Information processing apparatus and storage medium

CN115118444BActive Publication Date: 2026-09-11FUJIFILM BUSINESS INNOVATION CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111062144.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-03-18
Filing Date
2021-09-10
Publication Date
2026-09-11
Estimated Expiration
2041-09-10

AI Technical Summary

Benefits of technology

[0019] According to [1] or [6], even when the information processing device of the authentication collaboration destination is notified of the second communication address associated with the first communication address registered by the user in the external authentication device, instead of the first communication address, the information processing device is still able to verify the first communication address.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115118444B_ABST
    Figure CN115118444B_ABST
Patent Text Reader

Abstract

This invention provides an information processing apparatus and a storage medium. The information processing apparatus includes a storage device and a processor. The storage device stores restriction information indicating that a first communication address of a user registered with an external authentication device for authentication cooperation with an external authentication device to obtain a license to use the information processing apparatus must meet certain restrictions. The processor obtains first information issued by the external authentication device indicating successful authentication of the user. This first information includes a second communication address generated by the external authentication device corresponding to the first communication address. The processor sends second information requesting communication with a specified verification device to the second communication address contained in the first information. The processor obtains a verification result from the verification device indicating whether the sending source of the communication based on the second information, i.e., the first communication address, meets the restrictions. When the verification result indicates that the first communication address does not meet the restrictions, control is executed to prevent the user from authenticating with the external authentication device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an information processing device and a storage medium for storing information processing programs. Background Technology

[0002] Patent Document 1 discloses a system that enables a user ID in a local environment to collaborate with a user ID of an external website, i.e., a portal website, which provides cloud services. When the portal website receives a collaboration request from a user ID in the local environment, it requests unique information from the user ID to prove that the user is a user in the local environment and determines the authenticity of the unique information entered by the user. If the unique information is correct, it collaborates with the user ID; if the unique information is incorrect, it rejects the collaboration of the user ID.

[0003] Existing technical documents

[0004] Patent documents

[0005] Patent Document 1: Japanese Patent Application Publication No. 2020-038438 Summary of the Invention

[0006] The problem that the invention aims to solve

[0007] Previously, information processing devices that enabled users to access the information processing device after authentication collaborated with an external authentication device used to authenticate the user. Through this collaboration, the user was authenticated by the external authentication device, thereby gaining access to the information processing device without further authentication processing with the information processing device. Specifically, in such authentication collaboration systems, the external authentication device used the user's communication address (e.g., email address) as a user ID to identify the user during authentication.

[0008] Here, an information processing device that collaborates with an external authentication device may want to impose restrictions on the communication addresses registered by users with that external authentication device. For example, when an organization allows its users to use the information processing device through authentication collaboration with an external authentication device, it may want to restrict the username portion of the email address registered by the user with the external authentication device to a specific format (e.g., the username begins with an employee number).

[0009] On the other hand, the communication address registered by the user with the external authentication device is sometimes generated by the external authentication device rather than the user and notified to the information processing device. In this case, the information processing device cannot verify whether the communication address registered by the user with the external authentication device meets the restrictions.

[0010] The purpose of this disclosure is that the information processing device is able to verify the first communication address even when the information processing device at the authentication collaboration destination is notified of the second communication address associated with the first communication address registered by the user on the external authentication device, instead of the first communication address.

[0011] Methods for solving problems

[0012] [1] One aspect of this disclosure provides an information processing apparatus comprising a storage device and a processor, the storage device storing restriction information indicating that a first communication address of a user registered with an external authentication device for authentication cooperation with an external authentication device to obtain a license to use the information processing apparatus should meet restrictions, the processor acquiring first information published by the external authentication device indicating successful authentication of the user, the first information including a second communication address generated by the external authentication device corresponding to the first communication address, second information requesting communication with a specified verification device to the second communication address included in the first information, acquiring a verification result from the verification device indicating whether the sending source of the communication based on the second information, i.e., the first communication address, meets the restrictions, and when the verification result indicates that the first communication address does not meet the restrictions, executing control to disallow authentication cooperation between the user and the external authentication device.

[0013] [2] In the information processing apparatus described in [1], it may also be possible to receive a determination result of the validity of the first communication address based on the forwarding path of the communication from the user from the verification device, wherein when the determination result indicates that the first communication address is invalid, authentication cooperation between the user and the external authentication device is not allowed.

[0014] [3] In the information processing apparatus described in [1] or [2], the processor may provide at least a portion of the restriction information to the verification device, the verification device may determine whether the first communication address satisfies the restriction indicated by the restriction information provided by the processor, and provide its determination result to the processor.

[0015] [4] In the information processing device described in [3], the processor may also receive identification information input by the user in the information processing device after obtaining the first information, and provide the verification device with restriction information determined based on the received identification information, which indicates the restriction to be applied to the user.

[0016] [5] In the information processing device described in [1] or [2], the processor may also receive identification information input by the user in the information processing device after obtaining the first information. When the verification result indicates that the first communication address meets the restriction, the processor allows the user to perform authentication cooperation with the external authentication device and registers information indicating that the second communication address corresponds to the identification information.

[0017] [6] Other aspects of this disclosure provide a storage medium for storing an information processing program that causes a computer having a storage device for storing restriction information indicating that a first communication address of a user registered with an external authentication device for authentication cooperation to obtain a license to use the information processing device should meet the following actions: obtaining first information issued by the external authentication device indicating successful authentication of the user, the first information including a second communication address generated by the external authentication device corresponding to the first communication address; sending second information requesting communication with a specified verification device to the second communication address contained in the first information; obtaining from the verification device a verification result indicating whether the first communication address, the source of the communication based on the second information, meets the restriction; and when the verification result indicates that the first communication address does not meet the restriction, executing control to disallow authentication cooperation between the user and the external authentication device.

[0018] Invention Effects

[0019] According to [1] or [6], even when the information processing device of the authentication collaboration destination is notified of the second communication address associated with the first communication address registered by the user in the external authentication device, instead of the first communication address, the information processing device is still able to verify the first communication address.

[0020] According to [2], it is possible to further prevent authentication collaboration with external authentication devices for the user based on the forwarding path of communication from the second communication address to the authentication device.

[0021] According to [3], the information processing device and the verification device can be separated.

[0022] According to [4], the verification device can verify whether the first communication address meets the restrictions corresponding to the user.

[0023] According to [5], the information processing device can identify the user based on the second communication address. Attached Figure Description

[0024] Figure 1 This is a schematic diagram of the information processing system of this embodiment.

[0025] Figure 2 This is a schematic diagram of the user terminal.

[0026] Figure 3 This is a schematic diagram of the authentication server structure.

[0027] Figure 4 This is a schematic diagram of the verification device.

[0028] Figure 5 This is a first flowchart illustrating the processing flow of the information processing system of this embodiment.

[0029] Figure 6 This is a second flowchart illustrating the processing flow of the information processing system of this embodiment. Detailed Implementation

[0030] Figure 1 This is a schematic diagram of the structure of the information processing system 10 according to this embodiment. The information processing system 10 includes: a user terminal 12 for use by a user; an authentication server 14, which serves as an information processing device for authenticating the user; an external authentication device 16, which authenticates the user separately from the authentication server 14; a service providing server 18, which provides services to users authenticated by the authentication server 14; and a verification device 20. Furthermore, although... Figure 1 Only one user terminal 12 is shown, but the information processing system 10 may include multiple user terminals 12 for use by multiple users. The user terminal 12, authentication server 14, external authentication device 16, service provider server 18, and verification device 20 are connected to each other in a manner that enables them to communicate with each other, for example, via communication lines 22 including Internet lines, LAN (Local Area Network), etc.

[0031] The processing flow in the information processing system 10, which is the premise of this invention, is as follows.

[0032] First, the user accesses the service provider server 18 from the user terminal 12 to receive services provided by the service provider server 18. The services provided by the service provider server 18 to the user are, for example, document management services, but are not limited to these. The service provider server 18 requests the authentication server 14 to authenticate the accessing user. Furthermore, in this embodiment, the authentication server 14 and the service provider server 18 are separate servers, but the two servers can also be integrated. That is, the authentication server 14 can also provide services.

[0033] In this embodiment, the authentication server 14 is a server that provides authentication services in place of the service provided by the service provider server 18. This authentication service authenticates users who wish to accept one or more services, including those provided by the service provider server 18. The authentication server 14 stores user information associated with pre-registered users, namely user IDs and authentication information (e.g., passwords). The authentication server 14 can also authenticate users based on user information stored on its own device; however, in this embodiment, the authentication server 14 collaborates with an external authentication device 16. When a user accepts authentication from the external authentication device 16, it can be considered that the authentication server 14 has authenticated the user. The external authentication device 16 is, for example, a server provided by Apple Inc., and the authentication collaboration service provided by the external authentication device 16 is, for example, "Sign in with Apple," but the external authentication device 16 and the authentication collaboration service are not limited to these.

[0034] The external authentication device 16 also stores the user IDs and authentication information of pre-registered users. Users input their user IDs and authentication information into the external authentication device 16, thereby obtaining authentication from the external authentication device 16. Then, the external authentication device 16 sends a message indicating successful authentication to the authentication server 14.

[0035] In this embodiment, the communication address is used as the user ID stored in the authentication server 14 and the external authentication device 16. In this embodiment, the email address is used as the communication address. In this specification, the email address registered by the user in the authentication server 14 as the user ID is referred to as "email address 0", and the email address registered by the user in the external authentication device 16 as the user ID is referred to as "email address 1" as the first communication address.

[0036] Suppose that the email address 0 registered by the user in authentication server 14 is different from the email address 1 registered by the user in external authentication device 16. The cases where email address 0 and email address 1 are different are not limited to this; for example, consider the following scenarios.

[0037] The user is an employee of a company, and the company provides the user with a company domain email address. The user uses this company domain email address as their user ID to register with authentication server 14. That is, email address 0 is a company domain email address. Additionally, a user terminal 12 is provided to the user as a portable business terminal (e.g., a smartphone). The email address primarily used on user terminal 12 is a mobile operator domain email address. The user uses this mobile operator domain email address as their user ID to register with external authentication device 16. That is, email address 1 is a mobile operator domain email address. In this hypothetical scenario, email address 0 (company domain email address) and email address 1 (mobile operator domain email address) are different from each other.

[0038] Here, the user can configure the external authentication device 16 to prevent it from notifying the authentication server 14 of email address 1. By making this setting, the external authentication device 16 will no longer arbitrarily send email address 1 to other devices involved in authentication collaboration (in this embodiment, the authentication server 14), thus protecting the privacy of email address 1. In this case, the external authentication device 16 notifies the authentication server 14 of an email address different from email address 1. This address contains information indicating successful authentication and is generated by the external authentication device 16. In this specification, this email address generated by the external authentication device 16 and notified to the authentication server 14 is referred to as "email address 2" as the second communication address. The external authentication device 16 stores email address 1 and email address 2 in association. When the authentication server 14 wants to notify the user, it sends an email (referred to simply as "email" in this specification) to email address 2, and the external authentication device 16 forwards this email to email address 1 (i.e., the user).

[0039] When a user wants to use user terminal 12 to receive services provided by service provider server 18, the user enters email address 1 into external authentication device 16 for authentication. Then, external authentication device 16 authenticates the user and sends email address 2 as the authenticated user's user ID to authentication server 14. Therefore, it can be considered that authentication server 14 authenticated the user without knowing the user's email address 1.

[0040] Here, authentication server 14 sometimes wants to verify the user's email address 1. Verification refers to the process of determining whether email address 1 meets predetermined restrictions. For example, the restrictions could be that email address 1 consists of a string that follows prescribed rules, such as "employee ID@prescribed carrier domain". Alternatively, the restrictions could be an email address belonging to a specified domain. Of course, the restrictions are not limited to these.

[0041] When email address 1 does not meet the restrictions, authentication server 14 does not allow authentication cooperation with external authentication device 16, and does not consider that authentication server 14 has authenticated the user. Therefore, it can be considered that authentication server 14 has only authenticated users who have been authenticated by external authentication device 16 through email address 1 that meets the restrictions.

[0042] If authentication server 14 is deemed to have authenticated the user, then the user is allowed to utilize authentication server 14. Here, allowing the user to utilize authentication server 14 may include notifying service provider server 18 of the information indicating that authentication server 14 has authenticated the user, thereby enabling the user to utilize services from service provider server 18. Additionally, allowing the user to utilize authentication server 14 may include enabling the user to utilize services from authentication server 14 when authentication server 14 is providing services to the user.

[0043] However, as described above, when the external authentication device 16 notifies the authentication server 14 of email address 2 instead of email address 1, the authentication server 14 cannot know email address 1 and therefore cannot verify email address 1. Therefore, in this embodiment, according to the mechanism described below, even if the external authentication device 16 does not notify the authentication server 14 of email address 1, it can be considered that the authentication server 14 only authenticated the user who accepted authentication from the external authentication device 16 through email address 1 that meets the restrictions.

[0044] Figure 2 This is a schematic diagram of the user terminal 12. As mentioned above, it is assumed that the user terminal 12 is a portable terminal such as a smartphone, but the user terminal 12 is not limited to this, for example, it can also be a fixed personal computer, etc.

[0045] The communication interface 30 may be configured to include, for example, a network adapter. The communication interface 30 performs the function of communicating with other devices via the communication line 22.

[0046] The input interface 32 may be configured to include, for example, a touch panel, buttons, a mouse, or a keyboard. The input interface 32 is used to input user instructions to the user terminal 12.

[0047] The display 34 is configured to include, for example, a liquid crystal panel. The display 34 displays various screens. Specifically, the display 34 displays a login screen provided by the authentication server 14, a login screen provided by the external authentication device 16, or a service screen provided by the service provider server 18. Additionally, the display 34 displays the execution screens of the browser 38 and the email program 40, which will be described later.

[0048] The memory 36 may be configured to include, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), an eMMC (embedded Multi Media Card), ROM (Read-Only Memory), or RAM (Random Access Memory). The memory 36 stores programs used to operate various parts of the user terminal 12. Additionally, such as... Figure 2 As shown, memory 36 stores a browser 38 and an email application 40. Browser 38 is an application that communicates with other devices via HTTP (Hypertext Transfer Protocol) and displays content obtained from other devices. Email application 40 is an application for sending and receiving emails. In this embodiment, the user uses browser 38 to access service provider server 18 and receives services from service provider server 18.

[0049] Processor 42 refers to a processor in a broad sense, comprising at least one of general-purpose processors (such as CPUs (Central Processing Units)) and dedicated processing devices (such as GPUs (Graphics Processing Units), ASICs (Application Specific Integrated Circuits), FPGAs (Field-Programmable Gate Arrays), or programmable logic devices). Processor 42 may be composed of multiple processing devices located in physically separate locations, rather than a single processing device. Processor 42 controls various parts of the user terminal 12 according to a program stored in memory 36.

[0050] Figure 3 This is a schematic diagram of the structure of authentication server 14. Authentication server 14 may be composed of, for example, a server computer, but it can be any computer as long as it can perform the functions described below. Furthermore, authentication server 14 can also be composed of multiple computers. That is, the functions performed by authentication server 14 as described below can also be achieved through the cooperation of multiple computers.

[0051] The communication interface 50 may be configured to include, for example, a network adapter. The communication interface 50 performs the function of communicating with other devices via the communication line 22.

[0052] The memory 52, as a storage device, may be configured to include, for example, HDD, SSD, eMMC, ROM, or RAM. The memory 52 stores information processing programs used to enable the various components of the authentication server 14 to function. Additionally, as... Figure 3 As shown, user DB54 and restriction information 56 are stored in memory 52.

[0053] User DB54 stores user information related to users who have registered in the authentication service provided by authentication server 14. Specifically, the user ID is stored in association with authentication information (such as a password). As mentioned above, the user ID stored in user DB54 is the user's email address 0. Users can also log in directly to authentication server 14 by entering their email address 0 and authentication information into authentication server 14.

[0054] Restriction information 56 represents restrictions that the email address of a user authenticated by authentication server 14 (i.e., authentication service) must meet. These restrictions are, for example, predetermined by the administrator of authentication server 14. When the email address used as the user ID entered in the authentication process does not meet the restrictions represented by restriction information 56, authentication server 14 does not authenticate the user. In this embodiment, as described above, when a user logs into external authentication device 16 using email address 1, it is considered that authentication server 14 has authenticated the user. Therefore, restriction information 56 can be said to represent the restrictions that the email address 1 of a user registered with external authentication device 16 must meet to allow the use of authentication server 14 through authentication cooperation with external authentication device 16.

[0055] The same restrictions can be applied uniformly to all users, or different restrictions can be applied to different users. For example, different restrictions can be set for each user, or different restrictions can be set for each user group (e.g., each enterprise, etc.). In this case, restriction information 56 is information indicating the restrictions applied to each user.

[0056] Processor 58 refers to a processor in a broad sense, and is configured to include at least one of a general-purpose processor (e.g., a CPU) and a dedicated processing device (e.g., a GPU, ASIC, FPGA, or programmable logic device). Processor 58 may be configured not as a single processing device, but as a collaboration of multiple processing devices located in physically separate locations. Processor 58 performs the functions of an authentication collaboration processing unit 60, an authentication request unit 62, and an authentication result confirmation unit 64 according to the information processing program stored in memory 52.

[0057] When the authentication collaboration processing unit 60 receives a request to authenticate a user, it first provides the user with a login screen and displays it on the display 34 of the user terminal 12 (specifically, the browser 38). As described above, in this embodiment, the request to authenticate the user is received from the service provider server 18. Specifically, when a user accesses the service provider server 18 from the browser 38, the service provider server 18 requests authentication of the user by redirecting the access from the browser 38 to the authentication server 14. Alternatively, when the authentication server 14 is integrated with the service provider server 18, the authentication server 14 may also directly receive the request to authenticate the user from the user (browser 38).

[0058] In the login screen displayed on browser 38, when a user requests external authentication by external authentication device 16, browser 38 accesses external authentication device 16. External authentication device 16 causes browser 38 to display its login screen, requests the user's email address 1 and authentication information, and authenticates the user based on the entered email address 1 and authentication information. When external authentication device 16 successfully authenticates the user, it publishes a first message indicating successful authentication and sends it to authentication server 14. For example, based on the successful authentication from external authentication device 16, this message is transmitted to authentication server 14 via browser 38 as a parameter when external authentication device 16 redirects browser 38 to authentication server 14. Conversely, when external authentication device 16 fails to authenticate the user, it sends a message indicating authentication failure to authentication server 14, which is not considered as authentication of the user by authentication collaboration processing unit 60 based on this message.

[0059] The first information sent from the external authentication device 16 to the authentication server 14 includes: email address 2, which is generated by the external authentication device 16 corresponding to email address 1; and authentication code, which is a token with a short lifespan (validity period). Thus, the authentication collaboration processing unit 60 obtains the first information indicating successful authentication issued by the external authentication device 16, which includes email address 2 generated by the external authentication device 16 corresponding to email address 1.

[0060] When the authentication collaboration processing unit 60 receives the first information from the external authentication device 16, it sends a token request to the external authentication device 16. This token request includes the authentication code contained in the first information and the email address 2, which serves as the user ID. The external authentication device 16 verifies the received token request. For example, it verifies whether the authentication code is valid and whether the user represented by email address 2 has recently been authenticated. If the token request is valid, it sends a confirmation message indicating that the token request is valid to the authentication server 14. Based on the confirmation message from the external authentication device 16, the authentication collaboration processing unit 60 determines that the user has been authenticated by the external authentication device 16.

[0061] The authentication collaboration processing unit 60 can determine from the first information that the user represented by email address 2 has been authenticated by the external authentication device 16, but it cannot determine which user registered with user DB54 the user represented by email address 2 belongs to. Therefore, the authentication collaboration processing unit 60 requests identification information from the user who initially provided the login screen. In this embodiment, the authentication collaboration processing unit 60 requests the user ID, i.e., email address 0, from the authentication server 14. The authentication collaboration processing unit 60 associates email address 0, which is the identification information received from the user, with email address 2 contained in the first information.

[0062] The verification request unit 62 requests the verification device 20 (described in detail below) to verify whether the email address 1 used by the user for authentication in the external authentication device 16 meets the restrictions indicated by the restriction information 56. Specifically, the verification request unit 62 sends a second message requesting communication with the verification device 20 to the email address 2 (i.e., the external authentication device 16) contained in the first message received from the external authentication device 16. The second message may be an email containing the email address of the verification device 20 and a text requesting the sending of an email originating from email address 1 to the email address of the verification device 20. Additionally, the second message may include text notifying the verification device 20 that email address 1 is known to the verification device 20 when an email is sent to the verification device 20.

[0063] Upon receiving the second information, the external authentication device 16 determines the email address 1 corresponding to email address 2 and forwards the second information to the determined email address 1 (i.e., user terminal 12). The user who received the second information uses the email program 40 on user terminal 12 to confirm the content of the email containing the second information, and then uses the email program 40 to send the email originating from email address 1 to the verification device 20. This will be described in detail later, but the verification device 20 obtains the email address 1 from the email originating from user terminal 12 and verifies whether email address 1 meets the restrictions represented by restriction information 56 obtained from authentication server 14. Furthermore, the verification device 20 sends information indicating the verification result to authentication server 14.

[0064] Here, if the email as secondary information includes a text notifying that email address 1 will be known to verification device 20 when an email is sent to verification device 20, then the user can send an email to verification device 20 knowing that email address 1 will be known to verification device 20. If the user does not want email address 1 to be known to verification device 20, the user can also choose not to send an email to verification device 20. In this case, authentication cooperation between authentication server 14 and external authentication device 16 is not performed, so the user needs to accept authentication from authentication server 14 through another method to accept the services provided by service provider server 18.

[0065] The verification request unit 62 can generate secret information and include the generated secret information in the second information sent to the external authentication device 16. In this case, the verification request unit 62 stores the correspondence between the generated secret information and the corresponding email address 2. The secret information is used by the verification device 20 to confirm that the email sent from the user terminal 12 is indeed an email based on a verification request from the authentication server 14. When the second information contains secret information, the second information includes information requesting that an email containing the secret information be sent to the verification device 20.

[0066] The minimum requirement for secret information is that it is unique. For example, automatically generated random data can be used as secret information. The verification device 20 (specifically, the verification unit 76 (described in detail later)) that receives second information including the secret information sends the secret information to the authentication server 14. The verification request unit 62 confirms whether the secret information received from the verification device 20 is recently generated and sends its confirmation result back to the verification device 20. If the second information received by the verification device 20 is invalid, then the secret information received by the verification request unit 62 from the verification device 20 should not be information recently generated by the verification request unit 62. Therefore, the verification device 20 can determine that the second information is invalid based on the confirmation result sent by the verification request unit 62. When the second information is invalid, the verification device 20 can choose not to perform verification processing. Furthermore, based on the secret information received from the verification device 20, the verification request unit 62 can determine that the user has sent an email to the verification device 20 for the email address 2 corresponding to the secret information.

[0067] Additionally, the secret information may also include information indicating the date and time of the collaborative processing, which represents the date and time of the authentication collaborative processing between the authentication server 14 and the external authentication device 16. The collaborative processing date and time could be, for example, the time when the first information is obtained from the external authentication device 16, or the time when the verification request unit 62 sends the second information to the external authentication device 16. Because the secret information includes the collaborative processing date and time, the verification device 20 can confirm whether the secret information is recently generated without sending it to the authentication server 14. When the collaborative processing date and time represents a time from the current point in time to a specified time prior, the verification device 20 can choose not to perform verification processing.

[0068] Alternatively, the secret information may also include identification information used to identify the user, such as the user's email address 0. In this case, email address 0 is sent from the verification device 20 to the authentication server 14 along with the verification result. Thus, the verification request unit 62 can know which user the verification device 20 verified for email address 1 without storing the correspondence between the secret information and the corresponding email address 2 (or email address 0).

[0069] Additionally, the secret information may also include restriction information 56. Since the secret information contains restriction information 56, the verification device 20 can obtain the restriction information 56 when verifying the user's email address 1 without requesting the restriction information 56 from the authentication server 14. Furthermore, when different restrictions are applied to the user and email address 0 is received from the user, the verification request unit 62 can determine the restrictions that should be applied to that user based on the received email address 0, and include restriction information 56 representing the determined restrictions in the secret information. Thus, the verification device 20 can verify whether the user's email address 1 meets the restrictions corresponding to that user.

[0070] In addition, secret information may also include signature information, which is used to prevent tampering with the secret information.

[0071] The verification result confirmation unit 64 obtains the verification result from the verification device 20 regarding whether the user's email address 1 meets the restriction information 56. When the verification result indicates that the email address 1 meets the restriction information 56, the verification result confirmation unit 64 performs control, allowing the authentication server 14 to cooperate with the external authentication device 16 for authentication. That is, it is considered that the authentication server 14 has authenticated the user, and the verification result confirmation unit 64 notifies the service provider server 18 that the user has been authenticated. As a result, the service provider server 18 can provide services to the user.

[0072] Furthermore, when the verification result indicates that email address 1 meets the restriction information 56, the verification result confirmation unit 64 registers information indicating that the user's email address 0 corresponds to the email address 2 notified by the external authentication device 16 in the memory 52. ​​Therefore, even when the user has already passed external authentication, the authentication server 14 can identify the user based on email address 2 without individually requesting email address 0 from the user. For example, the authentication server 14 can grant the user appropriate permissions based on email address 2.

[0073] On the other hand, when the verification result indicates that email address 1 does not meet the restriction information 56, the verification result confirmation unit 64 performs control, disallowing authentication server 14 from collaborating with external authentication device 16. That is, even if the external authentication device 16 authenticates the user, it is not considered that authentication server 14 has authenticated the user. In this case, since authentication collaboration between authentication server 14 and external authentication device 16 is not performed, the user needs to undergo authentication by authentication server 14 through another method in order to receive the services provided by service provider server 18.

[0074] Figure 4 This is a schematic diagram of the verification device 20. The verification device 20 can be, for example, a server computer, but can be any computer as long as it can perform the functions described below. In this embodiment, the verification device 20 is separate from the authentication server 14, but the verification device 20 can also be integrated with the authentication server 14. When the verification device 20 is separate from the authentication server 14, the verification device 20 can be managed by a third-party organization independent of the authentication server 14. As described above, since the verification device 20 obtains the email address 1 that the user prohibits the external authentication device 16 from notifying the authentication server 14, it is preferable to use an organization trusted by the user as the third-party organization managing the verification device 20. For example, this third-party organization can be a public organization.

[0075] The communication interface 70 may be configured to include, for example, a network adapter. The communication interface 70 performs the function of communicating with other devices via the communication line 22.

[0076] The memory 72 may be configured to include, for example, an HDD, SSD, eMMC, ROM, or RAM. The memory 72 stores programs for enabling the various parts of the verification device 20 to function.

[0077] Processor 74 refers to a processor in a broad sense, and is configured to include at least one of a general-purpose processor (e.g., a CPU) and a dedicated processing device (e.g., a GPU, ASIC, FPGA, or programmable logic device). Processor 74 may be configured not as a single processing device, but as a collaboration of multiple processing devices located in physically separate locations. Processor 74 performs the functions of a verification unit 76 and a verification result providing unit 78 according to the program stored in memory 72.

[0078] The verification unit 76 obtains the user's email address 1 from the source address of the email sent by the user who received the second information. Additionally, the verification unit 76 receives restriction information 56 from the authentication server 14. As described above, the verification unit 76 can obtain the restriction information 56 by accessing the authentication server 14, or it can obtain the restriction information 56 contained in the second information. Based on this, the verification unit 76 verifies whether email address 1 meets the restrictions indicated by the restriction information 56.

[0079] In addition, the verification unit 76 verifies the secret information contained in the email received from the user. The verification of the secret information has been described above, therefore a repetition is omitted here.

[0080] The verification unit 76 can also refer to the forwarding path information contained in the attribute information (features) of the email received from the user, which indicates the forwarding path of the email, and determine the validity of email address 1 based on the forwarding path of the email. For example, when the email is sent to the verification device 20 via servers in multiple countries, the verification unit 76 can determine that email address 1 is invalid.

[0081] The verification result providing unit 78 provides the verification result of the verification unit 76 for email address 1 to the authentication server 14. Additionally, when the verification unit 76 determines the validity of email address 1 based on the email forwarding path, the verification result providing unit 78 also provides that determination result to the authentication server 14. When the verification result confirmation unit 64 of the authentication server 14 receives this determination result from the verification result providing unit 78, if the determination result indicates that email address 1 is invalid, authentication cooperation with the external authentication device 16 for that user is not permitted, and the authentication server 14 is not considered to have authenticated that user.

[0082] The structure of the information processing system 10 in this embodiment is summarized as described above. As described above, in the information processing system 10, when the external authentication device 16 authenticates a user, it sends first information indicating successful authentication and including the user's email address 2 to the authentication server 14. The authentication server 14's verification request unit 62 sends second information to email address 2 (i.e., the external authentication device 16) requesting communication with the authentication device 20. The external authentication device 16 forwards the second information to email address 1 (i.e., the user). Based on the second information, the user sends an email originating from email address 1 to the authentication device 20. Thus, the authentication device 20 obtains email address 1. The authentication device 20 verifies whether email address 1 meets the restrictions indicated by restriction information 56 and sends the verification result to the authentication server 14. By performing this process, even if notification of email address 1 from the external authentication device 16 to the authentication server 14 is prohibited, the authentication server 14 can still confirm whether the user's email address 1 meets the restrictions.

[0083] The following is in accordance with Figure 5 and Figure 6 The flowchart shown illustrates the processing flow of the information processing system 10.

[0084] exist Figure 5 In step S10, the user accesses the service provider server 18 from the browser 38 of the user terminal 12 in order to utilize the services provided by the service provider server 18.

[0085] In step S12, the service provider server 18 requests the authentication server 14 to authenticate the user and redirects the access from the user to the authentication server 14.

[0086] In step S14, the redirected browser 38 accesses the authentication server 14 to make an authentication request.

[0087] In step S16, the authentication collaboration processing unit 60 of the authentication server 14, which receives the authentication request from the browser 38, causes the browser 38 to display the login screen of the authentication server 14. On this login screen, the user can select external authentication.

[0088] In step S18, the user specifies external authentication in the login screen displayed in step S16. As a result, browser 38 accesses external authentication device 16.

[0089] In step S20, the external authentication device 16 causes the browser 38 to display the login screen of the external authentication device 16.

[0090] In step S22, the user enters the user ID (i.e., the email address 1 already registered in the external authentication device 16) and authentication information in the login screen displayed in step S20 to log in to the external authentication device 16.

[0091] In step S24, the external authentication device 16 authenticates the user based on the email address 1 and authentication information entered in step S22. Here, it is assumed that authentication is successful. When authentication is successful, the external authentication device 16 redirects the browser 38 to the authentication server 14. As a parameter at this time, the external authentication device 16 sends first information indicating successful authentication to the authentication server 14 via the browser 38. This first information includes the email address 2 corresponding to the entered email address 1 and the authentication code.

[0092] In step S26, the authentication collaboration processing unit 60 of the authentication server 14 sends a token request to the external authentication device 16. The token request includes the authentication code and email address 2 obtained in step S24.

[0093] In step S28, the external authentication device 16 verifies the token request received in step S26. Here, assuming the token request is valid, the external authentication device 16 sends a confirmation message indicating that the token request is valid to the authentication server 14.

[0094] In step S30, the authentication collaboration processing unit 60 of the authentication server 14 confirms that the user has been authenticated in the external authentication device 16.

[0095] In step S32, the authentication collaboration processing unit 60 of the authentication server 14 queries the user who received the authentication request in step S14 for the user ID, i.e., email address 0, in the authentication server 14.

[0096] In step S34, in response to the query from authentication server 14 in step S32, the user sends email address 0 to authentication server 14. The authentication collaboration processing unit 60 saves the email address 2 obtained in step S24 in association with the email address 0 obtained in step S34.

[0097] exist Figure 6 In step S36, the authentication request unit 62 of the authentication server 14 sends a second message to the email address 2 (i.e., the external authentication device 16) requesting to communicate with the authentication device 20. The second message includes the email address of the authentication device 20 and the aforementioned secret information.

[0098] In step S38, the external authentication device 16 forwards the second information to email address 1 (i.e., user terminal 12) corresponding to email address 2 received in step S36.

[0099] In step S40, based on the second information received in step S38, the user uses email program 40 to send an email containing secret information to the email address of verification device 20, using the email address of the sending source as email address 1.

[0100] In step S42, the verification unit 76 of the verification device 20 obtains email address 1 from the sender address of the email received in step S40. Additionally, as described above, the verification unit 76 verifies the secret information contained in the email.

[0101] In step S44, the verification unit 76 verifies whether the email address 1 obtained in step S40 meets the restrictions indicated by the restriction information 56. Here, as described above, the verification device 20 may access the authentication server 14 to obtain the restriction information 56, or the restriction information 56 may be contained within the secret information. Furthermore, the verification unit 76 refers to the forwarding path information, which indicates the forwarding path of the email received in step S40, and determines the validity of the email address 1 based on the forwarding path of the email.

[0102] In step S46, the verification result providing unit 78 of the verification device 20 sends the verification result of email address 1 and the determination result of the validity of email address 1 from step S44 to the authentication server 14.

[0103] In step S48, the verification result confirmation unit 64 of the authentication server 14 confirms the verification result and the validity determination result of email address 1 received in step S46. Here, the verification result of email address 1 indicates that email address 1 meets the restrictions indicated by restriction information 56, and the validity determination result of email address 1 indicates that email address 1 is valid. Therefore, the verification result confirmation unit 64 allows the authentication server 14 to cooperate with the external authentication device 16, and considers that the authentication server 14 has authenticated the user.

[0104] In step S50, the verification result confirmation unit 64 stores the email address 0 and email address 2, which were saved by the authentication collaboration processing unit 60 in step S34, in memory 52 in association.

[0105] In step S52, the authentication collaboration processing unit 60 of the authentication server 14 redirects the browser 38 to the service provider server 18. Along with this redirection, the authentication collaboration processing unit 60 sends information to the service provider server 18 indicating that the user has been authenticated to the service provider server 18. Thus, the service provider server 18 can provide services to the user.

[0106] In addition, when the verification result of email address 1 in step S48 indicates that email address 1 does not meet the restrictions indicated by restriction information 56, or when the validity determination result of email address 1 indicates that email address 1 is invalid, the verification result confirmation unit 64 does not allow the authentication server 14 to cooperate with the external authentication device 16 for authentication, does not consider the authentication server 14 to have authenticated the user, and ends the process without executing the processes of steps S50 and S52.

[0107] The embodiments of the present invention have been described above, but the present invention is not limited to the above embodiments, and various modifications can be made without departing from the spirit of the present invention.

Claims

1. An information processing device, comprising: Storage devices and processors The storage device stores restriction information indicating the limitations that a user's first communication address, registered with the external authentication device in order to cooperate with the external authentication device for authentication and obtain permission to use the information processing device, must meet. The processor The system obtains first information indicating successful authentication of the user, published by the external authentication device. This first information includes a second communication address generated by the external authentication device corresponding to the first communication address. Send a second message to the second communication address contained in the first message, requesting communication with the designated verification device. The verification device obtains a verification result indicating whether the sending source of the communication based on the second information, i.e., the first communication address, meets the restriction. When the verification result indicates that the first communication address does not meet the restriction, control is executed to prevent the user from authenticating with the external authentication device.

2. The information processing apparatus according to claim 1, wherein, The system also receives a determination result from the verification device regarding the validity of the first communication address based on the forwarding path of the communication from the user. If the determination result indicates that the first communication address is invalid, authentication cooperation between the user and the external authentication device is not permitted.

3. The information processing apparatus according to claim 1 or 2, wherein, The processor provides at least a portion of the restriction information to the verification device. The verification device determines whether the first communication address meets the restrictions indicated by the restriction information provided by the processor, and provides its determination result to the processor.

4. The information processing apparatus according to claim 3, wherein, The processor After obtaining the first information, the system receives the identification information input by the user in the information processing device. The restriction information, which is determined based on the received identification information and indicates the restriction that should be applied to the user, is provided to the verification device.

5. The information processing apparatus according to claim 1 or 2, wherein, The processor After obtaining the first information, the system receives the identification information input by the user in the information processing device. When the verification result indicates that the first communication address meets the restriction, authentication cooperation between the user and the external authentication device is allowed, and information indicating that the second communication address corresponds to the identification information is registered.

6. A storage medium for storing an information processing program that causes a computer equipped with storage devices for storing restriction information representing restrictions that a first communication address of a user registered with an external authentication device for authentication cooperation to obtain a license to use the information processing device must meet, to perform the following actions: The system obtains first information indicating successful authentication of the user, published by the external authentication device. This first information includes a second communication address generated by the external authentication device corresponding to the first communication address. Send a second message to the second communication address contained in the first message, requesting communication with the designated verification device. The verification device obtains a verification result indicating whether the sending source of the communication based on the second information, i.e., the first communication address, meets the restriction. When the verification result indicates that the first communication address does not meet the restriction, control is executed to disallow authentication cooperation between the user and the external authentication device.

Citation Information

Patent Citations

  • Management device, management system and program

    JP2020038438A

  • User account management method and system

    CN103916400A

  • Authentication method and system and proxy server

    CN106131079A