Service server, service providing system, authentication method, and program

The service server distinguishes between user devices during unauthorized access, enabling legitimate users to continue using services while blocking unauthorized access, thus addressing the inconvenience and support burden in conventional systems.

JP7777711B1Active Publication Date: 2025-11-28PAYPAY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025088785
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-11-28
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

Conventional network services that allow multiple device logins from a single account lead to inconvenience for genuine users when unauthorized access is detected, requiring cumbersome password resets and increased customer support burden.

Method used

A service server that differentiates between first and second user terminal devices during unauthorized access, allowing the first device to continue using the service while logging out the second, thereby minimizing inconvenience to genuine users.

Benefits of technology

This approach effectively prevents fraudulent use while maintaining convenience for legitimate users by allowing continued access for genuine users and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007777711000001_ABST
    Figure 0007777711000001_ABST
Patent Text Reader

Abstract

To suppress a decrease in convenience for a genuine user when a predetermined event occurs. [Solution] A service server that communicates with a user terminal device of a user on which an application program is running and provides a network service to the user, and is equipped with an authentication processing unit that, when a predetermined event occurs for a target account among multiple user accounts, invalidates the password corresponding to the target account, allows one or more first user terminal devices among the multiple user terminal devices logged in to the target account to continue using the network service, and logs out one or more second user terminal devices different from the first user terminal devices among the multiple user terminal devices logged in to the target account from the network service.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a service server, a service providing system, an authentication method, and a program. [Background technology]

[0002] Conventionally, a mechanism for automatically detecting fraudulent use of network services such as electronic payment services has been adopted (Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 7458538 Summary of the Invention [Problem to be solved by the invention]

[0004] Some network services allow users to log in to the same account from multiple terminal devices. In this type of network service, if a suspected unauthorized user has logged in to a certain account, the password for that account may be invalidated and all terminal devices logged in to that account may be simultaneously logged out. As a result, the genuine user must contact customer support to verify their identity, receive an explanation that their password may have been leaked, and then reset their password before they can continue using the network service. This series of steps is cumbersome for users, which can lead to them abandoning continued use of the network service or increase the response burden on customer support. Thus, with conventional technologies, the occurrence of such a predetermined event can sometimes result in reduced convenience for genuine users.

[0005] The present invention has been made in consideration of these circumstances, and one of its objectives is to provide a service server, a service providing system, an authentication method, and a program that can prevent a decrease in convenience for true users when a specified event occurs. [Means for solving the problem]

[0006] One aspect of the present invention is a service server that communicates with a user terminal device of a user on which an application program is running and provides a network service to the user, and is equipped with an authentication processing unit that, when a predetermined event occurs for a target account among multiple user accounts, invalidates the password corresponding to the target account, allows one or more first user terminal devices among the multiple user terminal devices logged in to the target account to continue using the network service, and logs out one or more second user terminal devices different from the first user terminal devices among the multiple user terminal devices logged in to the target account from the network service. [Effects of the Invention]

[0007] According to one aspect of the present invention, when fraudulent use is detected, it is possible to suppress a decrease in convenience for genuine users. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 illustrates basic aspects of brick-and-mortar electronic payment. [Figure 2] FIG. 1 is a diagram illustrating an example of a configuration for performing electronic payment (terminal payment) using a payment application. [Figure 3] FIG. 10 is a diagram showing an example of the contents of user information 172. [Figure 4] FIG. 10 is a diagram showing an example of the contents of affiliated store / shop information 174. [Figure 5] FIG. 10 is a diagram showing an outline of a processing flow when a user scan is performed. [Figure 6]FIG. 10 is a diagram showing an outline of the processing flow when a store scan is performed. [Figure 7] FIG. 1 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. [Figure 8] FIG. 10 is a diagram showing an example of an interface screen for an administrator provided by a management content providing unit 145. [Figure 9] FIG. 11 is a diagram (part 1) showing changes in the display screen of payment application 20 of the first user terminal device after a predetermined event occurs. [Figure 10] FIG. 10 is a diagram (part 2) showing changes in the display screen of payment application 20 of the first user terminal device after a predetermined event occurs. [Figure 11] FIG. 10 is a diagram (part 3) showing changes in the display screen of payment application 20 of the first user terminal device after a predetermined event occurs. [Figure 12] FIG. 10 is a fourth diagram showing changes in the display screen of payment application 20 of the first user terminal device after a predetermined event occurs. [Figure 13] 10 is a flowchart showing an example of the flow of processing executed by the payment server 100. DETAILED DESCRIPTION OF THE INVENTION

[0009] [overview] Hereinafter, with reference to the drawings, embodiments of a service server, a service providing system, an authentication method, and a program according to the present invention will be described. The service server communicates with an application program running on a user's terminal device and provides the user with a network service. Examples of the network service include electronic payment, shopping, auctions, flea markets, and finance. In the following description, the network service is an electronic payment service, and the service server is referred to as a payment server and the application program as a payment app. An electronic payment service is a service that supports payments for the purchase of goods and services at a store. A store is, for example, a physical store (real store) existing in real space, but may also include a virtual store for e-commerce. A virtual store may also include a store operated by an entity other than the operator of the electronic payment service. In such a case, when making a payment for a purchase at the virtual store, the user is controlled to transition to an interface screen for the electronic payment service. In an electronic payment service, a store is treated as belonging to, for example, an affiliated store (brand), and electronic payments made at a store are primarily made between the user and the affiliated store. Alternatively, electronic payments may be made between the user and the store.

[0010] [Electronic payment methods at brick-and-mortar stores] FIG. 1 illustrates the basic aspects of brick-and-mortar electronic payments. Electronic payments are generally carried out by three parties: a medium M held by a user U, store equipment E, and a payment system S. The medium M may be a portable computer device such as a smartphone or a credit card. The store equipment E resides in a physical brick-and-mortar store (hereinafter simply referred to as the store) in real space and may include a POS device, a wireless communication device, a credit card reader, a printed code image such as a QR Code (registered trademark), or a display device displaying the code image. In brick-and-mortar electronic payments, information that can identify the user and information about the payment amount are first shared unidirectionally or bidirectionally between the medium M and the store equipment E. At this time, either the medium M or the store equipment E optically reads various information from a code image displayed by the other, provides information via near-field communication (NFC), or reads the PAN (primary account number) using a credit card reader. Then, either the medium M or the store equipment E (the party that obtains information from the other) transmits the payment information required for the payment to the payment system S via a network NW. Both the medium M and the store equipment E may send some information to the payment system S. The payment system S manages various information about the user U and performs electronic payments between the store and the user U in various ways. Electronic payments are performed using either or both of a prepaid system and a postpaid system, or by other methods. In addition, electronic payments may also include so-called online shopping, which is performed between the user's terminal device and the payment system. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, etc. The various devices that communicate via the network NW, which will be described below, are assumed to have communication devices such as network cards and wireless communication modules.

[0011] [Configuration (Terminal Payment)] 2 is a diagram showing an example of the configuration for performing electronic payment (terminal payment) using a payment app. This electronic payment is performed mainly by a payment app 20 running on a user terminal device 10, which is one of the media M, one or more store payment terminals 30 and one or more store code images 40, which are one of the store facilities E, and a payment server 100, which constitutes part of a payment system S. The payment server 100 communicates with the user terminal device 10, the store payment terminal 30, and one or more information terminals 50 via a network NW.

[0012] The user terminal device 10 is a portable terminal device such as a smartphone or tablet. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input acceptance function, and a program execution function. In the following description, components for realizing these functions are referred to as a camera, a communication device, a touch panel, a central processing unit (CPU), etc. In the user terminal device 10, a processor such as a CPU executes a payment application 20, which operates in cooperation with a payment server 100 to provide electronic payment services to users. The payment application 20 is installed on the user terminal device 10 from, for example, an application distribution server (not shown) and controls the camera, communication device, touch panel, etc. of the user terminal device 10. In the following description, the terms "send information to the user terminal device 10 (or receive / acquire information from the user terminal device 10)" and "send information to the payment application 20 (or receive / acquire information from the payment application 20)" may be used interchangeably, but these terms are merely different expressions and are not intended to distinguish between them.

[0013] The store payment terminal 30 is installed, for example, in a store. The store payment terminal 30 is a computer device (or a collection of these) that has at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The store payment terminal 30 includes a so-called POS (Point of Sale) device, and the POS device may have a product price acquisition function and an optical reading function.

[0014] The store code image 40 is placed in a store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. The store code image 40 may be displayed on a display placed in the store (or on a display of a terminal device such as a smartphone or tablet terminal).

[0015] The information terminal 50 is used by the operator of the affiliated store who oversees the stores. In electronic payment services, customers who provide goods or services are treated as affiliated stores (brands), and one or more stores exist under the affiliated store. An affiliated store may operate only one store. The information terminal 50 is a smartphone, tablet terminal, personal computer, etc. An affiliated store interface 55 runs on the information terminal 50. The affiliated store interface 55 may be an affiliated store app or a web page displayed by a general-purpose browser. The affiliated store interface 55 accepts coupon settings and the like from the affiliated store operator and transmits them to the payment server 100. By executing the affiliated store interface 55, the information terminal 50 may have the function of displaying a code image corresponding to the store code image 40 or reading a code image displayed by the user terminal device 10 (in the latter case, an optical reading function is required).

[0016] The payment server 100 communicates with the credit card server 200 via a network NW. The payment server 100 includes, for example, a content provider 110, an information management unit 120, a payment processing unit 130, a fraud detection unit 140, a managed content provider 145, an authentication processing unit 150, a notification unit 155, and a storage unit 170. The components other than the storage unit 170 are realized by, for example, one or more hardware processors such as a CPU executing a program (software). Some or all of these components may be implemented using a large scale integration (LSI), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like. The program may be realized by hardware (including circuitry) such as a Gate Array (GPU) or a Graphics Processing Unit (GPU), or may be realized by a combination of software and hardware. The program may be stored in advance in a storage device (a storage device with a non-transitory storage medium) such as a hard disk drive (HDD) or flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device.

[0017] The storage unit 170 is a hard disk drive (HDD), a flash memory, a random access memory (RAM), or the like. The storage unit 170 may be a network-attached storage (NAS) device that the payment server 100 can access via a network. The storage unit 170 stores information such as user information 172, affiliated store / shop information 174, a fraud detection program 176, and a monitored account list 178. Note that a section including the fraud detection unit 140, the managed content providing unit 145, the authentication processing unit 150, and the notification unit 155 may be realized by a processor separate from the main part of the payment server 100, and configured as an "authentication device" applied to the payment server 100. The fraud detection program 176 and the monitored account list 178 may also be stored in a storage device separate from the storage unit 170.

[0018] The content providing unit 110 has, for example, a function of a web server, and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The content providing unit 110 provides the content to the user terminal device 10 in the form of a web page, and provides the user terminal device 10 with parameters required for the payment application 20 to render an image.

[0019] The information management unit 120 edits, adds, deletes, etc., user information 172 and affiliated store / shop information 174, and manages them.

[0020] 3 is a diagram showing an example of the contents of user information 172. User information 172 is information in which, for example, user URL, account ID, phone number, password, registration date, charge balance, electronic money type, terminal payment method, card payment method, various history information, identity verification flag, name, address, date of birth, email address, bank account, deferred payment settings, deferred payment condition information, etc. are associated with each other. Hereinafter, a user instance (electronic payment account) in which this information is associated may be referred to as an account. In the figure, items marked with "-" indicate that they are not set.

[0021] The user URL is used for remittance processing between users. When registering for the electronic payment service, registration of a phone number and password is required. The account ID is issued to the user by the payment server 100. The registration date is the date on which the user registered for the electronic payment service (the date on which the account was created). The charge balance is information indicating the balance of electronic money that the user has set by transferring money to the account in advance. Remittance methods include depositing money into an ATM (Automatic Teller Machine) of a designated service provider (bank) or transferring money from a registered bank account. The type of electronic money is information indicating, for example, whether the electronic money can be withdrawn or can only be used for electronic payments. The terminal payment method is setting information indicating whether the user will make electronic payment using the charge balance (balance payment) or by deferred payment in terminal payment. The card payment method is setting information indicating whether the user will make electronic payment using the charge balance (balance payment) or by deferred payment in card payment. The various historical information includes charge history, which is a record of the user transferring money to the electronic payment service in advance to increase the charge balance, and payment history, which shows the details of the payments made by the user for each payment (date and time, store ID of the store where the purchase was made, affiliated store ID, payment amount, payment method, etc.).

[0022] The identity verification flag is information indicating whether or not the user has completed identity verification using an ID document. Deferred payment can be selected if identity verification has been completed, and the user with account ID "002" in the figure has not completed identity verification and can only select balance payment as the terminal payment method. The bank account is the account number of a bank account that can be used to deposit funds into the electronic payment service. Deferred payment settings is information indicating whether or not the settings have been completed to make deferred payment selectable. Deferred payment condition information is information indicating various conditions such as the deferred payment limit and the amount used for the current month.

[0023] 4 is a diagram showing an example of the contents of affiliated store / store information 174. The affiliated store / store information 174 includes, for example, a first table 174A in which an affiliated store ID and a store ID are associated with a store URL, a second table 174B in which an affiliated store ID is associated with an affiliated store name and sales amount (described above), and a third table 174C in which a store ID is associated with a store ID. In addition to this information, the affiliated store / store information 174 may also include information such as the category of the affiliated store or store, the store's location, and payment patterns.

[0024] The payment processing unit 130 performs various processes for electronic payment. There are two methods for terminal payment: a first method (user scan) and a second method (store scan), which will be explained below.

[0025] FIG. 5 shows an overview of the process flow when a user scan is performed. First, the user terminal device 10, with the payment application 20 running, reads and decodes the store code image 40 using its optical reading function (S1). The store code image 40 contains store URL information. The payment application 20 sends first payment information, including the store URL and the user's account ID, to the payment server 100 (S2). The payment server 100 searches the affiliated store / store information 174 using the affiliated store ID and store ID corresponding to the store URL, acquires information about the affiliated store name and store name (S3), and sends this to the payment application 20 (S4). The user enters the payment amount into the payment application 20 on the screen displaying the affiliated store name and store name (S5). The payment application 20 then generates second payment information including at least the payment amount and sends it to the payment server 100 (S6).

[0026] If the "Terminal Payment Method" in the user information 172 of the user is set to "Balance Payment," the payment processing unit 130 of the payment server 100 performs electronic payment based on the received second payment information (S7-1). At this time, the payment processing unit 130 performs electronic payment by, for example, decreasing the charge balance managed in association with the user ID and increasing the item value of the affiliated store's sales proceeds. The item value of the affiliated store's sales proceeds is not used as electronic money itself, for example, but rather the amount corresponding to the item value of the sales proceeds is transferred to a bank account in a cycle determined by an agreement between the affiliated store and the electronic payment service. On the other hand, if the "Terminal Payment Method" is set to "Deferred Payment," the payment processing unit 130 transmits the first payment information and the second payment information to the credit card server 200 to request electronic payment (S7-2). The credit card server 200 performs electronic payment by adding the payment amount to the user's monthly usage amount based on the received information and deducting the monthly usage amount from the user's bank account after the closing date (S7-3).

[0027] Then, the payment processing unit 130 sends a payment completion notice (information for displaying a payment completion screen) to the payment app 20 via the content providing unit 110 (S8), and the payment app 20 displays the payment completion screen (S9). When the store code image 40 is displayed on a display installed in the store, the store code image 40 may include information on the payment amount in addition to the store URL. In this case, the procedure for the user to input the payment amount is omitted, and the information on the payment amount is included in the first payment information and sent to the payment server 100. Information on the affiliated store name and store name may be included and displayed on the payment completion screen.

[0028] FIG. 6 is a diagram showing an overview of the processing flow when a store scan is performed. First, when the payment app 20 is launched, when a payment operation is performed using the payment app 20, when an automatic update timing (e.g., every minute) occurs, and at other timings, the payment app 20 sends a request to issue a one-time code to the payment server 100 (S11). The payment processing unit 130 of the payment server 100 generates a one-time code (S12) and sends it to the payment app 20 (S13). The payment app 20 displays a code image, such as a QR code or barcode, generated based on the one-time code (S14). The user holds (presents) the display surface of the user terminal device 10 over the store payment terminal 30, and the store payment terminal 30 reads and decodes the code image using its optical reading function to obtain the one-time code, etc. (S15). The store payment terminal 30 then generates payment information including the one-time code, payment amount, affiliated store ID, store ID, etc., and sends it to the payment server 100 (S16). The payment amount information is acquired in advance by reading a barcode or manually entering it.

[0029] The payment processing unit 130 of the payment server 100 identifies the user corresponding to the one-time code based on the received information, and if the "terminal payment method" in the user information 172 of the user is set to "balance payment," it performs electronic payment based on the received second payment information (S17-1). The processing content at this time is the same as the processing of S7-1 in FIG. 5. On the other hand, if the "terminal payment method" is set to "post-payment," the payment server 100 transmits the first payment information and the second payment information to the credit card server 200 to request electronic payment (S17-2). The credit card server 200 adds the payment amount to the user's monthly usage amount based on the received information, and performs electronic payment by deducting the monthly usage amount from the user's bank account after the closing date (S17-3).

[0030] Then, the payment processing unit 130 transmits a payment completion notification to the payment application 20 via the content providing unit 110 (S18), and the payment application 20 displays a payment completion screen (S19).

[0031] Note that electronic payment may be performed using only one of the above patterns. Furthermore, the "account ID" described in FIG. 2 may be other information (e.g., a phone number) that can be used as user identification information. Furthermore, issuing a one-time code may be omitted in store scanning, and the payment application 20 may display a code image generated based on the user's account ID. In this case, the payment server 100 identifies the user corresponding to the account ID instead of identifying the user corresponding to the one-time code.

[0032] It should be noted that the "post-payment" settlement may be performed within the settlement server 100, rather than being managed by the credit card server 200. In this case, the components such as the settlement card 60 and the credit card server 200 may be omitted.

[0033] [Configuration (Card Payment)] 7 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. This electronic payment is performed mainly using a payment card 60, which is one of the media M, a credit card processing terminal 70, which is one of the store facilities E, a payment server 100, which constitutes part of a payment system S, and a credit card server 200. The credit card server 200 communicates with the credit card processing terminal 70 via a network NW.

[0034] The credit processing terminal 70 is installed in the store, similar to the in-store payment terminal 30. The credit processing terminal 70 includes, for example, a credit card reader and a POS device. The credit card terminal reads a personal identification number (PIN) from an inserted or held-up credit card and compares it with the PIN entered by the user. It also transmits a primary account number (PAN) read from the credit card to the credit card server 200 via the POS device. The POS device cooperates with the credit card terminal to transmit information such as the payment amount to the credit card server 200. A payment agent server (acquirer) may be interposed between the credit card processing terminal 70 and the credit card server 200; however, for simplicity, the following description omits the server server. The payment card 60 is, for example, similar to a commonly used credit card, with a communication chip embedded in the card substrate. The communication chip incorporates a storage medium storing the PIN and communicates with an external device via a contactor (or a wireless antenna). Alternatively, the payment card 60 may be a magnetic card. The information (messages) sent and received when using a credit card include an authorization message for authentication and a sales message for conveying the payment amount, but detailed explanations distinguishing between these will be omitted below.

[0035] The credit card server 200 communicates with the payment server 100 via a network NW. The credit card server 200 includes, for example, an information management unit 210, a credit interface 220, a payment allocation unit 230, a credit payment processing unit 240, and a memory unit 270. The components other than the memory unit 270 are implemented by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be implemented by hardware (including circuitry) such as an LSI, ASIC, FPGA, or GPU, or may be implemented by a combination of software and hardware. The program may be stored in advance in a storage device such as an HDD or flash memory (a storage device with a non-transitory storage medium), or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device. The memory unit 270 stores information such as card user information 272.

[0036] The information management unit 210 edits, adds, deletes, etc., and manages the card user information 272. The card user information 272 is information in which, for example, information unique to a user (e.g., PAN), a card payment method, and the user's account ID (used by the payment server 100) are associated with one another. The card payment method is setting information that indicates whether the user will make electronic payment using the charged balance (balance payment) or deferred payment when making a card payment.

[0037] The credit interface 220 determines whether the BIN (Bank Identification Number) in the PAN included in the message received from the credit processing terminal 70 is a code for the company, and if it is a code for the company, passes the message received from the credit processing terminal 70 to the payment allocation unit 230, and if it is not a code for the company, discards the received message.

[0038] The payment allocating unit 230 refers to the card user information 272 of the user corresponding to the message obtained from the credit interface 220, and determines whether the "card payment method" is set to "post-payment." If the "card payment method" is set to "post-payment," the payment allocating unit 230 notifies the credit interface 220 of this and passes the message obtained from the credit interface 220 to the credit payment processing unit 240. On the other hand, if the "card payment method" is set to "balance payment," the payment allocating unit 230 adds the user's account ID to the message obtained from the credit interface 220 and sends it to the payment server 100, requesting electronic payment. When requested to make electronic payment, the payment server 100 performs the same processes as S7-1 in Figure 5 and S17-1 in Figure 6.

[0039] The credit interface 220 checks the PAN and expiration date, and verifies whether the cumulative payment amount exceeds the current month's upper limit, etc. The credit payment processing unit 240 adds the payment amount to the user's monthly usage amount based on the information contained in the message obtained from the payment allocation unit 230, and performs electronic payment by deducting the monthly usage amount from the user's bank account after the closing date.

[0040] [Login Control] The following describes login control when a predetermined event occurs, which is executed by fraud detection unit 140, managed content providing unit 145, authentication processing unit 150, and notification unit 155. A predetermined event is, for example, an event that occurs due to an unauthorized login by an unauthorized user. An unauthorized login occurs when a password (and phone number) is stolen, for example, through phishing or other fraud.

[0041] The fraud detection unit 140 operates based on a fraud detection algorithm implemented by the fraud detection program 176. When the fraud detection unit 140 estimates that a fraudulent login has occurred to a certain account (a target account), it provisionally determines whether each of multiple user terminal devices corresponds to a first user terminal device or a second user terminal device. The first user terminal device is presumed to be the user terminal device 10 of the true user, and the second user terminal device is presumed to be the user terminal device 10 of a user suspected of fraudulent use (who has logged in fraudulently). The fraud detection algorithm presumes that a fraudulent user has fraudulently logged in to the target account based on the continuity of locations where electronic payments were made, sudden changes in the payment amount, location information of the user terminal device 10 sent from the payment application 20, the selection of the find source, the context of the login, and the like, and further makes the provisional determination based on the same information. The fraud detection unit 140 registers the fraudulent login along with the contents of the provisional determination in the monitored account list 178 and notifies the managed content providing unit 145. There are no particular restrictions on the specific form of the fraud detection algorithm, and any algorithm may be adopted as long as the validity of the processing results is ensured.

[0042] The management content providing unit 145 provides an administrator interface to the administrator terminal device 300. FIG. 8 is a diagram showing an example of the administrator interface screen provided by the management content providing unit 145. The management content providing unit 145 causes the administrator terminal device 300 to display a list of multiple user terminal devices 10 that have logged in to a target account suspected of fraudulent login, along with information indicating whether each user terminal device 10 has been estimated by the fraud detection unit 140 to be a first user terminal device or a second user terminal device. The monitored account list 178 is equivalent to the information shown on the screen in FIG. 8. For example, the administrator interface screen displays terminal information, browser, login location, status (logged in / logged out), and the like as reference information, and also displays the fraudulent login flag assigned by the fraud detection program 176 (e.g., 0 for the first user terminal device, 1 for the second user terminal device). On this interface screen, the administrator can mutually modify the first user terminal device and the second user terminal device. The administrator can correct the unauthorized login flag by operating the "Change Flag" button B1. Then, when the administrator operates the "Confirm" button B2 (performs a "predetermined operation"), it is determined whether each of the multiple user terminal devices 10 is a first user terminal device or a second user terminal device according to the unauthorized login flag at that time. At this time, the authentication processing unit 150 detects that a predetermined event has occurred.

[0043] Alternatively, instead of the above process, the fraud detection algorithm's decision may be used as confirmation information as to whether the user terminal device is the first user terminal device or the second user terminal device. In this case, when the fraud detection algorithm makes a decision, it is considered that a predetermined event has occurred. In this case, the administrator interface screen may be omitted, or may be displayed on the administrator terminal device 300 as reference information.

[0044] When a predetermined event occurs, the authentication processing unit 150 (1) invalidates the password corresponding to the target account, (2) allows one or more first user terminal devices to continue using the electronic payment service in a provisional login state, and (3) logs out one or more second user terminal devices from the electronic payment service. The provisional login state is a state in which a valid password does not exist and the use of electronic payment services, including electronic payments, can be continued. This allows a user presumed to be the genuine user to continue using the electronic payment service, while an unauthorized user who has hijacked the target account cannot use the electronic payment service. Note that in the following description, only one user terminal device 10 is selected as the first user terminal device. However, if the genuine user uses multiple user terminal devices 10 to receive electronic payment services, selecting multiple user terminal devices 10 as the first user terminal device would be more convenient for the genuine user. However, this weakens the effectiveness of user protection, so it can be said that there is a trade-off between these two. In this case, the notification unit 155 causes the payment app 20 of the first user terminal device to display a message prompting the user to reset their password.

[0045] 9 to 12 are diagrams showing changes in the display screen of the payment application 20 of the first user terminal device after a predetermined event occurs. The changes in the screen shown below are realized by terminal control by the payment application 20 in response to instructions and information provided by the payment server 100.

[0046] First, in the first user terminal device, a message indicating that an unauthorized login has been detected is displayed on the screen saver in accordance with an instruction from the notification unit 155 (left diagram in FIG. 9). When the user unlocks the first user terminal device and activates the payment application 20, a home screen IM1 of the payment application 20 is displayed (right diagram in FIG. 9). At this time, in accordance with the instruction from the notification unit 155, a display (banner) A1 prompting the user to reset the password is continuously displayed until the password is reset (i.e., while the provisional login state continues).

[0047] When the banner A1 on the home screen IM1 is operated, or the account icon I1 is operated and the security settings area A2 is selected from the account page IM2 (left diagram in Figure 10), a half sheet A3 is displayed (right diagram in Figure 10) prompting the user to change their password. When the "Change password" button B3 on the half sheet A2 is operated, the password change screen IM3 (left diagram in Figure 11) is displayed after the prescribed device authentication. When a new password is entered and the "Change password" button B4 is operated, a change completion screen IM4 is displayed (right diagram in Figure 11) indicating that the password has been reset.

[0048] When the "Check terminal" button B5 on the change completion screen IM4 is operated, a list screen IM5 of user terminal devices associated with the target account is displayed (FIG. 12). At this time, the payment application 20 requests the payment server 100 to transmit information corresponding to the target account from the monitored account list 178, and acquires this information. On this screen IM5, the user can delete some of the user terminal devices, log out all at once, reset the password, and so on. This allows the user to restrict the user terminal devices that can log in.

[0049] On the other hand, if an attempt is made to log in to the account of interest from the second user terminal device after the second user terminal device has been logged out of the electronic payment service, there will be no valid password if a new password has not been set, and if a new password has been set, the user will be prompted to enter the new password, making it impossible to log in unless the new password is stolen. Even if the new password is stolen, the second user terminal device will be registered in the monitored account list 178 on the payment server 100, making it impossible to pass terminal authentication and making it difficult to log in. This makes it possible to prevent fraudulent use of the genuine user's account while minimizing any decline in convenience for the genuine user.

[0050] 13 is a flowchart showing an example of the flow of processing executed by the payment server 100. First, the fraud detection unit 140 detects an unauthorized login (S100). In response to this, the management content providing unit 145 causes the administrator terminal device 300 to display the screen exemplified in FIG. 8 (S102).

[0051] When a confirmation operation is performed on the administrator terminal device 300 (S104, Yes), the authentication processing unit 150 invalidates the password corresponding to the target account (S106), places the first user terminal device in a provisional login state, allows the first user terminal device to continue using the electronic payment service (S108), and logs the second user terminal device out of the electronic payment service (S110).

[0052] Next, the notification unit 155 causes the first user terminal device to display a message prompting the user to change the password (S112). This message continues until the password is changed (S114). When the password is changed, the payment server 100 (for example, the authentication processing unit 150) registers the new password in the user information 172 (S116).

[0053] According to the embodiment described above, when a predetermined event occurs, it is possible to suppress a decrease in convenience for the true user.

[0054] The above describes the form for carrying out the present invention using an embodiment, but the present invention is not limited to such an embodiment, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]

[0055] E. Store Facilities M medium S payment system 10 User terminal device 20. Payment App 30 Store payment terminals 40 Store code image 60 Payment Cards 70 Credit card processing terminal 100 Payment Server 130 Payment processing unit 140 Fraud Detection Unit 145 Management Content Provider 150 Authentication processing unit 155 Notification Department 176 Fraud Detection Program 178 Monitored Account List 200 Credit Card Server

Claims

1. A service server that communicates with a user terminal device of a user on which an application program is running and provides a network service to the user, When a specified event occurs in a target account among multiple user accounts, invalidating the password corresponding to the account of interest; among the plurality of user terminal devices logged in to the target account, one or more first user terminal devices are allowed to continue using the network service; an authentication processing unit that logs out one or more second user terminal devices, different from the first user terminal device, from the network service among the plurality of user terminal devices logged in to the target account; the authentication processing unit detects that the predetermined event has occurred when a fraudulent use detection algorithm detects that a fraudulent user is suspected of having fraudulently logged into the target account on the plurality of user terminal devices and a predetermined operation is performed on an administrator terminal device connected to the service server; Service server.

2. The fraud detection algorithm further provisionally determines which of the plurality of user terminal devices corresponds to the first user terminal device and which of the plurality of user terminal devices corresponds to the second user terminal device, the predetermined operation includes an operation of confirming the first user terminal device and the second user terminal device, The service server according to claim 1.

3. when the predetermined event occurs, the authentication processing unit allows one first user terminal device among the plurality of user terminal devices logged in to the target account to continue using the network service; The service server according to claim 1.

4. and a notification unit that, when the predetermined event occurs and the authentication processing unit allows one or more first user terminal devices to continue using the network service, causes the one or more first user terminal devices to display a message prompting the user to reset a password. The service server according to claim 1.

5. the notification unit continues displaying a prompt to reset the password until the password is reset in the one or more first user terminal devices.

5. The service server according to claim 4.

6. The service server according to claim 1; the application program; A service providing system comprising:

7. a service server that communicates with a user terminal device on which an application program is running and provides a network service to the user; When a specified event occurs in a target account among multiple user accounts, invalidating the password corresponding to the account of interest; among the plurality of user terminal devices logged in to the target account, one or more first user terminal devices are allowed to continue using the network service; among the plurality of user terminal devices logged in to the target account, one or more second user terminal devices different from the first user terminal device are logged out from the network service; When detecting the occurrence of the predetermined event, if a fraudulent use detection algorithm detects that a fraudulent user is suspected of having fraudulently logged in to the target account on the plurality of user terminal devices, and a predetermined operation is performed on an administrator terminal device connected to the service server, the occurrence of the predetermined event is detected. Authentication method.

8. a processor of a service server that communicates with a user terminal device of a user on which an application program is running and provides a network service to the user; When a specified event occurs in a target account among multiple user accounts, A process of invalidating a password corresponding to the target account; A process of allowing one or more first user terminal devices among the plurality of user terminal devices logged in to the target account to continue using the network service; A process of logging out one or more second user terminal devices, which are different from the first user terminal device, from the network service among the plurality of user terminal devices logged in to the target account; A program for executing When detecting the occurrence of the predetermined event, the processor is caused to detect that the predetermined event has occurred when a fraudulent use detection algorithm detects that a fraudulent user is suspected of having fraudulently logged into the target account in one of the plurality of user terminal devices and a predetermined operation is performed in an administrator terminal device connected to the service server. program.

Citation Information

Patent Citations

  • Network service providing system, network service providing method, and program

    JP2015111329A

  • Fraudulence detection program, fraudulence detection method and fraudulence detection device

    JP2018124883A

  • Managing Password Expiry

    US20090199294A1

  • PROGRAM, INFORMATION PROCESSING APPARATUS, AND INFORMATION PROCESSING METHOD

    JP7458538B1