Authentication system, authentication server and program

The authentication system verifies the location of unauthorized terminals using trusted terminals or secure rooms, enhancing network security by allowing login only when the terminal is within a trusted space.

JP7753743B2Active Publication Date: 2025-10-15FUJIFILM BUSINESS INNOVATION CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021150489
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-15
Publication Date
2025-10-15
Estimated Expiration
2041-09-15

AI Technical Summary

Technical Problem

Existing network systems struggle to maintain high security levels when allowing users who are not authorized to log in, as the location of their terminals is not considered, leading to potential security breaches.

Method used

An authentication system that includes an authentication server and terminals, where the server requests and verifies location-specific authentication information from a second terminal to determine if the first terminal is within a trusted space, allowing login only if the first terminal is near a trusted second terminal or in a secure room.

Benefits of technology

Enhances network security by permitting login only when the terminal's location is verified within a trusted area, improving security without requiring manual administrator approval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007753743000001
    Figure 0007753743000001
  • Figure 0007753743000002
    Figure 0007753743000002
  • Figure 0007753743000003
    Figure 0007753743000003
Patent Text Reader

Abstract

To improve a security level of a network system as compared with a case when a location of a terminal used by a user whose log-in to a network system is not permitted is not considered.SOLUTION: An access point 2 and a beacon 3 are provided in a room 1 which a person allowed to log in an internal system can enter. An unauthenticated terminal 4 used by an unauthenticated person who is not allowed to log in the internal system has a position information acquiring unit 42 for returning position information acquired by the beacon 3 in response to a request from an authentication server 10. The authentication server 10 has a transmission requesting unit 121 for requesting transmission of the positional information in response to a log-in request from the unauthenticated terminal 4 and a verification unit 122 for verifying, based on the positional information acquired from the unauthenticated terminal 4, that any unauthenticated person is in the room 1 and, if it is proved that any unauthenticated person is in the room 1, allows the unauthenticated person to log in the internal system by estimating that the unauthenticated person is a trustful person.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication system, an authentication server, and a program. [Background technology]

[0002] In recent years, there has been an increasing trend of large companies collaborating with startups and freelancers. In these cases, it may be more efficient for engineers from the startups to visit the large company and connect their devices to the company's internal system so that they can work together as a team.

[0003] However, on the other hand, corporate security is tending to be strengthened, and many companies operate their network systems in a way that makes it difficult for outsiders to log in.

[0004] Assuming such a corporate network system environment, if an outsider, i.e., a user who is not authorized to log in to the network system, needs to log in, the company can address this issue by, for example, providing the outsider with authentication information such as a one-time password in advance under its management. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-062139 [Patent Document 2] Japanese Patent Application Laid-Open No. 2017-194972 [Patent Document 3] Japanese Patent Application Publication No. 2019-139457 Summary of the Invention [Problem to be solved by the invention]

[0006] Users who are not permitted to log in to a network system such as an in-house system typically work together with users who are permitted to log in to the network system, such as employees of the company who work together within the company's facilities, or work in rooms such as conference rooms where security is strictly maintained without moving around freely within the facility. In other words, the location of a user who is not permitted to log in to the network system, or in other words, the location of the terminal used by that user within the facility, is considered to be in an environment where security is guaranteed to a certain extent. Therefore, if it can be proven that the location of the terminal used by a user who is not permitted to log in to the network system is in a place where security is guaranteed, it is considered acceptable to allow the user to log in.

[0007] The present invention aims to improve the security level of a network system compared to a case where the location of a terminal used by a user who is not permitted to log in to the network system is not taken into consideration. [Means for solving the problem]

[0008] The authentication system according to the present invention comprises a first processor. , Ne an authentication server that authenticates a user who uses a terminal to which a login request to the network system is transmitted; a first terminal that has a second processor and is used by a user who is not permitted to log in to the network system; a second terminal used by a user who is permitted to log in to the network system; and the first processor is before In response to a login request from the first terminal, the first processor requests the first terminal to transmit authentication information that can prove that the first terminal is located within a specific space where a user who is permitted to log in to the network system can be located, the second processor acquires information that identifies the location of the first terminal in response to the request from the authentication server, and transmits the acquired information to the authentication server as the authentication information, and the first processor determines that the authentication information transmitted from the first terminal is Located within a specific space The information generated by the second terminal If it can be verified that , assuming that the first terminal is located within the specific space, The first terminal is permitted to log in to the network system.

[0013] The authentication system according to the present invention includes an authentication server having a first processor and performing authentication of a user who uses a terminal to which a login request to a network system is transmitted, a first terminal having a second processor and used by a user who is not permitted to log in to the network system, and a second terminal used by a user who is permitted to log in to the network system; ,of Yes ,beforeThe first processor requests transmission of authentication information of the second terminal in response to a login request from the first terminal, and if it can be verified from the information transmitted in response to the request that the information was generated by the second terminal in cooperation with the first terminal, the first terminal Near the second terminal The first terminal is permitted to log in to the network system, assuming that the first terminal is located within the space.

[0014] The first processor may request the first terminal to transmit the authentication information in response to a login request from the first terminal.

[0015] The first processor may request the second terminal to transmit the authentication information in response to a login request from the first terminal.

[0016] The first processor also includes authentication data in a request to send the certification information, and if the authentication data included in the certification information sent in response to the request does not match the authentication data included in the request, does not allow the first terminal to log in to the network system.

[0017] The authentication server according to the present invention comprises: An authentication system including a first terminal used by a user who is not permitted to log in to a network system, and a second terminal used by a user who is permitted to log in to the network system, An authentication server for authenticating a user who uses a terminal to which a login request to a network system is sent, the authentication server comprising: a processor; Record The processor is , the first terminal In response to a login request from A request is made for the transmission of certification information of the second terminal, and from the information transmitted in response to the request, the information is determined to have been generated by the second terminal in cooperation with the first terminal. If you can verify , the first terminal is considered to be located in a space near the second terminal, The aforementioned 1st Allowing the terminal to log in to the network system ,child It is characterized by the following.

[0018] The program according to the present invention includes an authentication server that authenticates a user who uses a terminal that has transmitted a login request to a network system. and an authentication system including a first terminal used by a user who is not permitted to log in to the network system, and a second terminal used by a user who is permitted to log in to the network system, wherein the authentication server To the computer that forms The first In response to a login request from the terminal, 1st The terminal is a user who is permitted to log in to the network system. a computer forming the first terminal is made to realize a function of requesting the first terminal to transmit certification information that can prove that the first terminal is located within a specific space where the second terminal can be located, a function of acquiring information that specifies the location of the first terminal in response to a request from the authentication server, and a function of transmitting the acquired information to the authentication server as the certification information, and a function of detecting in the computer forming the authentication server that the certification information transmitted from the first terminal is information generated by the second terminal located within the specific space in response to a request from the first terminal. If it can be verified that , assuming that the first terminal is located within the specific space, The aforementioned 1st A function that allows a terminal to log in to the network system ,of Make it happen. The program of the present invention is an authentication system having an authentication server that authenticates a user using a terminal to which a login request to a network system is sent, a first terminal used by a user who is not authorized to log in to the network system, and a second terminal used by a user who is authorized to log in to the network system, and causes a computer forming the authentication server to realize the following functions: requesting the transmission of authentication information for the second terminal in response to a login request from the first terminal; and, if it can be verified from the information sent in response to the request that the information was generated by the second terminal in cooperation with the first terminal, regarding the first terminal as being located within a space near the second terminal and allowing the first terminal to log in to the network system. [Effects of the Invention]

[0019] Claim 1, 7 According to the invention described above, the security level of the network system can be improved compared to when the location of a terminal used by a user who is not authorized to log in to the network system is not taken into consideration. Furthermore, verification can be performed based on the authentication information obtained by querying the first terminal, and if the first terminal can obtain the authentication information from the second terminal, login of the first terminal can be permitted.

[0024] Claim 2,6,8 According to the invention described in The security level of the network system can be improved compared to when the location of a terminal used by a user who is not permitted to log in to the network system is not taken into consideration. The first terminal can be permitted to log in by using the credibility of the second terminal as security.

[0025] Claim 3 According to the invention described in the above, the location of the first terminal can be verified even when the second terminal is in a specific space but is not logged in to the network system.

[0026] Claim 4 According to the invention described in the above, when the second terminal is logged in to the network system, the authentication information can be transmitted directly to the second terminal.

[0027] Claim 5 According to the invention described in the above, it is possible to avoid reusing authentication information. [Brief explanation of the drawings]

[0028] [Figure 1] 1 is a block diagram showing a first embodiment of an authentication system according to the present invention. [Figure 2] FIG. 4 is a diagram showing an example of an approval policy table according to the first embodiment. [Figure 3] FIG. 4 is a diagram showing an example of a beacon management table according to the first embodiment. [Figure 4] FIG. 3 is a diagram showing an example of a room information table according to the first embodiment. [Figure 5] FIG. 4 is a sequence diagram showing an approval process in the first embodiment. [Figure 6] FIG. 10 is a block diagram showing a second embodiment of an authentication system according to the present invention. [Figure 7] FIG. 11 is a diagram illustrating an example of an access point management table according to the second embodiment. [Figure 8] FIG. 11 is a diagram showing an example of an approved terminal management table in the second embodiment. [Figure 9] FIG. 11 is a diagram showing an example of a connected terminal table in the second embodiment. [Figure 10] FIG. 10 is a sequence diagram showing an approval process in the second embodiment. [Figure 11] FIG. 10 is a block diagram showing a third embodiment of an authentication system according to the present invention. [Figure 12] FIG. 11 is a sequence diagram showing an approval process in the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0029] Hereinafter, preferred embodiments of the present invention will be described with reference to the drawings.

[0030] Embodiment 1 1 is a block diagram showing a first embodiment of an authentication system according to the present invention. The authentication system according to this embodiment is incorporated into a LAN (Local Area Network) system (hereinafter referred to as an "internal system") established within a company, and performs user authentication when a user participates in the internal system. The authentication system according to this embodiment also approves a user who is not normally approved for participation in the internal system, in other words, a user who is not permitted to log in to the internal system, when the user is allowed to participate in the network.

[0031] 1, the in-house system in this embodiment is configured by an access point 2 and a beacon 3 installed in a room 1 within a company, a multifunction peripheral 5 and a repository 6 used by users of the in-house system, and an authentication server 10, all connected to a LAN 7. Note that, although the multifunction peripheral 5 and the repository 6 are shown in FIG. 1 as examples of devices used by users of the in-house system, this is only an example, and the number and types of devices are not limited to those shown in the system configuration example in FIG. 1.

[0032] Room 1 shown in Figure 1 is a specific space where a user who is permitted to log in to the company's internal system can be located. In other words, room 1 forms a highly secure space in the facility, and not just anyone is allowed to enter. As mentioned above, room 1 is a specific space where a user who is permitted to log in to the company's internal system can be located; in other words, only trustworthy people can enter. Therefore, if a user is in room 1, it is assumed that they have been guided to room 1 by a trustworthy person. Therefore, if it can be proven that a user is in room 1, the user can be presumed to be trustworthy, even if they are not permitted to log in to the company's internal system.

[0033] The unauthorized terminal 4 is a terminal device used by a user who is not permitted to log in to the company's internal system. The user of the unauthorized terminal 4 is positioned as a user who is not trusted because his / her personal information is not registered in the company's internal system, and an outsider, for example, corresponds to this user. In this embodiment, a user who uses the unauthorized terminal 4 and is not permitted to log in to the company's internal system will be referred to as an "outsider" or simply as a "user." An employee of another business location, even if they belong to the same company, may also correspond to an outsider. The terminal device used by this user cannot log in to the company's internal system before being approved by the authentication server 10, and is therefore referred to as an "unauthorized terminal" as described above.

[0034] The unauthorized terminal 4 is a portable information processing device, as it is a terminal device that the user brings into the room 1. For example, it is a mobile PC, a tablet terminal, or a smartphone. The unauthorized terminal 4 has a CPU as a second processor, ROM, RAM, storage as storage means, a short-range wireless communication interface and a mobile communication interface such as Wi-Fi (registered trademark) or BLE (Bluetooth (registered trademark) Low Energy) as communication means, and a user interface including a touch panel, a mouse, a keyboard, a display, etc.

[0035] The unauthorized terminal 4 has a login processing unit 41 and a location information acquisition unit 42. Note that components not used in the description of this embodiment are omitted from the figure. The login processing unit 41 transmits a login request to the authentication server 10 via the access point 2. In response to a request from the authentication server 10, the location information acquisition unit 42 acquires installation location information that identifies the location where the beacon is installed from the beacon 3 located closest to the terminal 4, and transmits the acquired location information to the authentication server 10.

[0036] Each of the components 41 and 42 in the unauthorized terminal 4 is realized by the cooperative operation of the computer that forms the unauthorized terminal 4 and a program that runs on a CPU installed in the computer.

[0037] Access point 2 is a repeater that performs wireless communication with communication devices located in room 1 and relays data communication between the communication devices and the in-house system. By communicating with access point 2 installed in room 1, the communication devices are able to prove that they are located in that room 1. Beacon 3 is a transmitter that uses low-power short-range wireless communication technology (e.g., BLE) to wirelessly transmit installation location information that identifies the installation location of the device itself.

[0038] Although only one room 1 is shown in FIG. 2, access points 2 and beacons 3 are installed in other highly secure rooms as well, similar to the room 1 shown in FIG.

[0039] The authentication server 10 constitutes the main part of the authentication system in this embodiment, and authenticates the user who uses the terminal to which the login request is sent. Furthermore, in the case of a login request from an unauthorized terminal 4, the authentication server 10 executes an approval process for login to the in-house system. The unauthorized terminal 4 is permitted to log in to the in-house system by receiving approval from the authentication server 10. The authentication server 10 can be realized with the hardware configuration of a conventional general-purpose server computer. That is, the authentication server 10 has a CPU as a first processor, a ROM, a RAM, a hard disk drive (HDD) as storage means, and a network interface provided as communication means. Furthermore, a user interface including input means such as a mouse and a keyboard and display means such as a display may be provided as necessary.

[0040] The authentication server 10 includes a policy check unit 11, an approval processing unit 12, and a storage unit 13. Components that are not used in the description of this embodiment are omitted from the drawing.

[0041] The policy check unit 11 performs a policy check when it receives a login request sent from an unauthorized terminal 4 via the access point 2. The approval processing unit 12 executes approval processing in response to the login request sent from the unauthorized terminal 4, thereby determining whether or not the unauthorized terminal 4 is permitted to access the in-house system, i.e., whether or not it is permitted to participate in the network of the in-house system.

[0042] The approval process performed by the approval processing unit 12 determines whether or not a user is permitted to participate in the in-house system network. This process is different from user authentication for a login request to one of the computers included in the in-house system, which typically specifies a user ID and password. The aforementioned "permission to log in to the in-house system" refers to whether or not a user can connect to the in-house system, in other words, whether or not the user can participate in the company's network system. In other words, "logging in to the in-house system" in this embodiment refers to connecting to the in-house system at or via the access point 2, in other words, being able to participate in the company's network system. This is different from logging in to one of the computers in the in-house system by specifying a user ID and password. However, in this embodiment, approval processing is performed in response to a login request from a user of the unapproved terminal 4, and approval allows the user to log in to one of the computers in the in-house system. Also, a user ID and password may be specified in a login request from a user of the unapproved terminal 4. For this reason, the approval process performed by the approval processing unit 12 may not be completely distinguishable from computer login processing. Incidentally, the computer the user logs in to may be included in the in-house system, but it is not necessarily the authentication server 10.

[0043] The approval processing unit 12 has a transmission request unit 121, a verification unit 122, and a result notification unit 123. The transmission request unit 121 requests the unapproved terminal 4 to transmit location information in response to a login request transmitted from the unapproved terminal 4. The verification unit 122 verifies the location information transmitted from the unapproved terminal 4 in response to the location information transmission request by the transmission request unit 121, and permits the unapproved terminal 4 to log in to the in-house system if it can be verified that the unapproved terminal 4 is located in room 1, that is, within a specific space where a user who is permitted to log in to the in-house system can be located. The result notification unit 123 notifies the unapproved terminal 4 of the result of the verification by the verification unit 122, that is, the determination result as to whether the unapproved terminal 4 is permitted to access the in-house system. In this embodiment, permitting the login of the user of the unapproved terminal 4 corresponds to notification of login permission.

[0044] The storage unit 13 stores various types of information that can be expressed in a table format as described below, specifically, various tables such as an approval policy table, a beacon management table, and a room information table.

[0045] 2 is a diagram showing an example of an approval policy table in this embodiment. In the approval policy table, an approval method for each access point 2 included in the in-house system is set as a policy. In the approval policy information, an IP address and an approval method are set in association with a source AP. An access point ID is set in the source AP as identification information for the access point 2. The IP address is set to the IP address assigned to the access point 2. The approval method is set to a method for approving an unapproved terminal 4 at the access point 2.

[0046] FIG. 3 is a diagram showing an example of a beacon management table in this embodiment. In the beacon management table, information for managing beacons 3 included in the in-house system is set. The management information for beacons 3 is set for each beacon 3 included in the in-house system, with the beacon, effective distance, adjacent AP, and room number associated with each other. A beacon ID is set in the beacon as identification information for the beacon 3. The effective distance is set to a distance defined as the effective range of wireless communication for the beacon 3. As shown in FIG. 1, at least one access point 2 and one beacon 3 are installed in room 1, and an access point ID is set in the adjacent AP as identification information for the access point 2 that is closest to the beacon 3. The room number is set to a room number as information specifying the room 1 in which the beacon 3 is installed.

[0047] FIG. 4 is a diagram showing an example of a room information table in this embodiment. In the room information table, information about a room 1 in which an access point 2 and a beacon 3 are installed in an in-house system is set. In the room information, a room number, a beacon, an AP, and map information are set in association with each other for each room 1. In the room number, a room number is set as information for identifying the room 1. In the beacon, a beacon ID is set as identification information for the beacon 3 installed in the room 1. In the AP, an access point ID is set as identification information for the access point 2 installed in the room 1. In the map information, spatial information indicating the characteristics of the room 1 is set. Details of the map information will be described later.

[0048] The components 11 and 12 of the authentication server 10 are realized by the cooperative operation of a computer that constitutes the authentication server 10 and a program running on a CPU installed in the computer. The storage unit 13 is realized by a HDD installed in the authentication server 10. Alternatively, RAM or a storage means included in the in-house system may be used via the LAN 7.

[0049] Furthermore, the programs used in the present embodiment can be provided not only by communication means, but also by being stored in a computer-readable recording medium such as a CD-ROM or USB memory. The programs provided from the communication means or recording medium are installed in a computer, and various processes are realized by the computer's CPU sequentially executing the programs.

[0050] Next, the operation of this embodiment will be described. In this embodiment, the process executed when a user who has entered room 1 carrying unapproved terminal 4 wishes to log in to an in-house system will be described using the sequence diagram shown in Fig. 5. Note that since the user always carries unapproved terminal 4 with them, the user's location and the location of unapproved terminal 4 will always match.

[0051] First, in response to a user operation, the login processing unit 41 in the unapproved terminal 4 transmits a login request including the MAC (Media Access Control) address of the terminal to the authentication server 10 (step 401).

[0052] The access point 2 relays a login request from the unauthorized terminal 4 to the authentication server 10 (step 201), and at this time adds an access point ID to the login request as identification information of the own device. In Fig. 5, the access point ID added to the login request is "AP2".

[0053] Note that access point 2 receives the login request sent from unauthorized terminal 4 at a specified port that can accept access requests and relays it to authentication server 10, but does not grant access to the in-house system. When unauthorized terminal 4 is approved in response to the login request, the connection destination of unauthorized terminal 4 is changed to a port that allows network communication with a computer in the in-house system. In subsequent processing, access point 2 also relays data exchanged between authentication server 10 and terminals such as unauthorized terminal 4 in room 1, but because it simply relays the data without performing any processing other than adding its own device's identification information, the subsequent processing at access point 2 is omitted in the sequence diagram.

[0054] When a login request is sent from an unauthorized terminal 4 via access point 2, policy check unit 11 in authentication server 10 checks the access point ID attached to the login request against the source AP in the authorization policy table to perform a policy check on the legitimacy of access point 2 that relayed the login request (step 101). According to the example table settings shown in Fig. 2, when policy check unit 11 identifies that the source of the login request is access point "AP2," it identifies the authorization method as "location information."

[0055] When the approval method is specified in this way, the transmission request unit 121 in the approval processing unit 12 requests the unauthorized terminal 4, which is the sender of the login request, to transmit certification information in accordance with the specified approval method (step 102). In this embodiment, the unauthorized terminal 4 requests transmission of location information that identifies the location where the beacon 3 is installed, as certification information that can prove that the unauthorized terminal 4 is located in the room 1 shown in Fig. 1, i.e., in a specific space.

[0056] In response to a request from the authentication server 10, the location information acquisition unit 42 in the unauthorized terminal 4 acquires installation location information from the beacon 3 located closest to the terminal by wireless reception (step 402). The installation location information includes a beacon ID.

[0057] When the location information acquisition unit 42 wirelessly receives installation location information from the beacon 3, it acquires the reception strength. Then, the location information acquisition unit 42 generates location information including the installation location information and the reception strength, and transmits it to the authentication server 10 as certification information (step 403). Note that if the location information acquisition unit 42 receives installation location information from multiple beacons 3, it determines that the beacon 3 with the greatest reception strength among the respective reception strengths is the beacon 3 located closest to the unapproved terminal 4.

[0058] When the unauthorized terminal 4 transmits location information as certification information in response to the certification information transmission request, the verification unit 122 verifies the acquired location information (step 103). Specifically, the verification unit 122 acquires the effective distance of the beacon 3 from the beacon ID included in the location information by referring to the beacon management table. Note that the access point ID is added to the certification information, so that the verification unit 122 can uniquely identify the effective distance to be acquired. The verification unit 122 converts the reception strength included in the location information into a distance and checks whether the converted distance, i.e., the straight-line distance between the unauthorized terminal 4 and the beacon 3 in room 1, is within the effective distance acquired from the beacon management table. If the straight-line distance is equal to or shorter than the effective distance, the verification unit 122 determines that the unauthorized terminal 4 is located inside room 1. In other words, the beacon ID included in the location information corresponds to information that identifies the location of the unauthorized terminal 4, but if the straight-line distance is equal to or shorter than the effective distance, it is also information specific to the room 1 in which the unauthorized terminal 4 is located.

[0059] As described above, room 1 in this embodiment is a specific space where a user who is permitted to log in to the company's internal system can be located. In other words, by proving that the unauthorized terminal 4 carried by the user is in room 1, the user is presumed to be a trustworthy person. In this way, the user is approved by borrowing the trust of room 1. Note that in this embodiment, if the straight-line distance between the unauthorized terminal 4 and the beacon 3 exceeds the effective distance of the beacon 3, the user may not be in room 1, and is therefore presumed to be an untrustworthy person. In other words, the verification unit 122 does not permit the user to log in to the company's internal system.

[0060] If it is proven that the user of the unapproved terminal 4 is in the room 1 and thus the user is presumed to be a trustworthy person, the result notification unit 123 notifies the unapproved terminal 4 that login is permitted (step 104).

[0061] When login is permitted as described above, the login processing unit 41 in the unauthorized terminal 4 logs in to the in-house system (step 404). Although no particular mention is made of the method for logging in to the in-house system, for example, the user may log in by the same operations as a trusted person. Alternatively, a login screen for logging in to the in-house system may be transmitted as the permission notification in step 104. Alternatively, in step 401, the user may perform a predetermined operation on the unauthorized terminal 4 to display the login screen, and enter a user ID and password to transmit a login request.

[0062] Incidentally, the unauthorized terminal 4 has proven that the user is in room 1 by acquiring the beacon ID of the beacon 3 installed in room 1 as installation location information. However, regardless of whether the beacon 3 is installed or not, the user may be proven to be in room 1 by someone else.

[0063] For example, if the unauthorized terminal 4 is equipped with a LiDAR (Light Detection and Ranging) scanner function, this LiDAR scanner function may be used. The "LiDAR scanner function" is a function that uses laser light to measure the distance to a distant object. Therefore, a user uses the LiDAR scanner function to measure the distance to their surroundings, that is, the distance to objects such as the walls, shelves, and fixtures inside the room 1. The information that identifies the interior shape of the room 1 through this measurement is information unique to the room 1 and is also spatial information that indicates the characteristics of the space known as the room 1. The map information in the room information table shown in FIG. 4 contains information that identifies the interior shape of the room 1.

[0064] Therefore, when spatial information acquired from the unauthorized terminal 4 using the LiDAR scanner function is transmitted as certification information, the verification unit 122 uses image analysis to compare the spatial information with map information set in the room information table, thereby determining whether the unauthorized terminal 4 is being used in the room 1. Note that by adding an access point ID to the certification information, the verification unit 122 can uniquely identify the map information to be compared with the spatial information.

[0065] Furthermore, even if the unauthorized terminal 4 is equipped with a camera function, it is possible to determine whether the unauthorized terminal 4 is being used in room 1 in the same manner as the LiDAR scanner function. In this case, an image captured by the camera becomes information that identifies the location of the unauthorized terminal 4, becomes information unique to room 1, and also becomes spatial information that indicates the characteristics of room 1. Then, a captured image of the interior of room 1 is set in the map information of the room information table shown in FIG.

[0066] When spatial information acquired using the camera function is sent as certification information, the verification unit 122 uses image analysis to compare the spatial information with map information set in the room information table, thereby determining whether the unauthorized terminal 4 is being used in the room 1.

[0067] When using a LiDAR scanner function or a camera function for acquiring spatial information, the unapproved terminal 4 acquires spatial information in step 402 instead of installation location information.

[0068] According to this embodiment, by confirming that the user of the unauthorized terminal 4 is in room 1, which is a specific space where a user who is permitted to log in to the company system can be located, the user is presumed to be a trustworthy person and is permitted to log in to the company system. This login is permitted or not in response to a login request by the user, utilizing the trust in the specific space, without obtaining permission from an administrator of the company system, etc., so that permission to log in can be obtained very easily without lowering the security level of the company system.

[0069] Embodiment 2 6 is a block diagram showing a second embodiment of an authentication system according to the present invention. Note that the same components as those in the first embodiment are given the same reference numerals, and the description thereof will be omitted where appropriate.

[0070] In this embodiment, an approved terminal 8 is present in the room 1. On the other hand, a beacon 3 is not particularly required.

[0071] While the unapproved terminal 4 is a terminal device used by a user who is not permitted to log in to the company's internal system, the approved terminal 8 is a terminal device used by a user who has already been approved to use the company's internal system and is therefore permitted to log in to the company's internal system. The user of the unapproved terminal 4 is not approved to log in to the company's internal system until he or she is proven to be trustworthy, and so for convenience of explanation, he or she will be referred to as an "unapproved person." On the other hand, the user of the approved terminal 8 must be delegated by the authentication server 10 to prove that the unapproved person is trustworthy, but since this user usually collaborates with the unapproved person, he or she will be referred to as a "collaborator" for convenience of explanation.

[0072] The approved terminal 8 is a portable information processing device, as it is a terminal device that a co-worker brings into the room 1. For example, it is a mobile PC, a tablet terminal, or a smartphone. The approved terminal 8 has a CPU as a third processor, ROM, RAM, storage as storage means, a short-range wireless communication interface and a mobile communication interface such as Wi-Fi (registered trademark) or BLE as communication means, and a user interface including a touch panel, a mouse, a keyboard, a display, etc.

[0073] The approved terminal 8 has a certification processing unit 81. Components not used in the description of this embodiment are omitted from the figure. The certification processing unit 81 certifies that an unapproved party is trustworthy. To this end, the certification processing unit 81 generates electronic signature data in response to a request from the authentication server 10 to send certification information, and transmits the data as certification information to the authentication server 10. The certification processing unit 81 in the approved terminal 8 is realized by cooperative operation between a computer forming the approved terminal 8 and a program running on a CPU installed in the computer.

[0074] The authentication server 10 may have the same configuration as in the first embodiment, except that the content of the certification information handled is different, as will be described in detail later.

[0075] In addition, the memory unit 13 stores various information that can be expressed in table format, specifically, in addition to the same approval policy table as in embodiment 1, the information is stored in various tables such as an access point management table, an approved terminal management table, and a connected terminal table.

[0076] FIG. 7 is a diagram showing an example of an access point management table in this embodiment. In the access point management table, management information for access points 2 included in the in-house system is set. In the management information for access points 2, an IP address, a management terminal, and a delegation recipient are set in association with the AP. An access point ID is set in the AP as identification information for the access point 2. An IP address that is address information unique to the access point 2 is set in the IP address. A terminal ID is set in the management terminal as identification information for the terminal used by the administrator of the access point 2. In this embodiment, a co-worker is delegated to provide proof to certify an unapproved person as trustworthy, and information for identifying the co-worker to whom the delegation is to be made is set in the delegation recipient.

[0077] FIG. 8 is a diagram showing an example of an approved terminal management table in this embodiment. In the approved terminal management table, management information related to approved terminals 8 used by co-workers who are permitted to log in to the in-house system is set. In the management information related to the approved terminal 8, a user, a role, and a public key are set in association with the terminal. A terminal ID is set in the terminal as identification information for the approved terminal 8. A user ID is set in the user as identification information for the user who uses the approved terminal 8. The role of the user in the in-house system is set in the role. FIG. 8 shows an example in which "Authority", which indicates a person who has the authority to approve an unapproved person, and "Normal user", which indicates a person who does not have the authority, are set in the role. A public key required for verifying the electronic signature by the user is set in the public key.

[0078] 9 is a diagram showing an example of a connected terminal table in this embodiment. In the connected terminal table, approved terminals 8 connected to the in-house system are registered. In the connected terminal table, an IP address, a connection source AP, and salt are set for each terminal. A terminal ID is set for each terminal as identification information for the approved terminal 8 connected to the in-house system. The IP address is set to the IP address assigned to the approved terminal 8. The connection source AP is set to an access point ID as identification information for the access point 2 to which the approved terminal 8 is wirelessly connected. "Salt" is a random code string, and the salt included in the connected terminal table is set as authentication data to be included in a request to transmit certification information to the approved terminal 8.

[0079] The unapproved terminal 4 has a login processing unit 41 and a response unit 43. The login processing unit 41 is the same as in the first embodiment. The response unit 43 responds to a confirmation inquiry from the approved terminal 8. The response unit 43 is realized by the cooperative operation of a computer forming the unapproved terminal 4 and a program running on a CPU installed in the computer.

[0080] In the above-mentioned first embodiment, room 1 is a specific space where a user who is permitted to log in to the company's internal system can be located, in other words, a space that only trustworthy people can enter, and an unauthorized person can borrow the trust of room 1 by proving that they are in room 1, thereby being permitted to log in to the company's internal system. In this embodiment, rather than whether or not an unauthorized person is in room 1, the specific space is the vicinity of the approved terminal 8 used by a co-worker, and an unauthorized person can borrow the trust of a nearby co-worker by proving that they are in the vicinity of the co-worker, thereby being permitted to log in to the company's internal system.

[0081] The following describes the processing that is executed when a user who has entered room 1 carrying an unapproved terminal 4 wishes to log in to an in-house system. Fig. 10 is a sequence diagram showing this processing, and corresponds to Fig. 5 used to explain the processing in embodiment 1. In Fig. 10, the same steps as in Fig. 5 are assigned the same step numbers, and explanations will be omitted where appropriate. In addition, since the co-worker always carries an approved terminal 8, the location of the co-worker and the location of the approved terminal 8 will always match.

[0082] As in the first embodiment, the login processing unit 41 in the unauthorized terminal 4 transmits a login request including the MAC address to the authentication server 10 (step 401). The access point 2 relays the login request from the unauthorized terminal 4 to the authentication server 10 (step 201), and at this time adds an access point ID to the login request as identification information of the own device. In this embodiment, the access point ID added to the login request is "AP4" as shown in Fig. 10.

[0083] When the policy check unit 11 in the authentication server 10 performs a policy check based on the login request (step 101), it identifies the authorization method as "delegation" from the access point ID "AP4".

[0084] In the above-mentioned first embodiment, in which the approval method is "location information," the authentication server 10 verifies the location of the user of the unapproved terminal 4 (i.e., the unapproved person), and if the unapproved person is in room 1, the unapproved person is presumed to be trustworthy. In contrast, in the present embodiment, in which the approval method is "delegation," the unapproved person is characterized by delegating the proof that he or she is trustworthy to a co-worker. In other words, in order to be able to log in to the company system, the unapproved person borrows the trust of room 1 in the first embodiment, but in this embodiment, he or she borrows the trust of a co-worker.

[0085] According to the settings in the access point management table, the delegation destination for the access point ID "AP4" is "only the management terminal." Therefore, the delegation destination can be uniquely identified as the approved terminal 8 having the terminal ID "X" set in the management terminal. Referring to the connected terminal table shown in FIG. 9, the approved terminal 8 having the terminal ID "X" (hereinafter referred to as "approved terminal X") is currently connected to the in-house system. In this case, the transmission request unit 121 in the approval processing unit 12 requests the approved terminal 8 to transmit digital signature data as certification information in accordance with the specified approval method (step 105). This request to transmit certification information is added with the MAC address of the unapproved terminal 4 that is the sender of the login request and a salt generated by the transmission request unit 121 in response to the request. In this embodiment, the generated salt is associated with the approved terminal X that is the request destination and registered in the connected terminal table shown in FIG. 9. However, the present invention is not limited to this. For example, the salt may be stored in association with the unapproved terminal 4 or the transmission request in a table not shown.

[0086] Upon receiving a request to transmit certification information from the authentication server 10, the certification processing unit 81 in the approved terminal X checks with the unapproved terminal 4, which can be identified from the MAC address (step 801). The information required for this check is transmitted using BLE. By using BLE, it is possible to prove that the unapproved person is in the vicinity of the co-worker. The contents to be checked include the desire to log in, whether or not to generate an electronic signature, etc.

[0087] The response unit 43 in the unapproved terminal 4 responds to the confirmation from the approved terminal 8 (step 405). This response proves that the unapproved person is in the vicinity of the co-worker and that the confirmation content is correct.

[0088] When a response is received from the unauthorized terminal 4, the certification processing unit 81 in the authorized terminal X applies an electronic signature to the MAC address and salt of the unauthorized terminal 4 received from the authentication server 10 (step 802), and transmits the electronic signature data to the authentication server 10 as certification information (step 803).

[0089] In the above description, the certification processing unit 81 in the approved terminal 8 cooperates with the response unit 43 in the unapproved terminal 4 to automatically generate electronic signature data that serves as certification information. However, the processes of confirming with the unapproved terminal 4, and transmitting the electronic signature and certification information to the authentication server 10 (steps 801 to 803) may be executed according to instructions from the co-worker. For example, the certification processing unit 81 displays confirmation content on a screen in response to a certification information transmission request from the authentication server 10. The displayed content may include the desire to log in, whether the electronic signature is valid, and whether the MAC address transmitted from the authentication server 10 is correct. The co-worker then confirms the displayed content by showing it to the unapproved person (step 801), and the unapproved person may respond by viewing the content displayed on the screen (step 405). Since the screen of the approved terminal 8 is presented to the unapproved person, it can be proven that the unapproved person is in the vicinity of the co-worker.

[0090] When electronic signature data is transmitted as certification information from the approved terminal 8 in response to the certification information transmission request, the verification unit 122 verifies the acquired electronic signature data (step 106). Specifically, the verification unit 122 extracts the public key of the approved terminal X from the approved terminal management table and decrypts the electronic signature data. Then, the verification unit 122 compares the decrypted salt with the salt of the approved terminal X contained in the connected terminal table. The verification unit 122 also compares the decrypted MAC address with the MAC address acquired from the unapproved terminal 4. Note that while the salt and the MAC address are individually compared here, it is also possible to, for example, calculate a hash value by combining the decrypted salt and the MAC address, and compare the calculated hash value with a hash value calculated by combining the transmitted salt and the MAC address. If the comparison based on the salt and the MAC address is successful, the verification unit 122 recognizes the unapproved user as trustworthy and allows the user to log in to the in-house system. On the other hand, if the salt and MAC address do not match as a result of the collation, the verification unit 122 does not permit the unauthorized person to log in to the company system.

[0091] As described above, if the verification unit 122 can verify from the electronic signature data transmitted from the approved terminal 8 that the electronic signature data was generated by the approved terminal 8 in cooperation with the unapproved terminal 4, the verification unit 122 considers the unapproved terminal to be in the vicinity of a collaborator and presumes the unapproved terminal to be a trustworthy person. The fact that the electronic signature data was generated by the approved terminal 8 can be proven by the fact that the electronic signature data can be decrypted with a public key registered in the approved terminal management table. Furthermore, since the electronic signature includes the MAC address of the unapproved terminal 4, it is presumed that the approved terminal 8 and the unapproved terminal 4 are in cooperation. In the above processing example, the authentication server 10 transmits the MAC address of the unapproved terminal 4 to the approved terminal 8 in step 105, but the approved terminal 8 may also acquire the MAC address from the unapproved terminal 4 in step 405, apply an electronic signature to the acquired MAC address, and transmit it to the authentication server 10. As a result, if the MAC address obtained from the approved terminal 8 matches the MAC address obtained from the unapproved terminal 4 in step 401, the verification unit 122 can more reliably prove that the approved terminal 8 and the unapproved terminal 4 are linked together.

[0092] If it is proven that the unapproved person is in the vicinity of the co-worker and is therefore presumed to be trustworthy, the result notification unit 123 notifies the unapproved terminal 4 that login is permitted (step 104). This allows the unapproved person to log in to the company's internal system (step 404).

[0093] In this embodiment, the range within which the approved terminal 8 can communicate wirelessly via BLE is considered to be the vicinity of the co-worker. However, since an unapproved person is considered to be acting together with the co-worker, the unapproved person may be considered to be in the vicinity of the co-worker when they are in the same room 1 as the co-worker, or when they are in a section of room 1, or when they are on the same floor, etc. Conversely, if the unapproved person is within the range within which the approved terminal 8 can communicate wirelessly via BLE, they may be considered to be in the vicinity of the co-worker even if they are outside room 1. Regardless of how the range within the vicinity of the co-worker is defined, in this embodiment, the unapproved person can borrow the trust of the co-worker, not room 1, and log in to the in-house system under the management of the co-worker.

[0094] Furthermore, in this embodiment, it is assumed that the approved terminal 8 and the unapproved terminal 4 exchange data using BLE, so it is clear that the unapproved person is near the co-worker. However, for example, it is also possible to use a beacon 3 as in embodiment 1, and have the authentication server 10 acquire the location information described in embodiment 1 from each of the approved terminal 8 and the unapproved terminal 4, and compare the respective location information to prove that the co-worker and the unapproved person are in the same room 1, i.e., that the unapproved person is near the co-worker.

[0095] Embodiment 3 11 is a block diagram showing a third embodiment of an authentication system according to the present invention. Note that the same components as those in the first and second embodiments are given the same reference numerals, and the description thereof will be omitted where appropriate.

[0096] The system configuration in this embodiment may be the same as that in embodiment 2. However, the unapproved terminal 4 includes an electronic signature request unit 44 instead of the response unit 43. Also, the approved terminal 8 includes a signature unit 82 instead of the certification processing unit 81.

[0097] An electronic signature request unit 44 in the unapproved terminal 4 requests the approved terminal 8 to execute an electronic signature in response to a request to send certification information from the authentication server 10. The electronic signature request unit 44 is realized by the cooperative operation of a computer forming the unapproved terminal 4 and a program running on a CPU installed in the computer.

[0098] Furthermore, the signature unit 82 in the approved terminal 8 issues an electronic signature in response to a request from the unapproved terminal 4. The signature unit 82 is realized by the cooperative operation of the computer forming the approved terminal 8 and a program running on a CPU installed in the computer.

[0099] The operation of this embodiment may be basically the same as that of the second embodiment. However, it differs from the second embodiment in that the authentication server 10 requests the unapproved terminal 4 to transmit certification information. Below, the process executed when a user who has entered the room 1 carrying the unapproved terminal 4 wishes to log in to the company system will be described with reference to the sequence diagram shown in FIG. 12. FIG. 12 corresponds to FIG. 5 in the first embodiment and FIG. 10 in the second embodiment. Therefore, in FIG. 12, the same processes as those in FIGS. 5 and 10 are assigned the same step numbers, and the description will be omitted as appropriate.

[0100] The login processing unit 41 in the unauthorized terminal 4 transmits a login request including a MAC address to the authentication server 10 as in the second embodiment (step 401). The access point 2 relays the login request from the unauthorized terminal 4 to the authentication server 10 (step 201), and adds the access point ID "AP4" to the login request.

[0101] When the policy check unit 11 in the authentication server 10 performs a policy check based on the login request (step 101), it identifies the authorization method as "delegation" from the access point ID "AP4".

[0102] According to the settings in the access point management table, the delegate for access point ID "AP4" can be identified as approved terminal X. However, unlike the case of embodiment 2, it is assumed that approved terminal X is not connected to the in-house system. In other words, information about approved terminal X is not registered in the connected terminal table shown in FIG. 9. In this case, the transmission request unit 121 in the approval processing unit 12 cannot transmit the certification information to the approved terminal 8, and therefore requests the unapproved terminal 4 to transmit electronic signature data generated by the approved terminal 8 as certification information (step 107). The transmission request unit 121 adds a salt generated by itself to the transmission request for the certification information.

[0103] When receiving the request to send the certification information transmitted from the authentication server 10, the digital signature request unit 44 in the unapproved terminal 4 requests an digital signature from the approved terminal X using BLE (step 406). This request is accompanied by the MAC address of the unapproved terminal and the salt received from the authentication server 10. Furthermore, by using BLE, the unapproved person is proven to be in the vicinity of the co-worker.

[0104] Incidentally, although approved terminal X is not connected to the company's internal system, since the co-worker is working together with the unapproved person, it is considered that they are in the same room 1. Therefore, when an electronic signature is requested from unapproved terminal 4, signature unit 82 in approved terminal X applies an electronic signature to the MAC address and salt of unapproved terminal 4 received from unapproved terminal 4 (step 802), and transmits the electronic signature data to unapproved terminal 4 (step 804).

[0105] When the digital signature data is transmitted from the approved terminal 8, the unapproved terminal 4 transmits the digital signature data to the authentication server 10 as certification information (step 407).

[0106] When electronic signature data is sent as certification information from the approved terminal 8 in response to a request to send certification information, the verification unit 122 verifies the acquired electronic signature data (step 106). The processing thereafter may be the same as in embodiment 2, and therefore the explanation will be omitted.

[0107] In this embodiment, the transmission sources of the electronic signature data are the unapproved terminal 4 and the approved terminal 8, which is different from the second embodiment. However, when the verification unit 122 in this embodiment can verify from the electronic signature data that the electronic signature data was generated by the approved terminal 8 in cooperation with the unapproved terminal 4, as in the second embodiment, the verification unit 122 considers the unapproved person to be in the vicinity of the co-worker and presumes the unapproved person to be trustworthy. The fact that the electronic signature data was generated by the approved terminal 8 can be proven by the fact that the electronic signature data can be decrypted with the public key registered in the approved terminal management table. Furthermore, because the electronic signature includes the MAC address of the unapproved terminal 4, the verification unit 122 can verify that the electronic signature data was generated by the approved terminal 8 in cooperation with the unapproved terminal 4.

[0108] As mentioned above, in this embodiment, the approved terminal X is not connected to the in-house system, in other words, it is not logged in to the in-house system and participating in the network, so it requests the unapproved terminal 4 to transmit certification information. In this case, as mentioned above, the approved terminal X is not registered in the connected terminal table shown in FIG.

[0109] Here, it is assumed that in the access point management table shown in FIG. 7, "All Authorities" is set as the delegation destination of the access point "AP4" instead of "Management Terminal Only." Here, according to the approved terminal management table shown in FIG. 8, the Role is "Authority" because, in addition to approved terminal X, there is also approved terminal 8 (hereinafter referred to as "approved terminal B") with a terminal ID of "B." And, according to the setting example of the connected terminal table shown in FIG. 9, approved terminal B is connected to the in-house system. In this case, the transmission request unit 121 in the authentication server 10 may transmit the certification information to approved terminal B. In this case, the same processing as in the second embodiment is executed with approved terminal B as approved terminal 8.

[0110] In each of the above embodiments, the process for connecting the unapproved terminal 4 to the in-house system has been described, but the processes described in each embodiment may be appropriately combined and executed within a range that does not contradict each other.

[0111] In addition, in embodiments 2 and 3, the approved terminal 8 generates electronic signature data, but it does not have to be an electronic signature; any information that can prove that the information was generated by the approved terminal 8, such as authentication information pre-registered in the authentication server 10, can be used.

[0112] Furthermore, in each of the above embodiments, the authentication system has been described as being incorporated into a company's internal system, but this is not a limitation and the system can be applied to a facility where multiple users work together.

[0113] In the above embodiments, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.).

[0114] Furthermore, the operations of the processors in the above embodiments may not only be performed by a single processor, but may also be performed by multiple processors located at physically separate locations working together. Furthermore, the order of the operations of the processors is not limited to the order described in the above embodiments, and may be changed as appropriate. [Explanation of symbols]

[0115] 1 Room, 2 Access point, 3 Beacon, 4 Unapproved terminal, 5 Multifunction printer, 6 Repository, 7 LAN, 8 Approved terminal, 10 Authentication server, 11 Policy check unit, 12 Approval processing unit, 13 Memory unit, 41 Login processing unit, 42 Location information acquisition unit, 43 Response unit, 44 Electronic signature request unit, 81 Certification processing unit, 82 Signature unit, 121 Transmission request unit, 122 Verification unit, 123 Result notification unit.

Claims

1. an authentication server including a first processor, which authenticates a user who uses a terminal to which a login request to the network system is transmitted; a first terminal including a second processor and used by a user who is not authorized to log in to the network system; a second terminal used by a user who is permitted to log in to the network system; and The first processor In response to a login request from the first terminal, the first terminal requests the first terminal to transmit authentication information capable of proving that the first terminal is located within a specific space where a user who is permitted to log in to the network system can be located; The second processor acquiring information specifying the location of the first terminal in response to a request from the authentication server; Transmitting the acquired information to the authentication server as the certification information; The first processor If it can be verified that the certification information transmitted from the first terminal is information generated by the second terminal located within the specific space in response to a request from the first terminal, the first terminal is deemed to be located within the specific space, and the first terminal is permitted to log in to the network system. An authentication system comprising:

2. An authentication server including a first processor, which authenticates a user who uses a terminal to which a login request to a network system is transmitted; a first terminal including a second processor and used by a user who is not authorized to log in to the network system; a second terminal used by a user who is permitted to log in to the network system; and The first processor requesting transmission of authentication information of the second terminal in response to a login request from the first terminal; If it can be verified from the information transmitted in response to the request that the information was generated by the second terminal in cooperation with the first terminal, the first terminal is deemed to be located in a space near the second terminal, and the first terminal is permitted to log in to the network system. An authentication system comprising:

3. 3. The authentication system according to claim 2, wherein the first processor requests the first terminal to transmit the authentication information in response to a login request from the first terminal.

4. 3. The authentication system according to claim 2, wherein the first processor requests the second terminal to transmit the authentication information in response to a login request from the first terminal.

5. The first processor including authentication data in the request for transmission of said credential; If the authentication data included in the certificate information sent in response to the request does not match the authentication data included in the request, the first terminal is not permitted to log in to the network system.

3. The authentication system according to claim 1 or 2.

6. An authentication system having a first terminal used by a user who is not permitted to log in to a network system and a second terminal used by a user who is permitted to log in to said network system, wherein an authentication server authenticates a user who uses a terminal to which a login request to said network system is transmitted, a processor; The processor: requesting transmission of authentication information of the second terminal in response to a login request from the first terminal; If it can be verified from the information transmitted in response to the request that the information was generated by the second terminal in cooperation with the first terminal, the first terminal is deemed to be located in a space near the second terminal, and the first terminal is permitted to log in to the network system.

1. An authentication server comprising:

7. An authentication system having an authentication server that authenticates a user who uses a terminal to which a login request to a network system is transmitted, a first terminal used by a user who is not permitted to log in to the network system, and a second terminal used by a user who is permitted to log in to the network system, A computer forming the authentication server, a function of requesting the first terminal to transmit, in response to a login request from the first terminal, authentication information that can prove that the first terminal is located within a specific space where a user who is permitted to log in to the network system can be located; a computer forming said first terminal, a function of acquiring information specifying the location of the first terminal in response to a request from the authentication server; a function of transmitting the acquired information to the authentication server as the certification information; Realize this, A computer forming the authentication server, a function of, when it can be verified that the certification information transmitted from the first terminal is information generated by the second terminal located within the specific space in response to a request from the first terminal, determining that the first terminal is located within the specific space and permitting the first terminal to log in to the network system; A program to achieve this.

8. An authentication system having an authentication server that authenticates a user who uses a terminal to which a login request to a network system is sent, a first terminal used by a user who is not permitted to log in to the network system, and a second terminal used by a user who is permitted to log in to the network system, A computer forming the authentication server, a function of requesting transmission of authentication information of the second terminal in response to a login request from the first terminal; a function of permitting the first terminal to log in to the network system when it can be verified from the information transmitted in response to the request that the information was generated by the second terminal in cooperation with the first terminal, by regarding the first terminal as being located in a space near the second terminal; A program to achieve this.

Citation Information

Patent Citations

  • Server device, content sharing system, program and application software

    JP2014089571A

  • Log-in server using one-time password, method and computer readable recording medium

    JP2015062139A

  • System, method and computer readable recording medium for linking television and smart phone using image authentication key

    JP2017194972A

  • Log-in support program, log-in support method, information processing terminal, and, log-in support system

    JP2019139457A

  • Location based sharing of a network access credential

    US20130115915A1