Information processing system, information processing method, authentication system, and program
The authentication system improves reliability by updating authentication codes frequently based on authentication information and time information, reducing the expiration date and enhancing security.
Patent Information
- Application Number
- JP2022201020
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-16
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-16
AI Technical Summary
Existing authentication systems using one-time passwords face challenges in further enhancing reliability due to relatively long expiration dates.
An authentication system that includes a code update unit, which updates authentication codes at predetermined periods based on authentication information and time information with an update cycle less than the predetermined period, thereby reducing the expiration date of authentication codes.
This approach significantly enhances the reliability of the authentication process by reducing the window of vulnerability through shorter, real-time expiration dates for authentication codes.
Smart Images

Figure 0007678261000001 
Figure 0007678261000002 
Figure 0007678261000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an information processing system, an information processing method, an authentication system, and a program. [Background technology]
[0002] As a measure to increase the reliability of the authentication process, a technique is known that uses a one-time password (also called OTP (One Time Password)), which is stronger than authentication using a password. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 5555799 specification Summary of the Invention [Problem to be solved by the invention]
[0004] However, in the above-mentioned conventional techniques, a relatively long validity period is set for the one-time password, making it difficult to further increase reliability.
[0005] Therefore, in one aspect, the present disclosure aims to effectively increase the reliability of the authentication process. [Means for solving the problem]
[0006] In one aspect, an authentication information acquisition unit that acquires authentication information; An information processing device is provided, comprising: a code update unit that updates an authentication code that is externally readable or externally transmittable at each predetermined period based on the authentication information and time information that changes at an update period equal to or shorter than a predetermined period. Effect of the Invention
[0007] In one aspect, the present disclosure makes it possible to effectively increase the reliability of the authentication process. [Brief description of the drawings]
[0008] [Figure 1] 1 is a block diagram of an authentication system according to an embodiment of the present invention. [Diagram 2] 1 is a timing chart (part 1) showing an example of the operation of the authentication system. [Diagram 3] 13 is a timing chart (part 2) showing an example of the operation of the authentication system. [Figure 4] 11 is a timing chart (part 3) illustrating an example of the operation of the authentication system. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] Hereinafter, each embodiment will be described in detail with reference to the accompanying drawings. Note that in the accompanying drawings, for ease of viewing, only some of the reference symbols may be attached to multiple parts having the same attribute.
[0010] An overview of an authentication system 1 according to an embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram of the authentication system 1 according to the present embodiment.
[0011] The authentication system 1 includes a server device 10 and one or more terminal devices 20. For simplicity, three terminal devices 20 are illustrated in Fig. 1, but the number of terminal devices 20 is arbitrary.
[0012] The server device 10 is, for example, an information processing system such as a server managed by an administrator that provides one or more authentication services. The terminal device 20 is, for example, a device used by a user, such as a mobile phone, a smartphone, a tablet terminal, a PC (Personal Computer), a head-mounted display, or a game device. A plurality of terminal devices 20 can be connected to the server device 10 via the network 3, typically in a different manner for each user.
[0013] The terminal device 20 is capable of executing an authentication service application according to this embodiment. The authentication service application may be received by the terminal device 20 from the server device 10 or a predetermined application distribution server via the network 3, or may be stored in advance in a storage device provided in the terminal device 20 or a storage medium such as a memory card readable by the terminal device 20. The server device 10 and the terminal device 20 are communicatively connected via the network 3. For example, the server device 10 and the terminal device 20 cooperate to execute various processes related to the authentication service.
[0014] The network 3 may include a wireless communication network, the Internet, a Virtual Private Network (VPN), a Wide Area Network (WAN), a wired network, or any combination of these.
[0015] In the following, the authentication system 1 realizes an example of an information processing system, but each element of a specific terminal device 20 (see terminal communication unit 21 to terminal control unit 25 in FIG. 1) may realize an example of an information processing system, or a plurality of terminal devices 20 may cooperate to realize an example of an information processing system. Also, the server device 10 may independently realize an example of an information processing system, or the server device 10 and one or more terminal devices 20 may cooperate to realize an example of an information processing system.
[0016] (Server device configuration) The configuration of the server device 10 will be specifically described. The server device 10 is composed of a server computer. The server device 10 may be realized by a plurality of server computers working in cooperation with each other. For example, the server device 10 may be realized by a server computer that provides various contents (e.g., time information) or a server computer that realizes an authentication server working in cooperation with each other. The server device 10 may also include a Web server. In this case, some of the functions of the terminal device 20 described later may be realized by a browser processing an HTML document received from the Web server and various programs associated therewith (JavaScript (registered trademark)).
[0017] As shown in FIG. 1, the server device 10 includes a server communication unit 11, a server storage unit 12, and a server control unit 13.
[0018] The server communication unit 11 includes an interface that communicates with an external device wirelessly or wiredly and transmits and receives information. The server communication unit 11 may include, for example, a wireless LAN (Local Area Network) communication module or a wired LAN communication module. The server communication unit 11 is capable of transmitting and receiving information to and from the terminal device 20 via the network 3.
[0019] The server storage unit 12 is, for example, a storage device, and stores various information and programs required for various processes related to the authentication service.
[0020] The server control unit 13 may include a dedicated microprocessor or a CPU (Central Processing Unit) that realizes a specific function by reading a specific program, a GPU (Graphics Processing Unit), etc. For example, the server control unit 13 cooperates with the terminal device 20 to execute an authentication service application in response to a user operation on the display unit 23 (touch panel) of the terminal device 20.
[0021] (Terminal Device Configuration) The following describes the configuration of the terminal device 20. As shown in Fig. 1, the terminal device 20 includes a terminal communication unit 21, a terminal storage unit 22, a display unit 23, an input unit 24, and a terminal control unit 25.
[0022] The terminal communication unit 21 includes an interface for communicating with an external device wirelessly or wiredly and transmitting and receiving information. The terminal communication unit 21 may include a wireless communication module, a wireless LAN communication module, or a wired LAN communication module that supports mobile communication standards such as LTE (Long Term Evolution) (registered trademark), LTE-A (LTE-Advanced), a fifth generation mobile communication system, and UMB (Ultra Mobile Broadband). The terminal communication unit 21 is capable of transmitting and receiving information to and from the server device 10 via the network 3.
[0023] The terminal storage unit 22 includes, for example, a primary storage device and a secondary storage device. For example, the terminal storage unit 22 may include a semiconductor memory, a magnetic memory, an optical memory, or the like. The terminal storage unit 22 stores various information and programs used in the authentication service-related processing received from the server device 10. The information and programs used in the authentication service-related processing may be acquired from an external device via the terminal communication unit 21. For example, an authentication service application program may be acquired from a predetermined application distribution server. Hereinafter, the application program may also be simply referred to as an application or an app.
[0024] The display unit 23 includes a display device such as a liquid crystal display or an organic EL (Electro-Luminescence) display. The display unit 23 is capable of displaying a variety of images. The display unit 23 is configured with, for example, a touch panel, and functions as an interface that detects a variety of user operations. Note that the display unit 23 may be in a form built into a head-mounted display, as described above.
[0025] The input unit 24 may include physical keys, and may further include any input interface including a pointing device such as a mouse.
[0026] The terminal control unit 25 includes one or more processors. The terminal control unit 25 controls the operation of the entire terminal device 20.
[0027] The terminal control unit 25 transmits and receives information via the terminal communication unit 21. For example, the terminal control unit 25 receives various information and programs used in authentication service-related processes from at least one of the server device 10 and other external servers. The terminal control unit 25 stores the received information and programs in the terminal storage unit 22. For example, the terminal storage unit 22 may store a browser (Internet browser) for connecting to a Web server.
[0028] Next, an example of the operation of the authentication system 1 will be described with reference to FIG. 2 and subsequent figures.
[0029] Figures 2 to 4 are timing charts showing an example of the operation of the authentication system 1. Figures 2 to 4 show a series of example operations, but only a part of them may be executed. Also, in addition to the user, an authenticating information terminal 40, an authenticated information terminal 42, an authentication server 50, an NTP server 52, and a content server 54 appear in Figures 2 to 4.
[0030] The authenticating information terminal 40 and the authenticated information terminal 42 may each be realized by the terminal device 20 shown in Fig. 1. The authentication server 50 and the content server 54 may be realized by one or more server devices 10 shown in Fig. 1. Therefore, in this case, in Figs. 2 to 4, the authentication system 1 may be realized by the authenticating information terminal 40, the authenticated information terminal 42, the authentication server 50, and the content server 54. Note that in a modified example, the authentication system 1 may be realized by the authenticating information terminal 40, the authenticated information terminal 42, and the authentication server 50.
[0031] Here, as an example, an operation example related to a game application will be described. The game application is implemented in the authenticated information terminal 42. In this embodiment, the game application includes an application portion for the authenticated side of the authentication service application, but they may be linked to each other as separate applications. The authenticating information terminal 40 and the authentication server 50 include an application portion for the authenticating side of the authentication service application.
[0032] Explaining in order from FIG. 2, the user first starts a game app on the authentication-to-be-authenticated information terminal 42 (step S200). That is, the terminal control unit 25 of the authentication-to-be-authenticated information terminal 42 starts a game application in response to, for example, a user operation. The terminal control unit 25 executes authentication service-related processing in cooperation with the server device 10. For example, the terminal control unit 25 of the authentication-to-be-authenticated information terminal 42 may output, for example, a GUI (Graphic User Interface) that detects a user operation on the screen of the display unit 23. The terminal control unit 25 can detect a user operation via the input unit 24. For example, the terminal control unit 25 can detect various operations by user gestures (operations corresponding to a tap operation, a long tap operation, a flick operation, a swipe operation, etc.).
[0033] Authentication-to-be-authenticated information terminal 42 executes the following processes based on the started game application. That is, the started game application is executed on authentication-to-be-authenticated information terminal 42, thereby realizing the following various operations of authentication-to-be-authenticated information terminal 42. First, the authentication service application portion of the game application of authentication-to-be-authenticated information terminal 42 generates a key pair (step S202), and displays a top screen on display unit 23 of authentication-to-be-authenticated information terminal 42 (step S204). The generation of the key pair may be executed when OAuth authentication is used. In this case, the key pair is used when generating an OAuth signature.
[0034] In the output state of the top screen of the authenticated information terminal 42, the user performs input for a predetermined request (hereinafter also referred to as "predetermined request input") via the input unit 24 (step S206). The predetermined request is arbitrary, but here it is a data transfer request accompanying a model change or the like, for example, a data transfer request for a game application. In another embodiment, the predetermined request may be the sharing of authentication information among multiple terminals. Note that such sharing may be a process for enabling the same or similar services to be used with the same account on multiple terminals.
[0035] In the game application of the authenticated information terminal 42, the authentication service application portion responds to the predetermined request input from the user and requests a one-time token (an example of authentication information) for authentication related to the current predetermined request (step S208).
[0036] In response to the request for a one-time token, the authentication server 50 generates a one-time token (step S210). The expiration date of the one-time token (an example of a first expiration date) is the expiration date from the current time, and the length of the expiration date (an example of a first length) is arbitrary, but may be, for example, about 5 minutes.
[0037] When the authentication server 50 generates the one-time token, it transmits the generated one-time token to the authentication-subject information terminal 42 that originated the request (step S212).
[0038] When the authentication service application portion of the game application of the authentication-receiving information terminal 42 receives the one-time token from the authentication server 50, it adds predetermined information to the one-time token (step S214). The predetermined information is arbitrary, and may represent, for example, an action (e.g., login) to be realized when authentication is successful. In this case, the predetermined information may differ depending on the action. The predetermined information may also be added for the purpose of checking the consistency of data between devices of the user by adding data (other than checking the real-time expiration date related to this authentication service, which will be described later) or passing data necessary for processing on the client side. Hereinafter, authentication information in which the predetermined information is added to the one-time token in this way is also referred to as "predetermined authentication information." In addition, in a modified example, the predetermined information may be omitted.
[0039] Next, the authentication service application portion of the game application of the authentication-to-be-authentication information terminal 42 executes a time synchronization process (see Q2) for acquiring accurate time information. Specifically, first, the authentication-to-be-authentication information terminal 42 transmits a request for current time information to the NTP server 52 (step S216). In response to the request, the NTP server 52 transmits the time information to the requesting authentication-to-be-authentication information terminal 42 (step S218). When the authentication-to-be-authentication information terminal 42 receives the time information from the NTP server 52, it synchronizes the time information in the authentication-to-be-authentication information terminal 42 with the received time information (step S220). By performing such a time synchronization process, the authentication-to-be-authentication information terminal 42 can generate time information synchronized with the NTP server 52 until at least a certain period has elapsed since the authentication-to-be-authentication information terminal 42 received the time information from the NTP server 52. Note that the authentication-to-be-authentication information terminal 42 may periodically execute the time synchronization process in advance. In this case, the time synchronization process may be omitted and the process may proceed to step S300.
[0040] When the authentication service application portion of the game application of the authenticated information terminal 42 completes the time synchronization process (see Q2), it subsequently executes the two-dimensional code generation / update process (see Q3) as shown in FIG.
[0041] The two-dimensional code generation / update process is repeatedly executed at a predetermined period ΔT1. The two-dimensional code generation / update process may be executed for one one-time token only within the expiration date of that one one-time token. The predetermined period ΔT1 is significantly shorter than the length of the expiration date of the one-time token. Here, "significantly" shorter (or longer) may mean, for example, a level of a different order of magnitude. For example, if the expiration date of the one-time token is about 5 minutes, the predetermined period ΔT1 may be between 0 and 10 seconds, and may preferably be about 0.1 seconds.
[0042] In the two-dimensional code generation / update process, the authenticated information terminal 42 adds a new expiration date (hereinafter also referred to as the "real-time expiration date") to the specified authentication information (step S300). The real-time expiration date is the expiration date from the current time, and in this case, the current time may be a time based on the time information. In the authenticated information terminal 42, the time information may be updated at a very short period according to the clock frequency, etc., of the authenticated information terminal 42. For example, in the authenticated information terminal 42, the time information may be updated at a period equal to or shorter than the specified period ΔT1 / 10. However, it is sufficient that the time information represents a different time when the two-dimensional code generation / update process is performed for each specified period ΔT1.
[0043] The length (an example of the second length) of the real-time expiration date (an example of the second expiration date) is significantly shorter than the length of the expiration date of the one-time token. The length of the real-time expiration date may be equal to or longer than a predetermined period ΔT1. For example, if the length of the expiration date of the one-time token is about 5 minutes, the length of the real-time expiration date may be between 0.1 seconds and 10 seconds, and may preferably be about 0.5 seconds.
[0044] Next, the authenticated information terminal 42 generates two-dimensional code data based on the predetermined authentication information with the real-time expiration date (step S302). The encrypted two-dimensional code data may be generated by encrypting the predetermined authentication information with the real-time expiration date.
[0045] Next, the authenticated information terminal 42 generates two-dimensional code image data based on the two-dimensional code data (step S304).
[0046] In this way, the authentication service application portion of the game application of the authenticated information terminal 42 generates two-dimensional code image data (an example of an authentication code) having a real-time expiration date based on that time at each predetermined period ΔT1.
[0047] In this embodiment, the two-dimensional code image (and the two-dimensional code data derived therefrom) is updated on the authenticated information terminal 42 side, not on the authentication server 50, so there is no need for communication between the authentication server 50 and the authenticated information terminal 42. This makes it possible to reduce the communication load and to quickly update the two-dimensional code image (generate it at a predetermined cycle ΔT1).
[0048] When the authenticated information terminal 42 generates the two-dimensional code image data, it outputs a two-dimensional code image based on the generated two-dimensional code image data onto the display unit 23 (step S306). Therefore, the user can visually recognize the two-dimensional code image via the display unit 23. The form of the two-dimensional code image is arbitrary, and may be, for example, a QR code (registered trademark) or the like.
[0049] In this embodiment, as described above, the two-dimensional code image data changes every predetermined period ΔT1, so that the two-dimensional code image (and the real-time expiration date) displayed on the display unit 23 of the authenticated information terminal 42 also changes every predetermined period ΔT1.
[0050] The user causes the authenticating information terminal 40 to read the two-dimensional code image displayed on the display unit 23 of the authenticated information terminal 42 (step S308). The authenticating information terminal 40 reads the two-dimensional code image to obtain two-dimensional code data related to the two-dimensional code image (steps S310 and S312). The authenticating information terminal 40 decodes the two-dimensional code data (step S314) to obtain the predetermined authentication information with the real-time expiration date described above.
[0051] Here, in this embodiment, as described above, the two-dimensional code image displayed on the display unit 23 of the authenticated information terminal 42 changes at predetermined intervals ΔT1, but the authenticating information terminal 40 can obtain the specified authentication information with the above-mentioned real-time expiration date based on the two-dimensional code image displayed on the authenticated information terminal 42 at the time of reading.
[0052] When the authentication information terminal 40 acquires the predetermined authentication information with the real-time expiration date in this way, it executes a time synchronization process (see Q4) to acquire accurate time information. Specifically, first, the authentication information terminal 40 transmits a request for current time information to the NTP server 52 (step S316). In response to the request, the NTP server 52 transmits time information to the requesting authentication information terminal 40 (step S318). When the authentication information terminal 40 receives the time information from the NTP server 52, it synchronizes the time information in the authentication information terminal 40 with the received time information (step S320). By performing such a time synchronization process, the authentication information terminal 40 can generate time information synchronized with the NTP server 52 until at least a certain period has elapsed since the authentication information terminal 40 received the time information from the NTP server 52. Note that the authentication information terminal 40 may periodically execute a time synchronization process in advance. In this case, the time synchronization process may be omitted and the process may proceed to step S400.
[0053] When the authenticating information terminal 40 acquires the predetermined authentication information with the real-time expiration date, it checks the real-time expiration date (step S400), and if the real-time expiration date has not passed, it displays a login confirmation screen (step S402). The authenticating information terminal 40 also transmits an output request for a screen display for biometric authentication and passcode authentication on the authenticated information terminal 42 to the content server 54 (step S404). If the real-time expiration date has passed, the authenticating information terminal 40 may not proceed to the process after step S402. In this case, it may be possible to restart the process from the middle, such as starting over from step S308, as appropriate.
[0054] In response to such an output request, the content server 54 presents a screen display for biometric authentication and passcode authentication to the user via the authenticated information terminal 42 (step S406). The user inputs information for biometric authentication and passcode authentication (step S408), and if the authentication is successful, a notification to that effect is sent from the content server 54 to the authenticating information terminal 40 (step S410).
[0055] When the authenticating information terminal 40 receives the notification, it transmits the predetermined authentication information with the real-time expiration date acquired as described above to the authentication server 50 (step S412). In the case of the predetermined authentication information transmitted to the authentication server 50, the predetermined authentication information with the real-time expiration date does not have to include the predetermined information described above. In other words, the predetermined authentication information with the real-time expiration date may be information including the original one-time token and the real-time expiration date.
[0056] 2 to 4, the authenticating information terminal 40 checks the real-time expiration date (step S400), but the authenticating information terminal 40 may omit checking the real-time expiration date. As in the example shown in Fig. 2 to 4, when the authenticating information terminal 40 checks the real-time expiration date, if the result of the check shows that the real-time expiration date is valid, the authenticating information terminal 40 may execute a process of updating (extending) the real-time expiration date. Such an update may be effective when the real-time expiration date is relatively short.
[0057] When the authentication server 50 receives the predetermined authentication information with the real-time expiration date, it judges the validity of the received predetermined authentication information with the real-time expiration date (and accordingly the validity of the two-dimensional code image related to the predetermined authentication information) (steps S414 and S416). At this time, the authentication server 50 judges the validity of the two-dimensional code image based on both the expiration date of the one-time token related to the two-dimensional code image and the real-time expiration date related to the two-dimensional code image. Specifically, it judges whether or not both expiration dates have passed based on the current time information. If both expiration dates have not passed, the authentication is successful. In this case, it executes a process corresponding to the predetermined request (step S418). In this embodiment, the authentication server 50 executes a data transfer process of the game application. In addition, the authentication server 50 notifies the authentication side information terminal 40 that the authentication has been successful (step S420). When the authentication side information terminal 40 receives the notification, it notifies the user that the login has been successful (step S422).
[0058] The user returns the screen on the authenticated information terminal 42 to the top screen (step S424), causing the top screen to be displayed (step S426), and then starts the game application (step S428).
[0059] In this way, according to the present embodiment, the real-time expiration date is taken into consideration along with the expiration date of the one-time token, thereby improving the reliability of authentication. In other words, by utilizing the relatively short real-time expiration date that essentially starts from the time when the two-dimensional code image is read, spoofing can be effectively prevented.
[0060] For example, assume that user A takes a screenshot of a two-dimensional code image displayed on the display unit 23 of his / her terminal device 20 and sends it to user B. In that case, due to the time it takes for user B to obtain and read the two-dimensional code image after the two-dimensional code image is generated, there is a high possibility that the real-time expiration date will have expired before the two-dimensional code image reaches the authentication server 50. This is particularly suitable when the length of the real-time expiration date is very short.
[0061] As described above, in this embodiment, the authenticated information terminal 42 can update the two-dimensional code image at high speed, and is therefore not affected by communication delays caused by communication between the authentication server 50 and the authenticated information terminal 42. This reduces inconveniences (possibility of impairing user convenience) such as failure to authenticate within the validity period due to communication delays.
[0062] In the example described above with reference to Figures 2 to 4, the authenticating information terminal 40 is assumed to be used by the same user as the user of the authenticated information terminal 42, but the relationship between the user of the authenticating information terminal 40 and the user of the authenticated information terminal 42 may be diverse depending on the purpose of authentication, etc.
[0063] In the examples described above with reference to Figs. 2 to 4, the authenticating information terminal 40 is preferably a portable terminal device 20 (e.g., a smartphone), and the authenticated information terminal 42 is preferably a stationary terminal device 20 (e.g., a desktop computer), but the authenticating information terminal 40 and / or the authenticated information terminal 42 may take various forms depending on the application. For example, the authenticating information terminal 40 may be a fixed terminal fixed to a predetermined position. In this case, being authenticated via the authenticating information terminal 40 may be used to prove that the user of the authenticated information terminal 42 is at a predetermined position at that time. Such applications are suitable for confirming attendance, distributing novelties and items at an event venue, and the like.
[0064] Also, in the example described above with reference to Figures 2 to 4, steps S402 to S410 are executed due to the characteristics of the application (predetermined request) of data transfer, but in the case of other applications, steps S402 to S410 may be omitted.
[0065] Also, in the examples described above with reference to FIGS. 2 to 4, the real-time expiration date is taken into account along with the expiration date associated with the one-time token, but the expiration date associated with the one-time token may be omitted.
[0066] 2 to 4 are application examples in real space, but the invention can also be applied to events in virtual space. In the case of a virtual space, the authenticating information terminal 40 is also a fixed terminal fixed at a predetermined position, but may be substantially realized by the server device 10 on the operator side of the virtual space. That is, in the case of a virtual space, the authenticating information terminal 40 and the authentication server 50 may be realized as an integrated unit.
[0067] In addition, in the case of a virtual space, the method in which the user holds the two-dimensional code image over the authenticating information terminal 40 to have it read can be diverse, and may simply be a method of giving a reading instruction near the position of the authenticating information terminal 40, or a method in which the display screen of the authenticated information terminal 42, which is in the form of a smartphone or the like in the virtual space, is directed toward the authenticating information terminal 40, as in the real space.
[0068] In the example described above with reference to Figures 2 to 4, the authenticated information terminal 42 executes the processing of step S212 in Figure 2, thereby realizing an example of an "authentication information acquisition unit" or "authentication side acquisition unit" described in the claims, the authenticated information terminal 42 executes the processing of step S300 in Figure 3, thereby realizing an example of a "code update unit" described in the claims, and the authenticated information terminal 42 executes the processing of step S208 in Figure 2, thereby realizing an example of an "authentication information request unit" described in the claims.
[0069] 2 to 4, the authentication side information terminal 40 executes the process of step S310 and step S312 in Fig. 3 to realize an example of a "code acquisition unit" or an "authentication side acquisition unit" as described in the claims, and the authentication side information terminal 40 executes the process of step S400 in Fig. 4 and / or the authentication server 50 executes the process of step S414 and step S416 in Fig. 4 to realize an example of a "determination unit" as described in the claims. Also, the authentication server 50 executes the process of step S210 and step S212 in Fig. 2 to realize an example of an "authentication information issuing unit" as described in the claims, and the authentication server 50 executes the process of step S418 in Fig. 4 to realize an example of a "processing execution unit" as described in the claims.
[0070] Although each embodiment has been described in detail above, the present invention is not limited to a specific embodiment, and various modifications and changes are possible within the scope of the claims. In addition, it is also possible to combine all or a plurality of the components of the above-described embodiments.
[0071] For example, in the above-described embodiment, an authentication code in the form of a two-dimensional code image is used, but other codes such as one-dimensional code images may be used instead of the two-dimensional code image. In this case, the other codes may be readable by any reading terminal using RFID (Radio Frequency Identification) or the like. Alternatively, instead of the two-dimensional code image, a random number sequence that can be image-recognized may be used as the authentication code.
[0072] In the above embodiment, the two-dimensional code image (and the two-dimensional code data derived therefrom) is updated on the authenticated information terminal 42 side, not on the authentication server 50 side, but may be updated on the authentication server 50 side. In this case, the possibility of tampering on the authenticated information terminal 42 side can be effectively reduced. [Explanation of symbols]
[0073] 1 Authentication System 3. Network 10. Server equipment 11 Server Communication Section 12 Server memory section 13 Server control unit 20 Terminal Equipment 21 Terminal communication unit 22 Terminal memory section 23 Display section 24 Input section 25 Terminal control unit 40 Authentication side information terminal (information processing device, second information processing device) 42 Authentication-required information terminal (information processing device, first information processing device) 50 Authentication server (information processing device, second information processing device) 52 NTP Server 54 Content Server
Claims
1. The system includes a first information processing device on the authenticated side and a second information processing device on the authenticating side, The first information processing device, An acquisition unit on an authenticatee side that acquires authentication information; a code update unit that updates the authentication code at each predetermined cycle based on the authentication information and time information at the time of update, the time information changing at an update cycle equal to or shorter than a predetermined cycle; The second information processing device is an acquisition unit on an authentication side that acquires the authentication code and decodes expiration date information indicating a time at which a second expiration date based on the time of the update expires; an authentication system comprising: a determination unit that determines the validity of the authentication code based on a relationship between the expiration date information and time information at a time point of determination.
2. The authentication system according to claim 1 , wherein the predetermined period is equal to or shorter than one second.
3. The authentication system of claim 1, wherein the second information processing device further includes an authentication information issuing unit that issues the authentication information to which a first expiration date having a first length based on a time of issuance and determined based on time information at a time of determination is associated.
4. The second expiration date has a second length based on the renewal time point, The authentication system of claim 3 , wherein the second length is less than the first length.
5. The authentication system according to claim 4 , wherein the length of the predetermined period is shorter than the second length.
6. The authentication system according to claim 4 , wherein the second information processing device determines validity of the authentication information based on both the first expiration date and the second expiration date.
7. The authentication system according to claim 6 , wherein the first information processing device and the second information processing device each execute a time synchronization process.
8. The authentication system according to claim 1 , wherein the first information processing device generates the authentication code based on data encrypted based on the authentication information and time information at a time of update.
9. The authentication system of claim 1 , wherein the authentication code is in the form of a two-dimensional code image.
10. The authentication system according to claim 3 , wherein the first information processing device further comprises an authentication information requesting unit that requests the authentication information in response to a predetermined input by a user.
11. The authentication system according to claim 10 , wherein the authentication information issuing unit issues the authentication information based on a request received from the first information processing device, and transmits the issued authentication information to the first information processing device.
12. 2. The authentication system according to claim 1, further comprising a process execution unit that executes a corresponding predetermined process based on a determination result by said determination unit that the authentication code is valid.
13. Executed by the authenticatee's computer, An acquisition step of an authenticatee side acquiring authentication information; a code update step of updating the authentication code at each predetermined cycle based on the authentication information and time information at the time of update, the time information changing at an update cycle equal to or shorter than a predetermined cycle; executed by the authenticator's computer, an acquisition step on the authentication side of acquiring the authentication code and decrypting expiration date information indicating a time at which a second expiration date based on the time of the update expires; an authentication method comprising: a determination step of determining validity of the authentication code based on a relationship between the expiration date information and time information at a time point of determination.
Citation Information
Patent Citations
Rock crusher
JP1980055799A
Privilege application service management system
JP2013171496A
Content user authentication system and content user authentication method
JP2020181395A
Communication system, electronic device, and program
JP2021158494A
Automatic thermometric device, result certification device, automatic thermometric method, and computer program
JP2021193510A