Authentication system, terminal, authentication server, authentication method, and program
Patent Information
- Application Number
- JP2025509354
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-07-23
- Publication Date
- 2025-10-03
AI Technical Summary
Existing authentication systems over networks fail to ensure confidentiality of user and device information during authentication, making it difficult to detect impersonation if authentication data is stolen.
The system uses a terminal and authentication server that generate and verify signatures using private keys linked to user and device certificates, ensuring encrypted communication to protect confidentiality and authenticate users and devices securely.
This approach allows for the verification of user and device authenticity while safeguarding confidential information, preventing impersonation and ensuring secure network connections.
Abstract
Description
Authentication system, terminal, authentication server, authentication method, and recording medium
[0001] The present disclosure relates to an authentication system, a terminal, an authentication server, an authentication method, and a recording medium.
[0002] When a user authenticates to an authentication system via a network, there is a technology that uses information about the user and the terminal to perform authentication.
[0003] Patent Document 1 discloses a method for authenticating a user by verifying whether the user has signed a nonce sent from an authentication server with his or her own private key.
[0004] Special Publication No. 2022-530136
[0005] However, in the invention described in Patent Document 1, when performing authentication, the PIN (Personal Identification Number) code entered by the user is transmitted to the authentication server together with a nonce. As a result, the confidentiality of the authentication information used during authentication is not ensured. Therefore, if the authentication information is stolen on the network, it is difficult for the authentication server to detect impersonation of the user or terminal.
[0006] An example of an objective of the present disclosure is to provide an authentication system that can verify the authenticity of a user and a terminal while protecting confidential information of the user and the terminal in authentication via a network.
[0007] An authentication system in one aspect of the present disclosure is an authentication system having a terminal and an authentication server for using a network system from the terminal, wherein the terminal is equipped with a security function means that generates a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signs specified data using the respective private keys, and a transmission / reception means that transmits signature data signed with the first private key and the second private key to the authentication server via cryptographic communication, and the authentication server is equipped with a verification means that verifies the signature data using a user certificate and a device certificate that it holds in advance, and a connection means that enables the terminal to connect to the network system if the user and device can be verified.
[0008] A terminal in one aspect of the present disclosure includes a security function means that generates a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signs specified data using the respective private keys, and a transmission / reception means that transmits signature data signed with the first private key and the second private key to an authentication server that authenticates the user and device via cryptographic communication.
[0009] An authentication server in one aspect of the present disclosure includes a verification means that verifies the user and device using a user certificate and a device certificate that are stored in advance for signature data received from the terminal to be authenticated, the signature data being signed with a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and a connection means that enables the terminal to connect to a network system if the user and device can be verified.
[0010] An authentication method in one aspect of the present disclosure is an authentication method in which an authentication server authenticates a terminal using a network system, in which the terminal generates a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, signs specified data using the respective private keys, and transmits the signature data signed with the first private key and the second private key to the authentication server via cryptographic communication, and the authentication server verifies the signature data using the user certificate and device certificate that it holds in advance, and if verification is successful, enables the terminal to connect to the network system.
[0011] In one aspect of the present disclosure, a recording medium stores a program that causes a computer to generate a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, sign specified data using the respective private keys, and transmit the signature data signed with the first private key and the second private key to an authentication server that authenticates the user and device via cryptographic communication.
[0012] In one aspect of the present disclosure, a recording medium stores a program that causes a computer to verify signature data received from a terminal to be authenticated, signed with a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, using a user certificate and device certificate that are stored in advance, and if verification is successful, enabling the terminal to connect to a network system.
[0013] According to one example of the effect of the present disclosure, it is possible to verify the authenticity of a user and a terminal while protecting the confidential information of the user and the confidential information of the user terminal.
[0014] Fig. 1 is a block diagram showing the configuration of an authentication system according to the present disclosure. Fig. 2 is a diagram showing a hardware configuration in which a terminal, an authentication authority server, and an authentication server according to the present disclosure are realized by a computer device and its peripheral devices. Fig. 3 is a flowchart showing the operation of the authentication system according to the present disclosure. Fig. 4 is a flowchart showing the operation of the authentication system according to the present disclosure.
[0015] Next, an embodiment will be described in detail with reference to the drawings.
[0016] [First Embodiment] Fig. 1 is a block diagram showing the configuration of an authentication system 10 according to the present disclosure. The authentication system 10 includes a terminal 100, a certificate authority server 200, and an authentication server 300, which are connected to one another via a network. While Fig. 1 illustrates a single terminal 100, multiple terminals 100 may be connected to a network system. The network system includes services or systems used on the network. The authentication system 10 is a system for verifying the authenticity of users and terminals when connecting to the network system. Authenticity refers to, for example, the ability to verify that the users and terminals are genuine and not impersonated users or terminals.
[0017] 2 is a diagram illustrating an example of a hardware configuration in which each of the terminal 100, the certificate authority server 200, and the authentication server 300 according to the first embodiment of the present disclosure is implemented by a computer device 500 including a processor. As shown in FIG. 2, the terminal 100, the certificate authority server 200, and the authentication server 300 each include a central processing unit (CPU) 501, memories such as a read-only memory (ROM) 502 and a random access memory (RAM) 503, a storage device 505 such as a hard disk for storing a program 504, a communication interface (I / F) 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the first embodiment, the terminal 100, the certificate authority server 200, and the authentication server 300 are connected to each component via a bus 512.
[0018] The CPU 501 operates an OS to control the terminal 100, the certificate authority server 200, and the authentication server 300 according to the first embodiment of the present invention. The CPU 501 also reads programs and data into memory from a recording medium 506 attached to, for example, a drive device 507. The CPU 501 also functions as a means for realizing each component of the terminal 100, the certificate authority server 200, and the authentication server 300 according to the first embodiment, or as a part of these components, and executes processing or commands in the flowcharts shown in Figures 3 and 4, which will be described later, based on the programs.
[0019] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium in the storage device is a non-volatile storage device, and the program is recorded therein. The program may also be downloaded from an external computer (not shown) connected to a communication network.
[0020] The input device 509 is realized by, for example, a mouse, a keyboard, built-in key buttons, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or built-in key buttons, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display, and is used to check output.
[0021] As described above, the terminal 100, the certificate authority server 200, and the authentication server 300 in Fig. 1 are realized by the computer hardware shown in Fig. 2. However, the means for realizing each component of the terminal 100, the certificate authority server 200, and the authentication server 300 are not limited to the configurations described in this specification.
[0022] <Certificate Registration> First, a method for registering a user certificate and a device certificate used for authentication in the authentication server 300 will be described.
[0023] 1, the terminal 100 is a device for using a network system, and includes a user authentication unit 101, a security function unit 102, and a transmission / reception unit 103.
[0024] The user authentication unit 101 collates identification information that identifies a user. The identification information includes one or more pieces of biometric information such as veins, fingerprints, palms, irises, voice, and faces, or a PIN code. The user authentication unit 101 accepts identification information input by a user. The user authentication unit 101 may also obtain the user's identification information by reading data in an IC card that stores the identification information. The user authentication unit 101 also collates the input identification information with the user's identification information stored in the terminal 100, and if the match is successful, the user signs in to the terminal 100.
[0025] The security function unit 102 includes a tamper-resistant storage area. The security function unit 102 is an area that is difficult to tamper with by a malicious third party. The security function unit 102 is configured with a hardware cryptographic module, such as a TPM (Trusted Platform Module), but is not limited to this as long as it has a configuration that can achieve tamper resistance. The TPM has high tamper resistance because it is difficult to tamper with the OS, hardware, or external physical hacking.
[0026] The security function unit 102 stores an endorsement key that was enclosed during the manufacturing process of the terminal 100. The endorsement key is assigned a unique identifier for each hardware cryptographic module and is used to identify the hardware cryptographic module.
[0027] The security function unit 102 uses a random number generation circuit to generate a pair of a first private key and a first public key corresponding to a user certificate for authenticating the network system, and a pair of a second private key and a second public key corresponding to a device certificate. The user certificate and the device certificate are each linked to an endorsement key. The pair of the first private key and the first public key is used to verify the user, and the pair of the second private key and the second public key is used to verify the terminal 100. Each private key is, for example, a private key in an AIK (Attestation Identity Key) and is paired with the user certificate and the device certificate stored in the authentication server 300, respectively. Each security function unit 102 stores the generated private key in a storage area of the hardware cryptographic module. The transmission unit 113 transmits each generated public key to the certification authority server 200.
[0028] (Certification Authority Server 200) As shown in FIG. 1, the certification authority server 200 includes an authentication information storage unit 201, a verification unit 202, a certificate issuance unit 203, and a transmission unit 204.
[0029] The authentication information storage unit 201 stores an endorsement key certificate of the terminal 100. The endorsement key certificate includes endorsement key information and is received from the terminal 100 or the vendor of the terminal 100.
[0030] The verification unit 202 verifies the existence of the terminal 100 by a known method using the endorsement key certificate and the endorsement key information included in the second public key received from the terminal 100. If the verification unit 202 can verify the existence of the terminal 100, it outputs the first and second public keys to the certificate issuing unit 203. On the other hand, if the verification unit 202 cannot verify the existence, it notifies the terminal 100 to that effect.
[0031] If the certificate issuance unit 203 can verify the second public key, it issues a device certificate by adding a signature to the second public key using the certificate authority's signature generation key. Similarly, it issues a user certificate by adding a signature to the first public key using the certificate authority's signature generation key. The certificate issuance unit 203 issues these certificates based on, for example, X.509. The certificate issuance unit 203 may set a validity period for each certificate.
[0032] The transmitting unit 204 transmits the issued device certificate and user certificate to the authentication server 300. Note that each certificate may be encrypted using a predetermined method to enhance security. The transmitting unit 204 also notifies the terminal 100 that registration of the device certificate and user certificate has been completed.
[0033] <Authentication> Next, a method for authenticating a user and a device using a user certificate and a device certificate registered in the authentication server 300 will be described.
[0034] (Terminal 100) When the user authentication unit 101 receives identification information input by a user, it compares the input identification information with the user's identification information stored in the terminal 100, and if the comparison is successful, the user signs in to the terminal 100 using the input identification information. The user authentication unit 101 also sends an authentication request to the authentication server 300 requesting verification of the user and the terminal 100. The user authentication unit 101 sends the authentication request using encrypted communication such as SSL (Secure Sockets Layer) or TLS (Transport Layer Security).
[0035] The security function unit 102 signs predetermined data using each of the first private key corresponding to the user certificate and the second private key corresponding to the device certificate. Specifically, the security function unit 102 first signs a nonce sent from the authentication server 300 using either the first private key or the second private key, and the transmitting / receiving unit 103 transmits the signature data to the authentication server 300. Thereafter, the security function unit 102 signs the signed nonce sent again from the authentication server 300 using the other private key.
[0036] The transmitting / receiving unit 103 receives a nonce transmitted by encrypted communication from the authentication server 300. The transmitting / receiving unit 103 also transmits signature data signed with each private key to the authentication server 300 by encrypted communication.
[0037] (Authentication Server 300) The authentication server 300 includes an authentication information storage unit 301, a transmission / reception unit 302, a verification unit 303, and a connection unit 304. The authentication information storage unit 301 stores a user certificate and a device certificate for authenticating the network system in association with each other. These certificates are issued by the certificate authority server 200 and are used to verify signature data received from the terminal 100.
[0038] When the transmitting / receiving unit 302 receives an authentication request from the terminal 100, it transmits a nonce to the terminal 100 by encrypted communication. Furthermore, when the transmitting / receiving unit 302 receives signature data signed with one of the private keys, it transmits the signed nonce to the terminal 100 by encrypted communication. When the transmitting / receiving unit 302 receives signature data signed with both the first and second private keys, it outputs the signature data to the verifying unit 303.
[0039] The verification unit 303 verifies the signature data using the user certificate and device certificate. The verification method performed by the verification unit 303 is a known method, and for example, the verification unit 303 verifies the user and device by decrypting the signature data using the public key written in each certificate. Note that if a validity period is set for each certificate, the verification unit 303 also verifies whether the validity period is still valid.
[0040] If the connection unit 304 can verify the user and the device, it controls the network between the terminal 100 and the network system to enable connection of the terminal 100 to the network system. If the connection unit 304 cannot verify at least one of the user and the device, it notifies the terminal 100 of that fact.
[0041] 3 and 4 are flowcharts showing an outline of the operation of the authentication system 10 according to the present disclosure. The processing according to these flowcharts may be executed based on program control by the processor described above. The flowchart in Fig. 3 shows the operation performed when a user certificate and a device certificate are registered in the authentication server 300, and the flowchart in Fig. 4 shows the operation performed when authenticating a user and a terminal 100.
[0042] First, the operation of registering a user certificate and a device certificate will be described. As shown in FIG. 3 , in the terminal 100, the user authentication unit 101 first signs in to the terminal 100 using identification information entered by the user (step S101). Next, the security function unit 102 generates a pair of a first private key and a first public key corresponding to the user certificate linked to the endorsement key, and a pair of a second private key and a second public key corresponding to the device certificate linked to the endorsement key (step S102). The security function unit 102 stores the generated first and second private keys in the security function unit 102, and the transmission / reception unit 103 transmits the first and second public keys to the certificate authority server 200 (step S103). When the certificate authority server 200 receives the first and second public keys from the terminal 100, the verification unit 202 verifies the endorsement key included in the second public key (step S104). If the verification is successful (S105; YES), the certificate issuing unit 203 issues a user certificate and a device certificate (step S106), and the transmitting unit 204 transmits them to the authentication server 300 (step S107). The transmitting unit 204 also notifies the authentication server 300 that the certificate registration has been completed (step S108). On the other hand, if the verification is not successful (S105; NO), the transmitting unit 204 notifies the authentication server 100 that the verification has failed (step S109). Finally, the output device 510 of the terminal 100 displays a message indicating that the authentication has failed or that the certificate registration has been completed (step S110). This completes the operation of the authentication system 10 to register the user certificate and the device certificate.
[0043] Next, the authentication operation between the user and the terminal 100 will be described. As shown in FIG. 4 , first, the user authentication unit 101 of the terminal 100 signs in to the terminal 100 using identification information entered by the user (step S111) and transmits an authentication request to the authentication server 300 (step S112). Next, in the authentication server 300, the transmitting / receiving unit 302 transmits a nonce to the terminal 100 (step S113). Next, in the terminal 100, the security function unit 102 signs the nonce using either the first private key or the second private key (step S114) and transmits the signature data to the authentication server 300 (step S115). Next, the authentication server 300 transmits the signature data signed with either private key again to the terminal 100 (step S116), and the security function unit 102 signs the nonce using the other private key (step S117) and transmits it again to the authentication server 300 (step S118).
[0044] Next, upon receiving the signature data signed with both private keys, the verification unit 303 verifies the signature data using the user certificate and the device certificate (step S119). If the verification is successful (S120; YES), the connection unit 304 enables the terminal 100 to connect to the network system (step S121). On the other hand, if the verification is unsuccessful (S120; NO), the transmission / reception unit 302 notifies the terminal 100 that the authentication has failed (step S122) and displays the authentication failure on the output device 510 of the terminal 100 (step S123). This completes the authentication system 10's operation of authenticating the user and the device.
[0045] In this embodiment, in the operation of authenticating a user and a terminal 100, the security function unit 102 of the terminal 100 signs a nonce sent from the authentication server 300 using the private keys, namely, the first private key corresponding to the user certificate and the second private key corresponding to the device certificate, and the verification unit 303 of the authentication server 300 verifies the signature data using the user certificate and the device certificate. This makes it possible to verify that a genuine user and device are being used to access the network system. Therefore, it can be verified that the user and terminal 100 are not being spoofed.
[0046] Furthermore, in this embodiment, the authentication system 10 performs verification using signature data in which a nonce is signed with each private key and these certificates, without using information about the user and the terminal 100. Therefore, verification is possible while protecting the confidential information of the user who is to be authenticated and the confidential information of the terminal 100.
[0047] As described above, according to this embodiment, it is possible to verify the authenticity of the user and the terminal 100 while protecting the confidential information of the user and the terminal 100.
[0048] In this embodiment, the user certificate, the device certificate, and the corresponding private key are linked to an endorsement key that identifies the hardware cryptographic module, which enables verification of not only the authenticity of the terminal 100 but also the existence of the terminal 100.
[0049] [Variation of the First Embodiment] A variation of the first embodiment of the present disclosure will be described. In the first embodiment described above, the cryptographic communication for exchanging data when signing using one of the first and second private keys is the same as the cryptographic communication for exchanging data when signing using the other private key. In contrast, different cryptographic communication may be used for exchanging data when signing each signature. That is, the security function unit 102 signs a nonce received from the authentication server 300 via the first cryptographic communication using one of the first and second private keys, and transmits the signature data to the authentication server 300 via the first cryptographic communication via the transmission / reception unit 103. Furthermore, the security function unit 102 signs a nonce with signature data received from the authentication server 300 via the second cryptographic communication using the other private key, and transmits the signature data signed with the first and second private keys to the authentication server 300 via the second cryptographic communication via the transmission / reception unit 103.
[0050] Furthermore, the security function unit 102 may sign the nonce received from the authentication server 300 when connecting to the network system using an aggregate signature obtained by aggregating the first private key and the second private key. For example, a Schnorr signature can be used as the aggregate signature. In this case, the number of times data is exchanged when sending signature data can be reduced, thereby reducing the transmission load on the network.
[0051] [Application Example] An example of a network system to which the authentication system 10 of the present disclosure can be applied is an autonomous driving system. In this case, the authentication system 10 authenticates the user by verifying the authenticity of the user and the terminal 100 installed in the user's vehicle. In this system, once the user is authenticated, the user can use the autonomous driving system in his or her own vehicle.
[0052] Another network system to which the authentication system 10 of the present disclosure can be applied is a car rental system. In this network system, the user certificate includes information about the validity period, and the validity period is set to correspond to the rental time of the car. In this case, the authentication system 10 verifies the authenticity of the user and the terminal 100 installed in the car used by the user, and verifies whether the user certificate is within its validity period. According to this system, the user is authenticated only if the user certificate is within its validity period, and the user can connect to the system to drive the car only during the rental time.
[0053] Although the present invention has been described above with reference to various embodiments, the present invention is not limited to the above embodiments. Various modifications to the configuration and details of the present invention that are understandable to those skilled in the art can be made within the scope of the present invention. For example, although multiple operations are described in order in the form of a flowchart, the order of description does not limit the order in which the multiple operations are performed. Therefore, when implementing each embodiment, the order of the multiple operations can be changed as long as it does not interfere with the content.
[0054] Some or all of the above-described embodiments can be described as follows: However, some or all of the above-described embodiments are not limited to the following.
[0055] (Supplementary Note 1) An authentication system having a terminal and an authentication server for using a network system from the terminal, wherein the terminal comprises: a security function means for generating a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signing specified data using the respective private keys; a sending and receiving means for sending signature data signed with the first private key and the second private key to the authentication server by encrypted communication; and the authentication server comprises: a verification means for verifying the signature data using the user certificate and the device certificate stored in advance; and a connection means for enabling the terminal to connect to the network system if the user and device can be verified.
[0056] (Supplementary Note 2) The authentication system according to Supplementary Note 1, wherein the security function means signs a nonce received from the authentication server by cryptographic communication upon connection to the network system, using one of the first private key and the second private key, and transmits the signature data to the authentication server via the transmission / reception means by cryptographic communication; after transmitting the signature data, signs the nonce with the signature data received from the authentication server by cryptographic communication, using the other private key, and transmits the signature data signed with the first private key and the second private key to the authentication server via the transmission / reception means by cryptographic communication.
[0057] (Supplementary Note 3) The authentication system according to Supplementary Note 1, wherein the security function means signs a nonce received from the authentication server through first cryptographic communication upon connection to the network system, using one of the first private key and the second private key, and transmits the signature data to the authentication server through the first cryptographic communication via the transmission / reception means; after transmitting the signature data, signs a nonce with signature data received from the authentication server through the second cryptographic communication, using the other private key, and transmits the signature data signed with the first private key and the second private key to the authentication server through the second cryptographic communication via the transmission / reception means.
[0058] (Supplementary Note 4) The authentication system described in Supplementary Note 1, wherein the security function means signs a nonce received from the authentication server via cryptographic communication when connecting to the network system, using a private key formed by aggregating the first private key and the second private key.
[0059] (Supplementary Note 5) An authentication system according to any one of Supplementary Notes 1 to 4, wherein the user certificate includes information regarding a validity period, and the authentication server permits the terminal to connect to the network system only within the validity period.
[0060] (Supplementary Note 6) The authentication system according to any one of Supplementary Notes 1 to 5, further including a certificate authority server, the certificate authority server comprising: a verification means for verifying the existence of the terminal when issuance of the device certificate is requested from the terminal; and a certificate issuing means for issuing the user certificate and the device certificate when the existence is confirmed.
[0061] (Supplementary Note 7) The authentication system according to any one of Supplementary Notes 1 to 6, wherein the network system is an autonomous driving system.
[0062] (Supplementary Note 8) The authentication system according to any one of Supplementary Notes 1 to 6, wherein the network system is a car rental system, and the user certificate has a validity period set corresponding to a rental time.
[0063] (Supplementary Note 9) A terminal comprising: a security function means for generating a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signing specified data using the respective private keys; and a transmission / reception means for transmitting signature data signed with the first private key and the second private key to an authentication server that authenticates the user and device by cryptographic communication.
[0064] (Supplementary Note 10) An authentication server comprising: a verification means for verifying a user and a device using a user certificate and a device certificate stored in advance for signature data received from a terminal to be authenticated, the signature data being signed with a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key; and a connection means for enabling connection of the terminal to a network system when the user and the device can be verified.
[0065] (Supplementary Note 11) An authentication method in which an authentication server authenticates a terminal that uses a network system, wherein the terminal generates a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, signs specified data using the respective private keys, transmits signature data signed with the first private key and the second private key to the authentication server via cryptographic communication, and the authentication server verifies the signature data using the user certificate and the device certificate that it holds in advance, and if verification is successful, enables the terminal to connect to the network system.
[0066] (Supplementary Note 12) A recording medium storing a program that causes a computer to execute the following steps: generate a first private key corresponding to a user certificate linked to an endorsement key, and a second private key corresponding to a device certificate linked to the endorsement key; sign specified data using the respective private keys; and transmit the signature data signed with the first private key and the second private key to an authentication server that authenticates the user and device via cryptographic communication.
[0067] (Supplementary Note 13) A recording medium storing a program that causes a computer to verify signature data received from a terminal to be authenticated, signed with a first private key corresponding to a user certificate linked to an endorsement key, and a second private key corresponding to a device certificate linked to the endorsement key, using the user certificate and device certificate stored in advance, and if verification is successful, enabling the terminal to connect to a network system.
[0068] 10 Authentication system 100 Terminal 101 User authentication unit 102 Security function unit 103 Transmission / reception unit 200 Certificate authority server 201 Authentication information storage unit 202 Verification unit 203 Certificate issuing unit 204 Transmission unit 300 Authentication server 301 Authentication information storage unit 302 Transmission / reception unit 303 Verification unit 304 Connection unit 500 Computer device 501 CPU 502 ROM 503 RAM 504 Program 505 Storage device 506 Recording medium 507 Drive device 508 Communication interface 509 Input device 510 Output device 511 Input / output interface 512 Bus
Claims
1. An authentication system having a terminal and an authentication server for using a network system from the terminal, the terminal includes a security function means for generating a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signing predetermined data using the respective private keys; a transmitting / receiving means for transmitting signature data signed with the first private key and the second private key to the authentication server by encrypted communication; a verification unit configured to verify the signature data using the user certificate and the device certificate stored in advance in the authentication server; and a connection means for enabling the terminal to connect to the network system if the user and device can be verified.
2. the security function means signs a nonce received from the authentication server by cryptographic communication when connecting to the network system, using either the first private key or the second private key, and transmits the signature data to the authentication server via the transmission / reception means by cryptographic communication; 2. The authentication system according to claim 1, wherein, after transmitting the signature data, a nonce with the signature data received from the authentication server through the cryptographic communication is signed using the other private key, and the signature data signed with the first private key and the second private key is transmitted to the authentication server via the transmitting / receiving means through the cryptographic communication.
3. the security function means signs a nonce received from the authentication server through first cryptographic communication at the time of connection to the network system, using either the first private key or the second private key, and transmits the signature data to the authentication server through the first cryptographic communication via the transmission / reception means; 2. The authentication system according to claim 1, wherein, after transmitting the signature data, a nonce with the signature data received from the authentication server through second cryptographic communication is signed using the other private key, and the signature data signed with the first private key and the second private key is transmitted to the authentication server through the second cryptographic communication via the transmission and reception means.
4. 2. The authentication system according to claim 1, wherein the security function means signs a nonce received from the authentication server by encrypted communication when connecting to the network system, using a private key obtained by aggregating the first private key and the second private key.
5. the user certificate includes information regarding a validity period; 3. The authentication system according to claim 1, wherein the authentication server permits the terminal to connect to the network system only during the validity period.
6. The authentication system further includes a certificate authority server; a verification means for verifying the existence of the terminal when a request for issuance of a device certificate is received from the terminal; 3. The authentication system according to claim 1, further comprising a certificate issuing unit that issues the user certificate and the device certificate when the existence of the user certificate and the device certificate is confirmed.
7. The authentication system according to claim 1 or 2, wherein the network system is an automated driving system.
8. 3. The authentication system according to claim 1, wherein the network system is a car rental system, and the user certificate has a validity period set corresponding to a rental period.
9. a security function means for generating a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signing predetermined data using the respective private keys; a transmitting / receiving means for transmitting signature data signed with the first private key and the second private key to an authentication server that authenticates a user and a device by cryptographic communication.
10. a verification means for verifying a user and a device, using the user certificate and the device certificate stored in advance, for signature data received from the terminal to be authenticated and signed with a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key; and a connection means for enabling the terminal to connect to a network system if the user and device can be verified.
11. An authentication method in which an authentication server authenticates a terminal that uses a network system, comprising: the terminal generates a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signs predetermined data using the respective private keys; transmitting signature data signed with the first private key and the second private key to the authentication server by encrypted communication; the authentication server verifies the signature data using the user certificate and the device certificate stored in advance; An authentication method that allows the terminal to connect to the network system if the authentication is successful.
12. generating a first private key corresponding to a user certificate linked to an endorsement key and a second private key corresponding to a device certificate linked to the endorsement key, and signing predetermined data using the respective private keys; A program that causes a computer to execute the following: sending signature data signed with the first private key and the second private key to an authentication server that authenticates a user and a device by cryptographic communication.
13. A program that causes a computer to verify signature data received from a terminal to be authenticated, signed with a first private key corresponding to a user certificate linked to an endorsement key, and a second private key corresponding to a device certificate linked to the endorsement key, using the user certificate and device certificate that are stored in advance, and if verification is successful, enabling the terminal to connect to a network system.