Information processing device, control method for information processing device, and program

The device controls credential synchronization based on social networking service usage and authentication strength to prevent unauthorized access in multi-device FIDO credentials, addressing the risk of biometric information leakage.

JP2026082300APending Publication Date: 2026-05-19CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2024-11-07
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

The leakage of biometric information through social networking services poses a risk of unauthorized account hijacking in multi-device FIDO credentials, as authentication methods matching leaked information can be exploited.

Method used

An information processing device with a module that acquires social networking service usage information and controls credential synchronization based on authentication strength and method, restricting synchronization if the user is using services that may expose biometric data.

Benefits of technology

Reduces the risk of credential leakage by ensuring secure synchronization of FIDO credentials only when safe authentication methods are used, preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026082300000001_ABST
    Figure 2026082300000001_ABST
Patent Text Reader

Abstract

In a multi-credential FIDO authentication system that synchronizes credential information across multiple devices, there is a risk of account hijacking if biometric information is leaked via social media or other means. [Solution] The authentication terminal 102 obtains information about the SNS used by the user using the authentication terminal 102 from the credential information management server 105 (S808 in Figure 8). If it determines from the obtained SNS information that the user is using an SNS (YES in S901), it restricts the execution of a synchronization process that obtains the credential information managed by the credential information management server 105 from the credential information management server 105 and saves it to the authenticator of the authentication terminal 102 (S903-S906).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, a control method for an information processing apparatus, and a program.

Background Art

[0002] There is FIDO (registered trademark) as an authentication system including biometric authentication. FIDO is an abbreviation of "Fast Identity Online". In addition, as an extended specification of credentials handled by FIDO (hereinafter referred to as "FIDO credentials"), multi-device FIDO credentials have been a topic of discussion in recent years.

[0003] In FIDO, registration work is performed in advance between an authenticator such as a user's terminal at hand and an authentication server, so that credentials such as a private key and a user ID are registered in the authenticator, and a public key is registered in the authentication server. Here, in the conventional FIDO, there is no specification for transmitting and storing credentials from the terminal where the credentials are registered to another terminal or server. Therefore, it has been a problem that the credentials could not be synchronized with a terminal different from the terminal used by the user in the registration work, and thus account recovery was not possible.

[0004] Patent Document 1 discloses a technique for permitting account recovery when a recovery request for an account is transmitted from a terminal of a synchronization destination to an authentication server in a state where an authenticator of a credentials issuer and a FIDO authenticator of a synchronization destination are linked, and the authentication conditions are satisfied.

[0005] In contrast, multi-device FIDO credentials transmit credentials from the FIDO client module of the registration terminal to the server that manages the client module during the credential registration process. This makes it possible to synchronize FIDO credentials to other terminals handled by the user. Means of synchronizing credentials include requesting the acquisition of credentials from the backup server from the terminal's FIDO client module, or transmitting credentials using BLE (Bluetooth Low Energy) terminal-to-terminal communication. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] Japanese Patent Publication No. 2023-000715 [Overview of the project] [Problems that the invention aims to solve]

[0007] On the other hand, the leakage of biometric information through information such as photos, audio, and videos uploaded to SNS (Social Networking Services) is becoming a growing concern. If authentication information such as facial features or fingerprints is leaked from such information, and the synchronized device uses an authentication method that matches the leaked authentication information, then in the case of the aforementioned multi-device FIDO credentials, there is a possibility that the account could be hijacked and used by unauthorized individuals without the owner's permission.

[0008] This invention was made to solve the above-mentioned problems. The purpose of this invention is to provide a mechanism that can reduce the risk of credential leakage in multi-device FIDO credentials. [Means for solving the problem]

[0009] The present invention relates to an information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, wherein the device includes an acquisition means for acquiring information of a social networking service used by a user of the information processing device from the server, and a control means for controlling the execution of a synchronization process that uses the information acquired by the acquisition means to acquire credential information managed by the server from the server and save it to the module, wherein the control means restricts the execution of the synchronization process if it determines from the information acquired by the acquisition means that the user is using a social networking service. [Effects of the Invention]

[0010] According to the present invention, the risk of credential leakage in multi-device FIDO credentials can be reduced. [Brief explanation of the drawing]

[0011] [Figure 1] A diagram illustrating the overall system configuration in the first embodiment. [Figure 2] A diagram illustrating the hardware configuration of each device in the first embodiment. [Figure 3] A diagram illustrating the modular configuration of each device in the first embodiment. [Figure 4] A diagram illustrating the credential registration screen in the first embodiment. [Figure 5] A sequence diagram illustrating the user authentication process in the first embodiment. [Figure 6] A sequence diagram illustrating the credential registration process in the first embodiment. [Figure 7] A flowchart illustrating the credential registration determination process in the first embodiment. [Figure 8] A sequence diagram illustrating the credential synchronization process in the first embodiment. [Figure 9]Flowchart illustrating the credential synchronization determination process in the first embodiment. [Figure 10] Diagram showing an example of a warning screen in the first embodiment. [Figure 11] Diagram illustrating the overall configuration of the system in the second embodiment. [Figure 12] Diagram illustrating the module configuration of each device in the second embodiment. [Figure 13] Sequence diagram illustrating the user authentication process in the second embodiment. [Figure 14] Sequence diagram illustrating the credential synchronization process in the second embodiment. [Figure 15] Diagram illustrating the module configuration of each device in the third embodiment. [Figure 16] Sequence diagram illustrating the credential registration process in the third embodiment. [Figure 17] Flowchart illustrating the credential registration determination process in the fourth embodiment.

Embodiments for Carrying Out the Invention

[0012] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. 〔First Embodiment〕 In this embodiment, the registration and synchronization of credential information in a multi-device FIDO credential authentication system are restricted according to the social networking service (SNS) usage information provided by a credential information management server, the authentication method of an authentication terminal, and the authentication strength required by an application server.

[0013] <System Configuration> FIG. 1 is a diagram illustrating the overall configuration of the system in the first embodiment of the present invention. In Figure 1, 101 and 102 are authentication terminals (information processing devices). Authentication terminals 101 and 102 send a request to application server 103 to create credential information and obtain challenge and recommended authentication level information from authentication server 104. Then, authentication terminals 101 and 102 create the credential information and send the result of the credential information creation to authentication server 104. Furthermore, authentication terminals 101 and 102 send a request to credential information management server 105 to register the credential information and obtain the registration result from credential information management server 105.

[0014] In addition, authentication terminals 101 and 102 send a credential information synchronization request to the credential information management server 105 and retrieve registered credential information. When authentication terminals 101 and 102 send the above synchronization request, they must perform an authentication request to the credential information management server 105 and succeed in authentication. Furthermore, authentication terminals 101 and 102 determine whether or not to register and synchronize the credential information and control the execution of the registration process and the synchronization process.

[0015] When application server 103 receives a request to create credential information from authentication terminals 101 and 102, it sends the same request to authentication server 104. Furthermore, when application server 103 receives the result of the credential information creation from authentication server 104, it sends the result to authentication terminals 101 and 102. Finally, application server 103 sends the authentication level information requested by the application to authentication server 104.

[0016] When the authentication server 104 receives a request to create credentials, it sends a challenge and information on the recommended authentication level obtained from the application server 103 to the authentication terminals 101 and 102. Furthermore, when the authentication server 104 receives the results of the credential information creation from the authentication terminals 101 and 102, it registers the public key with the authentication server 104 and sends the results of the credential information creation to the application server 103. Note that the authentication server 104 may be managed on the same server as the application server 103.

[0017] The credential information management server 105 manages credential information. When the credential information management server 105 receives a request from authentication terminals 101 and 102 to register credential information, it registers the credential information in the credential information management server 105 and sends the credential information registration result to authentication terminals 101 and 102. Furthermore, when the credential information management server 105 receives a request for credential information synchronization from the authentication terminals 101 and 102, it transmits the credential information to the authentication terminals 101 and 102. In addition, when using the synchronization function, the credential information management server 105 requires authentication of the user using the authentication terminals 101 and 102, and provides the authentication function to the authentication terminals 101 and 102. Furthermore, the credential information management server 105 holds information to determine whether the registered credential information belongs to an SNS, and also holds information about the type of media (media type) uploaded to that SNS.

[0018] Authentication terminal 101 is connected to the global network 108 via the local network 106. Authentication terminal 102 is also connected to the global network 108 via the local network 107. Furthermore, the authentication terminals 101 and 102, the application server 103, the authentication server 104, and the credential information management server 105 are connected to each other via the global network 108.

[0019] Local networks 106 and 107 are communication networks implemented by one or a combination of, for example, LANs, WANs, telephone lines, dedicated digital lines, ATM or frame relay lines, cable television lines, wireless lines for data broadcasting, etc. Global network 108 has the same configuration as local networks 106 and 107.

[0020] <Hardware configuration of authentication terminal and server> First, let's describe the hardware configuration of authentication terminals 101 and 102. Figure 2(a) is a block diagram showing an example of the hardware configuration of the information processing devices that make up authentication terminals 101 and 102. Here, the information processing devices that make up authentication terminals 101 and 102 are referred to as "authentication terminals".

[0021] The authentication terminal is equipped with a CPU 201 that executes software stored on a hard disk drive (HDD) 203, which is a storage device. The CPU 201 comprehensively controls each piece of hardware connected to the system bus 204.

[0022] Memory 202 functions as the main memory, work area, etc., of CPU 201. The hard disk drive (HDD) 203 records data as a large-capacity storage device. Alternatively, other storage devices such as an SSD (Solid State Drive) or eMMC (embedded MultiMediaCard) may be used in place of or in conjunction with the HDD.

[0023] The UI control unit 205 controls input from an input device 206, such as a touch panel. The network control unit 207 exchanges data bidirectionally with other nodes via the network.

[0024] The TPM (Trusted Platform Module) 208 is a storage device with tamper resistance to prevent external reading of stored data, intended for processing and maintaining confidential information. In this embodiment, the TPM 208 manages credential information such as biometric information itself used for authentication and private keys corresponding to biometric information.

[0025] The biometric information sensor 209 is a sensor that reads the biometric information of a user using an authentication terminal, such as the user's fingerprints, veins, voiceprint, iris, and facial image, and converts this information into a signal. The biometric information sensor 209 is implemented using a dedicated reader such as a fingerprint sensor, a camera, a microphone, etc.

[0026] Next, we will describe the hardware configuration of the application server 103, the authentication server 104, and the credential information management server 105. Figure 2(b) shows an example of the hardware configuration of each information processing device that makes up the application server 103, authentication server 104, and credential information management server 105. Here, each information processing device that makes up the application server 103, authentication server 104, and credential information management server 105 is referred to as a "server device".

[0027] The server device includes a CPU 210 that executes software stored on the HDD 212, which is a storage device. The CPU 210 comprehensively controls each piece of hardware connected to the system bus 213.

[0028] Memory 211 functions as the main memory, work area, etc., of the CPU 210. The HDD212 records data as a high-capacity storage device. Alternatively, other storage devices such as SSDs or eMMCs may be used in place of or in conjunction with the HDD.

[0029] The input control unit 214 controls input from an input device 215, such as a keyboard. Depending on the role of the server device, the configuration may not include the input control unit 214 or the input device 215.

[0030] The display control unit 216 controls the display on the display device 217, such as a liquid crystal display. Depending on the role of the server device, a configuration without the display control unit 216 and display device 217 is also possible. The network control unit 218 exchanges data bidirectionally with other nodes via the network.

[0031] In this embodiment, the information processing devices constituting the application server 103, authentication server 104, and credential information management server 105 are implemented by information processing devices provided as a cloud computing service. Cloud computing includes serverless computing and virtual machines. In cloud computing, multiple hardware resources as shown in Figure 2 are used. The application server 103, authentication server 104, and credential information management server 105 may each be implemented on a single physical machine, or they may be implemented on multiple physical machines.

[0032] <Functional Configuration> Figure 3 is a block diagram showing an example of the functional configuration of the authentication terminals 101 and 102, application server 103, authentication server 104, and credential information management server 105 in the first embodiment.

[0033] (Authentication terminal) The authentication terminals 101 and 102 are equipped with a browser 310, an authentication client 320, and an authenticator 330.

[0034] The browser (Web browser) 310 provides functions such as interpreting HTML (HyperText Markup Language), displaying web pages, receiving input from the user, and sending requests. In this embodiment, the browser 310 provides functions for displaying screens such as the credential information registration screen provided by the application server 103. An example of the credential information registration screen is shown in Figure 4.

[0035] Figure 4 shows an example of a credential information registration screen. The credential information registration screen is displayed in the browser 310 of the authentication terminal where the credential information is registered. When the "Yes" button is selected on the credential information registration screen, as shown in Figure 4, the credential information is registered.

[0036] Now, let's return to the explanation of Figure 3. The authentication client 320 provides functions to control the authentication process and registration of credential information required when a user registers their credential information. The credential information will be described in the function description of the credential information storage unit 332, which will be described later. The authentication client 320 also provides a function to control the synchronization of credential information.

[0037] The authenticator 330 comprises a biometric authentication processing unit 331, a credential information storage unit 332, a biometric information management unit 333, and a registration / synchronization determination unit 334. The biometric authentication processing unit 331 provides the function of requesting biometric information input from the user using the authentication terminal and the function of performing biometric authentication. Biometric authentication is performed by confirming that the biometric information received from the user exists in the biometric information table held by the biometric information management unit 333. The biometric information and the biometric information table will be described in the function description of the biometric information management unit 333. In addition, the biometric authentication processing unit 331 provides the function of creating credential information. The credential information will be described in the function configuration of the credential information storage unit 332.

[0038] The credential information storage unit 332 provides a function to store, for example, the credential information created when the public key for using the services provided by the application server 103 is registered with the authentication server 104 in the TPM 208.

[0039] Table 1 shows an example of a credential information table held in the credential information storage unit 332 of the authentication terminal 101. [Table 1] Table 2 shows an example of a credential information table held in the credential information storage unit 332 of the authentication terminal 102. This corresponds to the state where no credential information has been stored yet. [Table 2]

[0040] As shown in Tables 1 and 2, the credential information records in the credential information table include the authentication information ID, private key, user ID, and service URL. The authentication information ID is an ID that uniquely identifies the authentication information. The user ID is an ID that uniquely identifies the user information (user identification information). The service URL is the URL of the service provided by application server 103.

[0041] The biometric information management unit 333 manages the biometric information stored in the authenticator 330. Table 3 shows an example of a biometric information table managed by the biometric information management unit 333 of the authentication terminal 101. [Table 3] Table 4 shows an example of a biometric information table managed by the biometric information management unit 333 of the authentication terminal 102. [Table 4] As shown in Tables 3 and 4, each biometric record in the biometrics table includes a user ID and a biometrics ID, which is an ID that uniquely identifies the biometric information.

[0042] The registration / synchronization determination unit 334 receives SNS usage information from the credential information management server 105 and authentication level information from the application server 103, compares the authentication method of the biometric authentication processing unit 331 (e.g., "facial recognition") with the type of SNS media (e.g., "photo"), and determines whether or not to register and synchronize the credential information.

[0043] (Application Server 103) The application server 103 includes an authentication level management unit 340, an authentication processing unit 341, and a credential registration processing unit 342. The authentication level management unit 340 maintains the recommended authentication level when using the services provided by the application server 103. The authentication level management unit 340 also provides a function to transmit the authentication level to the authentication terminals 101 and 102.

[0044] Table 5 shows an example of an authentication level information table for authenticators maintained by the authentication level management unit 340. [Table 5] As shown in Table 5, the authentication level information includes the service name, service URL, and the authentication level, which is the security level of the authenticator as defined by FIDO.

[0045] The authentication processing unit 341 provides a function to request the credential information management server 105 to obtain information about users who use the services provided by the application server 103. The authentication processing unit 341 obtains the user authentication result from the credential information management server 105. In this embodiment, OpenID Connect is used for user authentication, but it is not limited to this, and other authentication methods such as HTTP authentication (Basic authentication / Digest authentication) may also be used.

[0046] The credential registration processing unit 342 receives credential registration requests from authentication terminals 101 and 102 and provides the function of sending credential registration requests to the authentication server 104. The credential registration processing unit 342 also receives credential registration results from authentication terminals 101 and 102 and provides the function of sending a request to the authentication server 104 to verify the credential registration results.

[0047] (Authentication Server 104) The authentication server 104 includes an authentication request management unit 350 and a public key management unit 351. The authentication request management unit 350 receives a request to create credential information sent from the application server 103 and provides a function to send a challenge and a recommended authentication level for credential registration. The recommended authentication level is obtained by sending a request to the application server 103 to obtain the recommended authentication level. In addition, the authentication request management unit 350 provides a function to verify the results of the credential information creation sent from the authentication terminals 101 and 102 and send the creation results to the application server 103. Furthermore, the authentication request management unit 350 provides a function to send a request to the public key management unit 351 to save the public key information included in the results of the credential information creation.

[0048] The public key management unit 351 receives a public key storage request sent from the authentication request management unit 350 and provides a function to store the public key. Table 6 shows an example of a public key table managed by the public key management unit 351. [Table 6] As shown in Table 6, the public key record in the public key table contains the authentication information ID and the public key.

[0049] (Credential information management server 105) The credential information management server 105 comprises a credential information management unit 360, a credential synchronization control unit 361, a user management unit 362, and an SNS information management unit 363. The credential information management unit 360 receives credential information registration requests from authentication terminals 101 and 102 and stores the credential information. In addition, the credential information management unit 360 receives requests from authentication terminals 101 and 102 to send URLs associated with the credential information and provides a function to send URLs of the credential information associated with users using authentication terminals 101 and 102 in bulk.

[0050] Table 7 shows an example of a credential information table maintained by the credential information management unit 360. [Table 7] As shown in Table 7, the credential information records in the credential information table include the authentication information ID, private key, user ID, and service URL.

[0051] The credential synchronization control unit 361 receives credential information synchronization requests from authentication terminals 101 and 102 and provides the function of transmitting credential information associated with users using authentication terminals 101 and 102 to authentication terminals 101 and 102.

[0052] The user management unit 362 provides a function to store user information of users who use the authentication terminals 101 and 102. The user management unit 362 also receives user authentication requests from the application server 103, performs user authentication processing, and issues token information for using the application server 103. Furthermore, when using the function to synchronize credential information provided by the credential information management server 105, the user management unit 362 provides a function to authenticate users who use the credential information management server 105. In this embodiment, authentication using the HTTP authentication (Basic authentication / Digest authentication) method is employed, but it is not limited to this, and other authentication methods such as OpenID Connect may also be used.

[0053] Table 8 shows an example of a user information table maintained by the user management unit 362. [Table 8] As shown in Table 8, the user information records in the user information table include the user ID and password.

[0054] The SNS Information Management Unit 363 manages URL information for popular social networking services (SNS). By cross-referencing this information with the credential information table managed by the Credential Information Management Unit 360, the SNS Information Management Unit 363 can obtain information about the SNS that a user is using. Furthermore, the SNS Information Management Unit 363 also manages information about the types of media uploaded to each SNS. In addition, the SNS Information Management Unit 363 transmits SNS usage information for each user to authentication terminals 101 and 102.

[0055] Table 9 shows an example of an SNS information table maintained by the SNS Information Management Department 363. [Table 9] As shown in Table 9, the SNS information records in the SNS information table include the user ID, service name, service URL, and media type.

[0056] <User Authentication Process> The user authentication process will be explained using Figure 5. In order to register the credential information associated with users using authentication terminals 101 and 102, it is necessary to verify whether the user is registered with the service. This process uses the authentication information of users using the credential information management server 105 to authenticate the service provided by the application server 103.

[0057] Figure 5 is a sequence diagram illustrating the processes of the authentication terminal 101, application server 103, and credential information management server 105 in the user authentication process of the first embodiment. Here, the authentication terminal 101 is used as an example of an authentication terminal for explanation, but the same applies to other authentication terminals (such as authentication terminal 102). In this figure, the processing of the authentication terminal 101 is achieved by the CPU 201 of the authentication terminal 101 reading a program stored in the HDD 203 into memory 202 and executing it. The processing of the application server 103 and the credential information management server 105 is achieved by the CPU 210 of each server reading a program stored in the HDD 212 into memory 211 and executing it.

[0058] When the user authentication process begins, in S501, the browser 310 of the authentication terminal 101 sends a login request to the application server 103. Upon receiving this request, the application server 103 proceeds to S502.

[0059] In S502, the authentication processing unit 341 of the application server 103 creates and stores a nonce (number used once) associated with the session. A nonce is a one-time random character used during encrypted communication. A specific example would be "1 999 888 777 666 555 444".

[0060] Next, in S503, the authentication processing unit 341 of the application server 103 sends an access request to the credential information management server 105 to the authentication terminal 101. For example, it adds a callback URL (set to the application server 103 itself) and the nonce created in S502 above as parameters, and redirects to the credential information management server 105. In response, the browser 310 of the authentication terminal 101 redirects to the credential information management server 105, and the authentication screen (not shown) of the credential information management server 105 is displayed in the browser 310. When the authentication information of the user using the authentication terminal 101 (explained here as user ID and password) is entered on this authentication screen and authentication is instructed to be performed, the browser 310 of the authentication terminal 101 proceeds to S504.

[0061] In S504, the browser 310 of the authentication terminal 101 sends an authentication request to the credential information management server 105. This authentication request includes the user ID and password of the user using the authentication terminal 101. Here, we will assume that the user ID is "user001" and the password is "userpass1". When the credential information management server 105 receives the above authentication request, it proceeds to process S505.

[0062] In S505, the user management unit 362 of the credential information management server 105 verifies the user ID and password included in the authentication request received from the authentication terminal 101. If this combination of user ID and password exists in a user information table like Table 10 held by the user management unit 362 (i.e., verification is successful), the user management unit 362 saves the nonce that was assigned as a parameter associated with the session and proceeds to S506.

[0063] Table 10 shows an example of a nonsense information table maintained by the user management unit 362. [Table 10] As shown in Table 10, the nonce information record in the nonce information table contains the session ID, which is the session identifier, and the nonce.

[0064] In S506, the user management unit 362 of the credential information management server 105 sends an authorization code to the authentication terminal 101. For example, the authorization code is attached as a parameter, and the terminal is redirected to the application server 103, which is set as the callback URL. In response, the authentication terminal 101 proceeds to S507. The authorization code is a time-limited token issued from the authorization endpoint, and a specific example is "dd1231FBC3123a987=".

[0065] In S507, the browser 310 of the authentication terminal 101 sends an authorization code to the application server 103. Upon receiving this authorization code, the application server 103 proceeds to S508.

[0066] In S508, the authentication processing unit 341 of the application server 103 sends a request to the credential information management server 105 for the acquisition of an ID token and a nonce, along with an authorization code. An ID token is a token defined in OpenID Connect that proves that the user who requested the issuance has been authenticated.

[0067] Now, let's explain ID tokens. An ID token consists of a header, payload, and signature, in that order. Note that it may not include a signature. The following are specific examples of ID tokens, but they are not exhaustive.

[0068] (Header) { “typ”: “assertion”, “alg”: “ES256”, “kid”: “aaaaaaaa-bbbb-1111-8888-999999999999” } (payload) { “response_type”: “id_token”, “redirect_url”: “http: / / example_srv.com / customer”, “iss”: “ODBIMWUwasdasd123UUUMXw”, “sub”: “dXIIMM123KKllss”, “iat”: 1903144999, “exp”: 1903149999 } (signature)

[0069] When the credential information management server 105 receives the request to obtain the above ID token and nonce, it proceeds to process S509. In S509, the user management unit 362 of the credential information management server 105 sends the ID token and the nonce from S505 to the application server 103. For example, it sends an ID token including the nonce. When the application server 103 receives the ID token and nonce, it proceeds to S510.

[0070] In S510, the authentication processing unit 341 of the application server 103 verifies the ID token and nonce. For example, in nonce verification, it verifies whether it matches the nonce issued and stored in S502 in association with the session. If the nonce verification is successful, the authentication processing unit 341 deletes the nonce stored in S502. The authentication processing unit 341 determines that authentication is successful if the verification of the ID token and nonce is successful, and that authentication is unsuccessful if these verifications fail. Next, in S511, the authentication processing unit 341 of the application server 103 sends the authentication result to the authentication terminal 101 and terminates the process.

[0071] Note that the user authentication process is not limited to the example shown in this embodiment. For example, authentication may be performed directly to the application server 103 using the user ID and password for using the application server 103, or authentication may be performed using FIDO with the credential information for using the application server 103 and biometric information stored in the authentication terminals 101 and 102 in advance.

[0072] <Credential Information Registration Process> The credential information registration process will be explained using Figure 6. The credential information registration process registers the credential information associated with users using the credential information management server 105 with the credential information management server 105, and registers the public key associated with the credential information with the authentication server 104. This process can only be executed if the user authentication process is successful.

[0073] Figure 6 is a sequence diagram showing the processes of the authentication terminal 101, application server 103, authentication server 104, and credential information management server 105 in the credential information registration process of the first embodiment. In this figure, the process of the authentication terminal 101 is realized by the CPU 201 of the authentication terminal 101 reading the program stored in the HDD 203 into memory 202 and executing it. The processes of the application server 103, authentication server 104, and credential information management server 105 are realized by the CPU 210 of each server reading the program stored in the HDD 212 into memory 211 and executing it.

[0074] When the credential information registration process begins, in S601, the browser 310 of the authentication terminal 101 sends a request to the application server 103 to create credential information for the user using the authentication terminal 101. Upon receiving this credential information creation request, the application server 103 proceeds to S602.

[0075] In S602, the credential registration processing unit 342 of the application server 104 sends a credential information creation request to the authentication server 104. Upon receiving the credential information creation request, the authentication server 104 proceeds to S603.

[0076] In S603, the authentication request management unit 350 of the authentication server 104 sends an authentication level acquisition request to the application 104. Upon receiving the authentication level acquisition request, the application 104 proceeds to process S604.

[0077] In S604, the authentication level management unit 340 of the application server 104 sends the authentication level to the authentication server 104. Upon receiving the authentication level, the authentication server 104 proceeds to S605.

[0078] In S605, the authentication request management unit 350 of the authentication server 104 sends a credential information registration request to the authentication terminal 101, along with the authentication level and challenge. The following are specific examples of requests included in the credential information registration sent from the authentication request management unit 350, but are not limited to these.

[0079] { challenge: “ASD123tre12312FE”, medicalLevel: “L2”, rp: { name: “AdminPage”, id: “https: / / example_srv.com / admin”, User: { id: “user001”, name: “user001”, displayName: “user001”, }, pubKeyCredParams: [ {alg: -7, type: “public-key”}, {alg: -257, type: “public-key”}], AuthenticatorSelection: { authenticatorAttachment: “platform”, requireResidentKey: true, } } }

[0080] When the authentication terminal 101 receives the authentication level, challenge, and credential information registration request, it proceeds to process S606. In S606, the registration / synchronization determination unit 334 of the authentication terminal 101 sends a request to the credential information management server 105 to acquire SNS information. Upon receiving the request to acquire SNS information, the credential information management server 105 proceeds to S607.

[0081] In S607, the SNS information management unit 363 of the credential information management server 105 sends the SNS information used by the user to the authentication terminal 101. An example of SNS information is shown below. { ServiceName: “ServiceA”, ServiceURL: “https: / / example_srv.com / servicea”, Type of Media: “Photo” } The example of SNS information above shows that a user is using an SNS with the service name "ServiceA" and the service URL "https: / / example_srv.com / servicea", and that the type of media uploaded to this SNS is "photos".

[0082] When authentication terminal 101 receives SNS information used by the user, it proceeds to process it with S608. In S608, the registration / synchronization determination unit 334 of the authentication terminal 101 performs a credential creation determination process using the received SNS information and authentication level. Details of this process will be explained in Figure 7 below. If this credential creation determination process determines to "stop registering credential information," the process in Figure 6 is terminated. On the other hand, if it determines to "register credential information," the process proceeds to S609.

[0083] In S609, the authentication terminal 101 acquires the biometric information of the user using the authentication terminal 101. Specifically, the authentication client 320 of the authentication terminal 101 sends a biometric information acquisition request to the biometric authentication processing unit 331. Upon receiving the biometric information acquisition request, the biometric authentication processing unit 331 waits until the user's biometric information is input from the biometric information sensor 209. Once the user's biometric information is input, the biometric authentication processing unit 331 acquires the feature quantities of the input biometric information. The feature quantities of biometric information are values ​​obtained by converting something unique to each individual, such as a fingerprint pattern, iris pattern, or vein shape, into values ​​that do not impair uniqueness. Biometric authentication is the process of identifying an individual using these unique feature quantities. It is desirable that the biometric information transmitted in this process be encrypted using a known encryption technology so that only the authenticator 103 can decrypt it.

[0084] Next, in S610, the biometric authentication processing unit 331 of the authentication terminal 101 performs the authentication process. Specifically, the biometric authentication processing unit 331 of the authentication terminal 101 sends a request to the biometric information management unit 333 to confirm that the biometric information acquired in S609 has been registered. If the biometric authentication processing unit 331 receives confirmation from the biometric information management unit 333 that the biometric information has already been registered, it determines that the authentication was successful; otherwise, it determines that the authentication failed and terminates the process.

[0085] If the biometric authentication process in S610 is successful, the biometric authentication processing unit 331 of the authentication terminal 102 proceeds to process S611. In S611, the biometric authentication processing unit 331 of the authentication terminal 101 creates credential information including a private key and a public key pair and sends a request to the credential information storage unit 332 to store it. When the credential information storage unit 332 receives the request to store the credential information, it stores the credential information. Table 12 shows an example of a credential information table after the credential information has been created. [Table 11]

[0086] Next, in S612, the authentication client 320 of the authentication terminal 101 sends the result of creating the credential information to the authentication server 104. The following is a specific example of the result of creating the credential information to be sent to the authentication server 104, but it is not limited to this example.

[0087] { “id”: “asda13123fdcccc9786546”, “rawId”: “10004”, “response”: { “clientDataJson”: { “type”: “webauthn.create”, “challenge”: “NKX1239887823ASd”, “origin”: “https: / / device101.me”, “crossOrigin”: false }, “attestationObject”: { “aaguid”: 0000000-0000-0000-0000-000000000000, “credentialId”: “10004”, “credentialPublicKey”: {"kty": "RSA", “alg”: “ECDSA_alg_sha256”, “crv”: p-256, “x”: “1aasdaVERSSDfs / werwcsdfsdf”, “y”: “oisdfsdbfsbdhs / easdas,casdasd” } }, “authenticatorAttachment”: “platform”, “type”: “public-key” }

[0088] The resulting credential information includes the challenge received in S605 and the public key created in 611, and is signed with the private key for the attestation. The attestation private key is a key corresponding to the model of the authentication terminal 101 and is pre-stored in the authentication terminal 101.

[0089] Upon receiving the above credential information creation result, the authentication server 104 proceeds to process S613. In S613, the authentication request management unit 350 of the authentication server 104 verifies the signature to the challenge included in the credential information creation result. If the verification is successful, it obtains the public key included in the credential information creation result, sends a public key storage request to the public key management unit 351, and stores the public key. On the other hand, if the verification fails, it notifies the authentication terminal 101 via the application server 103 that the challenge verification failed, and terminates this process.

[0090] Table 12 shows an example of a public key table managed by the public key management unit 351 after public key registration. [Table 12]

[0091] Next, in S614, the authentication request management unit 350 of the authentication server 104 sends the result of creating the credential information to the application server 103. Upon receiving the result of creating the credential information, the application server 103 proceeds to S615.

[0092] In S615, the credential registration processing unit 342 of the application server 103 sends the result of creating the credential information to the authentication terminal 101. Upon receiving the result of creating the credential information, the authentication terminal 101 proceeds to S616.

[0093] In S616, the authentication client 320 of the authentication terminal 101 sends a request to retrieve the credential information registered in the credential storage unit 332, and sends the retrieved credential information to the credential information management server 105. This communication uses known encrypted communication such as SSL (Secure Sockets Layer). When the credential information management server 105 receives the credential information, it proceeds to processing in S617.

[0094] In S617, the credential information management unit 360 of the credential information management server 105 stores the credential information. Table 13 shows an example of a registered credential information table in the credential information management unit 360 of the credential information management server 105. [Table 13]

[0095] Furthermore, in step S617 above, the credential information management server 105 sends the credential information registration result to the authentication terminal 101 and terminates this process. In other words, in the credential creation decision process of S608, if the registration conditions are met and it is determined to "register credential information," then the credential information can be registered. Details are explained in Figure 7.

[0096] <Credential creation decision process> The credential creation decision process executed by the authentication client 320 of the authentication terminal 101 at S608 in Figure 6 above will be explained with reference to Figure 7. Figure 7 is a flowchart showing an example of the credential creation decision process in the first embodiment. This process is performed in the credential information registration process to determine whether to create credential information. This process is realized by the CPU 201 of the authentication terminal 101 reading the program stored in the HDD 203 into the memory 202 and executing it.

[0097] First, when the credential creation determination process is started, in S701, the registration / synchronization determination unit 334 of the authentication terminal 101 examines the SNS information received in S607 in Figure 6 and determines whether or not this user has used SNS. If SNS is not used (the answer is NO in S701), the registration / synchronization determination unit 334 decides to "register credential information" and terminates the processing in this flowchart. In this case, the processing from S609 onwards in Figure 6 is performed.

[0098] On the other hand, if SNS is used (if YES in S701), the registration / synchronization determination unit 334 proceeds to S702. In S702, the registration / synchronization determination unit 334 compares the authentication method of the authenticator 330 of the authentication terminal 101 with the type of SNS media indicated by the SNS information that is being used. Next, in S703, the registration / synchronization determination unit 334 determines whether the authentication method and media type of the authenticator 330 match. For example, if the authentication method is "facial recognition" and the media type is "photo," or if the authentication method is "voiceprint" and the media type is "audio," the unit determines that the authentication method and media type match if there is a predetermined correspondence between the authentication method and the media type. Note that the authentication method, media type, and their correspondence shown here are just examples and are not limited to these. Also, if there are multiple SNS information entries, the unit determines that they match if at least one matches. Furthermore, the matching conditions may be changed according to the authentication level of the service received from the authentication server 104. For example, the matching conditions may be broadened when the service authentication level is high, and narrowed when the service authentication level is low.

[0099] If no matching authentication method and media type exist (resulting in NO in S703), the registration / synchronization determination unit 334 decides to "register the credential information" and terminates the processing of this flowchart. In this case, the processing from S609 onwards in Figure 6 is performed.

[0100] On the other hand, if there is a matching authentication method and media type (if YES is found in S703), the registration / synchronization determination unit 334 proceeds to S704. In S704, the registration / synchronization determination unit 334 checks whether the authentication level received in S605 in Figure 6 exceeds a predetermined threshold. If the authentication level exceeds the threshold, meaning a stronger authentication level is required (if the answer is YES in S704), the registration / synchronization determination unit 334 proceeds to S705. At S705, the registration / synchronization determination unit 334 decides to "stop registering credential information" and terminates the processing in this flowchart. In this case, the process in Figure 6 also terminates without processing from S609 onwards.

[0101] On the other hand, if the authentication level does not exceed the threshold (if NO in S704), the registration / synchronization determination unit 334 proceeds to S706. In S706, the registration / synchronization determination unit 334 displays a screen on the touch panel 206 of the authentication terminal 101 warning that there is a possibility of authentication information being leaked on the SNS (for example, a warning screen like the one in Figure 10).

[0102] Figure 10 shows an example of a warning screen in the first embodiment. In Figure 10, warning message 1001 is a message that notifies the user that there is a possibility of authentication information being leaked on the social networking service (SNS). When the user presses the Continue button 1002 or the Cancel button 1003 on the warning screen (i.e., when the user operation to select whether or not to execute the process is accepted), the registration / synchronization determination unit 334 proceeds to S707 in Figure 7.

[0103] In S707, the registration / synchronization determination unit 334 determines whether or not the continue button 1002 has been pressed. If the user presses the "Continue" button 1002 at this point (YES in S707), the registration / synchronization determination unit 334 proceeds to S708, determines to "register the credential information," and terminates the processing in this flowchart. In this case, the processing from S609 onwards in Figure 6 is performed.

[0104] On the other hand, if the user presses the cancel button 1003 (resulting in NO in S707), the registration / synchronization determination unit 334 proceeds to S705, determines to "stop the registration of credential information," and terminates the process in this flowchart. In this case, the process in Figure 6 also terminates without processing from S609 onwards.

[0105] As described above, registration of credential information will be restricted based on the user's use of social media, etc. Alternatively, if the answer to S703 is YES, the process may proceed directly to S705. In other words, if the type of media uploaded to the SNS used by the user matches the authentication method of the authenticator, the system may decide to "warn" or "suspend registration" regardless of the authentication level.

[0106] <Credential Information Synchronization Processing> The credential information synchronization process will be explained below using Figure 8. The credential information synchronization process synchronizes the credential information registered in the application server 103 with the authentication terminal 102 of the user utilizing the credential information management server 105. This synchronization, like the registration process, enables the synchronization of credential information if the authentication method of the authentication terminal 102, which is the destination of the credential information synchronization, does not match the SNS used.

[0107] Figure 8 is a sequence diagram showing the processing of the authentication terminal 102, application server 103, and credential information management server 105 in the credential information synchronization process of the first embodiment. In this figure, the processing of the authentication terminal 102 is realized by the CPU 201 of the authentication terminal 102 reading the program stored in the HDD 203 into memory 202 and executing it. The processing of the application server 103 and the credential information management server 105 is realized by the CPU 210 of each server reading the program stored in the HDD 212 into memory 211 and executing it.

[0108] When the credential information registration process begins, in S801, the browser 310 of the authentication terminal 102 sends an authentication request to the credential information management server 105. Upon receiving this authentication request, the application server 103 proceeds to S802.

[0109] In S802, the user management unit 362 of the credential information management server 105 sends a user information acquisition request to the authentication terminal 102. Upon receiving the user information acquisition request, the authentication terminal 102 proceeds to S803.

[0110] In S803, the browser 310 of the authentication terminal 102 displays the authentication screen (not shown) of the credential information management server 105 and accepts the user ID and password of the user using the authentication terminal 102. Upon receiving input from the user, the browser 310 of the authentication terminal 102 sends the user ID and password to the credential information management server 105. In this embodiment, the user ID is assumed to be "user002" and the password is assumed to be "userpass2". Upon receiving the user ID and password, the credential information management server 105 proceeds to S804.

[0111] In S804, the user management unit 362 of the credential information management server 105 performs verification of user information (user ID and password). If the matching user ID and password combination exists in the user information table, the authentication result is set to authentication success; otherwise, the authentication result is set to authentication failure.

[0112] Next, at S805, the user management unit 362 of the credential information management server 105 sends the verification result to the authentication terminal 102. Upon receiving the verification result, the authentication terminal 102 continues the process if the authentication result is successful, and terminates the process shown in Figure 8 if the authentication fails.

[0113] Next, in S806, the authentication terminal 102 sends a request to the credential information management server 105 to retrieve information about services provided by the application server 103, which is associated with the credential information to be synchronized and linked to the successfully authenticated user. Upon receiving this request, the credential information management server 105 proceeds to S807.

[0114] In S807, the credential synchronization control unit 361 of the credential information management server 105 sends a request to the credential information management unit 360 to obtain information about the application server associated with the credential information to be synchronized, which is linked to the authenticated user, and obtains it. The credential synchronization control unit 361 then sends the URLs of the services (service URLs) provided by the application server 103 that it has obtained to the authentication terminal 102 in a batch.

[0115] An example of a response sent from the credential synchronization control unit 361 is shown below. {"services": [“https: / / example_srv.com / customer”, “https: / / example_srv.com / distributor”, “https: / / example_srv.com / admin”] }

[0116] Furthermore, in S808, the SNS information management unit 363 of the credential information management server 105 transmits the SNS usage information used by the user who successfully authenticated to the authentication terminal 102. When authentication terminal 102 receives the service URL and SNS usage information sent in bulk, it proceeds to process S811.

[0117] In S811, the authentication client 320 of the authentication terminal 102 performs a credential synchronization determination process. Details of this process are explained in Figure 9 below. If this credential synchronization determination process determines to "synchronize the credential information," the process proceeds to S812. On the other hand, if it determines to "stop synchronizing the credential information," the process shown in Figure 8 is terminated.

[0118] In S812, the authentication client 320 of the authentication terminal 102 sends a request to the credential information management server 105 to retrieve the user's credential information associated with the service. Upon receiving this request, the credential information management server 105 proceeds to S813.

[0119] In S813, the credential synchronization control unit 361 of the credential information management server 105 obtains the user's credential information associated with the service specified in the acquisition request from the credential information management unit 360. Furthermore, the credential synchronization control unit 361 transmits the user's credential information associated with the service specified in the acquisition request to the authentication terminal 102. Upon receiving the credential information, the authentication terminal 102 proceeds to S814.

[0120] In S814, the authentication client 320 of the authentication terminal 102 sends a request to register credential information to the credential information storage unit 332, and registers the credential information.

[0121] <Credential synchronization determination process> The credential synchronization determination process performed by the registration / synchronization determination unit 334 of the authentication terminal 102 at S811 in Figure 8 above will be explained with reference to Figure 9. Figure 9 is a flowchart showing an example of the credential synchronization determination process in the first embodiment. This process is performed to determine the synchronization of credential information in the credential information synchronization process. This process is realized by the CPU 201 of the authentication terminal 101 reading the program stored in the HDD 203 into the memory 202 and executing it.

[0122] First, when the credential synchronization determination process is started, at S901, the registration / synchronization determination unit 334 of the authentication terminal 101 examines the SNS usage information received at S808 in Figure 8, and at S805 in Figure 8, determines whether or not the user who successfully authenticated has used SNS. If SNS is not used (the answer is NO in S901), the registration / synchronization determination unit 334 determines in S907 to "synchronize credential information" and terminates the processing of this flowchart. In this case, the processing from S812 onwards in Figure 8 is performed.

[0123] On the other hand, if SNS is used (if YES in S901), the registration / synchronization determination unit 334 proceeds to S902. In S902, the registration / synchronization determination unit 334 compares the authentication method of the authentication terminal 102 with the type of SNS media used as described above. Next, in S903, the registration / synchronization determination unit 334 determines whether the authentication method and media type match. For example, if the authentication method is "facial recognition" and the media type is "photo," or if the authentication method is "voiceprint" and the media type is "audio," the unit determines that the authentication method and media type match if there is a predetermined correspondence between the authentication method and media type. Note that the authentication method, media type, and their correspondence shown here are just examples and are not limited to these. Also, if there are multiple SNS information entries, the unit determines that they match if at least one of them matches.

[0124] If the authentication method and media type do not match (resulting in NO in S903), the registration / synchronization determination unit 334 determines in S907 to "synchronize credential information" and terminates the processing of this flowchart. In this case, the processing from S812 onwards in Figure 8 is performed.

[0125] On the other hand, if the authentication method and media type match (if the answer is YES in S903), the registration / synchronization determination unit 334 proceeds to S904. In S904, the registration / synchronization determination unit 334 displays a screen on the touch panel 206 of the authentication terminal 101 warning the user about the synchronization of credential information. This warning screen is the same as in Figure 10 and is therefore omitted.

[0126] On this warning screen, if the user presses the "Continue" or "Cancel" button, the registration / synchronization determination unit 334 proceeds to process S905. In S905, the registration / synchronization determination unit 334 determines whether or not the "Continue" button has been pressed. If the user presses the "Continue" button at this point (YES in S905), the registration / synchronization determination unit 334 determines in S907 to "synchronize the credential information" and terminates the processing of this flowchart. In this case, the processing from S812 onwards in Figure 8 is performed.

[0127] On the other hand, if the user presses the cancel button (resulting in NO at S905), the registration / synchronization determination unit 334 proceeds to S906, determines to "stop the synchronization of credential information," and terminates the processing of this flowchart. In this case, the process from S812 onwards in Figure 8 is not processed and the process terminates. Furthermore, depending on the authentication level of the URL in the service information list received by S807 in Figure 8 (for example, if the authentication level of the URL exceeds a predetermined threshold), it may be decided to "stop synchronization" without issuing a warning. On the other hand, if the authentication level of the URL does not exceed the threshold, a warning may be issued.

[0128] As described above, in the first embodiment, when the type of SNS media used by the user matches the authentication method of the authentication terminal, the risk of credential leakage in multi-device FIDO credentials can be reduced by restricting the registration and synchronization of credential information.

[0129] [Second Embodiment] In the second embodiment, a configuration for synchronizing credential information between authentication terminals will be described. In particular, a configuration that restricts the synchronization of credential information performed between authentication terminals according to the SNS usage information provided by the credential information management server, the authentication method of the authentication terminal, and the authentication strength required by the application server will be described.

[0130] <System Configuration> Figure 11 is a diagram illustrating the overall configuration of the system in a second embodiment of the present invention. In Figure 11, the authentication terminal 101, application server 103, authentication server 104, and credential information management server 105 are the same as in the system configuration of the first embodiment, so their explanation is omitted.

[0131] In Figure 11, 1101 is an authentication terminal. The authentication terminal 1101 sends a request to the application server 103 to create credential information and obtains challenge and recommended authentication level information from the authentication server 104. The authentication terminal 1101 then sends the registration result of the credential information to the authentication server 104. The authentication terminal 1101 also sends a request to the credential information management server 1102 to register the credential information and obtains the registration result from the credential information management server 1102. In addition, the authentication terminal 1101 sends a credential information synchronization request to the credential information management server 1102 and obtains the registered credential information. When sending a synchronization request, the authentication terminal 1101 must perform an authentication request to the credential information management server 1102 and succeed in authentication. Furthermore, the authentication terminal 1101 sends a request to the application server 103 to obtain recommended authentication level information and obtains the recommended authentication level information from the application server 103.

[0132] The credential information management server 1102 manages credential information. When it receives a request from the authentication terminal 1101 to register credential information, it registers the credential information in the credential information management server 1102 and sends the credential information registration result to the authentication terminal 1101. In addition, when the credential information management server 1102 receives a request from the authentication terminal 1101 to synchronize credential information, it sends the credential information to the authentication terminal 1101. Furthermore, when using this synchronization function, the credential information management server 1102 requires authentication of the user using the authentication terminal 1101 and provides the authentication function to the authentication terminal 1101.

[0133] The authorization terminal 1101 is connected to the global network 108 via the local network 107. Furthermore, authentication terminals 101 and 1101, application server 103, authentication server 104, credential information management server 105, and credential information management server 1102 are connected to each other via the global network 108.

[0134] <Hardware configuration of authentication terminal and server> Regarding the hardware configuration of the authentication terminal, the CPU, memory, hard disk drive (HDD), system bus, UI control unit, input device, network control unit, TPM, and biometric information sensor are the same as in the first embodiment and are therefore omitted. In the second embodiment, authentication terminals 101 and 1101 are each equipped with a proximity communication interface in addition to the above configuration. This proximity communication interface is a network interface for proximity communication such as NFC (Near Field Communication) or Bluetooth®. Authentication terminals 101 and 1101 communicate and exchange data using this proximity communication interface. Furthermore, in addition to the above configuration, authentication terminals 101 and 1101 are equipped with a camera and an image processing unit that processes input from the camera.

[0135] Note that the hardware configurations of the information processing devices comprising the application server 103, authentication server 104, and credential information management server 105 are the same as those in the first embodiment and are therefore omitted.

[0136] <Functional Configuration> Figure 12 is a block diagram showing an example of the functional configuration of authentication terminals 101, 1101, application server 103, authentication server 104, and credential information management servers 105, 1102 in the second embodiment, and components identical to those in Figure 3 are denoted by the same reference numerals.

[0137] The authentication terminals 101 and 1101 each include a browser 1210, an authentication client 1220, an image processing unit 1230, and an authenticator 330. In addition to the functions provided by the browser 310 in the first embodiment, the browser 1210 also provides the function of receiving an authentication terminal request from the authentication client 1220 and displaying a QR code (registered trademark). Here, it is described as a QR code, but other two-dimensional codes, barcodes, or other types of codes may also be used.

[0138] In addition to the functions provided by the authentication client 320 of the first embodiment, the authentication client 1220 provides a function to control the synchronization of credential information between authentication terminals. Furthermore, the authentication client 1120 provides a function to transmit the authentication level of the authentication terminal it is operating on when it receives an authentication level acquisition request sent from another authentication terminal.

[0139] The image processing unit 1230 provides a function for analyzing image information input by the user. In particular, in this embodiment, the image processing unit 1230 acquires and analyzes a QR code input by the user from the camera installed in the authentication terminal. Furthermore, if the image processing unit 1230 determines from the results of the analysis that it is a request for credential information synchronization processing, it sends a request for credential information synchronization processing to the authentication client 1220. The credential information synchronization processing is shown in Figure 13, which will be described later. Note that the authenticator 330, biometric authentication processing unit 331, credential information storage unit 332, and biometric information management unit 33 have the same configuration as in the first embodiment and are therefore omitted from this description.

[0140] Here, we will illustrate the credential information held by the credential information storage unit 332 of authentication terminals 101 and 102, and the biometric information table held by the biometric information management unit 333 of authentication terminals 101 and 1101.

[0141] Table 14 shows an example of a credential information table held by the credential information storage unit 332 of the authentication terminal 101. [Table 14] Table 15 shows an example of a credential information table held by the credential information storage unit 332 of the authentication terminal 1101. This corresponds to the state where no credential information has been stored yet. [Table 15]

[0142] Table 16 shows an example of a biometric information table maintained by the biometric information management unit 333 of the authentication terminal 101. [Table 16] Table 17 shows an example of a biometric information table maintained by the biometric information management unit 333 of the authentication terminal 1101. [Table 17]

[0143] The authentication level management unit 340, authentication processing unit 341, and credential registration processing unit 342 of the application server 103 have the same configuration as in the first embodiment, so they are omitted from this description. The authentication request management unit 350 and the public key management unit 351 of the authentication server 104 have the same configuration as in the first embodiment, so they are omitted here. The credential information management unit 360, credential synchronization control unit 361, user management unit 362, and SNS information management unit 363 of the credential information management servers 105 and 1102 have the same configuration as in the first embodiment and are therefore omitted from this description.

[0144] Here, we will illustrate the user information tables maintained by the user management unit 362 of the credential information management servers 105 and 1102. The structure of the credential information records and user information records is the same as in the first embodiment.

[0145] Table 18 shows an example of a user information table maintained by the user management unit 362 of the credential information management server 105. [Table 18] Table 19 shows an example of a user information table maintained by the user management unit 362 of the credential information management server 1102. [Table 19]

[0146] <Credential Management Server Authentication Process> The authentication process for the credential information management server will be explained using Figure 13. In this process, authentication is performed before authentication terminals 101 and 1101 perform the credential information synchronization process with credential information management servers 105 and 1102, respectively.

[0147] Figure 13 is a sequence diagram illustrating the processing of authentication terminals 101 and 1101 and credential information management servers 105 and 1102 in the credential information management server authentication process of the second embodiment. In this figure, the processing of authentication terminals 101 and 1101 is achieved by the CPU 201 of each authentication terminal reading a program stored in HDD 203 into memory 202 and executing it. The processing of credential information management servers 105 and 1102 is achieved by the CPU 210 of each credential information management server reading a program stored in HDD 212 into memory 211 and executing it.

[0148] When the credential information management server authentication process starts, in S1301, the browser 1210 of the authentication terminal sends an authentication request to the credential information management server. For example, in the case of authentication terminal 101, the request is sent to the credential information management server 105. In the case of authentication terminal 1101, the request is sent to the credential information management server 1102.

[0149] When the credential information management server receives this authentication request, it proceeds to S1302. In S1302, the user management unit 362 of the credential information management server sends a user information acquisition request to the authentication terminal. For example, in the case of credential information management server 105, the request is sent to authentication terminal 101. In the case of credential information management server 1102, the request is sent to authentication terminal 1101.

[0150] When the authentication terminal receives this user information acquisition request, it proceeds to S1303. In S1303, the authentication terminal's browser 1210 accepts input of the user ID and password of the user using the authentication terminal. After obtaining the input from the user, the authentication terminal's browser 1210 sends the acquired user ID and password to the credential information management server. For example, in the case of authentication terminal 101, the request is sent to the credential information management server 105. In the case of authentication terminal 1101, the request is sent to the credential information management server 1102. In this embodiment, for example, the user ID sent from authentication terminal 101 is "user001" and the password is "userpass1". Also, the user ID sent from authentication terminal 1101 is "user003" and the password is "userpass3".

[0151] When the credential information management server receives the user ID and password, it proceeds to process S1304. In S1304, the user management unit 362 of the credential information management server verifies the user information (the received user ID and password). For example, if the matching user ID and password combination exists in the user information table, the authentication result is set to "authentication successful"; otherwise, the authentication result is set to "authentication failed".

[0152] Next, in S1305, the user management unit 362 of the credential information management server sends the verification result to the authentication terminal and terminates this process. For example, in the case of credential information management server 105, the request is sent to the authentication terminal 101. In the case of credential information management server 1102, the request is sent to the authentication terminal 1101.

[0153] <Credential Information Synchronization Processing> The credential information synchronization process will be explained using Figure 14. In this process, the authentication terminal 1101 is synchronized with the credential information registered in the application server 103 held by the authentication terminal 101.

[0154] Figure 14 is a sequence diagram illustrating the processing of authentication terminal 101, authentication terminal 1101, and application server 103 in the credential information synchronization process of the second embodiment. In this figure, the processing of authentication terminals 101 and 1101 is achieved by the CPU 201 of each authentication terminal reading a program stored in HDD 203 into memory 202 and executing it. The processing of application server 103 is achieved by the CPU 210 of each credential information management server reading a program stored in HDD 212 into memory 211 and executing it.

[0155] When the credential information synchronization process is initiated, in S1401, the authentication client 1220 of the authentication terminal 101 sends a request to the browser 1210 to display a QR code. As a result, a QR code is displayed on the touch panel 206 of the authentication terminal 101. This QR code contains a code that requests the credential information synchronization process.

[0156] When a user reads this QR code using a camera (not shown) mounted on the authentication terminal 1001, in S1402, the image processing unit 1230 of the authentication terminal 1001 acquires the image information of the QR code entered by the user and performs analysis of the QR code. If the analysis determines that the QR code is a request for credential information synchronization processing, the authentication terminal 1101 starts communication with the authentication terminal 101, for example, using BLE (Bluetooth Low Energy). Since BLE is a well-known technology, an explanation is omitted here. Note that communication between the authentication terminal 1101 and the authentication terminal 101 is not limited to BLE, and other communication methods may be used.

[0157] Next, in S1403, the registration / synchronization determination unit 334 of the authentication terminal 1101 requests SNS usage information from the credential information management server 1102. Upon receiving this request, the credential information management server 1102 proceeds to processing in S1404.

[0158] In S1404, the SNS information management unit 363 of the credential information management server 1102 sends SNS information to the authentication terminal 1101. Upon receiving this SNS information, the authentication terminal 1101 proceeds to S1405.

[0159] In S1405, the registration / synchronization determination unit 334 of the authentication terminal 1101 transmits SNS usage information to the authentication terminal 101 via BLE. At the same time, the registration / synchronization determination unit 334 of the authentication terminal 1101 also transmits the authentication method of the authentication terminal 1101. Upon receiving this SNS usage information and authentication method, the authentication terminal 1101 proceeds to processing in S1406.

[0160] In S1406, the registration / synchronization determination unit 334 of the authentication terminal 101 executes a credential synchronization determination process. This process is the same as in Figure 9 and is therefore omitted. If this credential synchronization determination process determines to "synchronize the credential information," the process proceeds to S1407. On the other hand, if it determines to "stop synchronizing the credential information," the process in Figure 14 is terminated.

[0161] In S1407, the authentication client 1220 of the authentication terminal 101 transmits credential information to the authentication terminal 1101. This communication utilizes known encrypted communication such as SSL. Upon receiving this credential information, the authentication terminal 1001 proceeds to S1408.

[0162] In S1408, the authentication client 1220 of the authentication terminal 1101 sends a request to the credential information storage unit 332 to save the credential information received in 1407, and saves the credential information in the credential information storage unit 332.

[0163] Table 20 shows an example of the credential information table in the credential information storage unit 332 of the authentication terminal 1101 after credential information synchronization in this process. [Table 20]

[0164] As described above, in the second embodiment, when the type of SNS media used by the user matches the authentication method of the authentication terminal, the risk of credential leakage in multi-device FIDO credentials can be reduced by restricting the synchronization of credential information performed between authentication terminals.

[0165] [Third Embodiment] In the third embodiment, we describe a configuration that proposes an authentication method with stronger authentication strength, in addition to issuing a warning, when there is a risk of leakage of authentication information.

[0166] <System Configuration> The system configuration is the same as in the first embodiment, so we will omit the explanation. <Hardware configuration of authentication terminal and server> The hardware configuration is the same as in the first embodiment, so we will omit the explanation.

[0167] <Functional Configuration> Figure 15 is a block diagram showing an example of the functional configuration of the authentication terminals 101 and 102, application server 103, authentication server 104, and credential information management server 105 in the third embodiment, with the same reference numerals used for components identical to those in Figure 3.

[0168] Since the authorization terminals 101 and 102, the authentication server 104, and the credential information management server 105 have the same configuration as in the first embodiment, their description will be omitted. The application server 103 includes an authentication level management unit 340, an authentication processing unit 341, a credential registration processing unit 342, and an authentication method proposal unit 1501. The authentication method proposal unit 1501 manages authentication methods that have an extremely low risk of leakage on social networking services (SNS). Note that the authentication methods may be managed according to the application. When the authentication method proposal unit 1501 receives a request for an authentication method proposal from the authentication terminals 101 and 102, it transmits the authentication method to the authentication terminals 101 and 102.

[0169] <User Authentication Process> The user authentication process is the same as in the first embodiment, so we will omit its explanation.

[0170] <Credential Information Registration Process> The credential information registration process of the third embodiment will be explained with reference to Figure 16. In this process, compared with the credential information registration process in the first embodiment, a new authentication method is proposed when a warning or cessation of credential information registration is issued. Examples of authentication methods include vein authentication, iris authentication, and ear acoustic authentication.

[0171] Figure 16 is a sequence diagram showing the processes of the authentication terminal 101, application server 103, authentication server 104, and credential information management server 105 in the credential information registration process of the third embodiment. In this figure, the process of the authentication terminal 101 is realized by the CPU 201 of the authentication terminal 101 reading the program stored in the HDD 203 into memory 202 and executing it. The processes of the application server 103, authentication server 104, and credential information management server 105 are realized by the CPU 210 of each server reading the program stored in the HDD 212 into memory 211 and executing it.

[0172] The credential information registration processes S601 to S608 are the same as in the first embodiment, so their explanation will be omitted. If the result of the credential creation decision process in S608 is "Register credential information," the processes from S609 onwards in Figure 6 are performed, although this is not shown in Figure 16. On the other hand, if the result of the credential creation judgment process in S608 is a warning against registration, or "stop the registration of credential information" (i.e., if the authentication method of the authentication terminal and the type of SNS media used by the user match), the registration / synchronization judgment unit 334 of the authentication terminal 101 proceeds to S1601. In addition, in the credential creation judgment process of the third embodiment, if a warning is issued, the user operation in response to the warning may not be accepted, and the judgment result may be "warning," and the process may proceed to S1601.

[0173] In S1601, the registration / synchronization determination unit 334 requests the application server 103 to obtain the authentication method. This request includes, for example, the authentication method of the authentication terminal 101. Upon receiving this request, the application server 103 proceeds to S1602.

[0174] In S1602, the authentication method proposal unit 1501 of the application server 103 sends the managed authentication method back to the authentication terminal 101. At this time, it may perform a process to propose an authentication method with higher strength (higher authentication level) compared to the authentication method of the authentication terminal 101. Alternatively, for example, it may propose an authentication method that does not match the type of SNS media used by the user.

[0175] Upon receiving a response regarding the above authentication method, the authentication terminal proceeds to process S1603. In S1603, the registration / synchronization determination unit 334 of the authentication terminal 101 displays a screen on the touch panel 206 of the authentication terminal 101 that presents the received authentication method to the user.

[0176] <Credential Information Synchronization Processing> For the credential information synchronization process, it is conceivable to use a similar configuration to the registration process, proposing a new authentication method when a warning is issued.

[0177] As described above, according to the third embodiment, by proposing an authentication method with higher authentication strength when there is a risk of authentication information leakage, the risk of credential leakage in multi-device FIDO credentials can be reduced.

[0178] [Fourth Embodiment] In the fourth embodiment, we will describe a configuration that determines whether or not a service can be registered when the service to be registered in the multi-device FIDO credentials is an SNS. <System Configuration> Since the configuration is the same as in the first embodiment, the explanation will be omitted. <Hardware configuration of devices and information processing equipment> Since the hardware configuration is the same as in the first embodiment, we will omit the explanation. <Functional Configuration> Since the configuration is the same as in the first embodiment, the explanation will be omitted. <Credential Management Server Authentication Process> Since the configuration is the same as in the first embodiment, the explanation will be omitted.

[0179] <Credential creation decision process> The credential creation decision process of the fourth embodiment will be explained with reference to Figure 17. This process is responsible for determining the creation of credential information during the credential information registration process. If this process determines that there is a risk of biometric information leakage when attempting to register for an SNS, registration will be restricted.

[0180] Figure 17 is a flowchart showing an example of the processing of the registration / synchronization determination unit 334 of the authentication terminal 101 in the fourth embodiment. This processing is achieved by the CPU 201 of the authentication terminal 101 reading the program stored in the HDD 203 into the memory 202 and executing it.

[0181] First, when the credential creation decision process begins, in S1701, the registration / synchronization decision unit 334 of the authentication terminal 101 determines whether the service being registered is a service that poses a risk (potential) of biometric information leakage. This determination is made by comparing it with the SNS information obtained in S607 in Figure 6 and checking for any matches. If there are matches, it is determined that the service is at risk of leakage; if there are no matches, it is determined that the service is not at risk of leakage.

[0182] If the service does not pose a risk of leakage (the answer is NO in S1701), the registration / synchronization determination unit 334 decides in S1707 to "register the credential information" and terminates the processing of this flowchart. In this case, the processing from S609 onwards in Figure 6 is performed.

[0183] On the other hand, if the service is at risk of leakage (if YES in S1701), the registration / synchronization determination unit 334 proceeds to S1702. In S1702, the registration / synchronization determination unit 334 compares the authentication method of the authentication terminal 101 with the type of media for the service being registered. Next, in S1703, the registration / synchronization determination unit 334 checks whether the authentication method of the authentication terminal 101 matches the type of media of the service to be registered.

[0184] If no match is found (the result is NO in S1703), the registration / synchronization determination unit 334 decides in S1707 to "register the credential information" and terminates the processing of this flowchart. In this case, the processing from S609 onwards in Figure 6 is performed.

[0185] On the other hand, if a match exists (if YES is found in S1703), the registration / synchronization determination unit 334 proceeds to S1704. In S1704, the registration / synchronization determination unit 334 displays, on the touch panel 206 of the authentication terminal 101, a screen (for example, a warning screen as shown in FIG. 10) warning that the service to be registered has a risk of leakage of biological information. This warning screen is almost the same as that in FIG. 10 and is thus omitted.

[0186] When, on this warning screen, the user operates the continue button or the cancel button, the registration / synchronization determination unit 334 proceeds to S1705 for processing. In S1705, the registration / synchronization determination unit 334 determines whether the continue button has been operated. Here, when the user operates the continue button (YES in S1705), the registration / synchronization determination unit 334 proceeds to S1707, determines to "register credential information", and ends the processing of this flowchart. In this case, the processing after S609 in FIG. 6 is performed.

[0187] On the other hand, when the user operates the cancel button (NO in S1705), the registration / synchronization determination unit 334 proceeds to S1706, determines to "stop registering credential information", and ends the processing of this flowchart. In this case, in the processing of FIG. 6, neither the processing after S609 nor the processing is performed and the process ends.

[0188] As described above, according to the fourth embodiment, in the case where the service to be registered in the multi-device FIDO credential is an SNS, the risk of credential leakage can be reduced.

[0189] In each of the above embodiments, an example in which the authentication terminal acquires SNS information from the credential information management server 105 has been described. However, the authentication terminal may acquire SNS URL information and information on the types of media uploaded on the SNS from one or more other servers that manage the URL information of SNSs that are widespread in the world and the information on the types of media. In this case, the authentication terminal may obtain information on the SNS used by the user by matching the acquired SNS information with the service URL of the credential information corresponding to the user acquired from the credential information management server 105.

[0190] As described above, according to each embodiment, the risk of credential leakage in multi-device FIDO credentials can be reduced.

[0191] Note that the configurations of the various data described above and their contents are not limited to this, and it is needless to say that they may be configured with various configurations and contents according to the use and purpose. Although one embodiment has been described above, the present invention can be implemented in embodiments such as a system, device, method, program, or storage medium. Specifically, it may be applied to a system composed of a plurality of devices, or may be applied to a device composed of a single device. In addition, configurations combining the above embodiments are all included in the present invention.

[0192] 〔Other Embodiments〕 The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions. In addition, the present invention may be applied to a system composed of a plurality of devices or to a device composed of a single device. The present invention is not limited to the embodiments described above, and various modifications (including organic combinations of each embodiment) are possible based on the spirit of the invention, and these are not excluded from the scope of the invention. That is, all configurations that combine the above-described embodiments and their modified forms are included in the present invention.

[0193] This embodiment includes the following configurations, methods, and programs. (Composition 1) An information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, An acquisition means for acquiring information on social networking services used by users of the information processing device from the server, The module includes a control means that controls the execution of a synchronization process that uses the information acquired by the acquisition means to acquire credential information managed by the server from the server and save it to the module, The information processing apparatus is characterized in that the control means restricts the execution of the synchronization process when it determines from the information acquired by the acquisition means that the user is using a social networking service. (Configuration 2) The information on social networking services obtained by the aforementioned acquisition means includes information on the type of media uploaded to the social networking service. The information processing device according to Configuration 1, characterized in that the control means compares the media type of the social networking service used by the user, which is identified from the acquired information, with the authentication method of the module, and issues a warning if there is a predetermined correspondence between them. (Composition 3) The system includes a receiving means for receiving user input to select whether or not to perform the synchronization process in response to the aforementioned warning. The information processing apparatus according to configuration 2, characterized in that the control means switches whether or not to execute the synchronization process in response to the received user operation. (Composition 4) An information processing device having a module that can communicate with a first server that provides a service and a second server that manages credentials associated with the service and information for social networking services, and that provides a function for user authentication, A first acquisition means for acquiring information on social networking services used by users of the information processing device from the second server, The system includes a first control means that controls the execution of a registration process in which the information processing device registers the credential information associated with the service, created using the information acquired by the first acquisition means, to the second server. The information processing apparatus is characterized in that the first control means restricts the execution of the registration process when it determines from the information acquired by the first acquisition means that the user is using a social networking service. (Composition 5) The information on social networking services obtained by the first acquisition means includes information on the type of media uploaded to the social networking service. The information processing apparatus according to configuration 4, characterized in that the first control means compares the media type of the social networking service used by the user, which is identified from the acquired information, with the authentication method of the module, and restricts the execution of the registration process if there is a predetermined correspondence between them. (Composition 6) The information processing device according to configuration 5, characterized in that the first control means issues a warning when there is a predetermined correspondence between the media type of the social networking service used by the user and the authentication method of the module. (Composition 7) The system includes a receiving means for receiving user input to select whether or not to perform the synchronization process in response to the aforementioned warning. The information processing apparatus according to configuration 6, characterized in that the first control means switches whether or not to execute the registration process in response to the received user operation. (Composition 8) The system includes a second acquisition means for obtaining the authentication level of a service associated with the credential information managed by the second server, The information processing apparatus according to configuration 5, characterized in that the first control means does not execute the registration process if there is a predetermined correspondence between the media type of the social networking service used by the user and the authentication method of the module, and the acquired authentication level exceeds a predetermined authentication level. (Composition 9) A third acquisition means for acquiring information on the social networking service and authentication method of the other information processing device from another information processing device, the other information processing device acquired from the second server. The system includes a second control means that controls the execution of a synchronization process that uses the information acquired by the third acquisition means to transmit the credential information associated with the service held by the information processing device to the other information processing device, The information processing apparatus according to any one of configurations 4 to 8, characterized in that the second control means restricts the execution of the synchronization process when it is determined from the acquired information that the user is using a social networking service. (Composition 10) A fourth acquisition means that, when there is a predetermined correspondence between the media type of the social networking service used by the user and the authentication method of the module, obtains a proposal from the second server for an authentication method with a higher authentication level than the authentication method of the module, The information processing apparatus according to configuration 6, further comprising: a presentation means for presenting the authentication method acquired by the fourth acquisition means. (Composition 11) An information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, An acquisition means for acquiring information on social networking services used by users of the information processing device from the server, The system includes a control means that controls the execution of a registration process in which the information processing device registers the credential information associated with the service, created using the information acquired by the acquisition means, to the server. The information processing apparatus is characterized in that the control means restricts the execution of the registration process when it determines from the information acquired by the acquisition means that the service corresponding to the credential information to be registered in the registration process is a social networking service. (Method 1) A control method for an information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, The process of obtaining information from the server about social networking services used by users of the information processing device, The system includes a control step that controls the execution of a synchronization process that uses the information acquired in the acquisition step to acquire credential information managed by the server from the server and save it to the module, A control method for an information processing device, characterized in that, in the control step, if it is determined from the information acquired in the acquisition step that the user is using a social networking service, the execution of the synchronization process is restricted. (Method 2) A control method for an information processing device having a module that can communicate with a first server that provides a service and a second server that manages credentials associated with the service and information for social networking services, and that provides a function for user authentication, A first acquisition step involves acquiring information on social networking services used by users of the information processing device from the second server, A first control step for controlling the execution of a registration process of registering credential information associated with the service created by the information processing device in the second server by using the information acquired in the first acquisition step. In the first control step, when it is determined from the information acquired in the first acquisition step that the user is using a social networking service, the execution of the registration process is restricted. A control method for an information processing device, characterized by this. (Method 3) A second acquisition step of acquiring, from another information processing device, information on a social networking service used by a user who uses the other information processing device and information on an authentication method of the other information processing device, which the other information processing device has acquired from the second server. A second control step for controlling the execution of a synchronization process of transmitting credential information associated with the service held by the information processing device to the other information processing device by using the information acquired in the second acquisition step. In the second control step, when it is determined from the acquired information that the user who uses the other information processing device is using a social networking service, the execution of the synchronization process is restricted. The control method for an information processing device according to claim 13, characterized by this. [[ID=_{12}](Method 4) A control method for an information processing device that is communicable with a server that manages credential information associated with a service and information on a social networking service and has a module that provides a function for user authentication, An acquisition step of acquiring information on a social networking service used by a user who uses the information processing device from the server. A control step for controlling the execution of a registration process of registering credential information associated with the service created by the information processing device in the server by using the information acquired in the acquisition step. A control method for an information processing device, characterized in that, in the control step, if it is determined from the information acquired in the acquisition step that the service corresponding to the credential information to be registered in the registration process is a social networking service, the execution of the registration process is restricted. (Program 1) A program that causes a computer to execute one of the control methods for an information processing device described in one of methods 1 to 3.

Claims

1. An information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, An acquisition means for acquiring information on social networking services used by users of the information processing device from the server, The module includes a control means that controls the execution of a synchronization process that uses the information acquired by the acquisition means to acquire credential information managed by the server from the server and save it to the module, The information processing apparatus is characterized in that the control means restricts the execution of the synchronization process when it determines from the information acquired by the acquisition means that the user is using a social networking service.

2. The information on social networking services obtained by the aforementioned acquisition means includes information on the type of media uploaded to the social networking service. The information processing apparatus according to claim 1, characterized in that the control means compares the media type of the social networking service used by the user, which is identified from the acquired information, with the authentication method of the module, and issues a warning if there is a predetermined correspondence between them.

3. The system includes a receiving means for receiving user input to select whether or not to perform the synchronization process in response to the aforementioned warning. The information processing apparatus according to claim 2, characterized in that the control means switches whether or not to execute the synchronization process in response to the received user operation.

4. An information processing device having a module that can communicate with a first server that provides a service and a second server that manages credentials associated with the service and information for social networking services, and that provides a function for user authentication, A first acquisition means for acquiring information on social networking services used by users of the information processing device from the second server, The system includes a first control means that controls the execution of a registration process in which the information processing device registers the credential information associated with the service, created using the information acquired by the first acquisition means, to the second server. The information processing apparatus is characterized in that the first control means restricts the execution of the registration process when it determines from the information acquired by the first acquisition means that the user is using a social networking service.

5. The information on social networking services obtained by the first acquisition means includes information on the type of media uploaded to the social networking service. The information processing apparatus according to claim 4, characterized in that the first control means compares the media type of the social networking service used by the user, which is identified from the acquired information, with the authentication method of the module, and restricts the execution of the registration process if there is a predetermined correspondence between them.

6. The information processing apparatus according to claim 5, characterized in that the first control means issues a warning when there is a predetermined correspondence between the media type of the social networking service used by the user and the authentication method of the module.

7. The system includes a receiving means for accepting user input to select whether or not to perform the registration process in response to the aforementioned warning. The information processing apparatus according to claim 6, characterized in that the first control means switches whether or not to execute the registration process in response to the received user operation.

8. The system includes a second acquisition means for obtaining the authentication level of a service associated with the credential information managed by the second server, The information processing apparatus according to claim 5, characterized in that the first control means does not execute the registration process if there is a predetermined correspondence between the media type of the social networking service used by the user and the authentication method of the module, and the acquired authentication level exceeds a predetermined authentication level.

9. A third acquisition means for acquiring information on the social networking service and authentication method of the other information processing device from another information processing device, the other information processing device acquired from the second server. The system includes a second control means that controls the execution of a synchronization process that uses the information acquired by the third acquisition means to transmit the credential information associated with the service held by the information processing device to the other information processing device, The information processing apparatus according to any one of claims 4 to 8, characterized in that the second control means restricts the execution of the synchronization process when it determines from the acquired information that the user is using a social networking service.

10. A fourth acquisition means that, when there is a predetermined correspondence between the media type of the social networking service used by the user and the authentication method of the module, obtains a proposal for an authentication method with a higher authentication level than the authentication method of the module from the second server, The information processing apparatus according to claim 6, further comprising a presentation means for presenting the authentication method acquired by the fourth acquisition means.

11. An information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, An acquisition means for acquiring information on social networking services used by users of the information processing device from the server, The system includes a control means that controls the execution of a registration process in which the information processing device registers the credential information associated with the service, created using the information acquired by the acquisition means, to the server. The information processing apparatus is characterized in that the control means restricts the execution of the registration process when it determines from the information acquired by the acquisition means that the service corresponding to the credential information to be registered in the registration process is a social networking service.

12. A control method for an information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, The process of obtaining information from the server about social networking services used by users of the information processing device, The system includes a control step that controls the execution of a synchronization process that uses the information acquired in the acquisition step to acquire credential information managed by the server from the server and save it to the module, A control method for an information processing device, characterized in that, in the control step, if it is determined from the information acquired in the acquisition step that the user is using a social networking service, the execution of the synchronization process is restricted.

13. A control method for an information processing device having a module that can communicate with a first server that provides a service and a second server that manages credentials associated with the service and information for social networking services, and that provides a function for user authentication, A first acquisition step of acquiring information on social networking services used by users of the information processing device from the second server, The system includes a first control step which controls the execution of a registration process that registers the credential information associated with the service, created by the information processing device, to the second server using the information acquired in the first acquisition step, A control method for an information processing device, characterized in that, in the first control step, if it is determined from the information acquired in the first acquisition step that the user is using a social networking service, the execution of the registration process is restricted.

14. A second acquisition step in which the other information processing device acquires information on social networking services used by users of the other information processing device and information on the authentication method of the other information processing device, which the other information processing device has acquired from the second server. The system includes a second control step which controls the execution of a synchronization process that uses the information acquired in the second acquisition step to transmit the credential information associated with the service held by the information processing device to the other information processing device, The control method for an information processing device according to claim 13, characterized in that, in the second control step, if it is determined from the acquired information that a user of the other information processing device is using a social networking service, the execution of the synchronization process is restricted.

15. A control method for an information processing device having a module that can communicate with a server that manages credential information associated with a service and information of a social networking service, and that provides a function for user authentication, The process of obtaining information from the server about social networking services used by users of the information processing device, The system includes a control step that controls the execution of a registration process in which the information processing device registers the credential information associated with the service, created using the information acquired in the acquisition step, to the server. A control method for an information processing device, characterized in that, in the control step, if it is determined from the information acquired in the acquisition step that the service corresponding to the credential information to be registered in the registration process is a social networking service, the execution of the registration process is restricted.

16. A program for causing a computer to execute the control method for an information processing device described in any one of claims 12 to 15.