Relation authentication device and system
The relationship authentication system addresses the limitations of personal authentication by creating and collating identifiers to simplify procedures and enhance security, enabling cost-effective and secure authentication in IoT environments.
Patent Information
- Application Number
- PCT/JP2025/080004
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-26
- Filing Date
- 2025-01-07
- Publication Date
- 2025-07-17
AI Technical Summary
Existing personal authentication methods impose a heavy burden on users, require high costs for service providers, and have limitations in application to IoT, while existing authentication systems lack effective security measures.
A relationship authentication system that determines the legitimacy of relationship continuation by creating and collating identifiers for variously established relationships, simplifying user procedures, and enhancing security.
Simplifies user procedures, reduces costs, and enhances security, making it applicable to IoT systems.
Smart Images

Figure JP2025080004_17072025_PF_FP_ABST
Abstract
Description
Relation authentication device and system
[0001] The present invention is fundamentally different from existing technologies, and its target field relates to authentication devices and systems that are simple and have a high level of security.
[0002] The underlying technology is identity authentication, which authenticates the legitimacy of elements such as individuals and companies. Passwords, which are used for identity authentication, and their improved counterparts, passkeys, place a heavy burden on users and impose high costs on service providers, limiting their applicability to IoT. Prior Art Literature The present invention and existing technology (identity authentication) differ in principle, and there is no prior art or comparable prior literature that can be compared to the present invention.
[0003] The problems to be solved include simplifying the authentication procedures of the prior art, which are complicated, and improving security, which is an issue that has been raised.
[0004] The most important feature of the present invention is that it authenticates the validity of the relationship continuity.
[0005] The authentication system of the present invention has the advantages of simplifying user procedures, reducing costs, and increasing the level of security. It can also be applied to IoT, where existing authentication systems have had limitations.
[0006] Fig. 1 is an explanatory diagram showing one embodiment of a relation authentication device, and Fig. 2 is an explanatory diagram showing one embodiment of a relation authentication system according to the present invention.
[0007] This is achieved by setting up a matching unit or matching system that determines the legitimacy of relationship continuation, so that the wide variety of relationships that can exist can be continued legitimately.
[0008] First, we will provide an overview of the present invention. The present invention differs in principle from the background art (personal authentication) and incorporates novel terminology and concepts. Detailed explanations are provided below where necessary. All means, steps, systems, facilities, equipment, devices, functions, and technologies described herein may be arbitrarily combined and configured in various ways to appropriately implement the present invention. The described embodiments may be arbitrarily combined and configured to appropriately implement the present invention, achieving its purpose and enhancing its effectiveness. The terms used have different meanings depending on the embodiment. For example, a center may refer to a facility, base station, system, platform, server, etc., and may also include a cloud in some embodiments. Figure 1 shows one embodiment of the device of the present invention, where 1 is element a, 2 is element b, 3 is the center, 4 is a memory unit, 5 is a verification unit, and 6 is element c. (Elements a, b, and c are not limited to users, but may also include terminals used by elements a, b, and c, as well as memory units, processing units, output display units, etc., provided in the terminals, and conform to the specifications of each embodiment.) Figure 2 is an explanatory diagram of one system according to the present invention. The system starts (7), an element accesses the center (8), relationship data is created (9), and the relationship data is stored in the memory unit (10). When a new element accesses the center (11), the relationship data is verified (12). The terms "relationship authentication device" and "relationship authentication system" have broad meanings and refer to devices or systems that input, output, process, store, send, receive, and control information, and have specific functions. These devices generally take the form of smartphones, personal computers, centers, servers, and platforms. "Information" refers to anything that can be transmitted, including characters, symbols, numbers, audio, video, drawings, codes, and olfactory objects. "Elements" can be single or multiple, and examples include individuals, users, groups, organizations, and systems. Examples include government agencies, local governments, corporations such as companies, individuals, organizations, functions, home appliances, cars, transportation systems, and electricity, gas, and water infrastructure, and refer to all potential users and targets of the authentication device and system. A verification unit (including a verification system) is set up in a center or authentication unit (including an authentication system).) are also elements, and the relationship between a center and an individual user is also an element, and a relationship is established, and the means, system, and steps for creating relationship data are included. Components of the IoT are also broadly included as elements. "Relationships" in society are all relationships established between elements, such as the buying and selling and receiving of money and goods, the sending and receiving of various information, confirmations, contracts and reservations, and the communication and expression of various intentions, and all relationships that can be formed through information. Relationships have various meanings depending on the embodiment. In some cases, they include all events related to the relationship. In such examples, the identifier also includes the content of the event and derived phenomena. Events related to the relationship are classified, and the identifier is used to select the data from these classifications. In embodiments of the present invention, relationship data (identifiers) are collated to determine whether or not to proceed with the procedure for establishing a relationship. Relations include all procedures, processes, transactions, etc. related to daily life, business, education, entertainment, etc., conducted between individuals, mail-order companies, service and information providers, banks, government agencies, hospitals, travel agencies, etc. An "identifier" is an identifiable entity that can be composed of letters, symbols, numbers, sounds, videos, drawings, codes, olfactory objects, etc. In this invention, an "identifier" is described as "relationship data." Relationship data (identifiers) are assigned to relationships between elements in order to identify the relationships. Any identifier can be formed as long as it is identifiable. The "number" can be time, or latitude and longitude coordinates indicating a point location. There are no restrictions as long as it is identifiable. Olfactory objects can also be used as long as they can be identified, such as devices, people, and living things. The means and system for creating identifiers are provided in at least one of the following: a terminal, device, means, system, center, cloud, or a processing unit (including a processing system) set up in a third-party facility, device, facility, means, system, etc. Alternatively, a means or system for creating identifiers using these in combination is provided, and a means or step for storing the identifier in a memory unit or memory system provided therein is provided.The means and steps for verifying relationship data are provided in a processing unit (processing unit including a verification unit) or processing system provided in a terminal, center, authentication center, third-party facility, device, or system used. One example will be described. Elements a and b may be multiple and diverse. When element a establishes a broad social relationship (generally arising through transmission and reception over the Internet) between element a and element b, including politics, economics, culture, entertainment, lifestyle, education, business, research, etc., the center (including a server, cloud, etc.) provides a means for creating an ID (identifiable notation or various data) to be assigned to the elements a and b that establish the relationship. Relationships are typically formed using the Internet, but there are a wide variety of relationships involved, such as buying and selling in mail order sales, reservations for travel, taxis, dining, concerts, etc., bank remittance procedures, cryptocurrency transactions, email transmission and reception, contracts with individuals or corporations, use of applications and services, and control of home appliances, cars, hospitals, factories, transportation infrastructure, etc. There are no restrictions on the types of elements as long as they are capable of establishing the above relationship. The present invention is primarily implemented over the Internet. (Hereinafter, "means" has the meaning of "step" according to the embodiment. As one example, element a has a means (step) for accessing the center, and when the center is accessed (step), the center has a means (step) for creating an ID for element a, a means (step) for creating an ID for the center, and further has a means (step) for recording the time at any timing during the time when the relationship is executed. In some cases, the recorded numerical value is not time, but a numerical value of position data or any other arbitrary numerical value. In other cases, it is not a numerical value but an identifiable picture, code or cipher. There is a means (step) for storing data composed and created by the record and the IDs of element a and the center in a memory unit as collation data (relation data) related to the relationship between element a and the center. One general embodiment of the present invention will be described.The authentication device of the present invention, which differs in principle from personal authentication, provides a relationship authentication device equipped with a means for creating an identifier that distinguishes a relationship between element A and element B from other relationships when the relationship arises, and a means for storing the identifier in a memory unit. Personal authentication has traditionally been performed using biometric data such as passwords, fingerprints, and irises. These are all set and registered by the user (element), creating a burden. Setting and managing authentication data such as passwords and fingerprints poses risks and costs for both individuals and companies. Furthermore, security concerns have led to even the concept of zero trust being embraced. According to one embodiment of the present invention, the identifier is created by the authentication device, and attribute data of the user (element), such as name, address, evaluation, track record, and preferences, is managed separately from the identifier. Since the identifier can only be uploaded over the Internet for a limited time, the risk of theft is reduced. Examples include an example in which the identifier is created by a processing unit at a center, and an example in which the center and elements share the responsibility for identifier creation. For example, the processing unit at the center issues a creation instruction to the processing unit of the device used by the element. In an embodiment in which the terminals used by elements A and B create identifiers in response to the instructions, there is a possibility that the time may not match and may result in a discrepancy. In light of this example, it is preferable to provide a means (step) for the processing unit of the terminals used by elements A and B to recognize a discrepancy and determine that the identifiers are valid even if they do not match, rather than requiring that the identifiers match as a requirement for the comparison. This determination is not limited to the processing unit of the terminals used by elements A and B. There are also examples in which the determination is made by a processing unit such as a center or authentication unit. This is one example of satisfying the requirements set forth in this specification. The system is configured to recognize discrepant times as valid. In some embodiments, the relationship in the present invention includes all related events. It is desirable to provide a means for organizing and classifying the content of the events, using them as evaluation material, or providing a means for subjecting them to statistical analysis.
[0009] A novel relationship authentication device is realized by including a means for comparing the identifiers stored in the storage units of element A and element B, a means for determining whether the identifiers satisfy predetermined requirements through the comparison, and a means for approving the continuation of the procedure for establishing a relationship between element A and element B when it is determined that the requirements are satisfied. In one example, the identifier comparison is performed by a processing means in the matching unit included in the device. Various configurations for sending the identifier to the processing means in the matching unit are available, and are also described in other embodiments. In some embodiments, a process is set up, or a means for issuing a search instruction or sending instruction to the storage unit is provided. As described herein, there are various methods for managing identifiers, and various aspects of the management are incorporated, including cooperation with an authentication unit or a dedicated terminal, and various measures against unauthorized intervention. Risks are also reduced by defenses such as a list of confidential elements. An identifier generally consists of an ID assigned to element A and element B and the time recorded when the relationship was established. There are examples in which the ID and the time are set by the center, and examples in which element A or element B performs part of either. There are also examples in which element A or element B is not involved at all and does not know its own ID. There are examples in which the identifier is updated each time a relationship arises, and examples in which it is updated randomly, at a set time, or at any opportunity. Risk levels and security standards differ for IoT, critical infrastructure, cryptocurrency transactions, etc., so it can be applied arbitrarily.
[0010] This is a relation authentication system that differs in principle from existing identity authentication systems. When a relationship arises between element A and element B, a new relation authentication system is implemented by including step 1 of creating an identifier that distinguishes the relationship from other relationships, and step 2 of storing the identifier in a storage unit. Various embodiments have been shown regarding the method of creating and storing the identifier.
[0011] A novel relationship authentication system includes a step 3 of comparing the identifiers stored in the storage units of element A and element B, a step 4 of determining whether the identifiers satisfy predetermined requirements through the comparison, and a step 5 of approving the continuation of the procedure for establishing a relationship between element A and element B when it is determined that the requirements are satisfied. The requirements to be satisfied are arbitrary, and examples include using encryption or converting the data into a graphic or image to determine whether it is consistent. In one embodiment, the system includes a means for storing the relationship data in the storage units of the center and the terminal of element A (in a system embodiment, the term "means" may have the same meaning as "step"). When element A next applies for a relationship with the center (a step of accessing the center), the center includes a means (step) for retrieving the relationship data from the storage unit of the center, and a means (step) for retrieving the relationship data from the storage unit of element A's terminal and notifying a processing unit of element A's terminal of a transmission instruction to transmit the data to a processing unit of the center (or the matching unit of the authentication unit, etc.). The matching unit of the center or the matching unit of the authentication unit includes a means (step) for matching the relationship data. If the matching determines that the relationship data match (or satisfy the specified requirements) (step), it also includes a means (step) for approving element a's new application. When the center approves the procedure for element a's application (step), element a and the center execute the procedure via a predetermined communication means (step). For example, when element a wishes to establish a relationship with element b via the center and applies to the center (step), the center includes a means (step) for retrieving the previous relationship data between element a and element b from the memory unit of element a's terminal and issuing a transmission instruction to the processing unit of element a to send the data to the matching unit. Similarly, it includes a means (step) for retrieving the previous relationship data between element a and element b from the memory unit of element b's terminal and issuing a transmission instruction to the processing unit of element b's terminal to send the data to the matching unit. The matching unit of the center or the matching unit of the authentication unit includes a means (step) for matching relationship data.The system includes a means (step) for determining whether the relationship data matches (or satisfies predetermined requirements) through the comparison. When it is determined (step) that the data matches (or satisfies requirements), the system includes a means (step) for the processing unit of the center to approve the progress of the procedure for establishing a new relationship between element a and element b. Elements a and b are provided with a means (step) for executing the procedure via a predetermined communication means. When establishing a relationship using the Internet, if there is no past relationship history and it is the first time, there may or may not be a list of counterparties. For elements (users) managed by the center, the system includes a means (step) for creating a list operated by the center. In cases where there is no list, element b receiving a relationship request is often a government agency, local government, company, store, etc., and is planning to apply for an unspecified element a. In such cases, the center is provided with a means (step) for approving the establishment of the relationship, and the center and element a implementing the present invention follow the decision of element b. After the center approves the progress of the procedures to establish a relationship and the transmission and reception, the relationship between element a and element b is validly established when element b and element a confirm, agree, and acknowledge the conditions and content of the relationship using a specified communication method. In one example, the time when the center approves the progress of the procedures to establish a relationship and the transmission and reception is recorded, and relationship data is created based on that time. In some examples where either element a or b receives a relationship request, there are also embodiments in which the relationship is limited to the counterparty and content approved by the user, and the relationship is established when both parties confirm and agree.
[0012] This section explains the detection of abnormal processing of relationship data. Relationship data processing is diverse, and there are no restrictions on the combination of embodiments, resulting in numerous processing examples. (In this specification, the term "means" can also mean "steps.") Some embodiments include a means for establishing a predetermined process for processes leading to the creation of an identifier, storage in a memory unit, retrieval and transmission to a processing unit, and other processing and matching; a means for detecting that the process has been completed; a means for assigning a signature, stamp, or ID to the identifier to prove that the process has been completed; a means for detecting abnormal processing when processing that differs from the predetermined process is performed; and a means for not approving the progress of procedures related to the establishment of a new relationship when such processing is detected. An example is shown here: This is an example in which relationship data (identifiers) are forged and used fraudulently. Forged relationship data is likely to be sent to the matching unit without going through the predetermined process. In one example, relationship data is forged or stolen and sent to the matching unit without being retrieved from the memory unit. The processing unit includes a means (step) for determining that the process is different from the specified process because there is no stamp, signature, or ID indicating that the data has been retrieved from the storage unit, and a means (step) for disapproving the progress of the procedure for establishing a relation. Alternatively, in an example of an unauthorized search for relation data from the storage unit, the processing unit includes a means for determining that the process is different from the specified process because there is no stamp, signature, or ID indicating that the search prerequisites or conditions, such as a center's delivery instruction, are met, and a means for disapproving the continuation of the procedure. Alternatively, the system includes a means for intentionally setting unnecessary processes, a means (step) for recording the fact that such processes have been passed through, and a means (step) for determining that a procedure that does not pass through the set and specified processes is an unauthorized process. This embodiment is effective for important systems or high-risk systems, and it is desirable to set many processes. The processes may also be changed randomly as appropriate. An example will be described using users X and Y.The terminals Xa and Xb used by X (and similarly the terminals Ya and Yb used by Y) are provided with a means (step) for storing and saving relationship data in the memory units. In an example in which the processing unit of the center or authentication center (or Ya, depending on the embodiment) is provided with a means (step) for transmitting instructions to the processing units of Xa and Xb (in some embodiments, the instructions are accompanied by a signature or a code), the processing unit of the center or authentication center (or Xa, Ya, depending on the embodiment) is provided with a means (step) for determining that an abnormal process has occurred when relationship data is searched for in the memory unit despite the absence of the instruction or signature. When the processing units of Xa and Xb are provided with a means (step) for searching for the relationship data from the memory units of Xa and Xb, the processing unit of the center or authentication center (or Xa, Ya, depending on the embodiment) is provided with a means (step) for determining that an abnormal process has occurred when the relationship data is searched for without the search processing (operation of the means) of the processing units of Xa and Xb. In addition, when some steps, flows, means (steps), procedures, etc. are set for searching the memory units of Xa, Ya, Xb, and Yb for relationship data, it is desirable that the processing unit of the center or authentication center (or Xa or Ya, depending on the embodiment) be provided with means (steps) for determining that the processing is abnormal if the search is performed without the steps, flows, means, procedures, etc. In an example where the memory unit of the center (including a server, cloud, application operation center, etc.) or authentication center is provided with means (steps) for storing and saving relationship data, and the processing unit of the center or authentication center (or Xa or Ya, depending on the embodiment) is provided with means (steps) for sending instructions to the processing unit of the center or authentication center, the processing unit of the center or authentication center (or Xa or Ya, depending on the embodiment) is provided with means (steps) for determining that the processing is abnormal if the relationship data is searched for in the memory unit despite the absence of the instructions or signature.In addition, when certain steps, flows, means, procedures, etc. are set for searching relationship data in the storage unit, it is desirable for the processing unit of the center or authentication center (or Xa or Ya, depending on the embodiment) to have a means (step) for determining that the search is an abnormal process if the search is performed without the steps, flows, means, procedures, etc. When the abnormal process is detected, a means (step) for invalidating the detected relationship data is provided. In some embodiments, a creation means (step) for creating relationship data at that time is provided. In other embodiments, a means (step) for creating new relationship data by the creation means and storing it in the storage unit is provided. The abnormal process is a process that differs from the procedures and procedures such as steps, flows, processes, etc. set and configured in each embodiment, and includes a means (step) for estimating that there is a high possibility of a system error or unauthorized intervention by a third party. Here is an example of abnormal process. The searched relationship data is sent from the storage unit and processed by the processing unit for comparison, and during this process, it is scheduled to undergo the specified processing, such as transmission / reception and comparison. The system includes a means (step) for detecting, for example, that the relationship data has not been retrieved from the storage unit and passed through the transmitting / receiving unit, or that the relationship data has not been transferred to the matching "field" (matching unit) equipped with the matching means, and a means (step) for detecting, as an abnormal process, processing that differs from the steps, flows, procedures, procedures, processes, etc. in any embodiment configured and configured in each embodiment. In some cases, flows, procedures, and means are intentionally incorporated to facilitate detection in order to detect abnormal processing. It is desirable to intentionally incorporate unnecessary processes for the purpose of detection, and to include a detection means (step) for detecting, as an abnormal process, when the process does not pass through, or when the target of the means (the target of the means for detecting, confirming, recognizing the passage, etc. of relationship data) is not present (the absence of something that should be the target). The detection means can be implemented in a variety of ways, and some examples include a means for checking relationship data (means for recognizing the detection, confirmation, passage, etc. of the relationship data) before and after any (or all) of a specified flow, process, step, means, processing, etc.In some cases, when the confirmation (detection, recognition, etc.) means (step) confirms that normal processing has been performed, or when the processing unit determines that the processing is different from normal processing (the processing unit is provided with the means for making this determination), the processing unit is provided with a means for invalidating the relationship data.In some cases, the processing unit is provided with a means (step) for distributing newly created relationship data to a memory unit of a terminal used by the parties to the relationship.
[0013] In some implementations, new relationship data is not created and the validity of the relationship continuation is not recognized. (In some cases, for high-risk relationships, the procedure is suspended and the parties to the relationship are searched for.) Abnormal processing is a process different from the predetermined flow, step, means, procedure, processing, or process, and the predetermined flow, process, etc. are set arbitrarily depending on the implementation. Each time a predetermined flow, step, means, procedure, processing, etc. is executed normally, a means (step) is provided for adding a stamp (character, symbol, etc.) to the relationship data when the flow, step, means, procedure, processing, etc. is executed, a means (step) is provided for checking the presence or absence of the stamp, and a means (step) is provided for suspending the procedure when it is determined that the stamp is not present. In some implementations, a means (step) is provided for canceling (invalidating) the relationship data and a means (step) is provided for creating new relationship data at that time. The specific manner in which abnormal processing is detected is also arbitrary, and the response upon detection (whether to invalidate the relationship data, create new relationship data, distribute new relationship data, etc.) is also arbitrary.
[0014] In some cases, where the relationship is an initial one, the attributes and track record of element b, the party requesting the relationship, are unknown. Therefore, the processing unit or processing system of the terminal used by the center or element a may include a means (step) for issuing a warning to the requesting user (element a), and element a may include a means (step) for confirmation. Upon receiving the confirmation, element a's terminal may notify the center, and the center may then approve the establishment of the relationship. The warning is typically displayed as a visual, written, or audio message by the output unit of the terminal. Even in cases where element a mistakenly requests a relationship with element b, which has no relationship history, element a may preferably include a means (step) for performing confirmation upon instruction from the center, and a means (step) for the center to issue a warning to element a's terminal. In some embodiments, the center may include a means (step) for detecting abnormalities in the type, content, or numerical values of the element, which differ from those of a normal relationship, and a means (step) for executing the confirmation and a means (step) for issuing a warning to the user's terminal or the other party in the relationship. The means (steps) and methods for detecting abnormalities in the content, quality, quantity, and amount of relationships (anomaly detection) are optional. Generally, statistical methods are used.
[0015] In some embodiments involving high-risk relationships, the condition is that the element (user) be located at a predetermined location. For example, the system includes a means (step) for determining, as the location for executing the relationship, a location arbitrarily determined by the element, where it is difficult for third parties to be present, or a highly secure location such as near a police station or inside a bank. The system also includes a means (step) for verifying the presence of the element or the terminal at the predetermined location by using any method, such as Bluetooth, local radio waves, IC tags, or GPS, to confirm the terminal's latitude and longitude or its relationship to the predetermined location, thereby matching the element's location with the predetermined location. For example, the system includes a means (step) for verifying the location with a predetermined numerical value (location coordinate value). It is desirable to include a means (step) for verifying whether the element's location matches the predetermined location, and a means for approving the procedure upon verification, or upon verification of the location by a verification means (step) provided in the terminal. Using such means in conjunction with the present invention improves crime prevention and safety.
[0016] It is desirable to use the present invention in combination with countermeasures against malware and viruses. The system includes a means (step) for extracting the intent and content from data 1 received from an external source using AI, and a means (step) for the AI to create new data 2 based on the extracted intent and content. It also includes a means (step) for sending data 2 to an internal system virtually isolated from the outside. It also includes a means (step) for sending the remaining data after the intent and content has been extracted, or data 1, not to the internal system, but to an analysis unit provided in a separate system isolated from the internal system. The analysis unit includes a means (step) for analyzing the data or cultivating viruses, and, if malware or a virus is detected, a means (step) for searching for the sender of data 1 or taking action.
[0017] The authentication device and system include a means (step) for recording relationships that have been validly established (or relationships that have not been established) between an element and another element in the past as a relationship history, and a means (step) for storing the record in the storage unit (shown in the embodiments described in this specification). The storage means and the storing step are executed (steps) by a processing unit, processing system, storage unit, storage system, etc., of a center (in a broad sense, including a platform, cloud, etc.) or a terminal used by elements a and b. Alternatively, the record may be stored in a storage unit or storage system of a dedicated terminal used in combination. The means, system, form, tool, etc. for storing the record are arbitrary. The device and system include a means (step) for providing the record of the relationship history to the terminal or system of the element (user), and a means (step) for restoring the conditions and qualifications for establishing a new relationship when the terminal used by elements a and b breaks down or is lost. The system may include a means (step) for transmitting the relationship history to the other element or center, a means (step) for transmitting the relationship history, a means (step) for applying for a new relationship, a means (step) for evaluating the relationship history as past performance, and a means (step) for enabling the procedure for establishing a new relationship. Alternatively, the system may include a means (step) for recording the history of unsuccessful relationships and storing it in a memory unit of a terminal or center used by elements a and b, and it is also desirable to use the recorded history as material for preventing fraud or as material for evaluation.
[0018] In the authentication device and system, when an element establishes a relationship with another element, the device and system include a means (step) for representing the name, ID, etc. of the other element and providing the element with a list that allows the element to specify the element (the other element in the relationship). The list may be represented in a manner that allows the element using the list to be identified and to indicate the party to whom the application is to be made. The representation may be in a form that the element can recognize. It is desirable to use representation that is indistinguishable from third parties to prevent unauthorized use. In some cases, the list is stored in a memory unit of the terminal used by the element. In examples that include a means (step) for searching from a memory unit of the terminal, or a means (step) for sending the list from a center to the terminal and a means (step) for displaying the list on the output display unit of the terminal, it is preferable to include a means (step) for disclosing the list by the user (element) of the terminal using a fingerprint, PIN, etc., and a means (step) for keeping the list secret from third parties. In some cases, the list is stored in a memory unit of the center. Similarly, it is preferable to have a means (step) for disclosing the list using the fingerprint or PIN of the element (including a means (step) for sending the list from the center to the terminal), and a means (step) for not sending the list to the terminal when the disclosing means is not executed. By keeping the list secret, third parties can be prevented from establishing relationships fraudulently. Even when an element attempts to fraudulently establish a relationship with a counterparty with no relationship history, a means (step) for warning the element and a means (step) for confirmation can be provided, thereby preventing third parties from attempting to establish a relationship unrelated to the element. In other cases, the list is stored in a memory unit of a dedicated terminal used in conjunction with the terminal used by elements a and b, separate from the terminals used by elements a and b. In this example, it is also preferable to have a configuration that similarly includes a means (step) for disclosing the list using the fingerprint or PIN of the element, and a means (step) for keeping the list secret.
[0019] An example of a list is described below. The system includes a means (step) for creating a list of elements by the center. The system also includes a means (step) for creating the list by adding the element's evaluation (such as track record). The center also includes a means (step) for notifying the other party in the relationship of the evaluation of the element. The evaluation is determined based on the number of years without trouble or fraud, the track record of the relationship, and the number of years in history. Elements a and b generally desire relationships with parties with high evaluations. The evaluation increases if the number of years without trouble or fraud is long, and the relationship is of high quality and large scale. The center also includes a means (step) for sending a list of elements that have a track record with the element to a terminal used by the element. It is preferable to have a means for sending the list in an unreadable (concealed) form. In this example, the terminal receiving the list includes a means (step) for converting the list into a readable form. As an example, the element includes a means (step) for inputting a PIN or biometric data, or a means (step) for inputting a code or code into the terminal. This embodiment allows the list to be kept secret from third parties. As a result, the risk of the terminal executing a relationship with an element that the element is not aware of and has no history of performing is reduced, and the terminal can be prevented from being used fraudulently to cause damage to the element.
[0020] In some cases, recording media such as USB memory, cloud, or memo are used in combination as a means of concealing the list, and in other cases, they are used in combination for recovery (a means of restoring procedures in the event of a terminal failure or loss). In addition to using the list, recovery can also include a means (step) for storing relationship data using USB memory, cloud, memo, or any other means, and transmitting the relationship data to a center to restore the qualifications in the relationship between the center and the element. The relationship data only needs to be usable by the center to confirm the qualifications of the element, and a means (step) for sending any relationship data to a terminal used by the element at any time, at the center's discretion, is included. The element is included in a means (step) for storing the data using USB memory, cloud, memo, or any other means. During recovery, the element is included in a means (step) for transmitting the relationship data to the center on any terminal. The center is included in a means (step) for determining whether the received relationship data is authentic. If it is determined to be authentic, a means (step) for restoring the qualifications of the element is included. The element that has restored the qualification is provided with means (step) for sending the list to the terminal.
[0021] When the procedure for establishing a relationship between element a that requests a relationship and element b that receives the request is approved by the center, element a and element b have a means (step) for transmitting and receiving data via any communication means (with or without the intervention of the center). When elements a and b establish a relationship legitimately and without any problems, the center has a means (step) for assigning new relationship data to elements a and b. There are several forms of the assigning means (step) and targets. Examples include the terminals of elements a and b, equipment and facility devices, and the associated storage and processing units, center equipment and facility devices, and the associated storage and processing units, system storage and processing units, equipment and facility devices of an authentication unit that specializes in authentication, and the associated storage and processing units, cloud storage and processing units, and dedicated terminals used by elements a and b, as well as the terminals of elements a and b, and the associated storage and processing units, etc., that are used as targets for assignment.
[0022] Relationship data can be composed of letters, symbols, numbers, sounds, videos, drawings, codes, olfactory objects, etc., and any identifying material can be used as long as it is distinctive and identifiable. The identification means (steps), methods, and entities, such as humans, animals, or machines, are also optional. Typically, relationship data is composed of letters, symbols, and numbers. The relationship includes a means (step) for creating relationship data by combining the time when the relationship was legitimately established between elements a and b (multiple elements are possible; the number of elements is arbitrary, and in some cases, the element is singular in a relationship between a center and an element), the numerical values of the X and Y coordinates of the location (latitude and longitude) of at least one (or one) of elements a and b, and an ID assigned to the element by the center. The center also includes a means (step) for creating this relationship data. The creator of the relationship data is not limited to the center; in some cases, the creation means (step) is provided by either element a or b, or a facility or system specialized in creating relationship data.
[0023] Another embodiment is shown below. The center includes a means (step) for instructing the terminals of elements a and b and the processing units of related systems, facilities, devices, authentication units, etc., to record the same common time when the relationship is established. (A common time across all regions of the world, ignoring time differences, is desirable. In this example, the center includes a means and function for independently managing time, which progresses over time.) The center also includes a means for transmitting the IDs of elements a and b (or the terminals used by elements a and b) created by the center to the terminals of elements a and b and the processing units of related systems, facilities, devices, authentication units, etc. Because the IDs and times of elements a and b (or the terminals used by elements a and b) are not transmitted over the Internet, the risk of relationship data being stolen is reduced.
[0024] As one example, a device or system embodying the present invention includes a means (step) for sharing and storing relationship data in a storage unit. Alternatively, the processing units of the terminals of elements a and b and their associated systems, facilities, devices, authentication units, etc. include a means for storing relationship data in a storage unit. In a typical embodiment, the center includes a means (step) for instructing the terminals of elements a and b to record the same common time when a relationship is established. The center includes a means (step) for assigning an ID to elements a and b (or the terminals used by elements a and b), and the processing units of the terminals of elements a and b include a means (step) for creating relationship data using the time and ID. When elements a and b newly establish a relationship, the processing units of the terminals include a means (step) for receiving an instruction from the center and sending the relationship data to the center. The verification unit of the center or authentication unit includes a means (step) for verifying the relationship data. The configuration of these means (steps) aims to prevent relationship data from being sent over the Internet in advance. The relationship data is only released onto the Internet at the time of verification, thereby reducing the risk of theft or forgery.
[0025] A configuration that includes a means (step) for storing relationship data in a distributed manner and a means (step) for sending the data to the matching unit at the time of matching has the same effect. A configuration that includes a means for storing relationship data in a distributed manner in the memory units of the terminals used by elements a and b, the memory units of dedicated terminals used in conjunction with these, the memory unit of the center, the memory units used in conjunction with these, and other memory units used in conjunction with these, until the data is sent to the matching unit. Some embodiments also include a means (step) for sending the (distributedly stored) relationship data from the memory units to the matching unit at the time of matching. With this configuration, the relationship data is only released over the Internet at the time of matching, thereby reducing the risk of theft.
[0026] In this embodiment, the system includes a means (step) for assigning an ID for searching to a part (portion) of distributed relation data, a means (step) for searching the part of the relation data by the ID, and a means (step) for extracting the part from the storage unit and sending it to the collation unit.
[0027] In some embodiments, relationship data and relationship data parts are not stored in the memory units of the terminals used by elements a and b, nor in the memory units of the dedicated terminals used in conjunction with them. In these embodiments, the memory units of the terminals used by elements a and b are provided with means for storing IDs for searching for the relationship data and relationship data parts. A memory unit attached to the collation unit is provided with means for storing the relationship data and relationship data parts. In some embodiments, means (steps) for extracting the relationship data and relationship data parts from the memory unit and means (steps) for sending them to the collation unit are provided. According to these embodiments, the risk of relationship data being exposed over the Internet is reduced.
[0028] There are a variety of grounds for determining that the specified requirements are met when the matching means of the matching unit matches relationship data retrieved from a storage unit such as elements a and b, a center, or an authentication unit and sent to the matching unit. Other examples include determining that the matching requirements are met not by matching but by "matching" (meeting the requirements) according to the specified requirements, and using the sent relationship data to satisfy the specified requirements. The "requirements" in these examples vary and can be any, including matching, overlapping, or mixing to achieve significance. In some cases, a requirement is satisfied by combining a code with the relationship data. According to a system embodying the present invention, when the matching means of the matching unit matches and determines that the requirements are met, the system includes a means (step) for approving the continuation of the procedure to establish a relationship between elements a and b. In some embodiments, elements a and b are connected to a center and a matching unit, a storage unit and a processing unit, a user and a dedicated terminal used by the user, etc. The system includes a means (step) for not approving the continuation of the procedure for establishing the relationship between the elements a and b when the elements a and b are compared and it is determined that the requirements are not met. When the continuation of the procedure for establishing the relationship is approved, the system includes a means (step) for enabling the use of a predetermined transmission / reception means. The transmission / reception means may be a communication means managed and operated by the center, or may be a communication means managed and operated by another telecommunications carrier.
[0029] While attribute data for elements a and b may be stored, maintained, utilized, and managed by a center, it is preferable to use an evaluation system in conjunction with the data. The procedures, methods, techniques, steps, means, functions, configurations, equipment, devices, handling, and other aspects described in the specification, as well as examples of each aspect, may be implemented in a wide variety of combinations. While the center typically creates the relationship data, in one embodiment, the time recorded at any timing in the relationship may be Universal Time (UTC) or a time independently advanced by the center. It may also be a time common to all regions of the world that does not take time differences into account. It is sufficient for the time to progress over time. The IDs of elements a and b associated with the recorded time do not need to originate from the user or the center; they may be arbitrary and determined by the creator. It is sufficient to provide a means for identifying and searching for users using the relationship data. It is preferable for the data format to prevent direct association of the relationship data with users. It is also preferable to provide a means for preventing third parties from accessing the means for searching for users using the relationship data or the means for searching for relationship data using user IDs. As an example, when relationship data is created, there is Example 1, where it is stored and saved in the memory of the creator's system, Example 2, where it is distributed to the parties in the relationship, and Example 3, where it is sent to a network such as the Internet. Example 1 is generally used in conjunction with Examples 2 and 3, and Example 1 is mainly used at a center (including servers, sites, clouds, exchanges, etc.) is taken as an example, and as one example, a storage unit 1 of the center system is provided with a means (step) for storing and saving relation data assigned to relations involving the center (storage units 1 and 2 are installed for the purpose of preparing for trouble), a storage unit 2 of the center system is provided with a means (step) for storing and saving relation data assigned to relations relating to users (elements, users), and when any user applies for a relation, a means (step) for searching the storage units 1 and 2 for the relation data (data assigned to the relation between the user and the center) using the ID of the user and the ID of the center is provided, and The system includes a means (step) for transferring the relationship data to a matching unit that matches the relationship data, and when the relationship establishment procedure for which approval has been requested involves parties other than the center (including multiple parties and an unspecified number of parties), the system includes a means (step) for retrieving relationship data (assigned to the parties) from a storage unit using the IDs of the parties (including multiple parties and an unspecified number of parties), a means (step) for matching the relationship data of these parties (those involved in the relationship), and a means (step) for approving the relationship when it is determined that the specified requirements are met. In Example 2, in an example where the relationship does not involve a party and is between a user and the center, the system includes a means (step) for searching the relationship data of the applicant for the relationship procedure in the storage unit 2 using the user's ID, and before or after this, the processing unit of the center includes a means (step) for instructing the processing unit of the user's terminal to transmit the relationship data. In some examples, the system includes a means (step) for instructing the user to transmit. In some cases, the system is provided with a means (step) for the user to operate the terminal to retrieve relationship data from the terminal's memory and send it to the center. The processing unit of the user's terminal is provided with a means (step) for receiving the instruction and retrieving the relationship data (to which the user and center IDs are assigned) assigned to the last relationship between the user and the center from the memory. The terminal's memory is provided with a memory unit B dedicated to relationship data, and a means (step) for storing and saving data other than relationship data in memory unit A.The system comprises a means (step) for restricting the processing unit from accessing the memory unit B, a processing unit ii is placed in front of the memory unit B, and the processing unit comprises a means (step) for attaching a signature (created using any description such as letters, symbols, or number sequences) sent from the processing unit at the center to the processing unit ii. The processing unit at the center comprises a means (step) for sending the signature to the processing unit of the terminal. The memory unit comprises a means (step) for only following instructions accompanied by the signature. In some cases, a dedicated terminal having an independent memory unit B is used, and the system comprises a means (step) for sending and receiving data to and from the terminal used by the user via wired or wireless (contactless, Bluetooth, or other optional) communication, and a means (step) for only following instructions from the processing unit when the signature sent from the processing unit at the center is attached, as described above. Upon receiving the instruction accompanied by the sign, the processing units of the terminal and the dedicated terminal are provided with means (steps) for retrieving the relationship data from the memory unit (the processing unit of the dedicated terminal is provided with means (steps) for sending the relationship data to the processing unit of the terminal via the transceiver unit), the processing unit of the terminal is provided with means (steps) for sending the relationship data to the processing unit of the center via the transceiver unit, the processing unit of the center is provided with means (steps) for transferring the data to a matching "field", and at that "field" is provided with means (steps) for matching the relationship data stored in the memory unit of the center with the relationship data sent from the memory unit of the terminal or the memory unit of the dedicated terminal, and is provided with means for approving the relationship between the center and the applicant when it is determined that the specified requirements are met. In Example 2, when either user applies for a relationship, the system is provided with means (steps) for retrieving the relationship data from memory unit 2 using the IDs of the user and the other party, and means (steps) for transferring the relationship data to the matching "field", and before or after this, the processing unit of the center is provided with means (steps) for instructing the processing unit of the other party's terminal to send the relationship data. In some cases, the system is provided with a means (step) for instructing the other party to send the data. The other party operates the terminal to retrieve the relationship data from the storage unit of the terminal and send it to the center. The processing unit of the other party's terminal receives the instruction and retrieves the relationship data (which includes the IDs of the applicant and the other party) assigned to the last relationship between the applicant and the other party from the storage unit.The terminal includes a means (step) for searching for relationship data, a storage unit B dedicated to relationship data, a means (step) for storing and saving data other than relationship data in storage unit A, and a means (step) for restricting the processing unit from accessing storage unit B. Processing unit ii is located in front of storage unit B, and the processing unit includes a means (step) for attaching a signature (created using any description, such as letters, symbols, or number sequences) sent from the processing unit at the center to processing unit ii. The processing unit at the center includes a means (step) for transmitting the signature to the processing unit at the terminal. The storage unit includes a means (step) for only following instructions accompanied by the signature. In some cases, a dedicated terminal having an independent storage unit B is used, and the storage unit includes a means (step) for transmitting and receiving data to and from the terminal via wired or wireless (contactless, Bluetooth, or other optional means). As with the above, the terminal includes a means (step) for only following instructions from the processing unit when the signature sent from the processing unit at the center is attached. Upon receiving an instruction accompanied by the signature, the processing units of the terminal and the dedicated terminal include a means (step) for searching for the relevant relationship data from the storage unit. The processing unit of the dedicated terminal comprises a means (step) for sending relationship data to the processing unit of the terminal via the transmitting / receiving unit. The processing unit of the terminal comprises a means (step) for sending the relationship data to the processing unit of the center via the transmitting / receiving unit, and the processing unit of the center comprises a means (step) for transferring the data to a "field" for matching, a means (step) for matching the relationship data stored in the memory unit of the center at the "field" (matching unit) with the relationship data sent from the memory unit of the terminal or the memory unit of the dedicated terminal, and a means for approving the establishment of a relationship between the applicant and the other party when it is determined that the specified requirements are met.
[0030] In Example 3, a system symbolized by a network known as decentralized management, blockchain, or Web3 is used, and in examples where the location of specific data is not fixed even if it can be viewed by an unspecified number of people, specific data cannot be searched for; however, by providing a means (step) for storing relationship data on the network and a means (step) for searching for said relationship data, it is possible to make the relationship authentication system function. It is desirable to provide a means (step) for assigning relationship data assigned to the user's relationship (at least the relationship data at the time of initial setup) to the content of the final relationship (the content and result of the user's transaction), a means (step) for searching for said relationship data on the network, and a means (step) for confirming the content of the relationship attached to said relationship data. In one example, a relationship is established between users X and Y without the involvement of a center. In this example, either X or Y has a means (step) for creating relationship data, or the application has a means (step) for automatically creating relationship data, and both parties have a means (step) for storing and saving the relationship data in the memory of their terminal system. Upon a relationship request, the relationship data is automatically exchanged between the parties. The terminal's processing unit has a means (step) for verifying the data, and a means (step) for establishing the relationship when the relationship data meets the specified requirements. In this example, the network preferably has a means (step) for storing and saving the relationship data and relationship details between X and Y through "distributed management," a means (step) for searching for the relationship data as needed, a means (step) for verifying the relationship details attached to the relationship data, and a means (step) for restoring the asset status confirmed based on the details. According to a relationship authentication system, a center (including an application operator, server, etc.)) has a means (step) for instructing the processing unit of the user's device (such as a personal computer or smartphone) to search the memory unit and send relationship data to the center, and upon receiving the instruction, the processing unit of the device has a means (step) for following the instruction without any operation from the user.For example, there is a system that has a means (step) for applying for relationships to all users who meet the qualifications and conditions at once, and a means (step) for applying for relationships to other users at once if the user also meets the qualifications and conditions.
[0031] In a broad sense, authentication devices and systems include a means (step) for creating an identifier (an identifiable notation, any of which may include a code, design, sound, etc.) to be assigned to elements that establish a relationship in society (a relationship established by a human action or event) that is constructed by the human actions and events generated by elements (elements that make up society), such as government agencies, companies, and individuals; a means (step) for assigning the identifier to the elements (by any form or method); a means (step) for storing the identifier (any available identifier in a storage unit including a cloud, etc.); a means (step) for verifying the stored identifier when a new relationship is established between the elements (including the first and next time); a means (step) for determining whether the identifier satisfies specified requirements through the verification; and a means (step) for approving the establishment of the new relationship when it is determined that the requirements are satisfied).
[0032] In a broad sense, the authentication device and system comprises step 1 of creating an identifier to be assigned to the element that establishes a relationship when the element establishes a relationship in society, step 2 of assigning the identifier to the element, step 3 of storing the identifier in a memory unit, step 4 of comparing the stored identifier when a new relationship is established between the elements, step 5 of determining whether the identifier satisfies the requirements through the comparison, and step 6 of approving the establishment of the new relationship when it is determined that the requirements are satisfied.
[0033] In the authentication system, the present invention is primarily implemented over the Internet. For example, element a accesses a center (step 1). The center creates an ID for element a (step 2). The center's ID and element a's ID are further recorded with the time of day at any time during which the relationship was established (step 3). The data created using the record and the ID is used as matching data (relationship data) between element a and the center (step 4). This relationship data is stored in the memory of the center and the terminal of element a (step 5). When element a next applies for a relationship with the center (step 6, accesses the center), the center retrieves the relationship data from its memory (step 7). The relationship data is then retrieved from the memory of element a's terminal (step 8). A means is provided to issue an instruction to the processing unit of element a's terminal to send the data to the processing unit of the center (or the matching unit of the authentication unit) (step 9). The matching unit of the center or the matching unit of the authentication unit is provided with a means for matching the relationship data (step 10). If this matching determines that the relationship data match (or satisfy the specified requirements) (step 11), the center approves the continuation of the application procedure for element a's new application (step 12). In one embodiment, when element a wishes to establish a relationship with element b via the center and applies to the center, the center retrieves the previous relationship data between element a and element b from the memory unit of element a's terminal (step 13), retrieves the previous relationship data between element a and element b from the memory unit of element b's terminal (step 14), and instructs the processing units of element a and element b's terminals to send the data to the processing unit or matching unit of the center (or the processing unit or matching unit of the authentication unit) (step 15). The matching unit of the center or the matching unit of the authentication unit compares and determines the relationship data (step 16). This matching determines whether the relationship data match (or satisfy the specified requirements) (step 16).If it is determined that they match (or that the predetermined requirements are met), the processing unit of the center approves the continuation of the procedure for establishing a new relation between element a and element b (step 16).
[0034] In an authentication system, when an element establishes a relationship with another element, a list is provided to the element that describes the other elements and allows the element to be specified (Step 1). In some cases, the list is stored in the memory of the device used by the element, but a more preferable method is to disclose the list on the output display of the device using a fingerprint or a personal identification number (Step 2, preferably with a means for concealment). In other cases, the list is stored in the memory of a center, and similarly disclosed using the element's fingerprint or personal identification number (Step 2). When the disclosure method is not executed, a means for concealing the list is provided (Step 3). Concealing the list prevents a third party from fraudulently establishing a relationship (Step 4). Even if an element attempts to fraudulently establish a relationship with a party with no relationship history, a warning is issued to the element (Step 5), and a means for confirmation is provided (Step 6), preventing attempts to establish a relationship unrelated to the element (Step 7). In some cases, the list is stored in the memory of a dedicated terminal used in conjunction with the terminals used by elements a and b, separate from the terminals used by elements a and b. In this example as well, it is preferable to have the element disclosed by a fingerprint or a personal identification number, etc., and to keep it secret.
[0035] When element a establishes a relationship in society in a broad sense, including politics, economics, culture, entertainment, lifestyle, education, business, research, etc., with element b (including cases where elements a and b are multiple or numerous), an identifier (e.g., ID) is created to be assigned to the elements a and b establishing the relationship (Step 1). When there is no past relationship history (relationship history) and this is the first time, there may or may not be a list of counterparties. For elements (users) managed by the center, a list operated by the center is created. In cases where there is no list, element b receiving the relationship request is often a government agency, local government, company, store, etc., and is planning to apply to an unspecified element a, so the center approves the establishment of the relationship (Step 2). The center implementing the present invention follows the decision of element b (Step 3). After the center approves the procedures and transmission / reception for establishing the relationship, element b and element a confirm the conditions and content of the relationship (Step 4). When they agree and understand, the relationship between element a and element b is legitimately established (Step 5). In the case where either element a or b receives a relationship request, the procedure for establishing the relationship is approved only for relationships with partners and content approved by the user (step 6), and the relationship is established when element a and element b confirm and agree (step 7).
[0036] The relationships between the elements and other elements are stored as relationship history in the storage unit of the center (step 11), and the relationship history is provided to the terminal used by the element (step 12).
[0037] The system includes a means for storing relationships between elements and other elements as relationship history in a storage unit of the center, and a means for providing the relationship history to a terminal used by the element. Element A establishes a relationship with the center, element B establishes a relationship with the center, and element B establishes a relationship with element A. When the center receives a request to establish a relationship from either element A or element B, or from both, the system includes a means for comparing identifiers between the center and element A and between the center and element B, a means for confirming the validity of the identifiers, a means for extracting IDs of element A and element B from the identifiers between the center and element A and between the center and element B upon confirming validity, a means for adding time (examples include numbers or symbols other than time) related to the relationship, and a means for creating an identifier to be assigned to the relationship between element A and element B. While it is reasonable for the center to be responsible for managing the relationship history and creating and managing identifiers, how functions and means are shared between the center, terminals, etc. is determined based on factors such as cost, risk, and security standards. The system includes a means (step) for arbitrarily updating the identifiers assigned between elements and the center, and a means (step) for reflecting changes in attributes such as the presence or absence of elements, their names, addresses, and credit status. In one embodiment, the system includes a means (step) for the center to store and save the attribute data of elements, and a means (step) for managing the data. The system also includes a means (step) for using (providing, etc.) the attribute data of elements according to the classification and characteristics of the relationship, and according to the attributes and authority of the elements. In this example, the system includes a means (step) for classifying and managing the attribute data of elements to suit conditions set by the authority of the elements, agreements between elements, etc.
[0038] It can be used as an authentication system in areas where existing technology is not possible, such as verifying business partners and security for a wide variety of IoT devices. It is particularly effective in preventing spoofing.
[0039] 1 Element a 2 Element b 3 Center 4 Storage unit 5 Collation unit 6 Element c 7 Start 8 Access to center 9 Creation of relation data 10 Data storage 11 Access to center 12 Data collation
Claims
1. A relation authentication apparatus, comprising means for creating an identifier for distinguishing a relation generated between element A and element B from other relations, and means for storing the identifier in a storage unit.
2. The relation authentication apparatus according to claim 1, further comprising means for collating the identifier stored in the storage unit, means for determining whether the identifier meets the requirements defined thereby, and means for approving the continuation of the procedure for establishing a relation between the elements when it is determined that the requirements are met.
3. A relation authentication system, comprising step 1 of creating an identifier for distinguishing a relation generated between element A and element B from other relations, and step 2 of storing the identifier in a storage unit.
4. The relation authentication system according to claim 3, further comprising step 3 of collating the identifier stored in the storage unit, step 4 of determining whether the identifier meets the requirements defined thereby, and step 5 of approving the continuation of the procedure for establishing a relation between the elements when it is determined that the requirements are met.
Citation Information
Patent Citations
Equipment authentication system, server, method and program, terminal and storage medium
JP2005102163A
Information processing method and information processing system
JP2015219670A
Information communication device, authentication program for information communication device, and authentication method
JP2020057923A