Information processing apparatus, control method and program thereof, and system
By managing user ID and region mappings and using false responses, the system obscures user ID registration status, enhancing security by preventing determination of registration and reducing brute-force attack vulnerabilities.
Patent Information
- Application Number
- JP2021136656
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-09-11
- Filing Date
- 2021-08-24
- Publication Date
- 2025-07-09
- Estimated Expiration
- 2041-08-24
AI Technical Summary
Existing systems face security risks due to the ability to determine the registration status of user IDs based on region-specific responses from integration servers, which can be exploited for brute-force password attacks.
An information processing apparatus that manages mapping information between user IDs and regions, responds with false region information when a user ID is not registered, and uses methods like hash functions or pseudo-authentication to obscure the registration status.
This approach makes it difficult to determine the presence or absence of user ID registration, reducing security risks and protecting against unauthorized access attempts.
Smart Images

Figure 0007705305000001 
Figure 0007705305000002 
Figure 0007705305000003
Abstract
Description
Technical Field
[0001] The present invention relates to a response technology for a region identification request received from a client terminal via the Internet.
Background Art
[0002] In recent years, the use of cloud services deployed on the Internet has been expanding. In cloud services, IT devices such as servers and network devices are aggregated and installed and operated in a facility called a data center, and web application services are provided to users. Data centers are installed for each country or region, and companies that provide services worldwide deploy the same type of services in multiple data centers as needed.
[0003] Data such as a user's user ID, password, and email address is managed independently for each data center accessed by the user from the perspective of personal information protection. The user decides which data center to access according to the physical region and legal system, but if the data center is different, the URL for accessing the service site deployed in the data center is also different.
[0004] Regarding this point, Patent Document 1 discloses a method in which an integrated server identifies the region where a user is registered so that the user can access the service with a common URL, and a web client sends an authentication request to the authentication server in the identified region.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] As described above, the integration server identifies the region in which the user ID is registered and responds to the Web client. Also, in the case of an unregistered user ID, the integration server cannot identify the region and thus returns some kind of error. A malicious person can determine whether the used user ID is registered or not based on the response content from the integration server when accessing the integration server with an appropriate user ID. Therefore, if it is registered, there are security problems such as being used for a brute-force password attack using that user ID.
[0007] The present invention has been made to solve the above-described problems, and aims to provide a technique for making it difficult to determine the registration status of a user ID based on the region-specific response of an integration server and reducing security risks.
Means for Solving the Problems
[0008] To solve this problem, for example, the information processing apparatus of the present invention has the following configuration. That is, An information processing apparatus that transmits region information representing a corresponding region to a client terminal in response to a region-specific request received from the client terminal via the Internet, Communication means for communicating with the Internet, Management means for managing mapping information in which user information and region information are associated, Collation means for collating the mapping information of the management means when a region-specific request including user information for specifying a user is received from the client terminal via the communication means, When the collation result of the collation means indicates that the corresponding user information exists in the mapping information, the corresponding region information is transmitted to the client terminal as a response, Response means for transmitting false region information to the client terminal as a response when the collation result of the collation means indicates that the corresponding user information does not exist in the mapping information.
Advantages of the Invention
[0009] According to the present invention, it is possible to function as an integrated server that manages mapping information between user IDs and regions, and to make it difficult to determine the presence or absence of registration of a user ID at the requester who requested region identification, thereby reducing security risks.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Best Mode for Carrying Out the Invention
[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0012] [First Embodiment] A network configuration example of the information processing system according to this embodiment will be described with reference to the block diagram of FIG. 1.
[0013] The system includes a Web client 101 connected to the Internet 100, an integration server 130, and data centers 110 and 120. The Web client 101 is a client terminal equipped with the function of a Web browser and can utilize Web technologies such as cookies. The data centers 110 and 120 are independent of each other. In the embodiment, for convenience, the data centers are distinguished by the identification names based on the regions where the data centers are installed. Hereinafter, the data center 110 is referred to as the US region, and the data center 120 is referred to as the EU region.
[0014] In the computer network 111 within the US region 110, a reverse proxy server 112, an authentication server 113, and a resource server 114 are connected. Also, in the computer network 121 within the EU region 120, a reverse proxy server 122, an authentication server 123, and a resource server 124 are connected. Here, the term "region" refers to a certain range such as a country or a region, and there is no limitation to the range of the region. Similar server configurations are built in the US region 110 and the EU region 120. The reverse proxy servers 112 and 122 have the role of distributing external access requests to the servers inside the network. For example, the reverse proxy server determines whether to distribute to the authentication server or the resource server based on the path name of the URL. Different domain names specific to the region are assigned to the reverse proxy servers 112 and 122 respectively, and the domain names of the URLs are also different. Therefore, access is separated for each region. Access from the Web client 101 to the reverse proxy server 112 is distributed to the authentication server 113 and the resource server 114. On the other hand, access from the Web client 101 to the reverse proxy server 122 is distributed to the authentication server 123 and the resource server 124. Also, the reverse proxy servers 112 and 122 receive access requests. For this reason, the domain names and domains of the authentication server 113 and the resource server 114 are the same, and similarly, the domain names and domains of the authentication server 123 and the resource server 124 are the same. The authentication servers 113 and 123 perform authentication for requests from the Web client 101. The resource server 114 provides Web application services in response to being authenticated by the authentication server 113. Also, the resource server 124 provides Web application services in response to being authenticated by the authentication server 123.
[0015] The integrated server 130 is a server capable of communicating with the Web client 101, which is prepared to accept a common URL worldwide. The integrated server 130 may be deployed in a data center separate from the US region 110 and the EU region 120, or may be deployed in the US region 110 or the EU region 120. Also, multiple integrated servers may be deployed in multiple data centers, and a common URL may be assigned using GeoDNS (not shown). GeoDNS is a mechanism that transfers requests to a server that is network - close to the client making the request. For example, when the Web client 101 requests access to the common URL of the integrated server, and the location of the Web client 101 is close to the US region 110 on the network, the request is transferred to the integrated server 130 deployed in the US region 110.
[0016] The Web client 101 and various servers have a basic configuration as information processing devices. FIG. 2 shows the hardware configuration of the information processing device.
[0017] The information processing device includes a CPU 200, a RAM 201, a ROM 202, a network interface 203, an external storage device 204, a display device 205, and an input device 206.
[0018] The CPU 200 controls the operations of each part constituting the information processing device and is the main body that executes various processes described later as operations performed by the information processing device. The RAM 201 is a memory that temporarily stores data and control information and serves as a work area used when the CPU 200 executes various processes. The ROM 202 stores fixed operation parameters, operation programs, etc. of the information processing device.
[0019] The network interface 203 provides a function for connecting to and communicating with the Internet 100, computer networks 111 and 121. The information processing device can transmit and receive data to and from external devices through this network interface 203.
[0020] The external storage device 204 is a device for storing data and has an interface for receiving I / O commands for reading and writing data. The external storage device 204 may be a hard disk drive (HDD), a solid state drive (SSD), an optical disk drive, a semiconductor memory device, or other storage device. The external storage device 204 stores a computer program and data for causing the CPU 200 to execute each process described later as being performed by the information processing device.
[0021] The display device 205 is, for example, an LCD (Liquid Crystal Display) or the like, and displays information necessary for the user. The input device 206 is, for example, a keyboard, a mouse, a touch panel, or the like, and receives necessary input from the user. The display device 205 and the input device 206 constitute a user interface.
[0022] The Web client 101 and various servers (112 to 114, 122 to 124, 130) have the basic configuration of FIG. 2 as described above, but may have a unique configuration according to the usage form of the device. For example, if the Web client 101 is a smartphone, in addition to the configuration of FIG. 2, it will have an imaging sensor and a line connection configuration. However, since the description of the unique configuration is outside the essence of the present embodiment, it is omitted here.
[0023] Next, the functional configuration of the Web client 101 according to the present embodiment will be described with reference to the block diagram of FIG. 3. The configuration shown in FIG. 3 represents the functional configuration when the CPU 200 of the Web client 101 executes a program as a Web client.
[0024] The Web client 101 includes a display control unit 300, an input reception unit 301, a region identification request transmission unit 302, a region identification result reception unit 303, an authentication server determination unit 304, an authentication request transmission unit 305, and an authentication result reception unit 306. For the sake of explanation, assume that the hardware of the Web client 101 has the configuration shown in FIG. 2.
[0025] The display control unit 300 displays a login screen on the display device 205. Further, the display control unit 300 displays a login success screen and a login failure screen on the display device 205 according to the authentication result described later.
[0026] The input reception unit 301 receives the input of the user ID and password from the input device 206 for the login screen displayed by the display control unit 300.
[0027] The region identification request transmission unit 302 transmits a region identification request including the user ID received by the input reception unit 301 as user information to the integration server 130.
[0028] The region identification result reception unit 303 receives the region identification result transmitted from the integration server 130.
[0029] The authentication server determination unit 304 determines an authentication server to which an authentication request is to be transmitted based on the region received by the region identification result reception unit 303.
[0030] The authentication request transmission unit 305 transmits an authentication request based on the user ID and password received by the input reception unit 301 to the authentication server determined by the authentication server determination unit 304.
[0031] The authentication result reception unit 306 receives the authentication result transmitted from the authentication server.
[0032] Next, the processing procedure during the login process of the Web client 101 according to the present embodiment will be described with reference to the flowchart of FIG. 4.
[0033] First, at S400, the display control unit 300 acquires a login screen from the integrated server 130 and displays it on the display device 205. An example of the displayed login screen is shown in FIG. 5. The login screen 500 is composed of a user ID input area 501, a password input area 502, and a button 503 for confirming the input information by the user. Note that the login screen is not limited to being acquired from the integrated server 130, and for example, it may be acquired from the external storage device 204.
[0034] Next, at S401, the input reception unit 301 receives the input of the user ID and password from the user for the login screen (S401). Here, the user uses the input device 206 to input the user ID in the user ID input area 501 of the login screen 500, the password in the password input area 502, and confirms the input by pressing the button 503.
[0035] In response to the confirmation of the input of the user ID and password, at S402, the region specification request transmission unit 302 transmits a region specification request to the integrated server 130. Here, the region specification request at least includes the user ID received by the input reception unit 301. The integrated server 130 specifies the region in which the user ID is registered based on the received region specification request and responds to the Web client 101. The process of specifying the region by the integrated server 130 will be described later.
[0036] At S403, the region specification result reception unit 303 receives the region specification result from the integrated server 130.
[0037] Next, at S404, the authentication server determination unit 304 determines the authentication server to which the authentication request is to be sent based on the received region identification result. For example, if the region in which the user ID is identified as registered is the US region 110, the authentication server determination unit 304 determines the authentication server 113 in the US region 110 as the target for sending the authentication request. Similarly, if the region in which the user ID is identified as registered is the EU region 120, the authentication server determination unit 304 determines the authentication server 123 in the EU region 120 as the target for sending the authentication request.
[0038] At S405, the authentication request transmission unit 305 sends an authentication request to the authentication server determined as the transmission target. This authentication request includes at least the user ID and password received by the input reception unit 301. The URL specified at the time of transmission becomes a URL with a domain name unique to the US region 110 when the authentication server 113 in the US region 110 is determined as the target for sending the authentication request. Also, when the authentication server 123 in the EU region 120 is determined as the target for sending the authentication request, the URL becomes a URL with a domain name unique to the EU region 120. The authentication server authenticates the user based on the user ID and password included in the received authentication request and responds with the authentication result to the requesting Web client 101.
[0039] At S406, the authentication result reception unit 306 receives the authentication result sent from the authentication server. Then, at S407, the authentication result reception unit 306 determines whether the received authentication result is "success" or "failure". If it is a success (when S407 is YES), at S408, the display control unit 300 displays a login success screen on the display device 205 (S408). Also, the response from the authentication server includes an instruction to set the authentication token in the Cookie. On the other hand, if the authentication result is "failure" (when NO in S407), at S409, the display control unit 300 displays a login failure screen on the display device 205.
[0040] Next, the functional configuration of the integrated server 130 according to the present embodiment will be described with reference to the block diagram of FIG. 6. The configuration shown in FIG. 6 represents the functional configuration when the CPU 200 of the integrated server 130 executes a program for functioning as an integrated server. For convenience of explanation, it is assumed that the hardware of the integrated server 130 has the configuration shown in FIG. 2.
[0041] The integrated server 130 includes a region identification request receiving unit 600, a user ID conversion unit 601, a mapping information management unit 602, a mapping information verification unit 603, a region determination unit 604, and a region identification result transmission unit 605.
[0042] The region identification request receiving unit 600 receives a region identification request transmitted from the Web client 101 via the network interface 203.
[0043] The user ID conversion unit 601 converts the user ID included in the region identification request into a hash value.
[0044] The mapping information management unit 602 stores, holds, and manages the mapping information between the hash value of the user ID registered in each region and the region in which the user is registered in the external storage device 204. Storing the hash value of the user ID is to protect the user ID that may be personal information.
[0045] The mapping information verification unit 603 verifies (or searches) in the mapping information management unit 602 using the hash value of the user ID calculated by the user ID conversion unit as a key, determines whether it exists (verification result), and if it exists, identifies the corresponding region.
[0046] The region determination unit 604 determines a false region based on the user ID included in the region identification request.
[0047] The region identification result transmission unit 605 transmits, as a region identification result, region information indicating either the region identified by the mapping information collation unit 603 or the false region determined by the region determination unit 604 to the Web client 101 via the network interface 203.
[0048] Next, the region identification process of the integrated server 130 according to the present embodiment will be described with reference to the flowchart of FIG. 7.
[0049] First, at S700, the region identification request reception unit 600 receives a region identification request transmitted from the Web client 101. Then, at S701, the user ID conversion unit 601 calculates the hash value of the user ID included in the received region identification request.
[0050] Next, at S702, the mapping information collation unit 603 collates the region mapping information from the mapping information management unit 602 based on the hash value of the user ID obtained at S701.
[0051] An example of the mapping information between the hash value of the user ID and the region managed by the mapping information management unit 602 is shown in FIG. 8. "user_id_hash" in the first field is the hash value of the user ID, and "region" in the second field is the registered region of the user. As described above, the user ID is hashed and managed because the user ID may correspond to personal information.
[0052] At S703, the mapping information collation unit 603 determines whether a hash value matching the hash value obtained by the calculation at S701 exists in the mapping information. In other words, the mapping information collation unit 603 determines whether the user ID is registered.
[0053] When a matching hash value is found (when S703 is YES), in S704, the region identification result transmission unit 605 transmits the region associated with the matching hash value to the Web client 101 as the region identification result.
[0054] On the other hand, when the mapping information is not found (when NO in S703), in S705, the region determination unit 604 determines a false region. Then, in S706, the region identification result transmission unit 605 transmits the false region to the Web client 101 as the region identification result.
[0055] Here, the method for determining the false region in S705 will be described using the flowchart of FIG. 9.
[0056] First, in S900, the region determination unit 604 assigns a salt (a predetermined value or a predetermined character string) to the user ID included in the region identification request. Then, in S901, the region determination unit 604 calculates the output of the hash function with the assigned character string as the input as the hash value. Then, in S902, the region determination unit 604 regards the calculated hash value as a numerical value, divides it by the total number of regions, and obtains the remainder value. Next, in S903, the region determination unit 604 determines the region corresponding to the remainder value as the false region.
[0057] For example, in this embodiment, the total number of regions is 2. If the remainder value is 0, the US region is determined as the false region, and if the remainder value is 1, the EU region is determined as the false region. Thus, since the false region is uniquely determined from the user ID, the same region identification result will be responded each time even if a region identification request is transmitted multiple times for the same user ID. Therefore, it can be made difficult to determine whether the user ID is registered in any region.
[0058] Note that the method of uniquely determining a false region from the user ID is not limited to this. For example, the assignment of the sort of S900 may be omitted, and instead of calculating the hash value in S901, the hash value of the user ID calculated in S701 may be substituted. Also, when the user ID is registered in any region, since the region identification result responded by the integration server 130 changes from a false region to a true region before and after that, there is a possibility that the region in which the user ID is registered is determined based on this change. To solve this, the sort, hash function, and hash value calculation algorithm may be periodically changed for some or all user IDs.
[0059] As described above, for a region identification request for a user ID not registered in any region, the integration server 130 of the present embodiment responds with a false region uniquely determined from the user ID. Therefore, it becomes possible to make it difficult for the user of the request source (Web client) to determine whether the user ID is registered by the region identification request.
[0060] Note that in the present embodiment, the integration server 130 transmits the region in which the user ID is registered as the region identification result, and the Web client 101 determines the authentication server from the region, but it is not limited to this. For example, the integration server 130 may transmit, as the region identification result, the URL and domain for accessing the authentication server of the region in which the user ID is registered. Thereby, the authentication server determination process by the Web client 101 can be omitted, and it becomes possible to control the transmission destination of the authentication request in the integration server 130.
[0061] Also, in this embodiment, although the region where the user is registered is specified, it is not limited to this. For example, in order to determine the authentication / authorization server of the device or client service, the region where the device or client service is registered may be specified. Also, in order to control the authentication target of the authentication request sent by the Web client, the organization or realm where the user is registered may be specified.
[0062] [Second Embodiment] In the above first embodiment, in the region specifying process by the integration server 130, a method of determining a false region uniquely determined each time a region specification request is received has been described.
[0063] In this second embodiment, an example in which the same region specification result is responded each time a region specification request is sent a plurality of times for the same user ID will be described. And in this second embodiment, an example in which the integration server 130 uses fake mapping information associating the user ID and the false region information in addition to the mapping information shown in the first embodiment will be described. Note that the network configuration example, the hardware configuration example, the functional configuration example, and the login process by the Web client 101 are the same as those in the first embodiment, and thus the description thereof is omitted.
[0064] The details of the false region determination process (S705 in FIG. 7) in this second embodiment will be described with reference to the flowchart of FIG. 10.
[0065] First, at S1000, the mapping information collation unit 603 collates the fake mapping information in the mapping information management unit 602 using the hash value of the user ID calculated at S701 as a key. An example of the fake mapping information (stored and held in the external storage device 204) managed by the mapping information management unit 602 is shown in FIG. 11. "user_id_hash" in the first field is the hash value of the user ID, and "fake_region" in the second field is the false region information corresponding to the hash value of the user ID that has been responded in the past.
[0066] In S1001, the mapping information verification unit 603 determines whether there is a matching hash value in the false mapping information.
[0067] If it exists (when S1001 is YES), in S1002, the region determination unit 604 determines the region associated with the found hash value as the false region.
[0068] On the other hand, if there is no matching hash value (when S1001 is NO), in S1003, the region determination unit 604 determines the region randomly, for example. Then, in S1004, the mapping information management unit 602 adds and registers the false region determined in S1003 and the hash value of the user ID to the false mapping information.
[0069] As a result, since the false region for a given user ID is uniquely determined, the same region identification result will be responded each time even if a region identification request for the same user ID is sent multiple times. Therefore, it can be made difficult to determine whether the user ID is registered in any region. Although a method of randomly determining the region in S1003 has been described, it is not limited to this.
[0070] For example, the source IP address of the region identification request received in S700 may be analyzed, and a region geographically far from the source may be stored as mapping information. Generally, as the physical distance increases, the communication speed tends to decrease, so it becomes possible to reduce the frequency of sending authentication requests to the authentication server by attackers.
[0071] Thus, according to the information processing system according to this embodiment, for a region identification request for a user ID not registered in any region, the integrated server 130 responds with a false region uniquely determined from the user ID. Therefore, it becomes possible to make it difficult to determine whether the user ID is registered or not based on the region identification request.
[0072] [Third Embodiment] In the above first embodiment, in the region identification process by the integration server 130, a method of determining a false region uniquely determined each time a region identification request is received has been described.
[0073] In this third embodiment, a method will be described in which the integration server returns the region of a pseudo authentication server that does not perform authentication processing as a false region. Note that the description of the hardware configuration example is omitted because it is the same as that of the first embodiment.
[0074] A network configuration example of the information processing system according to this embodiment will be described with reference to the block diagram of FIG. 12.
[0075] In this embodiment, in addition to the network configuration of the first embodiment, a data center 1240 is added, and hereinafter, the data center 1240 is referred to as the AN region. A pseudo authentication server 1242 is connected to the computer network 1241 in the AN region 1240.
[0076] In this embodiment, the pseudo authentication server exists only in the AN region 1240, but is not limited thereto. The pseudo authentication server may exist in a plurality of regions or may also be in a region where an authentication server exists.
[0077] Next, the functional configuration of the integration server 130 according to this embodiment will be described with reference to the block diagram of FIG. 13. The configuration shown in FIG. 13 represents the functional configuration when the CPU 200 of the integration server 130 executes a program for functioning as an integration server. For convenience of explanation, it is assumed that the hardware of the integration server 130 has the configuration shown in FIG. 2.
[0078] In addition to the configuration of the first embodiment, the integrated server 130 includes an attacker determination unit 1306. Since 1300 to 1305 are the same as 600 to 605, the description thereof is omitted. The attacker determination unit 1306 determines whether the Web client is an attacker based on the region identification request and its accompanying information transmitted from the Web client 101.
[0079] Next, the functional configuration of the pseudo authentication server 1242 according to the present embodiment will be described with reference to the block diagram of FIG. 14. The configuration shown in FIG. 14 represents the functional configuration when the CPU 200 of the pseudo authentication server 1242 executes a program for functioning as the pseudo authentication server. For convenience of explanation, it is assumed that the hardware of the pseudo authentication server 1242 has the configuration shown in FIG. 2.
[0080] The pseudo authentication server 1242 includes an authentication request receiving unit 1400, a pseudo authentication unit 1401, an issuing unit 1402, and an authentication result transmitting unit 1403.
[0081] The authentication request receiving unit 1400 receives an authentication request transmitted from the Web client 101 via the network interface 203.
[0082] The pseudo authentication unit 1401 performs pseudo authentication on the authentication request received by the authentication request receiving unit 1400. The pseudo authentication may be a process that always returns an authentication failure, or only the format of the authentication request may be verified in the same manner as the normal authentication process.
[0083] For example, if the authentication servers 113 and 114 have a constraint that the user ID of the authentication request includes specific characters, and the user ID of the authentication request does not include specific characters, a format error is returned to the Web client. In that case, the pseudo authentication unit 1401 verifies whether the user ID of the authentication request includes specific characters in the same manner as the authentication server, and if not, returns a format error to the Web client.
[0084] The issuing unit 1402 issues a pseudo-authentication result based on the result of the pseudo-authentication unit 1401. In the case of authentication failure, the same pseudo-authentication result as the authentication result at the time of authentication failure in the authentication servers 113 and 114 is issued. Alternatively, as the pseudo-authentication result, a pseudo-authentication token having the same format as the authentication token issued when the authentication servers 113 and 114 authenticate successfully may be issued. The pseudo-authentication token is set in a Cookie in the Web client 101 in the same manner as a normal authentication token, but it is a token that cannot be used.
[0085] The authentication result transmission unit 1403 transmits the pseudo-authentication result issued by the issuing unit 1402 to the Web client 101 via the network interface 203.
[0086] Next, the region identification process of the integrated server 130 according to the present embodiment will be described using the flowchart of FIG. 15.
[0087] Since S1500 to S1502 are the same as S700 to S702 in the first embodiment, the description thereof will be omitted.
[0088] In S1503, the attacker determination unit 1306 determines whether the Web client 101 is an attacker. The additional information received together with the region identification request is used for the determination process. For example, the IP address, which is the transmission source information of the region identification request, is acquired as additional information, and if it is a specific IP address or IP address range, it is determined as an attacker. Also, only the legitimate Web client 101 may be made to transmit a specific character string as additional information together with the region identification request, and it is possible to determine whether it is an attacker based on the presence or absence of the additional information.
[0089] Furthermore, the attacker determination unit 1306 may associate the matching result of the mapping information matching unit 1303 with the attached information of the region identification request, save it as a region identification request history, and use it for attacker determination. The IP address, which is the attached information, may be associated with the matching result and saved. If there is a history of more than a certain number of matching failures within a predetermined time from the same IP address, the region identification request from the IP address may be determined to be an attacker.
[0090] When it is determined that it is not an attacker (when S1503 is NO), in S1504, the mapping information matching unit 1303 determines whether the hash value obtained by the calculation in S1501 exists in the mapping information, similar to S703.
[0091] When a matching hash value is found (when S1504 is YES), in S1505, the region identification result transmission unit 1305 transmits the region identification result to the Web client 101, similar to S704.
[0092] On the other hand, when it is determined to be an attacker (when S1503 is YES) or when the mapping information is not found (when S1504 is NO), in S1506, the region determination unit 1304 determines a false region. Then, in S1507, the region identification result transmission unit 1305 transmits the false region to the Web client 101 as the region identification result, similar to S706.
[0093] Here, the method for determining the false region in S1506 is the same as the flowchart in FIG. 9. However, in S902 and S903, the region of the pseudo authentication server is used instead of the region of the authentication server.
[0094] The region determination unit 1304 regards the calculated hash value as a numerical value in S902, divides it by the total number of regions of the pseudo authentication server, and obtains the remainder value. Next, in S903, the region determination unit 1304 determines the region of the pseudo authentication server corresponding to the remainder value as the false region.
[0095] As described above, for a region identification request for a user ID not registered in any region, the integrated server 130 of the present embodiment responds with a false region uniquely determined from the user ID. Further, for a request source (Web client) determined to be an attacker, a false region is also responded. At this time, the false region is selected from the regions of the pseudo authentication server. Therefore, it becomes difficult for the user of the request source (Web client) to determine whether the user ID is registered or not by the region identification request, and the burden on the authentication server can be reduced by using the pseudo authentication server.
[0096] [Fourth Embodiment] In the above-described third embodiment, a method of returning a region of a pseudo authentication server that does not perform authentication processing as a false region in the region identification process by the integrated server 130 has been described.
[0097] In this fourth embodiment, a method in which the integrated server determines whether the Web client is an attacker and notifies the authentication server to omit the authentication process of the authentication server will be described. Note that the network configuration example and the hardware configuration example are the same as those in the first embodiment, and thus the description thereof will be omitted.
[0098] Next, the functional configuration of the integrated server 130 according to the present embodiment will be described with reference to the block diagram of FIG. 16. The configuration shown in FIG. 16 represents the functional configuration when the CPU 200 of the integrated server 130 executes a program for functioning as an integrated server. For convenience of explanation, it is assumed that the hardware of the integrated server 130 has the configuration shown in FIG. 2.
[0099] In addition to the configuration of the third embodiment, the integrated server 130 includes an attacker information notification unit 1607. Since 1600 to 1606 are the same as 1300 to 1306, the description thereof is omitted. The attacker information notification unit 1307 notifies each authentication server of the information of the Web client determined as an attacker by the attacker determination unit 1606. The information to be notified may be any information that can identify the attacker, and information such as the IP address information of the Web client can be used.
[0100] Next, regarding the region specifying process of the integrated server 130 according to the present embodiment, although it is the same as the flowchart of FIG. 15, since it is different in some processes, only that process will be described.
[0101] In S1503, the attacker determination unit 1606 determines whether the Web client 101 is an attacker. The determination method is the same as that of the third embodiment, but if it is determined as an attacker, the attacker information notification unit 1607 notifies each authentication server of the attacker information.
[0102] The method for determining the false region in S1506 is the same as the flowchart of FIG. 9, and the false region is determined from among the authentication servers in the same manner as in the first embodiment.
[0103] Next, the functional configurations of the authentication servers 113 and 114 according to the present embodiment will be described with reference to the block diagram of FIG. 17.
[0104] The authentication servers 113 and 123 each include an authentication request receiving unit 1700, an authentication information management unit 1701, an authentication unit 1702, an issuing unit 1703, an attacker information utilization unit 1704, a pseudo authentication unit 1705, and an authentication result transmission unit 1706.
[0105] The authentication request receiving unit 1700 receives an authentication request transmitted from the Web client 101 via the network interface 203.
[0106] The authentication information management unit 1701 stores, holds, and manages authentication information associating the user IDs and passwords of users registered in each authentication server in the external storage device 204.
[0107] The authentication unit 1702 authenticates the user by comparing the authentication request received by the authentication request receiving unit 1700 with the authentication information managed by the authentication information management unit 1701.
[0108] The issuing unit 1703 issues an authentication token indicating that the user has been authenticated.
[0109] The attacker information utilization unit 1704 stores and holds the attacker information notified by the integrated server 130. In addition, it determines whether the Web client 101 that sent the authentication request is an attacker based on the stored attacker information.
[0110] The pseudo-authentication unit 1705 performs pseudo-authentication on the authentication request determined to be an attacker by the attacker information utilization unit 1704, in the same manner as the pseudo-authentication unit 1401 of the integrated server in the third embodiment. In that case, the issuing unit 1703 issues a pseudo-authentication result based on the result of the pseudo-authentication unit 1705, in the same manner as the issuing unit 1402 of the integrated server in the third embodiment.
[0111] The authentication result transmission unit 1706 transmits the authentication token or pseudo-authentication result issued by the issuing unit 1703 to the Web client 101 via the network interface 203.
[0112] Next, the authentication process of the authentication servers 113 and 123 according to this embodiment will be described using the flowchart of FIG. 18.
[0113] First, at S1800, the authentication request receiving unit 1700 receives the authentication request transmitted from the Web client 101.
[0114] Next, at S1801, the attacker information utilization unit 1704 determines whether the Web client 101 that transmitted the authentication request is an attacker. If it is determined that it is an attacker (YES at S1801), the process proceeds to S1807. If it is determined that it is not an attacker (NO at S1801), the process proceeds to S1802.
[0115] Next, at S1802, the authentication unit 1702 collates the user ID and password included in the authentication request received at S1800 with the authentication information managed by the authentication information management unit 1701.
[0116] If the user ID is registered in the authentication information management unit 1701 and the passwords also match (YES at S1803), at S1804, the issuance unit 1703 issues an authentication token. Then, at S1805, the authentication result transmission unit 1706 transmits the authentication token to the Web client 101 as an authentication result. On the other hand, if the passwords do not match (NO at S1803), at S1806, the authentication result transmission unit 1706 transmits the authentication result to the Web client 101 as an authentication failure.
[0117] Next, at S1807, the pseudo-authentication unit 1705 performs pseudo-authentication and the issuance unit 1703 issues a pseudo-authentication result. The description of the pseudo-authentication and the issuance of the pseudo-authentication result is omitted because it is the same as in the third embodiment.
[0118] Next, at S1808, the authentication result transmission unit 1706 transmits the pseudo-authentication result issued by the issuance unit 1402 to the Web client 101 via the network interface 203.
[0119] As described above, in this embodiment, the integrated server 130 determines whether the Web client 101 is an attacker and notifies the authentication servers 113 and 123, thereby performing pseudo-authentication instead of the authentication process of the authentication servers. As a result, it is possible to reduce the load on each authentication server for the requests of attackers without placing a pseudo-authentication server.
[0120] [Fifth Embodiment] In the first embodiment, a method of determining a false region uniquely determined each time a region specification request is received in the region specification process by the integration server 130 was described.
[0121] In this fifth embodiment, an example in which an authentication server specifies and responds to a region instead of the integration server will be described. Note that since the network configuration example and the hardware configuration example are the same as those in the first embodiment, the description thereof will be omitted.
[0122] First, the functional configuration of the Web client 101 according to the fifth embodiment will be described with reference to the block diagram of FIG. 19. The configuration shown in FIG. 19 represents the functional configuration when the CPU 200 of the Web client 101 executes a program as a Web client.
[0123] The Web client 101 includes a display control unit 1900, an input reception unit 1901, an authentication server determination unit 1902, an authentication request transmission unit 1903, an authentication result reception unit 1904, and an authentication request retransmission unit 1905. For convenience of explanation, it is assumed that the hardware of the Web client 101 has the configuration shown in FIG. 2.
[0124] The display control unit 1900 displays a login screen on the display device 205. Further, the display control unit 1900 displays a login success screen and a login failure screen on the display device 205 according to the authentication result described later.
[0125] The input reception unit 1901 receives the input of the user ID and password from the input device 206 for the login screen displayed by the display control unit 1900.
[0126] The authentication server determination unit 1902 determines a first authentication server and a second authentication server to which an authentication request is to be sent.
[0127] The authentication request sending unit 1903 sends the first authentication request based on the user ID and password received by the input receiving unit 1901 to the first authentication server determined by the authentication server determination unit 1902.
[0128] The authentication result receiving unit 1904 receives the authentication result transmitted from the authentication server.
[0129] The authentication request resending unit 1905 sends the second authentication request based on the user ID and password received by the input receiving unit 1901 to the second authentication server determined by the authentication server determination unit 1902.
[0130] Next, the processing procedure during the login process of the Web client 101 according to the fifth embodiment will be described with reference to the flowchart of FIG. 20.
[0131] First, in S2000, the display control unit 1900 acquires the login screen from the integration server 130 and displays it on the display device 205. Since the displayed login screen is the same as that in the first embodiment, the description thereof is omitted.
[0132] Next, in S2001, the input receiving unit 1901 receives the input of the user ID and password for the login screen from the user. Here, the user uses the input device 206 to input the user ID in the user ID input area 501 of the login screen 500, the password in the password input area 502, and presses the button 503 to confirm the input.
[0133] In response to the determination that the input of the user ID and password has been finalized, at S2002, the authentication server determination unit 1902 determines the first authentication server to which the authentication request is to be sent. For example, when the IP address of the Web client 101 is close to the US region 110, the authentication server determination unit 1902 determines the authentication server 113 in the US region 110 as the first authentication server. Similarly, when the IP address of the Web client 101 is close to the EU region 120, the authentication server determination unit 1902 determines the authentication server 123 in the EU region 120 as the first authentication server. In this way, by determining the authentication server close to the Web client used by the user as the first authentication server, the possibility of authenticating the user in the first authentication request described later is increased.
[0134] Next, at S2003, the authentication request transmission unit 1903 transmits the first authentication request to the first authentication server determined as the transmission target. This authentication request includes at least the user ID and password received by the input reception unit 1901. The URL specified at the time of transmission is a URL with a domain name unique to the US region 110 when the authentication server 113 in the US region 110 is determined as the transmission target of the authentication request. Also, when the authentication server 123 in the EU region 120 is determined as the transmission target of the authentication request, it is a URL with a domain name unique to the EU region 120. The authentication server authenticates the user based on the user ID and password included in the received authentication request, or determines the region, and responds to the requesting Web client 101 with the authentication result. The user authentication and region determination processing by the authentication server will be described later.
[0135] In S2004, the authentication result receiving unit 1904 receives the authentication result transmitted from the first authentication server. Then, in S2005, the authentication result receiving unit 1904 determines whether the received authentication result is an authentication token or a region. If it is an authentication token (when S2005 is YES), in S2006, the display control unit 1900 displays a login success screen on the display device 205. On the other hand, if the authentication result is a region (when S2005 is NO), in S2007, the authentication server determination unit 1902 determines a second authentication server to which the authentication request is to be resent based on the received region. For example, if the received region is the US region 110, the authentication server determination unit 1902 determines the authentication server 113 of the US region 110 as the second authentication server. Similarly, if the received region is the EU region 120, the authentication server determination unit 1902 determines the authentication server 123 of the EU region 120 as the second authentication server.
[0136] Next, in S2008, the authentication request resending unit 1905 sends a second authentication request to the second authentication server determined as the transmission target. This authentication request includes at least the user ID and password received by the input reception unit 1901. The URL specified at the time of transmission is a URL with a domain name unique to the US region 110 when the authentication server 113 of the US region 110 is determined as the transmission target of the authentication request. Also, when the authentication server 123 of the EU region 120 is determined as the transmission target of the authentication request, it is a URL with a domain name unique to the EU region 120. The authentication server authenticates the user or determines the region based on the user ID and password included in the received authentication request, and responds to the requesting Web client 101 with the authentication result.
[0137] In S2009, the authentication result receiving unit 1904 receives the authentication result transmitted from the second authentication server. Then, in S2010, the authentication result receiving unit 1904 determines whether the received authentication result is an authentication token or a region. If it is an authentication token (when S2010 is YES), in S2006, the display control unit 1900 displays a login success screen on the display device 205. On the other hand, if the authentication result is a region (when S2010 is NO), in S2011, the display control unit 1900 displays a login failure screen on the display device 205.
[0138] Next, the functional configurations of the authentication servers 113 and 123 according to the fifth embodiment will be described with reference to the block diagram of FIG. 21. The configuration shown in FIG. 21 represents the functional configuration when the CPUs 200 of the authentication servers 113 and 123 execute a program to function as authentication servers. For convenience of explanation, it is assumed that the hardware of the authentication servers 113 and 123 has the configuration shown in FIG. 2.
[0139] The authentication servers 113 and 123 each include an authentication request receiving unit 2100, an authentication information management unit 2101, an authentication unit 2102, an issuing unit 2103, a user ID conversion unit 2104, a mapping information management unit 2105, a mapping information verification unit 2106, a region determination unit 2107, and an authentication result transmission unit 2108.
[0140] The authentication request receiving unit 2100 receives an authentication request transmitted from the Web client 101 via the network interface 203.
[0141] The authentication information management unit 2101 stores, holds, and manages authentication information associating the user IDs and passwords of users registered in each authentication server in the external storage device 204.
[0142] The authentication unit 2102 authenticates the user by comparing the authentication request received by the authentication request receiving unit 2100 with the authentication information managed by the authentication information management unit 2101.
[0143] The issuing unit 2103 issues an authentication token indicating that the user has been authenticated.
[0144] The user ID conversion unit 2104 converts the user ID included in the authentication request into a hash value.
[0145] The mapping information management unit 2105 stores, holds, and manages in the external storage device 204 the mapping information between the hash value of the user ID registered in each region and the region where the user is registered. Storing the hash value of the user ID is to protect the user ID that may be personal information.
[0146] The mapping information verification unit 2106 verifies (or searches) in the mapping information management unit 2105 using the hash value of the user ID calculated by the user ID conversion unit as a key, determines whether it exists (verification result), and if it exists, identifies the corresponding region.
[0147] The region determination unit 2107 determines a false region based on the user ID included in the authentication request.
[0148] The authentication result transmission unit 2108 transmits an authentication result representing any one of the authentication token issued by the issuing unit 2103, the region specified by the mapping information verification unit 2106, or the false region determined by the region determination unit 2107 to the Web client 101 via the network interface 203.
[0149] Next, the authentication process of the authentication servers 113 and 123 according to the fifth embodiment will be described using the flowchart of FIG. 22.
[0150] First, at S2200, the authentication request receiving unit 2100 receives an authentication request transmitted from the Web client 101.
[0151] Next, in S2201, the authentication unit 2102 collates the user ID and password included in the authentication request received in S2200 with the authentication information managed by the authentication information management unit 2101.
[0152] If the user ID is registered in the authentication information management unit 2101 (when S2202 is YES) and the passwords also match (when S2203 is YES), in S2204, the issuing unit 2103 issues an authentication token. Then, in S2205, the authentication result transmission unit 2108 transmits the authentication token to the Web client 101 as the authentication result. On the other hand, when the passwords do not match (when S2203 is NO), in S2206, the region determination unit 2107 determines a false region. Then, in S2207, the authentication result transmission unit 2108 transmits the false region to the Web client 101 as the authentication result. Note that since the method for determining the false region is the same as that in S705 of the first embodiment, the description is omitted.
[0153] If the user ID is not registered in the authentication information management unit 2101 (when S2202 is NO), in S2208, the user ID conversion unit 2104 calculates the hash value of the user ID included in the authentication request received in S2200.
[0154] Next, in S2209, the mapping information collation unit 2106 collates the region mapping information from the mapping information management unit 2105 based on the hash value of the user ID obtained in S2208. Since the region mapping information is the same as the example in the first embodiment, the description is omitted.
[0155] When mapping information that matches the hash value is found (when S2210 is YES), in S2211, the authentication result transmission unit 2108 transmits the region associated with the matching hash value to the Web client 101 as the authentication result.
[0156] On the other hand, when the mapping information is not found (when S2210 is NO), in S2212, the region determination unit 2107 determines a false region. Then, in S2213, the authentication result transmission unit 2108 transmits the false region to the Web client 101 as an authentication result. Note that the method for determining the false region is the same as that in S705 of the first embodiment, so the description thereof is omitted.
[0157] As described above, the authentication servers 113 and 123 of the fifth embodiment respond with an authentication token to an authentication request including a correct user ID and password. When the Web client 101 determines the authentication server in which the user ID is registered as the first authentication server and transmits the first authentication request, the login is completed by one communication between the Web client and the authentication server, so the usability of the user is improved. Further, for an authentication request for a user ID not registered in any region and an authentication request with an incorrect password, a false region uniquely determined from the user ID is responded, so it is also possible to make it difficult to determine whether the user ID is registered.
[0158] Note that in the fifth embodiment, the authentication servers 113 and 123 determine and respond with a false region uniquely determined from the user ID, but this determination method may be common among the authentication servers. Thereby, since the region responded for each user ID is unique in each authentication server, it becomes possible to make it even more difficult to determine whether the user ID is registered.
[0159] (Other embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiment to a system or device via a network or a storage medium, and having one or more processors in a computer of the system or device read and execute the program. Further, it can also be realized by a circuit (for example, ASIC) that realizes one or more functions.
[0160] The invention is not limited to the above embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Therefore, claims are appended to disclose the scope of the invention.
Explanation of Signs
[0161] 100…Internet, 101…Web client, 110…US region, 120…EP region, 112, 122…Reverse proxy server, 113, 123…Authentication server, 114, 124…Resource server, 130…Integration server, 600…Region-specific request receiving unit, 601…User ID conversion unit, 602…Mapping information management unit, 603…Mapping information verification unit, 604…Region determination unit, 605…Region-specific result transmission unit
Claims
1. An information processing apparatus that transmits region information representing a corresponding region to a client terminal in response to a region specification request received from the client terminal via the Internet, comprising: communication means for communicating with the Internet; management means for managing mapping information in which user information and region information are associated; collation means for collating the mapping information of the management means when a region specification request including user information for specifying a user is received from the client terminal via the communication means; when the collation result of the collation means indicates that the corresponding user information exists in the mapping information, transmitting the corresponding region information to the client terminal as a response; response means for transmitting false region information to the client terminal as a response when the collation result of the collation means indicates that the corresponding user information does not exist in the mapping information An information processing apparatus characterized by comprising.
2. The user information includes a user ID for specifying a user, The management means manages, as the mapping information, information in which a hash value of the user ID and region information are paired, The collation means obtains a hash value from the user ID included in the received region specification request, and performs collation by searching the mapping information using the hash value as a key The information processing apparatus according to claim 1, characterized in that.
3. When the collation result of the collation means indicates that a value that matches the hash value of the corresponding user ID does not exist in the mapping information, the response means transmits, as a response, false region information uniquely determined by a numerical value represented by the hash value of the user ID The information processing apparatus according to claim 1, characterized in that.
4. The response means responds with information representing a region specified by a remainder value obtained by dividing a numerical value represented by the hash value of the user ID by the number of regions managed by the management means as the false region information The information processing apparatus according to claim 3, characterized in that.
5. The management means further manages false mapping information in which a hash value of a user ID that does not exist in the mapping information and the false region information are paired, The response means When the matching result of the matching means indicates that there is no value that matches the hash value of the user ID corresponding to the mapping information, and there is a value that matches the dummy mapping information, the corresponding dummy region information in the dummy mapping information is responded. When the matching result of the matching means indicates that there is no value that matches the hash value of the user ID corresponding to the mapping information and there is also no value that matches the dummy mapping information, a pair of the hash value of the user ID and new dummy region information is registered in the dummy mapping information, and the new dummy region information is responded. The information processing apparatus according to claim 1, characterized in that.
6. The apparatus further comprises attacker determination means for determining whether the client terminal is an attacker. In addition to the case where the corresponding user information does not exist in the mapping information, when the attacker determination means determines that the client terminal is an attacker, the response means also transmits dummy region information as a response. The information processing apparatus according to any one of claims 1 to 5, characterized in that.
7. The attacker determination means determines whether it is an attacker based on the region identification request and its accompanying information sent from the client terminal. The information processing apparatus according to claim 6, characterized in that.
8. The attacker determination means stores the region identification request and its accompanying information sent from the client terminal as a region identification request history associated with the result of the matching means, and uses the region identification request history to determine whether it is an attacker. The information processing apparatus according to claim 6, characterized in that.
9. A control method of an information processing apparatus having communication means for communicating with the Internet and management means for managing mapping information in which user information and region information are associated, and for transmitting region information representing the corresponding region to the client terminal in response to a region identification request received from the client terminal via the communication means, comprising: When a region identification request including user information for identifying a user is received from a client terminal via the communication means, a matching step of matching the mapping information of the management means. When the matching result of the matching process indicates that the corresponding user information exists in the mapping information, the corresponding region information is transmitted to the client terminal as a response, and a response process of transmitting false region information to the client terminal as a response when the matching result of the matching process indicates that the corresponding user information does not exist in the mapping information. A control method for an information processing apparatus, characterized by comprising the above.
10. A program for causing a computer to execute each step of the method according to claim 9 when the computer reads and executes it.
11. A system including an integrated server deployed in one or more regions, an authentication server deployed in one or more regions, and a pseudo authentication server deployed in one or more regions, wherein the integrated server has communication means for communicating with the Internet, management means for managing mapping information in which user information and region information are associated, matching means for matching the mapping information of the management means when receiving a region specification request including user information for specifying a user from a client terminal via the communication means, attacker determination means for determining whether the client terminal is an attacker, response means for transmitting the corresponding region information to the client terminal as a response when the matching result of the matching means indicates that the corresponding user information exists in the mapping information, and response means for transmitting the region information of the pseudo authentication server also when the matching result of the matching means indicates that the corresponding user information does not exist in the mapping information and when the attacker determination means determines that the client terminal is an attacker. The authentication server has communication means for communicating with the Internet, authentication means for authenticating a user when receiving an authentication request from the client terminal via the communication means, and response means for transmitting an authentication token as a response when the authentication result of the authentication means indicates successful authentication, and transmitting authentication failure as a response when authentication fails, to the client terminal. The pseudo authentication server has communication means for communicating with the Internet, and pseudo authentication means for pseudo authenticating a user when receiving an authentication request from the client terminal via the communication means. Response means for transmitting the spoof authentication result of the spoof authentication means as a response to the client terminal A system characterized by this.
12. The attacker determination means in the integrated server determines whether it is an attacker based on the region specification request sent from the client terminal and its attached information The system according to claim 11, characterized by this.
13. The attacker determination means in the integrated server stores the region specification request sent from the client terminal and its attached information as a region specification request history associated with the result of the collation means, and uses it for determining whether it is an attacker The system according to claim 11, characterized by this.
14. The spoof authentication means in the spoof authentication server regards it as authentication failure regardless of the content of the authentication request sent from the client terminal The response means in the spoof authentication server responds with a result imitating the authentication failure transmitted by the authentication server when authentication fails as the spoof authentication result The system according to claim 11, characterized by this.
15. The spoof authentication means in the spoof authentication server regards it as authentication success regardless of the content of the authentication request sent from the client terminal The response means in the spoof authentication server responds with a spoof authentication token imitating the authentication token transmitted by the authentication server when authentication is successful as the spoof authentication result The system according to claim 11, characterized by this.
16. A system including an integrated server deployed in one or more regions and an authentication server deployed in one or more regions, wherein The integrated server is Communication means for communicating with the Internet Management means for managing mapping information in which user information and region information are associated Collation means for collating the mapping information of the management means when receiving a region specification request including user information for specifying a user from a client terminal via the communication means Attacker determination means for determining whether the client terminal is an attacker Attacker information notification means for notifying the authentication server of attacker information indicating that the client terminal is an attacker via the communication means when the attacker determination means determines that it is an attacker When the verification result of the verification means indicates that the corresponding user information exists in the mapping information, the corresponding region information is transmitted to the client terminal as a response. In addition to the case where the verification result of the verification means indicates that the corresponding user information does not exist in the mapping information, when the attacker determination means determines that the client terminal is an attacker, there is also a response means for transmitting the region information of the pseudo authentication server. The authentication server has communication means for communicating with the Internet, stores the attacker information notified from the integration server via the communication means, and when receiving an authentication request from the client terminal, determines whether the client terminal is an attacker based on the attacker information. The attacker information utilization means has authentication means for authenticating a user using the authentication request received from the client terminal when the attacker information utilization means determines that the client terminal is not an attacker. has pseudo authentication means for pseudo authenticating a user when the attacker information utilization means determines that the client terminal is an attacker. has response means for transmitting, to the client terminal, an authentication token as a response when the authentication means indicates successful authentication, an authentication failure as a response when authentication fails, and the pseudo authentication result of the pseudo authentication means as a response when the pseudo authentication means is used. A system characterized by the above.
17. The attacker determination means in the integration server determines whether it is an attacker based on the region specification request sent from the client terminal and its accompanying information. The system according to claim 16, characterized in that.
18. The attacker determination means in the integration server stores the region specification request sent from the client terminal and its accompanying information as a region specification request history associated with the result of the verification means, and uses this region specification request history to determine whether it is an attacker. The system according to claim 16, characterized in that.
19. The pseudo authentication means in the authentication server regards it as authentication failure regardless of the content of the authentication request sent from the client terminal. The response means in the authentication server responds with a result imitating the authentication failure transmitted as the pseudo authentication result when authentication fails. The system according to claim 16, characterized in that.
20. The pseudo-authentication means in the authentication server regards it as a successful authentication regardless of the content of the authentication request sent from the client terminal, and the response means in the authentication server responds with a pseudo-authentication token imitating the authentication token to be transmitted when the authentication is successful as the pseudo-authentication result. The system according to claim 16, characterized in that.
21. An information processing apparatus that transmits an authentication result to the client terminal for an authentication request received from a client terminal via the Internet, comprising: communication means for communicating with the Internet; authentication means for authenticating a user when receiving an authentication request including user information for identifying the user from the client terminal via the communication means; management means for managing mapping information in which user information and region information are associated; collation means for collating the mapping information of the management means when the authentication result of the authentication means indicates that the authentication has failed due to an error in the user information; when the authentication result of the authentication means indicates that the authentication has been successful, transmitting an authentication token to the client terminal as a response; when the collation result of the collation means indicates that the corresponding user information exists in the mapping information, transmitting the corresponding region information to the client terminal as a response; response means for transmitting false region information to the client terminal as a response when the authentication result of the authentication means indicates that the authentication has failed regardless of an error in the user information, or when the collation result of the collation means indicates that the corresponding user information does not exist in the mapping information. An information processing apparatus characterized by comprising.
22. The user information includes a user ID for identifying the user, the management means manages information in which the hash value of the user ID and the region information are paired as the mapping information, and the collation means obtains a hash value from the user ID included in the received authentication request and performs collation by searching the mapping information using the hash value as a key. The information processing apparatus according to claim 21, characterized in that.
23. When the collation result of the collation means indicates that a value matching the hash value of the corresponding user ID does not exist in the mapping information, the response means transmits, as a response, false region information uniquely determined by the numerical value represented by the hash value of the user ID. The information processing apparatus according to claim 21, characterized in that.
24. The response means responds with information representing a region specified by a remainder value obtained by dividing a numerical value represented by a hash value of the user ID by the number of regions managed by the management means as the false region information. The information processing apparatus according to claim 23, characterized in that.
25. A control method for an information processing apparatus, comprising: a communication means for communicating with the Internet; and a management means for managing mapping information in which user information and region information are associated, and transmitting an authentication result to the client terminal in response to an authentication request received from the client terminal via the Internet. An authentication step of authenticating a user when an authentication request including user information for specifying the user is received from the client terminal via the communication means; A collation step of collating the mapping information of the management means when the authentication result of the authentication step indicates that the authentication has failed due to an error in the user information; When the authentication result of the authentication step indicates that the authentication has succeeded, an authentication token is transmitted to the client terminal as a response. When the collation result of the collation step indicates that the corresponding user information exists in the mapping information, the corresponding region information is transmitted to the client terminal as a response. A response step of transmitting false region information to the client terminal as a response when the authentication result of the authentication step indicates that the authentication has failed not due to an error in the user information, or when the collation result of the collation step indicates that the corresponding user information does not exist in the mapping information. A control method for an information processing apparatus, characterized by comprising.
26. A program for causing a computer to execute each step of the method according to claim 25 when the computer reads and executes the program.
27. A system including an authentication server deployed in one or more regions and a client terminal having a web browser. The authentication server is A communication means for communicating with the Internet; An authentication means for authenticating a user when an authentication request including user information for specifying the user is received from the client terminal via the communication means; A management means for managing mapping information in which user information and region information are associated; A collation means for collating the mapping information of the management means when the authentication result of the authentication means indicates that the authentication has failed due to an error in the user information. When the authentication result of the authentication means indicates successful authentication, an authentication token is transmitted to the client terminal as a response. When the collation result of the collation means indicates that the corresponding user information exists in the mapping information, the corresponding region information is transmitted to the client terminal as a response. When the authentication result of the authentication means indicates authentication failure regardless of user information error, or when the collation result of the collation means indicates that the corresponding user information does not exist in the mapping information, there is a response means for transmitting false region information to the client terminal as a response. The client terminal has an authentication request transmission means for transmitting a first authentication request to any one of the authentication servers deployed in one or more regions. When region information is responded to the authentication request, it has an authentication request retransmission means for transmitting a second authentication request to the authentication server of that region. A system characterized by the above.
28. The response means determines false region information in a common method among all authentication servers deployed in one or more regions and transmits it to the client terminal as a response. The system according to claim 27, characterized by the above.
29. The authentication request transmission means determines an authentication server based on the proximity from the client terminal among the authentication servers deployed in one or more regions and transmits a first authentication request. The system according to claim 27, characterized by the above.
Citation Information
Patent Citations
Intrusion countermeasure processing system, attack analysis / response device, network shutoff / simulation device and intrusion countermeasure processing method
JP2005004617A
Image alignment type authentication system
JP2007094523A
Attack determination device, and attack determination method and program
JP2010152773A
Cyber security system with adaptive machine learning features
JP2019032828A
System and control method thereof
JP2019101668A