Mutual authentication system, authentication service device, mutual authentication method, and authentication support program
The mutual authentication system facilitates secure and easy exchange of authentication information between authentication service devices and terminal devices using public and private key pairs, addressing the challenge of secure key exchange in existing technologies.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- KAWASAKI JUKOGYO KK
- Filing Date
- 2024-11-21
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies face challenges in securely and easily exchanging authentication keys between authentication service devices and terminal devices for mutual authentication.
A mutual authentication system involving an authentication service device and a terminal device, equipped with processing units, storage units, and communication units, that generates and implements an authentication support program to facilitate secure exchange of authentication information through a series of authentication processes using public and private key pairs.
Enables easy and secure exchange of authentication information between authentication service devices and terminal devices, ensuring mutual authentication and secure data transmission.
Smart Images

Figure 2026089947000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a technique for performing mutual authentication between an authentication service device and a terminal device.
Background Art
[0002] Patent Document 1 discloses a technique including receiving, on the relying party side, a request from a user to register an authentication unit; transmitting a code from the user to the relying party or from the relying party to the user via an authenticated out-of-band communication channel; verifying the identity of the user using the code; and registering the authentication unit in a responsive manner in response to a positive verification.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In order to improve security, it is required to exchange an authentication key between an authentication service device and a terminal device for mutual authentication. At this time, it is required to enable the authentication key to be exchanged easily and securely.
[0005] Therefore, an object of the present disclosure is to enable authentication information to be exchanged easily and securely between an authentication service device and a terminal device.
Means for Solving the Problems
[0006] The mutual authentication system is a mutual authentication system that performs mutual authentication between an authentication service device and a terminal device, wherein the authentication service device comprises a first storage unit for storing first authentication information, a first communication unit, and a first processing unit, and the terminal device comprises a second storage unit for storing second authentication information, a second communication unit, and a second processing unit, wherein the first processing unit generates an authentication support program that causes the terminal device to perform authentication processing with the authentication service device using the first authentication information, provides the authentication support program to the terminal device in an implementable form, prepares an authentication service associated with the authentication support program, and when the authentication support program is implemented in the terminal device, the first processing unit and the second processing unit The mutual authentication system includes a first communication unit and a second communication unit that communicate with each other, and further, the second processing unit performs processing according to the authentication assistance program, and the first processing unit performs the authentication service, thereby performing mutual authentication processing, the mutual authentication processing including a first authentication process in which the first processing unit and the second processing unit authenticate the authentication service device using the first authentication information, a data transmission and reception process in which the second processing unit transmits authentication information from the second authentication information to the authentication service device when the authentication service device is authenticated, and a second authentication process in which the first processing unit and the second processing unit authenticate the terminal device using the second authentication information.
[0007] Furthermore, the authentication service device is an authentication service device that performs mutual authentication with a terminal device, and comprises an authentication information storage unit that stores first authentication information, a communication unit, and a processing unit, wherein the processing unit generates an authentication support program that causes the terminal device to perform authentication processing with the authentication service device using the first authentication information, provides the authentication support program to the terminal device in an implementable manner, prepares an authentication service associated with the authentication support program, and, by executing the authentication service, communicates with the terminal device on which the authentication support program is implemented via the communication unit to authenticate the authentication service device using the first authentication information, and when the authentication service device is authenticated, receives the authentication information from the second authentication information of the terminal device via the communication unit, and authenticates the terminal device using the second authentication information.
[0008] Furthermore, the mutual authentication method is a mutual authentication method that performs mutual authentication between an authentication service device and a terminal device, wherein the authentication service device generates an authentication auxiliary program that causes the terminal device to perform authentication processing with the authentication service device using first authentication information, provides the authentication auxiliary program to the terminal device in an implementable manner, prepares an authentication service associated with the authentication auxiliary program, and when the authentication auxiliary program is implemented in the terminal device, communication takes place between the authentication service device and the terminal device, the terminal device performs processing according to the authentication auxiliary program and performs the authentication service, thereby performing mutual authentication processing, the mutual authentication processing is a mutual authentication method in which the authentication service device and the terminal device authenticate the authentication service device using the first authentication information, and when the authentication service device is authenticated, the terminal device transmits authentication information from the second authentication information to the authentication service device, and the authentication service device and the terminal device authenticate the terminal device using the second authentication information.
[0009] Furthermore, the authentication assistance program is an authentication assistance program provided to a terminal device for mutual authentication between the authentication service device and the terminal device, and includes information for performing authentication using first authentication information, and is a program that causes the terminal device to perform the following: connect to the authentication service executed by the authentication service device and associated with the authentication assistance program, and perform a process for authenticating the authentication service device using the first authentication information; and, if the authentication service device is authenticated, transmit the authentication information from the second authentication information to the authentication service device, and perform a process for authenticating the terminal device using the second authentication information. [Effects of the Invention]
[0010] This mutual authentication system allows for easy and secure exchange of authentication information between authentication service devices and terminal devices.
[0011] This authentication service device provides a device for a mutual authentication system that allows for the easy and secure exchange of authentication information.
[0012] This mutual authentication method allows for easy and secure exchange of authentication information between the authentication service device and the terminal device.
[0013] This authentication assistance program provides a program for easily and securely exchanging authentication information. [Brief explanation of the drawing]
[0014] [Figure 1] This is a block diagram showing the overall configuration of the mutual authentication system according to the embodiment. [Figure 2] This is a flowchart showing the overall process of the mutual authentication system. [Figure 3] This flowchart shows the process by which an authentication service device generates and provides an authentication assistance program. [Figure 4] This is a flowchart showing the first authentication process. [Figure 5]It is a flowchart showing the second authentication process. [Figure 6] It is a functional block diagram of the mutual authentication system during the process in which the authentication service device generates and provides an authentication assistance program. [Figure 7] It is a functional block diagram of the mutual authentication system during the first authentication process. [Figure 8] It is a functional block diagram of the mutual authentication system during the second authentication process. [Figure 9] It is a functional block diagram of the mutual authentication system after the second authentication process. [Figure 10] It is a flowchart showing an example of the process after the exchange of the first authentication information and the second authentication information.
Embodiments for Carrying Out the Invention
[0015] Hereinafter, a mutual authentication system according to an embodiment will be described. FIG. 1 is a block diagram showing the overall configuration of the mutual authentication system 10.
[0016] The mutual authentication system 10 is a system that performs mutual authentication between an authentication service device 20 and a terminal device 30. The mutual authentication system 10 is used, for example, in a remote monitoring service. The remote monitoring service connects the monitoring device 12 and the terminal device 30 via a communication network 14, and is a service for monitoring a monitoring target located at a position away from the monitoring device 12 through the terminal device 30 by the monitoring device 12. The communication network 14 may be wired, wireless, or a combination of them. Also, it is assumed that the communication network 14 passes through a public communication network.
[0017] The monitoring device 12 is a computer that collects various data from the terminal device 30, and is, for example, a cloud computer. The data 13d collected by the monitoring device 12 is stored in the storage unit 13, and based on the data 13d, information useful for the use or operation of the monitoring target of the terminal device 30 can be provided.
[0018] In order to provide such a remote monitoring service, the monitoring device 12 and the terminal device 30 are set to be connectable via the communication network 14. Thereby, the data acquired by the terminal device 30 is uploaded to the monitoring device 12.
[0019] It is preferable that the monitoring device 12 and the terminal device 30 are mutually authenticated from the viewpoint of security. The mutual authentication is performed, for example, by exchanging their public keys.
[0020] When the distance between the monitoring device 12 and the terminal device 30 is large, it is conceivable that the authentication information is exchanged via a communication network such as the Internet. In this case, it is desirable to be able to securely transmit the authentication information via the communication network. The present disclosure relates to a technique for securely exchanging authentication information via a communication network.
[0021] The mutual authentication system 10 includes an authentication service device 20 and a terminal device 30.
[0022] The authentication service device 20 is, for example, a device incorporated in the monitoring device 12 in a remote monitoring service. The authentication service device 20 is a computer including a first processing unit 22, a first storage unit 24, a first communication unit 26, and a storage unit 28.
[0023] The first processing unit 22 is a processor and includes an arithmetic circuit. The first storage unit 24 is composed of a non-volatile storage device such as an HDD (hard disk drive) or SSD (solid-state drive). The first storage unit 24 is an authentication information storage unit that stores first authentication information used for mutual authentication. The first communication unit 26 includes a communication circuit. The first processing unit 22 communicates with terminal equipment 30 via the communication network 14 through the first communication unit 26. The storage unit 28 is composed of a non-volatile storage device such as an HDD (hard disk drive) or SSD (solid-state drive). The first storage unit 24 and the storage unit 28 may be physically the same non-volatile storage device or may be different non-volatile storage devices. It is preferable that the storage area of the first storage unit 24 that stores the first authentication information is set to a more secure area that is inaccessible from the outside.
[0024] The storage unit 28 stores a program 28a that describes the procedure for the authentication service device 20 to perform authentication, as described later. The first processing unit 22 reads and executes the program 28a, thereby realizing the authentication process described later.
[0025] The storage unit 28 may store the authentication assistance program 50 generated by the first processing unit 22. The authentication assistance program 50 is provided to the terminal device 30 via the intermediary terminal device 40 and implemented in the terminal device 30. The authentication assistance program 50 is a program that causes the terminal device 30 to perform authentication processing with the authentication service device 20 using the first authentication information. In other words, the authentication assistance program 50 describes the procedure for causing the second processing unit 32 to perform authentication processing.
[0026] The first processing unit 22 provides the authentication assistance program 50 in a format that can be implemented on the terminal device 30. For example, the first processing unit 22 generates the authentication assistance program 50 in a format that can be implemented on the terminal device 30 and makes it downloadable via the communication network 14. After the authentication assistance program 50 is provided to the terminal device 30, the authentication assistance program 50 may be erased from the storage unit 28.
[0027] The authentication service device 20 may be implemented by a cloud computer, or by a dedicated system in which a single computer or multiple computers work together. In other words, the authentication service device 20 may be implemented by a processor in a physical or virtual computer reading and executing a program stored in auxiliary storage. For example, the authentication service device 20 may be implemented as a processing function in a monitoring device 12 implemented by a cloud computer.
[0028] Terminal device 30 is an edge terminal for monitoring the monitored object. The monitored object is, for example, a factory, storage facility, transport equipment, or transport device. Terminal device 30 may be equipped with various sensors for monitoring the monitored object. The various sensors are, for example, an imaging camera, a temperature sensor, a humidity sensor, or a speed sensor. Terminal device 30 may be equipped with multiple sensors.
[0029] The terminal device 30 is a computer comprising a second processing unit 32, a second storage unit 34, a second communication unit 36, and a storage unit 38.
[0030] The second processing unit 32 is a processor and includes an arithmetic circuit. The second storage unit 34 is composed of a non-volatile storage device such as an HDD (hard disk drive) or SSD (solid-state drive). The second storage unit 34 stores second authentication information used for mutual authentication. The second communication unit 36 includes a communication circuit. The second processing unit 32 communicates with the authentication service device 20 via the communication network 14 through the second communication unit 36. The storage unit 38 is composed of a non-volatile storage device such as an HDD (hard disk drive) or SSD (solid-state drive). The second storage unit 34 and the storage unit 38 may be physically the same non-volatile storage device or different non-volatile storage devices. For example, the second storage unit 34 may be a key storage function provided by a TPM (Trusted Platform Module).
[0031] By implementing the above-mentioned authentication support program 50 on the terminal device 30, the terminal device 30 can perform authentication with the authentication service device 20.
[0032] When using this mutual authentication system 10, an intermediary terminal device 40 may be used. The intermediary terminal device 40 is a computer equipped with a processing unit, a storage unit 44, and a communication unit 46, and is installed, for example, in the user environment of the terminal device 30. For example, the intermediary terminal device 40 is installed in an environment closer to the terminal device 30 than to the authentication service device 20. Specifically, the intermediary terminal device 40 is installed in the same premises, facilities, or building as the authentication service device 20. Alternatively, for example, the intermediary terminal device 40 is installed in the same private network as the authentication service device 20. The intermediary terminal device 40 can also communicate with the authentication service device 20 via the communication network 14.
[0033] Figure 2 is a flowchart showing the overall processing of the mutual authentication system 10. In Figure 2, the processing by the first processing unit 22 of the authentication service device 20 is shown on the left, and the processing by the second processing unit 32 of the terminal device 30 is shown on the right.
[0034] In step S1, the authentication service device 20 generates an authentication assistance program 50. The authentication assistance program 50 is a program that causes the terminal device 30 to perform an authentication process with the authentication service device 20 using the first authentication information. The authentication assistance program 50 is also used for authentication processes that use the second authentication information. The generated authentication assistance program 50 is provided to the terminal device 30 via the intermediary terminal device 40. The authentication information from the first authentication information is provided to the terminal device 30 together with the authentication assistance program 50.
[0035] As shown in step S11, the authentication assistance program 50 provided to the terminal device 30 is implemented in the terminal device 30.
[0036] When the authentication service device 20 generates the authentication assistance program 50, it prepares the authentication service associated with the authentication assistance program 50. By providing the authentication service, the authentication service device 20 becomes ready to sequentially provide the first authentication service (step S2), the first data transmission / reception service (step S3), the second authentication service (step S4), and the second data transmission / reception service (step S5).
[0037] Furthermore, the terminal device 30 communicates with the authentication service device 20 by executing the authentication assistance program 50. As a result, the terminal device 30 becomes ready to sequentially process the terminal-side first authentication service (step S12), the terminal-side first data transmission / reception service (step S13), the terminal-side second authentication service (step S14), and the terminal-side second data transmission / reception service (step S15).
[0038] The following mutual authentication process is performed by the processing in the terminal device 30 in accordance with the authentication assistance program 50 and the execution process of the authentication service in the authentication service device 20.
[0039] In other words, the first authentication process is performed by the execution of the first authentication service (step S2) in the authentication service device 20 and the terminal-side first authentication service (step S12) in the terminal device 30. The first authentication process is a process that authenticates the authentication service device 20 using information related to the first authentication information.
[0040] Once the authentication service device 20 is authenticated, the authentication service device 20 performs a first data transmission / reception service (step S3) and the terminal device 30 performs a terminal-side first data transmission / reception service (step S13), thereby transmitting the next authentication data between the authentication service device 20 and the terminal device 30. This data transmission / reception process includes the second processing unit 32 of the terminal device 30 transmitting the authentication information from the second authentication information to the authentication service device 20.
[0041] Subsequently, the second authentication process is executed by the execution of the second authentication service (step S4) in the authentication service device 20 and the terminal-side second authentication service (step S14) in the terminal device 30. The second authentication process is the process of authenticating the terminal device 30 using the second authentication information.
[0042] As a result, both the authentication service device 20 and the terminal device 30 are authenticated, and the information related to the first authentication information for the authentication of the authentication service device 20 and the information related to the second authentication information for the authentication of the terminal device 30 are exchanged with each other.
[0043] Subsequently, monitoring data is sent and received between the authentication service device 20 and the terminal device 30 through the execution of the second data transmission and reception service (step S5) in the authentication service device 20 and the terminal device 30 (step S15).
[0044] Let's explain each process in more detail.
[0045] Figure 3 is a flowchart showing the process related to step S1. Figure 4 is a flowchart showing the process related to steps S2, S3, S12, and S13. Figure 4 is a flowchart showing the process related to steps S4, S5, S14, and S15.
[0046] Figure 6 is a functional block diagram of the mutual authentication system 10 during processing as shown in Figure 3, Figure 7 is a functional block diagram of the mutual authentication system 10 during processing as shown in Figure 4, Figure 8 is a functional block diagram of the mutual authentication system 10 during processing as shown in Figure 5, and Figure 9 is a functional block diagram of the mutual authentication system 10 after authentication. In Figures 6 to 9, potential functions that are not enabled to be executable, functions that are disabled to be unexecutable, or unused equipment are indicated by a dashed-dot frame or a dashed-dot line.
[0047] I will explain this step by step. Referring to Figures 3 and 6, the process related to step S1, that is, the process by which the authentication service device 20 generates and provides the authentication assistance program 50, will be explained.
[0048] First, assume that the terminal device 30 has prepared and stored a second public key 62a and a second private key 62b as second authentication information 62 for the terminal device 30. The second public key 62a and the second private key 62b are keys of the second processing unit 32, which are managed by the second processing unit 32.
[0049] In step S21, the first processing unit 22 prepares a first public key 60a and a first private key 60b as a key pair as first authentication information. The first public key 60a may be a key with a certificate certified by a third-party organization. For example, the first public key 60a may be a key with an X.509 certificate certified by a CA (Certificate Authority) according to the X.509 standard. The second authentication information is information prepared for the authentication of the terminal device 30. If multiple terminal devices 30 are to be authenticated, the second authentication information may be prepared for each of the multiple terminal devices 30. The process of preparing the first public key 60a and the first private key 60b as first authentication information may be performed when the terminal device 30 requests device authentication. The first public key 60a and the first private key 60b are keys of the first processing unit 22 that are accessible from the first processing unit 22.
[0050] In the next step S22, it is determined whether or not a login has occurred. If a user logs in to the authentication service device 20 using the intermediary terminal device 40, it is determined that a login has occurred. It is preferable that the login is permitted by multi-factor authentication. Multi-factor authentication login is a login method that goes through multiple authentication stages. For example, multi-factor authentication login is a login method that goes through multiple passwords, or a password and a secret question. It is even more preferable that the login is permitted by multi-factor authentication. Multi-factor authentication login is a login method that is permitted by authentication of multiple types of factors. For example, the factors are knowledge factors, possession factors and biometric factors. With this, the first processing unit 22 can authenticate the intermediary terminal device 40 by multi-factor authentication or multi-factor authentication login. If it is determined that a login has occurred, the process proceeds to step S23.
[0051] In step S23, it is determined whether or not there is a device authentication request from the intermediary terminal device 40. If the user logs in to the authentication service device 20 using the intermediary terminal device 40 and enters a request to authenticate the terminal device 30, it is determined that there is a device authentication request, and the process proceeds to step S24.
[0052] In step S24, the first processing unit 22 generates a first authentication service 70a and a first data transmission / reception service 70b. The first authentication service 70a is a service that allows an authentication challenge to the first authentication service 70a when a first connection code 70a1 is specified.
[0053] Next, in step S25, the first processing unit 22 generates an authentication assistance program 50. The authentication assistance program 50 includes a first public key 60a and a first connection code 70a1. The authentication assistance program 50 is stored in the storage unit 28 so that it can be downloaded via the communication network 14.
[0054] The first authentication service 70a described above is associated with the authentication support program 50. The first authentication service 70a is a function that can authenticate only when processing in accordance with the authentication support program 50 is performed on the terminal device 30 where the authentication support program 50 is implemented. In this embodiment, the first authentication service 70a is associated with the authentication support program 50 in that it can authenticate using the first authentication information 60 and the first connection code 70a1 included in the authentication support program 50. The authentication service device 20 becomes ready to provide the first authentication service 70a in conjunction with the generation of the authentication support program 50.
[0055] The first data transmission service 70b is a function that enables data transmission and reception with the terminal device 30 when authentication is permitted by the first authentication service 70a.
[0056] If the processing functions of the authentication service device 20 are implemented by cloud computing, the first authentication service 70a may be implemented by a Provisioning Service for IoT devices, and the scope ID for connecting to the Provisioning Service may be used as the first connection code 70a1. In addition, the first data transmission and reception service 70b may be implemented by a management service that registers, authenticates, and manages the IoT devices used in the cloud computing environment.
[0057] In the next step S26, it is determined whether there is a request to download the authentication assistance program 50 from the intermediary terminal device 40. If it is determined that there is a download request, the process proceeds to the next step S27.
[0058] In the next step S27, the download of the authentication assistance program 50 to the intermediary terminal device 40 is permitted. This allows the user to download the authentication assistance program 50 to the intermediary terminal device 40. The authentication assistance program 50 is stored on the intermediary terminal device 40.
[0059] Therefore, when the first processing unit 22 authorizes login authentication for the intermediary terminal device 40 via the first communication unit 26, it provides the authentication assistance program 50 to the intermediary terminal device 40 via the first communication unit 26.
[0060] In other words, the user can download the authentication assistance program 50 via the communication network 14 by accessing the authentication service device 20 using the intermediary terminal device 40. The downloaded authentication assistance program 50 is provided from the intermediary terminal device 40 to the terminal device 30. For example, the authentication assistance program 50 may be provided from the intermediary terminal device 40 to the terminal device 30 via a portable recording medium such as a USB memory stick. Alternatively, the authentication assistance program 50 may be transmitted from the intermediary terminal device 40 to the terminal device 30 via a private network or a dedicated communication line.
[0061] The authentication assistance program 50 is stored in the terminal device 30, and when the user provides instructions for implementation to the terminal device 30, the second processing unit 32 of the terminal device 30 executes the process of implementing the authentication assistance program 50 in the terminal device 30. As a result, the terminal device 30 becomes capable of executing processes in accordance with the authentication assistance program 50.
[0062] Referring to Figures 4 and 7, the processes related to steps S2, S3 and S12, S13, i.e., the first authentication process, will be explained. The first authentication process is a process in which the authentication service device 20 is authenticated using the first authentication information through mutual communication between the first processing unit 22 and the second processing unit 32.
[0063] First, by implementing the authentication assistance program 50 on the terminal device 30, the terminal device 30 becomes capable of processing in accordance with the authentication assistance program 50.
[0064] In step S41, the second processing unit 32 of the terminal device 30 determines whether or not an authentication start instruction has been given. For example, if the user operates the terminal device 30 and gives an authentication start instruction to the authentication assistance program 50, the second processing unit 32 starts authentication. An instruction to start the authentication assistance program 50 may also be considered an authentication start instruction.
[0065] In the next step S42, the second processing unit 32 connects to the authentication service device 20 via the communication network 14 and requests authentication from the authentication service device 20 using the first connection code 70a1. As described above, the authentication assistance program 50 includes the first connection code 70a1 and the first public key 60a. When the authentication assistance program 50 is implemented in the terminal device 30, the first public key 60a can also be used as the key for the second processing unit 32 of the terminal device 30.
[0066] In step S31, the first processing unit 22 of the authentication service device 20 determines whether the authentication assistance program 50 is within its validity period. For example, the validity period of the authentication assistance program 50 is set in advance based on the generation time of the authentication assistance program 50. The validity period is set to allow sufficient time for the implementation of the authentication assistance program 50 and the authentication process, based on the generation time. For example, the validity period may be set to a time several hours after the generation time, or to a time several days after the generation time. If it is determined that the validity period is not within the validity period, the process is terminated. In other words, the first processing unit 22 stops the processing of the authentication service device 20 for the first authentication process using the first authentication information 60 after a predetermined time has elapsed. As a result, the authentication process using the authentication assistance program 50, which includes the first public key 60a and the first connection code 70a1, can no longer be performed. The termination of the process may be interpreted as the invalidation or deletion of the first authentication service 70a.
[0067] If it is determined in step S31 that the validity period of the authentication assistance program 50 is still valid, the first processing unit 22 proceeds to step S32.
[0068] In step S32, the first processing unit 22 determines whether or not there is an authentication request from the terminal device 30. If it is determined that there is an authentication request from the terminal device 30, the process proceeds to step S33. If it is determined that there is no authentication request, the process returns to step S31.
[0069] In step S33, the first processing unit 22 determines whether the authentication request uses the first connection code 70a1. If the first connection code 70a1 used in the authentication request matches the first connection code 70a1 for the first authentication service 70a, the process proceeds to the next step S34; otherwise, it returns to step S31. In other words, the second processing unit 32 executes processing using the first connection code 70a1 based on the authentication assistance program 50, thereby allowing the connection to the first authentication service 70a.
[0070] In steps S34 and S43, the first processing unit 22 and the second processing unit 32 perform authentication using the first private key 60b and the first public key 60a. That is, the first private key 60b is stored in the authentication service device 20, and the first public key 60a is stored in the terminal device 30. Authentication is performed using the first public key 60a and the first private key 60b through mutual communication between the first processing unit 22 and the second processing unit 32.
[0071] For example, in one of the first processing unit 22 and the second processing unit 32, the data to be signed is encrypted using one of the first public key 60a and the first private key 60b as the signing key. The encrypted data and the data to be signed are sent to the other of the first processing unit 22 and the second processing unit 32. The other of the first processing unit 22 and the second processing unit 32 verifies the encrypted data and the data to be signed using the other of the first public key 60a and the first private key 60b. Based on the verification result, it is determined whether authentication is successful or not. Verification may be performed in either the first processing unit 22 or the second processing unit 32.
[0072] As shown in step S35, the first processing unit 22 determines whether authentication is possible based on the verification result. If authentication is not possible, the process returns to step S31. If authentication is possible, the process proceeds to step S36.
[0073] If authentication is possible, it is guaranteed that the first public key 60a and the first private key 60b are a key pair that can be used for authentication. The first public key 60a and the first private key 60b are a key pair registered with the authentication service device 20. Therefore, authentication using the first authentication information 60, which includes the first public key 60a and the first private key 60b, can be considered authentication of the authentication service device 20. If the first public key 60a is a key with a certificate certified by a CA, the legitimacy of the authentication service device 20 is guaranteed.
[0074] If authentication is determined to be possible in step S35, then in step S36, the first authentication service 70a grants permission to the first data transmission / reception service 70b to transmit and receive data with the terminal device 30.
[0075] On the other hand, as shown in step S44, the second processing unit 32 of the terminal device 30 determines whether data transmission and reception are permitted. For example, if a user checks the authentication status in the authentication service device 20 through the intermediary terminal device 40 and confirms that the user has been authenticated, it inputs to the terminal device 30 that data transmission and reception are permitted. The determination of whether data transmission and reception are permitted in the second processing unit 32 may be made based on the input from the user. Alternatively, information indicating whether data transmission and reception are permitted may be transmitted from the authentication service device 20 to the terminal device 30, and the determination of whether data transmission and reception are permitted may be made based on this transmitted information.
[0076] If it is determined in step S44 that data transmission is permitted, the second processing unit 32 transmits the second public key 62a to the authentication service device 20 using the second data transmission service 72b, as shown in step S45. The second public key 62a is the authentication information from the second authentication information 62.
[0077] In step S37, the authentication service device 20 determines whether or not it has obtained the second public key 62a. If it determines that the second public key 62a has been obtained, it proceeds to step S38. Once the authentication service device 20 has obtained the second public key 62a, the second public key 62a can also be used as the key for the first processing unit 22.
[0078] In step S38, the first processing unit 22 generates the second authentication service 72a and the second data transmission / reception service 72b. The second authentication service 72a is a service that permits external connections in response to connection requests using the second connection code 72a1 and executes the second authentication process. The second authentication service 72a is implemented by a program that modifies the connection code of the program for the first authentication service 70a. Therefore, the first authentication service 70a and the second authentication service 72a are implemented by programs that were prepared to be executable in association with the authentication assistance program 50 when the authentication assistance program 50 was generated. The second data transmission / reception service 72b provides a function that enables data transmission and reception with the terminal device 30 when authentication is permitted by the second authentication service 72a.
[0079] Similar to the first authentication service 70a and the first data transmission / reception service 70b, if the processing functions of the authentication service device 20 are implemented by cloud computing, the second authentication service 72a may be implemented by a Provisioning Service for IoT devices, and the scope ID for connecting to the Provisioning Service may be used as the second connection code 72a1. Furthermore, the second data transmission / reception service 72b may be implemented by a management service that registers, authenticates, and manages the IoT devices used in the cloud computing environment.
[0080] In the next step S39, the first processing unit 22 uses the first authentication service 70a to send the second connection code 72a1 to the terminal device 30. After this, the process returns to step S31.
[0081] In step S46, the terminal device 30 determines whether or not it has received the second connection code 72a1. If it determines that it has been received, in step S47, it stores the second connection code 72a1 as the code for the next connection in the authentication assistance program 50.
[0082] In this state, the first public key 60a of the first authentication information 60, which is used for authentication by the authentication service device 20, is stored in the terminal device 30, and the second public key 62a of the second authentication information 62, which is used for authentication by the terminal device 30, is stored in the authentication service device 20.
[0083] Referring to Figures 5, 8, and 9, the processes related to steps S4, S5, and S14, S15, i.e., the second authentication process, will be explained. The second authentication process is a process in which the terminal device 30 is authenticated using the second authentication information through mutual communication between the first processing unit 22 and the second processing unit 32.
[0084] In step S61, the second processing unit 32 of the terminal device 30 connects to the authentication service device 20 via the communication network 14 and requests authentication from the authentication service device 20 using the second connection code 72a1.
[0085] In step S51, the first processing unit 22 of the authentication service device 20 determines whether or not there is an authentication request from the terminal device 30. If it is determined that there is an authentication request from the terminal device 30, the process proceeds to step S52.
[0086] In step S52, the first processing unit 22 determines whether the authentication request uses the second connection code 72a1. If the second connection code 72a1 used in the authentication request matches the second connection code 72a1 for the second authentication service 72a, the process proceeds to the next step S53; otherwise, it returns to step S51. In other words, the second processing unit 32 executes processing using the second connection code 72a1 based on the authentication assistance program 50, thereby allowing a connection to the second authentication service 72a. As described above, the second connection code 72a1 is a code associated with the second authentication service 72a.
[0087] In other words, the second processing unit 32 executes processing using the second connection code 72a1 based on the authentication assistance program 50, thereby granting permission to connect to the second authentication service 72a and enabling the execution of the second authentication process.
[0088] In steps S53 and S62, the first processing unit 22 and the second processing unit 32 perform authentication using the second private key 62b and the second public key 62a. That is, the second public key 62a is stored in the authentication service device 20, and the second private key 62b is stored in the terminal device 30. Authentication is performed using the second public key 62a and the second private key 62b through mutual communication between the first processing unit 22 and the second processing unit 32.
[0089] The authentication process here may be carried out in the same manner as the processes in steps S34 and S43 described above. Verification in the authentication process may be performed in either the first processing unit 22 or the second processing unit 32.
[0090] As shown in step S54, the first processing unit 22 determines whether authentication is possible based on the verification result. If authentication is not possible, the process returns to step S51. If authentication is possible, the process proceeds to step S55.
[0091] If authentication is possible, it is guaranteed that the second public key 62a and the second private key 62b are a key pair that can be used for authentication. The second public key 62a and the second private key 62b are a key pair registered in the terminal device 30. Therefore, authentication using the second authentication information 62, which includes the second public key 62a and the second private key 62b, can be considered as authentication of the terminal device 30.
[0092] In step S54, if authentication is deemed possible, both the authentication service device 20 and the terminal device 30 are authenticated using both the first authentication information 60 and the second authentication information 62.
[0093] Once the terminal device 30 is authenticated, in the next step S55, the second authentication service 72a grants the second data transmission / reception service 72b permission to send and receive data with the terminal device 30.
[0094] In this state, as shown in step S63, the second processing unit 32 of the terminal device 30 determines whether or not data transmission and reception is permitted. As described above, if permission for data transmission and reception is granted in step S55, that permission is granted to the terminal device 30. As a result, the terminal device 30 determines that data transmission and reception is permitted.
[0095] Subsequently, in steps S56 and S65, and as shown in Figure 9, the authentication service device 20 and the terminal device 30 become capable of sending and receiving data. The terminal device 30 can upload various data to the monitoring device 12 using the authenticated connection path as described above.
[0096] Even if the connection path is interrupted, the authentication service device 20 stores the second public key 62a of the second authentication information 62, and the terminal device 30 stores the first public key 60a of the first authentication information 60. Therefore, mutual authentication and data transmission may be performed by the flowchart shown in Figure 10. That is, steps S53 and S62 in the flowchart shown in Figure 5 are changed to steps S53a and S62a, which perform mutual authentication using the first authentication information 60 and the second authentication information 62. Then, the terminal device 30 accesses the second authentication service 72a using the second connection code 72a1, and the authentication service device 20 and the terminal device 30 are mutually authenticated using the first authentication information 60 and the second authentication information 62. Then, the terminal device 30 can upload various information to the monitoring device 12 over the mutually authenticated connection path.
[0097] The processing function that utilizes the first authentication information 60 and the second authentication information 62 described above may be a function provided by the authentication assistance program 50, or it may be a function provided by a processing program other than the authentication assistance program 50.
[0098] In this way, after the terminal device 30 is authenticated, the second processing unit 32 can use the second connection code 72a1 to access the second authentication service 72a, which is a service function of the first processing unit 22, and use the first authentication information 60 and the second authentication information 62 to perform mutual authentication and transmit the data of the terminal device 30 to the authentication service device 20.
[0099] It is preferable that the first authentication service 70a is deactivated after the second authentication service 70a has been enabled. The first authentication service 70a is deactivated after the above-mentioned validity period has elapsed. The first authentication service 70a may be deactivated at other times. For example, it may be deactivated when the second authentication service 72a is generated or around that time.
[0100] Furthermore, when reconnecting, mutual authentication can be performed using the first authentication information 60 and the second authentication information 62, so the determination of whether connection is possible using the connection code may be omitted.
[0101] With the mutual authentication system 10, authentication service device 20, mutual authentication method, and authentication support program 50 configured as described above, authentication can be performed between a terminal device 30 on which the authentication support program 50 generated by the authentication service device 20 is implemented, and the authentication service device 20 which executes the first authentication service 70a associated with the authentication support program 50. Furthermore, the authentication service device 20 is authenticated using the first authentication information 60, and when the authentication service device 20 is authenticated, the second processing unit 32 transmits the authentication information from the second authentication information 62 to the authentication service device 20. Thus, the second authentication information 62 can be exchanged securely. In addition, the terminal device 30 can easily perform the authentication process by implementing the authentication support program 50 generated by the authentication service device 20. Thus, authentication information 60 and 62 can be exchanged easily and securely between the authentication service device 20 and the terminal device 30.
[0102] The above authentication process may be conducted through a third-party organization or without a third-party organization.
[0103] Furthermore, when the first processing unit 22 authorizes login authentication for the intermediary terminal device 40 via the first communication unit 26, it provides the authentication assistance program 50 to the intermediary terminal device 40 via the first communication unit 26. Therefore, the authentication assistance program 50 can be easily provided to terminal devices 30 located in remote locations via the intermediary terminal device 40.
[0104] Furthermore, for example, terminal device 30 obtains the authentication assistance program 50 through login, implements it on terminal device 30, and performs the authentication process. Therefore, impersonation and other theft are unlikely to occur simply due to key leakage.
[0105] In this process, the first processing unit 22 authenticates the intermediary terminal device 40 through multi-factor authentication login, thereby securely providing the authentication assistance program 50 to the terminal device 30 located in a remote location.
[0106] Furthermore, the first authentication information 60 includes a first private key 60b and a first public key 60a, and the first processing unit 22 generates an authentication assistance program 50 that includes the first public key 60a. Then, using the first public key 60a of the second processing unit 32 and the first private key 60b of the first processing unit 22, the processing unit executes a process to authenticate the authentication service device 20. This allows the authentication service device 20 to be securely authenticated using a public key scheme.
[0107] Furthermore, the first processing unit 22 generates an authentication assistance program 50 that includes a first connection code 70a1, and then, as an authentication service, starts a first authentication service 70a to grant a connection in response to a connection request using the first connection code 70a1 and to execute the first authentication process. Then, the second processing unit 32 executes processing using the first connection code 70a1 based on the authentication assistance program 50, thereby granting permission for the connection of the first authentication service 70a and executing the first authentication process. As a result, the first processing unit 22 can use the first connection code 70a1 to determine whether the processing is being performed by the authentication assistance program 50 that it generated. Thus, the connection for authentication becomes more secure.
[0108] Furthermore, the first processing unit 22 stops the processing of the authentication service device 20 for the first authentication process using the first connection code 70a1, i.e., the first authentication service 70a, after a predetermined validity period has elapsed. For this reason, for example, if a long period of time has elapsed since the creation of the authentication assistance program 50, authentication by the authentication assistance program 50 will no longer be performed, making it difficult for the authentication assistance program 50 to be misused.
[0109] Furthermore, when the authentication service device 20 is authenticated, the second processing unit 32 transmits the second public key 62a from the second authentication information 62 as authentication information to the authentication service device 20, and the first processing unit 22 transmits the second connection code 72a1 to the second processing unit 32. In addition, as an authentication service, the first processing unit 22 starts the second authentication service 72a to grant a connection in response to a connection request using the second connection code 72a1 and to execute the second authentication process.
[0110] Then, the second processing unit 32 executes processing using the second connection code 72a1 based on the authentication assistance program 50, thereby granting permission to connect to the second authentication service 72a and executing the second authentication process.
[0111] Therefore, since authentication of the authentication service device 20 and authentication of the terminal device 30 are performed by access using separate connection codes 70a1 and 72a1, the exchange of authentication information is made more secure.
[0112] Furthermore, when the terminal device 30 is authenticated, the second processing unit 32 can access the first processing unit 22 using the second connection code 72a1, thereby transmitting the data of the terminal device 30 to the authentication service device 20 using the first authentication information 60 and the second authentication information 62. This allows the data of the terminal device 30 to be transmitted to the authentication service device 20 using a connection code different from the one used for initial authentication. By invalidating the connection code used for initial authentication, security can be improved.
[0113] Furthermore, the second authentication information 62 includes a second private key 62b and a second public key 62a, and the second processing unit 32 transmits the second public key 62a to the authentication service device 20 when the authentication service device 20 is authenticated. Then, the second processing unit 32 authenticates the terminal device 30 using the second private key 62b of the second processing unit 32 and the second public key 62a of the first processing unit 22. In this way, the terminal device 30 can be securely authenticated using a public key scheme.
[0114] {Note} This disclosure discloses the following aspects:
[0115] The first embodiment is a mutual authentication system that performs mutual authentication between an authentication service device and a terminal device, wherein the authentication service device comprises a first storage unit for storing first authentication information, a first communication unit, and a first processing unit, and the terminal device comprises a second storage unit for storing second authentication information, a second communication unit, and a second processing unit, wherein the first processing unit generates an authentication support program that causes the terminal device to perform authentication processing with the authentication service device using the first authentication information, provides the authentication support program to the terminal device in an implementable manner, prepares an authentication service associated with the authentication support program, and the first processing unit and the second processing unit are configured to perform mutual authentication when the authentication support program is implemented in the terminal device. The system is a mutual authentication system in which the first and second communication units communicate with each other via the first and second communication units, and further, the second processing unit executes processing according to the authentication assistance program, and the first processing unit executes the authentication service, and the mutual authentication process includes a first authentication process in which the first and second processing units authenticate the authentication service device using the first authentication information, a data transmission and reception process in which the second processing unit transmits authentication information from the second authentication information to the authentication service device when the authentication service device is authenticated, and a second authentication process in which the first and second processing units authenticate the terminal device using the second authentication information.
[0116] This mutual authentication system allows authentication between a terminal device that implements an authentication support program generated by an authentication service device and an authentication service device that performs an authentication service associated with said authentication support program. In this case, authentication does not have to be performed by a third-party organization. Moreover, the authentication service device is authenticated using the first authentication information, and when the authentication service device is authenticated, the second processing unit transmits the authentication information from the second authentication information to the authentication service device. Thus, authentication information can be exchanged securely. Furthermore, the terminal device can easily perform the authentication process by implementing the authentication support program generated by the authentication service device. Thus, authentication information can be exchanged easily and securely between the authentication service device and the terminal device.
[0117] A second embodiment is a mutual authentication system according to the first embodiment, wherein the first processing unit provides the authentication assistance program to the intermediary terminal device via the first communication unit when it has authorized login authentication of the intermediary terminal device via the first communication unit.
[0118] This makes it easier to provide authentication support programs to terminal devices located in remote locations, via intermediary terminal devices.
[0119] The third embodiment is a mutual authentication system according to the second embodiment, wherein the first processing unit authenticates the intermediary terminal device by multi-factor authentication login.
[0120] In this case, since the intermediary terminal device is authenticated through multi-factor authentication login, the authentication support program can be securely provided to terminal devices located in remote locations.
[0121] The fourth aspect is a mutual authentication system relating to any one of the first to third aspects, wherein the first authentication information includes a first private key and a first public key, the first processing unit generates the authentication auxiliary program including the first public key, and the first authentication process is a process that authenticates the authentication service device using the first public key of the second processing unit and the first private key of the first processing unit.
[0122] This allows for secure authentication of the authentication service device using a public key scheme.
[0123] The fifth embodiment is a mutual authentication system relating to any one of the first to fourth embodiments, wherein the first processing unit generates the authentication support program including a first connection code, and further initiates a first authentication service as the authentication service to permit a connection in response to a connection request using the first connection code and to execute the first authentication process, and the second processing unit executes a process using the first connection code based on the authentication support program so that a connection to the first authentication service is permitted and the first authentication process is executed.
[0124] In this case, the authentication assistance program and the first authentication service are associated by a connection code. This allows the first processing unit to use the connection code to determine whether the processing is being performed by an authentication assistance program that it generated.
[0125] The sixth aspect is a mutual authentication system relating to any one of the first to fifth aspects, wherein the first processing unit stops processing the authentication service device for the first authentication process that utilizes the first authentication information after a predetermined time has elapsed.
[0126] In this case, for example, if a long period of time has elapsed since the creation of the authentication assistance program, the authentication of the authentication service device using the first authentication information will be stopped, thereby making it more difficult for the authentication assistance program to be misused.
[0127] The seventh aspect is a mutual authentication system according to the fifth or sixth aspect, wherein when the authentication service device is authenticated, the second processing unit transmits authentication information from the second authentication information to the authentication service device, the first processing unit transmits a second connection code to the second processing unit, and further initiates a second authentication service as the authentication service to permit a connection in response to a connection request using the second connection code and to execute the second authentication process, and the second processing unit executes a process using the second connection code based on the authentication support program so that a connection to the second authentication service is permitted and the second authentication process is executed.
[0128] In this case, since authentication of the authentication service device and authentication of the terminal device are performed by access using separate connection codes, the exchange of authentication information is made more secure.
[0129] The eighth aspect is a mutual authentication system according to the seventh aspect, wherein when the terminal device is authenticated, the second processing unit accesses the first processing unit using the second connection code and transmits the data of the terminal device to the authentication service device using the first authentication information and the second authentication information.
[0130] This allows terminal device data to be transmitted to the authentication service device using a connection code different from the one used for initial authentication. By invalidating the connection code used for initial authentication, security can be improved.
[0131] The ninth aspect is a mutual authentication system relating to any one of the first to eighth aspects, wherein the second authentication information includes a second private key and a second public key, the second processing unit transmits the second public key to the authentication service device when the authentication service device is authenticated, and the second authentication process is a process of authenticating the terminal device using the second private key of the second processing unit and the second public key of the first processing unit.
[0132] This allows for secure authentication of terminal devices using a public key scheme.
[0133] A tenth embodiment is an authentication service device that performs mutual authentication with a terminal device, comprising: an authentication information storage unit that stores first authentication information; a communication unit; and a processing unit, wherein the processing unit generates an authentication auxiliary program that causes the terminal device to perform authentication processing with the authentication service device using the first authentication information, provides the authentication auxiliary program to the terminal device in an implementable manner, prepares an authentication service associated with the authentication auxiliary program, and, by executing the authentication service, communicates with the terminal device on which the authentication auxiliary program is implemented via the communication unit to authenticate the authentication service device using the first authentication information, and when the authentication service device is authenticated, receives authentication information from the second authentication information of the terminal device via the communication unit, and authenticates the terminal device using the second authentication information.
[0134] This authentication service device enables authentication between a terminal device that implements an authentication support program generated by the authentication service device and the authentication service device that performs the authentication service associated with the said authentication support program. Furthermore, the authentication service device is authenticated using the first authentication information, and when the authentication service device is authenticated, it receives the authentication information from the second authentication information. Thus, authentication information can be exchanged securely. In addition, the terminal device can easily perform the authentication process by implementing the authentication support program generated by the authentication service device. Thus, authentication information can be exchanged easily and securely between the authentication service device and the terminal device.
[0135] The eleventh aspect is a mutual authentication method for mutual authentication between an authentication service device and a terminal device, wherein the authentication service device generates an authentication auxiliary program that causes the terminal device to perform an authentication process with the authentication service device using first authentication information, provides the authentication auxiliary program to the terminal device in an implementable manner, prepares an authentication service associated with the authentication auxiliary program, and when the authentication auxiliary program is implemented in the terminal device, communication takes place between the authentication service device and the terminal device, the terminal device performs a process corresponding to the authentication auxiliary program and performs the authentication service, thereby performing a mutual authentication process, the mutual authentication process is a mutual authentication method in which the authentication service device and the terminal device authenticate the authentication service device using the first authentication information, and when the authentication service device is authenticated, the terminal device transmits authentication information from the second authentication information to the authentication service device, and the authentication service device and the terminal device authenticate the terminal device using the second authentication information.
[0136] This mutual authentication method allows authentication between a terminal device that implements an authentication support program generated by an authentication service device and an authentication service device that performs an authentication service associated with said authentication support program. Furthermore, the terminal device authenticates the authentication service device using the first authentication information, and when the authentication service device is authenticated, the terminal device transmits the authentication information from the second authentication information to the authentication service device. Thus, authentication information can be exchanged securely. In addition, the terminal device can easily perform the authentication process by implementing the authentication support program generated by the authentication service device. Thus, authentication information can be exchanged easily and securely between the authentication service device and the terminal device.
[0137] The twelfth aspect is an authentication support program provided to a terminal device for mutual authentication between the authentication service device and the terminal device, the program including information for performing authentication using first authentication information, and causing the terminal device to perform the following: connect to an authentication service executed by the authentication service device and associated with the authentication support program, and perform a process for authenticating the authentication service device using the first authentication information; and, if the authentication service device is authenticated, transmit authentication information from the second authentication information to the authentication service device, and perform a process for authenticating the terminal device using the second authentication information.
[0138] This authentication assistance program is executed on the authentication service device and connects to the authentication service associated with the authentication assistance program. Furthermore, it authenticates the authentication service device using the first authentication information, and when the authentication service device is authenticated, the terminal device transmits the authentication information from the second authentication information to the authentication service device. Thus, authentication information can be exchanged securely. In addition, the terminal device can easily perform the authentication process by implementing the authentication assistance program generated by the authentication service device. Thus, authentication information can be exchanged easily and securely between the authentication service device and the terminal device.
[0139] Furthermore, the configurations described in each of the above embodiments and modifications can be combined as appropriate, as long as they do not contradict each other.
[0140] The functions of the elements disclosed herein can be performed using circuits or processing circuits, including general-purpose processors, dedicated processors, integrated circuits, ASICs (Application Specific Integrated Circuits), conventional circuits, and / or combinations thereof, configured or programmed to perform the disclosed functions. A processor is considered a processing circuit or circuit because it includes transistors and other circuits. In this disclosure, a circuit, unit, or means is hardware that performs the enumerated functions, or hardware programmed to perform the enumerated functions. The hardware may be hardware disclosed herein, or other known hardware that is programmed or configured to perform the enumerated functions. If the hardware is a processor, which is considered a type of circuit, then the circuit, means, or unit is a combination of hardware and software, and the software is used to configure the hardware and / or the processor.
[0141] The above description is illustrative in all respects, and the invention is not limited thereto. It is understood that countless variations not illustrated can be conceivable without falling outside the scope of this invention. [Explanation of Symbols]
[0142] 10 Mutual Authentication Systems 14. Communication Network 20 Authentication Service Device 22 First Processing Unit 24 1st memory section 26. First Communications Department 28a Program 30 Terminal devices 32 Second Processing Unit 34 2nd memory section 36. Second Communications Department 40 Intermediary terminal equipment 50 Authentication Support Programs 60 First Authentication Information 60a First public key 60b 1st private key 62 Second Authentication Information 62a Second public key 62b 2nd private key 70a First Authentication Service 70a1 First connection code 70b First Data Transmission and Reception Service 72a Second Authentication Service 72a1 Second connection code 72b Second Data Transmission and Reception Service 80 Data Upload Service
Claims
1. A mutual authentication system that performs mutual authentication between an authentication service device and a terminal device, The authentication service device is A first storage unit that stores first authentication information, First Communications Department and, The first processing unit and Equipped with, The aforementioned terminal device is A second storage unit that stores the second authentication information, The Second Communications Department and, The second processing unit and Equipped with, The first processing unit, The terminal device generates an authentication support program that uses the first authentication information to perform authentication processing with the authentication service device. The aforementioned authentication support program is provided in a manner that can be implemented in the terminal device. Prepare an authentication service associated with the aforementioned authentication assistance program, By implementing the authentication assistance program in the terminal device, the first processing unit and the second processing unit communicate via the first communication unit and the second communication unit. Furthermore, the second processing unit executes processing according to the authentication assistance program, and the first processing unit executes the authentication service, thereby performing mutual authentication processing. The aforementioned mutual authentication process is: The first processing unit and the second processing unit perform a first authentication process in which they authenticate the authentication service device using the first authentication information, When the authentication service device is authenticated, the second processing unit performs a data transmission and reception process to send the authentication information from the second authentication information to the authentication service device. A mutual authentication system comprising: a first processing unit and a second processing unit, which authenticate the terminal device using the second authentication information; and a second authentication process.
2. A mutual authentication system according to claim 1, A mutual authentication system in which the first processing unit provides the authentication assistance program to the intermediary terminal device via the first communication unit when it authorizes login authentication of the intermediary terminal device via the first communication unit.
3. A mutual authentication system according to claim 2, The first processing unit is a mutual authentication system that authenticates the intermediary terminal device through multi-factor authentication login.
4. A mutual authentication system according to any one of claims 1 to 3, The aforementioned first authentication information includes a first private key and a first public key, The first processing unit generates the authentication assistance program including the first public key, The first authentication process is a process of authenticating the authentication service device using the first public key of the second processing unit and the first private key of the first processing unit, in a mutual authentication system.
5. A mutual authentication system according to any one of claims 1 to 3, The first processing unit is, The authentication assistance program, including the first connection code, is generated. Furthermore, as the authentication service, a first authentication service is started to grant a connection in response to a connection request using the first connection code and to execute the first authentication process. A mutual authentication system in which the second processing unit executes processing using the first connection code based on the authentication assistance program, thereby granting permission to connect to the first authentication service and executing the first authentication process.
6. A mutual authentication system according to any one of claims 1 to 3, A mutual authentication system in which the first processing unit stops processing the authentication service device for the first authentication process that uses the first authentication information after a predetermined time has elapsed.
7. A mutual authentication system according to claim 5, When the authentication service device is authenticated, the second processing unit transmits the authentication information from the second authentication information to the authentication service device, the first processing unit transmits the second connection code to the second processing unit, and further initiates a second authentication service as the authentication service to permit a connection in response to a connection request using the second connection code and to execute the second authentication process. A mutual authentication system in which the second processing unit executes processing using the second connection code based on the authentication assistance program, thereby granting permission to connect to the second authentication service and executing the second authentication process.
8. A mutual authentication system according to claim 7, A mutual authentication system in which, when the terminal device is authenticated, the second processing unit accesses the first processing unit using the second connection code, and transmits data from the terminal device to the authentication service device using the first authentication information and the second authentication information.
9. A mutual authentication system according to any one of claims 1 to 3, The aforementioned second authentication information includes a second private key and a second public key, The second processing unit transmits the second public key to the authentication service device when the authentication service device is authenticated. The second authentication process is a mutual authentication system in which the terminal device is authenticated using the second secret key of the second processing unit and the second public key of the first processing unit.
10. An authentication service device that performs mutual authentication with terminal devices, A first authentication information storage unit stores the authentication information, Communications Department and, Processing unit and Equipped with, The aforementioned processing unit, The terminal device generates an authentication support program that uses the first authentication information to perform authentication processing with the authentication service device. The aforementioned authentication support program is provided in a manner that can be implemented in the terminal device. Prepare an authentication service associated with the aforementioned authentication assistance program, By executing the authentication service, the authentication service device is authenticated using the first authentication information by communicating with the terminal device on which the authentication assistance program is implemented via the communication unit. When the authentication service device is authenticated, the authentication information from the second authentication information of the terminal device is received via the communication unit. An authentication service device that authenticates the terminal device using the second authentication information.
11. A mutual authentication method for performing mutual authentication between an authentication service device and a terminal device, The authentication service device is The terminal device generates an authentication support program that uses the first authentication information to perform authentication processing with the authentication service device. The aforementioned authentication support program is provided in a manner that can be implemented in the terminal device. Prepare an authentication service associated with the aforementioned authentication assistance program, When the authentication assistance program is implemented in the terminal device, communication takes place between the authentication service device and the terminal device. The terminal device performs a process corresponding to the authentication assistance program and executes the authentication service, thereby performing mutual authentication. The aforementioned mutual authentication process is: The authentication service device and the terminal device authenticate the authentication service device using the first authentication information. When the authentication service device is authenticated, the terminal device transmits the authentication information from the second authentication information to the authentication service device. A mutual authentication method in which the authentication service device and the terminal device authenticate the terminal device using the second authentication information.
12. An authentication assistance program provided to a terminal device for mutual authentication between the authentication service device and the terminal device, Includes information for performing authentication using the first authentication information, The aforementioned terminal device, The process involves connecting to an authentication service that is executed on the authentication service device and associated with the authentication assistance program, and authenticating the authentication service device using the first authentication information. When the authentication service device is authenticated, the authentication information from the second authentication information is transmitted to the authentication service device. A process for authenticating the terminal device using the second authentication information, A program to execute.