Authentication method for information access, authentication device for information access, and authentication program for information access
The authentication method addresses the challenge of handling sensitive device identification information by using hash values for authentication, enabling secure and compliant user authentication without storing the device's ID.
Patent Information
- Application Number
- PCT/JP2024/042217
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-11-28
- Publication Date
- 2025-06-12
AI Technical Summary
Existing authentication methods for information access face challenges in countries where device identification information is considered sensitive personal information, leading to restrictions on its transfer and storage, especially in systems providing services from abroad.
An authentication method that receives first authentication information from a device, compares it with registered information, and upon confirmation, receives a unique device ID, calculates its hash value, and compares it with a registered hash value, allowing for user authentication without storing the device's identification information.
This method enables secure user authentication without holding the device's identification information, complying with data privacy regulations and allowing international service provision.
Smart Images

Figure JP2024042217_12062025_PF_FP_ABST
Abstract
Description
Authentication method for information access, authentication device for information access, and authentication program for information access
[0001] The present disclosure relates to an authentication method for information access, an authentication device for information access, and an authentication program for information access.
[0002] Japanese Patent Application Laid-Open No. 2010-79795 discloses a technology relating to an authentication method for two-factor authentication.
[0003] One method of user authentication uses information from a user's device, such as a smartphone. A smartphone or other device sends identification information (such as a combination of an IP address and device serial number) to the system to communicate with the device. If the device is registered in the system, the system sends an authentication code to the device. The user then reads the authentication code from the device and sends it to the system, thereby verifying the user's identity. However, some countries consider device identification information to be important personal information and strictly restrict its transfer overseas. As a result, systems providing services from overseas cannot store and use device identification information in persistent storage.
[0004] The present disclosure has been made in consideration of the above points, and aims to provide an authentication method for information access, an authentication device for information access, and an authentication program for information access that perform user authentication without retaining device identification information.
[0005] In order to achieve the above-mentioned object, the authentication method for information access related to the technology of the present disclosure includes a processor receiving first authentication information from a device, comparing the received first authentication information with registered first authentication information, and if the comparison is confirmed, accepting a unique ID of the device as second authentication information, calculating a hash value of the received second authentication information, comparing the calculated hash value with a registered hash value, and if the comparison of the hash values is confirmed, sending an arbitrary code to the device, accepting the sent code, and comparing the received code with the code sent to the device.
[0006] If the hash values match, the processor may execute a process of generating the code and transmitting the generated code to the device.
[0007] In order to achieve the above object, an authentication method for information access related to the technology of the present disclosure includes a processor receiving first authentication information from a device, comparing the received first authentication information with registered first authentication information, and if the comparison is confirmed, accepting a unique ID of the device as second authentication information, calculating a hash value of the received second authentication information, comparing the calculated hash value with a registered hash value, and if the comparison of the hash values is confirmed, displaying a display on the device prompting the user for confirmation, and executing a process to accept a response from the user to the displayed display.
[0008] The first authentication information may be a user ID or a user ID and a password.
[0009] The first authentication information may be an electronic signature generated using a private key recorded on the device, and the processor may verify the received electronic signature using a registered public key.
[0010] In order to achieve the above object, an authentication device for information access related to the technology of the present disclosure includes a processor, which receives first authentication information from a device, compares the received first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the received second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, sends an arbitrary code to the device, accepts the sent code, and executes a process of comparing the received code with the code sent to the device.
[0011] In order to achieve the above object, an authentication device for information access related to the technology of the present disclosure includes a processor, which receives first authentication information from a device, compares the received first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the received second authentication information, compares the calculated hash value with the registered hash value, and if the match of the hash values is confirmed, displays a display on the device prompting the user to confirm, and executes a process of accepting a response from the user to the displayed display.
[0012] In order to achieve the above-mentioned object, an authentication program for information access relating to the technology disclosed herein causes a computer to execute a process of receiving first authentication information from a device, comparing the received first authentication information with registered first authentication information, and if the match is confirmed, accepting a unique ID of the device as second authentication information, calculating a hash value of the received second authentication information, comparing the calculated hash value with a registered hash value, and if the match of the hash values is confirmed, sending an arbitrary code to the device, accepting the sent code, and comparing the received code with the code sent to the device.
[0013] In order to achieve the above object, an authentication program for information access relating to the technology of the present disclosure causes a computer to receive first authentication information from a device, compare the received first authentication information with registered first authentication information, and if the match is confirmed, accept a unique ID of the device as second authentication information, calculate a hash value of the received second authentication information, compare the calculated hash value with the registered hash value, and if the match of the hash values is confirmed, display a display on the device prompting the user for confirmation, and execute a process to receive a response from the user to the displayed display.
[0014] According to the present disclosure, it is possible to provide an authentication method for information access, an authentication device for information access, and an authentication program for information access that perform user authentication without retaining device identification information.
[0015] Fig. 1 is a diagram illustrating a schematic configuration of an authentication system according to an embodiment of the disclosed technology. Fig. 2 is a block diagram illustrating a hardware configuration of an authentication server. Fig. 3 is a block diagram illustrating an example of a functional configuration of the authentication server. Fig. 4 is a flowchart illustrating a flow of authentication processing for information access by the authentication server. Fig. 5 is a flowchart illustrating a flow of authentication processing for information access by the authentication server. Fig. 6 is a diagram illustrating an example of a display displayed on a user terminal to prompt a user for confirmation.
[0016] An example of an embodiment of the present disclosure will be described below with reference to the drawings. The same reference numerals are used throughout the drawings to designate identical or equivalent components and parts. The dimensional proportions of the drawings are exaggerated for illustrative purposes and may differ from the actual proportions.
[0017] Fig. 1 is a diagram showing a schematic configuration of an authentication system according to this embodiment. The authentication system shown in Fig. 1 includes an authentication server 10 and a user terminal 20. The authentication server 10 and the user terminal 20 are connected to each other via a network 30 such as the Internet so that they can communicate with each other. Although Fig. 1 shows two user terminals 20, the number of user terminals 20 is not limited to this example.
[0018] The authentication server 10 executes a process of confirming whether a user has permission to use a predetermined service through two-factor authentication. The authentication server 10 is an example of an "authentication device for information access" of the present disclosure. The user terminal 20 is a terminal that uses the service and is an information processing device such as a personal computer, smartphone, or tablet terminal. The user terminal 20 is an example of a device of the present disclosure. The user terminal 20 executes client software. The client software is software used by a user who operates the user terminal 20, and can be either service-specific software or general-purpose software. For example, if the predetermined service uses a web application, the client software is a general-purpose web browser.
[0019] The authentication server 10 is connected to a database (DB) 40. The database 40 stores information for user authentication. In this embodiment, the database 40 stores a hash value of a unique ID of the user terminal 20, which identifies the user terminal 20, as information for user authentication. The unique ID of the user terminal 20 may include, for example, the serial number, MAC address, IP address, and serial number of a peripheral device (dongle) connected to the user terminal 20 of the user terminal 20.
[0020] In this embodiment, the authentication server 10 compares the first authentication information transmitted from the user terminal 20 with the registered first authentication information. The first authentication information may be, for example, a user ID and a password. If the authentication server 10 confirms authentication using the first authentication information, the authentication server 10 accepts second authentication information from the user terminal 20 that is different from the first authentication information, calculates a hash value of the accepted second authentication information, and compares the calculated hash value with the hash value registered in the database 40. If the authentication server 10 confirms that the hash values match, the authentication server 10 transmits an arbitrary code to the user terminal 20.
[0021] In this embodiment, the authentication server 10 acquires the unique ID of the user terminal 20 from the user terminal 20 as second authentication information. Note that the authentication server 10 only uses the unique ID of the user terminal 20 acquired from the user terminal 20 during authentication and does not permanently store it. As a result, the authentication system according to this embodiment can achieve two-factor authentication even if, for example, the authentication server 10 is located in a country different from the country in which the user terminal 20 is located and the unique ID of the user terminal 20 is not desired or cannot be stored in the authentication server 10.
[0022] FIG. 2 is a block diagram showing the hardware configuration of the authentication server 10. As shown in FIG.
[0023] 2, the authentication server 10 includes a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, a storage 14, an input unit 15, a display unit 16, and a communication interface (I / F) 17. Each component is connected to each other via a bus 19 so as to be able to communicate with each other.
[0024] The CPU 11 is a central processing unit that executes various programs and controls each component. That is, the CPU 11 reads programs from the ROM 12 or storage 14 and executes the programs using the RAM 13 as a work area. The CPU 11 controls the above components and performs various arithmetic processing in accordance with the programs registered in the ROM 12 or storage 14. In this embodiment, the ROM 12 or storage 14 stores an authentication program for information access that authenticates a user.
[0025] The ROM 12 stores various programs and various data. The RAM 13 temporarily stores programs or data as a working area. The storage 14 is configured with a storage device such as a hard disk drive (HDD), a solid state drive (SSD), or a flash memory, and stores various programs including an operating system and various data.
[0026] The input unit 15 includes a pointing device such as a mouse and a keyboard, and is used to input various types of information.
[0027] The display unit 16 is, for example, a liquid crystal display, and displays various information. The display unit 16 may be a touch panel type and function as the input unit 15.
[0028] The communication interface 17 is an interface for communicating with other devices such as the user terminal 20, and uses standards such as Ethernet (registered trademark), FDDI, and Wi-Fi (registered trademark).
[0029] When executing the authentication program for accessing the above information, the authentication server 10 uses the above hardware resources to realize various functions. The functional configuration realized by the authentication server 10 will be described below.
[0030] FIG. 3 is a block diagram showing an example of the functional configuration of the authentication server 10. As shown in FIG.
[0031] 3, the authentication server 10 has, as its functional components, a reception unit 101, a matching unit 102, a calculation unit 103, and a transmission unit 104. Each functional component is realized by the CPU 11 reading and executing an authentication program for information access stored in the ROM 12 or the storage 14.
[0032] The reception unit 101 receives various information related to the use of the service from the user terminal 20 via the network 30 .
[0033] When authenticating a user, the reception unit 101 first receives a user ID and password for using the service from the user terminal 20 via the network 30. If the received user ID and password match the registered user ID and password, the reception unit 101 then receives a unique ID of the user terminal 20 from the user terminal 20 via the network 30. If the hash value of the unique ID of the user terminal 20 matches the registered hash value, the reception unit 101 receives an authentication code for authentication from the user terminal 20 via the network 30.
[0034] The matching unit 102 performs a matching process using the information received by the reception unit 101. First, the matching unit 102 matches the user ID and password received by the reception unit 101 with a pre-registered user ID and password. The user ID and password are stored in the storage 14, for example.
[0035] If the user ID and password accepted by the accepting unit 101 match the pre-registered user ID and password, the comparing unit 102 then compares the hash value calculated by the calculating unit 103 for the unique ID of the user terminal 20 accepted by the accepting unit 101 with the hash value registered in the database 40. If the hash value calculated by the calculating unit 103 matches the hash value registered in the database 40, the comparing unit 102 then compares the authentication code accepted by the accepting unit 101 with the authentication code sent by the sending unit 104. Finally, if the authentication code accepted by the accepting unit 101 matches the authentication code sent by the sending unit 104, authentication of the user terminal 20 is completed, and the user terminal 20 is permitted to use the service.
[0036] The receiving unit 101 may accept an electronic signature generated using a private key recorded in the user terminal 20, instead of a user ID and password. When the electronic signature generated by the user terminal 20 is accepted, the comparing unit 102 authenticates the accepted electronic signature using a public key registered in the authentication server 10. This allows the authentication server 10 to check whether the correspondence between the user and the public key is appropriate. In this case, the electronic signature accepted by the receiving unit 101 is an example of first authentication information of the present disclosure.
[0037] The calculation unit 103 performs a calculation process of a hash value. Specifically, the calculation unit 103 calculates a hash value of a unique ID of the user terminal 20. The hash value calculated by the calculation unit 103 is used in the matching process by the matching unit 102.
[0038] The transmission unit 104 transmits various information to the user terminal 20 via the network 30. Specifically, the transmission unit 104 transmits information related to the matching process performed by the matching unit 102 to the user terminal 20. The information related to the matching process performed by the matching unit 102 includes information on the results of each match and, if the hash values match, authentication information for authenticating use of the system. The authentication information is an example of any code disclosed herein, and the authentication information for authenticating use of the system is, for example, a personal identification number (PIN) code, a one-time password, etc.
[0039] If the results of the user ID and password comparison, the hash value comparison, and the authentication code comparison all match, the transmission unit 104 transmits a message to the user terminal 20 indicating that the authentication was successful. On the other hand, if the results of the user ID and password comparison, the hash value comparison, or the authentication code comparison do not match, the transmission unit 104 transmits a message to the user terminal 20 indicating that the authentication was unsuccessful. If the authentication is successful, the user terminal 20 displays a message to the effect that the authentication was successful, and the user becomes able to use the system. If the authentication is unsuccessful, the user terminal 20 displays a message to the effect that the authentication was unsuccessful, and the user becomes unable to use the system.
[0040] With this configuration, the authentication server 10 can perform user authentication without storing the unique ID of the user terminal 20. For example, even if the country in which the authentication server 10 is installed strictly restricts the transfer of the unique ID of the user terminal 20 abroad because the unique ID of the user terminal 20 is considered to be important personal information and cannot be stored in permanent storage for use, it is still possible to perform user authentication using a hash value rather than the unique ID of the user terminal 20 itself.
[0041] Next, the operation of the authentication server 10 will be described.
[0042] 4 is a flowchart showing the flow of authentication processing for information access by the authentication server 10. The CPU 11 reads an authentication program for information access from the ROM 12 or the storage 14, loads it into the RAM 13, and executes it, thereby performing authentication processing for information access.
[0043] In step S101, the CPU 11 accepts a system user ID and password from the user terminal 20 that is attempting to use the system.
[0044] Following step S101, in step S102, the CPU 11 determines whether the user ID and password received from the user terminal 20 match the user ID and password registered in advance.
[0045] In step S102, if the user ID and password received from the user terminal 20 do not match the pre-registered user ID and password (step S102; No), the CPU 11 determines that the authentication has failed and terminates the authentication process. In step S102, if the user ID and password received from the user terminal 20 match the pre-registered user ID and password (step S102; Yes), then in step S103, the CPU 11 receives from the user terminal 20 a unique ID of the user terminal 20 used by the user who wishes to use the system, for authentication of use of the system.
[0046] Following step S103, in step S104, the CPU 11 calculates a hash value of the unique ID of the user terminal 20 received from the user terminal 20. Here, the CPU 11 may calculate not only the hash value of the unique ID of the user terminal 20 received from the user terminal 20, but also the hash value of the password received in step S101.
[0047] Following step S104, in step S105, the CPU 11 determines whether the calculated hash value matches a hash value registered in advance in the database 40.
[0048] In step S105, if the calculated hash value does not match the hash value pre-registered in the database 40 (step S105; No), the CPU 11 determines that the authentication has failed and terminates the authentication process. In step S105, if the calculated hash value matches the hash value pre-registered in the database 40 (step S105; Yes), then in step S106, the CPU 11 transmits authentication information for authenticating use of the system to the user terminal 20. The authentication information for authenticating use of the system is, for example, a PIN code, a one-time password, etc.
[0049] Following step S106, in step S107, the CPU 11 receives authentication information for authenticating use of the system from the user terminal 20.
[0050] Following step S107, in step S108, the CPU 11 determines whether the received authentication information matches the authentication information transmitted in step S106.
[0051] In step S108, if the received authentication information does not match the authentication information sent in step S106 (step S108; No), the CPU 11 determines that the authentication has failed and ends the authentication process. In step S108, if the received authentication information matches the authentication information sent in step S106 (step S108; Yes), the CPU 11 determines that the authentication has succeeded and ends the authentication process.
[0052] 5 shows another example of the operation of the authentication server 10. Fig. 5 is a flowchart showing the flow of authentication processing for information access by the authentication server 10. The CPU 11 reads an authentication program for information access from the ROM 12 or the storage 14, loads it into the RAM 13, and executes it, thereby performing authentication processing for information access.
[0053] In the flowchart shown in FIG. 5, the same parts as those in the flowchart shown in FIG. 4 will not be described.
[0054] In step S105, if the calculated hash value matches a hash value previously registered in the database 40 (step S105; Yes), then in step S111, the CPU 11 notifies the user terminal 20 to display a message prompting the user for confirmation.
[0055] 6 is a diagram showing an example of a display prompting the user for confirmation, displayed by the user terminal 20. In this display, the user can continue the authentication process at the authentication server 10 by selecting a confirmation button 201 within a set time period.
[0056] Following step S111, in step S112, the CPU 11 determines whether or not the user has performed an operation on the display prompting the user for confirmation within a predetermined time on the user terminal 20. That is, when the display shown in Fig. 6 is displayed on the user terminal 20, the CPU 11 determines whether or not the confirmation button 201 has been selected within a predetermined time.
[0057] In step S112, if the user does not operate the user terminal 20 in response to the display prompting the user to confirm within a predetermined time (step S112; No), the CPU 11 determines that the authentication has failed and ends the authentication process. In step S112, if the user operates the user terminal 20 within a predetermined time (step S112; Yes), the CPU 11 determines that the authentication has succeeded and ends the authentication process.
[0058] By performing this process, the authentication server 10 can perform user authentication without storing the unique ID of the user terminal 20. For example, even if the country in which the authentication server 10 is installed strictly restricts the transfer of the unique ID of the user terminal 20 abroad because the unique ID of the user terminal 20 is considered to be important personal information and cannot be stored in permanent storage for use, it is still possible to perform user authentication using a hash value rather than the unique ID of the user terminal 20 itself.
[0059] Although the embodiments of the present disclosure have been described in detail above with reference to the accompanying drawings, the technical scope of the present disclosure is not limited to such examples. It is clear that a person skilled in the art of the present disclosure can conceive of various modifications or alterations within the scope of the technical idea described in the claims, and it is understood that these modifications or alterations also naturally fall within the technical scope of the present disclosure.
[0060] Furthermore, the effects described in the above embodiments are explanatory or exemplary and are not limited to those described in the above embodiments. In other words, the technology according to the present disclosure may achieve other effects that are obvious to a person skilled in the art of the present disclosure from the description in the above embodiments, in addition to or instead of the effects described in the above embodiments.
[0061] In this specification, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed by connecting them with "and / or."
[0062] In the above embodiments, the authentication process for information access, which is executed by the CPU after reading the software (program), may be executed by various processors other than the CPU. Examples of such processors include programmable logic devices (PLDs) (such as field-programmable gate arrays (FPGAs)) whose circuit configuration can be changed after manufacture, and dedicated electrical circuits, such as application-specific integrated circuits (ASICs), which are processors with circuit configurations designed specifically for executing specific processes. Furthermore, the authentication process for information access may be executed by one of these various processors, or by a combination of two or more processors of the same or different types (e.g., multiple FPGAs, or a combination of a CPU and an FPGA). Furthermore, the hardware structure of these various processors is, more specifically, an electrical circuit that combines circuit elements such as semiconductor elements.
[0063] In addition, in the above embodiments, the authentication program for information access is pre-stored (installed) in a ROM or storage device, but this is not limiting. The program may be provided in a form recorded on a non-transitory recording medium such as a CD-ROM (Compact Disk Read Only Memory), a DVD-ROM (Digital Versatile Disk Read Only Memory), or a USB (Universal Serial Bus) memory. The program may also be downloaded from an external device via a network.
[0064] The following are supplementary clauses of the present disclosure. (Supplementary clause 1) An authentication method for information access, in which a processor executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, sends an arbitrary code to the device, accepts the sent code, and compares the accepted code with the code sent to the device. (Supplementary clause 2) The authentication method for information access according to Supplementary clause 1, in which if the match of the hash values is confirmed, the processor executes the following processes: generates the code, and sends the generated code to the device. (Supplementary Item 3) An authentication method for information access, in which a processor executes the following processes: accepts first authentication information, compares the accepted first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, displays on the device a message prompting the user for confirmation, and accepts a response from the user to the message. (Supplementary Item 4) The authentication method for information access according to any of Supplementary Items 1 to 3, in which the first authentication information is a user ID or a user ID and a password. (Supplementary Item 5) The authentication method for information access according to any of Supplementary Items 1 to 3, in which the first authentication information is a digital signature generated using a private key recorded on the device, and the processor verifies the accepted digital signature using a registered public key.(Supplementary Item 6) An authentication apparatus for information access, comprising a processor, which executes the following processes: accepts first authentication information from a device; compares the accepted first authentication information with registered first authentication information; accepts a unique ID of the device as second authentication information if the match is confirmed; calculates a hash value of the accepted second authentication information; compares the calculated hash value with a registered hash value; and, if the match is confirmed, transmits an arbitrary code to the device; accepts the transmitted code; and compares the accepted code with the code transmitted to the device. (Supplementary Item 7) An authentication device for information access, comprising a processor, which executes the following processes: accepts first authentication information from a device; compares the accepted first authentication information with registered first authentication information; accepts a unique ID of the device as second authentication information if the match is confirmed; calculates a hash value of the accepted second authentication information; compares the calculated hash value with a registered hash value; if the match is confirmed, displays a message on the device prompting a user to confirm; and accepts a response from the user to the message that has been displayed. (Supplementary Item 8) An authentication program for information access that causes a computer to execute the following processes: accept first authentication information from a device; compare the accepted first authentication information with registered first authentication information; accept a unique ID of the device as second authentication information if the match is confirmed; calculate a hash value of the accepted second authentication information; compare the calculated hash value with a registered hash value; if the match is confirmed, send an arbitrary code to the device; accept the sent code; and compare the accepted code with the code sent to the device.(Supplementary Item 9) An authentication program for information access that causes a computer to execute the following processes: accept first authentication information from a device; compare the accepted first authentication information with registered first authentication information; if the match is confirmed, accept a unique ID of the device as second authentication information; calculate a hash value of the accepted second authentication information; compare the calculated hash value with a registered hash value; if the match is confirmed, display on the device a message prompting a user to confirm; and accept a response from the user to the message that is displayed.
[0065] The disclosure of Japanese Patent Application No. 2023-208032, filed on December 8, 2023, is incorporated herein by reference in its entirety.
[0066] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.
Claims
1. An authentication method for accessing information, in which a processor executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, sends an arbitrary code to the device, accepts the sent code, and compares the accepted code with the code sent to the device.
2. The authentication method for accessing information according to claim 1, wherein, if a match of the hash values is confirmed, the processor executes a process of generating the code and transmitting the generated code to the device.
3. An authentication method for accessing information, in which a processor executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, displays a message on the device prompting a user to confirm the message, and accepts a response from the user to the message.
4. An authentication method for accessing information as described in any one of claims 1 to 3, wherein the first authentication information is a user ID or a user ID and a password.
5. An authentication method for accessing information described in any one of claims 1 to 3, wherein the first authentication information is an electronic signature generated using a private key recorded in the device, and the processor verifies the received electronic signature using a registered public key.
6. An authentication device for accessing information, comprising a processor that performs the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, accepts a unique ID of the device as second authentication information if the match is confirmed, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, transmits an arbitrary code to the device, accepts the transmitted code, and compares the accepted code with the code transmitted to the device.
7. An authentication device for information access comprising a processor, which executes the following processes: accepts first authentication information from a device, compares the accepted first authentication information with registered first authentication information, and if the match is confirmed, accepts a unique ID of the device as second authentication information, calculates a hash value of the accepted second authentication information, compares the calculated hash value with a registered hash value, and if the match is confirmed, displays a message on the device prompting a user to confirm the message, and accepts a response from the user to the displayed message.
8. An authentication program for accessing information, which causes a computer to execute the following processes: accept first authentication information from a device, compare the accepted first authentication information with registered first authentication information, accept a unique ID of the device as second authentication information if the match is confirmed, calculate a hash value of the accepted second authentication information, compare the calculated hash value with a registered hash value, and if the match is confirmed, send an arbitrary code to the device, accept the sent code, and compare the accepted code with the code sent to the device.
9. An authentication program for accessing information, which causes a computer to execute the following processes: accept first authentication information from a device; compare the accepted first authentication information with registered first authentication information; if the match is confirmed, accept a unique ID of the device as second authentication information; calculate a hash value of the accepted second authentication information; compare the calculated hash value with a registered hash value; if the match is confirmed, display on the device a message prompting a user to confirm; and accept a response from the user to the message displayed.
Citation Information
Patent Citations
Personal identification system avoiding leakage of personal information
JP2006244095A
Server, login processing method, and login processing program
JP2018106515A
Client device, key device, service providing device, user authentication system, user authentication method, program, and recording medium
WO2008099756A1