Device authentication system, authentication server, service providing server, and device authentication method

The device authentication system enhances IoT device security by using a terminal-assisted registration and server-based authentication with a one-time password and client signature verification to prevent unauthorized access.

JP7745778B2Active Publication Date: 2025-09-29MITSUBISHI ELECTRIC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024559754
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-22
Publication Date
2025-09-29
Estimated Expiration
2042-11-22

AI Technical Summary

Technical Problem

Existing IoT device authentication methods are vulnerable to unauthorized access when client credentials and device-specific identifiers are improperly installed on another device, allowing fraudulent use of services.

Method used

A device authentication system that includes a device, a terminal, an authentication server, and a service providing server, where the device transmits device information and a client certificate, the terminal facilitates registration and password issuance, and the authentication server performs registration, client authentication, and service permission determination using a one-time password and client signature verification.

Benefits of technology

Prevents unauthorized devices from accessing services by ensuring accurate registration, authentication, and permission determination, thereby securing service provision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007745778000001
    Figure 0007745778000001
  • Figure 0007745778000002
    Figure 0007745778000002
  • Figure 0007745778000003
    Figure 0007745778000003
Patent Text Reader

Abstract

A terminal (3) transmits, to an authentication server (4), registration request information containing device information including a device ID of a device (2). The authentication server (4) registers the device (2) on the basis of the received registration request information, and issues an authentication password for the device (2). The device (2) transmits, to the authentication server (4), authentication request information including the issued authentication password, the device ID, a client certificate, and a client signature. The authentication server (4) determines whether the device (2) is registered on the basis of the authentication password and device ID included in the received authentication request information, and performs client authentication of the device (2) on the basis of the client certificate and client signature included in the received authentication request information. The service provision server (5) provides a predetermined service to the device (2) if the device (2) is registered and a legitimate client.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a device authentication system, an authentication server, a service providing server, and a device authentication method. [Background technology]

[0002] IoT (Internet of Things) systems are advancing, enabling devices such as home appliances to connect to servers via the Internet and provide various services to the devices from the servers. In IoT systems, it is necessary to authenticate the legitimacy of the devices to prevent unauthorized use of the above services. A widely adopted authentication method is to authenticate the devices based on client certificates pre-installed on the devices.

[0003] However, if the client certificate is leaked and illegally installed on another device by a malicious third party, there is a concern that the other device may be permitted to access the server, leading to fraudulent use of the above-mentioned service.

[0004] In response to this, Patent Document 1 describes a configuration in which the server manages information that associates client credentials with device-specific identifiers, and if the combination of client credentials and device-specific identifier notified by the device when an authentication request is made does not match the managed information, an authentication error occurs. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Publication No. 2019-128858 Summary of the Invention [Problem to be solved by the invention]

[0006] However, in the configuration of Patent Document 1, if a third party improperly installs both the client credential and the device-specific identifier in another device, it is difficult to prevent the other device from accessing the server illegally. Therefore, there is a need for a meaningful technique to prevent the provision of services to unauthorized devices.

[0007] The present disclosure has been made in consideration of the above-described circumstances, and aims to provide a device authentication system and the like that can prevent services from being provided to unauthorized devices. [Means for solving the problem]

[0008] In order to achieve the above object, the device authentication system according to the present disclosure comprises: The system comprises a device, a terminal used by a user of the device, an authentication server, and a service providing server, The device transmits device information including device identification information for identifying the device; the terminal receives the device information transmitted from the device, and transmits to the authentication server registration request information including user identification information for identifying the user and the received device information; The authentication server receives the registration request information from the terminal, registers the device based on the received registration request information, and and becomes invalid after a certain period of time has passed. issuing an authentication password and transmitting the issued authentication password to the terminal; the terminal receives the authentication password from the authentication server and transmits the received authentication password to the device; the device receives the authentication password from the terminal, and transmits authentication request information including the received authentication password, the device identification information, a client certificate, and a client signature to the authentication server; the authentication server receives the authentication request information from the device, determines whether the device has been registered based on the authentication password and the device identification information included in the received authentication request information, and performs client authentication of the device based on the client certificate and the client signature included in the received authentication request information; The service providing server provides a predetermined service to the device if the device is registered and is a valid client. death, The authentication server invalidates the authentication password after determining whether the device is registered. . [Effects of the Invention]

[0009] According to the present disclosure, it is possible to prevent services from being provided to unauthorized devices. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 shows an overall configuration of a device service providing system according to a first embodiment. [Figure 2] FIG. 1 is a block diagram showing a hardware configuration of a device according to a first embodiment. [Figure 3] FIG. 1 is a block diagram showing a hardware configuration of a terminal according to a first embodiment. [Figure 4] FIG. 1 is a block diagram showing a hardware configuration of an authentication server according to a first embodiment. [Figure 5] FIG. 1 is a block diagram showing a hardware configuration of a service providing server according to a first embodiment. [Figure 6] A block diagram showing the functional configuration of a device and a terminal according to the first embodiment. [Figure 7] FIG. 1 is a block diagram showing the functional configuration of an authentication server and a service providing server according to a first embodiment. [Figure 8] FIG. 10 is a diagram showing an example of an account management table according to the first embodiment. [Figure 9] FIG. 10 is a diagram showing an example of a service management table according to the first embodiment. [Figure 10]1 is a flowchart showing the flow of operation of a device according to the first embodiment. [Figure 11] 1 is a flowchart showing the flow of operations of the authentication server according to the first embodiment. [Figure 12] 1 is a flowchart showing the flow of operations of the service providing server according to the first embodiment. [Figure 13] FIG. 1 is a sequence diagram showing the flow of operations of the device service providing system according to the first embodiment. [Figure 14] FIG. 10 is a diagram showing the overall configuration of a device service providing system according to a second embodiment. [Figure 15] FIG. 10 is a block diagram showing the functional configuration of an authentication server according to a second embodiment. [Figure 16] FIG. 10 is a diagram showing an example of a payment management table according to the second embodiment. [Figure 17] FIG. 10 is a block diagram showing a functional configuration of a service providing server according to a second embodiment. [Figure 18] FIG. 10 is a diagram showing an example of a service management table according to the second embodiment. [Figure 19] FIG. 10 is a diagram showing the overall configuration of a device service providing system according to a third embodiment. [Figure 20] A block diagram showing the functional configuration of a terminal according to a third embodiment. [Figure 21] FIG. 11 is a block diagram showing the functional configuration of an authentication server and a service providing server according to a third embodiment. [Figure 22] FIG. 10 is a sequence diagram showing the flow of operations of the device service providing system according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0012] (Embodiment 1) 1 is a diagram showing the overall configuration of a device service providing system 1 according to the first embodiment. The device service providing system 1 is a system that provides predetermined services to devices 2 installed in each user's home H, and includes the devices 2, a terminal 3, an authentication server 4, and a service providing server 5. The device service providing system 1 is an example of a device authentication system according to the present disclosure.

[0013] <Hardware configuration of device 2> The device 2 is an example of a device according to the present disclosure. The device 2 is, for example, a home appliance known as an IoT (Internet of Things) device, an information appliance, a network appliance, or a smart appliance, such as an air conditioner, a lighting device, or a television. As shown in FIG. 2 , the device 2 includes a first communication interface 20, a second communication interface 21, a main unit 22, a control circuit 23, and an auxiliary storage device 24.

[0014] The first communication interface 20 is hardware for performing wired or wireless LAN (Local Area Network) communication. The second communication interface 21 is hardware for performing ad-hoc communication such as BLE (Bluetooth (registered trademark) Low Energy) communication.

[0015] The main unit 22 is a component for realizing the original functions of the device 2. For example, if the device 2 is an indoor unit of an air conditioner, the main unit 22 includes, for example, actuators such as a fan and a solenoid valve, a heat exchanger, and sensors such as a temperature sensor, a thermal image sensor, and a refrigerant temperature sensor. If the device 2 is a lighting device, the main unit 22 includes, for example, an LED (Light-Emitting Diode). If the device 2 is a television, the main unit 22 includes, for example, a TV tuner, a liquid crystal or organic EL (Electroluminescence) display, and a speaker.

[0016] The control circuit 23 includes a CPU (Central Processing Unit), ROM (Read-Only Memory), RAM (Random-Access Memory), etc., and performs overall control of the device 2. The auxiliary storage device 24 includes a readable / writable nonvolatile semiconductor memory, an HDD (Hard Disk Drive), etc. Examples of the readable / writable nonvolatile semiconductor memory include an EEPROM (Electrically Erasable Programmable Read-Only Memory), a flash memory, etc. The auxiliary storage device 24 stores a program for operating the device 2 (hereinafter referred to as the "device operation program") and data used when the device operation program is executed.

[0017] The device 2 can acquire the device operation program or an update program for updating the device operation program from the service providing server 5 or another server via communication. These programs can also be stored and distributed on a computer-readable recording medium such as a CD-ROM (Compact Disc Read-Only Memory), a DVD (Digital Versatile Disc), a magneto-optical disk, a USB (Universal Serial Bus) memory, a HDD, an SSD (Solid-State Drive), or a memory card. When such a recording medium is directly or indirectly attached to the device 2, the device 2 can read the device operation program or update program from the recording medium and install it on itself.

[0018] <Hardware configuration of terminal 3> Terminal 3 is an example of a terminal according to the present disclosure. Terminal 3 is a smart device such as a smartphone or tablet terminal used by a user of device 2. As shown in Fig. 3, terminal 3 includes a display 30, an operation reception unit 31, a first communication interface 32, a second communication interface 33, a CPU 34, a ROM 35, a RAM 36, and an auxiliary storage device 37. These components are connected to each other via a bus 38.

[0019] The display 30 includes a display device such as a liquid crystal display, an organic EL display, etc. The display 30 displays various screens etc. in response to user operations under the control of the CPU 34. The operation reception unit 31 includes one or more input devices such as a push button, a touch panel, a touch pad, etc., receives operation input from the user, and outputs a signal related to the received operation to the CPU 34.

[0020] The first communication interface 32 is hardware for wireless LAN for connecting to a router (not shown) installed in the house H or an outdoor access point. The second communication interface 33 is hardware for performing ad hoc communication such as BLE communication. Although not shown, the terminal 3 may further include hardware for mobile data communication and may be configured to communicate with devices outside the home, such as the authentication server 4, based on, for example, 4G (fourth generation mobile communication system), 5G (fifth generation mobile communication system), etc.

[0021] The CPU 34 performs overall control of the terminal 3. The ROM 35 stores a plurality of pieces of firmware and data used when these pieces of firmware are executed. The RAM 36 is used as a work area for the CPU 34.

[0022] The auxiliary storage device 37 is configured to include a readable / writable nonvolatile semiconductor memory such as an EEPROM or a flash memory. The auxiliary storage device 37 stores various programs including application programs (hereinafter referred to as "terminal applications") for performing operations related to requests for user registration and requests for device 2 registration to the authentication server 4, and display operations related to services provided by the service providing server 5, as well as data used when these programs are executed.

[0023] The terminal 3 can acquire terminal apps or update programs for updating terminal apps from the service providing server 5 or other servers via communications. These programs can also be stored and distributed on computer-readable recording media such as CD-ROMs, DVDs, optical magnetic disks, USB memory, HDDs, SSDs, and memory cards. When such a recording medium is directly or indirectly attached to the terminal 3, the terminal 3 can read the terminal app or update program from the recording medium and install it on itself.

[0024] <Authentication Server 4 hardware configuration> The authentication server 4 is an example of an authentication server according to the present disclosure. The authentication server 4 is a so-called cloud server, and is connected to a network N such as the Internet. Upon receiving an authentication request from a device 2, the authentication server 4 determines whether or not provision of a service to the device 2 is permitted, and transmits determination result information indicating the determination result to the service providing server 5. As shown in FIG. 4 , the authentication server 4 includes a communication interface 40, a CPU 41, a ROM 42, a RAM 43, and an auxiliary storage device 44. These components are connected to each other via a bus 45.

[0025] The communication interface 40 is hardware for communicating with other devices via the network N, and is, for example, an interface based on Ethernet (registered trademark). The CPU 41 controls the authentication server 4 in an overall manner. The functions of the authentication server 4 realized by the CPU 41 will be described in detail later. The ROM 42 stores multiple pieces of firmware and data used when these pieces of firmware are executed. The RAM 43 is used as a working area for the CPU 41.

[0026] The auxiliary storage device 44 is composed of a readable / writable nonvolatile semiconductor memory, a HDD, etc. Examples of the readable / writable nonvolatile semiconductor memory include an EEPROM, a flash memory, etc. The auxiliary storage device 44 stores a program (hereinafter referred to as a "device authentication program") that manages user accounts, performs client authentication of a device 2 that has received an authentication request, and determines whether or not the provision of a service to the device 2 can be permitted, as well as data that is used when the device authentication program is executed.

[0027] The authentication server 4 can acquire the device authentication program or an update program for updating the device authentication program from another server via communication. These programs can also be stored and distributed on a computer-readable recording medium such as a CD-ROM, DVD, optical magnetic disk, USB memory, HDD, SSD, or memory card. When such a recording medium is directly or indirectly attached to the authentication server 4, the authentication server 4 can read the device authentication program or update program from the recording medium and install it on itself.

[0028] <Hardware configuration of service provider server 5> The service providing server 5 is an example of a service providing server according to the present disclosure. The service providing server 5 is a so-called cloud server, and is connected to the network N. The service providing server 5 provides a predetermined service to the device 2 for which the authentication server 4 has determined that provision of the service is permitted. For example, the service providing server 5 provides an energy saving control service that controls the operation of the device 2 so as to reduce the power consumption of the device 2, an anomaly detection service that monitors the operating state of the device 2, detects whether or not there is an abnormality in the device 2, and notifies the user if an abnormality is detected, and the like.

[0029] As shown in FIG. 5, the service providing server 5 includes a communication interface 50, a CPU 51, a ROM 52, a RAM 53, and an auxiliary storage device 54. These components are connected to one another via a bus 55. The communication interface 50 is hardware for communicating with other devices via a network N, and is, for example, an interface based on Ethernet (registered trademark). The CPU 51 comprehensively controls the service providing server 5. The functions of the service providing server 5 realized by the CPU 51 will be described in detail later. The ROM 52 stores multiple pieces of firmware and data used when these pieces of firmware are executed. The RAM 53 is used as a working area for the CPU 51.

[0030] The auxiliary storage device 54 is configured with a readable / writable nonvolatile semiconductor memory, a HDD, etc. Examples of the readable / writable nonvolatile semiconductor memory include an EEPROM, a flash memory, etc. The auxiliary storage device 54 stores a program for providing a service to the device 2 (hereinafter referred to as a "service providing program") and data used when the service providing program is executed.

[0031] The service providing server 5 can acquire the service providing program or an update program for updating the service providing program from another server via communication. These programs can also be stored and distributed on a computer-readable recording medium such as a CD-ROM, DVD, optical magnetic disk, USB memory, HDD, SSD, or memory card. When such a recording medium is directly or indirectly attached to the service providing server 5, the service providing server 5 can read the service providing program or update program from the recording medium and install it on itself.

[0032] <Functional configuration of device 2 and terminal 3> Fig. 6 is a block diagram showing the functional configuration of the device 2 and the terminal 3. As shown in Fig. 6, the device 2 includes a device information transmission unit 200, an authentication password reception unit 201, an authentication request unit 202, a service request unit 203, and a service execution unit 204. These functional units are realized by the control circuit 23 executing the above-mentioned device operation program stored in the auxiliary storage device 24.

[0033] The terminal 3 includes a device information receiving unit 300, a registration request unit 301, and an authentication password transmitting unit 302. These functional units are realized by the CPU 34 executing the above-mentioned terminal application stored in the auxiliary storage device 37.

[0034] In the device 2, when the device information transmission unit 200 is turned on, it periodically transmits the device information read from the device information storage unit 240 for a certain period of time via the second communication interface 21. Note that the device 2 may also unicast the device information to the terminal 3 via the first communication interface 20 or the second communication interface 21.

[0035] The device information storage unit 240 is a memory area provided by the auxiliary storage device 24. Device information is written to the device information storage unit 240 by the manufacturer of the device 2 when the device 2 is shipped from the factory. The device information includes a device ID (identifier) ​​and a device type. The device ID is an example of device identification information according to the present disclosure. The device ID is information for identifying the device 2, and is, for example, a serial number (also called a manufacturing number or serial code).

[0036] After transmitting the device information, the authentication password receiving unit 201 receives the authentication password sent from the terminal 3. The authentication password receiving unit 201 stores the received authentication password in the device information storage unit 240. Details of the authentication password will be described later. When the authentication password receiving unit 201 receives the authentication password, the authentication request unit 202 requests the authentication server 4 to authenticate the device 2 by transmitting authentication request information to the authentication server 4.

[0037] The authentication request information includes an authentication password, device information, a client certificate, and a client signature signed with the client private key. In this embodiment, it is assumed that the manufacturer of device 2 requests a certificate authority (not shown) to sign a client certificate including a client public key when shipping device 2 from the factory, and writes the client certificate signed by the certificate authority and the client private key paired with the client public key to authentication information storage unit 241. Authentication information storage unit 241 is a memory area provided by auxiliary storage device 24.

[0038] After requesting authentication of the device 2, the service request unit 203 requests the service providing server 5 to provide a service by transmitting service request information including the device ID to the service providing server 5. Note that if there are multiple services that can be provided by the device 2, the service request information may include information indicating the requested service. The service requested from the service providing server 5 can be specified by the user operating an operation panel provided on the device 2, a dedicated remote control for the device 2, or the terminal 3.

[0039] The service execution unit 204 executes the service provided by the service providing server 5. For example, if the service is an energy saving control service, the service execution unit 204 executes energy saving processing in accordance with a control command from the service providing server 5.

[0040] In the terminal 3, the device information receiving unit 300 receives the device information transmitted from the device 2. The device information receiving unit 300 supplies the received device information to the registration request unit 301. The registration request unit 301 requests the authentication server 4 to register the device 2 by transmitting registration request information including the user ID of the user of the device 2 and the device information supplied from the device information receiving unit 300 to the authentication server 4. The user ID is an example of user identification information according to the present disclosure. The user ID is information for identifying a user who has already been registered in the device service providing system 1, and is set by the user or the authentication server 4 at the time of user registration. In this embodiment, it is assumed that the user has previously operated the terminal 3 to access the authentication server 4 and performed user registration.

[0041] After requesting registration of device 2, registration request unit 301 receives an authentication password issued by authentication server 4 from authentication server 4, and supplies the received authentication password to authentication password sending unit 302. Authentication password sending unit 302 transmits the authentication password supplied from registration request unit 301 to device 2.

[0042] <Functional configuration of authentication server 4 and service providing server 5> Fig. 7 is a block diagram showing the functional configuration of the authentication server 4 and the service providing server 5. As shown in Fig. 7, the authentication server 4 includes a device registration unit 400, an authentication request information receiving unit 401, a registration determination unit 402, a client authentication unit 403, a service permission determination unit 404, and a determination result information transmitting unit 405. These functional units are realized by the CPU 41 executing the above-mentioned device authentication program stored in the auxiliary storage device 44.

[0043] The service providing server 5 includes a service management unit 500 and a service providing unit 501. These functional units are realized by the CPU 51 executing the above-mentioned service providing program stored in the auxiliary storage device 54.

[0044] In the authentication server 4, the device registration unit 400 is an example of a device registration means according to the present disclosure. When the device registration unit 400 receives a request to register the device 2 from the terminal 3, that is, when it receives registration request information from the terminal 3, it registers the device 2. In detail, the device registration unit 400 extracts device information included in the received registration request information and stores the extracted device information in the account management table 440. The device registration unit 400 also issues an authentication password to the device 2 and transmits the issued authentication password to the terminal 3. The authentication password is a password with usage restrictions, for example, valid only once within a certain period of time. In this embodiment, the authentication password is a one-time password. As described above, the authentication password is information required when the device 2 requests authentication of itself from the authentication server 4.

[0045] The account management table 440 is a data table for managing information about registered users, i.e., user accounts, and is stored in the auxiliary storage device 44. As shown in FIG. 8, the account management table 440 stores a user ID, a password, and registered device information for each user. As described above, the user ID is information for identifying a registered user, and is set by the user or the authentication server 4 at the time of user registration so as not to overlap with other user IDs. The password is set by the user at the time of user registration. The authentication server 4 authenticates whether the user is a registered user based on the set of the user ID and password.

[0046] The registered device information stores information about the device 2 registered by the user. In detail, for each registered device 2, device information (i.e., device ID and device type) and an authentication password issued to the device 2 are stored.

[0047] The authentication request information receiving unit 401 is an example of an authentication request information receiving means according to the present disclosure. The authentication request information receiving unit 401 receives authentication request information from the device 2, thereby accepting an authentication request from the device 2. Upon receiving the authentication request information from the device 2, the authentication request information receiving unit 401 extracts an authentication password and device information included in the received authentication request information, and supplies the extracted authentication password and device information to the registration determination unit 402. In addition, the authentication request information receiving unit 401 extracts a client certificate and a client signature included in the received authentication request information, and supplies the extracted client certificate and client signature to the client authentication unit 403.

[0048] The registration determination unit 402 is an example of a registration determination means according to the present disclosure. The registration determination unit 402 determines whether or not the device 2 has been registered based on the authentication password and device information supplied from the authentication request information receiving unit 401 and the account management table 440. In detail, the registration determination unit 402 determines whether or not registered device information matching the set of authentication password and device information supplied from the authentication request information receiving unit 401 is stored in the account management table 440. If registered device information matching the set is stored in the account management table 440, the registration determination unit 402 determines that the device 2 has been registered.

[0049] On the other hand, if registered device information matching the set is not stored in the account management table 440, the registration determination unit 402 determines that the device 2 is not registered. The registration determination unit 402 notifies the service permission determination unit 404 of the determination result. After determining whether the device 2 is registered, the registration determination unit 402 invalidates the authentication password of the device 2. Specifically, the registration determination unit 402 deletes the authentication password included in the registered device information corresponding to the device 2 in the account management table 440. Apart from deleting the authentication password by the registration determination unit 402, the authentication server 4 invalidates authentication passwords that have been issued for a certain period of time.

[0050] The client authentication unit 403 is an example of a client authentication means according to the present disclosure. The client authentication unit 403 performs client authentication of the device 2 based on the client certificate and client signature supplied from the authentication request information receiving unit 401. In detail, the client authentication unit 403 verifies the client public key included in the client certificate using the public key of the certificate authority acquired from the certificate authority. If the validity of the client public key can be confirmed, the client authentication unit 403 verifies the client signature using the client public key. On the other hand, if the validity of the client public key cannot be confirmed, the client authentication unit 403 notifies the service permission determination unit 404 of the authentication result that the device 2 is not a valid client.

[0051] If the client authentication unit 403 can confirm the validity of the client signature as a result of verifying the client signature, it notifies the service permission determination unit 404 of the authentication result that the device 2 is a valid client. On the other hand, if the validity of the client signature cannot be confirmed, the client authentication unit 403 notifies the service permission determination unit 404 of the authentication result that the device 2 is not a valid client.

[0052] The service permission determination unit 404 determines whether or not the provision of the service to the device 2 can be permitted based on the determination result notified by the registration determination unit 402 and the authentication result notified by the client authentication unit 403. In particular, if the service permission determination unit 404 determines that the device 2 is registered and that the device 2 is a valid client, it determines that the provision of the service to the device 2 can be permitted. On the other hand, if the device 2 is determined to be not registered or if the device 2 is determined to be an invalid client, the service permission determination unit 404 determines that the provision of the service to the device 2 cannot be permitted. The service permission determination unit 404 notifies the determination result information transmission unit 405 of the determination result.

[0053] The determination result information transmitting unit 405 transmits to the service providing server 5 the determination result information including the determination result of the service permission determining unit 404 and the device information of the device 2 (device ID and device type).

[0054] In the service providing server 5, the service management unit 500 appropriately updates the service management table 540. In detail, the service management unit 500 receives determination result information from the authentication server 4, and updates the service management table 540 based on the received determination result information. The service management table 540 is a data table for managing permission / denial of service provision for each device 2, and is stored in the auxiliary storage device 54. As shown in Fig. 9, the service management table 540 stores, for each device 2, a device ID, a device type, and information indicating permission or denial.

[0055] The service providing unit 501 is an example of a service providing means according to the present disclosure. When the service providing unit 501 receives a request for providing a service from the device 2, that is, when it receives service request information from the device 2, it determines whether or not the provision of the service to the device 2 is permitted by referring to the service management table 540 based on the device ID included in the received service request information. If the provision of the service to the device 2 is permitted, the service providing unit 501 provides a predetermined service (for example, an energy saving control service) to the device 2. On the other hand, if the provision of the service to the device 2 is not permitted, the service providing unit 501 does not provide the service to the device 2.

[0056] <Device 2 Operation> Hereinafter, the operation of the device 2 from startup to the start of service execution will be described with reference to FIG.

[0057] (Step S100) The device 2 transmits the device information (i.e., the device ID and device type) read from the device information storage unit 240 via the second communication interface 21. After that, the operation of the device 2 transitions to step S101. Note that even if the device 2 is in a power-on state, if it has already requested authentication of itself from the authentication server 4, it does not transmit the device information.

[0058] (Step S101) The device 2 waits for an authentication password to be transmitted from the terminal 3. If the authentication password is received (step S101: YES), the operation of the device 2 proceeds to step S102. If the authentication password is not received (step S101: NO), the device 2 continues to wait for an authentication password to be transmitted from the terminal 3.

[0059] (Step S102) The device 2 transmits authentication request information including the authentication password, device information, client certificate, and client signature signed with the client private key to the authentication server 4. Thereafter, the operation of the device 2 proceeds to step S103.

[0060] (Step S103) The device 2 transmits service request information including the device ID to the service providing server 5. After that, the operation of the device 2 proceeds to step S104.

[0061] (Step S104) The device 2 executes the service provided by the service providing server 5 .

[0062] <Authentication Server 4 Operation> The operation of the authentication server 4 will be described below with reference to Fig. 11. Although not shown in Fig. 11, when a new user performs a user registration operation via the terminal 3, the authentication server 4 also performs an operation to create a user account for the user.

[0063] (Step S200) The authentication server 4 determines whether or not registration request information has been received from the terminal 3. If registration request information has been received from the terminal 3 (step S200; YES), the operation of the authentication server 4 proceeds to step S201. If registration request information has not been received from the terminal 3 (step S200; NO), the operation of the terminal 3 proceeds to step S202.

[0064] (Step S201) The authentication server 4 registers the device 2 based on the received registration request information. Specifically, the authentication server 4 extracts the device information included in the received registration request information and stores the extracted device information in the account management table 440. Thereafter, the operation of the authentication server 4 returns to step S200.

[0065] (Step S202) The authentication server 4 determines whether or not authentication request information has been received from the device 2. If authentication request information has been received from the device 2 (step S202; YES), the operation of the device 2 proceeds to step S203. If authentication request information has not been received from the device 2 (step S202; NO), the operation of the device 2 returns to step S200.

[0066] (Step S203) The authentication server 4 determines whether the device 2 is registered, i.e., whether the device 2 has already been registered, based on the authentication password and device information included in the received authentication request information and the account management table 440. Thereafter, the operation of the authentication server 4 proceeds to step S204.

[0067] (Step S204) The authentication server 4 performs client authentication of the device 2 based on the client certificate and client signature included in the received authentication request information and the public key of the certificate authority acquired from the certificate authority. After that, the operation of the authentication server 4 proceeds to step S205.

[0068] (Step S205) Based on the determination result of step S203 and the authentication result of step S204, the authentication server 4 determines whether or not it is possible to permit provision of the service to the device 2. In particular, if the authentication server 4 determines that the device 2 is registered and that the device 2 is a valid client, it determines that it is possible to permit provision of the service to the device 2. On the other hand, if it determines that the device 2 is not registered or that the device 2 is not a valid client, the authentication server 4 determines that it is not possible to permit provision of the service to the device 2. Thereafter, the operation of the authentication server 4 proceeds to step S206.

[0069] (Step S206) The authentication server 4 transmits the determination result information including the determination result of step S205 and the device information of the device 2 to the service providing server 5. Thereafter, the operation of the authentication server 4 returns to step S200.

[0070] In the above, the order of determining whether or not registration exists (step S203) and client authentication (step S204) can be arbitrary, and the determination of whether or not registration exists may be performed after client authentication.

[0071] <Operation of service providing server 5> The operation of the service providing server 5 will be described below with reference to FIG.

[0072] (Step S300) The service providing server 5 determines whether or not it has received the determination result information from the authentication server 4. If it has received the determination result information from the authentication server 4 (step S300; YES), the operation of the service providing server 5 transitions to step S301. If it has not received the determination result information from the authentication server 4 (step S300; NO), the operation of the service providing server 5 transitions to step S302.

[0073] (Step S301) Based on the received determination result information, the service providing server 5 updates the service management table 540. After that, the operation of the service providing server 5 returns to step S300.

[0074] (Step S302) The service providing server 5 determines whether or not service request information has been received from the device 2. If service request information has been received from the device 2 (step S302; YES), the operation of the service providing server 5 proceeds to step S303. If service request information has not been received from the device 2 (step S302; NO), the operation of the service providing server 5 returns to step S300.

[0075] (Step S303) The service providing server 5 refers to the service management table 540 based on the device ID included in the received service request information to determine whether provision of the service to the device 2 is permitted. If provision of the service to the device 2 is permitted (step S303; YES), the operation of the service providing server 5 proceeds to step S304. If provision of the service to the device 2 is not permitted (step S303; NO), the operation of the service providing server 5 returns to step S300.

[0076] (Step S304) The service providing server 5 provides a predetermined service (for example, an energy saving control service) to the device 2. After that, the operation of the service providing server 5 returns to step S300.

[0077] <Operation of device service providing system 1> The overall operational flow of the equipment service providing system 1 will be described below with reference to FIG.

[0078] (Step S400) When the device 2 is turned on, it transmits device information including its own device ID and device type.

[0079] (Step S401) When the terminal 3 receives the device information from the device 2, it transmits to the authentication server 4 registration request information including the user ID of the user and the received device information.

[0080] (Step S402) When the authentication server 4 receives the registration request information from the terminal 3, it registers the device 2 based on the received registration request information.

[0081] (Step S403) The authentication server 4 issues an authentication password to the device 2 and transmits the issued authentication password to the terminal 3 .

[0082] (Step S404) When the terminal 3 receives the authentication password from the authentication server 4, it transmits the received authentication password to the device 2.

[0083] (Step S405) Upon receiving the authentication password from the terminal 3, the device 2 transmits to the authentication server 4 authentication request information including the received authentication password, its own device information, a client certificate, and a client signature signed with the client private key.

[0084] (Step S406) When the authentication server 4 receives the authentication request information from the device 2, it determines whether or not the device 2 has been registered based on the authentication password and device information included in the received authentication request information.

[0085] (Step S407) The authentication server 4 performs client authentication of the device 2 based on the client certificate and client signature included in the received authentication request information, and the public key of the certificate authority.

[0086] (Step S408) The authentication server 4 determines whether or not the provision of the service to the device 2 can be permitted based on the determination result in step S406 and the authentication result in step S407.

[0087] (Step S409) The authentication server 4 transmits the determination result information including the determination result and the device information of the device 2 (device ID and device type) to the service providing server 5.

[0088] (Step S410) Upon receiving the determination result information from the authentication server 4, the service providing server 5 updates the service management table 540 based on the received determination result information.

[0089] (Step S411) The device 2 requests the service providing server 5 to provide a service by transmitting service request information including its own device ID to the service providing server 5.

[0090] (Step S412) When the service providing server 5 receives the service request information from the device 2, it provides a predetermined service to the device 2 only if the provision of the service to the device 2 is permitted.

[0091] As described above, in the device service providing system 1 of this embodiment, the service providing server 5 provides services only to devices 2 for which user registration and device registration have been completed and which have been confirmed to be legitimate clients through client authentication. This makes it possible to prevent services from being provided to unauthorized devices.

[0092] Furthermore, the authentication server 4 issues an authentication password, which is a one-time password, to the device 2 whose device registration has been completed, and the terminal 3 transmits the issued authentication password to the device 2. When the device 2 requests its own authentication from the authentication server 4, it transmits authentication request information including the authentication password to the authentication server 4. The authentication server 4 determines whether the device 2 has been registered by taking into account not only the device ID but also the authentication password. This allows the authenticity of the device 2 to be determined with higher accuracy, further preventing the use of services by unauthorized devices.

[0093] (Variation 1) The service provided to the device 2 may include a mode in which the device 2 downloads a predetermined program from the service providing server 5 and executes the program at any timing. In this case, the service providing server 5 may permit downloading of the program only to devices 2 that are authorized to receive the service, or may permit downloading of the program to devices 2 that are not authorized to receive the service. In the latter case, the program is designed so that it cannot be executed as is, and the service providing server 5 separately transmits a license key for validating the downloaded program to devices 2 that have been confirmed to be authorized to receive the service.

[0094] (Variation 2) All or part of the functional units of the device 2 (see FIG. 6) may be implemented by dedicated hardware, all or part of the functional units of the terminal 3 (see FIG. 6) may be implemented by dedicated hardware, all or part of the functional units of the authentication server 4 (see FIG. 7) may be implemented by dedicated hardware, and all or part of the functional units of the service providing server 5 (see FIG. 7) may be implemented by dedicated hardware. Dedicated hardware is, for example, a single circuit, a composite circuit, a programmed processor, an ASIC (Application-Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof.

[0095] The technical ideas according to the above-described modifications may be realized independently or in appropriate combination.

[0096] (Embodiment 2) Next, a description will be given of embodiment 2 of the present disclosure. In the following description, components and the like common to embodiment 1 will be given the same reference numerals and descriptions thereof will be omitted.

[0097] 14 is a diagram showing the overall configuration of a device service providing system 1A according to Embodiment 2. The device service providing system 1A is a system that provides predetermined services to a device 2A installed in each user's residence H, and includes the device 2A, a terminal 3A, an authentication server 4A, and a service providing server 5A. The device service providing system 1A is an example of a device authentication system according to the present disclosure.

[0098] <Device 2A> Device 2A is an example of a device according to the present disclosure. The hardware configuration and functional configuration of device 2A are similar to those of device 2 (see FIGS. 2 and 6). However, when requesting the provision of a service from service providing server 5A, service request unit 203 of device 2A transmits service request information including a device ID and information indicating the requested service to service providing server 5A. The service requested from service providing server 5A can be specified by the user operating an operation panel provided on device 2A, a dedicated remote control for device 2A, or terminal 3A.

[0099] <Terminal 3A> Terminal 3A is an example of a terminal according to the present disclosure. The hardware configuration and functional configuration of terminal 3A are similar to those of terminal 3 (see FIGS. 3 and 6). However, terminal 3A further includes a functional unit that pays fees for services that incur charges in accordance with user operations. Hereinafter, services that incur charges will be referred to as "charged services."

[0100] <Authentication Server 4A> The authentication server 4A is an example of an authentication server according to the present disclosure. The hardware configuration of the authentication server 4A is similar to the hardware configuration of the authentication server 4 (see FIG. 4). As shown in FIG. 15, the authentication server 4A includes, as its functional configuration, a device registration unit 400, an authentication request information receiving unit 401, a registration determination unit 402, a client authentication unit 403, a service permission determination unit 404, a determination result information transmitting unit 405, a payment accepting unit 406, and a payment information transmitting unit 407. These functional units are realized when the CPU 41 of the authentication server 4A executes a device authentication program stored in the auxiliary storage device 44.

[0101] The functional configuration of authentication server 4A differs from the functional configuration of authentication server 4 (see FIG. 7) in that it newly includes a payment acceptance unit 406 and a payment information transmission unit 407. Payment acceptance unit 406 accepts payment of a fee for a billing service from the user via terminal 3A. The user pays the fee for the billing service, for example, by online payment. Payment acceptance unit 406 stores information related to the accepted payment in payment management table 441. Note that payment acceptance unit 406 does not accept payment of a fee corresponding to device 2A for which the service permission determination unit 404 has determined that provision of the service cannot be permitted.

[0102] The payment management table 441 is a data table for managing the billing services for which each user has already paid, and is stored in the auxiliary storage device 44. As shown in Fig. 16, the payment management table 441 stores a user ID and payment information for each user. The payment information is information that links the device 2 with the billing service for which payment has already been made, and stores the device ID and information indicating the billing service (for example, the name).

[0103] When the user pays the fee for the billing service, the payment information sending unit 407 sends the payment information to the service providing server 5 A. The payment information includes the user ID, the device ID, and information indicating the billing service for which the fee has been paid.

[0104] <Service providing server 5A> The service providing server 5A is an example of a service providing server according to the present disclosure. The hardware configuration of the service providing server 5A is similar to the hardware configuration of the service providing server 5 (see FIG. 5). As shown in FIG. 17, the service providing server 5A includes, as functional components, a service management unit 502 and a service providing unit 503. These functional units are realized by the CPU 51 included in the service providing server 5A executing a service providing program stored in the auxiliary storage device 54.

[0105] The functional configuration of service providing server 5A differs from the functional configuration of service providing server 5 (see FIG. 7) in that service management unit 502 and service providing unit 503 are provided instead of service management unit 500 and service providing unit 501. Service management unit 502 updates service management table 541 as appropriate. In detail, service management unit 502 receives determination result information from authentication server 4A, and updates service management table 541 based on the received determination result information. Service management unit 502 also receives payment information from authentication server 4A, and updates service management table 541 based on the received payment information.

[0106] The service management table 541 is a data table for managing permission / denial of service provision and paid billing services for each device 2A, and is stored in the auxiliary storage device 54. As shown in Fig. 18, the service management table 541 stores, for each device 2A, the device ID, the device type, information indicating whether permission or denial is granted, and information indicating paid billing services.

[0107] When the service providing unit 503 receives a request for providing a service from the device 2A, that is, when it receives service request information from the device 2A, it determines whether or not provision of the service to the device 2A is permitted by referring to the service management table 541 based on the device ID included in the received service request information. If provision of the service to the device 2A is permitted, the service providing unit 503 determines whether or not the service requested by the device 2A is a billable service. If the requested service is not a billable service, the service providing unit 503 provides the service to the device 2A.

[0108] On the other hand, if the requested service is a billable service, the service providing unit 503 refers to the service management table 541 and determines whether the fee for the requested service has been paid for the device 2A. If the fee for the service has been paid, the service providing unit 503 provides the service to the device 2A.

[0109] If provision of the service to the device 2A is not permitted, the service providing unit 503 does not provide the service to the device 2A. Also, if provision of the service to the device 2A is permitted but the service is a billable service and the fee has not yet been paid, the service providing unit 503 does not provide the service to the device 2A.

[0110] As described above, the device service providing system 1A in this embodiment has the same effects as the device service providing system 1 in the first embodiment, and further has the advantageous effect of being able to accommodate billing services.

[0111] (Variation 1) The service provided to the device 2A may include a mode in which the device 2A downloads a desired program from the service providing server 5A and executes the program at any timing. In this case, if the program is a program related to a billing service (hereinafter referred to as a "billing program"), the service providing server 5A may permit the device 2A to download the billing program only if the provision of the service is permitted and the user has paid the fee for the billing service.

[0112] Alternatively, the service providing server 5A may permit the device 2A to download the billing program even if the user has not paid the fee for the billing service. In this case, the billing program is designed to be inoperable as is, and the service providing server 5A will separately transmit a license key to the device 2A to activate the billing program once payment of the fee for the billing service has been confirmed.

[0113] (Variation 2) All or part of the functional units of the authentication server 4A (see FIG. 15) may be realized by dedicated hardware, and all or part of the functional units of the service providing server 5A (see FIG. 17) may be realized by dedicated hardware. The dedicated hardware may be, for example, a single circuit, a composite circuit, a programmed processor, an ASIC, an FPGA, or a combination thereof.

[0114] The technical ideas according to the above-described modifications may be realized independently or in appropriate combination.

[0115] (Embodiment 3) Next, a description will be given of embodiment 3 of the present disclosure. In the following description, components and the like common to embodiment 1 will be given the same reference numerals and descriptions thereof will be omitted.

[0116] 19 is a diagram showing the overall configuration of a device service providing system 1B according to the third embodiment. The device service providing system 1B is a system that provides predetermined services to devices 2 installed in each user's home H, and includes the devices 2, a terminal 3B, an authentication server 4B, and a service providing server 5B. The device service providing system 1B is an example of a device authentication system according to the present disclosure.

[0117] <Terminal 3B> Terminal 3B is an example of a terminal according to the present disclosure. The hardware configuration of terminal 3B is similar to the hardware configuration of terminal 3 (see FIG. 3). As shown in FIG. 20, terminal 3B includes, as functional components, a device information receiving unit 300, an authentication password transmitting unit 302, and a registration request unit 303. These functional units are realized by the CPU 34 included in terminal 3B executing a terminal application stored in the auxiliary storage device 37.

[0118] The functional configuration of terminal 3B differs from the functional configuration of terminal 3 (see FIG. 6) in that it includes a registration request unit 303 instead of registration request unit 301. When device information transmitted from device 2 is received by device information receiving unit 300, registration request unit 303 transmits registration request information including the user ID of the user of device 2 and the received device information to service providing server 5B, thereby requesting service providing server 5B to register device 2. The user ID is set by the user or service providing server 5B at the time of user registration. In this embodiment, it is assumed that the user has previously operated terminal 3B to access service providing server 5B and performed user registration.

[0119] After requesting registration of device 2, registration request unit 303 receives an authentication password issued by service providing server 5B from service providing server 5B and supplies the received authentication password to authentication password sending unit 302. The authentication password sending unit 302 transmits the authentication password supplied from registration request unit 303 to device 2.

[0120] <Authentication Server 4B> The authentication server 4B is an example of an authentication server according to the present disclosure. The hardware configuration of the authentication server 4B is similar to the hardware configuration of the authentication server 4 (see FIG. 4). As shown in FIG. 21, the authentication server 4B includes, as its functional configuration, a client authentication unit 403, an authentication request information receiving unit 408, and an authentication result information transmitting unit 409. These functional units are realized when the CPU 41 of the authentication server 4B executes a device authentication program stored in the auxiliary storage device 44.

[0121] The functional configuration of authentication server 4B differs from the functional configuration of authentication server 4 (see Figure 7) in that it has an authentication request information receiving unit 408 and an authentication result information transmitting unit 409 instead of the device registration unit 400, authentication request information receiving unit 401, registration judgment unit 402, service permission judgment unit 404 and judgment result information transmitting unit 405.

[0122] The authentication request information receiving unit 408 receives authentication request information from the device 2, thereby accepting an authentication request from the device 2. Upon receiving the authentication request information from the device 2, the authentication request information receiving unit 408 extracts the client certificate and client signature included in the received authentication request information, and supplies the extracted client certificate and client signature to the client authentication unit 403. The authentication request information receiving unit 408 also extracts the authentication password and device information included in the received authentication request information, and supplies the extracted authentication password and device information to the authentication result information sending unit 409.

[0123] The authentication result information transmitting unit 409 transmits the authentication password and device information supplied from the authentication request information receiving unit 408, and authentication result information including the authentication result of the client authentication unit 403, to the service providing server 5B.

[0124] <Service provider server 5B> The service providing server 5B is an example of a service providing server according to the present disclosure. The hardware configuration of the service providing server 5B is similar to the hardware configuration of the service providing server 5 (see FIG. 5). As shown in FIG. 21, the service providing server 5B includes, as its functional configuration, a service providing unit 501, a device registration unit 504, an authentication result information receiving unit 505, a registration determination unit 506, and a service management unit 507. These functional units are realized by the CPU 51 included in the service providing server 5B executing a service providing program stored in the auxiliary storage device 54.

[0125] The functional configuration of the service providing server 5B differs from the functional configuration of the service providing server 5 (see Figure 7) in that it has a device registration unit 504, an authentication result information receiving unit 505, a registration determination unit 506, and a service management unit 507 instead of the service management unit 500.

[0126] The device registration unit 504 is an example of a device registration means according to the present disclosure. When the device registration unit 504 receives a request to register the device 2 from the terminal 3B, that is, when it receives registration request information from the terminal 3B, it registers the device 2. In detail, the device registration unit 504 extracts device information included in the received registration request information and stores the extracted device information in the account management table 542. The device registration unit 504 also issues an authentication password to the device 2 and transmits the issued authentication password to the terminal 3B. The authentication password is a password with usage restrictions, for example, valid only once within a certain period of time. In this embodiment, the authentication password is a one-time password.

[0127] The account management table 542 is a data table for managing information about registered users, i.e., user accounts, and is stored in the auxiliary storage device 54. The structure of the account management table 542 is similar to that of the account management table 440 provided in the authentication server 4 in the first embodiment (see FIG. 8).

[0128] The authentication result information receiving unit 505 is an example of an authentication result information receiving means according to the present disclosure. The authentication result information receiving unit 505 receives authentication result information from the authentication server 4B. The authentication result information receiving unit 505 notifies the service management unit 507 of the authentication result included in the received authentication result information, i.e., the result of client authentication for the device 2. Furthermore, if the result of client authentication indicates that the device 2 is a valid client, the authentication result information receiving unit 505 extracts an authentication password and device information from the received authentication result information and supplies the extracted authentication password and device information to the registration determination unit 506.

[0129] The registration determination unit 506 is an example of a registration determination means according to the present disclosure. The registration determination unit 506 determines whether or not the device 2 has been registered based on the authentication password and device information supplied from the authentication result information receiving unit 505 and the account management table 542. In detail, the registration determination unit 506 determines whether or not registered device information matching the set of authentication password and device information supplied from the authentication result information receiving unit 505 is stored in the account management table 542. If registered device information matching the set is stored in the account management table 542, the registration determination unit 506 determines that the device 2 has been registered.

[0130] On the other hand, if registered device information matching the set is not stored in the account management table 542, the registration determination unit 506 determines that the device 2 is not registered. The registration determination unit 506 notifies the service management unit 507 of the determination result. After determining whether the device 2 is registered, the registration determination unit 506 invalidates the authentication password of the device 2. Specifically, the registration determination unit 506 deletes the authentication password included in the registered device information corresponding to the device 2 in the account management table 542. Apart from deleting the authentication password by the registration determination unit 506, the service providing server 5B invalidates authentication passwords that have been issued for a certain period of time.

[0131] The service management unit 507 determines whether or not the provision of the service to the device 2 can be permitted based on the result of the client authentication notified by the authentication result information receiving unit 505 and the determination result notified by the registration determination unit 506. In detail, the service management unit 507 determines that the provision of the service to the device 2 can be permitted if the device 2 is a valid client and has been registered. On the other hand, if the device 2 is not a valid client or has not been registered, the service management unit 507 determines that the provision of the service to the device 2 cannot be permitted. The service management unit 507 updates the service management table 540 (see FIG. 9) based on the above determination result.

[0132] <Operation of equipment service providing system 1B> The overall operational flow of the equipment service providing system 1B will be described below with reference to FIG.

[0133] (Step S500) When the device 2 is turned on, it transmits device information including its own device ID and device type.

[0134] (Step S501) When the terminal 3B receives the device information from the device 2, it transmits registration request information including the user ID of the user and the received device information to the service providing server 5B.

[0135] (Step S502) When the service providing server 5B receives the registration request information from the terminal 3B, it registers the device 2 based on the received registration request information.

[0136] (Step S503) The service providing server 5B issues an authentication password to the device 2 and transmits the issued authentication password to the terminal 3B.

[0137] (Step S504) When the terminal 3B receives the authentication password from the service providing server 5B, it transmits the received authentication password to the device 2.

[0138] (Step S505) Upon receiving the authentication password from terminal 3B, device 2 transmits authentication request information including the received authentication password, its own device information, a client certificate, and a client signature signed with the client private key to authentication server 4B.

[0139] (Step S506) The authentication server 4B performs client authentication of the device 2 based on the client certificate and client signature included in the received authentication request information, and the public key of the certificate authority.

[0140] (Step S507) The authentication server 4B transmits the authentication password and device information included in the authentication request information received from the device 2, and authentication result information including the result of client authentication of the device 2, to the service providing server 5B.

[0141] (Step S508) When the service providing server 5B receives the authentication result information from the authentication server 4B, it determines whether or not the device 2 has been registered based on the authentication password and device information included in the received authentication result information.

[0142] (Step S509) The service providing server 5B determines whether or not the provision of the service to the device 2 is permitted based on the result of the client authentication by the authentication server 4B and the result of the determination in step S508.

[0143] (Step S510) The service providing server 5B updates the service management table 540 based on the result of the determination in step S509.

[0144] (Step S511) The device 2 requests the service providing server 5B to provide a service by transmitting service request information including its own device ID to the service providing server 5B.

[0145] (Step S512) When the service providing server 5B receives the service request information from the device 2, it provides a predetermined service to the device 2 only if the provision of the service to the device 2 is permitted.

[0146] As described above, in the device service providing system 1B of this embodiment, the service providing server 5B provides services only to devices 2 for which user registration and device registration have been completed and which have been confirmed to be legitimate clients through client authentication. This makes it possible to prevent services from being provided to unauthorized devices.

[0147] Furthermore, the service providing server 5B issues an authentication password, which is a one-time password, to the device 2 whose device registration has been completed, and the terminal 3B transmits the issued authentication password to the device 2. When the device 2 requests its own authentication from the authentication server 4B, it transmits authentication request information including the authentication password to the authentication server 4B. The authentication server 4B transmits the authentication password together with the result of the client authentication of the device 2 to the service providing server 5B as authentication result information. The service providing server 5B determines whether the device 2 has been registered by taking into account not only the device ID but also the authentication password. This allows the authenticity of the device 2 to be determined with higher accuracy, further preventing the use of services by unauthorized devices.

[0148] Furthermore, since the user account is managed by the service providing server 5B, it is possible to employ a general-purpose authentication server as the authentication server 4B.

[0149] (Variation 1) The service provided to the device 2 may include a mode in which the device 2 downloads a predetermined program from the service providing server 5B and executes the program at any timing. In this case, the service providing server 5B may permit downloading of the program only to devices 2 that are authorized to receive the service, or may permit downloading of the program even to devices 2 that are not authorized to receive the service. In the latter case, the program is designed so that it cannot be executed as is, and the service providing server 5B separately transmits a license key for validating the downloaded program to devices 2 that have been confirmed to be authorized to receive the service.

[0150] (Variation 2) All or part of the functional units of the terminal 3B (see FIG. 20) may be realized by dedicated hardware, all or part of the functional units of the authentication server 4B (see FIG. 21) may be realized by dedicated hardware, and all or part of the functional units of the service providing server 5B (see FIG. 21) may be realized by dedicated hardware. Dedicated hardware is, for example, a single circuit, a composite circuit, a programmed processor, an ASIC, an FPGA, or a combination thereof.

[0151] (Variation 3) The technical ideas according to the second embodiment and its first modification can also be applied to this embodiment.

[0152] The technical ideas according to the above-described modifications may be realized independently or in appropriate combination.

[0153] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope. Furthermore, the above-described embodiments are intended to explain the present disclosure and do not limit the scope of the present disclosure. In other words, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and within the meaning of the disclosure equivalent thereto are considered to be within the scope of the present disclosure. [Industrial Applicability]

[0154] The present disclosure can be suitably adopted in a system that provides services from a server to devices such as home appliances. [Explanation of symbols]

[0155] 1, 1A, 1B Device service providing system, 2, 2A Device, 3, 3A, 3B Terminal, 4, 4A, 4B Authentication server, 5, 5A, 5B Service providing server, 20, 32 First communication interface, 21, 33 Second communication interface, 22 Main unit, 23 Control circuit, 24, 37, 44, 54 Auxiliary storage device, 30 Display, 31 Operation reception unit, 34, 41, 51 CPU, 35, 42, 52 ROM, 36, 43, 53 RAM, 38, 45, 55 Bus, 40, 50 Communication interface, 200 Device information transmission unit, 201 Authentication password reception unit, 202 Authentication request unit, 203 Service request unit, 204 Service execution unit, 240 Device information storage unit, 241 Authentication information storage unit, 300 Device information reception unit, 301, 303 Registration request unit, 302 Authentication password transmission unit, 400, 504 device registration unit, 401, 408 authentication request information reception unit, 402, 506 registration judgment unit, 403 client authentication unit, 404 service permission judgment unit, 405 judgment result information transmission unit, 406 payment acceptance unit, 407 payment information transmission unit, 409 authentication result information transmission unit, 440, 542 account management table, 441 payment management table, 500, 502, 507 service management unit, 501, 503 service provision unit, 505 authentication result information reception unit, 540, 541 service management table

Claims

1. The system comprises a device, a terminal used by a user of the device, an authentication server, and a service providing server, The device transmits device information including device identification information for identifying the device; the terminal receives the device information transmitted from the device, and transmits to the authentication server registration request information including user identification information for identifying the user and the received device information; the authentication server receives the registration request information from the terminal, registers the device based on the received registration request information, issues an authentication password to the device that becomes invalid after a certain period of time has passed, and transmits the issued authentication password to the terminal; the terminal receives the authentication password from the authentication server and transmits the received authentication password to the device; the device receives the authentication password from the terminal, and transmits authentication request information including the received authentication password, the device identification information, a client certificate, and a client signature to the authentication server; the authentication server receives the authentication request information from the device, determines whether the device has been registered based on the authentication password and the device identification information included in the received authentication request information, and performs client authentication of the device based on the client certificate and the client signature included in the received authentication request information; the service providing server provides a predetermined service to the device if the device is registered and is a valid client; The authentication server invalidates the authentication password after determining whether the device has been registered.

2. 2. The device authentication system according to claim 1, wherein, when the service is a service for which a fee is charged, the service providing server provides the service to the device if the device is registered and is a legitimate client, and if the fee for the service has been paid by the user.

3. The service providing server transmitting a predetermined program to the device in response to a request from the device; 3. The device authentication system according to claim 1, wherein if the device has been registered and is a valid client, a license key for validating the program is transmitted to the device.

4. The system includes a device, a terminal, a service providing server, and an authentication server, The device transmits device information including device identification information for identifying the device; the terminal receives the device information transmitted from the device, and transmits to the service providing server registration request information including user identification information for identifying a user of the device and the received device information; the service providing server receives the registration request information from the terminal, registers the device based on the received registration request information, issues an authentication password to the device that becomes invalid after a certain period of time has passed, and transmits the issued authentication password to the terminal; the terminal receives the authentication password from the service providing server and transmits the received authentication password to the device; the device receives the authentication password from the terminal, and transmits authentication request information including the received authentication password, the device identification information, a client certificate, and a client signature to the authentication server; the authentication server receives the authentication request information from the device, performs client authentication of the device based on the client certificate and the client signature included in the received authentication request information, and transmits to the service providing server authentication result information including the authentication password and the device identification information included in the received authentication request information and a result of the client authentication; a device authentication system in which the service providing server receives the authentication result information from the authentication server, determines whether the device is registered based on the authentication password and the device identification information included in the received authentication result information, provides a predetermined service to the device if the device is registered and is a legitimate client, and invalidates the authentication password after determining whether the device is registered.

5. a device registration means for receiving, from a terminal used by a user of a device, registration request information including user identification information for identifying the user and device information including device identification information for identifying the device, registering the device based on the received registration request information, issuing an authentication password to the device that becomes invalid after a certain period of time has passed, and transmitting the issued authentication password to the terminal; an authentication request information receiving means for receiving authentication request information from the device; a registration determination means for determining whether the device has been registered based on the authentication password and device identification information included in the authentication request information; a client authentication unit that performs client authentication of the device based on a client certificate and a client signature included in the authentication request information, The registration determination means invalidates the authentication password after determining whether the device has been registered.

6. a device registration means for receiving, from a terminal, registration request information including user identification information for identifying a user of the device and device information including device identification information for identifying the device, registering the device based on the received registration request information, issuing an authentication password to the device that becomes invalid after a certain period of time has passed, and transmitting the issued authentication password to the terminal; an authentication result information receiving means for receiving authentication result information including the authentication password, the device identification information, and a result of client authentication for the device from an authentication server; a registration determination means for determining whether the device has been registered based on the authentication password and the device identification information included in the received authentication result information; a service providing means for providing a predetermined service to the device when the device is registered and is a valid client; The registration determination means determines whether the device has been registered and then invalidates the authentication password.

7. A device transmits device information including device identification information for identifying the device; a terminal used by a user of the device receives the device information transmitted from the device, and transmits user identification information for identifying the user and registration request information including the received device information to an authentication server; the authentication server receives the registration request information from the terminal, registers the device based on the received registration request information, issues an authentication password to the device that becomes invalid after a certain period of time has passed, and transmits the issued authentication password to the terminal; the terminal receives the authentication password from the authentication server and transmits the received authentication password to the device; the device receives the authentication password from the terminal, and transmits authentication request information including the received authentication password, the device identification information, a client certificate, and a client signature to the authentication server; the authentication server receives the authentication request information from the device, determines whether the device has been registered based on the authentication password and the device identification information included in the received authentication request information, and performs client authentication of the device based on the client certificate and the client signature included in the received authentication request information; a service providing server providing a predetermined service to the device if the device is registered and is a valid client; The device authentication method, wherein the authentication server invalidates the authentication password after determining whether the device has been registered.

8. A device transmits device information including device identification information for identifying the device; a terminal receives the device information transmitted from the device, and transmits user identification information for identifying a user of the device and registration request information including the received device information to a service providing server; the service providing server receives the registration request information from the terminal, registers the device based on the received registration request information, issues an authentication password to the device that becomes invalid after a certain period of time has passed, and transmits the issued authentication password to the terminal; the terminal receives the authentication password from the service providing server and transmits the received authentication password to the device; the device receives the authentication password from the terminal, and transmits authentication request information including the received authentication password, the device identification information, a client certificate, and a client signature to an authentication server; the authentication server receives the authentication request information from the device, performs client authentication of the device based on the client certificate and the client signature included in the received authentication request information, and transmits to the service providing server authentication result information including the authentication password and the device identification information included in the received authentication request information and a result of the client authentication; a device authentication method in which the service providing server receives the authentication result information from the authentication server, determines whether the device is registered based on the authentication password and the device identification information included in the received authentication result information, provides a predetermined service to the device if the device is registered and is a legitimate client, and invalidates the authentication password after determining whether the device is registered.

Citation Information

Patent Citations

  • System for controlling and providing software

    JP2002140127A

  • Apparatus approval system

    JP2019128858A

  • System, method and program for provisioning, and network device

    JP2019148991A