System and control method thereof
The system securely manages FIDO credentials across devices by allowing only registered terminals to access and synchronize, reducing the risk of unauthorized use.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2024-11-12
- Publication Date
- 2026-05-22
AI Technical Summary
Existing FIDO authentication systems lack a mechanism to securely synchronize credentials across multiple devices, leading to potential misuse by unauthorized third parties if credentials are leaked.
A system and method that manages credential information through a management server, allowing only registered devices to access and synchronize credentials, while denying access to unauthorized devices.
Reduces the risk of credential leakage by ensuring only authorized devices can access and synchronize FIDO credentials, thereby preventing unauthorized use.
Smart Images

Figure 2026084776000001_ABST
Abstract
Description
Technical Field
[0005] , , , , ,
[0004]
[0001] The present invention relates to a system and a control method thereof.
Background Art
[0002] There is FIDO (registered trademark) as an authentication system including biometric authentication. FIDO is an abbreviation of "Fast Identity Online". In addition, as an extended specification of credentials handled by FIDO (hereinafter referred to as "FIDO credentials"), multi-device FIDO credentials have been a topic of discussion in recent years.
[0003] FIDO performs a registration operation in advance between an authenticator such as a user's terminal at hand and an authentication server. Credentials such as a private key and a user ID are registered in the authenticator, and a public key is registered in the authentication server. Here, in the conventional FIDO, there is no specification for transmitting and storing credentials from the terminal where the credentials are registered to another terminal or server. Therefore, it has been a problem that the credentials cannot be synchronized with a terminal different from the terminal used by the user in the registration operation, and thus account recovery cannot be performed.In contrast, multi-device FIDO credentials transmit credentials from the FIDO client module of the registration terminal to the server that manages the client module during the credential registration process. This makes it possible to synchronize FIDO credentials to other terminals handled by the user. Means of synchronizing credentials include requesting the acquisition of credentials from the backup server from the terminal's FIDO client module, or transmitting credentials using BLE (Bluetooth Low Energy) terminal-to-terminal communication. [Prior art documents] [Patent Documents]
[0006] [Patent Document 1] Patent No. 6600369 [Overview of the project] [Problems that the invention aims to solve]
[0007] A user's multi-device FIDO credentials are managed in conjunction with a credential management server account on the credential management server. Now, consider a scenario where the credentials used to log in to the credential management server account are leaked. In that case, an unauthorized third party who obtains the leaked credentials could potentially log in to the credential management server account on their own device and synchronize the multi-device FIDO credentials to their device. As a result, there was a possibility that the service could be misused by an unauthorized third party.
[0008] This invention was made to solve the above-mentioned problems. The purpose of this invention is to provide a mechanism that can reduce the risk of credential leakage in multi-device FIDO credentials. [Means for solving the problem]
[0009] The present invention relates to a system including an information processing device having a first module that provides a function for user authentication and a second module that manages the storage and use of credential information for authentication, and a management system that manages credential information associated with a service, wherein the management system has a holding means that holds information of terminals already registered with the management system and information of terminals that have been refused registration with the management system, and a first control means that, in response to a registration request from an information processing device for which no information is held in the holding means, makes a permission request to the registered terminal to request a response to allow or refuse registration of the information processing device, and causes the holding means to hold information of the information processing device in accordance with the response to the permission request, wherein the second module of the information processing device has a second control means that acquires information of terminals already registered with the management system and information of terminals that have been refused registration with the management system, which are managed by the management system, and controls the process of using the acquired information to store credential information managed by the management system in the first module, wherein the second control means does not store the credential information in the first module if the information processing device is a terminal that has been refused registration. [Effects of the Invention]
[0010] According to the present invention, the risk of credential leakage in multi-device FIDO credentials can be reduced. [Brief explanation of the drawing]
[0011] [Figure 1] A diagram illustrating the overall system configuration in this embodiment. [Figure 2] A diagram illustrating the configuration of an authentication terminal, application server, authentication server, and credential information management server. [Figure 3] A diagram illustrating the modular configuration of the system in the first embodiment. [Figure 4] A diagram illustrating the sequence of login processing. [Figure 5] A diagram illustrating the sequence of the authentication terminal registration process. [Figure 6] A diagram illustrating the authentication terminal registration permission request notification screen. [Figure 7A] A flowchart illustrating the authentication terminal registration determination process of the first embodiment. [Figure 7B] A flowchart illustrating the update process of the authentication terminal registration status. [Figure 8] A diagram illustrating the sequence of the credential information synchronization process. <T [Figure 9] A flowchart illustrating the credential synchronization determination process. [Figure 10] A diagram illustrating the sequence of the credential authentication process. [Figure 11] A diagram illustrating the credential authentication determination process. [Figure 12] A diagram illustrating the module configuration of the credential information management server in the second embodiment. [Figure 13] A flowchart illustrating the authentication terminal registration determination process of the second embodiment.
Embodiments for Carrying Out the Invention
[0012] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. 〔First Embodiment〕 In this embodiment, when logging in from an authentication terminal to a credential information management server, a method of requesting authentication terminal registration permission for a registered terminal and restricting the use of credential information from an unregistered authentication terminal, and a method of restricting the synchronization of credential information to an authentication terminal with a registration failure are disclosed.
[0013] <System Configuration> FIG. 1 is a diagram illustrating the overall configuration of a system in an embodiment of the present invention. 123 is a credential information management server that manages multi-device FIDO credential information (also referred to as "passkey"). Multi-device FIDO credential information is credential information that can be used on multiple devices synchronously. Hereinafter, multi-device FIDO credential information is simply referred to as "credential information".
[0014] 111 and 112 are authentication terminals used by the user. Here, it is assumed that the authentication terminal 111 is "registered" with the credential information management server 123 in advance. The registration method may be a method in which the system administrator applies for authentication terminal registration together with the information of the authentication terminal, and the system administrator registers the authentication terminal in association with the user information, or other methods may also be used.
[0015] When the user logs in to the credential information management server 123 using the authentication terminal 112, the authentication terminal 112 starts an authentication terminal registration process for the credential information management server 123. At this time, an authentication terminal registration permission request is sent from the credential information management server 123 to the "registered" authentication terminal 111. When the user responds with permission to this authentication terminal registration permission request, the authentication terminal 112 becomes "registered", and when the user responds with rejection, the authentication terminal 112 becomes "registration failed".
[0016] In addition, the authentication terminal 112 starts a credential information synchronization process for the credential information management server 123 at an arbitrary timing after login. At this time, only when the authentication terminal 112 is not "registration failed", the authentication terminal 112 can save the credential information. Furthermore, in order to log in to the application server 121 using the acquired credential information, the authentication terminal 112 starts a credential authentication process for the application server 121. At this time, only when the authentication terminal 112 is "registered", the credential authentication process is successful. If the authentication terminal 112 is not registered, the authentication terminal 112 starts an authentication terminal registration process for the credential information management server 123.
[0017] The application server 121 is a server that provides services. In the credential authentication process, when the application server 121 receives a credential authentication request from the authentication terminal 112, it sends the credential authentication request to the authentication server 122. Also, when it receives the credential authentication result from the authentication server 122, it sends the credential authentication result to the authentication terminal 112.
[0018] In the credential authentication process, when the authentication server 122 receives a credential authentication request from the application server 121, it sends a challenge to the authentication terminal 112. Then, when the authentication server 122 receives an assertion from the authentication terminal 112, it verifies the assertion using the public key and sends the credential authentication result to the application server 121.
[0019] In the authentication terminal registration process, when the credential information management server 123 receives an authentication terminal registration request from the authentication terminal 112, it sends an authentication terminal registration permission request to the registered authentication terminal 111 only if the authentication terminal 112 is "unregistered". Furthermore, when the credential information management server 123 receives an authentication terminal registration permission result from the registered authentication terminal 111, it manages the authentication terminal 112 as "registered" or "registration denied" according to the authentication terminal registration permission result. In addition, in the credential information synchronization process, when the credential information management server 123 receives a credential information synchronization request from the authentication terminal 112, it sends credential information, registered terminal information, and registration denied terminal information to the authentication terminal 112.
[0020] 100 represents a WAN (Wide Area Network), and in this embodiment, a WWW (World Wide Web) system is built on it. 110 and 120 are LANs (Local Area Networks) that connect each component. Authentication terminals 111 and 112 are connected to WAN 100 via LAN 110. Similarly, application server 121, authentication server 122, and credential information management server 123 are connected to WAN 100 via LAN 120.
[0021] The authentication terminals 111 and 112, application server 121, authentication server 122, and credential information management server 123 may each be configured on separate LANs, or they may be configured on the same LAN. Similarly, they may be configured on the same PC (Personal Computer) or server computer.
[0022] Furthermore, although the application server 121, authentication server 122, and credential information management server 123 are depicted as a single unit in Figure 1, they may also be server systems composed of multiple servers. For example, multiple servers may be clustered together to form the application server 121. In this embodiment, when referred to as a server system, it refers to a device that provides a specific service and consists of at least one server.
[0023] <Hardware configuration of devices and information processing equipment> The data management system according to this embodiment is implemented on a system consisting of a PC configured as shown in Figure 2. Figure 2(a) is a diagram illustrating the hardware configuration of authentication terminals 111 and 112. Figure 2(b) illustrates the hardware configuration of the application server 121, authentication server 122, and credential information management server 123. The hardware block diagrams shown in Figures 2(a) and 2(b) correspond to the hardware block diagrams of a typical information processing device, and the hardware configuration of a typical information processing device can be applied to the server computer and terminal of this embodiment.
[0024] In Figure 2(a), the CPU 251 executes programs such as the OS and applications stored in the program ROM of ROM 253 or loaded into RAM 252 from the hard disk 263. Here, OS is an abbreviation for Operating System, which runs on a computer, and hereafter the operating system will be referred to as OS. The processing of each flowchart described later can be realized by the execution of such programs by the CPU 251.
[0025] RAM252 functions as the main memory, work area, etc., of CPU251. The keyboard controller (KBC) 255 controls key input from the keyboard (KB) 261 and pointing devices and touch panels (not shown). The DP controller (DPC) 256 controls the display on the display (DP) 262. Furthermore, authentication terminals 111 and 112 may be configured to include touch panels or the like that have both input device functions such as a keyboard and output device functions such as a display.
[0026] The disk controller (DKC) 257 controls data access to hard disks (HDs) 263 and floppy disks (FDs) that store various types of data. Alternatively, the system may also include other storage devices such as SSDs (Solid State Drives) or eMMCs (embedded MultiMediaCards) instead of or in conjunction with the HDD (Hard Disk Drive). The network controller (NC) 258 is connected to the network and performs communication control processing with other devices connected to the network.
[0027] The TPM (Trusted Platform Module) 259 is a tamper-proof storage device that prevents the stored data from being read from the outside, for the purpose of processing and maintaining confidential information. In this embodiment, the TPM 259 manages the biometric information itself used for authentication, or credential information such as a secret key corresponding to the biometric information.
[0028] The biometric information sensor 260 is a sensor that reads the biometric information of users using the authentication terminal. For example, it reads information such as the user's fingerprint, vein pattern, voiceprint, iris, and facial image, and converts it into a signal. This is implemented using a dedicated reader such as a fingerprint sensor, a camera, a microphone, etc.
[0029] In Figure 2(b), components identical to those in Figure 2(a) are denoted by the same reference numerals. Note that depending on the roles of the application server 121, authentication server 122, credential information management server 123, etc., a configuration without KBC255, KB261, CPC unit 256, and DP262 is also acceptable.
[0030] Furthermore, the information processing devices that comprise the application server 121, authentication server 122, and credential information management server 123 are implemented by information processing devices provided as a cloud computing service. Cloud computing includes serverless computing and virtual machines.
[0031] In cloud computing, multiple hardware resources, as shown in Figure 2(b), are utilized. Alternatively, the application server 121, authentication server 122, and credential information management server 123 may each be implemented on a single physical machine.
[0032] In all subsequent explanations, unless otherwise specified, the hardware entity responsible for execution in the server computer and authentication terminal is the CPU 251, and the software entity is the application program installed on the hard disk (HD) 261. The software entity is realized by the CPU 251 executing these programs.
[0033] <Functional Configuration> Figure 3 illustrates the module configuration of the authentication terminals 111 and 112, application server 121, authentication server 122, and credential information management server 123 in the first embodiment. Each module of the device shown in Figure 3 is realized by the CPU 251 executing a program stored in the program ROM 253 or loaded into the RAM 252 from the hard disk 263 in each device.
[0034] (Authentication terminal) The authentication terminals 111 and 112 each include an authentication client 301, a browser 302, and an authenticator 310.
[0035] The authentication client 301 provides a function to control the authentication process required when a user uses credential information. The credential information is described in the function description of the credential information storage unit 312. The authentication client 301 also provides a function to control the synchronization of credential information. In addition, the authentication client 301 provides a function to determine if the authenticator is registered and a function to notify the user of an authentication terminal registration request. In systems where FIDO is applied, the authentication client 301 corresponds to a FIDO client.
[0036] A browser (Web browser) 302 provides the functionality to interpret HTML (HyperText Markup Language), display web pages, accept user input, and send requests. The authenticator 310 comprises a biometric authentication processing unit 311, a credential information storage unit 312, and a biometric information management unit 313.
[0037] The biometric authentication processing unit 311 provides functions for requesting the user to input biometric information and for performing biometric authentication. Biometric authentication is the process of confirming that the biometric information received from the user exists in the biometric information table held by the biometric information management unit 313. The biometric information and the biometric information table are described in the function description of the biometric information management unit 313.
[0038] The credential information storage unit 312 provides the function of storing credential information for using the services provided by the application server 121. The credential information storage unit 312 also provides the function of storing information about authentication terminals registered with the credential information management server 123.
[0039] Table 1 shows an example of a credential information table held in the credential information storage unit 312 of the authentication terminal 111. [Table 1] Table 2 shows an example of a credential information table held in the credential information storage unit 312 of the authentication terminal 112. Table 2 corresponds to the state where no credential information has been saved yet. [Table 2] As shown in Tables 1 and 2, the credential information record in the credential information table includes an authentication information ID, which is an ID that uniquely identifies the authentication information, a private key, a user ID, which is an ID that uniquely identifies the user information, and a service URL, which is the URL of the service provided by the application server 121.
[0040] Table 3 shows an example of an authentication terminal management table maintained in the credential information storage unit 312 of the authentication terminal 111. [Table 3] Table 4 shows an example of an authentication terminal management table held in the credential information storage unit 312 of the authentication terminal 112. Table 4 corresponds to the state where the authentication terminal information has not yet been saved. [Table 4] As shown in Tables 3 and 4, the authentication terminal record in the authentication terminal management table includes a user ID, which is an ID that uniquely identifies the user information, registered terminal information synchronized from the credential information management server 123, and information on terminals that were not registered.
[0041] The biometric information management unit 313 manages the biometric information stored in the authenticator 310. Table 5 shows an example of a biometric information table managed by the biometric information management unit 313 when the authentication terminal 111 is activated. [Table 5] Table 6 shows an example of a biometric information table managed by the biometric information management unit 313 when the authentication terminal 112 is used. [Table 6] As shown in Tables 5 and 6, each biometric record in the biometrics table includes a user ID and a biometrics ID, which is an ID that uniquely identifies the biometric information.
[0042] (Application Server) The application server 121 includes an authentication processing unit 320. The authentication processing unit 320 provides a function to request the credential information management server 123 to obtain information about users who use the services provided by the application server 121. The authentication processing unit 320 also obtains the user authentication result from the credential information management server 123. In this embodiment, OpenID Connect is used for user authentication, but other authentication methods such as HTTP authentication (Basic authentication / Digest authentication) may also be used.
[0043] (Authentication server) The authentication server 122 includes an authentication request management unit 330 and a public key management unit 331. The authentication request management unit 330 receives credential authentication requests sent from the application server 121 and provides a function to send a challenge when credentials are used. In addition, the authentication request management unit 330 uses the public key stored in the public key management unit 331 to verify assertions sent from authentication terminals 111 and 112 and provides a function to send the verification result to the application server 121.
[0044] The public key management unit 331 provides the function of storing public keys. Table 7 shows an example of a public key table managed by the public key management unit 331. [Table 7] As shown in Table 7, the public key record in the public key table contains the authentication information ID and the public key.
[0045] (Credential information management server) The credential information management server 123 comprises a credential information management unit 340, a credential synchronization control unit 341, an authentication terminal management unit 342, and a user management unit 343.
[0046] The credential information management unit 340 provides the function of storing credential information. Table 8 shows an example of a credential information table maintained by the credential information management unit 340. [Table 8] As shown in Table 8, the credential information record in the credential information table includes the authentication information ID, private key, user ID, and service URL.
[0047] The credential synchronization control unit 341 receives credential information synchronization requests from authentication terminals 111 and 112 and provides the function of transmitting credential information associated with users using authentication terminals 111 and 112, registered terminal information, and registration NG terminal information to authentication terminals 111 and 112.
[0048] The authentication terminal management unit 342 receives an authentication terminal registration request sent from the authentication terminal 112 and provides a function to determine whether the authentication terminal 112 is "registered" or "not eligible for registration." The authentication terminal management unit 342 also provides a function to send an authentication terminal registration permission request to the registered authentication terminal 111. Furthermore, the authentication terminal management unit 342 receives the authentication terminal registration permission result from the registered authentication terminal 111 and provides a function to update the "registered terminal information" and "not eligible for registration terminal information" associated with the user using the authentication terminal 112.
[0049] The user management unit 343 provides a function to store user information for users of authentication terminals 111 and 112, as well as registered terminal information and NG terminal information associated with users. The user management unit 343 also provides a function to receive user authentication requests from the application server 121, perform user authentication processing, and issue token information for using the application server 121. Furthermore, when using the function to synchronize credential information provided by the credential information management server 123, the user management unit 343 provides a function to authenticate users using the credential information management server 123. In this embodiment, authentication using the HTTP authentication method (Basic authentication / Digest authentication) is employed, but other authentication methods such as OpenID Connect may also be used.
[0050] Table 9 shows an example of a user information table maintained by the user management unit 343. The user information records in the user information table include user ID, password, registered device information, and device information that is not permitted for registration. [Table 9]
[0051] The processing of each device shown in the sequence in Figures 4, 5, 8, 9, and 10 is realized by the CPU 251 executing a program stored in the program ROM of ROM 253 or loaded into RAM 252 from the hard disk 263 in each device.
[0052] <Login process> The user login process will be explained using Figure 4. Figure 4 illustrates the sequence of the process (login process) for logging in from the authentication terminal 112 to the credential information management server 123. This process begins when the authentication terminal 112 sends a login request to the credential information management server 123.
[0053] In S401, the browser 302 of the authentication terminal 112 sends a login request to the credential information management server 123. Upon receiving this login request, the credential information management server 123 executes the process in S402.
[0054] In S402, the user management unit 343 of the credential information management server 123 sends a user information acquisition request to the authentication terminal 112. Upon receiving this user information acquisition request, the authentication terminal 112 proceeds to S403.
[0055] In S403, the browser 302 of the authentication terminal 112 accepts the user ID and password input of the user using the authentication terminal 112. Upon receiving the user ID and password input from the user, the browser sends the entered user ID and password to the credential information management server 123. In this embodiment, the user ID is "user002" and the password is "userpass2". Upon receiving this user ID and password, the credential information management server 123 proceeds to S404.
[0056] In S404, the user management unit 343 of the credential information management server 123 performs user information verification. If a user ID and password combination matching the received user ID and password exists in the user information table, the authentication result is set to "authentication successful"; otherwise, the authentication result is set to "authentication failed". Next, in S405, the user management unit 343 of the credential information management server 123 transmits the verification result from S404 to the authentication terminal 112. Upon receiving this verification result, the authentication terminal 112 determines whether the login process was successful or unsuccessful based on the verification result.
[0057] <Authentication terminal registration process> The authentication terminal registration process will be explained using Figure 5. Figure 5 illustrates the sequence of the process (authentication terminal registration process) for registering authentication terminal 112 using the registered authentication terminal 111. This process is executed when the login process is successful or during the credential authentication process described later (for example, at S1107 in Figure 11). This process is initiated when authentication terminal 112 sends an authentication terminal registration request to the credential information management server 123.
[0058] In S406, the browser 302 of the authentication terminal 112 sends an authentication terminal registration request to the credential information management server 123. This authentication terminal registration request includes the user ID and information about the authentication terminal 112. When the credential information management server 123 receives this authentication terminal registration request, it executes the process in S407.
[0059] In S407, the authentication terminal management unit 342 of the credential information management server 123 initializes the authentication terminal registration continuation flag to "True" and then performs the authentication terminal registration determination process. The authentication terminal registration determination process will be explained in Figure 7A below. If the authentication terminal registration continuation flag becomes "False" as a result of this authentication terminal registration determination process, this authentication terminal registration process is terminated. On the other hand, if the authentication terminal registration continuation flag is "True", the process proceeds to S408 and beyond.
[0060] In S408, the authentication terminal management unit 342 of the credential information management server 123 sends an authentication terminal registration permission request to the previously registered authentication terminal 111. This authentication terminal registration permission request includes the user ID and authentication terminal 112 information included in the authentication terminal registration request received in S406. Upon receiving this authentication terminal registration permission request, the authentication terminal 111 executes the process in S409.
[0061] In S409, the authentication client 301 of the authentication terminal 111 notifies the user of the request for permission to register the authentication terminal by displaying a notification screen as shown in Figure 6 on the display 262 of the authentication terminal 111.
[0062] Figure 6 is an example of the authentication terminal registration permission request notification screen. The notification screen in Figure 6 includes information about the authentication terminal 501, an "Allow" button 502, and a "Deny" button 503. When the user presses either the "Allow" button 502 or the "Deny" button 503 on this notification screen (i.e., when the user operation to select whether to allow registration is received), the authentication client 301 of the authentication terminal 111 proceeds to S410.
[0063] In S410, the authentication client 301 of the authentication terminal 111 sends an authentication terminal registration permission result to the credential information management server 123. This authentication terminal registration permission result includes the user ID of the user using the authentication terminal 112, information about the authentication terminal 112, and the permission result based on the user's input in response to the above notification (if the "Allow" button 502 is pressed, "Allow" is selected; if the "Deny" button 503 is pressed, "Deny" is selected).
[0064] In this example, notification is given via a screen display as shown in Figure 6, but notifications may also be given by other means such as email notifications or push notifications, user operations may be accepted by other means, and the authentication terminal registration permission result may be sent to the credential information management server 123 by other means.
[0065] When the credential information management server 123 receives the authentication terminal registration permission result from S410, it proceeds to process S411. In S411, the authentication terminal management unit 342 of the credential information management server 123 performs the authentication terminal registration status update process and terminates the login process. The authentication terminal registration status update process will be explained in Figure 7B below.
[0066] <Authentication terminal registration determination process> The authentication terminal registration decision process will be explained using Figure 7A. This process corresponds to the flow in which the credential information management server 123 makes a decision on whether to register the authentication terminal in S407 of the authentication terminal registration process shown in Figure 4. This process is initiated when the credential information management server 123 receives an authentication terminal registration request from the authentication terminal 112. Figure 7A is a flowchart illustrating the authentication terminal registration determination process of the first embodiment. The process shown in this flowchart is realized by the CPU 251 of the credential information management server 123 executing a program stored in the program ROM of ROM 253 or loaded from the hard disk 263 into RAM 252.
[0067] In S601, the authentication terminal management unit 342 of the credential information management server 123 receives an authentication terminal registration request sent from the authentication terminal 112. This authentication terminal registration request includes the user ID and information about the authentication terminal 112.
[0068] Next, in S602, the authentication terminal management unit 342 obtains registration NG terminal information associated with the user ID included in the authentication terminal registration request received in S601 from the user information table (for example, a table like Table 9) held by the user management unit 343.
[0069] Next, in S603, the authentication terminal management unit 342 determines whether the registration NG terminal information obtained in S602 includes the authentication terminal 112 (i.e., the information corresponding to the authentication terminal 112 received above). If the authentication terminal 112 is included in the registration NG terminal information (if the answer is Yes in S603), the authentication terminal management unit 342 transitions the process to S608. In S608, the authentication terminal management unit 342 changes the authentication terminal registration continuation flag to "False" and terminates the authentication terminal registration determination process.
[0070] On the other hand, if the authentication terminal 112 is not included in the registration NG terminal information (i.e., the result is No in S603), the authentication terminal management unit 342 transitions the process to S604. In S604, the authentication terminal management unit 342 retrieves registered terminal information associated with the received user ID from the user information table (for example, a table like Table 9) held by the user management unit 343.
[0071] Next, in S605, the authentication terminal management unit 342 determines whether or not there is any information in the registered terminal information obtained in S604 (i.e., whether or not there is no registered terminal information). If no registered terminal information exists (if the answer is Yes in S605), the authentication terminal management unit 342 transitions the process to S608, changes the authentication terminal registration continuation flag to "False", and terminates the authentication terminal registration determination process.
[0072] On the other hand, if registered terminal information exists (in the case of No in S605), the authentication terminal management unit 342 proceeds to S606. In S606, the authentication terminal management unit 342 determines whether the registered terminal information obtained in S604 includes the authentication terminal 112 (i.e., information corresponding to the received information of the authentication terminal 112). If the registered terminal information includes the authentication terminal 112, that is, if the target authenticator is already registered (if the answer is Yes in S606), the authentication terminal management unit 342 transitions the process to S608, changes the authentication terminal registration continuation flag to "False", and terminates the authentication terminal registration determination process.
[0073] On the other hand, if the registered terminal information does not include the authentication terminal 112, that is, if the target authenticator is not registered (unregistered) (the result is No in S606), the authentication terminal management unit 342 transitions the process to S607. In S607, the authentication terminal management unit 342 sets the authentication terminal registration continuation flag to "True" and terminates the authentication terminal registration determination process.
[0074] <Update process for authentication terminal registration status> The process for updating the registration status of the authentication terminal will be explained using Figure 7B. This process is a flow performed by the credential information management server 123 in S411 of the authentication terminal registration determination process to update the authentication terminal registration status. This process is initiated when the credential information management server 123 receives the authentication terminal registration permission result from the authentication terminal 112. Figure 7B is a flowchart illustrating the process of updating the registration status of an authentication terminal. The process shown in this flowchart is achieved by the CPU 251 of the credential information management server 123 executing a program stored in the program ROM of ROM 253 or loaded from the hard disk 263 into RAM 252.
[0075] In S620, the authentication terminal management unit 342 of the credential information management server 123 receives the authentication terminal registration permission result from the authentication terminal 112. This authentication terminal registration permission result includes the user ID, information about the authentication terminal 112, and the permission result (permit / deny).
[0076] Next, in S621, the authentication terminal management unit 342 determines whether the authentication terminal registration permission result received in S620 is OK (permitted) or NG (not permitted). If the authentication terminal registration permission result is OK (permission granted) (Yes in S621), the authentication terminal management unit 342 transitions the process to S622.
[0077] In S622, the authentication terminal management unit 342 adds the information of the authentication terminal 112 (included in the authentication terminal registration request) to the registered terminal information associated with the user (the user ID included in the authentication terminal registration request received in S406 of Figure 5) in the user information table held by the user management unit 343, and then terminates the process of updating the authentication terminal registration status.
[0078] On the other hand, if the authentication terminal registration permission result is NG (not permitted) (No in S621), the authentication terminal management unit 342 transitions the process to S623. In S623, the authentication terminal management unit 342 registers the information of the authentication terminal 112 in the user information table held by the user management unit 343, in the registration NG terminal information associated with the user, and then terminates the authentication terminal registration status update process.
[0079] <Credential Information Synchronization Processing> The credential information synchronization process will be explained using Figure 8. Figure 8 illustrates the sequence of the credential information synchronization process. This process is a sequence for synchronizing credentials from the credential information management server 123 to the authentication terminal 112. This process can only be executed if the login process is successful, and can be performed at any time, such as immediately after login, at scheduled times, or after a certain period has elapsed since login, but the timing is not limited to these. This process is started when the authentication terminal 112 sends a credential information synchronization request to the credential information management server 123. In this process, credential information can only be synchronized if the authentication terminal 112 to be synchronized is not marked as "registration NG".
[0080] In S701, the authentication client 301 of the authentication terminal 112 sends a credential information synchronization request to the credential information management server 123. This credential information synchronization request includes the user ID. When the credential information management server 123 receives this credential information synchronization request, it executes the process in S702.
[0081] In S702, the credential synchronization control unit 341 of the credential information management server 123 obtains credential information associated with the user from the credential information management unit 340. The credential synchronization control unit 341 also obtains registered terminal information and registration NG terminal information associated with the user from the user management unit 343. Furthermore, the credential synchronization control unit 341 transmits the user's credential information, registered terminal information, and registration NG terminal information obtained above to the authentication terminal 112. In detail, the credential information associated with the user ID included in the credential information synchronization request received in S701 is obtained from the credential information table shown in Table 8, and the registered terminal information and registration NG terminal information associated with the above user ID are obtained from the user information table shown in Table 9, and these are sent to the authentication terminal 112. Upon receiving this information, the authentication terminal 112 proceeds to process S703.
[0082] In S703, the authentication client 301 of the authentication terminal 112 initializes the credential synchronization continuation flag to "True" and then performs the credential synchronization determination process. The credential synchronization determination process will be explained in Figure 9 below. If the credential synchronization continuation flag becomes "False" as a result of this credential synchronization determination process, this credential information synchronization process is terminated. On the other hand, if the credential synchronization continuation flag is "True", the process proceeds to S704.
[0083] In S704, the authentication client 301 of the authentication terminal 112 registers the user's credential information received in S702 into the credential information table (a table like the one in Table 2) held by the credential information storage unit 312. The authentication client 301 also registers the registered terminal information and the registration NG terminal information received in S702 into the authentication terminal management table (a table like the one in Table 4) held by the credential information storage unit 312, and then terminates the credential information synchronization process.
[0084] <Credential synchronization determination process> The credential synchronization determination process will be explained using Figure 9. This process is the flow for determining credential synchronization performed by the authentication terminal 112 in step S703 of the credential information synchronization process shown in Figure 8. This process is initiated when the authentication terminal 112 receives credential information, registered terminal information, and registration NG terminal information from the credential information management server 123. Figure 9 is a flowchart illustrating the credential synchronization determination process. The process shown in this flowchart is implemented by the CPU 251 of the authentication terminal 112 executing a program stored in the program ROM 253 or loaded from the hard disk 263 into the RAM 252.
[0085] In S801, the authentication client 301 of the authentication terminal 112 receives credential information, registered terminal information, and registration NG terminal information from the credential information management server 123.
[0086] Next, in S802, the authentication client 301 of the authentication terminal 112 obtains information about the authenticator 310 in the authentication terminal 112. Next, in S803, the authentication client 301 of the authentication terminal 112 determines whether the authentication terminal 112 is included in the registration NG terminal information received in S801.
[0087] If the authentication terminal 112 is not included in the above registration NG terminal information (i.e., the result is No in S803), the authentication client 301 of the authentication terminal 112 proceeds to S804. In S804, the authentication client 301 of the authentication terminal 112 sets the credential synchronization continuation flag to "True" and terminates the credential synchronization determination process.
[0088] On the other hand, if the above registration NG terminal information includes authentication terminal 112 (if YES in S803), the authentication client 301 of authentication terminal 112 proceeds to S805. In S805, the authentication client 301 of the authentication terminal 112 changes the credential synchronization continuation flag to "False" and terminates the credential synchronization determination process.
[0089] In the credential information synchronization process shown in Figures 8 and 9 above, the credential synchronization determination process was performed on the authentication terminal side. However, it is also acceptable to perform the credential synchronization determination process on the credential information management server 123 side. In this case, the credential synchronization control unit 341 of the credential information management server 123 will perform the same determination process as shown in Figure 9. That is, the credential synchronization control unit 341 of the credential information management server 123 will determine whether the authentication terminal 112 is included in the registration NG terminal information associated with the user. If the authentication terminal 112 is not included in the registration NG terminal information associated with the user, the credential synchronization control unit 341 will send the user's credential information, registered terminal information, and registration NG terminal information to the authentication terminal 112. On the other hand, if the authentication terminal 112 is included in the registration NG terminal information associated with the above user, the credential synchronization control unit 341 controls the transmission of the user's credential information, registered terminal information, and registration NG terminal information to the authentication terminal 112. When the authentication client 301 of the authentication terminal 112 receives credential information from the credential information management server 123, it registers the received credential information in the credential information table held by the credential information storage unit 312. The authentication client 301 also registers the registered terminal information and registration NG terminal information in the authentication terminal management table (a table like the one in Table 4) held by the credential information storage unit 312. This configuration is also acceptable.
[0090] <Credential Authentication Process> The credential authentication process will be explained using Figure 10. Figure 10 illustrates the sequence of the credential authentication process. This process is a sequence in which the authentication terminal 112 logs into the application server 121 using the credential information synchronized to the authentication terminal 112. This process can only be executed if the credential information synchronization process is successful. This process starts when the authentication terminal 112 sends a credential authentication request to the application server 121. This process makes it possible to use the credential information only if the authentication terminal 112 is "registered".
[0091] In S1001, the authentication client 301 of the authentication terminal 112 sends a credential authentication request to the application server 121. Upon receiving this credential authentication request, the application server 121 executes the process in S1002.
[0092] In S1002, the authentication processing unit 320 of the application server 121 sends a credential authentication request to the authentication server 122. Upon receiving this credential authentication request, the authentication server 122 executes the process in S1003.
[0093] In S1003, the authentication request management unit 330 of the authentication server 122 sends an assertion acquisition request along with a challenge to the authentication terminal 112. An example of a request included in the assertion acquisition request sent from the authentication request management unit 330 is as follows:
[0094] { "status": "ok", "errorMessage": "", “challenge”: “ASD123tre12312FE”, "timeout": 20000, “rpId”: “example.co.jp”, "allowCredentials": [ { “id”: “f7shfnedkfcjvdenvg5vohOFvlQ”, "type": "public-key", "transports" : { "USB", "nfc", "ble", "internal" } } ], ”userVerification”: ”required” }
[0095] When the authentication terminal 112 receives the above challenge and assertion acquisition request, it proceeds to process S1004. In S1004, the authentication client 301 of the authentication terminal 112 initializes the credential authentication continuation flag to "True" and then performs the credential authentication determination process. The credential authentication determination process will be explained in Figure 11 below. If the credential authentication continuation flag becomes "False" as a result of this credential authentication determination process, this credential authentication process is terminated. On the other hand, if the credential authentication continuation flag is "True", the process proceeds to S1005 and beyond.
[0096] In S1005, the authentication client 301 of the authentication terminal 112 performs the authentication process. The authentication client 301 sends a request to the biometric authentication processing unit 311 to acquire biometric information. Upon receiving the request, the biometric authentication processing unit 311 waits until it receives the user's biometric information. The biometric authentication processing unit 311 acquires the feature quantities of the biometric information entered by the user. The feature quantities of biometric information are values obtained by converting something unique to each individual, such as a fingerprint pattern, iris pattern, or vein shape, into values that do not impair uniqueness. Biometric authentication is the process of identifying an individual using these unique feature quantities. Furthermore, the biometric authentication processing unit 311 sends a request to the biometric information management unit 313 to confirm that the acquired biometric information is registered. If the biometric authentication processing unit 311 receives from the biometric information management unit 313 that the biometric information is already registered, it determines that authentication was successful; otherwise, it terminates the credential authentication process. It is desirable that the biometric information transmitted in this process be encrypted using a known encryption technology so that only the authentication terminal 112 can decrypt it.
[0097] If authentication is successful in S1005, the authentication client 301 of the authentication terminal 112 proceeds to S1006. In S1006, the authentication client 301 of the authentication terminal 112 creates an assertion using the challenge received in S1003. Furthermore, it obtains a private key from the credential information storage unit 312 and signs the assertion created above.
[0098] An example of assertion is as follows: { “id”: “iPe3vi-z090G1Cal-eBNSHjfL_oylWphYOB6JhWboaA”, “rawId”: “gdo89w4jkngjaveiyhyvsjnkwe”, "type": "public-key", "response": { "authenticatorData": { “rpIdHash”: “sdeihnss84hit3dss”, "flags": 2, "signCount": 0 }, "clientDataJSON": { ``type'': ``webauthn.get'', “challenge”: “ASD123tre12312FE”, “origin”: “https: / / device101.me” }, “signature”: “vgehiuw4r5ngv9suenjkwn3rfsetghb”, "userHandle": "" } }
[0099] Next, in S1007, the authentication client 301 of the authentication terminal 112 sends the signed assertion created in S1006 to the authentication server 122. When the authentication server 122 receives this assertion, it proceeds to process S1008.
[0100] In S1008, the authentication request management unit 330 of the authentication server 122 verifies whether the signature and challenge included in the assertion received in S1007 are correct. If the verification fails, the authentication request management unit 330 of the authentication server 122 determines that credential authentication has failed, and if the verification is successful, it determines that credential authentication has succeeded.
[0101] Next, in S1009, the authentication request management unit 330 of the authentication server 122 sends the credential authentication result to the application server 121. Upon receiving this credential authentication result, the application server 121 proceeds to S1010. In S1010, the authentication processing unit 320 of the application server 121 sends the credential authentication result to the authentication terminal 112. The authentication terminal 112 receives this credential authentication result.
[0102] <Credential Authentication Determination Process> The credential authentication decision process will be explained using Figure 11. This process is the flow in which the authentication terminal 112 makes a decision to continue credential authentication in S1004 of the credential authentication process. This process starts when the authentication terminal 112 receives an assertion acquisition request from the authentication server 122. Figure 11 illustrates the credential authentication decision process. This flowchart is executed by the CPU 251 of the authentication terminal 112 executing a program stored in the program ROM 253 or loaded from the hard disk 263 into the RAM 252.
[0103] In S1101, the authentication client 301 of the authentication terminal 112 receives an assertion request from the authentication server 122. This assertion request includes a user ID. Next, in S1102, the authentication client 301 of the authentication terminal 112 retrieves registration NG terminal information associated with the user from the authentication terminal management table (tables like Table 3 and Table 4) held in the credential information storage unit 312. That is, it retrieves registration NG terminal information associated with the user ID included in the assertion acquisition request received in S1101.
[0104] Next, in S1103, the authentication client 301 of the authentication terminal 112 determines whether the registration NG terminal information obtained in S1102 contains terminal information corresponding to the authentication terminal 112 (i.e., it determines whether the target authentication terminal 112 is registration NG).
[0105] If the authentication terminal 112 fails to register (if the answer is Yes in S1103), the authentication client 301 of the authentication terminal 112 proceeds to S1109. In S1109, the authentication client 301 of the authentication terminal 112 changes the credential authentication continuation flag to "False" and terminates the credential authentication decision process.
[0106] On the other hand, in S1103 above, if the authentication terminal 112 is not registered (i.e., the result is No in S1103), the authentication client 301 of the authentication terminal 112 proceeds to S1104. In S1104, the authentication client 301 of the authentication terminal 112 retrieves registered terminal information associated with the user from the authentication terminal management table held in the credential information storage unit 312.
[0107] In S1105, the authentication client 301 of the authentication terminal 112 determines whether the terminal information is not present in the registered terminal information obtained in S1104. If the device information is not present in the registered device information (if the answer is Yes in S1105), the authentication client 301 of the authentication device 112 changes the credential authentication continuation flag to "False" in S1109 and terminates the credential authentication determination process.
[0108] On the other hand, in S1105 above, if the terminal information exists in the registered terminal information (if the result is No in S1105), the authentication client 301 of the authentication terminal 112 proceeds to S1106.
[0109] In S1106, the authentication client 301 of the authentication terminal 112 determines whether the registered terminal information obtained in S1104 contains information corresponding to the authentication terminal 112 (i.e., it determines whether the authentication terminal 112 is registered). If the authentication terminal 112 is already registered (Yes in S1106), the authentication client 301 of the authentication terminal 112 proceeds to S1108. In S1108, the authentication client 301 of the authentication terminal 112 sets the credential authentication continuation flag to "True" and terminates the credential authentication decision process.
[0110] On the other hand, in S1106 above, if the authentication terminal 112 is not registered (if the answer is No in S1106), the authentication client 301 of the authentication terminal 112 transitions the process to S1107.
[0111] In S1107, the authentication client 301 of the authentication terminal 112 executes the authentication terminal registration process, and in S1109, it changes the credential authentication continuation flag to "False" and terminates the credential authentication determination process. Alternatively, if the authentication terminal registration process in S1107 is completed and the authentication terminal 112 becomes "registered", the process may be transitioned to S1108, while if the authentication terminal 112 becomes "not registered", the process may be transitioned to S1109.
[0112] As described above, according to the first embodiment, trusted terminals are pre-registered on the credential management server, and the synchronization and use of multi-device FIDO credentials are restricted according to the registration status, so that credentials can be used only on trusted authentication terminals. In addition, it is possible to prevent credential information from being stored on untrusted authentication terminals that have been rejected for registration by the user. As a result, it becomes possible to manage credentials more securely.
[0113] In the credential information synchronization process shown in Figures 8 and 9, a configuration was described in which credential information can be synchronized only if the authentication terminal 112 to be synchronized is not marked as "Registration NG". However, it is also possible to synchronize credential information only if the authentication terminal 112 to be synchronized is both "Registration NG" and "Registered". In this case, a process is added between S803 and S804 to determine whether the authentication terminal 112 is included in the registered terminal information received in S801. In this determination, if the authentication terminal 112 is not included in the registration NG terminal information, the credential synchronization continuation flag is set to "False" in S805, while if it is included, the credential synchronization continuation flag is set to "True" in S804.
[0114] [Second Embodiment] In the second embodiment, the parts common to the first embodiment will be omitted from the explanation, and only the differences will be described below. When the authentication terminal registration process is performed, even if an authentication terminal registration permission request is sent to a registered authentication terminal, the user may not respond immediately. Therefore, if an unregistered authentication terminal logs in to the credential information management server multiple times, or if multiple credential authentication requests are sent from an unregistered authentication terminal, the registered authentication terminal will be notified of multiple authentication terminal registration permission requests.
[0115] On the other hand, there is an attack method called MFA Fatigue Attack (Multi-Factor Authentication Fatigue Attack). This attack method involves sending a large number of push notifications to the user, inducing them to grant permission by mistake. In the first embodiment, a request for permission to register the authentication terminal is notified each time an authentication terminal registration request is made from an unregistered authentication terminal, so it is desirable to prevent MFA Fatigue Attacks. This second embodiment describes a configuration that prevents such MFA Fatigue Attacks.
[0116] <Functional Configuration> Figure 12 illustrates the module configuration of the credential information management server 123 in the second embodiment. The credential information management server 123 includes a user management unit 1201 instead of the user management unit 343 shown in Figure 3. In addition to the functions of the user management unit 343 shown in Figure 3, the user management unit 1201 provides a function to manage information (history) of authentication terminal registration permission requests sent to registered authentication terminals 111.
[0117] Table 10 shows an example of a user information table maintained by the user management unit 1201. As shown in Table 10, the user information record in the user information table includes user ID, password, registered device information, device information that has been denied registration, and information on the submitted authentication device registration permission request. [Table 10]
[0118] <Authentication terminal registration determination process> The authentication terminal registration determination process will be explained using Figure 13. This process is the flow in which the credential information management server 123 makes a decision on whether to register an authentication terminal in S407 of the authentication terminal registration process. This process is initiated when the credential information management server 123 receives an authentication terminal registration request from the authentication terminal 112. Figure 13 is a flowchart illustrating the authentication terminal registration determination process of the second embodiment. The process shown in this flowchart is realized by the CPU 251 of the credential information management server 123 executing a program stored in the program ROM of ROM 253 or loaded from the hard disk 263 into RAM 252. The same steps as in Figure 7A are given the same step numbers and their explanations are omitted.
[0119] In the second embodiment, if the target authenticator is not registered (No in S606), the process proceeds to S1301. In S1301, the authentication terminal management unit 342 of the credential information management server 123 retrieves the transmitted authentication terminal registration permission request information associated with the user ID included in the authentication terminal registration request received in S601 from the user information table (a table like Table 10) held by the user management unit 1201. This transmitted authentication terminal registration permission request information includes a list of transmission times.
[0120] In S1302, the authentication terminal management unit 342 of the credential information management server 123 calculates the number of times an authentication terminal has been sent within the specified period from the sent authentication terminal registration permission request information obtained in S1301, and determines whether the number is below a threshold. In the example in Table 10, if the current time is "2023 / 11 / 16 15:21" and the specified period is within one hour, the number of sent messages will be "2". Note that the specified period and the threshold for the number of sent messages may be set in advance for each user, or they may be predetermined values set by the system.
[0121] Here, if the number of transmissions within the specified period is greater than the threshold (No in S1302), the authentication terminal management unit 342 of the credential information management server 123 transitions the process to S608. In this case, no authentication terminal registration permission request is sent to the registered authentication terminal 111, and the authentication terminal registration process ends. Therefore, it is possible to prevent a large number of push notifications from being sent to the user within a certain period of time, and to prevent MFA fatigue attacks. At this time, the credential information management server 123 may, for example, notify the registered terminal 111 that there is a possibility that a multi-factor authentication fatigue attack (MFA fatigue attack) is being carried out. This notification may be made by other methods such as email.
[0122] On the other hand, if the number of transmissions within the specified period is below the threshold (if the answer is Yes in S1302), the authentication terminal management unit 342 of the credential information management server 123 transitions the process to S1303.
[0123] In S1303, the authentication terminal management unit 342 of the credential information management server 123 registers the current time and the information of the requesting authentication terminal in the sent authentication terminal registration permission request information associated with the above user ID in the user information table held by the user management unit 1201, and proceeds to S607. In this case, an authentication terminal registration permission request is sent to the registered authentication terminal 111.
[0124] As described above, according to the second embodiment, it is possible to prevent a large number of push notifications from being sent to the user within a certain period of time, thereby preventing MFA fatigue attacks. As described above, each embodiment makes it possible to reduce the risk of credential leakage in multi-device FIDO credentials.
[0125] It should be noted that the structure and content of the various data described above are not limited to those mentioned, and it goes without saying that they can be composed of various structures and contents depending on the use and purpose. Although one embodiment has been described above, the present invention can take the form of, for example, a system, apparatus, method, program, or storage medium. Specifically, it may be applied to a system consisting of multiple devices, or to an apparatus consisting of a single device. Furthermore, any configurations combining the above embodiments are also included in the present invention.
[0126] [Other Embodiments] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions. Furthermore, the present invention may be applied to a system consisting of multiple devices or to a device consisting of a single device. The present invention is not limited to the embodiments described above, and various modifications (including organic combinations of each embodiment) are possible based on the spirit of the invention, and these are not excluded from the scope of the invention. That is, all configurations that combine the above-described embodiments and their modified forms are included in the present invention.
[0127] This embodiment includes the following configurations and methods. (Composition 1) An information processing device having a first module that provides functions for user authentication and a second module that manages the storage and use of authentication credential information, and a system including a management system that manages credential information associated with a service, The aforementioned management system is A holding means for holding information of terminals already registered in the management system and information of terminals that have been refused registration to the management system, The holding means has a first control means that, in response to a registration request from an information processing device whose information is not held in the holding means, makes a permission request to the registered terminal to request a response to allow or deny registration of the information processing device, and causes the information processing device to be held in the holding means according to the response to the permission request, The second module of the information processing device is The system includes a second control means that obtains information on terminals registered with the management system and information on terminals that have been refused registration to the management system, and controls the process of using the obtained information to save the credential information managed by the management system to the first module. The system is characterized in that the second control means prevents the information processing device from saving the credential information to the first module if the information processing device is a terminal whose registration has been rejected. (Configuration 2) The second module of the information processing device further includes a third control means for controlling the process for using the service using the credential information stored in the second module. The system according to Configuration 1, characterized in that the third control means executes processing to use the service when the information processing device is a registered terminal, and restricts processing to use the service when the information processing device is not a registered terminal. (Composition 3) The second control means, if the information processing device is not a terminal whose registration has been rejected, causes the credential information and the acquired information to be stored in the first module. The system according to configuration 2, characterized in that the third control means determines whether the information processing device is a registered terminal based on the information stored in the first module. (Composition 4) The system according to configuration 2 or 3, characterized in that the third control means does not execute processing to use the service if the information processing device is a terminal whose registration has been refused, and if the information processing device is neither a registered terminal nor a terminal whose registration has been refused, it causes the third control means to execute processing to register the information processing device with the management system. (Composition 5) The holding means of the management system further holds the history of the permission requests made by the first control means, The system according to any one of configurations 1 to 4, characterized in that the first control means of the management system does not make the permission request with respect to the information processing device if the number of times the permission request has been made with respect to the information processing device within a predetermined period exceeds a predetermined number, even if there is a registration request from an information processing device for which no information is held in the holding means. (Method 1) An information processing device having a first module that provides a function for user authentication and a second module that manages the storage and use of authentication credential information, and a control method for a system including a management system that manages credential information associated with a service, The management system executes the following: A first control step in which, in response to a registration request from the information processing device, a permission request is made to the terminal already registered in the management system to request a response indicating whether to permit or deny registration of the information processing device, and the information of the information processing device is stored in the holding means according to the response to the permission request, either the information of the registered terminal or the information of the terminal whose registration has been denied. Executed by the second module of the information processing device, The system includes a second control step which controls the process of obtaining information on terminals registered with the management system and information on terminals that have been refused registration to the management system, and using the obtained information to save the credential information managed by the management system to the first module. A system control method characterized in that, in the second control step, if the information processing device is a terminal whose registration has been rejected, the credential information is not stored in the first module.
Claims
1. An information processing device having a first module that provides a function for user authentication and a second module that manages the storage and use of authentication credential information, and a system including a management system that manages credential information associated with a service, The aforementioned management system is A holding means for holding information of terminals already registered in the management system and information of terminals that have been refused registration to the management system, The holding means has a first control means that, in response to a registration request from an information processing device whose information is not held in the holding means, makes a permission request to the registered terminal to request a response to allow or deny registration of the information processing device, and causes the information of the information processing device to be held in the holding means according to the response to the permission request, The second module of the information processing device is The system includes a second control means that obtains information on terminals registered with the system and information on terminals that have been refused registration to the system, and controls the process of using the obtained information to save the credential information managed by the system to the first module. The system is characterized in that the second control means prevents the information processing device from saving the credential information to the first module if the information processing device is a terminal whose registration has been rejected.
2. The second module of the information processing device further includes a third control means for controlling the process for using the service using the credential information stored in the second module. The system according to claim 1, characterized in that the third control means executes processing to use the service when the information processing device is the registered terminal, and restricts processing to use the service when the information processing device is not the registered terminal.
3. The second control means, if the information processing device is not a terminal whose registration has been rejected, causes the credential information and the acquired information to be stored in the first module. The system according to claim 2, characterized in that the third control means determines whether the information processing device is a registered terminal based on the information stored in the first module.
4. The system according to claim 2 or 3, characterized in that the third control means does not execute processing to use the service if the information processing device is a terminal whose registration has been refused, and if the information processing device is neither a registered terminal nor a terminal whose registration has been refused, it causes the third control means to execute processing to register the information processing device with the management system.
5. The holding means of the management system further holds the history of the permission requests made by the first control means, The system according to claim 1, characterized in that the first control means of the management system does not make the permission request with respect to the information processing device if the number of times the permission request has been made with respect to the information processing device within a predetermined period exceeds a predetermined number, even if there is a registration request from an information processing device for which no information is held in the holding means.
6. An information processing device having a first module that provides a function for user authentication and a second module that manages the storage and use of authentication credential information, and a control method for a system including a management system that manages credential information associated with a service, The management system executes the following: A first control step in which, in response to a registration request from the information processing device, a permission request is made to the terminal already registered in the management system to request a response indicating whether to permit or deny registration of the information processing device, and the information of the information processing device is stored in the holding means according to the response to the permission request, either the information of the registered terminal or the information of the terminal whose registration has been denied. Executed by the second module of the information processing device, The system includes a second control step which controls the process of obtaining information on terminals registered with the management system and information on terminals that have been refused registration to the management system, and using the obtained information to save the credential information managed by the management system to the first module. A system control method characterized in that, in the second control step, if the information processing device is a terminal whose registration has been rejected, the credential information is not stored in the first module.