Authentication server, work terminal, information processing method, and program

The authentication server addresses the challenge of securely and easily logging in to sites by storing and managing authentication information codes, enabling secure access through user and work terminals.

JP7690414B2Active Publication Date: 2025-06-10THE JAPAN RES INST
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022025212
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-22
Publication Date
2025-06-10
Estimated Expiration
2042-02-22

AI Technical Summary

Technical Problem

Conventional authentication systems lack a mechanism to easily log in to sites while ensuring the security of authentication information.

Method used

An authentication server that stores codes for authentication information corresponding to user identifiers, receives authentication requests, acquires and transmits codes to user terminals, and supports logging in to sites using access information.

Benefits of technology

Provides a secure and easy mechanism for logging in to sites, ensuring the security of authentication information and facilitating access through user and work terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007690414000001
    Figure 0007690414000001
  • Figure 0007690414000002
    Figure 0007690414000002
  • Figure 0007690414000003
    Figure 0007690414000003
Patent Text Reader

Abstract

To provide an authentication server, an operation terminal, an information processing method, and a program that can easily log in to a site while ensuring a security of authentication information to log in to the site.SOLUTION: In an information processing system including an authentication server, a user terminal, an operation terminal, and a site, the authentication server 1 includes a code storage unit 112 that stores codes for one or more pieces of authentication information in association with each of one or more user identifier, an authentication request reception unit 121 that receives an authentication request from the user terminal, a code acquisition unit 131 that acquires the code corresponding to the user identifier corresponding to the authentication request, a code transmission unit 141 that transmits the code to the user terminal, an access information reception unit 122 that receives from the operation terminal access information which is information corresponding to the code and is information to log in to each of the one or more sites, and a support unit 132 that performs support processing to log in to each of the one or more sites using the access information by the operation terminal.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an authentication server or the like that performs a support process for logging in to one or more sites. [Background technology]

[0002] Conventionally, when a user terminal accesses a URL specific to the user and the transition site, the URL is analyzed based on a predetermined master, a security check is performed, and if the check is successful, a login screen is displayed on the user terminal (see Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2017-182781 A Summary of the Invention [Problem to be solved by the invention]

[0004] However, in conventional technology, there was no mechanism that allowed users to easily log in to a site while ensuring the security of authentication information used to log in to the site. [Means for solving the problem]

[0005] The authentication server of the first invention is an authentication server comprising: a code storage unit in which codes for one or more authentication information corresponding to each of one or more user identifiers and enabling logging in to each of one or more sites are stored; an authentication request receiving unit that receives an authentication request corresponding to the user identifier from a user terminal; a code acquisition unit that acquires a code corresponding to the user identifier corresponding to the authentication request from the code storage unit in response to receiving the authentication request; a code sending unit that transmits the code acquired by the code acquisition unit to the user terminal; an access information receiving unit that receives the code sent by the code sending unit and receives access information, which is information corresponding to the code and is information for logging in to each of one or more sites, from a working terminal that has acquired the code from the user terminal that received the code sent by the code sending unit and output it; and a support unit that performs support processing for the working terminal to log in to each of one or more sites using the access information.

[0006] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site.

[0007] In addition, the authentication server of the second invention is an authentication server according to the first invention, in which the support unit performs a first support process of acquiring one or more authentication information corresponding to the access information, accessing one or more sites using each of the one or more authentication information, acquiring a webpage after logging in to each of the one or more sites, and sending the webpage to the work terminal, or performs a second support process of acquiring one or more authentication information corresponding to the access information, accessing one or more sites, acquiring a webpage for logging in to each of the one or more sites, constructing a webpage into which the authentication information corresponding to the webpage is input, and sending the webpage to the work terminal, or performs a third support process of acquiring one or more authentication information corresponding to the access information and sending it to the work terminal.

[0008] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site.

[0009] Furthermore, the authentication server of the third invention is an authentication server in which, compared to the first or second invention, the authentication information corresponds to a user terminal identifier that identifies the user terminal, the authentication request includes a user identifier and a user terminal identifier, and the code acquisition unit, in response to receiving the authentication request, acquires a code that enables logging in to one or more sites that can be logged in using the user identifier and one or more pieces of authentication information corresponding to the user terminal identifier corresponding to the authentication request.

[0010] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site.

[0011] Furthermore, the authentication server of the fourth invention is an authentication server according to any one of the first to third inventions, wherein the authentication information corresponds to a work terminal identifier that identifies the work terminal, the authentication request includes a user identifier and a work terminal identifier, and the code acquisition unit, in response to receiving the authentication request, acquires a code that enables logging in to one or more sites that can be logged in using one or more pieces of authentication information corresponding to the user identifier and the work terminal identifier that correspond to the authentication request.

[0012] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site.

[0013] Furthermore, the authentication server of the fifth invention is an authentication server according to the fourth invention, in which some authentication information is associated with a work terminal identifier while other authentication information is not associated with a work terminal identifier, and an authentication request may or may not have a work terminal identifier, and when an authentication request that does not have a work terminal identifier is received, the code acquisition unit is an authentication server that acquires a code that is authentication information corresponding to the user identifier corresponding to the authentication request and enables logging in to two or more sites that can be logged in to using the authentication information that does not correspond to a work terminal identifier.

[0014] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site.

[0015] In addition, the authentication server of the sixth invention is an authentication server further comprising, with respect to any one of the first to fifth inventions, a time information acquisition unit that acquires time information for the code acquired by the code acquisition unit, a time information storage unit that stores the time information in correspondence with a user identifier, and a prohibition processing unit that performs a prohibition process, which is a process for logging out or preventing login to a site corresponding to the user identifier, if a certain amount of time or more has passed since the time specified by the time information.

[0016] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site.

[0017] In addition, the work terminal of the seventh invention is a work terminal that includes a terminal code acquisition unit that acquires a code from a user terminal, a selection item set construction unit that constructs a selection item set in which two or more sites are selected items, the selection item set being information corresponding to the code acquired by the terminal code acquisition unit, a selection item set output unit that outputs the selection item set, a selection receiving unit that accepts the selection of one or more selection items from the selection item set, an access information construction unit that constructs access information for the sites corresponding to each of the one or more selection items, and an access information transmission unit that transmits the access information, and the work terminal becomes able to access the sites in response to the transmission of the access information.

[0018] This configuration provides a mechanism for easily logging in to a site while ensuring the security of the authentication information used to log in to the site. Effect of the Invention

[0019] The authentication server according to the present invention can provide a mechanism for easily logging in to a site while ensuring the security of authentication information for logging in to the site. [Brief description of the drawings]

[0020] [Figure 1] Conceptual diagram of information system A in embodiment 1. [Diagram 2] Block diagram of Information System A [Diagram 3] Block diagram of authentication server 1 [Figure 4] Block diagram of the work terminal 3 [Diagram 5] A flowchart for explaining an example of the operation of the authentication server 1. [Figure 6] 1 is a flowchart illustrating a first example of the support process. [Figure 7] 11 is a flowchart illustrating a second example of the support process. [Figure 8] 11 is a flowchart illustrating a third example of the support process. [Figure 9] A flowchart illustrating an example of the prohibition process. [Figure 10] A flowchart for explaining an example of the operation of the user terminal 2 [Figure 11] A flowchart illustrating an example of the operation of the work terminal 3. [Figure 12] The authentication information management table [Figure 13] A diagram showing the code information management table [Figure 14] FIG. 1 is a diagram for explaining a specific example of the operation of the information system A. [Figure 15] A diagram showing an example of the output [Figure 16] A diagram showing the code information management table [Figure 17] Overview of the computer system [Figure 18] Block diagram of the computer system DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0021] Hereinafter, an embodiment of an authentication server and the like will be described with reference to the drawings. Note that components with the same reference numerals in the embodiments perform similar operations, and therefore repeated description may be omitted.

[0022] (Embodiment 1) In this embodiment, an information system including an authentication server that provides a mechanism for easily logging in to one or more sites while ensuring the security of authentication information for logging in to the sites will be described.

[0023] In addition, in this embodiment, an information system including an authentication server for logging in to one or more sites using only a specific user terminal will be described.

[0024] In addition, in this embodiment, an information system including an authentication server for logging in to one or more sites only when a specific user terminal accesses the authentication server will be described.

[0025] In addition, in this embodiment, an information system including an authentication server that supports logging in to one or more sites only from a specific work terminal will be described.

[0026] Further, in this embodiment, an information system including an authentication server that issues a code and provides a mechanism for preventing work on a site from being performed after a predetermined time has elapsed since the code is issued will be described.

[0027] In this embodiment, information X being associated with information Y means that information Y can be obtained from information X, or information X can be obtained from information Y, and the method of association is not important. Information X and information Y may be linked, may exist in the same buffer, information X may be included in information Y, or information Y may be included in information X, etc.

[0028] 1 is a conceptual diagram of an information system A according to the present embodiment. The information system A includes an authentication server 1, one or more user terminals 2, one or more operation terminals 3, and one or more sites 4.

[0029] The authentication server 1 is a server that assists a user in logging in to one or more sites 4 from a work terminal 3. The authentication server 1 is a server that transmits a code to a user terminal 2. The authentication server 1 is usually a server, for example, a cloud server or an ASP server, but the type is not important.

[0030] The user terminal 2 is a terminal used by a user, and is a terminal that receives the code transmitted by the authentication server 1. The user terminal 2 is, for example, a so-called personal computer, a smartphone, or a tablet terminal, but the type is not important.

[0031] The work terminal 3 is a terminal used by a user, and is a terminal used when logging in to the site 4. The work terminal 3 is a terminal for performing various tasks on the site 4. The work terminal 3 is, for example, a so-called personal computer, a smartphone, or a tablet terminal, but the type is not important.

[0032] Site 4 is usually a so-called website, but it may be anything that can be logged in to. Site 4 may be, for example, an online e-commerce site or a content viewing site, but the type does not matter. Site 4 may be, for example, a cloud server or an ASP server, but the type does not matter.

[0033] The authentication server 1 and one or more user terminals 2 can communicate with each other via a network such as the Internet or a LAN. The one or more work terminals 3 and one or more sites 4 can communicate with each other via a network such as the Internet or a LAN.

[0034] Fig. 2 is a block diagram of an information system A in this embodiment. Fig. 3 is a block diagram of an authentication server 1. Fig. 4 is a block diagram of a work terminal 3.

[0035] The authentication server 1 includes a storage unit 11, a receiving unit 12, a processing unit 13, and a transmitting unit 14. The storage unit 11 includes an authentication information storage unit 111 and a code storage unit 112. The receiving unit 12 includes an authentication request receiving unit 121 and an access information receiving unit 122. The processing unit 13 includes a code acquiring unit 131, a support unit 132, a time information acquiring unit 133, a time information accumulation unit 134, and a prohibition processing unit 135. The transmitting unit 14 includes a code transmitting unit 141.

[0036] The user terminal 2 includes a user storage unit 21, a user reception unit 22, a user processing unit 23, a user transmission unit 24, a user reception unit 25, and a user output unit .

[0037] The work terminal 3 includes a work storage unit 31, a work acceptance unit 32, a work processing unit 33, a work transmission unit 34, a work receiving unit 35, and a work output unit 36. The work acceptance unit 32 includes a selection acceptance unit 321. The work processing unit 33 includes a terminal code acquisition unit 331, a selected item set configuration unit 332, an access information configuration unit 333, and an access unit 334. The work transmission unit 34 includes an access information transmission unit 341. The work receiving unit 35 includes a web page reception unit 351. The work output unit 36 ​​includes a selected item set output unit 361 and a web page output unit 362.

[0038] Various types of information are stored in the storage unit 11 constituting the authentication server 1. The various types of information are, for example, authentication information (to be described later), a code (to be described later), and a prohibited condition (to be described later).

[0039] The authentication information storage unit 111 stores one or more pieces of authentication information. The authentication information is information that enables logging in to one or more sites 4. The authentication information is, for example, an ID and a password. The authentication information is, for example, an ID. The ID is an identifier for logging in to the site 4, and is information that identifies a user. The ID may be called an account ID, a user ID, or the like. A user identifier is associated with each of the one or more pieces of authentication information. The user identifier is information that identifies a user. The user identifier is an ID of a user for enjoying a service provided by the authentication server 1. The user identifier is, for example, a user ID, a name, a telephone number, or an email address. The user identifier may be a user terminal identifier. The user terminal identifier is information that identifies the user terminal 2 of the user, and is, for example, a terminal ID, a MAC address, or a telephone number.

[0040] The authentication information storage unit 111 stores one or more pieces of authentication information in association with one or more user identifiers. It is preferable that the authentication information storage unit 111 stores two or more pieces of authentication information in association with one or more user identifiers.

[0041] It is preferable that the authentication information in the authentication information storage unit 111 also corresponds to a user terminal identifier that identifies the user terminal 2. When the authentication server 1 is accessed from a user terminal 2 identified by the user terminal identifier, the user terminal 2 can only log in to sites 4 that can be logged in using the authentication information paired with the user terminal identifier.

[0042] It is preferable that the authentication information in the authentication information storage unit 111 also corresponds to a work terminal identifier that identifies the work terminal 3. From the work terminal 3 identified by the work terminal identifier, it is possible to log in only to sites 4 that can be logged in using the authentication information paired with the work terminal identifier.

[0043] The code storage unit 112 stores codes for one or more pieces of authentication information in association with one or more user identifiers.

[0044] The code is information used to log in to the site 4 from the work terminal 3. The code is information corresponding to authentication information. The code may be authentication information. A code usually corresponds to one piece of authentication information, but may correspond to two or more pieces of authentication information. A code corresponding to authentication information is, for example, a code in which one or more pieces of authentication information are embedded. The code is, for example, a pattern code, a character string, or a numeric string. A pattern code is, for example, a two-dimensional code or a one-dimensional code. A two-dimensional code is, for example, a QR code (registered trademark) or a color code. A one-dimensional code is, for example, a barcode. It is preferable that each of the two or more codes is unique.

[0045] The receiving unit 12 receives various types of information, such as an authentication request (to be described later) and access information (to be described later).

[0046] The authentication request receiving unit 121 receives an authentication request corresponding to a user identifier from the user terminal 2. The user identifier is an identifier for accessing the authentication server 1. The authentication request has, for example, a password for accessing the authentication server 1. The authentication request has, for example, one or more pieces of information among a user terminal identifier, a work terminal identifier, and a site identifier. The site identifier is information for identifying the site 4. Note that the authentication request corresponding to a user identifier is, for example, an authentication request including the user identifier. It goes without saying that the authentication request corresponding to a user identifier may have the same meaning as an authentication request corresponding to a user terminal identifier.

[0047] The access information receiving unit 122 receives access information from the work terminal 3. The work terminal 3 is a terminal that acquires a code from the user terminal 2. The user terminal 2 is a terminal that receives and outputs a code transmitted by the code transmitting unit 141 described below. The access information is information for logging in to one or more sites 4. The access information is information corresponding to the code transmitted by the code transmitting unit 141. The access information is, for example, authentication information for logging in to the site 4. The authentication information is, for example, a user identifier and a password. The access information is, for example, a code identifier that identifies the code transmitted by the code transmitting unit 141.

[0048] The access information reception 122 receives the code transmitted by the code transmission unit 141, and receives access information, which is information corresponding to the code and is used to log in to one or more sites, from the working terminal 3 that has acquired the code from the user terminal 2 that output the code. Here, the code transmitted by the code transmission unit 141 and the code output from the user terminal 2 do not need to be the same information. It is sufficient that the code transmitted by the code transmission unit 141 and the code output from the user terminal 2 are associated with each other.

[0049] The processing unit 13 performs various types of processing. The various types of processing are, for example, processing performed by a code acquisition unit 131, a support unit 132, a time information acquisition unit 133, a time information accumulation unit 134, and a prohibition processing unit 135.

[0050] In response to receiving an authentication request, the code acquisition unit 131 acquires a code corresponding to a user identifier corresponding to the authentication request. For example, in response to receiving an authentication request, the code acquisition unit 131 acquires a code corresponding to a user identifier corresponding to the authentication request from the code storage unit 112. For example, in response to receiving an authentication request, the code acquisition unit 131 generates a code corresponding to a user identifier corresponding to the authentication request. Note that, for example, one or more pieces of authentication information corresponding to the user identifier are embedded in the code. In addition, when the information to be embedded is determined, a technique for generating a code in which the information is embedded is a publicly known technique. In addition, the code acquisition unit 131 may, for example, associate the acquired code with a user identifier corresponding to the received authentication request and temporarily store the code in the code storage unit 112.

[0051] For example, in response to receiving an authentication request, the code acquisition unit 131 acquires one or more pieces of authentication information corresponding to a user identifier corresponding to the authentication request and a user terminal identifier corresponding to the user identifier, and acquires a code using the one or more pieces of authentication information. More specifically, for example, in response to receiving an authentication request, the code acquisition unit 131 acquires one or more pieces of authentication information corresponding to a user identifier corresponding to the authentication request and a user terminal identifier corresponding to the user identifier from the authentication information storage unit 111. Next, the code acquisition unit 131 acquires, for example, a code corresponding to the one or more pieces of authentication information from the code storage unit 112. Note that the code acquisition unit 131 may generate a code in which the one or more pieces of authentication information are embedded. Also, the code acquisition unit 131 may temporarily store the acquired code in the code storage unit 112 in association with a user identifier corresponding to the authentication request and a user terminal identifier corresponding to the user identifier.

[0052] It is preferable that the code acquisition unit 131 judges whether or not a pair of a user identifier corresponding to an authentication request and a user terminal identifier corresponding to the user identifier exists in the authentication information storage unit 111, and acquires the code only when it is judged that the pair exists. Note that the user identifier corresponding to an authentication request and the user terminal identifier corresponding to the user identifier are, for example, the user identifier and user terminal identifier contained in the authentication request.

[0053] For example, in response to receiving an authentication request, the code acquisition unit 131 acquires a code using one or more pieces of authentication information corresponding to a user identifier and a work terminal identifier corresponding to the authentication request. More specifically, for example, in response to receiving an authentication request, the code acquisition unit 131 acquires one or more pieces of authentication information corresponding to a user identifier corresponding to the authentication request and a work terminal identifier corresponding to the user identifier from the authentication information storage unit 111. Next, the code acquisition unit 131 acquires, for example, a code corresponding to the one or more pieces of authentication information from the code storage unit 112. Note that the code acquisition unit 131 may generate a code in which the one or more pieces of authentication information are embedded. Also, the code acquisition unit 131 may temporarily store the acquired code in the code storage unit 112 in association with a user identifier corresponding to the authentication request and a work terminal identifier corresponding to the user identifier.

[0054] It is preferable that the code acquisition unit 131 judges whether or not a pair of a user identifier corresponding to an authentication request and a work terminal identifier corresponding to the user identifier exists in the authentication information storage unit 111, and acquires the code only when it is judged that the pair exists. Note that the user identifier corresponding to an authentication request and the work terminal identifier corresponding to the user identifier are, for example, the user identifier and the work terminal identifier included in the authentication request.

[0055] For example, in response to receiving an authentication request, the code acquisition unit 131 acquires a code using one or more pieces of authentication information corresponding to a user identifier corresponding to the authentication request, a user terminal identifier corresponding to the user identifier, and a work terminal identifier corresponding to the user identifier. More specifically, for example, in response to receiving an authentication request, the code acquisition unit 131 acquires one or more pieces of authentication information corresponding to a user identifier corresponding to the authentication request and a work terminal identifier corresponding to the user identifier from the authentication information storage unit 111. Next, the code acquisition unit 131 acquires, for example, a code corresponding to the one or more pieces of authentication information from the code storage unit 112. Note that the code acquisition unit 131 may generate a code in which the one or more pieces of authentication information are embedded. In addition, the code acquisition unit 131 may temporarily store the acquired code in the code storage unit 112 in association with a user identifier corresponding to the authentication request, a user terminal identifier corresponding to the user identifier, and a work terminal identifier corresponding to the user identifier.

[0056] It is preferable that the code acquisition unit 131 judges whether or not a set of a user identifier corresponding to the authentication request, a user terminal identifier corresponding to the user identifier, and a work terminal identifier corresponding to the user identifier exists in the authentication information storage unit 111, and acquires the code only when it is judged that the set exists. Note that the user identifier corresponding to the authentication request, the user terminal identifier corresponding to the user identifier, and the work terminal identifier corresponding to the user identifier are, for example, the user identifier, user terminal identifier, and work terminal identifier contained in the authentication request.

[0057] When an authentication request without a work terminal identifier is received, the code acquisition unit 131 acquires a code using authentication information that corresponds to a user identifier corresponding to the authentication request and does not correspond to a work terminal identifier. More specifically, the code acquisition unit 131 acquires, for example, one or more pieces of authentication information that correspond to a user identifier corresponding to the authentication request and do not correspond to a work terminal identifier from the authentication information storage unit 111 in response to receiving an authentication request. Next, the code acquisition unit 131 acquires, for example, a code corresponding to each of the one or more pieces of authentication information from the code storage unit 112. Note that the code acquisition unit 131 may generate a code in which the one or more pieces of authentication information are embedded, for example.

[0058] In response to the authentication request, the code acquisition unit 131 may perform authentication processing for logging in to the authentication server 1. Such authentication processing is, for example, processing using a user identifier and a password included in the authentication request, and is a known authentication technique, so detailed description will be omitted.

[0059] The support unit 132 performs a support process. The support process is a process of supporting the work terminal 3 to log in to one or more sites 4 by using the access information received by the access information receiving unit 122. Note that the support process may be any process that supports the work terminal 3 to log in to the site 4, and the details of the process are not important.

[0060] The support unit 132 performs, for example, a first support process, a second support process, or a third support process.

[0061] The support unit 132 performs a first support process of, for example, acquiring one or more pieces of authentication information corresponding to the access information, accessing one or more sites using each of the one or more pieces of authentication information, acquiring a web page after logging in to each of the one or more sites, and transmitting the web page to the work terminal 3.

[0062] The support department 132 performs a second support process of, for example, acquiring one or more pieces of authentication information corresponding to access information, accessing one or more sites, acquiring a web page for logging in to each of the one or more sites, configuring a web page with the authentication information corresponding to the web page input, and transmitting the web page to the work terminal 3.

[0063] The support department 132 performs a third support process of, for example, acquiring one or more pieces of authentication information corresponding to access information and transmitting the one or more pieces of authentication information to the work terminal 3. In the third support process, usually, logging in to the site from the work terminal 3 is performed without passing through the authentication server 1. In the third support process, it is preferable that the support department 132 transmits, for example, link information corresponding to each piece of authentication information together with the one or more pieces of authentication information. The link information is information of a link for accessing the site 4 corresponding to the authentication information, and is, for example, a URL or a URI.

[0064] The time information acquisition unit 133 acquires time information for the code acquired by the code acquisition unit 131. The time information for the code is usually information for specifying the time when the code transmission unit 141 transmits the code, but may also be information for specifying the time when the code acquisition unit 131 acquires the code. The time information is a time or an elapsed time counted by a timer from the time for the code.

[0065] The time information storage unit 134 stores the time information acquired by the time information acquisition unit 133 in association with the user identifier.

[0066] When the time information specified by the time information stored in the time information storage unit 134 has elapsed for a certain time or more or more than a certain time, the prohibition processing unit 135 performs prohibition processing. The prohibition processing is processing for logging out from the site 4 corresponding to the user identifier or processing for not logging in to the site 4 corresponding to the user identifier.

[0067] The transmission unit 14 transmits various types of information. The various types of information are, for example, codes.

[0068] The code transmission unit 141 transmits the code acquired by the code acquisition unit 131 to the user terminal 2.

[0069] In the user storage unit 21 that constitutes the user terminal 2, various types of information are stored. The various types of information are, for example, a user identifier for accessing the authentication server 1 and a password for accessing the authentication server 1.

[0070] The user reception unit 22 receives various instructions and information. The various instructions and information are, for example, an authentication request and a work terminal identifier. The authentication request has, for example, a password. The authentication request has, for example, a user terminal identifier and a work terminal identifier. The authentication request has, for example, a site identifier. The user reception unit 22 reads, for example, a code (e.g., a QR code) displayed on the work terminal 3 and acquires the work terminal identifier.

[0071] The input means for various instructions and information can be anything, such as a touch panel, a keyboard, a mouse, or a menu screen.

[0072] The user processing unit 23 performs various processes. The various processes are, for example, processes of changing the instructions and information received by the user reception unit 22 into instructions and information of a transmission structure. The various processes are, for example, processes of changing the information received by the user reception unit 25 into an output structure. The user processing unit 23 may configure an output code (e.g., a code with authentication information embedded (e.g., a QR code)) using the code (e.g., authentication information) received by the user reception unit 25.

[0073] The user transmission unit 24 transmits various information, instructions, etc. The various information, instructions, etc. are, for example, an authentication request.

[0074] The user reception unit 25 receives various information. The various information is, for example, a code and a work terminal identifier. The user reception unit 25 receives, for example, the work terminal identifier from the work terminal 3. The user reception unit 25 receives, for example, the work terminal identifier from the work terminal 3 by means of short-range wireless communication.

[0075] The user output unit 26 outputs various types of information. The various types of information are, for example, the information received by the terminal reception unit 35 and changed to the structure output by the terminal processing unit 33, and are, for example, codes and various screens. The user output unit 26 displays, for example, a code. The user output unit 26 transmits, for example, a code. When transmitting a code, it is preferable to use short-range wireless communication.

[0076] Here, output includes concepts such as display on a display, projection using a projector, printing by a printer, sound output, transmission to an external device, storage on a recording medium, and delivery of processing results to other processing devices or other programs.

[0077] Various types of information are stored in the work storage unit 31 that constitutes the work terminal 3. The various types of information are, for example, a user identifier for logging in to the site 4 and a password for logging in to the site 4.

[0078] The work reception unit 32 receives various types of instructions and information. The various types of instructions and information are, for example, a code acquisition instruction, a selection instruction, and a login instruction. The code acquisition instruction is an instruction to acquire a code. The code acquisition instruction is, for example, an instruction to read the code output to the user terminal 2. The code acquisition instruction is, for example, an instruction to receive a code from the user terminal 2. The selection instruction is an instruction to select one site 4 from one or two or more sites 4 to be logged in. The login instruction is an instruction to log in to one site 4.

[0079] The input means for various types of instructions and information can be anything, such as a touch panel, a keyboard, a mouse, or a menu screen.

[0080] The selection reception unit 321 receives the selection of one or more selection items from the set of selection items output by the selection item set output unit 361. The selection reception unit 321 receives the selection of one site 4 from two or more sites to be logged in. It can be said that the reception of such a selection is the reception of a selection instruction.

[0081] The work processing unit 33 performs various processes. The various processes are, for example, processes performed by the terminal code acquisition unit 331, the selection item set configuration unit 332, the access information configuration unit 333, and the access unit 334.

[0082] The terminal code acquisition unit 331 acquires a code from the user terminal 2. The terminal code acquisition unit 331 reads, for example, a code (e.g., a two-dimensional code) displayed on the user terminal 2. In such a case, the terminal code acquisition unit 331 includes, for example, a camera. The terminal code acquisition unit 331 receives a code from the user terminal 2, for example.

[0083] The selection item set configuration unit 332 configures a set of selection items that are information corresponding to the code acquired by the terminal code acquisition unit 331 and that have two or more sites 4 as selection items. The set of selection items is a set of selection items. The selection items are, for example, menu items constituting a menu, check boxes, and buttons. The selection items are components of a selectable user interface.

[0084] The access information configuration unit 333 configures access information for the site 4 corresponding to each of one or more selection items for the selection received by the selection reception unit 321.

[0085] The access unit 334 accesses the site 4 corresponding to each access information using one or more pieces of access information configured by the access information configuration unit 333. As a result of the access, it is possible to log in to the site 4. After logging in to the site 4, the user can perform work on the site 4.

[0086] The work transmission unit 34 transmits various information. The various information is, for example, access information.

[0087] The access information transmission unit 341 transmits access information. For example, the access information transmission unit 341 transmits the access information to Site 4. For example, the access information transmission unit 341 transmits the access information to the authentication server 1.

[0088] The work reception unit 35 receives various types of information. The various types of information are, for example, a web page and code.

[0089] The web page reception unit 351 receives a web page. The web page reception unit 351 receives the web page from Site 4. The web page reception unit 351 may also receive the web page from the authentication server 1. The web page is, for example, a web page after logging in to Site 4 or a web page for logging in to Site 4.

[0090] The work output unit 36 outputs various types of information. The various types of information are, for example, a set of selection items and a web page.

[0091] Here, output includes concepts such as display on a display, projection using a projector, printing by a printer, sound output, transmission to an external device, storage in a recording medium, and delivery of a processing result to another processing device or another program.

[0092] The selection item set output unit 361 outputs the selection item set configured by the selection item set configuration unit 332.

[0093] The web page output unit 362 outputs the web page received by the web page reception unit 351.

[0094] The storage unit 11, the authentication information storage unit 111, the code storage unit 112, the user storage unit 21, and the work storage unit 31 are preferably non-volatile recording media, but can also be realized with volatile recording media.

[0095] The process of storing information in the storage unit 11 or the like is not limited. For example, information may be stored in the storage unit 11 or the like via a recording medium, or information transmitted via a communication line or the like may be stored in the storage unit 11 or the like, or information input via an input device may be stored in the storage unit 11 or the like.

[0096] The receiving unit 12, the authentication request receiving unit 121, the access information receiving unit 122, the user receiving unit 25, the work receiving unit 35, and the web page receiving unit 351 are usually realized by wireless or wired communication means, but may also be realized by means of receiving broadcasts.

[0097] The processing unit 13, the code acquisition unit 131, the support unit 132, the time information acquisition unit 133, the time information storage unit 134, the prohibition processing unit 135, the user processing unit 23, the work processing unit 33, the terminal code acquisition unit 331, the selection item set configuration unit 332, the access information configuration unit 333, and the access unit 334 can usually be realized from a processor, a memory, etc. The processing procedures of the processing unit 13 etc. are usually realized by software, and the software is recorded on a recording medium such as a ROM. However, it may also be realized by hardware (dedicated circuit). Note that the processor is a CPU, MPU, GPU, etc., and its type is not limited.

[0098] The transmitting unit 14, the code transmitting unit 141, the user transmitting unit 24, the work transmitting unit 34, and the access information transmitting unit 341 are usually realized by wireless or wired communication means, but may also be realized by broadcast means.

[0099] The user reception unit 22, the work reception unit 32, and the selection reception unit 321 can be realized by a device driver of an input means such as a touch panel or a keyboard, control software of a menu screen, etc.

[0100] The user output unit 26, the work output unit 36, the selection item set output unit 361, and the web page output unit 362 may or may not be considered to include output devices such as displays and speakers. The user output unit 26 and the like can be realized by driver software of the output device or by the driver software of the output device and the output device or the like.

[0101] Next, an operation example of the authentication server 1 constituting the information system A will be described using the flowchart of FIG. 5.

[0102] (Step S501) The authentication request receiving unit 121 determines whether an authentication request has been received. If an authentication request has been received, the process proceeds to step S502, and if no authentication request has been received, the process proceeds to step S510.

[0103] (Step S502) The code acquisition unit 131 acquires user identifiers and the like included in the authentication request. Note that the user identifiers and the like are, for example, a user identifier, a user identifier and a user terminal identifier, a user identifier and a work terminal identifier, or a user identifier, a user terminal identifier, and a work terminal identifier.

[0104] (Step S503) The code acquisition unit 131 determines whether one or more pieces of authentication information corresponding to the user identifiers and the like acquired in step S502 exist in the authentication information storage unit 111. If one or more pieces of authentication information exist, the process proceeds to step S504, and if not, the process proceeds to step S509.

[0105] (Step S504) The code acquisition unit 131 acquires one or two or more codes corresponding to one or more pieces of authentication information corresponding to the user identifiers and the like acquired in step S502. Here, the code acquisition unit 131 may acquire the code corresponding to the user identifiers and the like acquired in step S502 from the code storage unit 112. Further, the code acquisition unit 131 may generate a code using one or more pieces of authentication information corresponding to the user identifiers and the like acquired in step S502.

[0106] (Step S505) The code transmission unit 141 transmits one or more codes acquired in step S504 to the user terminal 2.

[0107] (Step S506) The support unit 132 performs support processing. Examples of the support processing will be described using the flowcharts of FIGS. 6, 7, and 8.

[0108] (Step S507) The time information acquisition unit 133 acquires time information using a clock (not shown) or a timer (not shown).

[0109] (Step S508) The time information storage unit 134 associates the time information acquired in step S507 with the user identifier and stores it at least temporarily. Return to step S501.

[0110] (Step S509) The processing unit 13 composes an error message. The transmission unit 14 transmits the error message. Return to step S501.

[0111] (Step S510) The prohibition processing unit 135 performs prohibition processing. Return to step S501. Examples of the prohibition processing will be described using the flowchart of FIG. 9.

[0112] Note that in the flowchart of FIG. 5, the processing ends due to a power-off or a processing end interrupt.

[0113] Next, a first example of the support processing in step S506 will be described using the flowchart of FIG. 6.

[0114] (Step S601) The support unit 132 determines whether the user's access destination has been determined to be one. If it has been determined to be one, proceed to step S603; if not, proceed to step S602.

[0115] (Step S602) The access information receiving unit 122 determines whether it has received access information from the work terminal 3. If it has received the access information, it proceeds to step S603; if it has not received the access information, it returns to step S602.

[0116] (Step S603) The support unit 132 acquires the site identifier corresponding to the access information. Note that the site identifier corresponding to the access information is, for example, the site identifier included in the access information or the authentication information included in the access information.

[0117] (Step S604) The support unit 132 acquires the authentication information corresponding to the site identifier acquired in step S603. Note that the support unit 132 may acquire the authentication information included in the access information, or may acquire the authentication information corresponding to the site identifier from the authentication information storage unit 111 from the authentication information storage unit 111.

[0118] (Step S605) The support unit 132 uses the authentication information acquired in step S604 to log in to the site 4 identified by the site identifier, and acquires the web page after logging in.

[0119] (Step S606) The support unit 132 transmits the web page acquired in step S605 to the work terminal 3.

[0120] Next, regarding the second example of the support process in step S506, it will be described using the flowchart of FIG. 7. Note that in the flowchart of FIG. 7, the description of the same steps as in the flowchart of FIG. 6 is omitted.

[0121] (Step S701) The support unit 132 accesses the site 4 identified by the site identifier and acquires the login page, which is the page for logging in to the site 4.

[0122] (Step S702) The support unit 132 inputs the authentication information acquired in step S604 into the login page acquired in step S701.

[0123] (Step S703) The support department 132 sends the login page created in step S702 to the work terminal 3.

[0124] Next, regarding the third example of the support process in step S506, it will be described using the flowchart of FIG. 8. In the flowchart of FIG. 8, the description of the same steps as those in the flowchart of FIG. 6 is omitted.

[0125] (Step S801) The support department 132 sends the authentication information obtained in step S604 to the work terminal 3.

[0126] Next, regarding the example of the prohibition process in step S510, it will be described using the flowchart of FIG. 9.

[0127] (Step S901) The prohibition processing unit 135 assigns 1 to the counter i.

[0128] (Step S902) The prohibition processing unit 135 determines whether the i-th time information is stored. Note that the i-th time information is the time information accumulated in step S508.

[0129] (Step S903) The prohibition processing unit 135 obtains the current time information, which is the current time information, from a clock (not shown) or a timer (not shown).

[0130] (Step S904) The prohibition processing unit 135 obtains the elapsed time, which is the difference between the current time information and the i-th time information.

[0131] (Step S905) The prohibition processing unit 135 determines whether the elapsed time obtained in step S904 satisfies the prohibition condition. If the prohibition condition is satisfied, it proceeds to step S906, and if the prohibition condition is not satisfied, it proceeds to step S908.

[0132] (Step S906) The prohibition processing unit 135 performs an operation prohibition process for the user corresponding to the i-th time information. The operation prohibition process is a process that prevents the user from performing operations at the site 4 corresponding to the i-th time information using the work terminal 3. The operation prohibition process is, for example, for the site 4 during login,

[0133] (Step S907) The prohibition processing unit 135 deletes the i-th time information.

[0134] (Step S908) The prohibition processing unit 135 increments the counter i by 1. Return to Step S902.

[0135] Next, an operation example of the user terminal 2 will be described using the flowchart of FIG. 10.

[0136] (Step S1001) The user reception unit 22 determines whether it has received an authentication request from the user. If it has received an authentication request, it proceeds to Step S1002, and if it has not received an authentication request, it returns to Step S1001.

[0137] (Step S1002) The user processing unit 23 configures an authentication request to be transmitted using the authentication request received in Step S1001. The user transmission unit 24 transmits the authentication request to the authentication server 1.

[0138] (Step S1003) The user reception unit 25 determines whether it has received a code from the authentication server 1 in response to the transmission of the authentication request. If it has received a code, it proceeds to Step S1004, and if it has not received a code, it returns to Step S1003.

[0139] (Step S1004) The user processing unit 23 configures a code to be output using the received code. The user output unit 26 outputs the code. Return to Step S1001.

[0140] Note that in the flowchart of FIG. 10, the process ends due to a power-off or a processing end interrupt.

[0141] Next, an operation example of the work terminal 3 will be described using the flowchart of FIG. 11.

[0142] (Step S1101) The work reception unit 32 determines whether or not a code acquisition instruction has been received. If a code acquisition instruction has been received, the process proceeds to step S1102. If a code acquisition instruction has not been received, the process proceeds to step S1110.

[0143] (Step S1102) The terminal code acquisition unit 331 acquires the code output by the user terminal 2.

[0144] (Step S1103) The selection item set configuration unit 332 configures a selection item set using the code acquired in step S1102.

[0145] (Step S1104) The selection item set output unit 361 outputs the selection item set configured in step S1103.

[0146] (Step S1105) The selection reception unit 321 determines whether or not a selection of one item among the items included in the selection item set acquired in step S1104 has been received. If a selection of one item has been received, the process proceeds to step S1106. If a selection of one item has not been received, the process returns to step S1105.

[0147] (Step S1106) The access information configuration unit 333 configures access information corresponding to the selection received in step S1105.

[0148] (Step S1107) The access information transmission unit 341 transmits the access information. The access information is, for example, authentication information for logging in to the site 4 corresponding to the selection, or an ID for specifying the authentication information for logging in to the site 4 corresponding to the selection.

[0149] (Step S1108) The web page receiving unit 351 determines whether a web page has been received in response to the transmission of access information. If a web page has been received, it proceeds to step S1109; if not, it returns to step S1108. Note that the received web page is either the web page after logging in to the site 4 corresponding to the selection or the web page for logging in to the site 4 corresponding to the selection. The web page for logging in to the site 4 corresponding to the selection includes, for example, authentication information.

[0150] (Step S1109) The web page output unit 362 outputs the web page received in step S1108. It returns to step S1101.

[0151] (Step S1110) The work reception unit 32 determines whether an input has been received. If an input has been received, it proceeds to step S1111; if not, it returns to step S1101. Note that the input is, for example, an input to the web page output in step S1109.

[0152] (Step S1111) The work processing unit 33 etc. perform processing according to the input received in step S1110. It returns to step S1101.

[0153] In the flowchart of FIG. 11, the work reception unit 32 may receive a login instruction for logging in to one site 4. In such a case, the access information configuration unit 333 configures access information according to the login instruction, and the access unit 334 uses the access information to log in to one site 4.

[0154] Also, in the flowchart of FIG. 11, the processing ends due to a power-off or an interrupt of the end of processing.

[0155] Hereinafter, a specific operation example of the information system A in the present embodiment will be described.

[0156] Now, assume that the authentication information storage unit 111 of the authentication server 1 stores the authentication information management table shown in FIG. 12. The authentication information management table is a table that manages one or more pieces of authentication information for each user. The authentication information management table manages records having "ID", "user identifier", "user terminal identifier", "work terminal identifier", "site information", "authentication information", and "flag". "Site information" is information regarding the site 4 to which the user logs in, and has "site identifier" and "site URL". "Authentication information" is, here, "ID" and "PW". "ID" is information for identifying a record. "Site identifier" is information for identifying a site, and here, for example, it is the site name. "Site URL" is information for accessing the site 4, and here, it is the URL. "ID" is the ID for logging in to the site 4 (which may be called an account ID), and "PW" is the password for logging in to the site 4. "Flag" is information for specifying whether the site 4 is a site used for work or a site used privately. Flag "1" indicates that the corresponding site 4 is a site used for work. Flag "2" indicates that the corresponding site 4 is a private site.

[0157] Note that the authentication information in the authentication information management table is, for example, information input by the user to the user terminal 2, transmitted from the user terminal 2 to the authentication server 1, and accumulated by the authentication server 1.

[0158] Also, assume that the code storage unit 112 stores the code information management table shown in FIG. 13. The code information management table is a table that manages codes. The code here is, for example, a QR code. The code information management table manages one or more records having "ID", "user identifier", and "code".

[0159] In the "code" of "ID=1" in FIG. 13, authentication information for logging in to each of the three sites 4 of "ID=1" in FIG. 12 is embedded. Also, in the "code" of "ID=1", authentication information for logging in to each of the three sites 4 of "ID=2" in FIG. 12 is embedded. Note that each code in the code information management table is, for example, a code generated by the code acquisition unit 131 using one or more pieces of authentication information corresponding to the authentication information and embedding the one or more pieces of authentication information after the authentication information is accumulated.

[0160] In such a situation, a specific operation example of the information system A will be described with reference to FIG. 14.

[0161] (Specific Example 1) Assume that the user inputs an authentication request "<user identifier> U01" to the user terminal 2. Next, the user reception unit 22 of the user terminal 2 receives the authentication information. The user processing unit 23 uses the received authentication information to construct the authentication information to be transmitted. The user transmission unit 24 transmits the authentication information "<user identifier> U01" to the authentication server 1 (FIG. 14(1)).

[0162] Next, the authentication request reception unit 121 of the authentication server 1 receives the authentication request "<user identifier> U01". Next, the code acquisition unit 131 acquires the user identifier "U01" included in the authentication request. Next, the code acquisition unit 131 acquires the code corresponding to the user identifier "U01" from the code management table in FIG. 13. Next, the code transmission unit 141 transmits the code to the user terminal 2 (FIG. 14(2)).

[0163] Next, the user reception unit 25 of the user terminal 2 receives the code. Next, the user processing unit 23 uses the received code to construct the code to be output. Next, the user output unit 26 outputs the code (1401 in FIG. 14).

[0164] Next, the user inputs a code acquisition instruction to the work terminal 3. Next, the work reception unit 32 of the work terminal 3 receives the code acquisition instruction. Note that the work reception unit 32 receives, for example, a code acquisition instruction which is an instruction to read a code here. Next, the terminal code acquisition unit 331 reads the code 1301 output by the user terminal 2.

[0165] Next, the selection item set configuration unit 332 acquires the information embedded in the read code. Note that such embedded information is, for example, "<site information> <site identifier> EC01 <site URL> URL1 <id>ID11 <pw>PW11 <フラグ>2 < / サイト情報> <サイト情報> <サイト識別子>EC02 <サイトURL>URL2 <id>ID12 <pw>PW12 <flag>2< / サイト情報> <Site Information> <Site Identifier> Library <Site URL> URL3 <id>ID13 <pw>PW13 <flag>2< / サイト情報> <Site Information> <Site Identifier> Integration ID <Site URL> URL4 <id>ID14 <pw>PW14 <フラグ>1 < / サイト情報> <サイト情報> <サイト識別子>RDS <サイトURL>URL5 <id>ID15 <pw>PW15 <flag>1< / サイト情報> "

[0166] Next, the selection item set constructing unit 332 constructs a selection item set using the acquired information. Next, the selection item set output unit 361 outputs the constructed selection item set. An example of such output is shown in FIG.

[0167] In addition, in FIG. 15, the selection item set construction unit 332 constructs a selection item set with the selection items being the site identifier corresponding to "<flag>1" (work)" through "<flag>2" (personal)".

[0168] Next, it is assumed that the user selects the site "EC01" from among the site identifiers output in FIG. 15. Then, the selection receiving unit 321 of the work terminal 3 receives the selection of one item "EC01" from among the items included in the set of selected items. Next, the access information configuration unit 333 generates the access information "<site URL>URL1" corresponding to the received selection. <id>ID11 <pw>PW11". Next, the access information sending unit 341 sends the access information and the work terminal ID to the authentication server 1 (FIG. 14(4)). The work terminal ID is the ID of the work terminal for accessing the work terminal 3, for example, an IP address. Also, "linking of personal computer / smartphone information" in FIG. 14 means that the ID of the work terminal 3 is associated with the ID of the user terminal 2 and sent in association with the ID of the user terminal 2, thereby associating the work terminal 3 with the user terminal 2 in the authentication server 1.

[0169] Next, the access information receiving unit 122 of the authentication server 1 receives the access information “<site URL> URL1 <id>ID11 <pw>Next, the support unit 132 uses the access information to access the site 4 corresponding to "<site URL> URL1" and <id>ID11 <pw>Using “Password “and “PW11” and the work terminal ID, a request for authentication is made to site 4 (Figure 14 (4)).

[0170] Next, Site 4: <id>ID11 <pw>PW11" and the work terminal ID. <id>ID11 <pw>Using "PW11", perform authentication to permit login and obtain the web page after login. Next, Site 4 transmits the web page to the work terminal 3 identified by the work terminal ID (Fig. 14(5)).

[0171] Next, the work terminal 3 receives and outputs the web page. Thereafter, the user can perform various operations on Site 4 corresponding to "<Site URL> URL1" using the work terminal 3.

[0172] (Specific Example 2) In the specific example of this embodiment, assume that instead of Fig. 12, the code information management table shown in Fig. 16 is stored in the code storage unit 112 of the authentication server 1.

[0173] And assume that the user inputs the authentication request "<User Identifier> U01 <User Terminal Identifier> UT11 <Work Terminal Identifier> WT11" to the user terminal 2. Next, the user reception unit 22 of the user terminal 2 receives the authentication information. The user processing unit 23 constructs the authentication information to be transmitted using the received authentication information. The user transmission unit 24 transmits the authentication information to the authentication server 1 (Fig. 14(1)).

[0174] Next, the authentication request reception unit 121 of the authentication server 1 receives the authentication request "<User Identifier> U01 <User Terminal Identifier> UT11 <Work Terminal Identifier> WT11". Next, the code acquisition unit 131 acquires the user identifier "U01", user terminal identifier "UT11", and work terminal identifier "WT11" included in the authentication request. Next, the code acquisition unit 131 acquires the code corresponding to the user identifier, etc. from the code management table in Fig. 16. Next, the code transmission unit 141 transmits the code to the user terminal 2 (Fig. 14(2)).

[0175] Next, the user reception unit 25 of the user terminal 2 receives the code. The user processing unit 23 constructs the code to be output using the received code. Next, the user output unit 26 outputs the code (1401 in Fig. 14).

[0176] Next, the work acceptance unit 32 of the work terminal 3 accepts the code acquisition instruction. For example, the work acceptance unit 32 accepts the code acquisition instruction, which is an instruction to read a code here. The terminal code acquisition unit 331 reads the code output by the user terminal 2.

[0177] Next, the selection item group construction unit 332 acquires the information embedded in the read code. The embedded information may be, for example, "<site information> <site identifier> library <site URL> URL3 <id>ID13 <pw>PW13 <Flag>2

[0178] Next, the selection item set configuration unit 332 determines that the information of site 4 included in the embedded information is the information of one site, and does not configure a selection item set.

[0179] Next, the access information configuration unit 333 sets the access information corresponding to the embedded information as "<Site URL> URL3" <id>ID13 <pw>Obtain "PW13". Next, the access unit 334 accesses the site 4 identified by "URL3" using the access information, " <id>ID13 <pw>Log in to the site 4 using "PW13".

[0180] Thereafter, the user can perform various operations on the site 4 corresponding to "<site URL> URL3" using the work terminal 3.

[0181] As described above, according to this embodiment, it is possible to provide a mechanism that can easily log in to the site while ensuring the security of the authentication information for logging in to the site.

[0182] Also, according to this embodiment, it is possible to provide a mechanism that allows logging in to the site 4 from the work terminal 3 only when a specific user terminal 2 is used.

[0183] Furthermore, according to this embodiment, it is possible to provide a mechanism that allows logging in to the site 4 from the work terminal 3 only when a specific work terminal 3 is used.

[0184] Note that the processing in this embodiment may be implemented by software. And this software may be distributed by software download or the like. Also, this software may be recorded on a recording medium such as a CD-ROM and distributed. Note that this also applies to other embodiments in this specification. The software that realizes the authentication server 1 in this embodiment is a program as follows. That is, this program can access a code storage unit that stores codes for one or more pieces of authentication information that enable logging in to one or more sites, associated with one or more user identifiers, a computer, an authentication request receiving unit that receives an authentication request corresponding to the user identifier from the user terminal, a code acquisition unit that acquires, in response to the reception of the authentication request, the code corresponding to the user identifier from the code storage unit, a code transmission unit that transmits the code acquired by the code acquisition unit to the user terminal, an access information receiving unit that receives, from the work terminal that has received and output the code transmitted by the code transmission unit and acquired the code from the user terminal, access information that is information corresponding to the code and is information for logging in to one or more sites, and a program for causing the work terminal to function as a support unit that performs support processing for logging in to one or more sites using the access information.

[0185] Also, the software that realizes the work terminal 3 in the present embodiment is a program as follows. That is, this program causes a computer to function as a terminal code acquisition unit that acquires a code from a user terminal, a selection item set configuration unit that constitutes a selection item set that is information corresponding to the code acquired by the terminal code acquisition unit and has two or more sites as selection items, a selection item set output unit that outputs the selection item set, a selection reception unit that receives selection of one or more selection items from the selection item set, an access information configuration unit that constitutes access information for sites corresponding to the one or more selection items, and an access information transmission unit that transmits the access information. It is a program for causing the computer to be able to access the site in response to the transmission of the access information.

[0186] Also, FIG. 16 shows the appearance of a computer that executes the program described in this specification and realizes the authentication server 1 and the like in the various embodiments described above. The above-described embodiments can be realized by computer hardware and a computer program executed thereon. FIG. 16 is an overview diagram of this computer system 300, and FIG. 17 is a block diagram of the system 300.

[0187] In FIG. 16, the computer system 300 includes a computer 301 including a CD-ROM drive, a keyboard 302, a mouse 303, and a monitor 304.

[0188] In FIG. 17, in addition to the CD-ROM drive 3012, the computer 301 includes an MPU 3013, a bus 3014 connected to the CD-ROM drive 3012 and the like, a ROM 3015 for storing programs such as a boot-up program, a RAM 3016 connected to the MPU 3013 for temporarily storing instructions of an application program and providing a temporary storage space, and a hard disk 3017 for storing an application program, a system program, and data. Here, although not shown, the computer 301 may further include a network card for providing connection to a LAN.

[0189] A program for causing the computer system 300 to execute functions such as the authentication server in the above-described embodiment may be stored in the CD-ROM 3101, inserted into the CD-ROM drive 3012, and further transferred to the hard disk 3017. Alternatively, the program may be transmitted to the computer 301 via a network (not shown) and stored in the hard disk 3017. The program is loaded into the RAM 3016 during execution. The program may be loaded directly from the CD-ROM 3101 or the network.

[0190] The program does not necessarily include an operating system (OS) or a third-party program that causes the computer 301 to execute functions such as the authentication server in the above-described embodiment. The program only needs to include only the part of the instructions that calls appropriate functions (modules) in a controlled manner so as to obtain a desired result. How the computer system 300 operates is well known, and a detailed description thereof is omitted.

[0191] In the above program, in steps such as the step of transmitting information and the step of receiving information, processing performed by hardware, for example, processing performed by a modem or an interface card in the transmission step (processing that can only be performed by hardware) is not included.

[0192] Also, the computer that executes the above program may be singular or plural. That is, centralized processing may be performed, or distributed processing may be performed.

[0193] Also, in each of the above embodiments, it goes without saying that two or more communication means existing in one device may be physically realized by one medium.

[0194] Also, in each of the above embodiments, each process may be realized by being centrally processed by a single device, or may be realized by being distributedly processed by a plurality of devices.

[0195] Needless to say, the present invention is not limited to the above embodiments, and various modifications are possible, and those are also included in the scope of the present invention.

Industrial Applicability

[0196] As described above, the authentication server according to the present invention has an effect of being able to provide a mechanism that can easily log in to a site while ensuring the security of authentication information for logging in to the site, and is useful as an authentication server or the like.

Explanation of Signs

[0197] A Information system 1 Authentication server 2 User terminal 3 Work terminal 4 Site 11 Storage unit 12 Reception unit 13 Processing unit 14 Transmission unit 21 User storage unit 22 User reception unit 23 User processing unit 24 User transmission unit 25 User reception unit 26 User output unit 31 Work storage unit 32 Work Reception Unit 33 Work Processing Unit 33 Terminal Processing Unit 34 Work Transmission Unit 35 Terminal Reception Unit 35 Work Reception Unit 36 Work Output Unit 111 Authentication Information Storage Unit 112 Code Storage Unit 121 Authentication Request Reception Unit 122 Access Information Reception Unit 131 Code Acquisition Unit 132 Support Unit 133 Time Information Acquisition Unit 134 Time Information Accumulation Unit 135 Prohibition Processing Unit 141 Code Transmission Unit 321 Selection Reception Unit 331 Terminal Code Acquisition Unit 332 Selection Item Set Composition Unit 333 Access Information Composition Unit 334 Access Unit 341 Access Information Transmission Unit 351 Web Page Reception Unit 361 Selection Item Set Output Unit 362 Web Page Output Unit< / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id> < / pw> < / id>

Claims

1. A code storage unit that stores codes for one or more pieces of authentication information that enable login to one or more sites, associated with each user identifier of 1 or more; An authentication request receiving unit that receives an authentication request corresponding to a user identifier from a user terminal; A code acquisition unit that, in response to the reception of the authentication request, acquires a code corresponding to the user identifier from the code storage unit for the user identifier corresponding to the authentication request; A code transmission unit that transmits the code acquired by the code acquisition unit to the user terminal; An access information receiving unit that receives, from a work terminal that has received and output the code transmitted by the code transmission unit and acquired the code from the user terminal, access information that is information corresponding to the code and is information for logging in to one or more sites; An authentication server comprising: a support unit that performs support processing for the work terminal to log in to one or more sites using the access information.

2. The support unit: Acquires one or more pieces of authentication information corresponding to the access information, accesses one or more sites using the one or more pieces of authentication information, acquires a web page after logging in to the one or more sites, and performs a first support process of transmitting the web page to the work terminal, or acquires one or more pieces of authentication information corresponding to the access information, accesses one or more sites, acquires a web page for logging in to the one or more sites, constructs a web page in which authentication information corresponding to the web page is input, and performs a second support process of transmitting the web page to the work terminal, or acquires one or more pieces of authentication information corresponding to the access information and performs a third support process of transmitting it to the work terminal. The authentication server according to Claim 1.

3. The authentication information is also associated with a user terminal identifier that identifies a user terminal, The authentication request includes a user identifier and a user terminal identifier, The code acquisition unit: In response to the reception of the authentication request, acquires a code that enables login to one or more sites that can be logged in using the user identifier corresponding to the user identifier and one or more pieces of authentication information corresponding to the user terminal identifier. The authentication server according to Claim 1 or Claim 2.

4. The authentication information is also associated with a work terminal identifier that identifies a work terminal, The authentication request includes a user identifier and a work terminal identifier, The code acquisition unit: Upon receiving the authentication request, obtain code that enables login to one or more sites where login is possible using the user identifier corresponding to the user identifier and one or more pieces of authentication information corresponding to the work terminal identifier. The authentication server according to any one of claims 1 to 3.

5. Associated with one user identifier, some of the authentication information is associated with the work terminal identifier, while other authentication information is not associated with the work terminal identifier. The authentication request may or may not have a work terminal identifier. The code acquisition unit When the authentication request without the work terminal identifier is received, obtain code that enables login to the two or more sites that can be logged in using the authentication information corresponding to the user identifier corresponding to the user identifier and not associated with the work terminal identifier. The authentication server according to claim 4.

6. A time information acquisition unit that acquires time information for the code acquired by the code acquisition unit, A time information storage unit that stores the time information in association with the user identifier, When a time equal to or more than a certain time has elapsed since the time specified by the time information, further comprising a prohibition processing unit that performs a prohibition process that is a process for logging out or a process for not logging in to the site corresponding to the user identifier. The authentication server according to any one of claims 1 to 5.

7. A terminal code acquisition unit that acquires code from the user terminal, A selection item set configuration unit that configures a selection item set that is information corresponding to the code acquired by the terminal code acquisition unit and has two or more sites as selection items, A selection item set output unit that outputs the selection item set, A selection reception unit that receives selection of one or more selection items from the selection item set, An access information configuration unit that configures access information for the sites corresponding to the one or more selection items, An access information transmission unit that transmits the access information to the authentication server according to any one of claims 1 to 6, A work terminal that can access the site in response to the transmission of the access information.

8. A code storage unit that stores codes for one or more pieces of authentication information that enable login to one or more sites, associated with each user identifier of 1 or more, an authentication request reception unit, a code acquisition unit, a code transmission unit, an access information reception unit, and a support unit, and an information processing method realized by: An authentication request reception step in which the authentication request reception unit receives an authentication request corresponding to a user identifier from a user terminal; A code acquisition step in which the code acquisition unit acquires, from the code storage unit, a code corresponding to the user identifier corresponding to the authentication request in response to the reception of the authentication request; A code transmission step in which the code transmission unit transmits the code acquired in the code acquisition step to the user terminal; An access information reception step in which the access information reception unit receives, from a work terminal that has received and output the code transmitted in the code transmission step and acquired the code from the user terminal, access information that is information corresponding to the code and is information for logging in to one or more sites; An information processing method including a support step in which the support unit performs support processing for the work terminal to log in to one or more sites using the access information.

9. An information processing method realized by a terminal code acquisition unit, a selection item set configuration unit, a selection item set output unit, a selection reception unit, an access information configuration unit, and an access information transmission unit, comprising: A terminal code acquisition step in which the terminal code acquisition unit acquires a code from a user terminal; A selection item set configuration step in which the selection item set configuration unit configures a selection item set having, as selection items, two or more sites, which is information corresponding to the code acquired in the terminal code acquisition step; A selection item set output step in which the selection item set output unit outputs the selection item set; A selection reception step in which the selection reception unit receives selection of one or more selection items from among the selection item set; An access information configuration step in which the access information configuration unit configures access information for sites corresponding to the one or more selection items; An access information transmission step in which the access information transmission unit transmits the access information to the authentication server according to any one of Claims 1 to 6, and An information processing method that enables access to the site in response to the transmission of the access information.

10. A computer that can access a code storage unit storing codes for one or more pieces of authentication information that enable logging in to one or more sites, associated with each user identifier of 1 or more, An authentication request receiving unit that receives an authentication request corresponding to a user identifier from a user terminal, A code acquisition unit that, in response to the reception of the authentication request, acquires from the code storage unit the code corresponding to the user identifier corresponding to the authentication request, A code transmission unit that transmits the code acquired by the code acquisition unit to the user terminal, An access information receiving unit that receives, from a work terminal that has received and output the code transmitted by the code transmission unit and acquired the code from the user terminal, access information that is information corresponding to the code and is information for logging in to one or more sites, A program for causing the support unit to function as a support unit that performs support processing for the work terminal to log in to one or more sites using the access information.

11. A computer, A terminal code acquisition unit that acquires a code from a user terminal, A selection item set configuration unit that configures a selection item set that is information corresponding to the code acquired by the terminal code acquisition unit and that constitutes a set of selection items having two or more sites as selection items, A selection item set output unit that outputs the selection item set, A selection reception unit that receives selection of one or more selection items from among the selection item set, An access information configuration unit that configures access information for sites corresponding to the one or more selection items, A program for causing the computer to function as an access information transmission unit that transmits the access information to the authentication server according to any one of Claims 1 to 6, A program that enables the computer to access the site in response to the transmission of the access information.

Citation Information

Patent Citations

  • Server, controller, and program thereof

    JP2007306100A

  • Authentication system and authentication method

    JP2010238090A

  • Service provision system

    JP2012080235A

  • Information processing system and device control method

    JP2016081523A

  • Access management device, access management method and access management program

    JP2017182781A