Authentication server device, authentication method, and content receiving program
The authentication server device and method address the challenge of authenticating communication terminals in diverse wireless environments by using unique identifiers to ensure secure and timely digital content delivery.
Patent Information
- Application Number
- JP2021185147
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-12
- Publication Date
- 2025-12-15
- Estimated Expiration
- 2041-11-12
AI Technical Summary
Existing digital content distribution services face challenges in easily authenticating communication terminals across varying wireless communication environments.
An authentication server device and method that utilize identification information, such as global fixed IP addresses, MAC addresses, or service set identifiers, to authenticate wireless communication devices connected to communication terminals, determining their eligibility to receive digital content.
Facilitates easy authentication of communication terminals for digital content delivery regardless of communication environment, allowing for time-limited and location-specific content distribution.
Smart Images

Figure 0007785281000001 
Figure 0007785281000002 
Figure 0007785281000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an authentication server device, an authentication method, and a content receiving program. [Background technology]
[0002] In recent years, services have been provided in which digital content is distributed to the communication terminals of users who visit a store for the purpose of customer service, etc. For example, when a communication terminal is present within a range reached by radio waves from a predetermined wireless communication antenna, digital content is temporarily distributed to the communication terminal (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-157784 Summary of the Invention [Problem to be solved by the invention]
[0004] Such digital content distribution services are provided to each store by, for example, a service provider, and digital content is provided to a communication terminal connected to the store's wireless communication antenna via wireless communication within the store (for example, wireless LAN (Local Area Network)). In this case, when providing digital content to a communication terminal connected to the store's wireless communication device, authentication processing of the communication terminal providing the digital content may be required. However, wireless communication environments vary from store to store, and it may be difficult to easily authenticate a communication terminal under any communication environment. The present disclosure has been made in consideration of such problems, and aims to provide an authentication server device and an authentication method that can easily authenticate a wireless communication device that is the destination of digital content delivery to a communication terminal connected thereto, regardless of the communication environment. [Means for solving the problem]
[0005] In order to solve the above-mentioned problems, an authentication server device according to one aspect of the present disclosure includes a memory unit that stores identification information capable of identifying one of a plurality of facilities that can provide digital content; a receiving unit that receives, from a communication terminal that requests the provision of digital content, identification information of a wireless communication device to which the communication terminal is connected or of wireless communication provided by the wireless communication device; a processing unit that compares the identification information received from the communication terminal with the identification information stored in the memory unit, and, if the comparison results in a match, authenticates the wireless communication device and determines that the communication terminal is a communication terminal that can provide digital content; and a transmitting unit that transmits the authentication result from the processing unit to the communication terminal.
[0006] In addition, an authentication method according to one aspect of the present disclosure stores identification information capable of identifying one of a plurality of facilities capable of providing digital content, receives identification information of a wireless communication device to which the communication terminal is connected or of wireless communication provided by the wireless communication device from a communication terminal requesting the provision of digital content, compares the identification information received from the communication terminal with the stored identification information, and if the comparison results in a match, authenticates the wireless communication device, determines that the communication terminal is a communication terminal capable of providing digital content, and transmits the authentication result to the communication terminal.
[0007] Furthermore, a content receiving program according to one aspect of the present disclosure causes a computer to communicate with an authentication server device that authenticates that the communication terminal is capable of providing digital content and a content server device that distributes the digital content; transmit identification information for the wireless communication device to which the communication terminal is connected or for the wireless communication provided by the wireless communication device to the authentication server device; store identification information that can identify one of multiple facilities that can provide digital content, compare the identification information transmitted from the communication terminal with the stored identification information, and, if the comparison results in a match, authenticate the wireless communication device and determine that the communication terminal is a communication terminal that can provide digital content. The authentication server device receives the result of authentication as to whether the communication terminal is a communication terminal that can provide digital content; and, if it is determined that the communication terminal is a communication terminal that can provide digital content, requests the content server device to distribute the digital content. [Effects of the Invention]
[0008] According to the present disclosure, it is possible to provide an authentication server device, an authentication method, and a content reception program that can easily authenticate a wireless communication device to which a communication terminal is connected and to which digital content is delivered, regardless of the communication environment. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 2 is a block diagram illustrating a configuration example of functions and operations of an authentication server device according to the first embodiment of the present disclosure. [Figure 2] FIG. 2 is a schematic diagram illustrating an authentication method by an authentication server device according to the first embodiment of the present disclosure. [Figure 3] 1 is a flowchart illustrating an authentication method according to the present embodiment. [Figure 4A] 10 is a schematic diagram showing an example of a display on a display unit of a communication terminal when a wireless communication device to which the communication terminal is connected has not been authenticated. FIG. [Figure 4B]10 is a schematic diagram showing an example of a display on a display unit of a communication terminal when a wireless communication device to which the communication terminal is connected is authenticated. FIG. [Figure 5] FIG. 10 is a schematic diagram illustrating an authentication method by an authentication server device according to a second embodiment of the present disclosure. [Figure 6] FIG. 11 is a schematic diagram showing an example of a communication terminal screen during authentication by an authentication server device according to a second embodiment of the present disclosure. [Figure 7] FIG. 2 is a block diagram illustrating an example of a hardware configuration for realizing each functional unit of the authentication server device according to each embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. However, the embodiments described below are merely examples, and are not intended to exclude various modifications or applications of techniques not explicitly stated below. The present disclosure can be implemented in various modifications (for example, by combining the respective embodiments) within the scope of the gist thereof.
[0011] 1. First embodiment The authentication server device and authentication method according to the first embodiment will be described below with reference to FIGS. 1 to 3, 4A and 4B.
[0012] (1.1) Basic configuration of the system including the authentication server device The basic configuration and functions of each unit of an authentication server device 10 according to the first embodiment will be described with reference to Figures 1 and 2. Figure 1 is a block diagram showing an example of the configuration of the functions and operations of the authentication server device 10. Figure 2 is a schematic diagram illustrating an authentication method performed by the authentication server device 10.
[0013] The authentication server device 10 authenticates the communication terminal 30 connected via a network based on the identification information of the wireless communication to which the communication terminal 30 is connected or the identification information of the wireless communication device 40 that provides the wireless communication. In this embodiment, as an example, as shown in FIG. 1 , a case will be described in which an authentication server device 10 is connected via a network to a content server device 20 that distributes digital content and a wireless communication device 40 located in a facility. Here, the "facility" refers to a store, hospital, facility, mobile object (e.g., airplane, train, bus, taxi, etc.) that provides digital content to a communication terminal, or a predetermined outdoor area. In this embodiment, the communication terminal 30 is connected to the wireless communication device 40 via a network such as a wireless LAN, thereby connecting to the authentication server device 10 and the content server device 20 via the wireless communication device 40. The authentication server device 10 has a function of determining, for example, whether the content server device 20 can distribute digital content to the communication terminal 30. When the authentication server device 10 has authenticated the communication terminal 30, i.e., when it has determined that digital content can be distributed to the communication terminal 30, the content server device 20 distributes the digital content to the communication terminal 30. The content server device 20, the wireless communication device 40, and the communication terminal 30 connected to the authentication server device 10 will be described below.
[0014] <Content server device> The content server device 20 has a storage unit 22 that stores digital content to be distributed to the communication terminal 30. The content server device 20 also has a receiving unit 21 that receives a request for digital content distribution from the communication terminal 30, and a transmitting unit 23 that transmits the digital content to the communication terminal 30 connected to the wireless communication device 40 via the wireless communication device 40 installed in the facility. The content server device 20 performs an authentication check on the authentication server device 10 in response to a request from the communication terminal 30, and transmits the digital content to the authenticated communication terminal 30.
[0015] The digital content stored in the content server device 20 may be any content that can be distributed to the communication terminal 30, and examples include electronic books such as magazines, comics, information magazines, and books for young children. The digital content may also be videos, still images, music, or electronic coupons that can be used to receive discounts or exchange for products at facilities where the wireless communication device 40 is located. The following describes the case where the digital content is an electronic book.
[0016] The content server device 20 can also distribute different content to each facility. The content server device 20 can distribute content that is optimal for each facility, such as content that is rooted in the local characteristics of the area where the facility is located or content that is suited to the type of business the facility is in. This allows the content server device 20 to distribute, for example, tourist information about the area around the facility, advertisements with a strong local feel, and works by artists with ties to the area, or, if the facility is a beauty salon, to distribute a hair catalog magazine.
[0017] <Wireless communication device> The wireless communication device 40 is a device that provides wireless communication to the communication terminal 30. The wireless communication device 40 is, for example, an access point for wireless LAN communication, and has a MAC (Media Access Control address) address, which is a physical address that is an identification number assigned to uniquely identify the wireless communication device 40. For internet communication, the wireless communication device 40 is assigned an IP address by an internet service provider (ISP) with which the facility has a contract.
[0018] In this embodiment, a case will be described in which the IP address assigned to the wireless communication device 40 is a global fixed IP address. In the authentication server device 10 of this embodiment, the global fixed IP address assigned to the wireless communication device 40 is used as identification information for authenticating the communication terminal 30.
[0019] <Communication terminal> The communication terminal 30 is a mobile communication terminal such as a smartphone or a tablet personal computer, which can be carried by a user when visiting a facility. The communication terminal 30 may include, for example, a display unit 31 that displays a list of digital content that can be provided or digital content transmitted from the content server device 20. The communication terminal 30 may also include, for example, an audio output unit (not shown) that outputs the audio of the digital content transmitted from the content server device 20.
[0020] The communication terminal 30 is carried by a user when visiting a facility, and is connected to a wireless communication device 40 located in the facility. The communication terminal 30 is connected to the wireless communication device 40 when it is located within a range where radio waves from the wireless communication device 40 connected to the authentication server device 10 via a network can reach. In other words, the communication terminal 30 may be connected to the wireless communication device 40 even when it is outside the facility. As a result, when the communication terminal 30 connects to the authentication server device 10 via the wireless communication device 40, the global fixed IP address contained in the wireless communication device 40 is sent to the authentication server device 10, and authentication work is performed by the authentication server device 10.
[0021] (1.2) Basic configuration of the authentication server device The authentication server device 10 will be described in detail below. As shown in Fig. 2, for example, a communication terminal 30 connected to a wireless communication device 40 in a facility accesses the authentication server device 10 by reading a two-dimensional barcode containing predetermined URL information, thereby obtaining a global fixed IP address, which is identification information contained in the wireless communication device 40, and authenticating the communication terminal 30 if the global fixed IP address matches a global fixed IP address stored in the authentication server device 10. The content server device 20 displays the authentication result on the communication terminal 30 according to the authentication result in the authentication server device 10. The authentication server device 10 includes a receiving unit 11, a processing unit 12, a storage unit 13, and a transmitting unit 14. Each unit of the authentication server device 10 will be described in detail below.
[0022] <Storage section> The storage unit 13 stores identification information that can identify one of a plurality of facilities that can provide digital content. Here, "one of a plurality of facilities that can provide digital content" refers to, for example, a facility that has concluded a content distribution contract with a content distributor or the like that provides the digital content stored in the content server device 20. The storage unit 13 includes a global fixed IP address assigned to the wireless communication device 40 of the one facility as identification information assigned to the wireless communication device 40 of the facility that can provide the digital content.
[0023] Furthermore, the storage unit 13 may store, for each facility that can provide the digital content, a time during which the digital content can be provided. The time during which the digital content can be provided may be, for example, the opening hours or business hours of the facility identified by the identification information stored in the storage unit 13, or may be a predetermined time during which the digital content can be provided (for example, "2 hours") that is set in advance for each facility. By storing such a time period during which the digital content can be provided, it is possible to set an expiration date for the delivery of the digital content and limit the provision of the digital content to the communication terminal 30 to the operating hours (business hours) of the facility or a predetermined time for each communication terminal 30. Furthermore, the storage unit 13 may store, as identification information, information for specifying a facility (location information, facility name, etc.) other than the global fixed IP address in association with the facility.
[0024] <Receiving section> The receiving unit 11 receives, from the communication terminal 30 that requests the provision of digital content, identification information, i.e., the global fixed IP address, of the wireless communication device 40 that provides wireless communication and to which the communication terminal 30 is connected. The receiving unit 11 transmits the acquired identification information (global fixed IP address) to the processing unit 12.
[0025] <Processing section> The processing unit 12 compares the identification information (global fixed IP address) received from the communication terminal 30 with the identification information (global fixed IP address) stored in the storage unit 13. If the comparison results in a match, the processing unit 12 authenticates the wireless communication device 40 to which the communication terminal 30 is connected. If the comparison results in a match, the processing unit 12 determines that the communication terminal 30 connected to the wireless communication device 40 is a communication terminal that can provide digital content.
[0026] In addition, if the memory unit 13 stores the opening hours (business hours) of the facility as the time during which digital content can be provided for each facility that can provide digital content, the processing unit 12 may determine whether the communication terminal 30 is a communication terminal that can provide digital content based on the matching result based on the identification information, the time during which digital content can be provided, and the current time.
[0027] Furthermore, if the memory unit 13 stores the opening hours (business hours) of a facility that can provide digital content and the time the digital content can be provided, the processing unit 12 may associate the authentication result based on the matching result based on the identification information with a delivery expiration date (for example, the time two hours after the current time) calculated from the facility's opening hours, the time the digital content can be provided, and the current time.
[0028] Furthermore, when the receiving unit 11 receives an authentication token from the content server device 20 as described below, the processing unit 12 can transmit authentication information to the content server device 20 via the transmitting unit 14 indicating that the communication terminal 30 has been authenticated.
[0029] <Transmitter> The transmission unit 14 transmits the result of the determination (authentication) made by the processing unit 12 to the communication terminal 30. Upon receiving the authentication result, the communication terminal 30 connects to the content server device 20 and receives a list of digital contents and digital contents provided thereto. Furthermore, the transmission unit 14 may transmit an authentication token indicating that the communication terminal 30 is capable of providing digital content to the communication terminal 30. This allows the communication terminal 30 to transmit the authentication token to the content server device 20, and the content server device 20 to perform an authentication check with the authentication server using the authentication token.
[0030] Furthermore, the transmission unit 14 may transmit a provision time limit of the digital content as authentication information to the content server device 20. This allows the content server device 20 to limit provision of the digital content to the communication terminal 30 within the provision time limit.
[0031] (1.3) Authentication method The authentication method according to this embodiment will be described below. The authentication server device 10 according to this embodiment determines whether a communication terminal is capable of providing digital content in accordance with a pre-stored program that causes a computer to execute the authentication method.
[0032] The authentication method according to this embodiment is performed at least by the following method. (a) storing identification information that can identify one of a plurality of facilities that can provide digital content; (b) receiving, from a communication terminal requesting the provision of digital content, identification information of a wireless communication device to which the communication terminal is connected or of a wireless communication provided by the wireless communication device; (c) comparing the identification information received from the communication terminal with the stored identification information, and if the comparison results in a match, authenticating the wireless communication device and determining that the communication terminal is a communication terminal capable of providing digital content; (d) Send the authentication result to the communication terminal.
[0033] The authentication method according to this embodiment will be described in more detail below with reference to Fig. 3 as well as Fig. 1. Fig. 3 is a flowchart illustrating the authentication method according to this embodiment.
[0034] <Registering identification information> First, identification information is registered in the authentication server device 10 (steps S11 and S12). First, a global fixed IP address, which is identification information for identifying a facility that can provide digital content, is registered in the storage unit 13 of the authentication server device 10, and a database of the identification information is generated (step S11). The registered global fixed IP address is, for example, a global fixed IP address assigned to a wireless communication device 40 of a facility that has concluded a content distribution contract with a content distributor or the like that provides the digital content stored in the content server device 20. The registration of identification information is carried out, for example, several times a day, and when new identification information is to be stored, the database of identification information stored in the storage unit 13 is updated (step S12). The database of identification information is updated in parallel with the distribution of digital content, which will be described later.
[0035] <Digital content distribution> First, the communication terminal 30 is placed in the facility and connected to wireless communication provided by the wireless communication device 40 to which the global fixed IP address stored in the authentication server device 10 is assigned (step S21). Next, a web browser for displaying digital content or a list of digital content or an application having a digital content browsing function is launched (step S22). The web browser may be launched automatically, for example, by reading a two-dimensional barcode posted within the facility and including URL information for connecting to the authentication server device 10. Alternatively, the application may be launched by the user of the communication terminal 30, for example, by reading the two-dimensional barcode using a two-dimensional barcode reading function within the application. Furthermore, the communication terminal 30 may connect to wireless communication within the facility after the application is launched.
[0036] When the communication terminal 30 is connected to the wireless communication within the facility and a web browser or application is started, a confirmation screen indicating that the digital content distribution service will be used is displayed on the display unit 31 of the communication terminal 30 (step S23). Note that, in a connection where the identification information is a global fixed IP address, the display of the confirmation screen in step S12 is not necessarily required. Next, an authentication request including the global fixed IP address of the wireless communication device 40 to which the communication terminal 30 is connected as identification information is transmitted to the authentication server device 10 (step S24). At this time, information for identifying other facilities (location information, facility name, etc.) may be included in the identification information as needed.
[0037] When the authentication server device 10 receives the authentication request, it compares the identification information (global fixed IP address) included in the authentication request with the identification information (global fixed IP address) in the database stored in the storage unit 13 (step S25). If the comparison results in a match, the authentication server device 10 authenticates the wireless communication device 40 to which the communication terminal 30 is connected, and determines that the communication terminal 30 is a communication terminal that can provide digital content. If the comparison results in a mismatch, the authentication server device 10 does not authenticate the wireless communication device 40 to which the communication terminal 30 is connected, and determines that the communication terminal 30 is not a communication terminal that can provide digital content. The authentication server device 10 transmits the authentication result of the communication terminal 30 to the communication terminal 30 (step S26). At this time, the authentication server device 10 may transmit the authentication result together with an authentication token indicating that the communication terminal 30 is capable of providing digital content.
[0038] The communication terminal 30 acquires the authentication result from the authentication server device 10 (step S27), and if the wireless communication device 40 to which the communication terminal 30 is connected is not authenticated, an alert screen indicating that the wireless communication device 40 is not authenticated is displayed (step S28), as shown in FIG. 4A. Furthermore, when the wireless communication device 40 to which the communication terminal 30 is connected is authenticated, the communication terminal 30 transmits a request for a content list page to the content server device 20 (step S29). At this time, the request includes an authentication token and information for identifying the facility (such as the facility name).
[0039] Upon receiving the request for the content list page, the content server device 20 performs an authentication check on the authentication server device 10 (step S30). At this time, the authentication token received from the communication terminal 30 is sent to the authentication server device 10. Next, the authentication server device 10 collates the authentication token received from the content server device 20 (step S31), and transmits the authentication result based on the authentication token to the content server device 0 (step S32). At this time, the authentication server device 10 may include the distribution expiration date of the digital content in the authentication result. With the above, the authentication operation of the authentication server device 10 is completed.
[0040] Upon receiving the authentication result from the authentication server device 10, the content server device 20 transmits a content list page (step S33). Finally, communication terminal 30 displays a content list page on display unit 31 as shown in Fig. 4B (step S34). At this time, display unit 31 of communication terminal 30 displays a list of digital content distribution services subscribed to by the facility where wireless communication device 40 to which communication terminal 30 is connected is located. Thereafter, the communication terminal 30 requests the desired content from the content server device 20 in response to the user's selection of content displayed on the content list page, receives the content, and displays it on the display unit 31 . This completes the display of the digital content.
[0041] By displaying digital content authenticated in this way on the communication terminal 30, for example, there is no need to stock magazines in the store, and the digital content can be displayed on the communication terminal 30 owned by the customer, improving the sense of security in terms of hygiene. Furthermore, when a global fixed IP address is used as an identification method, digital content can be displayed using a web browser, which is preferable because it is not necessary to install a dedicated application on the communication terminal 30.
[0042] (1.4) Effects of this embodiment This embodiment has the following advantages. (1) The authentication server device of this embodiment authenticates the wireless communication device using the global fixed IP address assigned to the wireless communication device to which the communication terminal is connected, and determines whether or not digital content can be delivered to the communication terminal. Therefore, it is possible to easily authenticate the wireless communication device to which the digital content is delivered, to which the communication terminal is connected, using the global fixed IP address, which is the one and only piece of information.
[0043] (2) In the authentication server device of this embodiment, the available time for providing digital content is stored for each facility that can provide digital content, and the transmission unit can transmit the expiration date for distribution of the digital content to the content server device. Therefore, the provision of digital content can be limited to a time limit during which it can be provided.
[0044] 2. Second embodiment The authentication server device and authentication method according to the second embodiment will be described below.
[0045] (2.1) Basic configuration of the authentication server device The authentication server device 110 according to the second embodiment differs from the authentication server device 10 in that the identification information used to authenticate the communication terminal 30 is the physical address (MAC address) of the wireless communication device 40 instead of the global fixed IP address of the wireless communication device 40 to which the communication terminal 30 is connected. The storage unit 13 of the authentication server device 110 stores the physical address (MAC address) of the wireless communication device 40 as identification information instead of the global fixed IP address. The communication terminal 30, the wireless communication device 40, and the content server device 20 operate in the same manner as in the first embodiment, except that the physical address (MAC address) of the wireless communication device 40 is used to authenticate the wireless communication device 40 instead of the global fixed IP address.
[0046] (2.2) Authentication method The authentication method executed by the authentication server device 110 is also the same as in the first embodiment, except that the physical address (MAC address) of the wireless communication device 40 is used to authenticate the wireless communication device 40 instead of the global fixed IP address.
[0047] (2.3) Effects of this embodiment In this embodiment, the wireless communication device is authenticated using the MAC address, which is unique information, and therefore has the same effects as the first embodiment.
[0048] 3. Third embodiment An authentication server device and an authentication method according to the third embodiment will be described below.
[0049] (3.1) Basic configuration of the authentication server device The authentication server device 210 will be described in detail below. The authentication server device 210 according to the third embodiment includes a receiving unit 11, a processing unit 12, a storage unit 13, and a transmitting unit 14, similar to the authentication server device 10. The authentication server device 210 according to the third embodiment differs from the authentication server device 10 in that the identification information used to authenticate the communication terminal 30 is the service identifier (SSID) of the wireless communication provided by the wireless communication device 40, instead of the global fixed IP address of the wireless communication device 40 to which the communication terminal 30 is connected.
[0050] As shown in FIG. 5, for example, the authentication server device 210 according to this embodiment acquires at least a service identifier (SSID), which is identification information, by accessing the authentication server device 10 after a digital content reception application installed in the communication terminal 30 is started and connected to wireless communication within the facility. The authentication server device 210 authenticates the communication terminal 30 if the acquired service identifier (SSID) matches a stored one. The content server device 20 displays the authentication result on the communication terminal 30 in accordance with the authentication result in the authentication server device 210. Note that, as shown in FIG. 5, the communication terminal 30 checks connection to wireless communication and permission to use location information according to a program before providing identification information to the authentication server device 210.
[0051] The authentication server device 210 according to the third embodiment can perform authentication without using a global fixed IP address. In recent years, the depletion of global fixed IP addresses has become a problem, and an increasing number of Internet service providers (ISPs) use dynamic (variable) IP addresses for Internet connections. Furthermore, allocating a global fixed IP address often requires an additional fee, and many facilities therefore provide Internet connections using dynamic (variable) IP addresses. The authentication server device 210 of the third embodiment performs authentication using a service identifier (SSID), which is preferable because it can easily perform authentication even for wireless communication devices 40 in facilities that provide Internet connections using dynamic (variable) IP addresses, making it easier to distribute digital content.
[0052] The following describes in detail the authentication server device 210 and the communication terminal 30. Note that the wireless communication device 40 and the content server device 20 are the same as those in the first embodiment, and therefore descriptions thereof will be omitted.
[0053] <Storage section> The storage unit 13 includes, as identification information, a service set identifier (SSID) of the wireless communication device 40 connected to the authentication server device 10. The service set identifier (SSID) is an identifier for wireless communication that complies with IEEE 802.11. The service set identifier (SSID) is, for example, an identification name of the access point that is the wireless communication device 40.
[0054] The memory unit 13 may store only the service set identifier (SSID) as identification information when the service set identifier (SSID) is identification information that can identify a single facility, i.e., when the same service set identifier (SSID) is not used in different facilities. Even if the same service set identifier (SSID) is not used in different facilities, the memory unit 13 may store the service set identifier (SSID) as identification information in association with information for identifying another facility (location information, facility name, etc.).
[0055] Furthermore, if the service set identifier (SSID) of wireless communication device 40 is the same in multiple facilities, i.e., if the same service set identifier (SSID) is used in different facilities, memory unit 13 needs to store the service set identifier (SSID) as identification information in association with location information of the facility that can provide digital content (location information such as the facility's address or latitude and longitude).
[0056] The global fixed IP address and MAC address used in the first and second embodiments are assigned by an Internet service provider (ISP) or the manufacturer of the wireless communication device 40 and cannot be changed by the facility that manages the wireless communication device 40. On the other hand, the service set identifier (SSID) used in this embodiment can be set or changed by the facility that manages the wireless communication device 40, and the same service set identifier (SSID) may be set in different facilities. In this case, the service set identifier (SSID) is no longer unique information for each facility, making it difficult to provide digital content distribution services to only some of these facilities (for example, only stores in the Kanto region or only large stores).
[0057] For this reason, when a service set identifier (SSID) is used as identification information for the wireless communication device 40, it is preferable to use the service set identifier (SSID) together with location information of the communication terminal 30 connected to the wireless communication device 40. In this case, it becomes possible to identify a facility where the wireless communication device 40 connected to the communication terminal 30 is located, and it is possible to determine whether the communication terminal 30 is connected to the wireless communication device 40 of a facility that has subscribed to a digital content distribution service.
[0058] Furthermore, the storage unit 13 may store, as identification information, facility information such as the company name or store name of the facility that can provide the digital content, in association with the service set identifier (SSID) and location information of the facility that can provide the digital content. The location information of the device acquired by the communication terminal 30 often cannot detect differences in the vertical position. For example, although it can detect that the communication terminal 30 is located within a building, it may not be possible to detect which floor of the building the communication terminal 30 is located on. For this reason, by using facility information such as the company name or store name for authentication, more accurate authentication is possible.
[0059] <Receiving section> The receiving unit 11 receives, as identification information, from the communication terminal 30 that requests the provision of digital content, a service set identifier (SSID) and location information of the communication terminal 30. The receiving unit 11 may also acquire, from the communication terminal 30 that requests the provision of digital content, facility information of the facility where the wireless communication device 40 to which the communication terminal 30 is connected is located.
[0060] <Processing section> The processing unit 12 compares the identification information (service set identifier (SSID) and location information of the communication terminal 30) received from the communication terminal 30 with the identification information (service set identifier (SSID) and location information of the facility) stored in the storage unit 13. If the comparison results in a match, the processing unit 12 authenticates the wireless communication device 40 to which the communication terminal 30 is connected. At this time, the stored location information of the facility and the location information of the communication terminal 30 do not need to match perfectly. For example, if the communication terminal 30 is located within an area with a radius of several tens of meters to approximately 100 meters around the facility, it is determined that the location information of the facility and the location information of the communication terminal 30 match. Furthermore, the processing unit 12 may compare the facility information acquired from the communication terminal 30 with the facility information stored in the storage unit 13 about facilities that can provide digital content.
[0061] <Communication terminal> The communication terminal 30 used in this embodiment transmits a service set identifier (SSID) to the authentication server device 210 via the wireless communication device 40. When the authentication server device 10 authenticates the wireless communication device 40 using the service set identifier (SSID) and location information of the communication terminal 30, the communication terminal 30 transmits location information of its own device to the authentication server device 210. The location information of the communication terminal 30 may be, for example, location information obtained by a Global Positioning System (GPS), or, if the communication terminal 30 is connected to a base station of a telecommunications carrier, location information obtained by base station positioning.
[0062] (3.2) Authentication method The authentication method executed by the authentication server device 210 is the same as that of the first embodiment, except that the wireless communication device 40 is authenticated using at least the service set identifier (SSID) of the wireless communication device 40 instead of the global fixed IP address. As shown in Fig. 6, in the authentication method executed by the authentication server device 210, permission to use location information is confirmed in the communication terminal 30 before providing identification information to the authentication server device 210. Furthermore, in this authentication method, a connection to wireless communication may be confirmed when the communication terminal 30 connects to the wireless communication device 40 in the facility.
[0063] (3.3) Effects of this embodiment This embodiment has the following advantages. (3) The authentication server device of this embodiment authenticates the wireless communication device using the service set identifier (SSID) of the wireless communication device to which the communication terminal is connected, and determines whether or not digital content can be delivered to the communication terminal. Therefore, even if a communication terminal is connected to a wireless communication device to which a dynamic (variable) IP address is assigned, it is possible to easily authenticate the wireless communication device.
[0064] (4) In the authentication server device of this embodiment, the wireless communication device is authenticated using the service set identifier (SSID) of the wireless communication device to which the communication terminal is connected, along with the location information of the communication terminal, and it is also possible to determine whether digital content can be delivered to the communication terminal. Therefore, even if the same service set identifier (SSID) is used by wireless communication devices in different facilities, it is possible to easily authenticate the wireless communication device.
[0065] 4. Fourth embodiment A wireless communication device 40 that is authenticated by the authentication server device 10 according to this embodiment is connected to the A content reception program executed by the communication terminal 30 will now be described. The communication terminal 30 receives digital content in accordance with a program that causes a computer to execute at least the following operations (A) to (D). The following program is non-temporarily recorded on a recording medium such as a hard disk drive or memory, or on an optical disc such as a DVD disc or Blu-ray (registered trademark). The following program may be distributed via the Internet. Furthermore, the following program may be recorded on a cloud server and executed via the Internet. Such a content receiving program may be executed by, for example, a dedicated application for receiving digital content. Alternatively, the content receiving program may have its functions incorporated into an application for a store, which is an example of a facility. Furthermore, such a content receiving program may be provided as a software development kit (SDK).
[0066] (A) Communicating with an authentication server device that authenticates that digital content can be provided to a communication terminal and a content server device that distributes digital content (B) Transmitting to the authentication server device identification information of the wireless communication device to which the communication terminal is connected or the wireless communication provided by the wireless communication device. (C) storing identification information capable of identifying one of a plurality of facilities capable of providing digital content, comparing the identification information transmitted from the communication terminal with the stored identification information, and receiving the result of authentication as to whether the communication terminal is a communication terminal capable of providing digital content from an authentication server device that authenticates the wireless communication device and determines that the communication terminal is a communication terminal capable of providing digital content if the comparison results in a match; (D) When it is determined that the communication terminal is a communication terminal capable of providing digital content, the communication terminal requests the content server device to distribute the digital content.
[0067] 5. Hardware configuration of the authentication server device FIG. 7 is a block diagram showing an example of a hardware configuration for realizing each functional unit of the authentication servers 10, 110, and 210. As shown in FIG. As shown in FIG. 7 , the authentication server devices 10, 110, and 210 are realized by a computing device 1000. The computing device 1000 is an information processing device including a processor 1001, a ROM (Read Only Memory) 1002, a RAM (Random Access Memory) 103, and an auxiliary storage device (memory) 1004. An output device 1011, an input device 1012, and a display device 1013 are connected to the computing device 1000 via, for example, an external interface (I / F) 1005. A computer 1014 is connected to the computing device 1000 via, for example, a communication interface (I / F) 1006. The output device 1011, the input device 1012, the display device 1013, and the computer 1014 are each provided with a user interface (not shown) for connection to the computing device 1000. Here, the hardware resources of each part of the computing device 1000 cooperate with a predetermined program to implement each function of the processing unit 12 of the authentication server devices 10, 110, and 210.
[0068] The processor 1001 is a processor that performs overall control of the authentication server devices 10, 110, and 210. The processor 1001 reads a content reception program stored in the ROM 1002 via the bus 1007, and controls the authentication server devices 10, 110, and 210 in accordance with the content reception program. The ROM 1002 stores a program for executing an identification code determination method. The RAM 1003 temporarily stores calculation data, various data input by an operator via the input device 1012, and the like.
[0069] The auxiliary storage device 1004 is backed up by, for example, a battery (not shown), and the stored state is maintained even when the power to the authentication server devices 10, 110, and 210 is turned off. The auxiliary storage device 1004 stores data input via the external interface 1005 and data generated by each process. The auxiliary storage device 1004 also stores input data input by an operator from the input device 1012, as well as various data input via the external interface 1005 and the communication interface 1006.
[0070] The output device 1011 outputs data to the arithmetic device 1000 via the external interface 1005. The control of photography by the output device 1011 may be performed by the arithmetic device 1000 of the authentication server device 10 executing a program, or may be performed under control from another device.
[0071] The input device 1012 is a keyboard, a pointing device, a voice input device such as a microphone, or the like, and inputs commands and input data based on the operator's operations to the arithmetic unit 1000 via the external interface 1005 . The display device 1013 is, for example, a liquid crystal display (LCD) or an organic electro-luminescence display (OLED), and receives and displays various data from the arithmetic device 1000 via the external interface 1005. The display device 1013 displays, for example, various data loaded onto the memory of the arithmetic device 1000, data obtained as a result of executing a program, a database stored in the storage unit 13, and the like.
[0072] The computer 1014 is connected to the arithmetic device 1000 via a communication interface 1006 and a network 1008. The computer 1014 is equipped with a display device and an input device (not shown), and can input commands and input data based on operator operations via the input device to the arithmetic device 1000 via the network 1008, and can receive various data from the arithmetic device 1000 and display it on the display device. The network 1008 may be either a wired network or a wireless network. When the network 1008 is a wireless network such as a wireless LAN, Bluetooth (registered trademark), or a mobile communication network, the authentication server device 10 can receive commands in real time from an operator in a remote location, such as outside the work area, and can display the execution status of programs and acquired data to the operator in the remote location.
[0073] Although the present disclosure has been described above using embodiments, the technical scope of the present disclosure is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. It is clear from the claims that such modifications and improvements can also be included in the technical scope of the present disclosure. [Explanation of symbols]
[0074] 10,110,210 Authentication server device 11 Receiving unit 12 Processing section 13 Storage section 14 Transmitter 20 Content server device 30 Communication terminal 31 Display section 40 Wireless communication equipment
Claims
1. a storage unit that stores identification information that can identify one of a plurality of facilities that can provide digital content; a receiving unit that receives, from a communication terminal that requests the provision of the digital content, identification information of a wireless communication device to which the communication terminal is connected or identification information of a wireless communication provided by the wireless communication device; a processing unit that compares the identification information received from the communication terminal with the identification information stored in the storage unit, and when the comparison results in a match, authenticates the wireless communication device and determines that the communication terminal is a communication terminal that can provide the digital content; a transmitting unit that transmits a result of the authentication performed by the processing unit to the communication terminal; Equipped with a content server device that distributes the digital content, connected via a network; the receiving unit receives a request for authentication check from the content server device when the wireless communication device to which the communication terminal is connected is authenticated and a request for a content list page is transmitted from the communication terminal to the content server device; In response to the request for authentication check, the processing unit transmits to the content server device via the transmission unit an authentication result indicating that the communication terminal that is the sender of the request for the content list page is a communication terminal that can provide the digital content. Authentication server device.
2. The storage unit stores, as the identification information, one of a global fixed IP address assigned to the wireless communication device in the one facility, a service set identifier (SSID) of the wireless communication device, and a physical address of the wireless communication device. The authentication server device according to claim 1 .
3. the storage unit stores, as the identification information, the service set identifier (SSID) and location information of the facility that can provide the digital content in association with each other; The receiving unit acquires, from the communication terminal, the service set identifier (SSID) of the wireless communication to which the communication terminal is connected and location information of the communication terminal; The processing unit compares the service set identifier (SSID) received from the communication terminal with the service set identifier (SSID) stored in the storage unit, and also compares location information of the communication terminal with location information of the facility that can provide the digital content stored in the storage unit. The authentication server device according to claim 2 .
4. the storage unit stores, as the identification information, the service set identifier (SSID), location information of the facility that can provide the digital content, and facility information of the facility that can provide the digital content in association with each other; The receiving unit further acquires, from the communication terminal, facility information of a facility in which the wireless communication device to which the communication terminal is connected is installed, The processing unit compares the facility information acquired from the communication terminal with the facility information of the facility that can provide the digital content stored in the storage unit.
4. The authentication server device according to claim 2 or 3.
5. If the result of the comparison is a match, the processing unit determines that the communication terminal is connected to the wireless communication provided by the wireless communication device of the facility that can provide the digital content; The transmission unit transmits to the communication terminal an authentication token indicating that the communication terminal is capable of providing the digital content. The authentication server device according to any one of claims 1 to 4.
6. When the receiving unit receives the authentication token from the content server device, the processing unit transmits, via the transmitting unit, authentication information indicating that the communication terminal has been authenticated to the content server device. The authentication server device according to claim 5 .
7. the storage unit stores, for each facility that can provide the digital content, a time period during which the digital content can be provided; The transmission unit transmits the distribution expiration date of the digital content to the content server device as the authentication information. The authentication server device according to claim 6.
8. An authentication method executed by an authentication server device that authenticates that digital content can be provided to a communication terminal, comprising: the authentication server device includes a storage unit; storing, in a storage unit, identification information that can identify one of a plurality of facilities that can provide the digital content; receiving, from the communication terminal that requests the provision of the digital content, identification information of a wireless communication device to which the communication terminal is connected or identification information of wireless communication provided by the wireless communication device; comparing the identification information received from the communication terminal with the identification information stored in the storage unit, and if the comparison results in a match, authenticating the wireless communication device and determining that the communication terminal is a communication terminal capable of providing the digital content; transmitting a result of the authentication to the communication terminal; the authentication server device is connected to a content server device that distributes the digital content via a network; The receiving includes receiving a request for authentication check from the content server device when the wireless communication device to which the communication terminal is connected is authenticated and a request for a content list page is transmitted from the communication terminal to the content server device; The transmitting step transmits, to the content server device, an authentication result indicating that the communication terminal that is the sender of the request for the content list page is a communication terminal that can provide the digital content in response to the request for authentication check. Authentication method.
9. communicating with an authentication server device that authenticates that digital content can be provided to the communication terminal and a content server device that distributes the digital content; transmitting, to the authentication server device, identification information of a wireless communication device to which the communication terminal is connected or of a wireless communication provided by the wireless communication device; receiving a result of authentication as to whether or not the communication terminal is a communication terminal capable of providing the digital content from the authentication server device, which stores identification information capable of identifying one of a plurality of facilities capable of providing the digital content, compares the identification information transmitted from the communication terminal with the stored identification information, and, if the comparison results in a match, authenticates the wireless communication device and determines that the communication terminal is a communication terminal capable of providing the digital content; transmitting a request for a content list page to the content server device when the communication terminal is determined to be a communication terminal capable of providing the digital content; transmitting a request for authentication check from the content server device to the authentication server device; performing an authentication check in the authentication server device; transmitting an authentication result from the authentication server device to the content server device; transmitting the content list page from the content server device to the communication terminal; When digital content is selected from the content list page on the communication terminal, a request is made to the content server device to distribute the digital content; A content receiving program that causes a computer to execute the above.
Citation Information
Patent Citations
Method for controlling distribution of digital content
JP2004157784A
Data distribution system, data distribution method, and distribution server
JP2013257834A
Application authentication system, radio communication system, management server, and authentication information issuing method
JP2016099765A
Content distribution method and content distribution system
JP2019003239A
Authentication server, user terminal, content server, control method for these, and computer program
US20180192103A1