Information processing device, program, and method

The enhanced telephone authentication system addresses vulnerabilities in existing systems by using a purpose confirmation mechanism within the information processing device, program, and method, thereby enhancing security and preventing fraudulent activities.

JP7674801B1Active Publication Date: 2025-05-12유겐가이샤티아이에스 +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024231692
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-12
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

Existing telephone authentication systems are vulnerable to fraudulent activities where malicious third parties can deceive users into making calls from their registered numbers, leading to unauthorized changes in user registration information.

Method used

An information processing device, program, and method that enhance telephone authentication security by incorporating a purpose confirmation mechanism. This involves acquiring authentication request information with purpose identification, issuing an authentication telephone number, accepting calls to this number, transmitting a purpose confirmation message, obtaining a response, and determining authentication success based on the purpose identification and response.

Benefits of technology

The proposed solution significantly improves the security of telephone authentication by ensuring that only legitimate calls from authorized users can proceed with authentication, thereby preventing unauthorized changes to user registration information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007674801000001_ABST
    Figure 0007674801000001_ABST
Patent Text Reader

Abstract

Improve the security of phone authentication. [Solution] The system includes an authentication request acquisition unit 1013 that acquires authentication request information including purpose identification information that identifies the purpose of user authentication via telephone, a number issuing unit 1014 that issues an authentication phone number used for authentication in association with the purpose identification information, a call receiving unit 1015 that accepts calls to the authentication phone number via a user call terminal 201, a purpose confirmation unit 1016 that sends a purpose confirmation message associated with the purpose identification information to the user call terminal 201 and acquires a response to the purpose confirmation message from the user call terminal 201, and an authentication determination unit 1017 that determines whether authentication is successful or not based on the purpose identification information and the response.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing device, a program, and a method. [Background technology]

[0002] Telephone authentication using the user's telephone is used as an authentication method for identity verification when a user uses some service. Examples of telephone authentication include a method in which the user inputs a message to be sent to the user's telephone number from a web browser, a method in which a call is made to the user's telephone number and the user's answering of the call is confirmed, a method in which the user makes a call to a telephone number for authentication, or a method in which a telephone number from which a user makes a call is registered and authentication processing is performed based on a call from the registered telephone number (e.g., Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2015-184716 A Summary of the Invention [Problem to be solved by the invention]

[0004] A third party may obtain information for a user other than the third party to log in to the server by phishing through a fake website, and may attempt to change the registered information of the user in the server for unauthorized use. In this case, the server may request the third party disguised as the user to perform telephone authentication by calling from the user's registered telephone number, in order to check whether the change in the registered information has been unauthorized, using an authentication system. In this case, a malicious third party who receives a notice of telephone authentication from the server may present a notice similar to the notice to the user on a fake website and have the user make a call, thereby attempting to break through the authentication. In this way, if a third party deceives a user and then the user makes a call, the authentication system may determine that the call is a legitimate call from the user's telephone number, and unauthorized operations such as changing the registered information may be successful. Therefore, a more secure authentication method is required.

[0005] SUMMARY OF THE PRESENT EMBODIMENTS Accordingly, an object of the present invention is to provide an information processing device, a program, and a method that can improve the security of telephone authentication. [Means for solving the problem]

[0006] An information processing device according to one embodiment of the present disclosure includes an authentication request acquisition unit that acquires authentication request information including purpose identification information that identifies the purpose of a user's authentication by telephone, a number issuing unit that, when the authentication request information is acquired, issues an authentication phone number to be used for authentication in association with the purpose identification information, a call receiving unit that accepts calls to the authentication phone number through a user calling terminal, a purpose confirmation unit that, during a call with the user, sends a purpose confirmation message associated with the purpose identification information to the user calling terminal and acquires a response to the purpose confirmation message from the user calling terminal, and an authentication determination unit that determines whether the authentication is successful or not based on the purpose identification information and the response.

[0007] A program relating to another aspect of the present disclosure causes a computer to perform the following operations: acquire authentication request information including purpose identification information that identifies the purpose of authentication of a user by telephone and the user's user telephone number; when the authentication request information is acquired, issue an authentication telephone number to be used for authentication in association with the purpose identification information; accept a call to the authentication telephone number through the user's calling terminal; in a call with the user, send a purpose confirmation message associated with the purpose identification information to the user's calling terminal and acquire a response to the purpose confirmation message from the user's calling terminal; and determine whether the authentication is successful or not based on the purpose identification information and the response.

[0008] A method according to another aspect of the present disclosure includes a computer acquiring authentication request information including purpose identification information identifying a purpose of authentication of a user by telephone and the user's user telephone number; when the authentication request information is acquired, issuing an authentication telephone number to be used for authentication in association with the purpose identification information; accepting a call to the authentication telephone number through the user's calling terminal; during a call with the user, sending a purpose confirmation message associated with the purpose identification information to the user's calling terminal and acquiring a response to the purpose confirmation message from the user's calling terminal; and determining whether the authentication is successful or not based on the purpose identification information and the response. Effect of the Invention

[0009] According to the present invention, it is possible to provide an information processing device, a program, and a method capable of improving the security of telephone authentication. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 is a schematic diagram of a telephone authentication system. [Diagram 2] FIG. 2 is a block diagram of each device or terminal in the telephone authentication system. [Diagram 3] FIG. 4 is a diagram illustrating information stored in the telephone authentication device. [Figure 4] FIG. 11 is a diagram illustrating other information stored in the telephone authentication device. [Diagram 5] FIG. 2 is a diagram illustrating an example of information stored in a service provider device. [Figure 6] FIG. 2 is a diagram illustrating a process flow in a telephone authentication system. [Figure 7] FIG. 13 is a diagram showing an example of a screen displayed on a user's terminal. [Figure 8] 11 is a diagram illustrating a number issuing process in the telephone authentication device. FIG. [Figure 9] 11 is a diagram illustrating an authentication process in the telephone authentication device. FIG. [Figure 10] FIG. 2 is a diagram illustrating an operation input by a user. [Figure 11] FIG. 10 is a diagram illustrating an example of an unauthorized authentication attempt by a third party. [Figure 12] FIG. 13 is a diagram illustrating an example of a screen displayed in the case of unauthorized authentication. [Figure 13] FIG. 13 is a diagram illustrating an operation input by a user in the case of unauthorized authentication. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will now be described with reference to the accompanying drawings, in which like reference numerals denote like or similar configurations.

[0012] 1 shows a block diagram illustrating an outline of a telephone authentication system 10 according to the present embodiment. The telephone authentication system 10 includes a telephone authentication device 101, a user calling terminal 201, and a service provider device 301. In the telephone authentication system 10, the telephone authentication device 101, the user calling terminal 201, and the service provider device 301 are connected to a network N. The network N is, for example, the Internet. In the telephone authentication system 10, the telephone authentication device 101 and the service provider device 301 communicate with each other through the network N, and the user calling terminal 201 and the service provider device 301 communicate with each other through the network N.

[0013] In the telephone authentication system 10, the telephone authentication device 101 and the user telephone terminal 201 can be connected through a telephone line. The telephone line may include not only an analog line or a digital line, but also the Internet network or a wireless line to which an IP telephone or the like can be connected.

[0014] In the telephone authentication system 10, when a user who uses a service provided by the service provider device 301 performs some operation on the service provider device 301, the service provider device 301 requests the telephone authentication device 101 to issue an authentication telephone number. The authentication telephone number issued by the telephone authentication device 101 is presented to the user through the service provider device 301. Authentication is performed by a user call terminal 201 making a call to the telephone authentication device 101. In response to an authentication result request from the service provider device 301, the telephone authentication device 101 transmits an authentication result, and processing according to the authentication result is performed.

[0015] The authentication is performed, for example, when a user performs an operation to change information about the user registered in the service provider device 301. Alternatively, the authentication may be performed when an operation such as user registration is first performed on the service provider device 301, or when a user's phone number is registered. Whether or not telephone authentication is required can be appropriately set according to the desires of the administrator of the service provider device 301.

[0016] The telephone authentication device 101 is a server device having a computer that performs a predetermined process by executing a predetermined program stored in the telephone authentication device 101 .

[0017] The user calling terminal 201 is, for example, a calling device used by the user to make a call to the telephone authentication device 101, and is, for example, a smartphone. The user calling terminal 201 has a function capable of browsing a website provided by the service provider device 301. The type of website provided by the service provider device 301 is not limited, but in the example described below, a website provided by a credit card company will be described as an example. In this embodiment, the user calling terminal 201 in which the browsing function of the calling function is integrated into one terminal will be described as an example, but the user calling terminal 201 may be a fixed telephone terminal having only a calling function. When the user calling terminal 201 is a fixed telephone terminal, the user operates a terminal (such as a smartphone, a tablet terminal, or a personal computer) capable of browsing the website provided by the service provider device 301 to browse the website.

[0018] The service provider device 301 is a server device having a computer that performs a predetermined process by executing a predetermined program stored in a storage unit of the service provider device 301. The service provider device 301 is a device that provides services to individual users by users logging in through a browser. The service provider device 301 is, for example, a device managed by a credit card company, and is a device that enables users to change and set their registration information.

[0019] The individual components of the telephone authentication device 101, the user's telephone terminal 201, and the service provider device 301 will be described with reference to FIG.

[0020] The telephone authentication device 101 includes a communication unit 1011 , a storage unit 1012 , an authentication request acquisition unit 1013 , a number issuing unit 1014 , a power receiving unit 1015 , a purpose confirmation unit 1016 , an authentication judgment unit 1017 , and an update unit 1018 .

[0021] The communication unit 1011 controls communication with the service provider device 301 via the network N.

[0022] The storage unit 1012 stores various information used in the processes in the telephone authentication device 101. The storage unit 1012 has an authentication object DB 10121 and an authentication telephone number DB 10122.

[0023] 3, a description will be given of information stored in the authentication purpose DB 10121. The authentication purpose DB 10121 stores "business identification information", "purpose identification information", "authentication purpose", "purpose confirmation message", and "authentication judgment criteria".

[0024] As the "business identification information", information for identifying a business that is an administrator of the service provider device 301 and uses the telephone authentication service using the telephone authentication device 101 is stored. In the example of Fig. 3, "AAA" corresponding to business A and "BBB" corresponding to business B are stored as the business identification information.

[0025] As the "purpose identification information", information for identifying the purpose of telephone authentication, that is, the reason why telephone authentication is required, is stored. The purpose identification information is identification information assigned to each business operator. In the example of FIG. 3, the purpose identification information "1A", "2A", ... "6A" is associated with the business operator identification information "AAA" (business operator A), and the purpose identification information "1B", "2B" is associated with the business operator identification information "BBB" (business operator B). As the "authentication purpose", information indicating the reason why telephone authentication is required is stored. In the example of FIG. 3, the purpose identification information "1A" is associated with "email address change" and the purpose identification information "2A" is associated with "address change" as the authentication purpose, and stored. The authentication purpose can be arbitrarily set for any purpose identification information. In the example of FIG. 3, the authentication purpose of "address change" is associated with the purpose identification information "1B", and the authentication purpose of "email address change" is associated with the purpose identification information "2B". The association of the purpose identification information and the authentication purpose may be performed by setting the contents selected by each business operator in the telephone authentication device 101.

[0026] As the "purpose confirmation message", a purpose confirmation message transmitted from the telephone authentication device 101 to the user calling terminal 201 during telephone authentication is stored. In the example of FIG. 3, a purpose confirmation message corresponding to the case where the authentication purpose is "email address change" is stored as "message 1". Also, a purpose confirmation message corresponding to the case where the authentication purpose is "address change" is stored as "message 2". The purpose confirmation message may be voice data which is the call voice itself in a voice call with the user calling terminal 201, or may be character data which indicates the wording of the message itself. When the purpose confirmation message is character data, the voice data can be transmitted to the user calling terminal 201 by a voice reading function of the telephone authentication device 101.

[0027] As the "authentication judgment criterion", information that is a criterion for judging whether or not a user who has received a purpose confirmation message is making a call for authentication purposes is stored. For example, for purpose confirmation message 1, information is stored indicating that authentication is judged to be successful when a tone signal of "1" is sent from the user, and that authentication is judged to be unsuccessful when other tone signals are sent. For purpose confirmation message 2, information is stored indicating that authentication is judged to be successful when a tone signal of "2" is sent from the user, and that authentication is judged to be unsuccessful when other tone signals are sent. The authentication judgment criterion is set according to the contents of the purpose confirmation message. Here, the authentication judgment criterion is dynamically set. The authentication judgment criterion is randomly assigned a numerical value after a call from a user is received and it is confirmed that the authentication expiration date of the caller number and the authentication phone number is within the valid period. This makes it possible to prevent the same authentication judgment criterion from being reused each time authentication is performed, so that authentication can be performed more accurately.

[0028] 4, the information stored in the authentication telephone number DB 10122 will be described. The authentication telephone number DB 10122 stores information related to the authentication telephone number issued in response to a request from the service provider device 301. The authentication telephone number DB 10122 stores an "authentication telephone number", a "user telephone number", "purpose identification information", "authentication purpose", "authentication result", and an "authentication expiration date".

[0029] As the "authentication phone number", a phone number for authentication issued by the number issuing unit 1014 described later is stored. The authentication phone number is issued for each authentication, and in the example of FIG. 4, it is stored as "0800-XXX-1111", "0800-XXX-2222", and "0800-XXX-3333".

[0030] As the "user phone number", a phone number used by the user for telephone authentication, which is included in the information acquired by the telephone authentication device 101 from the service provider device 301 during authentication, is stored. The user phone numbers are stored in association with each authentication phone number. In the example of FIG. 3, the authentication phone number "080...1111" is associated with the user phone number "080...", the authentication phone number "080...2222" is associated with the user phone number "070...", and the authentication phone number "080...3333" is associated with the user phone number "090...".

[0031] As the "purpose identification information", purpose identification information included in information that the telephone authentication device 101 acquires from the service provider device 301 during authentication is stored. As the "authentication purpose", an authentication purpose corresponding to the purpose identification information is stored. As the "authentication purpose", the telephone authentication device 101 refers to the authentication purpose DB 10121 according to the purpose identification information acquired from the service provider device 301, and the authentication purpose corresponding to the purpose identification information is stored.

[0032] As the "authentication result", the result of authentication based on a call from the user telephone number to the authentication telephone number is stored. As the "authentication expiration date", the expiration date of authentication using the authentication telephone number is stored. The authentication expiration date is set when the number issuing unit 1014 issues a number. The length of the authentication expiration date can be set appropriately by the business operator or the administrator of the telephone authentication device 101. In the example of FIG. 4, the authentication result of authentication using the authentication telephone number "0800...1111" is "waiting for authentication", and the authentication expiration date is "2024 / 12 / 16 20:00:00" is stored. As the authentication result, the authentication result of authentication using the authentication telephone number "0800...2222" is "authentication successful", and the authentication result of authentication using the authentication telephone number "0800...3333" is "authentication failed". The authentication result is updated according to the authentication judgment result by the authentication judgment unit 1017 described later. Note that even if the authentication judgment unit 1017 judges that the authentication expiration date has passed, "authentication failure" is stored.

[0033] Returning to FIG. 2, the description of each unit of the telephone authentication device 101 will be continued. The authentication request acquisition unit 1013 acquires authentication request information including purpose identification information for identifying the purpose of authentication of a user by telephone. The authentication request acquisition unit 1013 acquires the authentication request information from the service provider device 301. The authentication request information includes business identification information, purpose identification information, and a user telephone number. The authentication request information is transmitted to the authentication request acquisition unit 1013 when the service provider device 301, which will be described later, requests the telephone authentication device 101 to perform authentication by telephone.

[0034] When the number issuing unit 1014 acquires authentication request information, it issues an authentication telephone number used for authentication in association with the purpose identification information. The number issuing unit 1014 updates the authentication telephone number DB 10122 using the issued authentication telephone number. The number issuing unit 1014 may store the authentication telephone number in association with the user telephone number in addition to the purpose identification information. Furthermore, when issuing an authentication telephone number, the number issuing unit 1014 may set an authentication deadline and update the authentication telephone number DB 10122 in association with the authentication telephone number. The number issuing unit 1014 pools a plurality of telephone numbers in a state of being assigned to each of the businesses, and when it acquires authentication request information, it issues the pooled telephone number as the authentication telephone number. At this time, a telephone number whose authentication deadline has passed may be returned to the pool so that it can be issued again after being determined as authentication failure.

[0035] The power receiving unit 1015 accepts a call to the authentication telephone number through the user's telephone terminal. The power receiving unit 1015 accepts a call to the authentication telephone number by controlling communication using a telephone line. The power receiving unit 1015 also determines whether the caller's number is a call from a user telephone number associated with the authentication telephone number. If the call is not a call from the user telephone number, the power receiving unit 1015 determines that authentication has failed.

[0036] The purpose confirmation unit 1016 transmits a purpose confirmation message associated with purpose identification information to the user's call terminal 201 during a call with the user, and acquires a response to the purpose confirmation message from the user's call terminal 201. When the call receiving unit 1015 determines that the call is from the user's phone number, the purpose confirmation unit 1016 refers to the authentication phone number DB 10122 and identifies purpose identification information associated with the authentication phone number or the user phone number. The purpose confirmation unit 1016 refers to the authentication purpose DB 10121 and identifies a purpose confirmation message corresponding to the purpose identification information. The purpose confirmation unit 1016 transmits the identified purpose confirmation message to the user's call terminal 201.

[0037] In the case of message 1 for changing an email address, the purpose confirmation message is a voice message (message example 1) stating, "This telephone authentication will change the registered email address. If you agree, enter 1. If not, enter 2." This purpose confirmation message includes an option to confirm whether the purpose of the call corresponds to the purpose identification information.

[0038] The purpose confirmation message is a voice message (Message Example 2) stating, "The following operations will be performed with this telephone authentication. Please enter the number of the appropriate operation. 1: Change the registered email address, 2: Change the registered address, 3: Other changes, 4: An operation other than the change operation." This purpose confirmation message includes multiple options, with option "1" corresponding to the purpose for which the call was made, and options "2," "3," and "4" corresponding to other purposes different from the purpose for which the user made the call.

[0039] The purpose confirmation message is a voice message (Message Example 3) stating, "This telephone authentication will change the registered email address. If you agree, please answer "Yes." If not, please answer "No." This purpose confirmation message includes an option to confirm whether the purpose of the call corresponds to the purpose identification information.

[0040] The purpose confirmation unit 1016 acquires a response to the purpose confirmation message. The response acquired corresponds to the content of the purpose confirmation message. For example, the response to the message example 1 is to input 1 as a tone signal if the call is made for the purpose of authenticating the change of the email address, and 2 otherwise, and the response is a tone signal of "1" or a tone signal of "2". The response to the message example 2 is to input 1 as a tone signal if the call is made for changing the email address, 2 as a tone signal if the call is made for changing the address, 3 as a tone signal if the call is made for other changes, and 4 as a tone signal if the call is made for an operation other than the change operation, and the response is any one of the tone signals "1" to "4". The response to the message example 3 is to input "yes" as a voice signal if the call is made for the purpose of authenticating the change of the email address, and "no" otherwise, and the response is a voice signal including "yes" or "no".

[0041] The authentication judgment unit 1017 judges whether the authentication is successful or not based on the purpose identification information and the response. Specifically, the authentication judgment unit 1017 judges that the authentication is successful when the response indicates that the purpose for which the user made the call corresponds to the purpose identification information, and judges that the authentication is unsuccessful when the response indicates that the purpose for which the user made the call does not correspond to the purpose identification information. The authentication judgment unit 1017 interprets the response acquired by the purpose confirmation unit 1016. When the response is a tone signal, the authentication judgment unit 1017 judges the number indicated by the tone signal, and identifies the authentication judgment criterion corresponding to the purpose confirmation message sent by the purpose confirmation unit 1016 by referring to the authentication purpose DB 10121.

[0042] The authentication judgment unit 1017 judges whether the authentication is successful or unsuccessful based on the authentication judgment criteria. For example, if a tone signal indicating "1" is received as a response to the message 1 corresponding to the purpose identification information 1A, the purpose of the user's call is to change the email address, which matches the authentication judgment criteria, so the authentication judgment unit 1017 judges that the authentication is successful. On the other hand, if a tone signal indicating anything other than "1" is received as a response to the message 1 corresponding to the purpose identification information 1A, the purpose of the user's call is not to change the email address, so the authentication judgment unit 1017 judges that the authentication is unsuccessful. The authentication judgment unit 1017 updates the authentication result stored in the authentication phone number DB 10122 according to the judgment on the authentication.

[0043] If the response is a voice signal uttered by the user, the authentication assessment unit 1017 analyzes the acquired voice signal and identifies the content of the utterance indicated by the voice signal. The authentication assessment unit 1017 judges whether the authentication is successful or unsuccessful based on an authentication judgment criterion set for the content of the utterance, for example, a criterion that authentication is successful if "yes" is given.

[0044] The update unit 1018 updates the purpose identification information associated with each of the business operator identification information. The update unit 1018 receives information for setting the purpose identification information associated with each of the business operator identification information, for example, by access from an administrator of the service provider device 301, and updates the purpose identification information associated with each of the business operator identification information based on the received information. This makes it possible to set purpose identification information that meets the needs of the business operator.

[0045] Next, the user calling terminal 201 will be described. The user calling terminal 201 has a communication unit 2011, a display unit 2012, a calling unit 2013, and an input unit 2014. The communication unit 2011 controls communication between the user calling terminal 201 and the service provider device 301. The display unit 2012 controls displaying a website provided by the service provider device 301. The calling unit 2013 controls a call through a telephone line between the user calling terminal 201 and the telephone authentication device 101. The input unit 2014 controls receiving input of a response to a purpose confirmation message.

[0046] Next, the service provider device 301 will be described. The service provider device 301 has a communication unit 3011, a storage unit 3012, and a control unit 3013. The communication unit 3011 controls communication between the service provider device 301 and the telephone authentication device 101 and the user calling terminal 201. The storage unit 3012 has a user DB 30121. The control unit 3013 controls the screen display of a website to be displayed on the user calling terminal 201.

[0047] 5 shows an example of information stored in the user DB 30121. The user DB 30121 stores information about users, such as "user identification information," "user phone number," "user email address," "user basic information," and "login password."

[0048] As "user identification information", information for managing individual users when the service provider device 301 provides a service is stored. As "user phone number", the phone number of each user is stored. As "user email address", the email address of each user is stored. As "user basic information", basic information of each user, such as an address, is stored. As "login password", a password for the user to log in to a website provided by the service provider device 301 is stored. In the example of FIG. 5, it is stored that the user with user identification information "USER01" has a user phone number of "080-XXXX-XXXX" and a user email address of "aaa@...".

[0049] The flow of authentication by the telephone authentication system 10 will be described with reference to Fig. 6. In Fig. 6 and other figures, communication through the network N is indicated by a solid line, and communication for a call through a telephone line is indicated by a dashed line.

[0050] In step S601, a user logs in to the service provider device 301 through the user telephone terminal 201. When logging in, for example, login authentication is performed using user identification information and a login password.

[0051] In step S602, a request to change the registered information is sent from the user who has successfully logged in to the service provider device 301 by operating the user telephone terminal 201. The request to change the registered information is, for example, a request to change the email address registered in the service provider device 301.

[0052] In step S603, the service provider device 301 identifies the object to be changed based on the change request. For example, the service provider device 301 identifies that the object for which the user is requesting to change is an email address.

[0053] In step S604, the service provider device 301 transmits to the user calling terminal 201 information for the user to confirm the contents of the changes through a website screen displayed on the user calling terminal 201. If the service provider device 301 stores information indicating that the change target identified in step S603 requires telephone authentication, the service provider device 301 transmits to the user information for the user to confirm the contents of the changes, including information for accepting operation input for telephone authentication, on a screen displayed on the user calling terminal 201.

[0054] In step S605, an operation for telephone authentication is acquired through a screen displayed on the user's call terminal 201. This operation is performed, for example, through a purpose confirmation screen 701 shown in FIG. 7. The purpose confirmation screen 701 displays that a registered email address is to be changed and displays the email addresses before and after the change. In addition, an authentication request button 7011 for acquiring an operation for telephone authentication is arranged on the purpose confirmation screen 701. When the user selects the authentication request button 7011, an operation for telephone authentication is acquired.

[0055] In step S 606 , the service provider device 301 receives a request for telephone authentication from the user's telephone terminal 201 .

[0056] In step S607, the service provider device 301 transmits authentication request information to the telephone authentication device 101. At this time, the service provider device 301 transmits the authentication request information including business identification information of the service provider, a user telephone number stored in the service provider device 301, and purpose identification information corresponding to the purpose of the telephone authentication.

[0057] In step S608, the telephone authentication device 101 performs a number issuing process. The details of the number issuing process will be described later.

[0058] In step S609, the issued authentication telephone number is transmitted from the telephone authentication device 101 to the service provider device 301. In step S610, the authentication telephone number is transmitted from the service provider device 301 to the user call terminal 201.

[0059] In step S611, the authentication phone number is displayed on the user call terminal 201. The authentication phone number is displayed on the user call terminal 201 as in a number display screen 702 shown in Fig. 7. On the number display screen 702, a message is displayed requesting that a call be made from the registered user phone number to the number displayed in the number display field 7021.

[0060] The number issuing process will be described with reference to Fig. 8. In step S801, the authentication request acquiring unit 1013 acquires authentication request information from the service provider device 301. In step S802, the number issuing unit 1014 refers to purpose identification information included in the authentication request information. For example, when authentication request information is sent from business A for the purpose of changing an email address, the number issuing unit 1014 refers to "1A" as purpose identification information.

[0061] In step S803, the number issuing unit 1014 refers to the user phone number included in the authentication request information.

[0062] In step S804, the number issuing unit 1014 issues an authentication telephone number.

[0063] In step S805, the number issuing unit 1014 stores the authenticated telephone number in association with the purpose identification information and the user telephone number. Specifically, the number issuing unit 1014 updates the authenticated telephone number DB 10122 to store the authenticated telephone number. At this time, the number issuing unit 1014 sets the default authentication result as "waiting for authentication".

[0064] In step S806, the number issuing unit 1014 updates the authenticated telephone number DB 10122 so as to set a validity period for the authenticated telephone number.

[0065] 6, in step S612, the user call terminal 201 makes a call to the authentication telephone number issued through the number issuing process. The call to the authentication telephone number is routed as a call to the telephone authentication device 101 through the telephone line.

[0066] In step S613, the receiving unit 1015 and the purpose confirmation unit 1016 perform a receiving process. In the receiving process, the receiving unit 1015 compares the caller's telephone number with the user telephone number associated with the authentication telephone number of the callee, and determines whether the call is from the user telephone number associated with the authentication telephone number and whether the authentication deadline associated with the authentication telephone number has not passed at the time of the call. If the call is not from the user telephone number or the authentication deadline has passed, the receiving unit 1015 records the authentication failure and ends the call. If the call is from the user telephone number and the authentication deadline has not passed at the time of the call, the purpose confirmation unit 1016 identifies the purpose identification information associated with the user telephone number and the purpose confirmation message corresponding to the purpose identification information. After the receiving process, in step S614, a call between the user call terminal 201 and the telephone authentication device 101 starts.

[0067] In step S615, the telephone authentication device 101 performs authentication processing. The authentication processing includes sending and receiving information via telephone with the user call terminal 201. The authentication processing will be described later.

[0068] In step S616, the service provider device 301 transmits an authentication result request to the telephone authentication device 101 to inquire about the authentication result. In step S617, the telephone authentication device 101 transmits the authentication result to the service provider device 301, for example, via the authentication judgment unit 1017. In step S618, the service provider device 301 transmits information to the user call terminal 201 for displaying a screen showing the authentication result on the user call terminal 201. This completes the authentication by the telephone authentication system 10. The user can grasp the authentication result through the user call terminal 201.

[0069] The authentication process will be described with reference to Fig. 9. In step S901, the purpose confirmation unit 1016 transmits a purpose confirmation message to the user's call terminal 201 through a telephone line.

[0070] In step S902, the user call terminal 201 acquires, via the input unit 2014, an input for responding to the purpose confirmation message.

[0071] In step S903, the purpose confirmation unit 1016 acquires from the user call terminal 201 a response to the purpose confirmation message.

[0072] Obtaining a response to the purpose confirmation message will be described with reference to FIG. 10. The user hears the message "This telephone authentication will change your registered email address. If you agree, enter 1. If not, enter 2" through the user calling terminal 201. The user inputs the response as a tone signal through the input screen 1001 of the user calling terminal 201. If the user's purpose is to change the email address, the input indicating the response to the purpose confirmation message is "1." In this case, the call unit 2013 transmits the tone signal of "1" to the telephone authentication device 101 as the response.

[0073] Returning to FIG. 9, in step S904, the authentication determination unit 1017 determines whether or not the purpose for which the user made the call corresponds to the purpose identification information.

[0074] In step S905 (step S904: NO), the authentication assessment unit 1017 records the authentication failure in association with the authenticated phone number, and ends the call.

[0075] In step S906 (step S904: YES), the authentication assessment unit 1017 records the successful authentication in association with the authenticated phone number.

[0076] In step S907, the authentication determination unit 1017 transmits a message indicating that the authentication has been successful to the user call terminal 201. The message is, for example, a voice message saying "Authentication has been successful."

[0077] In step S908, the call is ended by an operation on the user call terminal 201 or by processing by the telephone authentication device 101.

[0078] Advantages of telephone authentication by the telephone authentication system 10 will be described with reference to Figs. 11 to 13. Fig. 11 shows an example of processing when a third party with fraudulent intentions attempts to change registered information without the user's intention. More specifically, this is a case where a third party who has acquired a user's user identification information and login password through a phishing site attempts to change the user's email address in the service provider device 301. The email address is changed for fraudulent use of a credit card, for example, when credit card use confirmation is performed by sending a confirmation code to a registered email address. If a setting is made such that a confirmation code for credit card use is sent to an email address set by a third party, the third party will be able to freely use the card.

[0079] In step S1101, a third party who has acquired the user's user identification information and login password via a phishing site or the like logs into the service provider device 301 through the third party terminal 401. At this time, the service provider device 301 cannot detect that the login has been made by a third party.

[0080] In step S1102, a request to change the registered information is transmitted from third-party terminal 401. The request to change the registered information is, for example, a request to change an email address.

[0081] In step S1103, the service provider device 301 identifies the object to be changed based on the change request. For example, the service provider device 301 identifies that the object for which the user is requesting to change is an email address.

[0082] In step S1104, the service provider device 301 transmits information to the third party terminal 401 for prompting the user to confirm the contents of the changes through the website screen displayed on the third party terminal 401. If the service provider device 301 stores information indicating that the change target identified in step S603 requires telephone authentication, the service provider device 301 transmits information for prompting the user to confirm the contents of the changes to the screen displayed on the third party terminal 401, including information for accepting operation input for telephone authentication.

[0083] In step S1105, an operation for telephone authentication is acquired through a screen displayed on third-party terminal 401. This operation is performed, for example, through purpose confirmation screen 1201 shown in Fig. 12. Purpose confirmation screen 1201 displays that a registered email address will be changed, the email addresses before and after the change, and has authentication request button 12011 for acquiring an operation for telephone authentication. When the third party selects authentication request button 12011, an operation for telephone authentication is acquired.

[0084] In step S 1106 , the service provider device 301 receives a request for telephone authentication from the third party terminal 401 .

[0085] In step S1107, the service provider device 301 transmits authentication request information to the telephone authentication device 101. At this time, the service provider device 301 transmits the authentication request information including business identification information of the service provider, a user telephone number stored in the service provider device 301, and purpose identification information corresponding to the purpose of the telephone authentication.

[0086] In step S1108, the telephone authentication device 101 performs a number issuing process.

[0087] In step S1109, the issued authentication telephone number is transmitted from telephone authentication device 101 to service provider device 301. In step S1110, the authentication telephone number is transmitted from service provider device 301 to third party terminal 401. The authentication telephone number transmitted to third party terminal 401 is displayed in number display field 12021 on number display screen 1202 shown in FIG.

[0088] The third party requests the user to operate the user's call terminal 201 so that the user places a call to the displayed authenticated telephone number.

[0089] In step S1111, the third-party terminal 401 transmits information about a screen for unauthorized operation to the user call terminal 201. The screen for unauthorized operation is, for example, a purpose confirmation screen 1203 in Fig. 12, and a purpose such as "Perform identity verification to activate account" is displayed, which is different from the purpose of changing the email address that is recognized by the service provider device 301 and the telephone authentication device 101.

[0090] In step S1112, a telephone authentication request is transmitted from the user call terminal 201 to the third party terminal 401. The request is transmitted by operating the authentication request button 12031 on the purpose confirmation screen 1203.

[0091] In step S1113, third party terminal 401 transmits the authentication phone number acquired in step S1110 to user call terminal 201 to display the authentication phone number.

[0092] In step S1114, the number display screen 1204 is displayed on the user call terminal 201. The authentication phone number is displayed in a number display field 12041 on the number display screen 1204. This number is displayed on the user call terminal 201 at approximately the same time that the third party terminal 401 acquires the authentication phone number, so that authentication does not fail due to an authentication deadline based on the authentication phone number.

[0093] If the user does not notice that the number display screen 1204 is a screen displayed by a third party, a call is made from the user call terminal 201 to the telephone authentication device 101 in step S1115.

[0094] In step S1116, power receiving unit 1015 receives the call, and in step S1117, the call begins.

[0095] In step S1118, the telephone authentication device 101 performs an authentication process. The authentication process is similar to the process described with reference to FIG.

[0096] In step S1119, in order to inquire about the authentication result, the service provider device 301 transmits an authentication result request to the telephone authentication device 101. In step S1120, the telephone authentication device 101 transmits the authentication result to the service provider device 301 in response to the authentication result request.

[0097] In step S1121, the telephone authentication device 101 notifies the third party terminal 401 of the authentication result.

[0098] In the authentication process, the processes from step S904 to S908 in FIG. 9 determine whether the purpose of the telephone authentication corresponds to the purpose identification information obtained from the service provider device 301, and record the success or failure of the authentication.

[0099] When the purpose identification information transmitted to the telephone authentication device 101 through the service provider device 301 by the operation of the third party terminal 401 is information indicating an email address change, the purpose confirmation message is a message for confirming whether or not the telephone authentication is for changing the email address. As shown in the purpose confirmation screen 1203 in Fig. 12, when the user performs telephone authentication for the purpose of account activation, the user inputs a response indicating a different purpose in the purpose confirmation message.

[0100] Acquisition of a response to the purpose confirmation message in this case will be described with reference to FIG. 13. The user hears a message through the user calling terminal 201 saying, "This telephone authentication will change your registered email address. If you wish to change your email address, enter 1. If not, enter 2." The user inputs the response as a tone signal through the input screen 1301 of the user calling terminal 201. A user who wishes to activate their account inputs "2" as a response to the purpose confirmation message. In this case, the call unit 2013 transmits the tone signal of "2" to the telephone authentication device 101 as a response.

[0101] If a "2" tone signal is received as a response, the authentication judgment unit 1017 judges that the purpose of the user's call does not correspond to the purpose identification information, records the authentication failure in association with the authenticated phone number, and ends the call. Since the authentication result is a failure, the email address change is not executed.

[0102] In the telephone authentication system 10, a purpose confirmation message is sent during telephone authentication and a response to the purpose is obtained, so that the authentication is determined to be successful only when the purpose of the authentication matches the purpose for which the user made the call. This prevents a third party from breaking through to the telephone authentication even if the third party attempts to illegally change the registration information.

[0103] The present embodiment has been described above. The telephone authentication device 101 according to the present embodiment includes an authentication request acquisition unit 1013 that acquires authentication request information including purpose identification information that identifies the purpose of the authentication of a user by telephone, a number issuing unit 1014 that issues an authentication telephone number used for authentication in association with the purpose identification information when the authentication request information is acquired, a call receiving unit 1015 that accepts a call to the authentication telephone number through the user call terminal 201, a purpose confirmation unit 1016 that transmits a purpose confirmation message associated with the purpose identification information to the user call terminal 201 in a call with the user and acquires a response to the purpose confirmation message from the user call terminal 201, and an authentication determination unit 1017 that determines whether the authentication is successful or not based on the purpose identification information and the response.

[0104] In the telephone authentication device 101, an authentication telephone number and a purpose confirmation message are associated with purpose identification information included in the authentication request information. By transmitting the purpose confirmation message to the user call terminal 201 and acquiring a response to the purpose confirmation message, it is possible to determine whether the purpose of the user's call corresponds to the purpose identification information. This makes it possible to confirm the purpose of the user's call as well, so that it is possible to correctly determine whether authentication is possible even for fraudulent authentication requests based on operations unintended by the user, improving the security of telephone authentication.

[0105] In the telephone authentication device 101, the authentication request acquisition unit 1013 acquires authentication request information further including the user's user telephone number stored in the business server from the business server of a business that provides a service based on authentication, the number issuing unit 1014 issues the authentication telephone number in association with the purpose identification information and the user telephone number, the call receiving unit 1015 judges whether the call is a call from the user telephone number, and if the call is not a call from the user telephone number, judges that the authentication has failed, and if the call is a call from the user telephone number, the purpose confirmation unit 1016 transmits a purpose confirmation message corresponding to the user telephone number and acquires a response.

[0106] This allows the authentication to be determined as unsuccessful if a call is made to the authentication telephone number from a number different from the user telephone number, so that the purpose of the call can be more reliably confirmed by the user himself / herself. Note that since the success or failure of authentication can be determined only by obtaining a response to the purpose confirmation message, it is not necessary to determine whether the call is from the user telephone number.

[0107] In the telephone authentication device 101, the purpose confirmation unit 1016 may transmit a purpose confirmation message including one option for confirming whether the purpose for which the user made the call corresponds to the purpose identification information, and obtain a response to the one option.

[0108] This allows the user to simply input a response to one option, improving convenience for the user during confirmation.

[0109] In the telephone authentication device 101, the purpose confirmation unit 1016 may transmit a purpose confirmation message including multiple options, the multiple options including an option corresponding to the purpose for which the user made the call and an option corresponding to a purpose other than the purpose for which the user made the call, and obtain responses to the multiple options.

[0110] This allows the user to input responses to multiple options, reducing the possibility that an unintended response will be sent due to an erroneous operation, resulting in the authentication being determined to be successful.

[0111] In the telephone authentication device 101, the purpose confirmation unit 1016 may acquire a response to the purpose confirmation message from the user call terminal 201 as a voice signal based on the user's speech.

[0112] This eliminates the need for the user to perform operations via the input unit 2014 and allows the user to input a response in accordance with the flow of the call, thereby improving user convenience.

[0113] In the telephone authentication device 101, the authentication request information includes business operator identification information that identifies a business operator that provides a service based on the authentication, and the device is further provided with a memory unit 1012 in which purpose identification information is stored in association with each of the business operator identification information, and a purpose confirmation unit 1016 transmits a purpose confirmation message based on the business operator identification information and the purpose identification information.

[0114] This makes it possible to set a purpose confirmation message so as to correspond to the business operator identification information and purpose identification information, thereby making it possible to set a purpose confirmation message suited to the needs of the business operator.

[0115] The telephone authentication device 101 may further include an update unit 1018 that updates the purpose identification information associated with each of the business identification information.

[0116] This enables updating of purpose identification information to suit the needs of the business operator, thereby improving convenience for the business operator.

[0117] In the telephone authentication device 101, the number issuing unit 1014 issues an authentication telephone number by associating the authentication telephone number with an authentication expiration date, and the call receiving unit 1015 determines that authentication has failed when a call is received to an authentication telephone number whose authentication expiration date has expired. This makes it possible to determine whether authentication is possible or not according to the authentication expiration date.

[0118] In the telephone authentication device 101, the authentication judgment unit 1017 may invalidate the authentication telephone number used for authentication after the authentication is successful. This prevents the authentication telephone number from being used repeatedly, improving the security of the authentication. [Explanation of symbols]

[0119] 10... telephone authentication system, 101... telephone authentication device, 201... user call terminal, 301... service provider device, 401... third party terminal, 1013... authentication request acquisition unit, 1014... number issuing unit, 1015... receiving unit, 1016... purpose confirmation unit, 1017... authentication judgment unit, 1018... update unit

Claims

1. an authentication request acquisition unit that acquires authentication request information including purpose identification information that identifies a purpose of the user authentication by telephone; a number issuing unit that issues an authentication telephone number to be used for the authentication in association with the purpose identification information when the authentication request information is acquired; A call receiving unit that receives a call to the authenticated telephone number through a user's call terminal; a purpose confirmation unit that transmits a purpose confirmation message associated with the purpose identification information to the user's calling terminal during a call with the user and acquires a response to the purpose confirmation message from the user's calling terminal; an authentication determination unit that determines whether the authentication has been successful or not based on the purpose identification information and the response.

2. 2. The information processing device according to claim 1, the authentication request acquisition unit acquires, from a business server of a business providing a service based on the authentication, the authentication request information further including a user telephone number of the user stored in the business server; The number issuing unit issues the authentication telephone number in association with the purpose identification information and the user telephone number, The call receiving unit determines whether the call is the call from the user phone number, and if the call is not the call from the user phone number, determines that the authentication has failed; The purpose confirmation unit, when the call is from the user phone number, sends the purpose confirmation message corresponding to the user phone number and obtains the response.

3. 2. The information processing device according to claim 1, The purpose confirmation unit sends the purpose confirmation message including one option for confirming whether the purpose for which the user made the call corresponds to the purpose identification information, and obtains a response to the one option.

4. 2. The information processing device according to claim 1, The purpose confirmation unit sends a purpose confirmation message including multiple options, including options corresponding to the purpose for which the user made the call and options corresponding to other purposes different from the purpose for which the user made the call, and obtains responses to the multiple options.

5. 2. The information processing device according to claim 1, The purpose confirmation unit acquires a response to the purpose confirmation message from the user's call terminal as a voice signal based on the user's speech.

6. 2. The information processing device according to claim 1, the authentication request information includes business operator identification information for identifying a business operator that provides a service based on the authentication, a storage unit in which the purpose identification information is stored in association with each of the business operator identification information; Further equipped with The purpose confirmation unit transmits the purpose confirmation message based on the business identification information and the purpose identification information.

7. 7. The information processing device according to claim 6, The information processing device further comprises an update unit that updates the purpose identification information associated with each of the business operator identification information.

8. 2. The information processing device according to claim 1, the number issuing unit issues the authentication telephone number by associating the authentication telephone number with an authentication expiration date; The information processing device, wherein the call receiving unit determines that the authentication has failed when the call is received from an authenticated phone number whose authentication period has expired.

9. 2. The information processing device according to claim 1, The information processing device, wherein the authentication determination unit invalidates the authentication phone number used for the authentication after the authentication is successful.

10. On the computer, obtaining authentication request information including purpose identification information identifying a purpose of the user's authentication by telephone and a user telephone number of the user; when the authentication request information is acquired, an authentication telephone number used for the authentication is issued in association with the purpose identification information; Accepting a call to the authenticated telephone number through a user's telephone terminal; In a call with the user, a purpose confirmation message associated with the purpose identification information is transmitted to the user's call terminal, and a response to the purpose confirmation message is received from the user's call terminal; and determining whether authentication has been successful or not based on the purpose identification information and the response.

11. The computer obtaining authentication request information including purpose identification information identifying a purpose of the user's authentication by telephone and a user telephone number of the user; when the authentication request information is acquired, an authentication telephone number used for the authentication is issued in association with the purpose identification information; Accepting a call to the authenticated telephone number through a user's telephone terminal; In a call with the user, a purpose confirmation message associated with the purpose identification information is transmitted to the user's call terminal, and a response to the purpose confirmation message is received from the user's call terminal; determining whether authentication is successful or not based on the purpose identification information and the response.

Citation Information

Patent Citations

  • Reception system, reception auxiliary server, and reception processing server

    JP2005216250A

  • Telephone number registration / authentication system, method, authentication server, and program

    JP2007036562A

  • Identity verification system, identity verification means, identify verification method, and program thereof

    JP2013205862A

  • Authentication assisting device, authentication assisting method, and program

    JP2019067432A

  • User authentication system, telephone exchange device, user authentication method, and user authentication program

    JP2020140619A