Authentication device, authentication method, and authentication program
Patent Information
- Application Number
- JP2023145984
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-09-08
- Publication Date
- 2026-09-30
- Estimated Expiration
- 2043-09-08
AI Technical Summary
【0012】 本発明によれば、2段階認証の強度を向上できる。
Smart Images

Figure 0007926967000001 
Figure 0007926967000002 
Figure 0007926967000003
Abstract
Description
Technical Field
[0001] The present invention relates to a two-factor authentication system.
Background Art
[0002] Conventionally, two-factor authentication that requires a user to input a one-time password notified to a mobile terminal via SMS (Short Message Service) has been widely adopted in order to improve security during user authentication for web services (see, for example, Patent Document 1).
Prior Art Literature
Patent Literature
[0003]
Patent Document 1
Summary of the Invention
Problem to be Solved by the Invention
[0004] However, in recent years, there have been attacks in which malware or the like transmits data described in SMS to the outside, eavesdrops on the content, and then authenticates by impersonating a legitimate user, and countermeasures against such SMS eavesdropping are desired.
[0005] An object of the present invention is to provide an authentication device, an authentication method, and an authentication program that can improve the strength of two-factor authentication.
Means for Solving the Problem
[0006] The authentication device according to the present invention is a device that performs two-factor authentication using an authentication message for login access accompanied by a user ID, and comprises: a communication restriction unit that restricts communication to an authentication terminal identified by a telephone number associated with the user ID in response to the login access, excluding specific communication destinations including the authentication message sending server and the authentication device; a message sending unit that sends the authentication message indicating a one-time password to the authentication terminal after the communication restriction has been implemented; an authentication processing unit that, upon receiving the one-time password from the authentication terminal, verifies the validity of the one-time password to complete the login using the user ID; and a communication restriction release unit that releases the communication restriction in response to the completion of the login.
[0007] The authentication processing unit may invalidate the one-time password once the login is complete.
[0008] The aforementioned communication regulation unit may maintain a whitelist of specific communication destinations.
[0009] The login page for the login access includes code that performs a detection access to the communication detection server subject to the communication restrictions, and the authentication processing unit may fail the login when it receives notification from the communication detection server that the detection access has been made.
[0010] The authentication method according to the present invention is a method in which an authentication device performs two-factor authentication using an authentication message for login access accompanied by a user ID, and in response to the login access, it performs a communication restriction step in which it restricts communication to an authentication terminal identified by a telephone number associated with the user ID, excluding specific communication destinations including the server that sends the authentication message and the authentication device; after the communication restriction is implemented, it sends the authentication message indicating a one-time password to the authentication terminal; when it receives the one-time password from the authentication terminal, it verifies the validity of the one-time password to complete the login with the user ID; and in response to the completion of the login, it performs a communication restriction release step to release the communication restriction.
[0011] The authentication program according to the present invention is for causing a computer to function as the authentication device. [Effects of the Invention]
[0012] According to the present invention, the strength of two-factor authentication can be improved. [Brief explanation of the drawing]
[0013] [Figure 1] This figure shows the functional configuration of the authentication system in the first embodiment. [Figure 2] This is a sequence diagram showing the conventional SMS authentication process. [Figure 3] This sequence diagram illustrates what happens when an SMS eavesdropping attack occurs during the conventional SMS authentication process. [Figure 4] This is a sequence diagram showing the SMS authentication process in the first embodiment. [Figure 5] This is a sequence diagram showing the SMS authentication process in the second embodiment. [Modes for carrying out the invention]
[0014] [First Embodiment] Hereinafter, a first embodiment of the present invention will be described. The authentication server (authentication device) of the present embodiment prevents impersonation via SMS eavesdropping on a terminal by stopping general data communication of the user from the base station side before transmitting an SMS, and resuming the communication after authentication is completed.
[0015] FIG. 1 is a diagram showing the functional configuration of an authentication system 1 according to the present embodiment. The authentication system 1 is configured to perform SMS authentication using an authentication terminal 20 when a login terminal 30 performs login access accompanied by a user ID to the authentication server 10. Information including the telephone number of the authentication terminal 20 owned by a user is registered in the authentication server 10 in advance in association with the user ID. Note that the authentication terminal 20 may also serve as the login terminal 30.
[0016] The authentication terminal 20 is an information processing device capable of receiving an authentication message (hereinafter referred to as SMS) based on a telephone number for two-step authentication, and corresponds to a mobile terminal such as a smartphone. In the authentication terminal 20, in addition to an application (browser application) for accessing the authentication server 10, an application for receiving SMS operates.
[0017] The authentication server 10 is an information processing device including a control unit 11, a storage unit 12, and various input / output interfaces and the like. The control unit 11 functions as a communication restriction unit 111, a message transmission unit 112, an authentication processing unit 113, and a communication restriction cancellation unit 114 by executing software (authentication program) stored in the storage unit 12.
[0018] In response to login access accompanied by a user ID from the login terminal 30, the communication restriction unit 111 implements communication restriction excluding specific communication destinations including the authentication message transmission server and the authentication server 10 for the authentication terminal 20 identified by the telephone number associated with the user ID.
[0019] This communication restriction allows only communication to some IP addresses including the authentication server 10 and the SMS transmission server for communication from the authentication terminal 20. Specifically, this communication restriction is, for example, the same type of restriction as that which allows access only to an additional purchase page for communication data volume via additional charging when a user has used up the contract maximum communication data volume, and can be implemented by existing technology.
[0020] The communication restriction unit 111 may hold a whitelist of specific communication destinations with which the authentication terminal 20 is allowed to communicate. For example, a whitelist of important services such as emergency earthquake early warning by ETWS (Earthquake and Tsunami Warning System) and emergency calls may be held and communication may be maintained. However, since this communication restriction is intended to prevent information transfer to third parties, even if it is a site from a reliable provider, it is subject to restriction if it has a communication function with any arbitrary party or a data storage function or the like.
[0021] The message transmission unit 112 transmits an authentication message indicating a one-time password to the authentication terminal 20 after the communication restriction is implemented by the communication restriction unit 111. Note that the SMS may be transmitted via an SMS transmission server that is exempted from the communication restriction.
[0022] When the authentication processing unit 113 receives the one-time password indicated by SMS from the authentication terminal 20, it completes the login with the user ID by verifying the validity of this one-time password. Then, when the login is completed, the authentication processing unit 113 invalidates the one-time password used for authentication.
[0023] The communication restriction cancellation unit 114 cancels the communication restriction in response to the completion of login, and enables normal communication at the authentication terminal 20.
[0024] Here, the flow of SMS authentication according to the present embodiment will be described in comparison with the conventional flow. For the sake of simplicity, we will assume that authentication terminal 20 also functions as login terminal 30.
[0025] Figure 2 is a sequence diagram showing the conventional SMS authentication process. In step S1, the authentication terminal 20 accesses the login page of the authentication server 10 and attempts to log in using the user ID and password. In step S2, the authentication server 10 sends an SMS containing a one-time password to the authentication terminal 20 associated with the user ID.
[0026] In step S3, the authentication terminal 20 accepts the user's input of a one-time password sent via SMS to the login page. In step S4, the authentication terminal 20 sends the entered one-time password to the authentication server 10. In step S5, the authentication server 10 verifies the validity of the received one-time password, notifies the authentication terminal 20 of the completion of login, and sends the authentication information.
[0027] Figure 3 is a sequence diagram illustrating what happens when an SMS eavesdropping attack occurs in the conventional SMS authentication process. In step S11, the attacker's terminal (malicious server) accesses the authentication server 10 login page and attempts to log in using the user ID and password. In step S12, the authentication server 10 sends an SMS containing a one-time password to the authentication terminal 20 associated with the user ID.
[0028] In step S13, the malware running on authentication terminal 20 reads the one-time password contained in the received SMS. In step S14, the malware sends the read one-time password to a malicious server. In step S15, the malicious server sends the received one-time password to the authentication server 10. In step S16, the authentication server 10 verifies the legitimacy of the received one-time password, notifies the malicious server that sent the password that the login is complete, and sends the authentication information.
[0029] Figure 4 is a sequence diagram showing the SMS authentication process in this embodiment. In step S21, the authentication terminal 20 accesses the login page of the authentication server 10 and attempts to log in using the user ID and password. In step S22, the authentication server 10 implements communication restrictions on the authentication terminal 20 associated with the user ID. In step S23, the authentication server 10 sends an SMS containing a one-time password to the authentication terminal 20.
[0030] In step S24, the authentication terminal 20 accepts the user's input of a one-time password sent via SMS to the login page. In step S25, the authentication terminal 20 sends the entered one-time password to the authentication server 10. In step S26, the authentication server 10 verifies the validity of the received one-time password, notifies the authentication terminal 20 of the completion of login, and sends the authentication information.
[0031] In step S27, the authentication server 10 invalidates the one-time password used for authentication. In step S28, the authentication server 10 releases the communication restriction implemented in step S22.
[0032] According to this embodiment, in two-factor authentication using SMS, the authentication system 1 implements communication restrictions on the authentication terminal 20, excluding the authentication server 10 and the server involved in sending SMS messages. Therefore, by limiting the period during which the authentication terminal 20 can use the one-time password to the period during which communication restrictions are in place, the authentication system 1 can prevent attackers from reading the one-time password and sending it to a third party, even if the authentication terminal 20 contains malware. This prevents impersonation and improves the strength of two-factor authentication.
[0033] Furthermore, once the authentication server 10 successfully completes SMS authentication and the user's login is finished, it invalidates the one-time password used for authentication. This allows authentication system 1 to prevent the reuse of one-time passwords after communication restrictions are lifted, thereby ensuring security.
[0034] Furthermore, the authentication server 10 may maintain a whitelist of specific communication destinations to be excluded from communication restrictions. For example, by enabling the reception of earthquake early warnings and emergency calls, the authentication system 1 can avoid the risk of the authentication terminal 20 being unable to use important services during the authentication sequence.
[0035] [Second Embodiment] A second embodiment of the present invention will be described below. In this embodiment, the authentication terminal 20 has other communication means, such as Wi-Fi (registered trademark), in addition to mobile communication. In this case, the aforementioned communication restrictions alone would still allow communication to third parties.
[0036] Therefore, the authentication server 10 first notifies the user on the login page that Wi-Fi must be turned off in order to log in, and prompts the user to do so. Alternatively, the login page may include code to automatically turn off Wi-Fi. Furthermore, the authentication system 1 includes a communication detection server 40, and the login page provided by the authentication server 10 includes code for performing detection access to this communication detection server 40. Here, the communication detection server 40 is subject to communication restrictions and cannot be accessed via mobile communication during communication restrictions.
[0037] When the authentication processing unit 113 of the authentication server 10 receives notification from the communication detection server 40 that there has been a detection access, it determines that the authentication terminal 20 has another means of communication and, even if it receives a valid one-time password, it does not permit the login and causes it to fail.
[0038] Figure 5 is a sequence diagram showing the SMS authentication process in this embodiment. In step S31, the authentication terminal 20 accesses the login page of the authentication server 10 and attempts to log in using the user ID and password. In step S32, the authentication server 10 implements communication restrictions on the authentication terminal 20 associated with the user ID.
[0039] In step S33, if the authentication terminal 20 has a communication method such as Wi-Fi enabled in addition to the restricted mobile communication, it attempts to access the detection page of the communication detection server 40 according to a code pre-included on the login page. In step S34, the communication detection server 40 notifies the authentication server 10 that an access has been made from the authentication terminal 20. In step S35, the authentication server 10 disables login if it receives a notification from the communication detection server 40.
[0040] In step S36, the authentication server 10 sends an SMS containing a one-time password to the authentication terminal 20 only if it has not received a notification from the communication detection server 40. In step S37, the authentication terminal 20 accepts the user's input of a one-time password provided in the SMS message to the login page. In step S38, the authentication terminal 20 sends the entered one-time password to the authentication server 10. In step S39, the authentication server 10 verifies the validity of the received one-time password, notifies the authentication terminal 20 of the completion of login, and sends the authentication information.
[0041] In step S40, the authentication server 10 invalidates the one-time password used for authentication. In step S41, the authentication server 10 releases the communication restriction implemented in step S22.
[0042] According to this embodiment, the authentication terminal 20 attempts to access the communication detection server 40 subject to communication restrictions, according to a code pre-included on the login page. The authentication server prohibits login if this access occurs. This allows authentication system 1 to detect that there has been access to a page that should be restricted from receiving communications, and to determine that there is a possibility that intercepted SMS data may be sent externally. Therefore, by disabling login in this case, the strength of two-factor authentication can be improved.
[0043] Furthermore, the aforementioned embodiment makes it possible to improve the strength of SMS authentication, for example, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0044] Although embodiments of the present invention have been described above, the present invention is not limited to the embodiments described above. Furthermore, the effects described in the embodiments described above are merely a list of the most preferred effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0045] The authentication method by authentication system 1 is implemented by software. When implemented by software, the programs constituting this software are installed on an information processing device (computer). These programs may be distributed to users by being recorded on removable media such as a CD-ROM, or by being downloaded to the user's computer via a network. [Explanation of Symbols]
[0046] 1. Authentication System 10 Authentication Server 11 Control Unit 12 Storage section 20 Authentication terminals 30 Login terminals 40 Server for communication detection 111 Communications Regulatory Department 112 Message sending section 113 Authentication Processing Unit 114 Communication Restriction Deactivation Section
Claims
1. An authentication device that performs two-factor authentication using an authentication message for login access accompanied by a user ID, A communication restriction unit implements communication restrictions on the authentication terminal identified by the telephone number associated with the user ID in response to the login access, excluding specific communication destinations, including the authentication message sending server and the authentication device. After the aforementioned communication restriction is implemented, a message transmission unit transmits the authentication message containing the one-time password to the authentication terminal. Upon receiving the one-time password from the authentication terminal, the authentication processing unit verifies the validity of the one-time password and completes the login using the user ID. An authentication device comprising: a communication restriction release unit that releases the communication restriction upon completion of the aforementioned login.
2. The authentication device according to claim 1, wherein the authentication processing unit invalidates the one-time password when the login is completed.
3. The authentication device according to claim 1, wherein the communication regulation unit maintains a whitelist of specific communication destinations.
4. The login page for the aforementioned login access includes code that performs detection access to the communication detection server subject to the aforementioned communication restrictions, The authentication device according to claim 1, wherein the authentication processing unit, upon receiving notification from the communication detection server that a detection access has occurred, causes the login to fail.
5. An authentication method in which an authentication device performs two-factor authentication using an authentication message for login access accompanied by a user ID, A communication restriction step in which, in response to the login access, communication restrictions are implemented for the authentication terminal identified by the telephone number associated with the user ID, excluding specific communication destinations including the authentication message sending server and the authentication device, After the aforementioned communication restriction is implemented, a message transmission step is performed to send the authentication message containing the one-time password to the authentication terminal. Upon receiving the one-time password from the authentication terminal, the authentication process step completes the login using the user ID by verifying the validity of the one-time password. An authentication method that performs a communication restriction removal step to remove the communication restriction in response to the completion of the aforementioned login.
6. An authentication program for causing a computer to function as an authentication device according to any one of claims 1 to 4.
Citation Information
Patent Citations
Authentication system, authentication server, authentication method, and authentication program
JP2007058469A
Authentication server, authentication system, authentication method and authentication program
JP2022049854A
Computer-based systems configured for one-time passcode (OTP) protection and methods of use thereof
US20230096899A1
System and method for authentication using a mobile communication device
US9119076B1