Authentication System and Authentication Program
The authentication system uses telephone line calls to verify user identity by matching caller IDs, addressing the trade-off between security and convenience in existing systems, ensuring reliable and user-friendly authentication.
Patent Information
- Application Number
- JP2023182848
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-10-24
- Publication Date
- 2025-07-09
- Estimated Expiration
- 2043-10-24
AI Technical Summary
Existing authentication systems face a trade-off between security and convenience, where enhanced security leads to decreased convenience and vice versa, necessitating a system that can perform identity verification conveniently and reliably with high reliability.
An authentication system that utilizes a user-side terminal device and a server-side terminal device connected via telephone and Internet lines, where the server-side device manages calls and verifies the user's identity by matching the caller ID with a predetermined number, ensuring secure and reliable authentication without relying on complex internet connections.
This approach allows for convenient and reliable personal authentication by confirming the user's identity through telephone line calls, preventing impersonation and enhancing security without compromising user experience.
Smart Images

Figure 0007705165000001 
Figure 0007705165000002 
Figure 0007705165000003
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication system and an authentication program for performing authentication between a user and a web server.
Background Art
[0002] As an authentication system using an authentication server, Patent Document 1 discloses an authentication method capable of improving security and preventing a decrease in the authentication success rate. This authentication method includes a step of generating identification information in a communication terminal, a step of transmitting the telephone number of the communication terminal and the generated identification information from the communication terminal to the authentication server, a step of generating a password in the authentication server, and storing the generated password in a database in association with the transmitted telephone number and identification information, a step of transmitting the generated password from the authentication server to the communication terminal, a step of converting the transmitted password into a tone signal and transmitting it from the communication terminal via a telephone line when the communication terminal makes a call to a predetermined call destination using the caller number notification function, a step of the authentication server obtaining the telephone number notified by the caller number notification function and obtaining the password transmitted via the telephone line, a step of determining whether the obtained telephone number and password are stored in the database, and a step of making the identification information associated with the telephone number and password in the database available as authentication information for the communication terminal when the obtained telephone number and password are stored.
[0003] Patent Document 2 discloses a communication device that can be connected to a first network while requiring settings for connecting to a second network, and automatically performs such settings. This communication device includes a first transmission unit that transmits the identification information of the self-device via the first network with a predetermined server as the destination, a first reception unit that receives, as a response to the identification information transmitted by the first transmission unit, first setting information for connecting to the second network via the first network, and a first setting unit that sets the self-device to be connectable to the second network using the first setting information.
[0004] Patent Document 3 discloses a one-time password issuing device that can suppress unauthorized authentication by a third party and further improve user convenience. This device is a one-time password issuing device that is communicably connected to an authentication device that performs user authentication processing and issues a one-time password required for the authentication processing. The device includes a receiving means that receives registration number information indicating the telephone number of a telephone owned by the user from the authentication device, an extracting means that extracts one telephone number as the one-time password from a plurality of telephone numbers that can be received by the one-time password issuing device via a telephone line when the receiving means receives the registration number information, a storing means that stores the registration number information received by the receiving means and the one-time number information indicating the telephone number extracted by the extracting means in a predetermined storage device in association with each other, a notifying means that notifies the user of the one-time number information stored by the storing means, a determining means that determines whether a combination of the registration number information corresponding to the incoming call number of the telephone and the one-time number information corresponding to the outgoing call number of the telephone is stored in the storage device when there is a telephone line connection to the one-time password issuing device based on the one-time number information notified by the notifying means, and a transmitting means that transmits determination result information indicating the determination result by the determining means to the authentication device.
[0005] Patent Document 4 discloses a ticket management server used in a ticket management system that monitors tickets used for entry into events and the like. This ticket management server includes a control unit, a database that stores the ticket ID for identifying a ticket in association with the user's phone number, and a communication unit that can communicate with the user's user terminal via a network. The control unit determines whether there is an incoming call from the user's phone number associated with the ticket ID of the ticket to a predetermined ticket-issuing phone number that can receive power at the communication unit, and when the determination condition including that there is a call from the user's phone number associated with the ticket ID of the ticket to the ticket-issuing phone number is satisfied, causes the ticket issuing device to issue the ticket.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Patent Document 2
Patent Document 3
Patent Document 4
Summary of the Invention
Problems to be Solved by the Invention
[0007] When shopping in a physical store or conducting online shopping, it is necessary to perform identity verification to prevent unauthorized use by a third party during settlement. The system for this identity verification becomes more complex as the security is enhanced, which easily leads to a decrease in convenience. On the other hand, if convenience is to be enhanced, the accuracy of identity verification tends to be low. Thus, security and convenience are contradictory. For this reason, in a web service that performs identity verification, a system that can perform identity verification conveniently and reliably and has high reliability is desired.
[0008] An object of the present invention is to provide a highly reliable authentication system and authentication program that can perform user authentication conveniently and surely in a web service for performing user authentication.
Means for Solving the Problems
[0009] One aspect of the present invention is an authentication system including a user-side terminal device having a communication function via a telephone line and the Internet, a web server device connected to the Internet, and a server-side terminal device connected to the web server device and having a communication function via a telephone line. The server-side terminal device has a call management unit that manages incoming and outgoing calls via a telephone line. The web server device has a server unit that transmits web information via the Internet and a call request unit that requests the server-side terminal device to make an incoming or outgoing call to the user-side terminal device. When a request for providing a service that requires user authentication is received from the user-side terminal device via the Internet by the call request unit, the call request unit requests the call management unit to make an incoming or outgoing call to the user-side terminal device. When the call management unit is requested to make a call by the call request unit, the call management unit makes a call to the user-side terminal device via the telephone line, disconnects the telephone communication immediately after the user-side terminal device is notified of the calling party's telephone number, the call management unit receives the call made via the telephone line from the user-side terminal device to the calling party's telephone number, and when the notified telephone number upon reception matches the destination telephone number, permits the server unit to transmit web information related to the provision of the service from the server unit to the user-side terminal device.
[0010] Another aspect of the present invention is an authentication program executed by a computer included in an authentication system including a user terminal device having a communication function via a telephone line and the Internet, a web server device connected to the Internet, and a server-side terminal device connected to the web server device and having a communication function via a telephone line. The server-side terminal device has a call management unit that manages incoming and outgoing calls via a telephone line. The web server device has a server unit that transmits web information via the Internet and a call request unit that requests the server-side terminal device to make an incoming or outgoing call to the user terminal device. When there is a request for providing a service that requires personal authentication from the user terminal device to the web server device via the Internet, the call request unit requests the call management unit to make an incoming or outgoing call to the user terminal device in a request step; a transmission step in which the call management unit that has received the request for making an incoming or outgoing call in the request step makes a call to the user terminal device via a telephone line; a disconnection step in which, immediately after the call source telephone number is notified to the user terminal device after making a call in the transmission step, the telephone communication is disconnected; an incoming call step in which the call management unit receives an incoming call via a telephone line to the call source telephone number from the user terminal; and an information transmission step in which, when the telephone number notified when receiving the call in the incoming call step matches the destination telephone number, the server unit permits the transmission of web information related to the provision of the service from the server unit to the user terminal device are executed by the computer.
[0011] According to such a configuration, when a user attempts to receive a service that requires personal authentication from a web server device via the Internet, the user-side terminal device makes a phone call via a telephone line and disconnects the telephone line immediately after the caller ID of the originating phone number is notified to the user-side terminal device. Since the caller ID of the originating phone number is notified to the user-side terminal device, the user makes a call from the user-side terminal device that received the call to this number. On the server-side terminal device, by matching the called phone number with the received phone number, it is confirmed whether the user who attempted to receive the service is the person who possesses the user-side terminal device. By making and receiving phone calls via the telephone line between the user-side terminal device without using the Internet, impersonation of personal authentication is prevented.
Advantages of the Invention
[0012] According to the present invention, in a web service that performs personal authentication, it is possible to conveniently and reliably perform personal authentication, and to provide a highly reliable authentication system and authentication program.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Embodiments for Carrying Out the Invention
[0014] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the following description, the same members are denoted by the same reference numerals, and the description of the members once described will be omitted as appropriate.
[0015] (Authentication System) FIG. 1 is a configuration diagram illustrating the authentication system according to the present embodiment. The authentication system 1 according to the present embodiment includes a user-side terminal device 10 having a communication function via a telephone line TX and the Internet N, a web server device 20 connected to the Internet N, and a server-side terminal device 30 connected to the web server device 20 and having a communication function via the telephone line TX.
[0016] The user-side terminal device 10 includes, for example, a telephone terminal 11 and an information terminal 12. Specific examples of the telephone terminal 11 include a mobile phone and a smartphone. In the present embodiment, in addition to a smartphone that can download and install application software (so-called app), it is also possible to use a mobile phone (a mobile phone other than a smartphone) that does not have such a function as the telephone terminal 11.
[0017] Specific examples of the information terminal 12 include a tablet terminal and a personal computer. Note that the telephone terminal 11 and the information terminal 12 may be separate, or may be incorporated in the same housing. For example, in a smartphone or a tablet terminal having a communication function via a telephone line TX and a communication function via the Internet N, there are those configured by one device. In the present embodiment, for convenience of explanation, the case where the telephone terminal 11 and the information terminal 12 are separate is taken as an example.
[0018] A telephone number for performing communication (telephone call) via the telephone line TX is assigned to the telephone terminal 11. In the present embodiment, the telephone number assigned to the telephone terminal 11 of the user-side terminal device 10 is referred to as the telephone number telX. Since the personal authentication is performed using the telephone number telX, it is preferable to use a mobile phone line as the telephone line TX. The information terminal 12 executes a web browser that requests web information from the web server device via the Internet N and displays the received web information on the screen.
[0019] The web server device 20 is a device that provides web information to a web information request destination via the Internet N. The web server device 20 includes a server unit 21 that transmits web information via the Internet N, and a CGI (Common Gateway Interface) 22 that includes a function of requesting the server-side terminal device 30 to make an incoming and outgoing call to the user-side terminal device 10. In the present embodiment, the CGI 22 is an example of an incoming and outgoing call request unit.
[0020] It is preferable that an information terminal 25 be connected to the web server device 20. The information terminal 25 includes a service management unit 26 that controls the provision of services and a database DB that stores web information necessary for the provision of services. Specific examples of the information terminal 25 include a personal computer and an external storage device. The information terminal 25 is preferably connected to the web server device 20 via a communication path C using a second communication standard other than the first communication standard that is the communication standard of the Internet N. Here, an example of the first communication standard is TCP / IP, and an example of the second communication standard is USB (Universal Serial Bus).
[0021] Since the information terminal 25 including the database DB is provided separately from the web server device 20, direct access to the database DB is prevented even if the web server device 20 is illegally invaded. Furthermore, since the information terminal 25 and the web server device 20 are connected via a communication path C using a communication standard different from the communication standard of the Internet N, it becomes difficult for the information terminal 25 to be invaded from the outside via the Internet N. Generally, hacking is performed using the communication standard of the Internet N. Therefore, the web server device 20 may be illegally invaded via the Internet N. However, since the web server device 20 and the information terminal 25 are connected via a communication path C using a communication standard other than the communication standard of the Internet N, even if the web server device 20 is illegally invaded, it is difficult to illegally invade the information terminal 25 connected via a communication path C using another communication standard beyond that, and the security of the database DB can be enhanced.
[0022] The server-side terminal device 30 has a call management unit 31 that manages incoming and outgoing calls via a telephone line TX. The server-side terminal device 30 functions as an authentication server for performing personal authentication. The server-side terminal device 30 is provided with a determination ring buffer 32 that stores a telephone number for which personal authentication is to be performed, an incoming call ring buffer 33 that stores the telephone number of an incoming call via the telephone line TX, and a standing telephone list 34 that stores the telephone numbers associated with the user-side terminal devices 10. The determination ring buffer 32 is an example of a determination storage unit, the incoming call ring buffer 33 is an example of an incoming call storage unit, and the standing telephone list 34 is an example of a standing telephone storage unit. The ring buffer used for each of the determination ring buffer 32 and the incoming call ring buffer 33 is a ring-shaped stack, and the next after the end of the stack becomes the head of the stack. By using the ring buffer, it becomes easier to suppress the storage capacity and manage the storage of telephone numbers within a certain period (within a certain capacity). Note that the determination ring buffer 32 and the incoming call ring buffer 33 may be managed by switching a plurality of ring buffers to achieve load distribution. Thereby, it becomes possible to handle the case where personal authentication by many users is concentrated in a short time.
[0023] The standing telephone list 34 is a list for registering the telephone numbers of users who have obtained a certain level of credit (for example, website operating companies and related companies (such as financial companies)). Thereby, users corresponding to the telephone numbers registered in the standing telephone list 34 of the operating company or related companies can access the database DB necessary for business without user registration.
[0024] For example, a financial company may access a database DB in which "personal information" and "purchase history" are recorded and perform a process of transferring the purchase price from the user's transaction account to the transaction account of the sales store. When using a non-public service, access it from the non-public homepage. In this case, for example, create a homepage for the non-public service menu on a personal computer or the like. When executing the non-public service, directly select a predetermined button in the service menu of the homepage to start the web browser and request the non-public service to the CGI in the form of a request. On the other hand, if a financial company introduces an authentication system to its non-public web server, the operating company will be able to use the non-public services of the financial company. These processes are services provided to users who have obtained a certain level of credit. By registering the phone numbers of such users in the fixed phone list 34, it becomes possible to provide a smooth service through a more rapid authentication of the user than that of general users.
[0025] In such an authentication system 1, when a request for providing a service that requires user authentication is made from the user-side terminal device 10 to the web server device 20 via the Internet N, the CGI 22 requests the call management unit 31 to make a call to the user-side terminal device 10. When the call management unit 31 is requested to make a call by the CGI 22, it makes a call to the user-side terminal device 10 via the telephone line TX and disconnects the telephone communication immediately after the calling source telephone number (in this embodiment, the calling source telephone number telA) is notified to the user-side terminal device 10. By disconnecting the telephone communication immediately after the notification, the minimum necessary information can be effectively transmitted.
[0026] After the telephone communication is disconnected, the user uses the incoming user-side terminal device 10 to make a call to the calling source telephone number telA notified via the telephone line TX. The call management unit 31 receives the call made from the user-side terminal device 10 to the calling source telephone number telA via the telephone line. When the telephone number notified at the time of receiving the call matches the called telephone number, the server unit 21 permits the transmission of web information related to the service to the user-side terminal device 10.
[0027] Here, the calling phone number telA to be notified to the user-side terminal device 10 does not have to be fixed. For example, a plurality of calling phone numbers may be prepared, and one selected (for example, randomly selected) for each service (for each authentication) that performs user authentication may be notified to the user-side terminal device 10 as the calling phone number telA.
[0028] Also, the calling phone number telA may be switched according to the number of the same phone number telX stored in the determination ring buffer 32. Further, when a plurality of the same phone number telX are stored in the determination ring buffer 32 within a certain period of time, the calling phone number telA may be switched according to the number of stored ones. That is, for a user who performs user authentication many times within a predetermined period, by changing the calling phone number telA, based on the correspondence between the order of the requested services (for example, time information when the request is received) and the switched calling phone number telA, the accuracy of the user authentication process can be improved.
[0029] (User authentication method) Next, a user authentication method using the authentication system 1 according to the present embodiment will be described. FIGS. 2 to 5 are diagrams for explaining the screen transition when receiving the provision of a service that requires user authentication. These screens are displayed on the user-side terminal device 10. That is, the screen may be displayed on the screen of the telephone terminal 11 or may be displayed on the screen of the information terminal 12. In the present embodiment, the display of the screen by the web browser of the information terminal 12 is taken as an example.
[0030] Figure 2 shows an example of screen transition starting from the top menu of a service that requires personal authentication. For example, when the "Personal Information" button on the top page of an online store is clicked (selected), a sub-window for "Personal Authentication" pops up. Also, when a button such as "Store A" on the top page is clicked, the products handled by Store A are displayed. When the "Add to Cart" button below the product to be purchased is clicked, the product to be purchased is added to the cart. When the "Cart Check" button is clicked, a sub-window showing the contents of the cart pops up.
[0031] Figure 3 shows an example of the display of a sub-window when the "Personal Information" button is clicked starting from the top menu shown in Figure 2. On this screen, buttons (icons) corresponding to services such as "New", "Update", and "Reference" are displayed, and a text box (input field) for entering the phone number of the user-side terminal device 10 as the user ID is displayed. The user selects the button for the desired service from the screen display by the web browser of the information terminal 12 and enters the phone number of the phone terminal 11 held by the user as the user ID into the text box.
[0032] Figure 4(a) shows an example of the screen display when the "New" button is selected in Figure 3. When the user selects the "New" button, registration of the necessary information for newly subjecting the user to personal authentication is performed. In this information, a text box for entering the phone number that will be the user ID of the user is displayed. Selecting the "New" button again from here transitions to a screen for entering personal information. After the input (confirmation) of the necessary information is completed, the user selects the "Register" button. As a result, a display notifying registration completion such as "Registered." is made on the screen. The phone number and personal information entered as the user ID are stored, for example, in the database DB.
[0033] Figure 4(b) shows an example of the screen display when the "Update" button is selected in Figure 3. When the user selects the "Update" button, updates such as adding and modifying already registered information are performed. After the input (confirmation) of the information to be updated is completed, the user selects the "Update" button. As a result, a display notifying the completion of the update, such as "Updated.", is shown on the screen.
[0034] Figure 4(c) shows an example of the screen display when the "Reference" button is selected in Figure 3. When the user selects the "Reference" button, the reference of the already registered information is performed. By this process, the user ID (phone number) and personal information, which are the already registered user information, are displayed on the screen.
[0035] Figure 5 shows an example of the screen display when the "Purchase" button in the sub-window that displays the cart contents in Figure 2 is selected. The process performed by selecting the "Purchase" button is the process when performing personal authentication on a payment site using, for example, credit or coupons when purchasing a product in an online store. When the "Purchase" button is clicked, the screen transitions to the personal authentication screen. Here, since it is before personal authentication, it is preferable to display the purchase details in grayed out. When the "Authentication" button is clicked, the screen transitions to the authentication process screen. When the "Authentication" button is clicked here, the personal authentication process according to the present embodiment described later is performed, and when it is completed, a screen display notifying the completion of the process for the requested information such as "Completed." is shown.
[0036] When performing personal authentication when a customer purchases a product at a physical store instead of an online store, the store and the customer are on the user side, and a financial company such as a payment site using credit or coupons becomes the web server side to perform the customer's personal authentication.
[0037] When performing settlement when a customer shops or receives services at a store, on the web browser of the information terminal 12 used at the store, for example, the screen of the products of the retailer shown in FIG. 2 is displayed, and when settling at the cash register, the store clerk selects the "Add to Cart" button for the products the customer purchases. Then, when settling, the "Cart Confirmation" button is selected, and the "Purchase" button is selected. Thereby, the screen shown in FIG. 5 is transitioned to, and the same personal authentication process as before is performed.
[0038] (Personal Authentication Process in New Registration Service) FIG. 6 is a flowchart exemplifying the personal authentication process in the new registration service. When the user selects the "New" button from the home screen displayed by the web browser, enters the telephone number telX, and selects the "Register" button, the user-side terminal device 10 sends the information (calling party telephone number) of the user's telephone number telX to the web server device 20 via the Internet N.
[0039] Next, the web server device 20 sends a determination request (calling / terminating request) for the telephone number telX to the incoming / outgoing call management unit 31 of the server-side terminal device 30 by the CGI 22. The incoming / outgoing call management unit 31 that has received the determination request from the CGI 22 stores the telephone number telX in the determination ring buffer 32, and makes a call to the telephone number telX, which is the calling party telephone number, via the telephone line TX. Then, the incoming / outgoing call management unit 31 disconnects the telephone communication immediately after the calling party telephone number telA is notified to the user-side terminal device 10. Here, as described above, the calling party telephone number telA notified to the user-side terminal device 10 does not have to be fixed, and different calling party telephone numbers telA may be notified each time the personal authentication is executed.
[0040] Next, the web server device 20 sends HTML for new information registration to the user-side terminal device 10. On the user-side terminal device 10, the HTML for new information registration sent from the web server device 20 is displayed on the web browser. The user refers to the screen display for new information registration displayed on the web browser and inputs the necessary information.
[0041] Next, the user makes a phone call to the calling phone number telA notified when receiving a call on the user-side terminal device 10. The call management unit 31 of the server-side terminal device 30 receives the call made to the calling phone number telA, and performs an incoming call determination to determine whether the phone number telX (incoming call phone number) notified when receiving the call is included in the phone numbers stored in the determination ring buffer 32. If the phone number telX notified when receiving the call is included in the determination ring buffer 32, the calling phone number telX is stored in the incoming call ring buffer 33; if not, it is not stored.
[0042] Next, the user selects the "Register" button displayed on the web browser. Thereby, the input information is transmitted to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the call management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information of the phone number telX input by the user.
[0043] When the call management unit 31 of the server-side terminal device 30 receives the incoming call confirmation requested from the CGI 22, it checks whether the phone number telX is stored in the incoming call ring buffer 33, and sends the presence or absence thereof to the web server device 20.
[0044] The web server device 20 receives the presence or absence of an incoming call sent from the call management unit 31, and when there is a storage in the incoming call ring buffer 33, it executes the process by the service management unit 26. That is, the service management unit 26 receives the message sent from the CGI 22, executes the process of newly registering the phone number telX and personal information included in the message, and responds with the execution result to the web server device 20. Thereby, the information input by the user is newly registered in the database DB.
[0045] After the registration is completed, the web server device 20 sends a response HTML for notifying the registration completion to the user-side terminal device 10. On the other hand, when there is no incoming call, a response HTML for notifying that the registration could not be completed is sent to the user-side terminal device 10.
[0046] On the user-side terminal device 10, the response HTML transmitted from the web server device 20 is received and displayed on the screen by the web browser. That is, when the new registration is completed, for example, a message such as "Registered." is displayed, and when the new registration fails, for example, a message such as "Failed." is displayed.
[0047] (Personal authentication process in the update service) FIG. 7 is a flowchart illustrating the personal authentication process in the update service. When the user inputs the telephone number telX from the home screen displayed by the web browser and selects the "Update" button, the user-side terminal device 10 sends the information of the user's telephone number telX to the web server device 20 via the Internet N.
[0048] Next, the web server device 20 sends a determination request (calling and receiving request) of the telephone number telX to the incoming and outgoing call management unit 31 of the server-side terminal device 30 by CGI22. The incoming and outgoing call management unit 31 that has received the determination request from CGI22 stores the telephone number telX in the determination ring buffer 32 and makes a call to the telephone number telX via the telephone line TX. Then, the incoming and outgoing call management unit 31 disconnects the telephone communication immediately after the calling source telephone number telA is notified to the user-side terminal device 10. Here, as described above, the calling source telephone number telA notified to the user-side terminal device 10 does not have to be fixed, and different calling source telephone numbers telA may be notified each time the personal authentication is executed.
[0049] Next, the web server device 20 sends the HTML for updating the registration information to the user-side terminal device 10. On the user-side terminal device 10, the update HTML transmitted from the web server device 20 is displayed by the web browser. The user refers to the update screen display displayed by the web browser and performs updates such as adding and modifying necessary information.
[0050] Next, the user makes a call to the calling phone number telA notified when receiving a call on the user-side terminal device 10. The call sending / receiving management unit 31 of the server-side terminal device 30 receives the call made to the calling phone number telA, and performs an incoming call determination to determine whether the phone number telX (incoming call phone number) notified when receiving the call is included in the phone numbers stored in the determination ring buffer 32. If the phone number telX notified when receiving the call is included in the determination ring buffer 32, the calling phone number telX of the caller is stored in the incoming call ring buffer 33, and if not, it is not stored.
[0051] Next, after the phone line from the calling phone number telA is disconnected, the user selects the "Update" button displayed on the web browser. Thereby, the information updated with additions, corrections, etc. is transmitted to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the call sending / receiving management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information of the phone number telX input by the user.
[0052] When the call sending / receiving management unit 31 of the server-side terminal device 30 receives the incoming call confirmation requested from the CGI 22, it checks whether the phone number telX is stored in the incoming call ring buffer 33, and sends the presence or absence thereof to the web server device 20.
[0053] The web server device 20 receives the presence or absence of an incoming call sent from the call sending / receiving management unit 31, and if there is an incoming call, executes the process by the service management unit 26. That is, the service management unit 26 receives the message sent from the CGI 22, executes the process of updating the phone number telX and personal information included in the message, and responds with the execution result to the web server device 20. Thereby, the information updated by the user is registered in the database DB.
[0054] After the update registration is completed, the web server device 20 transmits response HTML for notifying the completion of the update registration to the user-side terminal device 10. On the other hand, when there is no incoming call, the web server device 20 transmits response HTML for notifying that the update could not be performed to the user-side terminal device 10.
[0055] The user-side terminal device 10 receives the response HTML transmitted from the web server device 20 and displays it on the screen using a web browser. That is, when the update registration is completed, a message such as "Updated." is displayed, and when the update registration could not be performed, a message such as "Failed." is displayed.
[0056] (Identity authentication process in the reference service) FIG. 8 is a flowchart illustrating the identity authentication process in the reference service. When the user enters the phone number telX from the home screen displayed by the web browser and selects the "Reference" button, the user-side terminal device 10 sends the information of the user's phone number telX to the web server device 20 via the Internet N.
[0057] Next, the web server device 20 sends a determination request (incoming / outgoing call request) for the phone number telX to the incoming / outgoing call management unit 31 of the server-side terminal device 30 by means of CGI22. The incoming / outgoing call management unit 31 that has received the determination request stores the phone number telX in the determination ring buffer 32 and makes a call to the phone number telX via the telephone line TX. Then, the incoming / outgoing call management unit 31 disconnects the telephone communication immediately after the calling party phone number telA is notified to the user-side terminal device 10. Here, as described above, the calling party phone number telA notified to the user-side terminal device 10 does not have to be fixed, and different calling party phone numbers telA may be notified each time the identity authentication is executed.
[0058] Next, the web server device 20 transmits HTML for reference of the registration information to the user-side terminal device 10. On the user-side terminal device 10, the reference HTML transmitted from the web server device 20 is displayed using a web browser. The information displayed in this reference HTML includes the telephone number telA of the server-side terminal device 30 that is the destination and the telephone number telX of the user input previously, and the personal information of the user is not yet displayed.
[0059] Next, the user makes a call to the calling telephone number telA notified when receiving a call on the user-side terminal device 10. The call sending / receiving management unit 31 of the server-side terminal device 30 receives the call made to the calling telephone number telA, and performs an incoming call determination to determine whether the telephone number telX (incoming call telephone number) notified when receiving the call is included in the telephone numbers stored in the determination ring buffer 32. When the telephone number telX notified when receiving the call is included in the determination ring buffer 32, the calling telephone number telX of the caller is stored in the incoming call ring buffer 33, and when it is not included, it is not stored.
[0060] Next, after the telephone line from the calling telephone number telA is disconnected, the user selects the "Confirm" button displayed on the web browser. As a result, the information of the telephone number telX is transmitted to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the call sending / receiving management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information of the telephone number telX input by the user.
[0061] When the call sending / receiving management unit 31 of the server-side terminal device 30 receives the incoming call confirmation requested from the CGI 22, it checks whether the telephone number telX is stored in the incoming call ring buffer 33, and sends the presence or absence thereof to the web server device 20.
[0062] The web server device 20 receives the presence or absence of an incoming call sent from the incoming and outgoing call management unit 31, and executes the processing by the service management unit 26 when there is an incoming call. That is, the service management unit 26 receives the message transmitted from the CGI 22, executes the process of referring to the personal information associated with the telephone number telX included in the message, and responds to the web server device 20 with the execution result. As a result, the information that the user wants to refer to is read from the database DB.
[0063] After reading the information, the web server device 20 transmits the response HTML including the read information to the user-side terminal device 10. On the other hand, when there is no incoming call, a response HTML for notifying that it cannot be referred to is transmitted to the user-side terminal device 10.
[0064] The user-side terminal device 10 receives the response HTML transmitted from the web server device 20 and displays it on the screen by the web browser. That is, when the information to be referred to is sent, the information (such as personal information) is displayed, and when it cannot be referred to, a message such as "Failed." is displayed.
[0065] In the personal authentication method using such an authentication system 1, mutual incoming and outgoing calls between the telephone number telX on the user-side terminal device 10 side and the calling source telephone number telA on the server-side terminal device 30 side use the telephone number notification function to perform personal authentication. Therefore, the exchange of the two telephone numbers required for personal authentication can be performed only by terminals that can use the telephone line TX. That is, in the present embodiment, it is not necessary to use dedicated authentication application software for notifying the two telephone numbers performed in the personal authentication process, and it can be realized by any terminal that can use telephone communication via the telephone line TX.
[0066] (Personal authentication process in the requested information service) FIG. 9 is a flowchart illustrating the personal authentication process in the requested information service. Here, as an example, a case will be described where the user side is a store and a customer, and the web server side is a payment site and a shop site. In this case, the telephone terminal 11 of the user-side terminal device 10 is possessed by the customer, and the information terminal 12 is used by the store. Also, the server-side terminal device 30 is used by the payment site, and the web server device 20 and the information terminal 25 are used by the shop site.
[0067] First, when the store on the user side selects the "Personal Authentication" button from the home screen displayed by the web browser, enters the telephone number telX, and selects the "Authentication" button, the information terminal 12 of the user-side terminal device 10 sends the information of the user's telephone number telX to the web server device 20 via the Internet N.
[0068] Next, the web server device 20 sends a determination request (calling and receiving request) of the telephone number telX to the incoming and outgoing call management unit 31 of the server-side terminal device 30 by CGI22. The incoming and outgoing call management unit 31 that has received the determination request from CGI22 stores the telephone number telX in the determination ring buffer 32, and makes a call to the telephone number telX of the telephone terminal 11 possessed by the customer via the telephone line TX. Then, the incoming and outgoing call management unit 31 disconnects the telephone communication immediately after the calling party telephone number telA is notified to the telephone terminal 11 possessed by the customer who is the user-side terminal device 10. Here, as described above, the calling party telephone number telA notified to the user-side terminal device 10 does not have to be fixed, and different calling party telephone numbers telA may be notified each time the personal authentication is executed.
[0069] Next, the web server device 20 sends authentication HTML to the information terminal 12 of the user-side terminal device 10. In the information terminal 12, the authentication HTML sent from the web server device 20 is displayed by the web browser. The store on the user side refers to the authentication screen display displayed by the web browser and inputs the necessary information.
[0070] Next, the customer on the user side makes a call from the telephone terminal 11 to the calling phone number telA notified when receiving an incoming call on the telephone terminal 11. The call management unit 31 of the server-side terminal device 30 receives the call made to the calling phone number telA, and performs an incoming call determination to determine whether the phone number telX notified when receiving the call is included in the phone numbers stored in the determination ring buffer 32. When the phone number telX notified when receiving the call is included in the determination ring buffer 32, the incoming call ring buffer 33 stores the calling phone number telX, and does not store it if it is not included.
[0071] Next, the store on the user side selects the "Authenticate" button displayed on the web browser. As a result, the input information is transmitted to the web server device 20 via the Internet N. The CGI 22 of the web server device 20 sends a request for incoming call confirmation to the call management unit 31 of the server-side terminal device 30. This request for incoming call confirmation includes the information of the phone number telX input by the user.
[0072] When the call management unit 31 of the server-side terminal device 30 receives the incoming call confirmation requested from the CGI 22, it checks whether the phone number telX is stored in the incoming call ring buffer 33, and sends the presence or absence thereof to the web server device 20.
[0073] The web server device 20 receives the presence or absence of an incoming call sent from the call management unit 31, and when there is a storage in the incoming call ring buffer 33, it executes the process by the service management unit 26. That is, the service management unit 26 receives the message sent from the CGI 22, executes the process for the request information included in the message (for example, payment process), and responds with the execution result to the web server device 20. As a result, the process for the information requested by the user side (for example, payment process) is provided. That is, when the customer's authentication is performed by this process, the credit payment from the customer to the store and the use of the coupon are completed, and the purchase of goods and the provision of services to the customer are performed.
[0074] In the above description, the case where the customer makes a payment at the store is taken as an example. However, when the customer makes a payment using an online sales site, the customer will use the information terminal 12 instead of the above store. That is, when the customer uses the information terminal 12 to shop or the like on the online sales site and makes a payment, the customer will perform the operations that the store side performs in the above processing. As a result, a customer using an online sales site can make a payment based on personal authentication and receive the purchase of goods or the provision of services.
[0075] (Authentication program) The authentication program applied to the authentication system 1 according to this embodiment is executed by a computer included in the authentication system 1. This authentication program may be stored in a storage medium or may be distributed via a network. FIG. 10 is a flowchart illustrating the incoming call management process in the authentication program. The incoming call management process is executed by the incoming and outgoing call management unit 31 of the server-side terminal device 30. First, as shown in step S101, it is determined whether there is a determination request (request step) from the CGI 22 to the incoming and outgoing call management unit 31. If there is a determination request, the process proceeds to step S102, and the telephone number tel (for example, the telephone number telX) is stored in the determination ring buffer 32.
[0076] Next, as shown in step S103, the incoming and outgoing call management unit 31 makes a call to the telephone number tel via the telephone line TX (calling step), and disconnects the telephone communication immediately after the calling party telephone number is notified to the user-side terminal device 10 (disconnecting step).
[0077] On the other hand, if it is determined in step S101 that there is no determination request, the process proceeds to step S104, and it is determined whether it is an incoming call (incoming call step) from the user-side terminal device 10. If it is an incoming call from the user-side terminal device 10, the process proceeds to step S105, and an incoming call determination is performed. The process of the incoming call determination will be described later.
[0078] If the call is not an incoming call from the user-side terminal device 10 in the determination of step S104, the process proceeds to step S106 to determine whether it is an incoming call confirmation sent from the CGI 22. If it is an incoming call confirmation, the process proceeds to step S107 to perform an incoming call notification. The process of the incoming call notification will be described later. On the other hand, if it is not an incoming call confirmation, the process returns to step S101. The incoming call management process is a loop process from step S101 to step S107.
[0079] Here, when there is a determination request shown in step S101, the call sending and receiving management unit 31 may not perform a determination request for the same telephone number for a certain period of time (for example, within about 1 minute) if a determination request for the same telephone number comes again in a short time. This can be used to prevent spam.
[0080] FIG. 11 is a flowchart illustrating the incoming call determination process in the authentication program. The incoming call determination process (step S105 in FIG. 10) is executed by the call sending and receiving management unit 31 of the server-side terminal device 30. The call sending and receiving management unit 31 makes a call to the telephone number tel for which the incoming call determination is to be made, and after performing a disconnection step of disconnecting the telephone communication immediately after the calling party telephone number is notified to the user-side terminal device 10, as shown in step S201, it determines whether the telephone number tel is included in the permanent telephone list 34. If the telephone number tel is included in the permanent telephone list 34, the process proceeds to step S202 to perform a process of storing the telephone number tel in the incoming call ring buffer 33.
[0081] If it is determined in step S201 that the telephone number tel is not included in the permanent telephone list 34, the process proceeds to step S203 to determine whether the telephone number tel is included in the determination ring buffer 32. If the telephone number tel is included in the determination ring buffer 32, the process proceeds to step S204 to perform a process of storing the telephone number tel in the incoming call ring buffer 33.
[0082] FIG. 12 is a flowchart illustrating the incoming call notification process in the authentication program. The incoming call notification process (step S107 in FIG. 10) is executed by the call management unit 31 of the server-side terminal device 30. First, as shown in step S301, it is determined whether the telephone number tel is included in the incoming call ring buffer 33. If the telephone number tel is included in the incoming call ring buffer 33, the process proceeds to step S302, where it is transmitted to CGI22 that the telephone number tel exists, and as shown in step S303, the telephone number tel is deleted from the incoming call ring buffer 33.
[0083] On the other hand, if it is determined in step S301 that the telephone number tel is not included in the incoming call ring buffer 33, the process proceeds to step S304, where it is transmitted to CGI22 that the telephone number tel does not exist.
[0084] FIG. 13 is a flowchart illustrating the service management process in the authentication program. The service management process is executed by the service management unit 26 of the web server device 20. First, as shown in step S401, it is determined whether there is a request for a new process from CGI22. If there is a request for a new process, the process proceeds to step S402, where a process of registering information newly is executed.
[0085] If there is no request for a new process, the process proceeds to step S403, where it is determined whether there is a request for an update process from CGI22. If there is a request for an update process, the process proceeds to step S404, where an information update process is executed.
[0086] If there is no request for an update process, the process proceeds to step S405, where it is determined whether there is a request for a reference process from CGI22. If there is a request for a reference process, the process proceeds to step S406, where an information reference process is executed.
[0087] After executing the new process in step S402, the update process in step S404, and the reference process in step S406 respectively, as shown in step S407, a process of transmitting response data to the web server device 20 is performed. On the other hand, if it is not a request for any of the new process, the update process, and the reference process, the process returns to step S401. The service management process is a loop process from step S401 to step S407.
[0088] As described above, according to the authentication system 1 and the authentication program according to the present embodiment, when a user attempts to receive a service that requires personal authentication from the web server device 20 via the Internet N, the user-side terminal device 10 makes a call via the telephone line TX, and immediately after the calling party telephone number telA is notified to the user-side terminal device 10, the telephone line TX is disconnected. As a result, the calling party telephone number telA is notified to the user-side terminal device 10 by the minimum necessary communication and remains as an incoming call history. Even if the user is not informed in advance of the telephone number (calling party telephone number telA) used for personal authentication, the user can obtain it from this incoming call history.
[0089] Then, the user uses the user-side terminal device 10 to make a call via the telephone line TX to the calling party telephone number telA in this incoming call history. On the server-side terminal device 30, by matching the called telephone number with the incoming telephone number, it is confirmed whether the user who attempted to receive the service holds the user-side terminal device 10. That is, since personal authentication is performed by making and receiving calls via the telephone line TX between the user-side terminal device 10 without going through the Internet N, impersonation by a third party is prevented.
[0090] Although the present embodiment and its application examples (modification examples, specific examples) have been described above, the present invention is not limited to these examples. For example, those obtained by appropriately adding, deleting, or changing the design of components by those skilled in the art to the foregoing embodiments or their application examples (modification examples, specific examples), or those obtained by appropriately combining the features of each embodiment are also included in the scope of the present invention as long as they have the gist of the present invention.
Explanation of Symbols
[0091] 1… Authentication system 10… User-side terminal device 11… Telephone terminal 12, 25… Information terminal 20… Web server device 21… Server section 22… CGI 26… Service management section 30… Server-side terminal device 31… Incoming / outgoing call management section 32… Judgment ring buffer 33… Incoming call ring buffer 34… Standing telephone list C… Communication path DB… Database N… Internet TX… Telephone line
Claims
1. A user-side terminal device having communication functions via a telephone line and the Internet, A web server device connected to the Internet, A server-side terminal device connected to the web server device and having a communication function via the telephone line, An authentication system comprising: The server-side terminal device has a call management unit that manages incoming and outgoing calls via the telephone line, The web server device, A server unit that transmits web information via the Internet, A call request unit that requests the server-side terminal device to make an incoming or outgoing call to the user-side terminal device, When there is a request for providing a service that requires personal authentication from the user-side terminal device to the web server device via the Internet, the call request unit requests the call management unit to make an incoming or outgoing call to the user-side terminal device, When the call management unit is requested to make a call by the call request unit, it makes a call to the user-side terminal device via the telephone line, and disconnects the telephone communication immediately after the user-side terminal device is notified of the calling party's telephone number, The call management unit receives a call made from the user-side terminal to the calling party's telephone number via the telephone line. When the called telephone number notified upon receipt matches the destination telephone number, the server unit is permitted to transmit web information related to the provision of the service to the user-side terminal device. This is the authentication system, The server-side terminal device, A determination storage unit that stores a telephone number for which personal authentication is to be performed, A receiving storage unit that stores the telephone number of an incoming call received via the telephone line, When there is a request for providing a service that requires personal authentication from the user-side terminal device to the web server device via the Internet, the call request unit requests the call management unit to notify the destination telephone number, which is the telephone number notified from the user-side terminal device, and to make an incoming or outgoing call to the user-side terminal device, When the call management unit is requested to make a call by the call request unit, it stores the destination telephone number in the determination storage unit and makes a call to the destination telephone number via the telephone line, When the call management unit receives a call made from the user-side terminal to the calling party's telephone number via the telephone line, it stores the incoming call telephone number, which is the telephone number of the received call, in the receiving storage unit, The incoming and outgoing call management unit is an authentication system that permits the transmission of web information related to the provision of the service from the server unit to the user-side terminal device when the incoming call phone number stored in the incoming call storage unit matches the destination phone number stored in the determination storage unit.
2. The server-side terminal device further includes a permanent phone storage unit that stores a phone number associated with the user-side terminal device. The incoming and outgoing call management unit receives an incoming call from the user-side terminal via the telephone line to the source phone number, and when the phone number notified upon receipt of the call matches the phone number stored in the permanent phone storage unit, permits the transmission of web information related to the provision of the service from the server unit to the user-side terminal device. The authentication system according to claim 1.
3. It further includes a database connected to the web server device. The database is connected to the web server via a communication path for transmitting and receiving information with the web server device using a second communication standard other than the first communication standard, which is the communication standard of the Internet. When the incoming and outgoing call management unit permits the transmission of the web information to the user-side terminal device, it has a function of reading the web information from the database using the second communication standard. The authentication system according to claim 1 or 2.
4. A user-side terminal device equipped with communication functions via a telephone line and the Internet. A web server device connected to the Internet. A server-side terminal device connected to the web server device and equipped with a communication function via the telephone line. An authentication program to be executed by a computer included in an authentication system including, The server-side terminal device has an incoming and outgoing call management unit that manages incoming and outgoing calls via the telephone line. The web server device, Has a server unit that transmits web information via the Internet, And an incoming and outgoing call request unit that requests the server-side terminal device to make an incoming or outgoing call to the user-side terminal device. When there is a request for the provision of a service that requires personal authentication from the user-side terminal device to the web server device via the Internet, a request step in which the incoming and outgoing call request unit requests the incoming and outgoing call management unit to make an incoming or outgoing call to the user-side terminal device. A calling step in which the incoming / outgoing call management unit that has received a request for an incoming or outgoing call in the request step makes a call to the user-side terminal device via the telephone line; A disconnection step of disconnecting a telephone call immediately after the calling party's telephone number is notified to the user-side terminal device after making a call in the calling step; An incoming call step in which a call made from the user-side terminal to the calling party's telephone number via the telephone line is received by the incoming / outgoing call management unit; An information transmission step of permitting transmission of web information related to the provision of the service from the server unit to the user-side terminal device when the telephone number notified at the time of receiving a call in the incoming call step matches the called party's telephone number; It is an authentication program for causing a computer to execute; The server-side terminal device, A determination storage unit that stores a telephone number for which personal authentication is planned; It further has a call storage unit that stores the telephone number of an incoming call received via the telephone line, The request step is, When there is a request for providing a service that requires personal authentication from the user-side terminal device to the web server device via the Internet, notifying the incoming / outgoing call management unit of the called party's telephone number, which is the telephone number notified from the user-side terminal device, and requesting an incoming / outgoing call to the user-side terminal device; The calling step is, Storing the called party's telephone number in the determination storage unit and making a call to the called party's telephone number via the telephone line; The incoming call step is, When the incoming / outgoing call management unit receives a call made from the user-side terminal to the calling party's telephone number via the telephone line, the incoming / outgoing call management unit stores the incoming call telephone number, which is the telephone number of the incoming call, in the call storage unit; The information transmission step is, An authentication program including permitting transmission of the web information from the server unit to the user-side terminal device when the incoming call telephone number stored in the call storage unit matches the called party's telephone number stored in the determination storage unit.
5. The server-side terminal device further has a permanent telephone storage unit that stores a telephone number associated with the user-side terminal device, The information transmission step is, The authentication program according to claim 4, comprising: when the telephone number notified from the user-side terminal when receiving a call in the incoming call step matches the telephone number stored in the fixed telephone storage unit, permitting the server unit to transmit web information related to the provision of the service to the user-side terminal device.
Citation Information
Patent Citations
Management method and management device for commercial transaction
JP2002170040A
Onetime password issuing device, program, and onetime password issuing method
JP2015082140A
Authentication support apparatus, personal authentication system, authentication support method, and program
JP2015179501A
Authentication system, authentication method, and authentication program
JP2016192023A
Communication device, server, and system
JP2017147672A