Authentication systems, mobile devices, and authentication devices
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- DENSO WAVE INC
- Filing Date
- 2024-12-12
- Publication Date
- 2026-06-24
AI Technical Summary
【0012】 (1)本開示の一形態によれば、携帯端末の認証システムが提供される。この認証システムは、前記携帯端末の認証を行う1以上の認証装置と、前記携帯端末に含まれるペア端末と、を備え、前記ペア端末は、前記1以上の認証装置のうちのいずれかの認証装置による認証実績があり、前記1以上の認証装置と通信できる端末通信部と、端末制御部と、備え、前記端末制御部は、前記1以上の認証装置による認証に必要な認証アプリケーションソフトを備え、前記認証アプリケーションソフトは、フォアグラウンド動作およびバックグラウンド動作を含む複数の動作状態で動作し、情報を格納できる第1パケットであって前記動作状態を表す態様で送信される第1パケットを前記端末通信部により、前記認証装置に送信し、前記認証装置は、前記端末通信部と通信できる装置通信部と、装置制御部と、を備え、前記装置制御部は、前記第1パケットを受信した場合において受信した第1パケットが表す動作状態に基づいて、フォアグラウンド認証処理または前記フォアグラウンド認証処理とは異なるバックグラウンド認証処理により、前記ペア端末を認証する。 認証アプリケーションソフトの動作状態は、ペア端末の認証処理に影響する場合がある。これにより、認証装置は、動作状態に応じて異なる認証処理を求められる場合がある。しかし、本開示の認証システムは、動作状態に応じて、異なる認証処理により認証実績のあるペア端末を認証できる。すなわち、本開示の認証システムは、ペア端末の認証について、認証実績のない携帯端末を認証するときよりも柔軟に対応できる。よって、本開示の認証システムは、認証の動作状態の影響により認証装置がペア端末を認証できない場合でも、異なる認証処理によりペア端末を認証できる可能性がある。 (2)上記形態の認証システムであって、前記受信した第1パケットは、フォアグラウンド動作中に送信されるフォアグラウンド第1パケットおよびバックグラウンド動作中に送信されるバックグラウンド第1パケットのいずれかであり、前記認証アプリケーションソフトは、前記フォアグラウンド第1パケットおよび前記バックグラウンド第1パケットの少なくとも一方に、前記第1パケットを送信する際の動作状態を表す識別情報を格納でき、前記装置制御部は、前記第1パケットを受信した場合において前記受信した第1パケットに前記フォアグラウンド動作を表す識別情報が含まれる場合、または、前記受信した第1パケットに前記バックグラウンド動作を表す識別情報が含まれない場合、前記フォアグラウンド認証処理を実行し、前記受信した第1パケットに前記バックグラウンド動作を表す識別情報が含まれる場合、または、前記受信した第1パケットに前記フォアグラウンド動作を表す識別情報が含まれない場合、前記バックグラウンド認証処理を実行してもよい。 このような態様とすることで、本開示の認証システムは、識別情報を第1パケットに格納することにより、容易に動作状態を表す第1パケットを実現できる。 (3)上記形態の認証システムであって、前記認証アプリケーションソフトは、経時変化するワンタイムパスワード情報を生成でき、前記フォアグラウンド動作中において、前記第1パケットの機能を制限せず、前記バックグラウンド動作中において、前記第1パケットの機能を制限し、不特定の対象と通信できる第1通信方式と、特定の対象と通信できる第2通信方式であって前記特定の対象との接続処理が必要である第2通信方式と、のいずれかの通信方式を選択して、前記端末通信部を介して通信でき、前記第1通信方式により通信する場合に、生成した前記ワンタイムパスワード情報を格納した前記第1パケットを送信し、前記第2通信方式により通信する場合に、新たに前記ワンタイムパスワード情報を、前記第1パケットとは異なる第2パケットに格納して、前記認証装置との接続中に送信し、前記バックグラウンド認証処理は、前記接続処理を実行して前記第2パケットを受信した場合、受信した第2パケットに格納された前記ワンタイムパスワード情報に基づいて、前記ペア端末を認証し、前記フォアグラウンド認証処理は、受信したフォアグラウンド第1パケットに格納された前記ワンタイムパスワード情報に基づいて、前記ペア端末を認証してもよい。 このような態様においては、バックグラウンド動作中に更新されたワンタイムパスワード情報が、第1パケットに格納されない可能性がある。しかし、本開示の認証システムは、第2パケットを受信することにより、機能を制限されない第2パケットからワンタイムパスワード情報を受信する。よって、本開示の認証システム、第1パケットに格納されたワンタイムパスワード情報が更新されないことによって、認証装置がペア端末を認証できなくなることを防止できる。 (4)上記形態の認証システムであって、前記認証装置は、初回の前記携帯端末の認証を第1種認証処理により行い、2回目以降を第2種認証処理により行うことができ、前記第1種認証処理は、前記第2通信方式が用いられ、前記第2種認証処理よりもセキュリティ性が高く、前記第2種認証処理は、前記フォアグラウンド認証処理と前記バックグラウンド認証処理を含み、前記第1種認証処理よりも処理の時間が短く、前記装置制御部は、前記第2種認証処理により前記ペア端末の認証が不可能な場合、前記第1種認証処理を実行し、前記第2種認証処理により前記ペア端末の認証が可能な場合、前記第1種認証処理を実行しなくてもよい。 このような態様とすることで、本開示の認証システムは、ペア端末の2回目以降の認証処理を短縮できる。さらに、本開示の認証システムは、第2種認証処理のみでペア端末を認証する態様よりもペア端末をより確実に認証できる。 (5)上記形態の認証システムであって、前記識別情報は、複数の前記動作状態を表す1文字が組み合わされた文字列でもよい。 このような態様とすることで、本開示の認証システムは、識別情報が1文字の態様に比べて、第1パケットに他の情報が格納される場合でも、識別情報が第1パケットから除外されることを防ぐことができる。すなわち、本開示の認証システムは、認証処理をより確実に実行できる。 本開示は、認証システム以外の種々の形態で実現することも可能である。例えば、携帯端末や認証装置の形態で実現することができる。
Smart Images

Figure 2026103135000001_ABST
Abstract
Claims
1. A mobile device authentication system, The system comprises one or more authentication devices for authenticating the mobile terminal, and a paired terminal included in the mobile terminal, The paired terminal has a history of authentication by one or more of the authentication devices, and comprises a terminal communication unit capable of communicating with one or more of the authentication devices, and a terminal control unit, The terminal control unit is equipped with authentication application software necessary for authentication by the one or more authentication devices. The aforementioned authentication application software is It operates in multiple operating states, including foreground and background operation. The terminal communication unit transmits a first packet, which is capable of storing information and is transmitted in a manner that represents the operating state, to the authentication device. The authentication device comprises a device communication unit capable of communicating with the terminal communication unit, and a device control unit. When the device control unit receives the first packet, An authentication system that authenticates the paired terminals based on the operational state represented by the first received packet, using either a foreground authentication process or a background authentication process different from the foreground authentication process.
2. The authentication system according to claim 1, The received first packet is either a foreground first packet transmitted during foreground operation or a background first packet transmitted during background operation. The aforementioned authentication application software is At least one of the foreground first packet and the background first packet can store identification information representing the operational state when the first packet is transmitted. When the device control unit receives the first packet, If the received first packet contains identification information representing the foreground operation, or if the received first packet does not contain identification information representing the background operation, the foreground authentication process is executed. An authentication system that performs the background authentication process if the received first packet contains identification information representing the background operation, or if the received first packet does not contain identification information representing the foreground operation.
3. The authentication system according to claim 2, The aforementioned authentication application software is It can generate one-time password information that changes over time. During the aforementioned foreground operation, the functionality of the first packet is not restricted. During the background operation, the functionality of the first packet is restricted. A first communication method that can communicate with an unspecified target, and a second communication method that can communicate with a specific target, which requires connection processing with the specific target, can be selected and used to communicate via the terminal communication unit. When communicating using the first communication method, the first packet containing the generated one-time password information is transmitted. When communicating using the second communication method described above, the one-time password information is newly stored in a second packet different from the first packet and transmitted during the connection with the authentication device. When the background authentication process executes the connection process and receives the second packet, it authenticates the paired terminal based on the one-time password information stored in the received second packet. The foreground authentication process is an authentication system that authenticates the paired terminal based on the one-time password information stored in the received foreground first packet.
4. The authentication system according to claim 3, The authentication device can perform the initial authentication of the mobile terminal using a first-type authentication process, and subsequent authentications using a second-type authentication process. The aforementioned first type authentication process uses the aforementioned second communication method and has higher security than the aforementioned second type authentication process. The aforementioned Type 2 authentication process includes the foreground authentication process and the background authentication process, and has a shorter processing time than the aforementioned Type 1 authentication process. The device control unit, If authentication of the paired terminal is not possible by the second type authentication process, the first type authentication process is executed. An authentication system that does not perform the first type authentication process if the paired terminal can be authenticated by the second type authentication process.
5. The authentication system according to claim 4, The authentication system wherein the identification information is a string of characters formed by combining multiple single characters representing the aforementioned operating states.
6. It is a mobile device, A terminal communication unit capable of communicating with one or more authentication devices, a terminal control unit, and a terminal communication unit are provided. Each of the one or more authentication devices comprises a device communication unit capable of authenticating one or more mobile terminals and communicating with the terminal communication unit, and a device control unit. The aforementioned mobile terminal has a history of authentication by one or more of the aforementioned authentication devices. The terminal control unit is equipped with authentication application software necessary for authentication by the one or more authentication devices. The aforementioned authentication application software is It operates in multiple operating states, including foreground and background operation. The terminal communication unit transmits a first packet, which is capable of storing information and is transmitted in a manner that represents the operating state, to the authentication device. When the device control unit receives the first packet, A mobile terminal that, based on the operating state represented by the received first packet, is authenticated by the device control unit through foreground authentication processing or background authentication processing different from the foreground authentication processing.
7. A mobile terminal according to claim 6, The received first packet is either a foreground first packet transmitted during foreground operation or a background first packet transmitted during background operation. The aforementioned authentication application software is At least one of the foreground first packet and the background first packet can store identification information representing the operational state when the first packet is transmitted. When the device control unit receives the first packet, The device control unit, if the received first packet contains identification information representing the foreground operation, or if the received first packet does not contain identification information representing the background operation, causes the foreground authentication process to be executed. A mobile terminal that, when the device control unit contains identification information representing the background operation in the received first packet, or when the received first packet does not contain identification information representing the foreground operation, causes the device control unit to execute the background authentication process.
8. A mobile terminal according to claim 7, The aforementioned authentication application software is It can generate one-time password information that changes over time. During the aforementioned foreground operation, the functionality of the first packet is not restricted. During the background operation, the functionality of the first packet is restricted. A first communication method that can communicate with an unspecified target, and a second communication method that can communicate with a specific target, which requires connection processing with the specific target, can be selected and used to communicate via the terminal communication unit. When communicating using the first communication method, the first packet containing the generated one-time password information is transmitted. When communicating using the second communication method described above, the one-time password information is newly stored in a second packet different from the first packet and transmitted during the connection with the authentication device. When the background authentication process executes the connection process and receives the second packet, it authenticates the mobile terminal based on the one-time password information stored in the received second packet. The foreground authentication process authenticates the mobile terminal based on the one-time password information stored in the received foreground first packet.
9. A mobile terminal according to claim 8, The authentication device can perform the initial authentication of the mobile terminal using a first-type authentication process, and subsequent authentications using a second-type authentication process. The aforementioned first type authentication process uses the aforementioned second communication method and has higher security than the aforementioned second type authentication process. The aforementioned Type 2 authentication process includes the foreground authentication process and the background authentication process, and has a shorter processing time than the aforementioned Type 1 authentication process. The authentication application software is controlled by the device control unit. If authentication of the mobile device is not possible through the Type 2 authentication process, the Type 1 authentication process is executed. A mobile device that, if authentication of the mobile device is possible through the Type 2 authentication process, does not allow the Type 1 authentication process to be executed.
10. A mobile terminal according to claim 9, The aforementioned identification information is a string of characters formed by combining multiple single characters representing the aforementioned operating states, in a mobile terminal.
11. An authentication device for authenticating mobile devices, It comprises a device communication unit capable of communicating with a terminal communication unit, and a device control unit, and has a track record of authentication of paired terminals included in the aforementioned mobile terminal. The paired terminal comprises a terminal communication unit capable of communicating with the authentication device, and a terminal control unit, The terminal control unit includes authentication application software necessary for authentication by one or more authentication devices. The aforementioned authentication application software is It operates in multiple operating states, including foreground and background operation. The terminal communication unit transmits a first packet, which is capable of storing information and is transmitted in a manner that represents the operating state, to the authentication device. When the device control unit receives the first packet, An authentication device that authenticates the paired terminals based on the operating state represented by the first received packet, by foreground authentication processing or background authentication processing different from the foreground authentication processing.
12. The authentication device according to claim 11, The received first packet is either a foreground first packet transmitted during foreground operation or a background first packet transmitted during background operation. The aforementioned authentication application software is At least one of the foreground first packet and the background first packet can store identification information representing the operational state when the first packet is transmitted. When the device control unit receives the first packet, If the received first packet contains identification information representing the foreground operation, or if the received first packet does not contain identification information representing the background operation, the foreground authentication process is executed. An authentication device that performs the background authentication process if the received first packet contains identification information representing the background operation, or if the received first packet does not contain identification information representing the foreground operation.
13. The authentication device according to claim 12, The aforementioned authentication application software is It can generate one-time password information that changes over time. During the aforementioned foreground operation, the functionality of the first packet is not restricted. During the background operation, the functionality of the first packet is restricted. A first communication method that can communicate with an unspecified target, and a second communication method that can communicate with a specific target, which requires connection processing with the specific target, can be selected and used to communicate via the terminal communication unit. When communicating using the first communication method, the first packet containing the generated one-time password information is transmitted. When communicating using the second communication method described above, the one-time password information is newly stored in a second packet different from the first packet and transmitted during the connection with the authentication device. When the background authentication process executes the connection process and receives the second packet, it authenticates the paired terminal based on the one-time password information stored in the received second packet. The foreground authentication process is an authentication device that authenticates the paired terminal based on the one-time password information stored in the received foreground first packet.
14. The authentication device according to claim 13, The initial authentication of the aforementioned mobile device can be performed using a Type 1 authentication process, and subsequent authentications can be performed using a Type 2 authentication process. The aforementioned first type authentication process uses the aforementioned second communication method and has higher security than the aforementioned second type authentication process. The aforementioned Type 2 authentication process includes the foreground authentication process and the background authentication process, and has a shorter processing time than the aforementioned Type 1 authentication process. The device control unit, If authentication of the paired terminal is not possible by the second type authentication process, the first type authentication process is executed. An authentication device that does not perform the first type authentication process if the paired terminal can be authenticated by the second type authentication process.
15. The authentication device according to claim 14, The authentication device is an authentication device in which the identification information is a string of characters formed by combining multiple single characters representing the aforementioned operating states.
Citation Information
Patent Citations
Authentication system
JP2020014149A