Authentication system and authentication program
The authentication system addresses the trade-off between security and convenience by using a call management unit to securely authenticate identities through telephone line communications, ensuring reliable and convenient web service authentication.
Patent Information
- Application Number
- JP2023182848
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-24
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2043-10-24
AI Technical Summary
Existing authentication systems face a trade-off between security and convenience, making it challenging to provide a reliable and convenient identity authentication service for web services.
An authentication system that includes a user-side terminal device, a web server device, and a server-side terminal device with a call management unit, allowing for secure identity authentication by making and receiving calls via a telephone line without relying on the Internet.
This solution enables highly reliable and convenient identity authentication by preventing impersonation and ensuring secure communication, thereby enhancing the security and usability of web services.
Smart Images

Figure 2025072238000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an authentication system and an authentication program for performing authentication between a user and a web server. [Background technology]
[0002] As an authentication system using an authentication server, Patent Document 1 discloses an authentication method that can improve security and prevent a decrease in the success rate of authentication. This authentication method includes the steps of generating identification information in a communication terminal, transmitting the telephone number of the communication terminal and the generated identification information from the communication terminal to an authentication server, generating a password in the authentication server and storing the generated password in a database in association with the transmitted telephone number and identification information, transmitting the generated password from the authentication server to the communication terminal, converting the transmitted password into a tone signal and transmitting it from the communication terminal via a telephone line when the communication terminal uses a caller ID function to call a predetermined destination, determining whether the acquired telephone number and password are stored in the database when the authentication server acquires the telephone number notified by the caller ID function and the password transmitted via the telephone line, and making the identification information associated with the telephone number and password in the database available as authentication information for the communication terminal when the acquired telephone number and password are stored.
[0003] Patent Document 2 discloses a communication device that is connectable to a first network but requires settings for connecting to a second network, and that automatically performs the settings. This communication device includes a first transmission unit that transmits identification information of the device via the first network to a predetermined server, a first reception unit that receives first setting information for connecting to the second network via the first network in response to the identification information transmitted by the first transmission unit, and a first setting unit that uses the first setting information to set the device so that it can be connected to the second network.
[0004] Patent Document 3 discloses a one-time password issuing device that can prevent unauthorized authentication by a third party and can further improve user convenience. This one-time password issuing device is communicatively connected to an authentication device that performs identity authentication processing for a user, and issues a one-time password required for the identity authentication processing, and comprises: a receiving means for receiving registration number information indicating the telephone number of a telephone device owned by the user from the authentication device; an extraction means for, when the receiving means receives the registration number information, extracting one telephone number as the one-time password from a plurality of telephone numbers that the one-time password issuing device can receive via a telephone line; a storage means for storing in a specified storage device, in association with the registration number information received by the receiving means and the one-time number information indicating the telephone number extracted by the extraction means; a notification means for notifying the user of the one-time number information stored in the storage means; a determination means for, when a telephone line connection is made to the one-time password issuing device based on the one-time number information notified by the notification means, determining whether or not a combination of the registration number information corresponding to the incoming number of the telephone and the one-time number information corresponding to the calling number of the telephone is stored in the storage device; and a transmission means for transmitting determination result information indicating the determination result by the determination means to the authentication device.
[0005] Patent Document 4 discloses a ticket management server used in a ticket management system that monitors tickets used for admission to an event, etc. This ticket management server includes a control unit, a database that stores a ticket ID for identifying a ticket and a user phone number in association with each other, and a communication unit that can communicate with a user terminal of a user via a network, and the control unit determines whether or not a predetermined ticket issuing phone number that can be received by the communication unit has received an incoming call from the user phone number associated with the ticket ID of the ticket, and when a determination condition is satisfied including the reception of a call from the user phone number associated with the ticket ID of the ticket to the ticket issuing phone number, the control unit causes the ticket issuing device to issue the ticket. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] JP 2017-151753 A [Patent Document 2] JP 2017-147672 A [Patent Document 3] JP 2015-082140 A [Patent Document 4] JP 2019-139312 A Summary of the Invention [Problem to be solved by the invention]
[0007] When shopping at a brick-and-mortar store or online, identity authentication is required to prevent unauthorized use by a third party during payment. The higher the security of this identity authentication system, the more complex it becomes, which tends to reduce convenience. On the other hand, increasing convenience tends to reduce the accuracy of identity authentication. In this way, security and convenience are in conflict with each other. For this reason, in web services that perform identity authentication, a system that can perform identity authentication conveniently and reliably, as well as being highly reliable, is desired.
[0008] An object of the present invention is to provide an authentication system and an authentication program that can conveniently and reliably perform personal authentication for web services that perform personal authentication, and that is highly reliable. [Means for solving the problem]
[0009] One aspect of the present invention is an authentication system including a user-side terminal device having a communication function via a telephone line and the Internet, a web server device connected to the Internet, and a server-side terminal device connected to the web server device and having a communication function via the telephone line, the server-side terminal device having an outgoing / incoming call management unit that manages outgoing and incoming calls via the telephone line, the web server device having a server unit that transmits web information via the Internet, and an outgoing / incoming call request unit that requests the server-side terminal device to make and receive calls to the user-side terminal device, the outgoing / incoming call request unit transmitting the web information from the user-side terminal device via the Internet, When a request for the provision of a service requiring personal authentication is made to the web server device, the call management unit requests the call origination and reception management unit to make and receive a call to the user's terminal device, and when the call origination and reception management unit receives a request for making and receiving a call from the call origination and reception request unit, it makes a call to the user's terminal device via a telephone line and disconnects the telephone communication immediately after the call origination telephone number is notified to the user's terminal device, and the call origination and reception management unit receives the call originated from the user's terminal device via the telephone line to the call origination telephone number, and if the telephone number notified upon receiving the call matches the destination telephone number, it allows the server unit to send web information related to the provision of the service to the user's terminal device.
[0010] Another aspect of the present invention is an authentication program executed by a computer included in an authentication system including a user-side terminal device having a communication function via a telephone line and the Internet, a web server device connected to the Internet, and a server-side terminal device connected to the web server device and having a communication function via the telephone line, the server-side terminal device having an outgoing / incoming call management unit that manages outgoing and incoming calls via the telephone line, the web server device having a server unit that transmits web information via the Internet, and an outgoing / incoming call request unit that requests the server-side terminal device to make and receive calls to the user-side terminal device, and when a request for provision of a service requiring personal authentication is made from the user-side terminal device to the web server device via the Internet, In this case, the computer is caused to execute the following steps: a request step in which the call request unit requests the call management unit to make and receive a call to the user's terminal device; a calling step in which the call management unit, having received the request for making and receiving a call in the request step, makes a call to the user's terminal device via a telephone line; a disconnection step in which, after making the call in the calling step, the telephone communication is disconnected immediately after the call originating telephone number is notified to the user's terminal device; an incoming call step in which the call originating telephone number made from the user's terminal via the telephone line is received by the call management unit; and, if the telephone number notified when the call is received in the incoming call step matches the destination telephone number, the computer is caused to execute an information transmission step in which the server unit permits the transmission of web information related to the provision of a service to the user's terminal device.
[0011] According to this configuration, when a user attempts to receive a service requiring personal authentication from a web server device via the Internet, a call is made to the user terminal device via a telephone line, and the telephone line is disconnected immediately after the caller's telephone number is notified to the user terminal device. Since the caller's telephone number has been notified to the user terminal device, the user makes a call from the user terminal device that received the call to this number. The server terminal device checks whether the caller's telephone number matches the caller's telephone number and confirms whether the user attempting to receive the service is the owner of the user terminal device. Spoofing of personal authentication is prevented by making and receiving calls via the user terminal device and a telephone line, not via the Internet. Effect of the Invention
[0012] According to the present invention, in a web service that performs personal authentication, it is possible to conveniently and reliably perform personal authentication, and to provide a highly reliable authentication system and authentication program. [Brief description of the drawings]
[0013] [Figure 1] 1 is a configuration diagram illustrating an authentication system according to an embodiment of the present invention. [Diagram 2] FIG. 13 is a diagram illustrating screen transitions when receiving a service that requires personal authentication. [Diagram 3] FIG. 13 is a diagram illustrating screen transitions when receiving a service that requires personal authentication. [Figure 4] 11A to 11C are diagrams illustrating screen transitions when receiving a service that requires personal authentication. [Diagram 5] FIG. 13 is a diagram illustrating screen transitions when receiving a service that requires personal authentication. [Figure 6] 13 is a flowchart illustrating an example of a personal authentication process in a new registration service. [Figure 7] 11 is a flowchart illustrating an example of a personal authentication process in an update service. [Figure 8] 11 is a flowchart illustrating an example of an identity authentication process in a reference service. [Figure 9] 11 is a flowchart illustrating an example of an identity authentication process in a requested information service. [Figure 10] 11 is a flowchart illustrating an example of an incoming call management process in the authentication program. [Figure 11] 11 is a flowchart illustrating an example of an incoming call determination process in the authentication program. [Figure 12] 10 is a flowchart illustrating an example of an incoming call notification process in the authentication program. [Figure 13] 11 is a flowchart illustrating a process of service management in the authentication program. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. In the following description, the same members are designated by the same reference numerals, and the description of members that have already been described will be omitted as appropriate.
[0015] (Authentication System) FIG. 1 is a configuration diagram illustrating an authentication system according to this embodiment. The authentication system 1 of this embodiment comprises a user-side terminal device 10 equipped with communication functions via a telephone line TX and the Internet N, a web server device 20 connected to the Internet N, and a server-side terminal device 30 connected to the web server device 20 and equipped with communication functions via the telephone line TX.
[0016] The user side terminal device 10 includes, for example, a telephone terminal 11 and an information terminal 12. Specific examples of the telephone terminal 11 include a mobile phone and a smartphone. In this embodiment, in addition to a smartphone capable of downloading and installing application software (so-called apps), a mobile phone without such a function (a mobile phone other than a smartphone) can also be used as the telephone terminal 11.
[0017] Specific examples of the information terminal 12 include a tablet terminal and a personal computer. The telephone terminal 11 and the information terminal 12 may be separate entities, or may be incorporated in the same housing. For example, some smartphones and tablet terminals have a communication function via a telephone line TX and a communication function via the Internet N, and these are configured as a single device. For convenience of explanation, this embodiment will be described with an example in which the telephone terminal 11 and the information terminal 12 are separate entities.
[0018] A telephone number is assigned to the telephone terminal 11 for communication (telephone) via the telephone line TX. In this embodiment, the telephone number assigned to the telephone terminal 11 of the user side terminal device 10 is telephone number telX. Since personal authentication is performed using telephone number telX, it is preferable to use a mobile phone line as the telephone line TX. The information terminal 12 executes a web browser that requests web information from a web server device via the Internet N and displays the received web information on a screen.
[0019] The web server device 20 is a device that provides web information to a requester of the web information via the Internet N. The web server device 20 has a server unit 21 that transmits the web information via the Internet N, and a CGI (Common Gateway Interface) 22 that includes a function of requesting the server side terminal device 30 to make and receive a call to the user side terminal device 10. In this embodiment, the CGI 22 is an example of a call request unit.
[0020] It is preferable that an information terminal 25 is connected to the web server device 20. The information terminal 25 includes a service management unit 26 that controls the provision of services, and a database DB that stores web information necessary for providing the services. Specific examples of the information terminal 25 include a personal computer and an external storage device. It is preferable that the information terminal 25 is connected to the web server device 20 via a communication path C based on a second communication standard other than a first communication standard that is a communication standard of the Internet N. Here, an example of the first communication standard is TCP / IP, and an example of the second communication standard is USB (Universal Serial Bus).
[0021] Since the information terminal 25 including the database DB is provided separately from the web server device 20, direct access to the database DB is prevented even if the web server device 20 is illegally intruded. Furthermore, since the information terminal 25 and the web server device 20 are connected by a communication path C based on a communication standard different from that of the Internet N, it becomes difficult to intrude into the information terminal 25 from the outside via the Internet N. Hacking is generally performed using the communication standard of the Internet N. Therefore, there is a possibility that the web server device 20 will be illegally intruded into via the Internet N. However, since the web server device 20 and the information terminal 25 are connected by a communication path C based on a communication standard other than that of the Internet N, even if the web server device 20 is illegally intruded into, it is difficult to illegally intrude into the information terminal 25 connected thereto via the communication path C based on a different communication standard, and the security of the database DB can be improved.
[0022] The server-side terminal device 30 has an outgoing / incoming call management unit 31 that manages outgoing and incoming calls via the telephone line TX. The server-side terminal device 30 functions as an authentication server that performs identity authentication. The server-side terminal device 30 is provided with a determination ring buffer 32 that stores a telephone number for which identity authentication is to be performed, an incoming call ring buffer 33 that stores a telephone number that has been received via the telephone line TX, and a permanent call list 34 that stores telephone numbers associated with the user-side terminal device 10. The determination ring buffer 32 is an example of a determination storage unit, the incoming call ring buffer 33 is an example of an incoming call storage unit, and the permanent call list 34 is an example of a permanent call storage unit. The ring buffers used for the determination ring buffer 32 and the incoming call ring buffer 33 are stacks in a ring state, and the next to the end of the stack is the top of the stack. By using the ring buffer, it is possible to suppress the storage capacity and to easily manage the storage of telephone numbers within a certain period (within a certain capacity). The determination ring buffer 32 and the incoming call ring buffer 33 may be managed by switching between multiple ring buffers to distribute the load. This makes it possible to handle cases where many users attempt identity authentication in a short period of time.
[0023] Permanent telephone list 34 is a list for registering telephone numbers of users who have earned a certain degree of trust (for example, site operating companies and related companies (financial companies, etc.)). This allows users corresponding to telephone numbers registered in permanent telephone list 34 of operating companies and related companies to access databases DB required for business without user registration.
[0024] For example, a financial company may access a database DB in which "personal information" and "purchase history" are recorded, and transfer the purchase price from the user's transaction account to the store's transaction account. In addition, when a private service is used, it is done from a private homepage. In this case, for example, a homepage with a private service menu is created on a personal computer, etc., and when a private service is to be executed, a specific button on the service menu on the homepage is directly selected to start a web browser and to request the private service from the CGI. On the other hand, if a financial company installs an authentication system on a private web server, the operating company will be able to use the financial company's private services. These processes are services provided to users who have earned a certain degree of trust, and by registering the telephone numbers of such users in the permanent telephone list 34, it becomes possible to provide smoother service by providing quicker identity authentication than for general users.
[0025] In such an authentication system 1, when the user terminal device 10 requests the web server device 20 via the Internet N to provide a service requiring personal authentication, the CGI 22 requests the call management unit 31 to make and receive a call to the user terminal device 10. When the call management unit 31 receives a call request from the CGI 22, it makes a call to the user terminal device 10 via the telephone line TX, and disconnects the telephone communication immediately after the caller's telephone number (in this embodiment, the caller's telephone number is telA) is notified to the user terminal device 10. By disconnecting the telephone communication immediately after the notification, the minimum necessary information can be sent effectively.
[0026] After the telephone communication is disconnected, the user uses the user terminal device 10 that received the call to caller telephone number telA notified of the incoming call via the telephone line TX. The call management unit 31 receives the call from the user terminal device 10 to caller telephone number telA via the telephone line, and if the telephone number notified at the time of the call matches the destination telephone number, it allows the server unit 21 to send web information related to the provision of the service to the user terminal device 10.
[0027] Here, the caller telephone number telA notified to the user side terminal device 10 does not have to be fixed. For example, a plurality of caller telephone numbers may be prepared, and one selected (for example, randomly selected) for each service that performs identity authentication (for each identity authentication) may be notified to the user side terminal device 10 as the caller telephone number telA.
[0028] Also, the caller telephone number telA may be switched depending on the number of the same telephone number telX stored in the judgment ring buffer 32. Also, when the same telephone number telX is stored multiple times in the judgment ring buffer 32 within a certain period of time, the caller telephone number telA may be switched depending on the number of stored telephone numbers. In other words, by changing the caller telephone number telA for a user who performs identity authentication multiple times within a specified period of time, the accuracy of identity authentication processing can be improved based on the correspondence between the order of requested services (for example, time information when the request was received) and the switched caller telephone number telA.
[0029] (Method of identity authentication) Next, a personal authentication method using the authentication system 1 according to this embodiment will be described. 2 to 5 are diagrams for explaining screen transitions when receiving a service that requires personal authentication. These screens are displayed on the user terminal device 10. That is, the screens may be displayed on the screen of the telephone terminal 11 or on the screen of the information terminal 12. In this embodiment, the screen display by the web browser of the information terminal 12 is taken as an example.
[0030] Figure 2 shows an example of the screen transitions from the top menu of a service that requires personal authentication. For example, when you click (select) the "Personal Information" button on the top page of an online shop, a "Personal Authentication" subwindow will pop up. Also, when you click a button on the top page, for example, "Retailer A," the products handled by Retailer A will be displayed. When you click the "Add to Cart" button below the product you want to purchase, the product you plan to purchase will be added to your cart. When you click the "Confirm Cart" button, a subwindow showing the contents of your cart will pop up.
[0031] Fig. 3 shows an example of the sub-window displayed when the "Personal Information" button is clicked from the top menu shown in Fig. 2. This screen displays buttons (icons) corresponding to services such as "New", "Update" and "Reference", as well as a text box (input frame) for inputting the telephone number of the user terminal device 10 as a user ID. The user selects the button for the desired service from the screen displayed by the web browser of the information terminal 12, and inputs the telephone number of the telephone terminal 11 owned by the user into the text box as a user ID.
[0032] FIG. 4(a) shows an example of the screen that appears when the "New" button is selected in FIG. 3. When a user selects the "New" button, the necessary information is registered to newly authenticate the user. This information includes a text box for inputting a phone number, which serves as the user's user ID. If the "New" button is further selected from here, the screen transitions to a screen for inputting personal information. Once the required information has been input (confirmed), the user selects the "Register" button. This causes a message to appear on the screen, such as "Registered," to appear to inform the user that registration has been completed. The phone number and personal information input as the user ID are stored, for example, in a database DB.
[0033] FIG. 4(b) shows an example of the screen that appears when the "Update" button is selected in FIG. 3. When a user selects the "Update" button, updates such as adding or correcting already registered information are made. Once the user has finished inputting (confirming) the information to be updated, they select the "Update" button. This causes a message to appear on the screen, such as "Updated," to inform the user that the update has been completed.
[0034] Figure 4(c) shows an example of the screen displayed when the "Reference" button is selected in Figure 3. When a user selects the "Reference" button, registered information is referenced. This process causes registered user information, such as user ID (phone number) and personal information, to be displayed on the screen.
[0035] FIG. 5 shows an example of the screen displayed when the "Purchase" button is selected in the subwindow displaying the cart contents in FIG. 2. The process performed by selecting the "Purchase" button is, for example, a process for performing identity authentication at a payment site using credit or coupons when purchasing a product at an online shop. Clicking the "Purchase" button transitions to a personal authentication screen. Since identity authentication has not yet been performed, it is preferable to display the purchase details in gray. Clicking the "Authentication" button transitions to an authentication processing screen. Clicking the "Authentication" button here performs identity authentication processing according to this embodiment, which will be described later, and when it is completed, a screen is displayed that notifies the completion of processing of the requested information, such as "Completed."
[0036] In addition, when a customer authenticates themselves when purchasing a product at a physical store rather than an online shop, the store and the customer are the users, and a financial company such as a payment site that accepts credit cards or coupons acts as the web server and authenticates the customer.
[0037] When a customer makes a payment for shopping or receiving a service at a store, the web browser of the information terminal 12 used at the store displays, for example, a screen showing the store's products as shown in FIG. 2, and when paying at the register, the store clerk selects the "Add to Cart" button for the product the customer wishes to purchase. Then, when paying, the customer selects the "Confirm Cart" button and then the "Purchase" button. This transitions to the screen shown in FIG. 5, where the same personal authentication process as above is carried out.
[0038] (Identity authentication process for new registration services) FIG. 6 is a flowchart illustrating an example of an identity authentication process in the new registration service. When a user selects the "New" button from the home screen displayed by the web browser, inputs telephone number telX, and selects the "Register" button, the user terminal device 10 sends information about the user's telephone number telX (destination telephone number) to the web server device 20 via the Internet N.
[0039] Next, the web server device 20 transmits a determination request (request for call) for the telephone number telX to the call management unit 31 of the server side terminal device 30 by CGI22. The call management unit 31, which has received the determination request from CGI22, stores the telephone number telX in the determination ring buffer 32 and makes a call to the telephone number telX, which is the destination telephone number, via the telephone line TX. Then, the call management unit 31 disconnects the telephone communication immediately after the call source telephone number telA is notified to the user side terminal device 10. Here, as explained above, the call source telephone number telA notified to the user side terminal device 10 does not need to be fixed, and a different call source telephone number telA may be notified each time personal authentication is performed.
[0040] Next, the web server device 20 transmits the HTML for registering new information to the user terminal device 10. The user terminal device 10 displays the HTML for registering new information transmitted from the web server device 20 in a web browser. The user refers to the screen display for registering new information displayed in the web browser and inputs the necessary information.
[0041] Next, the user makes a call to the caller's telephone number telA notified when the call was received at the user-side terminal device 10. The call management unit 31 of the server-side terminal device 30 receives the call made to the caller's telephone number telA, and performs an incoming call judgment to judge whether the telephone number telX (incoming telephone number) notified when the call was received is included in the telephone numbers stored in the judgment ring buffer 32. If the telephone number telX notified when the call was received is included in the judgment ring buffer 32, the caller's telephone number telX is stored in the incoming ring buffer 33, and if not, it is not stored.
[0042] Next, the user selects the "Register" button displayed on the web browser. This causes the entered information to be sent to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the outgoing call management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information on the telephone number telX entered by the user.
[0043] When the call origination / incoming call management unit 31 of the server-side terminal device 30 receives the call origination confirmation requested by the CGI 22, it checks whether the telephone number telX is stored in the incoming call ring buffer 33 and sends the result to the web server device 20.
[0044] The web server device 20 receives the information on the presence or absence of an incoming call sent from the outgoing / incoming call management unit 31, and if there is storage in the incoming call ring buffer 33, executes processing by the service management unit 26. That is, the service management unit 26 receives the message sent from the CGI 22, executes processing to newly register the telephone number telX and personal information contained in the message, and responds with the execution result to the web server device 20. As a result, the information entered by the user is newly registered in the database DB.
[0045] After the registration is completed, the web server device 20 transmits a response HTML to the user terminal device 10 to inform the user of the completion of the registration. On the other hand, if there is no call, the web server device 20 transmits a response HTML to the user terminal device 10 to inform the user that the registration was not successful.
[0046] The user terminal device 10 receives the response HTML sent from the web server device 20 and displays it on the screen using a web browser. That is, when the new registration is completed, a message such as "Registered" is displayed, and when the new registration is unsuccessful, a message such as "Failed" is displayed.
[0047] (Authentication process for update service) FIG. 7 is a flowchart illustrating an example of a personal authentication process in the update service. When a user inputs a telephone number telX on the home screen displayed by the web browser and selects the "Update" button, the user terminal device 10 sends information on the user's telephone number telX to the web server device 20 via the Internet N.
[0048] Next, the web server device 20 transmits a determination request (request for call) for the telephone number telX to the call management unit 31 of the server side terminal device 30 by CGI22. The call management unit 31, which has received the determination request from CGI22, stores the telephone number telX in the determination ring buffer 32 and makes a call to the telephone number telX via the telephone line TX. Then, the call management unit 31 disconnects the telephone communication immediately after the caller's telephone number telA is notified to the user side terminal device 10. Here, as explained above, the caller's telephone number telA notified to the user side terminal device 10 does not have to be fixed, and a different caller's telephone number telA may be notified each time personal authentication is performed.
[0049] Next, the web server device 20 transmits HTML for updating the registered information to the user terminal device 10. The user terminal device 10 displays the HTML for updating transmitted from the web server device 20 in a web browser. The user refers to the screen display for updating displayed in the web browser and performs updates such as adding and correcting the necessary information.
[0050] Next, the user makes a call to the caller's telephone number telA notified when the call was received at the user-side terminal device 10. The call management unit 31 of the server-side terminal device 30 receives the call made to the caller's telephone number telA, and performs an incoming call judgment to judge whether the telephone number telX (incoming telephone number) notified when the call was received is included in the telephone numbers stored in the judgment ring buffer 32. If the telephone number telX notified when the call was received is included in the judgment ring buffer 32, the caller's telephone number telX is stored in the incoming ring buffer 33, and if not, it is not stored.
[0051] Next, after the telephone line from the caller telephone number telA is disconnected, the user selects the "Update" button displayed on the web browser. This causes the updated information, such as additions and corrections, to be sent to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the outgoing / incoming call management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information of the telephone number telX entered by the user.
[0052] When the call origination / incoming call management unit 31 of the server-side terminal device 30 receives the call origination confirmation requested by the CGI 22, it checks whether the telephone number telX is stored in the incoming call ring buffer 33 and sends the result to the web server device 20.
[0053] The web server device 20 receives the information on the presence or absence of an incoming call sent from the outgoing / incoming call management section 31, and if an incoming call is received, executes processing by the service management section 26. That is, the service management section 26 receives the message sent from the CGI 22, executes processing to update the telephone number telX and personal information included in the message, and responds with the execution result to the web server device 20. As a result, the information updated by the user is registered in the database DB.
[0054] After the update registration is completed, the web server device 20 transmits a response HTML to the user terminal device 10 to notify the completion of the update registration. On the other hand, if there is no call, the web server device 20 transmits a response HTML to the user terminal device 10 to notify the user terminal device 10 that the update could not be performed.
[0055] The user terminal device 10 receives the response HTML sent from the web server device 20 and displays it on the screen using a web browser. That is, when the update registration is completed, a message such as "Updated" is displayed, and when the update registration is not completed, a message such as "Failed" is displayed.
[0056] (Identity authentication process in reference service) FIG. 8 is a flowchart illustrating an example of an identity authentication process in the reference service. When a user inputs a telephone number telX on the home screen displayed by the web browser and selects the "Reference" button, the user terminal device 10 sends information on the user's telephone number telX to the web server device 20 via the Internet N.
[0057] Next, the web server device 20 transmits a determination request (request for call) for the telephone number telX to the call management unit 31 of the server side terminal device 30 by CGI22. The call management unit 31, which has received the determination request from CGI22, stores the telephone number telX in the determination ring buffer 32 and makes a call to the telephone number telX via the telephone line TX. Then, the call management unit 31 disconnects the telephone communication immediately after the caller's telephone number telA is notified to the user side terminal device 10. Here, as explained above, the caller's telephone number telA notified to the user side terminal device 10 does not have to be fixed, and a different caller's telephone number telA may be notified each time personal authentication is performed.
[0058] Next, the web server device 20 transmits HTML for reference of the registration information to the user terminal device 10. The user terminal device 10 displays the reference HTML transmitted from the web server device 20 in a web browser. The information displayed in this reference HTML includes the telephone number telA of the server terminal device 30 to be called and the previously entered telephone number telX of the user, and the user's personal information is not yet displayed.
[0059] Next, the user makes a call to the caller's telephone number telA notified when the call was received at the user-side terminal device 10. The call management unit 31 of the server-side terminal device 30 receives the call made to the caller's telephone number telA, and performs an incoming call judgment to judge whether the telephone number telX (incoming telephone number) notified when the call was received is included in the telephone numbers stored in the judgment ring buffer 32. If the telephone number telX notified when the call was received is included in the judgment ring buffer 32, the caller's telephone number telX is stored in the incoming ring buffer 33, and if not, it is not stored.
[0060] Next, after the telephone line from the caller's telephone number telA is disconnected, the user selects the "Confirm" button displayed on the web browser. This causes the information of the telephone number telX to be sent to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the outgoing / incoming call management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information of the telephone number telX entered by the user.
[0061] When the call origination / incoming call management unit 31 of the server-side terminal device 30 receives the call origination confirmation requested by the CGI 22, it checks whether the telephone number telX is stored in the incoming call ring buffer 33 and sends the result to the web server device 20.
[0062] Web server device 20 receives the information on the presence or absence of an incoming call sent from outgoing / incoming call management section 31, and if an incoming call is received, executes processing by service management section 26. That is, service management section 26 receives the message sent from CGI 22, executes processing to refer to personal information linked to telephone number telX included in the message, and responds with the execution result to web server device 20. As a result, the information that the user wants to refer to is read from database DB.
[0063] After reading the information, the web server device 20 transmits a response HTML including the read information to the user terminal device 10. On the other hand, if there is no call, the web server device 20 transmits a response HTML to the user terminal device 10 to inform the user that the information cannot be viewed.
[0064] The user terminal device 10 receives the response HTML sent from the web server device 20 and displays it on the screen using a web browser. That is, if the information to be referenced is sent, that information (such as personal information) is displayed, and if it cannot be referenced, a message such as "Failed" is displayed.
[0065] In such an authentication method using the authentication system 1, authentication is performed by utilizing a telephone number notification function in mutual outgoing and incoming communication between the telephone number telX on the user terminal device 10 side and the caller telephone number telA on the server terminal device 30 side. Therefore, the exchange of both telephone numbers required for authentication can be performed only by a terminal that can use the telephone line TX. In other words, in this embodiment, the notification of both telephone numbers performed in the authentication process does not require the use of application software dedicated to authentication, and can be realized by any terminal that can use telephone communication via the telephone line TX.
[0066] (Authentication process for requested information service) FIG. 9 is a flowchart illustrating an example of an identity authentication process in a requested information service. Here, as an example, the case will be described where the user side is a store and a customer, and the web server side is a payment site and a shopping site. In this case, the telephone terminal 11 of the user side terminal device 10 is owned by the customer, and the information terminal 12 is used by the store. Also, the server side terminal device 30 is used by the payment site, and the web server device 20 and the information terminal 25 are used by the shopping site.
[0067] First, the store acting as the user selects the “Personal Authentication” button from the home screen displayed by the web browser, enters the telephone number telX, and then selects the “Authentication” button. The information terminal 12 of the user terminal device 10 then sends the information of the user's telephone number telX to the web server device 20 via the Internet N.
[0068] Next, the web server device 20 transmits a judgment request (call request) for the telephone number telX to the call management unit 31 of the server-side terminal device 30 by CGI22. The call management unit 31, which has received the judgment request from CGI22, stores the telephone number telX in the judgment ring buffer 32 and makes a call to the telephone number telX of the telephone terminal 11 held by the customer via the telephone line TX. Then, the call management unit 31 disconnects the telephone communication immediately after the call source telephone number telA is notified to the telephone terminal 11 held by the customer, which is the user-side terminal device 10. Here, as explained above, the call source telephone number telA notified to the user-side terminal device 10 does not have to be fixed, and a different call source telephone number telA may be notified each time personal authentication is performed.
[0069] Next, the web server device 20 transmits the authentication HTML to the information terminal 12 of the user side terminal device 10. The information terminal 12 displays the authentication HTML transmitted from the web server device 20 in a web browser. The store, which is the user side, refers to the authentication screen displayed in the web browser and inputs the necessary information.
[0070] Next, the customer, who is the user, makes a call from the telephone terminal 11 to the call originator telephone number telA notified when the call was received at the telephone terminal 11. The call originator management unit 31 of the server-side terminal device 30 receives the call originated to the call originator telephone number telA, and performs an incoming call judgment to judge whether or not the telephone number telX notified when the call was received is included in the telephone numbers stored in the judgment ring buffer 32. If the telephone number telX notified when the call was received is included in the judgment ring buffer 32, the call originator telephone number telX is stored in the incoming call ring buffer 33, and if not, it is not stored.
[0071] Next, the store, which is the user, selects the "Authenticate" button displayed on the web browser. This causes the entered information to be sent to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the outgoing call management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information on the telephone number telX entered by the user.
[0072] When the call origination / incoming call management unit 31 of the server-side terminal device 30 receives the call origination confirmation requested by the CGI 22, it checks whether the telephone number telX is stored in the incoming call ring buffer 33 and sends the result to the web server device 20.
[0073] The web server device 20 receives the presence or absence of an incoming call sent from the outgoing / incoming call management unit 31, and if there is storage in the incoming call ring buffer 33, executes processing by the service management unit 26. That is, the service management unit 26 receives a message sent from the CGI 22, executes processing (e.g., payment processing) for the request information contained in the message, and responds with the execution result to the web server device 20. In this way, processing (e.g., payment processing) for the information requested by the user is provided. That is, if the customer is authenticated by this processing, the customer's credit card payment with the store or coupon usage is completed, and the product is purchased or a service is provided to the customer.
[0074] In the above, an example was given in which a customer makes payment at a store, but when a customer makes payment using an online sales site, the customer uses information terminal 12 instead of the store. That is, when a customer uses information terminal 12 to shop at an online sales site and makes a payment, the customer performs the operations that would be performed by the store among the above processes. This allows a customer who uses an online sales site to make a payment based on identity authentication and purchase a product or receive a service.
[0075] (Certification Program) The authentication program applied in the authentication system 1 according to this embodiment is executed by a computer included in the authentication system 1. This authentication program may be stored in a storage medium, or may be distributed via a network. FIG. 10 is a flowchart illustrating an example of an incoming call management process in the authentication program. The process of incoming call management is executed by the outgoing call management section 31 of the server side terminal device 30 . First, as shown in step S101, it is determined whether or not a judgment request (request step) has been made to the call management unit 31 from the CGI 22. If a judgment request has been made, the process proceeds to step S102, where the telephone number tel (for example, telephone number telX) is stored in the judgment ring buffer 32.
[0076] Next, as shown in step S103, the call management unit 31 calls the telephone number tel via the telephone line TX (calling step), and immediately after the call source telephone number is notified to the user side terminal device 10, the telephone communication is disconnected (disconnecting step).
[0077] On the other hand, if it is determined in step S101 that the call is not a judgment request, the process proceeds to step S104, where it is determined whether or not the call is an incoming call (incoming call step) originated from the user terminal device 10. If the call is an incoming call originated from the user terminal device 10, the process proceeds to step S105, where an incoming call judgment is performed. The process of the incoming call judgment will be described later.
[0078] If it is determined in step S104 that the incoming call was not from a call originated from the user terminal device 10, the process proceeds to step S106, where it is determined whether or not the incoming call is an incoming call confirmation sent from the CGI 22. If it is an incoming call confirmation, the process proceeds to step S107, where an incoming call notification is performed. The incoming call notification process will be described later. On the other hand, if it is not an incoming call confirmation, the process returns to step S101. The incoming call management process is a loop process from step S101 to step S107.
[0079] Here, when there is a judgment request shown in step S101, if there is another judgment request for the same phone number within a short period of time (for example, within about one minute), the outgoing / incoming call management unit 31 may refrain from making a judgment request for that phone number for a certain period of time. This can be used to prevent spam.
[0080] FIG. 11 is a flowchart illustrating an example of an incoming call determination process in the authentication program. The call reception determination process (step S105 in FIG. 10) is executed by the call reception management unit 31 of the server side terminal device 30. The outgoing / incoming call management unit 31 calls the telephone number tel for which incoming call judgment is performed, and after performing a disconnection step of disconnecting the telephone communication immediately after the caller's telephone number is notified to the user's terminal device 10, judges whether the telephone number tel is included in the permanent telephone list 34 as shown in step S201. If the telephone number tel is included in the permanent telephone list 34, the process proceeds to step S202, and a process of storing the telephone number tel in the incoming call ring buffer 33 is performed.
[0081] If it is determined in step S201 that the telephone number tel is not included in the permanent telephone list 34, the process proceeds to step S203, where it is determined whether the telephone number tel is included in the determination ring buffer 32. If the telephone number tel is included in the determination ring buffer 32, the process proceeds to step S204, where the telephone number tel is stored in the incoming call ring buffer 33.
[0082] FIG. 12 is a flowchart illustrating an example of an incoming call notification process in the authentication program. The call notification process (step S107 in FIG. 10) is executed by the call management unit 31 of the server side terminal device 30. First, as shown in step S301, it is determined whether or not the telephone number tel is included in the incoming ring buffer 33. If the telephone number tel is included in the incoming ring buffer 33, the process proceeds to step S302, where a message is sent to the CGI 22 indicating that the telephone number tel is present, and the telephone number tel is deleted from the incoming ring buffer 33 as shown in step S303.
[0083] On the other hand, if it is determined in step S301 that the telephone number tel is not included in the incoming call ring buffer 33, the process proceeds to step S304, and a message is sent to the CGI 22 indicating that the telephone number tel does not exist.
[0084] FIG. 13 is a flowchart illustrating a service management process in the authentication program. The service management process is executed by the service management unit 26 of the web server device 20. First, as shown in step S401, it is determined whether or not a new process request has been received from the CGI 22. If a new process request has been received, the process proceeds to step S402, where a process for registering new information is executed.
[0085] If the request is not for a new process, the process proceeds to step S403 to determine whether or not a request for update processing has been received from the CGI 22. If a request for update processing has been received, the process proceeds to step S404 to execute the information update processing.
[0086] If the request is not for update processing, the process proceeds to step S405 to determine whether or not a request for reference processing has been received from the CGI 22. If a request for reference processing has been received, the process proceeds to step S406 to execute the information reference processing.
[0087] After executing the new process in step S402, the update process in step S404, and the reference process in step S406, the process of transmitting response data to the web server device 20 is performed as shown in step S407. On the other hand, if the request is not for any of the new process, update process, and reference process, the process returns to step S401. The service management process is a loop process from step S401 to step S407.
[0088] As described above, according to the authentication system 1 and authentication program of this embodiment, when a user attempts to receive a service requiring identity authentication from the web server device 20 via the Internet N, a call is made to the user terminal device 10 via the telephone line TX, and the telephone line TX is disconnected immediately after the caller's telephone number telA is notified to the user terminal device 10. As a result, the caller's telephone number telA is notified to the user terminal device 10 through the minimum necessary communication, and it remains as an incoming call history. Even if the user is not informed of the telephone number (caller's telephone number telA) used for identity authentication in advance, he or she can obtain it from this incoming call history.
[0089] Then, the user uses the user terminal device 10 to make a call via the telephone line TX to the caller telephone number telA in the incoming call history. The server terminal device 30 checks whether the callee's telephone number matches the incoming telephone number to confirm whether the user who is trying to receive the service is the owner of the user terminal device 10. In other words, since the user is authenticated by making and receiving a call via the user terminal device 10 and the telephone line TX, not via the Internet N, spoofing by a third party is prevented.
[0090] Although the present embodiment and its application examples (modifications, specific examples) have been described above, the present invention is not limited to these examples. For example, those in which a person skilled in the art appropriately adds, deletes, or modifies the design of the above-mentioned embodiments or their application examples (modifications, specific examples), or those in which the features of each embodiment are appropriately combined, are also included in the scope of the present invention as long as they include the gist of the present invention. [Explanation of symbols]
[0091] 1. Authentication system 10...User terminal device 11. Telephone terminal 12,25…Information terminal 20...Web server device 21…Server section 22...CGI 26…Service Management Department 30...Server side terminal device 31…Call Management Department 32…Judgment ring buffer 33...Incoming ring buffer 34... Permanent phone list C…Communication channel DB...database N…Internet TX: Telephone line
Claims
1. A user terminal device having a communication function via a telephone line and the Internet; a web server device connected to the Internet; a server-side terminal device connected to the web server device and equipped with a communication function via the telephone line; An authentication system comprising: the server-side terminal device has an outgoing / incoming call management unit that manages outgoing and incoming calls via the telephone line; The web server device A server unit that transmits web information via the Internet; a call request unit for requesting the server-side terminal device to make or receive a call to the user-side terminal device, the call request unit requests the call management unit to make and receive a call to the user terminal device when the user terminal device makes a request to the web server device via the Internet for a service requiring user authentication; When the call management unit is requested to make a call from the call request unit, the call management unit makes a call to the user terminal device via the telephone line, and disconnects the telephone communication immediately after the call source telephone number is notified to the user terminal device; The authentication system includes an incoming / outgoing call management unit that receives a call from the user terminal to the source telephone number via the telephone line, and if the telephone number notified upon receiving the call matches the destination telephone number, allows the server unit to send web information related to the provision of the service to the user terminal device.
2. The server side terminal device A determination storage unit that stores a telephone number for which personal authentication is to be performed; A storage unit for receiving calls that stores a telephone number received via the telephone line, When a request for provision of a service requiring personal authentication is received from the user terminal device to the web server device via the Internet, the call request unit requests the call management unit to notify the call destination telephone number, which is the telephone number notified from the user terminal device, and to make and receive a call to and from the user terminal device; the call management unit, when receiving a call from the call request unit, stores the destination telephone number in the determination storage unit and makes a call to the destination telephone number via the telephone line; When the call management unit receives a call from the user terminal to the call source telephone number via the telephone line, the call management unit stores an incoming telephone number, which is the telephone number of the incoming call, in the incoming call storage unit; The authentication system of claim 1, wherein the call management unit permits the transmission of web information related to the provision of the service from the server unit to the user terminal device when the incoming call telephone number stored in the incoming call memory unit matches the destination telephone number stored in the judgment memory unit.
3. The server side terminal device further includes a permanent telephone storage unit for storing a telephone number associated with the user side terminal device, The authentication system of claim 1, wherein the call management unit receives a call from the user terminal to the originating telephone number via the telephone line, and if the telephone number notified when the call is received matches the telephone number stored in the permanent telephone memory unit, allows the server unit to send web information related to the provision of the service to the user terminal device.
4. a database connected to the web server device; the database is connected to the web server via a communication path for transmitting and receiving information to and from the web server device according to a second communication standard other than the first communication standard which is the communication standard of the Internet; The authentication system according to claim 1 , wherein the call management unit has a function of reading out the web information from the database using the second communication standard when allowing the transmission of the web information to the user terminal device.
5. A user terminal device having a communication function via a telephone line and the Internet; a web server device connected to the Internet; a server-side terminal device connected to the web server device and equipped with a communication function via the telephone line; An authentication program executed by a computer included in an authentication system comprising: the server-side terminal device has an outgoing / incoming call management unit that manages outgoing and incoming calls via the telephone line; The web server device A server unit that transmits web information via the Internet; a call request unit for requesting the server-side terminal device to make or receive a call to the user-side terminal device, a request step in which, when a request for provision of a service requiring user authentication is made from the user terminal device to the web server device via the Internet, the call request unit requests the call management unit to make and receive a call to and from the user terminal device; a calling step in which the call management unit, having received the call making / receiving request in the request step, makes a call to the user side terminal device via the telephone line; a disconnecting step of disconnecting the telephone communication immediately after the call source telephone number is notified to the user side terminal device after the call is made in the calling step; a receiving step of receiving, at the call management unit, a call originating from the user terminal to the call origin telephone number via the telephone line; an information transmission step of permitting transmission of web information relating to the provision of the service from the server unit to the user side terminal device when the telephone number notified at the time of receiving the call in the receiving step matches the telephone number of the call destination; An authentication program that causes a computer to run.
6. The server side terminal device A determination storage unit that stores a telephone number for which personal authentication is to be performed; A storage unit for receiving calls that stores a telephone number received via the telephone line, The request step includes: when a request for provision of a service requiring user authentication is made from the user terminal device to the web server device via the Internet, notifying the call origination management unit of a destination telephone number, which is the telephone number notified from the user terminal device, and requesting the call origination and reception to the user terminal device; The transmitting step includes: storing the destination telephone number in the determination storage unit and making a call to the destination telephone number via the telephone line; The receiving step includes: When the call management unit receives a call from the user terminal to the call source telephone number via the telephone line, the call management unit stores an incoming telephone number, which is the telephone number of the incoming call, in the incoming call storage unit; The information transmitting step includes: An authentication program as described in claim 5, further comprising allowing the server unit to transmit the web information to the user terminal device when the incoming call telephone number stored in the incoming call memory unit matches the destination telephone number stored in the judgment memory unit.
7. The server side terminal device further includes a permanent telephone storage unit for storing a telephone number associated with the user side terminal device, The information transmitting step includes: An authentication program as described in claim 5, further comprising: when a telephone number notified from the user terminal when an incoming call is received in the incoming call step matches a telephone number stored in the permanent telephone memory unit, allowing the server unit to send web information related to the provision of the service to the user terminal device.
Citation Information
Patent Citations
Management method and management device for commercial transaction
JP2002170040A
Authentication support apparatus, personal authentication system, authentication support method, and program
JP2015179501A
Authentication system, authentication method, and authentication program
JP2016192023A
Authentication method and authentication server for authenticating portable terminal
WO2013076821A1
Onetime password issuing device, program, and onetime password issuing method
JP2015082140A