Authentication System, Authentication Method, and Program Using Image Passwords
The authentication system uses image component semantic information for secure and user-friendly password authentication, addressing the challenge of balancing ease and security by allowing flexible image component selection and analysis.
Patent Information
- Application Number
- JP2022009864
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-26
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-01-26
AI Technical Summary
Existing authentication methods using passwords face challenges in balancing ease of use and security strength, particularly when images are used, as they require displaying multiple images for accurate input, which can lead to security risks if leaked.
An authentication system that uses semantic information of image components as passwords, allowing flexible selection and identification through user interaction, such as clicking or gaze, without increasing the number of displayed images, and leveraging image analysis or AI for authentication.
Enhances security intensity by making passwords easy to remember and difficult to guess or infer, while maintaining a small number of displayed images, thus reducing the risk of unauthorized access.
Smart Images

Figure 0007713404000001 
Figure 0007713404000002 
Figure 0007713404000003
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication system that uses an image as a password.
Background Art
[0002] Conventionally, an authentication method has been known in which a password is input as an image of an image instead of characters. For example, in Patent Document 1, in order to simplify the password input operation and prevent erroneous operations, when performing personal authentication of a user of a system, among a plurality of images displayed on the display screen of a display device, a plurality of images assigned to the user are selected, and personal authentication is performed by determining whether or not the selected plurality of images are legitimate. In this method, a plurality of images are divided into a plurality of groups, a GUI for selecting one image for each of the plurality of groups is displayed on the display screen, a combination of the plurality of images selected by the GUI is converted into a character string indicating a password, and it is determined whether or not it is legitimate.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Generally, in authentication using a password, many use characters or numbers, and the security strength can be increased by changing the number of digits or the character types of the password. Also, there is an advantage that it is easy to use a common password in a plurality of systems, but there is also a risk that if a password leaks in one system, access to other systems becomes possible. Also, even when using an image as a password, in order to increase the security strength, it was necessary to display many images and have the user accurately input the image registered as the password.
[0005] Therefore, in the present invention, in view of the above problems, by using an image to appeal to human vision, not only a password that is easy to remember is set, but also the security strength can be enhanced without increasing the number of images displayed on the password input screen. An object of the present invention is to provide an authentication method for an image-based password that can achieve this.
Means for Solving the Problems
[0006] To solve the above problems, the present invention provides the following solutions.
[0007] (1) An authentication system that authenticates a user by an image, comprising: authentication rule setting means for setting an authentication rule for authenticating the user based on a combination of image components constituting the image; image display control means for controlling the display of the image; selection image reception means for receiving selection of the displayed image and the image components; meaning information acquisition means for acquiring meaning information representing characteristics of the image components of the selected image in character information; and authentication determination means for determining whether the acquired meaning information matches the meaning information set in the authentication rule.
[0008] (2) In the configuration described in (1) above, the meaning information acquisition means is characterized in that the image components are specified based on position information where the user clicks or touches an image on the screen.
[0009] (3) In the configuration described in (1) above, the meaning information acquisition means is characterized in that the image components are specified by detecting a position where the user wears smart glasses and focuses the line of sight.
[0010] (4) In the configuration according to any one of (1) to (3) above, the authentication rule setting means is characterized in that a mesh-shaped rectangle is displayed on the image to allow selection of the image components of the image.
[0011] (5) In the configuration described in (4) above, when the authentication rule setting means cannot identify semantic information within the selected rectangle in the user-specified image, it extracts the semantic information of the image by searching the periphery of the rectangle.
[0012] (6) In the configuration according to any one of (1) to (5) above, the image is characterized in that it is an image of a character of a brand related to the site operating the authentication system or an image of a product.
[0013] (7) An authentication method for authenticating a user by an image, comprising steps of: the authentication server setting an authentication rule for authenticating the user based on a combination of the image and image components; controlling the display of the image; receiving a selection of the displayed image and image components; obtaining semantic information representing the characteristics of the selected image components in character information; and determining whether the obtained semantic information matches the semantic information set in the authentication rule.
[0014] (8) A program characterized in that each step described in (7) above is executed in the authentication server or in a combination of the authentication server and a terminal.
Advantages of the Invention
[0015] According to the present invention, it is possible to provide an authentication method using an image-based password that can enhance security intensity without arbitrarily increasing the number of images displayed on the password input screen while serving as a password that appeals to human vision and is easy to remember.
Brief Description of the Drawings
[0016]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Mode for Carrying Out the Invention
[0017] Hereinafter, with reference to the accompanying drawings, embodiments for carrying out the present invention (hereinafter referred to as embodiments) will be described in detail. In the following figures, the same elements are denoted by the same numbers or symbols throughout the description of the embodiments.
[0018] <Summary> FIG. 1 is a diagram for explaining the outline of the image password according to the present invention. In the present invention, password authentication is performed using image information instead of password by character information. That is, in an authentication system for authenticating an individual, a plurality of images are displayed on an authentication screen, and the authentication (login) can be performed by selecting the correct image set as the password. Here, in order to use an image as a password (sometimes referred to as an "image password"), "meaning information" of the image is used instead of the identifier (image ID) of the image. The "meaning information" of the image is character information for specifying "image components" which are components constituting one image.
[0019] For example, the images A1 to A6 shown in FIG. 1 have common semantic information of "person" as a whole, but each image may have individual semantic information such as "gray-haired young man", "man in a suit", "woman with glasses", "girl in red clothes", "man in work clothes", "man with a purple tie", etc. Also, each image component should be given semantic information. As described above, semantic information is what expresses the characteristics of the components of an image in character information. For example, the names of the clothes, accessories, and items carried by the "person" (such as "T-shirt", "suit", "glasses", "ribbon", "tie", etc.) become the semantic information of the image components respectively. In addition to the names of the components, features such as shape, color, and pattern are also included. Furthermore, the background of the person may also be a component. That is, the background color, scenery, etc. may also be given semantic information as image components. Also, since the selection of the image components used as the password is based on the semantic information which is character information, more flexible image components can be defined compared to assigning identifiers to the image components.
[0020] Hereinafter, in an authentication system which is an embodiment of the present invention (hereinafter referred to as this system), a specific example of login using an image-based password and the features of this system will be described.
[0021] As shown in "(1) At login" in FIG. 1, multiple images are displayed on the login screen of this system, and an image having the semantic information to be input as the image password is selected from among these images. At this time, the selectable images shall randomly change on the screen. For example, assuming that the semantic information as the image password has already been set as "blue tie", at login, the tie part which is a component of the image shown by A2 shall be selected. At this time, if the image of A5 is selected and the tie part is selected, it means the same "blue tie" has been selected.
[0022] Rather than selecting the entire image, selecting image components allows a large amount of semantic information to be included in a single image, enabling the creation of multiple image passwords with a small number of images. Here, as a method of "selecting" image components, when the device displaying the login screen is a PC, it is only necessary to click on specific components in the image with a mouse. In the case of a device with a touch panel such as a smartphone, touch the location where you want to select the component with your finger or a pen. In either case, the position information of the image component in the image can be detected, and the image component can be authenticated including which position in the image was selected.
[0023] Although it is an extreme example, it is also possible to authenticate by displaying only one image on the login screen at a time and selecting the components of that single image in the correct order. In the case of a complex image, when a large number of images are displayed on a small screen such as a smartphone at once, the selection of image components becomes complicated, so it may be better to display only one image with a large number of components.
[0024] At the next login (or after a certain period of time), as shown in "(2) At the next login" in Figure 1, a plurality of different images are displayed, and the image components to be input are selected from among them. At this time, on the system, the semantic information of the image components selected on the login screen is extracted. This extraction may be performed by analyzing using known image analysis techniques or AI (Artificial Intelligence) techniques. At the time of authentication, the semantic information of the selected image components is specified, and it is determined whether the sequence of semantic information matches the semantic information as the password registered associated with the user's ID.
[0025] The authentication using the above image-based password has the following characteristics. (1) Since the images to be selected are provided for each system, it becomes difficult to divert the password between systems. That is, it is also possible to force the use of a system-specific password. (2) Passwords can be entered from different images with the same semantic information. For example, although Image A2 and Image A5 in Figure 1 are different images, they have a common image component of "blue necktie", so no matter which image is displayed, "blue necktie" can be selected as the image password. Also, there is no need to exchange image data between the terminal and the server, and it can be exchanged with image IDs. (3) Since the information of the image and the password is in an inclusion relationship, it is impossible to tell which is the password just by looking at the input operation on the login screen. That is, as an operation on the screen, it is impossible to tell which component of the image the user is focusing on to select the image. Therefore, even if someone peeks at the password input operation from the side, they cannot tell why the image was selected, which also helps prevent social engineering. (4) If the number of images displayed on the login screen is small, the possibility of the password being breached by random input increases. Also, if the entire image is selected one by one, the components that do not overlap between multiple images will become the password, making it easier for others to guess. To avoid this, when entering the password, allow multiple image components to be entered continuously. By doing this, the semantic information of one image cannot be narrowed down to one, and it becomes difficult to infer the semantic information from the selected image.
[0026] Also, as an extended function of this system, the type of image can be devised. For example, as the image used for the password, use the character of the brand related to the site that operates this system. Although the password input screen within the site tends to be plain, using the brand character of the site for the image can maintain the brand image of the entire site. Also, in the context of an increasing number of multi-factor authentications across multiple sites, it becomes easier for users to recognize which site they are currently authenticating on.
[0027] In addition, promotional activities may be carried out using images for passwords. For example, in a confectionery company, if the image displayed on the login screen is a person eating the company's product, it can also serve as a promotion for the company's products. Also, this month, by allowing users to log in with an image of a character from a certain anime, a tie-up with another company can be promoted. However, whether the user sets the above image as an image password is a separate issue.
[0028] <Functional Configuration of the System> FIG. 2 is a diagram showing the functional configuration of an authentication system according to an embodiment of the present invention. In this figure, the arrows between the functional blocks represent the data flow direction or the processing flow direction.
[0029] As shown in the figure, the authentication system of this embodiment is composed of an authentication server 10 and a user terminal 20 connected to the authentication server 10 via a network. The authentication server 10 includes, as its functional configuration, an image library DB 11, an authentication rule setting means 12, an image display control means 13, a selected image reception means 14, an image component detection means 15, a semantic information acquisition means 16, an authentication rule storage means 17, and an authentication determination means 18. Note that the authentication server 10 may be a physical server or a server realized on the cloud.
[0030] The user terminal 20 in this system may be a general PC (personal computer) or a tablet terminal such as a smartphone. Further, the user terminal 20 may be smart glasses, which are a type of wearable device equipped with sensors, cameras, microphones, speakers, displays, etc. When using smart glasses, the user can easily select image components by concentrating their gaze on a specific location on the screen.
[0031] Hereinafter, the functional configuration of the authentication server 10 in FIG. 2 will be described in order. The image library DB11 is a database for storing images in the authentication server 10, and stores image component data 11a for each image. FIG. 3 is a diagram showing an example of the image component data 11a stored in this image library DB11. The image component data 11a holds the classification of the image group (in this example, "person"), the image IDs of a plurality of images (such as image01~06), and the semantic information of the image components. Here, the "semantic information" is, as already described, character information that simply represents the external features of an entire image or each image component that constitutes the image. Images are classified by nouns such as "person", "animal", "building", "natural object", etc., and terms that further limit the external features of the image to the noun, for example, adjectives such as "red", "black-colored", "patterned with XX", or adjectival verbs such as "doing XX", "being XX" may be added. The semantic information may be a single term or may be composed of a combination of multiple terms.
[0032] In FIG. 3, it shows how the semantic information assigned to the entire image and the image components is held in tabular form. Table 101 stores the image IDs of image01~image06 displayed on the login screen 100 and the semantic information of the image components of each image. The semantic information may be manually added when registering the image in the database. Also, based on rules (semantic information) specified by the user from a group photo or the like, correct and incorrect figures may be cut out. For example, when instructing "blue tie", cut out the range where a person wearing a blue tie appears as the correct figure, and as the incorrect figure, deliberately cut out a person image with a different hair color, or an image with or without a hat so that the correct meaning "blue tie" cannot be inferred. Also, as described above, the image may be automatically decomposed into image components and the semantic information generated using image analysis technology or AI technology.
[0033] Returning to FIG. 2, the authentication rule setting means 12 provides a function for setting an authentication rule by an image for each user, that is, for setting image components to be used as a password. Although specific examples will be described later, the user can select a plurality of image components from the image database registered on the system or select a plurality of image components from the unique images stored in the user terminal or the like and register them as a password.
[0034] FIG. 4 is a diagram showing an example of a screen for registering this authentication rule in the system. In the authentication rule setting screen 102 shown, the user selects an arbitrary search word (in this example, "walking the dog"), and shows a state of setting (registering) an authentication rule using an image component as a password from among the image group image11 to image16 displayed as a result of the search.
[0035] When the user selects an image to be used as a password on the screen 102, a mesh-shaped rectangle is displayed on the image. Here, the system determines whether or not it can specify semantic information for the partial image in each mesh, and if the semantic information can be specified, it changes the color of the mesh or the like to indicate that the mesh (image component) can be used as a password. The image component for which the semantic information has been specified may be displayed with its outline emphasized.
[0036] If the semantic information of the mesh cannot be specified, it searches for the surrounding meshes, and when the semantic information can be specified, it collectively changes the color of the meshes in that range. At this time, the display size of the mesh may be changed. Needless to say, the image component data 103 stored in the image library DB11 is referred to for specifying the semantic information of the image component. In order for the user to easily find the image component, the range having the semantic information may be set to a specific mesh position. As for the usage, in the case of selecting images arranged in 3×3 or 4×4 or selecting a plurality of images arranged in 3 or 4 images multiple times, it is necessary to search for the part having the semantic information from the entire image many times, but by doing so, the desired position can be specified quickly.
[0037] Then, by clicking or touching the mesh specified as usable as a password by the user, or by concentrating the line of sight with smart glasses, the semantic information of the image components of the mesh can be specified as the password. In this example, on screen 102, (1) "dumpling hairstyle" is set as semantic information from the image of image13, (2) "no hairstyle" is set as semantic information from the image of image16, and (3) "gray back" is set as semantic information from the image of image15. The semantic information set in this way is saved as an authentication rule together with the set order.
[0038] Note that in the registered images in the image library DB11, image components and semantic information are stored in advance for each image. However, for user - unique images where the image components and semantic information cannot be identified, the scale of the mesh is automatically changed and the identification is attempted again. However, if the screen components and semantic information still cannot be identified, the user is instructed to select another image.
[0039] Returning to FIG. 2 again, the image display control means 13 reads a specific image from the image library DB11 or the user terminal 20 according to an operation from the user terminal 20 and displays it on the screen of the user terminal 20. In this example, as the type of image, an image of a single person is shown, but of course, it does not have to be a single - body image. For example, any image with features that are easy to distinguish, such as one or more people and animals, people and scenery, vehicles and buildings, or scenery, etc., is acceptable.
[0040] The selected - image receiving means 14 has a function of receiving the image selected by the user and the components of the image from the image displayed by the image display control means 13.
[0041] The image component detection means 15 detects the image received by the selected image reception means 14 and the analysis of the components of the image. For this detection, the position of the image on the screen or the position information of the clicked or touched location within a single image is used. Also, if the user terminal 20 is smart glasses, the position information of the location where the user concentrated their gaze on the screen is used.
[0042] The semantic information acquisition means 16 uses image analysis technology to detect the semantic information of the image and the image components. For example, if the image selected by the user is the entire image, the semantic information is extracted from the characteristics of the entire image. For example, for an image centered on a person, the semantic information such as "person", "male", "female", "child", "young person", "old person", etc. is first extracted. Furthermore, the occupation that can be identified from the appearance of the person (e.g., "baseball player", "doctor", "police officer", "singer", etc.) and the information about the person's actions (e.g., "a person running", "a person fishing", "a person walking", etc.) are also extracted as semantic information. Also, when the user selects a position within a specific image, if it can be determined that it is, for example, clothing, the type, shape, color, pattern, etc. of the clothing are also extracted as semantic information. Also, the hairstyle, color, accessories worn by the person, and the characteristics of the background are also extracted as semantic information.
[0043] The authentication rule storage means 17 stores the semantic information of the image components set as the password. It is not necessary to store the image data itself as the authentication rule.
[0044] The authentication determination means 18 determines whether the sequence of the semantic information of the image components selected on the login screen 100, etc. matches the sequence of the semantic information of the image components stored in the authentication rule storage means 17 associated with the user's ID. When the semantic information completely matches, it is determined that the normal authentication is completed.
[0045] The above functional configuration of the present system is merely an example, and one functional block (database and functional processing unit) may be divided, or a plurality of functional blocks may be combined into one functional block. Each functional processing unit reads a computer program stored in a storage device such as a CPU (Central Processing Unit) built into the device, (optionally including a GPU (Graphic Processing Unit)), ROM (Read Only Memory), flash memory, SSD (Solid State Drive), hard disk, etc., and is realized by the computer program executed by the CPU. That is, each functional processing unit realizes the computer program by reading and writing necessary data such as tables from a database (DB; Data Base) stored in the storage device or a storage area in the memory, and optionally controlling related hardware (e.g., input / output devices, display devices, communication interface devices). Also, the database (DB) in the embodiment of the present invention may be a commercial database, but also means a mere collection of tables or files, and the internal structure of the database itself is not limited.
[0046] <System processing flow>
[0047] Figure 5 is a diagram showing the processing flow of authentication rule setting by image. In the following processing flow diagrams (flowcharts), the processing order of each step may be changed as long as the input-output relationship of each step is not impaired. Also, Y and N under the decision block in the figure represent Yes and NO. "In the following description, the reference numerals of the functional blocks shown in FIG. 2 are omitted.
[0048] First, in step S10, the user is allowed to select whether to use the registered image as the password image. If the registered image is used, the process proceeds to step S13. Otherwise, the image data specified by the user is acquired (step S11), the user's image is analyzed using image analysis technology or AI technology, the semantic information of the image and its components is identified (step S12), and the process moves to step S15.
[0049] If the registered image is used, in step S13, the image image and image component data are read from the image library DB. Next, in step S14, an input of a search word from the user is accepted, and the images of the search results are displayed. Then, it is determined whether a specific image component is selected (clicked, touched, etc.) (step S15).
[0050] If a specific image component is selected, in step S16, the semantic information of that image component is acquired, and the semantic information of that image component is acquired (step S17). If a specific image component is not selected, the process returns to step S14 to accept the re - input of the search word.
[0051] Subsequently, in step S17, it is determined whether another image component is selected. If Yes, the process returns to step S16. If No, in step S18, the user is confirmed whether to complete the setting. When the setting is completed, finally, in step S19, the semantic information of the image components selected as the image password and their order are saved as the user's authentication rule.
[0052] Figure 6 is a diagram showing the processing flow of image password determination. First, in step S20, the position information selected (clicked, touched, etc.) on the screen displayed on the login screen is acquired.
[0053] Next, in step S21, it is determined whether there is semantic information in the image component of the position information. If the result is No, the process returns to step S20. If the result is Yes, in step S22, the semantic information is saved.
[0054] Then, in step S23, if it is determined that the user has finished selecting the position information, the process proceeds to step S24, where the acquired semantic information is compared with the semantic information stored in the authentication rule to determine whether the semantic information matches.
[0055] If the information matches in step S25, authentication is successful (step S26). If the semantic information does not match, authentication fails (step S27). At this time, in step S28, the user is asked to determine whether to reselect the position information (retry). If the user chooses to retry, the process returns to step S20. If the user chooses not to retry, the process ends.
[0056] <Effect of the Embodiment> As described above, according to this system, in order to perform authentication using an image, the image component used as a password is specified by semantic information which is character information. Therefore, compared with assigning an identifier to the image component, a flexible image component can be defined. The acquisition of this semantic information can identify the image component based on the position information where the user clicks or touches the image on the screen. Also, when using smart glasses, the semantic information can be identified by detecting the position information where the user focuses their line of sight without the user having to click or touch the screen.
[0057] In addition, for the authentication rule setting, by displaying a mesh-shaped rectangle on the image to be used as a password, it is possible to make it easier to select the image components of the image. Also, for a user-specified image, when the semantic information of the image components cannot be identified, the area around the mesh can be searched to identify the semantic information of the components in a wider range.
[0058] In addition, the images used in this system may basically be of any kind, but they may also be images of the characters or products of the brand related to the site that operates this system. By doing so, it is possible to maintain the brand image and expect a promotional effect, and it is also possible to make it easier for users to recognize which site they are currently authenticated on.
[0059] As described above, the present invention has been described using the embodiments. Needless to say, the technical scope of the present invention is not limited to the scope described in the above embodiments. It is obvious to those skilled in the art that various changes or improvements can be made to the above embodiments. Also, it is obvious from the description of the claims that forms with such changes or improvements can also be included in the technical scope of the present invention.
[0060] In addition, in the above embodiment, the present invention has been described as an invention of an object, that is, an authentication system (authentication server and user terminal). However, the present invention can also be regarded as an invention of an authentication method or an invention of a computer program (a program executed on the authentication system).
Explanation of Reference Numerals
[0061] 10 Authentication server 11 Image library DB 11a Image component data 12 Authentication rule setting means 13 Image display control means 14 Selected image reception means 15 Image component detection means 16 Semantic information acquisition means 17 Authentication rule storage means 18 Authentication determination means 20 User terminal 100 Image group 101 Image component data represented in tabular form 102 Authentication rule setting screen 103 Image component data represented in tabular form of the authentication rule setting screen
Claims
1. An authentication system for authenticating a user by an image, comprising: authentication rule setting means for setting an authentication rule for authenticating the user based on a combination of image components constituting the image; image display control means for controlling the display of the image; selected image reception means for receiving selection of the displayed image and the image components; meaning information acquisition means for acquiring meaning information expressing the characteristics of the image components of the selected image in character information; authentication determination means for determining whether the acquired meaning information matches the meaning information set in the authentication rule, wherein the authentication rule setting means further comprises means for extracting the meaning information of the image component by searching the periphery of the range when the meaning information of the image component cannot be specified within the range selected by the user on the screen. The authentication system is characterized by this.
2. The authentication system according to claim 1, wherein the meaning information acquisition means identifies the image component based on position information of a position where the user clicks or touches the image on the screen.
3. The authentication system according to claim 1, wherein the meaning information acquisition means identifies the image component by detecting a position where the user wears smart glasses and focuses the line of sight.
4. The authentication system according to claim 2 or 3, wherein the authentication rule setting means causes the user to select the image component by displaying a mesh-shaped rectangle on the image.
5. The authentication system according to claim 4, wherein the authentication rule setting means extracts the meaning information of the image by searching the periphery of the rectangle when the meaning information cannot be specified within the selected rectangle in the user-specified image.
6. The authentication system according to any one of claims 1 to 5, wherein the image is an image of a brand character or a product related to the site operating the authentication system.
7. An authentication method for authenticating a user by an image, comprising: an authentication server setting an authentication rule for authenticating the user based on a combination of the image and image components; controlling the display of the image; receiving selection of the displayed image and image components; A step of obtaining semantic information expressing the characteristics of the image components of the selected image in character information; A step of determining whether or not the obtained semantic information matches the semantic information set in the authentication rule, and execute; The step of setting the authentication rule includes a step of extracting the semantic information of the image component by searching the periphery of the range when the semantic information of the image component cannot be specified within the range selected on the screen by the user; An authentication method characterized by this.
8. A program characterized by causing each step described in Claim 7 to be executed in the authentication server or in a combination of the authentication server and the terminal.
Citation Information
Patent Citations
Personal authentication method
JP2001282738A
Information processing apparatus, information processing system, control method, and program
JP2014081729A
Authentication system, authentication method, authentication device, authentication program, authentication information input device, and authentication information input program
JP2015219594A
Icon password setting device and method for setting icon passwords using icon keywords
JP2015521311A
User authentication device for authenticating user, program executed by user authentication device, program executed by input device for authenticating user, and computer system having user authentication device and input device
JP2020064689A