Authentication system, false information providing site detection system, authentication method, false information providing site detection method, and program

The authentication system uses a whitelist and dummy information to identify and block malicious third parties, preventing impersonation and information leakage by employing a processing mechanism to manage authorized and unauthorized access effectively.

JP7725287B2Active Publication Date: 2025-08-19ACSION CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021131260
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-11
Publication Date
2025-08-19
Estimated Expiration
2041-08-11

AI Technical Summary

Technical Problem

Existing authentication systems fail to prevent damage from phishing sites by not anticipating the issue of stolen login information and do not effectively block malicious third parties from impersonating legitimate users.

Method used

An authentication system that uses a whitelist database to manage authorized user information, a dummy information database to identify malicious third parties, and a processing mechanism to block access from such parties, even after legitimate user information is leaked, by employing dummy information to identify and block unauthorized access.

Benefits of technology

The system quickly and reliably prevents damage from impersonation by malicious third parties without complex processing, blocking access and minimizing information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725287000001
    Figure 0007725287000001
  • Figure 0007725287000002
    Figure 0007725287000002
  • Figure 0007725287000003
    Figure 0007725287000003
Patent Text Reader

Abstract

To provide an authentication system and so on capable of preventing the exploitation against a malicious third party who desires to exploit various types of information used for authenticating an authorized user and capable of precisely preventing damage caused by "spoofing" an authorized user without complicated processing.SOLUTION: An authentication server device 10 has a configuration that the authentication server device performs authentication processing including dummy determination processing to determine if there is dummy information matching at least one of input identification information and input key information, that the device identifies the user who inputs inputting information as a malicious third party when it is determined that there is the dummy information matching the inputting information received by the dummy determination processing, and that the device performs specific processing such as registering the corresponding authorized user identification information and authorized key information in blacklist information against the malicious third party.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication system, a system for detecting a site providing false information, an authentication method, a method for detecting a site providing false information, and a program. [Background technology]

[0002] In recent years, fraudulent use, such as so-called spoofing, has been rapidly increasing in services such as internet banking services and online stores via the World Wide Web (WWW).

[0003] Recently, a technology has become known that detects unauthorized access based on information about a user's actions when the user accesses a website that provides various services on the Internet using an ID and password (for example, Patent Document 1). [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-63728 Summary of the Invention [Problem to be solved by the invention]

[0005] However, systems such as that described in Patent Document 1 simply record the actions of users who access websites and build a whitelist database, and do not anticipate the issue of preventing the damage that would result if a legitimate user's login information were to be stolen by a fake information provider site (i.e., if they were phished).

[0006] The present invention has been made to solve the above-mentioned problems, and its purpose is to provide an authentication system etc. that can prevent malicious third parties from exploiting various information used in authenticating legitimate users, and can accurately prevent damage caused by "impersonating" a legitimate user (i.e., damage caused by impersonation) without complex processing.

[0007] Another object of the present invention is to provide a false information site detection system that automates a system that can prevent the exploitation of information from legitimate users during authentication, which is the purpose of false information sites (i.e., phishing sites), from the establishment of such sites (making them viewable on the network), and easily constructs a system that can easily identify the authentication of such malicious third parties. [Means for solving the problem]

[0008] (1) In order to solve the above problems, the present invention provides: An authentication system that performs authentication for access from a communication terminal device of each user connected via a network, a whitelist management means for managing a whitelist database in which whitelist information is stored in advance, in which, for each authorized user, authorized user identification information indicating identification information for identifying the user is associated with authorized key information indicating key information used when performing the authentication; Dummy information to be used by a malicious third party, which is the same as the legitimate user identification information a dummy information management means for managing a dummy information database in which dummy information is registered in advance, in which dummy identification information having a format and dummy key information having the same format as the regular key information are associated with each other; a receiving means for receiving input information input by a user from the communication terminal device when performing the authentication; an authentication processing means for executing authentication processing of the user who inputs the input information based on information included in the received input information, including input identification information indicating the identification information and input key information indicating the key information, the whitelist information, and the dummy information; a specific processing means for performing a given specific processing based on a result of the authentication processing; Equipped with The authentication processing means execute the authentication process, which includes a dummy determination process of searching the dummy information database based on the input identification information and the input key information, and determining whether or not there is dummy information that matches at least one of the input identification information and the input key information; The specific processing means If the dummy determination process determines that there is dummy information that matches the received input information, the user who entered the input information is identified as a malicious third party, and the identification process is executed against the malicious third party.

[0009] With this configuration, the present invention can easily identify access by malicious third parties, so that not only can it block access from malicious third parties as an identification process, but if it obtains information about the communication terminal device of the malicious third party, it can also block access that uses the identification information and key information of legitimate users that are subsequently leaked using the communication terminal device.

[0010] Therefore, by using dummy information, the present invention can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating (i.e., logging in) legitimate users, and even after the information has leaked, the network service provider can quickly prevent damage associated with the leak.

[0011] As a result, the present invention can quickly and reliably prevent damage caused by a malicious third party "impersonating" a legitimate user (i.e., impersonation damage) without complex processing.

[0012] Note that "authorized user" refers to the person registered for authentication purposes, and indicates that the information used for authentication, such as ID and password, is not that of a malicious third party (i.e., a user who is not an unauthorized user).

[0013] The "authorized user identification information" includes, for example, the user's ID (that is, identification information) and the user name (user's name, nickname, or login name).

[0014] In addition, "key information" includes, for example, information for identifying the user from other users, such as a user name (including a nickname), a password, and pattern information, as well as information for identifying the user and information about the user.

[0015] Furthermore, "dummy information" is information that a malicious third party uses to exploit the authentication of others to expose criminals.

[0016] In addition to the above, "whitelist information" refers to, for example, the identification information and key information of authorized users. This shows the information in a list that combines information from other sources.

[0017] Furthermore, "same format" means, for example, that the same number of characters (including alphanumeric characters and symbols) or characters of the same type and combinable characters within a predetermined range of characters (e.g., 8 or more characters, 5 or more characters, 10 or less characters, etc.).

[0018] The "authentication process" is a process for verifying that the accessing user is the actual user, and at least determines whether or not the authentication that allows the user to access various information as a legitimate user has been successful.

[0019] Furthermore, the "identification process" includes, for example, a process of canceling the authentication process, a notification process of notifying an administrator of information regarding the identified malicious third party, and a registration process of registering the legitimate user identification information and legitimate key information used by the identified malicious third party as a blacklist to be blocked in future authentication.

[0020] (2) The present invention also provides a registration control means for registering terminal-related information indicating information about the communication terminal device that transmitted the input information as unauthorized access information in a database for unauthorized access information when it is determined by the dummy determination process that there is dummy information that matches the received input information; Further provided with When the receiving means receives, as the input information, input terminal related information indicating terminal related information related to the communication terminal device that transmitted the input information, The authentication processing means executes an access determination process to determine whether the received input terminal related information matches the unauthorized access information; The specific processing means If the received input terminal related information matches the unauthorized access information in the access determination process, the identification process is executed.

[0021] With this configuration, the present invention can easily identify access by malicious third parties, so that not only can it block access from malicious third parties as an identification process, but if it obtains information about the communication terminal device of the malicious third party, it can also block access that uses the identification information and key information of legitimate users that are subsequently leaked using the communication terminal device.

[0022] In other words, the present invention registers terminal-related information about a terminal device 20 that may have been used by a malicious third party, and by comparing it with the registered terminal-related information, it is possible to prevent information leakage based on other legitimate user identification information and legitimate key information that may have been leaked to fake information providing sites uncovered by the Me determination process.

[0023] "Terminal-related information" includes, for example, information indicating the type of communication terminal device (personal computer, tablet information terminal device, smartphone, etc.), information indicating the type of access application such as a web browser used by the communication terminal device to access the device, the type of language used set on the communication terminal device, and communication identification information for identifying the communication partner such as an IP address (logical address).

[0024] (3) The present invention also provides The identification information and the key information that have been used or may be used by unauthorized users are listed to prohibit the authentication process. The device further comprises a blacklist management means for managing a blacklist database in which blacklist information is stored, The specific processing means If the received input terminal related information matches the unauthorized access information in the access determination process, (a) searching the whitelist database based on the input identification information and input key information input together with the input terminal related information; (b) registering the authorized user identification information and the authorized key information that match the input identification information and the input key information in the blacklist information; The specific processing is executed.

[0025] With this configuration, the present invention can block access (i.e., authentication) based on legitimate information that shows signs of having been leaked, even if there is continuous access from a malicious third party, or even if the malicious third party accesses using another terminal device.

[0026] It should be noted that "blacklist information" refers to, for example, information on a list that combines the identification information and key information of legitimate users that have been used by malicious third parties.

[0027] In addition, the legitimate user identification information and legitimate key information registered in the "blacklist information" may also be registered in the whitelist information, or may be deleted from the whitelist information and registered only as a blacklist.

[0028] (4) The present invention also provides The identification process includes a notification process for notifying an administrator or a corresponding authorized user of information about the malicious third party.

[0029] With this configuration, the present invention can provide information about malicious third parties to the administrator.

[0030] The "notification process" includes, for example, notification by text via an information terminal device such as email or chat, notification on a screen such as a monitor of an information system (including a personal computer or portable information terminal device), notification by sound such as a siren, and notification by a light source (i.e., light) such as a specified lamp or LED.

[0031] (5) The present invention also provides The system further comprises a dummy information provision control means for providing the registered dummy information to a fake information providing site that exploits the legitimate user identification information and the legitimate key information.

[0032] With this configuration, the present invention can automate a system that can detect malicious third parties from the provision of dummy information, making it possible to easily build a system that can easily identify the authentication of such malicious third parties.

[0033] An "information providing site" refers to one or more pages on which various information and data such as images (including still images and videos) on web pages, sounds, and texts are made public on a network, and is a site used to provide network services to authorized users using authorized user identification information and authorized key information.

[0034] In addition, "fake information providing sites" are so-called phishing sites, which are sites that trick users into visiting them. This refers to sites that are used to steal personal information such as user names (including not only names but also nicknames), user IDs (user identification information), passwords, PIN numbers, and credit card numbers.

[0035] (6) The present invention also provides a legitimate site management means for managing a database in which provider information indicating information on a provider of a legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; an analysis and determination processing means for executing an analysis process to analyze a detection target site, which is an information providing site that exists on the network and is to be detected, and for executing a target site determination process to determine whether the detection target site is a fake information providing site or not, based on legitimate site information, target network address information indicating the address of the detection target site on the network, and target design information indicating information regarding the design that forms the detection target site; a dummy information provision control means for executing a process for providing the registered dummy information to the fake information providing site when the target site is determined to be a fake information providing site by the target site determination process; The present invention has a configuration further comprising:

[0036] With this configuration, the present invention can prevent "impersonation" of legitimate users with the aim of exploiting legitimate user identification information and legitimate key information by reversely utilizing false information providing sites (so-called phishing sites).

[0037] In other words, the present invention can identify the identification information and key information of legitimate users that have already been leaked by detecting fake information providing sites, allowing network service providers to quickly prevent damage associated with the leak, and can prevent the leakage of the identification information and key information of legitimate users in advance, thereby minimizing damage.

[0038] The present invention can be realized with a simple configuration as a system that can easily and quickly identify the authentication of a malicious third party.

[0039] It should be noted that "provider information" includes, for example, not only information used within an information provider site operated by a legitimately registered company, organization, or individual, but also information that is likely to be used on that information provider site.

[0040] Furthermore, "design-related information (design information)" refers to information such as the arrangement and overall composition of screen components (including moving images) such as pictures, symbols, marks, images, and text (including stylized ones), as well as color composition.

[0041] Furthermore, a "fake information site" refers to a site that masquerades as a company or individual and is mistaken for a genuine information site (i.e., a phishing site).

[0042] In addition to the above, the "processing for providing to a fake information providing site" includes not only the process of automatically providing dummy information to a fake information providing site, but also various processes that are performed manually by an administrator, etc. when providing dummy information to an information providing site, such as memory control for storing the network address of the fake information providing site, or notification control for notifying the system administrator.

[0043] (7) The present invention also provides The analysis and determination processing means By the analysis process, the presence or absence of the provider information and the legitimate design information in the detection target site is analyzed, and a detection target address indicating a network address in the detection target site is identified; The system is configured to execute the target site determination process to determine that the detection target site is the fake information provider site when at least one of the following conditions is met: (a) the detection target site contains the provider information, (b) the detection target site incorporates information that is identical to or deemed to be identical to the legitimate design information, and (c) the identified detection target address is an address that is different from the legitimate network address information but matches at least a portion of it.

[0044] With this configuration, the present invention can prevent "impersonation" of legitimate users with the aim of exploiting legitimate user identification information and legitimate key information by reversely utilizing fake information providing sites, and can also easily identify the authentication of malicious third parties and establish a simple system for such identification.

[0045] It should be noted that a "network address" is a unique address on a network for identifying an information providing site, such as a domain, a URL (Uniform Resource Locator), or an IP address.

[0046] In addition, "information considered to be identical" includes information that does not match completely, but where the text matching rate in each part (components that make up each page) or the color information (RGB values, brightness, luminance) matching rate is above a certain level.

[0047] (8) In order to solve the above problems, the present invention provides: A false information site detection system for detecting a false information site that is an information site that publishes given information on a network and is a legitimate information site, comprising: a legitimate site information management means for managing a legitimate site database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as identification information of a legitimate user and dummy key information having the same format as key information used when the legitimate user performs authentication on a legitimate information site are associated with each other; a detection means for executing a site detection process for detecting a new information providing site for disclosing given information having a network address on the network; an analysis and determination processing means for executing an analysis process for analyzing a detection target site that indicates the detected information providing site, and for executing a target site determination process for determining whether the detection target site is a fake information providing site that indicates the fake information providing site based on the stored legitimate site information; a dummy information provision control means for executing a process for providing the registered dummy information to the fake information providing site when the target site is determined to be a fake information providing site by the target site determination process; The configuration includes:

[0048] With this configuration, the present invention can detect false information provided by a website and prevent the spread of false information. Since it is possible to identify the identification information and key information of unauthorized users, the network service provider can quickly prevent damage associated with the leakage, and it is also possible to prevent the leakage of the identification information and key information of the legitimate user in advance, thereby minimizing damage.

[0049] The present invention can be realized with a simple configuration as a system that can easily and quickly identify the authentication of a malicious third party.

[0050] (9) In order to solve the above problems, the present invention provides: The system further comprises a management means for managing a legitimate address database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information, The analysis and determination processing means By the analysis process, the presence or absence of the provider information and the legitimate design information in the detection target site is analyzed, and a detection target address indicating a network address in the detection target site is identified; The system is configured to execute the target site determination process to determine that the detection target site is the fake information provider site when at least one of the following conditions is met: (a) the detection target site contains the provider information, (b) the detection target site incorporates information that is identical to or deemed to be identical to the legitimate design information, and (c) the identified detection target address is an address that is different from the legitimate network address information but matches at least a portion of it.

[0051] With this configuration, the present invention can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating (i.e., logging in) legitimate users by using dummy information, and can also quickly prevent damage associated with the leak of such information even after the information has been leaked by the network service provider.

[0052] Therefore, the present invention can quickly and reliably prevent damage caused by a malicious third party "impersonating" a legitimate user (i.e., impersonation damage) without complex processing.

[0053] (10) In order to solve the above problems, the present invention provides: A program that performs authentication for access from a communication terminal device of each user connected via a network, a whitelist management means for managing a whitelist database in which whitelist information is stored in advance, in which, for each authorized user, authorized user identification information indicating identification information for identifying the user is associated with authorized key information indicating key information used when performing the authentication; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as the legitimate user identification information and dummy key information having the same format as the legitimate key information are associated with each other; a receiving means for receiving input information input by a user from the communication terminal device when performing the authentication; an authentication processing means for performing authentication processing of a user who inputs the input information based on information included in the received input information, including input identification information indicating the identification information and input key information indicating the key information, the whitelist information, and the dummy information; and a specific processing means for performing a given specific processing based on a result of the authentication processing; Make the computer function as The authentication processing means execute the authentication process, which includes a dummy determination process of searching the dummy information database based on the input identification information and the input key information, and determining whether or not there is dummy information that matches at least one of the input identification information and the input key information; The specific processing means If the dummy determination process determines that there is dummy information that matches the received input information, the user who entered the input information is identified as a malicious third party, and the identification process is executed against the malicious third party.

[0054] With this configuration, the present invention can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating (i.e., logging in) a legitimate user, and can accurately prevent damage caused by such malicious third parties "impersonating" a legitimate user (i.e., damage caused by impersonation) without performing complex processing.

[0055] (11) In order to solve the above problems, the present invention provides: A program for detecting a fake information providing site that indicates an information providing site that publishes given information on a network, which is a legitimate information providing site, a legitimate site information management means for managing a legitimate site database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as identification information of a legitimate user and dummy key information having the same format as key information used when the legitimate user performs authentication on a legitimate information site are associated with each other; a detection means for executing a site detection process for detecting a new information providing site for disclosing given information having a network address on the network; an analysis and determination processing means for executing an analysis process for analyzing a detection target site that indicates the detected information providing site, and for executing a target site determination process for determining whether the detection target site is a fake information providing site that indicates the fake information providing site based on the stored legitimate site information; and a dummy information provision control means for executing a process for providing the registered dummy information to the fake information providing site when the target site is determined to be a fake information providing site by the target site determination process; The computer has a configuration that causes the computer to function as a

[0056] With this configuration, the present invention can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating (i.e., logging in) legitimate users by using dummy information, and can also quickly prevent damage associated with the leak of such information even after the information has been leaked by the network service provider.

[0057] Therefore, the present invention can quickly and reliably prevent damage caused by a malicious third party "impersonating" a legitimate user (i.e., impersonation damage) without complex processing.

[0058] The present invention provides a system that can easily and quickly identify the authentication of a malicious third party. The system can be realized with a simple configuration.

[0059] (12) In order to solve the above problems, the present invention provides: 1. An authentication method for performing authentication for access from a communication terminal device of each user connected via a network, comprising: Managing a whitelist database in which whitelist information is stored in advance, in which, for each authorized user, authorized user identification information indicating identification information for identifying the user is associated with authorized key information indicating key information used when performing the authentication; managing a dummy information database in which dummy information to be used by a malicious third party is registered in advance, the dummy information being associated with dummy identification information having the same format as the legitimate user identification information and dummy key information having the same format as the legitimate key information; receiving input information input by a user from the communication terminal device when performing the authentication; performing authentication processing of the user who input the input information based on information included in the received input information, the input identification information indicating the identification information and the input key information indicating the key information, the whitelist information, and the dummy information; and performing a given specific process based on the result of the authentication process; Including, execute the authentication process, which includes a dummy determination process of searching the dummy information database based on the input identification information and the input key information, and determining whether or not there is dummy information that matches at least one of the input identification information and the input key information; If the dummy determination process determines that there is dummy information that matches the received input information, the user who entered the input information is identified as a malicious third party, and the identification process is executed against the malicious third party.

[0060] With this configuration, the present invention can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating (i.e., logging in) a legitimate user, and can accurately prevent damage caused by such malicious third parties "impersonating" a legitimate user (i.e., damage caused by impersonation) without performing complex processing.

[0061] (13) In order to solve the above problems, the present invention provides: A method for detecting a fake information site that is an information site that publishes given information on a network, the method comprising: managing a legitimate site database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as identification information of a legitimate user and dummy key information having the same format as key information used when the legitimate user performs authentication on a legitimate information site are associated with each other; performing a site discovery process to discover new information providing sites for publishing given information having a network address on the network; Executing an analysis process for analyzing a detection target site indicating the detected information providing site, and executing a target site determination process for determining whether the detection target site is a fake information providing site indicating the fake information providing site based on the stored legitimate site information. , and When the target site is determined to be a fake information providing site by the target site determination process, a process is executed to provide the registered dummy information to the fake information providing site. The present invention has a configuration including the following.

[0062] With this configuration, the present invention can identify the identification information and key information of legitimate users that have already been leaked by detecting fake information providing sites, allowing the network service provider to quickly prevent damage associated with the leak, and can prevent the leakage of the identification information and key information of the legitimate users in advance, thereby minimizing damage.

[0063] The present invention can be realized with a simple configuration as a system that can easily and quickly identify the authentication of a malicious third party. [Brief explanation of the drawings]

[0064] [Figure 1] 1 is a system configuration diagram showing the configuration of an authentication management communication system in a first embodiment. [Figure 2] FIG. 2 is a functional block diagram illustrating an example of a configuration of an authentication server device according to the first embodiment. [Figure 3] FIG. 1 is a functional block diagram illustrating an example of a configuration of a terminal device according to a first embodiment; [Figure 4] 10A and 10B are diagrams illustrating an authentication process using dummy information for identifying a malicious third party in the authentication server device of the first embodiment. [Figure 5] A figure showing examples of whitelist information registered in the first database of the first embodiment, blacklist information registered in the second database, dummy information registered in the third database of this embodiment, and unauthorized access information registered in the fourth database. [Figure 6]10 is a flowchart (part 1) showing operations related to a dummy determination process, an unauthorized access determination process, an authentication process based on whitelist information, and a specific process executed based on the results of each process, which are executed by the authentication server device of the first embodiment. [Figure 7] 10 is a flowchart (part 2) showing the operations of the dummy determination process, the unauthorized access determination process, the authentication process based on whitelist information, and the specific process executed based on the results of each process, which are executed by the authentication server device of the first embodiment. [Figure 8] FIG. 10 is a system configuration diagram showing the configuration of an authentication management communication system in a second embodiment. [Figure 9] FIG. 10 is a functional block diagram illustrating an example of a configuration of an authentication server device according to a second embodiment. [Figure 10] 10A and 10B are diagrams illustrating a fake site detection process for detecting a fake information providing site and a dummy information provision control process for providing dummy information to the fake information providing site in the authentication management communication system 1 of the second embodiment. [Figure 11] FIG. 10 is a diagram illustrating an example of legitimate site information registered in the first database according to the second embodiment. [Figure 12] 10 is a flowchart showing operations related to a target site determination process and a dummy information provision process executed by the authentication server device of the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0065] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. The embodiment described below is an embodiment in which the authentication system and the false information site detection system of the present application are applied to an authentication management communication system using a network that includes a terminal device used by a user, an authentication server device that executes authentication processing, and a network service server device that provides network services.

[0066] [A] First embodiment [A1] Authentication management communication system First, the outline and system configuration of an authentication management communication system 1 according to this embodiment will be described with reference to FIG.

[0067] 1 is a system configuration diagram showing the configuration of an authentication management communication system 1 in this embodiment. To prevent the diagram from becoming too complicated, FIG. 1 shows only terminal devices 20 used by some users and some network service server devices (hereinafter also referred to as "service server devices") 30. That is, in an actual authentication management communication system 1, there are many more terminal devices 20 and service server devices 30 than are shown in FIG. 1.

[0068] (System Overview) As shown in FIG. 1, the authentication management communication system 1 of this embodiment is a system that performs authentication processing for a pre-registered user, and if the user authentication is successful, provides various network services to the authenticated user via the network.

[0069] The authentication management communication system 1 of this embodiment is configured to provide information of the same format as the information used by legitimate users during authentication as dummy information to be used by malicious third parties via phishing sites (i.e., fake information providing sites), etc., and when a process (i.e., authentication process) for authenticating to a specific information providing site is executed based on the dummy information, the terminal device 20 using the dummy information is identified as a terminal device used by a malicious third party.

[0070] In particular, the authentication management communication system 1 of this embodiment is configured to identify the user who used the dummy information as a malicious third party and identify the terminal device 20 used as a terminal device used by the malicious third party when at least one of identification information such as a user ID or account ID (hereinafter referred to as "input identification information" or "input ID") and key information such as a password or PIN (hereinafter referred to as "input key information") included in the input information entered by the user during the authentication process matches dummy information.

[0071] In other words, the authentication management communication system 1 of this embodiment is configured to not only easily identify access by malicious third parties and block access from malicious third parties, but also, if it obtains information about the terminal device 20 of the malicious third party, to block authentication using identification information (i.e., user ID or account ID) or key information (password or PIN) of a legitimate user that has been leaked using the terminal device 20 linked to the obtained information.

[0072] The authentication management communication system 1 of this embodiment has a configuration that can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating a legitimate user (i.e., when logging in), or accurately prevent damage caused by the malicious third party "impersonating" a legitimate user (i.e., damage caused by impersonation) without performing complex processing.

[0073] Note that a "legitimate user" refers to a person who is registered for authentication purposes, and is not a malicious third party who has not impersonated the person using information used for authentication such as ID and password (i.e., a user who is not an unauthorized user).

[0074] (System Configuration) As shown in FIG. 1, the authentication management communication system 1 of this embodiment performs authentication processing. The system is composed of an authentication server device 10 that executes various processes including the authentication process, a terminal device 20 (e.g., terminal devices 20A, 20B, 20C) that is connected to the authentication server device 10 via a network such as the Internet and accepts user operations related to various processes such as the authentication process, and a service server device 30 that provides predetermined network services such as financial institution services, financial transactions, or specific products and services when the user authentication process is successful.

[0075] The authentication server device 10 is an information processing device that executes various processes including authentication processing and personal identification processing by using, for example, an API (Application Programming Interface) or a predetermined platform.

[0076] Furthermore, the authentication server device 10 may be configured as one (device, processor) or as multiple (devices, processors).

[0077] The authentication server device 10 has various databases (broadly speaking, storage devices, memories) that store information about users (hereinafter referred to as "user information") and various information used in authentication processing or identity verification processing. However, the authentication server device 10 of this embodiment may also access databases (broadly speaking, storage devices, memories) connected via a network (intranet or the Internet).

[0078] Furthermore, the authentication server device 10 is configured to work in conjunction with each terminal device 20 and to execute authentication processing for the user of each terminal device 20 .

[0079] The terminal device 20 is a communication terminal device that is used by a user and is configured by an information processing device such as a PC (personal computer), a tablet-type information communication terminal device, a smartphone, a mobile phone, a game device, or an HMD.

[0080] In addition, the terminal device 20 is a device that can be connected to the authentication server device 10 via a network such as the Internet (WAN) or LAN, and is configured to establish a communication line with the authentication server device 10 via wired or wireless means to exchange various types of data.

[0081] In addition, the terminal device 20 has a configuration that includes a communication control function for communicating with the authentication server device 10, such as input information entered by the user, and a display function for performing display control using data received from the authentication server device 10 and the service server device 30.

[0082] The service server device 30 is a server device for providing various network services, including banking services that provide financial institution-related services, reservation services for restaurants, inns, transportation, etc., product sales services, SNS services, content provision services such as games, music, and videos, cloud services such as various applications such as email, and information provision services such as search and advertisements.

[0083] In particular, when the authentication server device 10 successfully authenticates a user, the service server device 30 is configured to log in the authenticated terminal device 20 to the network service it provides and execute various processes to provide the corresponding service to the user.

[0084] The service server device 30 may have various functions relating to authentication, such as the authentication process of the authentication server device 10.

[0085] [A2] Authentication server device Next, the authentication server device 10 of this embodiment will be described with reference to Fig. 2. Fig. 2 is an example of a functional block diagram showing the configuration of the authentication server device 10 of this embodiment.

[0086] 2, the authentication server device 10 of this embodiment includes a processing unit 100, a first database 140, a second database 141, a third database 142, a fourth database 143, a storage unit 170, an information storage medium 180, and a communication unit 196. Note that the authentication server device 10 does not need to include all of the units shown in FIG. 2, and may have a configuration in which some of them are omitted.

[0087] The storage unit 170 serves as a work area for the processing unit 100 and the like, and its function can be realized by hardware such as RAM (VRAM). In particular, the storage unit 170 functions as a work area used when various processes are executed.

[0088] The information storage medium 180 is computer-readable, and stores programs, data, etc. In other words, the information storage medium 180 stores programs for causing a computer to function as each unit of this embodiment (programs for causing a computer to execute the processing of each unit).

[0089] The processing unit 100 can perform various processes of this embodiment based on data read from a program (data) stored in this information storage medium 180.

[0090] For example, the information storage medium 180 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.

[0091] The first database 140 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, a memory (ROM), a memory card, or the like.

[0092] The first database 140 is a database in which information about one or more legitimate users for performing authentication processing is registered as information on a whitelist for authentication (hereinafter referred to as "whitelist information").

[0093] Like the first database 140, the second database 141 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, or a memory (ROM), a memory card, etc.

[0094] The second database 141 is a database in which information about one or more legitimate users who are prohibited from authentication processing is registered as blacklist information (hereinafter referred to as "blacklist information").

[0095] The second database 141 may be incorporated as a part of the first database 140.

[0096] Like the first database 140 and the second database 141, the third database 142 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, or a memory (ROM), a memory card, etc.

[0097] In addition, the third database 142 is a database in which one or more dummy pieces of information having the same format as the information about each legitimate user included in the whitelist information are registered as dummy list information, and which is used to expose malicious third parties.

[0098] The third database 142 may be incorporated as a part of the second database 141 or the first database 140.

[0099] Like each database, the fourth database 143 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, or a memory (ROM), a memory card, etc.

[0100] The fourth database 143 is a database in which information relating to the terminal device 20 used by an unauthorized user who has accessed using dummy information is registered as unauthorized access information.

[0101] The communication unit 196 performs various controls for communicating with the outside (for example, the terminal device 20 or the service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.

[0102] The processing unit 100 performs various processes of this embodiment based on programs (data) stored in the storage unit 170. Note that the processing unit 100 of this embodiment may read out programs and data stored in the information storage medium 180, temporarily store the read out programs and data in the storage unit 170, and perform processing based on the programs and data.

[0103] The processing unit 100 (processor) performs various processes using the main memory in the memory unit 170 as a work area. The functions of the processing unit 100 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.

[0104] Specifically, the processing unit 100 includes a communication control unit 101 , a DB management control unit 102 , an authentication processing unit 103 , a user information management control unit 104 , and a timer management unit 107 .

[0105] For example, the communication control unit 101 of this embodiment constitutes a receiving means of the present invention, the DB management control unit 102 constitutes a whitelist management means, a blacklist management means, and a dummy information management means of the present invention, and the authentication processing unit 103 of the present invention constitutes an authentication processing means of the present invention, and the user information management control unit 104 constitutes a specification processing means of the present invention.

[0106] The communication control unit 101 establishes a communication line with the terminal device 20, the service server device 30, etc. via the network, and communicates with them.

[0107] The DB management control unit 102 executes processes such as reading, writing, deleting, and updating of each piece of data in the first database (for whitelist) 140 and the third database (for dummy information) 160.

[0108] The authentication processing unit 103 receives input information entered via each terminal device 20 via the communication control unit 101, and performs authentication processing for each user based on the received input information (specifically, the user name or user ID and password), the whitelist information already registered in the first database 140, the blacklist information already registered in the second database 141, and the dummy information already registered in the third database 142.

[0109] The authentication processing unit 103 may perform authentication processing for each user using only the whitelist information and the dummy information, or may perform authentication processing using each piece of information independently.

[0110] The user information management control unit 104 performs a given specific process based on the result of the authentication process for each user.

[0111] Specifically, the user information management control unit 104 performs identification processing such as identifying malicious third parties, notifying information about the identified malicious third parties, updating a blacklist based on the information, or registering information about unauthorized access.

[0112] The timer management unit 107 has a function of measuring the current date and time and from a predetermined timing, and outputs the current time and the measurement result when the predetermined timing arrives.

[0113] [A3] Terminal equipment Next, the functions of the terminal device 20 will be described with reference to Fig. 3. Fig. 3 is a functional block diagram showing an example of the configuration of the terminal device 20 of this embodiment.

[0114] As shown in FIG. 3, the terminal device 20 of this embodiment has a processing unit 200, an imaging unit 250, an operation input unit 260 consisting of a touch panel or the like, a memory unit 270, an information storage medium 280, a display unit 290 consisting of a display element such as a liquid crystal panel, a communication unit 296, and a sound output unit 292.

[0115] The imaging unit 250 is made up of an imaging camera having a predetermined imaging angle and focal length and a predetermined imaging element such as a CCD, and an image generating unit that converts the output of the imaging camera into an image.

[0116] In addition, the imaging unit 250 works in conjunction with the processing unit 200 to transmit biometric information, such as facial image information obtained by capturing an image of the user's face and digitizing the facial image, to the authentication server device 10 when performing authentication processing.

[0117] The operation input unit 260 is a device for inputting input information from the player, and outputs the input information from the player to the processing unit 200 .

[0118] The operation input unit 260 of this embodiment includes a detection unit 262 that detects input information (input signals) from the user, and is configured by, for example, a lever, a button, a microphone, a touch panel display, a keyboard, a mouse, and the like.

[0119] The storage unit 270 serves as a work area for the processing unit 200 and the like, and its function can be realized by hardware such as RAM (VRAM).

[0120] The storage unit 270 of this embodiment includes a main storage unit 271 used as a work area, an image buffer 272 in which the final display image and the like are stored, and a user information storage unit 273 in which user information is stored. Note that a configuration in which some of these components are omitted may also be adopted.

[0121] The information storage medium 280 is computer-readable, and stores various applications, an OS (operating system), and, in particular, in this embodiment, various data including the user ID of the user corresponding to the terminal device 20.

[0122] That is, the information storage medium 280 stores applications for causing a computer to function as each unit of this embodiment (applications for causing a computer to execute the processing of each unit) and a user ID.

[0123] For example, the information storage medium 280 is an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk drive, a flash memory, a magnetic tape, a memory (ROM), a memory card, or the like.

[0124] The communication unit 296 performs various controls for communicating with the outside (e.g., other terminal devices 20, authentication server device 10, and service server device 30), and its functions are configured by hardware such as various processors or communication ASICs, programs, etc.

[0125] The processing unit 200 can perform various processes of this embodiment by reading and executing the applications stored in this information storage medium 280. Note that the types of applications stored in the information storage medium 280 are arbitrary.

[0126] The processing unit 200 performs various processes of this embodiment based on the application stored in the information storage medium 280. Note that the processing unit 200 of this embodiment may read out programs and data stored in the information storage medium 280, temporarily store the read out programs and data in the storage unit 270, and perform processing based on the programs and data.

[0127] The processing unit 200 (processor) performs various processes using the main memory in the memory unit 270 as a work area. The functions of the processing unit 200 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.

[0128] The processing unit 200 includes a communication control unit 210, a web browser 211, an imaging control unit 212, a display control unit 213, an input reception processing unit 214, a drawing unit 220, and a sound processing unit 230. Note that some of these units may be omitted.

[0129] The communication control unit 210 performs processing to transmit and receive data to and from the authentication server device 10 or the service server device 30. The communication control unit 210 also receives data transmitted from the authentication server device 10 or the service server device 30, and performs processing to store the received data in the storage unit 270, to analyze the received data, and to control other processing related to the transmission and reception of data.

[0130] The communication control unit 210 may also store and manage destination information (IP address, port number) of the authentication server device 10 and the service server device 30 in the information storage medium 280. When receiving input information from the user to start communication, the communication control unit 210 may communicate with the authentication server device 10 or the service server device 30.

[0131] In particular, the communication control unit 210 transmits the user's identification information, input information, or biometric information to the authentication server device 10, and performs processing to receive information related to the authentication process and information for receiving specified services from the authentication server device 10 and the service server device 30.

[0132] In addition, the communication control unit 210 may send and receive data with the authentication server device 10 and the service server device 30 at a predetermined interval, or may send and receive data with the authentication server device 10 when input information is received from the operation input unit 260.

[0133] The web browser 211 is an application program for viewing web pages (authentication screen, unlock screen, or service enjoyment screen) including information providing sites, and downloads HTML files, image files, etc. from the web server (authentication server device 10 or service server device 30), analyzes the layout, and controls the display.

[0134] Furthermore, the Web browser 211 transmits data to the Web server (the authentication server device 10 or the service server device 30) using an input form (links, buttons, text boxes, etc.).

[0135] The terminal device 20 can display information from a web server (for example, the service server device 30) specified by a URL via the Internet using the web browser 211. For example, the terminal device 20 can display each content (data such as HTML) received from the authentication server device 10 using the web browser 211.

[0136] When performing authentication processing in conjunction with the authentication server device 10, the imaging control unit 212 causes the imaging unit 250 to capture an image of the user's face and generate a facial image.

[0137] The imaging control unit 212 may provide the generated face image to the authentication server device 10 for use in authentication.

[0138] The display control unit 213 performs processing for displaying on the display unit 290. For example, the display control unit 213 may use the web browser 211 for display.

[0139] The input reception processing unit 214 recognizes input information input by the user from the operation input unit 260, and executes various processes based on the recognized information.

[0140] The drawing unit 220 performs drawing processing based on various processes performed by the processing unit 200, thereby generating an image, which is output to the display unit 290 by the display control unit 213.

[0141] The sound processing unit 230 performs sound processing based on the results of various processes performed by the processing unit 200 , generates background music, sound effects, voice, or the like, and outputs them to the sound output unit 292 .

[0142] [A4] Method of this embodiment [A4.1] Overview Next, the authentication process using dummy information for identifying a malicious third party in the authentication server device 10 of this embodiment will be described with reference to FIG.

[0143] FIG. 4 is a diagram for explaining the authentication process using dummy information for identifying a malicious third party in the authentication server device 10 of this embodiment.

[0144] FIG. 4 is a diagram for explaining the authentication process, lock control process, and unlock process including the identity verification process in the authentication management communication system 1 of this embodiment.

[0145] The authentication server device 10 of this embodiment is configured to perform authentication of access from each user's terminal device 20 connected via the network, and if the authentication fails (is unsuccessful), to execute processing to discontinue collaboration between the terminal device 20 and the service server device 30 (i.e., provision of the service).

[0146] In particular, the authentication server device 10 of this embodiment stores the first database 14 for each authorized user. The authentication process is performed using whitelist information consisting of registration information pre-registered in Kerberos, which is unique legitimate identification information that identifies a user, such as a user ID or account ID (hereinafter also referred to as "legitimate user identification information" or "legitimate user ID"), and legitimate key information (hereinafter referred to as "legitimate key information") that is key information set for each legitimate user, such as a password or PIN, and is used when performing authentication, and dummy information that is in the same format as the whitelist information and is intended to be used by malicious third parties.

[0147] The authentication server device 10 of this embodiment is configured to perform identification processes such as identifying malicious third parties, notifying information about the identified third parties, and updating the blacklist based on the information, based on the results of the authentication process (hereinafter referred to as the "authentication result").

[0148] Specifically, the authentication server device 10 of this embodiment: (A1) Whitelist information in which authorized user identification information and authorized key information are associated with each authorized user; (A2) Blacklist information including authorized user identification information and authorized key information that has been used or may be used by unauthorized users (hereinafter referred to as "unauthorized users" and users who may be malicious third parties), and (A3) Dummy information to be used by a malicious third party, in which dummy identification information having the same format as the legitimate user identification information and dummy key information having the same format as the legitimate key information are associated with each other; It has a configuration for managing the above.

[0149] Then, as shown in FIG. 4, the authentication server device 10: (B1) When performing authentication, input information (e.g., user ID (ID) and password (PASS)) input by the user from the terminal device 20 is received (see [1] in FIG. 4), (B2) Based on the information contained in the received input information, which is input identification information (ID) indicating identification information and input key information (PASS) indicating key information, as well as the whitelist information and dummy information, execute authentication processing for the user who input the input information (see [1] in Figure 4), (B3) Perform a specific process based on the result of the authentication process (see [2], [3], and [4] in Figure 4). It has the following structure.

[0150] In particular, the authentication server device 10, as shown in FIG. (C1) Based on the input identification information (ID) and the input key information (PASS), the third database 142 is searched, and an authentication process including a dummy determination process is performed to determine whether or not there is dummy information that matches at least one of the input identification information and the input key information (see [1] in FIG. 4 ). (C2) If it is determined that there is dummy information that matches the received input information through the dummy determination process, the user who entered the input information is identified as a malicious third party, and identification processing is performed against the malicious third party, such as registering the corresponding legitimate user identification information and legitimate key information in blacklist information (see [3] and [4] in Figure 4). It has the following structure.

[0151] On the other hand, when it is determined that there is whitelist information that matches the input information received by the authentication process, the authentication server device 10 is configured to control the collaboration between the service server device 30 and the terminal device 20, including the exchange of data, in order to provide the specified network service to the user who performed the authentication (see [2] in Figure 4).

[0152] In addition, the authentication server device 10 is configured to perform the following identification processes: a process to stop the authentication process; a notification process to notify the administrator of information about the identified malicious third party; and a registration process to register the legitimate user identification information and legitimate key information used by the identified malicious third party as a blacklist (see [4] in Figure 4).

[0153] FIG. 4 shows an example of a specific process (when a network service is provided) when a specific terminal device 20 instructs the execution of authentication processing together with input information (user identification information (ID) which is legitimate user identification information and password (PASS) which is legitimate key information) and when the authentication processing is successful and fails (when a network service is not provided).

[0154] In particular, Figure 4 shows not only an example of a case where the authentication process is successful, but also an example of a specific process (when a network service is not provided) when the authentication process fails, and when the authentication process fails, examples are shown of a case where the input information does not match the dummy information and a case where it matches the dummy information.

[0155] By having such a configuration, the authentication server device 10 of this embodiment can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating a legitimate user (i.e., when logging in), and can accurately prevent damage caused by the malicious third party "impersonating" a legitimate user (i.e., impersonation damage) without performing complex processing.

[0156] [A4.2] Whitelist information etc. Next, the whitelist information, blacklist information, dummy information, and unauthorized access information of this embodiment will be described with reference to FIG.

[0157] Note that Figure 5 is a diagram showing examples of whitelist information registered in the first database 140 of this embodiment, blacklist information registered in the second database 141 of this embodiment, dummy information registered in the third database 142 of this embodiment, and unauthorized access information registered in the fourth database 143. FIG.

[0158] (Whitelist information) The whitelist information is information stored in the first database 140, and is list information that combines the identification information and key information of authorized users.

[0159] Specifically, as shown in Figure 5(A), the whitelist information is associated with authorized user identification information (authorized user ID) for each authorized user, and includes authorized key information used when authenticating user names, passwords, etc., as well as user authentication information for identifying the user when performing authentication processing, such as user information (e.g., email addresses or mobile phone numbers), information about communication terminal devices used in the past (hereinafter referred to as "terminal-related information"), and design information.

[0160] In particular, the terminal-related information includes, for example, information indicating the type of communication terminal device (personal computer, tablet information terminal device, smartphone, etc.), information indicating the type of access application such as a web browser used by the communication terminal device to access, and communication identification information for identifying the communication partner such as an IP address (logical address).

[0161] The authorized user identification information may include a user name (user's name or nickname) in addition to the user ID.

[0162] In addition, the key information may include, for example, information for identifying the user from other users, such as a user name (including a nickname), a password, and pattern information, as well as information for identifying the user himself or herself and information about the user.

[0163] (Blacklist information) Blacklist information is information stored in the second database 141, and is authentication information relating to authorized users that has been used or may be used by unauthorized users who are not authorized users.

[0164] That is, blacklist information is, for example, information on a list that combines identification information and key information of legitimate users that have been used by malicious third parties.

[0165] Specifically, the blacklist information is simply registered as a blacklist for each target user on the blacklist, as shown in Figure 5(B), and is basically composed of information in the same format as each user identification information and each key information in the whitelist information.

[0166] Furthermore, the whitelist information registered in the blacklist may also be registered in the whitelist, or may be deleted from the whitelist and registered entirely as the blacklist only.

[0167] (Dummy list information) The dummy list information is information stored in the third database 142, and is information that lists dummy information that can be used by a malicious third party to expose the malicious third party.

[0168] That is, the dummy list information is a list of dummy information that a malicious third party uses to exploit authentication of other people and expose criminals.

[0169] Specifically, as shown in Figure 5(C), the dummy list information is composed of dummy identification information (dummy ID) having the same format as regular user identification information, and dummy key information having the same format as regular key information (e.g., regular password).

[0170] The same format means, for example, that the same number of characters (including alphanumeric characters and symbols) or characters of the same type and combinable characters within a predetermined range of characters (e.g., 8 or more characters, 5 or more characters, and 10 or less characters).

[0171] The dummy list information is the information in FIG. 5(C) excluding the terminal-related information.

[0172] (Unauthorized access information) The unauthorized access information is information stored in the fourth database 143, and includes information on the terminal device 20 used by an unauthorized user who has accessed the system by impersonating a legitimate user using the dummy information, and information on the terminal device 20, such as the communication environment of the terminal device 20 (i.e., terminal-related information).

[0173] Specifically, as shown in FIG. 5(C), the unauthorized access information associates one or more pieces of terminal-related information with each piece of dummy information stored in the dummy list information.

[0174] For example, the terminal-related information of each dummy information includes information indicating the type of terminal device 20 (personal computer, tablet information terminal device, smartphone, etc.), information indicating the type of access application such as a web browser used by the terminal device 20 to access, and communication identification information for identifying the communication partner such as an IP address (logical address).

[0175] The unauthorized access information is information including the terminal-related information in FIG. 5(C).

[0176] [A4.3] Authentication process [A4.3.1] Basic principles of authentication processing (authentication processing based on whitelist information) Next, the basic principles of the authentication process (authentication process based on whitelist information) of this embodiment will be described.

[0177] When authenticating a specific user (including authorized users and unauthorized users) who desires to undergo authentication processing, the authentication processing unit 103 receives input information input via each terminal device 20 of the specific user.

[0178] Specifically, the authentication processing unit 103 receives, as input information, identification information such as a login ID (hereinafter referred to as "input identification information") and key information such as a password (hereinafter referred to as "input key information").

[0179] Then, the authentication processing unit 103 searches the whitelist information in the first database 140 based on the input identification information and input key information included in the received input information, and executes authentication processing.

[0180] In particular, the authentication processing unit 103 detects authorized user identification information that matches the input identification information, and if matching authorized user identification information is detected, performs authentication processing for the specific user by comparing authorized key information stored in the first database 140 in association with the authorized user identification information with the input key information included in the received input information.

[0181] That is, the authentication processing unit 103 detects authorized user identification information that matches the input identification information, and if the authorized key information stored in association with the authorized user identification information matches the input key information, it determines that the authentication has been successful, and if they do not match, it determines that the authentication has failed.

[0182] If the authentication of the user is successful, the authentication processing unit 103 allows the user to log in to the network service provided by the service server device 30.

[0183] In this embodiment, during the execution of the above authentication process, a dummy determination process is performed to determine whether or not the authentication process has been executed using dummy information, a process to register terminal-related information (i.e., unauthorized access information) regarding a terminal device 20 that may have been used by a malicious third party (hereinafter referred to as "unauthorized access information registration process"), and an access determination process is performed to determine whether or not the input terminal-related information regarding the terminal device 20 that executed the authentication process matches the unauthorized access information and to determine whether or not the authorized user identification information and authorized key information have been leaked (whether or not there is a possibility that they have been leaked), or both processes are performed.

[0184] In addition, as the key information in this embodiment, a one-time password notified to the terminal device 20 or other communication devices or already assigned to a storage medium may be used, or an appropriate number or Other information such as input based on image instructions, date of birth, or telephone number assigned to the mobile terminal device may also be used.

[0185] Furthermore, in the authentication process of this embodiment, information capable of identifying an individual, such as a passport identification number or a driver's license number, may be used, or these types of information may be used in combination.

[0186] [A4.3.2] Dummy determination process (including some specific processes) Next, the dummy determination process (including a part of the specific process) of this embodiment will be described.

[0187] When performing the above authentication process, the authentication processing unit 103 performs a dummy determination process to determine whether the authentication process has been performed using dummy information provided to a malicious third party (i.e., information that has been intentionally leaked to a malicious third party in advance).

[0188] That is, for example, as described in the second embodiment, by providing malicious third parties such as fake information providing sites with dummy information in advance that is in the same format as legitimate user identification information and legitimate key information (i.e., information on each legitimate user listed in the whitelist information), and determining whether or not the authentication process has been performed using that dummy information, it is possible to expose such malicious third parties.

[0189] Specifically, when the authentication processing unit 103 receives input information including input identification information and input key information as described above, it searches the dummy list information stored in the third database 142 based on the input identification information included in the received input information, and performs a dummy determination process to determine whether or not there is matching dummy information.

[0190] Furthermore, if the authentication processing unit 103 determines through the dummy determination process that there is no dummy information that matches the input identification information, as described above, it searches the whitelist information in the first database 140 based on the input identification information and input key information contained in the received input information, and performs authentication processing.

[0191] On the other hand, when the authentication processing unit 103 determines through the dummy determination process that there is dummy information that matches the input identification information, it stops the authentication process as a specific process.

[0192] In particular, the authentication processing unit 103 may stop the authentication process and instruct the DB management control unit 102, the user information management control unit 104, or both, to execute a given specific process as a specific process.

[0193] During the authentication process, the authentication processing unit 103 searches the dummy list information before searching the whitelist information in the first database 140. However, the authentication processing unit 103 may search the dummy list information after searching the whitelist information in the first database 140.

[0194] In addition, the authentication processing unit 103 may perform a dummy determination process in which, based on both the input identification information and the input key information contained in the received input information, the authentication processing unit 103 searches the dummy list information stored in the third database 142 to determine whether or not there is matching dummy information, or may perform a dummy determination process in which, based on the input key information, the authentication processing unit 103 searches the dummy list information stored in the third database 142 to determine whether or not there is matching dummy information.

[0195] [A4.3.3] Irregular access detection process including irregular access information registration process Next, the unauthorized access determination process of this embodiment and the prerequisites for the unauthorized access determination process will be described. The following describes the process of registering information about unauthorized accesses.

[0196] (Registration of unauthorized access information) When performing the above authentication process, the DB management control unit 102 performs an unauthorized access information registration process to register terminal-related information (i.e., unauthorized access information) regarding the terminal device 20 that may have been used by a malicious third party.

[0197] In other words, the DB management control unit 102 is configured to register terminal-related information regarding the terminal device 20 that may have been used by a malicious third party, in order to prevent information leakage based on other legitimate user identification information and legitimate key information that may have been leaked to the malicious third party identified by the dummy determination process.

[0198] In particular, when the DB management control unit 102 determines that there is dummy information that matches the input information received through the dummy determination process, it registers terminal-related information indicating information about the terminal device 20 that sent the input information in the fourth database 143 as unauthorized access information.

[0199] Specifically, as described above, when the DB management control unit 102 determines through the dummy determination process in the authentication processing unit 103 that there is dummy information that matches the input identification information, it executes an illegal access information registration process to register the terminal-related information of the terminal device 20 that transmitted the input identification information in association with the corresponding dummy information in the fourth database 143 as illegal access information.

[0200] For example, the DB management control unit 102 uses communication identification information such as an IP address as the non-access information.

[0201] The DB management control unit 102 may use information other than the communication identification information, for example, information indicating the type of the terminal device 20 that sent the input information (personal computer, tablet information terminal device, smartphone, etc.), the type of language set in the terminal device 20, and information indicating the type of access application, such as a web browser, used by the terminal device 20 to access (i.e., to execute authentication processing). However, information that can be identified from other terminal devices 20 is preferable, and in other cases, it is preferable to use a combination of two or more pieces of information, or to use information together with unique information such as communication identification information.

[0202] (Illegal access detection process) When performing the above authentication process, the authentication processing unit 103 may perform an access judgment process in addition to or instead of the dummy judgment process, to determine whether the authentication is likely to be from a malicious third party based on terminal-related information (i.e., unauthorized access information) regarding the terminal device 20 that may have been used by a malicious third party.

[0203] That is, the authentication processing unit 103 executes an access determination process to determine whether or not the terminal device 20 that transmitted the input information is a terminal device 20 of a malicious third party.

[0204] Specifically, when the authentication processing unit 103 receives, as input information, input terminal-related information indicating terminal-related information related to the terminal device 20 that sent the input information, the authentication processing unit 103 executes an access determination process to determine whether the received input terminal-related information matches the unauthorized access information, and if the input terminal-related information received by the access determination process matches the unauthorized access information, the authentication processing unit 103 instructs the user information management control unit 104 to execute a specific process.

[0205] For example, the authentication processing unit 103 may convert the input identification information and the input key information into input information as described above. When the input terminal 100 receives the request, it acquires one or more pieces of terminal-related information (hereinafter referred to as "input terminal-related information") including communication identification information for identifying the communication partner, such as an IP address (logical address).

[0206] Then, based on the acquired input terminal-related information, the authentication processing unit 103 searches the non-access information stored in the fourth database 143 and performs an access determination process to determine whether or not there is terminal-related information that matches the input terminal-related information.

[0207] At this time, if the authentication processing unit 103 determines through the access determination process that there is no terminal-related information in the non-access information that matches the input terminal-related information, as described above, it searches the whitelist information in the first database 140 based on the input identification information and input key information contained in the received input information, and performs authentication processing.

[0208] In this embodiment, as described above, information other than the communication identification information may be used, such as information indicating the type of the terminal device 20 that transmitted the input information (personal computer, tablet information terminal device, smartphone, etc.), the type of language set in the terminal device 20, and information indicating the type of access application, such as a web browser, used by the terminal device 20 to access (i.e., to execute authentication processing). However, information that can be identified from other terminal devices 20 is preferable, and in other cases, it is preferable to use a combination of two or more pieces of information, or to use information together with unique information such as the communication identification information.

[0209] On the other hand, if the authentication processing unit 103 determines through the access determination process that there is terminal-related information in the non-access information that matches the input terminal-related information, it stops the authentication process and instructs the DB management control unit 102 to execute a specific process using blacklist information (hereinafter also referred to as a "blacklist registration process"), and the user information management control unit 104 to execute a specific process of notifying the system administrator and authorized users (hereinafter also referred to as a "notification control specific process").

[0210] During the authentication process, the authentication processing unit 103 searches the non-access information in the third database 142 before searching the whitelist information in the first database 140. However, it is preferable that the authentication processing unit 103 searches the non-access information after searching the whitelist information in the first database 140.

[0211] [A4.4] Specific processing (excluding processing to cancel authentication processing) [A4.4.1] Blacklisting Processing Next, a blacklist registration process, which is one of the specific processes executed by the DB management control unit 102 of this embodiment, will be described.

[0212] The DB management control unit 102 manages a blacklist database in which input identification information and input key information that have been used or may be used by unauthorized users (i.e., users who are assumed to be malicious third parties) are stored as blacklist information in which the identification information and key information are listed to prohibit authentication processing.

[0213] On the other hand, the authorized user identification information and authorized key information of authorized users cannot be registered in the blacklist from the beginning.

[0214] Therefore, in this embodiment, as described above, the terminal-related information relating to the terminal device 20 of a malicious third party is first registered in a blacklist using dummy information, and then, when an authentication process (i.e., access) using the terminal-related information is performed, the information used in the authentication process is blacklisted. The legitimate user identification information and legitimate key information thus entered are registered in blacklist information as information that has been used or may be used by a malicious third party.

[0215] Specifically, when executing the authentication process, if the DB management control unit 102 determines through the access determination process that the non-access information contains terminal-related information that matches the input terminal-related information, the DB management control unit 102 may cancel the authentication process and determine that the terminal device 20 that sent the input information is a terminal device 20 of a malicious third party, and register information about the terminal device 20 (i.e., the terminal-related information) in the blacklist information.

[0216] In other words, the DB management control unit 102 assumes that the terminal device 20 that sent the input information is a terminal device 20 of a malicious third party, determines that legitimate user information has been leaked regarding access using the terminal device 20 or a network address such as an IP address, and is configured to register various information for identifying the terminal device 20 and its communication environment in blacklist information in order to prohibit authentication and access based on the legitimate user information from that point on.

[0217] For example, the terminal-related information used in this embodiment includes information indicating the type of communication terminal device (personal computer, tablet information terminal device, smartphone, etc.), information indicating the type of access application such as a web browser used by the communication terminal device to access the device, and communication identification information such as an IP address (logical address) for identifying the communication partner.

[0218] Specifically, when it is determined by the access determination process that the non-access information contains terminal-related information that matches the input terminal-related information, the DB management control unit 102 stops the authentication process and (A1) Searching a whitelist database based on the input identification information and input key information input together with the input terminal related information; (A2) Registering the authorized user identification information and the authorized key information that match the input identification information and the input key information in blacklist information in the second database 141; Execute specific processing (i.e., blacklisting processing).

[0219] When blacklist information is registered in this manner, the authentication processing unit 103 executes authentication processing based on the blacklist during authentication processing.

[0220] Specifically, when performing the above authentication process, the authentication processing unit 103 may perform a blacklist determination process to determine whether the authentication is that of a malicious third party based on the blacklist information stored in the second database 141, in addition to or instead of the dummy determination process or the access determination process.

[0221] [A4.4.2] Notification control processing Next, a notification control process, which is one of the specific processes executed by the user information management control unit 104 of this embodiment, will be described.

[0222] When the authentication process fails (including when it is determined that the authentication process has failed by the dummy determination process or the unauthorized access determination process), the user information management control unit 104 notifies the administrator of the authentication management communication system 1, the authorized user, or both, of information about a malicious third party such as terminal-related information, the date and time of access, and information when the relevant dummy information was provided (if information about the malicious third party such as the date and time of provision or information about a fake information providing site is stored, that information). Execute the specified process.

[0223] In other words, not only when the input identification information or input key information does not match the legitimate user identification information or legitimate key information, but also when the dummy determination process determines that there is dummy information that matches the input identification information, or when the unauthorized access determination process determines that unauthorized access information that matches the input terminal-related information is stored in the fourth database 143, the user information management control unit 104 executes notification control processing to notify the system administrator of the relevant terminal-related information, etc.

[0224] Specifically, the user information management control unit 104 performs notification control processing such as notification control by text via the terminal device 20, such as email or chat, or notification on a screen such as a monitor of the terminal device (including a personal computer or portable information terminal device) 20, notification by sound such as a siren, and notification control by a light source (i.e., light) such as a specified lamp or LED.

[0225] For example, if the input identification information matches the legitimate user identification information but the input key information does not match the legitimate key information, the user information management control unit 104 notifies the user of the legitimate user identification information that the legitimate key information does not match.

[0226] [A4.5] Variations Next, a modification of this embodiment will be described.

[0227] In this embodiment, the authentication server device 10 performs the authentication process, including the dummy determination process or the unauthorized access determination process, but the authentication process based on the input information, authorized user identification information, and authorized key may be performed by the terminal device 20, and the dummy determination process or the unauthorized access determination process may be performed by the authentication server device 10.

[0228] In this case, the terminal device 20 has a part of the functions of the authentication processing unit 103.

[0229] In this embodiment, the authentication server device 10 and the service server device 30 are described as separate and independent entities, but they may be formed as a single server device or a single server system, or the authentication processing may be included in the service server device 30.

[0230] [A5] Operation in this embodiment Next, using Figures 6 and 7, we will explain the operations related to the dummy determination process, unauthorized access determination process, authentication process based on whitelist information, and specific process performed based on the results of each process performed by the authentication server device 10 of this embodiment.

[0231] 6 and 7 are flowcharts showing the operations related to the dummy determination process, the unauthorized access determination process, the authentication process based on whitelist information, and the specific process performed based on the results of each process, which are executed by the authentication server device 10 of this embodiment.

[0232] In this operation, it is assumed that for each user, legitimate user identification information and legitimate key information have already been registered in the first database 140 in association with each legitimate user, and that dummy information already registered in the second database 141 has been provided to a malicious third party such as a fake information training site.

[0233] In this operation, the unauthorized access information and the blacklist information are respectively It is assumed that the information is registered in the third database 142 and the fourth database 143, respectively.

[0234] First, when the authentication processing unit 103 receives input information including input identification information, input key information, and input terminal related information input by a user and transmitted from a terminal device (step S101), it searches the dummy list information stored in the third database 142 based on the input identification information and executes a dummy determination process to determine whether or not there is matching dummy information (step S102).

[0235] At this time, if the authentication processing unit 103 determines that there is dummy information that matches the input identification information, it executes an illegal access information registration process to register, in the fourth database 143, terminal-related information (i.e., input terminal-related information) regarding the terminal device 20 that sent the input information, which is included in the received input information such as an IP address, as illegal access information (step S103).

[0236] Next, the authentication processing unit 103 stops the authentication process (step S111), notifies the corresponding terminal device 20 of the stoppage (step S112), and terminates this operation.

[0237] On the other hand, if the authentication processing unit 103 determines that there is no dummy information that matches the input identification information, it executes an access determination process to determine whether the information contained in the input information, that is, terminal-related information (e.g., IP address) regarding the terminal device 20 that sent the input information, matches the already stored unauthorized access information (i.e., IP address) (step S104).

[0238] At this time, if the authentication processing unit 103 determines that the received input terminal related information (i.e., IP address) matches the unauthorized access information (i.e., IP address), it registers the input identification information and input key information included in the received input information associated with the input terminal related information in the blacklist information (step S105), and proceeds to processing of step S111.

[0239] On the other hand, if the authentication processing unit 103 determines that the received input terminal-related information (i.e., IP address) does not match the unauthorized access information (i.e., IP address), it searches the whitelist information in the first database 140 based on the input information and performs authentication processing (authentication processing based on the whitelist information) (step S106).

[0240] At this time, if the authentication processing unit 103 detects legitimate user identification information that matches the input identification information, it determines that the user authentication has been successful, logs the user in to the network service provided by the service server device 30 (step S107), and terminates this operation.

[0241] At this time, if the authentication processing unit 103 cannot detect authorized user identification information that matches the input identification information, the process proceeds to step S111.

[0242] [B] Second embodiment [B1] Authentication Management Communication System First, the outline and system configuration of the authentication management communication system 2 of this embodiment will be described with reference to FIG.

[0243] 8 is a system configuration diagram showing the configuration of the authentication management communication system 2 in this embodiment. In order to prevent the diagram from becoming complicated, in FIG. 1, only terminal devices 20 used by some users and some server devices for network services (hereinafter, 1 shows only one terminal device 20 and one service server device 30. In other words, in an actual authentication management communication system 1, there are many more terminal devices 20 and service server devices 30 than are shown in FIG.

[0244] (System Overview) In addition to the functions of the authentication management system of the first embodiment, the authentication management communication system 2 of this embodiment is characterized in that it detects fake information providing sites (hereinafter also referred to as "fake information providing sites") that are fake information providing sites that are legitimate information providing sites from among information providing sites that publish given information on the network, and provides dummy information to the detected fake information providing sites.

[0245] That is, as shown in FIG. 8, the authentication management communication system 2 of this embodiment is a system for preventing information leakage of legitimate users by monitoring each information providing site on the network and actively detecting fake information providing sites that resemble legitimate information providing sites of companies, organizations, or individuals and are used to defraud legitimate users of user identification information and key information such as user names (including not only names but also nicknames), user IDs, passwords, PIN numbers, and credit card numbers (i.e., information providing sites used in phishing scams, also known as phishing sites).

[0246] In particular, the authentication management communication system 2 of this embodiment can identify the identification information and key information of legitimate users that have already been leaked by detecting fake information providing sites, so that the network service provider can quickly prevent damage associated with such leakage, prevent the leakage of the identification information and key information of the legitimate users in advance, thereby minimizing damage, and is a system that can be realized with a simple configuration as a system that can easily and quickly identify the authentication of malicious third parties.

[0247] Specifically, the authentication management communication system 2 of this embodiment is configured to analyze each information providing site (hereinafter also referred to as a "detection target site"), and if the detection target site is determined to be a fake information providing site, to provide dummy information to the fake information providing site.

[0248] Similarly to the first embodiment, the authentication management communication system 2 has a configuration for preventing information leakage of authorized users by executing authentication processing based on the provided dummy information.

[0249] In the authentication management communication system 2 of this embodiment, the configuration other than the above-mentioned features is the same as that of the first embodiment, so the same members are given the same numbers and the description thereof will be omitted.

[0250] In addition, in this embodiment, an information providing site refers to one or more groups of pages for publishing various information and data such as images (including still images and videos) such as web pages, sounds, and texts on a network, and is a site used to provide network services to legitimate users using legitimate user identification information and legitimate key information.

[0251] (System Configuration) As shown in Figure 8, the authentication management communication system 1 of this embodiment is composed of an authentication server device 11 that performs various processes including site detection process for detecting fake information providing sites while performing authentication process related to authentication, a terminal device 20 (e.g., terminal devices 20A, 20B, 20C), and an information providing server device (service server device of the first embodiment) 30.

[0252] In particular, the authentication server device 11 of this embodiment has similar functions to the authentication server device 10 of the first embodiment, and is configured to perform a process of analyzing each information providing site by crawling, etc., a determination process of determining whether each analyzed information providing site is a fake information providing site, and a provision process of providing dummy information to the fake information providing site.

[0253] In this embodiment, the fake information providing site (hereinafter referred to as the “fake information providing site”) is provided by a server device 50 for the fake information providing site.

[0254] [B2] Authentication server device Next, the authentication server device 11 of this embodiment will be described with reference to Fig. 9. Fig. 9 is an example of a functional block diagram showing the configuration of the authentication server device 11 of this embodiment.

[0255] As illustrated in FIG. 9, the authentication server device 11 of this embodiment has a processing unit 300, a first database 140, a second database 141, a third database 142, a fourth database 143, and a fifth database 144, a memory unit 170, an information storage medium 180, and a communication unit 196.

[0256] The authentication server device 11 does not need to include all of the components shown in FIG. 9, and may have a configuration in which some of them are omitted.

[0257] Like each database, the fifth database 144 is formed by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a flash memory such as a solid state drive, a magnetic tape, or a memory (ROM), a memory card, etc.

[0258] The fifth database 144 is a database in which information (hereinafter referred to as "legitimate site information") relating to legitimate information providing sites of companies, organizations, or individuals (hereinafter referred to as "legitimate information providing sites") is stored in advance.

[0259] The fifth database 144 of this embodiment also includes an area for storing data indicating the analysis results of analyzing each information providing site by crawling, etc. However, the data of the analysis results may be stored in another database.

[0260] The processing unit 300 includes a communication control unit 101 , a DB management control unit 102 , an authentication processing unit 103 , a user information management control unit 104 , a fake site detection processing unit 105 , and a timer management unit 107 .

[0261] For example, the DB management control unit 102 constitutes the legitimate site management means and dummy information provision control means of the present invention, and the fake site detection processing unit 105 constitutes the detection means and analysis and determination processing means of the present invention.

[0262] The DB management control unit 102 executes processes such as reading, writing, deleting, and updating of each data item in the first database (whitelist database) 140, the third database (dummy information database) 142, and the fifth database 144.

[0263] Furthermore, when a false information providing site is detected, the DB management control unit 102 executes a process for providing dummy information to the false information providing site.

[0264] The fake site detection processing unit 105 performs a target site analysis process (i.e., crawling) to analyze each information providing site on the network, and then performs a target site determination process to determine whether the analyzed information providing site is a fake information providing site based on the analysis results.

[0265] [B3] Method of this embodiment [B3.1] Overview Next, a fake site detection process for detecting a fake information providing site and a dummy information provision control process for providing dummy information to the fake information providing site in the authentication management communication system 1 of this embodiment will be described with reference to FIG.

[0266] FIG. 10 is a diagram for explaining the fake site detection process for detecting fake information providing sites in the authentication management communication system 1 of this embodiment, and the dummy information provision control process for providing dummy information to the fake information providing sites.

[0267] The authentication server device 11 constantly monitors each information providing site on the network, and is configured to perform a fake site detection process to detect fake information providing sites (i.e., fake information providing sites) that "impersonate" companies or individuals and are mistaken for genuine information providing sites (i.e., fake information providing sites) before or during the authentication process of the first embodiment, and a dummy information provision control process to provide dummy information to the fake information providing sites.

[0268] In particular, the authentication server device 11, by linking with the authentication process of the first embodiment, has a configuration that automates the detection of false information providing sites that obtain information to "impersonate" legitimate users, and automates or supports the provision of dummy information to expose malicious third parties such as the operators of the false information providing sites, making it possible to easily identify the authentication of such malicious third parties.

[0269] Specifically, the authentication server device 11: (A1) legitimate site information in which provider information indicating information on a provider of a legitimate information providing site, legitimate network address information indicating an address on a network of the legitimate information providing site, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other; (A2) Dummy information in which dummy identification information having the same format as the identification information of a legitimate user is associated with dummy key information used when a legitimate user performs authentication on a legitimate information site; It has a configuration for managing the above.

[0270] Then, as shown in FIG. 10, the authentication server device 11 (B1) An analysis process for analyzing each information providing site (i.e., a detection target site) on the network (hereinafter referred to as the “target site analysis process”; see [1] in Figure 10). (B2) A target site determination process (see [2] in FIG. 10) that determines whether the target site is a fake information providing site based on the stored legitimate site information; and (B3) A process for providing registered dummy information to a false information providing site when the target site is determined to be a false information providing site by the target site determination process (hereinafter referred to as "dummy information providing process"; see [3] in Figure 10). The system has a configuration for executing the above.

[0271] In particular, the authentication server device 11 performs a dummy information providing process for automatically providing dummy information to a false information providing site, as well as a process for providing false information to the false information providing site. The system is configured to perform various processes required for manually providing dummy information to an information providing site by an administrator, etc., such as a notification control process for presenting the network address of the providing site and notifying the system administrator of the existence of the fake information providing site.

[0272] Note that Figure 10 shows an example in which a target site analysis process, a target site determination process, and a dummy information provision process are executed when a false information provision site (https: / / www.xxx.com / ) is provided on the network by a server device 50 for false information provision sites.

[0273] By having such a configuration, the authentication server device 11 of this embodiment can easily identify access by malicious third parties, and not only can it block access from malicious third parties as an identification process, but if it obtains information about the communication terminal device of the malicious third party, it can also block access using the identification information and key information of legitimate users that are subsequently leaked using the communication terminal device.

[0274] Furthermore, by using dummy information, the authentication server device 11 of this embodiment can prevent malicious third parties from exploiting various information (i.e., identification information such as ID and password, and key information) used when authenticating a legitimate user (i.e., when logging in), and even after the information has leaked, the network service provider can quickly prevent damage associated with the leak.

[0275] Therefore, the authentication server device 11 of this embodiment is capable of quickly and reliably preventing damage caused by a malicious third party "impersonating" a legitimate user (i.e., impersonation damage) without complex processing.

[0276] In addition, in this embodiment, the authentication process in the first embodiment may be omitted, and the system may function as a system specialized only in the fake site detection process including the target site analysis process and the target site determination process, and the dummy information provision control process.

[0277] [B3.2] Official site information Next, the legitimate site information of this embodiment will be described with reference to FIG.

[0278] FIG. 11 is a diagram showing an example of legitimate site information registered in the fifth database 144 of this embodiment.

[0279] (Official site information) Official site information is information stored in the fifth database 144, and is information provided to information providing sites operated by officially registered companies, organizations, or individuals themselves, as well as information incorporated therein.

[0280] Specifically, as shown in FIG. 11, the legitimate site information is associated with the site ID for each legitimate company, organization, or individual (i.e., a company, organization, or individual registered as a legitimate information provider). (A1) source information indicating the source information of a legitimate information provider site; (A2) legitimate network address information (hereinafter also referred to as "legitimate address information") indicating the network address (i.e., network address) of the legitimate information providing site; (A3) authentic design information indicating information about a design forming an authentic information providing site; It has the following characteristics.

[0281] In particular, the source information includes not only information used within an information providing site operated by a company, organization, or individual, but also information that is likely to be used on that information providing site.

[0282] For example, it includes the names of companies, organizations, and individuals, text introducing them, maps, information about products offered by them, and information about inquiries.

[0283] Furthermore, the network address information is information indicating a unique address on a network for identifying a site, such as a domain, a URL (Uniform Resource Locator), or an IP address.

[0284] In particular, the information about the domain may be analyzed and included in the analyzed state, such as information about each level domain, such as the original domain, subdomain, and top domain.

[0285] Furthermore, for example, information regarding design (design information) indicates information such as the arrangement and overall composition of screen components (including moving images) such as pictures, symbols, marks, images, and text (including stylized ones), as well as color composition.

[0286] In particular, the design information includes, for example, a logo mark of a company, organization, or individual, a screen configuration based on an image color, and images of the products or services that the company provides.

[0287] In this embodiment, the legitimate site information is registered in advance in the fifth database 144 by the administrator or the administrator of the legitimate site.

[0288] [B3.3] Target site determination process including target site analysis process Next, the target site determination process including the target site analysis process of this embodiment will be described.

[0289] (Overview of target site determination process including analysis process) The fake site detection processing unit 105 (A1) A target site analysis process that analyzes (crawls) each information providing site (i.e., a detection target site) on the network; and (A2) a target site determination process for determining whether each target site is a site providing false information based on the already analyzed legitimate site information; Execute.

[0290] In particular, the fake site detection processor 105 executes a target site analysis process for each information providing site on the network (for each site in the case where the network is made up of a group of multiple sites).

[0291] Furthermore, the fake site detection processing unit 105 executes the target site determination process for each target site based on the legitimate site information and the network address and design of the target site.

[0292] The fake site detection processing unit 105 is configured to store the analyzed target sites in the fifth database 144.

[0293] (Analysis processing) The fake site detection processing unit 105 performs analysis by crawling each target site. The network address of each detection target site (hereinafter referred to as "target network address information") and information regarding the design forming the detection target site (hereinafter referred to as "target design information") are analyzed.

[0294] Specifically, the fake site detection processing unit 105 reads files and data such as HTML format data, PHP format files, and linked data that make up each target site, collects various data such as images and text that are displayed or played, including their layout and design, and analyzes each data, file, and link.

[0295] In particular, based on the data of each information providing site collected by crawling, the fake site detection processing unit 105 identifies, for each information providing site, network addresses such as IP addresses (which may be partial addresses for identifying the country or provider), text data such as the title and company / organization names of each target site, and design information such as the placement and decoration of images and text.

[0296] The fake site detection processing unit 105 stores the analysis results for each detection target site in the fifth database 144 for each detection target site.

[0297] (Target site determination process) Based on the results of the analysis process, the fake site detection processing unit 105 executes a target site determination process to determine whether the target site is an unauthorized information providing site.

[0298] Specifically, in the target site determination process, the fake site detection processing unit 105 compares each legitimate site information and, for each legitimate site information, determines whether the identified detection target address is an address different from the legitimate network address information included in the legitimate site information. (C1) The site to be detected contains the source information included in the corresponding legitimate site information. (C2) The site to be detected incorporates information that is identical or deemed to be identical to legitimate design information contained in the corresponding legitimate site. (C3) The detection target address matches at least a part of the legitimate network address information included in the corresponding legitimate site information, or (C4) Two or more elements of (C1)-(C3) Determine whether it is included.

[0299] In addition, the fake site detection processing unit 105 determines whether the site to be detected contains information that is considered to be identical, where the text matching rate in each part (components that make up each page) or the color information (RGB values, brightness, luminance) matching rate is above a predetermined level.

[0300] Then, in the target site determination process, if the identified detection target address is an address different from the legitimate network address information and contains the above elements, the fake site detection processing unit 105 determines that the detection target site is a site providing fake information.

[0301] For example, the fake site detection processing unit 105 may detect a domain that is different from the original domain of the legitimate site and matches a part of the original domain, as follows: (D1) The same design, such as the same logo, is used. (D2) Data relating to the same design, such as the same logo, is read out; and (D3) The link is to a legitimate site. If one or more of the above judgments are true, the site is classified as a site providing false information. It is judged as a thread.

[0302] In this embodiment, the fake site detection processing unit 105 may use the site information of the fake information providing site to perform the target site determination process for the detection target site.

[0303] [B3.4] Dummy information provision process Next, the dummy information providing process of this embodiment will be described.

[0304] When the target site determination process determines that the detection target site is a fake information providing site, the DB management control unit 102 executes a dummy information providing process to provide dummy information registered in the third database 142 to the fake information providing site.

[0305] Specifically, the DB management control unit 102 reads out a set of dummy information, which is a combination of already registered dummy identification information and dummy key information, and inputs the read out dummy information into a designated input area of the false information providing site determined by the target site determination process.

[0306] Furthermore, in addition to or instead of the dummy information providing process, the DB management control unit 102 may execute a notification control process for notifying the administrator that a false information providing site has been detected.

[0307] Instead of automatically inputting the dummy information, the DB management control unit 102 (A1) A process of setting the network address of a false information providing site and directing the administrator to the false information providing site; (A2) A support process that supports the input of dummy information to a false information providing site, or (A3) Processing of (A1) and (A2), may be executed.

[0308] [B3.5] Variations Next, a modification of this embodiment will be described.

[0309] In this embodiment, the authentication server device 11 and the service server device 30 are described as separate and independent entities, but they may be formed as a single server device or a single server system, or the authentication processing may be included in the service server device 30.

[0310] [B4] Operation in this embodiment Next, the operations related to the target site determination process and the dummy information provision process executed by the authentication server device 11 of this embodiment will be described with reference to FIG.

[0311] FIG. 12 is a flowchart showing the operations related to the target site determination process and the dummy information provision process executed by the authentication server device 11 of this embodiment.

[0312] In this operation, it is assumed that the fifth database 144 already stores information about a plurality of legitimate sites, and that the second database 141 already has dummy information registered therein.

[0313] In addition, in this operation, it is assumed that analysis processing has already been performed on each information providing site that has been uploaded to the network, and that the analysis results of each information providing site, such as network addresses and design information, have been stored in the fifth database 144.

[0314] This operation will be described assuming that it is executed for each piece of legitimate site information. In the above, the execution timing may be set for each piece of legitimate site information, or the same execution timing may be set for all legitimate information sites.

[0315] First, when the fake site detection processing unit 105 detects that specific legitimate site information (hereinafter referred to as "specific legitimate site information") has been detected at a predetermined timing (hereinafter referred to as "detection timing"), such as when an administrator's instruction is received or when a predetermined date and time has arrived (step S201), it executes a target site determination process to determine whether or not the specific legitimate site information is a fake target site from the analysis results of each information providing site (i.e., target site) that has already been analyzed (step S202).

[0316] Specifically, the fake site detection processing unit 105 compares the specified legitimate site information with the analysis result of the corresponding target site, and determines, for example, (C1) The site to be detected contains source information. (C2) The site being detected incorporates information that is identical or deemed to be identical to legitimate design information, and (C3) The identified detection target address matches at least a part of the legitimate network address information, It is determined whether at least one of the above applies, and if any of the above matches the information stored in the legitimate site information, it is determined that the site to be detected is an unauthorized information providing site.

[0317] Also, at this time, if the fake site detection processing unit 105 determines that at least one of the analyzed information providing sites (i.e., the detection target site) is a fake information providing site, it proceeds to the processing of step S203, and if it determines that none of the information providing sites is a fake information providing site, it terminates this operation.

[0318] Next, if at least one of the analyzed information providing sites (that is, the detection target site) is determined to be a false information providing site, the DB management control unit 102 reads out the corresponding information providing site (step S203).

[0319] Finally, the DB management control unit 102 inputs (provides) the read dummy information of the information providing site into the area where input is requested (step S204), and ends this operation.

[0320] [C] Other The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, terms cited in the specification or drawings as broadly defined or synonymous terms can be replaced with broadly defined or synonymous terms in other descriptions in the specification or drawings.

[0321] The present invention includes configurations that are substantially the same as the configurations described in the embodiments (for example, configurations with the same functions, methods, and results, or configurations with the same purpose and effects). The present invention also includes configurations in which non-essential parts of the configurations described in the embodiments are replaced. The present invention also includes configurations that achieve the same effects as the configurations described in the embodiments or that can achieve the same purpose. The present invention also includes configurations in which publicly known technology is added to the configurations described in the embodiments.

[0322] Although the embodiments of the present invention have been described in detail as above, it will be readily apparent to those skilled in the art that many modifications can be made without substantially departing from the novel features and effects of the present invention. Therefore, all such modifications are intended to be included within the scope of the present invention. [Explanation of symbols]

[0323] 1, 2: Authentication management communication system 10, 11: Authentication server device 20: Terminal device 30: Service server device (information providing server device) 50: Server equipment for fake information providing site 100: Processing section 101: Communication control unit 102: DB management control unit 103: Authentication processing unit 104: User information management control unit 107: Timer management unit 140: First Database 141: Second database 142: Third Database 143: 4th Database 144: 5th Database 170: Storage section 180: Information storage medium 196: Communications Department 200: Processing section 210: Communication control unit 211: Web browser 212: Imaging control unit 213: Display control unit 214: Input reception processing unit 220: Drawing section 230: Sound processing unit 250: Imaging unit 260: Operation input section 262:Detection unit 270: Storage section 271: Main memory 272: Image buffer 273: User information storage unit 280: Information storage medium 290: Display section 292: Sound output unit 296: Communications Department

Claims

1. An authentication system that performs authentication for access from a communication terminal device of each user connected via a network, a whitelist management means for managing a whitelist database in which whitelist information is stored in advance, in which, for each authorized user, authorized user identification information indicating identification information for identifying the user is associated with authorized key information indicating key information used when performing the authentication; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as the legitimate user identification information and dummy key information having the same format as the legitimate key information are associated with each other; a receiving means for receiving input information input by a user from the communication terminal device when performing the authentication; an authentication processing means for performing authentication processing of a user who inputs the input information based on information included in the received input information, including input identification information indicating the identification information and input key information indicating the key information, the whitelist information, and the dummy information; a specific processing means for performing a given specific processing based on a result of the authentication processing; Equipped with The authentication processing means execute the authentication process including a dummy determination process of searching the dummy information database based on the input identification information and the input key information, and determining whether or not there is dummy information that matches at least one of the input identification information and the input key information; The specific processing means An authentication system characterized in that, when the dummy determination process determines that there is dummy information that matches the received input information, the user who entered the input information is identified as a malicious third party and the identification process is executed against the malicious third party.

2. 2. The authentication system according to claim 1, If it is determined by the dummy determination process that there is dummy information that matches the received input information, a terminal information indicating information about the communication terminal device that transmitted the input information is sent. a registration control means for registering the related information as unauthorized access information in an unauthorized access information database, When the receiving means receives, as the input information, input terminal related information indicating terminal related information related to the communication terminal device that transmitted the input information, The authentication processing means executes an access determination process to determine whether the received input terminal related information matches the unauthorized access information; The specific processing means an authentication system that executes the identification process when the received input terminal related information matches the unauthorized access information through the access determination process;

3. 3. The authentication system according to claim 2, The present invention further comprises a blacklist management means for managing a blacklist database in which the identification information and the key information that have been used or may be used by unauthorized users are stored as blacklist information indicating a list of the identification information and the key information for prohibiting the authentication process, The specific processing means If the received input terminal related information matches the unauthorized access information in the access determination process, (a) searching the whitelist database based on the input identification information and input key information input together with the input terminal related information; (b) registering the authorized user identification information and the authorized key information that match the input identification information and the input key information in the blacklist information; An authentication system that executes the specific process.

4. In the authentication system according to any one of claims 1 to 3, An authentication system, wherein the identification process includes a notification process of notifying an administrator or a corresponding authorized user of information about the malicious third party.

5. In the authentication system according to any one of claims 1 to 4, The authentication system further comprises a dummy information provision control means for providing the registered dummy information to a fake information providing site that exploits the legitimate user identification information and the legitimate key information.

6. 6. The authentication system according to claim 5, a legitimate site management means for managing a database in which provider information indicating information on a provider of a legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; an analysis and determination processing means for executing an analysis process to analyze a detection target site, which is an information providing site that exists on the network and is to be detected, and for executing a target site determination process to determine whether the detection target site is a fake information providing site or not, based on legitimate site information, target network address information indicating the address of the detection target site on the network, and target design information indicating information regarding the design that forms the detection target site; a dummy information provision control means for executing a process for providing the registered dummy information to the fake information providing site when the target site is determined to be a fake information providing site by the target site determination process; The authentication system further comprises:

7. 7. The authentication system according to claim 6, The analysis and determination processing means By the analysis process, the presence or absence of the provider information and the legitimate design information in the detection target site is analyzed, and a detection target address indicating a network address in the detection target site is identified; An authentication system that executes the target site determination process to determine that the detection target site is the fake information provider site when at least one of the following conditions is met: (a) the detection target site contains the provider information, (b) the detection target site incorporates information that is identical to or deemed to be identical to the legitimate design information, and (c) the identified detection target address is an address that is different from the legitimate network address information but matches at least a portion of it.

8. A false information site detection system for detecting a false information site that is an information site that publishes given information on a network and is a legitimate information site, comprising: a legitimate site information management means for managing a legitimate site database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as identification information of a legitimate user and dummy key information having the same format as key information used when the legitimate user performs authentication on a legitimate information site are associated with each other; a detection means for executing a site detection process for detecting a new information providing site for disclosing given information having a network address on the network; an analysis and determination processing means for executing an analysis process for analyzing a detection target site that indicates the detected information providing site, and for executing a target site determination process for determining whether the detection target site is a fake information providing site that indicates the fake information providing site based on the stored legitimate site information; a dummy information provision control means for executing a process for providing the registered dummy information to the fake information providing site when the target site is determined to be a fake information providing site by the target site determination process; A false information providing site detection system comprising:

9. 9. The false information providing site detection system according to claim 8, The analysis and determination processing means By the analysis process, the presence or absence of the provider information and the legitimate design information in the detection target site is analyzed, and a detection target address indicating a network address in the detection target site is identified; A false information providing site detection system that executes the target site determination process to determine that the detection target site is the fake information providing site when at least one of the following conditions is met: (a) the detection target site contains the source information, (b) the detection target site incorporates information that is identical to or deemed to be identical to the legitimate design information, and (c) the identified detection target address is an address that is different from the legitimate network address information but matches at least a portion of it.

10. A program that performs authentication for access from a communication terminal device of each user connected via a network, a whitelist management means for managing a whitelist database in which whitelist information is stored in advance, in which, for each authorized user, authorized user identification information indicating identification information for identifying the user is associated with authorized key information indicating key information used when performing the authentication; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as the legitimate user identification information and dummy key information having the same format as the legitimate key information are associated with each other; a receiving means for receiving input information input by a user from the communication terminal device when performing the authentication; an authentication processing means for performing authentication processing of a user who inputs the input information based on information included in the received input information, including input identification information indicating the identification information and input key information indicating the key information, the whitelist information, and the dummy information; and a specific processing means for performing a given specific processing based on a result of the authentication processing; Make the computer function as The authentication processing means execute the authentication process including a dummy determination process of searching the dummy information database based on the input identification information and the input key information, and determining whether or not there is dummy information that matches at least one of the input identification information and the input key information; The identification processing means A program characterized in that, when the dummy determination process determines that there is dummy information that matches the received input information, the program identifies the user who entered the input information as a malicious third party and executes the identification process against the malicious third party.

11. A program for detecting a fake information providing site that indicates an information providing site that publishes given information on a network, which is a legitimate information providing site, a legitimate site information management means for managing a legitimate site database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; a dummy information management means for managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as identification information of a legitimate user and dummy key information having the same format as key information used when the legitimate user performs authentication on a legitimate information site are associated with each other; a detection means for executing a site detection process for detecting a new information providing site for disclosing given information having a network address on the network; an analysis and determination processing means for executing an analysis process for analyzing a detection target site that indicates the detected information providing site, and for executing a target site determination process for determining whether the detection target site is a fake information providing site that indicates the fake information providing site based on the stored legitimate site information; and a dummy information provision control means for executing a process for providing the registered dummy information to the fake information providing site when the target site is determined to be a fake information providing site by the target site determination process; A program that causes a computer to function as a

12. 1. An authentication method for performing authentication for access from a communication terminal device of each user connected via a network, comprising: Managing a whitelist database in which whitelist information is stored in advance, in which, for each authorized user, authorized user identification information indicating identification information for identifying the user is associated with authorized key information indicating key information used when performing the authentication; managing a dummy information database in which dummy information to be used by a malicious third party is registered in advance, the dummy information being associated with dummy identification information having the same format as the legitimate user identification information and dummy key information having the same format as the legitimate key information; receiving input information input by a user from the communication terminal device when performing the authentication; performing authentication processing of the user who input the input information based on information included in the received input information, the input identification information indicating the identification information and the input key information indicating the key information, the whitelist information, and the dummy information; and performing a given specific process based on the result of the authentication process; Including, execute the authentication process including a dummy determination process of searching the dummy information database based on the input identification information and the input key information, and determining whether or not there is dummy information that matches at least one of the input identification information and the input key information; An authentication method characterized in that, when the dummy determination process determines that there is dummy information that matches the received input information, the user who entered the input information is identified as a malicious third party, and the identification process is executed against the malicious third party.

13. A method for detecting a fake information providing site that indicates an information providing site that publishes given information on a network, the method comprising: managing a legitimate site database in which provider information indicating information on a provider of the legitimate information providing site, legitimate network address information indicating an address of the legitimate information providing site on a network, and legitimate design information indicating information on a design forming the legitimate information providing site are associated with each other and pre-stored as legitimate site information; managing a dummy information database in which dummy information is registered in advance, the dummy information being used by a malicious third party, and in which dummy identification information having the same format as identification information of a legitimate user and dummy key information having the same format as key information used when the legitimate user performs authentication on a legitimate information site are associated with each other; performing a site discovery process to discover new information providing sites for publishing given information having a network address on the network; Executing an analysis process to analyze a detection target site that indicates the detected information providing site, and executing a target site determination process to determine whether the detection target site is a fake information providing site that indicates the fake information providing site based on the stored legitimate site information; and When the target site is determined to be a fake information providing site by the target site determination process, a process is executed to provide the registered dummy information to the fake information providing site. A method for detecting a website providing false information, comprising:

Citation Information

Patent Citations

  • Web site determining device and web site determining program

    JP2009087226A

  • User authentication system

    JP2015207241A

  • Service providing system, service providing method, collating device, collating method, and computer program

    JP2018063728A