User authentication system and portable terminal
By generating and verifying different authentication codes between the portable terminal and the authentication device, and combining it with biometric authentication, the problem of portable terminal authentication information being intercepted and eavesdropped is solved, and user authentication with higher security is achieved.
Patent Information
- Application Number
- CN201880065786.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-01-16
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2038-01-16
AI Technical Summary
In the prior art, when using an auxiliary authentication device of a portable terminal, authentication information is transmitted via wireless communication, which poses a security risk of being intercepted and eavesdropped, resulting in insufficient authentication security.
An authentication code generation and verification mechanism is adopted between the main device and the authentication device. A different authentication code is generated each time authentication is performed. Authentication is achieved through the authentication code sending request and reply components. Combined with biometric authentication, the security of authentication is improved.
By generating different authentication codes and biometric information authentication each time, the security of portable terminal user authentication is improved, illegal users are prevented from using it, and the confidentiality and reliability of authentication are enhanced.
Smart Images

Figure CN111194446B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a user authentication technology in an information processing device such as a portable terminal, and more particularly to a user authentication technology implemented using an auxiliary authentication device. Background Art
[0002] Among the security protection technologies for restricting the use of information processing devices such as portable terminals by others, there is a technology that uses an auxiliary authentication device other than the portable terminal. For example, Patent Document 1 discloses the following content: "A portable terminal device performs wireless communication between it and other wireless communication devices, which includes a storage unit, a wireless communication unit, and a control unit, the storage unit being used to store identification information of a specific wireless communication device registered in advance, and the wireless communication unit being used to receive signals sent from other wireless communication devices. The control unit obtains identification information contained in the signal received by the wireless communication unit, and when the identification information matches the identification information stored in the storage unit, enables a specific function of the portable terminal device (selected from the abstract)."
[0003] Prior art literature
[0004] Patent Literature
[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2005-130008 Summary of the Invention
[0006] Technical problem to be solved by the invention
[0007] The technology disclosed in Patent Document 1 prevents portable terminal devices from being used by anyone who does not possess a specific wireless communication device, without requiring complex operations. However, the information used for authentication, such as the identification information of the specific wireless communication device, is transmitted and received wirelessly. Patent Document 1 does not address issues such as interception and eavesdropping of this information.
[0008] The present invention has been made in view of the above-mentioned situation, and an object of the present invention is to provide a technology capable of improving security when performing user authentication of a portable terminal using a supplementary authentication device.
[0009] Technical means to solve the problem
[0010] The present invention provides a user authentication system, comprising a main device and an authentication device capable of communicating with the main device, for authenticating the user of the main device, and is characterized in that the main device comprises: an authentication code sending request unit, which generates an authentication code sending request containing a first value and sends it to the authentication device, wherein the first value is selected for each sending; a verification unit, which determines that the authentication is successful when the authentication code sent from the authentication device in response to the authentication code sending request is contained in the verification authentication code generated based on the first value; and a release unit, which enables a predetermined function when the verification unit determines that the authentication is successful, and the authentication device comprises an authentication code reply unit, which generates the authentication code based on the first value contained in the authentication code sending request and replies it to the main device.
[0011] Effects of the Invention
[0012] The present invention can improve the security of user authentication of a portable terminal using an auxiliary authentication device. Other technical problems, features, and effects than those described above will become clear through the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is an overall diagram of the user authentication system according to the first embodiment.
[0014] Figure 2 This is a hardware configuration diagram of the main device of the first embodiment.
[0015] Figure 3 This is a functional block diagram of the main device of the first embodiment.
[0016] Figure 4 (a) is a hardware configuration diagram of the authentication device according to the first embodiment, and (b) is a functional block diagram of the authentication device according to the first embodiment.
[0017] Figure 5 This is a flowchart of the user authentication process in the first embodiment.
[0018] Figure 6 (a) is an explanatory diagram for explaining an example of original authentication information according to the first embodiment, (b) is an explanatory diagram for explaining an example of an authentication code transmission request according to the first embodiment, and (c) is an explanatory diagram for explaining an example of an authentication code according to the first embodiment.
[0019] Figure 7 (a) is a hardware configuration diagram of the authentication device according to the second embodiment, and (b) is a functional block diagram of the authentication device according to the second embodiment.
[0020] Figure 8This is a flowchart of the user authentication process according to the second embodiment.
[0021] Figure 9 (a) is an explanatory diagram for illustrating an example of original authentication information of the second embodiment, (b) is an explanatory diagram for illustrating an example of an authentication code sending request of the second embodiment, and (c) and (d) are explanatory diagrams for illustrating an example of an authentication code of the second embodiment.
[0022] Figure 10 This is a functional block diagram of a main device according to the third embodiment.
[0023] Figure 11 (a) is a hardware configuration diagram of the authentication device according to the third embodiment, and (b) is a functional block diagram of the authentication device according to the third embodiment.
[0024] Figure 12 This is a flowchart of the user authentication process according to the third embodiment.
[0025] Figure 13 (a) is an explanatory diagram for explaining an example of the behavior history of the third embodiment, and (b) is an explanatory diagram for explaining an example of the normal behavior range of the modification of the third embodiment.
[0026] Figure 14 This is a flowchart of the action history collection process and authentication process of a modified example of the third embodiment.
[0027] Figure 15 (a) is a functional block diagram of a main device of the fourth embodiment, and (b) is a functional block diagram of an authentication device of the fourth embodiment.
[0028] Figure 16 (a) is a flowchart of the initial setting process of the fourth embodiment, and (b) is a flowchart of a modified example of the initial setting process of the fourth embodiment.
[0029] Figure 17 This is an explanatory diagram for explaining an example of a variable-output wireless communicator according to a modification of the fourth embodiment.
[0030] Figure 18 This is a flowchart of a user authentication process according to a modified example of the present invention.
[0031] Figure 19 This is a flowchart of a user authentication process according to another modified example of the present invention. DETAILED DESCRIPTION
[0032] The embodiments of the present invention will be described below with reference to the accompanying drawings. In this specification, unless otherwise specified, the same reference numerals are used for components having the same functions, and repeated descriptions are omitted.
[0033] First Implementation Method
[0034] First, an overview of a first embodiment of the present invention will be described. Figure 1 This is a diagram for explaining the outline of the user authentication system 100 according to the present embodiment.
[0035] The user authentication system 100 includes a main device 200 and an authentication device 300. The authentication device 300 is an auxiliary authentication device used to authenticate the user of the main device 200. That is, in this embodiment, specific functions of the main device 200 can only be used by the user holding the authentication device 300.
[0036] Typically, when using an authentication device 300 as such a supplementary authentication device, the authentication code is transmitted and received between it and the main device 200 via wireless communication. This communication is not secure. Therefore, if the authentication code is intercepted, even someone without the authentication device 300 can access the functions of the main device 200. To avoid this problem, this embodiment changes the authentication code sent from the authentication device 300 to the main device 200 each time, enhancing the confidentiality of the authentication code and improving the security of transmission and reception.
[0037] Next, the user authentication system 100 of the present embodiment that realizes the above-mentioned processing will be described.
[0038] [Main equipment]
[0039] First, let's describe the main device 200. The main device 200 is an information processing device with wireless communication and information processing capabilities. Examples include mobile phones, smartphones, tablets, wearable devices such as watches and head-mounted displays, feature phones, and other portable digital devices.
[0040] Figure 2 2 shows the hardware structure of the main device 200. As shown in the figure, the main device 200 includes a CPU (Central Processing Unit) 201, a system bus 202, a storage device 210, a communication processor 220, an expansion I / F 227, an operator 230, a video processor 240, an audio processor 250, and a sensor 260.
[0041] The CPU 201 is a microprocessor unit that controls the entire main device 200. The system bus 202 is a data communication path for transmitting and receiving data between the CPU 201 and each operation module in the main device 200.
[0042] The storage device 210 includes a ROM (Read Only Memory) 211 , a RAM (Random Access Memory) 212 , and a storage unit 213 .
[0043] The ROM 211 is a memory that stores basic operating programs such as an operating system and other operating programs. For example, an erasable ROM such as an EEPROM (Electrically Erasable and Programmable Read Only Memory) or a flash ROM is used as the ROM 211 .
[0044] The storage unit 213 is used to store the operation program and operation setting values of the main device 200, and various programs and various data required to realize each function of this embodiment.
[0045] The storage unit 213 can retain stored information even when no external power is supplied to the main device 200. Therefore, the storage unit 213 uses a flash ROM, an SSD (Solid State Drive), or an HDD (Hard Disk Drive), for example.
[0046] RAM 212 is a work area when the basic operation program and other operation programs are executed.
[0047] ROM211 and RAM212 can also be integrated with CPU201. In addition, ROM211 can also be used without Figure 2 Instead of the independent structure shown in FIG, a part of the storage area in the storage unit 213 is used. In other words, all or part of the functions of the ROM 211 can be replaced by a part of the area in the storage unit 213.
[0048] Each operating program stored in the ROM 211 or the storage unit 213 can be updated and its function expanded by, for example, executing a download process from each distribution server on the network.
[0049] The communication processor 220 includes a LAN (Local Area Network) communicator 221 , a telephone network communicator 222 , a wired communicator 223 , a short-range wireless communicator 224 , and a wireless communicator 225 .
[0050] The LAN communicator 221 is connected to a network via an access point (AP) device using a wireless connection based on Wi-Fi (registered trademark) or the like, and transmits and receives data with other devices on the network.
[0051] The telephone network communicator 222 performs calls and data transmission and reception through wireless communication with a base station of a mobile phone communication network.
[0052] The wired communicator 223 transmits and receives data with other devices near the main device 200 via a wired connection method such as USB (Universal Serial Bus).
[0053] The NFC device 224 transmits and receives data via wireless communication with other devices equipped with NFC devices. For example, the NFC device 224 is an interface for near-field communication (NFC), enabling bidirectional communication between devices equipped with NFC chips over extremely short distances ranging from a few centimeters to approximately one meter. This supports services such as electronic money installed in the main device 200 that utilize a contactless IC chip.
[0054] The wireless communicator 225 transmits and receives data with other devices equipped with wireless communicators via wireless communication. For example, Bluetooth (registered trademark) enables simple information exchange between information devices located several to several tens of meters apart using radio waves.
[0055] LAN communicator 221, telephone network communicator 222, wired communicator 223, short-range wireless communicator 224, and wireless communicator 225 each include an encoding circuit, a decoding circuit, an antenna, etc. In addition, communication processor 220 may further include a communicator for infrared communication or other communicators.
[0056] The expansion I / F 227 is an interface group for expanding the functionality of the main device 200. In this embodiment, it includes a video / audio I / F, an operation device I / F, and a memory I / F. The video / audio I / F is used to input video / audio signals from an external video / audio output device and output video / audio signals to an external video / audio input device. External operation devices such as a keyboard are connected via the operation device I / F. The memory I / F is used to connect to a memory card and other storage media for data transmission and reception.
[0057] The operator 230 is used to input operating instructions to the main device 200. In this embodiment, it includes a touch panel configured to be superimposed on the display 241 and an operating key composed of an arrangement of push button switches. Alternatively, only one of them may be used. In addition, the main device 200 can be operated using a keyboard connected to the expansion I / F 227. The main device 200 can also be operated using another portable information terminal device connected via wired or wireless communication. In addition, the touch panel function can also be provided by the display 241.
[0058] The video processor 240 includes a display 241 , an image signal processor 242 , and a camera 243 .
[0059] The display 241 is a display device such as a liquid crystal panel, and displays image data processed by the image signal processor 242 and provides it to the user of the main device 200. The image signal processor 242 includes a graphic RAM (not shown) and drives the display 241 based on the image data input to the graphic RAM. The image signal processor 242 performs format conversion, menu overlay processing, and other OSD (On-Screen Display) signal overlay processing as needed. The camera 243 is a photographic device that uses electronic devices such as CCD (Charge-Coupled Device) and CMOS (Complementary Metal Oxide Semiconductor) sensors to convert light input through the lens into electrical signals to capture image data of the surrounding environment and the target object.
[0060] The audio processor 250 includes a speaker 251, a sound signal processor 252, and a microphone 253. The speaker 251 provides a sound signal processed by the sound signal processor 252 to a user of the main device 200. The microphone 253 converts the user's voice or the like into sound data input.
[0061] The sensor 260 is a sensor group for detecting the status of the main device 200. In this embodiment, for example, it includes a GPS (Global Positioning System) receiver 261, a gyro sensor 262, a geomagnetic sensor 263, an acceleration sensor 264, an illumination sensor 265, a proximity sensor 266, and a biometric information sensor 267.
[0062] These sensor groups can detect the main device 200's position, tilt, orientation, movement, ambient brightness, and user biometric information. Furthermore, the main device 200 may include other sensors, such as pressure sensors like an air pressure sensor. Furthermore, location information is acquired by the GPS receiver 261. In locations where GPS waves are difficult to reach, the LAN communicator 221 can also utilize the location information of Wi-Fi access points. Similarly, the telephone network communicator 222 can utilize base station location information and transmission delays in telephone network communication waves to acquire location information. Furthermore, not all of these sensor groups need to be present.
[0063] Figure 2The structure example of the main device 200 shown includes a large number of structures that are not necessary for this embodiment, and even if these structures are not provided, the effect of this embodiment will not be impaired. In addition, it can further include structures such as digital transceiver functions and electronic money settlement functions that are not shown.
[0064] [Functional structure of the main device]
[0065] use Figure 3 The following describes functions that can be implemented by the main device 200. As described above, the main device 200 of this embodiment requests user authentication from the authentication device when a user attempts to execute a predetermined function, and enables the execution of the function if the authentication is successful.
[0066] To achieve this, the main device 200 includes an authentication code transmission request generation unit 271 , a verification unit 272 , an unlocking unit 273 , a transceiver unit 274 , and an action control unit 275 .
[0067] These functions are realized by CPU 201 loading the program stored in ROM 211 into RAM 212 and executing it as execution program 291. Figure 3 Functions implemented by programs stored in the ROM 211 are shown.
[0068] The storage unit 213 (main storage unit) stores original authentication information 281, an authentication code generation algorithm 282, and a transmission request generation algorithm 283 as reference information 280. This data is pre-stored in the storage unit 213. While executing the aforementioned functions, the CPU 201 stores this data in the temporary storage area 292 of the RAM 212 for use. The temporary storage area of the RAM 212 also stores data generated during the execution of the programs stored in the ROM 211, as well as data obtained from executing the programs.
[0069] The transceiver 274 controls data transmission and reception between the communication processor 220 or the expansion I / F 227 and an external device via, for example, a USB I / F.
[0070] The authentication code transmission request generation unit 271 generates an authentication code transmission request for requesting the authentication device 300 to transmit an authentication code. This authentication code transmission request is generated, for example, when an instruction to execute a function that requires authentication before execution (authentication-required function) is received. This authentication code transmission request is generated based on the transmission request generation algorithm 283. In this case, a different authentication code is generated for each request.
[0071] The generated authentication code transmission request is transmitted to the authentication device 300 via the transceiver 274. That is, the authentication code transmission request generating unit 271 and the transceiver 274 function as an authentication code transmission request unit.
[0072] Verification unit 272 verifies the legitimacy of the authentication code sent back from authentication device 300 in response to the authentication code transmission request. In this embodiment, a verification authentication code is generated using the authentication code transmission request, source authentication information 281, and authentication code generation algorithm 282. The generated verification authentication code is then compared (verified) with the returned authentication code to determine its legitimacy. For example, if the authentication code sent from authentication device 300 matches the verification authentication code, authentication is considered successful.
[0073] When the verification unit 272 determines that the authentication code is valid, the unlocking unit 273 enables (enables) the authentication-required function.
[0074] The operation control unit 275 controls each unit of the main device 200 to implement the authentication-required function permitted by the unlocking unit 273 , and also functions as a receiving unit that receives (accepts) various instructions from the operator 230 .
[0075] [Hardware structure of authentication equipment]
[0076] Next, the authentication device 300 will be described. The authentication device 300 is held by a user who is allowed to operate the main device 200, and generates and returns an authentication code in response to a request from the main device 200.
[0077] Figure 4 (a) shows the hardware structure of the authentication device 300 that realizes this function. As shown in the figure, the authentication device 300 includes a CPU 301, a system bus 302, a storage device 310, and a communication processor 320.
[0078] The CPU 301 is a microprocessor unit that controls the entire operation of the authentication device 300. The system bus 302 is a data communication path for transmitting and receiving data between the CPU 301 and each operation module in the authentication device 300.
[0079] The storage device 310 includes a ROM 311 , a RAM 312 , and a storage unit 313 , which have substantially the same functions and structures as the components of the same names in the main device 200 .
[0080] The communication processor 320 includes a wired communicator 323, a short-range wireless communicator 324, and a wireless communicator 325. These also have substantially the same functions and structures as the components of the same name in the main device 200.
[0081] The authentication device 300 may also include other structures similar to those of the main device 200. For example, it may further include an expansion I / F 227. In addition, it may also include the entire hardware structure of the main device 200.
[0082] [Functional structure of authentication equipment]
[0083] Next, use Figure 4 (b) illustrates the functions implemented by the authentication device 300. As described above, the authentication device 300 of this embodiment responds to a request from the main device 200 and returns an authentication code.
[0084] To achieve this, the authentication device 300 includes an authentication code generation unit 371 and a transceiver unit 372. These functions are realized by the CPU 301 loading a program stored in the ROM 311 into the RAM 312 as an execution program 391 and executing the program.
[0085] The storage unit 313 (authentication storage unit) includes original authentication information 281 and an authentication code generation algorithm 282 as reference information 380. These data are copies of the data with the same name that the main device 200 has.
[0086] When executing the above functions, CPU 301 stores these data in temporary storage area 392 of RAM 312 for use. The temporary storage area of RAM 312 also stores the following data, namely, the programs stored in ROM 311, data generated during program execution, and data obtained by executing the programs.
[0087] The transceiver 372 controls data transmission and reception with an external device via the communication processor 320 .
[0088] The authentication code generation unit 371 generates an authentication code upon receiving an authentication code transmission request from the main device 200 via the transceiver unit 372. The authentication code is generated using the information included in the authentication code transmission request, the original authentication information 281, and the authentication code generation algorithm 282. The generation method is the same as the method used by the verification unit 272 of the main device 200 to generate the verification authentication code.
[0089] The generated authentication code is returned to the main device 200 via the transceiver 372. That is, the authentication code generating unit 371 and the transceiver 372 function as an authentication code returning unit.
[0090] [User Authentication Process Flow]
[0091] Next, the flow of the user authentication process in this embodiment will be described. Figure 5 This is the process flow of the user authentication process in this embodiment. For example, this process is started upon receiving an instruction to execute the above-mentioned authentication-required function.
[0092] First, the transceiver 274 of the main device 200 transmits a communication start request to the authentication device 300 (step S1101 ).
[0093] Upon receiving the communication start request (steps S1201 and S1202 ), the transceiver 372 of the authentication device 300 performs a communication establishment process with the requesting device (main device 200 ) (steps S1203 and S1102 ).
[0094] Communication may be established, for example, by continuously performing polling from the authentication device 300 to detect the main device 200 entering a predetermined range and establish two-way communication.
[0095] On the authentication device 300 side, the standby state is maintained until the communication is established (step S1204). On the other hand, on the main device 200 side, if the communication start request is sent but the communication is not established (step S1103), if it is within the specified time, it returns to step S1101 and sends the communication start request again.
[0096] On the other hand, if the predetermined time has passed, it is considered as a timeout (step S1104), and the verification unit 272 determines that the authentication has failed. In this case, the verification unit 272 sets the authentication failure flag (step S1105) and ends the process.
[0097] When bidirectional communication is established (steps S1204 and S1103), first, the authentication code transmission request generation unit 271 of the main device 200 generates an authentication code transmission request (step S1110) and transmits it to the authentication device 300 (step S1111).
[0098] On the authentication device 300 side, when the transceiver 372 receives the authentication code transmission request (step S1205), the authentication code generation unit 371 generates an authentication code (step S1206). Then, the transceiver 372 sends the generated authentication code to the main device 200 (step S1207).
[0099] When the transceiver 274 of the main device 200 receives the authentication code (step S1112), the verification unit 272 determines its legitimacy (step S1113). As described above, the verification unit 272 determines whether the authentication code matches the pre-generated verification authentication code. If they match, the verification unit 272 determines that the authentication is successful, sets the authentication success flag (step S1114), and ends the process.
[0100] On the other hand, if they do not match, the checking unit 272 determines that the authentication has failed and moves to step S1105.
[0101] The authentication failure flag and the authentication success flag are stored in the temporary storage area 292 respectively.
[0102] Furthermore, when the user authentication process is completed and the authentication success flag is set, the unlocking unit 273 unlocks the function requiring authentication for which the execution instruction has been received, making it available for use. Specifically, the unlocking unit 273 accepts the user's instruction for the function (enables the user's instruction to be received).
[0103] In the user authentication process of this embodiment, data transmission and reception between the main device 200 and the authentication device 300 is performed by wireless communication between the wireless communicators 225 and 325, for example.
[0104] Next, the authentication code transmission request generation process of step S1110 and the authentication code generation process of step S1206 are described.
[0105] First, the authentication source information 281, the authentication code generation algorithm 282, and the transmission request generation algorithm 283 used at this time will be described.
[0106] In this embodiment, the original authentication information 281 stores a first value and a second value, which is different from the first value, in association with each other. When the first value is specified, the second value, which is registered in association with the first value, is returned. In this case, a different first value is specified each time an authentication code is requested. This results in a different authentication code being returned each time.
[0107] Figure 6 Figure (a) is an example of source authentication information 281 in this embodiment. As shown in the figure, source authentication information 281 includes an address 281a as a first value and a code 281b as a second value associated with each address 281a. In this embodiment, the address 281a is specified in the authentication code transmission request. The code 281b registered and associated with the specified address 281a is then used as the authentication code.
[0108] In this embodiment, the main device 200 is as follows Figure 6 As shown in (b) of FIG. 2 , one or more addresses 281a are sent as authentication code transmission request 285. The authentication device 300 is as follows. Figure 6 As shown in (c), the corresponding code 281b is generated as the authentication code 286.
[0109] The sending request generation algorithm 283 is used to define the method (rules) for generating the information to be sent as the authentication code sending request 285. In this embodiment, it defines how to determine the address 281a of the original authentication information 281 included in the authentication code sending request 285. For example, the value of the last digit of the moment indicated by the clock when the authentication code sending request is generated is used, or a random number generated by a random number generator or the like is used. The random number generator can be set in the main device 200. In addition, in the case of Figure 6 As shown in (b), when the authentication code transmission request 285 includes a plurality of addresses 281a, the order thereof may be determined at the same time.
[0110] The transmission request generation algorithm 283 is not limited to the above description. It is sufficient to set a different address 281a or a different group of addresses 281a each time an authentication code transmission request is generated. In addition, the transmission request generation algorithm 283 can also be arbitrarily set and changed by the user.
[0111] The authentication code transmission request generation unit 271 determines the address 281a of the authentication source information 281 according to the transmission request generation algorithm 283. Then, the authentication code transmission request 285 is generated using the determined address 281a. Furthermore, the information of the determined address 281a is output to the verification unit 272.
[0112] The authentication code generation algorithm 282 defines a method (rule) for generating the authentication code 286. In this embodiment, a process is registered for extracting a code registered in the authentication source information 281 in association with the address 281a included in the authentication code transmission request 285 and generating the code as the authentication code.
[0113] The authentication code generation unit 371 extracts the code associated with the address 281 a included in the authentication code transmission request 285 from the original authentication information 281 according to the authentication code generation algorithm 282 , and generates the code as an authentication code 286 .
[0114] For example, when using Figure 6 In the case of the original authentication information 281 shown in (a), the authentication code sending request 285 is as follows: Figure 6 As shown in (b), 2, 5, 7, and 9 are specified as addresses 281a. In this case, the following is generated and replied: Figure 6 The authentication code 286 includes 8, f, g, and 2 as shown in (c).
[0115] As described above, the user authentication system 100 of this embodiment includes a main device 200 and an authentication device 300. The main device 200 includes: an authentication code transmission request unit that generates an authentication code transmission request including a predetermined first value and transmits the request to the authentication device 300; a verification unit 272 that generates a verification authentication code based on the first value included in the authentication code transmission request and determines that authentication is successful if the authentication code transmitted from the authentication device 300 in response to the authentication code transmission request is included in the generated verification authentication code; and an unlocking unit 273 that enables a predetermined function if the verification unit 272 determines that authentication is successful. The authentication device 300 generates an authentication code based on the first value included in the authentication code transmission request and sends the generated authentication code back to the main device 200.
[0116] At this time, the main device 200 and the authentication device 300 share the original authentication information 281 and the authentication code generation algorithm 282. The original authentication information 281 includes multiple pairs of first values and second values associated with the first values. The authentication code generation algorithm 282 is used to generate an authentication code based on the original authentication information 281. The authentication code transmission request unit selects the first value from the original authentication information 281 according to a predetermined rule, and the authentication code response unit generates the authentication code using the second value stored in the original authentication information 281 in association with the transmitted first value.
[0117] Thus, with this embodiment, a different authentication code is returned each time an authentication code is requested. Therefore, even if the returned authentication code is intercepted or eavesdropped, it will not be used in the next authentication. Consequently, when using the auxiliary authentication device (authentication device 300) to authenticate a portable terminal (main device 200), a higher level of security can be achieved.
[0118] Modifications
[0119] The authentication code generation algorithm 282 may be a function. In this case, the authentication source information 281 may not be required. For example, the authentication code transmission request generation unit 271 includes the function's variables in the authentication code transmission request and transmits it. The variables are generated, for example, according to the transmission request generation algorithm 283.
[0120] In this case, the verification unit 272 uses the value returned by the function based on the variable as the verification authentication code. In addition, the authentication code generation unit 371 also returns the value returned by the function based on the sent variable as the authentication code 286.
[0121] Token technology, which generates a different authentication code each time a request is sent, can also be used to generate the authentication code. Token technology automatically generates different authentication codes based on, for example, the timing or number of authentication code requests. In this case, the main device 200 and the authentication device 300 share a common authentication code generation algorithm.
[0122] Each code of the original authentication information 281 is not limited to a single-character alphanumeric string, but may be a plurality of characters, a numeric string, a symbol, or the like.
[0123] By applying these modifications, the confidentiality of transmitted and received data can be further improved.
[0124] Second Implementation Method
[0125] Next, a second embodiment of the present invention will be described. In this embodiment, the authentication device further takes the result of the user authentication into consideration to generate an authentication code for reply.
[0126] The overall structure of the user authentication system 100 of this embodiment is basically the same as that of the first embodiment. The following describes this embodiment, focusing mainly on the structure that is different from the first embodiment.
[0127] In this embodiment, after communication is established between the main device 200 and the authentication device 300, similar to the first embodiment, the main device 200 sends an authentication code transmission request 285 to the authentication device 300. Upon receiving the authentication code transmission request 285, the authentication device 300 authenticates the user holding the authentication device 300, takes the success or failure of the authentication into account, and generates an authentication code 286 in response.
[0128] [Main equipment]
[0129] The hardware structure and functional modules of the main device 200 of this embodiment are the same as those of the first embodiment.
[0130] However, as will be described later, the authentication device 300 performs user authentication and reflects the authentication result in the returned authentication code 286. Therefore, in this embodiment, information that can distinguish whether the user authentication succeeded or failed is added to the authentication source information 281 and the authentication code generation algorithm 282.
[0131] Verification unit 272 generates a verification authentication code using source authentication information 281 and authentication code generation algorithm 282. Verification unit 272 generates the verification authentication code in a manner that allows for differentiation between the authentication code returned when authentication is successful and the authentication code returned when authentication fails. However, verification unit 272 may also generate only the verification authentication code associated with the authentication code returned when authentication is successful.
[0132] For example, if the verification code returned matches the verification code returned when the authentication fails, the verification unit 272 notifies the operation control unit 275 of the fact. The operation control unit 275 may then display a message on the display 241 indicating that the legitimate authentication device 300 is in the possession of an illegal holder.
[0133] [Authentication device]
[0134] The authentication device 300 of this embodiment will be described. As described above, the authentication device 300 of this embodiment performs user authentication. Therefore, the authentication device 300 of this embodiment includes functions and structures for performing user authentication.
[0135] Figure 7 (a) is a hardware configuration diagram of the authentication device 300 of this embodiment. As shown in this diagram, the authentication device 300 of this embodiment includes a biometric information sensor 367 in addition to the configuration of the authentication device 300 of the first embodiment.
[0136] Biometric sensor 367 is a sensor that collects biometric information. For example, if authentication device 300 is a wristwatch-style wearable terminal, it can be a pulse wave sensor or a heart rate sensor. Alternatively, it can be a camera, such as one that captures fingerprints, veins, or irises. Biometric sensor 367, along with biometric authentication unit 373 (described later), functions as a biometric information acquisition unit.
[0137] Figure 7 (b) is a functional block diagram of the authentication device 300 of this embodiment. As shown in this diagram, the authentication device 300 of this embodiment includes a biometric authentication unit 373 in addition to the configuration of the first embodiment. Specifically, the ROM 311 includes a program for implementing the biometric authentication unit 373.
[0138] The reference information 380 in the storage unit 313 further includes biometric information of the authorized user (holder) of the authentication device 300 as verification biometric information 383. This verification biometric information 383 is acquired in advance when the authorized holder acquires the authentication device 300. For example, in the case of a wristwatch-type terminal, the pulse wave or heart rate is acquired at a predetermined interval (e.g., 10 seconds, 1 minute, etc.) using the biometric information sensor 367 when the user first wears the device. The acquired results are then stored in the storage unit 313 as verification biometric information 383.
[0139] When the biometric authentication unit 373 of this embodiment receives the authentication code transmission request 285 via the transceiver unit 372, it acquires the biometric information of the holder at that time. The biometric information is acquired by the biometric information sensor 367. The acquired biometric information is then collated with the verification biometric information 383, and the collation result is output to the authentication code generation unit 371.
[0140] The authentication code generation unit 371 takes the verification result into consideration and generates the authentication code 286. A specific example will be described later.
[0141] Next, the flow of the user authentication process in this embodiment will be described. Figure 8 This is the process flow of the user authentication process in this embodiment. The description of the points that are the same as those in the first embodiment will be omitted.
[0142] When bidirectional communication is established (steps S1204 and S1103), the authentication code transmission request generation unit 271 of the main device 200 generates an authentication code transmission request 285 (step S1110) and sends it to the authentication device 300 (step S1111).
[0143] On the authentication device 300 side, when the transceiver unit 372 receives the authentication code transmission request 285 (step S1205), the biometric authentication unit 373 performs user authentication (step S2201). Here, biometric information is collected over a specified period of time. This biometric information is collected by the biometric information sensor 367. The acquired biometric information is then compared with the verification biometric information 383. The comparison result is then output to the authentication code generation unit 371.
[0144] The authentication code generation unit 371 generates an authentication code (step S2202), and the transceiver unit 372 transmits the generated authentication code to the main device 200 (step S1207). A specific example of the authentication code generated here will be described later.
[0145] When the transceiver unit 274 of the main device 200 receives the authentication code (step S1112), the verification unit 272 determines its legitimacy (step S1113). This embodiment also determines the consistency of the received authentication code with the pre-generated verification authentication code. If they are consistent, the verification unit 272 determines that the authentication is successful, sets the authentication success flag (step S1114), and ends the process.
[0146] On the other hand, if they do not match, the checking unit 272 determines that the authentication has failed and moves to step S1105.
[0147] When the user authentication process is completed and the authentication success flag is set, the unlocking unit 273 unlocks the authentication-required function instructed to be executed, allowing the function to be used. Specifically, the unlocking unit 273 accepts the user's instruction to execute the function.
[0148] Next, we will describe a specific example of the authentication code generated in this embodiment. First, we will describe a specific example of the authentication source information 281 prepared in this embodiment. In this embodiment, the authentication source information 281 stores, in association with a first value, a second value to be returned when the user authentication succeeds, and a third value to be returned when the user authentication fails.
[0149] Figure 9 (a) shows an example of source authentication information 281 in this embodiment. As shown in the figure, source authentication information 281 includes an address 281a as a first value, a code 1 (281b) as a second value associated (i.e., corresponding) with each address 281a, and a code 2 (281c) as a third value. The second value is used as a response when the authentication is successful, and the third value is used as a response when the authentication fails.
[0150] In this embodiment, the main device 200 also sends one or more addresses 281a as the authentication code transmission request 285. The authentication device 300 generates the corresponding code 1 (281b) or code 2 (281c) as the authentication code 286 in response, depending on whether the authentication is successful or not.
[0151] In the verification unit 272 of the main device 200 of this embodiment, as the verification authentication code, an authentication code composed of the code 1 (281b) returned when the user authentication is successful may be generated.
[0152] For example, when using Figure 9 In the case of the original authentication information 281 shown in (a), it is assumed that the authentication code sending request 285 is as follows Figure 9 As shown in (b), 2, 5, 7, and 9 are specified as addresses 281a. In this case, when biometric authentication succeeds, Figure 9 As shown in (c), the authentication code 286 containing 8, f, g, and 2 is generated and replied. On the other hand, in the case of biometric authentication failure, as shown in Figure 9 As shown in (d), an authentication code 286 including t, 4, 2, and g is generated and replied.
[0153] As described above, in addition to the configuration of the first embodiment, the present embodiment further performs biometric authentication of the holder on the authentication device 300 side, and generates an authentication code including the result of success or failure of the biometric authentication and returns it.
[0154] Therefore, with this embodiment, the main device 200 can also know whether the authentication device 300 has successfully authenticated the user. That is, based on the authentication code returned, the main device 200 can not only know whether the authentication device 300 is legitimate, but also whether it is held by a legitimate user.
[0155] Therefore, according to this embodiment, even if the authentication device 300 is legitimate, if its owner is not the legitimate owner, it is possible to detect whether the authentication device 300 is lost or stolen. Since such a judgment can be made, security can be ensured even if the authentication device 300 is lost or stolen.
[0156] As described above, according to this embodiment, it is possible to provide a user authentication system with higher security while maintaining high security in information transmission and reception.
[0157] Similar to the first embodiment, various modifications can be made to this embodiment.
[0158] Modifications
[0159] When the authentication device 300 successfully authenticates the user, a history of the authentication can be stored on the authentication device 300. As described above, in this embodiment, the authentication device 300 performs user authentication each time a request to transmit an authentication code is received. At this time, the success or failure is stored in the storage unit 313 in association with the time of the authentication.
[0160] It is also possible to configure such that, based on the returned authentication code 286, it is possible to distinguish between a case where the self-authentication has been successfully performed a predetermined number of times in succession and a case where the self-authentication has been successful only intermittently.
[0161] For example, Figure 9 As shown in (a), a fourth value (code 3 (281d)) is further stored in association with the first value as the original authentication information 281. If the authentication is continuously successful, the second value is returned, and if the authentication is only intermittently successful, the fourth value is returned.
[0162] Thus, the main device 200 can determine whether the authentication device 300 has never left the original owner's body or whether it has left the body at least once. In suspicious situations such as frequent authentication failures, for example, a PIN code can be further requested to enhance security.
[0163] Third Implementation Method
[0164] Next, a third embodiment of the present invention will be described. In this embodiment, both the main device 200 and the authentication device 300 record the user's behavior history (behavior trajectory). If the two behavior histories are consistent, the user authentication is deemed successful.
[0165] The user authentication system 100 of this embodiment has basically the same configuration as that of the first embodiment. This embodiment will be described below, focusing mainly on the configuration that differs from the first embodiment.
[0166] [Main equipment]
[0167] The hardware structure of the main device 200 of this embodiment is basically the same as that of the first embodiment. However, the functions implemented by the main device 200 are different. Figure 10 This figure shows the functional blocks of the main device 200 according to this embodiment.
[0168] As shown in the figure, the main device 200 of this embodiment, in addition to the configuration of the first embodiment, further includes a position information acquisition unit 277. Specifically, a program for implementing the position information acquisition unit 277 is stored in the ROM 211, and the CPU 201 loads the program into the RAM 212 and executes it, thereby implementing the functions of the position information acquisition unit 277.
[0169] The position information acquisition unit 277 acquires current position information, for example, via the GPS receiver 261. The acquired position information is associated with the acquisition time and stored in the storage unit 213 as an action history 284. In this embodiment, the action history 284 is used as original information for authentication.
[0170] The transmission request generation algorithm 283 of this embodiment is defined to specify a time period (period) of the action history 284 to be replied, for example. The authentication code generation algorithm 282 is defined to extract position information of the specified time period (period) from the action history 284.
[0171] Furthermore, the verification unit 272 of the main device extracts the action history (position information) for the period specified by the authentication code transmission request 285 from the action history 284 and generates an authentication code for verification.
[0172] [Authentication device]
[0173] Next, the authentication device 300 of this embodiment will be described. Figure 11 (a) is a hardware configuration diagram of the authentication device 300 of this embodiment. As shown in this diagram, the authentication device 300 of this embodiment includes a GPS receiver 361 in addition to the configuration of the first embodiment.
[0174] Figure 11 (b) is a functional block diagram of authentication device 300 according to this embodiment. As shown in this diagram, authentication device 300 according to this embodiment includes a location information acquisition unit 374 in addition to the configuration of the first embodiment. Furthermore, storage unit 313 includes an activity history 384, which registers the acquired location information in association with time.
[0175] When the authentication device 300 is powered on, the location information acquisition unit 374 calculates its own location information at predetermined time intervals based on the GPS signal received by the GPS receiver 361. The calculation result is then stored in the storage unit 313 as an activity history 384 in association with the time.
[0176] The authentication code generation unit 371 of this embodiment extracts the action history (position information) for the period specified by the authentication code transmission request 285 from the action history 384 and uses it as an authentication code.
[0177] In this embodiment, the main device 200 preferably acquires location information synchronously and at equal intervals with the authentication device 300. However, if this is difficult to achieve, the authentication code generation unit 371 determines the acquisition times closest to the start and end points of the period specified in the authentication code transmission request 285, and extracts the location information between the two acquisition times as the authentication code 286.
[0178] Alternatively, the checking unit 272 may set a predetermined tolerance range for each check, and determine that the match is within the tolerance range.
[0179] Next, the flow of the user authentication process in this embodiment will be described. Figure 12 This is the process flow of the user authentication process in this embodiment. The description of the points that are the same as those in the first embodiment will be omitted.
[0180] After bidirectional communication is established (steps S1204 and S1103), the authentication code transmission request generation unit 271 of the main device 200 generates an action history transmission request (step S3110) and transmits it to the authentication device 300 as the authentication code transmission request 285 (step S3111). Here, the period to be extracted from the stored action history 284 is specified.
[0181] When the transceiver 372 of the authentication device 300 receives the action history transmission request (step S3201), the authentication code generation unit 371 of the authentication device 300 extracts the action history (location information) for the specified period from the action history 384 stored in the storage unit 313 (step S3203) and generates the authentication code 286. The transceiver 372 then transmits the generated authentication code 286 (action history) to the main device 200 (step S3204).
[0182] When the transceiver unit 274 of the main device 200 receives the authentication code (step S3102), the verification unit 272 determines its legitimacy (step S3103). Here, the received authentication code is determined to be consistent with the pre-generated verification authentication code. In this embodiment, depending on the time when the location information was collected, the sent authentication code and the verification authentication code may not be completely consistent. Therefore, as described above, a specified allowable range can be set to determine whether they are consistent or inconsistent.
[0183] If they match, the checking unit 272 determines that the authentication is successful, sets the authentication success flag (step S1114), and ends the process.
[0184] On the other hand, if they do not match, the checking unit 272 determines that the authentication has failed and moves to step S1105.
[0185] The following shows an example of the action history 284 and 384 of this embodiment. Figure 13 1 and 2. (a) of FIG. 2 shows an example of an action history 284. As shown in FIG. 2, in the action history 284, longitude and latitude information is registered as position information 284b in association with time 284a. Figure 13 (a) shows an example in which the position information 284b is registered every one minute.
[0186] For example, when the location information for the period from 8:00 to 10:00 on November 1, 2017 is requested via the activity history transmission request, the authentication code generation unit 371 extracts the location information corresponding to that period from the activity history 384 and uses it as the authentication code 286. Furthermore, the location information used as the authentication code does not need to use all digits, taking into account accuracy.
[0187] According to this embodiment, the location information is stored as an action history in both the main device 200 and the authentication device 300. Furthermore, the action history for a predetermined period is received from the authentication device 300 as an authentication code.
[0188] In this embodiment, the authentication code sent during each authentication is also different. Therefore, as in the aforementioned embodiments, the security of authentication code transmission and reception is improved. Furthermore, this embodiment does not require the prior sharing of source authentication information between the main device 200 and the authentication device 300. Therefore, there is no need to transmit and receive data to share this source authentication information, resulting in a more secure user authentication system.
[0189] This embodiment can also be modified in various ways similar to the first embodiment.
[0190] Modifications
[0191] In this embodiment, both the main device 200 and the authentication device 300 constantly acquire location information and record it as a history of actions, but this is not the only method. For example, the execution of the authentication process can be controlled based on whether the location at the time of the specific process is within or outside the normal range of actions.
[0192] For example, on the main device 200 side, based on the actual result of successful authentication processing performed along with the specific processing, the range of its movement is determined from the collected position information.
[0193] In this modification, for example Figure 13 As shown in (b) of FIG. 1 , each time the verification unit 272 determines that authentication is successful, it stores the number of successful authentications (number of successful authentications) 284d in association with the location information 284c at the time of the authentication. The location information 284c uses the location information acquired by the location information acquisition unit 374 and stored in the activity history 284. Specifically, the location information 284c uses information specified by longitude and latitude.
[0194] Then, the checking unit 272 sets the position where the number of successful authentications 284d is greater than or equal to a predetermined number as the authentication performance position. In addition, the range determined based on the position information 284c corresponding to the authentication performance position is set as the normal action range 284e. Figure 13 In (b), for example, a location where the number of successful authentications 284d is 10 or more is considered an actual authentication location. Information about the normal range of action 284e, namely, location information 284c of the normal range of action 284e and the number of successful authentications 284d, is stored in storage unit 213 instead of action history 284. Different locations within the permissible range can be considered the same location.
[0195] The verification unit 272 determines whether the position of the main device 200 at the time of authentication is within the normal operating range 284e. If it is within the normal operating range 284e and the specific processing is not important, authentication of the authentication device 300 is omitted. If it is outside the normal operating range 284e or the specific processing is important, authentication of the authentication device 300 is performed.
[0196] Here, the important specific process refers to, for example, a settlement process such as a payment process, in which the amount is a predetermined fixed amount or more.
[0197] Furthermore, the main device 200 may store the action history 284 in the storage unit 213 in association with the process.
[0198] Furthermore, the normal action range 284e is not limited to the range determined by the certified performance position, and the normal action range 284e may be a range that is within a predetermined distance from the certified performance position.
[0199] Figure 14 The flow of action history collection and authentication processing in this variation is shown. As shown in the figure, the location information acquisition unit 277 determines whether the processing to be performed by the action control unit 275 is a specific processing (step S3301). If it is not a specific processing, the processing is executed (step S3309), and the flow ends.
[0200] On the other hand, if it is a specific process, the location information is acquired (step S3302). The action control unit 275 then further determines whether the specific process is an important process (step S3303). If it is an important process, authentication is performed (step S3305). If authentication is successful (step S3306), the verification unit 272 associates the acquired location information with the specific process and the acquisition time as an action history 284 (step S3307), and then executes the specific process (step S3309). At this time, the authentication device 300 may also store the same action history 284 (normal action range 284e).
[0201] On the other hand, when the authentication is unsuccessful (step S3306), the operation control unit 275 displays an error (step S3308) and ends the process.
[0202] If the specific processing is determined not to be important in step S3303 (step S3303), the verification unit 272 determines whether the main device 200 is located within the normal range of motion 284e (step S3304). If it is determined not to be within the normal range of motion 284e, the process proceeds to step S3305 where authentication processing is performed. On the other hand, if it is determined to be within the normal range of motion 284e, the process is executed (step S3309), and the flow ends.
[0203] For example, a specific process could be a checkout process performed at a store. With the above configuration, the location information of frequently visited stores is pre-registered. Therefore, if a checkout process is performed at a location other than the pre-registered store, the lock is not automatically released. This not only improves the security of data transmission and reception, but also ensures a higher level of security in the execution of the process.
[0204] In addition, the action history 284 of each process may be registered in association with a time period. In addition, the third embodiment may be combined with the first or second embodiment.
[0205] Furthermore, in this modified example, the authentication device 300 may store the same data as the authentication performance history (284c, 284d) as the action history 384, and request the transmission of the past authentication performance history (284c, 284d) in the authentication code transmission request. In this case, the verification unit 272 determines the legitimacy of the holder of the authentication device 300 by determining whether the authentication performance history (284c, 284d) of the authentication device 300 sent back in response to the request is identical to the authentication performance history (284c, 284d) recorded in the main device 200.
[0206] Fourth Implementation Method
[0207] Next, the fourth embodiment of the present invention will be described. Prior to the user authentication process described in the above embodiments, initial setup is required, whereby information required for user authentication, such as source authentication information, is transmitted from the main device 200 to the authentication device 300. This embodiment improves security during this initial setup.
[0208] In the first, second, and third embodiments described above, the main device 200 sets the original authentication information 281 and / or the authentication code generation algorithm 282 as initial settings and transmits them to the authentication device 300. Furthermore, whenever these are changed, they are transmitted from the main device 200 to the authentication device 300. In other words, each time the original authentication information 281 and / or the authentication code generation algorithm 282 are newly set or updated, initial settings are performed to share this information between the main device 200 and the authentication device 300.
[0209] In each of the above embodiments, the information sent from the main device 200 to the authentication device 300 during initial setting is different. Here, the first embodiment is used as a basis, and the description focuses mainly on the configuration that is different from the first embodiment.
[0210] The hardware configurations of the main device 200 and the authentication device 300 of this embodiment are basically the same as those of the first embodiment.
[0211] [Main equipment]
[0212] Figure 15 (a) shows the functional blocks of the main device 200 of this embodiment. As shown in this figure, the main device 200 of this embodiment includes an initial setting unit 278 in addition to the configuration of the first embodiment.
[0213] During initialization, the initialization unit 278 transmits the authentication source information 281 and authentication code generation algorithm 282 configured on the main device 200 to the authentication device 300. During this transmission, the initialization unit 278 does not use the usual transmission method used to transmit and receive data with the authentication device 300, but instead selects a communication method with a short reach or wired communication.
[0214] The original authentication information 281 and the authentication code generation algorithm 282 are pre-registered in the storage unit 213 by the user of the main device 200. Upon receiving an initial setting instruction from the user, the initial setting unit 278 of this embodiment selects a communication method for initial setting and performs initial setting processing.
[0215] As the communication method, the most secure communication method is selected among the communication methods that can be used for communication between the main device 200 and the authentication device 300. For example, wired communication using the wired communicator 223 is selected. In addition, in the case of wireless communication, wireless communication with the shortest reach is selected, such as wireless communication using the short-range wireless communication device 224.
[0216] The order of preference for selecting the communication method may be set in advance and stored in, for example, the storage unit 213. Alternatively, the user may designate the communicator to be used each time.
[0217] Furthermore, when wired communication is selected by the initial setting unit 278 , a message prompting the user to establish a wired connection between the main device 200 and the authentication device 300 may be displayed on the display 241 .
[0218] In addition, when the authentication device 300 is provided with a USB I / F, the USB I / F of the main device 200 and the USB I / F of the authentication device 300 can also be connected using a USB cable to perform data transmission.
[0219] Figure 15 (b) is a functional block diagram of the authentication device 300 of this embodiment. As shown in this figure, in addition to the configuration of the first embodiment, an initial setting unit 375 is included.
[0220] The initialization unit 375 performs processing when receiving the original authentication information 281 and the authentication code generation algorithm 282 from the main device 200. In this embodiment, the communication unit corresponding to the communication method set in the main device 200 is set as the receiving unit to receive information from the main device 200.
[0221] Figure 16(a) is a flowchart illustrating the initial setup process flow of this embodiment. It is assumed that at the time this process begins, the main device 200 has registered authentication source information 281 and authentication code generation algorithm 282. This process begins when the owner of the main device 200 receives an instruction to start initial setup.
[0222] First, the initialization unit 278 of the main device 200 selects a communication method (step S4101 ), and then transmits an initialization request to the authentication device 300 to request the establishment of communication using the selected communication method (step S4102 ).
[0223] When the authentication device 300 receives a communication establishment request as an initial setting request (step S4201), the initial setting unit 375 performs processing to establish communication using the requested communication method, and establishes communication using the communication method (step S4202).
[0224] When communication is established, the initial setting unit 278 performs initial setting, and transmits the original authentication information 281 and the authentication code generation algorithm 282 from the main device 200 to the authentication device 300 via the communication method (step S4103).
[0225] The initial setting unit 375 performs initial setting and stores the received authentication source information 281 and authentication code generation algorithm 282 in the storage unit 313 (step S4203). The initial setting unit 375 then notifies the initial setting unit 278 that the storage is complete, and the initial setting is terminated.
[0226] After the initial setting is completed, the initial setting unit 278 and the initial setting unit 375 each return the communication method of their own device to the communication method normally used (steps S4104 and S4204), and the processing ends.
[0227] You can also Figure 16 As shown in (b), the initial setting request is sent before communication is established in the normal communication method (steps S4301 and S4401), and the communication method is selected after communication is established (steps S4101 and S4202).
[0228] As described above, in this embodiment, during initial setup, that is, when the authentication source information 281, which serves as the basis for generating the authentication code, is shared between the main device 200 and the authentication device 300, data is transmitted and received using a communication method with a lower likelihood of leakage. This allows for a more secure user authentication system.
[0229] Modifications
[0230] In this embodiment, a communication method other than the wireless communicator 225 used in the user authentication process in the above-mentioned embodiments is selected to improve security, but the present invention is not limited to this.
[0231] For example, when the output of wireless communicator 225 is variable, the output can be made lower during initial processing than during normal circumstances such as user authentication processing.
[0232] Figure 17 FIG. 2 shows a configuration example of the output variable wireless communicator 225. The wireless communicator 225 includes a signal processor 225a, a variable resistor 225b, an outputter 225c, and an antenna 225d.
[0233] For example, during initialization, initialization unit 278 instructs wireless communicator 225 to reduce output. For example, it increases the resistance of variable resistor 225b to suppress output. Furthermore, after completing initialization, initialization unit 278 instructs wireless communicator 225 to return the resistance of variable resistor 225b to its original value.
[0234] Furthermore, according to this embodiment, after the original authentication information 281 and the authentication code generation algorithm 282 are shared, user authentication can be performed using either the first embodiment or the second embodiment.
[0235] Furthermore, during the initial processing, the authentication source information 281 and the authentication code generation algorithm 282 may be encrypted using a public key and sent from the main device 200 to the authentication device 300 .
[0236] Modifications
[0237] Furthermore, in each of the above embodiments, except for the specific processing in the modified example of the third embodiment, there is no particular limitation on the functions requiring authentication using the authentication device 300. For example, the user authentication processing in each of the above embodiments can be used for authentication when the main device 200 is unlocked, or for authentication when executing a predetermined specific application.
[0238] Modifications
[0239] For example, the main device 200 may also include multiple user authentication methods and use them together. Figure 18 This example shows the process flow for this situation. The example described here is that the screen lock is released through the first authentication process, a specific process is authenticated through the second authentication process, and a third authentication process is performed as a backup process if the second authentication process fails. The screen lock state refers to the state in which the main device 200 is in standby mode and does not accept operations other than authentication operations.
[0240] First, the action control unit 275 performs a first authentication process (step S5101). If the authentication is successful (step S5102), the unlocking unit 273 unlocks the screen of the main device 200 (step S5103). Otherwise, if the authentication fails, the process ends directly or returns to step S5101 to authenticate again.
[0241] When the screen lock is released and the user's operation instruction is received via the display 241 (step S5104), the action control unit 275 determines whether the instruction is a predetermined specific process (step S5105). If it is a specific process, the action control unit 275 performs the second authentication process (step S5106). On the other hand, if it is not a specific process, the process is directly executed (step S5108), and the process ends.
[0242] When the second authentication is successful (step S5107), the process proceeds to step S5108.
[0243] On the other hand, if the second authentication fails, the action control unit 275 displays an error message on the display 241 and prompts the user to perform a third authentication (step S5111). If the third authentication succeeds (step S5112: "Yes"), the process proceeds to step S5108 and continues. On the other hand, if the third authentication also fails (step S5112: "No"), the action control unit 275 displays an error message (step S5113) and ends the process.
[0244] In this variation, the first authentication, the second authentication, and the third authentication use different authentication methods. In this case, the user authentication based on the authentication device 300 can be used in any of the first authentication, the second authentication, and the third authentication.
[0245] For example, the first authentication may be authentication using biometric information such as fingerprints, veins, or irises, the second authentication may be authentication using the user of the authentication device 300 according to the above embodiments, and the third authentication may be authentication using a PIN code (password) input.
[0246] For example, in Figure 14 In the modified example of the third embodiment described above, if the user attempts to pay at a location other than a frequently visited store, authentication will fail, preventing the lock from being released. In such a case, as shown in this figure, by providing a third authentication method to be used in the event of a user authentication failure in the embodiment, payment can be made even at a new store simply by knowing the password. This allows for a balanced balance between convenience and security.
[0247] Furthermore, the user may be allowed to set which authentication method to use for each of the first authentication, the second authentication, and the third authentication.
[0248] Furthermore, if the main device 200 is capable of utilizing multiple authentication methods, multiple authentications may be performed in a specific process. Furthermore, the process may be performed only when all authentications performed are successful. Furthermore, the process may be performed only when at least one of the multiple authentications performed is successful.
[0249] An example of a specific process that uses multiple authentication methods and is executed only when all authentications are successful is settlement processing. Furthermore, the number of authentication methods used can be changed based on the settlement amount. Specifically, the higher the settlement amount, the greater the number of authentication methods used.
[0250] Modifications
[0251] Furthermore, it is also possible to periodically attempt to establish communication between the main device 200 and the authentication device 300. Figure 19 As shown, the action control unit 275 periodically attempts to establish communication starting from step S1101. If communication establishment fails, not only is the authentication failure flag set, but the time when communication failed to be established is also recorded (step S5201, accumulation of non-establishment time).
[0252] Even if communication is established in step S1103, the checking unit 272 checks the past period during which communication could not be established before generating the authentication code transmission request (step S5202). At this time, for example, it is determined whether there is a period during which communication could not be established for a predetermined period.
[0253] If communication cannot be established for a period exceeding the prescribed period, even if communication is established, authentication is considered to have failed, and the process moves to step S1105. On the other hand, if communication cannot be established for a period less than the prescribed time in step S5202, the user authentication process of the above-described embodiments is directly performed (step S5203).
[0254] Modifications
[0255] In the above embodiments, authentication device 300 is used as an auxiliary authentication device for main device 200, but this is not a limitation. For example, authentication device 300 may have the same functions as main device 200. Furthermore, main device 200 and authentication device 300 may also perform mutual authentication.
[0256] For example, if the two devices are a smartphone and a wearable terminal, when the smartphone performs a specific process, the smartphone functions as the main device 200, and the wearable terminal functions as the authentication device 300. Conversely, when the wearable terminal performs a specific process, the wearable terminal functions as the main device 200, and the smartphone functions as the authentication device 300.
[0257] Modifications
[0258] In the above embodiments, a case where one authentication device 300 is provided for one main device 200 is described as an example, but this is not limiting. Multiple authentication devices 300 may also be provided for one main device 200. In this case, each of the multiple authentication devices 300 has the original authentication information 281 and / or authentication code generation algorithm 282 possessed by the main device 200. Furthermore, authentication can be considered successful only if the authentication codes sent by all authentication devices 300 are identical. Alternatively, authentication can be considered successful only if the authentication codes sent by at least one authentication device 300 are identical.
[0259] The present invention is not limited to the above-described embodiments and includes various variations. For example, the above-described embodiments are described in detail to facilitate understanding of the present invention, but are not necessarily limited to including all of the described structures. A portion of the structure of a particular embodiment can be replaced with a structure of another embodiment, and a structure of another embodiment can be added to a structure of a particular embodiment. Furthermore, other structures can be added, deleted, or substituted for a portion of the structure of each embodiment.
[0260] Each of the aforementioned structures, functions, processing units, and the like may be partially or entirely implemented in hardware, for example, through integrated circuit design. Each of the aforementioned structures, functions, and the like may also be implemented in software by having a processor interpret and execute programs that implement the respective functions. Information such as programs, tables, and files that implement the respective functions may be stored in a storage device such as a memory, a hard disk, or an SSD (Solid State Drive), or in a storage medium such as an IC card, SD card, or DVD.
[0261] In addition, the control lines and information lines are marked only for the necessary parts for the description, and do not necessarily indicate all control lines and information lines on the product. In fact, it can be assumed that almost all structures are connected to each other.
[0262] Description of Reference Numerals
[0263] 100: User authentication system,
[0264] 200: Main device, 201: CPU, 202: System bus, 210: Storage device, 211: ROM, 212: RAM, 213: Storage unit, 220: Communication processor, 221: LAN communicator, 222: Telephone network communicator, 223: Wired communicator, 224: Short-range wireless communication device, 225: Wireless communication device, 225a: Signal processor, 225b: Variable resistor, 225c: Output device, 225d: Antenna, 227: Extension I / O F, 230: operator, 240: video processor, 241: display, 242: image signal processor, 243: camera, 250: audio processor, 251: speaker, 252: sound signal processor, 253: microphone, 260: sensor, 261: GPS receiver, 262: gyroscope sensor, 263: geomagnetic sensor, 264: acceleration sensor, 265: illumination sensor, 266: proximity sensor, 267: biometric information sensor,
[0265] 271: Authentication code transmission request generation unit, 272: Verification unit, 273: Unlocking unit, 274: Transceiver unit, 275: Action control unit, 277: Position information acquisition unit, 278: Initial setting unit, 280: Reference information, 281: Original information for authentication, 281a: Address, 281b: Code (1), 281c: Code 2, 281d: Code 3, 282: Authentication code generation algorithm, 283: Transmission request generation algorithm, 284: Action history, 284a: Time, 284b: Position information, 284c: Position information, 284d: Number of successful authentications, 285: Authentication code transmission request, 286: Authentication code, 291: Execution program, 292: Temporary storage area,
[0266] 300: Authentication device, 301: CPU, 302: System bus, 310: Storage device, 311: ROM, 312: RAM, 313: Storage unit, 320: Communication processor, 323: Wired communicator, 324: Short-range wireless communicator, 325: Wireless communicator, 361: GPS receiver, 367: Biometric information sensor, 371: Authentication code generation unit, 372: Transceiver unit, 373: Biometric authentication unit, 374: Location information acquisition unit, 375: Initial setting unit, 380: Reference information, 383: Biometric information for verification, 384: Action history, 391: Execution program, 392: Temporary storage area.
Claims
1. A user authentication system comprising a main device and an authentication device capable of communicating with the main device, wherein the user authentication system authenticates a user of the main device, and is characterized in that: The main device includes: an authentication code transmission request unit that generates an authentication code transmission request including a first value and transmits the request to the authentication device, wherein the first value is selected for each transmission; a verification unit that determines that the authentication is successful when the authentication code transmitted from the authentication device in response to the authentication code transmission request is included in the verification authentication code generated based on the first value; and a release unit that enables a predetermined function when the verification unit determines that the authentication is successful, The authentication device includes an authentication code reply unit, which generates the authentication code according to the first value included in the authentication code sending request and replies the authentication code to the main device. The main device also includes: A subject position information acquisition unit that acquires position information of the subject device at predetermined time intervals; and a main body storage unit storing the acquired location information of the main body device in association with the acquisition time; The authentication device further includes: an authentication location information acquisition unit that acquires location information of the authentication device at predetermined time intervals; and an authentication storage unit storing the acquired location information of the authentication device in association with the acquisition time; The authentication code transmission request unit uses a predetermined period within a period during which the subject position information acquisition unit acquires the position information of the subject device as the first value. The verification unit uses the location information of the main device stored in the main storage unit in association with the period as the action history of the main device during the period and uses it as the verification authentication code. The authentication code reply unit uses the location information of the authentication device stored in the authentication storage unit in association with the period included in the authentication code transmission request as a behavior history of the authentication device during the period as the authentication code.
2. The user authentication system according to claim 1, wherein: The authentication device further includes: a biometric information acquisition unit for acquiring biometric information of a holder holding the authentication device; and Biometric Authentication Department, The authentication storage unit further stores the biometric information acquired before authentication as verification biometric information. The biometric authentication unit acquires the biometric information in response to the authentication code transmission request, performs biometric authentication using the verification biometric information, and outputs the result to the authentication code reply unit. The authentication code reply unit generates the authentication code including a result of whether the biometric authentication is successful or not, and replies the authentication code to the main device.
3. The user authentication system according to claim 1, wherein: The main storage unit of the main device further stores the acquired location information of the main device in association with the number of successful authentications at each location determined based on the location information. When the authentication code transmission request unit receives an instruction to execute a process that satisfies a certain condition among predetermined specific processes, and when the position where the instruction is received is a position that is more than a specified distance away from the authentication performance position, the authentication code transmission request is generated, wherein the authentication performance position is a position corresponding to the following position information, which is the position information stored in the main body storage unit and is associated with the number of authentication successes that is more than a certain number of times, When the verification unit determines that the authentication is successful, the verification unit increments the number of successful authentications by 1.
4. The user authentication system according to claim 1, wherein: The predetermined function is a settlement function.
5. The user authentication system according to claim 1, wherein: The main device also includes: a first authentication section that performs a first authentication that is different from the authentication performed using the authentication device; and a receiving unit for receiving an operation instruction, The release unit enables the reception unit to receive the operation instruction when the authentication by the first authentication unit succeeds. The authentication code transmission request unit generates the authentication code transmission request when the reception unit receives the operation instruction to execute the function.
6. The user authentication system according to claim 1, wherein: The main device further includes a second authentication unit that performs a second authentication that is different from the authentication performed using the authentication device. The second authentication unit performs the second authentication if the verification unit does not determine that the authentication is successful.
7. The user authentication system according to claim 1, wherein: The main device also includes: a transceiver unit, configured to establish the communication with the authentication device; and a main body storage unit storing a non-establishment period indicating a period during which the transmitting and receiving unit cannot establish the communication; The authentication code transmission request unit does not generate the authentication code transmission request when the stored non-establishment period exceeds a predetermined period.
8. The user authentication system according to claim 1, wherein: The authentication device is a wearable terminal.
9. A portable terminal, characterized in that: include: an authentication code transmission request unit that generates an authentication code transmission request including a first value and transmits the request to the second device, wherein the first value is selected for each transmission; a verification unit that determines that the authentication is successful if the authentication code transmitted from the second device in response to the authentication code transmission request is included in the verification authentication code generated based on the first value; a release unit that enables a predetermined function when the verification unit determines that the authentication is successful; and an authentication code reply unit, which, upon receiving the authentication code sending request from the second device, generates the authentication code based on the first value included in the authentication code sending request and replies the authentication code to the second device; The portable terminal further includes: a position information acquiring unit that acquires position information of the portable terminal at predetermined time intervals; and a storage unit for storing the acquired location information of the portable terminal in association with an acquisition time; The authentication code transmission request unit uses a predetermined period within a period during which the position information acquisition unit acquires the position information of the portable terminal as the first value. The verification unit uses the position information of the portable terminal stored in the storage unit in association with the period as the behavior history of the portable terminal during the period and uses it as the verification authentication code. When the authentication code sending request is received from the second device, the authentication code generating unit uses the location information of the portable terminal stored in the storage unit in association with the period included in the authentication code sending request as the action history of the portable terminal during the period and uses it as the authentication code.
Citation Information
Patent Citations
Portable terminal device and security system
JP2005130008A
Securing a mobile computing device
CN103155528A
System for performing password management through wearable device
CN107026737A
Low power radiofrequency (RF) communication systems for secure wireless patch initialization and methods of use
US20110019824A1