To-be-authenticated device, authentication device, method for outputting authentication request, authentication method, and program
By encrypting initial data and using unique information for authentication requests, the system effectively prevents impersonation and ensures secure authentication.
Patent Information
- Application Number
- JP2024005185
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-17
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2044-01-16
AI Technical Summary
Existing authentication systems face challenges in preventing impersonation during the authentication process, necessitating secure authentication methods.
The authentication target device encrypts initial data to generate first encrypted data and outputs multiple authentication requests including unique information and second encrypted data, while the authentication device determines legitimacy based on matching shared data and consistent unique information.
This approach prevents spoofing and ensures secure authentication by making it difficult to predict initial data and ensuring data consistency, thereby enhancing security.
Smart Images

Figure 2025110850000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication target device, an authentication device, an authentication request output method, an authentication method, and a program.
Background Art
[0002] Conventionally, an authentication device is known that receives a plurality of authentication requests transmitted from an authentication target device and determines whether the authentication target device is legitimate using the plurality of authentication requests (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In an authentication device, when authenticating an authentication target device using a plurality of authentication requests transmitted from the authentication target device, there is a desire to perform secure authentication by preventing impersonation.
[0005] The present invention has been made in response to the above circumstances, and an object thereof is to provide an authentication target device, an authentication device, an authentication request output method, an authentication method, and a program that can achieve secure authentication by preventing impersonation.
Means for Solving the Problems
[0006] To achieve the above object, an authentication target device according to an aspect of the present invention includes an initial data acquisition unit that acquires initial data including a user identifier for identifying a user and unique information that is unique information, a first encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data, a second data acquisition unit that acquires second data including shared data shared with an authentication device, a second encryption unit that generates second encrypted data by encrypting the second data using the first data, and an output unit that outputs a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device respectively.
[0007] With such a configuration, in the authentication device that has received a plurality of authentication requests, based on whether the shared data corresponding to the second encrypted data included in the authentication request matches the shared data shared between the legitimate authentication target device and the authentication device, and whether the unique information included in the plurality of authentication requests is consistent, by determining whether the authentication target device is legitimate, it is possible to prevent spoofing and realize secure authentication. Also, by encrypting the initial data to obtain the first encrypted data, it is possible to make it difficult to predict the first data from the initial data.
[0008] Further, in the authentication target device according to an aspect of the present invention, the unique information may include at least any one of a time, a counter value, and a random number value.
[0009] With such a configuration, the unique information can be easily acquired.
[0010] Further, in the authentication target device according to an aspect of the present invention, the first encryption unit may acquire first encrypted data obtained by encrypting the initial data using an encryption key corresponding to the user identifier included in the initial data.
[0011] With such a configuration, it is possible to make it more difficult to predict the first data from the initial data.
[0012] Also, in the authentication target device according to one aspect of the present invention, the first encryption unit may acquire first encrypted data obtained by encrypting data of a predetermined data amount including initial data using an encryption key.
[0013] With such a configuration, the first encrypted data can be made to have a predetermined data amount.
[0014] Also, in the authentication target device according to one aspect of the present invention, the first encryption unit may generate first data by reducing the data amount of the first encrypted data.
[0015] With such a configuration, for example, the data amount of the authentication request can be made smaller.
[0016] Also, in the authentication target device according to one aspect of the present invention, the first encryption unit may reduce the data amount by hashing the first encrypted data.
[0017] With such a configuration, the data amount can be reduced by simple processing, and it can be made difficult to predict the first encrypted data from the first data.
[0018] Also, in the authentication target device according to one aspect of the present invention, the first encryption unit may reduce the data amount by extracting a part of the data of the first encrypted data.
[0019] With such a configuration, the data amount can be reduced by simple processing, and it can be made difficult to predict the first encrypted data from the first data.
[0020] Also, in the authentication target device according to one aspect of the present invention, the data amount of the first data and the data amount of the second data are the same, and the second encryption unit may generate second encrypted data that is the exclusive logical sum of the first data and the second data.
[0021] With such a configuration, the second data can be encrypted by simple processing.
[0022] Also, in the authentication target device according to one aspect of the present invention, the second data acquisition unit may acquire shared data from the authentication device.
[0023] With such a configuration, even if the authentication target device does not have a generator of shared data, the shared data can be shared between the authentication device and the authentication target device.
[0024] Also, in the authentication target device according to one aspect of the present invention, the shared data may include a random number.
[0025] With such a configuration, for example, the shared data can be made unique data.
[0026] Also, the authentication device according to one aspect of the present invention includes initial data including a user identifier for identifying a user and unique information that is unique information, and first data generated by acquiring first encrypted data obtained by encrypting the initial data. A reception unit that receives a plurality of different authentication requests including second encrypted data obtained by encrypting second data including shared data from the authentication target device; an encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit; a storage unit that stores shared data shared with a legitimate authentication target device; a determination unit that determines whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit matches the shared data stored in the storage unit, using the first data generated by the encryption unit; an authentication unit that determines that the authentication target device is legitimate when the unique information included in a plurality of authentication requests received from the authentication target device is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; and an authentication result output unit that outputs an authentication result that is a determination result by the authentication unit.
[0027] With such a configuration, it is possible to prevent spoofing and achieve secure authentication by determining whether the shared data corresponding to the second encrypted data included in the authentication request matches the shared data shared between the legitimate authentication device and the authenticator, and whether the unique information included in the plurality of authentication requests is consistent. Also, by encrypting the initial data to obtain the first encrypted data, it is possible to make it difficult for a third party to predict the first data.
[0028] Also, in the authenticator according to one aspect of the present invention, the unique information may include at least any one of a time, a counter value, and a random number value.
[0029] With such a configuration, the unique information can be easily obtained.
[0030] Also, in the authenticator according to one aspect of the present invention, the encryption unit may obtain the first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit using the encryption key corresponding to the user identifier included in the initial data.
[0031] With such a configuration, it is possible to make it more difficult for a third party to predict the first data.
[0032] Also, in the authenticator according to one aspect of the present invention, the encryption unit may obtain the first encrypted data obtained by encrypting data of a predetermined data amount including the initial data included in the authentication request received by the reception unit using the encryption key.
[0033] With such a configuration, the first encrypted data can be made to have a predetermined data amount.
[0034] Also, in the authenticator according to one aspect of the present invention, the encryption unit may generate the first data by reducing the data amount of the obtained first encrypted data.
[0035] With such a configuration, for example, the data amount of the authentication request can be made smaller.
[0036] Also, in the authentication device according to one aspect of the present invention, the data amount of the first data and the data amount of the second data are the same, and the second encrypted data may be the exclusive logical sum of the first data and the second data.
[0037] With such a configuration, the second data can be encrypted by simple processing.
[0038] Also, the authentication device according to one aspect of the present invention further includes a data output unit that generates shared data, outputs it to the authentication target device, and stores it in the storage unit, and the second encrypted data included in the authentication request received by the reception unit may be the encrypted second data including the shared data output by the data output unit.
[0039] With such a configuration, even if the authentication target device does not have a shared data generator, the second data can be shared between the authentication device and the authentication target device.
[0040] Also, in the authentication device according to one aspect of the present invention, the shared data may include a random number.
[0041] With such a configuration, for example, the shared data can be made unique data.
[0042] Also, the authentication request output method according to one aspect of the present invention includes a step of obtaining initial data including a user identifier for identifying a user and unique information that is unique information, a step of generating first data by obtaining first encrypted data obtained by encrypting the initial data, a step of obtaining second data including shared data shared by the authentication device, a step of generating second encrypted data by encrypting the second data using the first data, and a step of outputting a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device, respectively.
[0043] Also, according to one aspect of the present invention, an authentication method includes: an initial data including a user identifier for identifying a user and unique information which is unique information, and a first data generated by acquiring first encrypted data obtained by encrypting the initial data, using the first data to receive, from an authentication target device, a plurality of different authentication requests including second encrypted data obtained by encrypting second data including shared data; a step of generating the first data by acquiring the first encrypted data obtained by encrypting the initial data included in the received authentication request; a determination unit that determines whether the shared data corresponding to the second encrypted data included in the received authentication request matches the shared data stored in a storage unit in which the shared data shared with a legitimate authentication target device is stored, using the first data generated in the step of generating the first data; a step of determining that the authentication target device is legitimate when the unique information included in the plurality of authentication requests received from the authentication target device is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; and a step of outputting an authentication result which is a determination result in the step of determining whether the authentication target device is legitimate.
Effect of the Invention
[0044] According to an authentication target device, an authentication device, an authentication request output method, an authentication method, and a program according to one aspect of the present invention, it is possible to prevent impersonation and realize secure authentication.
Brief Description of the Drawings
[0045]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Embodiment for Carrying Out the Invention
[0046] Hereinafter, the authentication target device, authentication device, authentication request output method, and authentication method according to the present invention will be described using embodiments. In the following embodiments, components and steps denoted by the same reference numerals are the same or corresponding, and repeated description may be omitted. The authentication target device according to the present embodiment outputs a plurality of different authentication requests including initial data which is plaintext data including unique information, and second encrypted data obtained by encrypting second data using the initial data and first data obtained using the initial data. Further, the authentication device according to the present embodiment performs authentication of the authentication target device based on a determination result as to whether shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the authentication device, and whether the unique information included in the plurality of authentication requests is consistent.
[0047] FIG. 1 is a block diagram showing the configuration of an authentication system 100 according to the present embodiment, FIG. 2 is a diagram showing information transmitted and received between the authentication target device 1 and the authentication device 2, FIG. 3 is a diagram for explaining an example of processing related to generation of an authentication request in the authentication target device 1, and FIG. 4 is a diagram for explaining an example of processing related to authentication using a plurality of authentication requests in the authentication device 2.
[0048] As shown in FIG. 1, the authentication system 100 according to the present embodiment includes an authentication target device 1 and an authentication device 2. Note that FIG. 1 shows a case where the authentication system 100 has one authentication target device 1 and one authentication device 2, but this is not necessary. The authentication system 100 may have a plurality of authentication target devices 1 and one authentication device 2. In this case, a plurality of authentication requests may be output from each of the plurality of authentication target devices 1 to the authentication device 2. In the present embodiment, the case where information is exchanged between the authentication target device 1 and the authentication device 2 by communication, that is, transmission and reception of information, will be mainly described, and cases where this is not the case will be described later. The communication is usually wireless communication.
[0049] The communication standard of the wireless communication performed between the authentication target device 1 and the authentication device 2 is not limited. The wireless communication may be performed, for example, by the low power consumption of Bluetooth (registered trademark), by the BR (Basic Rate) / EDR (Enhanced Data Rate) of Bluetooth (registered trademark), by wireless LAN (IEEE802.11), by IEEE802.15.4 such as ZigBee (registered trademark), or by other wireless communication standards. The wireless communication may be, for example, short-range wireless communication. As an example, the authentication process of the authentication target device 1 may be performed after establishing a connection such as wireless communication between the authentication target device 1 and the authentication device 2 as shown in FIG. 2. Note that the process of establishing communication between the two devices before the start of the authentication process is not necessarily required, and the authentication process may be performed without establishing communication.
[0050] In this embodiment, an authentication request is output from the authentication target device 1 to the authentication device 2. The authentication target device 1 that outputs the authentication request includes a legitimate authentication target device 1 and a device that is not legitimate, that is, a device of an attacker who is a malicious third party. When the authentication device 1 receives the authentication request, it cannot distinguish between the two at that time. For convenience of explanation, the device that outputs the authentication request will be referred to as the authentication target device 1. Then, the authentication target device 1 determined to be legitimate will be referred to as the legitimate authentication target device 1, and the authentication target device 1 determined not to be legitimate, that is, the attacker's device, will be referred to as the illegitimate authentication target device 1.
[0051] In FIG. 1, the authentication target device 1 according to this embodiment includes a storage unit 11, an initial data acquisition unit 12, a first encryption unit 13, a second data acquisition unit 14, a second encryption unit 15, and an output unit 16. The authentication target device 1 may be, for example, a mobile information terminal having a communication function such as a smartphone, a tablet terminal, a PDA (Personal Digital Assistant), a notebook computer, a transceiver, or other devices. In this embodiment, the case where the authentication target device 1 is a smartphone will be mainly described.
[0052] In the storage unit 11, for example, a user identifier for identifying the user of the authentication target device 1 may be stored. The user identifier is not particularly limited as long as it can identify the user. As an example, it may be the user's phone number or email address, or a character string assigned to the user. Further, as the user identifier, for example, a device identifier for identifying the authentication target device 1 may be used. The device identifier may be, for example, the address of the authentication target device 1. Further, in the storage unit 11, for example, an encryption key corresponding to the user identifier stored in the storage unit 11 may be stored. Further, in the storage unit 11, for example, shared data may be stored. The encryption key and the shared data will be described later.
[0053] The process by which information is stored in the memory unit 11 is not limited. For example, information may be stored in the memory unit 11 via a recording medium, a communication line, or an input device, or information may be accumulated in the memory unit 11 by other components. The memory unit 11 is preferably realized by a non-volatile recording medium, but may also be realized by a volatile recording medium. The recording medium may be, for example, a semiconductor memory, a magnetic disk, an optical disk, or the like.
[0054] The initial data acquisition unit 12 acquires initial data including a user identifier for identifying a user and unique information that is unique information. The initial data acquisition unit 12 may, for example, read out the user identifier from the memory unit 11. The initial data acquisition unit 12 may, for example, generate unique information or receive unique information from other components or devices.
[0055] Each unique information acquired by the initial data acquisition unit 12 may be, for example, different information. For example, each time the initial data acquisition unit 12 acquires initial data, different initial data may be acquired. In this case, the unique information may be information unique to the authentication request. That is, for each authentication request, the unique information included in the authentication request may be different. Note that the fact that each unique information is different may mean that the unique information does not overlap within the period required for authentication. That is, the unique information may be information that does not overlap within a predetermined period. That period may be, for example, about 100 years. Therefore, when that period is exceeded, the unique information may overlap. As an example, if the unique information does not overlap for 100 years, the unique information acquired at a certain point in time and the unique information acquired after 101 years have elapsed from that point in time may overlap. Also, for example, when the authentication system 100 performs authentication for an event held on a specific day, the period during which the unique information does not overlap may be about one day or two days.
[0056] The unique information may include, for example, at least one of a time, a counter value, and a random number value. Also, information that is usually composed of unique information such as a time, a counter value, and a random number value and non-unique information (for example, the upper bits are unique information and the lower bits are non-unique information, etc.) will, as a result, become unique information. Therefore, the unique information may be composed of such unique information and non-unique information in this way.
[0057] The time may be, for example, the time at the point when the unique information is acquired. Since the period from when the unique information is acquired until the authentication request is sent is short, this time can be considered to be substantially the time when the authentication request is sent. It is preferable that the accuracy of the time is shorter than the transmission interval between multiple authentication requests. For example, the time may be a time in milliseconds. The time may be, for example, a time indicating the elapsed time based on a predetermined point in time. As an example, that time may be the UNIX time. In this case, it may be considered that the time also includes hours, minutes, year, month, and day. The initial data acquisition unit 12 may acquire the current time using, for example, a clock unit (not shown). Among the acquired time, for example, the lower digits that result in a desired period may be used as the unique information. Also, the time may include, for example, year, month, day, hour, minute, and second.
[0058] The counter value may be, for example, a value obtained by incrementing or decrementing a numerical value at a predetermined interval. The random number value may be generated using, for example, a random number table or a function that generates random numbers. As an example, the counter value and the random number value may have different values depending on the time. For example, the counter value and the random number value generated on one day and the counter value and the random number value generated on the next day may be different. By doing so, it is possible to prevent a malicious third party from reusing the unique information including the counter value and the random number value included in the authentication request sent from the legitimate authentication device 1, and to prevent forgery by a malicious third party.
[0059] In addition, the initial data may include information other than the user identifier and the unique information. The information other than the user identifier and the unique information included in the initial data may be, for example, information that the authentication device 1 wants to transmit to the authentication device 2.
[0060] The first encryption unit 13 generates first data using the initial data acquired by the initial data acquisition unit 12. The first encryption unit 13 may generate the first data, for example, by obtaining first encrypted data obtained by encrypting the initial data using an encryption key corresponding to the user identifier included in the initial data. Further, the first encryption unit 13 may generate the first data, for example, by obtaining first encrypted data obtained by encrypting data of a predetermined data amount including the initial data using an encryption key corresponding to the user identifier included in the initial data. The data of a predetermined data amount including the initial data may be, for example, data that has been padded to a predetermined data amount by padding the initial data. The padding method may be, for example, predetermined in advance. In this case, the first encryption unit 13 may have, for example, an encryption unit 13-1 that encrypts the padded initial data including the initial data including the user identifier ID and the unique information U and the padded information P using the encryption key K corresponding to the user identifier ID included in the initial data and outputs the first encrypted data ER1. The encryption by the encryption unit 13-1 may be performed by, for example, AES (Advanced Encryption Standard), or may be performed by another algorithm. The encryption key K may be, for example, an encryption key unique to the user identified by the user identifier included in the initial data, that is, an encryption key that only that user can know and other users cannot know. The encryption key may be stored in the storage unit 11 as an example.
[0061] The encryption key used by the first encryption unit 13 may be, for example, a key for symmetric-key encryption, or a public key or a private key for public-key encryption. In any case where an encryption key is used, it is preferable that the encryption key used in the first encryption unit 13 of the authentication target device 1 is the same as the encryption key used in the encryption unit 22 (to be described later) of the authentication device 2. As an example, when the encryption key used by the first encryption unit 13 of the authentication target device 1 is a public key for public-key encryption, it is preferable that the same public key is used in the encryption unit 22 of the authentication device 2. Note that, in any case where an encryption key is used, it is preferable that the encryption key is different for each authentication target device 1, that is, for each user.
[0062] Also, the first encryption unit 13 may use, for example, the first encrypted data itself as the first data, or may generate the first data by reducing the data amount of the first encrypted data. In the latter case, for example, the first encryption unit 13 may reduce the data amount by hashing the first encrypted data, or may reduce the data amount by extracting a part of the first encrypted data. The extraction of a part of the first encrypted data may be, for example, the extraction of the upper bits or the lower bits of a predetermined number of bits of the first encrypted data, or may be the extraction of the values of predetermined bits (digits) in the bit sequence of the first encrypted data. In the present embodiment, the case of generating the first data by hashing the first encrypted data will be mainly described. In this case, the first encryption unit 13 may have, for example, a hash generation unit 13-2 that hashes the first encrypted data ER1 and outputs the first data R1 as shown in FIG. 3.
[0063] The second data acquisition unit 14 acquires second data including shared data shared with the authentication device 2. The second data acquisition unit 14 may, for example, acquire the shared data from the authentication device 2 or generate the shared data. In the present embodiment, the former case will be mainly described. When the exchange of information between the authentication target device 1 and the authentication device 2 is performed by communication, as shown in FIG. 2, (2) the shared data is transmitted from the authentication device 2 to the authentication target device 1, and the second data acquisition unit 14 may receive the transmitted shared data from the authentication device 2. When the second data acquisition unit 14 generates the shared data, it is preferable to generate the shared data by the same algorithm as that of the authentication device 2. This is to enable the authentication target device 1 and the authentication device 2 to share the shared data. Note that the second data may be, for example, the shared data or may include data other than the shared data. In the latter case, as an example, information that the authentication target device 1 wants to convey to the authentication device 2 and that is not desired to be known to a third party may be included in the second data. In the present embodiment, the case where the second data is the shared data will be mainly described.
[0064] Note that the shared data may include, for example, random numbers. In this case, the shared data may be, for example, random number data, or may include data other than random number data. Also, data other than random numbers may be used as the shared data. In this embodiment, the case where the shared data is a random number will be mainly described. Also, it is preferable that the shared data is different for each authentication device 1, for example, but it may not be so. Also, in the former case, the shared data is, for example, information unique to one authentication process performed using a plurality of authentication requests for a certain authentication device 1. In different authentication processes, different shared data may be used, or the same shared data may be used in a plurality of authentication processes. Also, in the case where different shared data are used in different authentication processes, for example, the shared data may be different for each authentication request used in one authentication process, or the same shared data may be used for a plurality of authentication requests used in one authentication request. In this embodiment, the case where the shared data is different for each authentication device 1 and also different for each authentication process, but the same shared data is used in one authentication process will be mainly described. The second data acquisition unit 14 may store, for example, the acquired shared data or the second data in the storage unit 11.
[0065] The second encryption unit 15 obtains second encrypted data by encrypting the second data acquired by the second data acquisition unit 14 using the first data generated by the first encryption unit 13. The second encryption unit 15 may encrypt the second data using, for example, the first data as an encryption key. Also, the second encryption unit 15 may obtain, for example, second encrypted data ER which is the exclusive logical sum of the first data R1 and the second data R2, as shown in FIG. 3. In this embodiment, this case will be mainly described. When the exclusive logical sum of the first data and the second data is calculated by the second encryption unit 15, it is preferable that the data amount of the first data is the same as the data amount of the second data. That the data amounts are the same may mean, for example, that the number of bits is the same.
[0066] The output unit 16 outputs a plurality of different authentication requests to the authentication device 2. The authentication request is information including the initial data acquired by the initial data acquisition unit 12 and the second encrypted data acquired by the second encryption unit 15. The authentication request may include only the initial data and the second encrypted data, or may also include other information.
[0067] The plurality of authentication requests may each include a plurality of different initial data. By doing so, the plurality of authentication requests each become different information. Note that the second encrypted data included in a certain authentication request is obtained by encrypting the second data using the first data generated using the initial data included in that authentication request. Also, the second data used to acquire the second encrypted data included in the plurality of authentication requests used in one authentication process may, for example, all be the same. On the other hand, since the first data is different for each acquisition of the second encrypted data, the plurality of second encrypted data included in the plurality of authentication requests used in one authentication process are all different from each other. The plurality of authentication requests used in one authentication process refers to the plurality of authentication requests used in the process of determining whether the authenticated device 1 is legitimate.
[0068] Note that the authentication request may, for example, be output after being entirely encrypted. This encryption may, as an example, be performed using an encryption key common to the plurality of authenticated devices 1 that transmit the authentication request to the authentication device 2. In the present embodiment, the case where this encryption is not performed will mainly be described.
[0069] Here, this output may be, for example, transmission via a communication line to a predetermined device, display on a display device (such as a liquid crystal display or an organic EL display), printing by a printer, sound output by a speaker, or delivery to other components. When the exchange of information between the device under authentication 1 and the authentication device 2 is performed by communication, the output unit 16 may send a plurality of authentication requests to the authentication device 2. In this case, as shown in FIG. 2, (3) the transmission of the authentication request from the device under authentication 1 to the authentication device 2 may be repeated a plurality of times. Note that the output unit 16 may or may not include a device for performing output (such as a communication device or a display device). Also, the output unit 16 may be realized by hardware or by software such as a driver for driving those devices.
[0070] Also, when the authentication result is output from the authentication device 2 to the device under authentication 1, the device under authentication 1 may include a reception unit that receives the authentication result output from the authentication device 2. When the exchange of information between the device under authentication 1 and the authentication device 2 is communication, the reception unit may receive the authentication result from the authentication device 2. In this case, as shown in FIG. 2, (4) the transmission of the authentication result from the authentication device 2 to the device under authentication 1 may be performed, and the transmitted authentication result may be received by the device under authentication 1. The received authentication result may be output to the user of the device under authentication 1 as an example. The output may be, for example, display, sound output, or the like.
[0071] In FIG. 1, the authentication device 2 according to the present embodiment includes a reception unit 21, an encryption unit 22, a storage unit 23, a determination unit 24, an authentication unit 25, an authentication result output unit 26, and a data output unit 27. The authentication device 2 may be, for example, a device that authenticates the authenticated device 1 in an automatic ticket gate, a gate for entering a venue such as an event, a vending machine, a control device for locking and unlocking the door of a hotel or a rental conference room, a cash register, etc., or an information terminal having a communication function such as a computer or a smartphone that authenticates the authenticated device 1. In the present embodiment, the case where the authenticated device 1 is an information terminal having a communication function will be mainly described.
[0072] The reception unit 21 receives a plurality of different authentication requests from the authenticated device 1. When the exchange of information between the authenticated device 1 and the authentication device 2 is performed by communication, the reception unit 21 may receive a plurality of authentication requests from the authenticated device 1. The authentication requests to be received include, as described above, initial data including a user identifier for identifying a user and unique information that is unique information, and second encrypted data generated using the initial data. The second encrypted data is data obtained by encrypting second data including shared data using first data. The first data is data generated by obtaining first encrypted data obtained by encrypting the initial data included in the authentication request using an encryption key corresponding to the user identifier included in the initial data. When the reception time of the authentication request is also used for the authentication of the authenticated device 1, the reception unit 21 may, for example, obtain the reception time when receiving the authentication request and pass it to the authentication unit 25.
[0073] Note that, in the authenticated device 1, when the authentication request is output after being encrypted, the encrypted authentication request may be decrypted after the authentication request is received. In the present embodiment, as described above, the case where such encryption and decryption are not performed will be mainly described.
[0074] The reception unit 21 may receive information transmitted via, for example, a wireless communication line, may read the displayed information as described later, or may receive information by other methods. Note that the reception unit 21 may or may not include a device for reception (for example, a communication device or an imaging device). Further, the reception unit 21 may be realized by hardware or may be realized by software such as a driver for driving a predetermined device.
[0075] The encryption unit 22 generates first data using the initial data included in the authentication request received by the reception unit 21. It is preferable that the generation of this first data is performed in the same manner as the generation of the first data by the first encryption unit 13 of the authentication device 1. This is to generate the same first data as the first data generated in the authentication device 1. The encryption unit 22 may generate the first data, for example, by obtaining first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit 21 using the encryption key corresponding to the user identifier included in the initial data. Further, the encryption unit 22 may generate the first data, for example, by obtaining first encrypted data obtained by encrypting a predetermined amount of data including the initial data included in the authentication request received by the reception unit 21 using the encryption key corresponding to the user identifier included in the initial data. In this case, the encryption unit 22 may have, for example, as shown in FIG. 4, a generation unit 22-1 that generates padded initial data of a predetermined amount of data by padding the initial data, and an encryption unit 22-2 that encrypts the padded initial data using the encryption key K corresponding to the user identifier ID included in the initial data and outputs the first encrypted data ER1. For example, information associating the user identifier and the encryption key is stored in the storage unit 23, and the encryption unit 22 may obtain the encryption key K corresponding to the user identifier ID included in the initial data using the information.
[0076] Further, the encryption unit 22 may use, for example, the first encrypted data itself as the first data, or may generate the first data by reducing the data amount of the first encrypted data. The encryption unit 22 may reduce the data amount, for example, by hashing the first encrypted data, or may reduce the data amount by extracting a part of the first encrypted data. In the present embodiment, the former case will be mainly described. In this case, the encryption unit 22 may have, for example, a hash generation unit 22-3 that outputs the first data R1 by hashing the first encrypted data ER1 as shown in FIG. 4. Note that, as described above, the generation of the first data by the encryption unit 22 is performed in the same manner as the generation of the first data by the first encryption unit 13 of the authenticated device 1, and thus the detailed description thereof is omitted.
[0077] In the storage unit 23, shared data shared with the legitimate authenticated device 1 is stored. The sharing of the shared data with the legitimate authenticated device 1 may be performed, for example, by outputting the shared data from the authentication device 2 to the authenticated device 1, or may be performed by generating the same shared data in the authenticated device 1 and the authentication device 2. In the present embodiment, the former case will be mainly described. In the storage unit 23, for example, information associating a user identifier with shared data used in the authenticated device 1 of the user identified by the user identifier may be stored. In this way, the shared data corresponding to the user identifier can be specified. Note that it is preferable that the shared data is different for each user identifier. Further, in the storage unit 23, as described above, the encryption key for each user may also be stored.
[0078] The process of storing information in the storage unit 23 is not limited. For example, information may be stored in the storage unit 11 via a recording medium, a communication line, or an input device, or information may be accumulated in the storage unit 11 by other components. The storage unit 23 may be realized by a non-volatile recording medium or may be realized by a volatile recording medium. The recording medium may be, for example, a semiconductor memory, a magnetic disk, an optical disk, or the like.
[0079] The determination unit 24 determines whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit 21 matches the shared data stored in the storage unit 23, using the first data generated by the encryption unit 22. The shared data corresponding to the second encrypted data included in the authentication request is the shared data included in the second data used for generating the second encrypted data. For example, by decrypting the second encrypted data using the first data generated by the encryption unit 22, the second data corresponding to the second encrypted data can be specified, and the shared data included in the second data can be specified. Also, the shared data stored in the storage unit 23 may be, for example, the shared data stored in the storage unit 23 in association with the user identifier included in the authentication request.
[0080]
[0081] Further, when the second data is shared data, the determination unit 24 may, for example, use the first data generated by the encryption unit 22 to encrypt the second data, which is the shared data stored in association with the user identifier included in the received authentication request, to obtain second encrypted data, and compare the obtained second encrypted data with the second encrypted data included in the received authentication request, thereby determining whether the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit 23. In this case, when the two pieces of second encrypted data match, it may be determined that the two pieces of shared data match, and when the two pieces of second encrypted data do not match, it may be determined that the two pieces of shared data do not match.
[0082] The authentication unit 25 determines that the authentication target authentication device 1 is legitimate when the unique information included in a plurality of authentication requests received from the authentication target authentication device 1 is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit 23. Otherwise, it determines that the authentication target authentication device 1 is not legitimate. In the latter case, the authentication unit 25 may, for example, determine that the authentication target authentication device 1 is not legitimate when the unique information included in the plurality of authentication requests received from the authentication target authentication device 1 is not consistent, or may determine that the authentication target authentication device 1 is not legitimate when it is determined that the shared data corresponding to the second encrypted data included in at least any one of the plurality of authentication requests does not match the shared data stored in the storage unit 23.
[0083] The plurality of authentication requests used by the authentication unit 25 to determine whether the authentication device 1 is legitimate may be, for example, a predetermined number of authentication requests, or may be a plurality of authentication requests received during a predetermined period. The period may start, for example, from the time when the first authentication request is received.
[0084] Here, the determination of whether the unique information included in multiple authentication requests is consistent will be described. Whether multiple unique information is consistent may be determined, for example, by comparing the multiple unique information included in the multiple authentication requests with the multiple unique information generated or acquired by the authentication device 2, or may be determined by whether the multiple unique information conforms to a predetermined rule.
[0085] When the unique information is a counter value or a random number value, the authentication unit 25 acquires, for example, the counter value or the random number value using a function for acquiring the counter value or the random number value, a table such as a random number table, etc., and compares the acquired counter value or random number value with the counter value or random number value that is the multiple unique information respectively. When all of them match, it may be determined that the multiple unique information is consistent, and when at least one does not match, it may be determined that the multiple unique information is not consistent.
[0086] When the unique information is a counter value, the authentication unit 25 may determine that the multiple unique information is consistent when, for example, the counter value included in the multiple authentication requests satisfies a predetermined rule, and may determine that the multiple unique information is not consistent when it does not. The predetermined rule may be, for example, "the counter value increments by 2 each time". In this case, the authentication unit 25, for example, when arranging the counter values that are the unique information included in the multiple authentication requests in the order of reception of the authentication requests, may determine that the multiple unique information is consistent when the counter value increases by 2 each time, and may determine that the multiple unique information is not consistent when the increment of at least some of the counter values is not 2.
[0087] When the unique information is time, the authentication unit 25 may determine that the multiple unique information is consistent when, for example, for all of the multiple authentication requests used for authenticating the authentication device 1, the time difference between the time that is the unique information included in the authentication request and the reception time of the authentication request is smaller than a predetermined threshold, and may determine that the multiple unique information is inconsistent when it is not so. The reception time of the authentication request may be obtained, for example, by the reception unit 21 from a clock unit (not shown) when receiving the authentication request.
[0088] When the unique information is time, the authentication unit 25 may determine that the multiple unique information is inconsistent, for example, when the time that is the unique information does not increase according to the order of reception. For example, when the time that is the unique information included in the authentication request received at time point A indicates a time later than the time that is the unique information included in the authentication request received at time point B after time point A. In this case, it is considered that the authentication request received at time point B is the authentication request output from the legitimate authentication device 1 before the authentication request received at time point A, which has been duplicated and output again by the attacker's device.
[0089] When the unique information is time, the authentication unit 25, for example, for all of a plurality of authentication requests used for authenticating the authentication device 1, obtains the time difference between the time that is the unique information included in the authentication request and the reception time of the authentication request respectively. When all of the obtained plurality of time differences are constant, it may be determined that the plurality of unique information is consistent, and when not, it may be determined that the plurality of unique information is inconsistent. By doing so, even when the clock unit of the authentication device 1 and the clock unit of the authentication device 2 are not completely synchronized, it is possible to appropriately determine whether or not a plurality of unique information that is time is consistent. Since the authentication device 1 and the authentication device 2 usually perform the transfer of the authentication request over a short distance, it is considered that the delay caused by the transfer is substantially constant for a plurality of authentication requests. Note that the plurality of time differences being constant may mean, for example, that the difference between the maximum value and the minimum value of the plurality of time differences is smaller than a predetermined threshold, or that the variation (for example, variance, standard deviation, etc.) of the plurality of time differences is smaller than a predetermined threshold.
[0090] Note that the authentication unit 25 may, for example, make any two or more determinations among a plurality of determinations as to whether or not a plurality of unique information is consistent. In this case, in each of the two or more determinations, when it is determined that the plurality of unique information is consistent, it may be finally determined that the plurality of unique information is consistent, and when it is determined that the plurality of unique information is inconsistent in at least some of the determinations, it may be finally determined that the plurality of unique information is inconsistent. Even when the unique information includes any two or more types of information such as time, counter value, and random number value, determinations as to whether or not each type of information included in the unique information is consistent may be made respectively. Also in this case, when all types of information are consistent, it may be finally determined that the plurality of unique information is consistent, and when not, it may be finally determined that the plurality of unique information is inconsistent.
[0091] Note that, for example, when all of a plurality of authentication requests are transmitted from an unauthorized authentication device 1, the authentication unit 25 determines that the authentication device 1 is unauthorized. Also, for example, when a plurality of authentication requests include an authentication request transmitted from an unauthorized device, the authentication unit 25 determines that the authentication device 1 that transmitted the plurality of authentication requests is unauthorized. That is, even when a plurality of authentication requests are transmitted from a legitimate authentication device 1 and an unauthorized authentication device 1, the authentication device 1 that is the transmission source of the plurality of authentication requests is determined to be unauthorized. In this case, at least the attacker's device is included in the transmission source of the authentication request. Even if a legitimate authentication device 1 is included in the transmission source, since the two cannot be distinguished, both are determined to be unauthorized.
[0092] The authentication result output unit 26 outputs an authentication result that is a determination result by the authentication unit 25. The authentication result may be, for example, information indicating whether the authentication device 1 is legitimate or unauthorized. The authentication result output unit 26 may output the authentication result to, for example, a component or device that performs processing according to the authentication result. Also, the authentication result output unit 26 may output the authentication result to, for example, the authentication device 1 that output a plurality of authentication requests, that is, the authentication device 1 that is the authentication target. In this case, the user of the authentication device 1 can know about the authentication result. When the exchange of information between the authentication device 1 and the authentication device 2 is performed by communication, the authentication result output unit 26 may transmit the authentication result to the authentication device 1.
[0093] The data output unit 27 may generate shared data and output it to the authenticated device 1, and may also store the shared data in the storage unit 23. The data output unit 27 may store, for example, the shared data output to a certain authenticated device 1 in association with a user identifier for identifying the user of the authenticated device 1 in the storage unit 23. When the exchange of information between the authenticated device 1 and the authentication device 2 is performed by communication, the data output unit 27 may transmit the shared data to the authenticated device 1. The transmission may be performed, for example, by unicast. Note that the output of the shared data by the data output unit 27 to the authenticated device 1 is preferably performed in a secure manner so that the shared data is not known to a third party, but it may not be so. In the former case, the shared data may be encrypted and output using, for example, an encryption key associated with the user identifier for identifying the user of the authenticated device 1 stored in the storage unit 23, and may be output through a path different from the exchange of authentication requests. As an example, when the authentication request is transmitted and received by short-range wireless communication such as Bluetooth (registered trademark), the shared data may be transmitted and received via a wide-area communication network such as the Internet. Thus, when the shared data is output by the data output unit 27, the second encrypted data included in the authentication request received by the reception unit 21 from a legitimate authenticated device 1 is the result of encrypting the second data including the output shared data. In the present embodiment, the case where the shared data is transmitted from the authentication device 2 to the authenticated device 1 so that the shared data is not known to a third party will be mainly described.
[0094] Here, the outputs by the authentication result output unit 26 and the data output unit 27 may be, for example, transmission via a communication line to a predetermined device, printing by a printer, sound output by a speaker, display on a display device (e.g., a liquid crystal display or an organic EL display, etc.), storage on a recording medium, or delivery to other components. Note that the authentication result output unit 26 and the data output unit 27 may or may not include a device that performs the output (e.g., a communication device or a display device, etc.). Also, the authentication result output unit 26 and the data output unit 27 may be realized by hardware, or may be realized by software such as a driver that drives those devices.
[0095] Next, the operation of the authentication target device 1 will be described using the flowchart of FIG. 5. FIG. 5 is a flowchart showing an authentication request output method, which is the processing of the authentication target device 1 after communication between the authentication target device 1 and the authentication device 2 is established in FIG. 2. In the flowchart of FIG. 5, as described above, the case where the exchange of information between the authentication target device 1 and the authentication device 2 is performed by communication will be described.
[0096] (Step S101) The second data acquisition unit 14 determines whether or not it has received shared data. If it has received the shared data, it proceeds to step S102; otherwise, it repeats the process of step S101 until it receives the shared data.
[0097] (Step S102) The initial data acquisition unit 12 acquires initial data.
[0098] (Step S103) The first encryption unit 13 generates first data using the initial data acquired in step S102.
[0099] (Step S104) The second encryption unit 15 obtains second encrypted data by encrypting second data including the shared data received in step S101 using the first data generated in step S103.
[0100] (Step S105) The output unit 16 transmits an authentication request including the initial data acquired in step S102 and the second encrypted data acquired in step S104 to the authentication device 2.
[0101] (Step S106) The output unit 16 determines whether to end the transmission of the authentication request. If the transmission of the authentication request is to be ended, the series of processes for transmitting a plurality of authentication requests ends. Otherwise, the process returns to step S102. Note that the output unit 16 may determine to end the transmission of the authentication request, for example, when a predetermined number of authentication requests have been transmitted, or may determine to end the transmission of the authentication request when a predetermined period has elapsed since the first authentication request was transmitted. The determination process as to whether to end the transmission of the authentication request may be performed by a component other than the output unit 16, for example.
[0102] Note that it is preferable that the transmission interval of the authentication requests be short. This is because the authentication process by the authentication device 2 cannot be completed unless the transmission of a plurality of authentication requests is completed. As an example, the transmission interval of the authentication requests may be 200 ms or less, or may be 100 ms or less. Also, the order of the processes in the flowchart of FIG. 5 is an example, and the order of each step may be changed as long as the same result can be obtained.
[0103] Next, the operation of the authentication device 2 will be described using the flowchart of FIG. 6. FIG. 6 is a flowchart showing an authentication method which is the processing of the authentication device 2 after communication is established between the authentication device 1 and the authentication device 2 in FIG. 2. In the flowchart of FIG. 6, as described above, the case where the exchange of information between the authentication device 1 and the authentication device 2 is performed by communication will be described.
[0104] (Step S201) The data output unit 27 generates shared data, transmits it to the authentication device 1, and stores the shared data in the storage unit 23.
[0105] (Step S202) The reception unit 21 determines whether an authentication request has been received. If an authentication request has been received, the process proceeds to step S203; otherwise, the process proceeds to step S206.
[0106] (Step S203) The encryption unit 22 generates first data using the initial data included in the received authentication request.
[0107] (Step S204) The determination unit 24 determines whether the shared data corresponding to the second encrypted data included in the received authentication request matches the shared data stored in the storage unit 23, using the first data generated in step S203. If they match, the process returns to step S202; otherwise, the process proceeds to step S205.
[0108] (Step S205) The authentication unit 25 determines that the authenticated device 1 that sent the authentication request is not legitimate.
[0109] (Step S206) The authentication unit 25 determines whether to authenticate the authenticated device 1 using a plurality of authentication requests. If authenticating the authenticated device 1, the process proceeds to step S207; otherwise, the process returns to step S202. For example, the authentication unit 25 may determine to authenticate a certain authenticated device 1 when a predetermined number of authentication requests are received from that authenticated device 1, or may determine to authenticate a certain authenticated device 1 when a predetermined period has elapsed since the first authentication request was received from that authenticated device 1.
[0110] (Step S207) The authentication unit 25 determines whether the plurality of unique information included in the plurality of authentication requests received from a certain authenticated device 1 is consistent. If the plurality of unique information is consistent, the process proceeds to step S208; otherwise, the process proceeds to step S205.
[0111] (Step S208) The authentication unit 25 determines that the authenticated device 1 that sent the authentication request is legitimate.
[0112] (Step S209) The authentication result output unit 26 outputs the authentication result, which is the determination result by the authentication unit 25. Then, the series of processes for authenticating the authenticated device 1 is completed.
[0113] Note that the order of the processes in the flowchart of FIG. 6 is an example, and the order of each step may be changed as long as the same result can be obtained.
[0114] Next, the operations of the authenticated device 1 and the authentication device 2 according to the present embodiment will be described using a specific example. In this specific example, it is assumed that a legitimate authenticated device 1 sends 10 authentication requests to the authentication device 2. Also, in this specific example, the unique information is the time, and the authentication unit 25 determines that the 10 unique information is consistent when the time difference between the time, which is the unique information included in the authentication request, and the reception time of the authentication request is constant for all 10 authentication requests and the time difference between the time, which is the unique information, and the reception time is less than a predetermined threshold for all 10 authentication requests. In this specific example, first, the case where an authentication request is sent only from the legitimate authenticated device 1 will be described, and then the case where an attacker, who is a malicious third party, sends a forged authentication request will be described.
[0115] [Transmission of Authentication Request Only from Legitimate Authenticated Device 1] It is assumed that communication is established between the authenticated device 1 and the authentication device 2. At that time, it is assumed that the authentication device 2 has acquired the user identifier "U001" of the user of the authenticated device 1. Then, the data output unit 27 of the authentication device 2 generates shared data, which is a random number, and transmits it to the authenticated device 1, and associates the shared data with the user identifier "U001" and stores them in the storage unit 23 (Step S201). Note that the number of bits of the shared data is determined in advance.
[0116] The second data acquisition unit 14 of the authentication device 1 receives the shared data transmitted from the authentication device 2 and passes the second data, which is the shared data, to the second encryption unit 15 (step S101). The received second data, which is the shared data, may be stored in a recording medium (not shown).
[0117] Next, the initial data acquisition unit 12 acquires the time at that point, reads out the user identifier "U001" stored in the storage unit 11, and passes the initial data including the acquired time, which is unique information, and the read user identifier, to the encryption unit 22 and the output unit 16 (step S102). Upon receiving the initial data, the encryption unit 22 generates data of a predetermined number of bits by padding the initial data, encrypts the generated data using the encryption key stored in the storage unit 11 to obtain first encrypted data, and generates first data of a predetermined number of bits by hashing the first encrypted data, and passes it to the second encryption unit 15 (step S103). It is assumed that the number of bits of the first data and the number of bits of the second data are the same.
[0118] Upon receiving the first data, the second encryption unit 15 obtains second encrypted data, which is the exclusive OR of the first data and the second data, and passes it to the output unit 16 (step S104). Upon receiving the second encrypted data, the output unit 16 transmits an authentication request including the initial data and the second encrypted data to the authentication device 2 (step S105).
[0119] The authentication request transmitted from the authentication device 1 is received by the reception unit 21 of the authentication device 2, the initial data included in the authentication request is passed to the encryption unit 22, the pair of the unique information included in the initial data and the reception time of the authentication request is passed to the authentication unit 25, and the second encrypted data included in the authentication request is passed to the determination unit 24 (step S202).
[0120] Upon receiving the initial data, the encryption unit 22 generates data of a predetermined number of bits by padding the initial data, and encrypts the generated data using the encryption key stored in the storage unit 23 in association with the user identifier "U001" included in the initial data to obtain first encrypted data. By hashing the first encrypted data, first data of a predetermined number of bits is generated, and the first data and the user identifier included in the initial data are passed to the determination unit 24 (step S203).
[0121] Upon receiving the first data and the user identifier, the determination unit 24 obtains shared data, which is second data, by performing an exclusive OR operation between the second encrypted data and the first data, and reads the shared data stored in the storage unit 23 in association with the user identifier to determine whether the two pieces of shared data match (step S204). Here, it is assumed that the two pieces of shared data match. Thereafter, the process of transmitting an authentication request in the authentication device 1 and the process of receiving an authentication request in the authentication device 2 and determining whether the two pieces of shared data match are repeated (steps S102 to S106, S202 to S204). In this specific example, it is assumed that for all 10 authentication requests transmitted from the authentication device 1 to the authentication device 2, it is determined that the two pieces of shared data match.
[0122] When 10 authentication requests are received, the authentication unit 25 determines to authenticate the authentication device 1 (step S206), obtains the time differences for each of the 10 pairs of the unique information, which is the time received so far, and the reception time, and determines whether the 10 time differences are constant and whether the 10 time differences are smaller than a threshold (step S207). In this specific example, it is assumed that the 10 time differences are constant and each of the 10 time differences is smaller than the threshold. Then, the authentication unit 25 determines that the 10 pieces of unique information are consistent, determines that the authentication device 1 is legitimate, and passes the authentication result, which is the determination result, to the authentication result output unit 26 (step S208). Upon receiving the authentication result, the authentication result output unit 26 transmits the authentication result to the authentication device 1 and outputs it to components and devices that perform processing according to the authentication result (step S209). As a result, the user of the authentication device 1, that is, the user identified by the user identifier "U001", can know the authentication result indicating that the user is authenticated as legitimate and can receive services and the like according to the authentication result.
[0123] [Transmission of Authentication Requests Using Different Encryption Keys and Shared Data] Suppose that an attacker's device, which is a malicious third party, receives an authentication request sent from a legitimate authenticated device 1 and obtains a user identifier from the initial data included in the authentication request. Then, the attacker's device constructs new initial data using the obtained user identifier and unique information that is the time at the point when the attacker's device sends the authentication request, and repeatedly obtains second encrypted data in the same manner as the authenticated device 1 using the initial data, and sends an authentication request including the initial data and the second encrypted data to the authentication device 2. In this case, although the multiple unique information is consistent, since the malicious third party does not know the encryption key corresponding to the user identifier and the shared data, it is impossible to reproduce the second encrypted data included in the authentication request sent from the legitimate authenticated device 1. As a result, in the authentication device 2, it is determined that the shared data corresponding to the second encrypted data included in the received authentication request does not match the shared data stored in the storage unit 23 (step S204), and the attacker's device is determined to be illegitimate (step S205). In this way, it is possible to prevent spoofing by an attacker's device that is a malicious third party who does not know the encryption key and shared data used in the legitimate authenticated device 1.
[0124] Even if the shared data is known to a malicious third party, since the third party does not have the encryption key, it is impossible to reproduce the second encrypted data that is determined to be legitimate. Therefore, for example, the shared data may be passed from the authentication device 2 to the authenticated device 1 through an insecure path.
[0125] [Transmission after multiple authentication requests] The case where an attacker's device, which is a malicious third party, receives all authentication requests sent from a legitimate authenticated device 1 and then sends the plurality of authentication requests to the authentication device 2 at a later time will be described. When the attacker's device sends a plurality of authentication requests at a transmission interval different from that of the legitimate authenticated device 1, the time difference between the time, which is unique information included in the authentication request, and the reception time of the authentication request is not constant. As a result, in the authentication device 2, it is determined that the plurality of unique information does not match (step S207), and it is determined that the attacker's device is not legitimate (step S205). Further, even if the attacker's device can send a plurality of authentication requests at the same transmission interval as the legitimate authenticated device 1, if a time exceeding the threshold has elapsed from the transmission of the authentication request by the legitimate authenticated device 1 to the transmission of the authentication request by the attacker's device, the time difference between the time, which is unique information included in the authentication request, and the reception time of the authentication request is not less than the threshold. As a result, in the authentication device 2, it is determined that the plurality of unique information does not match (step S207), and it is determined that the attacker's device is not legitimate (step S205). In this way, it is possible to prevent spoofing by the attacker's device that has received a plurality of authentication requests.
[0126] Finally, examples of devices and systems that implement the authentication device 2 according to the present embodiment will be briefly described.
[0127] The authentication device 2 may be incorporated into an automatic ticket gate. And the automatic ticket gate may establish communication with the authentication device 1 existing nearby and transmit shared data to the authentication device 1. When the authentication device 1 owned by the user receives the shared data, it transmits a plurality of authentication requests to the authentication device 2 of the automatic ticket gate as described above. When the authentication device 2 determines that the authentication device 1 is legitimate using the plurality of authentication requests, the gate of the automatic ticket gate opens, and the user can enter or exit the ticket gate. Also, when the user enters or exits the ticket gate, the user is charged. In this way, for example, the user can board a train or the like without operating the smart phone or the like which is the authentication device 1.
[0128] The authentication device 2 may be incorporated into a vending machine for drinks or the like. And when the user operates the purchase button of the vending machine, the vending machine may establish communication with the authentication device 1 existing nearby and transmit shared data to the authentication device 1. When the authentication device 1 owned by the user receives the shared data, it transmits a plurality of authentication requests to the authentication device 2 of the vending machine as described above. When the authentication device 2 determines that the authentication device 1 is legitimate using the plurality of authentication requests, a product such as a drink corresponding to the purchase button operated by the user will come out of the vending machine, and the user can receive the product. Also, according to the process, the user is charged as appropriate. In this way, for example, the user can purchase a product from a vending machine without operating the smart phone or the like which is the authentication device 1.
[0129] The authentication device 2 may be installed near the entrance of venues for events such as concerts, sports games, seminars, art museums, museums, theme parks, sports clubs, members-only lounges, etc. In this case, the encryption key may be an event ticket or a membership card. Then, the authentication device 2 may establish communication with the authentication device 1 in the vicinity and transmit shared data to the authentication device 1. When the authentication device 1 owned by the user receives the shared data, it transmits a plurality of authentication requests to the authentication device 2 near the entrance of the venue as described above. When the authentication device 2 determines that the authentication device 1 is legitimate using the plurality of authentication requests, for example, it identifies the position of the authentication device 1 using the radio wave intensity of the authentication request, etc., and outputs information such as a ticket corresponding to the encryption key (for example, ticket type information, information on the owner of the ticket registered in advance, etc.) at the identified position. By looking at the display, event staff can identify people who do not have a ticket or membership card among those entering from the entrance. For people without a ticket or the like, the staff may request them to present a ticket or the like. In this way, for example, the user can enter an event venue, an art museum, a sports club, etc. without operating a smartphone or the like which is the authentication device 1.
[0130] The authentication device 2 may be incorporated into the cash register of a store. Then, for example, when a user or a store clerk operates the payment button of the cash register, the cash register may establish communication with the authentication device 1 nearby and transmit shared data to the authentication device 1. When the authentication device 1 possessed by the user receives the shared data, it transmits a plurality of authentication requests to the authentication device 2 of the cash register as described above. When the authentication device 2 determines that the authentication device 1 is legitimate using the plurality of authentication requests, a charge corresponding to the purchase amount is made for the payment means (for example, credit card, electronic money, etc.) registered in association with the key of the common key cryptography, so that the user may be able to receive the purchase target such as goods. In this way, for example, the user can purchase goods, etc. at a store without operating a smartphone or the like which is the authentication device 1.
[0131] The authentication device 2 may be incorporated into a device that requires personal authentication, such as a PC (Personal Computer) or an ATM (Automated Teller Machine). Then, for example, when a user operates a device such as a PC or an ATM, the device may establish communication with the authentication device 1 nearby and transmit shared data to the authentication device 1. When the authentication device 1 possessed by the user receives the shared data, it transmits a plurality of authentication requests to the authentication device 2 of the device as described above. When the authentication device 2 determines that the authentication device 1 is legitimate using the plurality of authentication requests, for the user registered in association with the key of the common key cryptography, for example, logging in to the PC may be performed, logging in to the website being operated on the PC may be performed, or cash withdrawal at the ATM may be performed. In this way, for example, the user can perform personal authentication on a device such as a PC or an ATM without entering a password, etc., and can operate the device.
[0132] In addition, the authentication device 1 and the authentication device 2 according to the present embodiment can also be used in situations other than those described above. For example, it may be used for authentication in carsharing, rental cars, boarding procedures for airplanes, etc. Further, for example, it may be used for user authentication when operating devices such as personal computers.
[0133] Note that in the above example, the case where shared data is transmitted after the establishment of communication between the authentication device 1 and the authentication device 2 has been mainly described, but it may not be so. The authentication device 2 may transmit different shared data according to time, for example, by broadcast such as a beacon. Then, the authentication device 1 may generate and transmit an authentication request using the shared data received from the authentication device 2. In this case, the association between the shared data and the user identifier in the authentication device 2 may be performed when the first authentication request is received. As an example, when the shared data stored in the storage unit 23 matches the shared data included in the second data obtained by decrypting the second encrypted data included in the first authentication request received from the authentication device 1 to be authenticated, the authentication device 2 may associate the user identifier included in the received first authentication request with the shared data stored in the storage unit 23.
[0134] Also, before the establishment of communication between the authentication device 1 and the authentication device 2, shared data may be transmitted from the authentication device 2 to the authentication device 1. In this case, for example, one piece of shared data may be transmitted, or a plurality of pieces of shared data may be transmitted. In the latter case, the authentication device 1 may use different shared data for each authentication, for example. Further, the transmission of the shared data from the authentication device 2 to the authentication device 1 may be performed through a path different from the authentication request, for example, or may be performed through the same path as the authentication request. In the latter case, the shared data may be encrypted and transmitted, for example.
[0135] As described above, according to the authenticated device 1 and the authentication device 2 according to the present embodiment, since the second encrypted data included in the authentication request is the result of encrypting the second data with the first data, for example, when the first data is generated using the first encrypted data obtained by encrypting the initial data with an encryption key, a malicious third party cannot newly generate the second encrypted data included in the authentication request. Therefore, a malicious third party cannot newly generate an authentication request for being judged as legitimate, and impersonation can be prevented. Further, even when a malicious third party acquires an authentication request transmitted from a legitimate authenticated device 1 and transmits the authentication request to the authentication device 2, for example, when the unique information is a time, by using the time difference between the time that is the unique information and the reception time of the authentication request, it can be determined that the device used by the malicious third party to transmit the authentication request is not the legitimate authenticated device 1. Further, even when the unique information is a counter value or a random number value, if the counter value or random number value generated according to the timing is different, the unique information that is the counter value or random number value cannot be used again in other situations, so impersonation by a malicious third party can be prevented.
[0136] In addition, since the unique information, which is information unique to the initial data, is included, the first data created using the initial data can be made different each time. That is, the first data can also be data that is uniquely determined in the same way as the unique information. Therefore, the second encrypted data obtained by encrypting the second data using the first data can also be made different each time. As a result, it is possible to make it difficult to predict the second data. Also, by reducing the data amount of the first encrypted data, the data amount of the second encrypted data can also be reduced. Therefore, the data amount of the authentication request can be reduced.
[0137] In addition, since the authentication request includes initial data, the authentication device 2 that has received the authentication request can use the authentication request to authenticate the device 1 to be authenticated and can also obtain information necessary for the processing after being authenticated as legitimate, such as user identifiers. Therefore, it becomes unnecessary to transmit information necessary for the processing after authentication from the device 1 to be authenticated after authentication, and the processing after authentication can be performed earlier. As described above, the initial data may further include information necessary for the processing after authentication, for example.
[0138] In addition, the authentication request includes initial data in plain text. In order to determine whether the shared data corresponding to the second encrypted data is equal to the shared data stored in the authentication device 2 using the initial data, as a result, it is also possible to confirm whether the initial data included in the authentication request has the correct content. Therefore, for example, even if a malicious third party sends an authentication request in which the initial data included in the authentication request is rewritten to the authentication device 2, the shared data corresponding to the second encrypted data included in the authentication request and the shared data stored in the authentication device 2 will not be equal. Therefore, the device that is the source of the authentication request will be determined to be illegitimate, and spoofing can be prevented.
[0139] In addition, in this embodiment, the case where the exchange of information between the authentication target device 1 and the authentication device 2 is communication has been mainly described. However, as described above, the exchange of information between the two devices may be performed by means other than communication. The exchange of information other than communication may be performed, for example, by information display and reading of the displayed information, by output and reception of a light blinking signal, by output and reception of sound waves or ultrasonic waves, or by other information transfer. When the exchange of information between the devices is performed by information display and reading of the displayed information, for example, the information to be output is displayed on a display device as an image of a code such as a barcode or a two-dimensional code, and the displayed code image is photographed and read by an imaging device such as a camera, so that information may be transferred between the authentication target device 1 and the authentication device 2. For example, the output unit 16 of the authentication target device 1 may display a barcode or a two-dimensional code of an authentication request. Then, the reception unit 21 of the authentication device 2 may acquire an authentication request from a photographed image obtained by photographing the displayed code, for example. Also, for example, the data output unit 27 of the authentication device 2 may display a barcode or a two-dimensional code of shared data. Then, the second data acquisition unit 14 of the authentication target device 1 may acquire shared data from a photographed image obtained by photographing the displayed code, for example. Also, when the exchange of information between the devices is performed by output and reception of a light blinking signal, for example, the information to be output is output from a light emitting unit as a light blinking signal, and the output light blinking signal is received by a light receiving unit, so that information may be transferred between the authentication target device 1 and the authentication device 2. Also, when the exchange of information between the devices is performed by output and reception of sound waves or ultrasonic waves, for example, the information to be output is output from an output unit as sound waves or ultrasonic waves, and the output sound waves or ultrasonic waves are received by a reception unit, so that information may be transferred between the authentication target device 1 and the authentication device 2.
[0140] Also, in the present embodiment, the case where the first encrypted data is data obtained by encrypting initial data using an encryption key corresponding to a user identifier included in the initial data has been mainly described, but this is not necessary. The first encrypted data may be data encrypted without using an encryption key. In this case, for example, the first encryption unit 13 may generate the first data by obtaining the first encrypted data obtained by encrypting the initial data, and the encryption unit 22 may generate the first data by obtaining the first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit 21. In this case, for example, the first encrypted data itself may be the first data.
[0141] Encryption without using an encryption key may be, for example, a process of reducing the data amount of the initial data. This process may be, for example, hashing, extraction of some data, a combination thereof, or other processes for reducing the data amount. The process of encryption without using an encryption key may be different for each authentication target device 1, or may be common among a plurality of authentication target devices 1. In the former case, the encryption unit 22 of the authentication device 2 may obtain the first encrypted data using the encryption process corresponding to the user identifier included in the received authentication request. In this case, since a malicious third party cannot generate the first data from the initial data, impersonation by a malicious third party can be prevented. Even if the encryption process without using an encryption key is common among a plurality of authentication target devices 1, for example, when the common data is not known to a malicious third party and the encryption by the second encryption unit 15 cannot decrypt using the first data, appropriate authentication can be performed. In this case, for example, the second data may be common data.
[0142] Also, in the present embodiment, the second data may be data including, for example, data other than the shared data as described above. In this case, for example, the second encrypted data may be obtained by encrypting data including the shared data and other data using the first data. By encrypting information other than the shared data as well, it becomes possible to output information that the third party does not want to know from the authenticated device 1 to the authentication device 2. In this case, when determining whether the shared data corresponding to the second encrypted data matches the shared data stored in the storage unit 23 of the authentication device 2, the shared data included in the second data obtained by decrypting the second encrypted data using the first data is compared with the shared data stored in the storage unit 23, which is preferable. In this way, when the second encrypted data is decrypted, the authentication device 2 can also obtain information other than the shared data encrypted together with the shared data.
[0143] In addition, in this embodiment, when shared data is output from the authentication device 2 to the device under authentication 1, the case where the entire shared data is output has been mainly described, but this is not necessary. For example, a first part that is a part of the shared data may be output from the authentication device 2 to the device under authentication 1. In this case, the second part that is the remaining part of the shared data may be held in the authentication device 2 and the device under authentication 1 in advance, for example, or may be passed from the authentication device 2 to the device under authentication 1 through a path different from the first part. In this case, for example, among the shared data, the first part may be commonly used in a plurality of devices under authentication 1, and the second part may be different for each device under authentication 1. As an example, the authentication device 2 may broadcast the first part of the shared data, and in the device under authentication 1 that has received it, the shared data may be configured using the received first part and the held second part. Also, as another example, the authentication device 2 may transmit the first part of the shared data to the device under authentication 1 through a first path, and transmit the second part of the shared data to the device under authentication 1 through a second path different from the first path. The first path may be, for example, a path such as short-range wireless communication through which an authentication request is transmitted and received. The second path may be, for example, a path of a wide-area communication network such as the Internet.
[0144] In addition, in this embodiment, the case where shared data is output from the authentication device 2 to the device under authentication 1 has been described. However, as described above, the shared data may be generated by the device under authentication 1. In this case, the authentication device 2 may not include the data output unit 27. In this case, the authentication device 2 may further include, for example, a shared data generation unit for generating the same shared data as the device under authentication 1.
[0145] Also, in this embodiment, the case where data of a predetermined data amount including initial data is mainly described for obtaining the first encrypted data has been mainly described, but it may not be the case. For example, the first encrypted data may be obtained by encrypting the initial data itself using an encryption key. In this case, for example, the data amount of each data included in the initial data may be determined in advance. By doing so, for example, the first encrypted data can be made to have a predetermined data amount.
[0146] Also, in this embodiment, the case where the encryption of the second data using the first data is mainly described as being performed by an exclusive OR operation has been mainly described, but it may not be the case. Needless to say, for example, the second data may be encrypted using the first data as an encryption key by another encryption method.
[0147] Also, when an authentication request is wirelessly transmitted from the authentication target device 1 to the authentication device 2, depending on the communication standard of the wireless communication, one authentication request may be duplicated and transmitted multiple times, and the same authentication request transmitted multiple times may be received simultaneously by the authentication device 1. In this case, among the multiple authentication requests received simultaneously, only one authentication request may be used for the authentication process, and the other authentication requests may not be used for the authentication process. Note that even in such a case, it is generally considered that it is rare for the same authentication request to be received multiple times by the authentication device 2. Therefore, for example, in the authentication device 2, when all of the multiple authentication requests used in one authentication are received two or more times, or when a predetermined ratio or more (for example, 50% or more, 80% or more, etc.) of the authentication requests are received two or more times, the authentication unit 25 of the authentication device 2 may determine that the device of an attacker, who is a malicious third party, is included in the source of the authentication request and determine that the authentication target device 1 is not legitimate.
[0148] In the above-described embodiment, each process or each function may be realized by being centrally processed by a single device or a single system, or may be realized by being distributively processed by a plurality of devices or a plurality of systems.
[0149] In the above-described embodiment, the transfer of information performed between each component may be performed, for example, by the output of information by one component and the reception of information by the other component when the two components that transfer the information are physically different, or when the two components that transfer the information are physically the same, it may be performed by shifting from the processing phase corresponding to one component to the processing phase corresponding to the other component.
[0150] In the above-described embodiment, information related to the processes executed by each component, for example, information received, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, mathematical formulas, addresses, etc. used in the processing by each component, may be temporarily or long-term held in a recording medium not shown even if not specified in the above description. Also, the accumulation of information in the recording medium not shown may be performed by each component or an accumulation unit not shown. Also, the reading of information from the recording medium not shown may be performed by each component or a reading unit not shown.
[0151] Further, in the above embodiment, when information used by each component or the like, for example, information such as threshold values, addresses, and various setting values used by each component in processing may be changed by the user, even if not specified in the above description, the user may appropriately be able to change such information, or not. When the user can change such information, the change may be realized, for example, by a reception unit (not shown) that receives a change instruction from the user and a change unit (not shown) that changes the information according to the change instruction. The reception of the change instruction by the reception unit (not shown) may be, for example, reception from an input device, reception of information transmitted via a communication line, or reception of information read from a predetermined recording medium.
[0152] Further, in the above embodiment, when two or more components included in the authentication target device 1 or the authentication device 2 have a communication device, an input device, or the like, the two or more components may physically have a single device, or may have separate devices.
[0153] Also, in the above embodiment, each component may be configured by dedicated hardware, or components that can be realized by software may be realized by executing a program. For example, each component can be realized by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory. At the time of its execution, the program execution unit may execute the program while accessing a storage unit or a recording medium. Note that the software that realizes the authentication device 1 in the above embodiment may be the following program. That is, this program causes a computer to function as an initial data acquisition unit that acquires initial data including a user identifier for identifying a user and unique information that is unique information, a first encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data, a second data acquisition unit that acquires second data including shared data shared with an authentication device, a second encryption unit that generates second encrypted data by encrypting the second data using the first data, and an output unit that outputs a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device, respectively.
[0154] Also, the software that realizes the authentication device 2 in the above embodiment may be a program as follows. That is, this program causes a computer that can access a storage unit storing shared data shared with a legitimate authentication device to use initial data including a user identifier for identifying a user and unique information that is unique information, and first data generated when first encrypted data obtained by encrypting the initial data is acquired, to receive from the authentication device a plurality of different authentication requests including second encrypted data obtained by encrypting second data including the shared data; a first encryption unit that generates the first data by acquiring the first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit; a determination unit that determines whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit matches the shared data stored in the storage unit, using the first data generated by the first encryption unit; an authentication unit that determines that the authentication target authentication device is legitimate when the unique information included in the plurality of authentication requests received from the authentication target authentication device is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; and a program for functioning as an authentication result output unit that outputs the authentication result that is the determination result by the authentication unit may be used.
[0155] Note that in the above program, the functions realized by the program do not include functions that can only be realized by hardware. For example, functions that can only be realized by hardware such as a modem or an interface card in an acquisition unit that acquires information or an output unit that outputs information are at least not included in the functions realized by the above program.
[0156] In addition, this program may be executed by being downloaded from a server or the like, or may be executed by reading a program recorded on a predetermined recording medium (for example, an optical disk such as a CD-ROM, a magnetic disk, a semiconductor memory, etc.). Further, this program may be used as a program constituting a program product.
[0157] Also, the computer that executes this program may be singular or plural. That is, centralized processing may be performed, or distributed processing may be performed.
[0158] FIG. 7 is a diagram showing an example of a computer system 900 that executes the above program to realize the authenticated device 1 and the authentication device 2 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.
[0159] In FIG. 7, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as a boot-up program and other programs, application programs, system programs, and a flash memory or the like in which data is stored, which is connected to the MPU 911 and temporarily stores instructions of the application program and provides a temporary storage space, a RAM 913, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, the ROM 912, etc. When the exchange of information between the authenticated device 1 and the authentication device 2 is performed other than by communication, the computer system 900 may further include devices used for the exchange of such information, for example, a camera, a light-emitting device, a light-receiving device, etc., as needed. Further, instead of the touch panel 914, a display and input devices such as a mouse and a keyboard may be provided.
[0160] A program for causing the computer system 900 to execute the functions of the authentication target device 1 and the authentication device 2 according to the above embodiment may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 when executed. Note that the program may be directly loaded from a network.
[0161] The program does not necessarily include an operating system (OS) for causing the computer system 900 to execute the functions of the authentication target device 1 and the authentication device 2 according to the above embodiment, or a third-party program, etc. The program may include only a portion of instructions that call appropriate functions and modules in a controlled manner so as to obtain a desired result. How the computer system 900 operates is well known, and a detailed description thereof is omitted.
[0162] Also, the above embodiments are examples for specifically implementing the present invention and do not limit the technical scope of the present invention. The technical scope of the present invention is indicated by the claims rather than the description of the embodiments, and it is intended that changes within the literal scope of the claims and the scope of equivalent meanings are included.
Explanation of Reference Numerals
[0163] 1 Authentication target device 2 Authentication device 11, 23 Storage unit 12 Initial data acquisition unit 13 First encryption unit 14 Second data acquisition unit 15 Second encryption unit 16 Output unit 21 Reception unit 22 Encryption unit 24 Judgment unit 25 Authentication unit 26 Authentication result output unit 27 Data output unit
Claims
1. An initial data acquisition unit that acquires initial data including a user identifier for identifying a user and unique information that is unique information, A first encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data, A second data acquisition unit that acquires second data including shared data shared with an authentication device, A second encryption unit that generates second encrypted data by encrypting the second data using the first data, An authentication device comprising: an output unit that outputs a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device.
2. The authentication device according to claim 1, wherein the unique information includes at least one of a time, a counter value, and a random number value.
3. The authentication device according to claim 1, wherein the first encryption unit acquires first encrypted data obtained by encrypting the initial data using an encryption key corresponding to the user identifier included in the initial data.
4. The authentication device according to claim 3, wherein the first encryption unit acquires first encrypted data obtained by encrypting data of a predetermined data amount including the initial data using the encryption key.
5. The authentication device according to claim 1, wherein the first encryption unit generates first data by reducing the data amount of the first encrypted data.
6. The authentication device according to claim 5, wherein the first encryption unit reduces the data amount by hashing the first encrypted data.
7. The authentication device according to claim 5, wherein the first encryption unit reduces the data amount by extracting a part of the first encrypted data.
8. The data amount of the first data is the same as the data amount of the second data, The authentication device according to any one of claims 1 to 7, wherein the second encryption unit generates second encrypted data that is an exclusive logical sum of the first data and the second data.
9. The authentication device according to any one of claims 1 to 7, wherein the second data acquisition unit acquires the shared data from the authentication device.
10. The authentication device according to any one of claims 1 to 7, wherein the shared data includes a random number.
11. Initial data including a user identifier for identifying a user and unique information that is unique information, and first data generated by acquiring first encrypted data obtained by encrypting the initial data are used to obtain second encrypted data obtained by encrypting second data including shared data. A reception unit that receives a plurality of different authentication requests including the encrypted data from an authentication target device; An encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit; A storage unit that stores shared data shared with a legitimate authentication target device; A determination unit that determines whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit matches the shared data stored in the storage unit, using the first data generated by the encryption unit; An authentication unit that determines that the authentication target device is legitimate when the unique information included in a plurality of authentication requests received from the authentication target device is consistent, and for each of the plurality of authentication requests, the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; An authentication apparatus comprising: an authentication result output unit that outputs an authentication result that is a determination result by the authentication unit.
12. The authentication apparatus according to claim 11, wherein the unique information includes at least one of a time, a counter value, and a random number value.
13. The encryption unit of the authentication apparatus according to claim 11, wherein the encryption unit obtains first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit using an encryption key corresponding to the user identifier included in the initial data.
14. The encryption unit of the authentication apparatus according to claim 13, wherein the encryption unit obtains first encrypted data obtained by encrypting data of a predetermined data amount including the initial data included in the authentication request received by the reception unit using the encryption key.
15. The encryption unit of the authentication apparatus according to claim 11, wherein the encryption unit generates first data by reducing the data amount of the acquired first encrypted data.
16. The data amount of the first data is the same as the data amount of the second data, The authentication apparatus according to any one of claims 11 to 15, wherein the second encrypted data is an exclusive logical sum of the first data and the second data.
17. a data output unit that generates shared data, outputs the shared data to the device to be authenticated, and stores the shared data in the storage unit; 16. The authentication device according to claim 11, wherein the second encrypted data included in the authentication request accepted by the accepting unit is obtained by encrypting the second data including the shared data output by the data output unit.
18. 16. The authentication device according to claim 11, wherein the shared data includes a random number.
19. A step of acquiring initial data including a user identifier for identifying a user and unique information that is unique information; generating first data by obtaining first encrypted data obtained by encrypting the initial data; obtaining second data including shared data sharing the authentication device; generating second encrypted data by encrypting the second data with the first data; and outputting a plurality of different authentication requests, each including the initial data and the second encrypted data, to the authentication device.
20. receiving, from the device to be authenticated, a plurality of different authentication requests each including initial data including a user identifier for identifying a user and unique information that is unique information, and second encrypted data obtained by encrypting second data including shared data using first data generated by obtaining first encrypted data obtained by encrypting the initial data; generating first data by obtaining first encrypted data obtained by encrypting initial data included in the accepted authentication request; a determination unit that determines, using the first data generated in the step of generating the first data, whether or not shared data corresponding to the second encrypted data included in the accepted authentication request matches shared data stored in a storage unit that stores shared data shared with a legitimate device to be authenticated; determining that the authenticated device is valid when it is determined that the unique information included in a plurality of authentication requests received from the authenticated device is consistent and that the shared data corresponding to the second encrypted data included in each of the plurality of authentication requests matches the shared data stored in the storage unit; and outputting an authentication result that is a determination result in the step of determining whether the authenticated device to be authenticated is valid.
21. Computer, an initial data acquisition unit that acquires initial data including a user identifier that identifies a user and unique information that is unique information; a first encryption unit that generates first data by obtaining first encrypted data obtained by encrypting the initial data; a second data acquisition unit that acquires second data including shared data shared with the authentication device; a second encryption unit that generates second encrypted data by encrypting the second data using the first data; a program for causing the computer to function as an output unit that outputs a plurality of different authentication requests, each including the initial data and the second encrypted data, to the authentication device;
22. A computer that can access a storage unit in which shared data shared with a legitimate device to be authenticated is stored, a receiving unit that receives from the device to be authenticated a plurality of different authentication requests, each of which includes initial data including a user identifier for identifying a user and unique information that is unique information, and second encrypted data obtained by encrypting second data including shared data using first data generated by obtaining first encrypted data obtained by encrypting the initial data; an encryption unit that generates first data by obtaining first encrypted data obtained by encrypting initial data included in the authentication request accepted by the acceptance unit; a determination unit that determines, using first data generated by the encryption unit, whether shared data corresponding to second encrypted data included in the authentication request accepted by the acceptance unit matches shared data stored in the storage unit; an authentication unit that determines that the authenticated device to be authenticated is valid when it is determined that unique information included in a plurality of authentication requests received from the authenticated device to be authenticated is consistent and that shared data corresponding to second encrypted data included in each of the plurality of authentication requests matches shared data stored in the storage unit; A program for causing the program to function as an authentication result output unit that outputs an authentication result that is a determination result made by the authentication unit.
Citation Information
Patent Citations
One-time id generating method, authentication method, authentication system, server, client, and program
JP2004282295A
Authentication verification system, device to be authenticated, authentication device, authentication verification method, authentication verification program, computer readable recording medium, and recorded apparatus
JP2021170757A
Device to be authenticated, authentication device, authentication request transmission method, authentication method, and program
JP2021170758A
Device to be authenticated, authentication device, authentication request transmission method, authentication method, and program
JP6732326B1
Authenticated device, authentication device, authentication request transmitting method, authentication method, and program
WO2020080301A1