Authentication method and system for authenticating server or terminal using public key encryption scheme
The authentication method uses cryptographic key pairs to securely authenticate servers and terminals without relying on reusable user IDs and passwords, enhancing security by ensuring unique authentication codes for each session.
Patent Information
- Application Number
- JP2023204830
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-16
AI Technical Summary
Conventional authentication methods for servers and terminals rely on reusable user IDs and passwords, making it difficult to authenticate users without risking security breaches when IDs are leaked.
The method involves generating server and terminal private and public keys, using these keys to encrypt and decrypt authentication codes, and transmitting encrypted codes between the server and terminal without revealing the private keys, thus eliminating the need for reusable user IDs and passwords.
This approach enhances security by ensuring that each authentication is unique and cannot be reused, thereby preventing unauthorized access and improving user authentication without relying on user IDs and passwords.
Smart Images

Figure 2025089884000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technique for authenticating a server or a terminal. In particular, it relates to a technique for a user ID (Identifier) and password that a terminal transmits to a server when the server authenticates the terminal.
Background Art
[0002] Conventionally, when a terminal authenticates a server via the Internet, a server certificate is used. Examples of protocols include TLS (Transport Layer Security) and SSL (Secure Socket Layer). The server certificate contains the server public key, and the terminal can verify the SSL server certificate by confirming the signature with the root certificate of the browser. TLS and SSL are technologies that combine security technologies such as public key cryptography, private key cryptography, digital certificates, and hash functions to prevent eavesdropping, tampering, and impersonation of data. By using such technologies, the terminal authenticates that the destination server is a legitimate server. On the other hand, when the server authenticates the terminal, the server sends an inquiry page for the user ID and password to the terminal. The terminal prompts the user to enter the user ID and password and sends this information to the server. Thereby, the server can authenticate the user operating the terminal.
[0003] Conventionally, there is a technique for authentication when a terminal controls a device in a system having a server, a terminal, and a device (see, for example, Patent Document 1). According to this technique, both the server and the device generate a time-based one-time password. The server transmits the one-time password generated by itself to the device via the terminal. The device accepts control by the terminal when the one-time password received from the terminal matches the one-time password generated by itself. In addition, there is also a security technology that supports multiple users and allows encrypted confidential information to be transferred not only to the owner but also to other users permitted by the owner (see, for example, Patent Document 2). According to this technology, multiple distributed keys are generated from a user key by secret sharing, each distributed key is held by each of the multiple users, and verification is performed using the hash value of the distributed key.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0005] According to the conventional technology described above, in order for the server to identify the user operating the terminal, it was common to use a user ID and password. In this case, the user would reuse the user ID and the like each time logging in to the server. Therefore, when the user ID and the like were leaked, there was a problem that it became difficult to authenticate the user. When using a user ID and the like, it is not assumed that the server always authenticates the terminal used by the user in a limited manner.
[0006] In contrast, the inventor of the present application considered whether the server could authenticate the terminal without a user ID or the like within an application. That is, the user operating the terminal can log in without a user ID or the like as long as using that application. Similarly, it was considered whether the terminal could authenticate the server without a server certificate within an application. That is, the user operating the terminal can authenticate the server without a server certificate and log in as long as using that application.
[0007] Also, according to the inventor of the present application, it was considered whether the server could authenticate that a first user operating a first terminal and a second user operating a second terminal are in a trust relationship without a user ID or the like. For example, when the confidential information of the first user stored in the first terminal is transferred to the second terminal of the second user, in some cases, the server may want to authenticate even the trust relationship between the first user and the second user. As confidential information transmitted and received under such a trust relationship, for example, there are cases where the inheritance information of the decedent is transferred to the heir or the biological information of the patient is transferred to the doctor.
[0008] Therefore, an object of the present invention is to provide an authentication method and a system that can authenticate a terminal or a server in an application without reusing a user ID and password for the server or the terminal.
Means for Solving the Problems
[0009] According to the present invention, in an authentication method in which a server authenticates a terminal operated by a user, a first step in which the server generates a server private key and a server public key; a second step in which the server generates a server authentication code for the terminal; a third step in which the server generates an encrypted server authentication code obtained by encrypting the server authentication code with the server public key; a fourth step in which the server transmits the encrypted server authentication code to the terminal; a fifth step in which the terminal transmits the encrypted server authentication code to the server when logging in to the server; a sixth step in which the server decrypts the encrypted server authentication code received from the terminal with the server private key to reproduce the server authentication code and authenticates the terminal characterized by having.
[0010] According to another embodiment of the authentication method of the present invention, The terminal has a specific application installed, stores the encrypted server authentication code within the specific application without disclosing it to the user, and the server is accessed by the terminal through the specific application. This is also preferable.
[0011] According to another embodiment of the authentication method of the present invention, Regarding the second step, the server generates a random one-time password as the server authentication code, and after successful authentication in the sixth step, repeats from the second step. This is also preferable.
[0012] According to another embodiment of the authentication method of the present invention, Regarding the second step, the server further combines user identification information with the server authentication code. This is also preferable.
[0013] According to another embodiment of the authentication method of the present invention, The server grants permissions for each file and / or directory that is confidential information to the owner user, owner group, and other users respectively. Regarding the second step, the server further includes the user identifier and group identifier that are user identification information and the home directory as the server authentication code. After successful authentication in the sixth step, the terminal is first accessed to the home directory included in the server authentication code, and access is performed for each file and / or directory according to the permissions for the user identifier and group identifier included in the server authentication code. This is also preferable.
[0014] According to another embodiment of the authentication method of the present invention, Regarding the first step, the eleventh step in which the server transmits the server public key to the terminal, A twelfth step in which the terminal generates encrypted user identification information by encrypting the user identification information with the server public key; A thirteenth step in which the terminal transmits the encrypted user identification information to the server; A fourteenth step in which the server decrypts the encrypted user identification information received from the terminal with the server private key to reproduce the user identification information It is also preferable to have.
[0015] According to another embodiment of the authentication method of the present invention, As an eleventh step, An 111th step in which the terminal generates a terminal private key and a terminal public key; An 112th step in which the terminal transmits the terminal public key to the server; An 113th step in which the server generates an encrypted server public key by encrypting the server public key with the terminal public key; An 114th step in which the server transmits the encrypted server public key to the terminal; An 115th step in which the terminal decrypts the encrypted server public key with the terminal private key to reproduce the server public key It is also preferable to have.
[0016] According to another embodiment of the authentication method of the present invention, A seventh step in which the terminal generates a terminal private key and a terminal public key; An eighth step in which the terminal generates a terminal authentication code for the server; A ninth step in which the terminal generates an encrypted terminal authentication code by encrypting the terminal authentication code with the terminal public key; A tenth step in which the terminal transmits the encrypted terminal authentication code to the server; An eleventh step in which the server transmits the encrypted terminal authentication code to the terminal when logging in from the terminal to the server; A twelfth step in which the terminal decrypts the terminal encrypted authentication code received from the server with the terminal private key to reproduce the terminal authentication code and authenticates the server It is also preferable to have.
[0017] According to the present invention, in an authentication method in which a terminal operated by a user authenticates a server, a first step in which the terminal generates a terminal private key and a terminal public key; a second step in which the terminal generates a terminal authentication code for the server; a third step in which the terminal generates an encrypted terminal authentication code obtained by encrypting the terminal authentication code with the terminal public key; a fourth step in which the terminal transmits the encrypted terminal authentication code to the server; a fifth step in which, when logging in from the terminal to the server, the server transmits the encrypted terminal authentication code to the terminal; a sixth step in which the terminal decrypts the encrypted terminal authentication code received from the server with the terminal private key to reproduce the terminal authentication code and authenticates the server characterized by having.
[0018] According to the present invention, in an authentication method in which a server associates and authenticates a first terminal and a second terminal operated by a user, a first step in which the server generates a server private key and a server public key; a second step in which the server generates a first server authentication code for the first terminal; a third step in which the server generates a first encrypted server authentication code obtained by encrypting the first server authentication code with the server public key; a forty-first step in which the server transmits the first encrypted server authentication code to the first terminal; a forty-second step in which the first terminal transfers the first encrypted server authentication code received from the server to the second terminal; a fifth step in which the second terminal transmits the first encrypted server authentication code to the server when logging in to the server; The sixth step in which the server decrypts the first encrypted server authentication code received from the second terminal with the server private key to reproduce the first server authentication code, and authenticates that the second terminal is associated with the first terminal is characterized by having
[0019] According to the present invention, the first terminal and the second terminal are connected by short-range wireless communication, narrow-area wireless communication, or wired communication, In the fifth step, based on an operation of a first user on the first terminal, the first encrypted server authentication code is transferred to the second terminal is characterized by
[0020] According to the present invention, after successful authentication in the sixth step, the server has a seventh step of generating a second server authentication code for the second terminal, an eighth step in which the server generates a second encrypted server authentication code obtained by encrypting the second server authentication code with the server public key, a ninety-first step in which the server transmits the second encrypted server authentication code to the second terminal, a ninety-second step in which the second terminal transfers the second encrypted server authentication code received from the server to the first terminal, a ninety-third step in which the first terminal transmits the second encrypted server authentication code to the server, a tenth step in which the server decrypts the second encrypted server authentication code received from the first terminal with the server private key to reproduce the second server authentication code, and authenticates that the first terminal is associated with the second terminal is further characterized by having
[0021] According to another embodiment of the authentication method of the present invention, Regarding the forty-second step, a four-hundred-and-twenty-first step in which the first terminal transmits the first public key to the second terminal, a four-hundred-and-twenty-second step in which the second terminal encrypts the second public key with the first public key and transmits it to the first terminal, The 423rd step in which the first terminal decrypts with the first private key and extracts the second public key, The 424th step in which the first terminal encrypts the first encrypted server authentication code received from the server with the second public key and transfers it to the second terminal, The 425th step in which the second terminal decrypts with the second private key and extracts the first encrypted server authentication code characterized by having.
[0022] According to another embodiment of the authentication method of the present invention, The first terminal is operated by a first user who stores personal information in the server, The second terminal is operated by a second user who accesses the personal information of the first user in the server is also preferable.
[0023] According to the present invention, in a system in which a server authenticates a terminal operated by a user, The server generates a server private key and a server public key, The server generates a server authentication code for the terminal, The server generates an encrypted server authentication code obtained by encrypting the server authentication code with the server public key, The server transmits the encrypted server authentication code to the terminal, When logging in to the server, the terminal transmits the encrypted server authentication code to the server, The server decrypts the encrypted server authentication code received from the terminal with the server private key to reproduce the server authentication code, and authenticates the terminal characterized by.
[0024] According to the present invention, in a system in which a terminal operated by a user authenticates a server, The terminal generates a terminal private key and a terminal public key, The terminal generates a terminal authentication code for the server, The terminal generates an encrypted terminal authentication code by encrypting the terminal authentication code with the terminal public key, The terminal transmits the encrypted terminal authentication code to the server, When logging in from the terminal to the server, the server transmits the encrypted terminal authentication code to the terminal, The terminal decrypts the encrypted terminal authentication code received from the server with the terminal private key to reproduce the terminal authentication code and authenticates the server characterized by this.
[0025] According to the present invention, in a system in which a server associates and authenticates a first terminal and a second terminal operated by a user, The server generates a server private key and a server public key, The server generates a first server authentication code for the first terminal, The server generates a first encrypted server authentication code by encrypting the first server authentication code with the server public key, The server transmits the first encrypted server authentication code to the first terminal, The first terminal transfers the first encrypted server authentication code received from the server to the second terminal, When logging in to the server, the second terminal transmits the first encrypted server authentication code to the server, The server decrypts the first encrypted server authentication code received from the second terminal with the server private key to reproduce the first server authentication code and authenticates that the second terminal is associated with the first terminal characterized by this.
Advantages of the Invention
[0026] According to the authentication method and system of the present invention, for a server or a terminal, the terminal or the server can be authenticated in an application without reusing the user ID and password.
Brief Description of the Drawings
[0027]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Embodiments for Carrying Out the Invention
[0028] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0029] FIG. 1 is a sequence diagram for a server in the present invention to authenticate a terminal.
[0030] According to the sequence of FIG. 1, the server 2 authenticates the terminal 1 operated by the user. Terminal 1 has a specific application installed and accesses Server 2 from that application. Terminal 1 is not limited to a user's smartphone or personal computer, and may be a disk device or a cloud device. Terminal 1 may access other devices that function as servers via a network as long as it can do so. Server 2 is accessed from Terminal 1 by that specific application. At that time, Server 2 executes a sequence to authenticate Terminal 1 operated by the user.
[0031] <Encryption stage> (S1) Server 2 generates a "server private key" and a "server public key". This is a general public key encryption method (for example, RSA encryption). Information encrypted with the public key can only be decrypted with the private key (encryption), and information encrypted with the private key can only be decrypted with the public key (signature).
[0032] (S2) Server 2 generates a "server authentication code" for Terminal 1. Here, the server authentication code may be, for example, a random "one-time password". By using a one-time password, Server 2 will generate a new one-time password each time it determines that authentication is successful upon login from Terminal 1.
[0033] (S3) Server 2 generates an "encrypted server authentication code" by encrypting the server authentication code with the "server public key".
[0034] (S4) Server 2 sends the encrypted server authentication code to Terminal 1. Then, Terminal 1 stores the encrypted server authentication code in that specific application. Here, the encrypted server authentication code is confined within that specific application and not disclosed to the user at all. Of course, since Terminal 1 does not know the server private key, it cannot decrypt the encrypted server authentication code either.
[0035] (S5) Subsequently, assume that the terminal 1 attempts to log in to the server 2. This is executed based on the user's operation on the terminal 1. At this time, the terminal 1 automatically sends the encrypted server authentication code to the server 2 via the application.
[0036] (S6) The server 2 decrypts the encrypted server authentication code received from the terminal 1 using the "server private key" to reproduce the "server authentication code". The reproduced server authentication code is, for example, a one-time password. Then, when the reproduced server authentication code matches the server authentication code generated in step S2, the server 2 determines that the authentication for the terminal 1 is successful.
[0037] Also, after the server 2 determines that the authentication is successful in step S6, it repeats the execution from step S2 again. As a result, each time the terminal 1 logs in and the authentication is successful, the server 2 will generate a new server authentication code (one-time password). The terminal 1 operates in the background with the app running and repeats for each login process.
[0038] The most important point in the sequence of FIG. 1 is that the encrypted server authentication code sent by the terminal 1 to the server 2 during login is encrypted with the "server public key". Therefore, since the terminal 1 naturally does not have the server private key, it cannot decrypt the encrypted server authentication code. The terminal 1 cannot log in unless it sends the encrypted server authentication code received from the server 2 to the server 2 as it is. Moreover, the encrypted server authentication code sent by the terminal 1 to the server 2 when logging in is different each time it logs in and can only be used once. As a result, from the perspective of the server 2, it can always authentically limit the terminal 1 used by the user without reusing the encrypted server authentication code required during login.
[0039] Figure 2 is a sequence diagram for encrypting user identification information transmitted from a terminal to a server.
[0040] Server 2 assigns "permissions" for each owner user, each owner group, and each other user, for example, for each file that is confidential information and / or for each directory. Permissions mean access rights. According to Figure 2, for example, the access rights to file AAA stored in directory / home / user1 are shown. (Type) l (Owner user access rights) rwx (Owner group access rights) rwx (Other user access rights) r-x (File information) 1 user1 group1 15 Apr 20 13:00 AAA Permissions generally are as follows. r Read w Write x Execute - None File information is, for example, information as follows. Number of links, owner name, owner group name, file size, last update date and time, file name
[0041] Terminal 1 has the "user identification information" of the operating user. User identification information is information about the user with respect to the access rights of Server 2. According to Figure 2, for example, the following user identification information is shown. (User name) USER1 (Login password) PW (User ID) user1 (Group ID) group1 (Home directory) / home / user1 (Login shell) / bin / bash The user ID may be arbitrarily determined alphanumeric characters by the user himself or by the server 2. As another embodiment, in the case of a mobile terminal such as a smartphone, it may be a unique identification number stored in the SIM card.
[0042] According to the sequence of FIG. 2, the confidentiality of the "user identification information" of the user operating the terminal 1 that has accessed the server 2 can be enhanced. This is executed when the server 2 generates the "server private key" and the "server public key" in step S1 of FIG. 1.
[0043] (S10) The server 2 generates a "server private key" and a "server public key". (S11) The server 2 transmits the "server public key" to the terminal 1. (S12) The terminal 1 generates "encrypted user identification information" obtained by encrypting user identification information (for example, user ID) with the "server public key". (S13) The terminal 1 transmits the encrypted user identification information to the server 2. (S14) The server 2 decrypts the encrypted user identification information received from the terminal 1 with the "server private key" and reproduces the user identification information. (S15) The server 2 identifies the user based on the user identification information.
[0044] As a result, as step S2, the server 2 can generate a server authentication code by further combining the "user identification information" with the one-time password. Server authentication code = One-time password + User identification information As a result, the user identification information is not transferred as plain text on the network.
[0045] According to FIG. 2, for step S2, the server 2 further includes, as the server authentication code, at least a user identifier (ID) that is the user identification information, a group identifier (ID), and a home directory. Although not shown in FIG. 2, after successful authentication in step S6 executed thereafter, the terminal 1 is first made to access the home directory included in the server authentication code. Then, the server 2 allows access for each file and / or for each directory according to the permissions for the user identifier and group identifier included in the server authentication code. According to FIG. 2, this means that the terminal 1 can access / home / user1 of the server 2 immediately after logging in.
[0046] FIG. 3 is a sequence diagram for encrypting the server public key transmitted from the server to the terminal.
[0047] According to the sequence of FIG. 3, regarding step S11 of FIG. 2, the confidentiality of the server public key can be enhanced. Generally, the server public key is assumed to be public, but since it is also the key for encrypting the server authentication code, an attempt is made to further improve the confidentiality. That is, the server public key is not transferred as plain text.
[0048] (S111) The terminal 1 generates a "terminal private key" and a "terminal public key". (S112) The terminal 1 transmits the "terminal public key" to the server 2. (S113) The server 2 generates an "encrypted server public key" obtained by encrypting the server public key with the "terminal public key". (S114) The server 2 transmits the encrypted server public key to the terminal 1. (S115) The terminal 1 decrypts the encrypted server public key with the "terminal private key" to reproduce the server public key. Thereafter, steps S12 and subsequent steps of FIG. 2 are executed.
[0049] FIG. 4 is a sequence diagram for authenticating the terminal and authenticating the server.
[0050] According to FIG. 4, steps S1 to S6 are the sequence in which the server 2 authenticates the terminal 1, which is exactly the same as FIG. 1. Steps S7 to S12 represent, symmetrically to steps S1 to S6, the sequence in which the terminal 1 authenticates the server 2.
[0051] (S7) The terminal 1 generates a "terminal private key" and a "terminal public key". (S8) The terminal 1 generates a "terminal authentication code" for the server 2. The terminal authentication code is preferably a random one-time password. (S9) The terminal 1 generates an "encrypted terminal authentication code" obtained by encrypting the terminal authentication code with the "terminal public key". (S10) The terminal 1 transmits the encrypted terminal authentication code to the server 2. (S11) When logging in from the terminal 1 to the server 2, the server 2 transmits the "encrypted terminal authentication code" to the terminal 1. (S12) The terminal 1 decrypts the terminal encrypted authentication code received from the server 2 with the "terminal private key" to reproduce the terminal authentication code. Then, when the reproduced terminal authentication code matches the server authentication code generated in step S8, the terminal 1 determines that the authentication of the server 2 is successful.
[0052] Also, after the terminal 1 determines that the authentication is successful in step S12, it repeats the execution from step S8 again. As a result, each time the terminal 1 successfully authenticates the server 2 before logging in, it generates a new terminal authentication code (one-time password).
[0053] FIG. 5 is a sequence diagram of the terminal authenticating the server in the present invention.
[0054] The sequence in FIG. 5 is such that, for the sequence in FIG. 4, the terminal operated by the user only executes the sequence of authenticating the server. (S1) The terminal 1 generates a "terminal private key" and a "terminal public key". (S2) The terminal 1 generates a "terminal authentication code" for the server 2. It is also preferable to generate a random one-time password as the terminal authentication code. (S3) The terminal 1 generates an "encrypted terminal authentication code" by encrypting the terminal authentication code with the "terminal public key". (S4) The terminal 1 transmits the "encrypted terminal authentication code" to the server 2. (S5) When logging in from the terminal 1 to the server 2, the server 2 transmits the "encrypted terminal authentication code" to the terminal 1. (S6) The terminal 1 decrypts the "encrypted terminal authentication code" received from the server 2 with the "terminal private key" to reproduce the "terminal authentication code". And when the reproduced terminal authentication code matches the server authentication code generated in step S2, the terminal 1 determines that the authentication with the server 2 is successful.
[0055] Also, after the terminal 1 determines that the authentication is successful in step S6, it repeats the execution from step S2 again. As a result, each time the terminal 1 successfully authenticates the server 2 before logging in, it will generate a new terminal authentication code (one-time password).
[0056] FIG. 6 is a system configuration diagram in which a server authenticates a first terminal via a second terminal.
[0057] According to FIG. 6, the first terminal 11 and the second terminal 12 are connected by short-range wireless communication (such as Bluetooth or Zigbee), short-range wireless communication (such as wireless LAN (Local Area Network)), or wired communication (USB (Universal Serial Bus) cable connection). Of course, if the amount of communication information is small, non-contact communication such as NFC (Near Field Communication) may also be used.
[0058] Here, the first terminal 11 and the second terminal 12 are preferably directly connected, and short-range wireless communication or wired communication is suitable. Since the transfer of secret information needs to be executed only based on the trust relationship between the first user and the second user, it is preferably a face-to-face and direct connection.
[0059] According to FIG. 6, for example, an inheritance management service between an heir and a successor, or a medical information management service between a patient and a doctor is assumed. For example, in the case of an inheritance management service, the first user operating the first terminal 11 becomes the "heir", and the second user operating the second terminal 12 becomes the "successor". Assume that the first user stores inheritance information in the first terminal 11 (such as a smartphone or a personal computer) he or she owns. The s information is not limited to financial asset information and real estate asset information, and may include will information and multimedia data (such as photos, voices, videos, etc.). According to the present invention, the server 2 can link and authenticate the heir and the successor.
[0060] FIG. 7 is a sequence diagram in which the server authenticates the second terminal via the first terminal.
[0061] According to FIG. 7, the server 2 links and authenticates the first terminal 11 operated by the first user and the second terminal 12 operated by the second user. (S1) First, the server 2 generates a "server private key" and a "server public key". (S2) The server 2 generates a "first server authentication code" for the first terminal 11. (S3) The server 2 generates a "first encrypted server authentication code" obtained by encrypting the first server authentication code with the "server public key". (S41) The server 2 transmits the "first encrypted server authentication code" to the first terminal 11. (S42) The first terminal 11 transfers the "first encrypted server authentication code" received from the server 2 to the second terminal 12. (S5) When the second terminal 12 logs in to the server 2, it sends the "first encrypted server authentication code" to the server 2. Here, based on the operation of the first user on the first terminal 11, the first encrypted server authentication code is transferred to the second terminal 12. (S6) The server 2 decrypts the "first encrypted server authentication code" received from the second terminal 12 with the server private key to reproduce the "first server authentication code", and authenticates that the second terminal is associated with the first terminal.
[0062] Here, in the case of FIG. 7, the first server authentication code includes the user identification information of the user of the first terminal 11. The server 2 will receive the first server authentication code from the second terminal 12. This means that the server 2 is authenticating the first terminal 11 via the second terminal 12.
[0063] FIG. 8 is a sequence diagram in which the server authenticates the first terminal via the second terminal.
[0064] (S7) After the authentication in step S6 is successful, the server 2 generates a "second server authentication code" for the second terminal 12. (S8) The server 2 generates a "second encrypted server authentication code" obtained by encrypting the second server authentication code with the server public key. (S91) The server 2 sends the "second encrypted server authentication code" to the second terminal 12. (S92) The second terminal 12 transfers the "second encrypted server authentication code" received from the server 2 to the first terminal 11. (S93) The first terminal 11 sends the "second encrypted server authentication code" to the server 2. (S10) The server 2 decrypts the "second encrypted server authentication code" received from the first terminal 11 with the server private key to reproduce the "second server authentication code", and authenticates that the first terminal 11 is associated with the second terminal 12.
[0065] Here, in the case of FIG. 8, the second server authentication code includes the user identification information of the user of the second terminal 12. The server 2 will receive the second server authentication code from the first terminal 11. This means that the server 2 is authenticating the second terminal 12 via the first terminal 11.
[0066] According to FIG. 1 described above, the terminal 1 is authenticated when logging in to the server 2. In contrast, according to FIGS. 7 and 8, the terminals from which the "encrypted server authentication code" received by the server 2 is sent are different. According to FIGS. 7 and 8, the server 2 authenticates by associating the terminal 11 operated by the first user and the terminal 12 operated by the second user. Also, by making the "group ID" of both the first server authentication code and the second server authentication code the same, the first terminal 11 and the second terminal 12 are authenticated as the same group. When the confidential information is something like legacy information, both the first user and the second user can also access the confidential information by constructing server authentication codes with the same group ID.
[0067] FIG. 9 is a sequence diagram in which the first terminal transmits an encrypted server authentication code to a second terminal in a trust relationship.
[0068] It is assumed that the first terminal 11 and the second terminal 12 can communicate with each other by short-range wireless communication, narrow-area wireless communication, or wired communication through the operations of the first user and the second user respectively. On the front end on the user side, at least an arbitrary second pairing number (one-time password, PIN (Personal Identification Number), or link key) is displayed on the display of the second terminal 12. Also, on the back end, the second terminal 12 transmits the second pairing number to the first terminal 11. According to FIG. 9, the second pairing number
[12345] is displayed on the second terminal 12. The first terminal 11 causes the first user to input the second pairing number
[12345] displayed on the second terminal 12 that is the connection partner. When the pairing number received from the second terminal 12 matches the pairing number input by the operation of the first user, the first terminal 11 determines that the authentication is OK.
[0069] The pairing number is a password for users to authenticate each other at the same location, and is, for example, a five-digit number. For example, when the pairing number input by the user is incorrect continuously for a predetermined number of times (for example, three times), it will be locked and further input of the pairing number will be prohibited.
[0070] It may further include the operation of the second user on the terminal 12. On the other hand of the front end on the user side, an arbitrary first pairing number is displayed on the display of the first terminal 11. Also, at the back end, the first terminal 11 transmits the first pairing number to the second terminal 12. According to FIG. 9, the first pairing number
[67890] is displayed on the first terminal 11. The second terminal 12 causes the second user to input the first pairing number
[67890] displayed on the first terminal 11 that is the connection partner. When the pairing number received from the first terminal 11 matches the pairing number input by the operation of the second user, the second terminal 12 determines that the authentication is OK.
[0071] Determining that the authentication is OK for the first terminal 11 or the second terminal 12 means that the operation is executed based on the trust relationship between the first user and the second user.
[0072] According to FIG. 9, for step S42, the following sequence is executed. (S421) The first terminal 11 transmits the first public key to the second terminal 12. (S422) The second terminal 12 encrypts the second public key with the first public key and transmits it to the first terminal 11. (S423) The first terminal 11 decrypts using the first private key and extracts the second public key. (S424) The first terminal 11 encrypts the "first encrypted server authentication code" received from the server 2 using the second public key and transfers it to the second terminal 12. (S425) Then, the second terminal 12 decrypts using the second private key and extracts the "first encrypted server authentication code".
[0073] Here, the most important point is that the confidentiality of the "second public key" is ensured. Since the second public key is used for encrypting the first encrypted server authentication code in step S424, it is deliberately made so that it cannot be known by devices other than the first terminal 11.
[0074] Also, regarding step S92 in FIG. 8 described above, it is also preferable to use the "second private key" to decrypt the second encrypted server authentication code. According to the present invention, the "second public key" corresponding to the second private key has its confidentiality ensured outside the first terminal 11. That is, the "second public key" is actually not publicly disclosed at all and is used as a private key known only to the first terminal 11 and the second terminal 12. The second encrypted server authentication code encrypted by such a second public key can maintain its high confidentiality.
[0075] <Application of the present invention to personal information access services> As a personal information access service, for example, when a first user accumulates their own personal information on a server and then designates a second user, it refers to a service in which the second user can access the personal information of the first user. For example, as the second user, it may be the case where a relative such as a spouse or child of the first user is designated, or it may be the case where a trust bank is designated. As the personal information of the first user, for example, a bank account or an ID (Identifier) is assumed.
[0076] FIG. 10 is an explanatory diagram of applying the present invention to a personal information access service.
[0077] According to FIG. 10, the following three stages in the personal information access service are represented. (a) Access stage of the first user (b) Designation stage of the second user (c) Access stage of the second user
[0078] In FIG. 10(a), an authentication process is executed between the first terminal 11 operated by the first user and the server 2. Then, the first user can store his / her personal information in the server 2. Here, it is only necessary that the first terminal 11 and the server 2 can communicate, and the sequence of the embodiments in FIGS. 1 to 5 described above is applied.
[0079] In FIG. 10(b), the first user designates the second user. At this time, an authentication process is executed among the first terminal 11 operated by the first user, the second terminal 12 operated by the second user, and the server 2. The server 2 authenticates the second terminal 12 of the second user via the first terminal 11 of the first user. Also, the server 2 authenticates the first terminal 11 of the first user via the second terminal 12 of the second user. Here, it is necessary for the first user's terminal 11, the second user's terminal 12, and the server 2 to communicate with each other, and the sequence of the embodiments in FIGS. 6 to 9 described above is applied.
[0080] In FIG. 10(c), an authentication process is executed between the second terminal 12 operated by the second user and the server 2. Then, the second user can access the personal information of the first user stored in the server 2. Here, it is only necessary that the second terminal 12 and the server 2 can communicate, and the sequence of the embodiments in FIGS. 1 to 5 described above is applied.
[0081] As described in detail above, according to the authentication method and system of the present invention, for a server or a terminal, the terminal or the server can be authenticated in an application without reusing the user ID and password.
[0082] According to the present invention, from the perspective of the server, the terminal used by the user can always be limitedly authenticated without reusing the user ID and password. Also, from the perspective of the terminal, the server managed by a specific application can also always be limitedly authenticated. Furthermore, from the perspective of the server, it is also possible to manage that both the first terminal used by the first user and the second terminal used by the second user can communicate under the trust relationship between the first user and the second user.
[0083] Regarding the various embodiments of the present invention described above, various changes, modifications, and omissions within the scope of the technical idea and perspective of the present invention can be easily made by those skilled in the art. The above description is merely an example and is not intended to impose any restrictions. The present invention is limited only by the scope of the claims and their equivalents.
Explanation of Reference Numerals
[0084] 1 Terminal 11 First Terminal 12 Second Terminal 2 Server
Claims
1. In an authentication method in which a server authenticates a terminal operated by a user, a first step in which the server generates a server private key and a server public key; a second step in which the server generates a server authentication code for the terminal; a third step in which the server generates an encrypted server authentication code obtained by encrypting the server authentication code with the server public key; a fourth step in which the server transmits the encrypted server authentication code to the terminal; a fifth step in which the terminal transmits the encrypted server authentication code to the server when logging in to the server; a sixth step in which the server decrypts the encrypted server authentication code received from the terminal with the server private key to reproduce the server authentication code and authenticates the terminal An authentication method characterized by comprising the above.
2. The terminal has a specific application installed, stores the encrypted server authentication code in the specific application without disclosing it to the user, and the server is accessed by the terminal through the specific application The authentication method according to claim 1, characterized by the above.
3. Regarding the second step, the server includes a random one-time password as the server authentication code, and repeats from the second step after successful authentication in the sixth step The authentication method according to claim 1 or 2, characterized by the above.
4. Regarding the second step, the server further combines user identification information with the server authentication code The authentication method according to claim 1 or 2, characterized by the above.
5. The server grants permissions for each file and / or directory that is confidential information to the owner user, owner group, and other users respectively. Regarding the second step, the server further includes, as the server authentication code, the user identifier and group identifier that are user identification information and the home directory. After successful authentication in the sixth step, the terminal is first made to access the home directory included in the server authentication code, and access is made for each file and / or directory according to the permissions for the user identifier and group identifier included in the server authentication code. The authentication method according to claim 4, characterized in that.
6. Regarding the first step, The eleventh step in which the server transmits the server public key to the terminal, The twelfth step in which the terminal generates encrypted user identification information obtained by encrypting the user identification information with the server public key, The thirteenth step in which the terminal transmits the encrypted user identification information to the server, The fourteenth step in which the server decrypts the encrypted user identification information received from the terminal with the server private key and regenerates the user identification information The authentication method according to claim 4, characterized by having.
7. As the eleventh step, The 111th step in which the terminal generates a terminal private key and a terminal public key, The 112th step in which the terminal transmits the terminal public key to the server, The 113th step in which the server generates an encrypted server public key obtained by encrypting the server public key with the terminal public key, The 114th step in which the server transmits the encrypted server public key to the terminal, The 115th step in which the terminal decrypts the encrypted server public key with the terminal private key and regenerates the server public key The authentication method according to claim 6, characterized by having
8. a seventh step in which the terminal generates a terminal private key and a terminal public key; an eighth step in which the terminal generates a terminal authentication code for the server; a ninth step in which the terminal generates an encrypted terminal authentication code obtained by encrypting the terminal authentication code with the terminal public key; a tenth step in which the terminal transmits the encrypted terminal authentication code to the server; an eleventh step in which, when logging in from the terminal to the server, the server transmits the encrypted terminal authentication code to the terminal; a twelfth step in which the terminal decrypts the terminal encrypted authentication code received from the server with the terminal private key to reproduce the terminal authentication code and authenticates the server The authentication method according to claim 1 or 2, characterized by having
9. In an authentication method in which a terminal operated by a user authenticates a server, a first step in which the terminal generates a terminal private key and a terminal public key; a second step in which the terminal generates a terminal authentication code for the server; a third step in which the terminal generates an encrypted terminal authentication code obtained by encrypting the terminal authentication code with the terminal public key; a fourth step in which the terminal transmits the encrypted terminal authentication code to the server; a fifth step in which, when logging in from the terminal to the server, the server transmits the encrypted terminal authentication code to the terminal; a sixth step in which the terminal decrypts the encrypted terminal authentication code received from the server with the terminal private key to reproduce the terminal authentication code and authenticates the server The authentication method characterized by having
10. In an authentication method in which a server associates and authenticates a first terminal and a second terminal operated by a user, A first step in which the server generates a server private key and a server public key; A second step in which the server generates a first server authentication code for the first terminal; A third step in which the server generates a first encrypted server authentication code obtained by encrypting the first server authentication code with the server public key; A forty-first step in which the server transmits the first encrypted server authentication code to the first terminal; A forty-second step in which the first terminal transfers the first encrypted server authentication code received from the server to the second terminal; A fifth step in which the second terminal transmits the first encrypted server authentication code to the server when logging in to the server; A sixth step in which the server decrypts the first encrypted server authentication code received from the second terminal with the server private key to reproduce the first server authentication code, and authenticates that the second terminal is associated with the first terminal; An authentication method characterized by comprising the above steps.
11. The first terminal and the second terminal are connected by short-range wireless communication, narrow-area wireless communication, or wired communication, In the fifth step, based on an operation of a first user on the first terminal, the first encrypted server authentication code is transferred to the second terminal. The authentication method according to claim 10, characterized by the above.
12. A seventh step in which, after successful authentication in the sixth step, the server generates a second server authentication code for the second terminal; An eighth step in which the server generates a second encrypted server authentication code obtained by encrypting the second server authentication code with the server public key; A ninety-first step in which the server transmits the second encrypted server authentication code to the second terminal; A ninety-second step in which the second terminal transfers the second encrypted server authentication code received from the server to the first terminal; A 93rd step in which a first terminal transmits a second encrypted server authentication code to a server; A 10th step in which the server decrypts the second encrypted server authentication code received from the first terminal with a server private key to reproduce a second server authentication code, and authenticates that the first terminal is associated with the second terminal; The authentication method according to claim 10 or 11, further comprising: **Claim 13** Regarding the 42nd step, A 421st step in which a first terminal transmits a first public key to a second terminal; A 422nd step in which the second terminal encrypts a second public key with the first public key and transmits it to the first terminal; A 423rd step in which the first terminal decrypts with a first private key and extracts the second public key; A 424th step in which the first terminal encrypts the first encrypted server authentication code received from the server with the second public key and transfers it to the second terminal; A 425th step in which the second terminal decrypts with a second private key and extracts the first encrypted server authentication code; The authentication method according to claim 10 or 11, comprising: **Claim 14** The first terminal is operated by a first user who stores personal information in the server, The second terminal is operated by a second user who accesses the personal information of the first user in the server. The authentication method according to claim 11, characterized in that: **Claim 15** In a system in which a server authenticates a terminal operated by a user, The server generates a server private key and a server public key, The server generates a server authentication code for the terminal, The server generates an encrypted server authentication code obtained by encrypting the server authentication code with the server public key, The server transmits an encrypted server authentication code to the terminal, When the terminal logs in to the server, the terminal transmits the encrypted server authentication code to the server, The server decrypts the encrypted server authentication code received from the terminal with the server private key to reproduce the server authentication code and authenticates the terminal A system characterized by this.
16. In a system where a terminal operated by a user authenticates a server, The terminal generates a terminal private key and a terminal public key, The terminal generates a terminal authentication code for the server, The terminal generates an encrypted terminal authentication code obtained by encrypting the terminal authentication code with the terminal public key, The terminal transmits the encrypted terminal authentication code to the server, When logging in from the terminal to the server, the server transmits the encrypted terminal authentication code to the terminal, The terminal decrypts the encrypted terminal authentication code received from the server with the terminal private key to reproduce the terminal authentication code and authenticates the server A system characterized by this.
17. In a system where a server associates and authenticates a first terminal and a second terminal operated by a user, The server generates a server private key and a server public key, The server generates a first server authentication code for the first terminal, The server generates a first encrypted server authentication code obtained by encrypting the first server authentication code with the server public key, The server transmits the first encrypted server authentication code to the first terminal, The first terminal transfers the first encrypted server authentication code received from the server to the second terminal, When the second terminal logs in to the server, the second terminal transmits the first encrypted server authentication code to the server, The server decrypts the first encrypted server authentication code received from the second terminal with the server private key to reproduce the first server authentication code, and authenticates that the second terminal is associated with the first terminal A system characterized by this.
Citation Information
Patent Citations
Authentication system
JP2021050556A
Information processing system, information processing method, and information processing device
WO2020003821A1