Distribution server, distribution method, and program
The distribution server addresses the issue of reassigned mobile phone numbers by using a reference date to determine authentication methods, ensuring messages reach the right user with reduced user burden.
Patent Information
- Application Number
- JP2022010032
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-26
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-01-26
AI Technical Summary
Existing messaging systems face challenges in ensuring messages reach the intended recipient when a mobile phone number is reassigned, and frequent user authentication burdens the user.
A distribution server determines a reference date based on user authentication history to decide between strict and simpler authentication methods, reducing unnecessary authentication and preventing messages from reaching the wrong user.
Prevents messages from being delivered to unintended recipients while minimizing user authentication burden by selectively applying strict or simpler authentication methods based on the reference date.
Smart Images

Figure 0007790170000001 
Figure 0007790170000002 
Figure 0007790170000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a distribution server, a distribution method, and a program. [Background technology]
[0002] There are electronic notification services that notify information online. Patent Document 1 discloses a technology for sending information to an email address that is likely to be immediately accessible by the recipient of the notification.
[0003] Among these electronic notification services, messaging services that use mobile phone numbers as destinations are widespread. Examples of messaging services that use mobile phone numbers as destinations include RCS (Rich Communication Services). By using a mobile phone number as the destination, it is possible to send a message even if the recipient's email address is unknown. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-241732 Summary of the Invention [Problem to be solved by the invention]
[0005] When sending a message addressed to a mobile phone number, if the user has terminated their contract with the carrier that provides the mobile phone number, the mobile phone number may be assigned to another user. In this case, the message may not reach the intended user, but may reach a different user. Depending on the content of the message, some messages may be highly important, so it is desirable for the message to reach the intended user.
[0006] In order to prevent messages from being delivered to users other than the intended recipient, it is possible to perform user authentication on the communication terminal corresponding to the recipient to verify that the subscriber of the telephone number is the user to whom the message is to be sent. However, there is a problem in that performing user authentication every time a message is sent places a heavy burden on the user.
[0007] The present invention has been made in consideration of the above circumstances, and its purpose is to provide a distribution server, a distribution method, and a program that can prevent messages from being delivered to users other than the intended recipient and reduce the burden on users. [Means for solving the problem]
[0008] In order to solve the above-mentioned problems, the distribution server of the present invention has a determination unit that determines a reference date for a communication terminal corresponding to a telephone number of a destination to which a message is to be sent based on a user authentication history that determines whether the subscriber of the telephone number is the user to whom the message is to be sent, and determines whether to perform the user authentication based on a first method based on the determined reference date, or to perform the user authentication based on a second method that is simpler than the first method, and an authentication unit that performs the user authentication based on the determination result by the determination unit.
[0009] Furthermore, in order to solve the above-mentioned problems, the distribution method of the present invention is a distribution method performed by a computer that is a distribution server, in which a judgment unit determines a reference date for a communication terminal corresponding to a telephone number of a destination to which a message is to be sent, based on a user authentication history that determines whether the subscriber of the telephone number is the user to whom the message is to be sent, and determines whether to perform the user authentication based on a first method or a second method that is simpler than the first method based on the determined reference date, and an authentication unit performs the user authentication based on the judgment result by the judgment unit.
[0010] In addition, in order to solve the above-mentioned problems, the present invention is a program for causing a computer to operate as the distribution server described above, and for causing the computer to function as each part of the distribution server. [Effects of the Invention]
[0011] According to the present invention, it is possible to prevent a message from being delivered to a user other than the intended addressee, and to reduce the burden on the user. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a schematic block diagram showing an example of the configuration of an information processing system 1 according to an embodiment. [Figure 2] 1 is a block diagram showing an example of the configuration of a distribution server 10 according to an embodiment. [Figure 3A] FIG. 2 is a diagram showing an example of authentication history information 120 according to the embodiment. [Figure 3B] FIG. 10 is a diagram showing another example of authentication history information 120 according to the embodiment. [Figure 4] 2 is a diagram illustrating a process performed by the distribution server 10 according to the embodiment. FIG. [Figure 5] 3 is a flowchart showing the flow of processing performed by the distribution server 10 according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0014] 1 is a schematic block diagram showing an example of the configuration of an information processing system 1 according to an embodiment. The information processing system 1 includes, for example, a distribution server 10, a company server 20, a telecommunications carrier server 30 (telecommunications carrier servers 30A and 30B), a communication terminal 40, and an authentication server 50.
[0015] The distribution server 10 is a server device managed by a business that provides a service for transmitting messages to the communication terminal 40. The distribution server 10 transmits (distributes) messages to the communication terminal 40 via the telecommunications carrier server 30. The distribution server 10 transmits messages using RCS (Rich Communication Services) or SMS (Short Message Service), which are message services addressed to telephone numbers. The distribution server 10 communicates with the company server 20 and the telecommunications carrier server 30 via wireless or wired communication. The service of sending messages to communication terminal 40 may be performed by distribution server 10, but may also be performed by corporate server 20. For example, corporate server 20 equipped with the functions of distribution server 10 may be operated by a company. In this case, the company of corporate server 20 can communicate with telecommunications carrier server 30 and send messages without going through the operator of distribution server 10. Furthermore, although the distribution server 10 may manage the messages notified to the communication terminal 40, the communication carrier server 30 may also manage the messages. For example, the communication carrier server 30 may be operated by a company (communications carrier) that has the functions of the distribution server 10 installed. In this case, the communication carrier server 30 can send messages to the communication terminal 40 in response to a request from the company server 20.
[0016] The corporate server 20 is a server device managed by a requester who requests the information processing system 1 to deliver a message. The requester is, for example, a company or organization, such as a bank or insurance company, that provides information to a destination user. The corporate server 20 communicates with the delivery server 10 via wireless or wired communication.
[0017] The telecommunications carrier server 30 is a server device managed by a telecommunications carrier. The telecommunications carrier is, for example, an MNO (Mobile Network Operator) that provides communication services using telephone numbers to the communication terminal 40 using communication lines that it owns or operates. The communication services include communication using RCS and SMS. The telecommunications carrier server 30 performs wireless or wired communication between the distribution server 10 and the communication terminal 40. In response to a distribution request from the distribution server 10, the telecommunications carrier server 30 transmits a message using RCS or SMS to the communication terminal 40. When there are multiple telecommunications carriers, a telecommunications carrier server 30 is provided for each telecommunications carrier. The telecommunications carrier server 30A is managed by a first telecommunications carrier, and the telecommunications carrier server 30B is managed by a second telecommunications carrier. Hereinafter, when the telecommunications carrier server is not particularly identified, it will be referred to as the telecommunications carrier server 30.
[0018] The communication terminal 40 is a communication device that can be associated with a telephone number, such as a smartphone or a mobile phone. A contract is made by a user or the like with a carrier of the carrier server 30 to use a communication service using the communication terminal 40. The communication terminal 40 is capable of communicating using a communication service provided by the contracted carrier. A telephone number is assigned to the communication terminal 40, and the communication terminal 40 has a function of communicating with this telephone number as a destination, i.e., communicating using RCS or SMS. The communication terminal 40 has, for example, a display unit such as a liquid crystal display and an operation unit such as a touch panel that accepts operations by a user. The communication terminal 40 communicates using a communication network with the communication carrier server 30 and the communication terminal 40 as communication partners. The user is, for example, a consumer.
[0019] The authentication server 50 is, for example, a server device that provides a public personal authentication service operated by J-LIS (Japan Agency for Local Government Information Systems).
[0020] FIG. 2 is a block diagram showing an example of the configuration of the distribution server 10 according to the embodiment. As shown in FIG. 2, the distribution server 10 includes a communication unit 11, a storage unit 12, and a control unit 13. The communication unit 11 communicates with the company server 20, the telecommunications carrier server 30, and the authentication server 50. The storage unit 12 stores various information, for example, authentication history information 120. The authentication history information 120 is information indicating a history of user authentication. User authentication is a process of determining, for a communication terminal 40 corresponding to a telephone number of a destination to which a message is to be sent, whether the subscriber of that telephone number is the user to whom the message is to be sent. Hereinafter, user authentication may also be referred to as identity verification. The authentication history information 120 may be stored in the company server 20. Alternatively, the authentication history information 120 may be stored in a server separate from the distribution server 10 and the company server 20. If the authentication history information 120 is stored in a server other than the distribution server 10, the storage unit 12 does not need to store the authentication history information 120. The storage unit 12 may also be configured to store matching information used for user authentication. The matching information is correct answer information that is matched when performing user authentication. The matching information may be, for example, user information that is information about the user, such as a telephone number, name, address, date of birth, and gender. This matching information may be stored in the company server 20. The matching information may also be stored in a server separate from the distribution server 10 and the company server 20. If the matching information is stored in a server other than the distribution server 10, the storage unit 12 does not need to store the matching information.
[0021] The storage unit 12 is configured by a storage medium such as a hard disk drive (HDD), a flash memory, an electrically erasable programmable read-only memory (EEPROM), a random access read / write memory (RAM), a read-only memory (ROM), or any combination of these storage media. The storage unit 12 may be, for example, a nonvolatile memory.
[0022] The control unit 13 includes, for example, a determination unit 130 and an authentication unit 131. The judgment unit 130 judges whether or not to perform user authentication on the destination communication terminal 40 before sending a message generated in response to a message sending request from the enterprise server 20 to the communication terminal 40 via the communication carrier server 30. The determination unit 130 determines the reference date based on the user authentication history. The reference date is a date that serves as a reference for determining whether or not to perform user authentication.
[0023] If the result of user authentication is OK, the determination unit 130 sets the date on which a "certain period (e.g., three months)" has elapsed since the date of user authentication as the reference date. The result of user authentication being OK means that the user authentication determines that the subscriber of the telephone number of the destination to which the message is to be sent is the user to whom the message is to be sent.
[0024] Furthermore, the "certain period" here may be determined arbitrarily. For example, a telecommunications carrier may operate in such a way that, after a predetermined period (e.g., three months or more) has passed since a user canceled their mobile phone contract and the phone number has been unused, the phone number is assigned to another user. The period until the phone number is reused after such cancellation is defined as the "certain period," and the determination unit 130 sets the date on which the certain period has passed since the date of initial user authentication as the reference date. Note that, since the period until the phone number is reused after cancellation is considered to differ depending on the telecommunications carrier, the above-mentioned "certain period" may be set for each telecommunications carrier.
[0025] When a message is notified to communication terminal 40 for the first time, determination unit 130 determines that user authentication based on the first method should be performed as initial user authentication. If the result of the initial user authentication is OK, determination unit 130 sets a date a certain period after the date on which the user authentication was performed as the reference date. When notifying a message for the second or subsequent times, the determination unit 130 determines whether to perform user authentication based on the first method based on the reference date, or to perform user authentication based on the second method, which is simpler than the first method. For example, when notifying a message after the reference date, the determination unit 130 determines to perform user authentication based on the first method. On the other hand, when notifying a message before the reference date, the determination unit 130 determines to perform user authentication based on the second method.
[0026] The first method here is a strict authentication method, such as public personal authentication, online personal authentication, carrier authentication, customer master authentication, etc. Which of these authentication methods to use for user authentication may be selectable by the distribution server 10 or the user, may be determined by the company that manages the company server 20, or may be determined in advance as one of the authentication methods.
[0027] Public personal authentication is an authentication method that verifies the identity of a user using a personal card, which is a public certificate. More specifically, public personal authentication is an authentication method that uses JPKI (Public Personal Authentication Service). This public personal authentication uses a personal card. The personal card is, for example, an IC (integrated circuit card) card that can store personal information. More specifically, a personal card is a My Number card. When performing public personal authentication, the user enters a password for using an electronic signature, and the My Number card is read by a communication terminal 40. This causes the authentication server 50 to process the public personal authentication. If the validity is confirmed, four basic pieces of information, such as the user's name, address, date of birth, and gender, can be obtained. Alternatively, the user may be identified by confirming the validity of the serial number of the electronic certificate used in the My Number card or its alternative information. Online personal authentication is an authentication method that verifies an individual's identity online based on information that is different from that on a personal card and that includes at least an image of the individual's appearance (for example, face). Online personal authentication is also called "online identity verification using other official documents." The technology used for online personal authentication may be eKYC (electronic Know Your Customer). Online personal authentication may also use the My Number card described above to obtain information (four basic pieces of information) embedded in the IC chip. Carrier authentication is an authentication method for verifying identity using carrier contract information relating to the contract between the contracted user and a telecommunications carrier of a communication terminal that provides communication services using a telephone number. Customer master authentication is an authentication method that uses a customer master managed by the company that is the sender of the message to verify the identity of the sender.
[0028] The second method here is simpler than the first method. The second method is, for example, a method that uses a code (for example, a four-digit PIN code) that is previously determined between the user and distribution server 10. In this case, if the code entered by the user into communication terminal 40 matches the code previously stored in distribution server 10, it is determined that the subscriber of the telephone number of the destination to which the message is to be sent is the destination user to whom the message is to be sent.
[0029] Alternatively, the second method may be a method using a confirmation message. A confirmation message is a message sent before the message requested by the requester is sent, and may contain phrases such as "We have an announcement to make. We will notify you after this message." When the confirmation message sent to communication terminal 40 is received, it indicates that at least the line is open and the telephone number has not been canceled. From this perspective, when a confirmation message is received, it may be assumed that the telephone number corresponding to communication terminal 40 has not been canceled and that communication terminal 40 maintains that telephone number, and it may be determined that the subscriber of the telephone number of the destination to which the message is to be sent is the user to whom the message is to be sent. As a second method, a method of sending the main text (the message requested by the requester) without notifying a confirmation message may be adopted. If the result of user authentication at the time of the previous notification was OK and a certain period of time has not passed since the previous notification, the line is open, that is, if the main text is received by communication terminal 40, it can be assumed that the telephone number has not been canceled and that the subscriber of that telephone number is the user.
[0030] The determination unit 130 may change the reference date based on the result of user authentication.
[0031] For example, when notifying a message for the second or subsequent time, if the result of user authentication based on the first method is OK, the judgment unit 130 changes the base date and sets the changed base date to a date that is a certain period after the date on which user authentication based on the first method was performed. Alternatively, when notifying a message for the second or subsequent time, if the result of user authentication based on the second method is OK, the judgment unit 130 may change the reference date and set the changed reference date to a date that is a certain period after the date on which user authentication based on the second method was performed.
[0032] The determination unit 130 may determine to perform user authentication according to the expiration date of the personal identification document (e.g., My Number card) used for user authentication by the first method. For example, if the date of sending a message is past the expiration date of the personal identification document, the determination unit 130 determines to perform user authentication even if the date of sending the message is before the reference date.
[0033] The authentication unit 131 performs user authentication according to the determination result by the determination unit 130 . When the determination unit 130 determines that user authentication using the first method should be performed, the authentication unit 131 performs any one of public personal authentication, online personal authentication, carrier authentication, and customer master authentication. For example, the authentication unit 131 compares the matching information with the authentication information, and if the verification conditions are met, determines that the user of the communication terminal 40 is the user to whom the message is to be sent, that is, the result of user authentication is OK. The authentication information is information about the user obtained in response to an operational input by the user in order to verify whether the user of the communication terminal 40 is the user to whom a message is to be sent. The verification condition is a condition for determining that the user of the communication terminal 40 is the user to whom a message is to be sent, and for example, the content of any predetermined item, such as name, address, date of birth, or gender, included in the verification information matches the content of the predetermined item included in the authentication information. All or part of the user authentication according to the first method may be performed by the company server 20, the carrier server 30, or the authentication server 50.
[0034] When the determination unit 130 determines that user authentication should be performed using the second method, the authentication unit 131 performs user authentication using a method simpler than the first method. For example, the authentication unit 131 displays a screen on the communication terminal 40 for prompting the user to input a code, and acquires the code entered by the user. The authentication unit 131 compares the acquired code with a code that has been previously determined between the user and the distribution server 10 and stored in the storage unit 12. When the two codes match, the authentication unit 131 determines that the user of the communication terminal 40 is the user to whom the message is to be sent, that is, that the result of user authentication is OK. All or part of the user authentication according to the second method may be performed by the company server 20, the carrier server 30, or the authentication server 50.
[0035] If the result of the user authentication performed by the authentication unit 131 is OK, the control unit 13 transmits a message to the communication terminal 40.
[0036] 3A is a diagram showing an example of authentication history information 120 according to the embodiment. The authentication history information 120 is generated for each telephone number of a destination to which a message is to be sent.
[0037] The authentication history information 120 includes, for example, information corresponding to a user ID, a mobile phone number, a reference date, a reference date setting date and time, user authentication by the first method, and user authentication by the second method. The user ID is information that identifies the user who sends the message. The mobile phone number is the phone number of the mobile phone subscribed to by the user. The reference date indicates the reference date determined based on the results of user authentication. The reference date setting date and time indicates the date and time when the reference date was set. User authentication by the first method includes information corresponding to each of the following items: final authentication method, final authentication result, and authentication date and time. The final authentication method indicates the method of user authentication by the first method that was performed last time, for example, public personal authentication, online personal authentication, carrier authentication, or customer master authentication. The final authentication result indicates the authentication result of user authentication by the first method that was performed last time, for example, whether authentication was successful or not. The authentication date and time indicates the date and time of user authentication by the first method that was performed last time. User authentication by the second method includes information corresponding to the same items as the user authentication by the first method described above. The final authentication method indicates the method of the previous user authentication by the second method, for example, a method using a code (e.g., a 4-digit PIN code), a method using a confirmation message, or a method of sending a text message without notifying a confirmation message. The final authentication result indicates the authentication result of the previous user authentication by the second method. The authentication date and time indicates the date and time of the previous user authentication by the second method.
[0038] For example, if no information indicating a date is stored in the base date, the determination unit 130 determines that the message to be notified this time is the first notification, that is, the first message to be notified to the user's phone number. In this case, the determination unit 130 determines to perform user authentication using the first method. The authentication unit 131 performs user authentication using the first method. The determination unit 130 stores the method of the user authentication performed this time in the "final authentication method" of the "user authentication using the first method." The determination unit 130 stores the result of the user authentication performed this time in the "final authentication result" of the "user authentication using the first method." The determination unit 130 stores the date and time of the user authentication performed this time in the "authentication date and time" of the "user authentication using the first method." The determination unit 130 stores the base date determined according to the result of the user authentication in the "base date." If the base date is changed (updated), the determination unit 130 stores the date and time when the base date was changed in the "base date setting date and time."
[0039] For example, if information indicating a date is stored on the reference date, the determination unit 130 determines that the message to be notified this time is not the first notification. In this case, the determination unit 130 determines whether to perform user authentication using the first method or the second method based on the information stored on the reference date. If the message is to be notified after the reference date, the determination unit 130 determines to perform user authentication based on the first method, and if the message is to be notified before the reference date, the determination unit 130 determines to perform user authentication based on the second method. When performing authentication using the second method, the authentication unit 131 performs user authentication using the second method. The judgment unit 130 stores the method of the user authentication performed this time in the "final authentication method" of "user authentication using the second method." The judgment unit 130 stores the result of the user authentication performed this time in the "final authentication result" of "user authentication using the second method." The judgment unit 130 stores the date and time when the user authentication was performed this time in the "authentication date and time" of "user authentication using the second method." The judgment unit 130 stores the base date determined according to the result of the user authentication in the "base date." If the base date is changed (updated), the judgment unit 130 stores the date and time when the base date was changed in the "base date setting date and time." Note that if authentication is performed using the second method, the base date may not be updated. When performing authentication using the first method, the authentication unit 131 performs user authentication using the first method. As in the case of the first notification, the determination unit 130 stores the method of user authentication performed this time, the authentication result, and the authentication date and time in each item of "user authentication using the first method." Also, as in the case of the first notification, the determination unit 130 stores the base date determined based on the result of user authentication in "base date." If the base date is changed (updated), the determination unit 130 stores the date and time when the base date was changed in "base date setting date and time."
[0040] 3B is a diagram showing another example of the authentication history information 120 according to the embodiment. The authentication history information 120 is generated for each telephone number of a destination to which a message is to be sent.
[0041] The authentication history information 120 includes, for example, a user ID, a mobile phone number, a reference date, and information corresponding to each of a plurality of messages (message 1, message 2, ...). The user ID is information that identifies the user who sends the message. The mobile phone number is the phone number of the mobile phone subscribed to by the user. The reference date indicates a reference date determined based on the result of user authentication. 3A and 3B, the base date may be stored in the distribution server 10, or may be transmitted to the company server 20 so that the base date is stored in the company server 20. A uniform base date may be adopted regardless of the request source, or an individual base date may be used depending on the request source.
[0042] The message includes, for example, information corresponding to the notification date, first flag, reception flag, and user authentication. The notification date indicates the date on which the message was notified. The first flag indicates whether the message is the first to be notified to the user's phone number. The reception flag indicates whether or not a confirmation message has been received when the confirmation message has been sent to the user's telephone number. The user authentication indicates the result of the user authentication. For example, the user authentication stores information corresponding to the authentication type and the authentication result. The authentication type indicates the type of user authentication that was performed. The authentication result indicates whether the result of the user authentication was OK or NG.
[0043] For example, if the first-time flag indicates that the message is notified for the first time, the determination unit 130 determines that user authentication should be performed using the first method. In this case, the determination unit 130 stores the type of user authentication using the first method in the authentication type. The authentication unit 131 performs user authentication using the first method. The determination unit 130 stores the result of the user authentication performed by the authentication unit 131 in the authentication result, and stores the reference date determined according to the result of the user authentication. For example, if the first-time flag indicates that the message is not the first time it has been notified, the determination unit 130 determines to perform user authentication using the second method based on the information stored on the reference date. In this case, the determination unit 130 stores the type of user authentication using the second method in the authentication type. The authentication unit 131 performs user authentication using the second method. The determination unit 130 stores the result of the user authentication performed by the authentication unit 131 in the authentication result, and stores the reference date determined according to the result of the user authentication. For example, if the first-time flag indicates that the message is not the first time it has been notified, the determination unit 130 determines to perform user authentication using the first method based on the information stored on the reference date. In this case, the determination unit 130 stores the type of user authentication using the first method in the authentication type. The authentication unit 131 performs user authentication using the first method. The determination unit 130 stores the result of the user authentication performed by the authentication unit 131 in the authentication result, and stores the reference date determined according to the result of the user authentication.
[0044] FIG. 4 is a diagram illustrating the processing performed by the distribution server 10 according to the embodiment. FIG. 4 schematically illustrates the dates on which messages indicated by notifications 1 to 5 were notified and the processing performed. In the example shown in this figure, the fixed period is set to three months. In other words, if the result of user authentication is OK, the base date will be three months after the date on which the user authentication was performed.
[0045] Notification 1 indicates that the first notification was sent on October 1, 2021. Because Notification 1 is the first notification, distribution server 10 performs user authentication using the first method. If the result of user authentication is OK, distribution server 10 sets the base date to January 1, 2022, three months after October 1, 2021. Notification 2 indicates that the second notification was sent on November 5, 2021. Because notification 2 was sent before the reference date, the distribution server 10 performs user authentication using the second method. The distribution server 10 may change the base date. Specifically, if the result of user authentication using the second method is OK, the distribution server 10 may change the base date from November 5, 2021 to February 5, 2022, three months later. Note that the example in this figure shows a case where the base date is not changed. Notification 3 indicates that the third notification was sent on December 4, 2021. Because notification 3 is a notification sent before the reference date, the distribution server 10 performs user authentication using the second method. The distribution server 10 may change the base date. Specifically, if the result of user authentication using the second method is OK, the distribution server 10 may change the base date from December 4, 2021 to March 4, 2022, three months later. Note that the example in this figure shows a case where the base date is not changed.
[0046] Notification 4 indicates that the fourth notification was sent on January 2, 2022. Because notification 4 is sent after the reference date, distribution server 10 performs user authentication using the first method. If the result of user authentication is OK, distribution server 10 sets the reference date to April 2, 2022, three months after January 2, 2022. Notification 5 indicates that the fifth notification was sent on February 3, 2022. Because notification 5 is a notification sent before the reference date, the distribution server 10 performs user authentication using the second method. The distribution server 10 may change the base date. Specifically, if the result of user authentication using the second method is OK, the distribution server 10 may change the base date from February 3, 2022 to May 3, 2022, which is three months later.
[0047] FIG. 5 is a flow diagram illustrating the flow of processing performed by the distribution server 10 according to the embodiment.
[0048] First, the distribution server 10 receives a message notification instruction (step S10). Next, the distribution server 10 determines whether the message to be notified this time is the first notification (step S11). If it is the first notification, the distribution server 10 performs user authentication using a first method (step S12). The distribution server 10 determines whether the result of the user authentication using the first method is OK (step S13). If the result is OK, the distribution server 10 sends the message, sets the reference date to a date a certain period (e.g., three months) after the date of user authentication (step S14), and ends the process.
[0049] On the other hand, if it is determined in step S11 that the notification is not the first time, the distribution server 10 determines whether the reference date has passed (step S15). If the reference date has passed, the distribution server 10 executes the process shown in step S12. If the reference date has not passed, the distribution server 10 performs user authentication using the second method (step S16). The distribution server 10 determines whether the result of the user authentication using the second method is OK (step S17), and if the result is OK, sends the message (step S18) and ends the process.
[0050] If the authentication result is NG in step S13 or step S17, the distribution server 10 ends the process without sending a message. Alternatively, the distribution server 10 may send a message to the communication terminal 40 indicating that the user's identity could not be confirmed through user authentication.
[0051] In step S18, the distribution server 10 may change the base date. In this case, the distribution server 10 sets the base date to a date that is a certain period (for example, three months) after the date on which the confirmation message is received.
[0052] As described above, the distribution server 10 of the embodiment includes a determination unit 130 and an authentication unit 131. The determination unit 130 determines a reference date according to a user authentication history (for example, authentication history information 120). User authentication is a process of determining whether the subscriber of a telephone number of a communication terminal corresponding to a telephone number of a destination to which a message is to be sent is the user to whom the message is to be sent. Based on the determined reference date, the determination unit 130 determines whether to perform user authentication based on a first method or a second method that is simpler than the first method. The authentication unit 131 performs user authentication according to the determination result by the determination unit 130. As a result, the distribution server 10 of the embodiment can perform either strict authentication or simple authentication depending on the user authentication history. By performing strict authentication, it is possible to prevent messages from being delivered to users other than the intended users. Furthermore, by performing simple authentication, it is possible to reduce the burden associated with user authentication. Therefore, it is possible to prevent messages from being delivered to users other than the intended users and to reduce the burden associated with user authentication.
[0053] Furthermore, in the distribution server 10 of this embodiment, the determination unit 130 determines that user authentication based on the second method should be performed on messages sent before the reference date. The determination unit 130 determines that user authentication based on the first method should be performed on messages sent after the reference date. If the determination unit 130 determines that the result of user authentication is OK (that the subscriber of the telephone number is the user), it changes the reference date to a date that is a certain period (e.g., three months) after the date of user authentication. This allows the distribution server 10 of this embodiment to perform simple authentication if it is within a certain period after strict authentication, thereby achieving the same effects as those described above.
[0054] Furthermore, in the distribution server 10 of this embodiment, when a message (e.g., a confirmation message) sent to the communication terminal 40 is received by the communication terminal 40 as user authentication based on the second method, the determination unit 130 determines that the result of the user authentication is OK (that the subscriber of the telephone number is the user). Alternatively, as user authentication based on the second method, the distribution server 10 determines that the subscriber of the telephone number is the user, and sends the main text (the message requested by the requester) without notifying the confirmation message. This makes it possible to confirm that the line is open and the telephone number has not been canceled, with almost no burden on the user. Therefore, the same effects as those described above are achieved.
[0055] In the above description, an example was given in which the reference date is set to the date on which a certain period of time (e.g., three months) has elapsed since the date on which user authentication was performed. However, this is not limiting. The reference date may be set arbitrarily based on the date on which user authentication was performed. For example, if the result of user authentication is OK, the date on which the user authentication was performed may be set as the "reference date." Then, if a certain period of time (e.g., three months) has elapsed since the date on which user authentication was performed, which is the "reference date," user authentication may be performed using the first method, and if the certain period of time has not elapsed, user authentication may be performed using the second method.
[0056] The information processing system 1 and the distribution server 10 in the above-described embodiment may be implemented in whole or in part by a computer. In this case, a program for implementing the functions may be recorded on a computer-readable recording medium, and the program may be loaded into the computer system and executed. Note that the term "computer system" as used herein includes hardware such as an OS and peripheral devices. Furthermore, the term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as hard disks built into the computer system. Furthermore, the term "computer-readable recording medium" may also include devices that dynamically store programs for a short period of time, such as communication lines used when transmitting programs via networks such as the Internet or telephone lines, or devices that store programs for a fixed period of time, such as volatile memory within the computer system serving as the server or client. The program may be for implementing some of the functions described above, or may be capable of implementing the functions in combination with a program already stored in the computer system, or may be implemented using a programmable logic device such as an FPGA (Field Programmable Gate Array).
[0057] Although an embodiment of the present invention has been described above in detail with reference to the drawings, the specific configuration is not limited to this embodiment, and includes designs within the scope of the gist of the present invention. [Explanation of symbols]
[0058] 1...information processing system, 10...distribution server, 20...company server, 30 (30A, 30B)...telecommunications carrier server, 40...communications terminal, 11...communication unit, 12...storage unit, 120...authentication history information, 13...control unit, 130...determination unit, 131...authentication unit
Claims
1. a determination unit that determines a reference date according to a history of user authentication for a communication terminal corresponding to a telephone number of a destination to which a message is to be sent, and determines whether to perform the user authentication based on a first method or a second method that is simpler than the first method, based on the determined reference date; an authentication unit that performs the user authentication in accordance with the determination result by the determination unit; A distribution server having the above configuration.
2. the determination unit determines to perform the user authentication based on the second method for messages sent before the reference date, and determines to perform the user authentication based on the first method for messages sent after the reference date, and when it is determined as a result of the user authentication that the subscriber of the telephone number is the user, changes the reference date to a date that is a certain period after the date on which the user authentication was performed. The distribution server according to claim 1 .
3. the determination unit determines, as the user authentication based on the second method, that a subscriber of the telephone number is the user when a message sent to the communication terminal is received by the communication terminal; 3. The distribution server according to claim 1 or 2.
4. A distribution method performed by a computer that is a distribution server, a determination unit determines a base date according to a history of user authentication for a communication terminal corresponding to a telephone number of a destination to which a message is to be sent, the user authentication determining whether the subscriber of the telephone number is a user to whom the message is to be sent, and determines whether to perform the user authentication based on a first method or a second method that is simpler than the first method based on the determined base date; an authentication unit that performs the user authentication in accordance with the determination result by the determination unit; Delivery method.
5. 4. A program for causing a computer to operate as the distribution server according to claim 1, wherein the program causes the computer to function as each unit included in the distribution server.
Citation Information
Patent Citations
E-mail sender
JP2007241732A
Method for generating authenticated electronic contract by customer of communication business company
JP2016143188A
API providing system, authentication server, API providing method, and program
JP2019164590A
Server device, control method and program
JP2021086270A
Information processing apparatus and information processing method
JP2022054390A