Authentication method, authentication device, and program

By identifying and guiding operations on location-specific devices, the method accurately verifies user presence, addressing the limitations of existing authentication methods by ensuring operations are performed correctly and sequentially, thus enhancing authentication accuracy.

JP7759953B2Active Publication Date: 2025-10-24PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023543714
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-24
Filing Date
2022-06-20
Publication Date
2025-10-24
Estimated Expiration
2042-06-20

AI Technical Summary

Technical Problem

Existing personal authentication methods, such as those described in Patent Document 1, fail to accurately verify a user's presence at a specific location, as they do not utilize devices present at the location for authentication.

Method used

An authentication method that identifies devices at a specific location, guides the user to perform operations on these devices, and compares the performed operations with predefined information to confirm the user's presence.

Benefits of technology

This method enhances the accuracy of verifying user presence by ensuring that operations are performed on operable devices and following a specific sequence, reducing false positives and improving overall authentication accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007759953000001
    Figure 0007759953000001
  • Figure 0007759953000002
    Figure 0007759953000002
  • Figure 0007759953000003
    Figure 0007759953000003
Patent Text Reader

Abstract

In this authentication method, a computer accepts information for requesting authentication that a user is present in a specific location, specifies at least one first apparatus present in the specific location as an apparatus for authentication, issues notification of authentication operation information for guiding execution of an operation for authentication upon the apparatus for authentication, verifies the authentication operation information against information indicating the operation executed upon the apparatus for authentication after notification of the authentication operation information is issued, and outputs information indicating the result of the verification.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to techniques for authenticating a user's presence at a particular location. [Background technology]

[0002] In recent years, it has become known that the accuracy of personal authentication can be improved by using multi-factor authentication that combines multiple authentication methods. For example, Patent Document 1 proposes realizing highly secure personal authentication with a simple configuration using a camera and a microphone.

[0003] However, Patent Document 1 does not take into consideration the use of a device present at the location where the user is present to authenticate that the user is present at the location. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-44778 Summary of the Invention

[0005] The present disclosure has been made to solve the above-mentioned problems, and aims to provide an authentication method, authentication device, and program that can authenticate that a user is present in a specific location.

[0006] An authentication method according to one embodiment of the present disclosure includes a computer receiving information requesting authentication that a user is present at a specific location, identifying at least one first device present at the specific location as an authentication device, notifying authentication operation information that guides the user to perform an authentication operation on the authentication device, comparing the authentication operation information with information indicating an operation performed on the authentication device after the authentication operation information is notified, and outputting information indicating the result of the comparison. [Brief explanation of the drawings]

[0007] [Figure 1] 1 is a diagram illustrating an example of an overall configuration of an authentication system according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a block diagram illustrating an example of the configuration of an authentication server. [Figure 3] FIG. 10 is a sequence diagram illustrating an example of authentication processing according to the first embodiment. [Figure 4] FIG. 10 is a sequence diagram illustrating an example of authentication processing according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] (Background to this disclosure) As described above, in recent years, it has become known that the accuracy of personal authentication can be improved by using multi-factor authentication that combines multiple authentication methods. For example, Patent Document 1 proposes improving the accuracy of personal authentication by combining personal authentication using image data of a person captured by a camera and personal authentication using voice data of the person captured by a microphone.

[0009] However, Patent Document 1 does not take into consideration the use of a device present at the location of the user to authenticate that the user is present at the location. Therefore, although the technology of Patent Document 1 can authenticate the identity of a user who is communicating using a mobile terminal, it cannot accurately grasp the location of the user.

[0010] Therefore, the present inventors have conducted extensive research into technologies for authenticating that a user is present in a specific location, and have arrived at the following aspects of the present disclosure.

[0011] An authentication method according to one embodiment of the present disclosure includes a computer receiving information requesting authentication that a user is present at a specific location, identifying at least one first device present at the specific location as an authentication device, notifying authentication operation information that guides the user to perform an authentication operation on the authentication device, comparing the authentication operation information with information indicating an operation performed on the authentication device after the authentication operation information is notified, and outputting information indicating the result of the comparison.

[0012] According to this configuration, when information requesting authentication that a user is present at a specific location is received, at least one first device present at the specific location is identified as an authentication device. Then, authentication operation information guiding the user to perform an authentication operation on the authentication device is notified. Therefore, when the user is present at the specific location, the user can perform an authentication operation on the authentication device present at the specific location by following the guidance indicated by the notified authentication operation information.

[0013] According to this configuration, information indicating an operation performed on an authentication device after notification of the authentication operation information is compared with the authentication operation information, and the result of the comparison is output. Therefore, if the result of the comparison indicates that the operation performed on the authentication device present at the specific location matches the authentication operation indicated by the authentication operation information for the authentication device, the person who inputs the information requesting authentication can authenticate that the user is present at the specific location.

[0014] In the above authentication method, the step of identifying the authentication device may include identifying a currently operable device among the at least one first device as the authentication device.

[0015] According to this configuration, among at least one first device present in the specific location, a currently operable device is identified as the authentication device. Therefore, it is possible to prevent a device that is currently inoperable from being identified as the authentication device. This makes it possible to prevent a user present in the specific location from being authenticated as not being present in the specific location due to being unable to perform authentication operations on the authentication device.

[0016] In the above authentication method, history information indicating a history of operations performed on the authentication device may further be acquired, and when notifying the authentication operation information, the history information may be referenced to determine, as the authentication operation, an operation that has been performed less frequently than a predetermined frequency from among a group of operations that can be performed on the authentication device.

[0017] According to this configuration, among the operations that can be performed on the authentication device, an operation that has been performed less frequently than a predetermined frequency is determined as the authentication operation, thereby preventing an operation that is performed on the authentication device more frequently than the predetermined frequency from being determined as the authentication operation.

[0018] This reduces the possibility of the user being mistakenly authenticated as being present at the specific location due to frequent authentication operations being performed on the authentication device by others when the user is not present at the specific location.

[0019] In the above authentication method, the at least one first device may be a plurality of first devices, and the step of identifying the authentication device may include identifying the plurality of first devices as the authentication devices, the step of notifying the authentication operation information may include determining the authentication operation for each of the plurality of first devices and notifying, as the authentication operation information, information guiding the execution of the authentication operation for each of the plurality of first devices, and the step of comparing may include comparing the authentication operation information with information indicating an operation executed for each of the plurality of first devices after the notification of the authentication operation information.

[0020] According to this configuration, the person who inputs the information requesting authentication can authenticate that the user is present at the specific location when the result of the comparison indicates that the operations performed on each of the multiple first devices identified as authentication devices after notification of the authentication operation information match the authentication operations on each of the multiple first devices indicated by the authentication operation information. This configuration can thereby improve the accuracy of authentication compared to when a single first device present at the specific location is identified as the authentication device.

[0021] In the above authentication method, the authentication operation information includes operation order information indicating an order in which the authentication operations are to be performed on each of the plurality of first devices, and the matching may further include matching an order in which operations performed on each of the plurality of first devices after notification of the authentication operation information with an order in which the authentication operations are to be performed on each of the plurality of first devices indicated by the operation order information.

[0022] According to this configuration, the person who inputs the information requesting authentication can authenticate that the user is present at the specific location when the result of the comparison indicates that the operations performed on each of the plurality of first devices match the authentication operations performed on each of the plurality of first devices and that the order of the operations performed on each of the plurality of first devices matches the order indicated by the operation order information. This configuration can improve the accuracy of authentication compared to a case where the authentication operation information does not include operation order information.

[0023] In the above authentication method, the authentication operation information may further include condition information indicating a condition regarding a time interval between the authentication operation for a second device included in the plurality of first devices and the authentication operation for a third device included in the plurality of first devices, and the matching may further include matching the time interval between the operation performed on the second device and the operation performed on the third device with the condition indicated by the condition information.

[0024] According to this configuration, the person who inputs the information requesting authentication can authenticate that the user is present at the specific location when the result of the comparison indicates that the operation performed on each of the multiple first devices matches the authentication operation for each of the multiple first devices, that the execution order of the operations performed on each of the multiple first devices matches the order indicated by the operation order information, and that the time interval between the authentication operation for the second device and the authentication operation for the third device satisfies the condition indicated by the condition information. This configuration can thereby improve the accuracy of authentication compared to a case where the authentication operation information does not include the condition information.

[0025] In the above authentication method, the operation order information may indicate that the authentication operation for the second device is to be performed followed by the authentication operation for the third device.

[0026] According to this configuration, the person inputting the information requesting authentication can authenticate that the user is present at the specific location if the result of the comparison indicates that the operation performed on each of the multiple first devices matches the authentication operation on each of the multiple first devices, that the order of execution of the operations performed on each of the multiple first devices matches the order indicated by the operation order information, and that the time interval between two consecutive authentication operations, that is, the authentication operation on a second device and the authentication operation on a third device, satisfies the condition indicated by the condition information.

[0027] In the above authentication method, the operation order information may indicate that the authentication operation for the second device is to be performed first, and the authentication operation for the third device is to be performed last.

[0028] According to this configuration, the person inputting the information requesting authentication can authenticate that the user is present at the specific location if the result of the comparison indicates that the operation performed on each of the multiple first devices matches the authentication operation on each of the multiple first devices, and that the time interval between the authentication operation performed first on the second device and the authentication operation performed last on the third device satisfies the condition indicated by the condition information.

[0029] In the above authentication method, location information indicating a location of the authentication device may further be acquired, and in notifying the authentication operation information, the location information may be referenced to determine the order indicated by the operation order information so that the distance traveled from when the authentication operation is performed on the second device to when the authentication operation is performed on the third device is the shortest.

[0030] According to this configuration, the order in which the authentication operations for each of the plurality of first devices are performed is determined so as to minimize the distance traveled from the first authentication operation to the last authentication operation, thereby minimizing the time required for the user to perform the plurality of authentication operations.

[0031] In the above authentication method, location information indicating a location of the authentication device may further be acquired, and in notifying the authentication operation information, the location information may be referenced to determine the order indicated by the operation order information so that the distance traveled from when the authentication operation is performed on the second device to when the authentication operation is performed on the third device is the longest.

[0032] According to this configuration, the order in which the authentication operations for each of the plurality of first devices are performed is determined so as to maximize the distance traveled from the first authentication operation to the last authentication operation, thereby reducing the possibility that the order in which the authentication operations for each of the plurality of first devices are performed will be the same as the order in which they are normally performed at the specific location.

[0033] This reduces the possibility of the user being mistakenly authenticated as being present at the specific location when the user is not present at the specific location because another person performs authentication operations on each of the multiple first devices in the order indicated by the operation order information.

[0034] An authentication device according to another aspect of the present disclosure includes a receiving unit that receives information requesting authentication that a user is present at a specific location; an identifying unit that identifies at least one first device present at the specific location as an authentication device; a notification unit that notifies authentication operation information that guides the user to perform an authentication operation on the authentication device; a matching unit that matches the authentication operation information with information indicating an operation performed on the authentication device after the authentication operation information is notified; and an output unit that outputs information indicating a result of the matching.

[0035] According to this configuration, the same effects as those of the above authentication method can be obtained.

[0036] A program according to another aspect of the present disclosure is a program that causes a computer to function, and causes the computer to function as: a receiving unit that receives information requesting authentication that a user is present at a specific location; an identifying unit that identifies at least one first device present at the specific location as an authentication device; a notification unit that notifies authentication operation information that guides the user to perform an authentication operation on the authentication device; a comparison unit that compares the authentication operation information with information indicating an operation performed on the authentication device after the authentication operation information is notified; and an output unit that outputs information indicating the result of the comparison.

[0037] According to this configuration, the same effects as those of the above authentication method can be obtained.

[0038] The present disclosure can also be realized as a system operated by such a program. Needless to say, such a computer program can be distributed on a non-transitory computer-readable recording medium such as a CD-ROM or via a communication network such as the Internet.

[0039] Note that the embodiments described below each illustrate a specific example of the present disclosure. The numerical values, shapes, components, steps, and step orders shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not described in an independent claim that represents a superordinate concept are described as optional components. Furthermore, in all embodiments, the respective contents can be combined.

[0040] (First embodiment) A first embodiment of the present disclosure will be described below with reference to the drawings. Fig. 1 is a diagram showing an example of the overall configuration of an authentication system 1 according to the embodiment of the present disclosure. The authentication system 1 includes at least one device 20, a user terminal 30, a device database (hereinafter referred to as device DB) 40, and an authentication server 10 (an example of an authentication device).

[0041] The device 20, the user terminal 30, and the authentication server 10 are communicably connected to each other via a communication network 90. ​​The communication network 90 is, for example, a public communication line such as the Internet. The communication network 90 may also be a local area network.

[0042] The device 20 is present in a facility used by a user. The device 20 may be communicably connected to other devices 20 and a user terminal 30 via a local network within the facility. The facility is, for example, a residence. The residence may be an apartment building or a single-family home. Alternatively, the facility may be an office. If the facility is a residence, the user of the device 20 is a resident. If the facility is an office, the user of the device 20 is a user of the office. Hereinafter, the residents and users of the facility will be referred to as users.

[0043] The devices 20 include electronic devices that are installed at predetermined positions within the facility, such as a washing machine, a rice cooker, a refrigerator, a microwave oven, an air conditioner, and an electronic lock. The devices 20 also include electronic devices that are movable within the facility, such as a cleaning robot.

[0044] The device 20 periodically transmits log information indicating its own operating status to the authentication server 10. The authentication server 10 stores the log information acquired from the device 20 in the device DB 40. The log information includes information indicating the date and time when the log information was transmitted (hereinafter, date and time information), identification information of the device 20, information indicating the operating status of the device 20 (hereinafter, status information), information indicating operations performed on the device 20 (hereinafter, operation information), etc. The operating status of the device 20 includes an idle state in which the device 20 is waiting to be operated, a state in which the device 20 is operating, a state in which an abnormality has occurred in the device 20, etc.

[0045] The user terminal 30 is an information communication terminal such as a laptop computer, smartphone, tablet terminal, etc., used by at least one user who uses the facility. The user terminal 30 is equipped with an LCD display for displaying various information, a speaker for outputting sounds indicated by various audio data, operation devices such as a touch panel and hard keys for performing various operations on the user terminal 30 such as inputting information, and a communication circuit for communicating with external devices such as the authentication server 10 via the communication network 90.

[0046] The user terminal 30 displays information on the liquid crystal display when the communication circuit receives information sent to a destination when notifying the user of the user terminal 30. Furthermore, when the communication circuit receives voice data sent to a destination when notifying the user of the user terminal 30, the user terminal 30 causes the speaker to output the voice indicated by the voice data.

[0047] The device DB 40 is configured with storage devices such as an HDD and an SSD. The device DB 40 stores information (hereinafter referred to as device information) about the devices 20. The device information includes the log information, information for managing the devices 20 (hereinafter referred to as device management information), and information for managing the facility where the devices 20 are located (hereinafter referred to as facility information).

[0048] The device management information includes identification information of the device 20, identification information of the facility where the device 20 is located, information indicating a set of operations that can be performed on the device 20 (hereinafter referred to as possible operation information), etc. The identification information of the facility is, for example, the address of the facility. The destination information includes, for example, the user's email address and the IP address of the user terminal 30 used by the user.

[0049] The facility information includes identification information of the facility, identification information of one or more users who use the facility, and information indicating the destination when notifying each of the one or more users of information (hereinafter referred to as destination information).

[0050] The authentication server 10 is configured by a single server device or a cloud server. When the authentication server 10 receives information (hereinafter, authentication request information) from an external server connected to the communication network 90 requesting authentication that a user is present at a facility (an example of a specific location) used by the user, the authentication server 10 executes authentication processing. Details of the authentication processing will be described later. Hereinafter, a facility used by a user will be referred to as a user-used facility.

[0051] 2 is a block diagram showing an example of the configuration of the authentication server 10. The authentication server 10 includes a communication circuit 120, a processor 100 (an example of a computer), and a memory 110.

[0052] The communication circuit 120 is a communication circuit compatible with a communication method using the communication network 90 such as Ethernet (registered trademark), and connects the authentication server 10 to the communication network 90 .

[0053] The communication circuit 120 receives log information from the device 20 via the communication network 90. ​​The communication circuit 120 outputs various pieces of information received via the communication network 90 to the processor 100. Under the control of the processor 100, the communication circuit 120 transmits various pieces of information via the communication network 90 to external devices connected to the communication network 90.

[0054] The processor 100 is configured with, for example, a CPU. The processor 100 controls the authentication server 10. For example, in order to execute the authentication process, the processor 100 functions as a reception unit 101, an identification unit 102, a notification unit 103, a matching unit 104, and an output unit 105. The reception unit 101 to the output unit 105 may be realized by the processor 100 executing a predetermined program, or may be configured with dedicated hardware circuits. The reception unit 101 to the output unit 105 will be described in detail later.

[0055] The memory 110 is configured by a nonvolatile rewritable semiconductor memory such as a flash memory, a hard disk drive (HDD), a solid state drive (SSD), or the like.

[0056] Next, a description will be given of the authentication process executed by the authentication server 10. In this description, details of the reception unit 101 to the output unit 105 (FIG. 2) will be given. FIG. 3 is a sequence diagram showing an example of the authentication process according to the first embodiment.

[0057] 3, an external server connected to the communication network 90 transmits authentication request information requesting authentication that the user is present at the user facility to the authentication server 10 (step S01). The authentication request information includes identification information of the user and identification information of the user facility.

[0058] In the authentication server 10, when the communication circuit 120 receives the authentication request information from the external server, the reception unit 101 receives the authentication request information (step S11).

[0059] Next, the identification unit 102 acquires device information about the devices 20 present in the facility used by the user from the device DB 40 (step S12).

[0060] Specifically, in step S12, the identification unit 102 acquires identification information of the facility used by the user from the authentication request information. The identification unit 102 acquires device management information and facility information including identification information of the facility that matches the identification information of the facility used by the user from the device DB 40. Furthermore, the identification unit 102 acquires identification information of the device 20 included in the acquired device management information, and acquires log information including the identification information of the device 20 from the device DB 40.

[0061] Next, the identification unit 102 refers to the device information acquired in step S12 and identifies at least one device 20 (an example of a first device) present in the user facility as an authentication device (hereinafter, referred to as an authentication device) (step S13).

[0062] For example, in step S13, the identification unit 102 identifies, as an authentication device, one of at least one device 20 present in the facility used by the user that is currently operable.

[0063] Specifically, the identification unit 102 refers to the log information obtained in step S12 that indicates that the device 20 is currently in an operable state. The log information that indicates that the device 20 is currently in an operable state refers to log information that includes state information that indicates that the device 20 is in an idle state or an operating state. The identification unit 102 identifies the device 20 that corresponds to the referenced log information as the authentication device. The device 20 that corresponds to the log information refers to the device 20 that is identified by the identification information of the device 20 that is included in the log information.

[0064] However, the present invention is not limited to this, and in step S13, the identification unit 102 may randomly identify one or more predetermined number of devices 20 as authentication devices from among at least one device 20 present in the facility used by the user.

[0065] Next, the notification unit 103 generates information (hereinafter, authentication operation information) that guides the user to perform an authentication operation on the authentication device identified in step S13 (step S14).

[0066] Specifically, in step S14, the notification unit 103 refers to the device management information acquired in step S12, including the identification information of the authentication device identified in step S13. The notification unit 103 randomly selects one operation from a group of operations that can be performed on the authentication device, which are indicated by the available operation information included in the referenced device management information. The notification unit 103 determines the selected operation as the authentication operation for the authentication device identified in step S13.

[0067] For example, suppose that a washing machine and a refrigerator are identified as authentication devices in step S13. In this case, in step S14, notification unit 103 determines, as the authentication operation for the washing machine, an operation to open the lid, which is randomly selected from a group of operations that can be performed on the washing machine, indicated by the possible operation information included in the device management information including the identification information of the washing machine. Similarly, notification unit 103 determines, as the authentication operation for the refrigerator, an operation to open the refrigerator door, for example.

[0068] Then, the notification unit 103 generates authentication operation information that guides the user to open the lid of the washing machine and the door of the refrigerator. The authentication operation information is, for example, text information and / or voice data indicating, "Please open the lid of the washing machine and the door of the refrigerator."

[0069] Next, the notification unit 103 notifies the authentication operation information generated in step S14 (step S15).

[0070] Specifically, the notification unit 103 refers to the facility information acquired in step S12 and acquires destination information indicating a destination when notifying information to the user indicated by the authentication request information accepted in step S11. The user indicated by the authentication request information is a user identified by the user identification information included in the authentication request information. The notification unit 103 controls the communication circuit 120 to transmit the authentication operation information generated in step S14 to the destination indicated by the destination information.

[0071] In the user terminal 30 used by the user indicated by the authentication request information accepted in step S11, when the communication circuit receives the authentication request information sent to the destination when notifying the information to the user, the authentication operation information is displayed on the liquid crystal display (step S31).

[0072] As a result, when the user checks the authentication operation information displayed on the liquid crystal display of the user terminal 30 (step S91), he or she performs an authentication operation on the authentication device according to the instructions indicated by the authentication operation information (step S92). As a result, the authentication device periodically transmits log information to the authentication server 10, and the device DB 40 stores log information indicating the operating state of the authentication device after the notification of the authentication operation information in step S15 (step S21).

[0073] In the authentication server 10, after step S15, the collating unit 104 acquires, at a predetermined timing, log information indicating operations performed on the authentication device after notification of the authentication operation information from the device DB 40 (step S16).

[0074] Specifically, the matching unit 104 executes step S16 when a predetermined time has elapsed since the authentication operation information was notified in step S15. The predetermined time is set to a time (e.g., 5 minutes) that is sufficiently longer than the time considered to be required for the authentication operation on the authentication device indicated by the authentication operation information notified in step S15.

[0075] In step S16, the matching unit 104 obtains log information from the device DB 40, which includes identification information of the authentication device identified in step S13 and date and time information indicating the date and time after the authentication operation information was notified in step S15.

[0076] The timing at which the matching unit 104 executes step S16 is not limited to this. For example, after the user executes the authentication operation on the authentication device in step S92, the user may operate the user terminal 30 to transmit information indicating that the authentication operation has been completed (hereinafter, operation completion information) to the authentication server 10. In this case, the matching unit 104 executes step S16 at the timing at which the communication circuit 120 receives the operation completion information.

[0077] Next, the collating unit 104 collates the log information acquired in step S16 with the authentication operation information notified in step S12 (step S17).

[0078] Specifically, in step S17, the matching unit 104 matches the operation performed on the authentication device after the notification of the authentication operation information in step S15, which is indicated by the operation information included in the log information acquired in step S16, with the authentication operation on the authentication device, which is indicated by the authentication operation information notified in step S15.

[0079] Next, the output unit 105 controls the communication circuit 120 to return (output) information indicating the result of the matching in step S17 to the external server that is the sender of the authentication request information accepted in step S11 (step S18).

[0080] For example, suppose that a washing machine and a refrigerator are identified as authentication devices in step S13, and authentication operation information for guiding the user to open the lid of the washing machine and the door of the refrigerator is generated in step S14. Then, suppose that the authentication operation information is notified to the user in step S15.

[0081] In this case, in step S17, the matching unit 104 matches the operations performed on the washing machine and the refrigerator after the notification of the authentication operation information in step S15, which are indicated by the operation information included in the log information acquired in step S16, with the operation of opening the lid of the washing machine and the operation of opening the door of the refrigerator, which are indicated by the authentication operation information.

[0082] If the operation performed on the washing machine after notification of the authentication operation information is an operation to open the lid of the washing machine and the operation performed on the refrigerator after notification of the authentication operation information is an operation to open the door of the refrigerator, the matching unit 104 generates information indicating that the user is present in the facility used by the user (hereinafter, matching result information). Otherwise, the matching unit 104 generates matching result information indicating that the user is not present in the facility used by the user.

[0083] In step S18, the output unit 105 returns the matching result information generated in step S17 to the external server that is the sender of the authentication request information received in step S11.

[0084] According to the configuration of the first embodiment, when the user is present at the user facility, the user can perform an authentication operation on the authentication device present at the user facility by following the guidance indicated by the authentication operation information notified in step S15. In this case, in step S17, information indicating the operation performed on the authentication device after the notification of the authentication operation information is compared with the authentication operation information, and comparison result information indicating the result of the comparison is returned to the external server.

[0085] Therefore, the external server can authenticate that the user is present at the user facility if the matching result information indicates that the operation performed on the authentication device present at the user facility matches the authentication operation on the authentication device indicated by the authentication operation information.

[0086] Therefore, this configuration can be used to authenticate that subscribers of private services such as mobile phone contracts and bank accounts reside at the residence indicated by the address entered at the time of signing the contract. This configuration can also be used to authenticate that users reside at the residence indicated by the address written on their resident registration card when using public institution services related to each household's address from home, such as applying for household benefits, obtaining a copy of their resident registration card, and voting in elections.

[0087] This configuration can also be used to authenticate that the purchaser of a high-value item above a certain price resides at the address entered at the time of purchase in order to guarantee the delivery address. This configuration can also be used when applying for a service that has a one-time use limit per household, such as entering a lottery. In other words, the applicant is required to enter an address when applying for the service, and this configuration is used to authenticate that the applicant resides at the residence at that address. This allows the applicant to be notified that use of the service is limited to one time per household if authentication using the same address is attempted more than once.

[0088] Furthermore, in step S13, when a currently operable device 20 among at least one device 20 present in the user facility is identified as an authentication device, a currently inoperable device 20 is not identified as an authentication device. This makes it possible to avoid a user present in the user facility being authenticated as not being present in the user facility due to being unable to perform authentication operations on the authentication device.

[0089] (Second embodiment) In the first embodiment, an example of authentication processing using authentication operation information generated in the authentication server 10 based on device information stored in the device DB 40 has been described. In the second embodiment, authentication server 10 authenticates that a user is present in a facility using authentication operation information manually generated by operating the user terminal 30. The following describes the second embodiment, focusing on differences from the first embodiment. Figure 4 is a sequence diagram showing an example of authentication processing according to the second embodiment.

[0090] 4, the user performs a predetermined operation to generate authentication operation information on the user terminal 30 (step S901). Specifically, the predetermined operation performed in step S901 includes an operation to identify at least one device 20 present in the facility used by the user as an authentication device, an operation to determine an authentication operation for each of the at least one device 20, and an operation to generate, as authentication operation information, information guiding the user to execute the authentication operation for each of the at least one device 20.

[0091] Next, the user terminal 30 transmits information requesting registration of the authentication operation information generated in step S901 (hereinafter, referred to as registration request information) to the authentication server 10 (step S301). The registration request information includes the user's identification information and the authentication operation information generated in step S901.

[0092] In the authentication server 10, when the communication circuit 120 receives the registration request information, the processor 100 associates the user identification information and authentication operation information included in the registration request information and stores them in the memory 110 (step S101).

[0093] Thereafter, in the authentication server 10, step S11, which is the same as in the first embodiment, is performed, and then steps S12 to S14 (FIG. 3) are omitted, and step S102 is performed.

[0094] In step S102, the notification unit 103 acquires the user identification information included in the authentication request information accepted in step S11, and acquires authentication operation information associated with the user identification information from the memory 110 (step S102). Thereafter, the processing from step S15 onwards is performed, which is the same as in the first embodiment, using the authentication operation information acquired in step S102.

[0095] As described above, according to the configuration of the second embodiment, it is possible to authenticate that a user is present in a facility using authentication operation information generated in advance by the user. Therefore, this configuration can be used, for example, in a service that remotely configures devices used in each household, to authenticate that the user is a root user (super user, administrator) of the device. In other words, instead of having the user enter a root user password, this configuration can be used to have the user perform authentication operations on an authentication device indicated by authentication operation information generated in advance by the root user.

[0096] Similarly, this configuration can be used, for example, to grant a service that uses sensor information from a user facility, such as a surveillance camera, the right to view the sensor information (permission to use the sensor information), or to grant a service that remotely operates the facilities and equipment of the user facility the right to remotely operate the facilities and equipment. This configuration makes it possible to prevent a service provider from accessing the facility's sensor information without permission or remotely operating the facilities and equipment of the facility when the user is not present at the facility.

[0097] Furthermore, in a home security service, when an abnormality is detected in a subscriber's facility, such as an intrusion by a suspicious person or a fire, the subscriber may be contacted by telephone to confirm the situation within the facility, such as whether the abnormality detection is a false positive. This configuration can also be used in this case. That is, when the contact is made, an authentication operation is performed on the authentication device indicated by the authentication operation information generated in advance by the subscriber. As a result, if the subscriber is authenticated as a user of the facility, the situation within the facility can be confirmed with the subscriber.

[0098] The present disclosure can employ the following modifications.

[0099] (1) In step S14 (FIG. 3), the notification unit 103 may refer to the operation information (an example of history information) included in the log information acquired in step S12 (FIG. 3) and determine, as an authentication operation, an operation that has been performed less frequently than a predetermined frequency from among a group of operations that can be performed on the authentication device.

[0100] An operation that has been performed less frequently than a predetermined frequency includes an operation that has never been performed. Furthermore, the frequency with which a first operation has been performed is, for example, the number of times the first operation has been performed relative to the total number of times operations have been performed on the authentication device (= the number of times the first operation has been performed / the total number of times). If there are multiple operations that have been performed less frequently than a predetermined frequency, the notification unit 103 may randomly select one operation from the multiple operations and determine the selected operation as the authentication operation.

[0101] According to this configuration, among a set of operations that can be performed on the authentication device, an operation that is performed less frequently than a predetermined frequency is determined as an authentication operation. Therefore, it is possible to prevent an operation that is performed on the authentication device more frequently than a predetermined frequency from being determined as an authentication operation. This reduces the possibility of erroneously authenticating the user as being present at the user facility due to frequent authentication operations being performed on the authentication device by another person when the user is not present at the user facility.

[0102] (2) When a plurality of devices 20 (one example of a plurality of first devices) are identified as authentication devices in step S13 (FIG. 3), in step S14 (FIG. 3), the notification unit 103 may not only determine an authentication operation for each of the plurality of devices 20, but also determine the order in which the authentication operations are to be performed for each of the plurality of devices 20. Then, the notification unit 103 may include information indicating the determined order (hereinafter, operation order information) in the authentication operation information.

[0103] In addition, in step S17 (FIG. 3), the matching unit 104 may further match the order of operations performed on each of the plurality of devices 20 identified as authentication devices with the order of operations for performing authentication on each of the plurality of devices 20 indicated by the operation order information.

[0104] For example, suppose that a washing machine and a refrigerator are identified as authentication devices in step S13 (FIG. 3). Also, suppose that in step S14 (FIG. 3), notification unit 103 determines the operation of opening the lid of the washing machine as the authentication operation for the washing machine, and the operation of opening the door of the refrigerator as the authentication operation for the refrigerator.

[0105] In this case, notification unit 103 further randomly determines the order in which to perform the authentication operations for the washing machine and the refrigerator. For example, notification unit 103 determines that the operation to open the washing machine lid will be performed first, and the operation to open the refrigerator door will be performed second. Then, notification unit 103 generates authentication operation information including operation order information indicating that the operation to open the washing machine lid will be performed first, and the operation to open the refrigerator door will be performed second.

[0106] The authentication operation information is, for example, text information and / or voice data expressing, "First, open the lid of the washing machine, and second, open the refrigerator door." In this case, the operation order information is text information and / or voice data expressing "first" and "second."

[0107] In step S17 (FIG. 3), collation unit 104 collates the operations performed on the washing machine and the refrigerator after the notification of the authentication operation information in step S15 (FIG. 3), which are indicated by the operation information included in the log information acquired in step S16 (FIG. 3), with the operation of opening the washing machine lid and the operation of opening the refrigerator door, which are indicated by the authentication operation information notified in step S15.

[0108] Furthermore, the collation unit 104 refers to the date and time information and operation information included in the log information acquired in step S16 (FIG. 3), and collates the execution order of the operations performed on the washing machine and the refrigerator after the notification of the authentication operation information in step S15 (FIG. 3) with the execution order of the operation to open the washing machine lid and the operation to open the refrigerator door, which is indicated by the operation order information included in the authentication operation information notified in step S15.

[0109] That is, the matching unit 104 refers to the date and time information and operation information included in the log information acquired in step S16 (FIG. 3), and if the first operation performed after notification of the authentication operation information is an operation to open the washing machine lid and the second operation performed is an operation to open the refrigerator door, as indicated by the order indicated by the operation order information, generates matching result information indicating that the user is present at the facility used by the user. Otherwise, the matching unit 104 generates matching result information indicating that the user is not present at the facility used by the user.

[0110] According to this configuration, when the matching result information indicates that the operation performed on each of the plurality of devices 20 identified as authentication devices matches the authentication operation performed on each of the plurality of devices 20, and the order of the operations performed on each of the plurality of devices 20 matches the order indicated by the operation order information, it is possible to authenticate that the user is present at the facility used by the user. This configuration can thereby improve the accuracy of authentication compared to when the authentication operation information does not include operation order information.

[0111] (3) In step S14 in the configuration of variant example (2), the notification unit 103 may further include, in the authentication operation information, information indicating a condition regarding the time interval between an authentication operation for one device (an example of a second device) included in the plurality of devices 20 identified as an authentication device in step S13 (FIG. 3) and an authentication operation for another device (an example of a third device) included in the plurality of devices 20 (hereinafter, condition information).

[0112] In addition, in step S17 (FIG. 3), the comparison unit 104 may further compare the time interval between the operation performed on the one device 20 and the operation performed on the other device 20 with the conditions indicated by the condition information.

[0113] For example, suppose that a washing machine, a refrigerator, and a microwave oven are identified as authentication devices in step S13 (FIG. 3). In step S14, notifying unit 103 determines the operation of opening the lid of the washing machine, the operation of opening the door of the refrigerator, and the operation of opening the door of the microwave oven as authentication operations for the washing machine, the refrigerator, and the microwave oven, respectively.

[0114] Furthermore, it is assumed that the notification unit 103 generates authentication operation information including operation order information indicating that the operation to open the lid of the washing machine is to be performed first, the operation to open the refrigerator door is to be performed second, and the operation to open the microwave oven door is to be performed third.

[0115] In this case, the notification unit 103 further includes, in the authentication operation information, condition information indicating a condition that, for example, the washing machine is the one device and the refrigerator is the other device, the time interval between the operation of opening the washing machine lid and the operation of opening the refrigerator door, which is executed next after the operation, is limited to a predetermined time (for example, one minute) or less.

[0116] The authentication operation information is, for example, text information and / or voice data expressing, "First, open the lid of the washing machine, then within one minute, open the refrigerator door second, and then open the microwave door third." In this case, the operation order information is text information and / or voice data expressing "first," "second," and "third." The condition information is text information and / or voice data expressing "within one minute."

[0117] In step S17 (FIG. 3), collation unit 104 collates the operations performed on the washing machine, refrigerator, and microwave oven after the notification of the authentication operation information in step S15 (FIG. 3), which are indicated by the operation information included in the log information acquired in step S16 (FIG. 3), with the operation of opening the lid of the washing machine, the operation of opening the door of the refrigerator, and the operation of opening the door of the microwave oven, which are indicated by the authentication operation information notified in step S15.

[0118] Furthermore, the collation unit 104 refers to the date and time information and operation information included in the log information acquired in step S16 (FIG. 3), and collates the execution order of the operations performed on the washing machine, refrigerator, and microwave oven after the notification of the authentication operation information in step S15 with the execution order of the operation of opening the washing machine lid, the operation of opening the refrigerator door, and the operation of opening the microwave oven door, which is indicated by the operation order information included in the authentication operation information notified in step S15.

[0119] Furthermore, the collation unit 104 refers to the date and time information and operation information included in the log information acquired in step S16 (FIG. 3), and collates the time interval between the operation performed on the washing machine, which is the one device, and the operation performed on the refrigerator, which is the other device, after the notification of the authentication operation information in step S15 (FIG. 3), with the condition indicated by the condition information included in the authentication operation information notified in step S15, which is "limit the time interval between the operation of opening the washing machine lid and the operation of opening the refrigerator door, which is executed next to the operation, to a predetermined time (e.g., one minute) or less."

[0120] That is, suppose that verification unit 104 references the operation information included in the log information acquired in step S16 (FIG. 3) and determines that, in accordance with the order indicated by the operation order information, the first operation performed after notification of the authentication operation information was an operation to open the lid of the washing machine, the second operation was an operation to open the refrigerator door, and the third operation was an operation to open the microwave oven door. In this case, when verification unit 104 further determines, in accordance with the condition indicated by the condition information, that the time interval between the operation performed on the washing machine (the one appliance) and the operation performed on the refrigerator (the other appliance) is equal to or shorter than a predetermined time, verification unit 104 generates verification result information indicating that the user is present at the user facility. In other cases, verification unit 104 generates verification result information indicating that the user is not present at the user facility.

[0121] The notification unit 103 may include, in the authentication operation information, condition information indicating a condition that the time interval between the operation of opening the lid of the washing machine, which is the first device, and the operation of opening the door of the microwave oven, which is the last device, is limited to a predetermined time (for example, 5 minutes) or less, with the washing machine being the one device and the microwave oven being the other device.

[0122] The authentication operation information is, for example, text information and / or voice data expressing, "First, open the lid of the washing machine, second, open the refrigerator door, and third, open the microwave door within five minutes of the first operation." In this case, the operation order information is text information and / or voice data expressing "first," "second," and "third." The condition information is text information and / or voice data expressing "within five minutes of the first operation."

[0123] According to this configuration, when the matching result information indicates that the operation performed on each of the plurality of devices 20 identified as authentication devices matches the authentication operation performed on each of the plurality of devices 20, that the order of the operations performed on each of the plurality of devices 20 matches the order indicated by the operation order information, and that the time interval between the operation performed on one device and the operation performed on the other device satisfies the condition indicated by the condition information, it is possible to authenticate that the user is present at the user facility. This configuration can thereby improve the accuracy of authentication compared to when the authentication operation information does not include the condition information.

[0124] (4) In the configurations of the modified examples (2) and (3), the device management information may further include information indicating the location of the device 20 (hereinafter, location information). The location information is, for example, information indicating the latitude, longitude, and altitude of the location of the device 20. The location information is not limited to this, and may be, for example, information indicating the latitude and longitude of the location of the device 20.

[0125] Then, in step S14 in the configurations of the modified examples (2) and (3), the notification unit 103 may determine the order in which to perform authentication operations for each of the multiple devices 20 identified as authentication devices, as follows.

[0126] Specifically, the notification unit 103 may refer to the location information included in the device management information acquired in step S12 (FIG. 3) and use a known route search algorithm to determine the order so that the user travels the shortest distance from when they perform an authentication operation on the first authentication device to when they perform an authentication operation on the last authentication device. This configuration can minimize the time required for the user to perform multiple authentication operations.

[0127] Alternatively, the notification unit 103 may refer to the location information included in the device management information acquired in step S12 (FIG. 3) and use a known route search algorithm to determine the order so that the user travels the longest distance from when they perform an authentication operation on the first authentication device to when they perform an authentication operation on the last authentication device.

[0128] This configuration reduces the possibility that the order in which authentication operations are performed on each of the multiple devices 20 identified as authentication devices will be the same as the order in which operations are normally performed at the user facility, thereby reducing the possibility that, when the user is not present at the user facility, another person performs authentication operations on each of the multiple devices 20 in the order indicated by the operation order information, resulting in erroneous authentication of the user as being present at the user facility.

[0129] (5) A part of the authentication server 10 may be configured by an authentication information generation server capable of communicating with the authentication server 10 via the communication network 90. ​​Specifically, steps S12 to S14 shown in Fig. 3 may be executed by the authentication information generation server instead of the authentication server 10, and the authentication information generation server may transmit the authentication operation information generated in step S14 to the authentication server 10. Then, in step S15 (Fig. 3), the notification unit 103 may notify the authentication operation information received by the communication circuit 120.

[0130] (6) The device DB 40 (FIG. 1) may be configured as a storage area of ​​the memory 110 (FIG. 2) included in the authentication server 10. [Industrial Applicability]

[0131] As described above, the present disclosure can be used in private services, public services, remote operation of equipment within a facility, home security services, etc. to authenticate that a user is present at a facility indicated by a specific address.

Claims

1. The computer Accepting information requesting authentication that a user is present at a particular location; Identifying at least one first device present in the specific location as a device for authentication; notifying the authentication operation information that guides the execution of an authentication operation on the authentication device; comparing information indicating an operation performed on the authentication device after the notification of the authentication operation information with the authentication operation information; outputting information indicating the result of the matching; Authentication method.

2. In identifying the authentication device, identifying a currently operable device among the at least one first device as the authentication device; The authentication method of claim 1 .

3. Furthermore, history information indicating a history of operations performed on the authentication device is acquired, In the notification of the authentication operation information, referring to the history information, and determining, as the authentication operation, an operation that has been executed less frequently than a predetermined frequency from among a group of operations that can be executed on the authentication device; The authentication method of claim 1 .

4. the at least one first device is a plurality of first devices, In identifying the authentication device, Identifying the plurality of first devices as the authentication devices; In the notification of the authentication operation information, determining an authentication operation for each of the plurality of first devices, and notifying, as the authentication operation information, information that guides the execution of the authentication operation for each of the plurality of first devices; In the collation, comparing information indicating operations performed on each of the plurality of first devices after the notification of the authentication operation information with the authentication operation information; The authentication method according to any one of claims 1 to 3.

5. the authentication operation information includes operation order information indicating an order in which the authentication operation is to be performed on each of the plurality of first devices, In the collation, Furthermore, the execution order of the operations performed on each of the plurality of first devices after the notification of the authentication operation information is compared with the order of the operations for authentication performed on each of the plurality of first devices indicated by the operation order information. The authentication method according to claim 4.

6. the authentication operation information further includes condition information indicating a condition regarding a time interval between the authentication operation for a second device included in the plurality of first devices and the authentication operation for a third device included in the plurality of first devices; In the collation, further comparing a time interval between the operation performed on the second device and the operation performed on the third device with the condition indicated by the condition information; The authentication method according to claim 5.

7. the operation order information indicates that the authentication operation for the third device is to be executed after the authentication operation for the second device; The authentication method according to claim 6.

8. the operation order information indicates that the authentication operation for the second device is to be performed first and the authentication operation for the third device is to be performed last; The authentication method according to claim 6.

9. Furthermore, location information indicating the location of the authentication device is acquired, In the notification of the authentication operation information, determining, with reference to the position information, the order indicated by the operation order information so as to minimize the distance traveled from when the authentication operation for the second device is performed until when the authentication operation for the third device is performed; The authentication method according to claim 8.

10. Furthermore, location information indicating the location of the authentication device is acquired, In the notification of the authentication operation information, With reference to the position information, the order indicated by the operation order information is determined so as to maximize the distance traveled between performing the authentication operation on the second device and performing the authentication operation on the third device. The authentication method according to claim 8.

11. a reception unit that receives information requesting authentication that a user is present at a specific location; an identification unit that identifies at least one first device present in the specific location as a device for authentication; a notification unit that notifies authentication operation information that guides the user to perform an authentication operation on the authentication device; a collating unit that collates information indicating an operation performed on the authentication device after the notification of the authentication operation information with the authentication operation information; an output unit that outputs information indicating the result of the matching; An authentication device comprising:

12. A program that causes a computer to function, The computer a reception unit that receives information requesting authentication that a user is present at a specific location; an identification unit that identifies at least one first device present in the specific location as a device for authentication; a notification unit that notifies authentication operation information that guides the user to perform an authentication operation on the authentication device; a collating unit that collates information indicating an operation performed on the authentication device after the notification of the authentication operation information with the authentication operation information; an output unit that outputs information indicating the result of the matching; A program that functions as a

Citation Information

Patent Citations

  • System and method for providing location proving information, stationary terminal, proving center, method for operating certificate referring device, and recording medium with work program recorded therein

    JP2002125049A

  • Image forming apparatus and system

    JP2005071272A

  • Mobile terminal location authentication system and mobile terminal location authentication method

    JP2013058841A

  • Authentication device

    JP2017044778A