Authentication method and system
The user authentication method and system address the issue of IdP unavailability by obtaining authentication tokens from an external reliable source, ensuring continuous access to web applications and enhancing security and usability.
Patent Information
- Application Number
- JP2023156535
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-09-22
- Filing Date
- 2023-09-21
- Publication Date
- 2025-06-16
- Estimated Expiration
- 2043-09-21
AI Technical Summary
Existing Single Sign-On (SSO) systems rely on the availability of an Identity Provider (IdP) for user authentication, which can lead to inconvenience and potential financial losses if the IdP is unavailable.
A user authentication method and system that obtain authentication tokens from an external reliable source, independent of the IdP's availability, using a processor to verify user identifiers and biometric authentication, and transfer the tokens to relining party applications.
Ensures continuous access to web applications even when the IdP is unavailable, enhancing usability and security by reducing reliance on a single authentication source.
Smart Images

Figure 0007692967000001 
Figure 0007692967000002 
Figure 0007692967000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a user authentication method and system for accessing a web application.
Background Art
[0002] Single Sign-On (SSO) is an authentication process in which a user can access multiple applications with a single set of login authentication information. For example, Single Sign-On is a common procedure in enterprises where a client accesses multiple resources connected to a Local Area Network (LAN).
[0003] Single Sign-On (SSO) can be implemented using an Identity Provider (IdP or IDP), which can be a system entity that creates, maintains, and manages principal ID information and provides authentication services to relying applications within a federation or distributed network. The Identity Provider (IdP) provides user authentication as a service. Relying party applications such as web applications entrust the user authentication step to a trustworthy Identity Provider. Such relying party applications are called federations, that is, they use a federation ID.
Summary of the Invention
Problems to be Solved by the Invention
[0004] An ID provider can be a reliable provider, for example, enabling a system to access other websites using single sign-on (SSO). Additionally, single sign-on (SSO) can enhance usability, such as reducing the number of passwords a user needs to enter when accessing multiple web applications. Further, an Identity Provider (IdP) can provide security, facilitate the connection between cloud computing resources and users, and reduce the need for users to re-authenticate when using mobile and roaming applications. However, if the IdP is unavailable for some reason, users will be unable to access web applications and their corresponding resources, which can cause inconvenience and potentially financial losses, for example.
Means for Solving the Problem
[0005] Therefore, even when an IdP is available, a method and system for user authentication of web applications that do not rely on the availability of the IdP by always obtaining authentication tokens from an external reliable source are desirable.
[0006] According to one embodiment, a user authentication method for accessing a web application, comprising: receiving, by a processor, a user identifier and a biometric authentication identifier of a user together with an access request to one or more relining party applications; verifying, by the processor, the user identifier and the biometric authentication identifier of the user associated with the access request to the one or more relining party applications; obtaining, by the processor, an authentication token of the user from an external reliable source; transferring, by the processor, the authentication token of the user obtained from the external reliable source to the one or more relining party applications; and receiving, on the processor, authentication for the user to access the one or more relining party applications from the one or more relining party applications. 、 If the authentication token of the user cannot be obtained from the external trusted source, the processor further comprises: requesting an updated authentication token of the user from an ID service provider; receiving the updated authentication token of the user from the ID service provider; and transferring the updated authentication token of the user to the external trusted source. done.
[0007] According to one embodiment, a computer program product for user authentication for accessing a web application, comprising a non-transitory computer-readable storage medium having program instructions to be executed therein, the program instructions being executable by a computer, and causing the computer to: receive a user identifier and a biometric authentication identifier of a user together with an access request to one or more relining party applications; verify the user identifier and the biometric authentication identifier of the user associated with the access request to the one or more relining party applications; obtain an authentication token of the user from an external reliable source; transfer the authentication token of the user obtained from the external reliable source to the one or more relining party applications; and receive authentication for the user to access the one or more relining party applications from the one or more relining party applications.If the authentication token of the user cannot be obtained from the external trusted source, it further comprises: requesting an updated authentication token of the user from an ID service provider; receiving the updated authentication token of the user from the ID service provider; and transferring the updated authentication token of the user to the external trusted source. Execute the method.
[0008] According to one embodiment, a user authentication system for accessing a web application, which receives a user identifier and a biometric identifier of a user together with an access request to one or more relining party applications, verifies the user identifier and the biometric identifier of the user associated with the access request to the one or more relining party applications, obtains an authentication token of the user from an external reliable source, transfers the authentication token of the user obtained from the external reliable source to the one or more relining party applications, and is configured to receive, from the one or more relining party applications, authentication for the user to access the one or more relining party applications If the authentication token of the user cannot be obtained from the external trusted source, it is configured to request an updated authentication token of the user from an ID service provider, receive the updated authentication token of the user from the ID service provider, and transfer the updated authentication token of the user to the external trusted source. Comprising a processor configured as above.
[0009] Both the above summary and the following detailed description are to be regarded as illustrative and explanatory, and are not to be construed as further elaborating the claimed invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0010]
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 4
Figure 5
[0011] Preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings. As much as possible, the same reference numbers are used in the drawings and the specification to refer to the same or similar parts.
[0012] FIG. 1 is a diagram of a system 100 for performing online authentication of a user 102 in a known system. The system 100 may include, for example, one or more computer systems 110, 120, 130. The one or more computer systems 110, 120, 130 can be, for example, personal computers, home security or office security systems within a home or office, servers, smartphones, smart tablets, cameras, routers, medical devices or apparatuses, multifunctional peripheral devices (MFPs) that can generate print data used in printers, print servers, printers, etc.
[0013] The one or more computer systems 110, 120, 130 may include a processor or central processing unit (CPU), and one or more memories for storing software programs and data. The processor or CPU executes the instructions of the computer program and operates and / or controls at least a part of the functions of the devices of the one or more computer systems 110, 120, 130. The one or more computer systems 110, 120, 130 may also include an operating system (OS) that manages the computer hardware and provides common services for efficiently executing various software programs. For example, the software programs may include, for example, an authentication module and / or application software for managing biometric identifiers, and / or, for example, printer driver software for one or more computer systems 110, 120, 130 such as computer system 110.
[0014] Computer system 110 is a multifunctional peripheral device (MFP) or a printer and can be connected to computer systems 120 and 130 via communication network 140. The multifunctional peripheral device (MFP) may include at least a copy function, an image reading function, a facsimile (FAX) function, and a printer function, and forms an image on a sheet based on, for example, a print job (print command) of the multifunctional peripheral device received from computer system 110.
[0015] For example, computer system 110 is a medical device or a medical apparatus and can be used, for example, for diagnostic and / or treatment purposes. Examples of the medical device or the medical apparatus may include a medical imaging device capable of obtaining, for example, a radiographic image, an angiographic image, an ultrasonic image, and / or a tomographic image. Alternatively, one or more of computer systems 110, 120, and 130, such as computer system 130, may be, for example, a backend database or an enterprise database system and can be indirectly accessed by one or more users through an external application via one or more of computer systems 110 and 120.
[0016] As shown in FIG. 1, system 100 can be used for online authentication of user 102 in a known manner of accessing one or more relining party applications 132, such as one or more web applications hosted by computer system 130. The one or more relining party applications 132 may include web applications such as, for example, Google Workspace (formerly G Suite) and / or web applications provided by Salesforce, Microsoft 365, and Box.
[0017] One or more computer systems 110, 120, 130 are connected via a communication network 140. The communication network 140 includes, for example, a wired or wireless conventional network and can have any number of configurations such as a star configuration, a token ring configuration, or other known configurations. The communication network 140 can include one or more local area networks (LANs), wide area networks (WANs) (such as the Internet), virtual private networks (VPNs), peer-to-peer networks, near field networks (such as Bluetooth(R)), cellular networks (such as 3G, 4G, 5G, and other generations), and / or other interconnected data paths through which multiple computing nodes can communicate.
[0018] Data can be transferred between one or more computer systems 110, 120, 130 in encrypted or unencrypted form using a variety of different communication protocols, including, for example, various Internet layer, transport layer, or application layer protocols. For example, Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Transmission Control Protocol (TCP), Hypertext Transfer Protocol (HTTP), Secure Hypertext Transfer Protocol (HTTPS), Dynamic Adaptive Streaming over HTTP (DASH), Real-Time Streaming Protocol (RTSP), Real-Time Transport Protocol (RTP) and Real-Time Transport Control Protocol (RTCP), File Transfer Protocol (FTP), WebSocket (WS), Wireless Access Protocol (WAP), various messaging protocols (such as SMS, MMS, XMS, IMAP, SMTP, POP, WebDAV, etc.), or other known protocols can be used to transfer data between one or more computer systems 110, 120, 130 via the network 140.
[0019] As shown in FIG. 1, user 102 can be authenticated using, for example, a single sign-on (SSO) authentication scheme. When user 102 is authenticated by computer system 110, in the first step (1), computer system 110 can request access to one or more relining party applications 132 hosted on computer system 130, for example, one or more web applications. Computer system 130 receives the request and, in step 2, redirects the request to computer system 110 to authenticate the user or digital ID of user 102 via ID provider 122 hosted on computer system 120. Computer system 110 receives the redirected request and forwards the authentication request to, for example, ID provider (IdP) 122 hosted by computer system 120. As shown in FIG. 1, computer system 120 can be an ID provider (IdP) 122 configured to store and manage the digital IDs of one or more users 102. In step 4, ID provider (IdP) 122 can confirm the ID of user 102 by an authenticator via, for example, a combination of username and password, or other elements including biometric elements. Further, ID provider (IdP) 122 can authenticate any entity connected to a network or system, such as computer systems 110, 140. In particular, ID provider (IdP) 122 can be used for managing user IDs in a cloud computing environment.
[0020] According to one embodiment, when the user 102, or the user 102 and the computer system 110, are authenticated by the Identity Provider (IdP) 122, the computer system 120 associated with the Identity Provider (IdP) 122 can send an authentication token for step 4 (which can include, for example, a user ID and an authentication cookie 150) to the computer system 110 for the user 102 and / or the user 102 and the computer system 110. In step 5, the computer system 110 can send the authentication token 150 to the computer system 130 that hosts the web application 132, and in step 6, the computer system 110 associated with the user 102 can receive access to one or more relying party applications 132 hosted on the computer system 130.
[0021] FIG. 2 is a diagram of a system 200 for authenticating the user 102 in an exemplary embodiment. As described above, when the user 102 accesses one or more relying party applications 132 hosted on the computer system 130, the authentication token 150 is generated, for example, by the Identity Provider (IdP) 122 hosted on the computer system 120. However, the Identity Provider (IdP) 122 may be unreachable, such as being unable to generate the authentication token 150 by the Identity Provider (IdP) 122, and thus the user 102 and the corresponding computer system 110 may be unable to access one or more relying party applications 132 hosted on the computer system 130.
[0022] As shown in FIG. 2, according to the embodiment, when the user identification cookie and the authentication cookie are cached in the web browser of the computing device 110 of the user 102, the user 102 can be identified without redirecting the authentication request to the ID Provider (IdP) 122. However, the caching of the user identification cookie and the authentication cookie is not valid unless the cache is cleared in the computer system 110 of the user 102. Therefore, there is a method and a system for authenticating the user 102 regardless of the state of the ID Provider (IdP) 122, and it is desirable that the method and the system 200 always obtain the authentication token 150 from, for example, an external reliable source 210 with which the computer system 110 is communicating or connected.
[0023] The system 200 may include, for example, one or more computer systems 110, 120, 220, and the secure container 210. The one or more computer systems 110, 120, 220 can generate print data that can be used, for example, in personal computers, home security or office security systems within a home or office, servers, smartphones, smart tablets, cameras, routers, medical devices or equipment, multifunction peripherals (or printers), printers, print servers, or multifunction peripherals (MFP), and the like. According to one embodiment, one or more of the computer systems 110, 220 may include at least one authentication application (or authentication module) for receiving an authenticator and / or a biometric identifier 230 that can authenticate the user 102.
[0024] According to one embodiment, the authenticator can be, for example, one or more of a password or passcode and the biometric identifier 230. According to an exemplary embodiment, the biometric identifier 230 can include characteristic and measurable properties used to label, describe, or identify an individual, which includes metrics related to human characteristics. For example, the biometric identifier 230 can include an individual's physiological characteristics, which include, but are not limited to, fingerprints, palm veins, face recognition, DNA (i.e., deoxyribonucleic acid), palm prints, palm shapes, iris recognition, retina, and / or odor / aroma.
[0025] Once the user 102 is authenticated, the user 102 can access one or more of the computer systems 110, 120, 130 disclosed herein. At least one authentication application can be configured to receive an authenticator and / or a biometric identifier, for example, via a keypad, for a username and password (password), and / or for a sensor, scan device, or an electronic reader capable of reading and / or obtaining data such as, for example, a proximity card, RFID card, smart card, wearable device, RSA token, and / or a biometric identifier. The one or more computer systems 110, 120, 130 can be accessed by the user 102 via at least one authenticator and / or biometric identifier 230, preferably via at least two or more authenticators and / or biometric identifier 230.
[0026] According to one embodiment, the computer system 110 can be incorporated into a home or office security system, which can include, for example, a method or system for authenticating a user 102 accessing a home or office via a door to a building, a floor or room of a home or office, such as an elevator and / or other secure rooms. Also, the methods and systems disclosed herein can be used for security protection of security systems within a user's home or office, devices such as computers, etc.
[0027] According to an exemplary embodiment, the secure container 210 is, for example, an executable software package or application that is isolated from other software packages or applications running on one or more computer systems 110. The secure container 210 is configured, for example, as shown in FIG. 1, for the containerization (or sandboxing) of authentication tokens such as user identification and authentication cookies 150 received from the computer system 130. The secure container 210 can be a trusted platform module (TPM), for example, a secure cryptographic processor or a dedicated microcontroller that protects the hardware with integrated cryptographic keys. According to one embodiment, the trusted platform module (TPM) can be a computer chip compliant with a standard. For example, Windows 11 includes a trusted platform module 2.0 (TPM 2.0), which is designed to enhance security against, for example, firmware and ransomware attacks. According to an exemplary embodiment, the secure container 210 can be a universal serial bus (USB) drive or a secure digital (SD) card. According to one embodiment, it is desirable for the secure container to be a USB drive or SD card that encrypts the stored data before writing it to the USB drive or SD card and decrypts it after reading. For example, symmetric encryption algorithms (such as AES, Twofish, Triple DES, etc.) and asymmetric encryption algorithms (such as RSA, etc.) can be used for the encryption and decryption of USB drives and SD cards. According to another embodiment, the secure container 210 can be a secure external drive. For example, the secure container 210 can be a computer system such as a mobile device or a smartphone.
[0028] According to one embodiment, the system 200 can be configured to secure the authentication token 150 within the secure container 210 in the user 102's computer system 110. However, instead of storing the authentication token 150 within the secure container 210 in the user 102's computer system 110, it may be desirable for the secure container 210 to be an external drive.
[0029] According to one embodiment, the authentication token 150 can be, for example, a time-based authentication token, which needs to be updated after a predetermined period as shown in FIG. 1. Alternatively, the authentication token 150 can require an update based on the number of uses, or a combination of a predetermined period and the number of uses or login times. Further, the authentication token 150 can include restrictions on one or more types of computer systems 110 on which the authentication token 150 can be used. For example, the authentication token 150 may not be able to be used with computer systems 110 such as mobile terminals or smartphones.
[0030] As shown in FIG. 2, the user 102 is authenticated, for example, by using a single sign-on (SSO) method that includes at least a biometric identifier in the computer system 110. For example, the user 102 can be authenticated via a computer system 220, such as a mobile device that provides access to the computer system 110. Alternatively, the computer system 110 can authenticate the user 102 by using, for example, a wearable device 222 that uses biometric technology. Biometric technology can include, for example, verifying the authenticity based on the physical characteristics (biometric information) of each user 102. For example, the user can be authenticated by their unique electrocardiogram based on the biometric information of the wearable device 222.
[0031] As disclosed herein, when user 102 is authenticated by computer system 110, in a first step (1) 160, computer system 110 can request access to one or more relining party applications 132 hosted on computer system 130 with an authentication token 150 obtained from secure container 210. Computer system 130 receives the request with the authentication token 150, and in step 2, 162, computer system 110 associated with user 102 can receive access to one or more web applications 132 hosted on computer system 130. According to one embodiment, computer system 130 can be a cloud computing configuration that distributes another web application 132 across one or more cloud computers.
[0032] Figures 3A and 3B are the flowchart 300 of the authentication of user 102 in the embodiment shown in FIG. 2. As shown in FIGS. 3A and 3B, it starts from step 302. In step 304, after user 102 is authenticated, for example, based on the biometric identifier 330, the computer system 110 can send an authentication request for the authentication token 150 to the secure container 210 using the single sign-on (SSO) method on the computer system 110. The secure container 210 can communicate with the computer system 110 via, for example, a communication protocol, and / or the secure container 210 can be physically connected to the computer system 110. In step 306, the computer system 110 obtains user authentication information including the authentication token 150 from the secure container 210 during communication or from the secure container 210 connected to the computer system 110. In step 308, the computer system 110 discriminates the user authentication information obtained from the secure container 210 within the computer system 110 of user 102, or the user authentication information obtained from the secure container 210, for example, the user authentication information obtained from a USB drive or an SD drive. For example, for the ID confirmation of user 102 who attempts to obtain an authentication token, user authentication information is used to perform user ID confirmation (proving who the user is), authentication (proving that the user is the user who claims to be), and authorization (proving that what the user is attempting to do is permitted). For example, the user authentication information can include additional authentication factors by combining unique identifiers such as the biometric identifier 330 and the user ID based on knowledge (something only user 102 knows), possession (something only user 102 has), and uniqueness (something that is only user 102) for two-factor authentication (2FA) or multi-factor authentication (MFA). For example, the additional authentication factor can be a password, or information regarding a physical object or the environment can be requested from user 102.The determination of the verification of the authentication information obtained from the secure container 210 may include determining whether the authentication token 150 is still valid and / or whether the authentication token 150 provides the user 102 with access to one or more relining party applications 132 hosted on the computer system 130.
[0033] In step 310, one or more relining party applications 132 verify the user authentication information of the authentication token received from the computer system 110. When the user authentication information is verified, in step 312, the computer system 110 of the user 102 can access one or more relining party applications 132 hosted on the computer system 130. According to one embodiment, in step 308, if the computer system 110 determines that the user authentication information is invalid, the process proceeds to step 314, where the computer system 110 can register user information from the user browser, and in step 316, an authentication request from the browser of the computer system 110 is sent to the ID provider (IdP) 122 (Figure 1). In step 318, if the user information is correct, the ID provider (IdP) 122 generates a user token (or authentication token) 150 and sends it to the computer system 110. In step 320, the computer system determines whether the user information of the user token (or authentication token) 150 is valid. If the user information is not valid in step 320, the process returns to step 314. If the user information is valid, the process proceeds to step 322, where the authentication token 150 is stored in the secure container 210, and the user authentication is set and updated in the secure container 210.
[0034] FIG. 4 is a flowchart of a method 400 for user authentication to access a Web application in an embodiment. As shown in FIG. 4, method 400 includes, at step 410, a user identifier and a biometric identifier 230 of user 102 being received by a processor along with an access request to one or more relining party applications 132. At step 420, the user identifier of user 102 and the biometric identifier 230 are verified by the processor in connection with an access request to one or more relining party applications 132. At step 430, an authentication token 150 of user 102 is obtained by the processor from an external trusted source 210. At step 440, the authentication token 150 of user 102 obtained from the external trusted source 210 is transferred by the processor to one or more relining party applications 132. At step 450, authentication from one or more relining party applications 132 for user 102 to access one or more relining party applications 132 is received on the processor.
[0035] According to one embodiment, the authentication token 150 is always obtained from an external trusted source 210 so that the user can access one or more relining party applications 132. When the processor is communicating with the ID service provider 122, the authentication token 150 is obtained from the external trusted source 210, and when not communicating with the ID service provider 122, the ID service provider 122 is configured to provide the authentication token 150.
[0036] According to one embodiment, a method includes replacing, by a processor, an authentication token 150 of an external trusted source 210 with an updated authentication token after a predetermined time period has elapsed or after a predetermined number of logins by a user 102. According to one embodiment, when the authentication token 150 of the user 102 cannot be obtained from the external trusted source 210, the processor requests an updated authentication token 152 of the user 102 from an ID service provider 122, the processor receives the updated authentication token 152 of the user from the ID service provider 122, and the processor transfers the updated authentication token 152 of the user 102 to the external trusted source 210. According to one embodiment, the method 200 may further include, for example, as needed, the processor requesting access for the user 102 to one or more relogging party applications 132, and the processor receiving a redirection request from the one or more relogging party applications 132 to obtain an updated authentication token 152 for the user 102 from the ID service provider 122.
[0037] According to one embodiment, the authentication token 150 of the user 102 is not obtained from the cache of the user browser of the computer system with the processor. The external trusted source 210 can be a secure container, for example, the secure container can be a Universal Serial Bus (USB) device or a Secure Digital (SD) card. The external trusted source 210 can be a secure external drive.
[0038] According to one embodiment, the method includes receiving, by a processor, a biometric identifier 230 from a biometric device, such as a computer system 220, where the biometric device includes one or more of a sensor, a scanning device, or an electronic reader, and the biometric identifier is at least one physiological characteristic of the user, and the at least one physiological characteristic is selected from fingerprints, palm veins, face recognition, DNA (deoxyribonucleic acid), palm prints, palm shapes, iris recognition, retina, and / or odor / aroma.
[0039] According to one embodiment, the biometric authentication device is a first mobile device, and is configured to communicate with a second mobile device such as a computer system 110 configured to host a processing server, for example.
[0040] According to one embodiment, the method further includes obtaining, by a processor, one or more of a period setting to an external trusted source 210 and a login setting of the number of login times of the user to the external trusted source 210 from an application for setting a period of the user, determining, based on the period setting or the login setting, the validity of an authentication token 150 of the external trusted source 210 for the user 102, and transferring, by the processor, the authentication token 150 of the user 102 to the external trusted source 210 when the period setting or the login setting is not exceeded by the user 102. According to one embodiment, the application sets a period setting for the user to an external trusted source 210, and sets the number of login times for the user 102 to the external trusted source 210 on the computer system 110.
[0041] According to one embodiment, the processor is part of a multifunctional peripheral device, and the method includes, by the processor, requesting one or more additional authentication elements from the user for multi-factor authentication of the user for access to the multifunctional peripheral device and for obtaining an authentication token of the user from an external trusted source and access to one or more relaying party applications 122.
[0042] FIG. 5 illustrates a representative computer system 500, and embodiments of the present disclosure, or portions thereof, can be implemented as computer-readable code executed on hardware. For example, one or more computer systems 110, 120, 130 related to the user authentication methods and systems disclosed herein can be implemented in whole or in part by a computer system 500 using hardware, software executed on the hardware, firmware, a non-transitory computer-readable medium storing instructions, or a combination thereof, and can be executed on one or more computer systems or other processing systems. Hardware, software executed on the hardware, or a combination thereof can implement the modules and components used to perform the methods and steps of the currently described methods and systems.
[0043] When using programmable logic, such logic is executed on a commercially available processing platform configured by executable software code and can be a special-purpose computer or a special-purpose device (e.g., a programmable logic array, an application-specific integrated circuit, etc.). Those skilled in the art will understand that embodiments of the disclosed subject matter can be practiced in a variety of computer system configurations, including multi-core multiprocessor systems, minicomputers, mainframe computers, computers linked or clustered with distributed functions, and pervasive or miniature computers that can potentially be embedded in virtually any device. For example, at least one processor device and one memory can be used to implement the foregoing embodiments.
[0044] The processor units or devices described in this book are a single processor, multiple processors, or combinations thereof. A processor device may have one or more processor "cores". The terms "computer program medium", "non-transitory computer-readable medium", and "computer-usable medium" described in this book are generally used to refer to tangible media such as removable storage device 518, removable storage device 522, and the hard disk attached to hard disk drive 512.
[0045] Various embodiments of the present disclosure will be described with respect to this representative computer system 500. Reading this specification, it will be apparent to those skilled in the relevant art how to implement the present disclosure using other computer systems and / or computer architectures. The operations are described as sequential processes, but in practice, some operations are performed in parallel, simultaneously, and / or in a distributed environment, and the program code is stored locally or remotely for access from a single-processor or multi-processor machine. Also, in some embodiments, the order of operations may be reconfigured without departing from the spirit of the disclosed subject matter.
[0046] The processor device 504 may be a processor device specially configured to execute the functions described in this document. The processor device 504 may be connected to a communication infrastructure 506 such as a bus, message queue, network, multi-core message passing scheme, etc. The network may be any network suitable for executing the functions disclosed herein, including a local area network ("LAN"), wide area network ("WAN"), wireless network ("Wi-Fi"), mobile communication network, satellite network, Internet, optical fiber, coaxial cable, infrared, radio frequency ("RF"), or a combination thereof. Other suitable network types and configurations will be apparent to those skilled in the relevant art. The computer system 500 may include a main memory 508 (e.g., random access memory, read-only memory, etc.), and may also include a secondary memory 510. The secondary memory 510 may include a hard disk drive 512 and a removable storage drive 514 such as a floppy disk drive, magnetic tape drive, optical disk drive, flash memory, etc.
[0047] The removable storage drive 514 can read and / or write to a removable storage device 518 in a well-known manner. The removable storage device 518 may include a removable storage medium that is read and written by the removable storage drive 514. For example, if the removable storage drive 514 is a floppy disk drive or a universal serial bus port, the removable storage device 518 may be a floppy disk or a portable flash drive, respectively. In one embodiment, the removable storage device 518 may be a non-transitory computer-readable recording medium.
[0048] In some embodiments, the secondary memory 510 may include alternative means for enabling a computer system 500 to load computer programs and other instructions, such as, for example, a removable storage device 522 and an interface 520. Examples of such means include, as will be apparent to those skilled in the relevant art, a program cartridge and a cartridge interface (such as those found in video game systems), a socket associated with a removable memory chip (such as EEPROM, PROM, etc.), and other removable storage devices 522 and interfaces 520.
[0049] Data stored in the computer system 500 (e.g., stored in the main memory 508 and / or the secondary memory 510) can be stored on a suitable computer-readable medium such as an optical storage device (e.g., compact disk, digital versatile disk, Blu-ray disk) or a magnetic storage device (e.g., hard disk drive). The data can be configured in any suitable database configuration, such as a relational database, a structured query language (SQL) database, a distributed database, an object database, etc. Suitable configurations and types of storage will be apparent to those skilled in the relevant art.
[0050] The computer system 500 may also include a communication interface 524. The communication interface 524 may be configured to transfer software and data between the computer system 500 and an external device. Exemplary communication interfaces 524 may include a modem, a network interface (e.g., Ethernet card), a communication port, a PCMCIA slot and card, etc. The software and data transferred via the communication interface 524 may be in signal form and may be electronic, electromagnetic, optical, or other signals apparent to those skilled in the relevant art. The signals may be transmitted via a communication path 526 and may be implemented using wires, cables, fiber optics, telephone lines, cellular phone links, radio frequency links, etc., configured to transmit the signals.
[0051] The computer system 500 may further include a display interface 502. The display interface 502 may be configured to transfer data between the computer system 500 and an external display 530. Exemplary display interfaces 502 may include a High-Definition Multimedia Interface (HDMI), a Digital Visual Interface (DVI), a Video Graphics Array (VGA), and the like. The display 530 may be any type of display suitable for displaying data transmitted via the display interface 502 of the computer system 500, such as a cathode ray tube (CRT) display, a liquid crystal display (LCD), a light emitting diode (LED) display, a capacitive touch display, a thin film transistor (TFT) display, and the like. Computer program media and computer-usable media may refer to memories such as main memory 508 and secondary memory 510, which may be memory semiconductors (such as DRAM). These computer program products may be means for providing software to the computer system 500. A computer program (e.g., computer control logic) may be stored in main memory 508 and / or secondary memory 510. The computer program may also be received via the communication interface 524. When such a computer program is executed, the computer system 500 may be enabled to execute the current method as described herein. In particular, when the computer program is executed, the processor device 504 may be enabled to execute the methods shown in FIGS. 1 to 4 described herein. Accordingly, such a computer program represents the control device of the computer system 500. If the present disclosure is implemented using software executed on hardware, the software is stored in a computer program product and loaded into the computer system 500 using a removable storage drive 514, an interface 520, and a hard disk drive 512, or a communication interface 524.
[0052] The processor device 504 may be composed of one or more modules or engines configured to execute the functions of the computer system 500. Each module or engine can be executed using hardware and, in some cases, can also utilize software executed on the hardware, such as program code stored in the main memory 508 or the secondary memory 510 and / or corresponding to the program. In such a case, the program code may be compiled by the processor device 504 (e.g., by a compilation module or engine) before being executed by the hardware of the computer system 500. For example, the program code can be source code written in a programming language that has been translated into a lower-level language such as assembly language or machine code so as to be executed by the processor device 504 and / or additional hardware components of the computer system 500. The process of compilation may include lexical analysis, preprocessing, syntax analysis, semantic analysis, syntactic-directed translation, code generation, code optimization, and the use of other techniques suitable for translating the program code into a low-level language suitable for controlling the computer system 500 to execute the functions disclosed herein. It will be apparent to those skilled in the relevant art that the computer system 500 becomes a computer system 500 specially programmed to execute the functions described above.
[0053] Techniques consistent with the present disclosure provide, among other things, methods and systems for user authentication. Various exemplary embodiments of the disclosed systems and methods have been described above, but these are to be understood as illustrative only and not limiting. They are not exhaustive and are not limited to the exact forms disclosed. Modifications and changes are possible in light of the above teachings or can be obtained from the practice of the disclosure without departing from the scope or range.
Claims
1. A user authentication method for accessing a web application, receiving, by a processor, a user identifier and a biometric identifier of a user together with an access request to one or more relining party applications; verifying, by the processor, the user identifier and the biometric identifier of the user associated with the access request to the one or more relining party applications; obtaining, by the processor, an authentication token of the user from an external reliable source; transferring, by the processor, the authentication token of the user obtained from the external reliable source to the one or more relining party applications; receiving, on the processor, authentication from the one or more relining party applications for the user to access the one or more relining party applications, comprising: when the authentication token of the user cannot be obtained from the external reliable source, requesting, by the processor, an updated authentication token of the user from an ID service provider; receiving, by the processor, the updated authentication token of the user from the ID service provider; further comprising transferring, by the processor, the updated authentication token of the user to the external reliable source.
2. The method according to claim 1, wherein the authentication token is always obtained from the external reliable source for the user to access the one or more relining party applications.
3. The method according to claim 1 or 2, wherein the processor is configured to obtain the authentication token from the external trusted source whether or not it is communicating with the ID service provider configured to provide the authentication token.
4. The method according to claim 1 or 2, further comprising replacing, by the processor, the authentication token of the external trusted source with an updated authentication token after a predetermined time has elapsed or after a predetermined number of logins by the user.
5. The method according to claim 1 or 2, wherein the authentication token of the user is not obtained from the cache of the user browser of the computer system with the processor.
6. The method according to claim 1 or 2, wherein the external trusted source is a secure container.
7. The method according to claim 6, wherein the secure container is a Universal Serial Bus (USB) device or a Secure Digital (SD) card.
8. The method according to claim 1 or 2, wherein the external trusted source is a secure external drive.
9. The method further comprising receiving, by the processor, the biometric identifier from a biometric device, wherein the biometric device includes one or more of a sensor, a scanning device, or an electronic reader, and the biometric identifier is at least one physiological characteristic of the user, and the at least one physiological characteristic is selected from one or more of fingerprint, palm vein, face recognition, DNA (deoxyribonucleic acid), palmprint, palm shape, iris recognition, retina, and / or odor / aroma.
10. The method according to claim 9, wherein the biometric authentication device is a first mobile device configured to communicate with a second mobile device configured to host a processing server including the processor. **Claim 11** Obtaining, by the processor, one or more of a period setting to an external trusted source and a login setting of the number of login times of the user to the external trusted source from an application for setting a period of the user, wherein the period setting or the login setting determines validity of the authentication token of the external trusted source based on the period setting or the login setting of the user, The method according to claim 1 or 2, further comprising: transferring, by the processor, the authentication token of the user to the trusted source when the user has not exceeded the period setting or the login setting. **Claim 12** The processor is part of a multifunctional peripheral device, The method according to claim 1 or 2, comprising: requesting, by the processor, one or more additional authentication elements from the user for multi-factor authentication of the user for access to the multifunctional peripheral device and for obtaining an authentication token of the user from the external trusted source and access to the one or more relaying party applications. **Claim 13** A computer program product for user authentication for accessing a web application, Comprising a non-transitory computer-readable storage medium having program instructions to be executed therein, the program instructions being executable by a computer, and causing the computer to Receive a user identifier and a biometric authentication identifier of a user together with an access request to one or more relaying party applications, Verifying the user identifier and the biometric identifier of the user associated with the access request to the one or more relining party applications; Obtaining an authentication token of the user from an external reliable source; Transferring the authentication token of the user obtained from the external reliable source to the one or more relining party applications; Receiving, from the one or more relining party applications, authentication for the user to access the one or more relining party applications; comprising; If the authentication token of the user cannot be obtained from the external reliable source, requesting an updated authentication token of the user from an ID service provider; receiving the updated authentication token of the user from the ID service provider; transferring the updated authentication token of the user to the external reliable source. A computer program product that further comprises a method for causing the execution of the above.
14. The computer program product according to claim 13, wherein the authentication token is always obtained from the external reliable source for the user to access the one or more relining party applications.
15. The computer program product according to claim 13 or 14, wherein the computer is configured to obtain the authentication token from the external reliable source whether or not it is communicating with the ID service provider configured to provide the authentication token.
16. The computer program product according to claim 13 or 14, further comprising replacing the authentication token of the external reliable source with an updated authentication token after a predetermined period of time has elapsed or after a predetermined number of logins by the user.
17. A user authentication system for accessing a web application, receiving a user identifier and a biometric identifier of a user together with an access request to one or more relaying party applications, verifying the user identifier and the biometric identifier of the user associated with the access request to the one or more relaying party applications, obtaining an authentication token of the user from an external reliable source, transferring the authentication token of the user obtained from the external reliable source to the one or more relaying party applications, configured to receive authentication for the user to access the one or more relaying party applications from the one or more relaying party applications, if the authentication token of the user cannot be obtained from the external reliable source, requesting an updated authentication token of the user from an ID service provider, receiving the updated authentication token of the user from the ID service provider, A system comprising a processor configured to transfer the updated authentication token of the user to the external reliable source.
18. The system according to claim 17, wherein the authentication token is always obtained from the external reliable source for the user to access the one or more relaying party applications.
Citation Information
Patent Citations
Authentication system, authentication method and computer program
JP2005346570A
Single login control method using portable medium, recording medium with program for realizing it stored therein, and device
JP2006073029A
Authentication system and authentication method
JP2008009644A
Method and system for extending authentication methods
JP2009519529A
Techniques for operating services with machine-generated authentication tokens
JP2017517823A