Data circulation system, connector device, and user authentication method

The data circulation system addresses the vulnerability of existing user authentication methods to impersonation by utilizing telephone communication services for secure identity verification through the data linkage infrastructure and connector devices, achieving reliable and cost-effective authentication.

JP7695435B1Active Publication Date: 2025-06-18NTT DOCOMO BUSINESS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024042674
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-18
Publication Date
2025-06-18
Estimated Expiration
2044-03-18

Smart Images

  • Figure 0007695435000001_ABST
    Figure 0007695435000001_ABST
Patent Text Reader

Abstract

Preventing impersonation and enabling highly reliable user authentication without imposing much labor or cost burden on service providers and users. 【Solution】In one aspect of the present invention, when performing data transmission using a data space by a connector device among users, the connector device stores user information of each user attempting to perform the above data transmission in a state including subscriber information assigned from the telephone communication carrier of the destination of subscription for the user. Further, each connector device is provided with an incoming / outgoing call function using the above subscriber information. Then, when performing data transmission among the above users, the connector devices transmit and receive user information including the subscriber information of the user on the other side to each other using the above incoming / outgoing call function, and authenticate the user of the communication partner by comparing the transmitted user information of the other side with the previously stored user information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] One aspect of the present invention relates to a data distribution system that distributes data using a data linkage platform, for example, between companies or industries, and a connector device and a user authentication method used in the data distribution system. [Background technology]

[0002] In recent years, a data sharing platform (hereafter referred to as data space) has been proposed that allows the mutual distribution of unique data held by multiple companies or industries, either domestic or international, that make up a supply chain. By using this data sharing platform, it becomes possible to efficiently collect and manage data on goods, such as products and parts, that are stored in a distributed manner across multiple companies, and data on services.

[0003] However, to use the data sharing platform safely, it is essential to authenticate users. Therefore, a technology has been proposed that prevents unauthorized access to the data sharing platform and enables safe distribution of data by connecting a user terminal and the data sharing platform via a connector device called a data space connector and executing an authentication procedure in the connector device (see, for example, Non-Patent Document 1). [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] “Prototype platform for interconnection with the core technology “IDS Connector” of the European “GAIA-X””, NTT Communications Corporation, April 8, 2021, Internet<URL: https: / / www.ntt.com / about-us / press-releases / news / article / 2021 / 0408.html> Summary of the Invention [Problem to be solved by the invention]

[0005] However, the user authentication method described in Non-Patent Document 1 is a method of managing and authenticating by associating the user ID issued by the operator of the data linkage infrastructure and the user ID issued by an external ID provider with the connector number of each user. Therefore, if someone copies the software that operates the connector device or the user ID and pretends to be a legitimate user, there is a risk that the data will be illegally stolen.

[0006] Also, to prevent such impersonation, for example, a new trust infrastructure or authentication system needs to be constructed, and troublesome procedures and management systems such as strict trust reviews are required. In this case, a great deal of labor and cost burden is imposed on the operator of the data linkage infrastructure and the users.

[0007] This invention has been made paying attention to the above circumstances, and aims to provide a technology that enables highly reliable user authentication by preventing impersonation without imposing a great deal of labor and cost burden on the operator and the users.

Means for Solving the Problems

[0008] In order to solve the above problems, one aspect of the data circulation system and its user authentication method according to this invention is that data transmission is performed via a data linkage infrastructure between a plurality of connector devices used by users, and the connector device and the data linkage infrastructure make telephone calls with each other by using the subscriber information assigned from the telephone communication carrier of the destination to make outgoing and incoming calls. In a data circulation system, Each of the plurality of connector devices stores its own user information including the subscriber information assigned to its own connector device in its own information storage unit, and stores the user information of the other party including the subscriber information assigned to the connector device on the other side of the data transmission in the other party information storage unit.

[0009] In this state, the first connector device, which is the requesting side of the data transmission, transmits communication request information including its own user information stored in the self-information storage unit to the second connector device, which is the receiving side of the data transmission, via the telephone communication using the incoming and outgoing calls. On the other hand, when the second connector device receives the communication request information, it collates the user information of the first connector device included in the received communication request information with the user information of the other party stored in the other-party information storage unit, determines the validity of the received user information, and when it is determined that the received user information is valid, transmits communication response information including the user information of the second connector device stored in the self-information storage unit to the first connector device via the telephone communication. The first connector device that has received the communication response information collates the user information of the second connector device included in the communication response information with the user information of the second connector device stored in the other-party information storage unit to determine the validity of the received second user information.

[0010] According to one aspect of the present invention, the following operational effects can be achieved. That is, the telephone communication services constructed by telephone communication operators in each country in accordance with international standards and laws provide services that are virtually impossible to impersonate by verifying the identity of users and strictly managing and authenticating their subscriber information (e.g., telephone numbers).

[0011] Therefore, by using the incoming and outgoing call function of the telephone communication service as described above for user authentication, the operating operator can prevent impersonation without newly constructing a large-scale authentication system and without having the user go through troublesome procedures related to credit checks, etc., and thereby can reliably identify and authenticate the communication partner.

Effects of the Invention

[0012] That is, according to one aspect of the present invention, it is possible to provide a technology that enables highly reliable user authentication by preventing impersonation without causing much labor or cost burden on the operating operator and the user.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0015] [One Embodiment] (Configuration Example) (1) System FIG. 1 is a diagram showing an example of the configuration of a data distribution system according to an embodiment of the present invention.

[0016] In FIG. 1, NW indicates an international network including a data cooperation infrastructure. The data cooperation infrastructure is also called a data space, and the data space is managed by a data space management device DSM installed by its operator.

[0017] In the above network NW, user terminals UTa, UTb,..., UTk used by industries, companies, or individuals in each country who wish to use the above data space are connected via connector devices CNa, CNb,..., CNk called data space connectors, respectively.

[0018] In addition, the network NW includes telephone communication networks operated by telephone communication carriers in each country. Each telephone communication network is managed by station devices TEx, TEy, TEz installed by each telephone communication carrier. The station devices TEx, TEy, TEz each include user databases SDx, SDy, …, SDz. In the user databases SDx, SDy, …, SDz, for example, telephone numbers assigned as subscriber information to users who have joined the telephone communication network are securely stored and managed as user information in a state associated with identification information (for example, a corporate number) for verifying the identity of the users. Note that the administrator of the data space has also joined the telephone communication network of their own country, and the telephone number is stored in the user database of the destination telephone communication carrier.

[0019] (2) Device (2-1) Connector devices CNa, CNb, …, CNk Figures 2 and 3 are block diagrams showing an example of the hardware configuration and software configuration of the connector devices CNa, CNb, …, CNk, respectively.

[0020] The connector devices CNa, CNb, …, CNk include a control unit 1 using a hardware processor such as a Central Processing Unit (CPU). A storage unit having a program storage unit 2 and a data storage unit 3, an IP communication interface (hereinafter abbreviated as interface I / F) unit 4, and a telephone communication I / F unit 5 are connected to the control unit 1 via a bus.

[0021] The IP communication I / F unit 4 transmits and receives data to and from a connector device that is the destination of data transmission via the network NW in accordance with a communication protocol defined in the IP network, and transmits and receives control information necessary for using the data space to and from the data space management device DSM.

[0022] The telephone communication I / F unit 5 transmits and receives information necessary for authenticating the connector device of the communication partner via the telephone communication network, between the connector device of the communication partner and the local devices TEx, TEy, …, TEz of the telephone communication carrier, respectively.

[0023] The program storage unit 2 is configured by combining, for example, a non-volatile memory such as an SSD (Solid State Drive) that can be written and read at any time as a storage medium and a non-volatile memory such as a ROM (Read Only Memory). In addition to middleware such as an OS (Operating System), it stores application programs necessary for executing various control processes according to one embodiment. Hereinafter, the OS and each application program are collectively referred to as a program.

[0024] The data storage unit 3 is, for example, a combination of a non-volatile memory such as an SSD that can be written and read at any time as a storage medium and a volatile memory such as a RAM (Random Access Memory), and has a user management area 31 and a telephone communication carrier management area 32.

[0025] The user management area 31 is an area managed by the data space operation provider and the user, and has a self-ID storage unit 311 and a partner-ID storage unit 312. The self-ID storage unit 311 stores the user's own identification information (self-ID) used when the user uses the data space for data transmission. The partner-ID storage unit 312 stores the identification information (partner-ID) of the partner with whom data transmission is performed using the data space.

[0026] The telephone communication carrier management area 32 includes a telephone number storage unit 321. The telephone number storage unit 32 stores the telephone number assigned to the user as subscriber information from the telephone communication carrier to which the user subscribes.

[0027] The control unit 1 includes a user registration control processing unit 11, a communication partner registration control processing unit 12, a data transmission control processing unit 13, and an authentication control processing unit 14 as the processing functions necessary to implement one embodiment.

[0028] These processing units 11 to 14 are all realized by causing the hardware processor of the control unit 1 to execute the application programs stored in the program storage unit 2. Note that some or all of the above processing units 11 to 14 may be realized using hardware such as LSI (Large Scale Integration) or ASIC (Application Specific Integrated Circuit).

[0029] The user registration control processing unit 11 executes processing for registering the user's own user information necessary for the user to use the data space as the sender in the data space management device DSM.

[0030] The communication partner registration control processing unit 12 executes processing for registering the user information of the user who will be the communication partner destination in its own connector device when the user uses the data space to perform data transmission.

[0031] The data transmission control processing unit 13 establishes a communication link with the connector device of the communication partner destination and performs data transmission when performing data transmission using the data space with the connector device of the communication partner destination.

[0032] The authentication control processing unit 14 executes an authentication procedure with the communication partner destination in advance when performing data transmission with the connector device of the communication partner destination. As processing functions therefor, it includes a telephone communication control unit 141, a partner ID verification processing unit 142, and a telephone number validity confirmation processing unit 143.

[0033] The telephone communication control unit 141 uses the incoming and outgoing call functions of the telephone communication service to transmit and receive communication requests and access information with the connector device of the communication partner destination.

[0034] When the partner ID verification processing unit 142 receives a communication request from the connector device on the transmission side, it verifies the user information included in the communication request with the user information of the partner previously stored in the partner ID storage unit 312, and determines whether there is matching user information.

[0035] When the telephone number validity confirmation processing unit 143 receives the communication request, it inquires of the local devices of the telephone communication carriers to which both parties of the communication request source subscribe about the validity of the telephone number included in the user information of the request source included in the communication request.

[0036] Note that the details of the authentication procedure using the telephone communication control unit 141, the partner ID verification processing unit 142, and the telephone number validity confirmation processing unit 143 will be described in the operation example.

[0037] (2-2) Data Space Management Device DSM FIG. 4 and FIG. 5 are block diagrams showing an example of the hardware configuration and software configuration of the data space management device DSM, respectively.

[0038] Similar to the connector device, the data space management device DSM also includes a control unit 6 using a hardware processor such as a central processing unit (CPU). Then, a storage unit having a program storage unit 7 and a data storage unit 8, a telephone communication I / F unit 9, and an IP communication I / F unit 10 are connected to the control unit 6 via a bus.

[0039] The telephone communication I / F unit 9 transmits and receives information for verifying the user's telephone number via the telephone communication network with the local devices TEx, TEy,..., TEz of the telephone communication carrier.

[0040] The IP communication I / F unit 10 transmits and receives requests related to user registration and notifications of registration results via the IP network with the user's connector devices CNa, CNb,..., CNk, and also transmits and receives requests for verifying communication permission and their responses.

[0041] The program storage unit 7 is configured by combining, for example, a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium and a non-volatile memory such as a ROM. In addition to middleware such as an OS, it stores application programs necessary for executing various control processes according to one embodiment. Hereinafter, the OS and each application program are collectively referred to as a program.

[0042] The data storage unit 8 is, for example, a combination of a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium and a volatile memory such as a RAM. As the main storage unit necessary for implementing one embodiment, it includes a user information storage unit 81 and a telephone number storage unit 822.

[0043] The user information storage unit 81 stores the user information in association with a telephone number for all users who have registered with the data space.

[0044] The telephone number storage unit 82 stores the telephone number assigned to the data space management device DSM by the telephone communication carrier to which the data space management device DSM subscribes.

[0045] The control unit 6 includes a user registration reception processing unit 61 and a user-to-user registration relay processing unit 62 as processing functions necessary for implementing one embodiment.

[0046] The above processing units 61 and 62 are both realized by causing the hardware processor of the control unit 6 to execute the application programs stored in the program storage unit 7. Note that part or all of the above processing units 61 and 62 may be realized using hardware such as an LSI or an ASIC.

[0047] When the user registration reception processing unit 61 receives a user registration request from the user's connector devices CNa, CNb, …, CNk, it requests the local devices TEx, TEy, …, TEz of the telephone communication carrier to which the requesting user subscribes to confirm the user's telephone number via the telephone communication network. Then, when it receives a reply indicating that the telephone number matches the confirmation request, it stores the user information of the user in the user information storage unit 81.

[0048] When the user - to - user registration relay processing unit 62 receives a communication permission request from the connector device used by the transmitting - side user, it transfers the request to the connector device used by the receiving - side user. Also, when a reply result to the request is returned from the connector device used by the receiving - side user, it transfers the reply result to the connector device used by the transmitting - side user.

[0049] (Operation example) Next, an operation example of the data distribution system configured as described above will be described.

[0050] Here, for example, as shown in FIG. 6, when data transmission is performed between the transmitting - side user A (also referred to as the sender A) and the receiving - side user B (also referred to as the receiver B) via the data space, the processes of registering users A and B in the data space management device DSM, registering the communication partner users B and A in their respective connector devices DNa and DNb, executing an authentication procedure using the telephone number with the communication partner user prior to data transmission, and performing data transmission between users A and B after authentication will be described respectively.

[0051] (1) Process of registering users A and B in the data space management device DSM (1 - 1) Registration of user A FIG. 7 is a sequence diagram showing an example of the procedure and processing content of the user registration process of user A executed between the connector device CNa used by user A and the data space management device DSM.

[0052] When user A performs a registration request operation for their own user registration on the user terminal UTa, in response to the registration request operation, the connector device CNa transmits a request for user registration from the IP communication I / F unit 4 to the data space management device DSM under the control of the user registration control processing unit 11. For example, the corporate number of the affiliated company, which is one of the attribute information of user A, and the telephone number assigned as subscriber information from the telephone communication carrier to user A are inserted into the above registration request. Note that as the attribute information of the user, information identifying the industry or place of residence to which the user belongs may be used instead of or in addition to the corporate number.

[0053] On the other hand, when the data space management device DSM receives the above request via the IP communication I / F unit 10, under the control of the user registration reception processing unit 61, first, based on the corporate number and telephone number of user A included in the above request, a confirmation request for user A is transmitted from the telephone communication I / F unit 9 to the local device TEx of the telephone communication carrier to which user A subscribes.

[0054] When receiving the above confirmation request, the local device TEx of the telephone communication carrier collates the telephone number and corporate number of user A included in the confirmation request with the user information stored in the user database SDx to determine whether they match. Then, the local device TEx returns the above determination result to the data space management device DSM.

[0055] When the data space management device DSM confirms that the telephone number and corporate number of user A match according to the above determination result, under the control of the user registration reception processing unit 61, it issues a connector number to the connector device CNa used by user A, and generates user information with the connector number added to the above telephone number and corporate number. Then, the generated user information of user A is stored in the user information storage unit 81.

[0056] FIG. 11 shows an example of the user information stored in the user information storage unit 81. In this example, a telephone number, a corporate number, and a connector number are stored in association with the name of the user, and information indicating the user's usage location is also stored.

[0057] When the registration process of the above user information is completed, the user registration reception processing unit 61 transmits a registration completion notification including the connector number of the connector device CNa and the corporate number of the user A from the IP communication I / F unit 10 to the connector device CNa of the user A, the request source.

[0058] When the connector device CNa receives the above registration completion notification, under the control of the user registration control processing unit 11, it stores the corporate number and the connector number of the user A included in the received registration completion notification in the self-ID storage unit 311.

[0059] Note that when the data space management device DSM receives a request from the connector device CNa, it may make a call to the user A using the telephone number included in the request, and determine the validity of the telephone number of the user A, that is, the life or death of the telephone number, based on the response result of the user A to this call.

[0060] (1-2) Registration of User B The user registration of the user B is also performed in the same procedure as the user registration process of the above user A.

[0061] FIG. 8 is a sequence diagram showing an example of the procedure and processing content of the user registration process of the above user B executed between the connector device CNb used by the user B and the data space management device DSM.

[0062] That is, in response to the registration request operation of the user terminal UTb, a request for registering the user B is sent from the connector device CNb to the data space management device DSM via the IP communication network. The corporate number and the telephone number of the user B are inserted into the above registration request.

[0063] On the other hand, when the data space management device DSM receives the above registration request via the IP communication I / F unit 10, based on the corporate number and phone number of user B included in the above registration request, it sends a confirmation request for user B from the phone communication I / F unit 9 to the local device TEz of the phone communication carrier with which user B subscribes.

[0064] The local device TEz of the phone communication carrier collates the phone number and corporate number of user B included in the confirmation request with the user information stored in the user database SDz to confirm whether they match. Then, the local device TEz returns the above confirmation result to the data space management device DSM.

[0065] When the data space management device DSM confirms that the phone number and corporate number of user B match according to the above determination result, under the control of the user registration acceptance processing unit 61, it issues a connector number to the connector device CNb used by user B, and generates user information with the above connector number added to the above phone number and corporate number. Then, it stores the generated user information of user B in the user information storage unit 81.

[0066] In this case as well, for example, as shown in FIG. 11, in addition to the phone number, corporate number of user B, and the connector number of the connector device CNb, information indicating the usage location may be stored.

[0067] When the registration process of the above user information is completed, the data space management device DSM sends a registration completion notification including the connector number of the above connector device CNb and the corporate number of user B from the IP communication I / F unit 10 to the connector device CNb of user B, the request source.

[0068] When receiving the above registration completion notification, the connector device CNb stores the corporate number and connector number of user B included in the received above registration completion notification in its own ID storage unit 311.

[0069] Note that, also in this case, when the data space management device DSM receives a request from the connector device CNb, it makes a call to user B using the phone number included in the request, and determines the validity of the phone number of user B based on the response result of user B to this call, that is, determines whether the phone number is valid or not.

[0070] (2) Process of registering the users of the communication partners in their respective connector devices Prior to data transmission, users A and B execute a process of registering the user information of the user who will be the communication partner of data transmission in their respective connector devices CNa and CNb.

[0071] FIG. 9 is a sequence diagram showing an example of the processing procedure for registering the user information of each other's communication partners between the connector devices DNa and DNb of users A and B.

[0072] Now, for example, assume that user A performs an operation to request communication permission with user B on the user terminal UTa in order to perform data transmission with user B. In this case, the connector device CNa generates a request to request the above communication permission under the control of the communication partner registration control processing unit 12, and transmits the generated request from the IP communication I / F unit 4 to the data space management device DSM. At this time, the above request inserts the corporate number of the communication partner user B, the phone number, corporate number of user A himself / herself, and the connector number of the connector device CNa.

[0073] In response, when the data space management device DSM receives the above request by the IP communication I / F unit 10, under the control of the user registration relay processing unit 62, it identifies user B from the corporate number of the communication partner included in the received request, and transmits request information from the IP communication I / F unit 10 to the connector device CNb of the identified user B. The phone number, corporate number of the requesting user A, and the connector number of the connector device CNa are inserted into this request information.

[0074] When the connector device CNb of user B receives the above request information, under the control of the communication partner registration control processing unit 12, it presents the corporate number of the requesting user A included in the received request information to the user terminal UTb. In response, when user B permits it, the communication partner registration control processing unit 12 of the connector device CNb stores the telephone number, corporate number, and connector device of user A included in the above request information in the partner ID storage unit 312. Then, the communication partner registration control processing unit 12 returns response information indicating the result of the communication permission / denial to the data space management device DSM. At this time, in the response information, only in the case of communication permission, the telephone number, corporate number, and connector number of user A, together with the telephone number, corporate number, and connector number of the connector device CNb of user B, are inserted.

[0075] When the data space management device DSM receives the response information from the connector device CNb of user B, under the control of the user - to - user registration relay processing unit 62, it identifies the destination user A based on the telephone number, corporate number, and connector number of user A included in the above response information, and transmits the registration information of user B from the IP communication I / F unit 10 to the connector device CNa of the identified user A.

[0076] When the connector device CNa receives the above registration information, under the control of the communication partner registration control processing unit 12, it stores the telephone number, corporate number, and connector number of the partner user B included in the received registration information, and the connector number of the connector device CNb in the partner ID storage unit 312.

[0077] (3) Authentication processing of communication partner during data transmission For example, when trying to transmit (share) data between user A and user B, first, authentication processing of the communication partner is executed between the connector device DNa of user A and the connector device DNb of user B.

[0078] Figure 10 is a sequence diagram showing an example of the processing procedure of the authentication processing executed between the connector devices DNa and DNb, and the processing procedure of the subsequent data transmission processing.

[0079] When an operation for requesting data transmission to User B is performed on the terminal UTa of User A, the connector device DNa makes a call to the connector device DNB based on the phone number of User B under the control of the telephone communication control unit 141. When a telephone communication link is established with the connector device DNB, the telephone communication control unit 141 sends a request for opening a communication channel (e.g., a data sharing request) to the connector device DNB via the telephone communication link from the telephone communication I / F unit 5 using a voice signal such as a short message or a DTMF signal.

[0080] The above request for opening a communication channel is inserted with the phone number and corporate number of User A, the connector number of the connector device DNa used by User A, and the phone number of the destination User B, which are stored in the self-ID storage unit 311, the counterpart-ID storage unit 312, and the phone number storage unit 321, respectively.

[0081] On the other hand, when the authentication control processing unit 14 of the connector device DNB of User B receives the request message for opening a communication channel transmitted from the connector device DNa of User A on the calling side via the telephone communication I / F unit 5, first, under the control of the counterpart-ID verification processing unit 142, it verifies the phone number, corporate number, and connector number of User A included in the received request for opening a communication channel with the subscriber information of the communication counterpart stored in the counterpart-ID storage unit 312, and determines whether each number matches.

[0082] Next, the authentication control processing unit 14 sends the phone number and corporate number of the originator User A included in the received request for opening a communication channel to the local device TEx of the telephone communication carrier to which User A subscribes from the telephone communication I / F unit 5 under the control of the phone number validity confirmation processing unit 143. In response, the local device TEx verifies the phone number and corporate number of User A with the user information managed by the user database SDx, and confirms the validity of the corresponding phone number. Then, it returns information indicating the verification result (whether it matches or not) to the connector device DNB that made the inquiry. Note that the process of confirming the validity of the phone number of the sender does not necessarily have to be performed.

[0083] As a result of verifying the phone number, corporate number, and connector number of the above user A and confirming the identity of user A, the authentication control processing unit 14 of the connector device DNb first generates authentication information representing a password / cryptographic key / certificate for accessing the URL (Uniform Resource Locator) where the data of user B is stored and its expiration date, and stores the generated authentication information in the counterpart ID storage unit 312 in a state associated with user A.

[0084] Then, the authentication control processing unit 14 generates access information including the above access URL and the above authentication information for the phone number, corporate number, and connector number of user B, and transmits the generated access information from the phone communication I / F unit 5 to the connector device CNa of the originating user A using short message or voice under the control of the phone communication control unit 141.

[0085] Upon receiving the above access information, the connector device DNa, under the control of the authentication control processing unit 14, collates the phone number, corporate number, and connector number of user B included in the received access information with the user information of the communication counterpart stored in the counterpart ID storage unit 312 to check the validity of each number of user B. Then, if the authentication control processing unit 14 confirms the validity of the received phone number, corporate number, and connector number of user B through the above check, it notifies the data transmission control processing unit 13 of the confirmation result.

[0086] (4) Data transmission processing When the legitimacy of users A and B is confirmed through the above authentication process, the following data transmission process is executed between the connector device DNa of user A and the connector device DNb of user B.

[0087] That is, first, in response to the access operation of user A on user terminal TEa, the data transmission control processing unit 13 of connector device DNa generates a data sharing request and transmits the generated data sharing request from IP communication I / F unit 4 to connector device DNB of user B. The above data sharing request is inserted with the access destination URL included in the access information sent from user B, the password / cryptographic key / certificate for accessing the URL, the data type of the request target, and the like.

[0088] On the other hand, when the data transmission control processing unit 13 of connector device DNB of user B receives the above data sharing request by IP communication I / F unit 4, it collates the password / cryptographic key / certificate included in the received data sharing request with the authentication information corresponding to user A stored in counterpart ID storage unit 312. If the authentication information matches as a result of the collation, the shared target data stored in the URL specified by the above data sharing request is read out, and the read shared target data is transmitted from IP communication I / F unit 4 to connector device DNa of user A.

[0089] (Effect) As described above, in one embodiment, in a data circulation system that performs data transmission using a data space between users A and B, user information of each of users A and B who attempt to perform the above data transmission is stored in connector devices DNa and DNB arranged between terminals UTa and UTb of users A and B and a data space management device DSM in a state including the telephone number assigned from the telephone communication carrier to which the users A and B subscribe. In addition, each of the connector devices DNa and DNB is provided with an incoming and outgoing call function using the above telephone number. When performing data transmission between users A and B, the connector devices DNa and DNB transmit and receive user information including the telephone numbers of the other users B and A to each other using the incoming and outgoing call function, and authenticate the users A and B of the communication partner by collating the sent user information of the other party with the previously stored user information.

[0090] That is, by including the telephone number securely managed by the telephone communication carrier for each user in the user information, and transmitting and receiving the user information via the telephone communication network using the incoming and outgoing call functions for telephone communication between the connector devices DNa and DNb, mutual authentication of the other party users is performed.

[0091] Therefore, even if the user ID or connector number is duplicated by someone, since authentication processing is performed using the telephone number strictly managed by the telephone communication carrier in association with the user, impersonation of the user is prevented, and thus highly reliable authentication can be realized.

[0092] [Other Embodiments] (1) In one embodiment, when the connector device DNa requests the connector device DNb to open a communication channel, the telephone number and corporate number of the user A who is the caller, the connector number of the connector device DNa used by the user A, and the telephone number of the user B who is the transmission destination are inserted into the request. However, communication path information may be inserted in addition to these numbers.

[0093] The communication path information is information representing the communication path exchanged between the local device TEx of the telephone communication carrier to which the user A subscribes, the local device TEy of the telephone communication carrier to which the data space management device DSM subscribes, and the local device TEz of the telephone communication carrier to which the user B on the communication partner side subscribes, and is configured as shown in FIG. 12, for example.

[0094] The connector device DNa of the user A transmits the above communication path information used by itself to the connector device DNb of the user B in addition to the communication channel opening request. By doing so, the connector device DNb that has received the communication channel opening request can confirm whether the communication is being performed from the location previously reported by the user A based on the communication path information included in the communication channel opening request.

[0095] (2) The telephone numbers used in this invention are not limited to those used in fixed telephone services. For example, they may also be telephone numbers used in mobile telephone services or IP telephone services. Also, in one embodiment, the case where the user and the data space operator each use different telephone communication carriers has been described as an example. However, they may also be the same telephone communication carrier, and various existing methods can also be used for the configuration of the telephone numbers and the incoming and outgoing call functions.

[0096] (3) In addition, with respect to the functional configurations, processing procedures, processing contents, etc. of the connector device and the data space management device, various modifications can be made and implemented without departing from the gist of this invention.

[0097] The embodiments of this invention have been described in detail above. However, the description up to this point is merely an exemplification of this invention in all aspects. Needless to say, various improvements and modifications can be made without departing from the scope of this invention. That is, in implementing this invention, a specific configuration corresponding to the embodiment may be appropriately adopted.

[0098] In short, this invention is not limited to the above embodiments as they are. In the implementation stage, the components can be modified and embodied without departing from the gist. Also, various inventions can be formed by appropriately combining a plurality of components disclosed in the above embodiments. For example, some components may be deleted from all the components shown in the embodiment. Furthermore, components from different embodiments may be appropriately combined.

Explanation of Reference Numerals

[0099] DSM… Data Space Management Device CNa, CNb, CNk… Connector Device UTa, UTb, UTk… User Terminal TEx, TEy, TEz… Office Device of Telephone Communication Carrier SDx, SDy, SDz… User Database 1, 6… Control Unit 2, 7… Program Storage Unit 3,8… Data storage unit 4,10… IP communication I / F unit 5,9… Telephone communication I / F unit 11… User registration control processing unit 12… Communication partner registration control processing unit 13… Data transmission control processing unit 14… Authentication control processing unit 141… Telephone communication control unit 142… Partner ID verification processing unit 143… Telephone number validity confirmation processing unit 31… User management area 311… Self ID storage unit 312… Partner ID storage unit 32… Telephone communication carrier management area 321… Telephone number storage unit 61… User registration reception processing unit 62… Relay processing unit during user-to-user registration 81… User information storage unit 82… Telephone number storage unit

Claims

1. A data distribution system for transmitting data between a plurality of connector devices each used by a user via a data linkage platform, the connector device and the data linking platform each have a telephone communication function for making and receiving calls using subscriber information assigned by a telephone communication carrier to which the connector device and the data linking platform are connected, Each of the plurality of connector devices includes: a user information storage unit for storing user information including the subscriber information assigned to the connector device; a counterpart information storage unit for storing counterpart user information including the subscriber information assigned to the connector device that is the counterpart of the data transmission; Equipped with a first connector device which is a requester of the data transmission; a processing unit that transmits communication request information including the user information stored in the user information storage unit to a second connector device that is a counterpart of the data transmission by using the telephone communication function; The second connector device includes: a processing unit that, when receiving the communication request information, compares user information of the first connector device included in the received communication request information with user information of the other party stored in the other party information storage unit, and determines the validity of the received user information; a processing unit that, when it is determined that the received user information is valid, transmits communication response information including the user information of the second connector device stored in the self information storage unit to the first connector device using the telephone communication function; Equipped with The first connector device includes: a processing unit that, when receiving the communication response information, compares user information of the second connector device included in the received communication response information with user information of the second connector device stored in the other party information storage unit to determine the validity of the received user information of the second connector device. A data distribution system comprising:

2. Each of the plurality of connector devices includes: a processing unit that transmits a user registration request including its own user information including subscriber information of its own connector device to the data linkage platform, receives connector identification information assigned to its own connector device from the data linkage platform in response to the user registration request, and stores the received connector identification information in the own information storage unit in addition to its own user information. The data distribution system according to claim 1 , further comprising:

3. The first connector device includes: a processing unit for transmitting a communication permission request including the user information of the second connector device to the second connector device; The second connector device includes: a processing unit that, when receiving the communication permission request, determines whether or not to permit communication based on user information of the first connector device included in the received communication permission request; a processing unit that stores the received user information of the first connector device in the other party information storage unit when the communication is permitted; a processing unit that transmits a registration request including the user information of the second connector device stored in the self-information storage unit to the first connector device; Equipped with The first connector device comprises: When the registration request is received, user information of the second connector device included in the received registration request is stored in the partner information storage unit. The data distribution system according to claim 1 .

4. The second connector device includes: a processing unit that, when receiving the communication permission request, performs call processing using the telephone communication function based on the subscriber information included in the user information of the first connector device included in the received communication permission request, and confirms the validity of the subscriber information based on a result of a call response of the first connector device to the call processing. The data distribution system according to claim 3 , further comprising:

5. the user information includes the subscriber information, attribute information of the user, and connector identification information assigned to the connector device by the data linkage platform; The second connector device includes: When the communication request information is received, the subscriber information, the user attribute information, and the connector identification information included in the user information of the first connector device included in the received communication request information are compared with the corresponding information included in the user information stored in the partner information storage unit, thereby determining the validity of the user information of the first connector device. The data distribution system according to claim 1 .

6. The first connector device comprises: transmitting the communication request information, including the user information of the user and information representing a communication path from the first connector device to the second connector device, to the second connector device using the telephone communication function; The second connector device includes: a processing unit that confirms a location of the first connector device based on information representing the communication path included in the received communication request information; The data distribution system according to claim 1 , further comprising:

7. A connector device used in a data distribution system that transmits data via a data linkage platform between a plurality of connector devices each used by a user, a telephone communication control unit that performs telephone communication with other connector devices via a telephone communication line by making and receiving calls using subscriber information assigned by a subscriber's telephone communication carrier; a user information storage unit for storing user information including the subscriber information; a counterpart information storage unit for storing counterpart user information including the subscriber information assigned to the connector device that is the counterpart of the data transmission; a processing unit for transmitting and receiving user information including the subscriber information stored in the self-information storage unit to and from the connector device that is the other party of the data transmission via the telephone communication line established by the telephone communication control unit; a processing unit that compares the received user information with user information including the subscriber information stored in the other party information storage unit and determines the validity of the received user information; A connector device comprising:

8. A user authentication method implemented by a data distribution system in which data is transmitted between a plurality of connector devices used by respective users via a data linkage platform, and the connector devices and the data linkage platform communicate with each other by making and receiving calls using subscriber information assigned by respective subscriber telephone carriers, comprising: Each of the plurality of connector devices includes: storing the user's own information including the subscriber information assigned to the connector device in a self information storage unit, and storing the other party's user information including the subscriber information assigned to the connector device that is the other party of the data transmission in a other party information storage unit; a first connector device which is a requester of the data transmission; transmitting communication request information including the user information stored in the user information storage unit to a second connector device which is the other party of the data transmission by the telephone communication using the outgoing and incoming calls; The second connector device includes: When the communication request information is received, the user information of the first connector device included in the received communication request information is compared with the user information of the other party stored in the other party information storage unit to determine the validity of the user information of the received first connector device; The second connector device includes: When it is determined that the received user information of the first connector device is valid, communication response information including the user information of the second connector device stored in the self-information storage unit is transmitted to the first connector device by using the telephone communication; The first connector device comprises: When the communication response information is received, the user information of the second connector device included in the received communication response information is compared with the user information of the second connector device stored in the other party information storage unit to determine the validity of the received user information of the second connector device. User authentication method.

Citation Information

Patent Citations

  • Server for dial-up connection

    JP2000349926A

  • Authentication system and authentication method of information terminal

    JP2005191830A

  • Authentication method, and network system

    JP2008028709A

  • Communication system, transmission side terminal equipment, and incoming side terminal equipment

    JP2008160212A

  • Information distribution control device, information distribution control method, program, and computer-readable storage medium

    WO2023224076A1