Authentication method for information access, authentication device for information access, and authentication program for information access
The authentication method addresses the challenge of using contact information in restricted data environments by employing hash value verification and code transmission, allowing for secure user authentication without storing sensitive contact information.
Patent Information
- Application Number
- PCT/JP2024/042216
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-11-28
- Publication Date
- 2025-06-12
AI Technical Summary
Existing authentication methods that use contact information, such as email addresses or phone numbers, face restrictions in countries where such information is considered sensitive personal data, making it difficult for systems providing international services to perform user authentication.
An authentication method that receives first authentication information, compares it with registered information, and then uses contact information to calculate and verify hash values, sending a code to the contact information destination for verification, thereby performing user authentication without storing the contact information itself.
This method enables user authentication without holding contact information, complying with strict data protection regulations by using hash values and avoiding permanent storage of sensitive user data across international borders.
Smart Images

Figure JP2024042216_12062025_PF_FP_ABST
Abstract
Description
Authentication method for information access, authentication device for information access, and authentication program for information access
[0001] The present disclosure relates to an authentication method for information access, an authentication device for information access, and an authentication program for information access.
[0002] Japanese Patent Application Laid-Open No. 2010-79795 discloses a technology relating to an authentication method for two-factor authentication.
[0003] When authenticating a user, contact information such as email addresses and phone numbers is widely used to contact the user. For example, email addresses are used for user accounts, or contact information is used as a possession factor in addition to knowledge factors such as passwords for two-factor authentication. However, some countries consider contact information to be important personal information and strictly restrict its transfer overseas. As a result, systems providing services from overseas cannot store and use contact information such as email addresses and phone numbers for contacting users in persistent storage.
[0004] The present disclosure has been made in consideration of the above points, and aims to provide an authentication method for information access, an authentication device for information access, and an authentication program for information access that perform user authentication without retaining contact information for contacting the user.
[0005] In order to achieve the above object, an authentication method for information access related to the technology of the present disclosure includes a processor receiving first authentication information from a device, comparing the received first authentication information with registered first authentication information, and if the comparison is confirmed, receiving contact information for contacting the user as the second authentication information, calculating a hash value of the received second authentication information, comparing the calculated hash value with the registered hash value, and if the comparison of the hash values is confirmed, sending an arbitrary code to the contact information, accepting the sent code, and comparing the received code with the code sent to the contact information.
[0006] If the hash value matches, the processor may execute a process of generating the code and transmitting the generated code to the contact information.
[0007] The contact information may be the user's email address and / or phone number.
[0008] The first authentication information may be a user ID or a user ID and a password.
[0009] The first authentication information may be an electronic signature generated using a private key recorded on the device, and the processor may verify the received electronic signature using a registered public key.
[0010] In order to achieve the above object, an authentication device for information access related to the technology of the present disclosure includes a processor, which receives first authentication information from a device, compares the received first authentication information with registered first authentication information, and if the match is confirmed, receives contact information for contacting the user as the second authentication information, calculates a hash value of the received second authentication information, compares the calculated hash value with the registered hash value, and if the match is confirmed, sends an arbitrary code to the contact information, accepts the sent code, and executes a process of comparing the received code with the code sent to the contact information.
[0011] In order to achieve the above object, an authentication program for information access relating to the technology of the present disclosure causes a computer to execute a process of receiving first authentication information from a device, comparing the received first authentication information with registered first authentication information, and if the match is confirmed, receiving contact information for contacting the user as the second authentication information, calculating a hash value of the received second authentication information, comparing the calculated hash value with the registered hash value, and if the match of the hash values is confirmed, sending an arbitrary code to the contact information, accepting the sent code, and comparing the received code with the code sent to the contact information.
[0012] According to the present disclosure, it is possible to provide an authentication method for information access, an authentication device for information access, and an authentication program for information access that perform user authentication without retaining contact information for contacting the user.
[0013] It is a diagram showing a schematic configuration of an authentication system according to an embodiment of the disclosed technique. It is a block diagram showing a hardware configuration of an authentication server. It is a block diagram showing an example of a functional configuration of the authentication server. It is a flowchart showing a flow of authentication processing for information access by the authentication server.
[0014] An example of an embodiment of the present disclosure will be described below with reference to the drawings. The same reference numerals are used throughout the drawings to designate identical or equivalent components and parts. The dimensional proportions of the drawings are exaggerated for illustrative purposes and may differ from the actual proportions.
[0015] Fig. 1 is a diagram showing a schematic configuration of an authentication system according to this embodiment. The authentication system shown in Fig. 1 includes an authentication server 10 and a user terminal 20. The authentication server 10 and the user terminal 20 are connected to each other via a network 30 such as the Internet so that they can communicate with each other. Although Fig. 1 shows two user terminals 20, the number of user terminals 20 is not limited to this example.
[0016] The authentication server 10 executes a process of confirming whether a user has permission to use a predetermined service through two-factor authentication. The authentication server 10 is an example of an "authentication device for information access" of the present disclosure. The user terminal 20 is a terminal that uses the service and is an information processing device such as a personal computer, smartphone, or tablet terminal. The user terminal 20 is an example of a device of the present disclosure. The user terminal 20 executes client software. The client software is software used by a user who operates the user terminal 20, and can be either service-specific software or general-purpose software. For example, if the predetermined service uses a web application, the client software is a general-purpose web browser.
[0017] The authentication server 10 is connected to a database (DB) 40. The database 40 stores information for authenticating a user. In this embodiment, the database 40 stores user contact information, such as a hash value of the user's email address and / or phone number, as information for authenticating a user.
[0018] In this embodiment, the authentication server 10 compares the first authentication information transmitted from the user terminal 20 with the registered first authentication information. The first authentication information may be, for example, a user ID and a password. If the authentication server 10 confirms authentication using the first authentication information, the authentication server 10 accepts second authentication information from the user terminal 20 that is different from the first authentication information, calculates a hash value of the accepted second authentication information, and compares the calculated hash value with the hash value registered in the database 40. If the authentication server 10 confirms that the hash values match, the authentication server 10 transmits an arbitrary code to the user terminal 20.
[0019] In this embodiment, the authentication server 10 acquires an email address and / or a telephone number as second authentication information from the user terminal 20. Note that the authentication server 10 only uses the email address and / or the telephone number acquired from the user terminal 20 during authentication and does not permanently store them. As a result, the authentication system according to this embodiment can achieve two-factor authentication even if, for example, the authentication server 10 is located in a country different from the country in which the user terminal 20 is located and the email address or telephone number is not desired or cannot be stored in the authentication server 10.
[0020] FIG. 2 is a block diagram showing the hardware configuration of the authentication server 10. As shown in FIG.
[0021] 2, the authentication server 10 includes a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, a storage 14, an input unit 15, a display unit 16, and a communication interface (I / F) 17. Each component is connected to each other via a bus 19 so as to be able to communicate with each other.
[0022] The CPU 11 is a central processing unit that executes various programs and controls each component. That is, the CPU 11 reads programs from the ROM 12 or storage 14 and executes the programs using the RAM 13 as a work area. The CPU 11 controls the above components and performs various arithmetic processing in accordance with the programs registered in the ROM 12 or storage 14. In this embodiment, the ROM 12 or storage 14 stores an authentication program for information access that authenticates a user.
[0023] The ROM 12 stores various programs and various data. The RAM 13 temporarily stores programs or data as a working area. The storage 14 is configured with a storage device such as a hard disk drive (HDD), a solid state drive (SSD), or a flash memory, and stores various programs including an operating system and various data.
[0024] The input unit 15 includes a pointing device such as a mouse and a keyboard, and is used to input various types of information.
[0025] The display unit 16 is, for example, a liquid crystal display, and displays various information. The display unit 16 may be a touch panel type and function as the input unit 15.
[0026] The communication interface 17 is an interface for communicating with other devices such as the user terminal 20, and uses standards such as Ethernet (registered trademark), FDDI, and Wi-Fi (registered trademark).
[0027] When executing the authentication program for accessing the above information, the authentication server 10 uses the above hardware resources to realize various functions. The functional configuration realized by the authentication server 10 will be described below.
[0028] FIG. 3 is a block diagram showing an example of the functional configuration of the authentication server 10. As shown in FIG.
[0029] 3, the authentication server 10 has, as its functional components, a reception unit 101, a matching unit 102, a calculation unit 103, and a transmission unit 104. Each functional component is realized by the CPU 11 reading and executing an authentication program for information access stored in the ROM 12 or the storage 14.
[0030] The reception unit 101 receives various information related to the use of the service from the user terminal 20 via the network 30 .
[0031] When authenticating a user, the reception unit 101 first receives a user ID and password for using the service from the user terminal 20 via the network 30. If the received user ID and password match the registered user ID and password, the reception unit 101 then receives the user's contact information, such as an email address and / or a telephone number, from the user terminal 20 via the network 30. If the hash value of the email address and / or telephone number matches the registered hash value, the reception unit 101 receives an authentication code for authentication from the user terminal 20 via the network 30.
[0032] The matching unit 102 performs a matching process using the information received by the reception unit 101. First, the matching unit 102 matches the user ID and password received by the reception unit 101 with a pre-registered user ID and password. The user ID and password are stored in the storage 14, for example.
[0033] If the user ID and password accepted by the accepting unit 101 match the pre-registered user ID and password, the matching unit 102 then matches the hash value calculated by the calculation unit 103 for the email address and / or phone number accepted by the accepting unit 101 with the hash value registered in the database 40. If the hash value calculated by the calculation unit 103 matches the hash value registered in the database 40, the matching unit 102 then matches the authentication code accepted by the accepting unit 101 with the authentication code sent by the sending unit 104. Finally, if the authentication code accepted by the accepting unit 101 matches the authentication code sent by the sending unit 104, authentication of the user terminal 20 is completed, and the user terminal 20 is permitted to use the service.
[0034] The receiving unit 101 may accept an electronic signature generated using a private key recorded in the user terminal 20, instead of a user ID and password. When the electronic signature generated by the user terminal 20 is accepted, the comparing unit 102 authenticates the accepted electronic signature using a public key registered in the authentication server 10. This allows the authentication server 10 to check whether the correspondence between the user and the public key is appropriate. In this case, the electronic signature accepted by the receiving unit 101 is an example of first authentication information of the present disclosure.
[0035] The calculation unit 103 performs a hash value calculation process. Specifically, the calculation unit 103 calculates a hash value of the user's contact information, such as an email address and / or a phone number. The hash value calculated by the calculation unit 103 is used in the matching process by the matching unit 102.
[0036] The transmission unit 104 transmits various information to the user terminal 20 via the network 30. Specifically, the transmission unit 104 transmits information related to the matching process performed by the matching unit 102 to the user terminal 20. The information related to the matching process performed by the matching unit 102 includes information on the results of each match and, if the hash values match, authentication information for authenticating use of the system. The authentication information for authenticating use of the system is, for example, a PIN (Personal Identification Number) code, a one-time password, etc.
[0037] If the results of the user ID and password comparison, the hash value comparison, and the authentication code comparison all match, the transmission unit 104 transmits a message to the user terminal 20 indicating that the authentication was successful. On the other hand, if the results of the user ID and password comparison, the hash value comparison, or the authentication code comparison do not match, the transmission unit 104 transmits a message to the user terminal 20 indicating that the authentication was unsuccessful. If the authentication is successful, the user terminal 20 displays a message to the effect that the authentication was successful, and the user becomes able to use the system. If the authentication is unsuccessful, the user terminal 20 displays a message to the effect that the authentication was unsuccessful, and the user becomes unable to use the system.
[0038] With this configuration, the authentication server 10 can perform user authentication without storing the contact information itself used to contact the user. For example, even if the country in which the authentication server 10 is installed strictly restricts the transfer of contact information outside the country as it is considered important personal information and cannot store it in permanent storage for use, it is possible to perform user authentication using a hash value of the contact information rather than the contact information itself used to contact the user.
[0039] Next, the operation of the authentication server 10 will be described.
[0040] 4 is a flowchart showing the flow of authentication processing for information access by the authentication server 10. The CPU 11 reads an authentication program for information access from the ROM 12 or the storage 14, loads it into the RAM 13, and executes it, thereby performing authentication processing for information access.
[0041] In step S101, the CPU 11 accepts a system user ID and password from the user terminal 20 that is attempting to use the system.
[0042] Following step S101, in step S102, the CPU 11 determines whether the user ID and password received from the user terminal 20 match the user ID and password registered in advance.
[0043] In step S102, if the user ID and password received from the user terminal 20 do not match the pre-registered user ID and password (step S102; No), the CPU 11 determines that the authentication has failed and terminates the authentication process. In step S102, if the user ID and password received from the user terminal 20 match the pre-registered user ID and password (step S102; Yes), then in step S103, the CPU 11 receives, from the user terminal 20, contact information of the user attempting to use the system, such as the user's email address and / or telephone number, for authentication of use of the system.
[0044] Following step S103, in step S104, the CPU 11 calculates a hash value of the contact information received from the user terminal 20. Here, the CPU 11 may calculate not only the hash value of the contact information received from the user terminal 20, but also the hash value of the password received in step S101.
[0045] Following step S104, in step S105, the CPU 11 determines whether the calculated hash value matches a hash value registered in advance in the database 40.
[0046] In step S105, if the calculated hash value does not match the hash value pre-registered in the database 40 (step S105; No), the CPU 11 determines that the authentication has failed and terminates the authentication process. In step S105, if the calculated hash value matches the hash value pre-registered in the database 40 (step S105; Yes), then in step S106, the CPU 11 transmits authentication information for authenticating use of the system to the contact information received in step S103. The authentication information for authenticating use of the system is, for example, a PIN code, a one-time password, etc.
[0047] Following step S106, in step S107, the CPU 11 receives authentication information for authenticating use of the system from the user terminal 20.
[0048] Following step S107, in step S108, the CPU 11 determines whether the received authentication information matches the authentication information transmitted in step S106.
[0049] In step S108, if the received authentication information does not match the authentication information sent in step S106 (step S108; No), the CPU 11 determines that the authentication has failed and ends the authentication process. In step S108, if the received authentication information matches the authentication information sent in step S106 (step S108; Yes), the CPU 11 determines that the authentication has succeeded and ends the authentication process.
[0050] By performing this process, the authentication server 10 can perform user authentication without storing the contact information itself used to contact the user. For example, even if the country in which the authentication server 10 is installed strictly restricts the transfer of contact information abroad as it is considered important personal information and cannot be saved in permanent storage for use, it is still possible to perform user authentication using a hash value of the contact information rather than the contact information itself to contact the user.
[0051] Although the embodiments of the present disclosure have been described in detail above with reference to the accompanying drawings, the technical scope of the present disclosure is not limited to such examples. It is clear that a person skilled in the art of the present disclosure can conceive of various modifications or alterations within the scope of the technical idea described in the claims, and it is understood that these modifications or alterations also naturally fall within the technical scope of the present disclosure.
[0052] Furthermore, the effects described in the above embodiments are explanatory or exemplary and are not limited to those described in the above embodiments. In other words, the technology according to the present disclosure may achieve other effects that are obvious to a person skilled in the art of the present disclosure from the description in the above embodiments, in addition to or instead of the effects described in the above embodiments.
[0053] In this specification, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed by connecting them with "and / or."
[0054] In the above embodiments, the authentication process for information access, which is executed by the CPU after reading the software (program), may be executed by various processors other than the CPU. Examples of such processors include programmable logic devices (PLDs) (such as field-programmable gate arrays (FPGAs)) whose circuit configuration can be changed after manufacture, and dedicated electrical circuits, such as application-specific integrated circuits (ASICs), which are processors with circuit configurations designed specifically for executing specific processes. Furthermore, the authentication process for information access may be executed by one of these various processors, or by a combination of two or more processors of the same or different types (e.g., multiple FPGAs, or a combination of a CPU and an FPGA). Furthermore, the hardware structure of these various processors is, more specifically, an electrical circuit that combines circuit elements such as semiconductor elements.
[0055] In addition, in the above embodiments, the authentication program for information access is pre-stored (installed) in a ROM or storage device, but this is not limiting. The program may be provided in a form recorded on a non-transitory recording medium such as a CD-ROM (Compact Disk Read Only Memory), a DVD-ROM (Digital Versatile Disk Read Only Memory), or a USB (Universal Serial Bus) memory. The program may also be downloaded from an external device via a network.
[0056] The following are supplementary clauses of the present disclosure. (Supplementary clause 1) An authentication method for information access, in which a processor executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, and if the match is confirmed, accepts contact information for contacting the user as second authentication information, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, sends an arbitrary code to the contact information, accepts the sent code, and compares the accepted code with the code sent to the contact information. (Supplementary clause 2) The authentication method for information access according to Supplementary clause 1, in which if the match is confirmed, the processor executes the following processes: generates the code, and sends the generated code to the contact information. (Supplementary clause 3) The authentication method for information access according to Supplementary clause 1 or Supplementary clause 2, in which the contact information is the user's email address and / or phone number. (Supplementary Item 4) The authentication method for information access according to any one of Supplementary Items 1 to 3, wherein the first authentication information is a user ID or a user ID and a password. (Supplementary Item 5) The authentication method for information access according to any one of Supplementary Items 1 to 3, wherein the first authentication information is a digital signature generated using a private key recorded in the device, and the processor verifies the received digital signature using a registered public key.(Supplementary Item 6) An authentication device for information access, comprising a processor, which performs the following processes: accepts first authentication information from a device; compares the accepted first authentication information with registered first authentication information; if the match is confirmed, accepts contact information for contacting a user as second authentication information; calculates a hash value of the accepted second authentication information; compares the calculated hash value with a registered hash value; if the match is confirmed, sends an arbitrary code to the contact information; accepts the sent code; and compares the accepted code with the code sent to the contact information. (Supplementary Item 7) An authentication program for information access that causes a computer to execute the following processes: accept first authentication information from a device; compare the accepted first authentication information with registered first authentication information; if the match is confirmed, accept contact information for contacting the user as second authentication information; calculate a hash value of the accepted second authentication information; compare the calculated hash value with a registered hash value; if the match is confirmed, send an arbitrary code to the contact information; accept the sent code; and compare the accepted code with the code sent to the contact information.
[0057] The disclosure of Japanese Patent Application No. 2023-208029, filed on December 8, 2023, is incorporated herein by reference in its entirety.
[0058] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.
Claims
1. An authentication method for accessing information, in which a processor executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, accepts contact information for contacting a user as second authentication information if the match is confirmed, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, sends an arbitrary code to the contact information, accepts the sent code, and compares the accepted code with the code sent to the contact information.
2. The authentication method for accessing information described in claim 1, wherein, if a match of the hash values is confirmed, the processor executes a process of generating the code and sending the generated code to the contact information.
3. The authentication method for information access according to claim 1 or 2, wherein the contact information is the user's email address and / or telephone number.
4. The authentication method for information access according to claim 1 or 2, wherein the first authentication information is a user ID or a user ID and a password.
5. An authentication method for information access as described in claim 1 or claim 2, wherein the first authentication information is an electronic signature generated using a private key recorded in the device, and the processor verifies the received electronic signature using a registered public key.
6. An authentication device for accessing information, comprising a processor, which executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, accepts contact information for contacting a user as second authentication information if the match is confirmed, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, sends an arbitrary code to the contact information, accepts the sent code, and compares the accepted code with the code sent to the contact information.
7. An authentication program for accessing information, which causes a computer to execute the following processes: accept first authentication information from a device; compare the accepted first authentication information with registered first authentication information; if the match is confirmed, accept contact information for contacting a user as second authentication information; calculate a hash value of the accepted second authentication information; compare the calculated hash value with a registered hash value; if the match is confirmed, send an arbitrary code to the contact information; accept the sent code; and compare the accepted code with the code sent to the contact information.
Citation Information
Patent Citations
Personal identification system avoiding leakage of personal information
JP2006244095A
Server, login processing method, and login processing program
JP2018106515A
Client device, key device, service providing device, user authentication system, user authentication method, program, and recording medium
WO2008099756A1