Authentication Requirement Setting Device, Authentication Requirement Setting Method, and Program

The authentication requirement setting device optimizes multi-factor authentication by calculating entropy and setting reduced input requirements, addressing the increased burden in conventional systems while maintaining security.

JP7709663B2Active Publication Date: 2025-07-17NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024526169
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-09
Publication Date
2025-07-17
Estimated Expiration
2042-06-09

AI Technical Summary

Technical Problem

Conventional multi-factor authentication systems increase user burden due to the time required for inputting multiple factors, despite enhancing security.

Method used

An authentication requirement setting device that calculates the entropy of combined authentication methods and sets requirements based on a threshold to minimize the number of inputs needed while maintaining security.

Benefits of technology

Reduces user burden during multi-factor authentication by optimizing the complexity of authentication inputs, ensuring security without compromising on safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007709663000001
    Figure 0007709663000001
  • Figure 0007709663000002
    Figure 0007709663000002
  • Figure 0007709663000003
    Figure 0007709663000003
Patent Text Reader

Abstract

The purpose of the present disclosure is to reduce a burden on a user required for authentication while ensuring the security of authentication even when multi-factor authentication is required. In view of the above, the present disclosure provides an authentication requirement setting device for setting an authentication requirement in a case where a plurality of authentication methods are used in combination, the authentication requirement setting device comprising: a selection reception unit that receives a selection of authentication methods; an entropy calculation unit that calculates the entropy of the received authentication methods; an authentication requirement setting unit that sets authentication requirements for satisfying a predetermined level of security on the basis of a difference between a threshold value and the calculated entropy; and an output unit that outputs the set authentication requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a technique for reducing the burden on user authentication by combining multiple authentication methods.

Background Art

[0002] In many network services including financial institutions, multi-factor authentication is used. By introducing multi-factor authentication that combines multiple factors (knowledge information, possession information, biometric information) for authentication, the security of the service can be improved (see Non-Patent Document 1).

Prior Art Documents

Non-Patent Documents

[0003]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the conventional technology, compared with single-factor authentication, it takes more time to input multiple factors, so there is a problem that the burden on the user increases.

[0005] The present invention has been made in view of the above points, and an object thereof is to reduce the burden on the user required for authentication while ensuring the security in authentication even when multi-factor authentication is required.

Means for Solving the Problems

[0006] In order to solve the above problems, the invention according to claim 1 is an authentication requirement setting device that sets authentication requirements when combining a plurality of authentication methods, comprising a selection reception unit that receives a selection of an authentication method, an entropy calculation unit that calculates the entropy of the received authentication method, a threshold value, an authentication requirement setting unit that sets authentication requirements satisfying a predetermined security based on the difference between the calculated entropy and the threshold value, and an output unit that outputs the set authentication requirements.

Effect of the Invention

[0007] As described above, according to the present invention, even when multi-factor authentication is required, it is possible to achieve the effect of reducing the burden on the user required for authentication while ensuring the security in authentication.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Mode for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0010] 〔System Configuration of the Embodiment〕 First, with reference to FIG. 1, the overall configuration outline of the communication system of the present embodiment will be described. FIG. 1 is an overall configuration diagram of the communication system according to the present embodiment.

[0011] As shown in FIG. 1, the communication system 1 of the present embodiment is constructed by an authentication requirement setting device 3 and a communication terminal 5.

[0012] The authentication requirement setting device 3 is composed of one or more computers. When the authentication requirement setting device 3 is composed of a plurality of computers, it may be referred to as the "authentication requirement setting device" or the "authentication requirement setting system".

[0013] The authentication requirement setting device 3 sets authentication requirements when at least two authentication methods (authentication methods based on knowledge information, possession information, or biometric information) required for multi-factor authentication are combined. Knowledge information is, for example, a password, a PIN (Personal Identification Number) code, a secret question (such as the name of a pet), etc. Possession information is, for example, a mobile phone, a hardware token, an IC (Integrated Circuit) card, etc. Biometric information is fingerprint authentication, iris authentication, voice authentication, etc. The combination method of the authentication methods may be, for example, fingerprint authentication and iris authentication classified into the same biometric information. Also, the set authentication requirements are, for example, the number of digits of a password to ensure a predetermined security recommended by a country or the like.

[0014] In FIG. 1, as an example, a notebook computer is shown as the communication terminal 5. In FIG. 1, the user operates the communication terminal 5. The user is a person who inputs a plurality of elements required for multi-factor authentication.

[0015] Also, the authentication requirement setting device 3 and the communication terminal 5 can communicate via a communication network 100 such as the Internet. The connection form of the communication network 100 may be either wireless or wired.

[0016] 〔Hardware Configuration〕 <Hardware Configuration of the Authentication Requirement Setting Device> Next, with reference to FIG. 2, the electrical hardware configuration of the authentication requirement setting device 3 will be described. FIG. 2 is an electrical hardware configuration diagram of the authentication requirement setting device.

[0017] As a computer, the authentication requirement setting device 3 includes a CPU (Central Processing Unit) 301, a ROM (Read Only Memory) 302, a RAM (Random Access Memory) 303, an SSD (Solid State Drive) 304, an external device connection I / F (Interface) 305, a network I / F 306, a media I / F 309, and a bus line 310, as shown in FIG. 2.

[0018] Among these, the CPU 301 controls the operation of the entire authentication requirement setting device 3. The ROM 302 stores programs used for driving the CPU 301, such as an IPL (Initial Program Loader). The RAM 303 is used as a work area for the CPU 301.

[0019] The SSD 304 reads or writes various data according to the control of the CPU 301. Note that an HDD (Hard Disk Drive) may be used instead of the SSD 304.

[0020] The external device connection I / F 305 is an interface for connecting various external devices. The external devices in this case include a display, a speaker, a keyboard, a mouse, a USB (Universal Serial Bus) memory, and a printer, etc.

[0021] The network I / F 306 is an interface for data communication via the communication network 100.

[0022] The media I / F 309 controls the reading or writing (storage) of data to / from a recording medium 309m such as a flash memory. The recording medium 309m also includes a DVD (Digital Versatile Disc), a Blu-ray Disc (registered trademark), etc.

[0023] The bus line 310 is an address bus, a data bus, etc. for electrically connecting each component such as the CPU 301 shown in FIG. 2.

[0024] Note that since the communication terminal 5 has the same hardware configuration as the authentication requirement setting device, its description is omitted.

[0025] 〔Functional Configuration of Authentication Requirement Setting Device〕 Subsequently, the functional configuration of the authentication requirement setting device 3 according to the present embodiment will be described with reference to FIG. 3. FIG. 3 is a functional configuration diagram of the authentication requirement setting device.

[0026] As shown in FIG. 3, the authentication requirement setting device 3 includes a selection reception unit 31, an entropy calculation unit 33, an authentication requirement setting unit 35, and an output unit 39. Each of these units is a function realized by an instruction from the CPU 301 in FIG. 2 based on a program.

[0027] The selection reception unit 31 receives the selection of one or more authentication methods sent from the communication terminal 5 or directly input to the authentication requirement setting device 3.

[0028] The entropy calculation unit 33 calculates the entropy of the authentication method received by the selection reception unit 31. The entropy in this case indicates the number of bits related to authentication. This will be described in detail later. When the selection reception unit 31 receives the selection of a plurality of authentication methods, the entropy calculation unit 33 calculates the total entropy of the plurality of authentication methods.

[0029] The authentication requirement setting unit 35 sets authentication requirements that meet a predetermined security level based on the difference between a threshold value and the entropy calculated by the entropy calculation unit 33. Specifically, when the entropy calculated by the entropy calculation unit 33 is less than the threshold value, the authentication requirement setting unit 35 sets an authentication requirement corresponding to the difference. Also, when the entropy calculated by the entropy calculation unit 33 is greater than or equal to the threshold value, the authentication requirement setting unit sets a predetermined authentication requirement (for example, sets the required number of digits of the password to 4 digits).

[0030] The output unit 39 outputs information on the setting result indicating the authentication requirements set by the authentication requirement setting unit 35 from the authentication requirement setting device 3 and transmits it to the communication terminal 5.

[0031] 〔Processing or operation of the authentication requirement setting device〕 Subsequently, with reference to FIG. 4, the processing or operation executed by the authentication requirement setting device 3 will be described. FIG. 4 is a flowchart showing the processing or operation executed by the authentication requirement setting device.

[0032] S11: The selection reception unit 31 receives the selection of one or more authentication methods sent from the communication terminal 5 or directly input to the authentication requirement setting device 3. The plurality of authentication methods are, for example, a password for knowledge authentication, authentication using an IC card as possession information, and fingerprint authentication as biometric information. Also, the plurality of authentication methods may be different authentication methods (for example, fingerprint authentication, iris authentication) for the same biometric information.

[0033] S12: The entropy calculation unit 33 determines whether the selection reception unit 31 has received the selection of a plurality of authentication methods.

[0034] S13: When the selection of a plurality of authentication methods has been received (S12; YES), the entropy calculation unit 33 calculates the sum of the entropies of the selected plurality of authentication methods.

[0035] Here, a method for calculating the overall entropy of authentication is defined. In this embodiment, the entropy of the authentication method used is represented by the number of bits, and the overall entropy of authentication is calculated in terms of the number of bits using the following (Equation 1).

[0036] Overall entropy of authentication = Sum of entropies (in bits) of each authentication method... (Equation 1) For example, in S11, when the selection reception unit 31 receives the selection of two authentication methods (fingerprint authentication, iris authentication), the entropy calculation unit 33 calculates as follows.

[0037] (Authentication method 1) Fingerprint authentication: Entropy "about 24 bits" False acceptance rate 0.00001% → Entropy 10 million Example of false acceptance rate of fingerprint authentication: See Reference 1 <Reference 1>https: / / jpn.nec.com / biometrics / fingerprint / about.html 10 million = (10^3)^2 × 10 ≒ (2^10)^2 × 2^4 = 2^20 × 2^4 = 2^24 (Authentication method 2) Iris authentication: Entropy "about 20 bits" False acceptance rate 1 / 1.2 million → Entropy 1.2 million Example of false acceptance rate of iris authentication: See Reference 2 <Reference 2> https: / / iris.pas-ta.io / about / 1.2 million ≒ (10^3)^2 ≒(2^10)^2 = 2^20 <Sum of entropies (in bits) of two authentication methods> 24 bits + 20 bits = 44 bits S14: When the selection of multiple authentication methods is not received (S12; NO), the entropy calculation unit 33 calculates the entropy of the selected authentication method.

[0038] S15: The authentication requirement setting unit 35 determines whether the entropy calculated by the entropy calculation unit 33 in S13 or S14 is less than the threshold value.

[0039] For example, the threshold value for satisfying a predetermined security (strength) is set in advance as 72 bits (expressing the 12th power of 64 in terms of the number of bits). If a password, which is an example of knowledge authentication, is the 12th power of 64 (64 types of characters (a~z·A~Z·0~9·+-), 12 characters), then 64 to the 12th power = 64^12 = (2^6)^12 = 2^72.

[0040] <The remaining number of bits required to satisfy the threshold of 72 bits> 72 (threshold) - 44 (calculation result of S13) = 28 (bits) In this case, since it is 28 bits lower than the threshold of 72 bits, it is less than the threshold value.

[0041] S16: If the entropy is less than the threshold value (S15; YES), the authentication requirement setting unit 35 sets the minimum necessary authentication requirements based on the difference between the threshold value and the entropy.

[0042] For example, in the above example, the user's password only needs to be 28 bits or more.

[0043] 28 bits = 2^28 = (2^6)^4 × 2^4 Thus, in terms of the number of password digits (number of characters, symbols), it corresponds to 4 to 5 digits.

[0044] Therefore, the authentication requirement setting unit 35 sets the number of password digits "5" as the minimum necessary authentication requirement to ensure security. Here, the authentication requirement setting unit 35 sets the number of password digits as the authentication requirement, but it may also be other knowledge information, or possession information or biometric information. Also, here, the authentication requirement setting unit 35 sets the authentication method (knowledge information) of the authentication requirement, but the user may also select the authentication method of the authentication requirement in S11.

[0045] S17: If the entropy is not less than the threshold value (if it is greater than or equal to the threshold value) (S15; NO), the authentication requirement setting unit 35 sets predetermined authentication requirements.

[0046] S18: The output unit 39 outputs information on the setting result indicating the authentication requirements set by the authentication requirement setting unit 35 from the authentication requirement setting device 3 and transmits it to the communication terminal 5.

[0047] Thus, the description of the processing or operation of the authentication requirement setting device ends.

[0048] 〔Effect of the Embodiment〕 As described above, according to this embodiment, when using a plurality of authentication methods such as biometric authentication together with the password input by the user, by reducing the authentication requirements such as the number of characters of the password by the amount of entropy (complexity) of the authentication method, it is possible to secure the safety in authentication and reduce the burden on the user required for authentication.

[0049] 〔Supplementary Explanation〕 The present invention is not limited to the above-described embodiment, and may be configured or processed (operated) as described below. (1) Although the authentication requirement setting device 3 can also be realized by a computer and a program, it is also possible to record this program on a (non-transitory) recording medium or provide it via the communication network 100. (2) In the above embodiment, a notebook personal computer is shown as an example of the communication terminal 5, but it is not limited thereto, and for example, a desktop personal computer, a tablet terminal, a smartphone, a smartwatch, a car navigation device, a refrigerator, a microwave oven, etc. may also be used. (3) The CPU 301 may be not only single but also plural.

Explanation of Reference Numerals

[0050] 1 Communication system 3 Authentication requirement setting device 5 Communication terminal 31 Selection reception unit 33 Entropy calculation unit 35 Authentication requirement setting unit 39 Output unit

Claims

1. An authentication requirement setting device for setting authentication requirements when combining a plurality of authentication methods, a selection reception unit that receives a selection of an authentication method, an entropy calculation unit that calculates the entropy of the received authentication method, an authentication requirement setting unit that sets authentication requirements satisfying a predetermined security based on a difference between a threshold value and the calculated entropy, an output unit that outputs the set authentication requirements, and an authentication requirement setting device having the above.

2. When the selection reception unit receives a selection of a plurality of the authentication methods, the entropy calculation unit calculates the total entropy of the plurality of authentication methods, and the authentication requirement setting unit sets the authentication requirements based on a difference between the threshold value and the calculated total entropy. The authentication requirement setting device according to claim 1.

3. The authentication requirement setting unit sets the authentication requirements corresponding to the difference when the entropy calculated by the entropy calculation unit is less than the threshold value. The authentication requirement setting device according to claim 1 or 2.

4. The authentication requirement setting unit sets predetermined authentication requirements when the entropy calculated by the entropy calculation unit is greater than or equal to the threshold value. The authentication requirement setting device according to claim 1 or 2.

5. The entropy is the number of bits related to authentication. The authentication requirement setting device according to claim 1 or 2.

6. The authentication requirements set by the authentication requirement setting unit are the number of digits of a password required for authentication. The authentication requirement setting device according to claim 1 or 2.

7. An authentication requirement setting method executed by an authentication requirement setting device for setting authentication requirements when combining a plurality of authentication methods, wherein the authentication requirement setting device executes a selection reception process for receiving a selection of an authentication method, an entropy calculation process for calculating the entropy of the received authentication method, an authentication requirement setting process for setting authentication requirements satisfying a predetermined security based on a difference between a threshold value and the calculated entropy, and an output process for outputting the set authentication requirements. The authentication requirement setting method executed by the authentication requirement setting device.

8. A program for causing a computer to execute the method according to claim 7. ​ ​

Citation Information

Patent Citations

  • Safe self-adaptive authentication system

    JP2019023859A

  • Authentication mediating device and authentication mediating program

    JP2020173507A

  • Content user authentication system and content user authentication method

    JP2020181395A

  • Continuous multi-factor authentication system

    US20200322330A1