Easy-connect authentication method, easy-connect authentication server, and easy-connect authentication program

The Easy Connect authentication method and server use biometric verification to ensure secure network access for new terminals, addressing security vulnerabilities in existing Easy Connect technologies.

JP2025116657AActive Publication Date: 2025-08-08NEC PLATFROMS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024011196
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-29
Publication Date
2025-08-08
Estimated Expiration
2044-01-29

AI Technical Summary

Technical Problem

Existing Easy Connect technologies facilitate new terminal connections to a network but compromise security, allowing unauthorized access and interception of network information.

Method used

An Easy Connect authentication method and server that utilize biometric information to authenticate new enrollee terminals by comparing stored user biometric information with received biometric information during connection requests, ensuring secure network access.

Benefits of technology

Facilitates secure new terminal connections to a network by preventing unauthorized access through biometric verification, maintaining security while allowing easy network integration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025116657000001_ABST
    Figure 2025116657000001_ABST
Patent Text Reader

Abstract

To provide an easy-to-connect authentication method, an easy-to-connect authentication server, and an easy-to-connect authentication program that facilitate a new connection of a terminal to a network while maintaining security.SOLUTION: An easy-connect authentication method includes a determination step of determining, when terminal information on a new enrollee terminal and biological information on a user are received from a configurator device 300 via an access point device 200 as a new connection request related to a new enrollee terminal 400 by an easy-connect authentication server 100 that stores the biological information on the user, whether or not the new enrollee terminal can be connected by collating the stored biological information with the received biological information.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an EasyConnect authentication method, an EasyConnect authentication server, and an EasyConnect authentication program. [Background technology]

[0002] There is a technology known as Easy Connect that makes it easy for a new enrollee terminal to connect to a network such as Wi-Fi (see Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2023-146162 Summary of the Invention [Problem to be solved by the invention]

[0004] The following analysis has been made from the perspective of the present invention, and the disclosures of the above-mentioned prior art documents are incorporated herein by reference.

[0005] The technology known as "Easy Connect" poses security risks as a trade-off for facilitating new terminal connections to a network. For example, in Patent Document 1, the operation for new connection is completed by reading a QR (Quick Response) code (registered trademark) of the terminal to be newly connected by a terminal device acting as a configurator. This makes it easy for a terminal belonging to a malicious user to newly connect. As a result, it is not possible to prevent information communicated via an access point from being intercepted or unauthorized use of the network.

[0006] Therefore, an object of the present invention is to provide a technique that contributes to facilitating new connection of a terminal to a network while maintaining security. [Means for solving the problem]

[0007] According to a first aspect of the present invention, EasyConnect authentication server that stores user biometric information a determination step of determining whether or not to allow connection of a new enrollee terminal by comparing the stored biometric information with the received biometric information when terminal information of the new enrollee terminal and biometric information of the user are received from the configurator device via the access point device as a new connection request for the new enrollee terminal; An Easy Connect authentication method is provided, which includes:

[0008] According to a second aspect of the present invention, a storage unit that stores biometric information of a user; a determination unit that, when receiving terminal information of a new enrollee terminal and biometric information of a user from a configurator device via an access point device as a new connection request for the new enrollee terminal, determines whether or not the new enrollee terminal is allowed to connect by comparing the stored biometric information with the received biometric information; An EasyConnect authentication server is provided, comprising:

[0009] According to a third aspect of the present invention, A computer that acts as an EasyConnect authentication server that stores the user's biometric information. a determination process for determining whether or not a new enrollee terminal can be connected by comparing the stored biometric information with the received biometric information when the terminal information and the user's biometric information of the new enrollee terminal are received from the configurator device via the access point device as a new connection request for the new enrollee terminal; An Easy Connect authentication program is provided that allows you to: [Effects of the Invention]

[0010] According to each aspect of the present invention, an Easy Connect authentication method, an Easy Connect authentication server, and an Easy Connect authentication program are provided that contribute to facilitating new connection of a terminal to a network while maintaining security. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram for explaining an overview. [Figure 2] FIG. 1 illustrates an example of a system. [Figure 3] FIG. 2 is a diagram showing a processing flow in the system. [Figure 4] FIG. 10 illustrates an example of a probe request. [Figure 5] FIG. 10 is a diagram showing a processing flow by an authentication server. [Figure 6] FIG. 1 illustrates an example of a computer. DETAILED DESCRIPTION OF THE INVENTION

[0012] Preferred embodiments of the present invention will be described in detail with reference to the drawings. Note that the reference numerals used in the following description are used for convenience to identify each element as an example to facilitate understanding, and are not intended to limit the present invention to the illustrated embodiment. Furthermore, the connecting lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Furthermore, although not explicitly shown, input and output ports exist at the input and output ends of each connecting line in the circuit diagrams, block diagrams, internal configuration diagrams, connection diagrams, and the like shown in this disclosure. The same applies to input and output interfaces.

[0013] First, an overview of the present invention will be described using as an example a system including an authentication server 100, an access point device 200, a configurator device 300, and an enrollee terminal 400 as shown in FIG.

[0014] 1, authentication server 100 includes storage unit 110 that stores user biometric information, and determination unit 120 that determines whether or not a new enrollee terminal 400 can connect. Determination unit 120 receives terminal information about new enrollee terminal 400 and user biometric information as a new connection request for new enrollee terminal 400 from configurator device 300 via access point device 200. Here, determination unit 120 determines whether or not a new enrollee terminal 400 can connect by comparing the stored biometric information with the received biometric information.

[0015] The differences between the present invention and the prior art will be explained using more specific examples. Here, a Wi-Fi router is assumed as an example of the access point device 200. A smartphone is assumed as an example of the configurator device 300. A tablet device is assumed as an example of the new enrollee terminal 400. The person who installs the access point device 200 is considered to be the user. The user's voiceprint is assumed as an example of biometric information. More specifically, a case is assumed in which a user installs home Wi-Fi, sets a smartphone as the configurator device 300, and newly connects a tablet device as the enrollee terminal 400.

[0016] In the prior art, a new connection operation is completed by using the camera of the configurator device 300 to read a QR (Quick Response) code displayed on the display of the enrollee terminal 400. Therefore, if a malicious person has the configurator device 300 read the QR code displayed on the display of the user's terminal while the user is not looking, the malicious person's terminal can be connected.

[0017] On the other hand, in the present invention, for example, in order to connect a new enrollee terminal 400, it is necessary to have the configurator device 300 read the QR code, and also to input voice (voiceprint) to the access point device 200. Even if a malicious person inputs voice, the present invention makes it impossible to authenticate the person, and it is possible to prevent the malicious person's terminal from connecting.

[0018] In the above overview, the access point device 200 and the configurator device 300 are configured as separate components, but they can also be configured as an integrated device. For example, if the access point device 200 is equipped with a camera for reading QR codes and a microphone for collecting audio, the access point device 200 and the configurator device 300 can be applied as an integrated device.

[0019] Although the above overview describes an example in which a QR code is used, a configuration using wireless communication is also possible. For example, the new enrollee terminal 400 may transmit a probe request including biometric information to the access point device 200. Furthermore, biometric information is not limited to voiceprints; fingerprints, irises, etc. may also be used.

[0020] [Embodiment 1] The system outlined above will be described in more detail below as embodiment 1. In embodiment 1, an access point device 200 and a configurator device 300 are integrated into one device, as shown in FIG.

[0021] A Wi-Fi router is exemplified as the access point device 200. The function of the configurator device 300 is also the same as that of the conventional technology, and therefore a description thereof will be omitted.

[0022] The enrollee terminal 400 is, for example, a terminal connected to a personal home Wi-Fi, and is exemplified by a smartphone, a tablet terminal, a laptop computer, a printer, etc. The enrollee terminal 400 also has a function for acquiring the user's biometric information (for example, a microphone for collecting the user's voice and a reader for collecting the user's fingerprints).

[0023] The authentication server 100 includes a storage unit 110 that stores biometric information of the user, as in the above outline, and a determination unit 120 that determines whether or not the new enrollee terminal 400 is allowed to connect.

[0024] The storage unit 110 stores, for example, the user's biometric information in association with the device identification (ID) of the access point device 200. This information is saved when the access point device 200 is installed by the user.

[0025] The determination unit 120 will be described along with the flow of processing for newly connecting the enrollee terminal 400.

[0026] The following describes the flow of processing for newly connecting an enrollee terminal 400. It is assumed that the device ID (hereinafter referred to as "AP-ID") of the access point device 200 and the user's biometric information have already been stored in the storage unit 110. In other words, it is assumed that the setup of the access point device 200 has been completed.

[0027] As shown in Fig. 3, first, when a new connection operation is performed on the enrollee terminal 400, the enrollee terminal 400 requests the operator to input voice (biometric information). When the voice is input, the enrollee terminal 400 transmits a probe request including the biometric information to the access point device 200. Here, Fig. 4 shows an example of the probe request. In Fig. 4, voiceprint information is used as the biometric information.

[0028] Upon receiving the probe request, the access point device 200 transmits its own device ID (AP-ID) and biometric information to the authentication server 100 and requests a bootstrap.

[0029] The determination unit 120 of the authentication server 100 reads out from the storage unit 110 the biometric information stored in association with the received AP-ID and compares it with the received biometric information. If the comparison result is OK, indicating that the stored biometric information (user's voice) matches the received biometric information (the voice of the operator of the enrollee terminal 400), the determination unit 120 determines that connection is permitted and issues a Bootstrap to the access point device 200. On the other hand, if the comparison result is NG, indicating that the stored biometric information (user's voice) does not match the received biometric information (the operator's voice), the determination unit 120 determines that connection is not permitted and issues an authentication failure to the access point device 200.

[0030] The access point device 200 that has received the bootstrap performs processing to newly connect the enrollee terminal 400 in the same manner as in the conventional technology. One example is processing in which DPP authentication, DPP configuration, etc. are exchanged between the access point device 200 and the enrollee terminal 400.

[0031] The following describes the flow of processing by the authentication server 100. As shown in Fig. 5, when a probe request including biometric information is received (step S01, Yes), the authentication server 100 compares the stored biometric information with the received biometric information (step S02). If the comparison result is OK (step S02, Yes), the authentication server 100 determines that connection is permitted and issues a bootstrap to the access point device 200 (step S03), and again waits for a probe request (returns to step S01). If the comparison result is NG (step S02, No), the authentication server 100 determines that connection is not permitted and issues an authentication failure to the access point device 200 (step S04), and again waits for a probe request (returns to step S01).

[0032] As described above, according to the present invention, it becomes easy to newly connect a terminal to a network while maintaining security.

[0033] [Transformation] (1) The biometric information stored in the authentication server 100 is not limited to the biometric information of the person who installed the access point device 200. In other words, the user is not limited to the person who installed the access point device 200.

[0034] For example, the user may be a person who first registers a terminal for connection with the access point device 200. In this case, the authentication server 100 receives the user's biometric information as the first new connection request, and stores the received biometric information in association with the device ID of the access point device 200.

[0035] The owner of the configurator device 300 may also be considered the user.

[0036] (2) The biometric information stored in the authentication server 100 may be the biometric information of multiple people. A specific example will be described below. First, assume that "father" installs the access point device 200 (home Wi-Fi router) and that "father's" biometric information is stored in the authentication server 100. When "mother" newly connects an enrollee terminal 400, "father's" biometric information needs to be entered. At that time, "mother's" biometric information may be stored in the authentication server 100. In this case, when "mother" newly connects another enrollee terminal 400, she only needs to enter her own biometric information. In other words, "father" can be considered the primary user, and "mother" can be considered the secondary user authenticated by the primary user.

[0037] (3) As described above, when the first enrollee terminal 400 owned by "mother" is newly connected, the biometric information of "father" must be input. Here, the authentication server 100 may request the input of biometric information via the enrollee terminal 400 owned by "father" that has already been registered for connection.

[0038] (4) The user's biometric information to be input when connecting the new enrollee terminal 400 may be input from any of the access point device 200, the configurator device 300, an enrollee terminal 400 that has already been registered for connection, and the new enrollee terminal 400.

[0039] As an example, consider a case where a new enrollee terminal 400 is connected by having the configurator device 300 read a QR code displayed on the display of the new enrollee terminal 400. In this case, the configurator device 300 may request the user to input biometric information for its own device, or the new enrollee terminal 400 may request the user to input biometric information for its own device. Here, it is also possible that the "configurator device 300" and the "registered enrollee terminal 400" are the same device.

[0040] It is also possible to consider a case where the access point device 200 newly connects the enrollee terminal 400 by reading a QR code displayed on the display of the new enrollee terminal 400. In this case, the access point device 200 may request the user to input biometric information for the access point device itself.

[0041] In any case, as long as the authentication server 100 can receive the user's biometric information as a new connection request for the new enrollee terminal 400, the present invention can be applied.

[0042] (5) The present invention can also be implemented as a program that causes a computer serving as Easy Connect authentication server 100 to execute the processing of the present invention. For example, as shown in FIG. 6, the computer includes a memory, a CPU (Central Processing Unit), and an interface. The memory also stores information corresponding to storage unit 110. The CPU reads out the program of the present invention from the memory and executes it, thereby realizing a processing module corresponding to determination unit 120.

[0043] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.

[0044] (Appendix 1) EasyConnect authentication server that stores user biometric information a determination step of determining whether or not to allow connection of a new enrollee terminal by comparing the stored biometric information with the received biometric information when terminal information of the new enrollee terminal and biometric information of the user are received from the configurator device via the access point device as a new connection request for the new enrollee terminal; Easy Connect authentication methods, including:

[0045] (Appendix 2) 2. The Easy Connect authentication method according to claim 1, wherein the user is a person who installed the access point device.

[0046] (Appendix 3) 2. The Easy Connect authentication method of claim 1, wherein the user is an owner of the configurator device.

[0047] (Appendix 4) 2. The Easy Connect authentication method of claim 1, wherein the user is an owner of an enrollee terminal that is already connected to the access point device.

[0048] (Appendix 5) a storage unit that stores biometric information of a user; a determination unit that, when receiving terminal information of a new enrollee terminal and biometric information of a user from a configurator device via an access point device as a new connection request for the new enrollee terminal, determines whether or not the new enrollee terminal is allowed to connect by comparing the stored biometric information with the received biometric information; An Easy Connect authentication server comprising:

[0049] (Appendix 6) A computer that acts as an EasyConnect authentication server that stores the user's biometric information. a determination process for determining whether or not a new enrollee terminal can be connected by comparing the stored biometric information with the received biometric information when the terminal information and the user's biometric information of the new enrollee terminal are received from the configurator device via the access point device as a new connection request for the new enrollee terminal; Easy Connect authentication program that runs.

[0050] The features described in Supplementary Notes 2 to 4 can also be applied to the EasyConnect authentication server and the EasyConnect authentication program.

[0051] The disclosures of the above-cited patent documents and other documents are incorporated herein by reference and may be used as the basis or part of the present invention, as necessary. Modifications and adjustments of the embodiments and examples are possible within the scope of the entire disclosure of the present invention (including the claims), and further based on the basic technical concepts thereof. Furthermore, various combinations and selections (including partial deletions) of the various disclosed elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible within the scope of the entire disclosure of the present invention. In other words, the present invention naturally embraces various modifications and alterations that would be possible by a person skilled in the art in accordance with the entire disclosure and technical concepts, including the claims. In particular, with regard to the numerical ranges set forth herein, any numerical value or subrange within that range should be construed as specifically set forth, even if not otherwise specified. Furthermore, the disclosures of the above-cited documents, when used in part or in whole in combination with the disclosures herein as part of the disclosure of the present invention, in accordance with the spirit of the present invention, are also deemed to be included in the disclosures of this application. [Explanation of symbols]

[0052] 100 Authentication Server 110 Storage section 120 Judgment section 200 Access Point Device 300 configurator device 400 Enrollee terminal

Claims

1. EasyConnect authentication server that stores user biometric information a determination step of determining whether or not to allow connection of a new enrollee terminal by comparing the stored biometric information with the received biometric information when terminal information of the new enrollee terminal and biometric information of the user are received from the configurator device via the access point device as a new connection request for the new enrollee terminal; Easy Connect authentication methods, including:

2. 2. The easy connect authentication method according to claim 1, wherein the user is a person who installed the access point device.

3. 2. The EasyConnect authentication method of claim 1, wherein the user is the owner of the configurator device.

4. 2. The easy connect authentication method according to claim 1, wherein the user is an owner of an enrollee terminal that is already connected to the access point device.

5. a storage unit that stores biometric information of a user; a determination unit that, when receiving terminal information of a new enrollee terminal and biometric information of a user from a configurator device via an access point device as a new connection request for the new enrollee terminal, determines whether or not the new enrollee terminal is allowed to connect by comparing the stored biometric information with the received biometric information; An Easy Connect authentication server comprising:

6. A computer that acts as an EasyConnect authentication server that stores the user's biometric information. a determination process for determining whether or not a new enrollee terminal can be connected by comparing the stored biometric information with the received biometric information when the terminal information and the user's biometric information of the new enrollee terminal are received from the configurator device via the access point device as a new connection request for the new enrollee terminal; Easy Connect authentication program that runs.

Citation Information

Patent Citations

  • Communication system, electronic device, and program

    JP2021158494A

  • Methods, devices and systems for automatically adding devices to network using wireless positioning techniques

    JP2023160794A

  • First communication device, computer program for first communication device, and application program for second communication device

    JP2023146162A