System, method, and program

An intermediary server issues tickets with extended expiration dates to manage authentication periods efficiently, reducing server load and enhancing security in game device authentication systems.

JP2025144695APending Publication Date: 2025-10-03NINTENDO CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024044500
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-21
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Existing authentication systems for game devices struggle with optimal expiration date management, leading to increased load on authentication servers and potential security vulnerabilities when devices reconnect after disconnection.

Method used

Implementing an intermediary server that issues tickets with extended expiration dates for services, allowing the authentication server to manage authentication periods more efficiently and reducing the need for frequent re-authentication.

Benefits of technology

This approach reduces server load and enhances security by allowing the authentication server to manage authentication periods more effectively, preventing frequent re-authentication requests and distributing the authentication process across multiple services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025144695000001_ABST
    Figure 2025144695000001_ABST
Patent Text Reader

Abstract

To solve the problem with a system for preforming authentication processing on the provision of a plurality of services that there is a possibility of control of an authentication server becoming complicated when an authentication server changes an expiration data for each service that a game device attempts to use.SOLUTION: A system includes a game device, an authentication server for performing first authentication processing for authenticating a game device in association with a first expiration date, a service provision server for providing a first service, and an intermediary server for performing second authentication processing. The game device is connected to the intermediary server when using the first service after being authenticated by the authentication server. The intermediary server transmits right information associated with a second expiration date to the game device when the authentication is made by the first authentication processing. The service provision server provides the first service when the second expiration data associated with the right information acquired from the game device is not expired. The game device requests the authentication server for authentication again according to the second expiration date.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a system, a method, and a program. [Background technology]

[0002] Patent Document 1 (JP 2014-102568 A) discloses a system having a server that provides specific services to game devices. The system in Patent Document 1 has an account server that authenticates whether a game device is properly registered. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2014-102568 Summary of the Invention [Problem to be solved by the invention]

[0004] In systems such as that of Patent Document 1, before a specific service is provided to a game device, an authentication server first performs an authentication process to authenticate whether the game device is a legitimately registered game device. If the authentication process is successful, the game device is connected to a service providing server that provides the specific service, and becomes able to use the specific service. An expiration date may be set for the authentication of the game device by this authentication server.

[0005] Even after the connection between the service providing server and the game device is once disconnected, the game device can directly connect to the service providing server and use a specific service without needing to be authenticated again as long as the authentication expiration date is not yet reached. After the expiration date has passed, the game device must be authenticated again by the authentication server. By setting an expiration date for authentication in this way, it is possible to reduce the load on the authentication server and ensure security.

[0006] Such an authentication server may not only authenticate game devices that use a specific service, but may also perform authentication processing for game devices that use various services other than the specific service, making it possible for a single authentication server to perform authentication for multiple services.

[0007] On the other hand, depending on the content of the service provided, the authentication expiration date set by the authentication server may not necessarily be optimal. In such a case, making the authentication server recognize the service that the game device is attempting to use and changing the expiration date for each service may lead to cumbersome control of the authentication server. [Means for solving the problem]

[0008] (Configuration 1) A system according to one embodiment includes at least one game device, an authentication server that executes a first authentication process to authenticate the game device by associating a first expiration date with the provision of a plurality of services, a service providing server that provides a first service of the plurality of services, and an intermediary server that executes a second authentication process with the game device. When the game device uses the first service after being authenticated by the authentication server, the intermediary server transmits rights information associated with the second expiration date to the game device if the connected game device has been authenticated by the first authentication process, and the service providing server provides the first service if the second expiration date associated with the rights information obtained from the game device has not expired, and the game device requests re-authentication from the authentication server in accordance with the second expiration date.

[0009] (Configuration 2) In configuration 1, the second expiration date is a date that comes after the first expiration date.

[0010] (Configuration 3) In configuration 1, the service providing server calculates a third expiration date based on the second expiration date, and adds the identification information of the game device to a queue for connection to the authentication server based on the expiration of the third expiration date.

[0011] (Configuration 4) In configuration 3, the second expiration date is a date that is later than the first expiration date.

[0012] (Configuration 5) In configuration 3, the third expiration date is a date that is later than the first expiration date.

[0013] (Configuration 6) In configuration 2 or 3, the first service is a service that maintains a session between the game device and the service providing server in order to transmit data from the service providing server to the game device.

[0014] (Configuration 7) In configuration 6, the game device is authenticated by the first authentication process, and is then provided with a second service different from the first service without being connected to the intermediary server.

[0015] (Configuration 8) A method according to one embodiment is a method executed by one or more processors and used in a system capable of providing a first service to at least one game device. The system includes an authentication server that executes a first authentication process to authenticate a game device by associating a first expiration date with the provision of multiple services, and a service providing server that provides a first service from the multiple services. The service providing server acquires rights information associated with a second expiration date from the game device, and if the second expiration date has not expired, provides the first service to the game device, and the game device requests re-authentication from the authentication server in accordance with the second expiration date. The method includes the steps of: determining whether the game device has been authenticated using the first authentication process associated with the first expiration date; executing a second authentication process to generate rights information if the game device has been authenticated using the first authentication process; and transmitting the generated rights information to the game device.

[0016] (Configuration 9) In configuration 8, the second expiration date is a date that is later than the first expiration date.

[0017] (Configuration 10) A program according to an embodiment is executed by one or more processors and is used in a system capable of providing a first service to at least one game device. The system includes an authentication server that executes a first authentication process to authenticate a game device by associating a first expiration date with the provision of multiple services, and a service providing server that provides a first service from the multiple services. The service providing server acquires rights information associated with a second expiration date from the game device, and if the second expiration date has not expired, provides the first service to the game device, and the game device requests re-authentication from the authentication server in accordance with the second expiration date. The program causes the one or more processors to execute the following steps: determine whether the game device has been authenticated using the first authentication process associated with the first expiration date; if the game device has been authenticated using the first authentication process, execute a second authentication process to generate rights information; and transmit the generated rights information to the game device.

[0018] (Configuration 11) In configuration 10, the second expiration date is a date that is later than the first expiration date.

[0019] (Configuration 12) A system according to one embodiment includes at least one game device, an authentication server that executes a first authentication process to authenticate the game device by associating a first expiration date with the provision of multiple services, and a service providing server that provides a first service among the multiple services. If the first expiration date has not expired, the service providing server provides the first service, calculates a third expiration date based on the first expiration date, and adds the game device to a queue to be connected to the authentication server based on the expiration of the third expiration date. [Effects of the Invention]

[0020] According to the present disclosure, in a system that performs authentication processing for the provision of multiple services, it is possible to realize a mechanism that enables authentication processing according to the service or the server that provides the service. [Brief explanation of the drawings]

[0021] [Figure 1] 1 is a schematic diagram showing an example of an information processing system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a schematic diagram showing an example of a hardware configuration of an authentication server included in the information processing system according to the present embodiment. [Figure 3] FIG. 2 is a schematic diagram showing an example of a hardware configuration of an intermediation server included in the information processing system according to the present embodiment. [Figure 4] FIG. 2 is a schematic diagram showing an example of a hardware configuration of a service providing server included in the information processing system according to the present embodiment. [Figure 5] FIG. 2 is a schematic diagram showing an example of a hardware configuration of a database server included in the information processing system according to the present embodiment. [Figure 6] FIG. 2 is a schematic diagram showing an example of a hardware configuration of a game device included in the information processing system according to the present embodiment. [Figure 7] 10 is a timing chart for explaining the flow of a process in which a constant connection service is provided by issuing a ticket. [Figure 8] FIG. 10 is a flowchart illustrating an authentication process performed by an authentication server. [Figure 9] FIG. 10 is a diagram showing an example of information included in a ticket issued as electronic data. [Figure 10] FIG. 10 is a flowchart illustrating a service provision start process performed by the service providing server. [Figure 11] 10 is a flowchart illustrating a push-out process executed by the service providing server. [Figure 12] FIG. 10 is a diagram for explaining an example of an order in which connections to an authentication server are made based on an expulsion deadline. DETAILED DESCRIPTION OF THE INVENTION

[0022] The present embodiment will be described in detail with reference to the drawings, in which the same or corresponding parts are designated by the same reference numerals and description thereof will not be repeated.

[0023] <Embodiment> [A. Overview] An example of the configuration of information processing system 100 according to the present embodiment will be described. Fig. 1 is a schematic diagram showing an example of information processing system 100 according to the present embodiment. Information processing system 100 is a system that provides various services to game devices 30A to 30C using servers such as a physical server group Pe1, a game server SP1, and an authentication server ND1.

[0024] 1, information processing system 100 includes game devices 30A-30C, a physical server group Pe1, a game server SP1, and an authentication server ND1. Game devices 30A-30C, the physical server group Pe1, the game server SP1, and the authentication server ND1 are configured to be connectable to one another via a network NW. Network NW is typically the Internet.

[0025] Each of the game devices 30A to 30C is typically a game-dedicated information processing device for providing games to users. By connecting to the network NW, the game devices 30A to 30C can play online competitive games with other users or download new game content from a game content distribution server (not shown). Hereinafter, each of the game devices 30A to 30C will be collectively referred to as "game device 30."

[0026] In this embodiment, the physical server group Pe1 is a server group that provides a constant connection service (persistent connection) to the game device 30. The constant connection service is a service that enables transmission of various information from the physical server group Pe1 to the game device 30 at any time by maintaining a connection between the physical server group Pe1 and the game device 30. In other words, the constant connection service is a service that maintains a session between the game device 30 and the service providing server FR1 in order to transmit data from the service providing server FR1 to the game device 30. A session refers to the state from the start to the end of communication between two elements in communication between information processing devices. While FIG. 1 illustrates only two game devices 30A, 30B, and 30C as the game devices 30, in reality, dozens, hundreds, or even more game devices 30 (not shown) are connected to the physical server group Pe1.

[0027] Examples of the various types of information transmitted from the physical server group Pe1 to the game device 30 by providing the always-on service may include, for example, information regarding system updates for the game device 30 itself, information regarding game content downloaded to the game device 30, and information exclusive to paid members. In the information processing system 100, various types of information can be transmitted from the physical server group Pe1 to the game device 30 at the timing when the physical server group Pe1 determines that the various types of information should be transmitted to the game device 30, without the user of the game device 30 actively operating the game device 30 to obtain the desired information.

[0028] For example, when the physical server group Pe1 has completed preparations for distributing a system update program for a game device 30, the physical server group Pe1 can transmit information about the system update for the game device 30 to all game devices 30 connected to the physical server group Pe1. This allows a user operating a game device 30 to automatically obtain the system update program from the physical server group Pe1 without having to operate the game device 30 to obtain the system update program. Note that the always-on service provided by the physical server group Pe1 may correspond to the "first service" in this disclosure.

[0029] In this embodiment, the physical server group Pe1 includes a service providing server FR1, a database server DB1, and an intermediary server TK1. The service providing server FR1 is a server that connects to the game device 30 and exchanges information with the game device 30. The service providing servers FR1 included in the physical server group Pe1 may be made up of five, ten, several tens, or more service providing servers.

[0030] The database server DB1 manages various information necessary to provide the always-on service to all game devices 30 connected to the physical server group Pe1. The database server DB1 stores user information. The user information is information for validating the game device 30 and may include, for example, the identification information of the game device 30, user account information associated with the game device 30, operation history information, and the like. The user account information may include, for example, the user's age, the region in which the game device 30 is used, and information for identifying other accounts registered as friends. The database server DB1 may also store session information indicating whether each of all game devices 30 to which the always-on service is provided from the physical server group Pe1 is connected to the service providing server FR1.

[0031] Before the service providing server FR1 and game device 30 connect to each other and start providing the constant connection service, the intermediary server TK1 authenticates the game device 30. That is, the intermediary server TK1 acts as an intermediary between the service providing server FR1 and game device 30A. A game device 30 connected to the physical server group Pe1 is first connected to the intermediary server TK1 out of the service providing server FR1, database server DB1, and intermediary server TK1 included in the physical server group Pe1.

[0032] The intermediary server TK1 issues a ticket associated with an expiration date for each game device 30. In this embodiment, the ticket is electronic data indicating that the game device 30 has the right to receive the constant connection service. The expiration date associated with the ticket is, for example, the point in time when four days have passed since the game device 30 was authenticated by the intermediary server TK1. In other words, the validity period of the ticket is four days.

[0033] The authentication process performed by the intermediary server TK1 may correspond to the "second authentication process" in this disclosure. The expiration date associated with the ticket may correspond to the "second expiration date" in this disclosure. Furthermore, the ticket, which is electronic data, corresponds to the "rights information" in this disclosure. Hereinafter, the expiration date associated with the ticket may be simply referred to as the "ticket expiration date."

[0034] The game server SP1 is a server that provides online game services to the game devices 30. For example, the game server SP1 is connected to game devices 30 to which specific game content has been downloaded via a network NW. The game server SP1 provides online competitive games to multiple game devices 30. Note that the game server SP1 is not limited to a server that provides online competitive games, and may be a server that provides various services.

[0035] More specifically, the game server SP1 in this embodiment acquires operation information indicating user operations from each game device 30 and progresses the game in accordance with the operation information. The game server SP1 transmits images according to the progress of the game to each game device 30. This allows the game server SP1 to provide an online game service to the game devices 30. The game device 30 can use the online game service by connecting only to the game server SP1 without connecting to the physical server group Pe1. The online game service provided by the game server SP1 may correspond to the "second service" in the present disclosure.

[0036] The authentication server ND1 is a server that authenticates whether or not the game device 30 is a legitimate game device 30. In the information processing system 100 of this embodiment, various services including the always-on service, online game service, etc. described above can be provided to the game device 30. The authentication server ND1 performs a process of authenticating the legitimacy of each game device 30 before the game device 30 can use the various services. This process of authenticating the legitimacy is performed based on, for example, whether the user has obtained the game device 30 through a legitimate procedure, whether an unauthorized program is being executed on the game device 30, etc.

[0037] Before using various services such as a constant connection service and an online game service, the game device 30 first connects to the authentication server ND1. When the game device 30 connects to the authentication server ND1, the game device 30 transmits user information to the authentication server ND1. As described above, the user information is information that indicates the legitimacy of the game device 30.

[0038] The authentication server ND1 determines the legitimacy of the game device 30 based on the user information received from the game device 30, and if no problem is found, authenticates the legitimacy of the game device 30. The game device 30 is able to receive the various services described above based on being authenticated by the authentication server ND1. If the game device 30 is unable to be authenticated by the authentication server ND1, it is unable to receive the various services.

[0039] In this embodiment, the authentication server ND1 associates an expiration date with each game device 30 and performs authentication. The expiration date of the authentication of the game device 30 by the authentication server ND1 is, for example, 24 hours from the time when the authenticity of the game device 30 is authenticated by the authentication server ND1. In other words, the period during which the authentication of the game device 30 by the authentication server ND1 is valid is 24 hours. The authentication process performed by the authentication server ND1 may correspond to the "first authentication process" in the present disclosure. The expiration date at which the validity of the authentication of the game device 30 by the authentication server ND1 expires may correspond to the "first expiration date" in the present disclosure.

[0040] In this embodiment, when the game device 30 requests to use any of the services other than the always-on service after the expiration date of the authentication of the game device 30 by the authentication server ND1 has expired, the game device 30 needs to be authenticated again by the authentication server ND1. This means that in the information processing system 100, the game device 30 needs to be periodically authenticated by the authentication server ND1, thereby improving security.

[0041] The authentication expiration date for the game device 30 may be different for each service. For example, a physical server group Pe1 that provides a constantly connected service is configured to be able to provide the service to the game device 30 for a longer period than the period during which the validity of the authentication by the authentication server ND1 is guaranteed. Therefore, if the validity of the authentication by the authentication server ND1 expires in a short period of time, the game device 30 may frequently connect to the authentication server ND1 to obtain re-authentication from the authentication server ND1 in order to receive the service provided by the physical server group Pe1. Such frequent connections may be undesirable. For this reason, it is conceivable that the authentication server ND1 may change the authentication expiration date for each service that the game device 30 intends to use. However, if the authentication server ND1 changes the authentication expiration date for each service that the game device 30 intends to use or for each server that provides the service, control of the authentication server ND1 may become complicated. Therefore, in this embodiment, a different authentication period is set for each service by issuing a ticket by the intermediary server TK1 (described later).

[0042] [B. Hardware configuration example] 2 to 6, examples of hardware configurations of authentication server ND1, intermediary server TK1, service providing server FR1, database server DB1, and game device 30 that constitute information processing system 100 according to the present embodiment will be described below.

[0043] 2 is a schematic diagram showing an example of a hardware configuration of authentication server ND1 included in information processing system 100 according to the present embodiment. Referring to FIG. 2, authentication server ND1 includes one or more processors 14, memory 15, storage 16, and communication unit 13. These components are connected to each other via bus 17 so as to be able to communicate data with each other. Note that authentication server ND1 may be an information processing device dedicated to authenticating game device 30, or may be realized using a general-purpose server.

[0044] The communication unit 13 communicates with the game device 30 via the network NW. The communication unit 13 has hardware necessary for wired communication and / or hardware necessary for wireless communication. Note that all or part of the processing of the communication unit 13 may be implemented by the processor 14.

[0045] The processor 14 is a processing entity (processing means) for executing the processes provided by the authentication server ND1. In this disclosure, the term "processor" refers to a processing circuit such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or a GPU (Graphics Processing Unit). The term "processor" encompasses a processing circuit that executes processing according to instruction codes written in a program, a processing circuit that integrates multiple functions such as an SoC (System on Chip), a hardwired circuit, and the like.

[0046] The memory 15 is a volatile storage device (storage medium) accessible by the processor 14, and may be, for example, a dynamic random access memory (DRAM) or a static random access memory (SRAM). The storage 16 is a non-volatile storage device (storage medium) accessible by the processor 14, and may be, for example, a hard disk or a flash memory. The storage 16 may be, for example, a storage medium such as an optical disk or a cartridge that is detachable from the authentication server ND1.

[0047] The storage 16 stores a system program 161 and an authentication program 162 to be executed by the processor 14. The processor 14 reads the system program 161 and the authentication program 162, deploys them in the memory 15, and executes them. The system program 161 is a program for operating the authentication server ND1, and includes, for example, an OS (Operating System) and firmware. Note that the memory 15 is not limited to a volatile storage device (auxiliary storage device), and may be a non-volatile storage device (main storage device). In this specification, the term "memory" encompasses at least volatile memory and non-volatile storage. The authentication program 162 is a program for authenticating the authenticity of the game device 30.

[0048] 3 is a schematic diagram showing an example of a hardware configuration of intermediate server TK1 included in information processing system 100 according to the present embodiment. Intermediate server TK1 has a communication unit 23, a processor 24, a memory 25, a storage 26, and a bus 27.

[0049] The components included in the relay server TK1 are connected to each other via a bus 27 so that they can communicate data with each other. A system program 261 in the storage 26 is a program for operating the relay server TK1, and includes, for example, an OS and firmware. In addition to the system program 261, a ticket issuance program 262 is stored in the storage 26. The ticket issuance program 262 is a program for issuing the above-mentioned ticket for each game device 30.

[0050] 4 is a schematic diagram showing an example of the hardware configuration of a service providing server FR1 included in information processing system 100 according to this embodiment. The service providing server FR1 has a communication unit 43, a processor 44, a memory 45, a storage 46, and a bus 47.

[0051] The components included in the service providing server FR1 are connected to each other via a bus 47 so as to be able to communicate data with each other. The system program 461 in the storage 46 is a program for operating the service providing server FR1, and includes, for example, an OS and firmware. In addition to the system program 461, the storage 46 also stores an eviction program 462. The eviction program 462 is a program that determines whether or not there is a game device 30 that should be evict from the physical server group Pe1 among the game devices 30 using the always-on service.

[0052] 5 is a schematic diagram showing an example of a hardware configuration of database server DB1 included in information processing system 100 according to the present embodiment. Database server DB1 has a communication unit 53, a processor 54, a memory 55, a storage 56, and a bus 57.

[0053] The components included in the database server DB1 are connected to each other via a bus 57 so as to be able to communicate data with each other. A system program 561 in the storage 56 is a program for operating the database server DB1, and includes, for example, an OS and firmware. In addition to the system program 561, the storage 56 also stores user information 562.

[0054] 6 is a schematic diagram showing an example of the hardware configuration of game device 30 included in information processing system 100 according to this embodiment. Game device 30 has a display 31, an operation unit 32, a communication unit 33, a processor 34, a memory 35, a storage 36, and a bus 37.

[0055] The display 31 displays an image generated as a result of information processing executed by the processor 34. The display 31 may be composed of multiple displays. The operation unit 32 accepts operations by the user operating the game device 30. The operation unit 32 includes, for example, push buttons, an operation lever, a touch panel, a mouse, a keyboard, etc.

[0056] The components included in the game device 30 are connected to each other so that data can be communicated via a bus 37. The system program 361 in the storage 36 is a program for operating the game device 30, and includes, for example, an OS and firmware.

[0057] In addition to a system program 361, storage 36 stores a game content program 362. Game content program 362 is a program for executing game content. The game content executed by game content program 362 may be downloaded, for example, from a game content distribution server (not shown). As described above, game device 30 is typically an information processing device dedicated to games, but game device 30 may be any general-purpose information processing device that is at least capable of executing games. In some aspects, game device 30 may be an information processing device such as a smartphone or tablet.

[0058] The system programs 161-561 and / or the authentication program 162, the ticket issuing program 262, the game content program 362, and the eviction program 462 contain instruction codes for realizing the processes described below. The "programs" that realize the processes according to this embodiment encompass the instruction codes contained in the system programs 161-561 and / or the instruction codes of the application programs contained in the authentication program 162, the ticket issuing program 262, the game content program 362, and the eviction program 462.

[0059] [C. Providing always-on service by issuing tickets] The following explains that in the information processing system 100 of this embodiment, if the expiration date of the authentication by the authentication server ND1 is changed for each service that the game device 30 intends to use, a ticket is issued by the intermediary server TK1 to prevent the control of the authentication server ND1 from becoming complicated.

[0060] Fig. 7 is a timing chart for explaining the process flow in which a constant connection service is provided by issuing a ticket. An example in which a constant connection service is provided to game device 30A will be explained below using Fig. 7. Fig. 7 shows the operations of game device 30A, authentication server ND1, relay server TK1, service provider server FR1, and database server DB1 in chronological order.

[0061] The game device 30A connects to the authentication server ND1 to receive the always-on service from the physical server group Pe1, and makes an authentication request (step S100). In step S100, the game device 30A transmits user information, such as the identification information of the game device 30A, user account information associated with the game device 30A, and operation history information of the game device 30A, to the authentication server ND1. The authentication server ND1 executes authentication processing based on the connection of the game device 30A (step S101).

[0062] Fig. 8 is a diagram showing a flowchart of authentication processing (step S101) by the authentication server ND1. The processing of the flowchart in Fig. 8 is realized by the processor 14 of the authentication server ND1 executing the authentication program 162.

[0063] The authentication server ND1 determines whether or not the authenticity of the game device 30A can be authenticated based on the information acquired from the game device 30A in step S100 (step S1011). If the authenticity of the game device 30A cannot be authenticated (NO in step S1011), the authentication server ND1 ends the process.

[0064] If the authenticity of the game device 30A can be authenticated (YES in step S1011), the authentication server ND1 generates an authentication token using the private key (step S1012). The authentication token is electronic data indicating that the authenticity has been authenticated by the authentication server ND1. The authentication server ND1 associates an expiration date with the authentication token and transmits the authentication token to the game device 30 (step S1013). Step S1013 in FIG. 8 corresponds to step S102 in FIG. 7. In this case, the associated expiration date is, for example, the time when a 24-hour period has elapsed since the time the authentication token was generated. Thereafter, the authentication server ND1 publishes a public key corresponding to the private key in step S1012 (step S1014). Note that the timing at which the public key is published is not limited to the timing of step S1014 shown in FIG. 8, and the public key may be published in advance, before the authentication process in step S101 is executed.

[0065] Returning to FIG. 7, game device 30A transmits the physical server group ID and password to relay server TK1 in addition to the authentication token received in step S102 (step S103). The physical server group ID and password are held by database server DB1 for managing each game device 30 in the physical server group Pe1. A game device 30 that has never connected to the physical server group Pe1 does not have a physical server group ID or password. When game device 30A connects to the physical server group Pe1 for the first time, physical server group Pe1 generates a physical server group ID and password unique to game device 30A, stores them in database server DB1, and transmits them to game device 30A.

[0066] If this is not the first time that game device 30 has connected to the physical server group Pe1, in step S103, game device 30 transmits the physical server group ID and password acquired at the time of the initial connection to relay server TK1. This allows physical server group Pe1 to identify and manage each game device 30 when providing a constant connection service to multiple game devices 30. The example in FIG. 7 shows an example in which game device 30A has not connected to the physical server group Pe1 for the first time, and game device 30A has a physical server group ID and a password.

[0067] The intermediary server TK1 performs a verification process on the authentication token received in step S103 (step S104). Specifically, the intermediary server TK1 uses the public key made public by the authentication server ND1 to determine whether the authentication token received in step S103 is valid (step S104). In the example of FIG. 7, the intermediary server TK1 verifies that the authentication token is valid. If the intermediary server TK1 cannot verify that the received authentication token is valid, the intermediary server TK1 does not provide the always-on service to the game device 30 that sent the authentication token.

[0068] Next, the intermediary server TK1 requests the database server DB1 for user information corresponding to the received physical server group ID and password (step S105). The database server DB1 stores the user information associated with the above-mentioned physical server group ID and password. The database server DB1 transmits the user information corresponding to the physical server group ID and password to the intermediary server TK1 (step S106).

[0069] The intermediary server TK1 performs a verification process on the received user information (step S107). Specifically, it checks whether the user information stored in the database server DB1 contains any problematic information. If there is no problem with the user information, the intermediary server TK1 executes a ticket issuing process (step S108). The intermediary server TK1 executes the ticket issuing program 262 to perform the process of step S108.

[0070] FIG. 9 is a diagram showing an example of information included in a ticket issued as electronic data. The ticket includes at least the identification information of the game device 30A to which the ticket is issued and an expiration date. In this embodiment, the expiration date associated with the ticket is four days after the intermediary server TK1 completes the user information verification process for the game device 30. The ticket shown in FIG. 9 is associated with an expiration date of 14:00:00 on March 14, 2024. That is, in the example ticket shown in FIG. 9, the intermediary server TK1 completed the user information verification process at 14:00 on March 10, 2024.

[0071] 7, the intermediary server TK1 transmits the ticket issued in step S108 to the game device 30A (step S109). To receive the constant connection service, the game device 30A transmits the ticket received in step S109 to the service providing server FR1 (step S110). Based on the receipt of the ticket, the service providing server FR1 executes a service provision start process (step S111).

[0072] 10 is a flowchart showing the service provision start process by the service providing server FR1. In step S110, the service providing server FR1 determines whether or not the ticket received is within its expiration date (step S1111). Specifically, the service providing server FR1 determines whether or not the execution start time of the process in step S1111 is before the expiration date associated with the ticket acquired from the game device 30A. If the execution start time of the process in step S1111 is after the expiration date, that is, if the ticket has already expired (NO in step S1111), the service providing server FR1 ends the process without providing the always-on connection service to the game device 30.

[0073] If the execution start time of the process of step S1111 is before the expiration date, i.e., if the ticket's expiration date has not yet expired (YES in step S1111), the service providing server FR1 starts providing the always-on service to the game device 30A that sent the ticket (step S1112). Thereafter, the service providing server FR1 sets an eviction deadline based on the expiration date associated with the ticket (step S1113). The eviction deadline is a deadline for requesting the game device 30, to which the always-on service is being provided, to be authenticated again by the authentication server ND1. In other words, the eviction deadline is a deadline by which the game device 30, to which the always-on service is being provided using the ticket, will be evict from the physical server group Pe1.

[0074] In this embodiment, the service providing server FR1 calculates the expiry deadline as a time point a predetermined time before the expiration date associated with the ticket. For example, if the expiry deadline is calculated as one hour before the ticket expiration date, in the example ticket shown in Fig. 9, the service providing server FR1 calculates the expiry deadline as 13:00:00 on Mar. 14, 2024.

[0075] Returning to FIG. 7, after executing step S111, the service providing server FR1 provides the game device 30A with a constant connection service. That is, the service providing server FR1 can transmit various information to the game device 30A at any time. Timing T11 is the expiration date of the authentication by the authentication server ND1. Since the ticket remains valid even after timing T11, the service providing server FR1 can provide the constant connection service to the game device 30A. On the other hand, if the game device 30A requests the provision of an online game service from a game server SP1 that does not issue a ticket after timing T11, the game device 30A must be authenticated again by the authentication server ND1.

[0076] In this embodiment, since the physical server group Pe1 has the intermediary server TK1 that issues tickets, the validity period of authentication for the always-on service can be extended. This allows the information processing system 100, which uses a single authentication server ND1 to perform authentication processing for the game device 30 with respect to the provision of multiple services, to perform authentication processing according to the service or the server that provides the service. Timing T12 is the expulsion deadline. The expulsion processing will be described below.

[0077] [D. Eviction Processing] The service providing server FR1 executes the process of step S112 at timing T12 based on the expiration of the expulsion time limit for the game device 30A. The process of step S112 is executed at 13:00:00 on Mar. 14, 2024.

[0078] When the expiry time limit for eviction of the game device 30A expires, the service providing server FR1 adds the game device 30A to the queue. The queue in step S112 is a waiting line stored in the service providing server FR1, and stores the identification information of the game device 30 to which the constant connection service is provided. Hereinafter, the service providing server FR1 adding the identification information of the game device 30 to the queue will simply be referred to as "the game device 30 being added to the queue."

[0079] The service providing server FR1 processes the game devices 30 stored in the queue in a FIFO (First In First Out) manner. Specifically, the service providing server FR1 transmits a command to the game device 30 that was stored first to connect to the authentication server ND1 first. When the service providing server FR1 has completed transmitting the command to connect to the authentication server ND1 to the game device 30, it removes the game device 30 from the queue.

[0080] When the oldest game device 30 stored in the queue becomes the game device 30A, the service providing server FR1 transmits a command to the game device 30A to connect to the authentication server ND1 (step S113). Upon receiving the command to connect to the authentication server ND1, the game device 30A is kicked out of the physical server group Pe1 and again requests authentication from the authentication server ND1 (step S114).

[0081] Fig. 11 is a flowchart of the eviction process executed by the service providing server FR1. The process of the flowchart in Fig. 11 is realized by the processor 44 of the service providing server FR1 executing the eviction program 462.

[0082] The service providing server FR1 executes the flowchart shown in Fig. 11 at predetermined intervals. For example, the service providing server FR1 periodically executes the processing of the flowchart in Fig. 11 every few seconds. The service providing server FR1 determines whether or not there is a game device 30 whose expulsion time limit has expired among the game devices 30 for which the constant connection service is being provided (step S201).

[0083] If there is a game device 30 whose expulsion time limit has expired (YES in step S201), the service providing server FR1 adds the game device 30 whose expulsion time limit has expired to the queue (step S202). In other words, the service providing server FR1 adds the identification information of the game device 30 to the queue. If there is no game device 30 whose expulsion time limit has expired (NO in step S201), the service providing server FR1 executes the process of step S203 without executing the process of step S202.

[0084] The service providing server FR1 determines whether or not a game device 30 is stored in the queue (step S203). In other words, the service providing server FR1 determines whether or not the identification information of any game device 30 among the game devices 30 currently providing the constant connection service is stored in the queue. If a game device 30 is stored in the queue (YES in step S203), the service providing server FR1 transmits a connection command to the authentication server ND1 to the game device 30 that was added to the queue earliest (step S204).

[0085] The service providing server FR1 removes from the queue the game device 30 that was added to the queue earliest (step S205). In other words, the service providing server FR1 deletes from the queue the identification information of the game device 30 that transmitted the connection command to the authentication server ND1 in step S204. If no game device 30 is stored in the queue (NO in step S203), the service providing server FR1 ends the process. The expulsion deadline may correspond to the "third expiration date" in the present disclosure.

[0086] Fig. 12 is a diagram for explaining an example of the order in which connections to the authentication server ND1 are made according to the expiry time limit. Fig. 12 shows the expiration times set for the game devices 30A to 30C. The horizontal axis of Fig. 12 is the time axis.

[0087] The game device 30A is authenticated by the authentication server ND1 at time T0. At this time, a 24-hour expiration date is associated with the authentication server ND1. The period from time T0 to time T4 is 24 hours. The game device 30A is connected to the intermediary server TK1, and a ticket is issued. In the example of FIG. 12, the game device 30A is authenticated by the intermediary server TK1 at time T1. The period from time T1 to time T7 is four days. Thereafter, the service providing server FR1 calculates the expulsion deadline for the game device 30A. The service providing server FR1 determines time T6 based on the time of time T7. The period between time T6 and time T7 is one hour.

[0088] The game devices 30B and 30C are authenticated by the authentication server ND1 at the same time. Each of the game devices 30B and 30C is authenticated by the authentication server ND1 at time T2. The period from time T2 to time T5 is 24 hours. Thereafter, each of the game devices 30B and 30C is connected to the intermediary server TK1, and a ticket is issued. In the example of FIG. 12, each of the game devices 30B and 30C is authenticated by the intermediary server TK1 at time T3. The period from time T3 to time T9 is four days. Thereafter, the service providing server FR1 calculates the expulsion deadlines for each of the game devices 30B and 30C. The service providing server FR1 determines time T8 based on the time point of time T9. The period between time T8 and time T9 is one hour.

[0089] Furthermore, by setting the expiration date of the ticket later than the expiration date of the authentication by the authentication server ND1, it is possible to prevent access from the game devices 30 from concentrating on the authentication server ND1 after the connection between the service providing server FR and the game devices 30 is restored after being disconnected due to a temporary failure of the network NW, for example. As a specific example, if the connection between the service providing server FR and the game devices 30 is disconnected between timing T4 and timing T5, causing a failure in the authentication server ND1, and if the failure is resolved after timing T5, the game devices 30A to 30C in this embodiment can reconnect to the service providing server FR without requesting re-authentication from the authentication server ND1. This makes it possible to prevent access from concentrating on the authentication server ND1.

[0090] Furthermore, game devices 30B and 30C whose expulsion deadlines expire at the same time are added to the queue. Since the queue is a single waiting line, game devices 30B and 30C are added in order. That is, a command to connect to authentication server ND1 is not sent to game devices 30B and 30C at the same time. This makes it possible for information processing system 100 to prevent multiple game devices 30 from concentrating on connecting to authentication server ND1 at the same time. Game devices 30B and 30C can use the constant connection service while added to the queue until the validity period of their tickets expires.

[0091] [E. Variations] Other embodiments that are partial modifications of the above-described embodiment will be described below. Each of the processors 14 to 54 may be configured on one chip or on multiple chips.

[0092] Each of the processors 14 to 54 and the associated processing circuitry may be configured as multiple computers interconnected by wire or wirelessly via a local area network, a wireless network, etc. The processors and the associated processing circuitry may also be configured as cloud computers that perform remote calculations based on input data and output the calculation results to other devices in remote locations.

[0093] In the above example, a constant connection service, an online game service, etc. have been described as examples of services that can be used by the game device 30 through authentication by the authentication server ND1. However, the services that can be used by the game device 30 through authentication by the authentication server ND1 are not limited to these, and may be, for example, a service that functions as a game shop that allows paid game content to be downloaded to the game device 30.

[0094] In FIG. 1, the authentication server ND1, service providing server FR1, database server DB1, intermediary server TK1, game server SP1, and game device 30 are depicted as a single device. However, these servers may be realized as a collection of multiple devices. For example, the service providing server FR1 may be configured to include multiple servers. Similarly, the game device 30 may be realized as a collection of multiple devices. The game device 30 may have separate components consisting of a main unit having at least a processor, a terminal unit having at least an operation unit, and a display unit having at least a display.

[0095] The service providing server FR1, database server DB1, and relay server TK1 may be mounted as different blades in a single chassis. The database server DB1 may also be included as a storage device within the service providing server FR1 or relay server TK1.

[0096] In the above description, the eviction deadline is calculated by the service providing server FR1. However, the eviction deadline may be calculated by the intermediary server TK1 when issuing the ticket, and may be associated with the ticket and transmitted to the game device 30A.

[0097] In the above example, the ticket expiration date is calculated by the intermediary server TK1 during the ticket issuing process. However, the intermediary server TK1 may include the expiration date of the authentication token in the ticket, and the service providing server FR1 may determine the extended expiration date based on the expiration date of the authentication token included in the ticket.

[0098] In the above example, the physical server group Pe1 is described as executing both the ticket issuing process and the expulsion process. However, the physical server group Pe1 may execute only one of the ticket issuing process and the expulsion process. For example, the physical server group Pe1 may determine the timing at which the game device 30 requests re-authentication from the authentication server ND1 based on the expiration date of the authentication of the authentication server ND1, while executing only the expulsion process using a queue.

[0099] In the above description, the expiration date associated with the ticket is, for example, four days after the game device 30 is authenticated by the intermediary server TK1. However, the expiration date associated with the ticket may be, for example, four days after the ticket is issued by the intermediary server TK1.

[0100] In the above example, the validity period of the authentication by the authentication server ND1 is 24 hours, and the validity period of the ticket is 4 days. In other words, the validity period of the ticket is later than the validity period of the authentication by the authentication server ND1. However, the validity period of the ticket may be earlier than the validity period of the authentication by the authentication server ND1.

[0101] In the above example, the user information verification process in step S108 is executed by the intermediary server TK1. However, the execution entity of the user information verification process in step S108 may be the database server DB1 or the service providing server FR1.

[0102] In the above example, it has been described that "user information" is transmitted from the game device 30 to the authentication server ND1, and that the "user information" is also stored in the database server DB1. This user information may be information for indicating the legitimacy of the game device 30, and the user information in the authentication server ND1 and the user information in the database server DB1 do not need to be the same information. For example, the user information in the authentication server ND1 may include information for determining the legitimacy of the user and the game device 30 more strictly than the user information in the database server DB1.

[0103] 11, the service providing server FR1 periodically executes the eviction process of steps S201 to S205. The service providing server FR1 may execute part of the process of steps S201 to S205 as a process different from the eviction process. Specifically, the service providing server FR1 may execute, in parallel, as separate processes, steps S201 and S202 for adding a game device 30 to the queue and steps S203 to S205 for removing the game device 30 from the queue.

[0104] In addition, "association" in this disclosure includes not only the direct association of "identification information of game device 30" and "ticket expiration date" within the same table, as shown in Figure 9, but also the indirect association of the two elements by referencing other tables or files.

[0105] In this disclosure, the term "server" encompasses both the meaning of computing resources (hardware) for executing the processing required by a server, and the meaning of a program for executing the processing required by a server or the state in which the program is being executed (software).

[0106] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]

[0107] 13-53 Communication unit, 14-54 Processor, 15-55 Memory, 16-56 Storage, 17-57 Bus, 30, 30A-30C Game device, 31 Display, 32 Operation unit, 100 Information processing system, 161-561 System program, 162 Authentication program, 262 Ticket issuing program, 362 Game content program, 462 Eviction program, 562 User information, DB1 Database server, FR1 Service providing server, Pe1 Physical server group, ND1 Authentication server, NW Network, SP1 Game server, T0-T9, T11, T12 Timing, TK1 Intermediary server.

Claims

1. at least one gaming device; an authentication server that executes a first authentication process for authenticating the game device by associating a first expiration date with the game device in relation to the provision of a plurality of services; a service providing server that provides a first service among the plurality of services; an intermediary server that executes a second authentication process for the game device; When the game device uses the first service after being authenticated by the authentication server, the game device connects to the intermediary server; the intermediary server, when the connected game device is authenticated by the first authentication process, transmits rights information associated with a second expiration date to the game device; the service providing server provides the first service if the second expiration date associated with the rights information acquired from the game device has not expired; The game device requests re-authentication from the authentication server in accordance with the second expiration date.

2. The system of claim 1 , wherein the second expiration date is later than the first expiration date.

3. the service providing server calculates a third expiration date based on the second expiration date; The system of claim 1 , further comprising adding the identification information of the gaming device to a queue for connection to the authentication server based on the expiration of the third expiration period.

4. The system of claim 3 , wherein the second expiration date is later than the first expiration date.

5. The system of claim 3 , wherein the third expiration date is later than the first expiration date.

6. 4. The system according to claim 2, wherein the first service is a service that maintains a session between the game device and the service providing server in order to transmit data from the service providing server to the game device.

7. The system according to claim 6, wherein the game device is not connected to the intermediary server and receives a second service different from the first service based on the fact that the game device has been authenticated by the first authentication process.

8. 1. A method executed by one or more processors for use in a system capable of providing a first service to at least one gaming device, comprising: The system comprises: an authentication server that executes a first authentication process for authenticating the game device by associating a first expiration date with the game device in relation to the provision of a plurality of services; a service providing server that provides the first service among the plurality of services, the service providing server acquires, from the game device, rights information associated with a second expiration date, and if the second expiration date has not expired, provides the first service to the game device; the game device requests authentication again from the authentication server in accordance with the second expiration date; The method comprises: a step of determining by the game device whether authentication has been performed by the first authentication process associated with the first expiration date; If the game device is authenticated by the first authentication process, executing a second authentication process to generate the right information; transmitting the generated rights information to the game device.

9. The method of claim 8 , wherein the second expiration date is later than the first expiration date.

10. A program executed by one or more processors and used for a system capable of providing a first service to at least one game device, comprising: The system comprises: an authentication server that executes a first authentication process for authenticating the game device by associating a first expiration date with the game device in relation to the provision of a plurality of services; a service providing server that provides the first service among the plurality of services, the service providing server acquires, from the game device, rights information associated with a second expiration date, and if the second expiration date has not expired, provides the first service to the game device; the game device requests authentication again from the authentication server in accordance with the second expiration date; The program causes the one or more processors to: a step of determining by the game device whether authentication has been performed by the first authentication process associated with the first expiration date; If the game device is authenticated by the first authentication process, executing a second authentication process to generate the right information; and a step of transmitting the generated rights information to the game device.

11. The program according to claim 10 , wherein the second expiration date is a date that is later than the first expiration date.

Citation Information

Patent Citations

  • Information processing system, information processing device, information processing program, and information processing method

    JP2014102568A