Authentication system, authentication method, and computer program

The authentication system addresses the challenge of verifying user identity and protecting personal information on e-commerce sites by using a portion of user and order data for authentication questions, thereby ensuring reliable authentication while reducing data leakage risks.

JP2025073165APending Publication Date: 2025-05-13株式会社DAQ
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023183688
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-26
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

As the number of user registrations and transactions on e-commerce sites increases, the number of orders associated with order processing also rises, necessitating effective identity verification while protecting personal information such as addresses and telephone numbers.

Method used

An authentication system that includes a communication unit, a question database managing questions related to user and order data, and an authentication unit that verifies user identity by inputting reception data, selecting questions randomly, and authenticating answers based on registered data.

Benefits of technology

The system reliably performs identity authentication while minimizing the risk of management data leakage by using only part of the management data for questions and implementing time limits and consecutive correct answer requirements for authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025073165000001_ABST
    Figure 2025073165000001_ABST
Patent Text Reader

Abstract

To provide an authentication system that can reduce the risk of personal information leakage while reliably performing authentication processing in electronic commerce.SOLUTION: An electronic commerce server 10 manages management data including personal data associated with a user ID assigned to each registered user and order data associated with an order ID assigned to each order. An authentication server 30 manages a plurality of questions that ask a user a part of personal data of the user. The authentication server 30 randomly selects at least one question from the plurality of questions, requests a user terminal 20 to provide an answer to the selected question, accepts the answer entered by the user terminal 20, and authenticates the user when it is determined that the answer is correct.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an authentication system, an authentication method, and a computer program for authenticating a user who accesses an electronic commerce server. [Background technology]

[0002] Patent Document 1 describes how questions to be asked to a user are created based on personal information registered in a database, and then the created questions are presented to the user. The system then prompts the user to input answers, and acquires the answers input by the user. This allows the system to authenticate the user and prevent unauthorized access. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2002-073198 A Summary of the Invention [Problem to be solved by the invention]

[0004] However, as the number of registered users increases and the number of product transactions increases at an electronic commerce site, the number of processes associated with order processing also increases accordingly, such as order cancellations, returns of purchased products, changing of passwords of registered users registered at the electronic commerce site, etc. In such processes, it is necessary to take into consideration the protection of personal information such as addresses and telephone numbers while reliably authenticating users. [Means for solving the problem]

[0005] An authentication system for solving the above problem is an authentication system that authenticates a user who accesses an electronic commerce server, the electronic commerce server managing management data including user identification data assigned to each registered user, personal data associated with the user identification data, order identification data assigned to each order, and order data associated with the order identification data. The authentication system includes a communication unit that communicates with the electronic commerce server and also with a user terminal, a question database that manages a plurality of questions that ask the user about a part of the user's management data, and an authentication unit that authenticates the user who has accessed through the user terminal. The authentication unit then requests the user terminal to input acceptance data, which is at least one of the identification data among the user identification data and the order identification data, queries the electronic commerce server for the acceptance data input by the user terminal, and upon obtaining registration data, which is at least a part of the management data associated with the identification data indicated by the acceptance data, randomly selects at least one question from the plurality of questions, requests the user terminal for an answer to the selected question, accepts the answer data input by the user terminal, and performs authentication when it is determined that the answer data is correct based on the registration data.

[0006] Also, an authentication method for solving the above problem is an authentication method for authenticating a user who accesses an electronic commerce server, the electronic commerce server managing management data including user identification data assigned to each registered user, personal data associated with the user identification data, order identification data assigned to each order, and order data associated with the order identification data. The authentication system includes a question database managing a plurality of questions that ask a user a part of the management data of the user. The authentication method includes the authentication system requesting the user terminal to input acceptance data that is at least one of the identification data of the user identification data and the order identification data, inquiring the electronic commerce server about the acceptance data input by the user terminal, and acquiring registration data that is at least a part of the management data associated with the identification data indicated by the acceptance data, randomly selecting at least one question from the plurality of questions, requesting the user terminal to provide an answer to the selected question, accepting the answer data input by the user terminal, and authenticating the user when it is determined that the answer data is correct based on the registration data.

[0007] The above authentication method can be realized by installing a program for executing the above authentication method in a computer that realizes an authentication system. The program is distributed through a network or through a portable recording medium such as an optical disk or a semiconductor memory, and installed in the computer.

[0008] According to the above configuration, since a part of the management data is used for the question, the identity of the user can be authenticated reliably. Also, since a part of the management data is used for the question, rather than the whole, it is possible to prevent the management data from being leaked.

[0009] In the above authentication system and authentication method, the authentication unit may be configured to accept the answer data within a time limit, and to perform authentication if the answer is correct. According to the above configuration, the authentication is determined to be successful only if the answer to the question is correctly answered within the time limit, thereby reducing the risk that the answer will be "correct" by repeatedly inputting the answer over a long period of time, thereby allowing unauthorized access.

[0010] In the above authentication system and authentication method, the authentication unit may be configured to randomly select questions from the plurality of questions that do not overlap with previous questions, and perform authentication when the questions are answered correctly consecutively.

[0011] According to the above configuration, by determining that authentication has been successful only if the answers to the questions are consecutively correct, it is possible to reduce the risk of accidentally providing a "correct" answer to a question and allowing unauthorized access.

[0012] In the above authentication system and authentication method, the received data may be order identification data, and the authentication unit may be further configured to accept a cancellation process for the order when authentication is successful.

[0013] According to the above configuration, when canceling an order, the order is confirmed using the order identification data, and then authentication is performed using questions that use part of the personal data. This makes it possible to reduce the risk of leakage of management data while ensuring reliable authentication.

[0014] In the above authentication system and authentication method, the received data may be order identification data, and the authentication unit may be further configured to accept a return process when authentication is successful.

[0015] According to the above configuration, when processing returns, after confirming the order with the order identification data, authentication is performed by asking questions using part of the management data. Therefore, it is possible to reduce the risk of leakage of management data while performing authentication processing reliably.

[0016] In the above authentication system and authentication method, the acceptance data may be the user identification data, and the authentication unit may be further configured to accept a password change process when authentication is successful.

[0017] According to the above configuration, when changing a password, after confirming the user identification data, authentication is performed by a question using a part of the management data, thereby making it possible to reduce the risk of leakage of the management data while ensuring the authentication process.

[0018] In the above authentication system and authentication method, the question may be configured to inquire about a part of personal data in the management data. According to the above configuration, the personal data for generating the questions is the credit card number required for payment in electronic commerce for any product, and the telephone number and postal code required for delivery. Therefore, when canceling or returning a product, the process is performed while checking the receipt, etc., so that the authentication process can be performed reliably. Effect of the Invention

[0019] According to the present invention, in electronic commerce, it is possible to reduce the risk of management data leaks while reliably performing authentication processing. [Brief description of the drawings]

[0020] [Figure 1] FIG. 1 is a block diagram showing an authentication system according to an embodiment. [Diagram 2] FIG. 2 is a block diagram of an electronic commerce server in an embodiment. [Diagram 3] FIG. 3 is a diagram showing a configuration of a registered user database in the embodiment. [Figure 4] FIG. 4 is a diagram showing a configuration of the order management database in the embodiment. [Diagram 5] FIG. 5 is a block diagram of a user terminal in the embodiment. [Figure 6] FIG. 6 is a block diagram of an authentication server in the embodiment. [Figure 7] FIG. 7 is a diagram showing a configuration of a question database in the embodiment. [Figure 8] FIG. 8 is a flowchart showing a process in an embodiment in which there is one question for authentication. [Figure 9] FIG. 9 is a flowchart showing a process for authenticating a user when there are a plurality of questions for authentication and the questions are answered correctly consecutively in an embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0021] An electronic commerce system including an authentication system to which the present invention is applied will now be described with reference to the drawings. [Overall structure] As shown in Fig. 1, the electronic commerce system 1 includes an electronic commerce server 10 that operates an electronic commerce site, a plurality of user terminals 20 that place product orders at the electronic commerce server 10, and an authentication server 30 that serves as an authentication system that performs user authentication processing. The electronic commerce server 10, the plurality of user terminals 20, and the authentication server 30 are mutually connected via a network such as the Internet. The electronic commerce server 10 operates the electronic commerce site, and controls product ordering and product provision.

[0022] The electronic commerce server 10 is also connected via a network to store terminals managed by store managers of stores that open on the electronic commerce site. After user registration, the user terminal 20 allows the user to order products. In user registration, a user's unique identification data, such as a user ID and password, are registered in association with the user. After ordering a product, the user terminal 20 allows the order to be canceled or the product to be returned. In addition, if the user forgets their password, the password can be changed, for example.

[0023] [Electronic Commerce Server] 2, the electronic commerce server 10 is a computer including a communication unit 11, a storage unit 12, and a control unit 13. The communication unit 11 communicates with a user terminal 20, an authentication server 30, and the like via a network.

[0024] The storage unit 12 is composed of a hard disk drive, a solid state drive (SSD), etc., and stores various programs and data. For example, a plurality of databases are constructed in the storage unit 12. Specifically, the storage unit 12 is constructed with a registered user database 12a, an order management database 12b, etc. The registered user database 12a is a database that manages personal data of registered users. The order management database 12b is a database that manages order data for each order. In the databases thus constructed in the storage unit 32, the personal data managed in the registered user database 12a, the order data managed in the order management database 12b, etc. are managed as management data. The control unit 13 is equipped with a CPU, a ROM, a RAM, etc., and executes various processes according to the programs stored in the ROM.

[0025] [Registered User Database] FIG. 3 is an example of the registered user database 12a. The registered user database 12a is a database that manages users who participate in the electronic commerce site. The registered user database 12a manages personal data such as an e-mail address, a password, a date of birth, a sex, a postal code, an address, a credit card number, and a telephone number in association with a unique user ID given to each user. The user ID is unique user identification data assigned to each user. The user ID may be assigned by the control unit 13 or may be designated by the user. The user ID may be the same as the e-mail address. The password may also be generated by the control unit 13 or may be determined by the user. The personal data is data that is initially entered and registered on a user registration page when the user uses the electronic commerce site with the user terminal 20. The personal data is data that can be added or changed after registration.

[0026] For example, the user ID "AAA" is associated with an email address "aaa@xco.○p", a password "a123", a date of birth "19710714", a gender "male", a postal code "123-○△□○", an address "AB-ku, Tokyo...", a credit card number "123...0121", and a telephone number "090-○○○○-1234". Furthermore, the user ID may be associated with the user's height, weight, clothing size, finger size, contact lens or eyeglass lens strength, etc. The user ID may also be associated with an account number.

[0027] By being registered in the registered user database 12a, the user is then able to place orders for products and the like on the electronic commerce site. In addition, the personal data registered in the registered user database 12a can be changed on a registration content change page.

[0028] [Order Management Database] FIG. 4 is an example of the order management database 12b. The order management database 12b is a database that manages the orders of each user. In the order management database 12b, the user ID belongs to a user registered in the registered user database 12a. The order ID is unique order identification data assigned to each order, and is identification data issued by the control unit 13. The order management database 12b manages order data such as the user ID, purchase date and time, store name, delivery destination, delivery status, order information, billed amount, and delivery destination phone number in association with each order ID. The order data is data that identifies the order, such as the time of the order, the store from which the order was placed, the product, and the billed amount.

[0029] For example, order ID "No. 1" is associated with order data such as user ID "AAA", purchase date and time "20220927", store name "Shop A", delivery destination "XX, AB-ku, Tokyo", delivery status "In delivery", order information "Book", billing amount "17,000 yen", and delivery destination phone number "045-XXX-6789". Furthermore, order ID "No. 1" has a delivery status of "In delivery", and "No. 2" has a delivery status of "In preparation". The delivery status transitions in the order of "In preparation", "In delivery", and "Delivered". When the delivery status is "In preparation" or "In delivery", the order can be canceled. Furthermore, when the delivery status is "Delivered", the item can be returned.

[0030] [User terminal] 5, the user terminal 20 is an information processing terminal such as a small computer including a communication unit 21, an operation display unit 22, a memory 23, and a control unit 24. The user terminal 20 is a portable or small terminal such as a smartphone or a tablet terminal carried by a pedestrian. The user terminal 20 may also be a stationary personal computer or the like.

[0031] The communication unit 21 communicates with computers such as the e-commerce server 10 and the authentication server 30 through a network. The operation display unit 22 is a touch panel. The operation display unit 22 has a display surface. The memory 23 is composed of a non-volatile memory or the like, and stores various programs and data. The control unit 24 has a CPU, ROM, RAM, etc., and executes various processes according to the programs stored in the ROM or the memory 23.

[0032] For example, when an electronic commerce site is accessed on the operation display unit 22, the control unit 24 displays a product display page, and when a selected product is selected, the control unit 24 displays a product detail page. Furthermore, when a purchase button, which is a displayed icon, is touched, a product purchase process is executed.

[0033] Furthermore, a cancel page is displayed for executing a cancel process to cancel an order for a product that has not yet been delivered or is currently being delivered. Furthermore, a return page is displayed for executing a return process to return a delivered product. Furthermore, a password change page is displayed for executing a password change process to change the password required when purchasing a product on the electronic commerce site. When executing the cancellation process, return process, and password change process, reception data such as the order ID and user ID can be entered, and answer data for questions can be entered.

[0034] [Authentication Server] 6, the authentication server 30 is a computer including a communication unit 31, a storage unit 32, and a control unit 33. The communication unit 31 communicates with computers such as the electronic commerce server 10 and the user terminal 20 via a network.

[0035] The communication unit 31 communicates with the electronic commerce server 10, the user terminal 20, etc., by, for example, an API (Application Programming Interface). The storage unit 32 is composed of a hard disk drive, an SSD (Solid State Drive), etc., and stores various programs and data. For example, one or more databases are built in the storage unit 32. Specifically, the storage unit 32 has a question database 32a, etc. built in it. The question database 32a, etc. are databases that manage questions for identity authentication when canceling an order, returning a delivered product, changing a password, etc. The control unit 33 has a CPU, a ROM, a RAM, etc., and executes various processes according to the programs stored in the ROM. The control unit 33 functions as an authentication unit that performs identity authentication.

[0036] [Question Database] FIG. 7 is an example of the question database 32a. The question database 32a manages question data in association with a question ID, which is unique question identification data assigned to each question for identity authentication. The question data asks about a part of each personal data registered in the registered user database 12a. The question data also asks about a part of each order data registered in the order management database 12b. The question database 32a holds many questions other than the question IDs "XXX", "YYY", "ZZZ", and "ZYZ". The questions here can be answered based on information known by the user who purchased the product, the store that sold the product, and the electronic commerce server 10. To save the user the trouble of inputting the questions when answering, it is preferable that the questions do not include hiragana, katakana, kanji, etc., but can be answered using numbers and symbols. It is also preferable that the questions do not include alphabets.

[0037] For example, the question ID "XXX" does not ask for the entire credit card number, but only asks for a part of it, in this embodiment, the last four digits of the credit card number. For the user ID "AAA", the credit card number is "123...0121". Therefore, for the user ID "AAA", the correct answer to the question ID "XXX" is "0121" (see FIG. 3). Furthermore, the question ID "YYY" does not ask for the entire phone number, but only asks for a part of it, in this embodiment, the last four digits of the phone number. For the user ID "AAA", the phone number is "090-OOOO-9876". Therefore, for the user ID "AAA", the correct answer to the question ID "YYY" is "9876" (see FIG. 3). Furthermore, the question ID "XYZ" does not ask for the entire billing amount, but only asks for a part of it, in this embodiment, the last four digits of the billing amount. For the user ID "AAA", the billing amount is "17,000 yen". Therefore, for user ID "AAA", the correct answer to question ID "XYZ" is "7000" (see FIG. 4). Furthermore, although not shown, there may be a question asking for part of the delivery destination's telephone number.

[0038] The authentication server 30 holds questions for the user in a question database 32a. On the other hand, the authentication server 30 does not hold correct answers for the user. When at least one of a user ID and an order ID is first input by the user terminal 20, the control unit 33 of the authentication server 30 transmits the ID to the electronic commerce server 10 and acquires personal data and order data associated with the user ID and the order ID. Here, the personal data and order data associated with the user ID and the order ID are referred to as registered data managed in the databases 12a and 12b.

[0039] The control unit 33 randomly selects a question from the question database 32a. Specifically, the control unit 33 extracts a plurality of questions from which an answer can be extracted from the registered data, and then randomly selects one question from the extracted plurality of questions. For example, when the registered data does not include a delivery destination telephone number, the control unit 33 does not select a question that asks about the last four digits of the delivery destination telephone number.

[0040] When the control unit 33 receives an answer to a question from the user terminal 20 of the user, it compares it with registered data, and if the answer from the authentication server 30 is "correct", it authenticates the user. If the answer from the authentication server 30 is "incorrect", the control unit 33 transmits a message to that effect to the user terminal 20. If the answer is "correct", the control unit 33 proceeds with the process, and receives and executes processes such as order cancellation, return processing, and password change processing.

[0041] Next, a case where the user cancels an order will be described. [If there is one question] FIG. 8 is a flowchart showing the process when there is one question for personal authentication.

[0042] First, in step S1, a portal site of the store of the purchased item is accessed. The control unit 33 of the authentication server 30 displays a page of the portal site on the display surface of the user terminal 20. The portal site has various links such as a link to access an introduction page of the items for sale, a link to access a purchase page of the items, a link to access a reception page for canceling an order, a link to access a page for returning the item, and a link to access a page for changing the password. To cancel an order, the link for canceling the order is clicked.

[0043] In step S2, the control unit 33 of the authentication server 30 displays a reception page for order cancellation on the display surface of the user terminal 20. On the reception page, reception data such as the order ID of the product to be canceled is entered using the user terminal 20. Then, when the confirmation button for the entered reception data such as the order ID is pressed, in step S3, the control unit 33 accepts the cancellation process.

[0044] In step S4, the control unit 33 transmits the order ID and the like to the electronic commerce server 10, and inquires whether the received data, such as the received order ID, is registered in the order management database 12b. If the order ID exists, the control unit 13 of the electronic commerce server 10 transmits to the authentication server 30 the order data associated with the order ID, and the registration data consisting of the personal data of the user ID associated with the order data, and the like. If the order ID does not exist, the control unit 33 transmits a message to that effect to the authentication server 30. In step S5, the control unit 33 receives a response to the inquiry from the electronic commerce server 10. In step S6, the control unit 33 determines whether the registration data transmitted from the electronic commerce server 10 has been received, and if so, proceeds to step S7. If not, the control unit 33 displays that the order ID does not exist, and returns to step S2.

[0045] In step S7, the control unit 33 randomly selects one question from the multiple questions managed in the question database 32a. Specifically, the control unit 33 extracts questions for which answers can be extracted from the registered data from the questions managed in the question database 32a. In other words, questions for which answers are not included in the registered data cannot be judged correct or incorrect by the control unit 33, so they are not included in the set when randomly selecting questions. For example, when the answer to the telephone number of the delivery destination is not included in the registered data, a question that asks about part of the telephone number of the delivery destination is not selected. Then, the control unit 33 randomly selects one question from the multiple extracted questions. According to the example of FIG. 7, the control unit 33 randomly selects one question from the question IDs "XXX", "YYY", "ZZZ" ... that are managed in the question database 32a and for which answers can be extracted from the registered data.

[0046] In step S8, the control unit 33 displays a question / answer page on the display surface of the user terminal 20, which displays the selected question and has an answer input field for inputting an answer to the question. On the question / answer page, the answer to the question to be displayed is input using the user terminal 20. When the confirmation button for the input answer is pressed, in step S9, the control unit 33 determines whether the answer to the question is correct based on the registered data. If the answer is "correct", the control unit 33 proceeds to step S10, and if the answer is "incorrect", the control unit 33 proceeds to step S11.

[0047] The control unit 33 displays the selected question on the display surface of the user terminal 20, counts the time limit from the point when the question can be answered, and determines whether the answer input is confirmed within the specified time. If the answer input is confirmed within the time limit, the process proceeds to step S10, and if not, the process proceeds to step S11.

[0048] For example, when a question ID is "XXX" and the question "What are the last four digits of your credit card number?" is asked to user ID "AAA", the control unit 13 checks the last four digits of the "credit card number" of user ID "AAA" to determine whether the answer is correct.

[0049] In step S10, the control unit 33 determines that the identity authentication that accepted the cancellation request was successful, and transmits a message to that effect to the electronic commerce server 10. The control unit 24 updates the order management database 12b. That is, the control unit 24 performs a cancellation process for the product associated with the order ID for which the order cancellation request was made.

[0050] If the answer to the question is determined to be "incorrect" in step S9, the control unit 33 determines in step S11 that the personal authentication has failed. In this case, the control unit 33 does not perform a cancellation process. The control unit 33 displays a message to that effect on the display surface of the user terminal 20. The control unit 33 then displays a page that, for example, prompts the user to redo the process from step S2.

[0051] In the case of a return process for returning a delivered product, the reception data such as the order ID of the product is input on the reception page. Then, the electronic commerce server 10 judges whether the order ID of the delivered product exists in the order management database 12b. Then, when the order ID of the delivered product exists, the control unit 33 of the authentication server 30 acquires the registration data. The registration data here is composed of the order data associated with the order ID, the personal data of the user ID associated with the order data, etc. Then, the control unit 33 extracts a question for which an answer can be extracted from the registration data from the questions managed in the question database 32a, and randomly selects one question from the extracted multiple questions. The control unit 33 judges whether the answer to the question is correct based on the registration data. The control unit 33 displays a question / answer page on the display surface of the user terminal 20. If the answer to the question is "correct", it is judged that the identity authentication that accepted the return application was successful, and transmits such a notice to the electronic commerce server 10. The control unit 24 performs the return process of the product of the order ID for which the return application was requested. If the answer to the question is "incorrect," it is determined that the identity authentication that accepted the return request has failed. The control unit 33 then displays a message to that effect on the display surface of the user terminal 20. After that, a page is displayed that prompts the user to repeat the process from step S2, for example.

[0052] In the case of a password change process for changing a password required for purchasing a product, reception data such as a user ID is input on a reception page. Then, the electronic commerce server 10 judges whether a user ID, etc. exists in the registered user database 12a. Then, when the user ID exists, the control unit 33 of the authentication server 30 acquires the registration data. The registration data here may be only personal data associated with the user ID. Then, the control unit 33 extracts questions for which an answer can be extracted from the registration data from the questions managed in the question database 32a, and randomly selects one question from the extracted multiple questions. The control unit 33 judges whether the answer to the question is correct based on the registration data. The control unit 33 displays a question / answer page on the display surface of the user terminal 20. If the answer to the question is "correct", it is judged that the identity authentication that accepted the password change request has been successful, and transmits a notice to that effect to the electronic commerce server 10. The control unit 24 performs a password change process associated with the user ID for which the password change request has been made. If the answer to the question is "incorrect," it is determined that the requested identity authentication has failed. The control unit 33 then displays a message to that effect on the display surface of the user terminal 20. After that, a page is displayed that prompts the user to repeat the process from step S2, for example.

[0053] [If there are multiple questions] Fig. 9 is a flowchart showing the process of authenticating a user when there are multiple questions for identity authentication and the user answers the questions correctly in succession. In this case, the processes from step S1 to step S6 shown in Fig. 8 are the same. That is, the authentication server 30 inquires of the electronic commerce server 10 whether or not reception data such as the order ID of the product to be canceled, which was entered using the user terminal 20, exists in the order management database 12b. If the order ID exists, the authentication server 30 acquires from the electronic commerce server 10 the order data associated with the order ID, and the registration data consisting of the personal data of the user ID associated with the order data, etc.

[0054] In step S21, the control unit 33 randomly selects one question from among the multiple questions managed in the question database 32a. Specifically, the control unit 33 extracts questions for which answers can be extracted from the registered data from among the questions managed in the question database 32a. Then, the control unit 33 randomly selects one question from the multiple extracted questions.

[0055] In step S22, the control unit 33 displays a question / answer page on the display surface of the user terminal 20, which displays the selected question and has an answer input field for inputting an answer to the question. On the question / answer page, the answer to the question to be displayed is input using the user terminal 20. When the confirmation button for the input answer is pressed, in step S23, the control unit 33 determines whether the answer to the question is correct based on the registered data. If the answer is "correct", the control unit 33 records in a specified recording area of ​​the memory unit 32 that the first question was correct. If the answer is "incorrect", the process returns to step S21 and a question is randomly selected from the multiple questions managed in the question database 32a.

[0056] The control unit 33 displays the selected question on the display surface of the user terminal 20, counts the time limit from the point when the answer can be answered, and determines whether the answer input is confirmed within the predetermined time. If the answer input is confirmed within the time limit, the process proceeds to step S24, and if not, the process returns to step S21.

[0057] In step S24, the control unit 33 randomly selects one question from among the multiple questions managed in the question database 32a. Here, the control unit 33 extracts questions from the questions managed in the question database 32a, for which an answer can be extracted from the registered data. The control unit 33 also excludes the previously selected question (step S21) to prevent the same question from being repeated. In step S25, the control unit 33 displays, on the display surface of the user terminal 20, a question / answer page that displays the selected question and has an answer input field for inputting an answer to the question. In the question / answer page, answers to the questions to be displayed using the user terminal 20, etc. are input.

[0058] Then, when the confirmation button for the input answer is pressed, in step S26, the control unit 33 judges whether the answer to the question was "correct" based on the registered data. If the answer was "correct", the control unit 33 records in a predetermined recording area of ​​the memory unit 32 that the second question was "correct". It also records that the answer was "incorrect". If the answer was consecutively correct, that is, the first question was "correct" and then the second question was also "correct", the process proceeds to step S27, and if the answer was "incorrect", the process proceeds to step S28.

[0059] If the number of consecutive correct answers is set to three, steps S24 to S26 may be repeated after it is determined in step S26 that the number of consecutive correct answers is three. Steps S24 to S26 are repeated according to the number of consecutive correct answers required for identity authentication. The number of consecutive correct answers may also be selected randomly. For example, when user A attempts identity authentication, the number of consecutive correct answers may be three, and when user B next attempts identity authentication, the number may be four.

[0060] The control unit 33 also displays the selected question on the display surface of the user terminal 20, counts the time limit from the point when the question can be answered, and determines whether the answer input is confirmed within the specified time. If the answer input is confirmed within the time limit, the process proceeds to step S27, and if not, the process proceeds to step S28.

[0061] In step S27, the control unit 33 determines that the identity authentication that accepted the cancellation request was successful, and transmits a message to that effect to the electronic commerce server 10. The control unit 24 updates the order management database 12b. That is, the control unit 24 performs a cancellation process for the product associated with the order ID for which the order cancellation request was made.

[0062] If the second question is "incorrect", the control unit 33 judges in step S28 whether the number of questions has reached the upper limit. This makes it possible to restrict access by a user who repeatedly answers questions. If two consecutive correct answers are required, the upper limit of the number of questions is set to three or more, such as three, four, etc. In other words, the upper limit of the number of questions may be at least (the number of consecutive correct answers that is the requirement) + (one). If the number of questions has not reached the upper limit, the control unit 33 returns to step S24. Here, one question is randomly selected from a plurality of questions that have not been asked so far. When the number of questions has reached the upper limit, the process proceeds to step S29. The number of consecutive correct answers that is required may also be selected randomly. In other words, the number of consecutive correct answers may be two or three.

[0063] In step S29, the control unit 33 determines that the personal authentication has failed. In this case, the control unit 33 does not perform the cancellation process. The control unit 33 displays a page on the display surface of the user terminal 20 that prompts the user to redo the process from step S2 (see FIG. 8).

[0064] In the case of return processing for returning a delivered product, the control unit 33 of the authentication server 30 also extracts questions for the user from those managed in the question database 32a and for which answers can be extracted from the registered data, and randomly selects one question from the extracted multiple questions. Then, the control unit 33 displays a question / answer page on the display surface of the user terminal 20. When the answers to the questions are consecutively correct, the control unit 33 determines that the personal authentication that accepted the return request was successful, and transmits a notice to that effect to the electronic commerce server 10. The control unit 24 performs return processing for the product of the order ID for which the return request was made. When the answers to the questions are not consecutively correct, the control unit 33 determines that the personal authentication that accepted the return request was unsuccessful. Then, the control unit 33 displays a notice to that effect on the display surface of the user terminal 20. After that, a page is displayed that prompts the user to redo the process from step S2, for example.

[0065] Also, in the case of a password change process for changing a password required for purchasing a product, questions are extracted from the questions managed in the question database 32a and for which answers can be extracted from the registered data, and one question is selected randomly from the extracted multiple questions. Then, a question / answer page is displayed on the display surface of the user terminal 20. When the answers to the questions are consecutively correct, the control unit 33 determines that the personal authentication that accepted the request for password change has been successful, and transmits a notice to that effect to the electronic commerce server 10. The control unit 24 performs a password change process associated with the user ID that has requested the password change. When the answers to the questions are not consecutively correct, the control unit 33 determines that the personal authentication that accepted the request has failed. Then, the control unit 33 displays a notice to that effect on the display surface of the user terminal 20. After that, a page is displayed that prompts the user to redo the process from step S2, for example.

[0066] [Effects of the embodiment] The above-described embodiment can provide the following advantages. (1) When authenticating the user, the user is authenticated using data known by the user and the electronic commerce server 10, i.e., part of the management data. Therefore, whether it is a cancellation process, a return process, or a password change process, the user must proceed with the process while checking not only their memory but also notes, etc. Therefore, these processes can be performed accurately.

[0067] (2) The questions for identity authentication use only part of the management data, not all of it. This makes it possible to prevent the management data from being leaked during identity authentication.

[0068] (3) By setting a time limit for answering questions, the risk of allowing unauthorized access by repeatedly entering the same answer over a long period of time and getting it right can be reduced. (4) By determining that identity authentication is successful only if the answers to questions are consecutively correct, the risk of accidentally providing "correct" answers to questions and allowing unauthorized access can be reduced.

[0069] (5) When canceling an order, the order is confirmed using the order ID, and then identity authentication is performed by asking questions using part of the registered data, which consists of the order data associated with the order ID and the personal data of the user ID associated with that order data, etc. This makes it possible to reduce the risk of leakage of managed data while ensuring reliable authentication processing.

[0070] (6) When processing returns, the order is confirmed using the order ID, and then identity authentication is performed by asking questions using part of the registered data, which is composed of the order data associated with the order ID and the personal data of the user ID associated with that order data, etc. This makes it possible to reduce the risk of leakage of managed data while ensuring reliable authentication processing.

[0071] (7) When changing a password, the user ID is confirmed, and then identity authentication is performed by asking questions that use part of the registered data, which is composed of personal data etc. associated with the user ID. This makes it possible to reduce the risk of leakage of managed data while ensuring reliable authentication processing.

[0072] (8) The personal data used to generate questions includes credit card numbers, which are necessary for payment in electronic commerce for any product, and telephone numbers and postal codes, which are necessary for delivery. Therefore, when canceling or returning an order, these processes are performed while checking the receipt, etc., so that authentication can be performed accurately.

[0073] [Modifications of the embodiment] The above embodiment can be further modified as follows.

[0074] The personal data for generating questions may be data other than the personal data required for user registration on an e-commerce site (such as credit card number, telephone number, and postal code), such as the user's height, weight, clothing size, finger size, contact lens or eyeglass lens strength, etc.

[0075] The identity authentication process may be used for processes other than order cancellation, return, and password change. For example, it may be used for processing changes to payment methods, delivery dates, and delivery addresses, and for canceling reservations for products that have not yet been released or are on backorder.

[0076] The reception data entered on the reception page is not limited to one piece of data such as an order ID or a user ID. The reception page may require the entry of both a user ID and an order ID, and may also require the entry of a password, regardless of whether the order is being cancelled or returned. [Explanation of symbols]

[0077] 1. Electronic commerce system 10...Electronic commerce server 11…Communications Department 12...Storage section 12a…Registered user database 12b…Order Management Database 13...Control section 20...User terminal 21…Communications Department 22...Operation display section 23…Memory 24...Control section 30...Authentication server 31…Communications Department 32...Storage section 32a…Question Database 33...Control section

Claims

1. 1. An authentication system for authenticating a user accessing an electronic commerce server, comprising: the electronic commerce server manages management data including user identification data assigned to each registered user, personal data associated with the user identification data, order identification data assigned to each order, and order data associated with the order identification data; The authentication system includes: A communication unit that communicates with the electronic commerce server and also communicates with a user terminal; a question database for managing a plurality of questions for the user regarding a part of the management data of the user; an authentication unit that authenticates the user who has accessed the system through the user terminal; The authentication unit Requesting the user terminal to input acceptance data, which is at least one of the user identification data and the order identification data, and inquiring the electronic commerce server about the acceptance data input by the user terminal; When registration data, which is at least a part of the management data associated with the identification data indicated by the reception data, is acquired, at least one question is randomly selected from the plurality of questions, an answer to the selected question is requested from the user terminal, answer data inputted by the user terminal is accepted, and authentication is performed when the answer data is determined to be correct based on the registration data. Authentication system.

2. The authentication unit accepts the answer data within a time limit and authenticates the answer if it is correct. The authentication system according to claim 1 .

3. The authentication unit randomly selects a question from the plurality of questions that does not overlap with a previous question, and performs authentication when the question is answered correctly in succession.

3. An authentication system according to claim 1 or 2.

4. The received data is the order identification data, Furthermore, the authentication unit accepts a cancellation process for the order when authentication is successful. The authentication system according to claim 1 .

5. The received data is the order identification data, Furthermore, the authentication unit accepts the return processing when authentication is successful. The authentication system according to claim 1 .

6. The reception data is the user identification data, Furthermore, the authentication unit accepts a password change process when authentication is successful. The authentication system according to claim 1 .

7. The question includes a question about a part of personal data in the management data. The authentication system according to claim 1 .

8. 1. A method for authenticating a user accessing an electronic commerce server, comprising: the electronic commerce server manages management data including user identification data assigned to each registered user, personal data associated with the user identification data, order identification data assigned to each order, and order data associated with the order identification data; the authentication system includes a question database for managing a plurality of questions that ask the user about a part of the management data of the user; The authentication method includes the steps of: Requesting a user terminal to input acceptance data, which is at least one of the user identification data and the order identification data, and inquiring the electronic commerce server about the acceptance data input by the user terminal; When registration data, which is at least a part of the management data associated with the identification data indicated by the reception data, is acquired, at least one question is randomly selected from the plurality of questions; Requesting an answer to the selected question from the user terminal, and accepting answer data input by the user terminal; When the answer data is determined to be correct based on the registered data, authentication is performed. Authentication method.

9. A computer program product for carrying out the authentication method according to claim 8.

Citation Information

Patent Citations

  • Device and method for authentication

    JP2002073198A