A user authentication device and a storage medium
By shooting QR codes in user authentication equipment and combining biometric authentication, the problems of complex operation and insufficient security in the prior art are solved, and efficient and reliable multi-factor user authentication is achieved.
Patent Information
- Application Number
- CN202080065125.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-18
- Filing Date
- 2020-05-19
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2040-05-19
AI Technical Summary
The existing user authentication technology has problems such as complex operation and insufficient security, especially in multi-factor authentication, which is difficult to achieve efficient and reliable identity verification.
User authentication equipment is used to obtain unique identification information by shooting QR codes, and combine biometric authentication, such as face recognition or voice-print authentication, to achieve multi-factor authentication.
A simple and reliable user authentication process is realized, which improves the security and efficiency of identity authentication and reduces user burden.
Smart Images

Figure CN114402320B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a user authentication device and a storage medium. Background Art
[0002] The basic technologies adopted in user authentication can be roughly classified into the following three categories.
[0003] First, user authentication is performed by the "possession" method. User authentication by the "possession" method is a user authentication method in which a user who possesses a predetermined object item is used as an authentication subject. The predetermined object item was originally an old-fashioned key or a bank cash card in the past. Recently, it is a security token used for an IC card, a USB dongle, etc. In addition, so-called SMS (Short Message Service) authentication also corresponds to user authentication by the "possession" method, and a user who possesses a portable information terminal that receives a predetermined message is used as an authentication subject.
[0004] Second, user authentication is performed by the "knowledge" method. User authentication by the "knowledge" method is a user authentication method in which a user who memorizes predetermined information as "knowledge" is used as an authentication subject. The predetermined information was originally a secret word in the past, and now includes a so-called PIN (Personal Identification Number) code, a password, a preset secret question and its answer, etc.
[0005] Third, user authentication is performed by the "biometric" method. User authentication by the "biometric" method is a user authentication method based on checking information related to a user's "biometric characteristics", from which an individual user can be identified. Among them, the face, iris, retina, vein, fingerprint, auricle, shape of the palm, voiceprint (voice), handwriting, DNA, etc. are all used as biometric information.
[0006] NPL 1 discloses a portable telephone equipped with a two-step authentication technique. First, when a user presses a function unlock key, face recognition is performed. As a result, when the user captured by the camera is determined to be the same user as the pre-registered person, the user is required to input a PIN. When the input PIN matches the pre-registered PIN, the function is unlocked.
[0007] PTL 1 discloses a user authentication technique in which a user uses an ID card or inputs ID information related to himself / herself explicitly through a keyboard, and then takes a picture of the user's face instead of inputting a password. After that, the face image data obtained as a result is compared with the face image data pre-stored and associated with the ID information, and when the comparison is unsuccessful, it is determined that the user who input the ID information is not the real user corresponding to the pre-registered face photo data.
[0008] NPL 2 discloses a technique in which an employee ID card on which user identification information such as an employee number is printed (as a two-dimensional color barcode called a "chameleon code") is photographed together with the face of the user, and then authentication is performed through double-checking, where both the face of the user and the employee ID card need to be verified.
[0009] Prior art documents
[0010] Non-patent literature
[0011] NPL 1: "FOMA P901iS User Manual, NTT DoCoMo, November 2005, pp. 342 - 344"
[0012] NPL 2: "(Searched on September 17, 2019) NeoFace KAOATO Room Access Option Regarding 'Chameleon Code'", Internet URL: https: / / www.nec-solutioninnovators.co.jp / sl / kaoato / cc.html
[0013] Patent documents
[0014] PTL 1: Japanese Patent Application Laid-Open No. 2004 - 265231
[0015] Object of the invention:
[0016] The present invention aims to solve the problems in the prior art. Summary of the invention
[0017] A user authentication device according to an aspect of the present invention includes: a photographing module that photographs a two-dimensional code displayed on a user authentication support terminal owned by a user who is an authentication subject, the two-dimensional code encoding at least a first identification information that uniquely identifies the user and a second identification information that is generated at the time of registration of the user authentication support terminal and uniquely identifies all user authentications by summarizing the user authentication support terminal; an authentication factor acquisition module that acquires an authentication factor different from either the first identification information or the second identification information;
[0018] a decoding module that decodes the two-dimensional code photographed by the photographing module to obtain the first identification information and the second identification information;
[0019] a first identification information query module that refers to a storage module to query whether there is the first identification information obtained by the decoding module, the storage module storing, for each user, the first identification information, the authentication factor associated with the first identification information, and the second identification information associated with the first identification information;
[0020] The second identification information verification module, when the query performed by the first identification information query module is successful, reads the second identification information associated with the first identification information obtained by the decoding module with reference to the storage module, and then verifies the second identification information obtained by the decoding module against the second identification information read from the storage module;
[0021] The authentication factor verification module, when the query performed by the first identification information query module is successful, reads the authentication factor associated with the first identification information obtained by the decoding module with reference to the storage module, and then verifies the authentication factor obtained by the authentication factor acquisition module against the authentication factor read from the storage module;
[0022] The determination module determines that the user authentication is successful when the verification by the second identification information verification module is successful and the verification by the authentication factor verification module is successful.
[0023] A storage medium according to one aspect of the present invention stores a program for causing a computer to function as each module of the user authentication device.
[0024] Advantages of the Invention
[0025] By using the present invention, user authentication can be highly reliably performed with a simple operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 Shows an overview of the user authentication system.
[0027] Figure 2 Is a block diagram showing the functional configuration of the user authentication device.
[0028] Figure 3 Shows the data structure of the database.
[0029] Figure 4 Is a block diagram showing the functional configuration of the user authentication support terminal.
[0030] Figure 5 Is a flowchart showing the user registration process executed by the user authentication device.
[0031] Figure 6 Is a flowchart showing the user registration process executed by the user authentication support terminal.
[0032] Figure 7 Is a flowchart showing the specific process executed in step S6.
[0033] Figure 8It is a flowchart showing the user authentication process executed by the user authentication support terminal.
[0034] Figure 9 It shows the first half of the flowchart of the user authentication process executed by the user authentication device.
[0035] Figure 10 It shows the second half of the flowchart of the user authentication process executed by the user authentication device.
[0036] Figure 11 It is a flowchart showing the specific processes executed in steps S49 and S50.
[0037] Figure 12 It is a schematic diagram showing the image captured by the camera of the user authentication device.
[0038] Figure 13 It is a block diagram showing the functional configuration of the user authentication device of the second embodiment.
[0039] Figure 14 It is a schematic diagram showing the data structure of the database of the second embodiment.
[0040] Figure 15 It is a flowchart showing the specific process of step S6 in the case where the additional authentication factor is a voice response to the "secret question".
[0041] Figure 16 It is a flowchart showing the specific processes of steps S49 and S50 in the case where the additional authentication factor is a voice response to the "secret question".
[0042] Figure 17 It is a schematic diagram showing the data structure of the database of the third embodiment.
[0043] Figure 18 It is an explanatory diagram showing the user authentication process using the event ID.
[0044] Explanation of reference numerals:
[0045] 10 User authentication device;
[0046] 13 Various ID acquisition modules;
[0047] 14 Database;
[0048] 16 Display module;
[0049] 21 Camera;
[0050] 22 Face detection module;
[0051] 23 Face feature extraction module;
[0052] 26 Various ID verification modules;
[0053] 27 Facial feature verification module;
[0054] 28 User authentication determination module;
[0055] 50 User authentication support terminal. Detailed implementation manners
[0056] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0057]
First Embodiment
[0058] Figure 1 The outline of the user authentication system 1 is shown. The user authentication system 1 includes a user authentication device 10 and a user authentication support terminal 50.
[0059] The user authentication device 10 is, for example, a personal computer (PC) used as a login target, on which a predetermined program (hereinafter referred to as "authentication application program") is installed and executed. In other words, the user authentication device 10 is incorporated into the login target PC. When the user performs a login operation, the user authentication device 10 executes an authentication process through the authentication application program, and when the authentication is successful, the user authentication device 10 allows the user to log in.
[0060] The user who logs in to the user authentication device 10 owns the user authentication support terminal 50 and uses the user authentication support terminal 50 during the user registration and authentication processes.
[0061] The user authentication support terminal 50 is, for example, a smart phone on which a predetermined program (hereinafter referred to as "authentication support application program") is installed and executed.
[0062] Figure 2 It is a block diagram showing the functional configuration of the user authentication device 10.
[0063] The user authentication device 10 includes an input module 11, an account query module 12, various ID acquisition modules 13, a database 14, a two-dimensional code encoding and generating module 15, a display module 16, a camera 21, a face detection module 22, a facial feature extraction module 23, a timestamp generation module 24, a two-dimensional code detection and decoding module 25, various ID verification modules 26, a facial feature verification module 27, and a user authentication determination module 28.
[0064] The input module 11 is an interface for inputting information related to user registration and user authentication. The input module 11 includes, for example, an application activation button for activating the authentication application program, and input fields for a login name and a password.
[0065] The account query module 12 queries whether there is an account of the user of the authentication subject to be registered according to the login information input into the input module 11. If there is, the account query module 12 obtains the account information of this account.
[0066] The various ID acquisition modules 13 obtain the account name from the account information obtained by the account query module 12. In addition, the various ID acquisition modules 13 generate a session ID for uniquely identifying this user registration and a series of user authentications based on this user registration. Then, the various ID acquisition modules 13 save the account name used as the main query key and the session ID associated with this account name into the database 14.
[0067] The session ID here is unique identification information generated during the user registration process (for example, when registering a new user authentication support terminal 50 in the user authentication device 10, or when re-registering the existing user authentication support terminal 50 in order to replace the authentication factor associated with the account name with a different authentication factor as described later, etc.), and jointly identifies all user authentication processes related to the user of the user authentication support terminal 50 used during user registration.
[0068] The QR code encoding generation module 15 generates a variety of ID data groups that combine the account name, session ID, and registration code obtained by the various ID acquisition modules 13, and generates QR code image data by encoding the variety of ID data groups into a QR code.
[0069] The display module 16 corresponds to, for example, a display device or a touch panel. The display module 16 displays the QR code based on the QR code image data generated by the QR code encoding generation module 15.
[0070] The QR code detection and decoding module 25 generates encrypted various ID data groups by detecting and decoding the QR code from the image generated by the camera 21. Then, the QR code detection and decoding module 25 decrypts the encrypted various ID data groups using the symmetric encryption key based on the registration code read from the database 14, and extracts the account name, session ID, and timestamp.
[0071] In addition, the QR code detection and decoding module 25 uses the timestamp provided by the timestamp generation module 24 to determine the validity period of decryption, and when the validity period has not been reached, provides the account name to the database 14 and provides the session ID to the various ID verification modules 26.
[0072] The timestamp generation module 24 issues a timestamp for determining the decryption validity period to the QR code detection and decoding module 25.
[0073] The various ID verification modules 26 use the account name as a query keyword to obtain the session ID from the database 14, verify the obtained session ID with the session ID decoded by the QR code detection and decoding module 25, and notify the verification result to the user authentication determination module 28.
[0074] The face feature verification module 27 uses the account name as a query keyword to obtain the registered face features from the database 14, verifies the obtained face features with the face features provided by the face feature extraction module 23, and notifies the verification result to the user authentication determination module 28.
[0075] When receiving each notification from the database 14, the various ID verification modules 26, and the face feature verification module 27, the user authentication determination module 28 determines whether to allow user authentication and outputs the authentication result to the outside.
[0076] The camera 21 captures the user's face during user registration, and during user authentication, the camera 21 generates an image by sequentially or simultaneously capturing the QR code and the user's face displayed on the display module 57 of the user authentication support terminal 50, and provides the obtained image to the face detection module 22 and the QR code detection and decoding module 25.
[0077] The face detection module 22 extracts the user's face area from the image generated by the camera 21 and provides the obtained face image data to the face feature extraction module 23.
[0078] The face feature extraction module 23 extracts face features from the face image data provided by the face detection module 22. During user registration, the face feature extraction module 23 saves the extracted face features in the database 14 in association with the account name, and during user authentication, the face feature extraction module 23 provides the extracted face features to the face feature verification module 27.
[0079] The database 14 stores the account name used as the main query key and various data associated with the account name.
[0080] In addition, the database 14 also stores the registration code input when introducing the user authentication device 10, that is, when the authentication application is installed in the login target PC.
[0081] Figure 3 is a schematic diagram showing the data structure of the database 14.
[0082] In the first embodiment, the database 14 stores the account name and session ID obtained by the various ID acquisition modules 13 and the face features provided by the face feature extraction module 23.
[0083] When a user registers, the database 14 saves the session ID provided by various ID acquisition modules 13 and the face features provided by the face feature extraction module 23 in association with the account name acquired by the various ID acquisition modules 13.
[0084] When the QR code detection and decoding module 25 asks whether an account name exists during user authentication, the database 14 notifies the user authentication determination module 28 of the query result. In addition, when the queried account name exists, the database 14 provides the session ID associated with the account name to the various ID verification modules 26, and also provides the face features associated with the account name to the face feature verification module 27.
[0085] Data query is performed in the database 14 using the account name as the main query key. Therefore, even in the case where a large number of users who are authentication subjects have been registered, clear and high-speed queries can be performed.
[0086] Figure 4 is a block diagram showing the functional configuration of the user authentication support terminal 50.
[0087] The user authentication support terminal 50 includes a camera 51, a QR code detection and decoding module 52, various ID acquisition modules 53, a storage module 54, a timestamp generation module 55, a QR code encoding generation module 56, and a display module 57.
[0088] The camera 51 captures the QR code displayed on the display module 16 of the user authentication device 10 and provides the acquired image to the QR code detection and decoding module 52.
[0089] The QR code detection and decoding module 52 generates a group of various ID data by detecting and decoding the QR code from the image acquired by the camera 51, and provides the group of various ID data to the various ID acquisition modules 53.
[0090] The various ID acquisition modules 53 extract the account name, session ID, and registration code from the group of various ID data provided by the QR code detection and decoding module 52, and save them in the storage module 54.
[0091] The QR code encoding generation module 56 generates a new group of various ID data by combining the account name and session ID read from the storage module 54 and the timestamp provided by the timestamp generation module 55. The QR code encoding generation module 56 encrypts the new group of various ID data using a symmetric encryption key based on the registration code read from the storage module 54, and then generates QR code image data encoding the new group of various ID data into a QR code.
[0092] At the time of user registration, the storage module 54 saves the account name, session ID, and registration code provided by various ID acquisition modules 53. At the time of user authentication, the storage module 54 reads the account name, session ID, and registration code, and provides the read account name, session ID, and registration code to the QR code encoding generation module 56.
[0093] The timestamp generation module 55 generates a timestamp for determining the decryption validity period and provides the generated timestamp to the QR code encoding generation module 56.
[0094] The display module 57 displays a QR code based on the QR code image data generated by the QR code encoding generation module 56.
[0095] Figure 5 It is a flowchart showing the user registration process executed by the user authentication device 10.
[0096] The user registration process is executed only once before the user authentication described later, in order to register the user authentication support terminal 50 used at the time of user authentication in the user authentication device 10.
[0097] In step S1, the authentication application of the user authentication device 10 is activated in response to the user's operation. Then, when the user's login information (login name and password) is input to the input module 11, the account query module 12 receives the login information.
[0098] In step S2, the account query module 12 asks the login target PC incorporated with the user authentication device 10 whether there is an account of a user corresponding to the login information input to the input module 11. When there is an account of a user corresponding to the input login information in the login target PC, various ID acquisition modules 13 acquire the account information of the account from the account management module (not shown) of the login target PC.
[0099] In step S3, various ID acquisition modules 13 acquire the account name from the acquired account information.
[0100] In step S4, various ID acquisition modules 13 generate a session ID, and save the generated session ID in the database 14 in association with the account name used as the main query key.
[0101] Note that when the same account name as the data to be stored already exists in the database 14 and overwrite update is allowed, the data associated with the account name is updated by being overwritten respectively.
[0102] In step S5, the QR code encoding generation module 15 reads the registration code from the database 14, generates various ID data groups that combine the account name, session ID, and registration code, and generates QR code image data by encoding the generated various ID data groups into QR codes. The display module 16 displays the QR code based on the QR code image data generated by the QR code encoding generation module 15.
[0103] In step S6, the various ID acquisition module 13 determines whether there is an additional authentication factor (such as a face feature). When the additional authentication factor exists, the various ID acquisition module 13 acquires the data of the additional authentication factor and stores it in the database 14 in association with the account name. Note that the specific processing performed in step S6 when the additional authentication factor is a face feature will be described below.
[0104] In step S7, the various ID acquisition module 13 determines whether the processing of step S6 has been performed for all additional authentication factors. If so, it proceeds to step S8; if not, it returns to step S6.
[0105] In step S8, user registration is verified. Here, the user authentication process to be described below is performed.
[0106] Figure 6 FIG. is a flowchart showing the user registration process executed by the user authentication support terminal 50.
[0107] Note that currently, the user authentication device 10 has executed step S5 such that the QR code is displayed on the display module 16.
[0108] In step S11, the authentication support application of the user authentication support terminal 50 is activated in response to the user's operation. When "user registration" is selected on the authentication support application, the camera 51 starts shooting. At this time, the user turns the camera 51 of the user authentication support terminal 50 towards the display module 16 of the user authentication device 10. As a result, the camera 51 captures the QR code.
[0109] In step S12, the QR code detection and decoding module 52 generates various ID data groups (including the account name, session ID, and registration code) by detecting and decoding the QR code based on the image data acquired by the camera 51.
[0110] In step S13, the various ID acquisition module 53 extracts the account name, session ID, and registration code from the various ID data groups provided by the QR code detection and decoding module 52 and stores them in the storage module 54.
[0111] In step S14, user registration is verified. Here, the user authentication process to be described below is performed.
[0112] Figure 7is a flowchart showing the specific processing executed in step S6 of Figure 5 More specifically, in step S6, when the additional authentication factor is a face feature, the following processing is executed.
[0113] In step S21, the camera 21 of the user authentication device 10 generates image data by photographing the face of the user.
[0114] In step S22, the face detection module 22 detects the face region from the image data generated by the camera 21.
[0115] In step S23, the face feature extraction module 23 extracts face features from the face region of the image data.
[0116] In step S24, since the face feature exists as an additional authentication factor, the various ID acquisition modules 13 save the acquired face features in association with the account name in the database 14.
[0117] Figure 8 is a flowchart showing the user authentication process executed by the user authentication support terminal 50.
[0118] In step S31, the authentication support application of the user authentication support terminal 50 is activated in response to the operation of the user. When "Authenticate" is selected on the authentication support application, the QR code encoding generation module 56 acquires the account name, session ID, and registration code from the storage module 54.
[0119] In step S32, the QR code encoding generation module 56 further generates a symmetric encryption key based on the registration code read from the storage module 54. Then, the QR code encoding generation module 56 encrypts the new various ID data group that combines the account name and session ID acquired in step S31 and the timestamp provided by the timestamp generation module using the symmetric encryption key.
[0120] The new encrypted various ID data group (hereinafter referred to as "encrypted various ID data group") includes a timestamp and depends on its generation time. Therefore, even if the symmetric encryption key itself does not depend on time, the encrypted various ID data group has properties similar to those of TOTP (Time-based One-Time Password). Alternatively, the QR code encoding generation module 56 can directly generate a time-dependent symmetric encryption key using the timestamp and generate the encrypted various ID data group using the time-dependent symmetric encryption key.
[0121] As long as the symmetric encryption key is based on the information shared between the user authentication device 10 and the user authentication support terminal 50, there is no particular limitation on it. For example, the symmetric encryption key can be a HOTP (HMAC (Hash-based Message Authentication Code)-based One-Time Password) that uses the number of times the past symmetric encryption key has been generated, etc. as the shared information.
[0122] In step S33, the QR code encoding generation module 56 generates QR code image data by encoding various ID data groups after encryption into a QR code. The display module 57 displays the QR code based on the image data generated by the QR code encoding generation module 56.
[0123] The user brings the display module 57 of the user authentication support terminal 50 close to the front of the camera 21 of the user authentication device 10. In addition, when the user is sitting directly in front of the user authentication device 10 (camera 21), the user can keep the QR code displayed on the display module 57 side by side with his / her own face while facing the user authentication device 10. Therefore, as will be described in detail below, the QR code displayed on the display module 57 is used for the authentication process performed by the user authentication device 10.
[0124] Figure 9 and 10 is a flowchart showing the user authentication process performed by the user authentication device 10.
[0125] In step S41, the authentication application of the user authentication device 10 is activated in response to the user's operation. Note that the authentication application can be activated simultaneously when the login target PC incorporating the user authentication device 10 is started. Then the camera 21 captures the QR code displayed on the display module 57 of the user authentication support terminal 50 and generates image data.
[0126] In step S42, the QR code detection and decoding module 25 generates various encrypted ID data groups by detecting and decoding the QR code based on the image data generated by the camera 21.
[0127] In step S43, the QR code detection and decoding module 25 generates a symmetric encryption key based on the registration code read from the database 14 and performs a decryption process on the various encrypted ID data groups by using the symmetric encryption key to obtain various ID data groups.
[0128] In step S44, the QR code detection and decoding module 25 determines whether the decryption process is successful. If successful, it proceeds to step S45; otherwise, it proceeds to step S52.
[0129] Here, as an example of a failed decryption process, for example, the case where the symmetric encryption keys do not match. In addition, as another example of failure, the decryption process is successful and various ID data groups are obtained, but according to the comparison result between the timestamp included in the various ID data groups and the timestamp obtained from the timestamp generation module within the user authentication device 10, it is determined that the decryption validity period has expired.
[0130] In step S45, various ID verification modules 26 obtain the account name from the various ID data groups obtained by the two-dimensional code detection and decoding module 25, and provide the obtained account name to the database 14.
[0131] In step S46, the database 14 queries whether the account name provided by the various ID verification modules 26 exists and notifies the query result to the user authentication determination module 28. When the account name exists, the process proceeds to step S47. When the account name does not exist, the process proceeds to step S52.
[0132] In step S47, the various ID verification modules 26 obtain the session ID from the various ID data groups obtained by the two-dimensional code detection and decoding module 25. In addition, the various ID verification modules 26 use the account name obtained in step S45 as a query keyword to obtain the session ID associated with the account name from the database 14.
[0133] In step S48, the various ID verification modules 26 compare the session ID obtained from the various ID data groups with the session ID from the database 14, and notify the comparison result to the user authentication determination module 28. When the comparison result indicates that the session IDs match, the process proceeds to step S49. When the session IDs do not match, the process proceeds to step S52.
[0134] The session ID is unique identification information generated during user registration and uniformly identifies all user authentication processes related to the user of the user authentication support terminal 50 that has been used during user registration. Therefore, for example, if the user loses the user authentication support terminal 50 used during user registration, the user authentication device 10 invalidates (e.g., sets to 0) the session ID generated and stored in the database 14 during user registration. As a result, when a third party performs spoof authentication using the lost user authentication support terminal 50, spoof authentication is blocked in step S48. Note that when it is desired to use a new user authentication support terminal 50 to replace the user authentication support terminal 50 that has been used during user registration, the user registration process must be re-executed.
[0135] In step S49, each ID verification module 26 uses the account name obtained in step S45 as a query keyword to obtain data on additional authentication factors associated with the account name from the database 14, and provides the obtained data to a preset verification module (not shown) related to the additional authentication factor.
[0136] In step S50, the predetermined verification module verifies the additional authentication factor data obtained by a predetermined method related to the additional authentication factor with the additional authentication factor data provided by the various ID verification modules 26 from the database 14, and notifies the verification result to the user authentication determination module 28. When the verification result indicates that the groups of additional authentication factor data match, the process proceeds to step S51, and when the groups of additional authentication factor data do not match, the process proceeds to step S52. Then, steps S49 and S50 are repeatedly executed for all the additional authentication factors. Additionally, when the additional authentication factor is a facial feature, the specific process shown in Figure 11 is executed.
[0137] In step S52, when the user authentication determination module 28 receives all the notifications from the database 14, the various ID verification modules 26, etc., it determines the authentication result (authentication successful or authentication rejected) and outputs the authentication result. More specifically, only when the account name, session ID, and additional authentication factor all match, the user authentication determination module 28 determines that the authentication is successful, and when any one of the elements of the account name, session ID, and additional authentication factor does not match, the user authentication determination module 28 determines to reject the authentication.
[0138] When the authentication is successful, the user authentication device 10 allows the user to log in to the login target PC. As a result, the user can log in to the login target PC incorporating the user authentication device 10, and then the user can freely operate the PC.
[0139] When the authentication is rejected, the user authentication device 10 prohibits the user from logging in to the login target PC. As a result, the user cannot log in to the login target PC incorporating the user authentication device 10, and thus the user cannot operate the PC.
[0140] Figure 11 is a flowchart showing the specific process executed in Figure 10 steps S49 and S50. More specifically, in steps S49 and S50, the following process is executed when the additional authentication factor is a facial feature.
[0141] In step S61, the camera 21 of the user authentication device 10 generates image data by photographing the user's face.
[0142] In step S62, the face detection module 22 detects the facial area from the image data generated by the camera 21.
[0143] In step S63, the face feature extraction module 23 extracts the face features from the facial area of the image data.
[0144] In step S64, the various ID verification modules 26 use the account name obtained in step S45 as a query keyword to obtain from the database 14 the face features associated with the account name, and provide the obtained face features to the face feature verification module 27.
[0145] In step S65, the face feature verification module 27 verifies the face features provided by the face feature extraction module 23 against the face features provided by the various ID verification modules 26 from the database 14, and notifies the verification result to the user authentication determination module 28. When the verification result indicates that the face features match, the process proceeds to step S51, and when the face features do not match, the process proceeds to step S52.
[0146] Figure 12 is a schematic diagram showing an image captured by the camera 21 of the user authentication device 10.
[0147] The user authentication in this embodiment consists of a two-step authentication process, namely, the authentication process related to whether the user "owns" the user authentication support terminal 50 registered in the user authentication device 10, the authentication by displaying a two-dimensional code such as a QR code (registered trademark) on the user authentication support terminal 50 (the first authentication process), and the face recognition process (the second authentication process) for determining whether the user is the registered user himself / herself through "biometric" authentication. Therefore, the camera 21 of the user authentication device 10 captures the two-dimensional code during the first authentication process and the user's face during the subsequent second authentication process.
[0148] However, in order to effectively execute the first and second authentication processes, the camera 21 can capture the two-dimensional code displayed on the user authentication support terminal 50 and the user's face simultaneously, as Figure 12 shown. In this case, the user authentication device 10 sequentially executes the first authentication process and the second authentication process. By being able to perform the first and second authentication processes through a single shooting operation in this way, the burden on the user can be reduced.
[0149] Note that in this embodiment, face recognition, which is one of the "biometric" authentications, is used as the second authentication process, but the second authentication process is not limited to face recognition. In other words, biometric authentication based on any biometric feature that can identify an individual and can be verified based on image matching technology can be used. More specifically, any user authentication method related to the user's "biometric", such as using iris, retina, vein, fingerprint, auricle, palm shape, etc., can identify individual users.
[0150]
Second Embodiment
[0151] Next, the second embodiment will be described. In addition, the same parts as those in the first embodiment have been labeled with the same reference numerals, and the repeated description thereof has been omitted.
[0152] The user authentication of the first embodiment consists of two-step authentication, including an authentication process (first authentication) related to whether the user "owns" the user authentication support terminal 50 registered in the user authentication device 10, and face recognition, which is one of the biometric authentications, as an additional authentication factor (second authentication).
[0153] In contrast, in the second embodiment, instead of face recognition, the authentication of the voice response to the "secret question" and voiceprint authentication, which is another biometric authentication, are used as additional authentication factors. That is, the user authentication of the second embodiment consists of three-stage authentication, including the same first authentication as in the first embodiment and the voice response authentication to the "secret question" (second authentication), and voiceprint authentication (third authentication).
[0154] Figure 13 It is a block diagram showing the functional configuration of the user authentication device 10 of the second embodiment.
[0155] At the time of user registration, the display module 16 displays a QR code and the text of the "secret question". At the time of user authentication, the display module 16 only displays the text of the "secret question".
[0156] The microphone 31 converts the voice of the response to the "secret question" into voice data of the response, and provides the obtained voice data of the response to the voiceprint extraction module 32 and the voice text conversion module 33.
[0157] The voiceprint extraction module 32 extracts voiceprint data from the voice data of the response provided by the microphone 31. At the time of user registration, the voiceprint extraction module 32 saves the voiceprint data in association with the account name in the database 14, and at the time of user authentication, the voiceprint extraction module 32 provides the voiceprint data to the voiceprint verification module 34.
[0158] The voice text conversion module 33 converts the voice data of the response provided by the microphone 31 into response text data by performing speech recognition and language analysis processing. At the time of user registration, the voice text conversion module 33 saves the response text data in association with the account name in the database 14, and at the time of user authentication, the voice text conversion module 33 provides the response text data to the response verification module 35.
[0159] The voiceprint verification module 34 compares the registered voiceprint data obtained from the database 14 using the account name as a query keyword with the voiceprint data provided by the voiceprint extraction module 32, and notifies the user authentication determination module 28 of the comparison result.
[0160] The answer verification module 35 verifies the registered answer text data obtained from the database 14 using the account name as the query keyword against the answer text data provided by the speech text conversion module 33, and notifies the user authentication determination module 28 of the verification result.
[0161] Upon receiving notifications from the database 14, various ID verification modules 26, the voiceprint verification module 34, and the answer verification module 35, the user authentication determination module 28 determines whether to allow user authentication and outputs the authentication result externally.
[0162] Figure 14 FIG. is a schematic diagram showing the data structure of the database 14.
[0163] In the second embodiment, the database 14 stores the account name and session ID obtained by the various ID acquisition modules 13, the answer text data provided by the speech text conversion module 33, and the voiceprint data provided by the voiceprint extraction module 32.
[0164] At the time of user registration, the database 14 saves the account name obtained by the various ID acquisition modules 13 in association with the session ID provided by the various ID acquisition modules 13, the answer text data provided by the speech text conversion module 33, and the voiceprint data provided by the voiceprint extraction module 32.
[0165] When the QR code detection and decoding module 25 asks for the account name during user authentication, the database 14 notifies the user authentication determination module 28 of the query result. In addition, when the queried account name exists, the database 14 provides the session ID associated with the account name to the various ID verification modules 26, and provides the voiceprint data and answer text data associated with the account name to the voiceprint verification module 34 and the answer verification module 35, respectively.
[0166] Data query is performed in the database 14 using the account name as the main query key. Therefore, even in the case where a large number of users as authentication subjects are registered, clear and high-speed queries can be performed.
[0167] The user authentication device 10 and the user authentication support terminal 50 configured as described above perform user registration processing in a manner similar to the first embodiment. However, note that the following processing is performed for additional authentication factors.
[0168] Figure 15 FIG. is a flowchart showing the specific processing performed in step S6 in the case where the additional authentication factor is an answer to a "secret question". Figure 5 FIG.
[0169] In step S71, the display module 16 of the user authentication device 10 displays "secret question" and prompts the user to answer. Note that in this embodiment, the display module 16 displays one "secret question", but it can also display multiple "secret questions". In the latter case, the user can be prompted to select one of the multiple "secret questions".
[0170] In step S72, the microphone 31 records the voice data of the answer spoken by the user.
[0171] In step S73, the voice text conversion module 33 converts the voice data of the answer obtained by the microphone 31 into text, and saves the obtained answer text data in association with the account name in the database 14.
[0172] In step S74, the voiceprint extraction module 32 extracts voiceprint data from the voice data obtained by the microphone 31, and saves the obtained voiceprint data in association with the account name in the database 14.
[0173] In addition, the user authentication device 10 and the user authentication support terminal 50 perform user authentication processing in a manner similar to the first embodiment. However, note that the following processing is performed for the additional authentication factor.
[0174] Figure 16 is a flowchart showing the specific processing performed in step S49 and step S50 in the case where the additional authentication factor is the answer to the "secret question". Figure 10 of the flowchart.
[0175] In step S81, it is judged whether it is the first time to perform the additional authentication process. When performing the additional authentication process for the first time, the process proceeds to step S82, and when it is not the first time to perform the additional authentication process, the process proceeds to step S87.
[0176] In step S82, the display module 16 of the user authentication device 10 displays "secret question" and prompts the user to answer.
[0177] In step S83, the microphone 31 records the voice of the user as the voice data of the answer.
[0178] In step S84, the voiceprint extraction module 32 extracts voiceprint data from the voice data of the answer.
[0179] In step S85, the various ID verification modules 26 use the account name obtained in step S45 as a query keyword, obtain the voiceprint data associated with the account name from the database 14, and provide the obtained voiceprint data to the voiceprint verification module 34.
[0180] In step S86, the voiceprint verification module 34 verifies the voiceprint data provided by the voiceprint extraction module 32 with the voiceprint data provided by the various ID verification modules 26 from the database 14, and notifies the verification result to the user authentication determination module 28.
[0181] On the other hand, in step S87, the voice data of the answer recorded in step S83 is read.
[0182] In step S88, the voice text conversion module 33 generates answer text data by converting the voice data of the answer into text.
[0183] In step S89, the various ID verification modules 26 use the account name obtained in step S45 as a query keyword, obtain the answer text data associated with the account name from the database 14, and provide the obtained answer text data to the answer verification module 35.
[0184] In step S90, the answer verification module 35 verifies the answer text data provided by the voice text conversion module 33 with the answer text data provided by the various ID verification modules 26 from the database 14, and notifies the verification result to the user authentication determination module 28.
[0185] In addition, in the present embodiment, voiceprint authentication, which is one of the "biometric" authentications, is used as the second authentication, but the second authentication is not limited to voiceprint authentication. In other words, biometric authentication based on any biometric feature that can identify an individual and is extracted when answering the "secret question" can be used.
[0186] For example, a handwriting input device, a handwritten text recognition module, and a handwriting extraction module can be used respectively instead of the microphone 31, the voice text conversion module 33, and the voiceprint extraction module 32. In other words, a handwritten answer (such as a signature, etc.) can be used instead of a voice answer.
[0187]
Third Embodiment
[0188] Next, the third embodiment will be described. Note that the same parts as those in the above embodiments have been marked with the same reference numerals, and the repeated description thereof has been omitted.
[0189] Figure 17 is a schematic diagram showing the data structure of the database 14 in the third embodiment.
[0190] In the database 14 of the first embodiment, as Figure 3 shown, the session ID and the face feature are stored together with the account name as various data associated with the account name, and the account name is used as the main query key.
[0191] In contrast, in the database 14 of the third embodiment, asFigure 17 As shown, in addition to the session ID and face features, an event ID is also stored as various data associated with the account name. The event ID is identification information that uniquely identifies each process of user registration and user authentication.
[0192] (User registration process: User authentication device 10)
[0193] In the user registration process, the user authentication device 10 performs a process similar to that of Figure 5 . However, the user authentication device 10 executes steps S4 and S5 using the event ID as follows.
[0194] In step S4, the various ID acquisition module 13 generates a session ID and an event ID, and saves the generated session ID and event ID in the database 14 in association with the account name used as the main query key.
[0195] In step S5, the QR code encoding generation module 15 reads the registration code from the database 14, generates a group of various ID data combining the account name, session ID, event ID, and registration code, and generates QR code image data by performing QR code encoding on the generated group of various ID data. The display module 16 displays the QR code based on the QR code image data generated by the QR code encoding generation module 15.
[0196] (User registration process: User authentication support terminal 50)
[0197] In the user registration process, the user authentication support terminal 50 performs a process similar to that of Figure 6 . However, the user authentication support terminal 50 executes steps S12 and S13 using the event ID as follows.
[0198] In step S12, the QR code detection and decoding module 52 generates a group of various ID data (including the account name, session ID, event ID, and registration code) by detecting and decoding the QR code based on the image data acquired by the camera 51.
[0199] In step S13, the various ID acquisition module 53 extracts the account name, session ID, event ID, and registration code from the group of various ID data provided by the QR code detection and decoding module 52, and saves the extracted account name, session ID, event ID, and registration code in the storage module 54.
[0200] (User authentication process)
[0201] In this embodiment, the event ID is used for the user authentication process.
[0202] Figure 18 is an explanatory diagram of the user authentication process using the event ID. The nth (≥1) user authentication process is executed as follows.
[0203] (n-th user authentication process)
[0204] The user authentication support terminal 50 generates an event ID (e.g., event ID (n+1)) separate from the event ID (e.g., event ID (n)) stored in the storage module 54. Here, the event ID (1) is the event ID stored in the storage module 54 by the user authentication support terminal 50 in Figure 6 step S13 of the user registration process shown.
[0205] By executing the Figure 8 processing of steps S31 to S33 shown, the user authentication support terminal 50 displays a QR code that includes information on the event ID (n) for the current user authentication and the event ID (n+1) for the next authentication.
[0206] On the other hand, the user authentication device 10 performs the user authentication process in a similar manner to Figure 9 and Figure 10 shown. That is, the user authentication device 10 captures the QR code displayed on the user authentication support terminal 50 and obtains various ID data groups (including the account name, session ID, event ID (n), and event ID (n+1)) from the QR code (steps S41 to S44).
[0207] When the decryption is successfully completed and the account name query and session ID verification are successful (steps S45 to S48), the user authentication device 10 verifies the event ID (n) and performs the processing of steps S49 to S52.
[0208] Specifically, the various ID verification modules 26 of the user authentication device 10 obtain the event ID (n) from the various ID data groups. In addition, the various ID verification modules 26 use the obtained account name as a query keyword to obtain from the database 14 the event ID (n) provided by the user authentication support terminal 50 during the previous user authentication and stored in the database 14 in association with the account name. Additionally, the event ID (1) obtained by the user authentication device 10 (various ID acquisition modules 13) from the database 14 during the first user authentication is Figure 5 generated by the user authentication device 10 (various ID acquisition modules 13) in step S4 of the user registration process shown and stored in the database 14 in association with the account name used as the main query key.
[0209] Next, various ID verification modules 26 verify the event ID(n) obtained from various ID data groups with the event ID(n) from the database 14 and notify the verification result to the user authentication determination module 28. When the verification result indicates that the two event IDs(n) match, the process proceeds to step S49. When the two event IDs(n) do not match, the process proceeds to step S52. Then, steps S49 to S52 are executed in a manner similar to the first embodiment.
[0210] Then, the user authentication device 10 (various ID verification modules 26) obtains the event ID(n + 1) from various ID data groups and stores the obtained event ID(n + 1) by overwriting the event ID(n) stored in the database 14 in association with the account name. As a result, the event ID(n) stored in the database 14 is updated to the event ID(n + 1).
[0211] On the other hand, the user authentication support terminal 50 (various ID acquisition modules 53) also stores the generated event ID(n + 1) in the storage module 54 by overwriting the existing event ID(n).
[0212] As described above, after the user authentication process is completed by the user authentication device 10, the event ID(n) jointly stored in the user authentication device 10 and the user authentication support terminal 50 is updated to the event ID(n + 1). At this time, the nth user authentication process has been completed.
[0213] Therefore, in the user authentication process of the third embodiment, the event ID generated after the user registration process or the previous user authentication process is verified. Therefore, in the user authentication process of the third embodiment, the user is required to use the same user authentication support terminal 50 as the previous use.
[0214] In Figure 6 In step S11 of the user registration process shown, in principle, multiple user authentication support terminals for backup etc. can be registered simultaneously instead of only registering one main user authentication support terminal 50. In the first embodiment, if the backup user authentication support terminal 50 falls into the hands of a third party, the third party can successfully complete user authentication using the backup user authentication support terminal 50.
[0215] In addition, in the third embodiment, since the event ID shared during the previous user authentication is verified during each user authentication, using a backup user authentication support terminal 50 that was not used during the previous user authentication cannot successfully complete user authentication.
[0216] As described above, in the third embodiment, the backup user authentication support terminal 50 can be safely handled. Note that if the user authentication support terminal 50 used in the last user authentication is in the hands of a third party, the user authentication device 10 can, by means of confirming the legitimacy of the user, for example, by querying whether the account corresponding to the login information (login name and password) used in the user registration process exists, omit only the step of checking the event ID (n) in the current user authentication process.
[0217] In this case, while using the backup user authentication support terminal 50, the user authentication device 10 omits only the step of checking the event ID (n) in the current user authentication process and saves the event ID (n + 1) after the current user authentication process. As a result, the backup user authentication support terminal 50 can be used as the main user authentication support terminal 50 starting from the next user authentication, rather than the user authentication device 10 performing special processing such as invalidating the event ID in its database 14.
[0218] The present invention is not limited to the above embodiments, and can be applied to, for example, the following structures.
[0219] The database 14 does not have to exist in the login target PC incorporating the user authentication device 10. For example, the database 14 can exist in an external server that can access the database 14.
[0220] In the present invention, the first identification information is not limited to the account name, and can also be an account GUID (Globally Unique Identifier) generated when creating the account and capable of uniquely identifying the account in terms of time and space. Of course, the first identification information can also be an employee number or the like.
[0221] The present invention is not limited to PC login authentication, and can also be applied to any object that requires user authentication. For example, the present invention can also be applied to a room access management device provided at the entrance of a secret room for managing confidential information to manage access to the secret room.
Claims
1. A user authentication device, comprising: a photographing module configured to photograph a two-dimensional code displayed on a user authentication support terminal owned by a user who is an authentication subject, wherein the two-dimensional code is formed by encoding at least first identification information and second identification information into the two-dimensional code, the first identification information uniquely identifies the user, and the second identification information relates to registration of the user authentication support terminal and is uniquely identified by summarizing user authentication using the user authentication support terminal; an authentication factor acquisition module configured to acquire an authentication factor different from any one of the first identification information and the second identification information; a decoding module configured to acquire the first identification information and the second identification information by decoding the two-dimensional code; a first identification information query module configured to refer to a storage module to query whether there is the first identification information acquired by the decoding module, and the storage module stores, for the user, the first identification information, the authentication factor associated with the first identification information, and the second identification information associated with the first identification information; a second identification information verification module configured to, when the query by the first identification information query module is successful, read the second identification information associated with the first identification information acquired by the decoding module from the storage module, and then verify the second identification information acquired by the decoding module with the second identification information read from the storage module; an authentication factor verification module configured to, when the query by the first identification information query module is successful, read the authentication factor associated with the first identification information acquired by the decoding module from the storage module, and then verify the authentication factor acquired by the authentication factor acquisition module with the authentication factor read from the storage module; and a determination module configured to determine that the authentication of the user is successful when the verification by the second identification information verification module is successful and the verification by the authentication factor verification module is successful.
2. The user authentication device according to claim 1, wherein when the authentication factor is a facial feature, the photographing module photographs the face of the user and the two-dimensional code simultaneously or separately, and wherein the authentication factor acquisition module acquires the facial feature based on the face image of the user photographed by the photographing module.
3. The user authentication device according to claim 1, wherein the authentication factor acquisition module acquires a plurality of authentication factors, and when the query performed by the first identification information query module is successful, the authentication factor verification module reads all the authentication factors associated with the first identification information obtained by the decoding module from the storage module, and respectively verifies all the authentication factors acquired by the authentication factor acquisition module with all the authentication factors read from the storage module, and wherein when the verification performed by the second identification information verification module is successful and all the verifications performed by the authentication factor verification module are successful, the determination module determines that the user authentication is successful.
4. The user authentication device according to claim 1, further comprising a second identification information invalidation module, which invalidates the second identification information associated with the first identification information stored in the storage module.
5. The user authentication device according to claim 1, further comprising: a third identification information verification module; and a third identification information generation module, which generates initial third identification information during the registration of the user authentication support terminal, and the third identification information uniquely identifies each user authentication process for determining the authentication of the user; wherein the photographing module photographs the two-dimensional code, which is formed by additionally encoding the third identification information and is displayed by the user authentication support terminal, and the third identification information is generated by the third identification information generation module or by the user authentication support terminal; wherein the decoding module additionally acquires the third identification information by decoding the two-dimensional code photographed by the photographing module; wherein the storage module additionally stores the third identification information associated with the first identification information; wherein when the query performed by the first identification information query module is successful, the third identification information verification module reads the third identification information associated with the first identification information obtained by the decoding module from the storage module, and verifies the third identification information obtained by the decoding module with the third identification information read from the storage module, and wherein when the verification performed by the second identification information verification module, all the verifications performed by the authentication factor verification module, and the verification performed by the third identification information verification module are successful, the determination module determines that the user authentication is successful.
6. The user authentication device according to claim 5, wherein, When performing the first user authentication on the user, the user authentication support terminal generates third identification information for uniquely identifying the second user authentication performed after the first user authentication of the user, and while saving the third identification information in the user authentication support terminal, stores the third identification information in the storage module.
7. The user authentication device according to claim 5, wherein when the first identification information and the second identification information are stored in a plurality of user authentication support terminals, and when user authentication is performed using a user authentication support terminal different from the previous one among the plurality of user authentication support terminals, on the premise that predetermined user authentication information has been input, when the verification performed by the second identification information verification module is successful and all verifications performed by the authentication factor verification module are successful, the determination module determines that the user authentication is successful.
8. The user authentication device according to claim 1, wherein the two-dimensional code is a QR code.
9. A non-transitory computer-readable medium having stored thereon a program for causing a computer to function as each module of the user authentication device according to claim 1.
Citation Information
Patent Citations
Face picture recording system and method
JP2004265231A
Matrix barcode enhancement through capture and use of neighboring environment image
US9213931B1