EasyConnect authentication method, EasyConnect authentication server, and EasyConnect authentication program
The authentication server verifies user biometrics to secure new terminal connections, addressing security vulnerabilities in Easy Connect by ensuring only authorized devices can connect.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NEC PLATFROMS LTD
- Filing Date
- 2024-01-29
- Publication Date
- 2026-07-29
AI Technical Summary
Existing Easy Connect technologies facilitate new terminal connections to networks but compromise security, allowing unauthorized access and information theft due to the ease of reading QR codes by malicious users.
An authentication server stores user biometric information and compares it with incoming biometric data from new terminals to determine connection authorization, integrating voice or other biometric inputs to enhance security.
Facilitates secure new terminal connections to networks by preventing unauthorized access through biometric verification, ensuring only authorized devices can connect.
Smart Images

Figure 0007896898000001 
Figure 0007896898000002 
Figure 0007896898000003
Abstract
Description
Technical Field
[0001] The present invention relates to an Easy Connect authentication method, an Easy Connect authentication server, and an Easy Connect authentication program.
Background Art
[0002] There is a technology for facilitating the new connection of a new Enrollee terminal to a network such as Wi-Fi, so-called Easy Connect. (See Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] The following analysis is made from the perspective of the present invention. Each disclosure of the above prior art documents is incorporated herein by reference.
[0005] In the technology called Easy Connect, there is a security risk as a trade-off for facilitating the new connection of a terminal to a network. For example, in Patent Document 1, the operation for new connection is completed by reading the QR (Quick Response) code (registered trademark) of the new connection terminal by a terminal device as a configurator. Therefore, a terminal of a malicious user can also be easily newly connected. As a result, it is impossible to prevent the theft of information communicated via an access point and the unauthorized use of the network.
[0006] Therefore, the present invention aims to provide a technology that contributes to facilitating new connections of terminals to a network while maintaining security. [Means for solving the problem]
[0007] According to the first aspect of the present invention, The EasyConnect authentication server stores the user's biometric information. When a new connection request for a new enloading terminal is received from a configurator device via an access point device, the determination step determines whether or not the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. An EasyConnect authentication method is provided, which includes [this].
[0008] According to a second aspect of the present invention, A memory unit that stores the user's biometric information, When a new connection request for a new enloading terminal is received from a configurator device via an access point device, the determination unit determines whether or not the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. An EasyConnect authentication server equipped with the following features is provided.
[0009] According to a third aspect of the present invention, A computer acting as an EasyConnect authentication server that stores the user's biometric information, When a new connection request for a new enloading terminal is received from the configurator device via the access point device, a determination process is performed to determine whether the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. An EasyConnect authentication program is provided to enable this. [Effects of the Invention]
[0010] According to each aspect of the present invention, an EasyConnect authentication method, an EasyConnect authentication server, and an EasyConnect authentication program are provided that contribute to facilitating new terminal connections to a network while maintaining security. [Brief explanation of the drawing]
[0011] [Figure 1] This is a diagram to explain the general overview. [Figure 2] This figure shows an example of the system. [Figure 3] This diagram shows the processing flow within the system. [Figure 4] This figure shows an example of a probe request. [Figure 5] This diagram shows the processing flow by the authentication server. [Figure 6] This is a diagram showing an example of a computer. [Modes for carrying out the invention]
[0012] Preferred embodiments of the present invention will be described in detail with reference to the drawings. The reference numerals in the drawings provided below are for illustrative purposes only and are not intended to limit the present invention to the illustrated embodiments. Furthermore, the connecting lines between blocks in each figure include both bidirectional and unidirectional lines. Unidirectional arrows schematically represent the flow of the main signal (data) and do not exclude bidirectional flow. In addition, although not explicitly shown, input and output ports exist at the input and output ends of each connecting line in the circuit diagrams, block diagrams, internal configuration diagrams, and connection diagrams disclosed herein. The same applies to input / output interfaces.
[0013] First, as shown in Figure 1, a system including an authentication server 100, an access point device 200, a configurator device 300, and an enrollment terminal 400 will be used as an example to explain an overview of the present invention.
[0014] As shown in FIG. 1, the authentication server 100 includes a storage unit 110 that stores biometric information of a user, and a determination unit 120 that determines whether a new enrollment terminal 400 can be connected. The determination unit 120 receives, as a new connection request regarding the new enrollment terminal 400, terminal information of the new enrollment terminal 400 and biometric information of the user from the configurator device 300 via the access point device 200. Here, the determination unit 120 determines whether the new enrollment terminal 400 can be connected by comparing the stored biometric information with the received biometric information.
[0015] The differences between the present invention and the prior art will be described with more specific examples. Here, a Wi-Fi router is assumed as an example of the access point device 200. Also, a smartphone is assumed as an example of the configurator device 300. Further, a tablet terminal is assumed as an example of the new enrollment terminal 400. And a person who installs the access point device 200 is regarded as a user. Also, the user's voiceprint is assumed as an example of biometric information. More specifically, a case is assumed where the user installs a home Wi-Fi, sets a smartphone as the configurator device 300, and newly connects a tablet terminal as the enrollment terminal 400.
[0016] In the prior art, a new connection operation is completed by reading a QR (Quick Response) code displayed on the display of the enrollment terminal 400 by a camera of the configurator device 300. Therefore, even if a malicious person causes the configurator device 300 to read a QR code displayed on the display of his own terminal while the user is looking away, the terminal of the malicious person may be connected.
[0017] On the one hand, in the present invention, for example, in order to connect the new enrollee terminal 400, in addition to the operation of having the QR code read by the configurator device 300, an input of voice (voiceprint) to the access point device 200 is required. Even if a malicious person inputs voice, in the present invention, authentication will not be possible and connection of the malicious person's terminal can be prevented.
[0018] In the above summary, the access point device 200 and the configurator device 300 are configured as separate components, but it is also possible to have an integrated configuration. For example, if the access point device 200 includes a camera for reading QR codes and a microphone for collecting voice, it can be applied as an integrated configuration of the access point device 200 and the configurator device 300.
[0019] Also, in the above summary, an example using a QR code was described, but a configuration using wireless communication can also be adopted. For example, the new enrollee terminal 400 may transmit a probe request including biometric information to the access point device 200. Also, the biometric information is not limited to voiceprint, and fingerprint, iris, etc. can also be adopted.
[0020] [Embodiment 1] Hereinafter, as Embodiment 1, the system of the above summary will be described in more detail. In Embodiment 1, as shown in FIG. 2, an integrated configuration of the access point device 200 and the configurator device 3 is adopted. Note: There seems to be a typo in the original text where it says "configurator device 3" instead of "configurator device 300".
[0021] The access point device 200 is exemplified by a Wi-Fi router. Also, since the function as the configurator device 300 is the same as in the prior art, the description thereof is omitted.
[0022] The Enrolly terminal 400 is a device connected to a personal home Wi-Fi network, and is exemplified by smartphones, tablets, laptops, and printers. The Enrolly terminal 400 also includes functions for acquiring the user's biometric information (for example, a microphone to collect the user's voice and a reader to collect the user's fingerprints).
[0023] The authentication server 100 includes a storage unit 110 that stores the user's biometric information, as described above, and a determination unit 120 that determines whether or not a new enrollment terminal 400 can be connected.
[0024] The memory unit 110 stores, for example, the user's biometric information in association with the device ID (identification) of the access point device 200. This information is saved when the access point device 200 is installed by the user.
[0025] The determination unit 120 will be explained in accordance with the process flow for newly connecting the enloading terminal 400.
[0026] The following describes the process for connecting a new enrollment terminal 400. It is assumed that the storage unit 110 already contains the device ID of the access point device 200 (hereinafter referred to as "AP-ID") and the user's biometric information. In other words, it is assumed that the setup of the access point device 200 is complete.
[0027] As shown in Figure 3, when a new connection operation is performed on the enloading terminal 400, the enloading terminal 400 requests the operator to input their voice (biometric information). Once voice is input, the enloading terminal 400 sends a probe request containing biometric information to the access point device 200. Here, Figure 4 shows an example of a probe request. In Figure 4, voiceprint information is used as biometric information.
[0028] Upon receiving a probe request, the access point device 200 sends its device ID (AP-ID) and biometric information to the authentication server 100 and requests a bootstrap.
[0029] The determination unit 120 of the authentication server 100 reads the biometric information stored in association with the received AP-ID from the storage unit 110 and compares it with the received biometric information. If the comparison result is OK, indicating that the stored biometric information (user's voice) and the received biometric information (operator's voice of the enrollment terminal 400) match, the determination unit 120 determines that connection is permitted and issues a Bootstrap to the access point device 200. On the other hand, if the comparison result is NG, indicating that the stored biometric information (user's voice) and the received biometric information (operator's voice) do not match, the determination unit 120 determines that connection is not possible and issues an authentication failure to the access point device 200.
[0030] Upon receiving the Bootstrap, the access point device 200 performs the process of newly connecting the enloading terminal 400 in the same manner as in conventional technology. One example of this is the process of exchanging DPP Authentication, DPP Configuration, etc., between the access point device 200 and the enloading terminal 400.
[0031] The following describes the processing flow by the authentication server 100. As shown in Figure 5, when the authentication server 100 receives a probe request containing biometric information (Step S01, Yes), it compares the stored biometric information with the received biometric information (Step S02). If the comparison result is OK (Step S02, Yes), the authentication server 100 determines that the connection is permitted and issues a Bootstrap to the access point device 200 (Step S03), and then waits for a probe request again (returns to Step S01). If the comparison result is NG (No) (Step S02, No), the authentication server 100 determines that the connection is not possible and issues an authentication failure to the access point device 200 (Step S04), and then waits for a probe request again (returns to Step S01).
[0032] As described above, the present invention makes it easier to establish new connections for terminals to a network while maintaining security.
[0033] [Variant form] (1) The biometric information stored by the authentication server 100 is not limited to the biometric information of the person who installed the access point device 200. In other words, the user is not limited to the person who installed the access point device 200.
[0034] For example, the user may be the person who first registers a terminal connection to the access point device 200. In this case, the authentication server 100 receives the user's biometric information as the first new connection request and stores the received biometric information in association with the device ID of the access point device 200.
[0035] Alternatively, the owner of the configurator device 300 may also be considered a user.
[0036] (2) The biometric information stored in the authentication server 100 may belong to multiple individuals. Let's illustrate with a specific example. First, suppose "Father" installs an access point device 200 (home Wi-Fi router), and "Father's" biometric information is stored in the authentication server 100. Now, when "Mother" connects her Enrolly terminal 400, she needs to enter "Father's" biometric information. At that time, "Mother's" biometric information may also be stored in the authentication server 100. In this case, when "Mother" connects another Enrolly terminal 400, she only needs to enter her own biometric information. In other words, "Father" can be considered the primary user, and "Mother" can be considered a secondary user who has been authenticated by the primary user.
[0037] (3) As described above, when the first Enroller terminal 400 owned by "Mother" is newly connected, the biometric information of "Father" is required. Here, the authentication server 100 may request the input of biometric information via the Enroller terminal 400 owned by "Father" that has already been registered for connection.
[0038] (4) When connecting a new enrollment terminal 400, the user's biometric information may be entered from any of the following: the access point device 200, the configurator device 300, a registered enrollment terminal 400, or the new enrollment terminal 400.
[0039] As an example, consider a case where a new enrollment terminal 400 is connected by reading a QR code displayed on the display of the new enrollment terminal 400 using the configurator device 300. In this case, the configurator device 300 may request the user to input biometric information for its own device, or the new enrollment terminal 400 may request the user to input biometric information for its own device. Here, it is also considered that the "configurator device 300" and the "enrollment terminal 400 that has already been registered for connection" are the same device.
[0040] Furthermore, it is conceivable that a new connection to the enrolling terminal 400 may be established by the access point device 200 reading a QR code displayed on the display of the new enrolling terminal 400. In this case, the access point device 200 may request the user to input biometric information to its own device.
[0041] In any case, the present invention is applicable if the authentication server 100 can receive the user's biometric information as a new connection request for a new enrollment terminal 400.
[0042] (5) Furthermore, the present invention can also be developed as a program that causes a computer acting as an EasyConnect authentication server 100 to execute the processing of the present invention. For example, as shown in Figure 6, the computer includes memory, a CPU (Central Processing Unit), and an interface. The memory also stores information corresponding to the storage unit 110. The CPU reads the program of the present invention from the memory and executes it to realize a processing module corresponding to the determination unit 120.
[0043] Some or all of the above embodiments may also be described as follows, but are not limited to the following:
[0044] (Note 1) The EasyConnect authentication server stores the user's biometric information. When a new connection request for a new enloading terminal is received from a configurator device via an access point device, the determination step determines whether or not the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. Easy Connect authentication method, including [specific method / method].
[0045] (Note 2) The Easy Connect authentication method described in Appendix 1, where the user is the person who installed the access point device.
[0046] (Note 3) The Easy Connect authentication method described in Appendix 1, where the user is the owner of the configurator device.
[0047] (Note 4) The Easy Connect authentication method described in Appendix 1, wherein the user is the owner of the enrollment terminal connected to the access point device.
[0048] (Note 5) A memory unit that stores the user's biometric information, When a new connection request for a new enloading terminal is received from a configurator device via an access point device, the determination unit determines whether or not the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. An EasyConnect authentication server equipped with [feature name].
[0049] (Note 6) A computer acting as an EasyConnect authentication server that stores the user's biometric information, When a new connection request for a new enloading terminal is received from the configurator device via the access point device, a determination process is performed to determine whether the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. An EasyConnect authentication program that enables this process.
[0050] Furthermore, the features described in Appendix 2-4 can also be applied to the EasyConnect authentication server and EasyConnect authentication program.
[0051] Furthermore, each disclosure of the above-mentioned patent documents cited is incorporated into this document by reference and may be used as the basis or part of the present invention as necessary. Within the framework of the full disclosure of the present invention (including the claims), further modifications and adjustments to the embodiments or examples are possible based on the basic technical concept. Also, within the framework of the full disclosure of the present invention, various combinations or selections (including partial deletions) of various disclosure elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. In other words, the present invention naturally includes the full disclosure, including the claims, and various modifications and alterations that a person skilled in the art could make in accordance with the technical concept. In particular, with respect to the numerical ranges described in this document, any numerical value or sub-range included within that range should be interpreted as being specifically described, even if not otherwise stated. Furthermore, each disclosure of the above-mentioned cited documents may, as necessary, be used in part or in whole as part of the disclosure of the present invention, in accordance with the spirit of the present invention, and this is also considered to be included in the disclosure of this application. [Explanation of Symbols]
[0052] 100 Authentication Servers 110 Storage section 120 Judgment section 200 Access Point Devices 300 Configurator Devices 400 Enrollment Terminals
Claims
1. The EasyConnect authentication server stores the user's biometric information. When a new connection request for a new enloading terminal is received from a configurator device via an access point device, the determination step determines whether or not the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. Includes, The stored biometric information is the biometric information of a user associated with a first device or terminal different from the new enloading terminal. The received biometric information is the biometric information of a user linked to the second terminal, which is the new enloading terminal. If a match is found in the aforementioned verification, the user associated with the first device or terminal and the user associated with the second terminal are considered to be the same person, and the connection of the new enrollment terminal is permitted. Easy Connect authentication method.
2. The Easy Connect authentication method according to Claim 1, wherein the biometric information of a user associated with a first device or terminal different from the new enrollment terminal is the biometric information of the person who installed the access point device.
3. The Easy Connect authentication method according to Claim 1, wherein the biometric information of a user associated with a first device or terminal different from the new enrollment terminal is the biometric information of the owner of the configurator device.
4. The Easy Connect authentication method according to Claim 1, wherein the biometric information of a user associated with a first device or terminal different from the new enloading terminal is the biometric information of the owner of an enloading terminal already connected to the access point device.
5. A memory unit that stores the user's biometric information, When a new connection request for a new enloading terminal is received from a configurator device via an access point device, the determination unit determines whether or not the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. Equipped with, The stored biometric information is the biometric information of a user associated with a first device or terminal different from the new enloading terminal. The received biometric information is the biometric information of a user linked to the second terminal, which is the new enloading terminal. If a match is found in the aforementioned verification, the user associated with the first device or terminal and the user associated with the second terminal are considered to be the same person, and the connection of the new enrollment terminal is permitted. EasyConnect authentication server.
6. A computer acting as an EasyConnect authentication server that stores the user's biometric information, When a new connection request for a new enloading terminal is received from the configurator device via the access point device, a determination process is performed to determine whether the new enloading terminal can connect by comparing the stored biometric information with the received biometric information. An EasyConnect authentication program that enables the execution of The stored biometric information is the biometric information of a user associated with a first device or terminal different from the new enloading terminal. The received biometric information is the biometric information of a user linked to the second terminal, which is the new enloading terminal. If a match is found in the aforementioned verification, the user associated with the first device or terminal and the user associated with the second terminal are considered to be the same person, and the connection of the new enrollment terminal is permitted. Easy Connect Authentication Program.