Gateway device, multi-factor authentication proxy method, and multi-factor authentication proxy system

The gateway device automates authentication processes for devices connecting to servers, addressing inefficiencies in manual methods by performing automated multi-factor authentication, thereby reducing workload and ensuring timely connections.

JP2025159658APending Publication Date: 2025-10-21HITACHI IND EQUIP SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024062412
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-08
Publication Date
2025-10-21

AI Technical Summary

Technical Problem

Existing authentication methods require manual intervention, which is inefficient and time-consuming for devices that need to connect to servers automatically, such as manufacturing devices and management devices at production sites.

Method used

A gateway device with a communication unit, storage device, and CPU that stores authentication information and automatically performs multi-factor authentication processes, including ID and password input, and selection of authentication methods, eliminating the need for manual handling.

Benefits of technology

Enables automated authentication, reducing the workload of personnel and ensuring real-time connection processing by handling both one-step and multi-factor authentications without human intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025159658000001_ABST
    Figure 2025159658000001_ABST
Patent Text Reader

Abstract

To realize automated authentication functions.SOLUTION: A gateway device enables communication between an interconnection device and a server on a network. The gateway device includes at least a communication unit, a storage device, and a CPU. The gateway device preliminarily stores, in the storage device, first information related to first authentication processing required to establish communication with the server, and also preliminarily stores, in the storage device, second authentication information that is different in type from the first authentication information and related to second authentication processing required to establish communication with the server, or includes an authentication information acquisition unit, which is provided either internally or externally to the gateway device, to acquire the information. In response to a request from the interconnection device to communicate with the server, the CPU automatically performs the first authentication processing related to the first authentication information and the second authentication processing related to the second authentication information.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a gateway device, a multi-factor authentication proxy method, and a multi-factor authentication proxy system. [Background technology]

[0002] In various systems, in order to ensure information security, authentication processing is widely performed each time a connection is made to a server, etc. Since the authentication processing requires a terminal with an authentication processing function, a terminal without the authentication function cannot perform this authentication processing, resulting in the problem of being unable to connect to the server, etc.

[0003] One example of a solution to this problem is the technology disclosed in Patent Document 1. Patent Document 1 provides a technology that addresses this authentication problem by requesting proxy authentication from a terminal with an authentication function. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] International Publication No. 2009-028606 Summary of the Invention [Problem to be solved by the invention]

[0005] The method disclosed in Patent Document 1 still requires manual authentication. However, there are now a wide variety of devices that require connection to a server. For example, there is a need to connect to a server from devices that do not require manual intervention, such as automated devices, manufacturing devices, and management devices at production sites.

[0006] The present invention has been made based on the above circumstances, and one of the problems to be solved is to realize automation of the authentication function. [Means for solving the problem]

[0007] A gateway device that enables communication between a connected device and a server on a network, the gateway device has at least a communication unit, a storage device, and a CPU; storing in advance in the storage device first information relating to first authentication processing necessary for establishing communication with the server; an authentication information acquisition unit that stores in advance in the storage device, or acquires from a built-in or external device, second authentication information that is different in type from the first authentication information and that is related to a second authentication process required to establish communication with the server; The CPU is a gateway device that automatically performs a first authentication process related to the first authentication information and a second authentication process related to the second authentication information in response to a communication request from the connected device to the server. [Effects of the Invention]

[0008] The present invention makes it possible to realize automation of the authentication function. Further configurations and effects of the present invention will become apparent throughout the entire specification below. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 2 is an explanatory diagram of the role of a gateway device. [Figure 2] FIG. 1 is a schematic explanatory diagram of a problem in conventional authentication processing. [Figure 3] FIG. 1 is an explanatory diagram of an embodiment of the present invention. [Figure 4] FIG. 2 is an explanatory diagram of a hardware configuration of a gateway device according to an embodiment of the present invention. [Figure 5] FIG. 1 is an explanatory diagram of an embodiment of the concept of authentication processing in the present invention. [Figure 6] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 7] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 8] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 9] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 10]FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 11] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 12] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 13] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 14] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 15] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 16] FIG. 10 is an explanatory diagram of another embodiment of the present invention. [Figure 17] 10 is an example of a screen display according to the present invention. [Figure 18] 10 is an example of a screen display according to the present invention. [Figure 19] FIG. 10 is a flowchart showing an example of how to respond when the notification period is exceeded or when authentication is not successful. DETAILED DESCRIPTION OF THE INVENTION [Example]

[0010] The role of the gateway device is explained in Figure 1.

[0011] The gateway device 10 has a function of connecting the connection device 20 with a server 31 and an authentication server 32 via a communication network 30. Here, the server 31 is the original connection target, and includes not only servers but also cloud processing systems. The authentication server 32 is a server for performing authentication processing. In the figure, 31 and 32 are shown as separate entities, but examples in which they are integrated are also included. Furthermore, the connection devices are not particularly limited, and include a wide range of devices such as PCs, business terminals, devices with communication functions at production sites, and management PCs.

[0012] 2 is a schematic diagram illustrating the problems with conventional authentication work, in which 100 is the target of authentication processing.

[0013] When a connection request is made from connection device 20 to server 31 via gateway device 10, an authentication request is sent to authentication server 32. If the authentication process fails, server 31 does not permit the connection between connection device 20 and server 31. For this reason, conventionally, an authentication request is sent to an individual authentication device such as a smartphone or dedicated terminal, which performs authentication processing to obtain connection permission from server 31 and establish a connection between connection device 20 and server 31. However, this work is manual, and the more connection requests and connection targets there are, the more work the person in charge of this manual work has to do. This not only increases the person's workload, but also poses the problem that connection takes time or cannot be secured depending on the person's schedule.

[0014] FIG. 3 is an explanatory diagram of an embodiment of the present invention, illustrating the basic concept of the gateway device 10 of the present invention.

[0015] The gateway device 10 of the present invention has a communication unit 11, an input unit 12, an authentication information database 13, and an authentication information acquisition unit 14. The input unit 12 is required to register in advance in the authentication information database 13 an ID, a password, etc. to be used for authentication. Therefore, it is desirable that the input unit 12 be a device that allows input of characters and numbers, such as a keyboard or a touch panel. However, the input unit 12 in Fig. 3 may be provided physically directly outside the gateway device 10 or indirectly via a network or communication line.

[0016] One of the features of the present invention is that by registering personal authentication information in advance in the authentication information database 13, the gateway device 10 can automatically perform authentication processing on behalf of the user.

[0017] The authentication information held in the authentication information database 13 is roughly divided into two types.

[0018] The first type is text information such as an ID and password. This information is usually required in the first stage of the authentication process.

[0019] The second type is unique information for multi-factor authentication. For example, this information may be information about a SIM card for receiving SMS, biometric information, etc. The type of unique information to be used depends on the unique information required by the connected server 31 or authentication server 32, and the corresponding information is stored in advance in the authentication information database 13.

[0020] The authentication information may be, for example, a hardware device using a SIM card for communication and a corresponding slot. Alternatively, biometric information such as a fingerprint, a finger vein pattern, or a retinal pattern may be acquired in advance by a corresponding device as the authentication information acquisition unit 14 and registered in advance in the authentication information database 13.

[0021] 4 is a diagram illustrating an example of the hardware configuration of the gateway device 10 of the present invention. It has an input device 62 corresponding to the input unit 12 of FIG. 3, and a communication device 63 corresponding to the communication unit 11 of FIG. 3. The authentication information database 13 is stored in a storage device 61. The storage device 61 may be a rewritable memory, a HDD drive, or any other type of device. The CPU 60 takes the lead in realizing each function and executing various processes. The authentication process performed by proxy in the present invention is also performed by the CPU 60. 45 is a connection bus.

[0022] 3 may be provided as dedicated hardware in the gateway device 10. Alternatively, it may exist outside the gateway device 10. Some examples will be described later.

[0023] 5 is an explanatory diagram of an embodiment of the concept of authentication processing in the present invention. A detailed description will be given below in order according to the diagram.

[0024] (1) Information transmission 100 from the connection device 20 to the gateway device 10 is performed.

[0025] This information transmission can be various information, such as file transmission, business information transmission, data transmission, message transmission, and the like.

[0026] (2) Transmission of a connection request 300 from the gateway device 10 to the server 31.

[0027] (3) Transmission of the authentication and authorization request 301 from the server 31 to the authentication server 32.

[0028] (4) Transmission of a first-stage authentication request from the authentication server 32 to the gateway device 10.

[0029] This corresponds to the case where the person in charge manually handles the call as shown in Figure 2, where an ID and password input screen is displayed on a smartphone or the like, and the person in charge inputs and transmits the ID and password. On the other hand, in the present invention, the process is as follows.

[0030] (5) Implementation of ID and password automatic reading 101.

[0031] In the present invention, responses to requests to input an ID and password are automatically processed by the gateway device 10. That is, the CPU 60 automatically analyzes the ID and password request information or its display screen information, and automatically inputs the ID and password registered in advance in the authentication information database 13 in a predetermined format or at a predetermined screen position.

[0032] (6) Send ID and password 202. The ID and password in (5) are automatically transmitted by the gateway device 10 to the authentication server 32 without human intervention. At this time, for example, when authentication is performed by inputting an ID and password in a predetermined position on a predetermined screen, the CPU 60 automatically analyzes the position of a send button or the like on the screen along with the information input, and transmits information corresponding to clicking that button.

[0033] (7) The authentication server 32 performs the authentication process 1. The authentication server 32 performs ID and password authentication in authentication process 402. When the first stage of authentication process is cleared, the process proceeds to the next stage.

[0034] (8) Transmission of a request to select an authentication method related to the second-stage authentication as multi-factor authentication from the authentication server 32 to the gateway device 10. This step is omitted when a second-stage authentication method as multi-factor authentication has been designated or registered in advance in the authentication server 32. For example, the selection request is made in a format in which multiple authentication methods are displayed on the screen.

[0035] (9) Automatic selection of authentication method in the gateway device 10.

[0036] The CPU 60 automatically selects a compatible option from the authentication method options displayed on the screen. In this case, compatible means that the option matches the type of information pre-registered in the authentication information database 13. When using SMS authentication, the option is selected when SIM information has been pre-registered in the authentication information database 13 or when a SIM card is inserted in the authentication information acquisition unit 14. For simplicity of explanation, the following description will be given using the example of SMS authentication.

[0037] The gateway device 10 automatically selects SMS authentication as the method automatic selection 102. The CPU 60 automatically performs the process of clicking a position on the display screen corresponding to SMS authentication and clicking the send button. Note that such appropriate selection and clicking at a position on the display screen can be achieved using technology that is already widely used in robot AI for routine business processing.

[0038] (10) Communication of selection results. Selection information that SMS authentication is selected as the method (SMS) transmission 204 is transmitted from the gateway device 10 to the authentication server 32 .

[0039] (11) Sending authentication SMS. The authentication server 32 transmits an authentication password input screen to the gateway device 10 as the selected authentication method, SMS authentication. At the same time, the authentication server 32 transmits a one-time password to the SMS associated with the corresponding SIM. In FIG. 5, this is collectively shown as authentication SMS transmission 205.

[0040] (12) Implementation of automatic SMS interpretation. The gateway device 10 recognizes the one-time password input screen sent from the authentication server 32. In parallel, it automatically analyzes the description on the SMS screen of the one-time password sent in the SMS linked to the SIM, and extracts the character string or number sequence of the one-time password. Then, it automatically inputs the one-time password into the one-time password input screen. These processes are automatically performed by the CPU 60. This series of operations is performed as SMS automatic interpretation 103.

[0041] (13) One-time password input reply. The gateway device 10 sends a one-time password input reply 206 to the authentication server 32 .

[0042] (14) Authentication process 2 is performed by the authentication server 32. As authentication process 2 at 402, the authentication server 32 determines whether the one-time password returned from the gateway device 10 is valid, and determines whether the authentication process of the two-step authentication is successful.

[0043] Although the above is an example of two-step authentication, examples of multi-step authentication are not limited to two steps.

[0044] (15) Issuance of certification and approval notices. If the authentication is successful, the authentication server 32 sends an authentication and authorization notification 302 to the server 31 and also sends an authentication and authorization notification 207 to the gateway device 10 .

[0045] The operations of the authentication server 32 in the above steps (4) to (15) are operations that a normal authentication server 32 performs, and do not require any special changes or measures on the part of the authentication server 32. On the contrary, the effect and advantage of the present invention lies in the fact that the gateway device 10 can automatically support multi-stage authentication for a normal authentication server 32.

[0046] (16) Connection and information transmission. After the multi-step authentication is completed, the gateway device 10 can be interconnected with the server 31 and exchange information. As mentioned in (1), this information transmission can be of various types. Examples include the transmission of files, business information, data, and messages.

[0047] As described above in detail, the gateway device 10 according to the present invention realizes automatic authentication processing. Furthermore, it is possible to automatically handle not only one-step authentication but also multi-factor authentication or multi-step authentication. This makes it possible, in principle, to eliminate the need for a person to handle authentication, thereby reducing the workload of the person in charge and realizing real-time connection processing.

[0048] Furthermore, a proxy method for multi-factor authentication and a proxy system for multi-factor authentication based on the above configuration or the above technical idea are also within the scope of the disclosure of the present invention and are claimed as inventions. [Example]

[0049] This embodiment is basically the same in configuration and effect as embodiment 1. Fig. 6 is a diagram corresponding to Fig. 3 in embodiment 1. The difference is that the authentication information acquisition unit 14 is integrated with the gateway device 10 in Fig. 3, whereas it is located outside the gateway device 10 in Fig. 6. Of course, it is essential that the gateway device 10 and the authentication information acquisition unit 14 can exchange information directly or indirectly.

[0050] In Figure 5, we have mainly used SMS authentication as the second-step authentication method. However, it is also possible to use a biometric authentication method, which is considered to be as highly secure as SMS authentication, as the second-step authentication method.

[0051] In such a case, biometric authentication information such as a fingerprint, a finger vein pattern, a retinal pattern, etc. is acquired in advance by the authentication information acquisition unit 14 in Fig. 6 and stored in advance in the authentication information database 13. In this case, it is desirable that the gateway device 10 be installed in a remote location so that the person in charge can acquire the biometric authentication information at a more convenient location without having to go to the gateway device 10.

[0052] FIG. 6 is a diagram corresponding to such a situation, in which the authentication information acquisition unit 14 is installed outside the gateway device 10.

[0053] In this embodiment, the same effects as those of the first embodiment are achieved, and the second authentication information can be easily obtained. [Example]

[0054] This embodiment is basically the same in configuration and effect as embodiment 2. Fig. 7 is a diagram corresponding to Fig. 6 in embodiment 2. The difference is that the authentication information acquisition unit 14 exists outside the gateway device 10, but via the communication network 30.

[0055] In this embodiment, the authentication information acquisition unit 14 can be installed in a more convenient location such as an office or a management office, and the authentication information acquisition unit 14 can be shared by a large number of gateway devices 10.

[0056] In this embodiment, the same effects as those of the second embodiment are achieved, and the number of authentication information acquisition units 14 is reduced, thereby reducing system costs and improving convenience. [Example]

[0057] This embodiment is basically the same in configuration and effect as embodiment 1. Fig. 8 is a diagram corresponding to Fig. 3 in embodiment 1. The difference is that a distribution server 33 and a mobile terminal 34 are directly or indirectly connected to a gateway device 10 via a communication network 30.

[0058] The distribution server 33 has a role of performing a communication management function. Depending on the system configuration, it is conceivable that communication between the server 31 and the gateway device 10, or communication between the authentication server 32 and the gateway device 10, can be performed more smoothly if it is performed via the distribution server 33 having a communication management function, rather than directly between them. In such cases, it is desirable to have the distribution server 33. In particular, when there are multiple servers 31 or multiple cloud-based systems corresponding to the servers 31, it becomes difficult for the gateway device 10 to determine which server is the other party. In such cases, providing the distribution server 33 reduces the load on the gateway device 10 and prevents malfunctions.

[0059] The mobile terminal 34 is expected to be used in various roles. For example, it may be used as an operation terminal through which a person in charge issues instructions to the connected device 20, or it may function in place of the authentication information acquisition unit 14.

[0060] The configuration of FIG. 8 also allows for other uses.

[0061] That is, one example of such a use is to acquire authentication information on a separate terminal that is not directly connected to the gateway device 10, for example, a mobile terminal 34, and send it to the distribution server 33 or the authentication server 32, and then distribute the authentication information from the distribution server 33 or the authentication server 32 to the gateway device 10.

[0062] The concept of specifying a deadline for authentication information will be explained in the next embodiment 4, and the mobile terminal 34 in FIG. 8 can also be used as the terminal that specifies the deadline. [Example]

[0063] 9 is a diagram corresponding to FIG. 3 of the first embodiment. The difference from FIG. 3 is that the gateway device 10 includes a designated period management unit 15 and a designated period information database 16.

[0064] The designated period means specifying the period during which the gateway device 10 performs automatic authentication processing. The purpose of setting a designated period is for security purposes. If automatic response were permitted indefinitely and indefinitely, there would be a risk of unauthorized access occurring over a long period of time if external intrusions were permitted through security holes that are not noticed by personnel or administrators. Therefore, by limiting the period for automatic response, it is possible to achieve both improved security measures and improved convenience and real-time performance by eliminating the need for manual operation by personnel.

[0065] The period during which automatic response is permitted or during which the gateway device 10 is made to perform automatic response can be set variously depending on the installation environment, actual situation, etc. of the connection device 20 and the gateway device 10.

[0066] For example, the idea is to allow automatic responses only when a person in charge is present, and not allow automatic responses when the person in charge is absent. This makes it possible to eliminate the risk of unexpected processing or unauthorized access while the person in charge is absent, for example, after leaving work.

[0067] Furthermore, if signs of unauthorized access are detected or there is a risk of unauthorized access, the specified period can be exceeded, meaning the process can be returned to human authentication by the person in charge, making it possible to shift to a more secure and vigilant approach to operations.

[0068] The designated period can be input to the designated period information database 16, for example, from the input unit 12 or the input device 62 in Fig. 4. The input designated period is stored in the storage device 61 in Fig. 4.

[0069] When the gateway device 10 receives a connection request from the connection device 20 to the server 31, the designated period management unit 15 determines whether the gateway device 10 is within a period permitted for automatic authentication processing. This is done by the CPU 60 in Fig. 4 comparing the current time from the built-in timer or time information with the designated period stored in the designated period information database 16 to determine whether the time is within the designated period.

[0070] If it is within the specified period, automatic authentication processing will be performed.

[0071] If the specified period is not reached, automatic authentication processing is not performed. In this case, for example, a log may be recorded stating that connection to connection device 20 could not be established, or the person in charge may be notified by email or a dedicated app that a server connection request was received from connection device 20 but the connection was rejected because it was outside the specified period.

[0072] 19 is a flowchart showing an example of how to handle cases outside the designated period or when authentication is unsuccessful. An example of how to handle cases outside the designated period will be described using this diagram.

[0073] First, the gateway device 10 receives a connection request from the connection device 20 to the server 31. This is connection request 500 from the connection device. The gateway device 10 compares the designated period information in the designated period information database of FIG. 9 with the current time in the designated period management unit 15 in the CPU 30 of FIG. 4. This is processing 501 to determine whether or not the time is within the designated period. If it is determined that the time is outside the designated period, the CPU 30 determines whether or not the setting is set to contact the person in charge. This is contact setting necessity determination 505.

[0074] If the contact requirement setting is not set in 505, the person in charge is not contacted, and the connection failure notification is sent to the connected device in 507. The reason for this is that if the specified period does not occur, the automatic authentication process from 501 onwards will not be started, so no security issues will arise. Furthermore, the person in charge can respond to the connection request event from the connected device by, for example, checking the log notified to the connected device in 507 after arriving at work in the morning and responding to the connected device.

[0075] If the authentication is within the specified period in 501, first authentication processing 502 and second authentication processing 503 are performed. If OK in 502, the process proceeds to 503, and if OK in 503, the process proceeds to 504, and communication between the connected device and the server is automatically started in 504, as the multi-factor authentication has been cleared.

[0076] If authentication fails in either 502 or 503, the process transitions to the flow on the right side of FIG. 19, and a notification is sent to the person in charge at 506. This situation indicates that some kind of error or trouble has occurred in the automatic authentication system. Therefore, the person in charge must check the status of the gateway device 10, identify the problem occurring during automatic authentication, and take action. Examples of possible causes include normal communication trouble, automatic authentication trouble, mismatch of mutual information with the authentication server 32, and failure of automatic analysis of the input screen due to a change in the layout of the authentication screen. All of these are handled by the person in charge. Since resolving the problem may require a request to the company's information management department or the supplier of the gateway device 10, the notification function to the person in charge here is extremely important.

[0077] Furthermore, if authentication is not successful in either 502 or 503, a notification is sent to the person in charge in 506, and a notification of connection failure is also sent to the connection device in 507. This allows the connection device 20 to store, as a log, any cases in which a connection with the server 31 is not established.

[0078] As described above in detail, this embodiment can achieve an improved security level in addition to the effects of embodiment 1. Furthermore, by appropriately setting the notification function for the person in charge, when a problem occurs with the automatic authentication function, the person in charge can quickly grasp the problem and start to deal with it. [Example]

[0079] Fig. 10 is a diagram corresponding to Fig. 9 of the fifth embodiment. In this embodiment, the authentication information acquisition unit 14, which is located inside the gateway device 10 in Fig. 9, is arranged outside the gateway device 10.

[0080] In this embodiment, the effects described in the fifth embodiment and the effects described in the second embodiment can be achieved together. [Example]

[0081] FIG. 11 is an example of a configuration that roughly combines the configuration of the sixth embodiment shown in FIG. 10 and the configuration of the third embodiment shown in FIG.

[0082] In this embodiment, the effects described in the fifth embodiment and the effects described in the third embodiment can be achieved together. [Example]

[0083] Fig. 12 is basically the same as Fig. 9 of the fifth embodiment. The difference is that instead of only one connection device 20 being connected to the gateway device 10, multiple connection devices 20 are connected via a HUB 40.

[0084] The gateway device 10 can individually recognize the connected device 20 by various methods, such as a physical recognition method based on the connection position of the HUB 40, a method based on a digital certificate, or a method based on an IP address or MAC address.

[0085] 12 shows an example of a wired LAN in which the HUB 40 is individually connected to each of the connection devices 20. Another corresponding example will be described next.

[0086] 13 shows an example of a series connection with a single wire, using a serial connection or a transition connection between connected devices 20. When connecting in series with a single wire like this, it is desirable to use a series connection management device such as a communication control controller 41, either in combination with a HUB 40 or alone, from the perspective of simplifying the system configuration.

[0087] 14 shows an example in which multiple connection devices 20 are connected to a gateway device 10 via a wireless hub 42. Even at factories and other work sites, wireless communication functions are increasingly being implemented in connection devices 20 due to the ease of device installation. In such cases, wireless connections may be used via a wireless hub or the like. Of course, wireless and wired connections may be mixed. In FIG. 14, solid lines represent wired connections and dotted lines represent wireless connections when connecting the wireless hub 42 and each connection device 20.

[0088] In addition to the effects of the fourth embodiment, this embodiment realizes an increase in the number of connected devices 20. Therefore, this embodiment is particularly suitable for applications where there are a large number of connected devices, particularly in factories and production sites.

[0089] The idea of ​​increasing the number of connected devices 20 disclosed in this embodiment and others can be used not only in this embodiment but also in combination with each embodiment disclosed in this specification. [Example]

[0090] Fig. 15 is basically the same as Fig. 9 of the fifth embodiment. The difference is that the designated period setting system 35 is connected to the gateway device 10 via the communication network 30 in Fig. 15.

[0091] There are various ways to set a designated period depending on the purpose. Therefore, the designated period setting system 35 is described as a concept that encompasses various implementation means that can input or acquire information about the designated period. For example, a designated period can be set individually by a person in charge using a mobile terminal such as a smartphone, or the designated period can be automatically updated in real time in combination with an access control system to enable automatic response only when a person in charge is present, or the designated period can be set in advance to match the operating hours of a factory or office. Other advance scheduling methods may also be used.

[0092] 16 shows an example of a designated period setting system 35 that uses an attendance system 36. By linking the attendance information of the attendance system 36 with the designated period of the gateway device 10 appropriately or in real time, it becomes possible to operate the gateway device 10 so that it automatically responds only when the person in charge is at work.

[0093] In either method, the designated period is not completely fixed in advance in the gateway device 10, but is made flexibly changeable, thereby making it possible to set a designated period for automatic response that suits the actual situation, thereby achieving both flexibility in actual operation and deduction for security response.

[0094] This embodiment can be applied in combination with any of the first to seventh embodiments, and the combined effects of each embodiment can be achieved. [Example]

[0095] In the ninth embodiment, a method for setting a designated period according to the actual situation of another device or user, different from the connection device 20, has been described with regard to the automatic authentication or authentication proxy function by the gateway device 10.

[0096] However, the present invention also allows for operation in which connection device 20 sets a designated period, or the automatic authentication or authentication proxy function is enabled when the connection device 20's status or request content is used as a trigger.

[0097] One possible example is an emergency situation in an unmanned factory that operates 24 hours a day, where if the connected device 20 does not access the server 31 urgently and take action even at night when no one is present, it could lead to an accident, serious trouble, or production line shutdown.

[0098] Even in such a case, if the gateway device 10 stubbornly follows the preset designated time and rejects a connection request from the connection device 20 to the server 31 as being outside the designated time, information security may be ensured, but in some cases, it may be expected that this may have a negative impact on economic safety and physical security.

[0099] Therefore, from the viewpoint of making actual operation more flexible, it is desirable to preset the designated period information database 16 of the gateway device 10 with statuses, cases, contact code numbers from the connected device 20, etc. that allow automatic authentication in response to a request from the connected device 20, or authentication proxy function, and to set the designated period management unit 15 by the CPU 60 so that it can start automatic authentication in response to a request from the connected device 20, or authentication proxy function. [Example]

[0100] This embodiment is basically the same as embodiment 10. The difference is that the designated period management unit 15 is provided with an AI judgment function, the AI ​​is given a certain degree of judgment authority, and the designated period management unit 15 makes a judgment when a connection request is received from the connection device 20.

[0101] With the recent rapid advancement of AI technology, the judgment ability and reliability of AI are reaching a level comparable to that of a person in charge. Therefore, it is possible to more proactively provide an AI judgment function to the designated period management unit 15, giving the AI ​​a certain degree of judgment authority and having it make judgments when a connection request comes from the connection device 20. This allows for a response with the same level of flexibility as a person in charge can make a judgment.

[0102] Furthermore, one way to improve the reliability and appropriateness of such decisions is to have an external AI make the decisions in some cases, rather than relying on the AI ​​built into the gateway device 10. This is because the accuracy and capabilities of AI also depend on the capabilities of the server running the AI, the size of the database, and the size of the training examples.

[0103] Therefore, it is more desirable for the gateway device 10 to communicate information and status to an AI decision engine installed in an external server or cloud via the communication network 30, and have the AI ​​decision engine decide whether to perform automatic authentication or the authentication proxy function by the gateway device 10. Even in this case, the content exchanged at this stage is not the actual communication content from the connection device 20, but is limited to information related to the limited decision on whether to approve automatic authentication or the authentication proxy function, thereby avoiding information security problems. [Example]

[0104] FIG. 17 illustrates an example of an input screen for a designated period in relation to each of the above embodiments.

[0105] Reference numeral 50 denotes a display device and 51 a display face. First authentication information is input from the input means, and ID information as 52 and password information as 53 are displayed on the display screen 51 for confirmation. Reference numeral 54 denotes a specified period. There are various setting methods, such as date, time, date and time.

[0106] After inputting the information, the designated period is set in the gateway device 10 by selecting the setting button 55. Also, by selecting the automatic link button 56, the designated period may be automatically set using information from the attendance system of Fig. 16 or another system. Note that when allowing a decision by AI as explained in the tenth embodiment, a button called "AI decision" may be provided.

[0107] Fig. 18 is an example of a management screen for checking the information currently set in the gateway device 10. A management screen 57 is displayed on the display screen 51. Fig. 19 displays the ID, password, specified period, information on the connecting device as the connection source, and information on the server as the connection destination.

[0108] As described above, one of the features of the gateway device 10 of the present invention is that it is possible to display on the screen at least the designated period relating to the automatic authentication or the authentication proxy function.

[0109] The above information may also be stored on the connected device 20 side.

[0110] The display screen 50 also includes a display screen on a monitor device provided in the connected device 20, and a display screen displayed on the screen of an operation terminal or mobile terminal via the communication network 30.

[0111] The technical concept of the present invention has been described above in detail. The present invention is not limited to the above-described embodiments. Of course, the scope of the present invention also includes the application of a combination of the technical concepts of the respective embodiments. Furthermore, as long as the technical concept described above is included, modified examples and related examples are also included in the scope of the disclosure of the present invention.

[0112] Furthermore, even if the connected device 20 itself is capable of performing authentication, such as a PC or manufacturing device with a built-in general-purpose OS or standard browser, it is conceivable that updates may not have been performed properly. Even in such cases, a certain level of security can be ensured by using the gateway device of the present invention. Furthermore, it is possible to support the latest authentication methods.

[0113] Furthermore, the present invention can also be applied to connected devices 20, such as factory and industrial equipment and industrial PCs. Unlike consumer products that are replaced every few years, these devices are often used for 10 years or more, making it difficult to support the latest authentication methods. By using the gateway device of the present invention or a multi-factor authentication proxy method or system, industrial-related products and systems with long usage periods can always be connected to the latest server systems, eliminating limitations on the usable life of the entire system. This avoids the disposal or replacement of still-usable industrial equipment simply because the OS has expired, contributing to reducing unnecessary waste, production costs, and environmental impact throughout the entire production system.

[0114] The above-described embodiments have been described mainly from the perspective of the gateway device 10. However, the scope of the present invention also includes a multi-factor authentication proxy method and a multi-factor authentication proxy system that apply the above-described technical concepts.

[0115] Based on the technical idea of ​​the present invention described above in detail, an example of the concept of the present invention can be expressed as follows.

[0116] <Part 1> A gateway device that enables communication between a connected device and a server on a network, the gateway device has at least a communication unit, a storage device, and a CPU; storing in advance in the storage device first information relating to first authentication processing necessary for establishing communication with the server; an authentication information acquisition unit that stores in advance in the storage device, or acquires from a built-in or external device, second authentication information that is different in type from the first authentication information and that is related to a second authentication process required to establish communication with the server; The CPU is a gateway device that automatically performs a first authentication process related to the first authentication information and a second authentication process related to the second authentication information in response to a communication request from the connected device to the server.

[0117] <Part 2> In the gateway device described in <No. 1>, the automatic response is performed only during a specified period.

[0118] <Part 3> <2> The gateway device according to the second aspect, wherein the first authentication information is a combination of an ID and a password, and the second authentication information is SMS authentication.

[0119] <Part 4> In the gateway device described in <Item 3>, the authentication information acquisition unit is configured as an external device to the gateway device or via a network.

[0120] <Part 5> In the gateway device described in <Item 2>, the specified period is set in conjunction with attendance information.

[0121] <Part 6> In the gateway device described in <Item 1>, the connection device is a gateway device that is an industrial device used in a factory or a management device thereof.

[0122] <Part 7> In the gateway device described in <No. 1>, the automatic response is determined in cooperation with AI to determine whether it is possible.

[0123] <Part 8> A method for proxying multi-factor authentication that enables communication between a connected device and a server on a network, a first step of automatically performing a first authentication process using pre-stored authentication information; a second step of automatically performing a second authentication process different in type from the first authentication process using other authentication information stored in advance or authentication information acquired each time; A method of proxying multi-factor authentication that automatically supports multi-factor authentication.

[0124] <No. 9> <Item 8> The method for proxying multi-factor authentication according to the present invention, wherein the automatic response is performed only during a specified period.

[0125] <Part 10> <Item 9> A method for proxying multi-factor authentication, wherein the first authentication information is a combination of an ID and a password, and the second authentication information is SMS authentication.

[0126] <Part 11> In the multi-factor authentication proxy method described in <No. 10>, the SMS authentication automatically analyzes the one-time password input screen and automatically extracts the one-time password from the received one-time password email, and then enters and transmits the automatically extracted one-time password on the one-time password input screen.

[0127] <Part 12> <Item 9> A method for proxying multi-factor authentication according to the above, wherein the specified period is set in conjunction with attendance information.

[0128] <Part 13> <Item 8> A method for proxying multi-factor authentication according to the above, wherein the connection device is an industrial device used in a factory or a management device thereof.

[0129] <Part 14> In a multi-factor authentication proxy system that enables communication between a connected device and a server on a network, The multi-factor authentication proxy system includes a gateway device having at least a communication unit, a storage device, and a CPU, the gateway device stores in advance in the storage device first information related to first authentication processing required to establish communication with the server; an authentication information acquisition unit that stores in advance in the storage device, or acquires from a built-in or external device, second authentication information that is different in type from the first authentication information and that is related to a second authentication process required to establish communication with the server; The CPU is a multi-factor authentication proxy system that automatically performs a first authentication process related to the first authentication information and a second authentication process related to the second authentication information in response to a communication request from the connected device to the server.

[0130] <Part 15> <14> The multi-factor authentication proxy system according to the above, wherein the automatic response is performed only during a specified period.

[0131] <Part 16> <15> A multi-factor authentication proxy system according to the above <15>, wherein the first authentication information is a combination of an ID and a password, and the second authentication information is SMS authentication.

[0132] <Part 17> <No. 14> In the multi-factor authentication proxy system described above, the authentication information acquisition unit is configured externally to the gateway device or via a network.

[0133] <Part 18> <15> In the multi-factor authentication proxy system described in <No. 15>, the specified period is set in conjunction with attendance information.

[0134] <Part 19> <No. 14> In the multi-factor authentication proxy system described above, the connected device is an industrial device used in a factory or a management device thereof.

[0135] <Part 20> <14> In the multi-factor authentication proxy system described above, the automatic response is a multi-factor authentication proxy system in which AI determines whether or not the automatic response is possible. [Explanation of symbols]

[0136] 10: Gateway device 11: Communications Department 12: Input section 13: Credentials database 14: Authentication information acquisition section 20: Connected device 20 30: Communication Network 31: Server 32:Authentication server 32 40:HUB 41: Communication controller 42:Wireless HUB 50:Display device 60:CPU 61:Storage device 62: Input device 63:Communication equipment

Claims

1. A gateway device that enables communication between a connected device and a server on a network, the gateway device has at least a communication unit, a storage device, and a CPU; storing in advance in the storage device first information relating to a first authentication process required for establishing communication with the server; an authentication information acquisition unit that stores in advance in the storage device, or acquires from a built-in or external device, second authentication information that is different in type from the first authentication information and that is related to a second authentication process required to establish communication with the server; The CPU is a gateway device that automatically performs a first authentication process related to the first authentication information and a second authentication process related to the second authentication information in response to a communication request from the connected device to the server.

2. 2. The gateway device according to claim 1, wherein said automatic response is performed only during a specified period.

3. 3. The gateway device according to claim 2, wherein the first authentication information is a combination of an ID and a password, and the second authentication information is SMS authentication.

4. 4. The gateway device according to claim 3, wherein the authentication information acquisition unit is external to the gateway device or is configured via a network.

5. 3. The gateway device according to claim 2, wherein the specified period is set in association with attendance information.

6. 2. The gateway device according to claim 1, wherein the connection device is an industrial device used in a factory or a management device thereof.

7. 2. The gateway device according to claim 1, wherein the automatic response is determined in cooperation with AI.

8. A method for proxying multi-factor authentication that enables communication between a connected device and a server on a network, a first step of automatically performing a first authentication process using pre-stored authentication information; a second step of automatically performing a second authentication process different in type from the first authentication process using other authentication information stored in advance or authentication information acquired each time; A method of proxying multi-factor authentication that automatically supports multi-factor authentication.

9. 9. The method for proxying multi-factor authentication according to claim 8, wherein the automatic response is performed only during a specified period.

10. 10. The method for proxying multi-factor authentication according to claim 9, wherein the first authentication information is a combination of an ID and a password, and the second authentication information is SMS authentication.

11. 11. The method for proxying multi-factor authentication according to claim 10, wherein the SMS authentication automatically analyzes a one-time password input screen, automatically extracts a one-time password from a received one-time password email, and inputs and transmits the automatically extracted one-time password into the one-time password input screen.

12. 10. The method for performing multi-factor authentication according to claim 9, wherein the specified period is set in association with attendance information.

13. 9. The method for proxying multi-factor authentication according to claim 8, wherein the connection device is an industrial device used in a factory or a management device thereof.

14. In a multi-factor authentication proxy system that enables communication between a connected device and a server on a network, The multi-factor authentication proxy system includes a gateway device having at least a communication unit, a storage device, and a CPU, the gateway device stores in advance in the storage device first information related to first authentication processing required to establish communication with the server; an authentication information acquisition unit that stores in advance in the storage device, or acquires from a built-in or external device, second authentication information that is different in type from the first authentication information and that is related to a second authentication process required to establish communication with the server; The CPU is a multi-factor authentication proxy system that automatically performs a first authentication process related to the first authentication information and a second authentication process related to the second authentication information in response to a communication request from the connected device to the server.

15. 15. The multi-factor authentication surrogate system according to claim 14, wherein the automatic response is performed only during a designated period.

16. 16. The multi-factor authentication surrogate system according to claim 15, wherein the first authentication information is a combination of an ID and a password, and the second authentication information is SMS authentication.

17. 15. The multi-factor authentication surrogate system according to claim 14, wherein the authentication information acquisition unit is configured as an external unit to the gateway device or via a network.

18. 16. The multi-factor authentication surrogate system according to claim 15, wherein the specified period is set in conjunction with attendance information.

19. 15. The multi-factor authentication surrogate system according to claim 14, wherein the connection device is an industrial device used in a factory or a management device thereof.

20. 15. The multi-factor authentication surrogate system according to claim 14, wherein the automatic response is determined by AI to determine whether it is possible to respond automatically.

Citation Information

Patent Citations

  • Authentication terminal and network terminal

    WO2009028606A1