Service providing apparatus, authentication method, and program

The service providing apparatus addresses the security and convenience issues in conventional user authentication by using telephone number verification and valid call timing confirmation, enhancing the overall authentication process.

JP7691553B1Active Publication Date: 2025-06-11PAYPAY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024096737
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-06-11
Estimated Expiration
2044-06-14

AI Technical Summary

Technical Problem

Conventional user authentication methods, especially when the terminal device is not registered, are prone to security risks such as phishing and require manual input of authentication codes, making the process inconvenient and operationally cumbersome.

Method used

A service providing apparatus that collaborates with a user application to manage user accounts linked to telephone numbers, utilizing an authentication process that involves notifying the user application with a first telephone number, recognizing a second telephone number from a call to the first number, and authenticating the user based on the matching telephone numbers and valid call timing.

Benefits of technology

This solution enhances the convenience of user authentication by reducing the need for manual input and improving security by leveraging telephone number verification and valid call timing confirmation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691553000001_ABST
    Figure 0007691553000001_ABST
Patent Text Reader

Abstract

In a system where a user's account is managed linked to a phone number, to improve the convenience of user authentication. 【Solution means】A service providing device that provides a predetermined service to a user in cooperation with a user application operating on the user's terminal device, manages the user's account information linked to the user's phone number, executes an authentication process for authenticating a service user, and in the authentication process, when receiving an authentication request from the user application, notifies the user application of a first phone number that is the phone number of this device, when receiving an incoming call to the first phone number, recognizes a second phone number that is the phone number of the caller, obtains time information regarding the call from the user application after disconnection, and authenticates the user of the user application when the second phone number matches the first phone number and the validity of the timing related to the call is confirmed based on the time information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a service providing apparatus, an authentication method, and a program.

Background Art

[0002] Conventionally, in authenticating a user who logs in to a service, in addition to the specified authentication means, it is confirmed whether the terminal device of the login request source is a registered terminal device. If the terminal device of the login request source is not a registered terminal device, additional authentication using a QR code (registered trademark, the same applies hereinafter) or SMS (Short Message Service) may be performed (see, for example, Patent Documents 1 and 2).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the conventional technology, when the terminal device of the login request source is not a registered terminal device, in some cases, identity verification is performed by issuing an authentication code (hereinafter referred to as an authentication code) to the user and having the user reply it. However, in this case, there is a possibility that the legitimate user's account may be misused by a third party who has illegally obtained the authentication code by means such as phishing. Also, in this case, information such as the notified authentication code, ID, and password has to be manually input into a predetermined application, which may be troublesome. As described above, in the conventional technology, further improvement in convenience has been demanded from the viewpoints of security and operability.

[0005] The present invention has been made in consideration of such circumstances, and in a system in which a user's account is managed linked to a telephone number, one of the objectives is to provide a service providing apparatus, an authentication method, and a program that can improve the convenience of user authentication.

Means for Solving the Problems

[0006] One aspect of the present invention is a service providing apparatus that collaborates with a user application operating on a user's terminal device to provide a predetermined service to the user, the service providing apparatus including: a management unit that manages the user's account information linked to the user's telephone number; and an authentication processing unit that executes an authentication process for authenticating a user of the service. The authentication process, when receiving an authentication request from the user application, notifies the user application of a first telephone number that is the telephone number of the own apparatus, recognizes a second telephone number that is the telephone number of the caller of the call to the first telephone number when receiving a call to the first telephone number after the notification of the first telephone number, acquires time information regarding the call from the user application after the call is disconnected, and authenticates the user of the user application when the second telephone number matches the first telephone number and the validity of the timing of the call is confirmed based on the time information.

Effects of the Invention

[0007] According to one aspect of the present invention, it is possible to provide a service providing apparatus, an authentication method, and a program that can improve the convenience of user authentication in a system in which a user's account is managed linked to a telephone number.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Embodiments for Carrying Out the Invention

[0009] Hereinafter, with reference to the drawings, embodiments of the service providing apparatus, authentication method, and program of the present invention will be described. Various apparatuses such as "servers", "management apparatuses", and "information providing apparatuses" that provide services to users or perform internal analysis may be realized by a decentralized group of apparatuses, and the operators of each apparatus may be different. Also, the holder of the hardware of the apparatus (provider of the cloud server) and the operator who actually operates may be different. The application program and the payment server cooperate to provide an electronic payment service. In the following description, the application program is referred to as a payment application. The electronic payment service is a service that supports payment for the purchase of goods and services in a store. The store is, for example, a physical store (actual store) existing in the real space, but may include a virtual store for e-commerce. The virtual store may include those provided by a party different from the operator of the electronic payment service. In that case, at the time of payment for shopping in the virtual store, it is controlled to transition to the interface screen of the electronic payment service. In the electronic payment service, the store is, for example, treated as belonging to a franchise (brand), and processing such as payment when a purchase action is performed in the store is mainly performed between the user and the franchise. Instead of this, processing such as payment may be performed between the user and the store.

[0010] [Electronic Payment Service] FIG. 1 is a diagram showing an example of a configuration for realizing an electronic payment service. The electronic payment service is realized centering around a payment server 100. The payment server 100 communicates with, for example, each of one or more user terminal devices 10, one or more first store terminal devices 50, and one or more second store terminal devices 70 via a network NW. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, and the like.

[0011] The user terminal device 10 is, for example, a portable terminal device such as a smartphone or a tablet terminal. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input reception function, and a program execution function. In the following description, the configurations for realizing these functions are respectively referred to as a camera, a communication device, a touch panel, a CPU (Central Processing Unit), and the like. In the user terminal device 10, the settlement application 20 is executed by a processor such as a CPU, and thus operates to provide an electronic payment service to the user in cooperation with the payment server 100. The settlement application 20 is installed in the user terminal device 10 from, for example, an application store, and controls a camera, a communication device, a touch panel, and the like. The input reception function may include a function of acquiring information necessary for biometric authentication such as fingerprint authentication and iris authentication.

[0012] The first store terminal device 50 is installed, for example, in a store. The first store terminal device 50 is a computer device having at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The first store terminal device 50 includes a so-called POS (Point of Sale) device, and the product price acquisition function and the optical reading function may be realized by the POS device. The store code image 60 is placed in the store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. Note that the store code image 60 may be displayed by a display placed in the store (which may be a display of a terminal device such as a smartphone).

[0013] The second store terminal device 70 is used by the operator of the franchise store. The second store terminal device 70 is a smartphone, a tablet terminal, a personal computer, or the like. In the second store terminal device 70, an interface 72 for the franchise store operates. The interface 72 for the franchise store may be an application for the franchise store or a browser. The interface 72 for the franchise store accepts settings of coupons, etc. by the operator of the franchise store and transmits them to the payment server 100. The second store terminal device 70 which is a smartphone has functions of displaying a code image corresponding to the store code image or reading the code image displayed by the user terminal device 10 by executing the application for the franchise store.

[0014] The payment server 100 realizes electronic payment based on the payment information received from the user terminal device 10 or the first store terminal device 50. The first store terminal device 50 may include a POS device and a franchise store server. In that case, the payment information is transmitted from the POS device to the payment server 100 via the franchise store server. In the following description, without particularly distinguishing this, it is assumed that the payment information is transmitted from the first store terminal device 50.

[0015] FIG. 2 and FIG. 3 are sequence diagrams illustrating a rough flow of electronic payment. There may be two patterns, pattern 1 and pattern 2, in the electronic payment.

[0016] In the case of pattern 1 shown in FIG. 2 (hereinafter referred to as user scan), the user terminal device 10 in the state where the settlement application 20 is started decodes the store code image 60 by means of an optical reading function (S1). The store code image 60 includes information on the store URL (Uniform Resource Locator). This store URL is obtained by adding information capable of identifying the store to the domain of the electronic payment service, and is associated with the franchise store ID, store ID, etc. in the payment server 100 (described later). The settlement application 20 transmits first settlement information including the store URL and the account ID to the settlement server 100 (S2). The settlement server 100 searches for store information (described later) from the franchise store ID and store ID corresponding to the store URL, acquires information on the franchise store name and store name (S3), and transmits it to the settlement application 20 (S4). The user inputs the settlement amount into the user terminal device 10 on the screen where the franchise store name and store name are displayed (S5). Then, the user terminal device 10 generates second settlement information including at least the settlement amount and transmits it to the settlement server 100 (S6). The settlement server 100 performs an electronic settlement based on the received second settlement information (S7). Then, the settlement server 100 transmits a settlement completion notice (information for displaying a settlement completion screen) to the settlement application 20 (S8), and the settlement application 20 displays a settlement completion screen (S9). When the store code image 60 is displayed by a display placed in the store, the store code image 60 may include not only the store URL but also information on the settlement amount. In this case, the procedure for the user to input the settlement amount is omitted, and the information on the settlement amount is included in the first settlement information and transmitted to the settlement server 100. Information on the franchise store name and store name may be included and displayed on the settlement completion screen.

[0017] In the case of pattern 2 shown in FIG. 3 (hereinafter referred to as store scan), when the payment application 20 is launched, when a payment operation is performed in the payment application 20, when it reaches the automatic update timing (for example, every minute), and at other timings, the payment application 20 sends a request for issuing a one-time code to the payment server 100 (S11). The payment server 100 generates a one-time code (S12) and sends it to the payment application 20 (S13). The payment application 20 displays a code image such as a QR code or a barcode generated based on the one-time code (S14). The user shields (presents) the display surface of the user terminal device 10 against the first store terminal device 50. The first store terminal device 50 decodes the code image by means of an optical reading function and acquires a one-time code or the like (S15). Then, the first store terminal device 50 generates payment information including the one-time code, the payment amount, the franchise ID, the store ID, etc., and sends it to the payment server 100 (S16). The information on the payment amount has been acquired in advance by barcode reading, manual input, or the like. The payment server 100 identifies the user corresponding to the one-time code based on the received information and performs an electronic payment (S17). Then, the payment server 100 sends a payment completion notification to the payment application 20 (S18), and the payment application 20 displays a payment completion screen (S19).

[0018] Note that the electronic payment may be performed in only one of the above patterns. Also, the "account ID" described in FIG. 2 may be other information (for example, a telephone number) that can be used as the identification information of the user. Further, in the store scan, the issuance of the one-time code may be omitted, and the payment application 20 may display a code image generated based on the user's account ID. In that case, instead of identifying the user corresponding to the one-time code, the payment server 100 identifies the user corresponding to the account ID.

[0019] [Payment Server] FIG. 4 is a configuration diagram of the settlement server 100 according to the first embodiment. The settlement server 100 includes, for example, a communication unit 110, a content providing unit 120, a settlement processing unit 130, an information management unit 140, a user authentication unit 150, and a storage unit 170. Components other than the communication unit 110 and the storage unit 170 are realized, for example, by a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including a circuit unit; circuitry) such as LSI (Large Scale Integration), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), or GPU (Graphics Processing Unit), or may be realized by cooperation between software and hardware. The program may be stored in advance in a storage device (a storage device having a non-transitory storage medium) such as an HDD (Hard Disk Drive) or a flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or a CD-ROM, and may be installed in the storage device by mounting the storage medium on a drive device.

[0020] The storage unit 170 is an HDD, a flash memory, a RAM (Random Access Memory), or the like. The storage unit 170 may be a NAS (Network Attached Storage) device accessible by the settlement server 100 via a network. Information such as user information 172, content information 174, and franchise / store information 176 is stored in the storage unit 170.

[0021] The communication unit 110 is a communication interface for connecting to the network NW. The communication unit 110 is, for example, a network interface card.

[0022] The content providing unit 120 has, for example, the function of a web server and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The content providing unit 120 appropriately reads necessary content from the content information 174 and provides it to the user terminal device 10. The user terminal device 10 accepts various inputs by the user in a state where the content is reproduced by the payment application 20, and transmits the above-described payment information and the like to the payment server 100.

[0023] The payment processing unit 130 performs payment processing based on the payment information transmitted by the user terminal device 10 or the first store terminal device 50. The payment processing unit 130 performs payment processing while referring to the user information 172.

[0024] FIG. 5 is a diagram showing an example of the content of the user information 172. The user information 172 is an example of the user's registration information. The user information 172 includes, for example, a user URL, an account ID, a telephone number, a password, as well as an email address, a user ID, name, address, date of birth, registration date, remaining recharge amount, credit payment setting, credit payment limit, credit payment usage amount, available credit payment amount, payment method setting, bank account, credit card number, recharge history information, payment history information, login authentication setting, and other information that are associated. The user URL is used for money transfer processing between users. When newly registering for the electronic payment service, registration of a telephone number and a password is required. The account ID is issued to the user by the payment server 100, and the user ID is an ID that the user can optionally set (it is not necessary to set it). Similarly, the email address, and the name, address, and date of birth are also information that the user can optionally set (it is not necessary to set it). The registration date is the date when the user registered for the electronic payment service (the date when the account was created). Hereinafter, an instance of the user (electronic payment account) in which these pieces of information are associated is referred to as an account.

[0025] The remaining charge amount is information indicating the remaining amount of electronic money set by the user making a remittance to the account in advance. As means of remittance, there are remittances from the ATM (Automatic Teller Machine) of a designated operator (bank), remittances from a registered bank account, etc. The credit payment setting is information indicating whether the setting for enabling electronic settlement by credit payment has been completed or not, and is set to either "completed" or "not completed". The credit payment limit is the limit amount of credit payment available per month, the credit payment used amount is the amount of credit payment already used in the current month, and the available credit payment amount is the amount of credit payment available in the current month obtained by subtracting the credit payment used amount from the credit payment limit. Although only one credit payment limit is shown in the figure, in reality, there are further upper limits per day, etc., and the lower of them may be set as the credit payment limit. Further details of credit payment will be described later. The settlement method setting is setting information indicating whether the user conducts an electronic settlement using the remaining charge amount or a settlement by credit payment at that time. Each of the bank account and credit card number is information (account number, card number) of a bank account or credit card number that can receive deposits for the electronic settlement service. The charge history information is the history of the user increasing the remaining charge amount by making a remittance to the electronic settlement service in advance. The settlement history information is information showing the breakdown of the settlements made by the user (date and time, store ID of the store where the purchase action was taken, settlement amount, settlement method, etc.) for each settlement. The login authentication setting is the setting information of the authentication method registered as the first authentication method described later.

[0026] Figure 6 is a diagram showing an example of the content of the affiliated store / store information 176. The affiliated store / store information 176 includes, for example, a first table 176A in which an affiliated store ID and a store ID are associated with the store URL, a second table 176B in which an affiliated store name and sales amount (described above) are associated with the affiliated store ID, and a third table 176C in which a store name is associated with the store ID. In addition to these information, the affiliated store / store information 176 may include information such as the category of the affiliated store or store, the location of the store, and the settlement pattern.

[0027] Based on the information acquired from the user terminal device 10 and the second store terminal device 70, the information management unit 140 manages the user information 172 and the affiliated store / store information 176. The information management unit 140 adds, edits, deletes, etc. new records for the user information 172 and the affiliated store / store information 176.

[0028] The user authentication unit 150 performs authentication processing for users logging in to the electronic payment service. Specifically, the user authentication unit 150 processes the login request of the user received from the user terminal device 10 in the payment server 100. More specifically, the user authentication unit 150 basically performs user authentication in a method that does not require the user to input text information such as a password or an authentication code. Hereinafter, user authentication by such a method is referred to as "passwordless authentication". By such passwordless authentication, the user can complete the login in a minimum of two operations after displaying the login screen of the payment application 20. The user authentication unit 150 is an example of an "authentication processing unit".

[0029] [Electronic Payment] When the payment processing unit 130 acquires payment information from the user terminal device 10 or the first store terminal device 50, it refers to the user information 172 to acquire the "payment method setting" of the user. For users whose "payment method setting" is set to "charge balance", the payment processing unit 130 performs electronic payment as follows. For example, the payment processing unit 130 performs electronic payment by reducing the charge balance managed in association with the user ID and increasing the item value of the sales amount of the affiliated store. The item value of the sales amount of the affiliated store is not, for example, used as electronic money itself, and the amount corresponding to the item value of the sales amount is transferred to the bank account in a cycle according to the agreement between the affiliated store and the electronic payment service.

[0030] The settlement processing unit 130 performs electronic settlement as follows for users whose "setting information" is set to "credit payment". Credit payment is a payment method through cooperation with a credit card company, which is a separate entity from the operator of the electronic payment service. The operator of the electronic payment service acts as the creditor and allows electronic settlement that does not depend on the remaining recharge amount within the credit payment limit. In addition, in order to receive the credit payment service, it may be required to obtain a credit card provided by the operator of the electronic payment service. The amount used for credit payment is settled collectively for one month on the payment date of the following month, for example, by debit from a bank account. In this case, the settlement processing unit 130 performs provisional settlement by adding the settlement amount to the credit payment usage amount and subtracting the same amount from the available credit payment amount, and at the closing date, performs processing to debit the settlement for the current month on the payment date of the following month as described above, or requests the operator of the credit card company to perform such processing. If the settlement amount exceeds the available credit payment amount at the time of provisional settlement, an error notification is returned to the settlement application 20.

[0031] [Passwordless Authentication] Conventionally, there was also a survey result that in one login process, users had to perform an average of more than 30 input operations, such as entering a password or an authentication code. To such an extent, the conventional authentication method imposed a heavy operation load on users. In contrast, in this embodiment, with the above-described passwordless authentication, it is possible to complete user authentication with a minimum of two operations from the login screen. Whether the minimum number of operations is two or not may vary depending on the specifications of the user terminal device 10 (especially the specifications of the operating system), etc., but the difference in the number of operations that occurs is at most one or two times, and compared with the conventional about 30 times, the number of operations is significantly reduced without fail.

[0032] FIG. 7 and FIG. 8 are diagrams showing an example of screen transition in passwordless authentication. In the example of FIG. 7, it shows the state where the authentication method selection screen D10, the sign-in screen D20, and the top screen D30 transition in this order. The authentication method selection screen D10 is a screen for allowing the user to select an authentication method when logging in to the payment app 20. The authentication method selection screen D10 has, for example, a first authentication method selection section D11, a second authentication method selection section D12, and a third authentication method selection section D13. The first authentication method selection section D11, the second authentication method selection section D12, and the third authentication method selection section D13 are user interfaces such as buttons and links, for example. Here, the payment app 20 is an example of a "user app".

[0033] The first authentication method selection unit D11 receives a selection operation for the first authentication method. The second authentication method selection unit D12 receives a selection operation for the second authentication method. The second authentication method is, for example, an authentication method using a phone number. The third authentication method selection unit D13 receives a selection operation for the third authentication method. The third authentication method is, for example, an authentication method using a medium for personal identification (e.g., the My Number Card in Japan) issued by the country or administrative agency to which the user belongs. The "ccc card" in FIG. 7 is an example of a medium for personal identification. FIG. 7 shows a situation where the authentication method selection screen D10 has transitioned to the sign-in screen D20 due to the operation of the first authentication method selection unit D11. The sign-in screen D20 is a screen that receives an operation for the user to sign in to the first type of web service. FIG. 7 is an example configured such that the sign-in screen D20 is overlaid on the authentication method selection screen D10. For example, the sign-in screen D20 includes a display unit D21 that displays confirmation items for the user regarding signing in to the first type of web service, and an operation unit D22 that receives an operation for the user to instruct the execution of signing in. When the user operates the operation unit D22, an authentication process by the first type of web service is performed, and when the authentication is successful, the screen of the payment application 20 transitions to the top screen D30. The top screen D30 is the screen first displayed after logging in to the payment application 20. For example, various operation menus related to the electronic payment service may be displayed on the top screen D30.

[0034] More specifically, the first authentication method is a method of authenticating a login to the electronic payment service using the authentication function of a certain web service when the user has an account of the certain web service. Here, the certain web service refers to a type of web service that can be recognized by the payment server 100 communicating with the payment application 20 as having an account of the user. Hereinafter, such a type of web service will be referred to as the "first type of web service", and other web services will be referred to as the "second type of web service" to distinguish between the two.

[0035] Generally, since an application operating on a terminal device is created in a format corresponding to the OS of the operating environment, the application contains information about the OS of the operating environment inside it. Therefore, by communicating with the settlement application 20, the settlement server 100 can recognize the OS type of the user terminal device 10 on which the settlement application 20 is operating. Therefore, when the account of the first type of web service is linked to the OS of the user terminal device 10, the settlement server 100 can recognize that the user of the settlement application 20 has an account of the first type of web service by recognizing the OS type of the user terminal device 10 on which the settlement application 20 to be communicated operates. As an example of the OS linked to such a first type of web service, Android (registered trademark) provided by Google (registered trademark) and iOS provided by Apple (registered trademark) can be mentioned. For example, when the OS of the user terminal device 10 is Android (registered trademark), the settlement server 100 can recognize that the user has an account of the web service provided by Google (registered trademark) by communicating with the settlement application 20. Similarly, when the OS of the user terminal device 10 is iOS (registered trademark), the settlement server 100 can recognize that the user has an account of the web service provided by Apple (registered trademark) by communicating with the settlement application 20. The settlement server 100 causes the authentication method corresponding to the first type of web service recognized in this way to be displayed on the authentication method selection screen D10 as the first authentication method. "aaa-ID" described in FIG. 7 is an example illustration of the first type of web service.

[0036] In addition, for the first type of web service, the user's account is linked to the OS (Operating System) of the user terminal device 10 used by the user. Also, the first type of web service manages the login state in combination with the user and the user terminal device 10, and when the login state to its own service is maintained for the user who is the authentication requester, it authenticates the user without requiring a password. On the other hand, the user terminal device 10 is used in a state where the user has logged in to the first type of web service with the account linked to the OS. Therefore, according to the first authentication method, the user can log in to the payment application 20 without entering a password.

[0037] For example, in the second authentication method, the input of a phone number and a password is required, whereas in the first authentication method, the login can be completed by two operations, namely the operation of the first authentication method selection unit D11 and the operation of the operation unit D22. Also, the confirmation items regarding signing in to the first type of web service only need to be confirmed at least at the first time of using the first authentication method, and may be omitted at the time of subsequent use. Therefore, according to the first authentication method, at the shortest, the login can be completed by only one operation of the operation of the first authentication method selection unit D11. Since the total number of characters of the phone number and the password is considered to be about 30 characters statistically, the first authentication method can significantly reduce the input operation load of the user in the authentication at the time of login.

[0038] FIG. 8 is an example of a screen transition when implementing a first authentication method by combining authentication using a first type of web service and biometric authentication. FIG. 8 is an example when biometric authentication is applied to the confirmation operation of the sign-in screen D20. In FIG. 8, the same reference numerals as those in FIG. 7 are given to the same user interface as in FIG. 7. Here, fingerprint authentication is used as biometric authentication, but it may be replaced with other biometric authentication such as voiceprint authentication or iris authentication. In the case of the example of FIG. 8, compared with the case of the example of FIG. 7, the number of operations increases by at most one operation, and similar to the case of the example of FIG. 7, the input operation load at the time of login can be significantly reduced compared to other authentication methods. The "bbb-ID" described in FIG. 8 is an example of a first type of web service different from the example of FIG. 7.

[0039] Conventionally, although presenting the authentication function by web services such as SNS (Social Networking Service) as an option for the authentication method when logging in to other systems or services has been done, conventionally, any web service has been presented as an option regardless of whether it is a first type of web service or a second type of web service. Since the second type of web service is not linked to the OS of the user terminal device 10, the user is required to input authentication information at the time of authentication. On the other hand, in the present embodiment, the OS type of the user terminal device 10 is recognized on the side of the payment server 100, and when the OS type is linked to the first type of web service, the first type of web service is presented as an option for the authentication method instead of the second type of web service. Therefore, when the first type of web service is selected, the user is not required to input authentication information, so login with fewer operations than before becomes possible. For example, in the example of FIG. 7, the user can complete the login with a minimum of two operations: the operation of the first authentication method selection section D11 on the authentication method selection screen D10 and the operation of the operation section D22 on the next sign-in screen D20.

[0040] FIG. 9 is a diagram showing an example of the processing flow when the settlement server 100 authenticates a user by passwordless authentication when logging in to the electronic payment service. Here, it is assumed that at the start of a series of processes, the payment application 20 is not started on the user terminal device 10 and the user is not logged in to the electronic payment service. First, the user operates the user terminal device 10 to start the payment application 20 (S101). The payment application 20 requests content information for displaying the authentication method selection screen D10 to the settlement server 100 at startup (S102). In response to this request, the settlement server 100 returns the content information of the authentication method selection screen D10 to the payment application 20 (S103). The payment application 20 displays the authentication method selection screen D10 using the content information provided by the settlement server 100 and accepts a selection operation of the authentication method for the authentication method selection screen D10 (S104). The payment application 20 notifies the settlement server 100 of the selection result of the authentication method (S105).

[0041] Here, the case where the authentication method using the first type of web service is selected will be described. When receiving the notification in S105, the payment server 100 recognizes that the user has selected the authentication method using the first type of web service as the authentication method when logging in to the electronic payment service (S106), and causes the payment app 20 to display the sign-in screen D20 of the first type of web service (S107). Here, part or all of the content information for displaying the sign-in screen D20 may be included in the content information 174, or may be obtained from the system of the first type of web service. The payment app 20 accepts the user's operation (authentication execution) on the sign-in screen D20 (S108), and notifies the system of the first type of web service to that effect (S109). Subsequently, when the first type of web service authenticates the user (S110), it notifies the payment app 20 to that effect (S111), and the payment app 20 notifies the payment server 100 that the authentication using the first type of web service has been successful (S112). When receiving this notification, the payment server 100 transmits the content information for causing the payment app 20 to display the top screen D30 (S113), and when the top screen D30 is displayed on the payment app 20 (S114), the user's login to the electronic payment service is completed.

[0042] The processing flow described in FIG. 9 assumed a situation where the first type of web service was registered in advance in the electronic payment service as the user's authentication method. However, if the user terminal device 10 used by the user is changed due to reasons such as a model change, since the new user terminal device 10 is not registered in the electronic payment service, regardless of whether the above-mentioned use registration of passwordless authentication (registering the first type of web service as the passwordless authentication method) has been implemented, the payment server 100 requests the user to perform a model change procedure for changing the registration of the previous user terminal device 10 to the new user terminal device 10. After the user completes the model change procedure, it becomes possible to use the payment app 20 on the new user terminal device 10. In the following description, for simplicity, the previous user terminal device 10 is referred to as the old terminal 10, and the changed user terminal device 10 is referred to as the new terminal 10.

[0043] Note that whether the user terminal device 10 has been changed can be identified by the settlement server 100 managing the device ID of the settlement application 20 in association with the user. More specifically, the settlement server 100 acquires the device ID of the settlement application 20 from the settlement application 20 at the access source, and can detect that the user terminal device 10 has been changed when the acquired device ID does not match the device ID previously associated with the user. Such an authentication method based on the consistency of the device ID is used as a means to authenticate the user terminal device 10 at the access source and the user, either by itself or in combination with other authentication methods. Such an authentication method is generally called device authentication or terminal authentication.

[0044] In the settlement server 100 of the embodiment, the user authentication unit 150 has such a device authentication function, and can detect whether the user terminal device 10 has been changed by this device authentication function. Further, the settlement server 100 can be configured to perform authentication by combining the results of device authentication in the above-described first authentication method, second authentication method, and third authentication method.

[0045] Hereinafter, an example of a method for causing a user who has completed the use registration of passwordless authentication to perform a device change procedure will be described. Here, it is assumed that the device change procedure is a procedure completed by the user logging in to the electronic payment service from the settlement application 20 of the new terminal 10.

[0046] <First Example of Device Change Procedure> FIG. 10 is a diagram showing an example of screen transition of the payment application 20 according to the first embodiment of the model change procedure. The model change procedure according to the first embodiment is completed by displaying a two-dimensional code for the model change procedure on the payment application 20 of the old terminal 10 and reading the two-dimensional code with the payment application 20 of the new terminal 10. A user who performs the model change procedure first causes the payment application 20 of the old terminal 10 to display an authentication method selection screen D41 and selects an authentication method to be used for login. Here, the case where the first type of web service is selected as the authentication method will be described. FIG. 10 is an example in the case where "aaa-ID" illustrated in FIG. 7 is selected as the first type of web service. When the user selects the authentication method using "aaa-ID", a sign-in screen D42 using "aaa-ID" is displayed on the payment application 20, and when an execution operation of sign-in is performed on the sign-in screen D42, a two-dimensional code display screen D43 is displayed on the payment application 20. Here, the authentication by the first type of web service is an example of "authentication of the first element". Note that even when "bbb-ID" illustrated in FIG. 8 is the first type of web service instead of "aaa-ID", although the form of the sign-in screen D42 is different (see FIG. 8), the basic flow is the same as that in the case of FIG. 10.

[0047] The two-dimensional code display screen D43 includes, for example, a two-dimensional code CD for the model change procedure and a link LK for transitioning to the procedure when the old terminal 10 is not at hand. The two-dimensional code CD encodes a one-time code with an expiration date issued by the payment application 20. The one-time code contains information for identifying the user. The user logs in to the payment application 20 on the old terminal 10 and reads the two-dimensional code CD displayed on the new terminal 10 using the payment application 20. The payment application 20 sends the one-time code read from the two-dimensional code to the payment server 100, and the payment server 100 authenticates the user when it is confirmed that the one-time code received from the payment application 20 of the old terminal 10 matches the issued one-time code. After authenticating the user, the payment server 100 registers the new terminal 10 linked to the user's account information and notifies the payment application 20 of the new terminal 10 of the successful authentication, so that the top screen D44 is displayed on the payment application 20 of the new terminal 10.

[0048] When the authentication method by phone number is selected on the authentication method selection screen D41 in FIG. 10, as shown in the next FIG. 11, signing in with "aaa-ID" may replace the authentication by phone number and password. In this case, on the payment application 20 of the new terminal 10, the authentication method selection screen D41 transitions to the phone number input screen D45 and the password input screen D46 in that order. The payment application 20 obtains the user's phone number and password through the phone number input screen D46 and the password input screen D46 and sends them to the payment server 100. The payment server 100 attempts to authenticate the user with the phone number and password received from the payment application 20 of the new terminal 10, and if the authentication is successful, it causes the two-dimensional code display screen D43 to be displayed on the payment application 20 of the new terminal 10.

[0049] <Second Embodiment of the Model Change Procedure> FIG. 12 is a diagram showing an example of screen transition of the settlement application 20 according to the second embodiment of the model change procedure. The second embodiment is an example in which, although signing in is successful with the "aaa-ID" selected on the authentication method selection screen D41 of the first embodiment, the use registration of passwordless authentication using "aaa-ID" has not been made for the account. In this case, the settlement server 100 causes the settlement application 20 to display a registration confirmation screen D47 prompting the use registration of passwordless authentication using "aaa-ID", and upon receiving an operation for executing the registration, causes a transition to the sign-in screen D48. The sign-in screen D48 is the same as the sign-in screen D42. When the sign-in by the sign-in screen D48 is successful, the settlement server 100 causes the top screen D44 to be displayed on the settlement application 20.

[0050] <Third Embodiment of Model Change Procedure> FIG. 13 is a diagram showing an example of screen transition of the settlement application 20 according to the third embodiment of the model change procedure. The third embodiment provides an authentication means by call origination (hereinafter referred to as "call origination authentication") instead of the two-dimensional code, so that in the first embodiment, when the old terminal 10 is not in the user's hand, the user can perform the model change procedure. Since the screen transition up to the two-dimensional code display screen D43 is the same as that in FIG. 10, the illustration here is omitted. In this case, the user can cause the settlement application 20 to display an alternative authentication method selection screen D51 by operating the link LK on the two-dimensional code display screen D43. On the alternative authentication method selection screen D51, options for authentication methods that can replace the authentication method by the two-dimensional code are displayed, and the options for authentication methods that can replace the authentication method by the two-dimensional code include an authentication method D511 by call origination. When the user selects the authentication method D511 by call origination on the alternative authentication method selection screen D51, the settlement application 20 displays a call origination permission screen D52. Here, the authentication by call origination is an example of the "second factor authentication".

[0051] The call permission screen D52 is a screen that requests the user to permit the execution of a call by the payment app 20. When the user permits the execution of a call for the payment app 20, a call authentication execution screen D53 is displayed on the payment app 20. The call authentication execution screen D53 is a screen that accepts an operation instruction to execute a call for the payment app 20. When an operation instruction to execute a call is performed on the call authentication execution screen D53, the payment app 20 makes a call to the phone number of the payment server 100. Here, it is assumed that the phone number of the new terminal 10 has not been changed from the phone number of the old terminal 10 by MNP (Mobile Number Portability). When receiving this call, the payment server 100 recognizes the phone number of the caller and the user, and determines whether the phone number matches the phone number registered for the user. When the phone number of the caller matches the registered phone number, the payment server 100 authenticates the user and causes the top screen D44 to be displayed on the payment app 20 of the new terminal 10.

[0052] As described above, according to the first to third embodiments, even when a user who has registered for passwordless authentication undergoes a device change procedure, by performing authentication using the first type of web service, the user can be made to undergo the device change procedure without having to input an ID or password.

[0053] [Call Authentication] As described above, call authentication is a method of causing the payment app 20 of the requester to make a call and authenticating the user when the phone number of the caller matches the registered phone number. Call authentication is common with the second authentication method described above in terms of using a phone number, but is different from the second authentication method in that the user is made to make a call.

[0054] Note that for call origination authentication, basically, it suffices to authenticate the user based on whether the calling phone number is registered. However, simply verifying the calling phone number may allow a third party to easily impersonate the user. Therefore, in the call origination authentication of this embodiment, in addition to verifying the calling phone number, the security is enhanced by verifying the verification information based on the call origination. Here, as an example of the realization method, the following two examples will be described. The first example is a method of verifying the legitimacy of the calling party by transmitting and receiving verification information between the payment server 100 and the payment app 20 along with the call origination. The second example is a method of verifying the calling party using the timing of various operations performed by the user terminal device 10 regarding the authentication call origination as verification information.

[0055] [First Embodiment of Call Origination Authentication] FIG. 14 is a diagram showing an example of the flow of processing according to the first embodiment of call origination authentication. The sequence chart in FIG. 14 is started, for example, in response to an execution instruction operation for call origination on the call origination authentication execution screen D53 in FIG. 13. First, the payment app 20 requests a verification one-time code from the payment server 100 (S201). In the first embodiment, the verification one-time code is the verification information. When the payment server 100 receives the request in S201, it issues a verification one-time code and associates it with the user ID of the requesting user (S202). The payment server 100 notifies the payment app 20 of the verification one-time code issued in S202 (S203). The payment app 20 can transmit the notified verification one-time code to the payment server 100 by transmitting it to the payment server 100 as option information for the call origination. Option information is numerical information that can be automatically transmitted to the called party by specifying it during the call origination. Generally, option information can be specified in comma-separated form following the called phone number. The numerical value specified as option information is automatically transmitted to the called party by a push signal of the corresponding numerical value.

[0056] Here, an application program (hereinafter referred to as the "phone app") that provides a voice call function using a public telephone line is pre-installed in the user terminal device 10, and the payment app 20 is configured to make a call to the payment server 100 using the phone app. In this case, when the payment app 20 specifies the destination phone number and executes a call initiation command, the phone app AP is launched (S204). The launched phone app AP makes a call to the specified phone number (S205). When the payment server 100 receives the call initiation in S205 (S206), a call is started between the payment server 100 and the phone app AP. When the call between the payment server 100 and the phone app AP is started, the phone app AP transmits the option information (verification one-time code) specified by the payment app 20 to the payment server 100 by a push signal (S207). When the payment server 100 receives the option information, it disconnects the call line (S208). In the user terminal device 10, the phone app terminates in response to the disconnection of the call line, and due to the termination of the phone app, the control of the application returns from the phone app AP to the payment app 20 (S209).

[0057] Subsequently, the payment server 100 identifies the user of the calling party by referring to the user information 172 based on the calling party phone number of the call initiation received in S206 and recognizing the user ID associated with the calling party phone number (S210). The payment server 100 checks the consistency between the verification one-time code issued in S202 and the option information acquired in S207 for the user identified in S210 (S211), and notifies the payment app 20 of the authentication result determined based on the consistency (S212). Specifically, the payment server 100 determines that authentication is successful when the verification one-time code matches the option information, and determines that authentication fails when they do not match.

[0058] Subsequently, the payment app 20 determines whether the call authentication was successful based on the authentication result notified in S212 (S213). Here, if it is determined that the call authentication has failed, the payment app 20 notifies an authentication error (S214). On the other hand, if it is determined in S213 that the call authentication was successful, the payment app 20 transitions to the top screen (S215).

[0059] [Second Embodiment of Call Authentication] FIG. 15 is a diagram showing an example of a processing flow according to a second embodiment of call authentication. In FIG. 15, since the processing of S201 to S211 is the same as that in the case of FIG. 14, the description thereof will be omitted as appropriate. In the second embodiment, the payment app 20 acquires and records the call start time from the phone app (or the log of the phone app, etc.) in response to the execution of the call in S205 (S221), and acquires and records the call arrival time from the phone app (or the log of the phone app, etc.) in response to the execution of the incoming call in S206 (S222), and stores the disconnection time in response to the disconnection of the call line in S208 (S223). The disconnection time may be the time when the control of the application returns to the payment app 20 in S209, or may be acquired from the phone app (or the log of the phone app, etc.). The payment app 20 transmits the time information indicating the call start time, call arrival time, and disconnection time recorded in S221 to S223 to the payment server 100 (S224). In the second embodiment, the verification one-time code and the time information are the verification information.

[0060] On the other hand, in addition to confirming the consistency of the verification one-time code (S211), the settlement server 100 also confirms the validity of the performed call initiation from the perspective of timing based on the time information received in S224 (S225), and notifies the settlement application 20 of the authentication result determined based on the consistency and validity (S226). For example, when it is determined that all conditions related to the validity confirmation are true, the settlement server 100 determines that the timing related to the call initiation is appropriate, and when it is determined that any one or more conditions are false, it determines that the timing is inappropriate. The first condition, the second condition, and the third condition exemplified below are examples of the conditions related to the validity confirmation. The conditions related to the validity confirmation may include any one or more of the conditions exemplified below. Note that the conditions exemplified below are just examples, and the conditions related to the validity confirmation may include conditions different from those exemplified below as long as they are based on any one or more of the call start time, call arrival time, and call disconnection time.

[0061] (First condition) The elapsed time from the issuance of the verification one-time code to the call start time is less than the threshold value. The threshold value may be any time that can be regarded as the call start authentication being performed by a correct operation, and may be appropriately designed based on the time required for the normal operation when a general user performs the call start authentication. (Second condition) The call arrival time indicated by the time information matches the call arrival time at the settlement server 100. (Third condition) The call disconnection time indicated by the time information matches the call disconnection time at the settlement server 100. Note that the time consistency in the second condition and the third condition may be determined in a form that allows a certain degree of delay in the communication line.

[0062] When the consistency of the verification one-time code is confirmed and the validity of the timing related to the call initiation is confirmed, the settlement server 100 determines that the authentication is successful. When either one or both are not confirmed, the settlement server 100 determines that the authentication fails. Note that even when either one is not confirmed, the settlement server 100 may be configured to manage the user as a monitoring target and succeed in the user's login authentication. Also, in this case, the electronic payment service may be configured to be provided to the user as a restricted user with certain functions restricted.

[0063] Also, as a modification of the second embodiment, the processes (S201 to S203, S211) related to the confirmation of the consistency of the verification one-time code may be omitted, and only the validity of the timing related to the call initiation may be used to verify the validity of the caller. In this case, the settlement server 100 may be configured to authenticate the user when the validity of the timing related to the call initiation is confirmed in S225 for the user ID specified in S210.

[0064] According to the call initiation authentication of the first embodiment or the second embodiment, the user of the electronic payment service can be authenticated without having the user input a password. Note that in call initiation authentication, since the settlement server 100 needs to receive the call initiation from the user terminal device 10, basically, a call charge is incurred for the caller. However, if a call charge is incurred every time of authentication, the burden on the user side is large. Therefore, it is desirable that the call initiation authentication be performed in a manner (for example, so-called free dial) such that no call charge is imposed on the caller by the reception on the settlement server 100 side.

[0065] According to the embodiment described above, in a system in which a user's account is managed in association with a telephone number, the convenience of user authentication can be improved.

[0066] <Modification> In the embodiment, although the method for realizing call origination authentication has been described, it is also possible to replace call origination with SMS (Short Message Service) for SMS origination authentication. In this case, in S204 of FIG. 14 (or FIG. 15), the payment app 20 may send an SMS message with option information described in the text to the destination phone number. Also, in this case, in S205 of FIG. 14 (or FIG. 15), the payment server 100 may obtain the option information from the text of the received SMS message. Also, the use of passwordless authentication for authentication is not limited to a specific use. Passwordless authentication may be used as an authentication method in one-factor authentication or as an authentication method in two-factor authentication. Also, for example, passwordless authentication may be used for authentication when the user logs in to the payment app 20 or for authentication when the user changes the password.

[0067] Also, in call origination authentication, the payment server 100 may be configured to notify the payment app 20 of the destination phone number. In this case, the payment server 100 may hold several candidates for the destination phone number in advance and select one phone number from the candidate phone numbers in response to an authentication request and notify the payment app 20. The phone number to be notified may be randomly selected or selected based on a predetermined rule.

[0068] In the embodiment, the content displayed on the screen of the payment application 20 is controlled based solely on the content information provided from the payment server 100 to the payment application 20. However, the control of the content displayed on the screen of the payment application 20 may be implemented by the payment application 20 alone, or may be implemented by the cooperation of the payment application 20 and the payment server 100. Also, these control methods may differ for each displayed screen. Further, the screen displayed on the payment application 20 may be generated based on information provided from an external system other than the payment application 20 and the payment server 100. For example, while the timing of transitioning to the sign-in screen D20 is controlled by the payment application 20 or the payment server 100, the sign-in screen D20 itself may be provided from the system of the first type web service. Also, the payment server 100 may be configured such that the content provision to the payment application 20 regarding the login to the electronic payment service is executed by the user authentication unit 150 instead of the content provision unit 120. Further, in the above embodiment, the electronic payment service is an example of the "predetermined service", and the "predetermined service" is not limited to the electronic payment service. In the embodiment, the electronic payment service may be modified to provide any service.

[0069] As described above, the embodiments for implementing the present invention have been described using the embodiments. However, the present invention is not limited to such embodiments, and various modifications and substitutions can be made without departing from the gist of the present invention.

Description of Reference Numerals

[0070] 10 User terminal device 20 Payment application 50 First store terminal device 60 Store code image 70 Second store terminal device 72 Interface for franchisees 100 Payment server 110 Communication unit 120 Content provision unit 130 Settlement Processing Unit 140 Information Management Unit 150 User Authentication Unit 170 Memory Unit 172 User Information 174 Content Information 176 Franchise / Store Information D10 Authentication Method Selection Screen D20 Sign-in Screen D30 Top Screen

Claims

1. A service providing device that provides a predetermined service to a user in cooperation with a user application running on a terminal device of the user, a management unit that manages the account information of the user in association with the telephone number of the user; an authentication processing unit that executes an authentication process for authenticating a user of the service; Equipped with The authentication process includes: When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, After disconnecting the call, time information regarding the call from the user's terminal device is obtained from the user application; a user of the user application is authenticated when the second telephone number matches a third telephone number that is registered in advance for the user and the validity of the timing of the call is confirmed based on the time information; the time information includes a second time which is a call start time between the terminal device and a destination of a call made in response to the authentication request, the authentication processing unit determines that the timing is valid when a first condition is satisfied that the second time substantially coincides with a time when the device receives the outgoing call; Service providing device.

2. A service providing device that provides a predetermined service to a user in cooperation with a user application running on a terminal device of the user, a management unit that manages the account information of the user in association with the telephone number of the user; an authentication processing unit that executes an authentication process for authenticating a user of the service; Equipped with The authentication process includes: When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, After disconnecting the call, time information regarding the call from the user's terminal device is obtained from the user application; a user of the user application is authenticated when the second telephone number matches a third telephone number that is registered in advance for the user and the validity of the timing of the call is confirmed based on the time information; the time information includes a third time which is a disconnection time of a call made by the terminal device in response to the authentication request; the authentication processing unit determines that the timing is valid when a first condition is satisfied that the third time substantially coincides with a time when the device disconnects the outgoing call; Service providing device.

3. the time information includes a first time which is a time when the call was originated from the terminal device, The authentication processing unit: When the authentication request is accepted, the first telephone number is notified to the user application; determining that the timing is appropriate when, in addition to the first condition, a second condition is satisfied that the first time is included in a period from the time when the first telephone number is notified to the time when a predetermined time has elapsed; The service providing device according to claim 1 or 2.

4. A service providing device that provides a predetermined service to a user in cooperation with a user application running on a terminal device of the user, a management unit that manages the account information of the user in association with the telephone number of the user; an authentication processing unit that executes an authentication process for authenticating a user of the service; Equipped with The authentication process includes: When an authentication request is received from the user application, a one-time code is issued and notified to the user application; When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, When the second telephone number matches a third telephone number that is preregistered for the user, the user of the user application is authenticated; the user application makes a call to a telephone number of the service providing device using the one-time code notified from the service providing device as option information for the call; The authentication processing unit: If the identification information of the user application is not associated with the identification information of the user and the user is successful in authentication by the first type web service, prompting the user to carry out a model change procedure via the user application; In the device change procedure, the first type web service is registered as an authentication method for the user in association with the user, The first type web service is a type of web service that allows the service providing device to recognize that the user has an account. Service providing device.

5. A service providing device that provides a predetermined service to a user in cooperation with a user application running on a terminal device of the user, a management unit that manages the account information of the user in association with the telephone number of the user; an authentication processing unit that executes an authentication process for authenticating a user of the service; Equipped with The authentication process includes: When an authentication request is received from the user application, a one-time code is issued and notified to the user application; When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, When the second telephone number matches a third telephone number that is preregistered for the user, the user of the user application is authenticated; the user application makes a call to a telephone number of the service providing device using the one-time code notified from the service providing device as option information for the call; The authentication processing unit: When a first authentication is successful for a user of the user application using a first-factor authentication method that is different from the authentication using the telephone call, and identification information of the user application is not associated with identification information of the user, the user is prompted to carry out a model change procedure via the user application; In the model change procedure, the authentication by making the call is executed as a second authentication of a second factor. Service providing device.

6. The authentication processing unit: The issued one-time code is stored in association with the user, When the call is received, the target user is identified based on the caller's phone number, If the optional information is associated with the identified user, authenticating the user. The service providing device according to claim 4 or 5.

7. The user application transmits an SMS (Short Message Service) message including the option information to a telephone number of the service providing device instead of the call origination; the authentication processing unit, when receiving an SMS message after the notification of the one-time code, authenticates the user of the user application if option information included in the SMS message matches the one-time code; The service providing device according to claim 4 or 5.

8. A service providing device that provides a predetermined service to a user in cooperation with a user application running on a terminal device of the user, Manage the user's account by linking it to the user's telephone number; Executing an authentication process to authenticate a user of the service; 1. An authentication method, comprising: The authentication process includes: When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, After disconnecting the call, time information regarding the call from the user's terminal device is obtained from the user application; a user of the user application is authenticated when the second telephone number matches a third telephone number that is registered in advance for the user and the validity of the timing of the call is confirmed based on the time information; the time information includes a second time which is a call start time between the terminal device and a destination of a call made in response to the authentication request, The authentication process determines that the timing is valid when a first condition is satisfied that the second time substantially coincides with a time when the device receives the outgoing call. Authentication method.

9. A service providing device for providing a predetermined service to a user in cooperation with a user application running on a terminal device of the user, Manage the user's account by linking it to the user's telephone number; Executing an authentication process to authenticate a user of the service; 1. An authentication method, comprising: The authentication process includes: When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, After disconnecting the call, time information regarding the call from the user's terminal device is obtained from the user application; a user of the user application is authenticated when the second telephone number matches a third telephone number that is registered in advance for the user and the validity of the timing of the call is confirmed based on the time information; the time information includes a third time which is a disconnection time of a call made by the terminal device in response to the authentication request; The authentication process determines that the timing is valid when a first condition is satisfied that the third time substantially coincides with a time when the device disconnects the outgoing call. Authentication method.

10. A service providing device for providing a predetermined service to a user in cooperation with a user application running on a terminal device of the user, Manage the user's account by linking it to the user's telephone number; Executing an authentication process to authenticate a user of the service; 1. An authentication method, comprising: The authentication process includes: When an authentication request is received from the user application, a one-time code is issued and notified to the user application; When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, When the second telephone number matches a third telephone number that is registered in advance for the user, the user of the user application is authenticated; the user application makes a call to a telephone number of the service providing device using the one-time code notified from the service providing device as option information for the call; The authentication process includes: If the identification information of the user application is not associated with the identification information of the user and the user is successful in the authentication by the first type web service, prompting the user to carry out a model change procedure via the user application; In the device change procedure, the first type web service is registered as an authentication method for the user in association with the user, The first type web service is a type of web service that allows the service providing device to recognize that the user has an account. Authentication method.

11. A service providing device for providing a predetermined service to a user in cooperation with a user application running on a terminal device of the user, Manage the user's account by linking it to the user's telephone number; Executing an authentication process to authenticate a user of the service; 1. An authentication method, comprising: The authentication process includes: When an authentication request is received from the user application, a one-time code is issued and notified to the user application; When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, When the second telephone number matches a third telephone number that is preregistered for the user, the user of the user application is authenticated; the user application makes a call to a telephone number of the service providing device using the one-time code notified from the service providing device as option information for the call; The authentication process includes: When a first authentication is successful for a user of the user application using a first-factor authentication method that is different from the authentication using the telephone call, and identification information of the user application is not associated with identification information of the user, the user is prompted to carry out a model change procedure via the user application; In the model change procedure, the authentication by making the call is executed as a second authentication of a second factor. Authentication method.

12. A service providing device that provides a predetermined service to a user in cooperation with a user application running on a terminal device of the user, Linking the user's account to the user's telephone number and managing it; Executing an authentication process for authenticating a user of the service; A program for: The authentication process includes: When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, After disconnecting the call, time information regarding the call from the user's terminal device is obtained from the user application; a user of the user application is authenticated when the second telephone number matches a third telephone number that is registered in advance for the user and the validity of the timing of the call is confirmed based on the time information; the time information includes a second time which is a call start time between the terminal device and a destination of a call made in response to the authentication request, The authentication process determines that the timing is valid when a first condition is satisfied that the second time substantially coincides with a time when the device receives the outgoing call. program.

13. A service providing device that provides a predetermined service to a user in cooperation with a user application that operates on a terminal device of the user, Linking the user's account to the user's telephone number and managing it; Executing an authentication process for authenticating a user of the service; A program for: The authentication process includes: When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, After disconnecting the call, time information regarding the call from the user's terminal device is obtained from the user application; a user of the user application is authenticated when the second telephone number matches a third telephone number that is registered in advance for the user and the validity of the timing of the call is confirmed based on the time information; the time information includes a third time which is a disconnection time of a call made by the terminal device in response to the authentication request; The authentication process determines that the timing is valid when a first condition is satisfied that the third time substantially coincides with a time when the device disconnects the outgoing call. program.

14. A service providing device that provides a predetermined service to a user in cooperation with a user application that operates on a terminal device of the user, Linking the user's account to the user's telephone number and managing it; Executing an authentication process for authenticating a user of the service; A program for: The authentication process includes: When an authentication request is received from the user application, a one-time code is issued and notified to the user application; When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, When the second telephone number matches a third telephone number that is preregistered for the user, the user of the user application is authenticated; the user application makes a call to a telephone number of the service providing device using the one-time code notified from the service providing device as option information for the call; The authentication process includes: If the identification information of the user application is not associated with the identification information of the user and the user is successful in authentication by the first type web service, prompting the user to carry out a model change procedure via the user application; In the device change procedure, the first type web service is registered as an authentication method for the user in association with the user, The first type web service is a type of web service that allows the service providing device to recognize that the user has an account. program.

15. A service providing device that provides a predetermined service to a user in cooperation with a user application that operates on a terminal device of the user, Linking the user's account to the user's telephone number and managing it; Executing an authentication process for authenticating a user of the service; A program for: The authentication process includes: When an authentication request is received from the user application, a one-time code is issued and notified to the user application; When a call is received from a first telephone number, which is a telephone number addressed to the device itself, after receiving an authentication request from the user application, the device recognizes a second telephone number, which is a telephone number of the call originator, When the second telephone number matches a third telephone number that is preregistered for the user, the user of the user application is authenticated; the user application makes a call to a telephone number of the service providing device using the one-time code notified from the service providing device as option information for the call; The authentication process includes: When a first authentication is successful for a user of the user application using a first-factor authentication method that is different from the authentication using the telephone call, and identification information of the user application is not associated with identification information of the user, the user is prompted to carry out a model change procedure via the user application; In the model change procedure, the authentication by making the call is executed as a second authentication of a second factor. program.

Citation Information

Patent Citations

  • Method and system for personal authentication

    JP2002055955A

  • Authentication support apparatus, personal authentication system, authentication support method, and program

    JP2015179501A

  • Authentication system, authentication method, and authentication program

    JP2016192023A

  • Information processing device, information processing method, and program

    JP7202500B1

  • Information processing device, information processing method, and program

    JP7247416B1