Authentication device, control method, and program
The authentication device facilitates resetting authentication information by using multiple terminal authentications and tokens, addressing the issue of forgotten credentials and unavailable contact methods, ensuring secure and cost-effective identity verification.
Patent Information
- Application Number
- JP2024094505
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-11
- Publication Date
- 2025-12-23
AI Technical Summary
Users are unable to reset their authentication information when they forget their credentials and the registered contact information is no longer available.
An authentication device that allows users to reset their authentication information by successfully authenticating on multiple terminals, using a first terminal and then a second terminal, and issuing authentication success terminal tokens to verify the user's identity.
Enables users to reset their authentication information even when traditional contact methods fail, reducing the need for costly manual intervention and ensuring secure identity verification.
Smart Images

Figure 2025185976000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technique for resetting authentication information set in an authentication system. [Background technology]
[0002] Currently, various services are provided via connections to the Internet, and these services are used by many users. When using these Internet services, users may create an account to use the service. Generally, when creating an account, the user registers authentication information such as a user identifier (ID) and a password to be used for identity authentication. When creating an account, the user may also be asked for contact information to exchange information with an authentication device or authentication system. The contact information may be, for example, an email address, a telephone number, or the like, which are communication means that the user can use. For example, when a user creates an account, a message for identity verification may be sent to the registered contact, and identity verification may be performed by the user responding to this message. The identity verification message may include information such as a one-time password.
[0003] In such an authentication system that manages account information related to a user's account and authenticates the user, if the user forgets their authentication information, the user needs to reset the authentication information. For example, the authentication system may notify the user's contact information of information for resetting the authentication information, and the user may take action based on this information. Resetting the authentication information may also be called account recovery. The authentication information to be reset may include a user ID or password, and resetting the authentication information may involve changing the user ID or resetting the password. In this case, if the user changes their email address or phone number, it may become impossible to communicate with the user using the contact information registered in the authentication system. Patent Document 1 describes a technology that prompts a user to change their email address if an email sent to the email address provided by the user is not delivered to the user. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 3768383 Summary of the Invention [Problem to be solved by the invention]
[0005] If a user forgets their authentication information and the contacts registered in the user's account are no longer available, the user will not be able to reset their authentication information.
[0006] To provide a technique that allows a user to reset authentication information even when the user has forgotten his / her authentication information and the contact information registered in the user's account is no longer available. [Means for solving the problem]
[0007] An authentication device according to one aspect of the present invention comprises: an accepting means for accepting a request to reset authentication information used by the authentication device when authenticating a user; a determining means for determining to accept the resetting of the authentication information based on the fact that a user made the request using a first terminal and then made the request using a second terminal different from the first terminal, and that previous authentications of the user using both the first terminal and the second terminal have been successful; and a notifying means for notifying the user to accept the resetting of the authentication information based on the determination to accept the resetting of the authentication information. [Effects of the Invention]
[0008] According to the present invention, even if a user is unable to log in based on his / her authentication information and the contacts registered in the user's account are no longer available, the user can reset the authentication information. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 illustrates an example of the configuration of an authentication system. [Figure 2] FIG. 2 is a diagram illustrating an example of a hardware configuration of an apparatus that constitutes an authentication system. [Figure 3] FIG. 2 illustrates an example of a functional configuration of an authentication device. [Figure 4] FIG. 10 illustrates an example of a table for managing authentication information. [Figure 5] FIG. 10 illustrates an example of a table for managing token information. [Figure 6] FIG. 10 is a diagram illustrating an example of a sequence of messages exchanged between devices. [Figure 7] FIG. 10 is a diagram illustrating an example of a processing flow executed by the authentication device. [Figure 8] FIG. 10 is a diagram illustrating an example of a screen displayed when resetting authentication information. [Figure 9] FIG. 10 is a diagram illustrating an example of a screen displayed when resetting authentication information. [Figure 10] FIG. 10 is a diagram illustrating an example of a screen displayed when resetting authentication information. [Figure 11] FIG. 10 is a diagram illustrating an example of a screen displayed when resetting authentication information. [Figure 12] FIG. 10 is a diagram illustrating an example of a screen displayed when resetting authentication information. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0011] (System Configuration) 1 shows an example of the configuration of an authentication system according to this embodiment. The authentication system can be configured with a terminal 101, a terminal 102, an authentication device 111, and an information server 121. Each of the terminal 101, the terminal 102, the authentication device 111, and the information server 121 is connected to a network 131 and can communicate with each other via the network 131.
[0012] Terminal 101 and terminal 102 are terminals operated by users, and may be, but are not limited to, a camera, printer, tablet, smartphone, personal computer (PC), mobile phone, video camera, headset, etc. Fig. 1 shows a configuration in which the authentication system includes two terminals, terminal 101 and terminal 102, but the authentication system may include three or more terminals. Terminal 101, terminal 102, etc. may be referred to as terminal 100 without distinction.
[0013] The authentication device 111 accepts registration of authentication information from a user, manages the authentication information, and authenticates the user based on the user's request. The authentication information may be, for example, a user identifier (ID) or a password. The password may be, for example, any combination of numbers, letters, symbols, etc. The authentication information is not limited to these and may be any information or combination thereof that can be used to verify the user's identity. For example, the authentication information may be the user's answer to a predetermined question or the user's date of birth. The authentication information may be any information that is set in advance by the user and that allows the authentication device 111 to verify the user's identity. The authentication device 111 may accept setting of authentication information from the user using the terminal 100. The authentication device 111 may also store the authentication information received from the user. The authentication information received from the user may be stored in the authentication device 111, an external storage medium, or another device accessible from the authentication device 111. When the authentication device 111 receives an authentication request from a user, it authenticates the user by comparing the information received along with the authentication request with the authentication information it holds.
[0014] The information server 121 provides an information service to a user via the terminal 100. The information service provided by the information server 121 may be, for example, a video distribution service, an online storage service, a social networking service (SNS), an online shopping service, a remote access service, or the like. The information service is not limited to these and may be any service that can be provided from the information server 121 to the terminal 100 via the network 131. While FIG. 1 shows a configuration in which the authentication system includes one authentication device 111 and one information server 121, there may be multiple authentication devices 111 and multiple information servers 121. In this case, one authentication device 111 may provide an authentication service to multiple information servers 121. The authentication service is, for example, a service in which the authentication device 111 authenticates a user on behalf of the information server 121 and provides the authentication result to the information server 121. The authentication device 111 may also be configured integrally with the information server 121. Furthermore, when the authentication device 111 is configured integrally with the information server 121, the authentication service provided by the authentication device 111 may be used for authentication for services provided by other information servers.
[0015] A user may create an account to receive information services from the information server 121. The account may be created in the authentication server 121 or may be created in the information server 121. When a user creates an account, authentication information required for authentication to verify the user's identity may be registered in the authentication system. For example, if a user account is created in the information server 121 and the authentication device 111 authenticates the user, the authentication information used to authenticate the user may be stored in the authentication device 111. In this case, the information server 121 may transfer information entered by the user to the authentication device when the user logs in to the account created by the user. The authentication device 111 may perform authentication based on the authentication information stored therein and provide the result to the information server 121. The user may also create an account in the authentication device 111. In this case, the user's authentication information may also be stored in the authentication device 111. For example, when a user attempts to log in to the information server 121, the user may be redirected to the authentication device 111. In this case, if the authentication device 111 successfully authenticates the user, the user may be redirected to the information server 121 and be able to receive information services.
[0016] When logging in using a created account, a user may be prompted to enter authentication information. For example, the authentication information to be entered may be a user ID and a password. The combination of the user ID and password entered by the user may be verified against authentication information stored in the authentication system, thereby authenticating the user. For example, if the combination of the entered user ID and password matches any of the combinations of user IDs and passwords stored in the authentication system, the user may be determined to be the user. If the user forgets the password set as their authentication information, user authentication will fail, and the user will be unable to receive information services. In such a case, the user must reset their authentication information to be able to receive information services again. Resetting authentication information may also be referred to as account recovery. For example, the user may reset their password by replacing the set password with a new password. To do this, the user may request the authentication device 111 to reset the authentication information. When the authentication device 111 receives the user's request, it performs user authentication to determine whether to reset the user's authentication information. In this case, the authentication device 111 requires another means other than the combination of the set user ID and password to verify the identity of the user. For example, as another means for verifying the identity of the user, the user may register information indicating a communication means that the user can use to communicate with the authentication device 111 as a contact in the authentication system. The authentication device 111 notifies the contact of predetermined information, and the user takes action based on the predetermined information, thereby verifying the identity of the user. For example, the information indicating the contact may be the user's email address or telephone number. The information indicating the contact is not limited to these and may also be the user's social media account, etc. The information indicating the contact may be any information indicating a communication means that the user can use without going through authentication by the authentication device 111. The predetermined information that the authentication device 111 notifies the user's contact of the user may be, for example, a link for resetting authentication information.In this case, the user can reset the authentication information by accessing the link notified to the email address or the like. The predetermined information that the authentication device 111 notifies the user's contact information is not limited to this, and may be, for example, a one-time password. In this case, the authentication device 111 can reset the authentication information when the user presents the one-time password notified to the user's email address or the like to the authentication system. The predetermined information that the authentication device 111 notifies the user's contact information is not limited to this, and may be any information that allows the authentication device 111 to confirm that the user has been able to access the system by the user performing a corresponding action based on the predetermined information.
[0017] On the other hand, there are cases where a user cannot use the contact information that they previously set. For example, if the user cancels the communication service to which they subscribed when they set their authentication information, the user may no longer be able to use the email address, phone number, or other information that they previously set. If the user is unable to log in using the authentication information because they have forgotten it, for example, and the contact information is no longer available, the user will be unable to reset the authentication information and will therefore be unable to receive the information service. In such a case, for example, if the information service provider has a call center, the user may communicate with the call center to request that the call center manually reset their authentication information. However, resetting the authentication information via the call center requires time and cost for the user. Furthermore, since maintaining a call center also incurs costs for the information service provider, it is preferable that manual resetting of authentication information not occur frequently.
[0018] In consideration of these circumstances, in this embodiment, the authentication device resets the authentication information based on receiving requests to reset the authentication information from multiple terminals that were used to authenticate a previous user and that were successful in that authentication. For example, the authentication device may accept the reset of the authentication information based on the fact that a user made a request using a first terminal and then made the same request using a second terminal, and that previous authentications of the user using both the first and second terminals were successful. When accepting the reset of the authentication information, the authentication device notifies the user to accept the reset of the authentication information. The terminal used when the user authentication was successful may be identified using predetermined information. For example, when the user authentication is successful, the authentication device may provide first information to the terminal used for the authentication. The first information may be referred to as an authentication success terminal token. Based on the fact that the first terminal and the second terminal each hold an authentication success terminal token, the authentication device may identify that previous authentications of the user using each terminal were successful. The authentication success terminal token may be stored in the terminal in association with the user and included in the request when the user requests resetting of authentication information. In this case, the authentication device may acquire the authentication success terminal token from the accepted request. Furthermore, when the authentication device accepts a request, it may request the authentication success terminal token from the terminal used for the request. In this case, each terminal may transmit the authentication success terminal token it holds to the authentication device based on the request from the authentication device. The authentication device may identify that requests have been made from multiple terminals based on the fact that each authentication success terminal token is associated with the same user. Furthermore, when the authentication device accepts a request via a first terminal, it may provide second information to the user. The second information may be called a one-time token or a recovery code. When the user makes a request via a second terminal, the user may notify the authentication device of the second information. The authentication device may identify that requests have been made from multiple terminals by associating each request using the second information.In this way, the authentication device is configured to reset the authentication information based on receiving requests to reset the authentication information from multiple terminals that have been used to authenticate users in the past and that have successfully authenticated them. By verifying that the device used for the request is a device associated with the user, it is possible to reset the authentication information while ensuring that the request is from the user himself / herself.
[0019] The device configuration, functional configuration, and processing flow of the authentication device 111 of this embodiment will be described below.
[0020] (Device configuration) FIG. 2 shows an example of the hardware configuration of the authentication device 111 of this embodiment. The terminal 100 and information server 121 included in the authentication system may also be configured similarly. The authentication device 111 may be configured, for example, to include a CPU 201, a RAM 202, a ROM 203, a network interface (I / F) 204, an external storage device 205, a display device 206, and an input device 207. The CPU 201 controls the operation of each component of the authentication device 111 and is responsible for executing various processes (described later) performed by the authentication device 111. The RAM 202 is a memory that temporarily stores data and control information and serves as a work area used by the CPU 201 when executing various processes. The ROM 203 stores fixed operational setting values, operating programs, and the like for the authentication device 111. The network I / F 204 provides a function for connecting to and communicating with the network 131. The authentication device 111 can send and receive data to and from external devices via this network I / F 204. The external storage device 205 is a device that stores data and has an interface that accepts I / O commands for reading and writing data. The external storage device 205 may be a hard disk drive (HDD), a solid state drive (SSD), an optical disk drive, a semiconductor storage device, or other storage device. The external storage device 205 may store computer programs and data for causing the CPU 201 to execute each process, which will be described later as being performed by the authentication device 111. The display device 206 is, for example, an LCD (Liquid Crystal Display) or the like, and displays information required by the user. The input device 207 is, for example, a keyboard, a mouse, a touch panel, or the like, and accepts required input from the user.
[0021] (Functional configuration) The functional configuration of the authentication device 111 in this embodiment will be described. Fig. 3 shows an example of a block diagram of the authentication device 111. The authentication device 111 may be configured to include a user information storage unit 301, an authentication processing unit 302, an authentication information resetting processing unit 303, a terminal confirmation unit 304, a token storage unit 305, and an authentication information resetting notification unit 306. The authentication device 111 may also include a recommended behavior output unit 307, a service information acquisition unit 308, and a service identification unit 309.
[0022] The user information storage unit 301 holds authentication information set by a user. The user's authentication information may be registered in the user information storage unit 301 when the user creates an account. The user's authentication information may also be updated when the user resets the authentication information. For example, as shown in FIG. 4, the user information storage unit 301 may store each piece of authentication information received from a user in association with a user ID 401. The user's authentication information may include a user ID 401 and a password 402. The user ID 401 is an ID that uniquely identifies each user in the authentication system, and may be, for example, a combination of numbers, letters, symbols, etc. The password 402 is associated with each user ID 401. For example, a user ID of "000001" is associated with a password of "aaa," and a user ID of "000002" is associated with a password of "bbb." The password 402 may be, for example, a combination of numbers, letters, symbols, etc. The user information storage unit 301 may store an email address 403 in association with the user ID 401. The email address 403 may be used as the user's contact information. The email address 403 may also be used as the user's user ID. For example, when a user logs in, the user may be authenticated by checking whether the combination of information input by the user matches the combination of the user ID 401 or the email address 403 and the password 402. In this case, the user information storage unit 301 may store an email address as the user's contact information, separate from the email address 403 used for user authentication. These email addresses may be the same or different.
[0023] The authentication processing unit 302 authenticates a user based on a request from the user. For example, when the authentication processing unit 302 receives an authentication request from a user via the terminal 100, it authenticates the user by comparing input information included in the authentication request with authentication information stored in the user information storage unit 301. For example, the input information may be the user's user ID and password. If authentication is successful, the authentication processing unit 302 issues an authentication success terminal token and transmits it to the terminal 100. The authentication success terminal token is stored in the terminal 100. The authentication success terminal token may be stored, for example, as a cookie. The authentication success terminal token is added to, for example, a user authentication request or a request to reset authentication information, and can be used to identify that the terminal used for these requests is the terminal used when the user's authentication was successful. The authentication processing unit 302 also notifies the token storage unit 305 of the authentication success terminal token together with the user ID.
[0024] The authentication information resetting processing unit 303 processes a request for authentication information reset from a user. For example, the authentication information resetting processing unit 303 may receive a reset request from the user via each of the terminal 101 and the terminal 102 from the network I / F 204. The authentication information resetting processing unit 303 may also work with the user information storage unit 301 to identify the user who made the request based on the account information included in the request. The authentication information resetting processing unit 303 may also work with the token storage unit 305 and the terminal confirmation unit 304 to identify the user associated with the token included in the request. The authentication information resetting processing unit 303 may determine whether to reset the authentication information based on whether the identified user matches. If the authentication information resetting processing unit 303 determines to reset the authentication information, it may notify the user of information for resetting the authentication information using the authentication information reset notification unit 306. Furthermore, the authentication information resetting processing unit 303 may notify the user of information recommending the user to make a request using multiple terminals via the recommended action output unit 307. For example, when the user makes a request using the terminal 101, the authentication information resetting processing unit 303 may notify the user of information urging the user to make a request using the terminal 102. In this case, the authentication information resetting processing unit 303 may provide a one-time token to the terminal 101.
[0025] The terminal confirmation unit 304 determines whether the terminal 100 used to request the resetting of authentication information is a terminal that was used in a previous authentication of the requesting user and that authentication was successful. For example, the terminal confirmation unit 303 may determine whether the combination of the user ID of the requesting user and the token ID of the successfully authenticated terminal token included in the request matches the combination of the user ID and token ID stored in the token storage unit 305. The terminal confirmation unit 303 may also determine whether the successfully authenticated terminal token has expired. Based on these determination results, the terminal confirmation unit 303 may determine that the terminal 100 is a terminal that was used in a previous authentication of the requesting user and that authentication was successful. Note that when the terminal confirmation unit 303 is notified of only the successfully authenticated terminal token from the authentication information reset processing unit 303, it may determine whether the token is within its expiration date, and if so, may respond using the user ID associated with the token. In this case, the authentication information resetting processing unit 303 may compare the notified user ID with the user ID included in the request based on the validity of the authentication success terminal token, and reset the authentication information associated with this user ID.
[0026] The token storage unit 305 stores successful authentication terminal tokens issued by the authentication processing unit 302 and one-time tokens issued by the authentication information resetting processing unit 303. For example, as shown in FIG. 5, the token storage unit 305 may store each token or information related to the token in association with a user ID. The token storage unit 305 may store, for example, a user ID 401, a token ID 501, a token expiration date 502, and a token type 503 in association with each other. For example, when user authentication is successful, the token storage unit 305 may add the notified user ID and information on the successful authentication terminal token as a record to the table shown in FIG. 5. The user ID 401 is the same as the user ID 401 in FIG. 4. The token ID 501 is information that uniquely identifies each token in the authentication system. For example, the token ID 501 may be a combination of numbers, letters, symbols, etc. A token ID may be assigned for each type of token based on a predetermined rule. The expiration date 502 indicates the expiration date of each token. A token becomes invalid after its expiration date. The token type 503 indicates the type of token. For example, the token type 503 may indicate whether the token is an authentication success terminal token or a one-time token. The token type is not limited to these and may be other types. FIG. 5 shows, for example, that a user with user ID "000001" has been issued a successful authentication terminal token with token ID "Token001" and a one-time token with token ID "1234." It also shows that a user with user ID "000002" has been issued a successful authentication terminal token with token ID "Token002" and a one-time token with token ID "5678." Note that multiple tokens of the same type may be issued to a specific user. For example, a successful authentication terminal token with a different token ID may be issued for each terminal used by the user for authentication. Furthermore, a one-time token with a different token ID may be issued each time the user requests to reset authentication information.
[0027] The service information acquisition unit 308 and the service identification unit 309 identify the service used by the user through authentication. For example, the service information acquisition unit 308 may acquire, from the information server 121, identification information capable of identifying the service used by the requesting user and the type of user information used for the service. Furthermore, the service identification unit 309 may identify the service used by the user and the type of user information used for the service, based on the identification information. For example, the authentication device 111 may set, as a condition for resetting the user authentication information, the request for resetting the user authentication information using as many terminals as possible, based on the service used by the user and the type of user information used by the service.
[0028] (Processing flow) The following describes the sequence between devices in the authentication system described above and the flow of processing executed by the authentication device 111. FIG. 6 shows an example of a sequence of messages exchanged between the authentication device 111 and the terminals 101 and 102. This sequence may be initiated when a user makes a request to reset authentication information. In this example, the user first makes a request using the first terminal 101, and then makes a request using the second terminal 102. The user makes a request to reset authentication information using the first terminal 101 (F601). For example, the user may request resetting by accessing a website for logging in to a service provided by the information server 121 and accessing a screen provided on the website for requesting resetting of authentication information. For example, when the user accesses a screen for requesting resetting of authentication information on a website provided by the information server 121, the user may be redirected to a website provided by the authentication device 111.
[0029] When the authentication device 111 receives a request from a user, it executes processing based on the request. For example, if the request includes user account information (such as a user ID or email address), the authentication device 111 determines whether the account information matches any of the account information stored in the user information storage unit 301. If the account information included in the request matches any of the account information stored in the user information storage unit 301, the authentication device 111 identifies the user ID associated with the account information. Furthermore, if the request includes an authentication success terminal token, the authentication device 111 determines whether the authentication success terminal token is valid, and if it is valid, identifies the user ID associated with the authentication success terminal token using the token storage unit 305. Then, the authentication device 111 determines whether the user ID associated with the account information included in the request matches the user ID associated with the authentication success terminal token. If these user IDs match, the authentication device 111 determines that the first terminal 101 was used to authenticate this user in the past and that authentication was successful. If it is not possible to confirm that these user IDs match, the authentication device 111 determines that it cannot identify that the first terminal 101 was used to authenticate this user in the past and that the authentication was successful. For example, if the user IDs do not match or the authentication success terminal token is invalid, the authentication device 111 determines that it cannot identify that the first terminal 101 was used to authenticate this user in the past and that the authentication was successful. Then, the authentication device 111 sends a response to the first terminal 101 (F602). For example, if the authentication device 111 identifies that the first terminal 101 was used to authenticate this user in the past and that the authentication was successful, it can notify the user to make a request again using another terminal. In this case, the authentication device 111 can include a one-time token in the response. The one-time token can include a recovery code. On the other hand, if the authentication device 111 is unable to determine that the first terminal 101 was used to authenticate this user in the past and that authentication was successful, it may notify the user to make the request again using another terminal.For example, the authentication device 111 may notify the user to make a request again using a terminal that was used for previous authentication and that was successful.
[0030] Upon receiving a response from the authentication device 111, the first terminal 101 may display a message to the user based on the content of the response. For example, the first terminal 101 may display a message to the user urging them to make a request again using another terminal. The first terminal 101 may also display a message indicating that the first terminal 101 was used to authenticate the user in the past and that the authentication was successful. This allows the user to recognize which step of the process required to reset the authentication information the user is currently at. The first terminal 101 may also display a message indicating that it was not possible to confirm that the first terminal 101 was used to authenticate the user in the past, or that it was not possible to confirm that the first terminal 101 was the terminal used when the authentication was successful. This allows the user to recognize that the previous authentication was not successful using this terminal. If the response includes a one-time token, the first terminal 101 may display a recovery code to the user. This allows the user to recognize that they should enter this recovery code when making a request using another terminal.
[0031] Based on the display on the first terminal 101, the user makes a request to reset the authentication information using the second terminal 102 (F603). The user can make the request using the second terminal 102 in the same way as the request was made using the first terminal 101. At this time, the user can make the request by inputting a recovery code. In this case, the recovery code can be included in the request.
[0032] When the authentication device 111 receives a request made using the second terminal 102, it executes processing based on the request in the same manner as if the request had been made using the first terminal 101. For example, the authentication device 111 may identify a user ID associated with the user's account information and the authentication success terminal token included in the request. If the respective user IDs match, the authentication device 111 determines that the second terminal 102 was used to authenticate the user in the past and that the authentication was successful. If the authentication device 111 confirms that each terminal 100 was used to authenticate the user in the past and that the authentication was successful in processing based on a request using the first terminal 101 and the second terminal 102, it may determine to reset the authentication information of the user. For example, if the user IDs identified in the processing based on the respective requests match, it may determine to reset the authentication information of the user. Furthermore, if a recovery code is included in the request, the authentication device 111 may determine to reset the authentication information based on the recovery code. For example, the authentication device 111 obtains a user ID associated with a one-time token corresponding to the recovery code from the token storage unit 305. When a user ID identified from the account information included in the request, a user ID identified from the authentication success terminal token, and a user ID identified from the one-time token match, the authentication device 111 may determine to reset the authentication information of this user. That is, when the user ID identified from the account information included in the request matches the user ID identified from the authentication success terminal token, the authentication device 111 may confirm that the second terminal was used to authenticate this user in the past and that the authentication was successful. Furthermore, when this user ID matches the user ID identified from the one-time token, the authentication device 111 may confirm that the user who made the request using the second terminal 102 and the user who made the request using the first terminal 101 are the same user. The method by which the authentication device 111 confirms that a user made a request using the first terminal 101 and the second terminal 102 is not limited to the above.For example, in an authentication system, the identifier (such as a serial number or address number) of the terminal used by the user when authentication was successful may be stored along with the user ID, and when a request to reset authentication information is received from the user, the terminal identifier may be obtained from the terminal to confirm the request.
[0033] When the authentication device 111 determines that the user's authentication information should be reset, it notifies the user of information for resetting (F604). For example, the information for resetting may be displayed on the screen of the second terminal 102. The information for resetting may be information for accepting input of the information to be reset. Furthermore, the information for resetting may be information indicating a link for accepting input of the information to be reset. The information for resetting may be any information for accepting input of the information to be reset. The user inputs the information to be reset using the second terminal 102 and notifies the authentication device 111 (F605). The authentication device 111 may update the user's authentication information that it holds using the notified information to be reset.
[0034] (Processing flow in authentication device) FIG. 7 shows an example of a processing flow executed by the authentication device 111 when resetting authentication information. This processing may be initiated when a user makes a request to reset authentication information. For example, the user may access a website for logging in to a service provided by the information server 121 via the terminal 100 and request resetting of authentication information by accessing a screen provided on the website for requesting resetting of authentication information. FIG. 8 shows an example of a screen used when a user requests resetting of authentication information. The user enters an email address previously set in the authentication system in a field 801 for entering an email address and presses a password reset button 802. This notifies the authentication device 111 of a request to reset authentication information, including information indicating the email address entered by the user. Note that the field 801 may be a field for entering a user ID. In this case, a request including information indicating the user ID entered by the user is notified to the authentication device 111. The field 801 may be a field for entering any information indicating the user's account information. In the following description, it is assumed that the user first accesses a website using the first terminal 101 and makes a request to the authentication device 111.
[0035] When the authentication device 111 receives a request to reset authentication information from a user via the first terminal 101 (S701), it acquires account information related to the user's account included in the request. For example, the account information may be the user's email address or user ID entered in Fig. 8. Note that if an authentication success terminal token associated with this user is stored in the first terminal 101, the authentication success terminal token may be included in the request.
[0036] The authentication device 111 determines whether the account information acquired from the request matches any of the user's authentication information stored in the user information storage unit 301 (S702). If the acquired email address matches any of the user's email addresses stored in the user information storage unit 305 (YES in S702), the authentication device 111 may transmit information for resetting the authentication information to that email address (S703). Note that, if the authentication device 111 acquires account information other than an email address, such as a user ID, from the request, it determines whether the account information matches information included in any of the user's authentication information stored in the user information storage unit 301. If the account information matches information included in any of the user's authentication information stored in the user information storage unit 301, the authentication device 111 may notify the email address associated with the account information of the user for resetting the authentication information. The information for resetting the authentication information may be, for example, a link for resetting the authentication information or a one-time password. Note that, before transmitting the information for resetting the authentication information, the authentication device 111 may confirm with the user whether or not to transmit the information. For example, the authentication device 111 may request the user to confirm that it will send information for resetting the authentication information by displaying the destination email address, or by indicating to the user that it will send the information without displaying the email address. If the authentication device 111 receives user confirmation for the sending, it sends the information for resetting the authentication information. On the other hand, if the authentication device 111 does not receive user confirmation for the sending, it does not send the information for resetting the authentication information to the destination email address. In either case, the authentication device 111 may continue processing to reset the authentication information using the successful authentication terminal token. If the user can reset the authentication information using the email address entered in FIG. 8 or the email address stored as a contact address in the user information storage unit 301, the user may reset the authentication information using the notified information. In this case, the flow of FIG. 7 may be completed when the user completes resetting the authentication information.On the other hand, if the authentication information cannot be reset using the email address entered in Fig. 8 or the contact email address stored in the user information storage unit 301, the authentication device 111 can continue processing to reset the authentication information using the authentication success terminal token. In this example, the explanation will continue assuming that the user is in a situation where they cannot reset the authentication information using the contact email address stored in the user information storage unit 301. Note that fields 803 and 804 in Fig. 8 will be explained later.
[0037] When a user is unable to reset authentication information using an email address, the authentication device 111 performs processing for resetting authentication information using an authentication success terminal token. FIG. 9 shows an example of a screen used to prompt a user to reset authentication information using an authentication success terminal token. In this example screen, a field 901 indicates the email address to which the authentication device 111 has notified information for resetting authentication information based on a user request. The screen also indicates an action the user should take if the user is unable to use this email address. For example, if email reception is not possible, the user may be prompted to request the resetting of authentication information from another terminal that has been used to log in to a service using the current account. The information indicating the action the user should take is not limited to this, and any information that prompts the user to make a request using a terminal other than the first terminal may be used. Based on this, the user may request the resetting of authentication information using the second terminal 102.
[0038] Furthermore, in order to determine whether to reset authentication information using the successful authentication terminal token, the authentication device 111 confirms that the first terminal 101 used by the user to make a request has been used to authenticate the user in the past and that the authentication was successful. For example, if the request received from the first terminal 101 includes a successful authentication terminal token, the authentication device 111 compares the information on this token with the information on the token stored in the token storage unit 305 (S704). For example, the authentication device 111 identifies the token ID of the successful authentication terminal token included in the request and determines whether the token ID is within its expiration date. If the token is within its expiration date, the authentication device 111 then identifies the user ID associated with the token ID and compares it with the user ID associated with the account information included in the request. For example, the authentication device 111 identifies the user ID based on the association between the token ID and the user ID shown in FIG. 5. Furthermore, the authentication device 111 identifies the user ID from the email address included in the request based on the association between the email address and the user ID shown in FIG. 4. Based on the match between these user IDs, the authentication device 111 determines that the first terminal 101 is a terminal used for previous authentication of this user, and that that authentication was successful. If the request does not include an authentication success terminal token, the authentication device 111 may request the first terminal 101 to transmit an authentication success terminal token. In this case, the first terminal 101 may transmit the authentication success terminal token to the authentication device 111 in response to the request by the authentication device 111.
[0039] The authentication terminal 111 may issue a one-time token if the user ID of the successful authentication terminal token acquired from the first terminal 101 matches the user ID stored in the token storage unit 305 (YES in S704). The one-time token has a shorter expiration date than the successful authentication terminal token and may include information that the user can easily enter manually (e.g., a token ID). The authentication device 111 may notify the first terminal 101 of the issued one-time token (S705). The first terminal 101 may display to the user a screen including information indicated by the received one-time token (recovery code). The recovery code may be a token ID. The authentication device 111 may also store the issued one-time token in the token storage unit 305 together with the corresponding user ID, etc. The one-time token may be used in a request to reset authentication information when the user requests the resetting of authentication information using the second terminal 102 in a subsequent process.
[0040] FIG. 10 shows an example of a screen displaying a recovery code when prompting a user to reset authentication information using an authentication success terminal token. Compared to the screen of FIG. 9, this screen example displays a recovery code as information to be used when requesting authentication information reset from another terminal when the user is unable to receive email. The recovery code may be displayed in field 1001. Based on this information, the user may input the recovery code when requesting authentication information reset using the second terminal 102. For example, the user may access a screen for requesting authentication information reset using the second terminal 102 in the same manner as when making the request using the first terminal 101. In this case, the user may input the recovery code indicated by the one-time token in field 803 for inputting the recovery code on the screen shown in FIG. 8 and press the “Next” button 804. This may result in a request including information indicating the recovery code being notified to the authentication device 111. The second terminal 102 may generate a one-time token using the same method as the authentication device 111 based on the recovery code entered by the user. In this case, the second terminal 102 may generate a one-time token corresponding to the one-time token held in the authentication device 111 and include it in the request. Alternatively, the second terminal 102 may make a request including the recovery code, and the authentication device 111 may associate the recovery code with the one-time token. By including the one-time token in the request by the second terminal 102, it becomes possible to associate the request by the first terminal 101 with the request by the second terminal 102.
[0041] Note that the authentication device 111 may not need to issue a one-time token if the user ID of the successful authentication terminal token acquired from the first terminal 101 matches the user ID stored in the token storage unit 305. In this case, for example, the authentication device 111 first identifies the user ID associated with the successful authentication terminal token acquired from the second terminal 102 used by the user in the subsequent process. Then, the authentication device 111 may determine that the requests are from the same user based on the fact that the user ID is the same as the user ID in the successful authentication terminal token acquired from the first terminal 101. This makes it possible to associate multiple requests as requests from the same user without issuing a one-time token. The authentication device 111 may further determine that the requests are from the same user if the time interval between the requests received from each terminal 100 is within a predetermined period. This reduces the possibility of another user unauthorizedly changing authentication information.
[0042] When the authentication device 111 receives a request for resetting authentication information from a user via the second terminal 102 (S705), the authentication device 111 may execute the same processing as when the request for resetting authentication information is received from the user via the first terminal 101. For example, the authentication device 111 acquires the user's account information included in the request. If the account information acquired from the request is included in any of the user's authentication information stored in the user information storage unit 301, the authentication device 111 determines whether the request includes an authentication-successful terminal token. If the request includes an authentication-successful terminal token, the authentication device 111 compares the information of this token with the information of the token stored in the token storage unit 305 to confirm that the second terminal 101 is a terminal used in a previous authentication and that the authentication was successful. Then, the authentication device 111 may associate these requests based on, for example, the fact that the account information included in the requests received from the first terminal 101 and the second terminal 102 indicates the same user. Furthermore, the authentication device 111 can associate these requests by having the same user ID stored in association with the successful authentication terminal token included in each request. By associating the requests received from each terminal 100 in this way, the authentication device 111 can confirm that the requests were made via multiple terminals 100 that were used to authenticate the user in the past and that were successfully authenticated.
[0043] On the other hand, if a one-time token is included in the request received from the second terminal 102, the authentication device 111 may associate the request using the one-time token. For example, the authentication device 111 may check the expiration date of the one-time token included in the request, and if it is within the expiration date (YES in S707), identify the user ID associated with this token. On the other hand, the authentication device 111 may check the expiration date of the successful authentication terminal token included in the request, and if it is within the expiration date, identify the user ID associated with this token. If the user IDs associated with the one-time token and the successful authentication terminal token match (YES in S708), the authentication device 111 may confirm that the request was made via two terminals 100 that were used to authenticate the user in the past and that authentication was successful.
[0044] When the authentication device 111 confirms that the request was made via two terminals 100 that were used for the user's past authentication and that the authentication was successful, it notifies the second terminal 102 of information for resetting the authentication information (S709). This allows the user to reset the authentication information. FIG. 11 shows an example of a screen for the user to reset the authentication information. For example, the screen may indicate that the user's request meets the conditions for resetting the authentication information. As an example, if a one-time token is used, it may indicate that the input of a recovery code was confirmed using a terminal that was used for the user's past authentication and that the authentication was successful. The screen may also indicate means for the user to reset the authentication information. For example, a field 1101 may be displayed in which the user inputs a new email address to reset the authentication information using a new email address. When the user inputs a new email address in the field 1101 and presses a password reset button 1102, the email address input by the user may be notified to the authentication device 111. The authentication device 111 may notify the notified email address of information for resetting the authentication information. In this case, the authentication device 111 may change the user's contact information registered in the device using the notified email address. Note that the screen for the user to reset the authentication information may have a configuration other than that shown in FIG. 11. For example, instead of or in addition to the field 1101 for inputting a new email address, a field for resetting the authentication information may be provided. This allows the user to change either or both of the contact information and the authentication information on a single screen.
[0045] If a request by a user using the second terminal 102 does not satisfy the conditions for resetting authentication information, the authentication device 111 may notify the user that the conditions were not satisfied. For example, if the authentication device 111 cannot confirm that the request was made using a terminal that was used for previous authentication of the user and that authentication was successful, the authentication device 111 may notify the user of information indicating that terminal confirmation failed (S710). For example, if the one-time token included in the request has expired (NO in S707), the authentication device 111 may notify the user of information indicating that terminal confirmation failed. Furthermore, if the user ID associated with the one-time token does not match the user ID associated with the successful authentication terminal token (NO in S708), the authentication device 111 may notify the user of information indicating that terminal confirmation failed. FIG. 12 shows an example of a screen displayed to the user when the authentication device 111 cannot perform terminal confirmation. The screen may indicate that the conditions for resetting authentication information were not satisfied. For example, the screen may indicate that it was not confirmed that previous authentication was successful using the second terminal 102. The screen may also indicate an action that the user should take, for example, that the user should contact a call center.
[0046] (Variation) In the above description, an example has been given in which the authentication device 111 determines to reset the authentication information when the user requests resetting of the authentication information using the two terminals that were used when authentication was successful in the past. The conditions for the authentication device 111 to determine to reset the authentication information are not limited to this. For example, the authentication device 111 may determine to reset the authentication information when the user requests resetting of the authentication information using a predetermined number of terminals that is equal to or greater than two. In this case, the first terminal 101 and the second terminal 102 may be included in the predetermined number of terminals. If the number of terminals required to allow resetting of the authentication information increases, it becomes more difficult to allow resetting, which reduces the possibility that the authentication information will be reset by a third party other than the user, and the security of information management may be improved.
[0047] When the condition for resetting authentication information is that a user has requested resetting authentication information using a predetermined number of terminals (two or more), the authentication device 111 determines whether the condition for resetting authentication information is satisfied each time processing based on each received request is completed. Here, the processing based on the request may be, for example, processing to identify a user from account information included in a request received from a specific terminal, and to confirm that the specific terminal is a terminal used in the user's previous authentication and that the authentication was successful. The processing based on the request may also be processing to associate requests using a user ID associated with a one-time token or an authentication-success terminal token. For example, the condition for resetting authentication information may be satisfied when the number of requests from the same user, in which the user ID associated with the account information included in the request matches the user ID associated with the authentication-success terminal token included in the request, exceeds a predetermined number. The condition for resetting authentication information may also be satisfied when a request including a one-time token associated with a specific user ID has been used to authenticate a user associated with that user ID in the past and is made from a predetermined number minus one of the terminals where that authentication was successful. When the condition for resetting authentication information is satisfied, the authentication device 111 notifies the user of information for resetting authentication information.
[0048] The predetermined number of terminals for determining whether to reset the authentication information may be a fixed number. In this case, the larger the predetermined number is set, the more secure the information management can be. On the other hand, if the predetermined number is set too large, a user who uses only a small number of terminals may not be able to satisfy the condition.
[0049] The predetermined number of terminals for determining whether to reset the authentication information may be determined based on the total number of terminals used when previous users were successfully authenticated. For example, the predetermined number may be controlled to increase in proportion to the number of terminals used when previous users were successfully authenticated. In this case, the predetermined number may dynamically change depending on the number of terminals used by the user, which may lead to the device being used by a larger number of users.
[0050] The predetermined number of terminals for determining whether to reset the authentication information may be associated with a service provided through authentication. For example, the predetermined number may be associated with each of one or more services provided through authentication. As an example, the predetermined number may be determined based on a value indicating the importance of a service provided through authentication by the authentication device 111. The importance may be, for example, the magnitude of the impact that would occur if unauthorized access were made. The higher the confidentiality of a service used by a user, the higher the risk of a third party unauthorizedly resetting the authentication information. For example, a service in which many users use the same information, such as a video distribution service, may be assigned a low value indicating the importance. Furthermore, a service in which information of specific users, such as a storage service, is stored may be assigned a high value indicating the importance. The value indicating the importance of a service may be preset for each service based on the content of the service, or may be dynamically set based on a predetermined algorithm. The authentication device 111 may acquire identification information for identifying a service used by the requesting user and determine whether to reset the authentication information using the predetermined number associated with the service identified by the identification information. For example, authentication device 111 may provide information identifying the requesting user (e.g., a user ID) to information server 121 and obtain, from information server 121, specific information that can identify the service being used by the user. If authentication device 111 manages the correspondence between services and predetermined numbers within its own device, it may determine the predetermined number based on the specific information obtained from information server 121. On the other hand, authentication device 111 may obtain, from information server 121, information indicating the importance of a service, rather than information indicating the specific service being used by the user. In this case, authentication device 111 may determine the correspondence between the information indicating the importance of the service and the predetermined number, and thereby determine the predetermined number to be used. For example, the specific information may be the name of the service, the type of service, the importance of the service, etc.
[0051] The predetermined number may be associated with each type of information held in a service available through authentication by the authentication device 111. For example, a predetermined number may be associated with each type of user information used by each service provided through authentication. For example, the predetermined number may be determined based on a value indicating the importance of the user's information held in the service used by the user. The higher the confidentiality of information registered or uploaded by the user to receive the service or information held by the service provider as history, etc., the higher the risk of a third party fraudulently resetting the authentication information. For example, if the information registered by the user in the service is public information registered for the purpose of disclosing it to third parties, the value indicating the importance of the information may be set low. Furthermore, if the information held in the service is sensitive information of the user (personal information such as purchase history or undisclosed information), the value indicating the importance of the information may be set high. The value indicating the importance of the information may be set in advance based on the type and content of each piece of information, or may be dynamically set based on a predetermined algorithm. The authentication device 111 may acquire specific information for identifying information about the user held in the service used by the requesting user, and determine the predetermined number based on the information about the user identified by the specific information. For example, authentication device 111 may provide information identifying the requesting user (e.g., a user ID) to information server 121, and obtain from information server 121 specific information capable of specifying the type of user information used in the service being used by the user. If authentication device 111 manages the association between the type of user information and a predetermined number in its own device, authentication device 111 may specify the predetermined number based on the specific information obtained from information server 121. Using the specified predetermined number, authentication device 111 may determine whether or not to reset the authentication information.
[0052] While the above describes an example in which the number of terminals used by a user is used to determine whether or not to reset the authentication information, the authentication device 111 may use the number of operating systems (OSs) used in the request instead of or in addition to the number of terminals. For example, if a browser is used as a terminal, the condition for resetting the authentication information may be that a request is made from each of terminals having two or more arbitrary OSs. This allows a user who uses one physical terminal to create multiple virtual terminals to flexibly make requests via each OS. On the other hand, by making the condition that a request is made from multiple terminals with different OSs, it becomes more difficult to reset the authentication information, thereby improving the security of information management.
[0053] Furthermore, the authentication device 111 may be configured to reset the authentication information using an authentication success token only when the user is unable to reset the authentication information using a pre-set contact. This, for example, eliminates the need for processing from FIG. 704 onward in FIG. 7, thereby reducing the processing load on the authentication device 111. For example, upon receiving a request from a user, the authentication device 111 may display a screen prompting the user to select a reset method and accept input from the user. For example, if the user selects resetting the authentication information using a pre-set contact, the authentication device 111 may not execute processing such as token matching even if the request includes an authentication success token. On the other hand, if the user does not select resetting the authentication information using a pre-set contact, the authentication device 111 may execute processing such as matching the token included in the authentication success token in the request. Note that the authentication device 111 may execute one of the reset methods without receiving a request from the user. For example, upon receiving a request from the user, the authentication device 111 may notify the user's pre-set contact of information for resetting the authentication information, and may not execute processing such as token matching for a predetermined period of time. In this case, if the authentication information based on the information notified by the user to the contact address is not reset within a predetermined period of time, the authentication device 111 may perform token verification or the like.
[0054] As described above, according to this embodiment, the authentication device resets the authentication information based on receiving requests to reset the authentication information from multiple terminals that were used to authenticate a previous user and that successfully authenticated that user. Using this configuration, by verifying that the device used for the request is a device associated with the user, it is possible to reset the authentication information while ensuring that the request is from the user himself / herself, even if the user's pre-defined contact information is unavailable. This allows the authentication device to reset the authentication information based on the user's request, eliminating the need for the user to contact a call center, etc. Furthermore, by requiring the use of multiple terminals associated with the user, the security of information management can be maintained.
[0055] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0056] (Summary of the embodiment) At least some of the above-described embodiments can be summarized as follows. (Item 1) An authentication device, a receiving means for receiving a request to reset authentication information used by the authentication device when authenticating a user; a determination means for determining to accept the resetting of the authentication information based on the fact that a user has made the request using a first terminal and then made the request using a second terminal different from the first terminal, and that previous authentications of the user using both the first terminal and the second terminal have been successful; and a notification means for notifying the user to accept resetting of the authentication information based on the determination that the resetting of the authentication information is accepted. An authentication device characterized by: (Item 2) further comprising a providing means for providing the first information to the terminal used for the user authentication when the authentication of the user is successful; The determination means determines that past authentication of the user using each of the first terminal and the second terminal has been successful, based on the first information being held in each of the first terminal and the second terminal. 2. The authentication device according to item 1, (Item 3) The determination means acquires the first information from the request, thereby confirming that the first information is held. 3. The authentication device according to item 2. (Item 4) The determination means determines to accept the resetting of the authentication information when a predetermined number of terminals, two or more including the first terminal and the second terminal, have made the request and the past authentication of the user using each of the predetermined number of terminals has been successful. 4. The authentication device according to any one of items 1 to 3. (Item 5) The predetermined number is determined based on the total number of terminals that have been used when the user has been successfully authenticated in the past. 5. The authentication device according to item 4, (Item 6) one or more services are associated with each of the predetermined numbers; The authentication device an acquisition means for acquiring specific information capable of identifying the service being used by the user through authentication by the authentication device; and specifying means for specifying the predetermined number associated with the service specified by the specifying information as the predetermined number to be used in the determination by the determining means. 5. The authentication device according to item 4, (Item 7) one predetermined number is associated with each type of information held in a service available through authentication by the authentication device; The authentication device an acquisition means for acquiring specific information capable of identifying the type of information related to the user held in a service that the user is using through authentication by the authentication device; and a specifying unit that specifies the predetermined number to be used in the determination by the determining unit based on the type of information specified by the specifying information. 5. The authentication device according to item 4, (Item 8) The determining means, when an operating system used in the predetermined terminal that made the request is different from an operating system used in the first terminal, treats the request from the predetermined terminal as the request from the second terminal. 8. The authentication device according to any one of items 1 to 7, (Item 9) The system further comprises an output means for outputting, to the first terminal, predetermined information that, when the user makes the request using the first terminal, prompts the user to make the request using a terminal other than the first terminal. 9. The authentication device according to any one of items 1 to 8, characterized in that: (Item 10) the predetermined information output by the output means includes second information to be used when the user makes the request from a terminal other than the first terminal; When the determination means receives the request including the second information, the determination means treats the request as the request from the second terminal. 10. The authentication device according to item 9, (Item 11) The output means further outputs, when it is determined that the resetting of the authentication information is to be accepted, information for accepting a second contact point different from the first contact point previously set by the user to the second terminal. 11. An authentication device according to item 10. (Item 12) When the second contact information is accepted, the notification means sends a notification to the second contact information to accept resetting of the authentication information from the user. Item 12. An authentication device according to item 11. (Item 13) The second information has an expiration date. 13. The authentication device according to any one of items 10 to 12. (Item 14) A control method executed by an authentication device, comprising: a receiving step of receiving a request to reset authentication information used by the authentication device when authenticating a user; a determining step of determining to accept the resetting of the authentication information based on the fact that the user made the request using a first terminal and then made the request using a second terminal different from the first terminal, and that previous authentications of the user using both the first terminal and the second terminal have been successful; and a notification step of notifying the user to accept resetting of the authentication information based on the determination that the resetting of the authentication information is accepted. A control method comprising: (Item 15) A program for causing a computer to function as each of the means possessed by the authentication device described in any one of items 1 to 13.
[0057] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0058] 101: First terminal, 102: Second terminal, 111: Authentication device, 121: Information server, 131: Network
Claims
1. An authentication device, a receiving means for receiving a request to reset authentication information used by the authentication device when authenticating a user; a determination means for determining to accept the resetting of the authentication information based on the fact that a user has made the request using a first terminal and then made the request using a second terminal different from the first terminal, and that previous authentications of the user using both the first terminal and the second terminal have been successful; and a notification means for notifying the user to accept resetting of the authentication information based on the determination that the resetting of the authentication information is accepted. An authentication device characterized by:
2. The method further comprises providing means for providing the first information to a terminal used for user authentication when the authentication of the user is successful, The determination means determines that past authentication of the user using each of the first terminal and the second terminal has been successful, based on the first information being held in each of the first terminal and the second terminal.
2. The authentication device according to claim 1.
3. The determination means acquires the first information from the request, thereby confirming that the first information is held.
3. The authentication device according to claim 2.
4. The determination means determines to accept the resetting of the authentication information when a predetermined number of terminals, two or more including the first terminal and the second terminal, have made the request and the past authentication of the user using each of the predetermined number of terminals has been successful.
2. The authentication device according to claim 1.
5. The predetermined number is determined based on the total number of terminals that have been used when the user has been successfully authenticated in the past.
5. The authentication device according to claim 4.
6. one or more services are associated with each of the predetermined numbers; The authentication device an acquisition means for acquiring specific information capable of identifying the service being used by the user through authentication by the authentication device; and specifying means for specifying the predetermined number associated with the service specified by the specifying information as the predetermined number to be used in the determination by the determining means.
5. The authentication device according to claim 4.
7. one predetermined number is associated with each type of information held in a service available through authentication by the authentication device; The authentication device an acquisition means for acquiring specific information capable of identifying the type of information related to the user held in a service that the user is using through authentication by the authentication device; and a specifying unit that specifies the predetermined number to be used in the determination by the determining unit based on the type of information specified by the specifying information.
5. The authentication device according to claim 4.
8. The determining means, when an operating system used in the predetermined terminal that made the request is different from an operating system used in the first terminal, treats the request from the predetermined terminal as the request from the second terminal.
2. The authentication device according to claim 1.
9. The system further comprises an output means for outputting, to the first terminal, predetermined information that, when the user makes the request using the first terminal, prompts the user to make the request using a terminal other than the first terminal.
2. The authentication device according to claim 1.
10. the predetermined information output by the output means includes second information to be used when the user makes the request from a terminal other than the first terminal; When the determination means receives the request including the second information, the determination means treats the request as the request from the second terminal.
10. The authentication device according to claim 9.
11. The output means further outputs, when it is determined that the resetting of the authentication information is to be accepted, information for accepting a second contact point different from a first contact point previously set by the user to the second terminal.
11. The authentication device according to claim 10.
12. When the second contact information is accepted, the notification means sends a notification to the second contact information to accept resetting of the authentication information from the user.
12. The authentication device according to claim 11.
13. The second information has an expiration date.
11. The authentication device according to claim 10.
14. A control method executed by an authentication device, comprising: a receiving step of receiving a request to reset authentication information used by the authentication device when authenticating a user; a determining step of determining to accept the resetting of the authentication information based on the fact that the user made the request using a first terminal and then made the request using a second terminal different from the first terminal, and that previous authentications of the user using both the first terminal and the second terminal have been successful; and a notification step of notifying the user to accept resetting of the authentication information based on the determination that the resetting of the authentication information is accepted. A control method comprising:
15. A program for causing a computer to function as each of the means included in the authentication device according to claim 1.
Citation Information
Patent Citations
E-mail system, system processing method of the e-mail system, and recording medium recording a program therefor
JP3768383B2
Cited By
Semiconductor device
US12557348B2