Authentication system, authentication method, and program

By obtaining the terminal's phone number and fingerprint information, and sending SMS to obtain the fingerprint information of the connection source for consistency confirmation, the problem of authentication agents in SMS authentication is solved, and a safer authentication process is achieved.

CN120303656APending Publication Date: 2025-07-11菱沼升 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280102303.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

It is difficult to prevent authentication proxy behavior in existing SMS authentication, and users can pass the authentication without using their own terminal.

Method used

通过获取终端的电话号码和指纹信息,发送包含访问信息的SMS,获取连接源的指纹信息,并在一致性确认后进行认证。

Benefits of technology

Effectively prevent improper behavior of using telephone numbers for authentication and ensure the legality and security of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120303656A_ABST
    Figure CN120303656A_ABST
Patent Text Reader

Abstract

A telephone number acquisition unit (101) acquires, from a terminal (30) to be authenticated, a telephone number of the terminal (30). A first FP acquisition unit (102) acquires a first FP specifying a terminal (30). A short message service (SMS) transmission unit (201) transmits, to the telephone number acquired by the telephone number acquisition unit (101), an SMS (short message service) in which a URL for connection to an authentication device (20) is recorded, and transmits the SMS to the telephone number acquired by the telephone number acquisition unit (101). A second FP acquisition unit (202) acquires a second FP that specifies a connection source to which a connection is performed by means of a URL. The authentication unit (203) authenticates the terminal (30) by confirming that the first FP matches the second FP.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system, an authentication method, and a program. Background Art

[0002] It has become widespread that users use services such as online banking, online shopping, and online transactions via terminals such as smartphones and mobile phones. In order to use such services, users need to undergo authentication.

[0003] In recent years, authentication has been performed using a telephone number set in a smartphone, a mobile phone, or the like. For example, Non-Patent Document 1 describes an SMS authentication in which a short message (hereinafter referred to as SMS (Short Message Service)) is sent to a smartphone, and the confirmation code described in the SMS is input on the network (Web) to perform personal authentication. Since telephone subscription generally requires personal confirmation with a communication carrier, a user who has a telephone number can be regarded as a user who has completed personal confirmation. Therefore, compared with authentication based on a password or the like, in authentication using a telephone number such as SMS authentication, it is possible to expect an effect of preventing improper acts such as impersonation.

[0004] Prior Art Documents

[0005] Non-Patent Documents

[0006] Non-Patent Document 1: What is SMS authentication? Mechanism, introduction method for strengthening personal confirmation (What is SMS authentication? Mechanism, introduction method for strengthening personal confirmation), Aspic, [Online, retrieved on October 13, 2022], Internet, <URL: https: / / www.aspicjapan.org / asu / article / 4367> Summary of the Invention

[0007] Problems to be Solved by the Invention

[0008] In the above SMS authentication, it is difficult to prevent improper acts such as authentication agency. In this authentication agency, an SMS containing a confirmation code is sent to the terminal of the authentication agent, and the authentication agent conveys the confirmation code described in the SMS to the user, whereby the user can pass the authentication without using the telephone number set in his or her own terminal.

[0009] In view of the above actual situation, the present invention has been completed, and an object thereof is to provide an authentication system or the like that can prevent improper acts in authentication using a telephone number.

[0010] Means for Solving the Problems

[0011] To achieve the above object, the authentication system of the present invention includes:

[0012] A telephone number acquisition unit that acquires a telephone number from a terminal to be authenticated;

[0013] A first determination information acquisition unit that acquires first determination information for determining the terminal;

[0014] An SMS sending unit that sends an SMS (Short Message Service) to the telephone number acquired by the telephone number acquisition unit, where the SMS records access information for connecting to the present system;

[0015] A second determination information acquisition unit that acquires second determination information for determining a connection source that connects through the access information; and

[0016] An authentication unit that authenticates the terminal by confirming that the first determination information and the second determination information are consistent.

[0017] Advantages of the Invention

[0018] According to the present invention, improper behavior in authentication using a telephone number can be prevented. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 FIG. is a diagram showing a configuration example of an authentication system according to Embodiment 1 and Embodiment 2 of the present invention.

[0020] Figure 2 FIG. is a block diagram showing a configuration example of a service providing apparatus according to Embodiment 1 and Embodiment 2 of the present invention.

[0021] Figure 3 FIG. is a diagram showing a configuration example of a customer DB according to Embodiment 1 and Embodiment 2 of the present invention.

[0022] Figure 4 FIG. is a block diagram showing a configuration example of an authentication apparatus according to Embodiment 1 and Embodiment 2 of the present invention.

[0023] Figure 5 FIG. is a diagram showing a configuration example of an authentication DB according to Embodiment 1 of the present invention.

[0024] Figure 6 FIG. is a diagram showing a configuration example of a terminal DB according to Embodiment 1 of the present invention.

[0025] Figure 7 FIG. is a block diagram showing a configuration example of a terminal according to Embodiment 1 and Embodiment 2 of the present invention.

[0026] Figure 8 FIG. is a functional configuration diagram of an authentication system according to Embodiment 1 of the present invention.

[0027] Figure 9 It is a flowchart (Part 1) showing an example of member registration processing according to Embodiment 1 of the present invention.

[0028] Figure 10 It is a flowchart (Part 2) showing an example of member registration processing according to Embodiment 1 of the present invention.

[0029] Figure 11 It is a flowchart (Part 3) showing an example of member registration processing according to Embodiment 1 of the present invention.

[0030] Figure 12 It is a diagram showing an example of a telephone number input interface according to Embodiment 1 of the present invention.

[0031] Figure 13 It is a diagram showing an example of the URL described in the SMS according to Embodiment 1 of the present invention.

[0032] Figure 14 It is a diagram showing an example of the SMS according to Embodiment 1 of the present invention.

[0033] Figure 15 It is a flowchart showing an example of login processing according to Embodiment 1 of the present invention.

[0034] Figure 16 It is a diagram showing an example of a login screen according to Embodiment 1 of the present invention.

[0035] Figure 17 It is a diagram showing a configuration example of an authentication DB according to Embodiment 2 of the present invention.

[0036] Figure 18 It is a diagram showing a configuration example of a terminal DB according to Embodiment 2 of the present invention.

[0037] Figure 19 It is a functional configuration diagram of an authentication system according to Embodiment 2 of the present invention.

[0038] Figure 20 It is a flowchart (Part 1) showing an example of member registration processing according to Embodiment 2 of the present invention.

[0039] Figure 21 It is a flowchart (Part 2) showing an example of member registration processing according to Embodiment 2 of the present invention.

[0040] Figure 22 It is a flowchart (Part 3) showing an example of member registration processing according to Embodiment 2 of the present invention.

[0041] Figure 23 It is a diagram showing an example of a telephone number input screen according to Embodiment 2 of the present invention.

[0042] Figure 24 This is a diagram showing an example of a voice input screen for Embodiment 2 of the present invention.

[0043] Figure 25 This is a functional block diagram of an authentication system which is a modification example of Embodiment 2 of the present invention.

[0044] Figure 26 This is a flowchart (Part 1) showing an example of member registration processing which is a modification example of Embodiment 2 of the present invention.

[0045] Figure 27 This is a flowchart (Part 2) showing an example of member registration processing which is a modification example of Embodiment 2 of the present invention.

[0046] Figure 28 This is a diagram showing an example of a voice input screen for a modification example of Embodiment 2 of the present invention. Detailed Embodiments

[0047] Hereinafter, each embodiment of the present invention will be described in detail with reference to the accompanying drawings. It should be noted that in the drawings, the same or equivalent parts are denoted by the same reference numerals.

[0048] (Embodiment 1)

[0049] Figure 1 This is a diagram showing the overall configuration of the authentication system 1 according to Embodiment 1 of the present invention. The authentication system 1 includes a service providing device 10 and an authentication device 20. The service providing device 10 is connected to the terminal 30 via the Internet N1. The authentication device 20 is connected to the terminal 30 via the telephone network N2, and is also connected to the service providing device 10 and the terminal 30 via the Internet N1.

[0050] The service providing device 10 is a Web server that provides various services to users via the Internet N1. The "services" mentioned here are, for example, online banking, online shopping, online transactions, electronic ticketing systems, etc. that use the Internet N1. To use the services, the user downloads a dedicated application to the terminal 30, or accesses a dedicated website for using the services through a web browser. When using the services for the first time, the user needs to execute the application downloaded to the terminal 30, and register the user ID, password, etc. (member registration) from the application screen or the browser screen in the customer DB (database) 121 described later. It should be noted that the service providing device 10 may be composed of one computer or multiple computers.

[0051] Next, the structure of the service providing device 10 will be described. As Figure 2 shown, the service providing device 10 includes: a data communication unit 11, a storage unit 12, and a control unit 13.

[0052] Under the control of the control unit 13, the data communication unit 11 performs data communication with the terminal 30 and the authentication device 20 via the Internet N1.

[0053] The storage unit 12 is a hard disk drive or the like, and stores various data required for the operation of the service providing device 10. For example, the storage unit 12 stores a customer DB 121.

[0054] The customer DB 121 stores information related to users who can use the services provided by the service providing device 10. Specifically, as Figure 3 shown, the customer DB 121 stores a user ID, a password, a terminal phone number, a name, an address, etc. for each user who can use the service. The user ID stored in the customer DB 121 is information that uniquely identifies the user. The password stored in the customer DB 121 is the password required for the user to log in to the service. To log in to the service, the user needs to register at least the user ID and password in the customer DB 121. The terminal phone number stored in the customer DB 121 is the phone number set in the terminal 30 owned by the user. The customer DB 121 may also be stored in an external server or the like that can be accessed by the service providing device 10.

[0055] Returning to Figure 2 , the control unit 13 includes a CPU (Central Processing Unit), a ROM (ReadOnly Memory), a RAM (Random Access Memory), etc. (all not shown). The CPU uses the RAM as a working memory and controls the entire service providing device 10 by appropriately executing various programs stored in the ROM and the storage unit 12.

[0056] Returning to Figure 1 , the authentication device 20 will be described. The authentication device 20 authenticates whether the terminal 30 accessing the service providing device 10 is legitimate. The authentication device 20 may be composed of one computer or multiple computers.

[0057] Next, the configuration of the authentication device 20 will be described. As Figure 4 shown, the authentication device 20 includes a telephone communication unit 21, a data communication unit 22, a storage unit 23, and a control unit 24.

[0058] Under the control of the control unit 24, the telephone communication unit 21 performs the sending and receiving of SMS and telephone communication based on the SIP (Session Initiation Protocol) standard with the terminal 30 via the telephone network N2. Under the control of the control unit 24, the data communication unit 22 communicates with the service providing device 10 via the Internet N1.

[0059] The storage unit 23 is, for example, a hard disk drive or the like, and stores various data required for the operation of the authentication device 20. For example, the storage unit 23 stores an authentication DB 231 and a terminal DB 232.

[0060] The authentication DB 231 is a database that temporarily stores information referred to in the member registration process described later. Specifically, as Figure 5 shown, in the authentication DB 231, the terminal telephone number, OTP (One Time Password), the first FP (fingerprint), and the registration date and time information indicating the date and time when these information are registered in the authentication DB 231 are stored in a corresponding manner.

[0061] The terminal telephone number stored in the authentication DB 231 is the telephone number obtained from the terminal 30 that has requested authentication from the service providing device 10. The terminal telephone number is the key of the authentication DB 231, and no entry with the same terminal telephone number will be registered in the authentication DB 231. The SMS for user authentication is sent to this terminal telephone number.

[0062] The OTP stored in the authentication DB 231 is a one-time password such as a random number generated each time authentication is performed. The OTP is the information notified by SMS sent to the terminal telephone number.

[0063] The first FP (fingerprint) stored in the authentication DB 231 is identification information for uniquely identifying the terminal 30 that has requested authentication from the service providing device 10. The first FP is obtained by hashing multiple unchangeable attribute values of the terminal 30. For example, "Fingerprintjs2" in the JavaScript library can be used to obtain the terminal FP.

[0064] Returning to Figure 4 , the terminal DB 232 is a database that stores information related to the terminal 30 that has completed authentication in the member registration process described later. The terminal DB 232 is referred to when a user who has been registered as a member in the member registration process operates the terminal 30 to log in to the application. As Figure 6 shown, in the terminal DB 232, the telephone number (terminal telephone number) of the terminal 30 that has completed authentication in the member registration process, the terminal ID of the terminal 30, and the registration date and time information indicating the date and time when these information are registered in the terminal DB 232 are stored in a corresponding manner. The terminal ID is authentication information generated to uniquely identify the terminal. For example, it is information obtained by combining a random number and date and time information and hashing them. The terminal DB 232 is an example of the authentication information storage unit of the present invention.

[0065] Return to Figure 4 The control unit 24 includes a CPU, a ROM, a RAM, etc. (all not shown). The CPU uses the RAM as a working memory and controls the entire authentication device 20 by appropriately executing various programs stored in the ROM and the storage unit 23.

[0066] Return to Figure 1 Next, the terminal 30 will be described. The terminal 30 is, for example, a smart phone used by a user. The terminal 30 is connected to the authentication device 20 via the telephone network N2 in a manner enabling telephone communication. In addition, the terminal 30 is connected to the service providing device 10 and the authentication device 20 via the Internet N1 in a manner enabling data communication. As Figure 7 shown, the terminal 30 includes a telephone communication unit 31, a data communication unit 32, an input unit 33, a display unit 34, a storage unit 35, a control unit 36, a microphone 37, and a speaker 38.

[0067] The telephone communication unit 31 performs telephone communication or SMS transmission / reception with the authentication device 20 via the telephone network N2 under the control of the control unit 36. The data communication unit 32 communicates with the service providing device 10 via the Internet N1 under the control of the control unit 36.

[0068] The input unit 33 is a touch panel, various buttons, etc., and is used to input various information into the terminal 30. For example, when the user first uses the service, the input unit 33 is operated to input the telephone number of the terminal 30.

[0069] The display unit 34 is, for example, a liquid crystal display, etc., and outputs various information under the control of the control unit 36. For example, when the service is first used, the display unit 34 displays a telephone number input screen for inputting the telephone number of the terminal 30, etc.

[0070] The storage unit 35 is, for example, a hard disk drive, a flash memory, and stores various data and programs required for the operation of the terminal 30. For example, the storage unit 35 stores programs of applications for using the services provided by the service providing device 10, etc. In addition, when the authentication is successful in the member registration process described later, the terminal ID of the terminal 30 is stored in the storage unit 35.

[0071] The control unit 36 includes a CPU, a ROM, and a RAM, etc. (all not shown). The CPU uses the RAM as a working memory and controls the entire terminal 30 by appropriately executing various programs stored in the ROM and the storage unit 35.

[0072] The microphone 37 picks up the sound emitted from the user, converts it into an electrical signal, and outputs it to the control unit 36. The speaker 38 reproduces various sounds based on the control of the control unit 36.

[0073] Next, with reference to Figure 8The functional configuration of the authentication system 1 according to Embodiment 1 of the present invention will be described. The service providing device 10 includes a telephone number acquisition unit 101, a first FP acquisition unit 102, and a service providing unit 103 as functional configurations. These units are realized by the cooperation of the data communication unit 11, the storage unit 12, and the control unit 13 of the service providing device 10.

[0074] The authentication device 20 includes an SMS sending unit 201, a second FP acquisition unit 202, and an authentication unit 203 as functional configurations. These units are realized by the cooperation of the telephone communication unit 21, the data communication unit 22, the storage unit 23, and the control unit 24 of the authentication device 20.

[0075] The telephone number acquisition unit 101 acquires the telephone number (terminal telephone number) of the terminal 30 from the terminal 30 of the user who is to perform member registration. The telephone number acquisition unit 101 is an example of the telephone number acquisition unit of the present invention.

[0076] The first FP acquisition unit 102 acquires the FP (hereinafter, the first FP) from the terminal 30 from which the telephone number has been acquired. In addition, the first FP acquisition unit 102 sends the terminal telephone number and the terminal FP to the authentication device 20 to request authentication. The first FP acquisition unit 102 is an example of the first determination information acquisition unit of the present invention.

[0077] The SMS sending unit 201 generates a one-time password (OTP), and sends an SMS for notifying the OTP to the terminal telephone number. The OTP records the access information, i.e., the URL, for accessing the present system (authentication device 20). The SMS sending unit 201 is an example of the SMS sending unit of the present invention.

[0078] The second FP acquisition unit 202 acquires the FP (hereinafter, the second FP) of the connection source (if appropriate, the terminal 30 that has requested authentication) that is connected through the URL described in the SMS sent by the SMS sending unit 201. The second FP acquisition unit 202 is an example of the second determination information acquisition unit of the present invention.

[0079] The authentication unit 203 authenticates the terminal 30 that has requested member registration by confirming the consistency between the first FP and the second FP. In addition, when authenticating the terminal 30 for the second time and later, the authentication unit 203 confirms that the terminal ID of the terminal 30 is stored in the terminal DB 232 for authentication. The authentication unit 203 is an example of the authentication unit of the present invention.

[0080] When the authentication unit 203 completes the authentication of the terminal 30, the service providing unit 103 performs various processes (for example, member registration, login, etc.) for providing services to the terminal 30.

[0081] Next, use Figures 9 - 11 the flowchart of Figures 9 - 11 to explain the actions of the membership registration process for registering the user's ID, password, etc. as a member who can use the service when the user first uses the service provided by the service providing device 10 in the authentication system 1.

[0082] The user operates the input unit 33 of his / her own terminal 30 to access a specific website, thereby downloading an application for using the service provided by the service providing device 10. And, when the user operates the input unit 33 of the terminal 30 and first starts the downloaded application, the membership registration process is executed.

[0083] First, the control unit 36 of the terminal 30 causes the display unit 34 to display Figure 12 the telephone number input screen shown in Figure 12 (step S101). The user operates the input unit 33, enters the telephone number of the terminal 30 (hereinafter, also referred to as the terminal telephone number) in the input field of the displayed telephone number input interface, and clicks the confirmation button. In response to this operation, the control unit 36 of the terminal 30 acquires the FP (first FP) of the terminal 30 (step S102).

[0084] Next, the control unit controls the data communication unit 32 to send a membership registration request including the acquired first FP and the terminal telephone number input in the telephone number input screen to the service providing device 10 (step S103).

[0085] When receiving the membership registration request, the control unit 13 of the service providing device 10 confirms that an entry having the terminal telephone number included in the membership registration request is not registered in the customer DB 121 (step S104). In the case where such an entry has been registered, there is a possibility of duplicate registration, so the process ends as an error.

[0086] After the confirmation in step S104 is completed, the control unit 13 sends the terminal telephone number and the first FP received from the terminal 30 to the authentication device 20 to request terminal authentication (step S105).

[0087] The control unit 24 of the authentication device 20 that has received the authentication request generates a one-time password (hereinafter, OTP) by generating a random number, etc. And, the control unit 24 registers the received terminal telephone number, terminal FP, and the generated OTP in a corresponding manner in the authentication DB 231 (step S107).

[0088] Next, the control unit 24 creates a URL that includes the generated OTP in the parameter for accessing the authentication device 20 (step S108). An example of the URL created in step S108 is shown in Figure 13。And the control unit 24 sends an SMS containing the created URL to the terminal phone number (step S109).

[0089] As Figure 14 shown, the SMS received from the authentication device 20 is displayed on the display unit 34 of the terminal 30 (step S110). The user clicks on the URL recorded in the SMS via the input unit 33. In response to this, the control unit 36 connects to the authentication device 20, which is the connection destination indicated by the clicked URL, via the Internet N1, and sends the OTP included in the parameters of the URL to the authentication device 20 (step S111).

[0090] The control unit 13 of the authentication device 20 confirms that the entry having the OTP received from the connected terminal 30 is registered in the authentication DB 231 (step S112). Thereby, it is confirmed that the connection is from the terminal 30 that sent the SMS. It should be noted that, in the case where it is not registered, the process ends as an authentication error.

[0091] Next, the control unit 13 requests the connected terminal to obtain the FP (step S113). The control unit of the terminal that has received this request obtains the FP (second FP), which is its own identification information, and sends it to the authentication device 20 (step S115).

[0092] When the second FP is received, the control unit 24 of the authentication device 20 confirms that the first FP registered in the authentication DB 231 in step S107 is consistent with the second FP received from the authentication device (step S116). Thereby, it can be confirmed that the terminal 30, which is the acquisition source of the phone number for which authentication has been requested, is the same as the destination of the SMS, and thus authentication of the terminal 30 is completed. It should be noted that, in the case where the consistency cannot be confirmed, the process ends as an authentication error.

[0093] Next, the control unit 24 generates a terminal ID (step S117). The terminal ID is authentication information used for authentication of the terminal 30 in the second and subsequent times. For example, the control unit 24 may generate information such as a combination of a random number and date-time information as the terminal ID. Alternatively, the control unit 24 may also generate the fingerprint (first FP) of the terminal 30 received from the service providing device 10 as the terminal ID.

[0094] Further, the control unit 24 performs a process for causing the connected terminal 30 to store the generated terminal ID. Specifically, the control unit 24 sends the generated terminal ID to the connected terminal 30 and instructs the terminal 30 to store the terminal ID (step S118). The control unit 24 that performs the process of step S118 is an example of the terminal authentication information storage unit of the present invention. The control unit 36 of the terminal that receives the instruction from the authentication device 20 stores the received terminal ID in the storage unit 35 (step S119). It should be noted that, at this time, ideally, the control unit 36 stores the terminal ID in an area of the storage unit 35 that is inaccessible or difficult for the user to access. Further, the control unit 24 of the authentication device 20 newly stores the created terminal ID and the terminal telephone number in a corresponding manner in the terminal DB 232 (step S120).

[0095] Next, the control unit 24 notifies the service providing device 10 of the intention to complete the authentication of the terminal 30 (step S121). The control unit 13 of the service providing device 10 that receives this notification sends the screen data of the membership registration screen to the terminal 30 and instructs to display the membership registration screen (step S122). Thereby, the membership registration screen is displayed on the display unit 34 of the terminal 30 (step S123). It should be noted that the screen data of the membership registration screen may be stored in advance in the storage unit 35 of the terminal 30, and in step S121, only an instruction to display the membership registration screen is given.

[0096] The user of the terminal 30 performs the following operations: operating the input unit 33, inputting information required for membership registration (for example, user ID, password, name, address, etc.) from the membership registration screen, and determining the input information. In response to this operation, the control unit 36 of the terminal 30 sends the information input to the membership registration screen to the service providing device 10 (step S124).

[0097] The control unit 13 of the service providing device 10 registers the information received from the terminal 30 in the customer DB 121 (step S125). Through the above, the membership registration process ends. Through the membership registration process, the user performs membership registration, and thereafter, can use the services provided by the service providing device 10 by executing the application and logging in.

[0098] Next, with reference to Figure 15 the flowchart, the login process will be described, in which a user who has performed membership registration in the service provided by the service providing device 10 through the above membership registration process logs in to the service from the terminal 30.

[0099] When a user who has completed the membership registration process operates the input unit 33 of his own terminal 30 to start the application of the service provided by the service providing device 10, the login process is executed.

[0100] First, the control unit 36 of the terminal 30 causes the display unit 34 to display Figure 16 the login screen shown (step S201). The user operates the input unit 33, inputs their own ID and password registered in the membership registration process to the login screen, and clicks the login button. In response to this operation, the control unit 36 of the terminal 30 sends the terminal ID of this terminal 30, the input user ID, and the password stored in the storage unit 35 to request login from the service providing device 10 (step S202).

[0101] The control unit 13 of the service providing device 10 that has received the login request confirms that an entry with a group of the received user ID and password has been registered in the customer DB121 (step S203). If such a group is not registered, the user ID or password entered by the user is incorrect, and the process ends as an error.

[0102] When an entry with a group of the received user ID and password is confirmed in the customer DB121, the control unit 13 obtains the terminal phone number included in this entry (step S204). And the control unit 13 sends the terminal ID obtained from the terminal 30 and the obtained terminal phone number to the authentication device 20 to request authentication (step S205).

[0103] The control unit 24 of the authentication device 20 that has received the authentication request confirms that the received terminal ID and terminal phone number are registered in the terminal DB232 in a corresponding manner (step S206). If it is not registered in the terminal DB232, it is considered a login from a device other than the terminal 30 that has received the authentication in the above membership registration process, so the process ends as an error.

[0104] When the registration in the terminal DB232 is confirmed in step S206, the control unit 24 notifies the service providing device 10 that the authentication has been completed (step S207). The control unit 13 of the service providing device 10 that has received this notification permits the login of the terminal that has made the login request, sends the screen data of the login completion screen indicating this meaning to the terminal 30 (step S208), and causes the terminal 30 to display it (step S209). Through the above, the login process ends. Hereinafter, between the terminal 30 whose login is permitted and the service providing device 10, various data are transmitted and received according to the user's operation, and various services are provided to the user.

[0105] Thus, according to this embodiment, when obtaining a phone number from the terminal 30 to be authenticated, determination information (first FP) is obtained from the terminal 30. And, an SMS containing a URL for connecting to the authentication device 20 is sent to the obtained phone number, and determination information (second FP) of the terminal 30 accessed through this URL is obtained. And, when the first FP and the second FP match, the terminal 30 is authenticated. That is, in this embodiment, it can be confirmed that the terminal 30 to be authenticated is the same as the destination of the SMS. Thereby, improper acts such as authentication agents passing authentication by inputting a phone number different from the phone number set in the terminal 30 can be prevented.

[0106] In addition, according to this embodiment, when the authentication of the terminal is completed in the member registration process, a terminal ID is generated as authentication information and is held by both the terminal 30 and the authentication device 20. And, the second and subsequent authentications (for example, login authentication) are performed by confirming that the terminal ID stored in the terminal 30 is the same as the terminal ID stored by the authentication device 20. Therefore, in the second and subsequent authentications of the terminal 30, there is no need for the process of sending an SMS, and authentication can be easily performed without spending effort and cost.

[0107] (Embodiment 2)

[0108] In the above Embodiment 1, SMS was used for authentication. In contrast, the feature of Embodiment 3 is that authentication is performed by making a phone call to the terminal 30 without using SMS.

[0109] As Figure 1 shown, the authentication system 2 of Embodiment 2 includes a service providing device 10 and an authentication device 20 in the same way as the authentication system 1 of Embodiment 1. The configurations of the service providing device 10 and the authentication device 20 of Embodiment 2 are as Figure 2 、 Figure 4 shown, and are substantially the same as the configurations of the service providing device 10 and the authentication device 20 of Embodiment 1. In addition, the configuration of the terminal 30 of Embodiment 3 is as Figure 7 shown, and is substantially the same as the configuration of the terminal 30 of Embodiment 1.

[0110] However, in Embodiment 3, the configurations of the authentication DB 231 and the terminal DB 232 stored in the storage unit 23 of the authentication device 20 are different from those of Embodiment 1. The configuration of the authentication DB 231 of Embodiment 2 is shown in Figure 17。In the authentication DB 231 of the present embodiment, the terminal telephone number, keyword, and registration date and time information indicating the date and time when these pieces of information are registered in the authentication DB 231 are stored in a corresponding manner. The terminal telephone number stored in the authentication DB 231 is the telephone number obtained from the terminal 30 that has requested authentication from the service providing apparatus 10. The keyword stored in the authentication DB 231 is a keyword for making a telephone call to the terminal telephone number and comparing it with the voice information obtained from the call destination.

[0111] The configuration of the terminal DB 232 of Embodiment 2 is shown in Figure 18 。Compared with the terminal DB 232 of the first embodiment, the terminal DB 232 of the present embodiment further stores voiceprint information. The voiceprint information is data obtained from the voice information acquired by a voice acquisition unit 206 described later. The terminal DB 232 is an example of the voiceprint information storage unit of the present invention.

[0112] Next, with reference to Figure 19 , the functional configuration of the authentication system 2 of Embodiment 2 of the present invention will be described. The service providing apparatus 10 includes a telephone number acquisition unit 104, a keyword notification unit 105, and a service providing unit 106 as functional configurations. These units are realized by the data communication unit 11, storage unit 12, and control unit 13 of the service providing apparatus 10 cooperating to operate.

[0113] The authentication apparatus 20 includes a transfer setting determination unit 204, a keyword generation unit 205, a voice acquisition unit 206, and an authentication unit 207 as functional configurations. These units are realized by the telephone communication unit 21, data communication unit 22, storage unit 23, and control unit 24 of the authentication apparatus 20 cooperating to operate.

[0114] The telephone number acquisition unit 104 acquires the telephone number (terminal telephone number) of the terminal 30 from the user's terminal 30 for which membership registration is to be performed.

[0115] The transfer setting determination unit 204 makes a telephone call to the telephone number acquired by the telephone number acquisition unit 104 and determines whether a call transfer setting has been made for the call destination. Here, the call transfer setting means that when there is an incoming call, the incoming call is transferred to the telephone number of another terminal registered in advance. The transfer setting determination unit 204 is an example of the transfer setting determination unit of the present invention.

[0116] When the transfer setting determination unit 204 determines that no transfer setting has been made, the keyword generation unit 205 generates a keyword for voice authentication and sends it to the service providing apparatus 10.

[0117] The keyword notification unit 105 notifies the terminal 30, which has the telephone number obtained by the telephone number acquisition unit 104, of the keyword received from the keyword generation unit 205 via the Internet N1. The keyword notification unit 105 is an example of the keyword notification unit of the present invention.

[0118] When the transfer setting determination unit 204 determines that the transfer setting has not been performed, the voice acquisition unit 206 acquires voice information from the call destination to which the transfer setting determination unit 204 has made a phone call. The voice acquisition unit 206 is an example of the voice acquisition unit of the present invention.

[0119] The authentication unit 207 authenticates the terminal 30 by confirming that the voice acquired by the voice acquisition unit 206 matches the keyword notified by the keyword notification unit 105.

[0120] When the authentication unit 203 completes the authentication of the terminal 30, the service providing unit 103 performs various processes (e.g., membership registration, login, etc.) for providing services to the terminal 30.

[0121] Next, with reference to Figures 20 - 22 the flowchart, the operation of the membership registration process in the authentication system 2 will be described. It should be noted that for the steps common to the membership registration process of the first embodiment, the description will be appropriately omitted or simplified.

[0122] When the membership registration process starts, the control unit 36 of the terminal 30 causes the display unit 34 to display Figure 23 the telephone number input screen shown in (step S301). When a telephone number (terminal telephone number) is input to the telephone number input screen by the operation of the user and the confirmation button is clicked, the control unit 36 sends a membership registration request including the terminal telephone number input to the telephone number input screen to the service providing device 10 (step S302).

[0123] When the membership registration request is received, the control unit 13 of the service providing device 10 confirms that an entry having the terminal telephone number included in the membership registration request is not registered in the customer DB 121 (step S303), and sends the terminal telephone number received from the terminal 30 to the authentication device 20 to request authentication (step S304).

[0124] The control unit 24 of the authentication device 20, which has been requested for authentication, controls the telephone communication unit 21 to make a phone call to the terminal telephone number for which authentication has been requested from the service providing device 10 (step S305). Since the telephone communication unit 21 makes a phone call based on SIP, the authentication device 20 receives a response signal (response) including a status code indicating the status of the call destination from the call destination (step S306).

[0125] Next, the control unit 24 determines whether a call transfer setting has been made for the call destination based on the status code included in the received response signal (step S307). For example, the control unit 24 can determine that there is a transfer setting when the status code is "181" indicating transfer in progress, and determine that there is no transfer setting for other status codes.

[0126] In the case where a call transfer setting has been made for the call destination (step S307: Yes), the control unit 24 cuts off the call to the terminal phone number and ends the process as an error (step S308).

[0127] On the other hand, in the case where a call transfer setting has not been made for the call destination (step S307: No), the control unit 24 generates a keyword for voice authentication (step S309). This keyword is data representing an arbitrary string, word, article, etc. For example, the control unit 24 generates multiple keywords such as "apple, banana, pineapple" consisting of three words. It should be noted that it is also possible to pre-store multiple keywords in the storage unit 23, and in step S309, the control unit 24 selects one keyword from these keywords.

[0128] Next, the control unit 24 registers the received terminal phone number and the generated keyword in a corresponding manner in the authentication DB231 (step S310). And the control unit 24 sends the generated keyword to the service providing device 10 (step S311). The control unit 13 of the service providing device 10 sends the keyword received from the authentication device to the terminal (step S312).

[0129] When receiving the keyword from the service providing device 10, the control unit 36 of the terminal 30 causes the display unit 34 to display a voice input screen as shown in Figure 24 to prompt voice input (step S313). A message for prompting the user to perform voice input of the received keyword "apple, banana, pineapple" is displayed on this voice input screen. In addition, a call display caused by the call made by the authentication device 20 in step S305 is performed at the upper part of this voice input confirmation screen.

[0130] The user operates the input unit 33 to answer the phone call according to the message on the voice input confirmation screen. For example, in the case of Figure 24 , the user operates the input unit 33 to click "Answer". Thus, a phone call communication is established between the terminal 30 and the authentication device 20. And the user speaks the keyword displayed on the voice input screen (which is "apple, banana, pineapple" in the case of Figure 24 ) towards the microphone 37 of the terminal 30, and this voice signal is sent to the authentication device 20 via the telephone network N2 (step S314).

[0131] The control unit 24 of the authentication device 20 that has received the voice signal confirms that the voice represented by the voice signal is consistent with the generated keyword (step S315). Specifically, the control unit 24 converts the received voice signal into a character string through a known voice recognition technology, and it is only necessary to confirm that the converted character string is consistent with the keyword registered in the authentication DB 231. In the case where it fails to confirm the consistency between the voice signal and the keyword, the process ends as an error.

[0132] In the case where the confirmation between the voice signal and the keyword is completed, the control unit 24 of the authentication device 20 analyzes the received voice signal through a known voice recognition technology to obtain voiceprint information (step S316). It should be noted that after obtaining the voiceprint information, the control unit 24 can also cut off the telephone communication with the terminal 30.

[0133] Next, the control unit 24 generates a terminal ID in the same manner as in Embodiment 1 (step S317). This terminal ID is, for example, information obtained by combining a random number and date-time information, or a fingerprint of the terminal 30, etc. It should be noted that in the case where the terminal ID is a fingerprint, the control unit 24 needs to request a fingerprint from the terminal 30. And the control unit 24 sends the generated terminal ID to the terminal 30 and instructs to store the terminal ID (step S318). The control unit 36 of the terminal 30 that has received this instruction stores the received terminal ID in the storage unit 35 (step S319). And the control unit of the authentication device newly registers the voiceprint information obtained in step S316, the terminal ID created in step S317, and the terminal telephone number in a corresponding manner in the terminal DB 232 (step S320).

[0134] Hereinafter, the same processing as the member registration processing of Embodiment 1 is performed. That is, the control unit 24 of the authentication device 20 notifies the service providing device 10 of the meaning that the authentication of the terminal 30 has been completed (step S321). The control unit 13 of the service providing device 10 that has received this notification sends the screen data of the member registration screen to the terminal 30 and instructs to display the member registration screen (step S322). Thereby, the member registration screen is displayed on the display unit 34 of the terminal 30 (step S323).

[0135] The user operation input unit 33 of the terminal 30 performs the following operations: inputs information required for member registration (for example, user ID, password, name, address, etc.) to the member registration screen, and determines the input information. In response to this operation, the control unit 36 of the terminal 30 sends the information input to the member registration screen to the service providing device 10 (step S324).

[0136] The control unit 13 of the service providing device 10 registers the information received from the terminal 30 in the customer DB 121 (step S325). Through the above, the membership registration process ends.

[0137] It should be noted that the login process of this embodiment has no substantial difference from the login process of Embodiment 1, so the description is omitted.

[0138] In this way, according to this embodiment, when the telephone number is obtained from the terminal 30 to be authenticated, a keyword for voice input is sent to the terminal 30, and a telephone call is made to the obtained telephone number to obtain voice information. And the terminal 30 is authenticated by confirming that the voice information is consistent with the sent keyword. Thus, since it can be confirmed that the terminal 30 to be authenticated is the same as the telephone call destination, improper behaviors such as authentication proxy that inputs a telephone number different from the telephone number set in the terminal 30 to pass the authentication can be prevented.

[0139] In addition, in this embodiment, when performing authentication, it is confirmed whether the telephone number for making a telephone call has a call forwarding setting. And in the case of a telephone number with a call forwarding setting, it will be an authentication error. Thus, improper behaviors such as the following can also be prevented: when an improper actor performs membership registration for his own terminal 30, he inputs the telephone number of another terminal that is set to forward incoming calls to his own terminal 30, so that the telephone call from the authentication device 20 to another terminal is forwarded to his own terminal to obtain the incoming call telephone number, and thus the authentication can be completed without sending the telephone number of his own terminal.

[0140] In addition, in this embodiment, when the authentication of the terminal 30 is completed, the voiceprint information obtained from the obtained voice information is stored in the authentication device in a manner corresponding to the terminal telephone number. Therefore, even after that, when the user changes the model of the terminal without changing the telephone number, the original user can be identified and the authentication during the model change can be correctly performed.

[0141] (Modification of Embodiment 2)

[0142] In the above Embodiment 2, the authentication device 20 makes a telephone call to the terminal telephone number to obtain voice information from the terminal 30 and perform authentication, but it can also perform authentication by making a telephone call from the terminal 30 to the authentication device 20. Hereinafter, this modification will be described.

[0143] Figure 25This is a functional block diagram of the authentication system 3 of this modification example. In this modification example, different from the authentication system 2 of the second embodiment, the authentication device 20 does not have a transfer setting determination unit 204. In addition, the voice acquisition unit 206 acquires voice information from the call source (terminal 30) through a phone call with the phone number acquired by the phone number acquisition unit 104. For the functions of the other structures, they are substantially the same as those of the structures of the authentication system 2 of the second embodiment, so the description is omitted.

[0144] Next, with reference to Figure 26 ~the flowchart of the figure, the operation of the membership registration process in this modification example will be described. It should be noted that for the steps common to the membership registration process of the second embodiment, the description will be appropriately omitted or simplified.

[0145] When the membership registration process starts, the control unit 36 of the terminal 30 causes the display unit 34 to display a phone number input screen (step S401). When a phone number (terminal phone number) is input to the phone number input screen through the operation of the user and the confirmation button is clicked, the control unit 36 sends a membership registration request including the terminal phone number input to the phone number input screen to the service providing device 10 (step S402).

[0146] When receiving the membership registration request, the control unit 13 of the service providing device 10 confirms that an entry with the terminal phone number included in the membership registration request is not registered in the customer DB 121 (step S403), and sends the terminal phone number received from the terminal 30 to the authentication device 20 to request authentication (step S404).

[0147] The control unit 24 of the authentication device 20 requested for authentication generates a keyword for voice authentication (step S405). And the control unit 24 registers the received terminal phone number and the generated keyword in a corresponding manner in the authentication DB 231 (step S406), and sends the generated keyword to the service providing device 10 ( Figure 27 , step S407). The control unit 13 of the service providing device 10 sends the keyword received from the authentication device to the terminal (step S408).

[0148] When receiving the keyword from the service providing device 10, the control unit 36 of the terminal 30 causes the display unit 34 to display as Figure 28The voice input screen for prompting voice input as shown (step S409). On this voice input screen, the phone number "0321110001" for tapping to make a phone connection with the authentication device 20 and a message for prompting the user to perform voice input of the received keywords "apple, banana, pineapple" are displayed. It should be noted that it is also possible that after establishing a phone connection with the terminal 30, the control unit 24 of the authentication device 20 notifies the terminal 30 of the keywords through voice guidance, rather than displaying the keywords on the voice input screen.

[0149] The user touches the displayed part of the phone number via the input unit 33 according to the message on the voice input confirmation screen. In response to this operation, the control unit 36 of the terminal 30 controls the phone communication unit 31 to make a phone call to the authentication device 20 (step S410).

[0150] The control unit 24 of the authentication device 20 confirms that the incoming call phone number from the terminal 30 is the same as the acquired terminal phone number (step S411). In the case where the incoming call phone number is different from the terminal phone number, the control unit 24 does not answer the phone call and ends the process as an error.

[0151] In the case where the confirmation is completed in step S411, the control unit 24 of the authentication device 20 answers the phone call from the terminal 30 (step S412). Thereby, a phone communication is established between the authentication device 20 and the terminal 30. And the user speaks the keywords displayed on the voice input screen (if it is Figure 28 then "apple, banana, pineapple") towards the microphone 37 of the terminal 30, and this voice signal is sent to the authentication device 20 via the telephone network N2 (step S413).

[0152] The control unit 24 of the authentication device 20 that receives the voice signal confirms that the voice represented by this voice signal is the same as the generated keyword (step S414). Thereafter, in the same manner as the authentication process of Embodiment 2, the steps S316 to S325 Figure 22 are executed.

[0153] In this way, even in the method of making a phone call from the terminal 30 to the authentication device 20, the terminal 30 can be authenticated by voice signal in the same manner as in Embodiment 2.

[0154] (Other Variation Examples)

[0155] The above-described embodiments are examples and can be variously modified and applied. For example, in the above-described embodiments, authentication at the time of member registration when using the service for the first time has been described. However, the present invention is not limited to authentication at the time of member registration, but can be applied to all scenarios that require authentication of the terminal 30. For example, the present invention can also be applied to authentication when logging in to the service from the terminal 30. In this case, the terminal 30 sends an authentication request including an ID and a password input by the user to the service providing device 10. Then, after the service providing device 10 confirms that the received ID and password are correct with reference to the customer DB 121, it obtains the terminal phone number of the user from the customer DB 121 and sends it to the authentication device 20 to request authentication. Hereinafter, in the same manner as the above-described member registration process, execute Figure 9 step S106 of Figure 20 or steps subsequent to step S305 of

[0156] to authenticate the terminal 30.

[0157] In addition, in the above-described embodiments, it has been described that the service providing device 10 and the authentication device 20 are constituted by independent devices. However, the authentication systems 1 to 3 can also be constituted by one or more devices obtained by integrating the functions of the two devices.

[0158] The present invention can be variously implemented and deformed without departing from the broad spirit and scope of the present invention. In addition, the above-described embodiments are used to explain the present invention and do not limit the scope of the present invention. That is, the scope of the present invention is shown by the claims rather than the embodiments. And various deformations implemented within the scope of the claims and the meaning of the invention equivalent thereto are regarded as being within the scope of the present invention.

[0159] Description of reference numerals:

[0160] 1, 2, 3: authentication system; 10: service provider; 20: authentication device; 30: terminal; N1: Internet; N2: telephone network; 11, 22, 32: data communication unit; 12, 23, 35: storage unit; 121: customer DB; 13, 24, 36: control unit; 21, 31: telephone communication unit; 231: authentication DB; 232: terminal DB; 33: input unit; 34: display unit; 37: microphone; 38: speaker; 101, 104: telephone number acquisition unit; 102: first FP acquisition unit; 103, 106: service provider; 105: keyword notification unit; 201: SMS sending unit; 202: second FP acquisition unit; 203, 207: authentication unit; 204: transfer setting determination unit; 205: keyword generation unit; 206: voice acquisition unit.

Claims

1. An authentication system, comprising: A telephone number acquisition unit that acquires a telephone number from a terminal to be authenticated; A first determination information acquisition unit that acquires first determination information for determining the terminal; The SMS sending unit sends a short message SMS to the telephone number obtained by the telephone number obtaining unit, wherein, This SMS records access information for connecting to this system; A second determination information acquisition unit that acquires second determination information for determining the connection source connected through the access information; And An authentication unit that authenticates the terminal by confirming the consistency between the first determination information and the second determination information.

2. The authentication system according to claim 1, further comprising: A terminal authentication information storage unit that, when the authentication of the terminal is completed by the authentication unit, performs a process for causing the terminal to store authentication information; and An authentication information storage unit that stores the authentication information, In the case of authenticating the terminal for the second and subsequent times, the authentication unit acquires the authentication information from the terminal and confirms that the acquired authentication information has been stored in the authentication information storage unit, thereby authenticating the terminal.

3. An authentication system, comprising: A telephone number acquisition unit that acquires a telephone number from a terminal to be authenticated; A keyword notification unit that notifies the terminal of a keyword for voice authentication; A voice acquisition unit that makes a phone call to the telephone number acquired by the telephone number acquisition unit to acquire voice information from the call destination, or acquires voice information from the call source through a phone call from the telephone number acquired by the telephone number acquisition unit; And An authentication unit that authenticates the terminal by confirming the consistency between the voice acquired by the voice acquisition unit and the keyword sent by the keyword notification unit.

4. The authentication system according to claim 3, further comprising: A transfer setting determination unit that makes a phone call to the telephone number acquired by the telephone number acquisition unit to determine whether a phone transfer setting has been made, In the case where the transfer setting determination unit determines that a phone transfer setting has been made, the authentication unit does not authenticate the terminal.

5. The authentication system according to claim 3 or 4, further comprising: A voiceprint information storage unit that, when the authentication of the terminal is completed by the authentication unit, acquires voiceprint information from the voice information acquired by the voice acquisition unit and stores it in a manner corresponding to the telephone number acquired by the telephone number acquisition unit.

6. An authentication method, having the following steps: A telephone number acquisition step of acquiring a telephone number from a terminal to be authenticated; A first determination information acquisition step of acquiring first determination information for determining the terminal; SMS sending step, sending a short message SMS to the telephone number obtained in the telephone number obtaining step, wherein, This SMS records access information for connecting to this system; A second determination information acquisition step of acquiring second determination information for determining the connection source connected through the access information; And An authentication step of authenticating the terminal by confirming the consistency between the first determination information and the second determination information.

7. An authentication method, having the following steps: A telephone number acquisition step of acquiring a telephone number from a terminal to be authenticated; Keyword notification step, notifying the terminal of a keyword for voice authentication; Voice acquisition step, making a phone call to the phone number obtained in the phone number acquisition step to acquire voice information from the call destination, or acquiring voice information from the call source through an incoming call from the phone number obtained in the phone number acquisition step; And Authentication step, authenticating the terminal by confirming that the voice acquired in the voice acquisition step is consistent with the keyword notified in the keyword notification step.

8. A program that causes a computer to function as the following units: Phone number acquisition unit, acquiring a phone number from a terminal to be authenticated; First determination information acquisition unit, acquiring first determination information for determining the terminal; The SMS sending unit sends a short message SMS to the telephone number obtained by the telephone number obtaining unit, wherein, This SMS records access information for connecting to this system; Second determination information acquisition unit, acquiring second determination information for determining the connection source that connects through the access information; And Authentication unit, authenticating the terminal by confirming the consistency of the first determination information and the second determination information.

9. A program that causes a computer to function as the following units: Phone number acquisition unit, acquiring a phone number from a terminal to be authenticated; Keyword notification unit, notifying the terminal of a keyword for voice authentication; Voice acquisition unit, making a phone call to the phone number acquired by the phone number acquisition unit to acquire voice information from the call destination, or acquiring voice information from the call source through an incoming call from the phone number acquired by the phone number acquisition unit; And Authentication unit, authenticating the terminal by confirming that the voice acquired by the voice acquisition unit is consistent with the keyword notified by the keyword notification unit.