Data circulation system, connector device, and user authentication method

The data distribution system uses telephone carrier subscriber information for secure user authentication, addressing impersonation risks and reducing operational costs by integrating with existing telephone communication services.

JP2025143008AActive Publication Date: 2025-10-01NTT DOCOMO BUSINESS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024042674
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-18
Publication Date
2025-10-01
Estimated Expiration
2044-03-18

AI Technical Summary

Technical Problem

Existing user authentication methods in data sharing platforms are vulnerable to impersonation and require significant effort and cost for constructing new trust infrastructure and authentication systems, posing a risk of unauthorized data access.

Method used

A data distribution system that utilizes telephone carrier subscriber information for user authentication by storing user information in connector devices and verifying it through telephone communication services, eliminating the need for a new authentication system and cumbersome procedures.

Benefits of technology

Provides highly reliable user authentication without additional cost or effort, leveraging existing telephone communication services to prevent impersonation and ensure secure data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025143008000001_ABST
    Figure 2025143008000001_ABST
Patent Text Reader

Abstract

To enable a reliable user authentication by preventing spoofing without causing much labor and cost burdens on an operation company and users.SOLUTION: In the case of performing data transmission using a data space between users using connector devices, user information on the respective users attempting to perform the data transmission is stored in the connector device in a state of including subscriber information assigned to the users from phone telecommunication carriers of subscription destinations. The respective connector devices have a call outgoing / incoming function using the subscriber information. In performing the data transmission between the users, authentication of a communication partner user is performed, respectively, by transmitting / receiving user information including subscriber information on a user on the partner side using the call outgoing / incoming function and collating the transmitted subscriber information on the partner side with previously stored user information.SELECTED DRAWING: Figure 10
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] One aspect of the present invention relates to a data distribution system that distributes data between companies or industries using a data linkage platform, and a connector device and a user authentication method used in the data distribution system. [Background technology]

[0002] In recent years, a data sharing platform (hereafter referred to as "data space") has been proposed that allows the mutual distribution of unique data held by multiple companies or industries within or between countries that make up a supply chain. By using this data sharing platform, it becomes possible to efficiently collect and manage data on goods such as products and parts that are stored in a distributed manner across multiple companies, as well as data on services.

[0003] However, user authentication is essential for safe use of the data sharing platform. Therefore, a technology has been proposed that connects the user terminal and the data sharing platform via a connector device called a data space connector, and executes an authentication procedure in this connector device to prevent unauthorized access to the data sharing platform and enable safe distribution of data (see, for example, Non-Patent Document 1). [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] “Prototype platform for interconnection with the core technology of the European GAIA-X, IDS Connector,” NTT Communications Corporation, April 8, 2021, Internet<URL: https: / / www.ntt.com / about-us / press-releases / news / article / 2021 / 0408.html> Summary of the Invention [Problem to be solved by the invention]

[0005] However, the user authentication method described in Non-Patent Document 1 is a system in which user IDs issued by the data sharing platform operator or by an external ID provider are linked to the connector number of each user, and are managed and authenticated. Therefore, if someone copies the software that runs the connector device or the user ID and poses as a legitimate user, there is a risk that data may be illegally stolen.

[0006] Furthermore, preventing the above-mentioned spoofing would require the construction of a new trust infrastructure and authentication system, as well as tedious procedures and management systems such as strict credit screening, which would impose a great deal of effort and cost on the operators and users of the data sharing infrastructure.

[0007] This invention has been made in light of the above circumstances, and aims to provide a technology that prevents impersonation and enables highly reliable user authentication without imposing a significant burden on operators and users in terms of effort and cost. [Means for solving the problem]

[0008] In order to solve the above problems, one aspect of the data distribution system and its user authentication method according to the present invention is a data distribution system in which data is transmitted between a plurality of connector devices used by each user via a data linkage infrastructure, and the connector devices and the data linkage infrastructure communicate with each other by making and receiving calls using subscriber information assigned by the respective subscriber's telephone carrier, and Each of the multiple connector devices stores its own user information, including the subscriber information assigned to that connector device, in its own information storage unit, and also stores the other party's user information, including the subscriber information assigned to the connector device that is the other party in the data transmission, in its other party information storage unit.

[0009] In this state, the first connector device, which is the requesting party of the data transmission, transmits communication request information including its own user information stored in its own information storage unit to the second connector device, which is the other party of the data transmission, via the telephone communication using the outgoing and incoming call. In response, when the second connector device receives the communication request information, it compares the user information of the first connector device included in the received communication request information with the user information of the other party stored in its other party information storage unit to determine the legitimacy of the received user information. If it determines that the received user information is legitimate, it transmits communication response information including the user information of the second connector device stored in its own information storage unit to the first connector device via the telephone communication. Upon receiving the communication response information, the first connector device compares the user information of the second connector device included in the communication response information with the user information of the second connector device stored in its other party information storage unit to determine the legitimacy of the received second user information.

[0010] According to one aspect of the present invention, the following effects can be achieved. In other words, telephone communication services provided by telephone carriers in each country in accordance with international standards and laws and regulations provide services that are virtually impossible to spoof by verifying the identity of the user and strictly managing and authenticating subscriber information (such as telephone numbers).

[0011] Therefore, by performing user authentication by combining the call originating and receiving functions of telephone communication services as described above, operators can prevent impersonation without having to build a new large-scale authentication system and without requiring users to go through cumbersome procedures such as credit checks, thereby making it possible to reliably identify, specify, and authenticate the other party of a communication. [Effects of the Invention]

[0012] In other words, according to one aspect of the present invention, it is possible to provide a technology that prevents impersonation and enables highly reliable user authentication without imposing a significant effort or cost burden on the operating company or user. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram showing an example of the overall configuration of a data distribution system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of the hardware configuration of a connector device used in the data distribution system shown in FIG. [Figure 3] FIG. 3 is a block diagram showing an example of the software configuration of the connector device used in the data distribution system shown in FIG. [Figure 4] FIG. 4 is a block diagram showing an example of the hardware configuration of a data space management device used by an operator of a data linkage platform in the data distribution system shown in FIG. [Figure 5] FIG. 5 is a block diagram showing an example of the software configuration of a data space management device used by an operator of a data linkage platform in the data distribution system shown in FIG. [Figure 6] FIG. 6 is a diagram showing a connection configuration between the connector device, the data space management device, and the telephone carrier in the data distribution system shown in FIG. [Figure 7] FIG. 7 is a sequence diagram showing the procedure of the registration control process carried out between the connector device and the data space management device when user information of user A is registered in the data distribution system shown in FIG. [Figure 8] FIG. 8 is a sequence diagram showing the procedure of the registration control process carried out between the connector device and the data space management device when registering information required for authenticating user B in the data distribution system shown in FIG. [Figure 9]FIG. 9 is a sequence diagram showing the processing procedure for registering user information of communication partners in the connector devices of users A and B in the data distribution system shown in FIG. [Figure 10] FIG. 10 is a sequence diagram showing the procedure of authentication processing executed before data transmission between connector devices of users in the data distribution system shown in FIG. [Figure 11] FIG. 11 is a diagram showing an example of user information managed by the data space management device. [Figure 12] FIG. 12 is a diagram showing an example of communication path information indicating a communication path when data is transmitted between users. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0015] [One embodiment] (Configuration example) (1) System FIG. 1 is a diagram showing an example of the configuration of a data distribution system according to an embodiment of the present invention.

[0016] In Figure 1, NW indicates an international network including a data sharing platform. The data sharing platform is also called a data space, and the data space is managed by a data space management device (DSM) installed by the data sharing platform operator.

[0017] User terminals UTa, UTb, ..., UTk used by industries, companies or individuals in each country who wish to use the data space are connected to the network NW via connector devices CNa, CNb, ..., CNk, each called a data space connector.

[0018] The network NW also includes telephone communication networks operated by telephone communication carriers in each country. Each telephone communication network is managed by central office equipment TEx, TEy, TEz installed by the respective telephone communication carrier. Central office equipment TEx, TEy, TEz each has a user database SDx, SDy, ..., SDz. In the user database SDx, SDy, ..., SDz, for example, telephone numbers assigned as subscriber information to users who subscribe to the telephone communication network are securely stored and managed as user information, linked to identification information (for example, a corporate number) for verifying the user's identity. Note that the data space administrator is also subscribed to the telephone communication network in his / her own country, and his / her telephone number is stored in the user database of the telephone communication carrier to which he / she subscribes.

[0019] (2) Equipment (2-1) Connector device CNa, CNb, ..., CNk 2 and 3 are block diagrams showing examples of the hardware and software configurations of the connector devices CNa, CNb, . . . , CNk, respectively.

[0020] The connector devices CNa, CNb, ..., CNk are equipped with a control unit 1 that uses a hardware processor such as a central processing unit (CPU), and this control unit 1 is connected via a bus to a memory unit having a program memory unit 2 and a data memory unit 3, an IP communication interface (hereinafter, the interface will be abbreviated as I / F) unit 4, and a telephone communication I / F unit 5.

[0021] The IP communication I / F unit 4 sends and receives data via the network NW with the connector device that is the destination of the data transmission in accordance with the communication protocol specified in the IP network, and also sends and receives control information necessary for using the data space with the data space management device DSM.

[0022] The telephone communication I / F unit 5 transmits and receives information necessary for authenticating the connector device of the communication partner, and between the telephone communication carrier's central office devices TEx, TEy, ..., TEz, respectively, via the telephone communication network.

[0023] The program storage unit 2 is configured by combining, for example, a non-volatile memory such as a solid-state drive (SSD) as a storage medium that can be written to and read from at any time, and a non-volatile memory such as a read-only memory (ROM), and stores middleware such as an operating system (OS), as well as application programs required to execute various control processes according to one embodiment. Hereinafter, the OS and each application program will be collectively referred to as the program.

[0024] The data storage unit 3 is, for example, a combination of a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium, and a volatile memory such as RAM (Random Access Memory), and has a user management area 31 and a telephone carrier management area 32.

[0025] The user management area 31 is an area managed by the data space operator and the user, and includes a self ID storage unit 311 and a partner ID storage unit 312. The self ID storage unit 311 stores the user's own identification information (self ID) used when transmitting data using the data space. The partner ID storage unit 312 stores the identification information (partner ID) of the partner with whom data is transmitted using the data space.

[0026] The telephone carrier management area 32 includes a telephone number storage unit 321. The telephone number storage unit 32 stores telephone numbers assigned to users as subscriber information by the telephone carriers to which the users subscribe.

[0027] The control unit 1 includes a user registration control processing unit 11, a communication partner registration control processing unit 12, a data transmission control processing unit 13, and an authentication control processing unit 14 as processing functions required to implement an embodiment.

[0028] These processing units 11 to 14 are all realized by causing a hardware processor in the control unit 1 to execute an application program stored in the program storage unit 2. Note that some or all of the processing units 11 to 14 may be realized using hardware such as an LSI (Large Scale Integration) or an ASIC (Application Specific Integrated Circuit).

[0029] The user registration control processing unit 11 executes a process for registering the user's own user information, which is necessary for the user to use the data space as a sender, in the data space management device DSM.

[0030] The communication partner registration control processing unit 12 executes a process for registering user information of a user who is to be a communication partner in its own connector device when the user transmits data using the data space.

[0031] When transmitting data between a communication partner connector device and the data transmission control processing unit 13 using the data space, the data transmission control processing unit 13 establishes a communication link with the communication partner connector device and transmits the data.

[0032] The authentication control processing unit 14 executes an authentication procedure with the communication partner in advance when transmitting data to the communication partner's connector device, and is equipped with a telephone communication control unit 141, a partner ID matching processing unit 142, and a telephone number validity confirmation processing unit 143 as processing functions for this purpose.

[0033] The telephone communication control unit 141 uses the call originating and receiving function of the telephone communication service to send and receive communication requests and access information to and from the connector device of the other party of communication.

[0034] When the other party ID matching processing unit 142 receives a communication request from the above-mentioned originating connector device, it matches the user information contained in the above-mentioned communication request with the other party's user information pre-stored in the other party ID storage unit 312, and determines whether there is any matching user information.

[0035] When the telephone number validity confirmation processing unit 143 receives the communication request, it inquires about the validity of the telephone number included in the user information of the requester included in the communication request from the central office device of the telephone communication carrier to which both of the communication requesters subscribe.

[0036] Details of the authentication procedure using the telephone communication control unit 141, the other party ID matching processing unit 142, and the telephone number validity confirmation processing unit 143 will be explained in the operation example.

[0037] (2-2) Data Space Management Unit (DSM) 4 and 5 are block diagrams showing an example of the hardware configuration and software configuration of the data space management device DSM, respectively.

[0038] Like the connector device, the data space management device DSM also has a control unit 6 that uses a hardware processor such as a central processing unit (CPU). A storage unit having a program storage unit 7 and a data storage unit 8, a telephone communication I / F unit 9, and an IP communication I / F unit 10 are connected to this control unit 6 via a bus.

[0039] The telephone communication I / F unit 9 transmits and receives information for verifying the telephone number of a user between the central office devices TEx, TEy, . . . , TEz of the telephone communication carrier via the telephone communication network.

[0040] The IP communication I / F unit 10 transmits and receives requests for user registration and notifications of registration results between the user's connector devices CNa, CNb, ..., CNk via the IP network, and also transmits and receives requests to confirm communication permission and their responses.

[0041] The program storage unit 7 is configured by combining, for example, a nonvolatile memory such as an SSD that can be written to and read from at any time as a storage medium, and a nonvolatile memory such as a ROM, and stores middleware such as an OS as well as application programs required to execute various control processes according to an embodiment. Hereinafter, the OS and each application program will be collectively referred to as the program.

[0042] The data storage unit 8 is, for example, a combination of a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium, and a volatile memory such as RAM, and is equipped with a user information storage unit 81 and a telephone number storage unit 822 as the main storage units required to implement one embodiment.

[0043] The user information storage unit 81 stores the user information of all users who have registered with the data space in association with their telephone numbers.

[0044] The telephone number storage unit 82 stores telephone numbers assigned to the data space management device DSM by the telephone carrier to which the data space management device DSM subscribes.

[0045] The control unit 6 includes a user registration reception processing unit 61 and a user-to-user registration relay processing unit 62 as processing functions necessary to implement an embodiment.

[0046] The processing units 61 and 62 are both realized by causing a hardware processor in the control unit 6 to execute an application program stored in the program storage unit 7. Note that part or all of the processing units 61 and 62 may be realized using hardware such as an LSI or an ASIC.

[0047] When the user registration reception processing unit 61 receives a user registration request from the user's connector devices CNa, CNb, ..., CNk, it requests the station devices TEx, TEy, ..., TEz of the telephone communication carrier to which the requesting user subscribes to verify the user's telephone number via the telephone communication network. Then, when it receives a response to the verification request indicating that the telephone numbers match, it stores the user information of the user in the user information storage unit 81.

[0048] When the user-to-user registration relay processing unit 62 receives a request for permission to communicate from a connector device used by a user on the sending side, it transfers the request to a connector device used by a user on the receiving side. Also, when a response to the request is returned from the connector device used by the user on the receiving side, it transfers the response to the connector device used by the user on the sending side.

[0049] (Example of operation) Next, an example of the operation of the data distribution system configured as above will be described.

[0050] Here, as shown in Figure 6, we will take the example of data transmission between a sending user A (also called sender A) and a receiving user B (also called receiver B) via a data space, and explain the process of registering users A and B in the data space management device DSM, the process of registering the communicating users B and A in their own connector devices DNa and DNb, respectively, the process of performing an authentication procedure using telephone numbers with the communicating users prior to data transmission, and the process of transmitting data between users A and B after authentication.

[0051] (1) Registering users A and B in the data space management device DSM (1-1) Registration of User A FIG. 7 is a sequence diagram showing an example of the procedure and processing contents of the user registration process for the user A, which is executed between the connector device CNa used by the user A and the data space management device DSM.

[0052] When user A performs a registration request operation for registering himself / herself on the user terminal UTa, in response to the registration request operation, the connector device CNa, under the control of the user registration control processing unit 11, transmits a request for user registration from the IP communication I / F unit 4 to the data space management device DSM. The registration request includes, for example, the corporate number of the company to which user A belongs, which is one of the attribute information of user A, and the telephone number assigned to user A by the telephone carrier as subscriber information. Note that, instead of or in addition to the corporate number, information identifying the industry to which user A belongs, place of residence, etc. may be used as the user's attribute information.

[0053] In response to this, when the data space management device DSM receives the above request via the IP communication I / F unit 10, under the control of the user registration reception processing unit 61, it first sends a confirmation request for user A from the telephone communication I / F unit 9 to the central office device TEx of the telephone communication carrier to which user A subscribes, based on the corporate number and telephone number of user A contained in the above request.

[0054] Upon receiving the confirmation request, the central office device TEx of the telephone carrier checks the telephone number and corporate number of User A included in the confirmation request against the user information stored in the user database SDx to determine whether they match, and then returns the result of the check to the data space management device DSM.

[0055] When the data space management device DSM confirms that the telephone number and corporate number of user A match based on the above judgment result, it issues a connector number to the connector device CNa used by user A under the control of the user registration reception processing unit 61, and generates user information in which the connector number is added to the telephone number and corporate number.The generated user information of user A is then stored in the user information storage unit 81.

[0056] 11 shows an example of user information stored in the user information storage unit 81. In this example, a telephone number, a corporate number, and a connector number are stored in association with the user's name, and information indicating the user's location of use is also stored.

[0057] Upon completing the above user information registration process, the user registration reception processing unit 61 sends a registration completion notification including the connector number of the connector device CNa and the corporate number of user A from the IP communication I / F unit 10 to the connector device CNa of user A, which sent the request.

[0058] When the connector device CNa receives the registration completion notification, under the control of the user registration control processing unit 11, it stores the corporate number and connector number of user A contained in the received registration completion notification in the self ID memory unit 311.

[0059] In addition, when the data space management device DSM receives a request from the connector device CNa, it may call user A using the telephone number included in the request, and determine the validity of user A's telephone number, i.e., whether the telephone number is alive or dead, based on user A's response to the call.

[0060] (1-2) Registration of User B User B's user registration is performed in the same procedure as the user A's user registration process described above.

[0061] FIG. 8 is a sequence diagram showing an example of the procedure and processing contents of the user registration processing for user B, which is executed between the connector device CNb used by user B and the data space management device DSM.

[0062] That is, in response to a registration request operation on the user terminal UTb, a request for registration of user B is sent from the connector device CNb to the data space management device DSM via the IP communication network. The corporate number and telephone number of user B are inserted into the registration request.

[0063] In response, when the data space management device DSM receives the above registration request via the IP communication I / F unit 10, it sends a confirmation request for user B from the telephone communication I / F unit 9 to the central office device TEz of the telephone communication carrier to which user B subscribes, based on the corporate number and telephone number of user B contained in the above registration request.

[0064] The central office device TEz of the telephone carrier verifies whether the telephone number and corporate number of User B included in the confirmation request match the user information stored in the user database SDz, and then returns the confirmation result to the data space management device DSM.

[0065] When the data space management device DSM confirms that the telephone number and corporate number of user B match based on the above judgment result, it issues a connector number to the connector device CNb used by user B under the control of the user registration reception processing unit 61, and generates user information in which the connector number is added to the telephone number and corporate number.The generated user information of user B is then stored in the user information storage unit 81.

[0066] In this case, too, as shown in FIG. 11, information indicating the location of use may be stored in addition to the telephone number of user B, the corporate number, and the connector number of the connector device CNb.

[0067] Upon completing the user information registration process, the data space management device DSM sends a registration completion notification including the connector number of the connector device CNb and the corporate number of user B from the IP communication I / F unit 10 to the connector device CNb of user B, the request sender.

[0068] When the connector device CNb receives the registration completion notification, it stores in its own ID storage unit 311 the corporate number and connector number of user B included in the received registration completion notification.

[0069] In this case, too, when the data space management device DSM receives a request from the connector device CNb, it may call user B using the telephone number included in the request, and determine the validity of user B's telephone number, i.e., whether the telephone number is alive or dead, based on user B's response to the call.

[0070] (2) The process of registering the communication partner user to their own connector device Prior to data transmission, users A and B execute a process of registering user information of users who will be communication partners of data transmission in their own connector devices CNa and CNb.

[0071] FIG. 9 is a sequence diagram showing an example of a processing procedure for registering user information of communication partners between connector devices DNa and DNb of users A and B. In FIG.

[0072] For example, suppose that user A performs an operation on the user terminal UTa to request permission to communicate with user B in order to transmit data to user B. In this case, the connector device CNa, under the control of the communication partner registration control processing unit 12, generates a request requesting permission to communicate and transmits the generated request from the IP communication I / F unit 4 to the data space management device DSM. At this time, the corporate number of user B, who is the communication partner, as well as user A's own telephone number, corporate number, and connector number of the connector device CNa are inserted into the request.

[0073] In response, when the data space management device DSM receives the request via the IP communication I / F unit 10, under the control of the user-to-user registration relay processing unit 62, it identifies user B from the corporate number of the communication destination included in the received request, and transmits request information from the IP communication I / F unit 10 to the connector device CNb of the identified user B. The telephone number of the requesting user A, the corporate number, and the connector number of the connector device CNa are inserted into this request information.

[0074] Upon receiving the request information, the connector device CNb of user B, under the control of the communication partner registration control processing unit 12, presents the corporate number of requesting user A, which is included in the received request information, to the user terminal UTb. If user B responds by granting permission, the communication partner registration control processing unit 12 of the connector device CNb stores the telephone number, corporate number, and connector device of user A, which are included in the request information, in the communication partner ID storage unit 312. The communication partner registration control processing unit 12 then returns response information indicating the result of the communication permission or denial to the data space management device DSM. At this time, the response information includes user A's telephone number, corporate number, and connector number, as well as user B's telephone number, corporate number, and connector number of the connector device CNb, only if communication is permitted.

[0075] When the data space management device DSM receives the response information from the connector device CNb of user B, under the control of the user-to-user registration relay processing unit 62, it identifies the destination user A based on the telephone number, corporate number, and connector number of user A contained in the response information, and transmits the registration information of user B from the IP communication I / F unit 10 to the connector device CNa of the identified user A.

[0076] When the connector device CNa receives the above registration information, under the control of the communication partner registration control processing unit 12, it stores the telephone number, corporate number, and connector number of the connector device CNb of the destination user B contained in the received registration information in the destination ID memory unit 312.

[0077] (3) Authentication of communication partners during data transmission For example, when user A and user B attempt to transmit (share) data, first, authentication processing of the communication partners is executed between the connector device DNa of user A and the connector device DNb of user B.

[0078] FIG. 10 is a sequence diagram showing an example of the procedure of authentication processing executed between connector devices DNa and DNb and the procedure of subsequent data transmission processing.

[0079] When an operation to request data transmission to user B is performed on user A's terminal UTa, connector device DNa calls connector device DNb based on user B's telephone number under the control of telephone communication control unit 141. Then, when a telephone communication link is established with connector device DNb, telephone communication control unit 141 transmits a communication channel opening request (e.g., a data sharing request) to connector device DNb from telephone communication I / F unit 5 via the telephone communication link, for example, by using a short mail or a sound signal such as a DTMF signal.

[0080] The above-mentioned opening request includes the telephone number and corporate number of user A stored in the self ID memory unit 311, the other party ID memory unit 312, and the telephone number memory unit 321, respectively, the connector number of the connector device DNa used by user A, and the telephone number of the other party, user B.

[0081] In response to this, when the authentication control processing unit 14 of the connector device DNb of user B receives the opening request message sent from the connector device DNa of the calling user A via the telephone communication I / F unit 5, it first, under the control of the other party ID matching processing unit 142, matches the telephone number, corporate number, and connector number of user A contained in the received opening request request with the subscriber information of the communication partner stored in the other party ID memory unit 312, and determines whether the numbers match.

[0082] Next, under the control of the telephone number validity confirmation processing unit 143, the authentication control processing unit 14 transmits the telephone number and corporate number of the sender user A contained in the received activation request from the telephone communication I / F unit 5 to the central office device TEx of the telephone communications carrier to which user A subscribes. In response, the central office device TEx compares the telephone number and corporate number of user A with the user information managed in the user database SDx to confirm the validity of the corresponding telephone number. It then returns information indicating the confirmation result (whether or not there is a match) to the connector device DNb that originated the inquiry. Note that the process of confirming the validity of the sender's telephone number does not necessarily have to be performed.

[0083] When user A's identity is confirmed as a result of comparing user A's telephone number, corporate number, and connector number, the authentication control processing unit 14 of the connector device DNb first generates authentication information representing the password / encryption key / certificate and its expiration date for accessing the URL (Uniform Resource Locator) where user B's data is stored, and stores the generated authentication information in the other party ID memory unit 312 while linking it to user A.

[0084] Then, the authentication control processing unit 14 generates access information including the access URL and the authentication information for user B's telephone number, corporate number, and connector number, and sends the generated access information to the connector device CNa of the calling user A from the telephone communication I / F unit 5 using short mail or voice under the control of the telephone communication control unit 141.

[0085] Upon receiving the access information, the connector device DNa, under the control of the authentication control processing unit 14, checks whether each number of user B is correct by comparing the telephone number, corporate number, and connector number of user B contained in the received access information with the user information of the communication partner stored in the partner ID storage unit 312. If the authentication control processing unit 14 confirms the validity of the received telephone number, corporate number, and connector number of user B through the above check, it notifies the data transmission control processing unit 13 of the confirmation result.

[0086] (4) Data transmission processing When the authenticity of users A and B is confirmed by the above authentication process, data transmission processing is executed between the connector device DNa of user A and the connector device DNb of user B as follows.

[0087] That is, first, in response to an access operation by user A on user terminal TEa, the data transmission control processing unit 13 of the connector device DNa generates a data sharing request and transmits the generated data sharing request from the IP communication I / F unit 4 to the connector device DNb of user B. The data sharing request contains the access destination URL included in the access information sent from user B, the password / encryption key / certificate for accessing the URL, the type of data to be requested, etc.

[0088] In response to this, when the data sharing request is received by the IP communication I / F unit 4, the data transmission control processing unit 13 of the connector device DNb of user B compares the password / encryption key / certificate included in the received data sharing request with the authentication information corresponding to user A stored in the partner ID storage unit 312. If the comparison results in a match, the data to be shared that is stored in the URL specified by the data sharing request is read, and the read data to be shared is transmitted from the IP communication I / F unit 4 to the connector device DNa of user A.

[0089] (effect) As described above, in one embodiment, in a data distribution system in which data is transmitted between users A and B using a data space, connector devices DNa and DNb, located between the terminals UTa and UTb of users A and B and the data space management device DSM, store user information for each user A and B who intends to transmit data, including telephone numbers assigned to users A and B by their respective telephone carriers. Each connector device DNa and DNb also has a function for making and receiving calls using the telephone numbers. When transmitting data between users A and B, the connector devices DNa and DNb use the function to send and receive user information, including the telephone numbers of the other users B and A, and verify the received user information against the previously stored user information to authenticate the other users A and B.

[0090] In other words, the user information includes the telephone number that is securely managed by the telephone carrier for each user, and the above user information is sent and received via the telephone communication network using the call originating and receiving function for telephone communication between the connector devices DNa and DNb, thereby allowing each party to mutually authenticate the other user.

[0091] Therefore, even if the user ID or connector number is duplicated by someone, the authentication process is performed using the telephone number that is associated with the user and strictly managed by the telephone carrier, so user spoofing is prevented, thereby achieving highly reliable authentication.

[0092] [Other embodiments] (1) In one embodiment, when the connector device DNa requests the connector device DNb to open a communication channel, the request includes the telephone number and corporate number of the sender, user A, the connector number of the connector device DNa used by user A, and the telephone number of the destination user, user B. However, communication path information may be inserted in addition to these numbers.

[0093] The communication path information is information representing the communication path exchanged between the central office device TEx of the telephone carrier to which user A subscribes, the central office device TEy of the telephone carrier to which the data space management device DSM subscribes, and the central office device TEz of the telephone carrier to which user B, the communication partner, subscribes, and is configured, for example, as shown in Figure 12.

[0094] The connector device DNa of user A sends the communication path information it uses in addition to the communication channel opening request to the connector device DNb of user B. In this way, the connector device DNb that receives the communication channel opening request can confirm whether user A is communicating from a location declared in advance, based on the communication path information included in the communication channel opening request.

[0095] (2) The telephone numbers used in this invention are not limited to those used in fixed-line telephone services, but may also be those used in mobile telephone services or IP telephone services. In addition, although one embodiment has been described using an example in which the user and the data space operator use different telephone carriers, they may also use the same telephone carrier. Furthermore, various existing methods can be used for telephone number configuration and call origination / reception functions.

[0096] (3) In addition, the functional configurations of the connector device and data space management device, as well as the processing procedures and processing contents thereof, can be modified in various ways without departing from the spirit of the present invention.

[0097] Although the embodiments of the present invention have been described in detail above, the above description is merely an example of the present invention in every respect. It goes without saying that various improvements and modifications can be made without departing from the scope of the present invention. In other words, when implementing the present invention, specific configurations according to the embodiments may be appropriately adopted.

[0098] In short, this invention is not limited to the above-described embodiments, and in the implementation stage, the components can be modified and embodied without departing from the spirit of the invention. Furthermore, various inventions can be formed by appropriately combining multiple components disclosed in the above-described embodiments. For example, some components may be omitted from all the components shown in the embodiments. Furthermore, components from different embodiments may be appropriately combined. [Explanation of symbols]

[0099] DSM...Data Space Management Unit CNa, CNb, CNk...connector device UTa, UTb, UTk...user terminal TEx, TEy, TEz...telephone carrier station equipment SDx, SDy, SDz...user database 1,6...Control section 2,7...Program memory section 3,8...Data storage section 4,10...IP communication I / F section 5,9...Telephone communication I / F section 11...User registration control processing unit 12...Communication partner registration control processing unit 13...Data transmission control processing unit 14...Authentication control processing unit 141...Telephone communication control section 142...Partner ID matching processing unit 143...Telephone number validity confirmation processing unit 31…User management area 311…Self ID storage unit 312...Partner ID storage section 32…Telephone carrier management area 321...Telephone number storage section 61...User registration reception processing unit 62...User registration relay processing unit 81...User information storage unit 82...Telephone number storage section

Claims

1. A data distribution system that transmits data between a plurality of connector devices used by users via a data linkage platform, The connector device and the data linkage platform each have a telephone communication function for making and receiving calls using subscriber information assigned by a telephone carrier to which the connector device and the data linkage platform are subscribed, Each of the plurality of connector devices includes: a user information storage unit for storing user information including the subscriber information assigned to the connector device; a counterpart information storage unit for storing counterpart user information including the subscriber information assigned to the connector device that is the counterpart of the data transmission; Equipped with a first connector device that requests the data transmission; a processing unit that transmits communication request information including the user's own user information stored in the user information storage unit to a second connector device that is a counterpart of the data transmission using the telephone communication function; The second connector device a processing unit that, when receiving the communication request information, compares the user information of the first connector device included in the received communication request information with the user information of the other party stored in the other party information storage unit, and determines the validity of the received user information; a processing unit that, when it is determined that the received user information is valid, transmits communication response information including the user information of the second connector device stored in the self-information storage unit to the first connector device using the telephone communication function; Equipped with The first connector device a processing unit that, when receiving the communication response information, compares the user information of the second connector device included in the received communication response information with the user information of the second connector device stored in the partner information storage unit to determine the validity of the received user information of the second connector device. A data distribution system comprising:

2. Each of the plurality of connector devices includes: a processing unit that transmits a user registration request including its own user information including subscriber information of its own connector device to the data linkage platform, receives connector identification information assigned to its own connector device from the data linkage platform in response to the user registration request, and stores the received connector identification information in the own information storage unit in addition to its own user information. The data distribution system according to claim 1 , further comprising:

3. The first connector device a processing unit that transmits a communication permission request including the user information of the second connector device to the second connector device; The second connector device a processing unit that, when receiving the communication permission request, determines whether or not to permit communication based on user information of the first connector device included in the received communication permission request; a processing unit that stores the received user information of the first connector device in the other party information storage unit when communication is permitted; a processing unit that transmits a registration request including the user information of the second connector device stored in the self-information storage unit to the first connector device; Equipped with The first connector device When the registration request is received, the user information of the second connector device included in the received registration request is stored in the partner information storage unit. The data distribution system according to claim 1 .

4. The second connector device a processing unit that, when receiving the communication permission request, performs call processing using the telephone communication function based on the subscriber information included in the user information of the first connector device included in the received communication permission request, and confirms the validity of the subscriber information based on the result of the call response of the first connector device to the call processing. The data distribution system according to claim 3 , further comprising:

5. the user information includes the subscriber information, attribute information of the user, and connector identification information assigned to the connector device by the data linkage platform; The second connector device When the communication request information is received, the subscriber information, the user attribute information, and the connector identification information included in the user information of the first connector device included in the received communication request information are compared with the corresponding information included in the user information stored in the partner information storage unit, thereby determining the validity of the user information of the first connector device. The data distribution system according to claim 1 .

6. The first connector device transmitting the communication request information, which includes the user information and information representing a communication path from the first connector device to the second connector device, to the second connector device using the telephone communication function; The second connector device a processing unit that confirms the location of the first connector device based on information representing the communication path included in the received communication request information; The data distribution system according to claim 1 , further comprising:

7. The connector device is used in a data distribution system that transmits data via a data linkage platform between multiple connector devices each used by a user, a telephone communication control unit that performs telephone communication with other connector devices via telephone communication lines by making and receiving calls using subscriber information assigned by a subscriber's telephone communication carrier; a user information storage unit that stores user information including the subscriber information; a counterpart information storage unit for storing counterpart user information including the subscriber information assigned to the connector device that is the counterpart of the data transmission; a processing unit that transmits and receives user information including the subscriber information stored in the self-information storage unit to and from the connector device that is the other party in the data transmission via the telephone communication line established by the telephone communication control unit; a processing unit that compares the received user information with user information including the subscriber information stored in the other party information storage unit and determines the validity of the received user information; A connector device comprising:

8. A user authentication method executed by a data distribution system in which data is transmitted between a plurality of connector devices used by users via a data linkage infrastructure, and the connector devices and the data linkage infrastructure communicate with each other by making and receiving calls using subscriber information assigned by the telephone carriers to which the users subscribe, comprising: Each of the plurality of connector devices includes: storing the user information of the user including the subscriber information assigned to the connector device in the own information storage unit, and storing the user information of the other party including the subscriber information assigned to the connector device that is the other party of the data transmission in the other party information storage unit; a first connector device that requests the data transmission; transmitting communication request information including the user's own user information stored in the own information storage unit to a second connector device that is the other party of the data transmission by the telephone communication using the outgoing and incoming call; The second connector device When the communication request information is received, the user information of the first connector device included in the received communication request information is compared with the user information of the other party stored in the other party information storage unit to determine the validity of the user information of the received first connector device; The second connector device If the received user information of the first connector device is determined to be valid, communication response information including the user information of the second connector device stored in the self-information storage unit is transmitted to the first connector device using the telephone communication; The first connector device When the communication response information is received, the user information of the second connector device included in the received communication response information is compared with the user information of the second connector device stored in the partner information storage unit to determine the validity of the received user information of the second connector device. User authentication method.

Citation Information

Patent Citations

  • Server for dial-up connection

    JP2000349926A

  • Authentication system and authentication method of information terminal

    JP2005191830A

  • Authentication method, and network system

    JP2008028709A

  • Communication system, transmission side terminal equipment, and incoming side terminal equipment

    JP2008160212A

  • Information distribution control device, information distribution control method, program, and computer-readable storage medium

    WO2023224076A1