Information systems, login control devices, change devices, and programs

The information system facilitates the addition of new login targets and modification of authentication information by using a separate change device, addressing the inefficiencies in existing systems by allowing seamless integration and management of user access without altering the login control device.

JP7853674B2Active Publication Date: 2026-04-30ENCOURAGE TECH
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
ENCOURAGE TECH
Filing Date
2022-02-15
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

Existing login control devices require significant changes or additional processing when adding new login targets or changing authentication information, making it difficult to manage user access efficiently.

Method used

An information system with a login control device and a modification device that allows for seamless addition of new login targets and modification of authentication information without altering the login control device, using a separate change device to manage authentication changes through a login instruction receiving unit, support unit, and modification processing units.

Benefits of technology

Enables easy addition of new login targets and modification of authentication information without requiring changes to the login control device, ensuring efficient user access management and timely updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007853674000001
    Figure 0007853674000001
  • Figure 0007853674000002
    Figure 0007853674000002
  • Figure 0007853674000003
    Figure 0007853674000003
Patent Text Reader

Abstract

To provide an information system that can log in to a login target without inputting authentication information corresponding to the login target, and that does not require major changes or additional processing to a login control apparatus when adding a new target to be logged in.SOLUTION: An information system comprises a login control apparatus, a change apparatus, and a terminal apparatus. The login control apparatus includes a login instruction reception unit and a support unit. The login instruction reception unit receives a login instruction corresponding to a user identifier and a target identifier from the terminal apparatus. The support unit performs support processing for login to a target identified by the target identifier by a user of the terminal apparatus identified by the user identifier, using authentication information changed by the change apparatus. The change apparatus acquires new authentication information, and performs change processing for changing the authentication information of the user corresponding to the login instruction to the new authentication information.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information system or the like that can log in to a login target without inputting authentication information corresponding to the login target.

Background Art

[0002] Conventionally, there has been a login control device that can log in to a login target without inputting authentication information corresponding to one or more login targets (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the prior art, when newly adding a target for logging in using a login control device, significant changes or additional processing to the login control device were required. Also, in the prior art, it was not possible to easily change the authentication information of login targets managed by a login control device that supports each user to be able to log in to one or more login targets without inputting authentication information (for example, authentication information).

Means for Solving the Problems

[0005] The first information system of this invention is an information system having a login control device and a modification device, and is an information system that supports login from a terminal device to one or more targets, wherein the login control device comprises a login instruction receiving unit that receives a login instruction from a terminal device corresponding to a user identifier and a target identifier, and a support unit that performs support processing for a user of a terminal device identified by a user identifier to log in to a target identified by a target identifier using authentication information corresponding to the target identifier and user identifier corresponding to the login instruction, which has been modified by the modification device, and the modification device comprises a first new authentication information acquisition unit that acquires new authentication information corresponding to a target identifier and a user identifier, and a modification unit that performs modification processing to change the authentication information of a user identified by a user identifier in the target identified by the target identifier to the new authentication information.

[0006] With this configuration, when adding a new user to log in, it is not necessary to make significant changes to the login control device or add any processing steps.

[0007] Furthermore, the information system of this second invention, compared to the first invention, comprises a login control device further comprising a second new authentication information acquisition unit that acquires new authentication information corresponding to a user identifier and a target identifier, and a change request transmission unit that transmits a change request having the new authentication information acquired by the second new authentication information acquisition unit to a change device, the change device further comprising a change request receiving unit that receives the change request, and the first new authentication information acquisition unit acquires the new authentication information contained in the change request received by the change request receiving unit.

[0008] With this configuration, when adding a new user to log in, it is not necessary to make significant changes to the login control device or add any processing steps.

[0009] Furthermore, the information system of this third invention is an information system in which, compared to the first or second invention, the modification unit acquires the administrator identifier and administrator authentication information of the target, and performs modification processing using the administrator identifier, administrator authentication information and new authentication information.

[0010] This configuration allows for easy modification of authentication information for the target system.

[0011] Furthermore, the information system of this fourth invention is an information system in which, with respect to any one of the first to third inventions, the modification part performs modification processing when predetermined conditions are met.

[0012] This configuration allows the authentication information to be easily changed at the appropriate time.

[0013] Furthermore, the information system of this fifth invention is an information system in which, compared to the fourth invention, the predetermined condition is that a change request is received in response to the login instruction receiving unit receiving a login instruction from a terminal device.

[0014] This configuration allows the authentication information to be changed at the appropriate time.

[0015] Furthermore, the information system of this sixth invention is an information system in which, unlike the fourth invention, predetermined conditions are met at predetermined times.

[0016] This configuration allows the authentication information to be changed at the appropriate time.

[0017] Furthermore, the information system of this seventh invention is an information system in which, compared to the fourth invention, the predetermined condition is that a change request has been received from the login control device.

[0018] This configuration allows the authentication information to be changed at the appropriate time.

[0019] Furthermore, the information system of this eighth invention is an information system in which, with respect to any one of the first to seventh inventions, the modification unit performs modification processing using a different interface for each of two or more objects.

[0020] With such a configuration, for the login control device, the authentication information of two or more targets can be changed in one way.

[0021] Further, the information system of the ninth invention is an information system having a login control device and two or more change devices with respect to the eighth invention, and the change units of the two or more change devices each perform change processing for one or more different targets.

[0022] With such a configuration, when newly adding a target for login, a significant change or addition of processing to the login control device becomes unnecessary.

[0023] Further, the information system of the tenth invention is such that, with respect to the ninth invention, the login control device transmits a change request, which is an instruction to change the authentication information to new authentication information, to the change device corresponding to the target identified by the target identifier, and the change device receives the change request and performs change processing in response to the reception of the change request.

[0024] With such a configuration, when newly adding a target for login, a significant change or addition of processing to the login control device becomes unnecessary.

Advantages of the Invention

[0025] According to the information system of the present invention, by separating the change device that performs the change processing for changing the authentication information of the target from the login control device, when newly adding a target for login, a significant change or addition of processing to the login control device becomes unnecessary.

Brief Description of the Drawings

[0026] [Figure 1] Conceptual diagram of the information system A in Embodiment 1 [Figure 2] Block diagram of the same information system A [Figure 3] Block diagram of the same change device 2 [Figure 4] Flowchart for explaining an operation example of the same login control device 1 [Figure 5] Flowchart illustrating an example of operation of the modification device 2. [Figure 6] A flowchart illustrating an example of the process for changing authentication information for the same target group. [Figure 7] A flowchart illustrating an example of the process for changing the management authentication information. [Figure 8] A flowchart illustrating an example of the operation of terminal device 3. [Figure 9] Diagram showing the login information management table. [Figure 10] Diagram showing the user information management table. [Figure 11] Diagram showing the information management table for the same target group. [Figure 12] Block diagram of the login control device 5 [Figure 13] Conceptual diagram of information system B in Embodiment 2 [Figure 14] Block diagram of the same information system B [Figure 15] A flowchart illustrating an example of the operation of the login control device 6. [Figure 16] Flowchart illustrating an example of operation of the modification device 7. [Figure 17] A flowchart illustrating an example of the operation of terminal device 3. [Figure 18] This diagram illustrates a specific example of the operation of information system B. [Figure 19] Diagram showing the login information management table. [Figure 20] Diagram showing the user information management table. [Figure 21] Diagram showing the information management table for the same target group. [Figure 22] Overview of the computer system in the above embodiment [Figure 23] Block diagram of the computer system [Modes for carrying out the invention]

[0027] The following describes embodiments of the information system, etc., with reference to the drawings. Note that components denoted by the same reference numerals in the embodiments perform similar operations, and therefore, further explanation may be omitted.

[0028] (Embodiment 1) In this embodiment, an information system is described that includes a change device for automatically changing authentication information (e.g., a password) for logging in to one or more login targets (hereinafter referred to as "targets" as appropriate). It is preferable that there be two or more login targets.

[0029] Furthermore, this embodiment describes an information system equipped with a change device that automatically changes authentication information when predetermined conditions are met. The predetermined conditions include, for example, a predetermined time, or receiving instructions from a login control device.

[0030] Furthermore, in this embodiment, we will describe an information system that includes a modification device for automatically changing authentication information for two or more different targets using the same interface.

[0031] Furthermore, in this embodiment, an information system comprising a login control device for transmitting change requests will be described.

[0032] In this specification, information X being associated with information Y means that information Y can be obtained from information X, or information Y can be obtained from information X, and the method of association is irrelevant. Information X and information Y may be linked, may reside in the same buffer, may information X be contained in information Y, or information Y may be contained in information X, and so on.

[0033] Figure 1 is a conceptual diagram of information system A in this embodiment. Information system A comprises one or more login control devices 1, one or more change devices 2, one or more terminal devices 3, and one or more login targets 4. Note that information system A does not necessarily have to include terminal devices 3 or login targets 4.

[0034] Login control device 1 is a device that processes the login process for a user to log in to a login target 4 without having to enter authentication information corresponding to the login target. Login control device 1 is a so-called server, such as a cloud server or ASP server, but the type is not limited.

[0035] Modification device 2 is a device that processes the authentication information used to log in to login target 4, automatically changing it. Modification device 2 is a so-called server, such as a cloud server or ASP server, but the type is not limited.

[0036] Terminal device 3 is a device used by the user. The user is, for example, a user who logs in to login target 4. Terminal device 3 can be, for example, a personal computer, smartphone, or tablet device, but the type is not limited.

[0037] Login target 4 is the target that the user logs into. Login target 4 is the target that the user uses. Login target 4 can be, for example, a web server, OS, middleware, application, SaaS, IaaS, or network equipment, but the type is not limited. Note that the interface and method for logging into login target 4 usually differ for each login target 4. Login target 4 can also be called the target system or, as mentioned above, the target.

[0038] Figure 2 is a block diagram of information system A in this embodiment. Figure 3 is a block diagram of change device 2 in this embodiment.

[0039] The login control device 1 comprises a control storage unit 11, a control receiving unit 12, a control processing unit 13, and a control transmission unit 14. The control storage unit 11 comprises a login information storage unit 111. The control receiving unit 12 comprises a login instruction receiving unit 121. The control processing unit 13 comprises a support unit 131 and an unauthorized detection unit 132. The control transmission unit 14 comprises a change request transmission unit 141.

[0040] The modification device 2 comprises a storage unit 21, a receiving unit 22, a processing unit 23, and a transmitting unit 24. The storage unit 21 comprises a user information storage unit 211 and a time information storage unit 212. The receiving unit 22 comprises a modification request receiving unit 221. The processing unit 23 comprises a first new authentication information acquisition unit 231 and a modification unit 232. The first new authentication information acquisition unit 231 comprises an old authentication information acquisition unit 2311 and a new authentication information acquisition unit 2312. The modification unit 232 comprises a target authentication information modification unit 2321 and a management authentication information modification unit 2322.

[0041] The terminal device 3 comprises a terminal storage unit 31, a terminal receiving unit 32, a terminal processing unit 33, a terminal transmission unit 34, a terminal receiving unit 35, and a terminal output unit 36.

[0042] The control storage unit 11, which constitutes the login control device 1, stores various types of information. These types of information include, for example, the target login information, which will be described later.

[0043] The login information storage unit 111 stores one or more target login information entries. Each of the one or more target login information entries is associated with, for example, a user identifier. In other words, there may be one target login information entry for each user. Each of the one or more target login information entries is associated with, for example, a target identifier. In other words, there may be one target login information entry for each target 4.

[0044] The target login information is the information necessary to log in to Target 4. The target login information includes, for example, a target identifier and authentication information. The target login information includes, for example, the administrator ID and administrator authentication information of an administrator who can log in to Target 4 and change the authentication information of a general user. The target identifier is information that identifies Target 4. The target identifier is, for example, the URL for accessing Target 4, the IP address for accessing Target 4, or the ID of Target 4. The target login information may also include a target user identifier. The target user identifier is the identifier of the user who logs in to Target 4. The target user identifier is the user ID for logging in to Target 4. Note that the target user identifier may be the same as the user identifier. The authentication information is information used for authentication when logging in to Target 4, and is, for example, a password, a key (e.g., an SSH key), or an authentication token.

[0045] A user identifier is information that identifies a user. Examples of user identifiers include a user's ID, email address, or phone number. For example, a user identifier might be the ID a user uses to log in to login control device 1.

[0046] The control receiving unit 12 receives various information and instructions. The control receiving unit 12 receives various information and instructions from the change device 2, terminal device 3, or target 4. These various information and instructions include, for example, login instructions, new authentication information, screen information, and requests to change management authentication information.

[0047] A request to change the management authentication information is a request to change the authentication information managed by the login information storage unit 111. A request to change the management authentication information has one or more user identifiers. For example, a request to change the management authentication information has a user identifier, a target identifier, and new authentication information. For example, a request to change the management authentication information has a user identifier, a target identifier, old authentication information, and new authentication information.

[0048] The control receiving unit 12 receives new authentication information from, for example, the change device 2. The new authentication information is the new authentication information for logging into target 4, and is the changed authentication information. Such new authentication information is associated with, for example, a user identifier and a target identifier. Such new authentication information is associated with, for example, a target identifier and old authentication information. The old authentication information is the authentication information for logging into target 4, and is the authentication information before the change.

[0049] The control receiving unit 12 receives screen information from, for example, the target 4. This screen information is, for example, information for configuring the screen after logging into the target 4. The screen information is, for example, screen information in which authentication information and a user ID for logging into the target 4 are entered into the authentication information field and the user ID field, respectively. The authentication information field is the field in which authentication information is entered. The user ID field is the field in which the user ID is entered. The screen information can be implemented using, for example, HTML, XML, a program, etc., but the means of implementation is not limited.

[0050] The login instruction receiving unit 121 receives login instructions from the terminal device 3. A login instruction is an instruction for a user to log in to the target 4 from the terminal device 3. A login instruction has, for example, a target identifier. A login instruction is, for example, an instruction corresponding to a user identifier. A login instruction has, for example, a target user identifier. The target user identifier is a user identifier managed by target 4. Note that the login instruction receiving unit 121 may receive the user identifier and the target identifier at different times. An instruction when the user identifier and the target identifier are received at different times is also a login instruction.

[0051] The control processing unit 13 performs various processes. These processes include, for example, those performed by the support unit 131 and the fraud detection unit 132.

[0052] Support unit 131 performs support processing. Support processing is the process of assisting the user corresponding to the received login instruction to log in to target 4.

[0053] The support unit 131 obtains, for example, authentication information from the login information storage unit 111 that corresponds to the target identifier in the login instruction and the user identifier corresponding to the target identifier. Next, the support unit 131 uses the authentication information to perform support processing for the user of the terminal device 3 to log in to the target 4 identified by the target identifier in the login instruction.

[0054] The support unit 131 obtains, for example, the target identifier contained in the login instruction, the target user identifier corresponding to the target identifier, and authentication information from the login information storage unit 111. Next, the support unit 131 uses, for example, the target user identifier and authentication information to perform support processing for the user of the terminal device 3 to log in to the target 4 identified by the target identifier contained in the login instruction.

[0055] The support unit 131, for example, obtains new authentication information for logging into target 4 and passes this new authentication information to the terminal device 3 that sent the login instruction. The new authentication information may be generated by the support unit 131 or received from the modification device 2 that generated the new authentication information.

[0056] The support process described here is a process that allows the user to log in without entering authentication information. For example, the support process involves logging into target 4 and sending screen information that constitutes the initial screen of target 4 to terminal device 3. For example, the support process involves sending screen information of the login screen in which authentication information for logging into target 4 has been entered into the fields to terminal device 3. For example, the support process involves obtaining new authentication information for logging into target 4 and sending this new authentication information to terminal device 3 that sent the login instruction. For example, authentication information refers to authentication information, or authentication information and target user identifier (user ID for logging into target 4).

[0057] The fraud detection unit 132 detects unauthorized logins. The conditions for determining that a login is unauthorized are not specified. The fraud detection unit 132 is capable of detecting various types of unauthorized logins. For example, the fraud detection unit 132 detects that there have been N or more failed login attempts to the login control device 1 (where N is a natural number greater than or equal to 1). The fraud detection unit 132 receives information from target 4 indicating that an unauthorized login has occurred. The information indicating that an unauthorized login has occurred includes, for example, a target user identifier. It is preferable that the information indicating that an unauthorized login has occurred includes a target identifier.

[0058] The control transmission unit 14 transmits various types of information. These types of information include, for example, change requests.

[0059] The change request transmission unit 141 transmits a change request to the change device 2. It is preferable for the change request transmission unit 141 to transmit a change request to the change device 2 when predetermined conditions are met. These predetermined conditions include, for example, the fraud detection unit 132 detecting an unauthorized login, a predetermined time arriving, and a login instruction being received.

[0060] A change request is a request to change authentication information. A change request may be information that identifies the authentication information to be changed, information that identifies the user of the authentication information to be changed, information that identifies target 4 of the authentication information to be changed, or information that does not identify the authentication information, user, or target 4. If the change request is information that identifies the authentication information to be changed, the change request will have, for example, a user identifier and a target identifier. If the change request is information that identifies the user of the authentication information to be changed, the change request will have, for example, a user identifier. If the change request is information that identifies target 4 of the authentication information to be changed, the change request will have, for example, a target identifier. A change request will have, for example, an administrator identifier (administrator ID) and administrator authentication information (e.g., administrator password) in target 4. A change request will have, for example, an administrator identifier, administrator authentication information, and new authentication information in target 4. A change request will have, for example, an administrator identifier, administrator authentication information, new authentication information, and old authentication information in target 4.

[0061] It is preferable that the change request sent by the change request transmission unit 141 to the change device 2 has the same structure when changing the authentication information of any of the target 4. In other words, it is preferable that the method is the same when changing the authentication information of any of the target 4.

[0062] The storage unit 21, which constitutes the modification device 2, stores various types of information. These types of information include user information (described later), time information (described later), authentication information rules (described later), and modification interface information (described later).

[0063] The user information storage unit 211 stores one or more user information. User information is information about a user. User information includes a user identifier. User information may also include one or more user attribute values. User attribute values ​​may be time information as described later.

[0064] The time information storage unit 212 stores one or more time information entries. Time information is information that identifies the time when authentication information is changed. For example, time information could be 12:00 on the 1st of each month, or 12:00 on December 25, 2021. Time information may also be associated with a user identifier. In other words, the timing of authentication information changes may differ depending on the user. Time information may also be associated with a target identifier. In other words, the timing of authentication information changes may differ depending on the target 4.

[0065] The receiving unit 22 receives various types of information. These types of information include, for example, change requests, which will be described later.

[0066] The change request receiving unit 221 receives change requests. The change request receiving unit 221 usually receives change requests from the login control device 1. However, it may also receive change requests from the terminal device 3 or the target device 4.

[0067] The processing unit 23 performs various processes. These processes include, for example, those performed by the first new authentication information acquisition unit 231 and the modification unit 232.

[0068] The first new authentication information acquisition unit 231 acquires new authentication information. The new authentication information is information corresponding to the target identifier and the user identifier. In other words, the new authentication information is the new authentication information for one user in one target 4.

[0069] The first new authentication information acquisition unit 231 acquires the information necessary for updating the new authentication information. This necessary information includes the new authentication information. The necessary information may also include the old authentication information. The necessary information may also include the user identifier. The necessary information may include, for example, the administrator identifier of target 4, the administrator authentication information, the target user identifier, and the new authentication information.

[0070] The old authentication information acquisition unit 2311 acquires one or more old authentication information from the login information storage unit 111. The old authentication information acquired by the old authentication information acquisition unit 231 is the current authentication information of the target identified by the target identifier paired with the user identifier stored in the user information storage unit 211. Note that if the old authentication information is not used when changing the authentication information for target 4, the old authentication information acquisition unit 231 is unnecessary.

[0071] The old authentication information acquisition unit 2311 preferably acquires old authentication information from the login control device 1 (which can also be said to be from the login information storage unit 111) for each of the one or more targets 4. Acquiring old authentication information for each of the one or more targets 4 means that the authentication information is paired with a specific user identifier, and for each of the one or more target identifiers, the authentication information paired with that target identifier is acquired from the login information storage unit 111.

[0072] The old authentication information acquisition unit 2311 preferably acquires old authentication information from the login control device 1 for each of the one or more users. Acquiring old authentication information for each of the one or more users means acquiring one or more pieces of authentication information from the login control device 1 that are paired with a specific user identifier.

[0073] The old authentication information acquisition unit 2311 preferably acquires old authentication information from the login control device 1 for each of the one or more users and each of the one or more targets 4. Acquiring old authentication information for each of the one or more users and each of the one or more targets 4 means acquiring one or more pieces of authentication information from the login control device 1 that are paired with one or more user identifiers and one or more target identifiers.

[0074] The number of old authentication credentials acquired by the old authentication credentials acquisition unit 2311 at any given time is irrelevant. In other words, the number of authentication credentials changed at any given time is irrelevant.

[0075] The new authentication information acquisition unit 2312 acquires new authentication information for each of the one or more targets, which is identified by the user identifier stored in the user information storage unit 211.

[0076] The method by which the new authentication information acquisition unit 2312 acquires the new authentication information is not specified. The new authentication information acquisition unit 2312 generates new authentication information, for example. The new authentication information acquisition unit 2312 reads the new authentication information from the recording medium, for example. The recording medium may be the storage unit 21 or it may be located on an external device. The recording medium may store, for example, a large number of unique authentication information. The new authentication information acquisition unit 2312 acquires new authentication information contained in a change request received by the change request receiving unit 221, for example.

[0077] The following describes an example of the process by which the new authentication information acquisition unit 2312 generates new authentication information. The new authentication information acquisition unit 2312 generates unique new authentication information based on, for example, user-specific information. More specifically, the new authentication information acquisition unit 2312 generates new authentication information by, for example, providing user-specific information to a hash function and executing the hash function. User-specific information is information unique to a user. User-specific information includes, for example, the user's email address, telephone number, ID, and authentication information.

[0078] When the new authentication information acquisition unit 2312 generates new authentication information, it is preferable to generate new authentication information that satisfies the authentication information rules for target 4. Authentication information rules are rules for authentication information. Authentication information rules include, for example, rules regarding the number of characters in the authentication information and rules regarding the types of characters that make up the authentication information. Authentication information rules include, for example, that the authentication information (e.g., password) has a number of characters equal to or greater than a threshold, that the authentication information contains a number of character types equal to or greater than a threshold, that the authentication information contains a specific type of character (e.g., that it contains English letters, symbols and numbers, or that it contains uppercase English letters, lowercase English letters and numbers), and that the strength level of the authentication information is equal to or greater than a threshold. Authentication information rules may also be a set of two or more rules (e.g., that it is 8 characters or more and contains English letters, symbols and numbers). It is preferable that the authentication information rules for target 4 are stored in the storage unit 21 in pairs with the target identifier.

[0079] It is preferable for the new authentication information acquisition unit 2312 to acquire one or more attribute values ​​of the old authentication information acquired by the old authentication information acquisition unit 2311 and generate new authentication information using those attribute values. Attribute values ​​include, for example, the number of characters and the types of characters. That is, for example, the new authentication information acquisition unit 2312 may acquire the number of characters of the old authentication information acquired by the old authentication information acquisition unit 2311 and generate new authentication information with the same number of characters or more. The new authentication information acquisition unit 2312 may also acquire one or more types of characters (for example, uppercase letters, lowercase letters, and numbers) of the old authentication information acquired by the old authentication information acquisition unit 2311 and generate new authentication information that includes those types of characters.

[0080] The modification unit 232 performs modification processing to change the authentication information of the user identified by the user identifier in target 4, which is identified by the target identifier, to the new authentication information acquired by the new authentication information acquisition unit 2312.

[0081] The modification unit 232, for example, uses the administrator identifier, administrator authentication information, target user identifier, and new authentication information of target 4 obtained by the first new authentication information acquisition unit 231 to change the authentication information of the user identified by the target user identifier of target 4 to the new authentication information. Here, the modification unit 232, for example, logs into target 4 using the administrator identifier and administrator authentication information (for example, as a supervisor) and rewrites the authentication information of the user identified by the target user identifier with the new authentication information.

[0082] The target authentication information change unit 2321 performs a target authentication information change process for each of the one or more targets 4, using the old authentication information acquired by the old authentication information acquisition unit 2311 and the new authentication information acquired by the new authentication information acquisition unit 232 to change the authentication information of the user identifier or the user identified by the target user identifier in the target 4 identified by the target identifier from the old authentication information to the new authentication information.

[0083] The target authentication information change unit 2321, for example, uses the administrator identifier, administrator authentication information, target user identifier, and new authentication information of target 4 acquired by the first new authentication information acquisition unit 231 to perform a target authentication information change process to change the authentication information of the user identified by the target user identifier of target 4 to the new authentication information.

[0084] The target authentication information change process is performed, for example, using the API corresponding to target 4. The target authentication information change process is performed, for example, by executing an external program corresponding to target 4. The target authentication information change unit 233 usually performs the target authentication information change process using the target user identifier.

[0085] The target authentication information modification unit 2321 preferably performs the target authentication information modification process when predetermined conditions are met. These predetermined conditions may include, for example, conditions related to time information, detection of fraud, or receipt of a modification request.

[0086] The target authentication information modification unit 2321 performs the target authentication information modification process, for example, when the time information in the time information storage unit 212 is identified.

[0087] The target authentication information modification unit 2321 performs, for example, target authentication information modification processing in response to the receipt of a modification request.

[0088] The target authentication information modification unit 2321 performs the target authentication information modification process using, for example, a different interface for each of the two or more targets. A different interface could be a different API, a different external program, a different method, etc.

[0089] The management authentication information change unit 2322 is the authentication information of the login information storage unit 111, and performs management authentication information change processing to change the authentication information that is paired with the user identifier and target identifier to new authentication information.

[0090] The transmitting unit 24 transmits various types of information. These types of information include, for example, new authentication information, information indicating that the authentication information has been changed, and the time the authentication information was changed. The transmitting unit 24 transmits these types of information to, for example, the login control device 1.

[0091] The terminal storage unit 31, which constitutes the terminal device 3, stores various types of information. These types of information include, for example, a user identifier.

[0092] The terminal reception unit 32 receives various instructions and information. These instructions and information include, for example, login instructions and target identifiers. A login instruction includes, for example, a user identifier. A login instruction includes, for example, a target user identifier. A login instruction includes, for example, a target identifier and a target user identifier.

[0093] Any means of inputting instructions and information is acceptable, such as a touch panel, keyboard, mouse, or menu screen.

[0094] The terminal processing unit 33 performs various processes. These processes include, for example, changing instructions and information received by the terminal receiving unit 32 into instructions and information in a structure to be transmitted, and changing information received by the terminal receiving unit 35 into a structure to be output. These processes include, for example, obtaining new authentication information from the login control device 1. These processes include, for example, logging into target 4 using the target user identifier included in the login instruction and the new authentication information obtained from the login control device 1.

[0095] The terminal transmission unit 34 transmits various types of information and instructions. These types of information and instructions include, for example, login instructions and target identifiers.

[0096] The terminal receiving unit 35 receives various types of information. These types of information include, for example, new authentication information and screen information.

[0097] The terminal output unit 36 ​​outputs various types of information. These various types of information include, for example, information received by the terminal receiving unit 35 and modified in a structure that is output by the terminal processing unit 33, such as various screens.

[0098] Here, "output" is a concept that includes display on a screen, projection using a projector, printing with a printer, sound output, transmission to an external device, storage on a recording medium, and transfer of processing results to other processing devices or other programs.

[0099] The login target 4 receives a login instruction from the login control device 1 or terminal device 3 and performs the login process. The login process, for example, involves performing an authentication process, and if authentication is permitted, sending the screen information after login to terminal device 3. Since the login process is publicly known technology, a detailed explanation is omitted.

[0100] The control storage unit 11, login information storage unit 111, storage unit 21, user information storage unit 211, time information storage unit 212, and terminal storage unit 31 are preferably made of non-volatile recording media, but can also be made of volatile recording media.

[0101] The process by which information is stored in the control storage unit 11, etc. is not relevant. For example, information may be stored in the control storage unit 11, etc. via a recording medium, information transmitted via a communication line, etc. may be stored in the control storage unit 11, etc., or information input via an input device may be stored in the control storage unit 11, etc.

[0102] The control receiving unit 12, login instruction receiving unit 121, receiving unit 22, change request receiving unit 221, and terminal receiving unit 35 are usually implemented by wireless or wired communication means, but may also be implemented by means of receiving broadcasts.

[0103] The control processing unit 13, support unit 131, fraud detection unit 132, processing unit 23, first new authentication information acquisition unit 231, modification unit 232, old authentication information acquisition unit 2311, new authentication information acquisition unit 2312, target authentication information modification unit 2321, management authentication information modification unit 2322, and terminal processing unit 33 can typically be implemented using a processor, memory, etc. The processing procedures of the control processing unit 13, etc., are typically implemented in software, and this software is recorded on a recording medium such as ROM. However, it may also be implemented in hardware (dedicated circuitry). The processor can be a CPU, MPU, GPU, etc., and the type is not specified.

[0104] The control transmission unit 14, the change request transmission unit 141, the transmission unit 24, and the terminal transmission unit 34 are usually implemented by wireless or wired communication means, but may also be implemented by broadcasting means.

[0105] The terminal reception unit 32 can be implemented using device drivers for input means such as touch panels and keyboards, or control software for menu screens, etc.

[0106] The terminal output unit 36 ​​may or may not be considered to include output devices such as displays and speakers. The terminal output unit 36 ​​can be implemented using driver software for an output device, or a driver software for an output device and an output device.

[0107] Next, we will explain an example of the operation of information system A. First, we will explain an example of the operation of login control device 1 using the flowchart in Figure 4.

[0108] (Step S401) The login instruction receiving unit 121 determines whether or not it has received a login instruction from the terminal device 3. If a login instruction is received, the process proceeds to step S402; otherwise, the process proceeds to step S406.

[0109] (Step S402) The support unit 131 obtains the user identifier contained in the login instruction received in step S401.

[0110] (Step S403) The support unit 131 obtains the target identifier contained in the login instruction received in step S401.

[0111] (Step S404) The support unit 131 obtains the target user identifier and authentication information corresponding to the user identifier obtained in step S402 and the target identifier obtained in step S403 from the login information storage unit 111.

[0112] (Step S405) The support unit 131 performs a login process for target 4, identified by the target identifier obtained in step S404, using the target user identifier and authentication information obtained in step S404. The support unit 131 then receives the login screen information, which is the screen information of the login result, from target 4 and transmits it to the terminal device 3 that sent the login instruction. The process returns to step S401. Note that the processing in this step is support processing for logging in.

[0113] (Step S406) The control receiving unit 12 determines whether or not it has received a request to change the management authentication information from the change device 2. If a request to change the management authentication information is received, the unit proceeds to step S407; if no request to change the management authentication information is received, the unit proceeds to step S413.

[0114] (Step S407) The control processing unit 13 obtains one or more user identifiers, etc., that are present in the management authentication information change request. The user identifiers, etc., include the user identifier, the target identifier, and the new authentication information. The user identifiers, etc., may also include the user identifier, the target identifier, the old authentication information, and the new authentication information.

[0115] (Step S408) The control processing unit 13 assigns 1 to counter i.

[0116] (Step S409) The control processing unit 13 determines whether or not an i-th user identifier exists among the one or more user identifiers obtained in step S407. If an i-th user identifier exists, the process proceeds to step S410; otherwise, the process returns to step S401.

[0117] (Step S410) The control processing unit 13 obtains the new authentication information etc. possessed by the i-th user identifier etc. The new authentication information etc. includes the user identifier, the new authentication information and the target identifier, or the new authentication information, the target identifier and the target user identifier.

[0118] (Step S411) The control processing unit 13 overwrites the old authentication information in the login information storage unit 111, which is the old authentication information corresponding to the i-th user identifier, etc., with the new authentication information obtained in step S410.

[0119] (Step S412) The control processing unit 13 increments counter i by 1. Return to step S409.

[0120] (Step S413) The control processing unit 13 determines whether the change conditions have been met. If the change conditions have been met, the process proceeds to step S414; otherwise, the process returns to step S401.

[0121] (Step S414) The control processing unit 13 configures a change request corresponding to a user identifier, a target identifier, or a user identifier and a target identifier that satisfies the change conditions. The change request may, for example, have one or more user identifiers, one or more target identifiers, or a pair of one or more user identifiers and a target identifier.

[0122] (Step S415) The change request transmission unit 141 transmits the change request configured in step S414 to the change device 2. Return to step S401.

[0123] In the flowchart in Figure 4, a request to change management authentication information may be an instruction to change one piece of authentication information, or an instruction to change two or more pieces of authentication information.

[0124] Furthermore, in the flowchart of Figure 4, processing is terminated by power off or processing termination interrupts.

[0125] Next, an example of the operation of the modification device 2 will be explained using the flowchart in Figure 5.

[0126] (Step S501) The change request receiving unit 221 determines whether or not it has received a change request from the login control device 1. If a change request is received, the unit proceeds to step S502; otherwise, the unit proceeds to step S507.

[0127] (Step S502) The processing unit 23 assigns 1 to counter i.

[0128] (Step S503) The processing unit 23 determines whether or not the i-th target (target identifier) ​​corresponding to the change request exists. If the i-th target identifier exists, the process proceeds to step S504; otherwise, it returns to step S501.

[0129] (Step S504) The target authentication information change unit 233, etc., performs the target authentication information change process. An example of the target authentication information change process will be explained using the flowchart in Figure 6.

[0130] (Step S505) The management authentication information change unit 234 performs the management authentication information change process. An example of the management authentication information change process will be explained using the flowchart in Figure 7.

[0131] (Step S506) The processing unit 23 increments counter i by 1. The process returns to step S503.

[0132] (Step S507) The processing unit 23 determines whether the change conditions have been met. If the change conditions have been met, the process proceeds to step S508; otherwise, the process returns to step S501.

[0133] (Step S508) The processing unit 23 assigns 1 to counter i.

[0134] (Step S509) The processing unit 23 determines whether or not the i-th user identifier of a user that satisfies the change conditions exists. If the i-th user identifier exists, the process goes to step S510; otherwise, it returns to step S501.

[0135] (Step S510) The processing unit 23 obtains one or more target login information for target 4 whose authentication information is to be changed, which is the target login information paired with the i-th user identifier, from the user information storage unit 211.

[0136] (Step S511) The processing unit 23 assigns 1 to counter j.

[0137] (Step S512) The processing unit 23 determines whether the j-th target login information exists among the target login information obtained in step S510. If the j-th target login information exists, the process proceeds to step S513; otherwise, the process proceeds to step S516.

[0138] (Step S513) The target authentication information change unit 233, etc., performs the target authentication information change process. An example of the target authentication information change process will be explained using the flowchart in Figure 6.

[0139] (Step S514) The management authentication information change unit 234 performs the management authentication information change process. An example of the management authentication information change process will be explained using the flowchart in Figure 7.

[0140] (Step S515) The processing unit 23 increments counter j by 1. The process returns to step S512.

[0141] (Step S516) The processing unit 23 increments counter i by 1. The process returns to step S509.

[0142] In the flowchart in Figure 5, the trigger for changing authentication information may be either receiving a change request or meeting the change conditions, or it may be either one or the other.

[0143] Furthermore, as shown in the flowchart in Figure 5, processing is terminated by power off or processing termination interrupts.

[0144] Next, an example of the process for changing the target authentication information in step S504 will be explained using the flowchart in Figure 6.

[0145] (Step S601) The old authentication information acquisition unit 231 acquires the target identifier of the target 4 whose authentication information is to be changed.

[0146] (Step S602) The old authentication information acquisition unit 231 obtains the target user identifier of the user whose authentication information is to be changed, and obtains the target user identifier that is paired with the target identifier obtained in step S601 from the user information storage unit 211.

[0147] (Step S603) The old authentication information acquisition unit 231 acquires the authentication information (old authentication information) that corresponds to the target user identifier acquired in step S602 from the user information storage unit 211.

[0148] (Step S604) The new authentication information acquisition unit 232 acquires the authentication information rules for the target identified by the target identifier acquired in step S601. The new authentication information acquisition unit 232 acquires the user-specific information of the user (e.g., target user identifier, user identifier, etc.). The new authentication information acquisition unit 232 uses the user-specific information to generate new authentication information that matches the acquired authentication information rules. The new authentication information acquisition unit 232 generates the new authentication information using, for example, a hash function.

[0149] (Step S606) The target authentication information change unit 233 obtains the change interface information from the storage unit 21 that corresponds to the target identifier obtained in step S601.

[0150] (Step S607) The target authentication information change unit 233 uses the change interface information obtained in step S606, the target user identifier, the old authentication information, and the new authentication information to change the authentication information of the user identified by the target user identifier in target 4 identified by the target identifier obtained in step S601 from the old authentication information to the new authentication information. The unit then returns to the higher-level processing.

[0151] Next, an example of the management authentication information change process in step S505 will be explained using the flowchart in Figure 7.

[0152] (Step S701) The management authentication information change unit 234 obtains the user identifier of the user whose authentication information is to be changed.

[0153] (Step S702) The management authentication information change unit 234 obtains the target identifier obtained in step S601.

[0154] (Step S703) The management authentication information change unit 234 acquires the new authentication information acquired by the new authentication information acquisition unit 232.

[0155] (Step S704) The management authentication information change unit 234 constitutes a management authentication information change request having a user identifier, a target identifier, and new authentication information.

[0156] (Step S705) The management authentication information change unit 234 sends the management authentication information change request configured in step S704 to the login control device 1. It returns to the higher-level processing.

[0157] In addition, in the flowchart of Figure 7, instead of sending a request to change the management authentication information to the login control device 1, the management authentication information change unit 234 may execute a request to change the management authentication information (e.g., a function or module) and change the authentication information managed by the login control device 1.

[0158] Next, an example of the operation of terminal device 3 will be explained using the flowchart in Figure 8.

[0159] (Step S801) The terminal reception unit 32 determines whether or not it has received a login instruction. If it has received a login instruction, it proceeds to step S802; otherwise, it proceeds to step S811.

[0160] (Step S802) The terminal processing unit 33 configures the login instruction to be transmitted. The terminal transmission unit 34 transmits the login instruction to the login control device 1.

[0161] (Step S803) The terminal receiving unit 35 determines whether or not it has received login screen information. If it has received login screen information, it proceeds to step S804; otherwise, it proceeds to step S805.

[0162] (Step S804) The terminal processing unit 33 configures the login screen using the login screen information received in step S803. The terminal output unit 36 ​​outputs the login screen. The process returns to step S801. The login screen is preferably the initial screen after logging into target 4, but it may also be a screen where authentication information for logging into target 4 is entered.

[0163] (Step S805) The terminal receiving unit 35 determines whether or not it has received target selection screen information. If it has received target selection screen information, it proceeds to step S806; otherwise, it returns to step S803. The target selection screen information is information for configuring the target selection screen. The target selection screen is a screen for selecting a target 4 to log in to. The target selection screen is a screen for selecting one target 4 from one or more target 4s that the user can log in to. The target selection screen has selection objects for selecting a target 4. Selection objects include, for example, buttons, menu items, checkboxes, etc.

[0164] (Step S806) The terminal processing unit 33 configures the target selection screen using the target selection screen information received in step S805. The terminal output unit 36 ​​outputs the target selection screen.

[0165] (Step S807) The terminal reception unit 32 determines whether or not it has received a target selection instruction. If it has received a target selection instruction, it proceeds to step S808; otherwise, it returns to step S807.

[0166] (Step S808) The terminal processing unit 33 obtains the target identifier, etc., corresponding to the target selection instruction. The terminal transmission unit 34 transmits the target identifier, etc., to the login control device 1. The target identifier, etc., usually includes the target identifier and the user identifier. For example, the target identifier, etc., includes the target identifier and the target user identifier.

[0167] (Step S809) The terminal receiving unit 35 determines whether or not it has received login screen information. If it has received login screen information, it proceeds to step S810; otherwise, it returns to step S809.

[0168] (In step S810, the terminal processing unit 33 configures the login screen using the login screen information received in step S803. The terminal output unit 36 ​​outputs the login screen. The process returns to step S801.)

[0169] (Step S811) The terminal reception unit 32 determines whether or not it has received instructions or information. If it has received instructions or information, it proceeds to step S812; otherwise, it returns to step S801. Instructions or information refer to instructions or information.

[0170] (Step S812) The terminal processing unit 33, etc., performs processing according to the instructions received in step S811. Return to step S801.

[0171] In the flowchart shown in Figure 7, processing is terminated by power-off or processing termination interrupts.

[0172] Next, an example of the operation of Object 4 will be described. For example, Object 4 performs user authentication processing in response to the login support processing of the login control device 1, and if authentication is permitted, sends login screen information to the login control device 1 or terminal device 3. Also, for example, in response to an instruction from the change device 2 to change the authentication information, Object 4 overwrites the authentication information that corresponds to the instruction and is managed for authentication processing from the old authentication information to the new authentication information.

[0173] The following describes a specific example of the operation of information system A in this embodiment.

[0174] The login information storage unit 111 of the login control device 1 stores the login information management table shown in Figure 9. The login information management table is a table for managing login information. The login information management table manages one or more records that have "ID", "User Identifier", "Login PW", and "Login Information". "Login Information" has "Target Identifier", "Target User Identifier", "Password", and "Change Date". "ID" is information that identifies the record. "User Identifier" is the ID of the user who logs in to the login control device 1. "Login PW" is the password for logging in to the login control device 1. "Login Information" includes information for logging in to Target 4. "Change Date" is the date the password was changed. In Figure 9, Target 4 identified by the target identifier "AP1" is an application. Also, Target 4 identified by the target identifiers "DB1" and "DB2" are databases. Furthermore, Target 4 identified by the target identifiers "NT1" and "NT2" are network devices. Network devices are, for example, routers. The authentication information here is the password.

[0175] The storage unit 21 of the change device 2 stores the user information management table shown in Figure 10. The user information management table is a table that manages user identifiers and time information corresponding to users. The user information management table manages one or more records that have an "ID", a "user identifier", and "time information". The "ID" is information that identifies the record. The "time information" is information that specifies the timing when each user's password is changed.

[0176] The storage unit 21 of the modification device 2 stores the target information management table shown in Figure 11. The target information management table is a table that manages information related to target 4. The target information management table manages one or more records that have "ID", "Target Identifier", "Modification Interface Information", "Authentication Information Rules", and "Time Information". "ID" is information that identifies the record. "Modification Interface Information" is information that identifies the function or module for changing the authentication information (in this case, the password) of target 4. "Authentication Information Rules" is information that indicates the rules for authentication information in target 4. The "-" in "Authentication Information Rules" indicates that there may be no authentication information rules or that the information for authentication information rules is not available. "Time Information" is information that identifies the timing for changing the authentication information for each target 4.

[0177] In light of the above situation, the following two specific examples will be explained. Specific example 1 is a case where authentication information is changed at a predetermined time. Specific example 2 is a case where authentication information is changed when fraud is detected.

[0178] (Specific example 1) Let's assume it's now December 1, 2021. Next, the processing unit 23 of the change device 2 obtains the current date and time, "December 1, 2021, 0:00:00", from a clock (not shown). Next, the target authentication information change unit 2321 of the change device 2 obtains the attribute value "<User Identifier>U001 <Time Information>1st of every month" from the record "ID=1" in the user information management table in Figure 10. Next, the target authentication information change unit 2321 determines that the obtained current date and time satisfies "<Time Information>1st of every month". In other words, the target authentication information change unit 2321 determines that the change conditions are met for the user "<User Identifier>U001".

[0179] Meanwhile, the target authentication information change unit 2321 retrieves the attribute value "<User Identifier>U002 <Time Information>-" from the record with "ID=2" and determines from "<Time Information>-" that the user with "<User Identifier>U001" does not meet the change conditions.

[0180] The target authentication information change unit 2321 then retrieves three target login information items that correspond to the user identifier "U001" from the user information management table in Figure 9. These three target login information items correspond to target identifiers "AP1", "DB1", and "NT1".

[0181] Next, the target authentication information modification unit 2321, etc., has the user identifier "U001" and modifies the authentication information of the target identifier "AP1" as follows.

[0182] In other words, the old authentication information acquisition unit 2311 acquires the password "123456AA" and the target user identifier "UAP11" which are paired with the user identifier "U001" and target identifier "AP1". Next, the new authentication information acquisition unit 2312 acquires the authentication information rule "8 digits or more, includes [0-9], includes [az] [AZ]" which is paired with the target identifier "AP1" from the table in Figure 11. Next, the new authentication information acquisition unit 232 substitutes the unique old password (user-specific information) "123456AA" into a hash function, executes the hash function, and obtains new authentication information "XXa126@55" which matches the authentication information rule.

[0183] Next, the target authentication information change unit 233 obtains the PW change interface information "chg_pw(target user ID, old PW, new PW)" which is paired with the target identifier "AP1" from the target information management table (Figure 11).

[0184] Next, the target authentication information change unit 233 assigns the target user ID "UAP11", the old password "123456AA", and the new password "XXa126@55" to the function "chg_pw(target user ID, old password, new password)" and executes the function.

[0185] Execution of this function changed the password managed by target 4, identified by target identifier "AP1", and the password of the user identified by target user ID "UAP11", from the old password "123456AA" to the new password "XXa126@55".

[0186] Next, the administrative authentication information change unit 2322 performs the administrative authentication information change process as follows: Specifically, the administrative authentication information change unit 2322 obtains the user identifier "U001" of the user whose password is to be changed.

[0187] Next, the management authentication information change unit 2322 obtains the target identifier "AP1". The management authentication information change unit 234 also obtains the new password "XXa126@55" obtained by the new authentication information acquisition unit 2312.

[0188] Next, the management authentication information change unit 2322 constructs a management authentication information change request "Change Request (U001,AP1,XXa126@55)" which has a user identifier, a target identifier, and a new password. Next, the management authentication information change unit 2322 transmits the management authentication information change request "Change Request (U001,AP1,XXa126@55)" to the login control device 1.

[0189] Next, the control receiving unit 12 of the login control device 1 receives the management authentication information change request from the change device 2.

[0190] Next, the control processing unit 13 obtains the user identifier "U001", the target identifier "AP1", and the new password "XXa126@55" from the management authentication information change request.

[0191] Next, the control processing unit 13 replaces the password in the login information management table in Figure 9, which is the authentication information paired with the user identifier "U001" and the target identifier "AP1", with the new password "XXa126@55".

[0192] Furthermore, the control processing unit 13 rewrites the modification date in the login information management table in Figure 9, which is the date paired between the user identifier "U001" and the target identifier "AP1", to "December 1, 2021".

[0193] As a result of the above process, the password managed by the login control device 1 was also changed.

[0194] Next, the target authentication information change unit 2321, etc., changes the password for the user identifier "U001" and target identifier "DB1" as follows. That is, the old authentication information acquisition unit 2311 acquires the password "@Ab465" and the target user identifier "UDB11" which are paired with the user identifier "U001" and target identifier "DB1". Next, the new authentication information acquisition unit 2312 determines that it cannot acquire an authentication information rule that is paired with the target identifier "DB1". Then, the new authentication information acquisition unit 2312 acquires the authentication information rule "6 digits, including [0-9], including [az] or [AZ]" from the password "@Ab465". Next, the new authentication information acquisition unit 2312 substitutes the unique old password (user-specific information) "@Ab465" into a hash function, executes the hash function, and obtains a new password "Ux12T7" which matches the authentication information rule "6 digits, including [0-9], including [az] or [AZ]".

[0195] Next, the target authentication information change unit 2321 obtains the change interface information "PWCHG.exe" which is paired with the target identifier "DB1" from the target information management table (Figure 11).

[0196] Next, the target authentication information change unit 2321 provides the target user ID "UDB11", the old password "@Ab465", and the new password "Ux12T7" to the execution module "PWCHG.exe", and then executes the execution module.

[0197] As a result of executing this module, the password managed by target 4, identified by target identifier "DB1", and for the user identified by target user ID "UDB11", was changed from the old password "@Ab465" to the new password "Ux12T7".

[0198] Next, the administrative authentication information change unit 2322 performs the administrative authentication information change process as follows: Specifically, the administrative authentication information change unit 2322 obtains the user identifier "U001" of the user whose password is to be changed.

[0199] Next, the management authentication information change unit 2322 obtains the target identifier "DB1". The management authentication information change unit 2322 also obtains the new password "XXa126@55" obtained by the new authentication information acquisition unit 2312.

[0200] Next, the management authentication information change unit 2322 constructs a management authentication information change request "Change Request (U001, DB1, Ux12T7)" which has a user identifier, a target identifier, and a new password. Next, the management authentication information change unit 2322 transmits the management authentication information change request "Change Request (U001, DB1, Ux12T7)" to the login control device 1.

[0201] Next, the control receiving unit 12 of the login control device 1 receives the management authentication information change request from the change device 2.

[0202] Next, the control processing unit 13 obtains the user identifier "U001", the target identifier "DB1", and the new password "Ux12T7" from the management authentication information change request.

[0203] Next, the control processing unit 13 replaces the password in the login information management table in Figure 9, which is the password paired with the user identifier "U001" and the target identifier "DB1", with the new password "Ux12T7".

[0204] Furthermore, the control processing unit 13 rewrites the modification date in the login information management table in Figure 9, which is the date paired between the user identifier "U001" and the target identifier "DB1", to "December 1, 2021".

[0205] As a result of the above process, the password managed by the login control device 1 was also changed.

[0206] Similarly, the password for the user identified by user identifier "U001," which corresponds to the target identifier "NT1," will also be changed.

[0207] (Specific example 2) Now, let's assume that Target 4, which is a network device, has detected (detected malicious activity) that there have been more than a threshold number of access attempts with the user identifier "<Target User Identifier>UNT22" and with incorrect passwords. Furthermore, let's assume that Target 4 is a network device identified by the target identifier "NT2".

[0208] Next, let's assume that target 4 sent the change request "<target identifier>NT2 <target user identifier>UNT22 <password>1234" to the change device 2. Note that the change request may also be sent from target 4 to the change device 2 via the login control device 1.

[0209] Next, the change request receiving unit 221 of the change device 2 receives the change request "<Target Identifier>NT2 <Target User Identifier>UNT22 <Password>1234" from the target 4.

[0210] Next, the old authentication information acquisition unit 2311 obtains the target identifier "NT2", the target user identifier "UNT22", and the password (old password) "1234" from the received change request.

[0211] Next, the new authentication information acquisition unit 2312 acquires the authentication information rule "4 digits or more" for the target identified by the target identifier "NT2". Next, the new authentication information acquisition unit 2312 acquires the user-specific information "1234" for the user in question. The new authentication information acquisition unit 2312 uses this user-specific information to generate a new password "@987A" that matches the acquired authentication information rule.

[0212] Next, the target authentication information change unit 2321 obtains the change interface information "XXX.exe" which is paired with the target identifier "NT2" from the table in Figure 11. Then, the target authentication information change unit 2321 provides the execution module "XXX.exe" with the target user identifier "UNT22", the old password "1234", and the new password "@987A", and executes the execution module.

[0213] As a result of executing this module, the password managed by target 4, identified by target identifier "NT2", and for the user identified by target user ID "UNT22", was changed from the old password "1234" to the new password "@987A".

[0214] Next, the management authentication information change unit 2322 performs the management authentication information change process as follows: The management authentication information change unit 2322 obtains the target user identifier "UNT22" of the user whose password is to be changed. The management authentication information change unit 2322 also obtains the target identifier "NT2". The management authentication information change unit 2322 also obtains the old password "1234" obtained by the old authentication information acquisition unit 2311. The management authentication information change unit 2322 also obtains the new password "@987A" obtained by the new authentication information acquisition unit 2312.

[0215] Next, the management authentication information change unit 2322 constructs a management authentication information change request "Change Request (UNT22,NT2,1234,@987A)" which has the target user identifier and the new password. Next, the management authentication information change unit 2322 transmits the management authentication information change request "Change Request (UNT22,NT2,1234,@987A)" to the login control device 1.

[0216] Next, the control receiving unit 12 of the login control device 1 receives the management authentication information change request from the change device 2.

[0217] Next, the control processing unit 13 obtains the target user identifier "UNT22", target identifier "NT2", old password "1234", and new password "@987A" from the management authentication information change request.

[0218] Next, the control processing unit 13 replaces the passwords in the login information management table in Figure 9, which are the passwords paired with the target user identifiers "UNT22" and "NT2", with the new password "@987A".

[0219] Furthermore, the control processing unit 13 rewrites the modification date in the login information management table in Figure 9, which is the date paired between the user identifier "U002" and the target identifier "NT2", to "December 1, 2021".

[0220] As a result of the above process, the password for the specific target 4 of the user whose infringement was detected, which is managed by the login control device 1, was also changed.

[0221] As described above, according to this embodiment, when adding a new target 4 to log in using the login control device 1, it is not necessary to make significant changes to the login control device 1 or add any processing.

[0222] Furthermore, according to this embodiment, the authentication information of the login target managed by the login control device 1 can be easily changed.

[0223] Furthermore, according to this embodiment, the authentication information of the login target managed by the login control device can be easily changed at an appropriate time.

[0224] In this embodiment, the login control device may also have the function of changing the authentication information of the change device 2. A block diagram of the login control device 5 in such a case is shown in Figure 12. The login control device 5 comprises a login information storage unit 111, a time information storage unit 212, a login instruction receiving unit 121, a support unit 131, an old authentication information acquisition unit 2311, a new authentication information acquisition unit 2312, a target authentication information change unit 2321, and a management authentication information change unit 2322.

[0225] The login control device 5 includes, for example, a login information storage unit 111 that stores one or more target login information, each associated with one or more user identifiers, and having a target identifier and authentication information; a login instruction receiving unit 121 that receives login instructions from a terminal device, which are instructions corresponding to a user identifier and having a target identifier; and authentication information corresponding to the target identifier in the login instruction and the user identifier corresponding to the target identifier, which is obtained from the login information storage unit and used to allow the user of the terminal device to log in to the target identified by the target identifier. The system comprises a support unit 131 that performs support processing, a new authentication information acquisition unit 2312 that acquires new authentication information identified by the user identifier for each of the one or more targets, a target authentication information change unit 2321 that performs target authentication information change processing for each of the one or more targets to change the authentication information of the user identified by the user identifier in the target identified by the target identifier from the old authentication information to the new authentication information using the new authentication information, and a management authentication information change unit 2322 that performs management authentication information change processing to change the authentication information of the login information storage unit, which is a pair of the user identifier and the target identifier, to the new authentication information.

[0226] Furthermore, the processing in this embodiment may be implemented in software. This software may be distributed by software download or the like. Alternatively, this software may be recorded on a recording medium such as a CD-ROM and distributed. This also applies to other embodiments in this specification. The software that implements the login control device 1 in this embodiment is a program as follows. In other words, this program is a login instruction receiving unit that receives a login instruction corresponding to a user identifier and a target identifier from the terminal device, and a support unit that functions as a support unit that performs support processing for a user of the terminal device identified by the user identifier to log in to the target identified by the target identifier, using authentication information corresponding to the target identifier and the user identifier corresponding to the login instruction, which has been modified by the modification device.

[0227] Furthermore, the software that implements the modification device 2 in this embodiment is the following program. In other words, this program causes a computer that can access a user information storage unit where user information including a user identifier is stored to function as a first new authentication information acquisition unit that acquires new authentication information corresponding to a target identifier and a user identifier, and a modification unit that performs modification processing to change the authentication information of the user identified by the user identifier in the target identified by the target identifier to the new authentication information.

[0228] (Embodiment 2) In this embodiment, an information system comprising a change device that automatically changes authentication information for logging into one or more targets will be described.

[0229] In this embodiment, the login control device generates new authentication information. In this embodiment, the authentication information is updated when the login control device receives a login instruction from the terminal device. In this embodiment, the terminal device obtains the new authentication information from the login control device and uses this new authentication information to log in to the target.

[0230] Furthermore, in this embodiment, it is preferable for the information system to include a change device corresponding to two or more targets. That is, it is preferable for at least one change device to correspond to one target. However, one change device may correspond to two or more targets. The fact that a change device corresponds to a target means that the change device can change the authentication information managed by that target.

[0231] Figure 13 is a conceptual diagram of information system B in this embodiment. Information system B comprises one or more login control devices 6, one or more change devices 7, one or more terminal devices 3, and one or more login targets 4. Note that information system B does not necessarily have to include terminal devices 3 or login targets 4. Furthermore, this explanation will mainly assume that there is only one login control device 6.

[0232] Figure 14 is a block diagram of information system B in this embodiment.

[0233] The login control device 6, which constitutes information system B, comprises a control storage unit 61, a control receiving unit 62, a control processing unit 63, and a control transmission unit 64. The control storage unit 61 comprises a login information storage unit 611. The control receiving unit 62 comprises a login instruction receiving unit 621. The control processing unit 63 comprises a second new authentication information acquisition unit 631 and a support unit 632. The control transmission unit 64 comprises a change request transmission unit 641.

[0234] The modification device 7 comprises a storage unit 71, a receiving unit 72, a processing unit 73, and a transmitting unit 74. The receiving unit 72 comprises a modification request receiving unit 721. The processing unit 73 comprises a first new authentication information acquisition unit 731 and a modification unit 732.

[0235] The login control device 6 is the target 4 that corresponds to the login instruction, and sends a change request, which is an instruction to change the authentication information to new authentication information, to the change device 7 that corresponds to the target 4 identified by the target identifier.

[0236] The login control device 6 sends a change request to the change device 7, which corresponds to the target 4 identified by the target identifier corresponding to the received login instruction. The change request is an instruction to change the authentication information to new authentication information.

[0237] Various types of information are stored in the control storage unit 61. These types of information include, for example, login information.

[0238] The login information storage unit 611 stores login information for one or more targets 4. This login information includes, for example, administrator information for target 4. Administrator information is typically the information required to log in to target 4 as an administrator. Administrator information includes an administrator identifier and administrator authentication information. The administrator identifier can also be described as an administrative ID. Administrator authentication information can also be described as administrative authentication information. Administrator authentication information may include, for example, the administrator's password, administrator's key (e.g., an SSH key), and administrator's authentication token. It is preferable that the administrator information is associated with the target identifier, which is the identifier of target 4. Note that the login information storage unit 611 may be the same as the login information storage unit 111.

[0239] The control receiving unit 62 receives various instructions and information. These instructions and information include, for example, login instructions.

[0240] The login instruction receiving unit 621 receives a login instruction from the terminal device 3. Here, the login instruction includes, for example, a target user identifier. The target user identifier corresponds to a target identifier. Typically, the target 4 to log in to can be identified by the login instruction, or the target user identifier contained within the login instruction. The login instruction includes, for example, a target identifier and a target user identifier. The login instruction also includes, for example, a target identifier, a target user identifier, and authentication information. Here, the authentication information is the so-called old authentication information before the update. The login instruction includes, for example, information for logging into the login control device 6 (for example, a user identifier, or a user identifier and a password).

[0241] The control processing unit 63 performs various processes. These processes include, for example, those performed by the second new authentication information acquisition unit 631 and the support unit 632.

[0242] The control processing unit 63 may perform authentication processing using the user identifier and authentication information (e.g., password) included in the login instruction, and only perform the functions of the login control device 6 (e.g., changing authentication information, the support processing described below) if authentication is permitted. In this case, one or more pairs of user identifiers and authentication information are stored in the control storage unit 61.

[0243] The second new authentication information acquisition unit 631 acquires new authentication information corresponding to the user identifier and target identifier corresponding to the login instruction received by the control receiving unit 62. Here, the acquired new authentication information may also correspond to the target user identifier corresponding to the user identifier and target identifier corresponding to the login instruction. Alternatively, the acquired new authentication information may also correspond to the target user identifier and authentication information included in the login instruction. Note that this authentication information is the authentication information currently managed in target 4.

[0244] The method by which the second new authentication information acquisition unit 631 acquires the new authentication information is not limited. The second new authentication information acquisition unit 631 may generate the new authentication information or read the new authentication information from a storage medium. The processing of the second new authentication information acquisition unit 631 may be the same as the processing of the new authentication information acquisition unit 2312.

[0245] The second new authentication information acquisition unit 631 generates unique new authentication information based, for example, on user-specific information. More specifically, the second new authentication information acquisition unit 631 generates new authentication information by, for example, providing user-specific information to a hash function and executing the hash function. User-specific information includes, for example, the target user identifier, authentication information, the user's email address, telephone number, and ID.

[0246] The second new authentication information acquisition unit 631 preferably generates new authentication information based on the authentication information rules corresponding to target 4.

[0247] The support unit 632 uses the authentication information corresponding to the target identifier and user identifier that correspond to the received login instruction, and the authentication information (new authentication information) that has been changed by the modification device 7, to perform support processing for a user of terminal device 3 identified by the user identifier to log in to the target identified by the target identifier. Note that the user identifier here may also be the target user identifier, which is the user identifier of the target 4 to be logged in.

[0248] The support unit 632 obtains, for example, the administrator identifier and administrator authentication information of target 4 corresponding to the received login instruction from the login information storage unit 611. More specifically, the support unit 632 obtains, for example, the target user identifier of the received login instruction. Next, the support unit 632 obtains, for example, the administrator identifier and administrator authentication information of target 4 corresponding to the said target user identifier from the login information storage unit 611.

[0249] Furthermore, the support unit 632 may obtain the old authentication information paired with the target user identifier from the received login instruction or the control storage unit 61. The support unit 632 also obtains the new authentication information obtained by the second new authentication information acquisition unit 631, for example. Next, the support unit 632 configures a change request having, for example, an administrator identifier, administrator authentication information, a target user identifier, and new authentication information. The change request may also contain the old authentication information. The change request usually contains information that identifies the target 4. The information that identifies the target 4 is, for example, the target identifier and the target user information.

[0250] Furthermore, it is preferable for the support unit 632 to transmit the new authentication information acquired by the second new authentication information acquisition unit 631 to the terminal device 3. The timing of such transmission of new authentication information is usually after the authentication information of target 4 has been changed from the old authentication information to the new authentication information by the change device 7.

[0251] Furthermore, the support process is typically a process that assists the user in logging into target 4 without having to enter authentication information. Here, the support process includes a process for changing authentication information. Note that the support process may also include the support process described in Embodiment 1.

[0252] The control transmission unit 64 transmits various types of information and instructions. These types of information and instructions include, for example, change requests and new authentication information.

[0253] The control transmission unit 64 transmits, for example, new authentication information to the terminal device 3. However, the support unit 632 may also transmit the new authentication information to the terminal device 3. The control transmission unit 64 transmits, for example, new authentication information to the terminal device 3 in response to a request from the terminal device 3. However, the control transmission unit 64 may also proactively transmit new authentication information to the terminal device 3.

[0254] The control transmission unit 64 may also send reception completion information to the terminal device 3 that sent the login instruction. Reception completion information indicates that the login instruction has been successfully received.

[0255] The change request transmission unit 641 transmits a change request containing the new authentication information acquired by the second new authentication information acquisition unit 631 to the change device 7. It is preferable for the change request transmission unit 641 to transmit the change request configured by the support unit 632 to the change device 7. Alternatively, the support unit 632 may transmit the change request to the change device 7. In this case, the change request transmission unit 641 is unnecessary.

[0256] The timing of when the change request transmission unit 641 transmits the change request to the change device 7 is not specified. It is preferable for the change request transmission unit 641 to transmit the change request to the change device 7 when login information is received. For example, the change request transmission unit 641 transmits the change request to the change device 7 when the authentication information has not been changed for a certain period of time or longer. For example, it is preferable for the change request transmission unit 641 to transmit the change request to the change device 7 when the time information stored in the control storage unit 61 indicates.

[0257] Furthermore, if there are two or more targets 4, it is preferable for the change request transmission unit 641 to send a change request having the same structure to the change device 7, regardless of which target 4's authentication information is being changed. This allows the login control device 6 to easily handle the addition of new targets 4 logged in from the terminal device 3. In other words, even if the addition of new targets 4 logged in from the terminal device 3 requires no or very minor changes to the login control device 6's program. However, login information for the new target 4, which is normally stored in the login control device 6, needs to be added to the login information storage unit 611.

[0258] The change device 7 receives a change request from the login control device 6 and performs the change processing in response to the receipt of the change request. The change processing is the process of changing the authentication information managed by target 4. The change device 7 changes the authentication information in a different way for each target 4, for example. Different methods include using different interfaces, different modules, different communication methods, etc.

[0259] The storage unit 71 stores various types of information. These types of information include, for example, one or more modification interface information. The modification interface information is usually associated with a target identifier. The modification interface information identifies the interface for modifying the authentication information managed by the target 4. The modification interface information includes, for example, information identifying an API and the name of the execution module.

[0260] The receiving unit 72 receives various instructions and information. These instructions and information include, for example, change requests.

[0261] The change request receiving unit 721 receives a change request from the login control device 6.

[0262] The processing unit 73 performs various processes. These processes include, for example, those performed by the first new authentication information acquisition unit 731 and the modification unit 732.

[0263] The first new authentication information acquisition unit 731 acquires new authentication information corresponding to the target identifier of the target 4 that manages the authentication information to be updated and the user identifier (or target user identifier) ​​of the user of the terminal device 3. Here, the first new authentication information acquisition unit 731 acquires the new authentication information contained in the change request received by the change request receiving unit 721.

[0264] The modification unit 732 performs modification processing to change the authentication information of the user identified by the user identifier in target 4, which is identified by the target identifier, to the new authentication information.

[0265] The modification unit 732, for example, obtains the administrator identifier, administrator authentication information, target user identifier, and new authentication information contained in the change request received by the change request receiving unit 721. Next, the modification unit 732 performs the change processing using the obtained administrator identifier, administrator authentication information, target user identifier, and new authentication information.

[0266] The modification unit 732, for example, accesses target 4 determined from the target identifier or target user identifier of the change request received by the change request receiving unit 721, and performs the change processing using the administrator identifier, administrator authentication information, target user identifier, and new authentication information.

[0267] The modification unit 732 may, for example, obtain modification interface information corresponding to the target identifier of target 4 whose authentication information is to be changed from the storage unit 71. Then, the modification unit 732 may, for example, use the modification interface information, the administrator identifier, the administrator authentication information, the target user identifier, and the new authentication information to change the authentication information of the user identified by the target user identifier of target 4 to the new authentication information. The modification unit 732 may also, for example, use the modification interface information, the administrator identifier, the administrator authentication information, the target user identifier, the new authentication information, and the old authentication information to change the authentication information of the user identified by the target user identifier of target 4 to the new authentication information.

[0268] The modification unit 732 preferably performs modification processing when predetermined conditions are met. The modification unit 732 preferably performs modification processing using a different interface for each of the two or more targets 4. In this case, the modification unit 732 uses modification interface information corresponding to each target 4. Different interfaces include, for example, different APIs, different external programs, different methods, etc.

[0269] The transmitting unit 74 transmits various types of information.

[0270] The control storage unit 61, the login information storage unit 611, and the storage unit 71 are preferably made of non-volatile recording media, but can also be made of volatile recording media.

[0271] The process by which information is stored in the control storage unit 61, etc. is not relevant. For example, information may be stored in the control storage unit 61, etc. via a recording medium, information transmitted via a communication line, etc. may be stored in the control storage unit 61, etc., or information input via an input device may be stored in the storage unit 71, etc.

[0272] The control receiving unit 62, the login instruction receiving unit 621, the receiving unit 72, and the change request receiving unit 721 are typically implemented by wireless or wired communication means.

[0273] The control processing unit 63, the second new authentication information acquisition unit 631, the support unit 632, the processing unit 73, the first new authentication information acquisition unit 731, and the modification unit 732 can typically be implemented using a processor, memory, etc. The processing procedures of the modification unit 732, etc., are typically implemented in software, and this software is recorded on a recording medium such as ROM. However, it may also be implemented in hardware (dedicated circuitry). The processor can be a CPU, MPU, GPU, etc., and the type is not limited.

[0274] The control transmission unit 64, the change request transmission unit 641, and the transmission unit 74 are typically implemented by wireless or wired communication means.

[0275] Next, an operation example of the information system B will be described. First, an operation example of the login control device 6 will be described using the flowchart of FIG. 15.

[0276] (Step S1501) The login instruction receiving unit 621 determines whether a login instruction has been received from the terminal device 3. If a login instruction is received, the process proceeds to step S1502; if no login instruction is received, the process returns to step S1501.

[0277] (Step S1502) The second new authentication information acquisition unit 631 acquires the target user identifier and the like. The target user identifier and the like, for example, include a target user identifier, an administrator identifier, and administrator authentication information.

[0278] The second new authentication information acquisition unit 631, for example, acquires the target user identifier included in the login instruction received in step S1501. Next, the second new authentication information acquisition unit 631, for example, acquires a target identifier determined from the target user identifier, or a target identifier included in the login instruction received in step S1501. Next, the second new authentication information acquisition unit 631 acquires the administrator identifier and administrator authentication information paired with the target identifier from the login information storage unit 611.

[0279] Here, the process of acquiring the target user identifier and the like may be performed by the support unit 632.

[0280] (Step S1503) The second new authentication information acquisition unit 631 acquires new authentication information. Note that the second new authentication information acquisition unit 631, for example, generates new authentication information.

[0281] (Step S1504) The support unit 632 constructs a change request having the new authentication information acquired in step S1503, the target identifier, the target user identifier, the administrator identifier, and the administrator authentication information acquired in step S1502.

[0282] The change request may also include old authentication information paired with the target user identifier. In such cases, the control storage unit 61 stores the pair of the target user identifier and the old authentication information, and the second new authentication information acquisition unit 631 acquires the authentication information paired with the acquired target user identifier from the control storage unit 61. The control storage unit 61 manages the pair of the target user identifier and the old authentication information, for example, by associating them with the target identifier and / or the user identifier.

[0283] (Step S1505) The change request transmission unit 641 transmits the change request configured in step S1504 to the change device 7.

[0284] (Step S1506) The control transmission unit 64 determines whether it is time to send the reception completion information. If it is time to send the reception completion information, the unit proceeds to step S1507; otherwise, it returns to step S1506.

[0285] This step is a waiting process to prevent terminal device 3 from performing the login process until the authentication information in target 4 is changed. The control transmission unit 64 determines, for example, that it is not time to send the acceptance completion information until a predetermined time (for example, 2 seconds) has elapsed since the change request was sent. The control transmission unit 64 also determines, for example, that it is not time to send the acceptance completion information until the control reception unit 62 receives information from the change device 7 indicating that the authentication information change process is complete.

[0286] (Step S1507) The control transmission unit 64 transmits reception completion information to the terminal device 3 that sent the login instruction. Return to step S1501.

[0287] In the flowchart shown in Figure 15, processing is terminated by power-off or processing termination interrupts.

[0288] Next, an example of the operation of the modification device 7 will be explained using the flowchart in Figure 16.

[0289] (Step S1601) The change request receiving unit 721 determines whether or not it has received a change request from the login control device 6. If a change request is received, the unit proceeds to step S1602; otherwise, it returns to step S1601.

[0290] (Step S1602) The modification unit 732 obtains a target identifier included in the change request, or a target identifier determined from information included in the change request (for example, a target user identifier).

[0291] (Step S1603) The modification unit 732 obtains modification interface information from the storage unit 71 that corresponds to the target identifier obtained in step S1602.

[0292] (Step S1604) The first new authentication information acquisition unit 731 acquires the new authentication information, etc. included in the change request. The new authentication information, etc. includes, for example, the new authentication information, the target user identifier, the administrator identifier, and the administrator authentication information.

[0293] (Step S1605) The modification unit 732 uses the new authentication information obtained in step S1604 to change the authentication information of the user identified by the target user identifier, which is managed in the target 4 identified by the target identifier obtained in step S1602, at the interface specified by the modification interface information obtained in step S1603, and using the new authentication information obtained in step S1604. The process returns to step S1601.

[0294] In the flowchart shown in Figure 16, processing is terminated by power-off or processing termination interrupts.

[0295] Next, an example of the operation of terminal device 3 will be explained using the flowchart in Figure 17. In the flowchart in Figure 17, the explanation for the same steps as in the flowchart in Figure 8 will be omitted.

[0296] (Step S1701) The terminal reception unit 35 determines whether it has received the reception completion information from the login control device 6. If it has received the reception completion information, it proceeds to step S1702; if it has not received the reception completion information, it returns to step S1701.

[0297] (Step S1702) The terminal processing unit 33 or the terminal reception unit 35 acquires new authentication information from the login control device 6. Such new authentication information is the new authentication information corresponding to the login instruction transmitted in step S802.

[0298] (Step S1703) The terminal processing unit 33 or the terminal transmission unit 34 uses the target user identifier included in the login instruction received in step S801 and the new authentication information acquired in step S1702 to log in to the target 4 identified by the target identifier. It returns to step S801. The target identifier is included in, for example, the login instruction received in step S801.

[0299] In the flowchart of FIG. 17, the process ends due to a power-off or a processing end interrupt.

[0300] Hereinafter, a specific operation example of the information system B in the present embodiment will be described with reference to FIG. 18. The conceptual diagram of the information system B is FIG. 13.

[0301] Currently, the login information storage unit 611 of the login control device 6 stores the login information management table shown in Figure 19. The login information management table is a table for managing login information. The login information management table manages one or more records that have "ID", "Target Identifier", "Login Information", and "Authentication Information Rules". "Login Information" has "Administrative Account", "Administrative PW", and "Time Information". "Administrative Account" is an example of an administrator identifier. "Administrative PW" is an example of administrator authentication information. Here, the authentication information is assumed to be a password. Here, the authentication information of target 4 is changed each time a login instruction to target 4 is received, but the authentication information of target 4 is also changed if the "Time Information" is satisfied. In other words, in "ID=1" in Figure 19, the authentication information is changed every 30 days using the time information "every 30 days".

[0302] Furthermore, the control storage unit 61 of the login control device 6 stores the user information management table shown in Figure 20. The user information management table is information that users need to use the login control device 6, and it is a table that manages information that identifies the targets 4 that users can access. The user information management table manages one or more records that have "ID", "User Identifier", "Login PW", "Target Identifier", and "Target User Identifier". "User Identifier" and "Login PW" are the user ID and password that the user needs to use the login control device 6. According to Figure 20, a user identified by user identifier "U001" can log in to the login control device 6 using login PW "PW1" and use the functions of the login control device 6. In addition, a user identified by user identifier "U001" can log in to two targets 4 with target identifiers "OS1" and "AP1".

[0303] Furthermore, the storage unit 71 of the modification device 7 stores the target information management table shown in Figure 21. The target information management table is a table that manages information for changing the authentication information of target 4. The target information management table manages one or more records that have "ID", "target identifier", "modification interface information", and "parameters to provide". Here, "modification interface information" is the name of the execution module or function for changing the authentication information. The software corresponding to the execution module name or function name is stored in the storage unit 21. The "parameters to provide" is information that specifies the parameters to be given to the module specified by the modification interface information. Also, the parameters shall be given to the module in the order described in "parameters to provide".

[0304] In this situation, a specific example of the operation of information system B will be explained below using Figure 18.

[0305] Assume the user has entered a login instruction into terminal device 3 containing "<User Identifier>U001 <Login PW>PW1 <Target Identifier>OS1". Next, terminal device 3 receives the login instruction and transmits it to login control device 6 (Figure 18 (1)).

[0306] Next, the login instruction receiving unit 621 of the login control device 6 receives a login instruction "<User Identifier>U001 <Login PW>PW1 <Target Identifier>OS1" from the terminal device 3.

[0307] Next, the second new authentication information acquisition unit 631 acquires the target identifier "OS1" contained in the login instruction. The second new authentication information acquisition unit 631 acquires the target user identifier "UOS1", which is paired with the user identifier "U001" contained in the login instruction, from the user information management table (Figure 20). If the target user identifier "UOS1" is included in the login instruction, the second new authentication information acquisition unit 631 may acquire the target user identifier "UOS1" from the received login instruction.

[0308] Next, the second new authentication information acquisition unit 631 obtains the management account, management password, and authentication information rules that correspond to the target identifier "OS1" from the login information management table (Figure 19). The second new authentication information acquisition unit 631 also obtains user-specific information (for example, the target user identifier "UOS1"). Then, the second new authentication information acquisition unit 631 generates a unique new authentication information "Abc3921D" using the user-specific information to match the acquired authentication information rules (Figure 18 (2)).

[0309] Next, the support unit 632 constructs a change request "<Administrative Account>Admin <Administrative Password>12345AB <Target User Identifier>UOS1 <New Authentication Information>Abc3921D <Target Identifier>OS1" which has the generated new authentication information, the acquired target user identifier "UOS1", the administrative account "Admin", and the administrative password "12345AB".

[0310] Next, the change request transmission unit 641 transmits the configured change request to the change device 7 (Figure 18 (3)).

[0311] Next, the change request receiving unit 721 of the change device 7 receives a change request "<Administrative Account>Admin <Administrative Password>12345AB <Target User Identifier>UOS1 <New Authentication Information>Abc3921D <Target Identifier>OS1" from the login control device 6 (Figure 18 (3)).

[0312] Next, the modification unit 732 obtains the modification interface information "CHG.exe" and "parameters to be provided" that correspond to the target identifier "OS1" in the modification request from the target information management table (Figure 21).

[0313] Next, the modification unit 732 provides the "<administrative account>Admin <administrative password>12345AB <target user identifier>UOS1 <new authentication information>Abc3921D" contained in the modification request to the module identified by the modification interface information "CHG.exe", and executes that module (Figure 18 (4)).

[0314] As a result of the above processing, the authentication information of the user identified by the target user identifier "UOS1" in Target 4, which is identified by the target identifier "OS1", has been updated to the new authentication information "Abc3921D".

[0315] Next, the control transmission unit 64 of the login control device 6 determines that it is time to send the reception completion information and transmits the reception completion information to the terminal device 3.

[0316] Next, the terminal receiving unit 35 of terminal device 3 receives the reception completion information. Then, the terminal processing unit 33 obtains the new authentication information "Abc3921D" from the login control device 6. It should be assumed that the terminal processing unit 33 holds a program or module that corresponds to the API for obtaining the new authentication information from the login control device 6.

[0317] Next, the terminal processing unit 33 of terminal device 3 uses the target user identifier "UOS1" contained in the received login instruction and the acquired new authentication information "Abc3921D" to log in to target 4 identified by target identifier "OS1".

[0318] Through the above process, users will be able to log in to Target 4 and use Target 4 in a simple and secure manner.

[0319] As described above, according to this embodiment, when a new target 4 for login is added, no significant changes or additions to the login control device 6 are required.

[0320] Furthermore, according to this embodiment, the login control device 6 can change the authentication information of two or more targets in a single method.

[0321] Figure 22 also shows the external appearance of a computer that executes the program described herein to realize the various embodiments of the modification device 2 described above. The embodiments described above can be realized with computer hardware and computer programs executed thereon. Figure 22 is an overview of this computer system 300, and Figure 23 is a block diagram of the system 300.

[0322] In Figure 22, the computer system 300 includes a computer 301 with a CD-ROM drive, a keyboard 302, a mouse 303, and a monitor 304.

[0323] In Figure 23, the computer 301 includes, in addition to the CD-ROM drive 3012, an MPU 3013, a bus 3014 connected to the CD-ROM drive 3012, a ROM 3015 for storing programs such as boot-up programs, a RAM 3016 connected to the MPU 3013 for temporarily storing instructions for application programs and providing temporary storage space, and a hard disk 3017 for storing application programs, system programs, and data. Although not shown here, the computer 301 may further include a network card that provides connectivity to a LAN.

[0324] The program that causes the computer system 300 to execute the functions of the modified device 2, etc., as described above, may be stored on the CD-ROM 3101, inserted into the CD-ROM drive 3012, and then transferred to the hard disk 3017. Alternatively, the program may be transmitted to the computer 301 via a network (not shown) and stored on the hard disk 3017. The program is loaded into the RAM 3016 during execution. The program may also be loaded directly from the CD-ROM 3101 or the network.

[0325] The program does not necessarily have to include an operating system (OS) or third-party program that causes the computer 301 to execute functions such as the modification device 2 of the above embodiment. The program only needs to include the instruction portion that calls appropriate functions (modules) in a controlled manner and obtains the desired result. How the computer system 300 operates is well known, so a detailed explanation is omitted.

[0326] In the above program, steps such as sending information and receiving information do not include hardware-based processing, such as processing performed by a modem or interface card in the transmission step (processing that can only be performed by hardware).

[0327] Furthermore, the computer running the above program may be a single computer or multiple computers. In other words, it may perform centralized processing or distributed processing.

[0328] Furthermore, it goes without saying that in each of the above embodiments, two or more communication means present in a single device may be physically implemented in a single medium.

[0329] Furthermore, in each of the above embodiments, each process may be implemented by centralized processing by a single device, or by distributed processing by multiple devices.

[0330] It goes without saying that the present invention is not limited to the embodiments described above, and various modifications are possible, all of which are also included within the scope of the present invention. [Industrial applicability]

[0331] As described above, the information system according to the present invention has the effect of eliminating the need for significant changes or additional processing of the login control device when adding a new target for login, by separating the change device that performs change processing to change the authentication information of the target from the login control device. Therefore, it is useful as an information system that realizes a platform in which one or more targets can be easily and securely logged in. [Explanation of symbols]

[0332] 1, 5, 6 Login control device 2.7 Change device 3 Terminal devices 4. Target 11, 61 Control storage unit 12, 62 Control receiving unit 13, 63 Control Processing Unit 14, 64 Control Transmitter 21, 71 Storage Unit 22, 72 Receiving section 23, 73 Processing Unit 24, 74 Transmitter 31 Terminal storage section 32 Terminal reception area 33 Terminal Processing Unit 34 Terminal transmission unit 35 Terminal receiving unit 36 Terminal output section 111, 611 Login Information Storage Unit 121, 621 Login instruction receiving unit 131, 631 Support Department 132 Fraud Detection Unit 141, 641 Change Request Transmission Unit 211 User Information Storage Unit 212 Time Information Storage Unit 221, 721 Change Request Receiving Unit 231, 731 First New Authentication Information Acquisition Department Changes in sections 232 and 732. 631 Second New Authentication Information Acquisition Department 632 Support Department 641 Change Request Transmission Unit 2311 Former Authentication Information Acquisition Department 2312 New Authentication Information Acquisition Department 2321 Target Authentication Information Change Section 2322 Management Authentication Information Change Section

Claims

1. An information system having a login control device and a change device, which is an information system that supports logins to one or more targets from two or more terminal devices, The aforementioned login control device is A login instruction receiving unit receives login instructions corresponding to a user identifier and a target identifier from the terminal device, The system comprises authentication information corresponding to the target identifier and user identifier corresponding to the login instruction, and a support unit that performs support processing for a user of the terminal device identified by the user identifier to log in to the target identified by the target identifier using the authentication information modified by the modification device, The aforementioned modification device is The first new authentication information acquisition unit acquires new authentication information corresponding to the target identifier and the user identifier, An information system comprising a modification unit that performs modification processing to change the authentication information of a user identified by the user identifier in an object identified by the target identifier to the new authentication information.

2. The aforementioned login control device is A second new authentication information acquisition unit acquires new authentication information corresponding to the user identifier and the target identifier, The system further comprises a change request transmission unit that transmits a change request having the new authentication information acquired by the second new authentication information acquisition unit to the change device, The aforementioned modification device is The system further comprises a change request receiving unit that receives the aforementioned change request, The aforementioned first new authentication information acquisition unit is: The information system according to claim 1, wherein the change request receiving unit acquires new authentication information contained in the change request it has received.

3. The aforementioned modified part is, The information system according to claim 1 or claim 2, which obtains an administrator identifier and administrator authentication information for the aforementioned target, and performs the change processing using the administrator identifier, the administrator authentication information and the new authentication information.

4. The aforementioned modified part is, The information system according to any one of claims 1 to 3, which performs the modification process when predetermined conditions are met.

5. The aforementioned predetermined conditions are: The information system according to claim 4, wherein a change request is received in response to the login instruction receiving unit receiving the login instruction from the terminal device.

6. The aforementioned predetermined conditions are: The information system according to claim 4, which occurs at a predetermined time.

7. The aforementioned predetermined conditions are: The information system according to claim 4, wherein a change request has been received from the login control device.

8. The aforementioned modified part is, The information system according to any one of claims 1 to 7, which performs the modification process using a different interface for each of two or more targets.

9. An information system having a login control device and two or more change devices, The information system according to claim 8, wherein each of the two or more modification devices performs the modification process on one or more different targets.

10. The aforementioned login control device is A change request is sent to the change device corresponding to the target identified by the target identifier, which is an instruction to change the authentication information to the new authentication information. The aforementioned modification device is The information system according to claim 9, which receives the change request and performs the change processing in response to the receipt of the change request.

11. A login control device comprising an information system according to any one of claims 1 to 10, comprising a login control device and a change device, A login instruction receiving unit receives login instructions from a terminal device that correspond to a user identifier and a target identifier, A login control device comprising: an authentication information corresponding to the target identifier and the user identifier corresponding to the login instruction, and a support unit that performs support processing for a user of a terminal device identified by the user identifier to log in to the target identified by the target identifier using the authentication information changed by the modification device.

12. A change device comprising a login control device and a change device, which constitutes the information system according to claim 2, A change request receiving unit receives a change request from the login control device that has new authentication information corresponding to a user identifier and a target identifier, A first new authentication information acquisition unit acquires the new authentication information contained in the change request received by the change request receiving unit, A modification device comprising: a modification unit that performs modification processing to change the authentication information of a user identified by the user identifier in the target identified by the target identifier to the new authentication information.

13. Computers, A program for causing a login control device to function as described in claim 11.

14. Computers, A program for causing the device to function as the modification device described in claim 12.

Citation Information

Patent Citations

  • Password management system

    JP2000259566A

  • Authentication system, and authentication server device and user device and application server device

    JP2009223452A

  • Access management device

    JP2013045278A

  • Web-based single sign-on with form-fill proxy applications

    JP2016537696A

  • Management device, computer-readable recording medium, and management method

    US20140059661A1