd | セキュリティ記憶媒体、ファイル管理システムおよびファイル管理方法 |
| JPWO2015068452A1 (ja) * | 2013-11-06 | 2017-03-09 | 株式会社村田製作所 | 無線通信システム及びワンタイムパスワードの生成、認証方法 |
| JP2019194863A (ja) * | 2014-04-16 | 2019-11-07 | ジェイエーエムエフ・ソフトウェア・エルエルシー | 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること |
| JP2021145365A (ja) * | 2014-04-16 | 2021-09-24 | ジェイエーエムエフ・ソフトウェア・エルエルシー | 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること |
| JP7238015B2 (ja) | 2014-04-16 | 2023-03-13 | ジェイエーエムエフ・ソフトウェア・エルエルシー | 他のモバイル装置での集中を制限して動作を行なうためにモバイル装置を使用すること |
| JP2024544644A (ja) * | 2021-11-30 | 2024-12-03 | 北京博衍思創信息科技有限公司 | Usbデバイスアクセス制御の方法、装置及び電子機器 |
| JP7787612B2 (ja) | 2021-11-30 | 2025-12-17 | 北京博衍思創信息科技有限公司 | Usbデバイスアクセス制御の方法、装置及び電子機器 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20120254955A1 (en) | 2012-10-04 |
| KR20120099782A (ko) | 2012-09-11 |
| JPWO2011077512A1 (ja) | 2013-05-02 |
| EP2518659A1 (en) | 2012-10-31 |
| CN102667798A (zh) | 2012-09-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JPWO2011077512A1 (ja) | 本人認証方法、本人認証システム及び携行型通信端末 | |
| US11706212B2 (en) | Method for securing electronic transactions | |
| CN106991317B (zh) | 安全验证方法、平台、装置和系统 | |
| EP3312750B1 (en) | Information processing device, information processing system, and information processing method | |
| EP3271885B1 (en) | Multi-device transaction verification | |
| CN110232568B (zh) | 移动支付方法、装置、计算机设备及可读存储介质 | |
| US20240403863A1 (en) | Multi-device authentication process and system utilizing cryptographic techniques | |
| US20150333911A1 (en) | Id system and program, and id method | |
| US20110197267A1 (en) | Secure authentication system and method | |
| US7357329B2 (en) | IC card, terminal device, and data communication method | |
| KR20180108713A (ko) | 이동 단말 p2p에 기초한 신용 지불 방법 및 장치 | |
| WO2011048645A1 (ja) | 端末管理システム及び端末管理方法 | |
| WO2015161699A1 (zh) | 数据安全交互方法和系统 | |
| WO2001082151A1 (fr) | Dispositif externe et systeme d'authentification | |
| WO2015161690A1 (zh) | 数据安全交互方法和系统 | |
| JP2004220402A (ja) | Eコマース認証システムおよび方法 | |
| KR101212510B1 (ko) | 위치기반의 서비스 보안 시스템 및 그 방법 | |
| JPH10198636A (ja) | 個人認証システムおよび個人認証方法 | |
| CN114253414B (zh) | 用于非接触式pin输入的系统和方法 | |
| KR20070029537A (ko) | 무선단말기와 연동한 개인별고유코드를 활용한인증시스템과 그 방법 | |
| KR20010067759A (ko) | 일회용식별코드를 이용한 통합개인인증 방법 | |
| KR101700833B1 (ko) | 카드 사용자 인증 시스템 및 그를 위한 인증서버와 휴대단말기 | |
| EP4250210B1 (en) | Devices, methods and a system for secure electronic payment transactions | |
| EP4250208B1 (en) | Devices, methods and a system for secure electronic payment transactions | |
| KR20130005635A (ko) | 보안 모바일 결제 시스템 및 그 제공방법 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 200980163114.5 Country of ref document: CN |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 09852529 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2011547128 Country of ref document: JP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 13516044 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2009852529 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 20127018923 Country of ref document: KR Kind code of ref document: A |