Single sign-on authentication system and single sign-on authentication device
The SSO authentication system addresses the user workload and compatibility issues of existing systems by using a DHCP server and SSO authentication server to authenticate based on pre-registered MAC addresses, reducing user input requirements and enhancing security.
Patent Information
- Application Number
- JP2022111692
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-12
- Publication Date
- 2025-05-21
- Estimated Expiration
- 2042-07-12
AI Technical Summary
Existing SSO authentication systems require users to input a user identifier and password, which can increase user workload and may necessitate additional setup or device compatibility for certificate or biometric authentication.
An SSO authentication system that includes a DHCP server and an SSO authentication server connected via a network, where the DHCP server assigns IP addresses and stores MAC addresses, and the SSO authentication server determines authentication permission based on pre-registered MAC addresses, eliminating the need for user input of credentials.
This solution reduces user workload by eliminating the need for users to input credentials during authentication and simplifies the authentication process, while also improving security by ensuring only authorized MAC addresses can access network resources.
Smart Images

Figure 0007680988000001 
Figure 0007680988000002 
Figure 0007680988000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a single sign-on (SSO) authentication system and an SSO authentication device. [Background technology]
[0002] Patent Document 1 shows an authentication system capable of providing a service user with a service according to pre-SSO information after SSO using SAML (Security Assertion Markup Language). Specifically, when an SP (Service Provider) server receives an SSO access from a user terminal, the SP server stores pre-SSO communication session information of the user terminal in an information storage unit as pre-SSO information, and redirects the user terminal to an IdP (Identify Provider) server. The IdP server performs SSO authentication by referring to an SSO authentication DB using authentication information input from the user terminal, and redirects the user terminal to the SP server if the SSO authentication is successful. After the SSO authentication is successful, the SP server acquires pre-SSO information from the information storage unit, and provides the user terminal with a service according to the contents of the pre-SSO information. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2016-118930 A Summary of the Invention [Problem to be solved by the invention]
[0004] For example, SSO authentication systems are known that enable login to multiple web services, applications, etc. with one authentication procedure, as typified by the method using SAML described in Patent Document 1. During the authentication procedure, a user is usually required to input a user identifier and password. Meanwhile, certificate authentication and biometric authentication exist as methods that omit the input of a user identifier and password. However, when certificate authentication is used, it may be necessary to install a certificate in advance on the device to be authenticated. Furthermore, when biometric authentication is used, a separate device compatible with biometric authentication must be provided.
[0005] The present invention has been made in view of the above, and one of its objects is to provide an SSO authentication system and an SSO authentication device that can reduce the workload of a user.
[0006] The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings. [Means for solving the problem]
[0007] Among the inventions disclosed in this application, a brief outline of a representative embodiment will be described as follows.
[0008] An SSO authentication system according to an embodiment includes a DHCP server that assigns an IP address to a user terminal, and an SSO authentication server that is connected to the user terminal and the DHCP server via a network and determines whether or not to permit SSO authentication in response to an authentication request from the user terminal. When the DHCP server assigns an IP address to the user terminal, it stores a correspondence between the assigned IP address and the MAC address of the user terminal. The SSO authentication server holds an authentication table in which MAC addresses that permit SSO authentication are registered in advance. When the SSO authentication server receives a packet including an authentication request from the user terminal, it acquires from the DHCP server a MAC address that corresponds to the source IP address of the received packet, and determines whether or not to permit SSO authentication based on whether or not the acquired MAC address is registered in the authentication table. Effect of the Invention
[0009] To briefly explain the effect obtained by a representative embodiment of the invention disclosed in this application, it is possible to reduce the workload of the user. [Brief description of the drawings]
[0010] [Figure 1] 1 is a schematic diagram illustrating a configuration example of an SSO authentication system according to a first embodiment. [Diagram 2] 2 is a sequence diagram showing an example of processing contents of a main part of the SSO authentication system in FIG. 1. [Diagram 3] 2 is a block diagram showing an example of the configuration of a main part of an SSO authentication server appearing in FIG. 1. [Figure 4] FIG. 11 is a schematic diagram illustrating a configuration example of an SSO authentication system according to a second embodiment. [Diagram 5] 5 is a sequence diagram showing an example of processing contents of a main part of the SSO authentication system in FIG. 4. [Figure 6] 5 is a block diagram showing an example of the configuration of a main part of an SSO authentication server in FIG. 4. [Figure 7] FIG. 11 is a schematic diagram illustrating a configuration example of an SSO authentication system according to a third embodiment. [Figure 8] It is a sequence diagram showing an example of the processing content of the main part of the SSO authentication system in FIG. 7. [Figure 9] It is a block diagram showing a configuration example of the main part of the SSO authentication server in FIG. 7. [Figure 10] It is a schematic diagram showing a configuration example of the SSO authentication system according to Embodiment 4. [Figure 11] It is a sequence diagram showing an example of the processing content of the main part of the SSO authentication system in FIG. 10. [Figure 12] It is a sequence diagram showing an example of processing content different from that in FIG. 11. [Figure 13] It is a schematic diagram showing a configuration example different from that in FIG. 10 of the authentication management table in FIG. 10.
Mode for Carrying Out the Invention
[0011] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all the drawings for explaining the embodiments, the same members are generally denoted by the same reference numerals, and repeated explanations thereof are omitted.
[0012] (Embodiment 1) <Overview of the SSO Authentication System> FIG. 1 is a schematic diagram showing a configuration example of the SSO authentication system according to Embodiment 1. Here, as an example of the SSO authentication system, the case of using the SAML method is taken. The SSO authentication system shown in FIG. 1 includes a DHCP (Dynamic Host Configuration Protocol) server 11, an SSO authentication server 12, a directory server 13, service providers SPa and SPb, and user terminals TM10 and TM20. These devices are connected to each other via a network 10.
[0013] The service providers SPa and SPb are servers that provide Web services, applications, etc. In the present specification, the multiple service providers SPa and SPb are collectively referred to as the service provider SP. Also, the user terminals TM10 and TM20 are collectively referred to as the user terminal TM.
[0014] The network 10 includes an L2 switch (not shown) that handles layer 2 (L2) processing of the OSI reference model, and a router 15 that handles layer 3 (L3) processing. In this example, at least the SSO authentication server 12 is connected to each device including the user terminals TM10 and TM20 via the router 15. The router 15 may be an L3 switch, and the specification does not particularly distinguish between the router 15 and the L3 switch.
[0015] The DHCP server 11 assigns an IP address to the user terminal TM. The DHCP server 11 includes a storage unit 21 that holds an IP management table 22. The storage unit 21 and storage units 23 and 25 described below are configured, for example, by a combination of RAM and non-volatile memory. In the IP management table 22, the correspondence between IP addresses and MAC addresses is registered as IP address assignment information. When the DHCP server 11 assigns an IP address to the user terminal TM, it stores the correspondence between the assigned IP address and the MAC address of the user terminal TM.
[0016] In this example, the DHCP server 11 assigns an IP address IPA10 in response to an IP address assignment request from the terminal TM10, and registers the correspondence between the IP address IPA10 and the MAC address MA10 of the terminal TM10 in the IP management table 22. The DHCP server 11 also assigns an IP address IPA20 in response to an IP address assignment request from the terminal TM20, and registers the correspondence between the IP address IPA20 and the MAC address MA20 of the terminal TM20 in the IP management table 22.
[0017] The SSO authentication server (SSO authentication device) 12 determines whether or not to permit SSO authentication in response to an authentication request from the user terminal TM. The SSO authentication server 12 is called Idp in the SAML method. The SSO authentication server 12 includes a storage unit 23 that holds an authentication table 24. In the authentication table 24, MAC addresses that permit SSO authentication are registered in advance as permitted MAC address information. In addition to the MAC addresses, the authentication table 24 may also register in advance a user identifier UID corresponding to the MAC addresses. In this example, the authentication table 24 registers a correspondence relationship between the MAC address MA10 of the terminal TM10 and the user identifier UID10 of the user 14a who uses the terminal TM10.
[0018] The directory server 13 is, for example, a Lightweight Directory Access Protocol (LDAP) server that manages various resources connected to the network 10. The directory server 13 includes a storage unit 25 that holds a resource management table 26. Resource management information for managing various resources connected to the network 10 is registered in advance in the resource management table 26. Note that in order to use the network 10, the resources that use the network 10 must be registered in advance in the resource management table 26.
[0019] In this example, the user identifiers UID10 and UID20 of the users 14a and 14b who use the user terminals TM10 and TM20 are preregistered as user accounts in the resource management table 26. Computer identifiers set for printers, servers, etc. may also be registered as computer accounts in the resource management table 26. Furthermore, attribute information is associated with each account. For example, the attribute information of a user account may include various types of user information such as the user's employee number, affiliation, email address, password information, and access authority information.
[0020] In this configuration, when the SSO authentication server 12 generally receives a packet including an SSO authentication request from the user terminal TM, it obtains the MAC address corresponding to the source IP address of the received packet from the DHCP server 11. Then, the SSO authentication server 12 determines whether to permit SSO authentication based on whether the obtained MAC address is registered in the authentication table 24.
[0021] That is, the SSO authentication server 12 performs SSO authentication based on the MAC address of the user terminal TM. Specifically, it receives an L3 packet from the user terminal TM and performs SSO authentication based on the L2 MAC address. As a result, when performing SSO authentication, the user does not need to input the user identifier UID and password. Consequently, it becomes possible to reduce the user's workload. Note that the user terminal TM for which SSO authentication is permitted can access a plurality of service providers SPa, SPb without inputting the user identifier UID and password thereafter by the SSO function.
[0022] Also, when the obtained MAC address is registered in the authentication table 24, the SSO authentication server 12 obtains the user identifier UID corresponding to the MAC address from the authentication table 24. Then, the SSO authentication server 12 determines whether the obtained user identifier UID is registered in the resource management table 26 of the directory server 13 by sending the obtained user identifier UID to the directory server 13, and permits SSO authentication if it is registered. Thereby, it is possible to permit SSO authentication after confirming that the user is permitted to use the network 10. That is, security can be improved.
[0023] <Operation of the SSO Authentication System> Fig. 2 is a sequence diagram showing an example of the processing contents of the main part of the SSO authentication system in Fig. 1. In Fig. 2, first, the user terminal TM performs a predetermined DHCP process with the DHCP server 11, and an IP address is assigned by the DHCP server 11 (step S101). Specifically, the DHCP server 11 receives an L2 broadcast frame including a DHCP discover from the user terminal TM, and assigns an IP address to the user terminal TM by responding to the DHCP discover. Then, when the DHCP server 11 assigns the IP address in step S101, it registers the correspondence between the MAC address of the user terminal TM included in the frame from the user terminal TM and the assigned IP address in the IP management table 22 (step S102).
[0024] After that, the user terminal TM transmits an SSO authentication request to the SSO authentication server 12 using an L3 packet (step S103). In response to this, the SSO authentication server 12 refers to the IP management table 22 of the DHCP server 11 using the source IP address included in the packet as a key, and acquires a MAC address corresponding to the IP address from the DHCP server 11 (step S104). Next, the SSO authentication server 12 determines whether the MAC address acquired in step S104 is registered in the authentication table 24 (step S105).
[0025] If the MAC address is not registered in the authentication table 24 in step S105, the SSO authentication server 12 requests the user to input a user identifier UID and password PW (step S106-2). Specifically, the SSO authentication server 12 displays an input screen for the user identifier UID and password PW on the user terminal TM. On the other hand, if the MAC address is registered in the authentication table 24 in step S105, the SSO authentication server 12 refers to the authentication table 24 using the MAC address acquired in step S104 as a key. As a result, the SSO authentication server 12 acquires the user identifier UID corresponding to the MAC address (step S106-1).
[0026] Next, the SSO authentication server 12 judges whether the user identifier ID is registered in the resource management table 26 by transmitting the user identifier UID acquired in step S106-1 to the directory server 13 (steps S107, S108). Specifically, the SSO authentication server 12 transmits the user identifier UID to the directory server 13 using, for example, LDAP, and receives information on whether the user identifier UID is registered from the directory server 13. If the user identifier UID is registered, the SSO authentication server 12 also receives user information, i.e., attribute information (step S107). The SSO authentication server 12 judges whether the user identifier ID is registered in the resource management table 26 based on the received information (step S108).
[0027] In step S108, if the user identifier ID is registered in the resource management table 26, the SSO authentication server 12 permits the SSO authentication and transmits a permission response to the user terminal TM (step S109-1). On the other hand, in step S108, if the user identifier ID is not registered in the resource management table 26, the SSO authentication server 12 rejects the SSO authentication and transmits a rejection response to the user terminal TM (step S109-2).
[0028] As a specific example of the process shown in Fig. 2, assume that the user terminal TM10 in Fig. 1 transmits an authentication request to the SSO authentication server 12 (step S103). In this case, the MAC address MA10 is acquired based on the IP address IPA10 of the user terminal TM10 (step S104). The MAC address MA10 is registered in the authentication table 24, and the user identifier UID10 corresponding to the MAC address MA10 is registered in the resource management table 26 (steps S105, S108). Therefore, an authorization response is transmitted to the user terminal TM10 (step S109-1).
[0029] On the other hand, assume that the user terminal TM20 in Fig. 1 transmits an authentication request to the SSO authentication server 12 (step S103). In this case, the MAC address MA20 is acquired based on the IP address IPA20 of the user terminal TM20 (step S104). The MAC address MA20 is not registered in the authentication table 24 (step S105). For this reason, the user terminal TM20, specifically the user 14b, is requested to input a user identifier UID and a password PW (step S106-2). Although details are omitted, when the user 14b inputs the user identifier UID and password PW, the SSO authentication server 12 checks them against the resource management table 26 in the directory server 13 to determine whether or not to permit authentication.
[0030] In step S107, the user information, i.e., the attribute information, may include an access right such as an access right to only one service provider SPa among two service providers SPa and SPb. In this case, the SSO authentication server 12 transmits an authorization response in step S109-1 only when the user terminal TM accesses the service provider SPa.
[0031] As a specific example, in SAML, the user terminal TM may access the service provider SPa, and an authentication request may occur in step S103 in the form of a redirect from the service provider SPa via the user terminal TM. The SSO authentication server 12 transmits an authorization response to the user terminal TM because the user information in step S107 includes access authority to the service provider SPa. The authorization response is an authentication token or the like for permitting access to the service provider SPa. On the other hand, in response to an authentication request generated by the user terminal TM accessing the service provider SPb, the SSO authentication server 12 transmits a rejection response to the user terminal TM because the user information in step S107 does not include access authority to the service provider SPb.
[0032] Note that the SSO authentication system according to the embodiment is not necessarily limited to the SAML method, and can also be applied to other methods such as, for example, the reverse proxy method. In the reverse proxy method, for example, the SSO authentication server 12 is used as a reverse proxy server, and the access from the user terminal TM to the service providers SPa and SPb is always configured to pass through the reverse proxy server. In this case, the reverse proxy server may perform the processing as shown in FIG. 2 in response to the authentication request from the user terminal TM, and send an authenticated cookie or the like as the permission response in step S109-1.
[0033] <Details of the SSO Authentication Server> FIG. 3 is a block diagram showing a configuration example of the main part of the SSO authentication server in FIG. 1. The SSO authentication server (SSO authentication device) 12 shown in FIG. 3 includes a processing unit 30 and a communication unit 31 in addition to a storage unit 23 that holds the authentication table 24 shown in FIG. 1. The processing unit 30 is realized, for example, by a processor executing a control program (not shown) stored in the storage unit 23. However, the processing unit 30 is not limited to this, and part or all of it may be realized by an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), or the like. The communication unit 31 is realized, for example, by an Ethernet (registered trademark) interface circuit or the like.
[0034] The processing unit 30 includes a source IP address acquisition unit 35, a MAC address acquisition unit 36, a user identifier acquisition unit 37, a user information verification unit 38, and an authentication determination unit 39. The source IP address acquisition unit 35 receives the authentication request packet ARQ from the user terminal TM10 via the communication unit 31, and acquires the source IP address S-IP of the authentication request packet ARQ.
[0035] The MAC address acquisition unit 36 acquires a MAC address corresponding to the acquired source IP address S-IP from the DHCP server 11 via the communication unit 31. The user identifier acquisition unit 37 determines whether the acquired MAC address is registered in the authentication table 24. If the MAC address is registered in the authentication table 24, the user identifier acquisition unit 37 acquires a user identifier UID corresponding to the MAC address by referring to the authentication table 24 using the MAC address as a key.
[0036] The user information verification unit 38 transmits the user identifier UID acquired by the user identifier acquisition unit 37 to the directory server 13 via the communication unit 31, thereby determining whether the user identifier UID is registered in the resource management table 26. Furthermore, if the user identifier UID is registered in the resource management table 26, the user information verification unit 38 acquires user information IMa corresponding to the user identifier UID, i.e., attribute information, from the resource management table 26.
[0037] The authentication judgment unit 39 judges whether or not to permit SSO authentication based on the judgment result of the user identifier acquisition unit 37, i.e., registration presence / absence information IMr of the MAC address in the authentication table 24. More preferably, the authentication judgment unit 39 judges whether or not to permit SSO authentication based on the judgment result of the user information verification unit 38, i.e., whether or not the user identifier UID is registered in the resource management table 26 and the user information IMu when the user identifier UID is registered, in addition to the registration presence / absence information IMr. In detail, the authentication judgment unit 39 judges that authentication is permitted when the MAC address is registered in the authentication table 24 and the user identifier UID is registered in the resource management table 26. At this time, the authentication judgment unit 39 may judge whether or not to permit authentication by reflecting the access authority that may be included in the user information IMu.
[0038] <Major Effects of the First Embodiment> In the method of Embodiment 1 described above, the SSO authentication server 12 obtains the MAC address corresponding to the IP address assigned to the user terminal TM in cooperation with the DHCP server 11, and performs SSO authentication based on the MAC address. As a result, when performing SSO authentication, it is not necessary to input the user identifier UID or the password PW, and it is also not necessary to prepare a certificate or the like, so it is possible to reduce the work load of the user. In addition, when performing SSO authentication, it is not necessary to use a biometric authentication device or the like, so it is possible to reduce costs.
[0039] (Embodiment 2) <Outline of SSO Authentication System> FIG. 4 is a schematic diagram showing a configuration example of the SSO authentication system according to Embodiment 2. The SSO authentication system shown in FIG. 4 differs from the configuration example shown in FIG. 1 in the following two points. As the first difference, the directory server 13 in FIG. 1 is not provided, and instead, the SSO authentication server 12a holds the resource management table 26 in the directory server 13 in the storage unit 23. As the second difference, accompanying the first difference, the SSO authentication server 12a performs different processing from the case of FIG. 1.
[0040] That is, the storage unit 23 in the SSO authentication server 12a holds, in addition to the authentication table 24 representing the correspondence between the MAC address that permits SSO authentication and the user identifier UID, a resource management table 26 for managing various resources connected to the network. And generally, similar to the case of FIG. 1, when the MAC address obtained from the DHCP server 11 is registered in the authentication table 24, the SSO authentication server 12a obtains the user identifier UID corresponding to the MAC address from the authentication table 24. However, different from the case of FIG. 1, the SSO authentication server 12a determines whether the obtained user identifier UID is registered in the resource management table 26 without communicating with the directory server 13, and permits SSO authentication when it is registered.
[0041] <Operation of SSO Authentication System> FIG. 5 is a sequence diagram showing an example of the processing content of the main part of the SSO authentication system in FIG. 4. In FIG. 5, the processing content from step S101 to steps S106-1 and S106-2 is the same as in the case of FIG. 2. Thereafter, in step S108a, the SSO authentication server (SSO authentication device) 12a, unlike the case of FIG. 2, determines whether or not to register the user identifier UID acquired in step S106-1 in the resource management table 26 without going through the processing in step S107.
[0042] Thereafter, in the same manner as in the case of FIG. 2, the SSO authentication server 12a transmits a permission response or a rejection response to the user terminal TM based on whether or not the user identifier UID is registered in the resource management table 26 (steps S109-1 and S109-2). Although not shown, when the user identifier UID is registered in the resource management table 26 in step S108a, the SSO authentication server 12a appropriately processes the user information, that is, the attribute information of the user identifier UID in the same manner as in the case of FIG. 2.
[0043] <Details of SSO Authentication Server> FIG. 6 is a block diagram showing a configuration example of the main part of the SSO authentication server in FIG. 4. The SSO authentication server 12a shown in FIG. 6 is different in the following two points compared to the configuration example shown in FIG. 3. As the first difference, the storage unit 23 holds a resource management table 26 in addition to the authentication table 24. As the second difference, the user information verification unit 38a performs different processing from the case of FIG. 3.
[0044] That is, the user information verification unit 38a determines whether or not the user identifier UID acquired by the user identifier acquisition unit 37 is registered in the resource management table 26 without communicating with the directory server 13. Also, in the same manner as in the case of FIG. 3, when the user identifier UID is registered in the resource management table 26, the user information verification unit 38a acquires the user information IMu corresponding to the user identifier UID, that is, the attribute information, from the resource management table 26.
[0045] <Principal effects of Embodiment 2> As described above, by using the method of Embodiment 2, the same effects as those described in Embodiment 1 can be obtained. Furthermore, since the SSO authentication server 12a includes the resource management table 26, the directory server 13 becomes unnecessary, and it becomes possible to reduce the device cost and communication load.
[0046] (Embodiment 3) <Outline of SSO authentication system> FIG. 7 is a schematic diagram showing a configuration example of an SSO authentication system according to Embodiment 3. The SSO authentication system shown in FIG. 7 is different from the configuration example shown in FIG. 4 in the following points. That is, the storage unit 23 in the SSO authentication server 12b holds an authentication management table 45. Accordingly, the SSO authentication server 12b performs different processing from the case of FIG. 4.
[0047] In the authentication management table 45, information for managing various resources connected to the network 10 is registered in advance, and a MAC address that permits SSO authentication is registered as part of the information. That is, the authentication management table 45 is like an integration of the authentication table 24 and the resource management table 26 shown in FIG. 4. The SSO authentication server 12b generally determines whether to permit SSO authentication based on whether the MAC address obtained from the DHCP server 11 is registered in the authentication management table 45.
[0048] In this example, in the authentication management table 45, a MAC address MA10 that permits SSO authentication is registered as attribute information associated with the user identifier UID10, which is a user account, that is, as one of the user information. In this case, when the SSO authentication server 12b receives an authentication request from the user terminal TM10 having the MAC address MA10, it permits SSO authentication based on the MAC address.
[0049] On the other hand, in the authentication management table 45, the MAC address is not registered in the attribute information of the user identifier UID20. In this case, when the SSO authentication server 12b receives an authentication request from the user terminal TM20 having the MAC address MA20, the SSO authentication by the MAC address is not permitted. Instead, the SSO authentication server 12b requests the user 14b to input the user identifier UID and the password.
[0050] <Operation of SSO Authentication System> FIG. 8 is a sequence diagram showing an example of the processing content of the main part of the SSO authentication system in FIG. 7. Regarding the processing content from step S101 to step S104 in FIG. 8, it is the same as in the case of FIG. 5. Thereafter, in step S105a, the SSO authentication server (SSO authentication device) 12b determines whether the MAC address obtained in step S104 is registered in the authentication management table 45. However, in step S105a, unlike the case of step S105 in FIG. 5, when the MAC address is registered in the authentication management table 45, inevitably, the user identifier UID is also registered in the authentication management table 45.
[0051] Thereafter, when the MAC address is registered in the authentication management table 45, the SSO authentication server 12b transmits a permission response to the user terminal TM (step S106a-1). On the other hand, when the MAC address is not registered in the authentication management table 45, the SSO authentication server 12b requests the user using the user terminal TM to input the user identifier UID and the password PW (step S106a-2). Although not shown, when the MAC address is registered in the authentication management table 45 in step S105a, the SSO authentication server 12b appropriately processes the user information, that is, the attribute information of the corresponding user identifier UID, in the same manner as in the case of FIG. 2.
[0052] <Details of SSO Authentication Server> FIG. 9 is a block diagram showing a configuration example of the main part of the SSO authentication server in FIG. 7. The SSO authentication server 12b shown in FIG. 9 is different from the configuration example shown in FIG. 6 in the following two points. As the first difference, the storage unit 23 holds an authentication management table 45. As the second difference, the user identifier acquisition unit 37 and the user information verification unit 38a are not provided, and an authentication determination unit 46 that performs a process different from that in the case of FIG. 5 is provided.
[0053] The authentication determination unit 46 determines whether SSO authentication is permitted based on whether the MAC address acquired by the MAC address acquisition unit 36 is registered in the authentication management table 45. Specifically, the authentication determination unit 46 refers to the authentication management table 45 using the acquired MAC address as a key to determine whether the MAC address is registered. If it is registered, the corresponding user information IMu, that is, the attribute information excluding the MAC address, is acquired. Then, when the MAC address is registered in the authentication management table 45, the authentication determination unit 46 permits SSO authentication.
[0054] <Main effects of Embodiment 3> As described above, by using the method of Embodiment 3, effects similar to the various effects described in Embodiments 1 and 2 can be obtained. Furthermore, since SSO authentication can be managed based on one authentication management table 45, it becomes possible to improve the efficiency of network management.
[0055] (Embodiment 4) <Outline of SSO authentication system> FIG. 10 is a schematic diagram showing a configuration example of the SSO authentication system according to Embodiment 4. The SSO authentication system shown in FIG. 10 has substantially the same configuration as that in FIG. 7. However, the configuration of the authentication management table 45c held by the storage unit 23 in the SSO authentication server 12c is different from that in the case of FIG. 7. Accordingly, the processing content of the SSO authentication server 12c is also different from that in the case of FIG. 7.
[0056] In the authentication management table 45c, for each MAC address that permits SSO authentication, strictly speaking, for each user identifier UID, an entity ID representing the service provider SP targeted by SSO is registered in advance as one of the attribute information. In other words, access rights are registered as one of the attribute information. In the example of FIG. 10, for the user identifier UID10 corresponding to the MAC address MA10, only the access right to the service provider SPa is granted. On the other hand, for the user identifier UID20, access rights to the service providers SPa and SPb are granted.
[0057] When the MAC address obtained by the SSO authentication server 12c from the DHCP server 11 is registered in the authentication management table 45c, the SSO authentication server 12c permits the SSO authentication to the service provider SP represented by the entity ID corresponding to the MAC address. In this example, when the SSO authentication server 12c receives an authentication request from the user terminal TM10 having the MAC address MA10, the SSO authentication based on the MAC address is permitted, and access only to the service provider SPa is permitted.
[0058] On the other hand, when the SSO authentication server 12b receives an authentication request from the user terminal TM20 having the MAC address MA20, the SSO authentication based on the MAC address is not permitted, and the user 14b is requested to input the user identifier UID and the password. When the correct user identifier UID20 and password are input by the user 14b, the SSO authentication server 12b permits the SSO authentication and permits access to the service providers SPa and SPb.
[0059] <Operation of the SSO Authentication System> Fig. 11 is a sequence diagram showing an example of the processing contents of the main part of the SSO authentication system in Fig. 10. Fig. 12 is a sequence diagram showing an example of the processing contents different from those in Fig. 11. There are two types of authentication methods using SAML: a method that starts from access to a service provider SP, and a method that starts from access to an SSO authentication server 12c that is an Idp. Fig. 11 shows the former method, and Fig. 12 shows the latter method.
[0060] In Fig. 11, the process contents of steps S101 and S102 are the same as those in Fig. 8. After that, in step S201, the user terminal TM accesses the service provider SP, unlike the case in Fig. 8. As a specific example, assume that an access to the service provider SPa occurs. In response to the access from the user terminal TM, the service provider SPa redirects an authentication request including the entity ID of the service provider SPa to the SSO authentication server 12c via the user terminal TM (step S103a).
[0061] 8, the SSO authentication server 12c acquires from the DHCP server 11 a MAC address corresponding to the source IP address included in the authentication request (step S104).Then, the SSO authentication server 12c determines whether the acquired MAC address is registered in the authentication management table 45c (step S105a).If the MAC address is not registered in the authentication management table 45c, the SSO authentication server 12c requests the user who uses the user terminal TM to input a user identifier UID and a password PW (step S202-2).
[0062] On the other hand, if the MAC address is registered in the authentication management table 45c in step S105a, the SSO authentication server 12c determines whether the entity ID of the service provider SPa included in the authentication request in step S103a is registered in the authentication management table 45c (step S202-1), unlike the case of Fig. 8. Specifically, the SSO authentication server 12c determines whether the entity ID of the service provider SPa is registered in the authentication management table 45c in association with the target MAC address, or more precisely, the target user identifier UID.
[0063] In step S202-1, if the entity ID of the service provider SPa is registered in the authentication management table 45c, the SSO authentication server 12c redirects the authentication token or the like representing the permission response to the service provider SPa via the user terminal TM (step S203-1). On the other hand, in step S202-1, if the entity ID of the service provider SPa is not registered in the authentication management table 45c, the SSO authentication server 12c transmits a rejection response to the user terminal TM (step S203-2).
[0064] In Fig. 12, the process contents from step S101 to step S105a are the same as those in Fig. 8. If the MAC address is not registered in the authentication management table 45c in step S105a, the SSO authentication server 12c requests the user who uses the user terminal TM to input a user identifier UID and a password PW (step S301-2).
[0065] On the other hand, if the MAC address is registered in the authentication management table 45c in step S105a, the SSO authentication server 12c transmits selection information of the service provider SP to the user terminal TM (step S301-1). Specifically, the SSO authentication server 12c displays icons or the like representing the service providers SPa and SPb that are targets of SSO on the screen of the user terminal TM.
[0066] After that, the user who uses the user terminal TM selects the service provider SP to be accessed by clicking on the icon displayed on the screen or the like (step S302). As a specific example, assume that the service provider SPa is selected. In response to this, the user terminal TM sends a login request including the entity ID of the selected service provider SPa to the SSO authentication server 12c (step S303).
[0067] The SSO authentication server 12c receives the login request in step S303 and determines whether the entity ID of the service provider SPa included in the login request is registered in the authentication management table 45c (step S304). Specifically, the SSO authentication server 12c determines whether the entity ID of the service provider SPa is registered in the authentication management table 45c in association with the target MAC address, strictly speaking, the target user identifier UID.
[0068] In step S304, if the entity ID of the service provider SPa is registered in the authentication management table 45c, the SSO authentication server 12c redirects an authentication token or the like indicating a permission response to the service provider SPa via the user terminal TM (step S305-1). On the other hand, in step S304, if the entity ID of the service provider SPa is not registered in the authentication management table 45c, the SSO authentication server 12c sends a rejection response to the user terminal TM (step S305-2).
[0069] <Details of the SSO authentication server> The configuration of the SSO authentication server 12c in Fig. 10 is almost the same as that in Fig. 9. However, in the fourth embodiment, the storage unit 23 holds the authentication management table 45c shown in Fig. 10, and the user information Imu acquired from the authentication management table 45c by the authentication judgment unit 46 includes the entity ID of the service provider SP. When the MAC address acquired by the MAC address acquisition unit 36 is registered in the authentication management table 45c, the authentication judgment unit 46 permits SSO authentication to the service provider SP represented by the entity ID corresponding to the MAC address.
[0070] <Modification of the authentication management table> Fig. 13 is a schematic diagram showing an example of a configuration of the authentication management table in Fig. 10 that is different from that of Fig. 10. Unlike the case of Fig. 10, the authentication management table 45d shown in Fig. 13 has two MAC addresses MA10 and MA11 registered in correspondence with the user identifier UID10. Furthermore, the entity ID of the service provider SPa is registered in correspondence with the MAC address MA10, and the entity ID of the service provider SPb is registered in correspondence with the MAC address MA12.
[0071] In this case, when the SSO authentication server 12c receives an authentication request from a user terminal TM10 having a MAC address MA10, the SSO authentication server 12c permits SSO authentication only to the service provider SPa. Also, when the SSO authentication server 12c receives an authentication request from a user terminal having a MAC address MA11, the SSO authentication server 12c permits SSO authentication only to the service provider SPb.
[0072] <Major Effects of the Fourth Embodiment> As described above, by using the method of the fourth embodiment, it is possible to obtain the same effects as those described in the first to third embodiments. Furthermore, it is possible to restrict access to the service provider SP based on information on access authority associated with a MAC address, specifically, on an entity ID. As a result, it is possible to realize a highly flexible network management.
[0073] The invention made by the present inventor has been specifically described above based on the embodiments, but the present invention is not limited to the above-mentioned embodiments and can be modified in various ways without departing from the gist of the invention. For example, the above-mentioned embodiments have been described in detail to easily explain the present invention, and the present invention is not necessarily limited to those having all of the configurations described. In addition, it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of one embodiment. In addition, it is possible to add, delete, or replace a part of the configuration of each embodiment with another configuration. [Explanation of symbols]
[0074] 10: network, 11: DHCP server, 12, 12a, 12b: SSO authentication server (SSO authentication device), 13: directory server, 14a, 14b: user, 15: router, 21, 23, 25: storage unit, 22: IP management table, 24: authentication table, 26: resource management table, 30: processing unit, 31: communication unit, 35: source IP address acquisition unit, 36: MAC address acquisition unit, 37: user identifier acquisition unit, 38: user information verification unit, 39: authentication judgment unit, 45, 45c: authentication management table, SP: service provider, TM: user terminal
Claims
1. A DHCP server that assigns IP addresses to user terminals; a single sign-on authentication server that is connected to the user terminal and the DHCP server via a network and determines whether or not to permit single sign-on authentication in response to an authentication request from the user terminal; a resource management table in which user identifiers permitted to be authenticated are registered; Equipped with When the DHCP server assigns an IP address to the user terminal, the DHCP server stores a correspondence relationship between the assigned IP address and a MAC address of the user terminal; The single sign-on authentication server, holding an authentication table in which MAC addresses for which single sign-on authentication is permitted and user identifiers corresponding to the MAC addresses are registered in advance; When receiving a packet including the authentication request from the user terminal, obtain a MAC address corresponding to a source IP address of the received packet from the DHCP server, and determine whether the obtained MAC address is registered in the authentication table; If the acquired MAC address is registered in the authentication table, the user identifier corresponding to the MAC address is acquired from the authentication table, and it is determined whether the acquired user identifier is registered in the resource management table. If the acquired user identifier is registered in the resource management table, the single sign-on authentication is permitted. If the acquired MAC address is not registered in the authentication table, the user is requested to input the user identifier and password via the user terminal; a directory server connected to the single sign-on authentication server via the network and holding the resource management table for managing various resources connected to the network, including the user identifier; when the MAC address acquired from the DHCP server is registered in the authentication table, the single sign-on authentication server transmits the user identifier acquired from the authentication table to the directory server to determine whether the user identifier is registered in the resource management table; Single sign-on authentication system.
2. 2. The single sign-on authentication system according to claim 1, The network includes a router connected between the user terminal and the DHCP server and performing layer 3 processing of the OSI reference model. Single sign-on authentication system.
3. A single sign-on authentication device that is connected to the user terminal and the DHCP server via a network and determines whether or not to permit single sign-on authentication in response to an authentication request from the user terminal, on the premise that a DHCP server stores a correspondence relationship between the assigned IP address and a MAC address of the user terminal when the DHCP server assigns an IP address to the user terminal, and further on the premise that a resource management table is provided in which user identifiers for which authentication is permitted are registered, comprising: a storage unit that holds an authentication table in which MAC addresses that are permitted to be authenticated for single sign-on and user identifiers corresponding to the MAC addresses are registered in advance; a MAC address acquisition unit that, when receiving a packet including the authentication request from the user terminal, acquires a MAC address corresponding to a source IP address of the received packet from the DHCP server; a user identifier acquiring unit that acquires the user identifier corresponding to the MAC address from the authentication table when the acquired MAC address is registered in the authentication table; a user information verification unit that determines whether the acquired user identifier is registered in the resource management table; an authentication determination unit that permits authentication of the single sign-on when the user identifier is registered in the resource management table, and requests a user to input the user identifier and a password via the user terminal when the MAC address acquired by the MAC address acquisition unit is not registered in the authentication table; Equipped with the single sign-on authentication device is connected via the network to a directory server that holds the resource management table for managing various resources connected to the network, including the user identifier; the user information verification unit transmits the user identifier acquired by the user identifier acquisition unit to the directory server to determine whether the user identifier is registered in the resource management table; Single sign-on authentication device.
Citation Information
Patent Citations
Authentication method, authentication device, and program
JP2008287524A
Authentication system
JP2016110300A
Authentication system
JP2016118930A
Server device and network system
JP2021165977A
Authentication system, method, and program
JP2022087192A