Information processing device, information processing method, and program

JP7783328B2Active Publication Date: 2025-12-09PAYPAY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024067080
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-04-17
Publication Date
2025-12-09
Estimated Expiration
2042-03-07

AI Technical Summary

Benefits of technology

【0007】 本発明の一態様によれば、他人による不正ログインを防止することができる情報処理装置、情報処理方法、およびプログラムを提供することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007783328000001
    Figure 0007783328000001
  • Figure 0007783328000002
    Figure 0007783328000002
  • Figure 0007783328000003
    Figure 0007783328000003
Patent Text Reader

Abstract

To provide an information processing apparatus, an information processing method, and program which can prevent other person from carrying out unauthorized log-in.SOLUTION: The present invention is directed to an information processing apparatus which can communicate with a first terminal device and a second terminal device. The information processing apparatus generates first code information obtained by encoding first authentication information to then generate second code information obtained by encoding second authentication information, transmits the first code information and the second code information generated by a code information generating unit to the first terminal device, receives, from the second terminal device, the first authentication information obtained by capturing and decoding the first code information and the second authentication information obtained by capturing and decoding the second code information, and thereby authenticates the second terminal device based on the first authentication information and the second authentication information. The first code information is captured prior to the second code information, and a time-limited period of the second authentication information is shorter than that of the first authentication information.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] Conventionally, authentication services using SMS (Short Message Service) have been known. For example, Patent Document 1 proposes an authentication system that sends an SMS authentication value to a pre-registered mobile device, displays an authentication window for the user to input the SMS authentication value, and performs identity authentication based on the SMS authentication value input by the user. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Special Publication No. 2019-517087 Summary of the Invention [Problem to be solved by the invention]

[0004] However, with the technology described in Patent Document 1, if the SMS authentication value is stolen from a phishing site or the like, a phishing perpetrator may be able to illegally log in.

[0005] The present invention has been made in consideration of the above circumstances, and one of its objects is to provide an information processing device, an information processing method, and a program that can prevent unauthorized login by other people. [Means for solving the problem]

[0006] One aspect of the present invention is an information processing device capable of communicating with a first terminal device and a second terminal device, comprising: a code information generation unit that generates first code information in which first authentication information is coded in response to a request from the second terminal device, and then generates second code information in which second authentication information different from the first authentication information is coded; a transmission unit that transmits the first code information and the second code information generated by the code information generation unit to one of the first terminal device and the second terminal device; a reception unit that receives from the other of the first terminal device and the second terminal device the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; and an authentication unit that authenticates the second terminal device based on the first authentication information and the second authentication information received by the reception unit, wherein the first code information is photographed before the second code information, and the first authentication information and the second authentication information are time-limited information, and the time-limited period of the second authentication information is shorter than the time-limited period of the first authentication information to better prevent fraudulent acquisition compared to the first authentication information. [Effects of the Invention]

[0007] According to one aspect of the present invention, it is possible to provide an information processing device, an information processing method, and a program that can prevent unauthorized login by a third party. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram illustrating an example of a configuration for realizing an electronic payment service. [Figure 2] FIG. 1 is a diagram illustrating an example of the general flow of electronic payment. [Figure 3] FIG. 2 is a configuration diagram of a payment server 100. [Figure 4] FIG. 10 is a diagram showing an example of the contents of user information 172. [Figure 5] 10 is a flowchart illustrating an example of a login authentication process. [Figure 6] FIG. 10 is a sequence diagram illustrating an example of a first authentication process. [Figure 7] FIG. 10 is a diagram showing an example of a display screen of a first user terminal device 10A on which a QR code is displayed. [Figure 8] FIG. 10 is a sequence diagram illustrating an example of a second authentication process according to the first embodiment. [Figure 9] FIG. 10 is a diagram showing an example of a display screen of a second user terminal device 10B on which a QR code is displayed. [Figure 10] FIG. 10 is a sequence diagram illustrating an example of a second authentication process according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] An information processing device, an information processing method, and a program according to the present invention will be described below with reference to the drawings. The information processing device is realized by one or more processors. In the following description, the information processing device provides an electronic payment service and is referred to as a "payment server." However, the information processing device may also provide any service that involves login, such as shopping, auctions, chat, microblogging, or other services. An electronic payment service is a service that supports payments for the purchase of goods or services at a store. A store is, for example, a physical store (real-world store) that exists in real space.

[0010] First Embodiment [Electronic payment service] Figure 1 shows an example of a configuration for realizing an electronic payment service. The electronic payment service is realized mainly by a payment server 100. The payment server 100 communicates with, for example, one or more user terminal devices 10 and one or more store terminal devices 50 via a network NW. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, etc.

[0011] The user terminal device 10 is, for example, a portable terminal device such as a smartphone or tablet terminal. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input acceptance function, and a program execution function. In the following description, the components for realizing these functions are referred to as a camera, a communication device, a touch panel, a CPU (Central Processing Unit), etc. In the user terminal device 10, a processor such as a CPU executes a payment application 20, which operates in cooperation with the payment server 100 to provide electronic payment services to users. The payment application 20 controls the camera, communication device, touch panel, etc.

[0012] The store terminal device 50 is installed, for example, in a store. The store terminal device 50 is a computer device having at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The store terminal device 50 may include a so-called POS (Point of Sale) device, and the product price acquisition function and the optical reading function may be realized by the POS device. The store code image 60 is placed in the store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. The store code image 60 may also be displayed on a display placed in the store.

[0013] The payment server 100 performs electronic payment based on payment information received from the user terminal device 10 or the store terminal device 50. The payment server 100 performs electronic payment, for example, by increasing or decreasing the charge balance managed in association with the user ID (in other words, by depositing or withdrawing electronic money). Electronic payment may include methods such as revolving payment or credit payment that allow purchases of a larger amount than the charge balance at the time of purchase.

[0014] FIG. 2 illustrates an example of the general flow of electronic payment. There may be two patterns for electronic payment: Pattern 1 and Pattern 2. In Pattern 1, first, the payment app 20 is launched on the user terminal device 10, and a code image such as a QR code or barcode is displayed. The user holds (presents) the display surface of the user terminal device 10 over the store terminal device 50. The store terminal device 50 decodes the code image using its optical reading function and acquires information such as the account ID. The store terminal device 50 then generates payment information including the account ID, payment amount, store ID, etc., and transmits it to the payment server 100. The payment amount information has been acquired in advance by reading a barcode or manually entering it. Based on the received information, the payment server 100 transfers the payment amount from the user's electronic payment account to the store's electronic payment account, thereby completing the payment process.

[0015] In pattern 2, the user terminal device 10, with the payment app 20 running, decodes the store code image 60 using its optical reading function. The store code image 60 contains information such as the store name. The user enters the payment amount into the user terminal device 10 on the screen displaying the store name, etc. The user terminal device 10 then generates payment information including the account ID, payment amount, store ID, etc., and transmits it to the payment server 100. The payment server 100 performs payment processing based on the received information. Note that electronic payment may be performed only in one of the above patterns. The "account ID" described in Figure 2 may also be other information (e.g., a phone number) that can be used as user identification information.

[0016] [Payment server] 3 is a configuration diagram of the payment server 100. The payment server 100 includes, for example, a communication unit 110, a payment content providing unit 120, a payment processing unit 122, a code information generating unit 124, a determination unit 126, an authentication unit 128, an information management unit 130, and a storage unit 170. The components other than the communication unit 110 and the storage unit 170 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry) such as an LSI (Large Scale Integration), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a GPU (Graphics Processing Unit), or may be realized by a combination of software and hardware. The program may be stored in advance in a storage device such as an HDD (Hard Disk Drive) or flash memory (a storage device with a non-transitory storage medium), or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device.

[0017] The storage unit 170 is a HDD, a flash memory, a RAM (Random Access Memory), etc. The storage unit 170 may be a NAS (Network Attached Storage) device that the payment server 100 can access via a network. The storage unit 170 stores information such as user information 172 and payment content information 174.

[0018] The communication unit 110 is a communication interface for connecting to the network NW. The communication unit 110 is, for example, a network interface card. The communication unit 110 functions as a transmitter that transmits information via the network NW and as a receiver that receives information via the network NW.

[0019] The payment content providing unit 120 has, for example, a function of a web server, and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The payment content providing unit 120 reads out necessary content from the payment content information 174 as appropriate and provides it to the user terminal device 10. The user terminal device 10 accepts various inputs from the user while content is being played by the payment application 20, and transmits the above-mentioned payment information and the like to the payment server 100.

[0020] The payment processing unit 122 performs payment processing based on the payment information transmitted by the user terminal device 10 or the store terminal device 50. The payment processing unit 122 performs payment processing while referring to the user information 172.

[0021] [User information] FIG. 4 is a diagram showing an example of the contents of user information 172. User information 172 is an example of user registration information. For example, user information 172 is an account ID (which may be omitted) associated with information such as a phone number and password, which are the minimum required for new registration, as well as an email address, user ID, device ID, charge balance, bank account, credit card number, charge history information, and payment history information. Information other than the phone number, password, device ID, charge balance, charge history information, and payment history information is optional information. Hereinafter, a user instance (electronic payment account) associated with this information will be referred to as an account. The phone number may be used as a login ID for the electronic payment service.

[0022] The user ID is an example of user identification information used by the payment server 100 to identify a user, and is information that can be arbitrarily set by the user, such as the user's nickname. The device ID is an example of information used by the payment server 100 to identify the user terminal device 10. For example, the device ID may be information generated by combining information such as the IMEI (International Mobile Equipment Identifier), information about the manufacturer of the user terminal device 10, and the ID of the OS (Operating System).

[0023] The charge balance is information indicating the balance of electronic money that has been set by the user by transferring funds to the account in advance. Methods of transfer include transfer from an ATM (Automatic Teller Machine) of a designated service provider (bank) or transfer from a registered bank account. The bank account and credit card number are information on the bank account or credit card number (account number, card number) that can be used to deposit funds into the electronic payment service. The charge history information is a history of the user transferring funds to the electronic payment service in advance to increase the charge balance. The payment history information is information that indicates the breakdown of payments made by the user for each payment (date and time, store ID of the store where the purchase was made, payment amount, etc.).

[0024] [Phishing techniques] When a user changes the model of their smartphone, for example, they may attempt to log in to an electronic payment service using a terminal device other than the terminal device that has already been authenticated as the terminal device used by the user. In this case, the user inputs authentication information from the existing terminal device, and authentication processing for the new terminal device is performed. However, if the authentication information is fraudulently obtained by a third party, there is a possibility that unauthorized logins to the electronic payment service may be performed from the third party's terminal device. For this reason, the present embodiment aims to prevent unauthorized logins by third parties (e.g., phishing perpetrators). Therefore, before describing the details of the processing of this embodiment, phishing techniques will be described.

[0025] Phishing is a fraudulent act carried out over the Internet to obtain information such as a user's login ID, password, and authentication code. In recent years, the number of phishing sites has increased rapidly, and there has been no end to the number of victims who have had their login IDs, passwords, and authentication codes stolen. This embodiment aims to reduce the number of login attempts by phishing perpetrators and to discourage phishing perpetrators from setting up phishing sites by increasing the login strength.

[0026] Phishers obtain users' login IDs (such as phone numbers) and passwords in the following manner: (1) Phishers trick users into accessing a fake login site and entering their login ID and password. (2) The phisher attempts to log in to the legitimate login site from their own terminal using the entered login ID and password. Because the access is from a terminal other than the user's, a message containing an authentication code is sent to the user's terminal via SMS (Short Message Service) or other means to prevent unauthorized access. (3) The phisher displays a screen on a fake login site that asks the victim to enter the authentication code sent via SMS. (4) The phisher then uses the authentication code entered by the user into the fake login site to enter it into the legitimate login site using the phisher's terminal device, completing the login process.

[0027] The problem with the above-mentioned phishing techniques is that the user enters an authentication code on a fake login site. Therefore, in this embodiment, a terminal device (existing environment) that has already been authenticated as a terminal device used by the user and a terminal device (new environment) that has not yet been authenticated are allowed to log in using the terminal device in the new environment only when they are physically close to each other. Details of this embodiment are described below.

[0028] [Login authentication process] 5 is a flowchart showing an example of login authentication processing. The processing according to this flowchart is executed by the payment server 100. First, the communication unit 110 of the payment server 100 receives a login request from the user terminal device 10 (S11). The login request includes information such as a login ID (such as a telephone number), a password, and a device ID.

[0029] Next, the authentication unit 128 compares the login ID (such as a telephone number) and password included in the login request with the user information 172 to determine whether the login authentication has been successful (S12). Specifically, the authentication unit 128 determines that the login authentication has been successful if the login ID (such as a telephone number) included in the login request is registered in the user information 172 and the password included in the login request matches the password included in the user information 172. On the other hand, the authentication unit 128 determines that the login authentication has failed if the login ID (such as a telephone number) included in the login request is not registered in the user information 172 or the password included in the login request does not match the password included in the user information 172.

[0030] If the authentication unit 128 determines that the login authentication has failed, it transmits a login failure notification to the user terminal device 10 (S13), and ends the processing according to this flowchart.

[0031] On the other hand, if it is determined that the login authentication is successful, the authentication unit 128 compares the device ID included in the login request with the user information 172 to determine whether the login is from a new environment (S14). Here, the new environment refers to a terminal device that has not been authenticated as a terminal device used by the user. Also, the existing environment refers to a terminal device that has already been authenticated as a terminal device used by the user.

[0032] Specifically, the authentication unit 128 determines that the login is from a new environment when the device ID included in the login request does not match the device ID included in the user information 172. On the other hand, the authentication unit 128 determines that the login is from an existing environment when the device ID included in the login request matches the device ID included in the user information 172.

[0033] If the authentication unit 128 determines that the login is not from a new environment (i.e., if it determines that the login is from an existing environment), it sends a login success notification to the user terminal device 10 (S15) and terminates the processing according to this flowchart.

[0034] On the other hand, if the authentication unit 128 determines that the login is from the new environment, the determination unit 126 determines whether or not the login is from payment application 20 (S16). If the authentication unit 128 determines that the login is from payment application 20, it executes a first authentication process, which will be described later (S17). On the other hand, if the authentication unit 128 determines that the login is not from payment application 20, it executes a second authentication process, which will be described later (S18). If the login is not from payment application 20, it is, for example, a case where the login is from a web browser.

[0035] The payment app 20 is installed on a terminal device equipped with a camera, such as a smartphone or tablet terminal. Therefore, if the login is from the payment app 20, a first authentication process is performed, which is an authentication process using the camera of the user terminal device 10 that sent the login request. On the other hand, if the login is not from the payment app 20 (for example, if the login is from a web browser), the user terminal device 10 may not be equipped with a camera. Therefore, if the login is not from the payment app 20, a second authentication process is performed, which is an authentication process that does not use the camera of the user terminal device 10 that sent the login request. Details of the first authentication process and the second authentication process are described below.

[0036] [First authentication process] 6 is a sequence diagram showing an example of the first authentication process. In explaining this sequence diagram, a terminal device (existing environment) that has already been authenticated as a terminal device used by a user is referred to as first user terminal device 10A, and a terminal device (new environment) that has not yet been authenticated is referred to as second user terminal device 10B. The following describes the first authentication process when a login request is made from second user terminal device 10B to payment server 100.

[0037] First, the communication unit 110 of the payment server 100 sends an SMS notification to the first user terminal device 10A, which is an existing environment (S101). The SMS notification is a notification by short message using the user's phone number. The SMS notification includes a URL (Uniform Resource Locator) for launching the payment application 20.

[0038] When the first user terminal device 10A receives the SMS notification from the payment server 100, it launches the payment application 20 (S102). For example, the first user terminal device 10A launches the payment application 20 in response to the user selecting a URL included in the SMS notification.

[0039] Next, the code information generation unit 124 of the payment server 100 generates a QR code in which the authentication information is coded (S103). For example, the authentication information may be time-limited information such as a one-time password. The code information generation unit 124 then transmits the generated QR code from the communication unit 110 to the first user terminal device 10A (S104). Upon receiving the QR code from the payment server 100, the first user terminal device 10A displays the QR code on the screen of the payment application 20 (S105).

[0040] 7 is a diagram showing an example of the display screen of the first user terminal device 10A on which a QR code is displayed. As shown in Fig. 7, the display screen of the first user terminal device 10A displays the QR code C and a message such as "Please read the QR code with a new terminal."

[0041] Next, the second user terminal device 10B, which is the new environment, photographs the QR code displayed on the first user terminal device 10A (S106). Specifically, the user photographs the QR code displayed on the first user terminal device 10A using the camera of the second user terminal device 10B.

[0042] The second user terminal device 10B also acquires authentication information by decoding the captured QR code (S107), and then transmits the acquired authentication information to the payment server 100 (S108).

[0043] When the communication unit 110 of the payment server 100 receives the authentication information from the second user terminal device 10B, the authentication unit 128 of the payment server 100 performs a process of verifying the authentication information (S109). Specifically, the authentication unit 128 determines whether the authentication information included in the QR code sent to the first user terminal device 10A matches the authentication information received from the second user terminal device 10B. If the authentication information included in the QR code sent to the first user terminal device 10A does not match the authentication information received from the second user terminal device 10B, the authentication unit 128 transmits a login denial notice from the communication unit 110 to the second user terminal device 10B.

[0044] On the other hand, if the authentication information included in the QR code transmitted to the first user terminal device 10A matches the authentication information received from the second user terminal device 10B, the authentication unit 128 transmits a login permission notification to the second user terminal device 10B from the communication unit 110 (S110). This allows login from the second user terminal device 10B, which is the new environment.

[0045] Thereafter, the information management unit 130 performs an update process of the user information 172 (S111). Specifically, the information management unit 130 writes the device ID (i.e., the device ID of the second user terminal device 10B) included in the login request transmitted from the second user terminal device 10B into the user information 172 in association with the login ID (such as a telephone number) included in the login request.

[0046] According to the first authentication process described above, it is necessary to photograph the QR code displayed on first user terminal device 10A with second user terminal device 10B. That is, since authentication must be performed in a situation where first user terminal device 10A and second user terminal device 10B are physically close to each other, it is possible to prevent unauthorized logins by phishing perpetrators.

[0047] [Second authentication process] 8 is a sequence diagram showing an example of the second authentication process according to the first embodiment. In the first authentication process described above, the payment server 100 transmits a QR code to the first user terminal device 10A, but in the second authentication process, the payment server 100 transmits a QR code to the second user terminal device 10B. This is because there is a possibility that the second user terminal device 10B does not have a camera. Below, we will explain the second authentication process when a login request is made from the second user terminal device 10B to the payment server 100.

[0048] First, the communication unit 110 of the payment server 100 sends an SMS notification to the first user terminal device 10A, which is the existing environment (S201). As described above, the SMS notification is a notification by short message using the user's phone number, and includes a URL for launching the payment application 20.

[0049] When the first user terminal device 10A receives the SMS notification from the payment server 100, it launches the payment application 20 (S202). For example, the first user terminal device 10A launches the payment application 20 in response to the user selecting a URL included in the SMS notification.

[0050] Next, the code information generation unit 124 of the payment server 100 generates a QR code in which the authentication information is coded (S203). For example, the authentication information may be time-limited information such as a one-time password. The code information generation unit 124 also transmits the generated QR code from the communication unit 110 to the second user terminal device 10B (S204). When the second user terminal device 10B, which is in the new environment, receives the QR code from the payment server 100, it displays the QR code on the display unit of the second user terminal device 10B (S205).

[0051] 9 is a diagram showing an example of the display screen of the second user terminal device 10B on which a QR code is displayed. As shown in Fig. 9, the display screen of the second user terminal device 10B displays the QR code C and a message such as "Please read the QR code with an existing terminal."

[0052] Next, the first user terminal device 10A, which is the existing environment, photographs the QR code displayed on the second user terminal device 10B (S206). Specifically, the user photographs the QR code displayed on the second user terminal device 10B using the camera of the first user terminal device 10A.

[0053] The first user terminal device 10A also acquires authentication information by decoding the captured QR code (S207), and then transmits the acquired authentication information to the payment server 100 (S208).

[0054] When the communication unit 110 of the payment server 100 receives the authentication information from the first user terminal device 10A, the authentication unit 128 of the payment server 100 performs a process of verifying the authentication information (S209). Specifically, the authentication unit 128 determines whether the authentication information included in the QR code sent to the second user terminal device 10B matches the authentication information received from the first user terminal device 10A. If the authentication information included in the QR code sent to the second user terminal device 10B does not match the authentication information received from the first user terminal device 10A, the authentication unit 128 transmits a login denial notice from the communication unit 110 to the second user terminal device 10B.

[0055] On the other hand, if the authentication information included in the QR code transmitted to the second user terminal device 10B matches the authentication information received from the first user terminal device 10A, the authentication unit 128 transmits a login permission notification to the second user terminal device 10B from the communication unit 110 (S210). This allows login from the second user terminal device 10B, which is the new environment.

[0056] Thereafter, the information management unit 130 performs an update process of the user information 172 (S211). Specifically, the information management unit 130 writes the device ID (i.e., the device ID of the second user terminal device 10B) included in the login request transmitted from the second user terminal device 10B into the user information 172 in association with the login ID (such as a telephone number) included in the login request.

[0057] According to the second authentication process described above, it is necessary to photograph the QR code displayed on second user terminal device 10B with first user terminal device 10A. That is, since authentication must be performed in a situation where first user terminal device 10A and second user terminal device 10B are physically close to each other, it is possible to prevent unauthorized logins by phishing perpetrators. Furthermore, even if second user terminal device 10B, which is a new environment, is not equipped with a camera, unauthorized logins can be prevented.

[0058] As described above, the payment server 100 (information processing device) of the first embodiment includes the code information generation unit 124, the communication unit 110, the authentication unit 128, and the determination unit 126. When a login request is received from the second user terminal device 10B, the code information generation unit 124 generates a QR code (code information) in which authentication information is encoded. The communication unit 110 transmits the generated QR code to either the first user terminal device 10A or the second user terminal device 10B, and receives authentication information obtained by photographing and decoding the QR code from the other of the first user terminal device 10A and the second user terminal device 10B. The authentication unit 128 authenticates the second user terminal device 10B based on the received authentication information. The determination unit 126 determines to which of the first user terminal device 10A and the second user terminal device 10B the QR code should be sent, depending on the login method of the second user terminal device 10B. This prevents unauthorized logins by third parties.

[0059] Furthermore, in the first embodiment, determination unit 126 determines whether to send the QR code to first user terminal device 10A or second user terminal device 10B, depending on whether the login request from second user terminal device 10B is a login request from payment application 20. Specifically, if the login request from second user terminal device 10B is a login request from payment application 20, determination unit 126 determines to send the QR code to first user terminal device 10A, and if the login request from second user terminal device 10B is not a login request from payment application 20, determination unit 126 determines to send the QR code to first user terminal device 10A. This is because if the login request is from payment application 20, second user terminal device 10B is presumed to be a mobile terminal device with a camera function, but if the login request is not from payment application 20, it is presumed that the login is via a web browser and second user terminal device 10B is a PC (Personal Computer) or the like without a camera function. This ensures that the QR code is photographed by the user terminal device 10 equipped with a camera, and the authentication process can be carried out reliably.

[0060] Furthermore, in the first embodiment, the communication unit 110 sends an SMS notification containing an address for launching the payment application 20 to the first user terminal device 10A before the QR code is generated by the code information generation unit 124. This allows the payment application 20 to be launched without delay in the first user terminal device 10A.

[0061] Second Embodiment In the first embodiment described above, authentication using a QR code is performed only once, whereas in the second embodiment, authentication using a QR code is performed multiple times to further strengthen security.

[0062] As shown in S205 of FIG. 8, in the second authentication process of the first embodiment, a QR code is displayed on the second user terminal device 10B. However, if a phisher displays this QR code on a fake login site and a user photographs the displayed QR code with a user terminal device in the existing environment, there is a possibility that unauthorized login will be performed using the phisher's terminal device. For this reason, when displaying the QR code on the second user terminal device 10B, it is preferable to display it multiple times as quickly as possible. Note that the first authentication process of the second embodiment is the same as the first authentication process of the first embodiment, so a description thereof will be omitted. Details of the second embodiment will be described below.

[0063] 10 is a sequence diagram showing an example of the second authentication process according to the second embodiment. The second authentication process when a login request is made from the second user terminal device 10B to the payment server 100 will be described below.

[0064] First, the communication unit 110 of the payment server 100 sends an SMS notification to the first user terminal device 10A, which is the existing environment (S301). As described above, the SMS notification is a notification by short message using the user's phone number, and includes a URL for launching the payment application 20.

[0065] When the first user terminal device 10A receives the SMS notification from the payment server 100, it launches the payment application 20 (S302). For example, the first user terminal device 10A launches the payment application 20 in response to the user selecting a URL included in the SMS notification.

[0066] Next, the code information generation unit 124 of the payment server 100 generates a first QR code in which the first authentication information is encoded (S303). For example, the first authentication information may be time-limited information such as a one-time password. Furthermore, the code information generation unit 124 transmits the generated first QR code from the communication unit 110 to the second user terminal device 10B (S304).

[0067] When second user terminal device 10B, which is in the new environment, receives the first QR code from payment server 100, it displays the first QR code on the display unit of second user terminal device 10B (S305). At this time, second user terminal device 10B displays the first QR code for only a first time period (e.g., 30 seconds). For example, second user terminal device 10B may receive information about the first time period along with the first QR code from payment server 100 in S304, and display the first QR code for only a time period according to the received information about the first time period.

[0068] Next, the first user terminal device 10A, which is the existing environment, photographs the first QR code displayed on the second user terminal device 10B (S306). Specifically, the user photographs the first QR code displayed on the second user terminal device 10B using the camera of the first user terminal device 10A.

[0069] The first user terminal device 10A also acquires first authentication information by decoding the captured first QR code (S307), and then transmits the acquired first authentication information to the payment server 100 (S308).

[0070] When the communication unit 110 of the payment server 100 receives the first authentication information from the first user terminal device 10A, the authentication unit 128 of the payment server 100 performs a process of verifying the first authentication information (S309). Specifically, the authentication unit 128 determines whether the first authentication information included in the first QR code transmitted to the second user terminal device 10B matches the first authentication information received from the first user terminal device 10A. If the first authentication information included in the first QR code transmitted to the second user terminal device 10B does not match the first authentication information received from the first user terminal device 10A, the authentication unit 128 transmits a login denial notice from the communication unit 110 to the second user terminal device 10B.

[0071] On the other hand, if the first authentication information included in the first QR code transmitted to the second user terminal device 10B matches the first authentication information received from the first user terminal device 10A, the code information generation unit 124 generates a second QR code in which second authentication information different from the first authentication information is encoded (S310). For example, the second authentication information may be time-limited information such as a one-time password. The code information generation unit 124 also transmits the generated second QR code from the communication unit 110 to the second user terminal device 10B (S311).

[0072] When the second user terminal device 10B, which is in the new environment, receives the second QR code from the payment server 100, it displays the second QR code on the display unit of the second user terminal device 10B (S312). At this time, the second user terminal device 10B displays the second QR code for a second time period (e.g., 5 seconds) that is shorter than the first time period. For example, in S311, the second user terminal device 10B may receive information about the second time period along with the second QR code from the payment server 100, and display the second QR code for a time period according to the received information about the second time period.

[0073] When the first QR code is photographed in S306, the first QR code is displayed for a relatively long time (e.g., 30 seconds) in consideration of the startup time of the camera function, since this is the first time the code is photographed. On the other hand, when the second QR code is photographed in S313, the camera function has already been activated, so the display time of the second QR code is set to a short time (e.g., 5 seconds). This more reliably prevents the second authentication information from being fraudulently obtained by phishers.

[0074] Next, the first user terminal device 10A, which is the existing environment, photographs the second QR code displayed on the second user terminal device 10B (S313). Specifically, the user photographs the second QR code displayed on the second user terminal device 10B using the camera of the first user terminal device 10A.

[0075] The first user terminal device 10A also acquires second authentication information by decoding the captured second QR code (S314), and then transmits the acquired second authentication information to the payment server 100 (S315).

[0076] When the communication unit 110 of the payment server 100 receives the second authentication information from the first user terminal device 10A, the authentication unit 128 of the payment server 100 performs a process of verifying the second authentication information (S316). Specifically, the authentication unit 128 determines whether the second authentication information included in the second QR code transmitted to the second user terminal device 10B matches the second authentication information received from the first user terminal device 10A. If the second authentication information included in the second QR code transmitted to the second user terminal device 10B does not match the second authentication information received from the first user terminal device 10A, the authentication unit 128 transmits a login denial notice from the communication unit 110 to the second user terminal device 10B.

[0077] On the other hand, if the second authentication information included in the second QR code transmitted to the second user terminal device 10B matches the second authentication information received from the first user terminal device 10A, the authentication unit 128 transmits a login permission notification to the second user terminal device 10B from the communication unit 110 (S317). This allows login from the second user terminal device 10B, which is the new environment.

[0078] Thereafter, the information management unit 130 performs an update process of the user information 172 (S318). Specifically, the information management unit 130 writes the device ID (i.e., the device ID of the second user terminal device 10B) included in the login request transmitted from the second user terminal device 10B into the user information 172 in association with the login ID (such as a telephone number) included in the login request.

[0079] According to the second embodiment described above, unauthorized logins by other people can be prevented, as in the first embodiment. Furthermore, according to the second embodiment, the code information generation unit 124 generates a first QR code (first code information) in which first authentication information is coded, and then generates a second QR code (second code information) in which second authentication information different from the first authentication information is coded. If both authentications based on the first QR code and authentications based on the second QR code are successful, the authentication unit 128 authenticates the second user terminal device 10B as a terminal device used by the user. This makes it possible to more reliably prevent unauthorized logins by phishers.

[0080] Furthermore, according to the second embodiment, the time available for capturing an image of the second QR code (second code information) is shorter than the time available for capturing an image of the first QR code (first code information), which more reliably prevents the second authentication information from being illegally obtained by phishers.

[0081] According to the second embodiment, authentication based on the first and second QR codes is performed in the second authentication process as an example. However, this is not limiting. For example, authentication based on the first and second QR codes may be performed in the first authentication process. This is because displaying the QR code multiple times and for as short a time as possible is effective in preventing unauthorized logins, even if a phisher somehow manages to photograph the QR code displayed on the first user terminal device 10A, which is an existing environment. In this case, the communication unit 110 of the payment server 100 may transmit the first and second QR codes to the first user terminal device 10A, and the second user terminal device 10B may photograph the first and second QR codes displayed on the first user terminal device 10A. If both the authentication based on the first and second QR codes are successful, the authentication unit 128 of the payment server 100 may authenticate the second user terminal device 10B as a terminal device used by the user.

[0082] In the first and second embodiments, the communication unit 110 sends an SMS notification containing an address for launching the payment app 20 to the first user terminal device 10A before the code information generation unit 124 generates a QR code, but this is not limited to this. For example, the communication unit 110 may send a push notification for launching the payment app 20 to the first user terminal device 10A before the code information generation unit 124 generates a QR code. The push notification is a message that can be sent directly to the first user terminal device 10A and is displayed on the first user terminal device 10A together with a notification sound. In this case, the user launches the payment app 20 on the first user terminal device 10A based on the push notification.

[0083] Furthermore, in the first and second embodiments, the explanations have been given on the assumption that the payment app 20 is installed in the first user terminal device 10A. However, if the payment app 20 is not installed in the first user terminal device 10A, the communication unit 110 may send an SMS notification to the first user terminal device 10A to cause the first user terminal device 10A to install the payment app 20. This enables the payment app 20 to be used in the first user terminal device 10A, and makes it possible to activate the camera function from the payment app 20, etc.

[0084] Furthermore, in the first and second embodiments, the communication unit 110 may transmit location information based on the IP (Internet Protocol) address of the second user terminal device 10B or information regarding the purpose of the login (for example, the service to which the user is attempting to log in) to the first user terminal device 10A and cause it to be displayed. This allows the user who owns the first user terminal device 10A to determine whether or not an unauthorized login is being attempted by a phisher.

[0085] In addition to the authentication processes of the first and second embodiments, the authentication unit 128 may acquire location information of the first user terminal device 10A and the second user terminal device 10B, and determine that the first user terminal device 10A and the second user terminal device 10B are operated by the same person if the distance between the first user terminal device 10A and the second user terminal device 10B is within a predetermined distance. The location information may be information obtained by, for example, a Global Positioning System (GPS). The authentication unit 128 may also determine whether the first user terminal device 10A and the second user terminal device 10B are operated by the same person based on the location information as well as sensor information obtained from the first user terminal device 10A and the second user terminal device 10B (such as the degree of tilt of the user terminal device at the time of operation, temperature information, humidity information, etc.).

[0086] In the first and second embodiments, the payment server 100 performs the authentication process, but this is not limiting. For example, an authentication server may be constructed as an information processing device that performs the authentication process, separate from the payment server 100.

[0087] The above describes the form for carrying out the present invention using an embodiment, but the present invention is not limited to such an embodiment, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]

[0088] 10 User terminal device 20. Payment App 50 Store terminal equipment 60 Store Code Image 100 Payment Server 110 Communication unit (transmitter, receiver) 120 Payment Contents Department 122 Payment processing unit 124 Code information generation unit 126 Judgment section 128 Authentication Section 130 Information Management Department 170 Memory Department

Claims

1. An information processing device capable of communicating with a first terminal device and a second terminal device, a code information generating unit that generates first code information in which first authentication information is coded in response to a request from the second terminal device, and then generates second code information in which second authentication information different from the first authentication information is coded; a transmitting unit that transmits the first code information and the second code information generated by the code information generating unit to one of the first terminal device and the second terminal device; a receiving unit that receives, from the other of the first terminal device and the second terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; an authentication unit that authenticates the second terminal device based on the first authentication information and the second authentication information received by the receiving unit; Equipped with the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. Information processing device.

2. An information processing device capable of communicating with a first terminal device and a second terminal device, a code information generating unit that generates first code information in which first authentication information is coded in response to a request from the second terminal device, and then generates second code information in which second authentication information different from the first authentication information is coded; a transmitting unit that transmits the first code information and the second code information generated by the code information generating unit to the first terminal device; a receiving unit that receives, from the second terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; an authentication unit that authenticates the second terminal device based on the first authentication information and the second authentication information received by the receiving unit; Equipped with the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. Information processing device.

3. An information processing device capable of communicating with a first terminal device and a second terminal device, a code information generating unit that generates first code information in which first authentication information is coded in response to a request from the second terminal device, and then generates second code information in which second authentication information different from the first authentication information is coded; a transmitting unit that transmits the first code information and the second code information generated by the code information generating unit to the second terminal device; a receiving unit that receives, from the first terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; an authentication unit that authenticates the second terminal device based on the first authentication information and the second authentication information received by the receiving unit; Equipped with the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. Information processing device.

4. The time-limited period of the first authentication information is longer than the activation time of a camera function for capturing the first code information. The information processing device according to any one of claims 1 to 3.

5. the transmitting unit transmits the second code information after the authentication unit completes authentication based on the first authentication information. The information processing device according to any one of claims 1 to 3.

6. an information processing device capable of communicating with a first terminal device and a second terminal device, generating first code information in which first authentication information is coded in response to a request from the second terminal device, and then generating second code information in which second authentication information different from the first authentication information is coded; transmitting the first code information and the second code information to one of the first terminal device and the second terminal device; receiving, from the other of the first terminal device and the second terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; authenticating the second terminal device based on the received first authentication information and the received second authentication information; the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. Information processing methods.

7. an information processing device capable of communicating with a first terminal device and a second terminal device, generating first code information in which first authentication information is coded in response to a request from the second terminal device, and then generating second code information in which second authentication information different from the first authentication information is coded; Transmitting the first code information and the second code information to the first terminal device; receiving, from the second terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; authenticating the second terminal device based on the received first authentication information and the received second authentication information; the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. Information processing methods.

8. an information processing device capable of communicating with a first terminal device and a second terminal device, generating first code information in which first authentication information is coded in response to a request from the second terminal device, and then generating second code information in which second authentication information different from the first authentication information is coded; Transmitting the first code information and the second code information to the second terminal device; receiving, from the first terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; authenticating the second terminal device based on the received first authentication information and the received second authentication information; the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. Information processing methods.

9. An information processing device capable of communicating with a first terminal device and a second terminal device, generating first code information in which first authentication information is coded in response to a request from the second terminal device, and then generating second code information in which second authentication information different from the first authentication information is coded; transmitting the first code information and the second code information to one of the first terminal device and the second terminal device; receiving, from the other of the first terminal device and the second terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; authenticating the second terminal device based on the received first authentication information and the received second authentication information; the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. program.

10. An information processing device capable of communicating with a first terminal device and a second terminal device, generating first code information in which first authentication information is coded in response to a request from the second terminal device, and then generating second code information in which second authentication information different from the first authentication information is coded; transmitting the first code information and the second code information to the first terminal device; receiving, from the second terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; authenticating the second terminal device based on the received first authentication information and the received second authentication information; the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. program.

11. An information processing device capable of communicating with a first terminal device and a second terminal device, generating first code information in which first authentication information is coded in response to a request from the second terminal device, and then generating second code information in which second authentication information different from the first authentication information is coded; transmitting the first code information and the second code information to the second terminal device; receiving, from the first terminal device, the first authentication information obtained by photographing and decoding the first code information and the second authentication information obtained by photographing and decoding the second code information; authenticating the second terminal device based on the received first authentication information and the received second authentication information; the first code information is captured before the second code information is captured, the first authentication information and the second authentication information are time-limited information, In order to more effectively prevent unauthorized acquisition of the second authentication information compared to the first authentication information, the time limit period of the second authentication information is shorter than the time limit period of the first authentication information. program.

Citation Information

Patent Citations

  • Digital voucher authentication

    EP2922010A2

  • Server device, service providing system, service transition method, and service transition program

    JP2008067098A

  • Migration method, migration program, service providing server, and service providing system

    JP2017194770A

  • Authentication method and system

    JP2019517087A

  • Electronic ticket admission verification Anti-counterfeiting system and method thereof

    JP2020038659A