Authentication control program and information processing device

The authentication control program simplifies the use of external biometric sensors by automatically updating system states and reducing restarts, addressing the cumbersome setup of existing systems.

JP2026075411APending Publication Date: 2026-05-08FUJITSU CLIENT COMPUTING LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
FUJITSU CLIENT COMPUTING LTD
Filing Date
2024-10-22
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing systems require cumbersome operations to enable the use of external biometric sensors for user authentication, as they are restricted by built-in sensors with enhanced security features that need manual registry updates to disable.

Method used

An authentication control program automatically updates the system state to allow the use of external biometric sensors by detecting their connection and initiating a restart, simplifying the process by reducing the number of required restarts.

Benefits of technology

Improves usability by automating the transition to enable external biometric sensors for user authentication, reducing the complexity and time needed for setup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026075411000001_ABST
    Figure 2026075411000001_ABST
Patent Text Reader

Abstract

Improve the usability to enable the use of external biometric sensors for user authentication. [Solution] The storage unit 12 stores status information 14 indicating whether the biosensor used for user authentication is in a protected state restricted to the biosensor 11. When the processing unit 13 detects that the biosensor 20 has been connected to the information processing unit 10 when the information processing unit 10 is in a protected state and the status information 14 is a first value indicating that it is in a protected state, it updates the status information 14 to a second value indicating that the protected state has been released. When the information processing unit 10 restarts and the updated status information 14 is applied, releasing the protected state, the processing unit 13 performs user authentication using the biosensor 20.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication control program and an information processing apparatus.

Background Art

[0002] In recent years, biometric authentication using biometric information such as face, vein, fingerprint, iris, etc. has been widely used. Such biometric authentication is used, for example, for user authentication when using a computer or various services.

[0003] In addition, various mechanisms for enhancing computer security have been proposed. For example, a computer equipped with a security chip having functions such as verification of the legitimacy of hardware and software and cryptographic processing has been proposed.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] As a mechanism for realizing a secure sign-in using biometric authentication, there is an information processing apparatus that includes a built-in biometric sensor whose legitimacy has been proven and has a protection function that restricts the biometric sensor used for user authentication to this built-in biometric sensor. However, when using such an information processing apparatus, there are cases where some users or the services used by the users want to use an external biometric sensor different from the above-mentioned built-in biometric sensor.

[0006] In order to enable the use of external biosensors, the above-mentioned protection features must be disabled. However, disabling these protection features requires cumbersome operations, such as modifying specific registry entries.

[0007] In one aspect, the present invention aims to provide an authentication control program and information processing device that can improve operability for enabling the use of external biosensors for user authentication. [Means for solving the problem]

[0008] One proposal provides an authentication control program that causes a computer to perform the following actions: When the computer detects that a second biosensor has been connected to it, and the computer is in a protected state where the biosensors used for user authentication are restricted to a first biosensor built into the computer, and the state information stored in the computer's memory is a first value indicating that it is in a protected state, the computer updates the state information to a second value indicating that the protected state has been released. When the computer restarts and the updated state information is applied, releasing the protected state, the computer performs user authentication using the second biosensor.

[0009] In another proposal, an information processing device is provided having a first biosensor, a memory unit, and a processing unit. The memory unit stores state information indicating whether the biosensor used for user authentication is in a protected state restricted to the first biosensor. When the information processing device is in a protected state and the state information is a first value indicating a protected state, the processing unit detects that a second biosensor has been connected to the information processing device, updates the state information to a second value indicating that the protected state has been released. When the information processing device is restarted and the updated state information is applied, releasing the protected state, the processing unit performs user authentication using the second biosensor. [Effects of the Invention]

[0010] One aspect is improved usability for enabling the use of external biometric sensors for user authentication. [Brief explanation of the drawing]

[0011] [Figure 1] This figure shows an example of the configuration and processing of an information processing device according to the first embodiment. [Figure 2] This figure shows an example of the hardware configuration of a PC according to the second embodiment. [Figure 3] This figure shows an example of a procedure for disabling the ESS depending on the connection of an external sensor. [Figure 4] This diagram shows an example of the configuration of processing functions that a PC has. [Figure 5] This is an example flowchart illustrating the event processing procedure by the event processing unit. [Figure 6] This is an example flowchart showing the authentication and registration process performed by the authentication processing unit. [Figure 7] This diagram shows an example of the processing flow when an external biosensor is connected. [Figure 8] This diagram shows an example of the processing flow when the PC starts up after the process shown in Figure 7. [Figure 9] This is an example flowchart showing the procedure for uninstalling an authentication control program. [Modes for carrying out the invention]

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. [First Embodiment]

[0013] Figure 1 is a diagram showing an example of the configuration and processing of an information processing device according to the first embodiment. The information processing device 10 shown in Figure 1 is a computer such as a PC (personal computer), and has a biosensor 11, a storage unit 12, and a processing unit 13.

[0014] The biological sensor 11 acquires biological information of a predetermined body part of the user. The acquired biological information is used for user authentication. This biological sensor 11 is built into the information processing device 10. Also, the biological sensor 11 may be, for example, a biological sensor whose legitimacy is proven and which can communicate securely with the processing unit 13.

[0015] The storage unit 12 is, for example, a storage area secured in a storage device included in the information processing device 10. The processing unit 13 is, for example, a processor included in the information processing device 10. In this case, the processing of the processing unit 13 described later is realized, for example, by the processor executing a predetermined program.

[0016] Note that an external device such as a biological sensor 20 described later can be connected to the information processing device 10. Although not shown in the figure, the information processing device 10 includes a device connection interface to which such an external device is connected.

[0017] This information processing device 10 can take a protected state in which the biological sensor used for user authentication is limited to the built-in biological sensor 11 in the information processing device 10. In the protected state, basically, user authentication cannot be performed using the external biological sensor 20 attached to the information processing device 10.

[0018] On the other hand, depending on the user or the service used by the user, there is a case where an external biological sensor 20 different from the biological sensor 11 is desired to be used. In order to enable user authentication using such a biological sensor 20, it is necessary to解除 the protected state.

[0019] Also, the storage unit 12 stores state information 14 indicating whether it is in a protected state or not. The state information 14 is, for example, a setting value corresponding to a specific registry key. In the present embodiment, when the state information 14 is on (the first value), it indicates that it is in a protected state, and when it is off (the second value), it indicates that the protected state has been解除.

[0020] However, simply updating the state information 14 does not change the state of the information processing device 10. After updating the state information 14, the information processing device 10 restarts and the updated state information 14 is applied, at which point the information processing device 10 actually transitions to the state indicated by the updated state information 14.

[0021] Therefore, after connecting the biosensor 20 to the protected information processing device 10, a complicated procedure is required to enable user authentication using the biosensor 20, which involves updating the status information 14 to OFF and restarting the information processing device 10. In particular, if the status information 14 is a setting value corresponding to a specific registry key, the operation to update the status information 14 becomes extremely complicated.

[0022] To address such problems, the processing unit 13 performs the following actions. When the processing unit 13 detects that the biosensor 20 has been connected to the information processing device 10 while the information processing device 10 is in a protected state and the status information 14 is ON (step S1), it updates the status information 14 from ON to OFF (step S2).

[0023] Subsequently, the information processing device 10 is restarted (step S3). For example, the processing unit 13 may, at a predetermined timing after the status information 14 has been updated to "off," display information prompting the user to restart on a display device (not shown). In this case, the user can restart the information processing device 10 according to the displayed information.

[0024] When the information processing device 10 restarts, the updated state information 14 is applied, and the protection state is released. This makes it possible to perform user authentication using the biosensor 20, so the processing unit 13 performs user authentication using the biosensor 20 (step S4).

[0025] According to the above process, the status information 14 is automatically updated to "off" in response to the connection of the biosensor 20. Then, when the information processing device 10 restarts, the protection state is released, and user authentication using the biosensor 20 becomes possible. This simplifies the procedure from connecting the biosensor 20 to enabling user authentication using the biosensor 20. Therefore, the usability of enabling the use of an external biosensor 20 for user authentication is improved.

[0026] [Second Embodiment] Next, a second embodiment will be described. In the second embodiment, a PC is used as an example of the information processing device 10. The PC according to this embodiment is configured to allow sign-in to the OS (Operating System) using biometric authentication.

[0027] Figure 2 shows an example of the hardware configuration of a PC according to the second embodiment. The PC 100 shown in Figure 2 includes a processor 101, RAM (Random Access Memory) 102, HDD (Hard Disk Drive) 103, GPU (Graphics Processing Unit) 104, input I / F (interface) 105, reading device 106, network I / F 107, device connection I / F 108, and biosensor 109.

[0028] The processor 101 provides comprehensive control over the entire PC 100. The processor 101 may be, for example, a CPU (Central Processing Unit), MPU (Micro Processing Unit), DSP (Digital Signal Processor), ASIC (Application Specific Integrated Circuit), or PLD (Programmable Logic Device). Alternatively, the processor 101 may be a combination of two or more elements from among the CPU, MPU, DSP, ASIC, and PLD.

[0029] PC100 may have multiple processors 101. Among the multiple processes performed by PC100, the processor that performs one process may be different from the processor that performs a different process. The processor 101 may also be called processor circuitry.

[0030] RAM102 is used as the main memory of PC100. At least a portion of the OS program and application programs to be executed by processor 101 are temporarily stored in RAM102. Additionally, various data necessary for processing by processor 101 are stored in RAM102.

[0031] HDD103 is used as an auxiliary storage device for PC100. HDD103 stores the OS program, application programs, and various data. Note that other types of non-volatile storage devices, such as SSDs (Solid State Drives), can also be used as auxiliary storage devices.

[0032] A display device 51 is connected to the GPU 104. The GPU 104 displays images on the display device 51 according to instructions from the processor 101. The display device 51 can be an LCD or an OLED (Electroluminescent) display.

[0033] An input device 52 is connected to the input interface 105. The input interface 105 transmits the signals output from the input device 52 to the processor 101. The input device 52 can be a keyboard or a pointing device. Examples of pointing devices include a mouse, touch panel, tablet, touchpad, and trackball.

[0034] A portable recording medium 53 is attached to and detached from the reading device 106. The reading device 106 reads the data recorded on the portable recording medium 53 and transmits it to the processor 101. The portable recording medium 53 can be an optical disc, a semiconductor memory, or the like.

[0035] Network I / F 107 transmits and receives data with other devices via network 54.

[0036] Device connection interface 108 is a communication interface for connecting peripheral devices to the PC100. Device connection interface 108 is, for example, a USB (Universal Serial Bus) interface. In this embodiment, a biosensor 55 is connected to the device connection I / F 108 as an example of peripheral equipment. The biosensor 55 is a sensor for acquiring the user's biometric information.

[0037] The biosensor 109 is also a sensor for acquiring the user's biometric information. While the biosensor 55 is externally connected to the PC100 via the device connection I / F 108, the biosensor 109 is built into the PC100.

[0038] The biometric information acquired by the biosensors 55 and 109 includes, for example, veins, fingerprints, irises, and faces. In this embodiment, as an example, biosensor 55 is a fingerprint sensor that detects fingerprints, and biosensor 109 is a vein sensor that detects veins in the palm of the hand. In this case, biosensors 55 and 109 include, for example, an illumination device that irradiates infrared light onto the target body part (fingers and palm, respectively), and a camera that detects reflected light from the body part.

[0039] The processing capabilities of the PC100 can be realized with the hardware configuration described above.

[0040] Incidentally, the PC100 in this embodiment is equipped with a protection function that allows secure sign-in to the OS using biometric authentication with a built-in biosensor 55. For example, the PC100 is compatible with Microsoft's "Secured-core PC" concept. Such a PC100 is equipped with ESS (Enhanced Sign-in Security) functionality that enables secure sign-in to the OS (specifically Windows, registered trademark) using biometric authentication.

[0041] ESS provides a mechanism to protect biometric information acquired from ESS-compatible biosensors embedded in devices from being stolen and misused by programs other than the operating system. To this end, ESS-compatible biosensors have a certificate proving their legitimacy incorporated into them during the manufacturing process.

[0042] In the PC100 of this embodiment, the built-in biosensor 109 supports such an ESS (Evaluation System). The user's biometric information acquired by the biosensor 109 is stored in a memory area inaccessible to the OS and applications running on the OS. For example, the user's biometric information is stored in a non-volatile memory installed inside the biosensor 109. Also, for example, when biometric authentication processing is performed using the biosensor 109, the biosensor 109 may communicate with the processor 101 via a security chip separate from the processor 101. A Trusted Platform Module (TPM) can be used as such a security chip. Furthermore, for example, at least a part of the biometric authentication processing using the biosensor 109 may be executed using a program independent of the OS (for example, a virtualized program module).

[0043] In this case, when ESS is enabled, an external biosensor that does not support ESS cannot be used for signing in to the OS. In this embodiment, the biosensor 55 connected to the device connection I / F 108 does not support ESS, so it cannot be used when ESS is enabled. In order to use the external biosensor 55 when signing in to the OS, ESS must be disabled beforehand.

[0044] However, disabling ESS requires updating the settings corresponding to specific registry keys and restarting the PC100 to apply the updated settings, which presents a problem as the operation is cumbersome.

[0045] In the following explanation, the setting value corresponding to the registry key mentioned above will be referred to as the "ESS status value." An "on" ESS status value indicates that ESS is enabled, while an "off" ESS status value indicates that ESS is disabled. This ESS status value is an example of the status information shown in Figure 1.

[0046] Furthermore, as shown in Figure 3 below, it is also being considered to automate some of the above steps for disabling ESS.

[0047] Figure 3 shows an example of a procedure for disabling the ESS in response to the connection of an external sensor.

[0048] In the example shown in Figure 3, assume that the biosensor 55 is connected to the device connection I / F 108 while the PC 100 is shut down. Then, assume that the PC 100 is started up in this state. The PC 100 will then start up with ESS enabled (step S11). The started PC 100 will detect that the biosensor 55 (external sensor) is connected and update the ESS status value from on to off (step S12). Then, the PC 100 will be restarted by user operation.

[0049] Upon restart, the updated ESS status value is applied to PC100, and PC100 starts up with ESS disabled (step S13). PC100 performs biometric authentication using the external biometric sensor 55 to sign in to the OS (step S14). If authentication is successful, sign-in to the OS is completed (step S15).

[0050] However, if the biosensor 55 is connected while the PC100 is running, the process in step S12 of Figure 3 is not executed. Therefore, if the ESS is disabled using the procedure in Figure 3 in the case where the biosensor 55 is connected while the PC100 is running, the procedure becomes complicated as follows.

[0051] When the biosensor 55 is connected, the PC 100 is restarted by the user. This results in the same state as step S11 in Figure 3, and the processes from step S11 onwards are executed. Specifically, the ESS status value is updated to off (step S12), and the PC 100 is restarted again. As a result, the PC 100 starts up with ESS disabled (step S13), biometric authentication processing using the biosensor 55 is performed (step S14), and sign-in to the OS is completed (step S15). In this way, the PC 100 is restarted twice, making the procedure complicated and requiring a long time to sign in.

[0052] To address these issues, in this embodiment, the PC 100 automatically updates the ESS status value to "off" even if an external biosensor 55 is connected after startup. This reduces the number of restarts required until the user can sign in using the biosensor 55 to just one, simplifying the procedure and improving user experience. Furthermore, the PC 100 displays information on the display device 51 prompting the user to restart at an appropriate time after turning off the ESS status value. This further improves user experience.

[0053] Figure 4 shows an example of the configuration of processing functions provided by a PC. As shown in Figure 4, the PC 100 includes a storage unit 120, an OS 130, an ESS authentication processing unit 140, an authentication control unit 150, and applications 160a, 160b, ...

[0054] The memory unit 120 is a memory area reserved in the storage device provided by the PC 100, such as RAM 102 or HDD 103. The memory unit 120 stores biometric authentication information 121, 122, ESS status value 123, external device information 124, and a restart flag 125.

[0055] The biometric authentication information 121 includes the user's biometric information that is verified when user authentication is performed using the built-in biosensor 109 while the ESS is enabled. If the biosensor 109 detects veins in the palm, the biometric authentication information 121 includes pre-registered vein feature quantities generated based on the vein pattern detected by the biosensor 109.

[0056] The biometric authentication information 122 includes the user's biometric information that is verified when user authentication is performed using the external biometric sensor 55 while the ESS is disabled. When the biometric sensor 55 detects a fingerprint, the biometric authentication information 122 includes the fingerprint feature quantities generated based on the fingerprint pattern detected by the biometric sensor 55, which are registered in advance.

[0057] Here, the biometric authentication information 121 is stored in a memory area accessible only to the ESS authentication processing unit 140. On the other hand, the biometric authentication information 122 is stored in a memory area accessible in common to the OS 130, the authentication control unit 150, and applications 160a, 160b, ...

[0058] The ESS status value 123 indicates whether ESS is enabled or disabled. If ESS status value 123 is ON, it indicates that ESS is enabled; if it is OFF, it indicates that ESS is disabled. Furthermore, as mentioned above, the ESS status value 123 corresponds to a specific registry key.

[0059] External device information 124 registers a list of identification information indicating the models of external biosensors that can be used for user authentication when ESS is disabled.

[0060] The restart flag 125 indicates whether or not to display a message prompting the user to restart PC100. When restart flag 125 is on, it indicates that the message will be displayed; when it is off, it indicates that the message will not be displayed. Restart flag 125 is reset to off each time PC100 starts up.

[0061] The OS130 processes are executed by the processor 101 running the OS program. The OS130 performs basic management and control of the hardware and applications running on the OS of the PC100.

[0062] The ESS authentication processing unit 140 performs its operations using a predetermined program. For example, at least a portion of the ESS authentication processing unit 140's operations may be implemented by the processor of a security chip (not shown) in the PC 100 executing a predetermined program. Alternatively, at least a portion of the ESS authentication processing unit 140's operations may be implemented by the processor 101 executing a program independent of the OS program. The ESS authentication processing unit 140 refers to the biometric authentication information 121 and performs user authentication processing using the built-in biosensor 109.

[0063] The processing of the authentication control unit 150 and applications 160a, 160b, etc. is realized by the processor 101 executing individual application programs that run on the OS 130. The authentication control unit 150 is also a type of application, and its processing is executed using an application program called the "authentication control program".

[0064] The authentication control unit 150 includes an event processing unit 151, an authentication processing unit 152, and an uninstaller 153.

[0065] The event processing unit 151 monitors connection events of external devices (peripherals) to the PC 100 and disconnection events of external devices from the PC 100. When the event processing unit 151 detects that a biosensor 55 requiring ESS (Energy Storage System) disabling has been connected to the PC 100, it updates the ESS status value 123 to OFF.

[0066] The authentication processing unit 152 performs biometric authentication processing based on biometric information detected by the external biometric sensor 55 when the ESS is disabled. The authentication processing unit 152 also performs processing to register the biometric information for performing biometric authentication processing using the external biometric sensor 55 in the biometric authentication information 122.

[0067] The uninstaller 153 uninstalls the authentication control program that implements the processing of the authentication control unit 150. During this uninstallation, the uninstaller 153 updates the ESS status value 123 to ON if it was OFF.

[0068] Applications 160a, 160b, ... each perform a predetermined process. For example, one of applications 160a, 160b, ... may be a browser that displays a website.

[0069] Figure 5 is an example flowchart showing the procedure for event processing by the event processing unit. [Step S21] The event processing unit 151 monitors for connection events of external devices to the PC 100 and disconnection events of external devices from the PC 100. When the event processing unit 151 detects a connection event or a disconnection event, processing proceeds to step S22. On the other hand, if the event processing unit 151 does not detect any connection or disconnection events, it continues to monitor for these events.

[0070] The authentication control unit 150 starts after the OS 130 has started but before the sign-in process for the OS 130 begins. Therefore, the event monitoring by the event processing unit 151 in step S21 starts before the sign-in process for the OS 130 begins.

[0071] [Step S22] The event processing unit 151 determines whether the restart flag 125 is on. If the restart flag 125 is on, the event processing shown in Figure 5 ends; otherwise, the process proceeds to step S23.

[0072] [Step S23] The event processing unit 151 determines whether ESS is enabled. This determination is made, for example, based on the result of a query made by the event processing unit 151 to the OS 130. If ESS is enabled, the process proceeds to step S24; if ESS is disabled, the event processing shown in Figure 5 ends.

[0073] [Step S24] The event processing unit 151 determines whether the detected event is a connection event. If a connection event is detected, the process proceeds to step S25. If a disconnection event is detected, the event processing shown in Figure 5 ends.

[0074] [Step S25] The event processing unit 151 determines whether the connected external device is a biosensor 55 that requires ESS to be disabled. If the identification information indicating the model of the external device obtained from the connected external device is registered in the external device information 124, it is determined that the connected external device is a biosensor 55 that requires ESS to be disabled. If the connected external device is the corresponding biosensor, the process proceeds to step S26; otherwise, the event processing shown in Figure 5 ends.

[0075] [Step S26] The event processing unit 151 updates the ESS status value 123 to OFF.

[0076] [Step S27] The event processing unit 151 updates the restart flag 125 to ON. In the process shown in Figure 5 above, when the restart flag 125 is off and ESS is enabled, and an external biosensor 55 that requires ESS to be disabled is connected, the ESS status value 123 is updated to off, and the restart flag 125 is updated to on. When the ESS status value 123 is turned off, ESS will be disabled after the PC100 is restarted. Also, when the restart flag 125 is turned on, if a process using the biosensor 55 occurs afterward, a message prompting the user to restart the PC100 will be displayed.

[0077] Furthermore, if the biosensor 55 is disconnected (removed from PC100) while ESS is disabled (step S23: No), the ESS status value 123 will remain off, and ESS will remain disabled. This is because, once the use of the external biosensor 55 is initiated, the biosensor 55 is designed to continue to be used until the authentication control program is uninstalled.

[0078] Furthermore, in practice, the process shown in Figure 5 is repeatedly executed while the authentication control unit 150 is running.

[0079] Figure 6 is an example flowchart showing the procedure for authentication and registration processing by the authentication processing unit. [Step S31] The authentication processing unit 152 monitors whether a process using the biosensor has occurred. Processes using the biosensor include, for example, sign-in processes for the OS 130, login processes for various services, and registration processes for biometric information obtained from the biosensor. If the authentication processing unit 152 detects the occurrence of such a process, the process proceeds to step S32. On the other hand, if the authentication processing unit 152 does not detect the occurrence of such a process, it continues to monitor for the occurrence of processes.

[0080] [Step S32] The authentication processing unit 152 determines whether the biosensor used in the process detected in step S31 is a biosensor 55 that requires ESS to be disabled. If identification information indicating the model of the biosensor to be used is registered in the external device information 124, it is determined that the biosensor 55 requires ESS to be disabled. If the biosensor to be used is the corresponding biosensor, the process proceeds to step S33; otherwise, the process proceeds to step S37.

[0081] [Step S33] The authentication processing unit 152 determines whether the restart flag 125 is on. If the restart flag 125 is on, the process proceeds to step S36; otherwise, the process proceeds to step S34.

[0082] [Step S34] The authentication processing unit 152 determines whether ESS is enabled. This determination is made, for example, based on the result of a query made by the authentication processing unit 152 to the OS 130. If ESS is enabled, the process proceeds to step S35; if ESS is disabled, the process proceeds to step S37.

[0083] [Step S35] The authentication processing unit 152 updates the ESS status value 123 to OFF.

[0084] [Step S36] The authentication processing unit 152 displays information on the display device 51 prompting the user to restart the PC 100.

[0085] For example, if the process of updating the restart flag 125 to ON and the process of determining the value of the restart flag 125 in step S33 are executed by different program modules, the restart flag 125 may be updated to ON after step S35. In this case, step S33 is executed after the restart flag 125 is updated, and it is determined to be "ON" (Yes), and the process proceeds to step S36.

[0086] [Step S37] The authentication processing unit 152 executes a biometric authentication process or a biometric information registration process using the relevant biometric sensor. For example, if the biometric information obtained from the relevant biometric sensor is not registered in the biometric authentication information (either of the biometric authentication information 121 or 122), or if a new user's biometric information is to be registered, the biometric information registration process is executed. On the other hand, if the biometric information obtained from the relevant biometric sensor is already registered in the biometric authentication information, the biometric authentication process is executed.

[0087] In practice, the process shown in Figure 6 is executed repeatedly while the authentication control unit 150 is running.

[0088] As shown in Figure 5, when the restart flag 125 is off and ESS is enabled, and an external biosensor 55 that requires ESS to be disabled is connected, the ESS status value 123 is updated to off, and the restart flag 125 is updated to on. Subsequently, if the occurrence of a process using the biosensor 55 is detected in step S31 in Figure 6, "Yes" is determined in steps S32 and S33, and display information prompting a restart is displayed in step S36. The user who connected the biosensor 55 to the PC 100 can then restart the PC 100 according to the above display information when using the biosensor 55. The restart operation applies the ESS status value 123 which has been updated to off, the PC 100 starts up with ESS disabled, and user authentication using the biosensor 55 (step S37) becomes possible.

[0089] In this way, a user who has connected the biosensor 55 to the PC100 no longer needs to manually rewrite the ESS status value 123. Furthermore, when using the biosensor 55 again, the user can restart the PC100 according to the displayed information, starting the PC100 with ESS disabled and performing user authentication using the biosensor 55. Therefore, the user experience for enabling the use of an external biosensor 55 for user authentication is improved.

[0090] Next, using Figures 7 and 8, we will explain an example of the processing flow when the biosensor 55 is connected while the PC 100 is starting up. Here, as an example, we will explain the case where the biosensor 55 is connected during the period from when the OS 130 starts up until the user signs in to the OS 130.

[0091] Figure 7 shows an example of the processing flow when an external biosensor is connected. [Step S41] PC100 starts up with ESS enabled. At this time, the external biosensor 55 is not connected. OS130 starts up on PC100, and then the authentication control unit 150 starts up.

[0092] [Step S42] Assume that the biosensor 55 is connected to the PC 100 before the sign-in process for the OS 130 is executed. The event processing unit 151 of the authentication control unit 150 detects the connection event of the biosensor 55 (corresponding to step S21: Yes in Figure 5).

[0093] [Step S43] The event processing unit 151 updates the ESS status value 123 to OFF (corresponding to Step S26) and updates the restart flag 125 to ON (corresponding to Step S27).

[0094] [Step S44] The sign-in process for OS130 is initiated. For example, when the sign-in screen for OS130 is displayed by OS130, the authentication processing unit 152 of the authentication control unit 150 detects that a process using the biosensor 55 has occurred (corresponding to step S31:Yes in Figure 6).

[0095] [Step S45] The authentication processing unit 152, seeing that the restart flag 125 is on, displays information prompting the user to restart on the display device 51 (corresponding to Step S33: Yes, Step S36).

[0096] Figure 7 shows an example of a display screen 170 that includes information prompting a restart. This display screen 170 displays information 171 that prompts the user to restart the PC 100 using text information. The display screen 170 also displays a guide display section 172 to guide the position of a biological body part (a finger in this example) relative to the biosensor 55. This display screen 170 is displayed, for example, superimposed on the sign-in screen.

[0097] [Step S46] The user restarts PC100 according to the displayed information 171 above. As a result, PC100 restarts. The ESS status value 123, which was updated to OFF by the restart, is applied to PC100, and PC100 starts up with ESS disabled. At this time, the external biosensor 55 is ready for use for user authentication. Also, the restart flag 125 is initialized to OFF. On PC100, OS130 starts up, and then the authentication control unit 150 starts up. The authentication control unit 150 starts up before the sign-in process for OS130 is executed.

[0098] [Step S47] The sign-in process for OS130 is initiated. For example, when the sign-in screen for OS130 is displayed by OS130, the authentication processing unit 152 of the authentication control unit 150 detects that a process using the biosensor 55 has occurred (corresponding to step S31:Yes in Figure 6).

[0099] [Step S48] The authentication processing unit 152 determines that the biosensor 55 is a biosensor that requires ESS to be disabled (Step S32: Yes), determines that the restart flag 125 is off (Step S33: No), and determines that ESS is disabled (Step S34: No). As a result, the process in step S37 is executed.

[0100] Here, assuming the biosensor 55 is connected to the PC 100 for the first time, a biometric information registration process is executed to perform user authentication using the biosensor 55. The authentication processing unit 152 obtains the user's fingerprint pattern from the biosensor 55 and registers the biometric information, which represents the feature quantities of the fingerprint pattern, in the biometric authentication information 122.

[0101] [Step S49] User sign-in to OS130 is completed. With the above process, the user no longer needs to manually rewrite the ESS status value 123 after connecting the biosensor 55 to the PC 100. Furthermore, when using the biosensor 55 later, the user can restart the PC 100 according to the display information 171, starting the PC 100 with ESS disabled and performing user authentication using the biosensor 55. Therefore, the user's ease of use in enabling the use of an external biosensor 55 for user authentication is improved. In addition, since the PC 100 is restarted only once from the time the biosensor 55 is connected until it can be used, the time until the biosensor 55 can be used is shortened.

[0102] In this embodiment, for example, the restart of PC100 to disable ESS is not performed automatically, but only in response to user input. This is because, at the time of the restart, the user may be performing some task on PC100, and if it were to be automatically and forcibly restarted in that case, data may be lost. To avoid such a situation, this embodiment displays a message prompting the user to restart before the restart is performed.

[0103] However, under certain conditions, a restart may occur automatically. For example, under the condition that only one user signs in to OS130 on PC100 (only one user's biometric information is registered in biometric authentication information 121), if the biometric sensor 55 is connected before signing in to OS130, as shown in Figure 7, PC100 may automatically restart without displaying any information prompting a restart in step S45.

[0104] Figure 8 shows an example of the processing flow when the PC is started up after the process in Figure 7. In Figure 8, as an example, it is assumed that after the process in Figure 7 is executed, the PC 100 shuts down and then restarts with the external biosensor 55 still connected.

[0105] [Step S51] PC100 starts up with ESS disabled. On PC100, OS130 starts up, and then the authentication control unit 150 starts up. Note that the authentication control unit 150 starts up before the sign-in process for OS130 is executed.

[0106] [Step S52] The sign-in process for OS130 is initiated. For example, when the sign-in screen for OS130 is displayed by OS130, the authentication processing unit 152 of the authentication control unit 150 detects that a process using the biosensor 55 has occurred (corresponding to step S31:Yes in Figure 6).

[0107] [Step S53] The authentication processing unit 152 further determines that the biosensor 55 is a biosensor that requires ESS to be disabled (Step S32: Yes), determines that the restart flag 125 is off (Step S33: No), and determines that ESS is disabled (Step S34: No). As a result, the biometric authentication process in step S37 is executed.

[0108] The authentication processing unit 152 displays, for example, the display screen 180 shown in Figure 8 on the display device 51. The display screen 180 displays, for example, text information 181 that guides the user to perform fingerprint authentication using an external biosensor 55, and a guide display unit 182 that guides the user to the position of a biological part (a finger in this example) relative to the biosensor 55.

[0109] The authentication processing unit 152 acquires the user's fingerprint pattern from the biosensor 55, generates biometric information representing the feature quantities of the fingerprint pattern, and compares it with the biometric information registered in the biometric authentication information 122. If the similarity between the two pieces of biometric information being compared exceeds a predetermined threshold, it is determined that user authentication has been successful.

[0110] [Step S54] User sign-in to OS130 is completed. Through the above process, the user will be able to continue performing user authentication using the external biometric sensor 55.

[0111] Figure 9 is an example flowchart showing the procedure for uninstalling the authentication control program.

[0112] [Step S61] The uninstaller 153 determines whether ESS is enabled. This determination is made, for example, based on the result of a query made by the authentication processing unit 152 to the OS 130. If ESS is enabled, the process proceeds to step S63; if ESS is disabled, the process proceeds to step S62.

[0113] [Step S62] The uninstaller 153 updates the ESS status value 123 to ON.

[0114] [Step S63] Uninstaller 153 uninstalls the authentication control program.

[0115] In this embodiment, once the use of the external biosensor 55 is initiated, the use of the biosensor 55 is to continue. When the authentication control program is uninstalled, it is determined that the use of the biosensor 55 has ended, and the ESS status value 123 is updated to off. From then on, the PC100 is used with ESS enabled.

[0116] Furthermore, the processing functions of the devices shown in each of the above embodiments (for example, the information processing device 10, PC 100) can be realized by a computer. In that case, a program describing the processing content of the functions that each device should have is provided, and by executing that program on the computer, the above processing functions are realized on the computer. The program describing the processing content can be recorded on a recording medium that can be read by a computer. Examples of recording media that can be read by a computer include magnetic storage devices, optical discs, and semiconductor memory. Examples of magnetic storage devices include hard disk drives (HDDs) and magnetic tapes. Examples of optical discs include CDs (Compact Discs), DVDs (Digital Versatile Discs), and Blu-ray Discs (BD, registered trademark).

[0117] When distributing a program, portable recording media such as DVDs and CDs containing the program are sold. Alternatively, the program can be stored in the storage device of a server computer and transferred from the server computer to other computers via a network.

[0118] A computer executing a program stores programs, for example, those recorded on a portable storage medium or transferred from a server computer, in its own memory. The computer then reads the program from its memory and executes the processing according to the program. Alternatively, the computer can directly read the program from the portable storage medium and execute the processing according to that program. Furthermore, the computer can sequentially execute the processing according to the programs received from a server computer connected via a network, each time a program is transferred. [Explanation of symbols]

[0119] 10 Information Processing Devices 11,20 Biosensors 12 Storage section 13 Processing Unit 14 Status Information S1~S4 Steps

Claims

1. On the computer, When the computer is in a protected state in which the biosensors used for user authentication are restricted to a first biosensor built into the computer, and the state information stored in the computer's memory is a first value indicating that it is in the protected state, the computer detects that a second biosensor has been connected to the computer, and updates the state information to a second value indicating that the protected state has been released. When the computer is restarted and the updated state information is applied, thereby releasing the protection state, user authentication is performed using the second biosensor. An authentication control program that executes a process.

2. To the aforementioned computer, After updating the status information to the second value, if a process requiring user authentication occurs, display information prompting the computer to restart is displayed on the display unit. The authentication control program according to claim 1, which further executes processing.

3. To the aforementioned computer, When the status information is updated to the second value, restart information indicating that a restart is required is registered in the storage unit. When a process requiring user authentication occurs, and if the restart information is registered, a message prompting the user to restart the computer is displayed on the display unit. The authentication control program according to claim 1, which further executes processing.

4. The storage unit of the computer stores a list of models in which one or more identification pieces indicating the models of biosensors that cannot be used for user authentication when in the protected state are registered. The process of updating the state information to the second value is performed when an identification number indicating the model of the second biosensor connected to the computer is registered in the model list information. The authentication control program according to claim 1.

5. When the aforementioned computer starts up, If the status information is the first value, the biosensor of the model registered in the model list information is made unusable for user authentication to sign in to the computer's OS (Operating System). If the status information is the second value, the biosensor of the model registered in the model list information is set to a state where it can be used for user authentication to sign in to the OS. The authentication control program according to claim 4.

6. In an information processing device, The first biosensor, A storage unit that stores state information indicating whether the biosensor used for user authentication is in a protected state restricted to the first biosensor, When the information processing device is in the protected state and the state information is a first value indicating the protected state, and it is detected that a second biosensor has been connected to the information processing device, the state information is updated to a second value indicating that the protected state has been released, and when the information processing device is restarted and the state information updated to the second value is applied, thereby releasing the protected state, the processing unit performs user authentication using the second biosensor. An information processing device having

7. The processing unit updates the state information to the first value when uninstalling a program that performs a process to update the state information to the second value in response to the detection of connection of the second biosensor, and a process to perform user authentication using the second biosensor when the protection state is released. The information processing apparatus according to claim 6.

Citation Information

Patent Citations

  • Computer having biometric authentication device

    JP2010146048A

  • Information processing device

    JP2024064380A