Authentication method, authentication system, provision server, and program

The authentication method addresses the challenge of limited authentication data by using token data and registration codes to establish secure SSH tunnels, ensuring security and enabling tunnel establishment even with limited data transmission.

WO2025126478A1PCT designated stage expired Publication Date: 2025-06-19KAMOME ENG

Patent Information

Application Number
PCT/JP2023/045103
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing SSH-based authentication systems face challenges in establishing secure communication tunnels when the amount of authentication information that can be transmitted is limited, potentially compromising security.

Method used

The proposed authentication method involves an authentication server transmitting token data to a user terminal, which then requests a registration code from a providing server. This registration code is used to establish a tunnel between the user terminal and the providing server, with the authentication server verifying the token data to ensure secure authentication.

Benefits of technology

This method allows for the establishment of secure SSH tunnels even when the data amount of authentication information is limited, ensuring sufficient security and enabling tunnel establishment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023045103_19062025_PF_FP_ABST
    Figure JP2023045103_19062025_PF_FP_ABST
Patent Text Reader

Abstract

This authentication server 1 transmits token data to a user terminal 3, and transmits an authentication result of the token data transmitted from a provision server 2 to the provision server 2. The provision server 2 comprises: an issuance unit 22 that, when receiving the token data from the user terminal 3, transmits a registration code associated with the token data to the user terminal 3; and a connection unit 23 that, when receiving the registration code and a request for establishing a tunnel between a processing unit and the user terminal 3, transmits the token data associated with the registration code to the authentication server 1, and when receiving, from the authentication server 1, the result indicating that the authentication has been performed, establishes a tunnel between a processing unit 25 and the user terminal 3.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method, authentication system, providing server and program

[0001] The present disclosure relates to an authentication method, an authentication system, a provision server, and a program.

[0002] SSH (Secure Shell) is known (see Non-Patent Document 1). SSH is an encryption network protocol. SSH allows a protected communication path to be established on an unsecured network. By using the protected communication path, a provider server can safely operate network services. In this specification, a communication path protected by SSH on an unsecured network is referred to as an SSH tunnel or tunnel.

[0003] Single sign-on (SSO) is also known (see Non-Patent Document 2). In SSO, once a user is authenticated through a single authentication process, the user is able to use resources of other independent software systems.

[0004] "Secure Shell", [online], WIKIPEDIA, [Retrieved August 18, 2023], Internet <URL: https: / / en.wikipedia.org / wiki / Secure_Shell> "Single sign-on", [online], WIKIPEDIA, [Retrieved August 18, 2023], Internet <URL: https: / / en.wikipedia.org / wiki / Single_sign-on>

[0005] However, depending on the software that implements SSH, there may be a limit on the amount of authentication information data that can be transmitted before establishing a tunnel during authentication, etc. On the other hand, in authentication servers such as single sign-on, the amount of data required for user authentication tends to be large in order to ensure security.

[0006] Therefore, if the amount of authentication information that can be transmitted before the tunnel is established is limited, the authentication server may not be able to authenticate the user terminal with a sufficient amount of data to ensure security. In such a situation, the tunnel cannot be established with sufficient security.

[0007] The present disclosure has been made in consideration of the above circumstances, and the purpose of the present disclosure is to provide a technology that can establish a tunnel while ensuring sufficient security even when the amount of authentication information data that can be transmitted is limited.

[0008] An authentication method of one aspect of the present disclosure is an authentication system including a user terminal, a providing server that provides an application, and an authentication server that authenticates the user terminal's use of the providing server, wherein the authentication server transmits token data for authenticating the user terminal to the user terminal, the user terminal transmits the token data to the providing server, and upon receiving the token data from the user terminal, the providing server transmits a registration code associated with the token data to the user terminal, the user terminal transmits the registration code to the providing server to request establishment of a tunnel between the user terminal and a processing unit of an application provided by the providing server, the providing server receives the registration code from the user terminal and identifies the token data associated with the received registration code, the providing server transmits the identified token data to the authentication server, the authentication server transmits an authentication result of the token data transmitted from the providing server to the providing server, and upon receiving a result of authentication from the authentication server, the providing server establishes a tunnel between the processing unit and the user terminal.

[0009] An authentication system according to one aspect of the present disclosure is an authentication system comprising: a user terminal; a provision server that provides an application; and an authentication server that authenticates the user terminal's use of the provision server, wherein the authentication server transmits token data for authenticating the user terminal to the user terminal and transmits an authentication result of the token data transmitted from the provision server to the provision server; the user terminal transmits the token data to the provision server, receives a registration code from the provision server, and transmits the registration code to the provision server to request establishment of a tunnel between the user terminal and a processing unit of an application provided by the provision server; the provision server comprises a processing unit that provides an application, an issuing unit that, upon receiving the token data from the user terminal, transmits a registration code associated with the token data to the user terminal, and a connection unit that, upon receiving a request from the user terminal for establishment of a tunnel between the processing unit and the user terminal, transmits the token data associated with the registration code to the authentication server, and, upon receiving a result of authentication from the authentication server, establishes a tunnel between the processing unit and the user terminal.

[0010] A provision server of one embodiment of the present disclosure includes a processing unit that provides an application, an issuing unit that, when it receives token data from a user terminal for an authentication server to authenticate the user terminal, sends a registration code associated with the token data to the user terminal, and a connection unit that, when it receives a request from the user terminal to establish a tunnel between the processing unit and the user terminal and the registration code, sends the token data associated with the registration code to the authentication server, and, when it receives a result from the authentication server indicating that it has been authenticated, establishes a tunnel between the processing unit and the user terminal.

[0011] One aspect of the present disclosure is a program that causes a computer to function as the f provision server.

[0012] According to the present disclosure, it is possible to provide a technique that can establish a tunnel while ensuring sufficient security even when the amount of data of authentication information that can be transmitted is limited.

[0013] Fig. 1 is a diagram illustrating the system configuration of an authentication system according to the present disclosure and the functional blocks of a provision server. Fig. 2 is a diagram illustrating an example of the data structure of correspondence data. Fig. 3 is a sequence diagram illustrating processing in the authentication system. (Part 1) Fig. 4 is a sequence diagram illustrating processing in the authentication system. (Part 2) Fig. 5 is a diagram illustrating the hardware configuration of a computer used in the provision server.

[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the description of the drawings, the same parts are designated by the same reference numerals and the description thereof will be omitted.

[0015] (Authentication System) An authentication system 8 according to the present disclosure will be described with reference to Fig. 1. The authentication system 8 includes an authentication server 1, an authentication server, and a user terminal 3. The authentication server 1, the authentication server, and the user terminal 3 are connected via a communication network 5 so as to be able to communicate bidirectionally.

[0016] The authentication server 1 authenticates the use of the provision server 2 by the user terminal 3. The authentication server 1 authenticates the user terminal 3 when the user terminal 3 uses an application provided by the provision server 2. The authentication server 1 may be an authentication server that provides single sign-on.

[0017] The authentication server 1 issues token data for authenticating the user terminal 3 and transmits it to the user terminal 3. Upon receiving the token data from the provision server 2, the authentication server 1 authenticates the token data and transmits the authentication result of the token data to the provision server 2.

[0018] The authentication server 1 generates token data by, for example, applying a digital signature to a predetermined character string. The authentication server 1 may also set a deadline for authenticating the token data in the token data.

[0019] The authentication server 1 confirms that the token data sent from the providing server 2 (1) was sent by the authentication server 1, (2) was generated using the digital signature of the authentication server 1, and (3) was received from the providing server 2 within the deadline set by the authentication server 1. If the authentication server 1 can confirm these points, it sends an authentication result to the providing server 2, including a message indicating that authentication will be performed. If the authentication server 1 cannot confirm at least one of these points, it sends an authentication result to the providing server 2, including a message indicating that authentication will not be performed.

[0020] The user terminal 3 is authenticated by the authentication server 1 and uses the application service provided by the provision server 2 .

[0021] The user terminal 3 obtains token data from the authentication server 1. The user terminal 3 transmits the token data to the provision server 2 and receives a registration code from the provision server 2. The user terminal 3 transmits the registration code to the provision server 2 and requests the establishment of a tunnel between the user terminal 3 and the processing unit 25 of the application provided by the provision server 2. Once the tunnel is established, the user terminal 3 uses the established tunnel to enjoy the application service provided by the processing unit 25.

[0022] The provision server 2 provides application services to be used by the user terminal 3 after authentication by the authentication server 1. In the present disclosure, the provision server 2 will be described as having a first processing unit 25a and a second processing unit 25b that provide application services. The provision server 2 can provide any number of services. In the present disclosure, when there is no need to distinguish between the first processing unit 25a and the second processing unit 25b, they may be simply referred to as the processing unit 25.

[0023] In the present disclosure, an SSH tunnel is established between the user terminal 3 and a processing unit 25 that provides an application service used by the user terminal 3. At this time, the authentication system 8 establishes the tunnel while ensuring sufficient security even if the software that realizes SSH limits the amount of authentication information data that can be transmitted during authentication before the SSH tunnel is established.

[0024] 1, the provision server 2 includes various data such as the correspondence data 24, and various functions including an authentication unit 21, a first processing unit 25a, and a second processing unit 25b. Each data is stored in a storage device such as a memory 902 or a storage 903. Each function is implemented in a CPU 901.

[0025] 2, the correspondence data 24 associates registration codes with token data. The token data is data transmitted from the user terminal 3 and is used by the authentication server 1 to authenticate the user terminal. The token data is generated, for example, by a digital signature of the authentication server 1. The registration code is data that uniquely identifies the token data transmitted from the user terminal 3.

[0026] Token data is data that is normally transmitted from the user terminal 3 to the provision server 2 by the function of the software that realizes SSH when authenticating the user terminal 3. Software specifications impose limits on the amount of data that can be transmitted when authenticating the user terminal 3. In the present disclosure, the amount of token data may exceed the amount of data specified in the SSH software specifications. On the other hand, the amount of data for the registration code is within the range of the amount of data specified in the SSH software specifications.

[0027] The first processing unit 25a provides a first application service, and the second processing unit 25b provides a second application service.

[0028] The authentication unit 21 includes an issuing unit 22 and a connecting unit 23 .

[0029] When the issuing unit 22 receives the token data from the user terminal 3, it transmits a registration code associated with the token data to the user terminal 3. The token data is data issued by the authentication server 1 to authenticate the user terminal 3.

[0030] When the issuing unit 22 receives the token data, it issues registration data corresponding to the token data, associates the registration data with the token data, and stores the association data in the association data 24. The issuing unit 22 returns the issued registration code to the user terminal 3.

[0031] The connection unit 23 receives a request for establishing a tunnel between the processing unit 25 and the user terminal 3 and a registration code from the user terminal 3. The connection unit 23 identifies token data associated with the registration code received from the user terminal 3 from the correspondence data 24, and transmits the identified token data to the authentication server 1.

[0032] The authentication server 1 then checks the token data and attempts authentication, and transmits an authentication result, including whether or not the token data has been authenticated, to the provision server 2.

[0033] When the connection unit 23 receives a result of authentication from the authentication server 1, it establishes a tunnel between the processing unit 25 and the user terminal 3. If the provision server 2 has multiple processing units 25, it establishes a tunnel with the processing unit 25 specified by the user terminal 3.

[0034] (Authentication Method) With reference to FIGS. 3-4, an authentication method according to the present disclosure will be described.

[0035] In step S1, the user terminal 3 logs in to the authentication server 1. In step S2, the authentication server 1 authenticates the user terminal 3.

[0036] In step S3, the user terminal 3 transmits a request to issue token data to the authentication server 1. The authentication server 1 generates token data by applying a digital signature to predetermined data. In step S4, the authentication server 1 transmits the generated token data to the user terminal 3.

[0037] In step S5, the user terminal 3 transmits the token data received in step S4 to the provision server 2. The user terminal 3 transmits the token data to the provision server 2 in accordance with a REST API (Representational State Transfer Application Programming Interface) defined by the provision server 2.

[0038] In step S6, upon receiving the token data, the authentication unit 21 of the provision server 2 issues a registration code for identifying the token data. The authentication unit 21 associates the issued registration code with the received token data and stores them in the correspondence data 24. In step S7, the authentication unit 21 transmits the registration code issued in step S6 to the user terminal 3.

[0039] In step S8, the user terminal 3 transmits a request to establish a tunnel to the provision server 2. This request includes the identifier of the application provided by the provision server 2 and the registration code received in step S7.

[0040] In step S9, when the authentication unit 21 of the provision server 2 receives the request from the user terminal 3, it obtains token data corresponding to the registration code included in the request from the correspondence data 24. Here, the provision server 2 can associate the tunnel request received from the user terminal 3 with token data of a data amount sufficient to ensure security.

[0041] In step S10, the authentication unit 21 transmits an authentication request for the user terminal 3 to the authentication server 1. This authentication request includes the token data acquired from the correspondence data 24.

[0042] In step S11, the authentication server 1 authenticates the token data acquired in step S10. If authentication is successful, in step S12 the authentication server 1 transmits an authentication result including a message that authentication is successful to the provision server 2. If authentication is not successful, in step S12 the authentication server 1 transmits an authentication result including a message that authentication is not successful to the provision server 2.

[0043] In step S12, the authentication unit 21 of the provision server 2 receives the authentication result from the authentication server 1. If the authentication result indicates that authentication is not permitted, the provision server 2 rejects the request from the user terminal 3. If the authentication result indicates that authentication is permitted, the provision server 2 transmits an instruction to establish a tunnel between the provision server 2 and the user terminal 3 to the processing unit 25 corresponding to the application ID received in step S8.

[0044] When the processing unit 25 of the provision server 2 receives the instruction to establish a tunnel from the authentication unit 21, in step S14, a tunnel is established between the provision server 2 and the user terminal 3. The user terminal 3 uses the established tunnel to receive the application service provided by the processing unit 25.

[0045] In this authentication system 8, the provision server 2 associates token data having a data volume sufficient to ensure security with a registration code within the range of data volume that can be transmitted as authentication information. The user terminal 3 requests establishment of a tunnel using the registration code, and the provision server 2 transmits the token data corresponding to the registration code received at the time of the request to the authentication server 1, requesting authentication of the user terminal 3.

[0046] This allows the authentication system 8 to establish a tunnel while ensuring sufficient security even when the amount of authentication information data that can be transmitted is limited.

[0047] Each of the devices of the authentication server 1, provision server 2, and user terminal 3 of the present embodiment described above is, for example, a general-purpose computer system including a CPU (Central Processing Unit, processor) 901, a memory 902, a storage 903 (HDD: Hard Disk Drive, SSD: Solid State Drive), a communication device 904, an input device 905, and an output device 906. In this computer system, the CPU 901 executes a program loaded on the memory 902, thereby realizing the functions of each device.

[0048] Each device may be implemented by one computer or by multiple computers, or may be a virtual machine implemented by a computer.

[0049] The programs of each device can be stored in a computer-readable recording medium such as a HDD, SSD, USB (Universal Serial Bus) memory, CD (Compact Disc), DVD (Digital Versatile Disc), or can be distributed via a network. The computer-readable recording medium is, for example, a non-transitory recording medium.

[0050] The present disclosure is not limited to the above-described embodiments, and various modifications are possible within the scope of the present disclosure.

[0051] REFERENCE SIGNS LIST 1 Authentication server 2 Provision server 3 User terminal 5 Communication network 8 Authentication system 21 Authentication unit 22 Issuance unit 23 Connection unit 24 Corresponding data 25 Processing unit 901 CPU 902 Memory 903 Storage 904 Communication device 905 Input device 906 Output device

Claims

1. In an authentication system comprising a user terminal, a providing server that provides an application, and an authentication server that authenticates the use of the providing server by the user terminal, the authentication server transmits token data for authenticating the user terminal to the user terminal, the user terminal transmits the token data to the providing server, when the providing server receives the token data from the user terminal, the providing server transmits a registration code associated with the token data to the user terminal, the user terminal transmits the registration code to the providing server to request establishment of a tunnel between a processing unit of the application provided by the providing server and the user terminal, the providing server receives the registration code from the user terminal, identifies the token data associated with the received registration code, the providing server transmits the identified token data to the authentication server, the authentication server transmits an authentication result of the token data transmitted from the providing server to the providing server, and when the providing server receives a result indicating that the authentication is successful from the authentication server, the providing server establishes a tunnel between the processing unit and the user terminal. Authentication method.

2. The user terminal transmits the token data in accordance with a REST API defined by the providing server, and the providing server transmits a registration code associated with the token data to the user terminal in accordance with the REST API. The authentication method according to claim 1.

3. The authentication server generates token data by digital signature, and when it is confirmed that the token data is generated by the digital signature of the authentication server, the authentication result includes a confirmation of successful authentication. The authentication method according to claim 1.

4. An authentication system comprising a user terminal, a providing server that provides an application, and an authentication server that authenticates the use of the providing server by the user terminal, wherein the authentication server transmits token data for authenticating the user terminal to the user terminal, transmits an authentication result of the token data transmitted from the providing server to the providing server, the user terminal transmits the token data to the providing server, receives a registration code from the providing server, transmits the registration code to the providing server to request establishment of a tunnel between a processing unit of the application provided by the providing server and the user terminal, the providing server includes a processing unit that provides an application, an issuing unit that transmits a registration code associated with the token data to the user terminal when receiving the token data from the user terminal, and a connection unit that transmits the token data associated with the registration code to the authentication server when receiving a request for establishment of a tunnel between the processing unit and the user terminal and the registration code from the user terminal, and establishes a tunnel between the processing unit and the user terminal when receiving a result indicating authentication from the authentication server.

5. A providing server comprising a processing unit that provides an application, an issuing unit that transmits a registration code associated with the token data to the user terminal when receiving the token data for authenticating the user terminal by the authentication server from the user terminal, and a connection unit that transmits the token data associated with the registration code to the authentication server when receiving a request for establishment of a tunnel between the processing unit and the user terminal and the registration code from the user terminal, and establishes a tunnel between the processing unit and the user terminal when receiving a result indicating authentication from the authentication server.

6. A program for causing a computer to function as the providing server according to claim 5.

Citation Information

Patent Citations

  • Processing print requests

    JP2013537664A

  • Communication control server, communication control method and program

    JP2015133016A

  • Information processing system and authentication method

    JP2016042327A

  • Information processor, method, and program

    JP2019012365A

  • Apparatus, method and program for automating business process with operation to intra-company server on intra-company network

    JP2020091512A

Cited By

  • Registration-based application authentication

    US20260149599A1