Authentication apparatus, authentication method, and program
The authentication device manages subscriber and learner IDs with complementary usage authorities, addressing inconsistent access rights in learning services by enabling flexible and controlled transfer or sharing of application permissions.
Patent Information
- Application Number
- JP2024037183
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-11
- Publication Date
- 2025-09-25
- Estimated Expiration
- 2044-03-11
AI Technical Summary
Existing learning service systems fail to appropriately grant subscriber and learner IDs permission to use applications, as the services used by the contracting party and learner often differ, leading to inconsistent access rights.
An authentication device that generates ID groups including subscriber and learner IDs, sets complementary usage authorities, and authenticates application usage based on these authorities, allowing transfer, loan, or sharing of rights within defined limits.
Enables appropriate and flexible access rights management for both subscriber and learner IDs, ensuring all applications within a group have sufficient permissions, and allows controlled transfer or sharing of usage rights.
Smart Images

Figure 2025138219000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an authentication device, an authentication method, and a program for authenticating the use of an application related to a learning service. [Background technology]
[0002] An example of prior art related to account management for learning services is Patent Document 1. The account management system in Patent Document 1 is a system that aims to improve convenience while avoiding the cumbersome task of associating parental accounts with student accounts, which frequently occurs in learning services.
[0003] The account management system of Patent Document 1 stores, in a network environment, a set of first main / sub information for a first main / sub account and a set of second main / sub information for a second main / sub account, and when it receives from the user of the first sub account, who is the parent of student α, that the user of the first sub account is the same as the user of the second sub account, who is the parent of student β, it stores in association with the first sub information, which is the user ID of student α's parent, and information regarding the second main account related to the second sub account, which is information regarding student β's account related to student β's parent account. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2024-5320 Summary of the Invention [Problem to be solved by the invention]
[0005] When using learning services, the services used by the contracting party and the learner often differ. For example, the contracting party uses services such as applying for and signing up for learning services, while the learner often does not use these services. On the other hand, the learner often uses services such as correspondence tutoring and online classes, while the contracting party does not use these services. On the other hand, it may be desirable for services such as checking grades and learning progress to be available to both the contracting party and the learner.
[0006] Therefore, an object of the present disclosure is to provide an authentication device that can appropriately grant a subscriber ID and a learner ID permission to use an application related to a learning service. [Means for solving the problem]
[0007] The authentication device of the present disclosure includes an ID group generation unit, a usage authority setting unit, and an application usage authentication unit.
[0008] The ID group generation unit generates a group including subscriber IDs for subscribers of the learning service and learner IDs for learners of the learning service.
[0009] The usage authority setting unit grants usage authority for multiple applications related to the learning service to at least one of the subscriber ID and the learner ID within the group, and sets the usage authority so that the usage authority for all applications is complementary between the subscriber ID and the learner ID within the group.
[0010] The application usage authentication unit authenticates the use of applications for terminals logged in with a contractor ID or learner ID based on the set usage authority. [Effects of the Invention]
[0011] According to the authentication device of the present disclosure, it is possible to appropriately grant the subscriber ID and learner ID the right to use applications related to learning services. [Brief explanation of the drawings]
[0012] [Figure 1] These are diagrams showing patterns of generating groups including subscriber IDs and learner IDs, where Figure 1(A) shows a case where a group is generated with a single subscriber ID and a single learner ID, Figure 1(B) shows a case where a group is generated with a single subscriber ID and multiple learner IDs, Figure 1(C) shows a case where a group is generated with multiple subscriber IDs and a single learner ID, and Figure 1(D) shows a case where a group is generated with multiple subscriber IDs and multiple learner IDs. [Figure 2] These figures show examples of application displays on a portal site used with each ID, where Figure 2(A) shows an example of application display on a portal site displayed on a terminal logged in with a subscriber ID, and Figure 2(B) shows an example of application display on a portal site displayed on a terminal logged in with a learner ID. [Figure 3] FIG. 10 is a diagram showing another example of a display on a portal site. [Figure 4] A diagram showing variations in usage rights. [Figure 5] FIG. 10 is a diagram showing an example of a flag attached to a usage authority. [Figure 6] FIG. 1 is a block diagram showing the device configuration of an application use authentication system according to a first embodiment. [Figure 7] FIG. 2 is a block diagram showing the functional configuration of the authentication device according to the first embodiment. [Figure 8] 4 is a flowchart showing the basic operation of the authentication device according to the first embodiment. [Figure 9] 10 is a flowchart showing the operation of changing the usage authority of the authentication device according to the first embodiment. [Figure 10] FIG. 4 is a diagram showing an example of database changes in the authentication device according to the first embodiment. [Figure 11] FIG. 2 is a diagram showing an example of the functional configuration of a computer. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present disclosure will be described in detail. Note that components having the same functions are assigned the same numbers, and redundant explanations will be omitted. [Example]
[0014] The terms used in this specification will be explained below.
[0015] <Contractor ID> This is an ID (identifier) generated for the subscriber of a learning service. A subscriber is the entity that contracts for and purchases the learning service, and if the learning service is targeted at students, the subscriber is typically the student's guardian. Alternatively, the subscriber may be a school. In some cases, a school that is a subscriber purchases learning services in bulk through a corporate contract and distributes them to its students. The subscriber uses the subscriber ID to log in to the application portal site.
[0016] <Student ID> This is an ID (identifier) generated for learners of a learning service. A learner is an entity that uses a learning service to learn, and if the learning service targets students, the learner is typically a student. Learners use their learner ID to log in to the application's portal site.
[0017] <Group> A group of IDs is generated that includes a contractor ID and a learner ID. As shown in Figure 1(A), a group may be generated with a single contractor ID and a single learner ID. A typical example would be a group consisting of one contractor parent and one learner student. As shown in Figure 1(B), a group may be generated with a single contractor ID and multiple learner IDs. A typical example would be a group consisting of contractor parents of multiple students (e.g., siblings) and multiple learner students, or a group consisting of a contractor school and its students. As shown in Figure 1(C), a group may be generated with multiple contractor IDs and a single learner ID. A typical example would be a group consisting of multiple contractor parents (e.g., father, mother, grandparents) and one learner student. As shown in Figure 1(D), a group may be generated with multiple contractor IDs and multiple learner IDs. A typical example would be a group consisting of multiple contractor parents (e.g., father, mother, grandparents) and multiple learner students.
[0018] <Application> There are multiple types of applications related to learning services, such as those related to purchasing, signing up for, and signing up for learning services, those related to purchasing learning materials for learning services, those for viewing classes, those for correcting answers, and those for viewing grades.
[0019] <Portal site> A portal site is a site that serves as a gateway for users to use applications. For example, the applications of the portal site displayed on a terminal logged in with a subscriber ID are as shown in Figure 2(A). In the example of the same figure, a subscriber can use the "Apply for Annual Course" app, the "Purchase Teaching Materials" app, and the "Check Grades" app via the portal site. Also, for example, the applications of the portal site displayed on a terminal logged in with a learner ID are as shown in Figure 2(B). In the example of the same figure, a learner can use the "Cram School Lessons" app, the "Study Progress" app, the "Check Grades" app, and the "School Lessons" app via the portal site. Another example of the display of a portal site is as shown in Figure 3.
[0020] <Usage rights> The above applications are set with usage permissions. A terminal logged in with an ID that does not have usage permissions for the application cannot use the application. Application usage permissions are given to at least one of the subscriber ID and learner ID within the group, and are set so that usage permissions for all applications are shared between the subscriber ID and learner ID within the group.
[0021] Complementing usage rights within a group refers to making up for insufficient usage rights granted to a subscriber ID within a group with usage rights granted to a learner ID within the same group, thereby ensuring that usage rights for all applications within the group are sufficient.
[0022] <Changeable, Unchangeable> As shown in Figure 4, there are two types of usage rights: "immutable," which means that usage rights cannot be changed, and "mutable," which means that usage rights can be changed. Changing usage rights refers to changing the ownership of usage rights by transferring, lending, sharing, etc. Therefore, "mutable usage rights" refers to whether usage rights can be transferred, lent, or shared.
[0023] <Transferable> The transferability of usage rights means that the application usage rights that belong to one ID can be transferred, i.e., handed over, to another ID. After the transfer, the transferor no longer has the usage rights, and only the transferee has the usage rights.
[0024] <Available for loan> The ability to lend usage rights means that the application usage rights that belonged to a certain ID can be lent, i.e., loaned, to another ID. After the loan, the original user no longer has the usage rights, and the usage rights only exist for the recipient.
[0025] <Shareable> Sharing usage rights means that the application usage rights that belong to one ID can be shared with another ID, i.e., two IDs can jointly possess the same usage rights. After sharing, both the sharing source and the shared destination will have the usage rights.
[0026] <Number Limit> A limit can be set on the number of transfers, loans, and shares mentioned above. If a limit is set on the number of transfers, loans, and shares, the ID in question cannot transfer, loan, or share to other IDs in excess of the limit. For example, the ID of the transferee, loanee, or sharer can be set to 0, preventing further transfers, loans, or shares.
[0027] <Necessity of approval> Regarding the above-mentioned transfer, loan, and sharing, it is also possible to set cases where the transferee, lender, or sharer wishes to cancel the transfer, loan, or sharing, and where cancellation is not possible without the approval of the transferor, lender, or sharer, or where cancellation is possible freely without the approval of the transferor, lender, or sharer.
[0028] <Restrictions on target> It is possible to place restrictions on the IDs of the transferor, lender, and sharer, as well as the IDs of the transferee, lender, and sharer. For example, it is possible to limit the ID of the transferee to the same group as the ID of the transferor. For example, it is possible to set the IDs of the transferee, lender, and sharer to be unable to be transferred, lent, or shared further.
[0029] <flag> As shown in Figure 5, depending on the type of application, it is possible to set whether or not to "transfer," "lend," or "share," as well as restrictions on the number and the target. As shown in the figure, whether or not to "transfer," "lend," or "share," and restrictions on the target can be managed using flags of 0 or 1.
[0030] The device configuration of the application usage authentication system of the first embodiment will be described below with reference to Fig. 6. As shown in the figure, the application usage authentication system 1 of the present embodiment includes an authentication device 11, an administrator terminal 12, N (N is an integer of 2 or more) user terminals 13-1, 13-2, ..., 13-N, and M (M is an integer of 2 or more) application providing servers 14-1, 14-2, ..., 14-M. Each device will be described below.
[0031] <Authentication Device 11> The authentication device 11 is a device that generates ID groups, sets application usage authority, and authenticates the use of applications for terminals. As shown in Fig. 7, the authentication terminal 11 of this embodiment includes an ID group generation unit 111, a usage authority setting unit 112, an application usage authentication unit 113, a database 114, an information receiving unit 115, and an information transmitting unit 116.
[0032] The database 114 stores information about groups, information about the attribution of application usage rights, information about the type of application and whether it can be transferred, lent, or shared, information about number restrictions, information about target restrictions, and the like.
[0033] <Administrator terminal 12> The administrator terminal 12 is a terminal operated by an administrator of the application usage authentication system 1. When the administrator terminal 12 logs in to the portal site with administrator authority, it can change the attribution of usage authority for any application to any ID. Although not shown in the figure, the administrator terminal 12 includes an information sending unit that has the function of sending information, an information receiving unit that has the function of receiving information, an information display unit that has the function of displaying information, an information input unit that has the function of inputting information, and the like.
[0034] <User terminals 13-1, ..., 13-N> The user terminals 13-1, ..., 13-N are terminals that log in to the portal site using a subscriber ID or a learner ID, receive authentication of the authority to use various applications, and execute various applications if the authentication is successful. Although not shown in the figure, the user terminals 13-1, ..., 13-N include an information sending unit that has the function of sending information, an information receiving unit that has the function of receiving information, an information display unit that has the function of displaying information, an information input unit that has the function of inputting information, etc.
[0035] <Application provider servers 14-1, ..., 14-M> The application providing servers 14-1, ..., 14-M are servers that control various applications. Although not shown in the figure, the application providing servers 14-1, ..., 14-M each include an information transmitting unit that has the function of transmitting information, an information receiving unit that has the function of receiving information, an information display unit that has the function of displaying information, and the like.
[0036] <Basic operation of authentication device 11> The basic operation of the authentication device 11 will be described below with reference to Fig. 8. The ID group generation unit 111 generates a group including subscriber IDs for subscribers of the learning service and learner IDs for learners of the learning service (S111). The usage authority setting unit 112 grants usage authority for multiple applications related to the learning service to at least one of the subscriber IDs and learner IDs in the group, and sets the usage authority so that usage authority for all applications is complementary between the subscriber IDs and learner IDs in the group (S112). The application usage authentication unit 113 authenticates the use of applications for terminals logged in with the subscriber ID or learner ID based on the set usage authority (S113).
[0037] As mentioned above, depending on the type of application, the application usage permissions may include permissions that cannot be transferred, loaned, or shared with other IDs in the group (unchangeable), and permissions that can be transferred, loaned, or shared with other IDs in the group (changeable).
[0038] In addition, application usage rights may include the ability to return usage rights that have been transferred, loaned, or shared with another ID to the ID from which they were transferred, loaned, or shared, and to delete the usage rights of the ID to which they were transferred, loaned, or shared.
[0039] Furthermore, the application usage authority may include an ability to transfer, lend, or share with other IDs within the group, with a limit on the number of times the application usage authority can be transferred, lent, or shared with other IDs.
[0040] For example, it is preferable that the right to use an application for viewing a lesson is given only to the learner's ID and cannot be transferred, loaned, or shared with other IDs in the group.
[0041] For example, it would be preferable if the authority to use an application for purchasing learning services or materials to be used in learning services is given only to the subscriber ID, and can be transferred, loaned, or shared with other subscriber IDs within the group, but cannot be transferred, loaned, or shared with learner IDs within the group.
[0042] Also, for example, it would be preferable if the authorization to use an application for viewing the grades of learners in a learning service could be transferred, lent, or shared with other IDs in the group.
[0043] For example, it would be preferable if the application usage rights for a corporate contracted learning service were limited to the number that could be transferred, loaned, or shared, and could only be transferred, loaned, or shared from a subscriber ID to a learner ID within a group.
[0044] <Operation to change the usage authority of the authentication device 11> 9, when the usage authority setting unit 112 of the authentication device 11 receives a transfer request, a loan request, a sharing request, or a return request from a user terminal 13-1, ..., 13-N logged in with a contractor ID or a learner ID, the usage authority setting unit 112 determines whether the conditions of the possibility flag (transferable / non-transferable / non-lendable / non-shareable), the number restriction condition, and the target restriction condition are met, and if these conditions are met, the usage authority setting unit 112 of the authentication device 11 changes the attribution of the corresponding usage authority based on the received transfer request, loan request, sharing request, or return request (S112-1).On the other hand, if these conditions are not met, the usage authority setting unit 112 of the authentication device 11 displays an error message (S112-2).
[0045] <Example of rewriting Database 114 due to change in usage rights> In the database 114, the attribution of usage rights may be expressed as shown in the example of Fig. 10. In the example of Fig. 10, 00AA is set as the learner ID of Student A. Student A's learner ID: 00AA is given the usage rights for application ID: xxxx1 and application ID: xxxx2, and the usage rights for application ID: xxxx2 are shared with 99BB, which is the subscriber ID of Parent B.
[0046] In response to this, Received{{"xxxx2", "00AA"}} is displayed in the usage permissions of parent B's contractor ID: 99BB, indicating that the usage permissions for application ID: xxxx2 have been shared with learner ID: 00AA. If learner ID: 00AA requests that the sharing of usage permissions for application ID: xxxx2 with contractor ID: 99BB be discontinued (request for return of usage permissions), the two pieces of data shown in the shaded and underlined areas in the figure will be deleted.
[0047] In addition, Student A's learner ID: 00AA has been transferred, loaned, or shared with the right to use application ID: xxxx3 from another account ID: "55CC."
[0048] In addition, Parent B's subscriber ID: 99BB has been granted permission to use application ID: xxxx4.
[0049] As described above, according to the authentication device 11 of this embodiment, the use authority for multiple applications related to learning services is granted to at least one of the subscriber ID and the learner ID in the group, and the use authority is set so that the use authority for all applications is complementary between the subscriber ID and the learner ID in the group, so that the use authority for applications related to learning services can be appropriately granted to the subscriber ID and the learner ID. Furthermore, according to the authentication device 11 of this embodiment, when the conditions are met, the attribution of the corresponding use authority is changed based on a transfer request, a loan request, a sharing request, or a return request, so that the use authority for applications related to learning services can be appropriately changed for the subscriber ID and the learner ID.
[0050] <Additional Notes> The functions performed by the components described herein may be implemented in circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), a CPU (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to perform the described functions. A processor includes transistors and other circuits and is considered to be circuitry or processing circuitry. A processor may also be a programmed processor that executes programs stored in memory.
[0051] In this specification, a circuitry, unit, or means is hardware that is programmed to realize or performs the described functions, which may be any hardware disclosed herein or any hardware known to be programmed to realize or perform the described functions.
[0052] If the hardware is a processor considered to be a type of circuitry, the circuitry, means, or unit is a combination of the hardware and software used to configure the hardware and / or processor.
[0053] The various processes described above can be implemented by loading a program that executes each step of the above method into the recording unit 10020 of the computer shown in Figure 11 and operating the control unit 10010, input unit 10030, output unit 10040, etc.
[0054] The program describing the processing contents can be recorded on a computer-readable recording medium, which may be, for example, a magnetic recording device, an optical disk, a magneto-optical recording medium, a semiconductor memory, or any other suitable recording medium.
[0055] The program may be distributed, for example, by selling, transferring, lending, etc. a portable recording medium such as a DVD or CD-ROM on which the program is recorded. Furthermore, the program may be stored in a storage device of a server computer, and then transferred from the server computer to another computer via a network, thereby distributing the program.
[0056] A computer that executes such a program may first temporarily store the program recorded on a portable recording medium or transferred from a server computer in its own storage device. Then, when executing a process, the computer reads the program stored on its own recording medium and executes the process in accordance with the read program. Alternatively, the computer may read the program directly from a portable recording medium and execute the process in accordance with the program. Furthermore, the computer may execute the process in accordance with the program each time a program is transferred from a server computer to the computer. The server computer may not transfer the program to the computer, but may instead execute the process through a so-called ASP (Application Service Provider) service, which realizes the processing function by issuing an execution instruction and obtaining the results. Furthermore, the server computer may execute the process on a terminal using a so-called SaaS (Software as a Service) service, which allows users to use part of the server computer along with the program. In this embodiment, the program includes information used for computer processing that is equivalent to a program (such as data that is not a direct instruction to the computer but has properties that define computer processing).
[0057] Furthermore, in this embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized by hardware.
Claims
1. an ID group generation unit that generates a group including a subscriber ID for a subscriber of a learning service and a learner ID for a learner of the learning service; a usage authority setting unit that grants usage authority for a plurality of applications related to the learning service to at least one of the subscriber ID and the learner ID in the group, and sets the usage authority so that the usage authority for all of the applications is complementary between the subscriber ID and the learner ID in the group; An application use authentication unit that authenticates the use of the application for the terminal logged in with the contractor ID or the learner ID based on the set usage authority. Authentication device.
2. 2. The authentication device according to claim 1, The usage authority of the application is Depending on the type of the application, the IDs may be either ones that cannot be transferred, lent, or shared with other IDs in the group, or ones that can be transferred, lent, or shared with other IDs in the group. Authentication device.
3. 3. The authentication device according to claim 2, The usage authority of the application is This includes the ability to return the usage rights that have been transferred, loaned, or shared to another ID to the ID from which the transfer, loan, or sharing originated, and to delete the usage rights of the ID to which the transfer, loan, or sharing originated. Authentication device.
4. 4. The authentication device according to claim 3, The usage authority of the application is Includes items that can be transferred, lent, or shared with other IDs within the group, with a limit on the number of items that can be transferred, lent, or shared with other IDs. Authentication device.
5. 5. The authentication device according to claim 4, The right to use the application for viewing lessons is given only to the learner ID and cannot be transferred, lent, or shared with other IDs in the group. Authentication device.
6. 5. The authentication device according to claim 4, The authority to use the application for purchasing the learning service or the learning materials used in the learning service is given only to the subscriber ID, and can be transferred, lent, or shared with other subscriber IDs in the group, but cannot be transferred, lent, or shared with the learner IDs in the group. Authentication device.
7. 5. The authentication device according to claim 4, The use authority of the application for viewing the grades of the learner in the learning service is of a nature that can be transferred, lent, or shared with other IDs in the group. Authentication device.
8. 5. The authentication device according to claim 4, The right to use the application for the learning service contracted by the corporation is limited in the number of rights that can be transferred, lent, or shared, and is of a nature that can only be transferred, lent, or shared from the contractor ID within the group to the learner ID. Authentication device.
9. 5. The authentication device according to claim 4, The usage authority setting unit Based on a transfer request, a lending request, a sharing request, or a return request received from a user terminal logged in with the contractor ID or the learner ID, a change is made to the attribution of the corresponding usage rights. Authentication device.
10. An authentication method performed by an authentication device, comprising: generating a group including subscriber IDs for subscribers of a learning service and learner IDs for learners of the learning service; a step of granting use authority for a plurality of applications related to the learning service to at least one of the subscriber ID and the learner ID in the group, and setting the use authority so that the use authority for all of the applications is complementary between the subscriber ID and the learner ID in the group; and a step of authenticating the use of the application for the terminal logged in with the contractor ID or the learner ID based on the set usage authority. Authentication method.
11. A program that causes a computer to function as the authentication device according to any one of claims 1 to 9.
Citation Information
Patent Citations
Controller of mechanical parking system, mechanical parking system, and control method of mechanical parking system
JP2017096053A
Information processing system, information processing equipment and program
JP2018010363A
Terminal device, server device, control method and program
JP2021009266A
Service providing system, service providing method, and information processing system
JP2021179677A
Account management system and account management program
JP2024005320A