Intermediate authentication device, intermediate authentication method, and program
The intermediate authentication device streamlines personal authentication by storing and managing authentication data, simplifying processes and reducing costs for service users and providers by minimizing direct inquiries to certification authorities.
Patent Information
- Application Number
- JP2024114629
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-18
- Publication Date
- 2026-01-29
AI Technical Summary
Existing personal authentication processes are cumbersome and inefficient due to varying interfaces and procedures across different services, requiring service providers to inquire with certification authorities each time, leading to increased complexity and cost for all parties involved.
An intermediate authentication device and method that stores authentication data from certification authorities, compares and responds to service provider inquiries, and manages authentication data efficiently, reducing the need for direct inquiries to certification authorities.
Simplifies and speeds up the authentication process for service users and providers, reduces transaction costs, and unifies interfaces across multiple services, while minimizing direct inquiries to certification authorities.
Smart Images

Figure 2026013904000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an intermediate authentication device, an intermediate authentication method, and a program. [Background technology]
[0002] Conventionally, service users may be required to undergo personal authentication by the service provider. In such personal authentication, the service provider can inquire with a certification authority based on information provided by the service user, and can authenticate the user and confirm that documents have not been tampered with.
[0003] As a technology related to personal authentication, for example, Patent Document 1 below discloses a technology related to the issuance of digital certificates used for personal authentication. This technology enables the issuance of more reliable digital certificates by controlling the issuance of short-term digital certificates for authentication based on long-term digital certificates. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 7131756 Summary of the Invention [Problem to be solved by the invention]
[0005] However, service users are required to go through a process for personal authentication for each service they wish to use, regardless of the trustworthiness of the digital certificate, which is cumbersome because the interface and procedures differ for each service. Furthermore, service providers are required to inquire with a certification authority according to the authentication content each time they receive personal authentication from a service user, and the certification authority must also respond each time. Therefore, it is desirable for personal authentication to enable the three parties - service users, service providers, and certification authorities - to complete the process more efficiently.
[0006] In view of the above-mentioned problems, an object of the present invention is to provide an intermediate authentication device, an intermediate authentication method, and a program that enable parties involved in personal authentication to perform the procedure more efficiently. [Means for solving the problem]
[0007] In order to solve the above-described problems, an intermediate authentication device according to one aspect of the present invention is an intermediate authentication device that includes: a memory unit that, when authentication data indicating that a service user has been authenticated by a certification authority is acquired from the certification authority, stores the acquired authentication data; a reception unit that receives an inquiry from a service provider to confirm the authentication data of the user to be authenticated; a comparison unit that compares authentication information of the user to be authenticated with the authentication data stored in the memory unit to confirm whether the authentication data of the user to be authenticated has been acquired; and a response unit that, based on the comparison result, responds to the provider informing it of the presence or absence of the authentication data of the user to be authenticated.
[0008] An intermediate authentication method according to one aspect of the present invention is an intermediate authentication method executed by a computer, the intermediate authentication method including: a storage step of storing authentication data indicating that a user of a service has been authenticated by a certification authority when the authentication data is acquired from the certification authority; a receiving step of receiving an inquiry from a provider of the service to confirm the authentication data of the user to be authenticated; a comparison step of comparing authentication information of the user to be authenticated with the authentication data stored by the storage step to confirm whether the authentication data of the user to be authenticated has been acquired; and a reply step of replying to the provider, based on the comparison result, whether or not the authentication data of the user to be authenticated is available.
[0009] A program according to one aspect of the present invention is a program that causes a computer to function as: a storage means that stores authentication data indicating that a user of a service has been authenticated by an authentication authority when the authentication data is acquired from the authentication authority; a receiving means that receives an inquiry from a provider of the service to confirm the authentication data of the user to be authenticated; a comparison means that compares authentication information of the user to be authenticated with the authentication data stored in the storage means and confirms whether the authentication data of the user to be authenticated has been acquired; and a reply means that, based on the comparison result, returns to the provider information indicating whether or not the authentication data of the user to be authenticated is available. [Effects of the Invention]
[0010] According to the present invention, those involved in personal authentication can carry out the procedure more efficiently. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating an overview of an authentication service according to an embodiment of the present invention. [Figure 2] 1 is a block diagram showing an example of a configuration of an authentication system according to an embodiment of the present invention and a functional configuration of an intermediate [Figure 3] FIG. 10 is a sequence diagram showing an example of a flow of processing based on authenticator information according to the embodiment. [Figure 4] FIG. 10 is a sequence diagram showing an example of a flow of processing based on alternative authentication information according to the embodiment. [Figure 5] FIG. 10 is a block diagram showing an example of a functional configuration of an intermediate authentication device in a modified example of the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0013] <1. Overview of authentication services> First, an overview of the authentication service SA according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an overview of the authentication service SA according to this embodiment. The authentication service SA is a service that allows users of various services to receive the authentication required to use the services. This authentication includes, for example, personal authentication and qualification confirmation.
[0014] Personal authentication is performed to verify that a service user is the person in question. Personal authentication is performed, for example, by online identity verification (eKYC: electronic Know Your Customer) or a public personal authentication service (JPKI: Japanese Public Key Infrastructure). In online identity verification (eKYC), identity verification is performed online by comparing an image of a photo ID document (such as a driver's license) with an image of the person's appearance (face). The Public Personal Authentication Service (JPKI) authenticates individuals using the signature electronic certificate and user authentication electronic certificate embedded in the IC chip of the My Number card.
[0015] Eligibility verification involves checking whether a service user is eligible to receive a service, for example, by presenting a health insurance card at a hospital or by presenting an ID card to verify age.
[0016] As an example, Figure 1 shows the flow of the authentication service SA when a service user U1 uses multiple services such as a first service and a second service. As shown in Figure 1, the authentication service SA involves the service user U1, the service provider U2, the intermediate certification authority U3, and the certification authority U4 as related parties.
[0017] A service user U1 is a user of various services. A service provider U2 is a provider of various services. A first service provider U2a is a provider of a first service. A second service provider U2b is a provider of a second service. The intermediate certification authority U3 is an institution that acts as an intermediary between the service provider U2 and the certification authority U4. The intermediate certification authority U3 acts as an intermediary between the service provider U2 and the certification authority U4, and undertakes to authenticate the service user U1 on behalf of the service provider U2. The intermediate certification authority U3 manages the authentication data obtained from the certification authority U4. The authentication data is data that indicates that the service user U1 has been authenticated by the certification authority U4. When the intermediate certification authority U3 receives an inquiry from the service provider U2 about the service user U1 to be authenticated, it responds with an authentication result based on the authentication data it manages. The certification authority U4 is an organization that authenticates the service user U1 who is the authentication target. In this embodiment, the certification authority U4 performs authentication only when an inquiry is made by the intermediate certification authority U3.
[0018] (1) When using the first service A service user U1 first provides authentication information to a first service provider U2a. Authentication information is information necessary for authentication. Examples of authentication information include personal information printed on an identification card (such as a driver's license or student ID) or a health insurance card, and a signature electronic certificate or user electronic certificate embedded in the IC chip of a My Number card.
[0019] The first service provider U2a makes an inquiry to the intermediate certification authority U3 based on the authentication information provided by the service user U1. In response to the inquiry, the first service provider U2a confirms the authentication data of the service user U1 to be authenticated.
[0020] When the intermediate certification authority U3 receives an inquiry from the first service provider U2a, it checks whether or not authentication data is available. For example, the intermediate certification authority U3 compares the authentication information of the service user U1 to be authenticated with the authentication data managed by the intermediate certification authority U3, and checks whether or not the authentication data of the service user U1 has been obtained.
[0021] If the authentication data has been acquired, the intermediate authentication authority U3 returns the authentication result to the first service provider U2a based on the authentication data.
[0022] If the authentication data has not been obtained, the intermediate certification authority U3 inquires of the certification authority U4 about the authentication data of the service user U1 to be authenticated, based on the authentication information of the service user U1. When the certification authority U4 receives an inquiry from the intermediate certification authority U3, it authenticates the service user U1 who is the authentication target, and returns the authentication data to the intermediate certification authority U3. The intermediate certification authority U3 stores the authentication data obtained from the certification authority and returns the authentication result to the first service provider U2a.
[0023] The first service provider U2a determines whether the service user U1 can use the service based on the authentication result from the intermediate certification authority U3. If it is determined that the service is available, the first service provider U2a provides the service to the service user. On the other hand, if it is determined that the service is not available, the first service provider U2a does not provide the service to the service user.
[0024] (2) When using the second service The service user U1 provides authentication information to the second service provider U2b. The second service provider U2b makes an inquiry to the intermediate certification authority U3 based on the authentication information provided by the service user U1. After the inquiry, the process proceeds in the same manner as when the service user U1 uses the first service described above.
[0025] It is assumed that when service user U1 uses a second service that provides a service similar to the first service, he / she is unable to prepare the same authentication information as the authentication information used for authentication when using the first service. In this case, service user U1 may provide alternative authentication information to second service provider U2b. Alternative authentication information is information that serves as a substitute for authentication information. For example, if service user U1 uses a health insurance card as authentication information when using the first service, the alternative authentication information when using the second service may be a driver's license or the like other than the health insurance card.
[0026] When using alternative authentication information, the service user U1 provides the alternative authentication information to the second service provider U2b. The second service provider U2b makes an inquiry to the intermediate certification authority U3 based on the alternative authentication information provided by the service user U1. When the intermediate certification authority U3 receives an inquiry from the second service provider U2b, it checks whether or not authentication data is available by using the alternative authentication information. For example, the intermediate certification authority U3 compares the alternative authentication information of the service user U1 to be authenticated with the authentication data managed by the intermediate certification authority U3, and checks whether or not authentication data for the service user U1 has been acquired. After checking, the intermediate certificate authority U3 returns the authentication result to the second service provider U2b, regardless of whether the authentication data has been obtained or not.
[0027] In this way, by making alternative authentication information available, convenience is improved when a service user uses a service that requires the same authentication among multiple services. For example, assume that service user U1 presents his / her health insurance card as authentication information when visiting Hospital A at the beginning of the month and is authenticated. However, assume that service user U1 forgets his / her health insurance card when visiting Hospital B for the first time within the same month. In this case, service user U1 presents a driver's license or the like as alternative authentication information instead of his / her health insurance card. If verification using this alternative authentication information confirms that service user U1 was authenticated with his / her health insurance card at Hospital A at the beginning of the month, service user U1 can use Hospital B.
[0028] <2. Authentication system configuration> The above has described an overview of the authentication service SA according to this embodiment. Next, the configuration of the authentication system 1 according to this embodiment will be described with reference to Fig. 2. Fig. 2 is a block diagram showing an example of the configuration of the authentication system 1 according to this embodiment and the functional configuration of the intermediate authentication device 30.
[0029] The authentication system 1 shown in FIG. 2 is a system for realizing the authentication service SA described with reference to FIG. As shown in FIG. 2, the authentication system 1 includes a user terminal 10, a provider terminal 20, an intermediate authentication device 30, and an authentication device 40.
[0030] (1) User terminal 10 The user terminal 10 is a terminal used by a service user U1. The user terminal 10 is, for example, a mobile terminal such as a smartphone or a tablet terminal, or a PC (Personal Computer). The user terminal 10 is connected to the provider terminal 20 so as to be able to communicate with the provider terminal 20.
[0031] A service user U1 operates a user terminal 10 to provide authentication information or alternative authentication information to a service provider U2. For example, the service user U1 takes a picture of an identification card, health insurance card, or the like using a user terminal 10 with a camera function and sends the image as authentication information or alternative authentication information to the provider terminal 20. The service user U1 may also read an electronic certificate from the IC chip of a My Number card using a user terminal 10 with a reading function and send it as authentication information or alternative authentication information to the provider terminal 20.
[0032] (2) Provider terminal 20 The provider terminal 20 is a terminal used by the service provider U2. The provider terminal 20 is, for example, a mobile terminal such as a smartphone or a tablet terminal, or a PC. The provider terminal 20 is connected to the user terminal 10 and the intermediate authentication device 30 so as to be able to communicate with them.
[0033] The service provider U2 operates the provider terminal 20 to provide authentication information or alternative authentication information to the intermediate authentication authority U3 and query authentication data. For example, the service provider U2 transmits the authentication information or alternative authentication information that the provider terminal 20 receives from the user terminal 10 to the intermediate authentication device 30.
[0034] (3) Intermediate authentication device 30 The intermediate authentication device 30 is a device that functions as the intermediate authentication authority U3. The intermediate authentication device 30 is configured from one or more servers (for example, cloud servers), PCs, etc. The intermediate authentication device 30 is connected to the provider terminal 20 and the authentication device 40 so that they can communicate with each other.
[0035] The intermediate authentication device 30 collates the authentication data based on the authentication information or alternative authentication information received from the provider terminal 20. If the authentication data has already been acquired, the intermediate authentication device 30 transmits an authentication result to the provider terminal 20 based on the acquired authentication data. On the other hand, if the authentication data has not already been acquired, the intermediate authentication device 30 transmits authentication information to the authentication device 40 to inquire about the authentication data, and transmits the authentication result to the provider terminal 20 based on the authentication data acquired from the authentication device 40. Note that if the result of the collation using the alternative authentication information shows that the authentication data has not already been acquired, the intermediate authentication device 30 does not query the authentication device 40 about the authentication data using the alternative authentication information.
[0036] (4) Authentication device 40 The authentication device 40 is a device that functions as the authentication station U4. The authentication device 40 is configured from one or more servers (for example, cloud servers), PCs, etc. The authentication device 40 is connected to the intermediate authentication device 30 so that it can communicate with them.
[0037] The authentication device 40 performs authentication based on the authentication information received from the intermediate authentication device 30 and transmits authentication data to the intermediate authentication device 30 .
[0038] <3. Functional configuration of the intermediate authentication device> The configuration of the authentication system 1 according to this embodiment has been described above. Next, the functional configuration of the intermediate authentication device 30 according to this embodiment will be described with reference to FIG. As shown in FIG. 2, the intermediate authentication device 30 includes a communication unit 310, a storage unit 320, and a control unit 330.
[0039] (1) Communications unit 310 The communication unit 310 has a function of transmitting and receiving various information. The communication unit 310 is communicably connected to the provider terminal 20 and the authentication device 40. In communication with the provider terminal 20, the communication unit 310 receives authentication information or alternative authentication information and transmits an authentication result. In communication with the authentication device 40, the communication unit 310 transmits authentication information and receives authentication data.
[0040] (2) Storage section 320 The storage unit 320 has a function of storing various types of information. The storage unit 320 is configured by a storage medium provided as hardware in the intermediate authentication device 30, such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, an electrically erasable programmable read-only memory (EEPROM), a random access read / write memory (RAM), a read-only memory (ROM), or any combination of these storage media.
[0041] The storage unit 320 stores authentication data indicating that the service user U1 has been authenticated by the authentication authority U4. When the authentication data is acquired from the authentication authority U4 by the functions of the confirmation unit 333, acquisition unit 334, and accumulation unit 335, which will be described later, the storage unit 320 stores and accumulates the acquired authentication data.
[0042] (3) Control unit 330 The control unit 330 has a function of controlling the overall operation of the intermediate authentication device 30. The control unit 330 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) that the intermediate authentication device 30 has as hardware to execute a program. As shown in FIG. 2, the control unit 330 includes a receiving unit 331 , a collating unit 332 , a confirming unit 333 , an acquiring unit 334 , a storing unit 335 , a replying unit 336 , and a managing unit 337 .
[0043] (3-1) Reception Section 331 The reception unit 331 has a function of receiving an inquiry from the service provider U2 to confirm the authentication data of the service user U1 to be authenticated. The reception unit 331 receives the inquiry from the provider terminal 20 via the communication unit 310. At this time, the reception unit 331 acquires the authentication information or alternative authentication information that the communication unit 310 receives from the provider terminal 20 together with the inquiry request, and inputs it to the matching unit 332.
[0044] (3-2) Collation unit 332 The matching unit 332 has a function of performing matching. The matching unit 332 matches the authentication information of the service user U1 to be authenticated with the authentication data stored in the storage unit 320, and checks whether the authentication data of the service user U1 to be authenticated has been acquired.
[0045] If the user to be authenticated cannot provide the authentication information used to obtain the authentication data stored in the memory unit 320, the matching unit 332 checks whether the authentication data has already been obtained based on alternative authentication information that serves as a substitute for the authentication information.
[0046] (3-3) Verification Section 333 The confirmation unit 333 has a function of inquiring the authentication authority U4 about the authentication data of the service user U1. The confirmation unit 333 checks the result of the comparison performed by the comparison unit 332 using the authentication information. If the comparison result shows that the authentication data of the service user U1 to be authenticated has not yet been obtained, the confirmation unit 333 inquires the authentication authority U4 about the authentication data of the service user U1. At this time, the confirmation unit 333 transmits the authentication information of the service user U1 to the authentication device 40 via the communication unit 310.
[0047] (3-4) Acquisition part 334 The acquisition unit 334 has a function of acquiring authentication data from the authentication station U4. The acquisition unit 334 acquires the authentication data that the communication unit 310 receives from the authentication device 40 in response to an inquiry from the confirmation unit 333 to the authentication device 40.
[0048] (3-5) Storage unit 335 The storage unit 335 has a function of storing authentication data, and stores the authentication data acquired by the acquisition unit 334 in the storage unit 320.
[0049] (3-6) Reply section 336 The reply unit 336 has a function of replying to an inquiry from the service provider U2. Based on the collation result, the reply unit 336 replies to the service provider U2 as to whether or not there is authentication data for the service user U1 to be authenticated. At this time, the reply unit 336 transmits information indicating the presence or absence of authentication data as the authentication result to the provider terminal 20 via the communication unit 310.
[0050] The replying unit 336 may transmit the authentication data itself to the provider terminal 20. Furthermore, the replying unit 336 may ensure security by transmitting information indicated by the zero-knowledge proof response to the provider terminal 20 as the authentication result. The zero-knowledge proof response is, for example, a response indicating the authentication result as true or false. Furthermore, the replying unit 336 may encrypt the information to be transmitted to the provider terminal 20.
[0051] (3-7) Management Department 337 The management unit 337 has a function of managing data on the processing status of each unit, and outputs the processing status in the form of, for example, a dashboard.
[0052] <4. Processing flow> The functional configuration of the intermediate authentication device 30 according to this embodiment has been described above. Next, the flow of processing according to this embodiment will be described with reference to FIGS.
[0053] (1) Processing flow based on authentication information The flow of processing based on the authentication information will be described with reference to Fig. 3. Fig. 3 is a sequence diagram showing an example of the flow of processing based on the authentication information according to this embodiment.
[0054] As shown in FIG. 3, first, the user terminal 10 transmits authentication information to the provider terminal 20 in response to an operation by the service user U1 (step S101). Next, in response to an operation by the service provider U2, the provider terminal 20 queries the intermediate authentication device 30 about the authentication data of the service user U1 (step S102). At this time, the provider terminal 20 transmits the authentication information received from the user terminal 10 to the intermediate authentication device 30 together with the query request.
[0055] The receiving unit 331 of the intermediate authentication device 30 receives an inquiry from the provider terminal 20 via the communication unit 310 (step S103). At this time, the receiving unit 331 acquires authentication information that the communication unit 310 receives from the provider terminal 20 together with the inquiry request, and inputs the authentication information to the matching unit 332.
[0056] Next, the matching unit 332 of the intermediate authentication device 30 matches the authentication information with the authentication data (step S104). The matching unit 332 matches the authentication information input from the reception unit 331 with the authentication data stored in the storage unit 320, and checks whether the authentication data of the service user U1 to be authenticated has been acquired.
[0057] If the result of the check shows that the authentication data has not been acquired (step S105 / NO), the process proceeds to step S106. On the other hand, if the authentication data has been acquired (step S105 / YES), the process proceeds to step S110.
[0058] When the process proceeds to step S106, the confirmation unit 333 of the intermediate authentication device 30 queries the authentication device 40 about the authentication data of the service user U1 (step S106). At this time, the confirmation unit 333 transmits the authentication information of the service user U1 together with the query request to the authentication device 40 via the communication unit 310.
[0059] Next, the authentication device 40 authenticates the service user U1 based on the authentication information received from the intermediate authentication device 30, and transmits the authentication result (authentication data) to the intermediate authentication device 30 (step S107).
[0060] Next, the acquisition unit 334 of the intermediate authentication device 30 acquires the authentication data received by the communication unit 310 from the authentication device 40 (step S108). Next, the accumulation unit 335 of the intermediate authentication device 30 stores the authentication data acquired by the acquisition unit 334 in the storage unit 320 (step S109). After the data is accumulated, the process proceeds to step S110.
[0061] When the process proceeds to step S110, the reply unit 336 of the intermediate authentication device 30 replies to the provider terminal 20 with the authentication result of the service user U1 (step S110). At this time, the reply unit 336 transmits information indicating the presence or absence of authentication data as the authentication result to the provider terminal 20 via the communication unit 310.
[0062] Next, in response to an operation by the service provider U2, the provider terminal 20 responds to the user terminal 10 as to whether the service user U1 can use the service (step S111). At this time, the service provider U2 checks the authentication result received by the provider terminal 20 from the intermediate authentication device 30 and determines whether the service user U1 can use the service.
[0063] (2) Processing flow based on alternative authentication information The flow of processing based on the alternative authentication information will be described with reference to Fig. 4. Fig. 4 is a sequence diagram showing an example of the flow of processing based on the alternative authentication information according to this embodiment.
[0064] As shown in FIG. 4, first, the user terminal 10 transmits alternative authentication information to the provider terminal 20 in response to an operation by the service user U1 (step S201). Next, in response to an operation by the service provider U2, the provider terminal 20 queries the intermediate authentication device 30 about the authentication data of the service user U1 (step S202). At this time, the provider terminal 20 transmits the alternative authentication information received from the user terminal 10 to the intermediate authentication device 30 together with the query request.
[0065] The receiving unit 331 of the intermediate authentication device 30 receives an inquiry from the provider terminal 20 via the communication unit 310 (step S203). At this time, the receiving unit 331 acquires alternative authentication information that the communication unit 310 receives from the provider terminal 20 together with the inquiry request, and inputs the information to the matching unit 332.
[0066] Next, the matching unit 332 of the intermediate authentication device 30 matches the alternative authentication information with the authentication data (step S204). The matching unit 332 matches the alternative authentication information input from the reception unit 331 with the authentication data stored in the storage unit 320, and checks whether the authentication data of the service user U1 to be authenticated has been acquired.
[0067] Next, the reply unit 336 of the intermediate authentication device 30 replies to the provider terminal 20 with the authentication result of the service user U1 (step S205). At this time, the reply unit 336 transmits information indicating the presence or absence of authentication data as the authentication result to the provider terminal 20 via the communication unit 310.
[0068] Next, in response to an operation by the service provider U2, the provider terminal 20 responds to the user terminal 10 as to whether the service user U1 can use the service (step S206). At this time, the service provider U2 checks the authentication result received by the provider terminal 20 from the intermediate authentication device 30 and determines whether the service user U1 can use the service.
[0069] The processing flow according to this embodiment has been described above. As described above, the intermediate authentication device 30 according to this embodiment includes: a storage unit 320 that stores authentication data indicating that a service user has been authenticated by the certification authority when the authentication data is acquired from the certification authority; a reception unit 331 that receives an inquiry from a service provider to confirm the authentication data of the user to be authenticated; a comparison unit 332 that compares the authentication information of the user to be authenticated with the authentication data stored in the storage unit 320 to confirm whether or not the authentication data of the user to be authenticated has been acquired; and a reply unit 336 that replies to the provider, based on the comparison result, about the presence or absence of authentication data of the user to be authenticated.
[0070] This configuration allows the intermediate certification authority U3 to undertake authentication on behalf of the service user U1, thereby reducing the number of steps in the authentication service process and speeding it up. For the service user U1, the interfaces and procedures for multiple services are unified, making it less complicated. Furthermore, for the service provider U2, it is sufficient to inquire only with the intermediate certification authority U3 regardless of the authentication content, eliminating the need to inquire with the certification authority U4 according to the authentication content. Furthermore, for the certification authority U4, fewer inquiries from the service provider U2 reduces the number of transactions and requests. Therefore, the intermediate authentication device 30 according to this embodiment enables the parties involved in personal authentication to carry out the procedure more efficiently.
[0071] Note that a fee may be charged for making an inquiry to the certification authority U4. For example, if the service user U1 makes an inquiry directly to the certification authority U4, the service user U1 will have to pay the fee. In contrast, in this embodiment, the intermediate certification authority U3, not the service user U1, makes the inquiry to the certification authority U4, so no fee is charged to the service user U1. Therefore, the intermediate authentication device 30 according to this embodiment can reduce the cost burden on the service user U1 when a fee is charged for making an inquiry to the certification authority U4.
[0072] <5. Variations> The present embodiment has been described above. Next, modified examples of the present embodiment will be described. Note that the modified examples described below may be applied to the embodiment alone or in combination with the embodiment. Furthermore, the modified examples may be applied in place of the configuration described in the embodiment, or may be applied in addition to the configuration described in the embodiment.
[0073] In the above-described embodiment, an example has been described in which the service user U1 provides the authentication information or the alternative authentication information to the service provider U2 using the camera function or the reading function of the user terminal 10. However, the present invention is not limited to such an example. For example, the service user U1 may manually input the authentication information or the alternative authentication information into the user terminal 10 and provide it to the service provider U2. Furthermore, the service user U1 may provide the authentication information or alternative authentication information to the service provider U2 without going through the user terminal 10. In this case, the service user U1 may present, for example, an identification card to the service provider U2, and the service provider U2 may input the information using the camera function or reading function of the provider terminal 20 or input it manually.
[0074] Furthermore, in the above-described embodiment, expiration management of authentication data and bucket management of authentication data may be performed. Here, the expiration management function of authentication data and the bucket management function of authentication data will be described with reference to FIG. 5. FIG. 5 is a block diagram showing an example of the functional configuration of the intermediate authentication device 30a in a modified example of this embodiment. As shown in FIG. 5, the intermediate authentication device 30a further includes an expiration management unit 338 and a bucket management unit 339 in addition to the functional configuration of the intermediate authentication device 30 described with reference to FIG. 2 in the above-described embodiment.
[0075] The expiration management unit 338 has a function of managing the expiration date of the authentication data. The expiration management unit 338 sets the period during which the authentication data can be stored in the storage unit 320 as the expiration date, and invalidates or discards the authentication data when the expiration date has expired. This reduces the effort required for the service provider U2 to manage the authentication data. Furthermore, when the expiration date of the authentication data inquired about by the service provider U2 is approaching, the expiration date management unit 338 may notify the service provider U2 that the expiration date is imminent. This allows the service provider U2 to know in advance whether the authentication data will expire, and by re-acquiring the authentication data before the expiration date, the service provider U2 can efficiently manage the authentication data.
[0076] If the authentication data has expired, the confirmation unit 333 inquires of the authentication device 40 (authentication authority U4) about the expired authentication data. In response to the inquiry, the acquisition unit 334 reacquires the authentication data from the authentication device 40. The accumulation unit 335 stores the authentication data reacquired by the acquisition unit 334 in the storage unit 320. The authentication data may be automatically reacquired by the intermediate authentication device 30 when the expiration date has passed. In this case, the service provider U2 can reduce the effort required to manage the authentication data. Alternatively, the authentication data may be manually reacquired in response to an operation by the service provider U2 that recognizes that the expiration date has passed.
[0077] The bucket management unit 339 has a function of managing authentication data in buckets. The bucket management unit 339 manages multiple pieces of authentication data accumulated in the storage unit 320 by grouping them into buckets. For example, the bucket management unit 339 manages the authentication data in the storage unit 320 by grouping the authentication data into any number of buckets, such as by purpose, role, or period. The bucket management unit 339 may extract a list of services that the service user U1 can use and services that the service user U1 cannot use based on the combination of authentication data included in the bucket, and may present the list to the service user U1. The bucket management unit 339 may also recommend new services that the service user U1 can use based on the combination of authentication data included in the bucket. The function of this bucket management unit 339 enables the service user U1 to grasp his / her own authentication status, and can also expect to enjoy new services.
[0078] We will now explain a use case of bucket management. For example, if you have been authenticated to use a certain facility, you can be authorized to use other facilities as well. Specifically, if there is a bucket containing authentication data indicating that you have been authenticated to use a facility in a specific area, by referencing that bucket, you can be authorized to use other facilities in the same area. Examples of facilities in a specific area include multiple hospitals in Chiyoda Ward and multiple art museums in Taito Ward. Furthermore, if a person has been authenticated for a specific event, related merchandise can be purchased at a discount. Specifically, if there is a bucket containing authentication data indicating that the proof of attendance for a specific event has been authenticated, by referencing that bucket, it is possible to authenticate the purchase of discounted merchandise related to that specific event. Specific events include, for example, music concerts, theaters, and movie theaters. Furthermore, if a person has a specific qualification or has been authenticated at a specific event, it may be possible to participate in other specific events. Specifically, if there is a bucket containing authentication data indicating that a credential for a specific qualification or a participation certificate for a specific event has been authenticated, it is possible to be authenticated for participation in other specific events by referencing that bucket. The specific qualification may be, for example, an IT qualification, and the other specific event may be, for example, an invitation-only technical event.
[0079] The above describes a modified example of this embodiment. Note that some or all of the functions of the authentication system 1 and the intermediate authentication device 30 in the above-described embodiment may be implemented by a computer. In this case, a program for implementing these functions may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read into and executed by a computer system. Note that the term "computer system" here includes hardware such as an OS and peripheral devices. Additionally, "computer-readable recording media" refers to portable media such as flexible disks, optical magnetic disks, ROMs, CD-ROMs, etc., and storage devices such as hard disks built into computer systems. Furthermore, "computer-readable recording media" may also include devices that dynamically store programs for a short period of time, such as communication lines when transmitting programs via networks such as the Internet or communication lines such as telephone lines, and devices that store programs for a certain period of time, such as volatile memory within computer systems that serve as servers or clients in such cases. Furthermore, the above program may be one that realizes part of the above-mentioned functions, or may be one that can realize the above-mentioned functions in combination with a program already recorded in a computer system, or may be one that is realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).
[0080] The embodiments of the present invention have been described in detail above with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes can be made within the scope of the gist of the present invention. [Explanation of symbols]
[0081] 1...authentication system, 10...user terminal, 20...provider terminal, 30, 30a...intermediate authentication device, 40...authentication device, 310...communication unit, 320...storage unit, 330, 330a...control unit, 331...reception unit, 332...collation unit, 333...confirmation unit, 334...acquisition unit, 335...storage unit, 336...reply unit, 337...management unit, 338...expiration management unit, 339...bucket management unit
Claims
1. a storage unit that stores, when authentication data indicating that a service user has been authenticated by a certification authority is acquired from the certification authority, the acquired authentication data; a reception unit that receives an inquiry from a provider of the service to confirm the authentication data of the user to be authenticated; a verification unit that verifies authentication information of the user to be authenticated against the authentication data stored in the storage unit and confirms whether the authentication data of the user to be authenticated has been acquired; a reply unit that returns to the provider information indicating whether or not the authentication data of the user to be authenticated is present based on the result of the matching; An intermediate authentication device comprising:
2. a confirmation unit that, when it is determined from the comparison result that the authentication data of the user to be authenticated has not been acquired, inquires of the certification authority about the authentication data of the user; an acquisition unit that acquires the authentication data from the certification authority; a storage unit that stores the authentication data acquired by the acquisition unit in the storage unit; The intermediate authentication device of claim 1 further comprising:
3. an expiration date management unit that sets a period during which the authentication data can be stored in the storage unit as an expiration date, and invalidates or discards the authentication data when the expiration date has expired; The intermediate authentication device of claim 2 further comprising:
4. the expiration date management unit, when the expiration date of the authentication data inquired about by the provider is near, notifies the provider that the expiration date is about to expire; The intermediate authentication device of claim 3 .
5. If the expiration date has expired, the confirmation unit inquires of the certificate authority about the expired authentication data; the acquisition unit reacquires the authentication data from the certification authority; the accumulation unit accumulates the authentication data reacquired by the acquisition unit in the storage unit. The intermediate authentication device of claim 3 .
6. the verification unit, when the user to be authenticated cannot provide the authentication information used to acquire the authentication data stored in the storage unit, verifies whether the authentication data has been acquired based on alternative authentication information that replaces the authentication information; The intermediate authentication device of claim 1 .
7. a bucket management unit that manages the plurality of pieces of authentication data stored in the storage unit as a bucket, extracts a list of services that the user can use and cannot use based on a combination of the authentication data included in the bucket, and presents the list to the user; The intermediate authentication device of claim 1 further comprising:
8. a storage step of storing, when authentication data indicating that a service user has been authenticated by the authentication authority is acquired from the authentication authority, the acquired authentication data; a receiving step of receiving an inquiry from a provider of the service to confirm the authentication data of the user to be authenticated; a verification step of verifying whether or not the authentication data of the user to be authenticated has been acquired by verifying the authentication information of the user to be authenticated against the authentication data stored in the storage step; a reply step of replying to the provider whether or not the authentication data of the user to be authenticated is present based on the result of the matching; 1. A computer-implemented intermediate authentication method comprising:
9. Computer, a storage means for storing, when authentication data indicating that a service user has been authenticated by a certification authority is acquired from the certification authority, the acquired authentication data; a receiving means for receiving an inquiry from a provider of the service to confirm the authentication data of the user to be authenticated; a verification means for verifying authentication information of the user to be authenticated against the authentication data stored in the storage means, and confirming whether the authentication data of the user to be authenticated has been acquired; a replying means for replying to the provider whether or not the authentication data of the user to be authenticated is present based on the result of the collation; A program to function as a
Citation Information
Patent Citations
Issuance of short-term digital certificates based on verification of long-term digital certificates
JP7131756B2