Authentication method, authentication system, providing server, and program

The authentication method addresses the challenge of limited authentication information by using token data and registration codes to ensure secure SSH tunnel establishment, even when data volume is restricted, thereby maintaining sufficient security.

JP7691689B1Active Publication Date: 2025-06-12KAMOME ENG
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024519126
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-12
Estimated Expiration
2043-12-15

AI Technical Summary

Technical Problem

Existing authentication systems face challenges in establishing secure SSH tunnels when the amount of authentication information that can be transmitted is limited, as this restricts the ability to ensure sufficient security during the authentication process.

Method used

The proposed authentication method involves an authentication server transmitting token data to a user terminal, which then forwards this data to a providing server. The providing server issues a registration code associated with the token data, allowing the user terminal to request the establishment of a tunnel. The providing server verifies the token data with the authentication server, ensuring authentication before establishing the tunnel.

Benefits of technology

This approach enables the establishment of secure SSH tunnels even when the data volume of authentication information is limited, ensuring sufficient security and successful tunnel establishment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691689000001
    Figure 0007691689000001
  • Figure 0007691689000002
    Figure 0007691689000002
  • Figure 0007691689000003
    Figure 0007691689000003
Patent Text Reader

Abstract

The authentication server 1 transmits the token data to the user terminal 3 and transmits the authentication result of the token data transmitted from the provision server 2 to the provision server 2. When the provision server 2 receives the token data from the user terminal 3, it includes an issuing unit 22 that transmits the registration code associated with the token data to the user terminal 3, and when it receives a request to establish a tunnel between the processing unit and the user terminal 3 and the registration code from the user terminal 3, it transmits the token data associated with the registration code to the authentication server 1, and when it receives a result indicating that the authentication has been successful from the authentication server 1, it includes a connection unit 23 that establishes a tunnel between the processing unit 25 and the user terminal 3.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an authentication method, an authentication system, a providing server, and a program.

Background Art

[0002] SSH (Secure Shell) is known (see Non-Patent Document 1). SSH is an encrypted network protocol. According to SSH, a protected communication path can be established on an unprotected network. Using the protected communication path, a providing server can operate network services securely. In this specification, on an unprotected network, a communication path protected by SSH is referred to as an SSH tunnel or a tunnel.

[0003] Also, single sign-on (SSO) is known (see Non-Patent Document 2). In SSO, once a user is authenticated by a single authentication process, the user can use the resources of other independent software systems.

Prior Art Documents

Non-Patent Documents

[0004]

Non-Patent Document 1

Non-Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, depending on the software that implements SSH, the amount of authentication information that can be transmitted may be limited before establishing a tunnel, such as during authentication. On the other hand, in an authentication server such as single sign-on, the amount of data for user authentication tends to increase in order to ensure security.

[0006] Therefore, when the amount of authentication information that can be transmitted is limited before establishing a tunnel, the authentication server may not be able to authenticate the user terminal with a sufficient amount of data to ensure security. In such a situation, it is not possible to establish a tunnel while ensuring sufficient security.

[0007] The present disclosure has been made in view of the above circumstances, and an object of the present disclosure is to provide a technique capable of establishing a tunnel while ensuring sufficient security even when the amount of authentication information that can be transmitted is limited.

Means for Solving the Problem

[0008] The authentication method according to one aspect of the present disclosure is an authentication system including a user terminal, a providing server that provides an application, and an authentication server that authenticates the use of the providing server by the user terminal. The authentication server transmits token data for authenticating the user terminal to the user terminal. The user terminal transmits the token data to the providing server. When the providing server receives the token data from the user terminal, the providing server transmits a registration code associated with the token data to the user terminal. The user terminal transmits the registration code to the providing server and requests the establishment of a tunnel between the processing unit of the application provided by the providing server and the user terminal. The providing server receives the registration code from the user terminal, identifies the token data associated with the received registration code, the providing server transmits the identified token data to the authentication server, the authentication server transmits the authentication result of the token data transmitted from the providing server to the providing server, and when the providing server receives the result of being authenticated from the authentication server, the providing server establishes a tunnel between the processing unit and the user terminal.

[0009] An authentication system according to an aspect of the present disclosure includes a user terminal, a providing server that provides an application, and an authentication server that authenticates the use of the providing server by the user terminal. The authentication server transmits token data for authenticating the user terminal to the user terminal, and transmits an authentication result of the token data transmitted from the providing server to the providing server. The user terminal transmits the token data to the providing server, receives a registration code from the providing server, transmits the registration code to the providing server, and requests establishment of a tunnel between a processing unit of the application provided by the providing server and the user terminal. When the providing server receives the token data from the user terminal, the providing server includes an issuing unit that transmits a registration code associated with the token data to the user terminal, and when the providing server receives a request for establishing a tunnel between the processing unit and the user terminal and the registration code from the user terminal, the providing server transmits the token data associated with the registration code to the authentication server, and when the providing server receives a result indicating that the authentication has been performed from the authentication server, the providing server includes a connection unit that establishes a tunnel between the processing unit and the user terminal.

[0010] A providing server according to an aspect of the present disclosure includes a processing unit that provides an application, and an issuing unit that transmits a registration code associated with the token data to the user terminal when the providing server receives the token data for authenticating the user terminal from the authentication server, and when the providing server receives a request for establishing a tunnel between the processing unit and the user terminal and the registration code from the user terminal, the providing server transmits the token data associated with the registration code to the authentication server, and when the providing server receives a result indicating that the authentication has been performed from the authentication server, the providing server includes a connection unit that establishes a tunnel between the processing unit and the user terminal.

[0011] An aspect of the present disclosure is a program for causing a computer to function as the above providing server.

Advantages of the Invention

[0012] According to the present disclosure, even when the data volume of the authenticable authentication information is limited, it is possible to provide a technology that can sufficiently ensure security and establish a tunnel.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the description of the drawings, the same reference numerals are given to the same parts and the description thereof is omitted.

[0015] (Authentication System) Referring to FIG. 1, the authentication system 8 according to the present disclosure will be described. The authentication system 8 includes an authentication server 1, an authentication server, and a user terminal 3. The authentication server 1, the authentication server, and the user terminal 3 are connected to be communicable bidirectionally via a communication network 5.

[0016] The authentication server 1 authenticates the use of the providing server 2 by the user terminal 3. The authentication server 1 authenticates the user terminal 3 when the user terminal 3 uses an application provided by the providing server 2. The authentication server 1 may be an authentication server that provides single sign-on.

[0017] The authentication server 1 issues token data for authenticating the user terminal 3 and sends it to the user terminal 3. When the authentication server 1 receives the token data from the providing server 2, it authenticates the token data and sends the authentication result of the token data to the providing server 2.

[0018] The authentication server 1 generates token data by, for example, digitally signing a predetermined character string. The authentication server 1 may also set an expiration date for the authentication server 1 to authenticate the token data in the token data.

[0019] The authentication server 1 confirms that the token data sent from the providing server 2 was (1) sent by the authentication server 1, (2) generated by the digital signature of the authentication server 1, and (3) received from the providing server 2 within the expiration date set by the authentication server 1. If these can be confirmed, the authentication server 1 sends an authentication result including the fact that it has authenticated to the providing server 2. If at least any one of these cannot be confirmed, the authentication server 1 sends an authentication result including the fact that it has not authenticated to the providing server 2.

[0020] The user terminal 3 receives authentication by the authentication server 1 and uses the application service provided by the providing server 2.

[0021] The user terminal 3 obtains token data from the authentication server 1. The user terminal 3 sends the token data to the providing server 2 and receives a registration code from the providing server 2. The user terminal 3 sends the registration code to the providing server 2 and requests the establishment of a tunnel between the processing unit 25 of the application provided by the providing server 2 and the user terminal 3. When the tunnel is established, the user terminal 3 enjoys the application service provided by the processing unit 25 using the established tunnel.

[0022] The providing server 2 provides the application service used by the user terminal 3 through authentication by the authentication server 1. In the present disclosure, a case where the providing server 2 includes a first processing unit 25a and a second processing unit 25b that provide the application service will be described. The number of services that the providing server 2 can provide is arbitrary. In the present disclosure, when the first processing unit 25a and the second processing unit 25b are not distinguished, they may simply be described as the processing unit 25.

[0023] In the present disclosure, an SSH tunnel is established between the user terminal 3 and the processing unit 25 that provides the application service used by the user terminal 3. At this time, even when the amount of authentication information that can be transmitted is limited during authentication before establishing the SSH tunnel in the software that realizes SSH, the authentication system 8 ensures sufficient security and establishes the tunnel.

[0024] (Providing server) As shown in FIG. 1, the providing server 2 includes each piece of data such as the corresponding data 24, and the functions of the authentication unit 21, the first processing unit 25a, and the second processing unit 25b. Each piece of data is stored in a storage device such as the memory 902 or the storage 903. Each function is implemented in the CPU 901.

[0025] As shown in FIG. 2, the corresponding data 24 associates a registration code with token data. The token data is data transmitted from the user terminal 3 and is data for the authentication server 1 to authenticate the user terminal. The token data is generated, for example, by the digital signature of the authentication server 1. The registration code is data that uniquely identifies the token data transmitted from the user terminal 3.

[0026] Token data is originally data that is transmitted from the user terminal 3 to the providing server 2 during authentication of the user terminal 3 by the function of the software that realizes SSH. Due to the software specifications, there is a limit on the amount of data that can be transmitted during authentication of the user terminal 3. In the present disclosure, the amount of token data may exceed the amount of data defined by the specifications of the SSH software. On the other hand, the registration code is within the range of the amount of data defined by the specifications of the SSH software.

[0027] The first processing unit 25a provides a first application service. The second processing unit 25b provides a second application service.

[0028] The authentication unit 21 includes an issuing unit 22 and a connection unit 23.

[0029] When the issuing unit 22 receives token data from the user terminal 3, it transmits a registration code associated with the token data to the user terminal 3. The token data is data issued by the authentication server 1 to authenticate the user terminal 3.

[0030] When the issuing unit 22 receives the token data, it issues registration data corresponding to the token data, associates the registration data with the token data, and stores it in the corresponding data 24. The issuing unit 22 returns the issued registration code to the user terminal 3.

[0031] The connection unit 23 receives a request to establish a tunnel between the processing unit 25 and the user terminal 3 and a registration code from the user terminal 3. The connection unit 23 specifies the token data associated with the registration code received from the user terminal 3 from the corresponding data 24 and transmits the specified token data to the authentication server 1.

[0032] Here, the authentication server 1 checks the token data and attempts authentication. The authentication server 1 transmits an authentication result including whether the token data has been authenticated to the providing server 2.

[0033] When the connection unit 23 receives the result indicating that it has been authenticated from the authentication server 1, it establishes a tunnel between the processing unit 25 and the user terminal 3. When the providing server 2 has a plurality of processing units 25, a tunnel is established with the processing unit 25 designated from the user terminal 3.

[0034] (Authentication method) Referring to FIGS. 3-4, the authentication method according to the present disclosure will be described.

[0035] In step S1, the user terminal 3 logs in to the authentication server 1. In step S2, the authentication server 1 authenticates the user terminal 3.

[0036] In step S3, the user terminal 3 sends a request to the authentication server 1 to issue token data. The authentication server 1 generates token data by applying an electronic signature to predetermined data. In step S4, the authentication server 1 sends the generated token data to the user terminal 3.

[0037] In step S5, the user terminal 3 sends the token data received in step S4 to the providing server 2. The user terminal 3 sends the token data to the providing server 2 in accordance with the REST API (Representational State Transfer Application Programming Interface) defined by the providing server 2.

[0038] In step S6, when the authentication unit 21 of the providing server 2 receives the token data, it issues a registration code for identifying the token data. The authentication unit 21 associates the issued registration code with the received token data and stores it in the correspondence data 24. In step S7, the authentication unit 21 sends the registration code issued in step S6 to the user terminal 3.

[0039] In step S8, the user terminal 3 sends a request to establish a tunnel to the providing server 2. This request includes the identifier of the application provided by the providing server 2 and the registration code received in step S7.

[0040] In step S9, when the authentication unit 21 of the providing server 2 receives a request from the user terminal 3, it acquires, from the corresponding data 24, the token data corresponding to the registration code included in this request. Here, the providing server 2 can associate token data of a data volume sufficient to ensure security with the tunnel request received from the user terminal 3.

[0041] In step S10, the authentication unit 21 sends an authentication request for the user terminal 3 to the authentication server 1. This authentication request includes the token data acquired from the corresponding data 24.

[0042] In step S11, the authentication server 1 authenticates the token data acquired in step S10. If authentication is successful, in step S12, the authentication server 1 sends an authentication result including the fact of authentication to the providing server 2. If authentication fails, in step S12, the authentication server 1 sends an authentication result including the fact of non - authentication to the providing server 2.

[0043] In step S12, the authentication unit 21 of the providing server 2 receives the authentication result from the authentication server 1. If the authentication result includes the fact of non - authentication, the providing server 2 rejects the request of the user terminal 3. If the authentication result includes the fact of authentication, the providing server 2 sends an instruction to establish a tunnel with the user terminal 3 to the processing unit 25 corresponding to the application ID received in step S8.

[0044] When the processing unit 25 of the providing server 2 receives an instruction to establish a tunnel from the authentication unit 21, in step S14, a tunnel is established between the processing unit 25 and the user terminal 3. The user terminal 3 enjoys the application service provided by the processing unit 25 using the established tunnel.

[0045] According to such an authentication system 8, the providing server 2 associates token data having a data volume that can sufficiently ensure security with a registration code within the range of the data volume that can be transmitted as authentication information. The user terminal 3 requests the establishment of a tunnel using the registration code, and the providing server 2 transmits the token data corresponding to the registration code received at the time of the request to the authentication server 1 to request the authentication of the user terminal 3.

[0046] Thereby, even when the data volume of the authentication information that can be transmitted is limited, the authentication system 8 can sufficiently ensure security and establish a tunnel.

[0047] Each of the devices of the authentication server 1, the providing server 2, and the user terminal 3 described above in the present embodiment is, for example, a general-purpose computer system including a CPU (Central Processing Unit, processor) 901, a memory 902, a storage 903 (HDD: Hard Disk Drive, SSD: Solid State Drive), a communication device 904, an input device 905, and an output device 906. In this computer system, each function of each device is realized by the CPU 901 executing a program loaded on the memory 902.

[0048] Note that each device may be implemented by one computer, or may be implemented by a plurality of computers. Also, each device may be a virtual machine implemented on a computer.

[0049] The programs of each device can be stored in a computer-readable recording medium such as an HDD, an SSD, a USB (Universal Serial Bus) memory, a CD (Compact Disc), or a DVD (Digital Versatile Disc), or can be distributed via a network. The computer-readable recording medium is, for example, a non-transitory recording medium.

[0050] Note that the present disclosure is not limited to the above-described embodiments, and various modifications are possible within the scope of the gist thereof.

Description of Reference Numerals

[0051] 1 Authentication server 2 Provision server 3 User terminal 5 Communication network 8 Authentication system 21 Authentication unit 22 Issuing unit 23 Connection unit 24 Corresponding data 25 Processing unit 901 CPU 902 Memory 903 Storage 904 Communication device 905 Input device 906 Output device

Claims

1. A user terminal, A providing server that provides an application, In an authentication system comprising an authentication server that authenticates the use of the providing server by the user terminal, The authentication server transmits token data for authenticating the user terminal to the user terminal, The user terminal transmits the token data to the providing server, When the providing server receives the token data from the user terminal, the providing server transmits a registration code associated with the token data to the user terminal, The user terminal transmits the registration code as authentication information to the providing server by SSH and requests the establishment of a tunnel between the processing unit of the application provided by the providing server and the user terminal, The providing server receives the registration code from the user terminal, identifies the token data associated with the received registration code, The providing server transmits the identified token data to the authentication server, The authentication server transmits the authentication result of the token data transmitted from the providing server to the providing server, When the providing server receives a result indicating that authentication has been successful from the authentication server, the providing server establishes a tunnel between the processing unit and the user terminal, The token data exceeds the data volume of authentication information that can be transmitted by the SSH, and the registration code is within the range of the data volume of authentication information that can be transmitted by the SSH An authentication method.

2. The user terminal transmits the token data in accordance with the REST API defined by the providing server, The providing server transmits a registration code associated with the token data to the user terminal in accordance with the REST API The authentication method according to claim 1.

3. The authentication server generates token data by digital signature, When it is confirmed that the token data is generated by the digital signature of the authentication server, the authentication result includes a confirmation of authentication The authentication method according to claim 1.

4. A user terminal, A providing server that provides an application, An authentication system comprising an authentication server that authenticates the use of the providing server by the user terminal, wherein The authentication server Transmits token data for authenticating the user terminal to the user terminal, Send the authentication result of the token data sent from the providing server to the providing server. The user terminal Send the token data to the providing server, and receive a registration code from the providing server. Send the registration code as authentication information to the providing server by SSH, and request the establishment of a tunnel between the processing unit of the application provided by the providing server and the user terminal. The providing server A processing unit that provides an application, When receiving the token data from the user terminal, an issuing unit that sends a registration code associated with the token data to the user terminal. When receiving a request for establishing a tunnel between the processing unit and the user terminal and the registration code from the user terminal, send the token data associated with the registration code to the authentication server, and when receiving a result indicating that the authentication has been successful from the authentication server, a connection unit that establishes a tunnel between the processing unit and the user terminal. The token data exceeds the data volume of the authentication information that can be transmitted by SSH, and the registration code is within the range of the data volume of the authentication information that can be transmitted by SSH. Authentication system.

5. A processing unit that provides an application, When receiving token data for the authentication server to authenticate the user terminal from the user terminal, an issuing unit that sends a registration code associated with the token data to the user terminal. When receiving a request for establishing a tunnel between the processing unit and the user terminal and the registration code by SSH from the user terminal, send the token data associated with the registration code to the authentication server, and when receiving a result indicating that the authentication has been successful from the authentication server, a connection unit that establishes a tunnel between the processing unit and the user terminal. Comprising The token data exceeds the data volume of the authentication information that can be transmitted by SSH, and the registration code is within the range of the data volume of the authentication information that can be transmitted by SSH. The providing server.

6. A program for causing a computer to function as the providing server according to claim 5.

Citation Information

Patent Citations

  • Processing print requests

    JP2013537664A

  • Communication control server, communication control method and program

    JP2015133016A

  • Information processing system and authentication method

    JP2016042327A

  • Information processor, method, and program

    JP2019012365A

  • Apparatus, method and program for automating business process with operation to intra-company server on intra-company network

    JP2020091512A