To-be-authenticated device, authentication device, method for outputting authentication request, authentication method, and program
The authentication device uses encrypted authentication requests with unique and shared data to securely authenticate devices, preventing impersonation and ensuring legitimacy through consistent matching of encrypted data, thereby enhancing security in authentication systems.
Patent Information
- Application Number
- PCT/JP2024/044707
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-16
- Filing Date
- 2024-12-18
- Publication Date
- 2025-07-24
AI Technical Summary
Existing authentication systems face challenges in preventing impersonation and ensuring secure authentication of devices, particularly in scenarios where multiple authentication requests are transmitted from both legitimate and illegitimate sources.
An authentication device that generates and processes encrypted authentication requests using unique information and shared data, including a first encryption unit to encrypt initial data and a second encryption unit to encrypt shared data, allowing for secure authentication by matching shared data and unique information across multiple requests.
This approach effectively prevents impersonation by ensuring that only legitimate devices can authenticate, enhancing security and reliability in authentication processes.
Smart Images

Figure JP2024044707_24072025_PF_FP_ABST
Abstract
Description
Device to be authenticated, authentication device, authentication request output method, authentication method, and program
[0001] The present invention relates to an authenticatee device, an authenticating device, an authentication request output method, an authentication method, and a program.
[0002] 2. Description of the Related Art Conventionally, there is known an authentication device that receives a plurality of authentication requests transmitted from a device to be authenticated and determines whether the device to be authenticated is legitimate using the plurality of authentication requests (see, for example, Patent Document 1).
[0003] International Publication No. 2020 / 080301
[0004] When an authenticating device authenticates a device to be authenticated using a plurality of authentication requests transmitted from the device to be authenticated, there is a demand for secure authentication by preventing spoofing.
[0005] The present invention has been made in response to the above circumstances, and aims to provide an authenticated device, an authenticating device, an authentication request output method, an authentication method, and a program that can achieve secure authentication by preventing impersonation.
[0006] In order to achieve the above object, an authenticated device according to one aspect of the present invention comprises an initial data acquisition unit that acquires initial data including a user identifier that identifies a user and unique information that is unique information; a first encryption unit that generates first data by acquiring first encrypted data that is the encrypted initial data; a second data acquisition unit that acquires second data that includes shared data shared with the authentication device; a second encryption unit that generates second encrypted data by encrypting the second data using the first data; and an output unit that outputs a plurality of different authentication requests to the authentication device, each including the initial data and the second encrypted data.
[0007] With this configuration, an authentication device that receives multiple authentication requests can determine whether the authenticated device is legitimate based on whether the shared data corresponding to the second encrypted data included in the authentication requests matches the shared data shared between the legitimate authenticated device and the authentication device, and whether the unique information included in the multiple authentication requests is consistent, thereby preventing spoofing and achieving secure authentication. Also, by encrypting initial data to obtain first encrypted data, it is possible to make it difficult to predict the first data from the initial data.
[0008] In the authenticated device according to one aspect of the present invention, the unique information may include at least one of a time, a counter value, and a random number value.
[0009] With this configuration, the unique information can be easily obtained.
[0010] In addition, in an authenticated device according to one aspect of the present invention, the first encryption unit may obtain first encrypted data by encrypting initial data using an encryption key corresponding to a user identifier included in the initial data.
[0011] With this configuration, it is possible to make it more difficult to predict the first data from the initial data.
[0012] In the authenticated device according to one aspect of the present invention, the first encryption unit may obtain first encrypted data by encrypting a predetermined amount of data including the initial data using an encryption key.
[0013] With this configuration, the first encrypted data can be reduced to a predetermined data amount.
[0014] In the authenticated device according to one aspect of the present invention, the first encryption unit may generate the first data by reducing the amount of data in the first encrypted data.
[0015] With this configuration, for example, the amount of data required for authentication can be reduced.
[0016] In the authenticated device according to one aspect of the present invention, the first encryption unit may reduce the amount of data by hashing the first encrypted data.
[0017] With this configuration, the amount of data can be reduced by simple processing, and it is also possible to make it difficult to predict the first encrypted data from the first data.
[0018] In the authenticated device according to one aspect of the present invention, the first encryption unit may reduce the amount of data by extracting part of the first encrypted data.
[0019] With this configuration, the amount of data can be reduced by simple processing, and it is also possible to make it difficult to predict the first encrypted data from the first data.
[0020] In addition, in an authenticated device according to one aspect of the present invention, the data amount of the first data and the data amount of the second data may be the same, and the second encryption unit may generate second encrypted data which is the exclusive OR of the first data and the second data.
[0021] With this configuration, the second data can be encrypted through a simple process.
[0022] In the authenticated device according to one aspect of the present invention, the second data acquisition unit may acquire the shared data from the authentication device.
[0023] With this configuration, shared data can be shared between the authenticator and the device to be authenticated even if the device to be authenticated does not have a generator of the shared data.
[0024] In the authenticated device according to one aspect of the present invention, the shared data may include a random number.
[0025] With this configuration, for example, shared data can be made unique.
[0026] and an authentication device according to one aspect of the present invention includes: a reception unit that receives from a device to be authenticated a plurality of different authentication requests, each of which includes initial data including a user identifier that identifies a user and unique information that is unique information, and second encrypted data, in which second data including shared data is encrypted using first data generated by obtaining first encrypted data, in which the initial data is encrypted; an encryption unit that generates first data by obtaining the first encrypted data, in which the initial data included in the authentication request received by the reception unit is encrypted; a memory unit that stores shared data shared with a legitimate device to be authenticated; a determination unit that determines, using the first data generated by the encryption unit, whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit matches the shared data stored in the memory; an authentication unit that determines that the device to be authenticated is legitimate when it is determined that the unique information included in the plurality of authentication requests received from the device to be authenticated is consistent and that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the memory for each of the plurality of authentication requests; and an authentication result output unit that outputs an authentication result, which is the determination result by the authentication unit.
[0027] With this configuration, by determining whether the device to be authenticated is legitimate based on whether the shared data corresponding to the second encrypted data included in the authentication request matches the shared data shared between the legitimate device to be authenticated and the authenticator, and based on whether the unique information included in the multiple authentication requests is consistent, it is possible to prevent spoofing and achieve secure authentication. Furthermore, by obtaining the first encrypted data by encrypting the initial data, it is possible to make it difficult for a third party to predict the first data.
[0028] In the authentication device according to an aspect of the present invention, the unique information may include at least one of a time, a counter value, and a random number value.
[0029] With this configuration, the unique information can be easily obtained.
[0030] In addition, in an authentication device according to one aspect of the present invention, the encryption unit may obtain first encrypted data by encrypting initial data included in the authentication request accepted by the acceptance unit using an encryption key corresponding to a user identifier included in the initial data.
[0031] Such a configuration can make it more difficult for a third party to predict the first data.
[0032] In addition, in an authentication device according to one aspect of the present invention, the encryption unit may obtain first encrypted data by encrypting a predetermined amount of data, including initial data, included in the authentication request accepted by the acceptance unit, using an encryption key.
[0033] With this configuration, the first encrypted data can be reduced to a predetermined data amount.
[0034] In the authentication device according to an aspect of the present invention, the encryption unit may generate the first data by reducing the amount of data of the acquired first encrypted data.
[0035] With this configuration, for example, the amount of data required for authentication can be reduced.
[0036] In addition, in an authentication device according to one aspect of the present invention, the data amount of the first data and the data amount of the second data may be the same, and the second encrypted data may be an exclusive OR of the first data and the second data.
[0037] With this configuration, the second data can be encrypted through a simple process.
[0038] In addition, an authentication device according to one aspect of the present invention further includes a data output unit that generates shared data, outputs it to the device to be authenticated, and stores it in a memory unit, and the second encrypted data included in the authentication request accepted by the acceptance unit may be encrypted second data including the shared data output by the data output unit.
[0039] With this configuration, the second data can be shared between the authenticator and the device to be authenticated even if the device to be authenticated does not have a generator of the shared data.
[0040] In the authentication device according to one aspect of the present invention, the shared data may include a random number.
[0041] With this configuration, for example, shared data can be made unique.
[0042] Furthermore, an authentication request output method according to one aspect of the present invention includes the steps of: acquiring initial data including a user identifier that identifies a user and unique information that is unique information; generating first data by acquiring first encrypted data that is the initial data encrypted; acquiring second data including shared data shared with the authentication device; generating second encrypted data by encrypting the second data using the first data; and outputting a plurality of different authentication requests, each including the initial data and the second encrypted data, to the authentication device.
[0043] Furthermore, an authentication method according to one aspect of the present invention includes the steps of: receiving from an authenticated device a plurality of different authentication requests, each of which includes initial data including a user identifier for identifying a user and unique information that is unique information, and second encrypted data, in which second data including shared data is encrypted using first data generated by obtaining first encrypted data, in which the initial data is encrypted; generating first data by obtaining the first encrypted data, in which the initial data included in the received authentication request is encrypted; a determination unit that determines, using the first data generated in the first data generating step, whether the shared data corresponding to the second encrypted data included in the received authentication request matches the shared data stored in a memory unit in which the shared data shared with the legitimate authenticated device is stored; determining that the authenticated device to be authenticated is legitimate when it is determined that the unique information included in the plurality of authentication requests received from the authenticated device to be authenticated is consistent and that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the memory unit for each of the plurality of authentication requests; and outputting an authentication result, which is the determination result in the step of determining whether the authenticated device to be authenticated is legitimate.
[0044] According to an aspect of the present invention, the authenticatee device, authenticator, authentication request output method, authentication method, and program can prevent spoofing and realize secure authentication.
[0045] FIG. 1 is a block diagram showing the configuration of an authentication system according to an embodiment of the present invention; FIG. 2 is a diagram showing transmission and reception of information between an authenticatee device and an authenticator device in the embodiment; FIG. 3 is a diagram for explaining generation of an authentication request in the embodiment; FIG. 4 is a diagram for explaining authentication using an authentication request in the embodiment;
[0046] The authenticatee device, authenticator device, authentication request output method, and authentication method according to the present invention will be described below using embodiments. In the following embodiments, components and steps denoted with the same reference numerals are the same or equivalent, and repeated description may be omitted. The authenticatee device according to the present embodiment outputs a plurality of different authentication requests, each including initial data, which is plaintext data including unique information, and second encrypted data obtained by encrypting second data using first data obtained using the initial data. The authenticator according to the present embodiment authenticates the authenticatee device based on a determination result of whether shared data corresponding to the second encrypted data included in the authentication request matches shared data stored in the authenticator, and on whether the unique information included in the plurality of authentication requests is consistent.
[0047] FIG. 1 is a block diagram showing the configuration of an authentication system 100 according to this embodiment, FIG. 2 is a diagram showing information transmitted and received between the device to be authenticated 1 and the authenticating device 2, FIG. 3 is a diagram for explaining an example of processing related to the generation of an authentication request in the device to be authenticated 1, and FIG. 4 is a diagram for explaining an example of processing related to authentication using multiple authentication requests in the authenticating device 2.
[0048] As shown in Fig. 1, an authentication system 100 according to this embodiment includes a device to be authenticated 1 and an authenticator 2. While Fig. 1 illustrates a case in which the authentication system 100 includes one device to be authenticated 1 and one authenticator 2, this is not necessarily the case. The authentication system 100 may include multiple devices to be authenticated 1 and one authenticator 2. In this case, multiple authentication requests may be output from each of the multiple devices to be authenticated 1 to the authenticator 2. Furthermore, this embodiment will mainly describe a case in which information exchange between the device to be authenticated 1 and the authenticator 2 is performed by communication, i.e., by sending and receiving information; other cases will be described later. This communication is usually wireless communication.
[0049] The communication standard of the wireless communication performed between the device to be authenticated 1 and the authenticating device 2 does not matter. The wireless communication may be performed, for example, using low-power Bluetooth (registered trademark), Bluetooth (registered trademark) BR (Basic Rate) / EDR (Enhanced Data Rate), wireless LAN (IEEE 802.11), IEEE 802.15.4 such as ZigBee (registered trademark), or other wireless communication standards. The wireless communication may be, for example, short-range wireless communication. As an example, as shown in FIG. 2, the authentication process of the device to be authenticated 1 may be performed after establishing a connection, such as wireless communication, between the device to be authenticated 1 and the authenticating device 2 (1). Note that the process of establishing communication between the two devices before starting the authentication process is not necessarily required, and the authentication process may be performed without establishing communication.
[0050] In this embodiment, an authentication request is output from the authenticated device 1 to the authenticating device 2, and the authenticated device 1 that outputs the authentication request can be a legitimate authenticated device 1 or an illegitimate device, i.e., a device of a malicious third party or attacker. Since the authenticating device 1 cannot distinguish between the two at the time of receiving the authentication request, for convenience of explanation, the device that outputs the authentication request will be called the authenticated device 1. Then, the authenticated device 1 that is judged to be legitimate will be called the legitimate authenticated device 1, and the authenticated device 1 that is judged to be invalid, i.e., the attacker's device, will be called the invalid authenticated device 1.
[0051] 1, the device to be authenticated 1 according to this embodiment includes a storage unit 11, an initial data acquisition unit 12, a first encryption unit 13, a second data acquisition unit 14, a second encryption unit 15, and an output unit 16. The device to be authenticated 1 may be, for example, a smartphone, a tablet terminal, a personal digital assistant (PDA), a notebook computer, a portable information terminal with a communication function such as a transceiver, or other devices. In this embodiment, the case where the device to be authenticated 1 is a smartphone will be mainly described.
[0052] The storage unit 11 may store, for example, a user identifier that identifies the user of the device to be authenticated 1. The user identifier is not particularly limited as long as it can identify the user, and may be, for example, the user's telephone number or email address, or a character string assigned to the user. Furthermore, a device identifier that identifies the device to be authenticated 1 may be used as the user identifier. The device identifier may be, for example, the address of the device to be authenticated 1. Furthermore, the storage unit 11 may store, for example, an encryption key corresponding to the user identifier stored in the storage unit 11. Furthermore, the storage unit 11 may store, for example, shared data. The encryption key and shared data will be described later.
[0053] The process by which information is stored in the storage unit 11 is not important. For example, information may be stored in the storage unit 11 via a recording medium, a communication line, or an input device, or information may be accumulated in the storage unit 11 by other components. The storage unit 11 is preferably realized by a non-volatile recording medium, but may also be realized by a volatile recording medium. The recording medium may be, for example, a semiconductor memory, a magnetic disk, an optical disk, or the like.
[0054] The initial data acquisition unit 12 acquires initial data including a user identifier for identifying a user and unique information that is unique information. The initial data acquisition unit 12 may, for example, read the user identifier from the storage unit 11. The initial data acquisition unit 12 may, for example, generate the unique information, or may receive the unique information from another component or device.
[0055] Each piece of unique information acquired by the initial data acquisition unit 12 may be different, for example. For example, different initial data may be acquired each time the initial data acquisition unit 12 acquires initial data. In this case, the unique information may be information specific to the authentication request. That is, the unique information included in each authentication request may be different. Note that "each piece of unique information is different" may mean that the unique information does not overlap within a period required for authentication. That is, the unique information may not overlap within a predetermined period. That period may be, for example, approximately 100 years. Therefore, the unique information may overlap after that period. For example, if the unique information does not overlap for 100 years, the unique information acquired at a certain time may overlap with the unique information acquired 101 years after that time. Furthermore, for example, when the authentication system 100 performs authentication for an event held on a specific day, the period during which the unique information does not overlap may be approximately one or two days.
[0056] The unique information may include, for example, at least one of a time, a counter value, and a random number value. Also, information that is typically composed of unique information such as a time, a counter value, or a random number value, and non-unique information (for example, information in which the higher-order bits are unique information and the lower-order bits are non-unique information) will ultimately become unique information. Therefore, the unique information may be composed of unique information and non-unique information in this way.
[0057] The time may be, for example, the time when the unique information is acquired. Because the period between the acquisition of the unique information and the transmission of the authentication request is short, this time can be considered to be essentially the time when the authentication request is transmitted. It is preferable that the accuracy of the time be shorter than the transmission interval between multiple authentication requests. For example, the time may be measured in milliseconds. The time may be, for example, a time indicating the elapsed time from a predetermined point in time. For example, the time may be UNIX time. In this case, the time may be considered to include the hour, minute, and year, month, and day. The initial data acquisition unit 12 may acquire the current time using, for example, a clock unit (not shown). Of the acquired time, for example, the lower digits that form the desired cycle may be used as unique information. Furthermore, the time may include, for example, the year, month, day, hour, minute, and second.
[0058] The counter value may be, for example, a value obtained by incrementing or decrementing a numerical value at predetermined intervals. The random number value may be generated using, for example, a random number table or a function that generates random numbers. As an example, the counter value or random number value may vary depending on the time of year. For example, the counter value or random number value generated on one day may be different from the counter value or random number value generated the next day. In this way, it is possible to prevent a malicious third party from reusing unique information, including a counter value or random number value, included in an authentication request sent from a legitimate device to be authenticated 1, thereby preventing impersonation by a malicious third party.
[0059] The initial data may also include information other than the user identifier and the unique information. The information other than the user identifier and the unique information included in the initial data may be, for example, information that the authenticated device 1 wishes to transmit to the authenticating device 2.
[0060] The first encryption unit 13 generates first data using the initial data acquired by the initial data acquisition unit 12. The first encryption unit 13 may generate the first data by, for example, acquiring first encrypted data obtained by encrypting the initial data using an encryption key corresponding to the user identifier included in the initial data. Alternatively, the first encryption unit 13 may generate the first data by, for example, acquiring first encrypted data obtained by encrypting a predetermined amount of data including the initial data using an encryption key corresponding to the user identifier included in the initial data. The predetermined amount of data including the initial data may be data obtained by padding the initial data to a predetermined amount. The padding method may be, for example, predetermined. In this case, the first encryption unit 13 may include, for example, an encryption unit 13-1 shown in FIG. 3 that encrypts padded initial data including the initial data (including the user identifier ID and unique information U) and the padded information P using an encryption key K corresponding to the user identifier ID included in the initial data, and outputs the first encrypted data ER1. The encryption by the encryption unit 13-1 may be performed by, for example, the Advanced Encryption Standard (AES), or by another algorithm. The encryption key K may be, for example, an encryption key unique to a user identified by a user identifier included in the initial data, i.e., an encryption key that can only be known by that user and not by other users. The encryption key may be stored in the storage unit 11, for example.
[0061] The encryption key used by the first encryption unit 13 may be, for example, a key for common key encryption, or a public key or private key for public key encryption. Whichever encryption key is used, it is preferable that the encryption key used by the first encryption unit 13 of the device to be authenticated and the encryption key used by the encryption unit 22 (described later) of the authentication device 2 are the same. As an example, if the encryption key used by the first encryption unit 13 of the device to be authenticated 1 is a public key for public key encryption, it is preferable that the same public key be used in the encryption unit 22 of the authentication device 2. Note that, whichever encryption key is used, it is preferable that the encryption key be different for each device to be authenticated 1, i.e., for each user.
[0062] Furthermore, the first encryption unit 13 may use the first encrypted data itself as the first data, or may generate the first data by reducing the amount of data from the first encrypted data. In the latter case, for example, the first encryption unit 13 may reduce the amount of data by hashing the first encrypted data, or may reduce the amount of data by extracting a portion of the first encrypted data. Extracting a portion of the first encrypted data may be, for example, extracting the most significant or least significant bits of a predetermined number of bits in the first encrypted data, or extracting the value of a predetermined bit (digit) in the bit string of the first encrypted data. In this embodiment, the case where the first data is generated by hashing the first encrypted data will be mainly described. In this case, the first encryption unit 13 may include, for example, a hash generation unit 13-2 that hashes the first encrypted data ER1 and outputs the first data R1, as shown in FIG. 3 .
[0063] The second data acquisition unit 14 acquires second data including shared data shared with the authentication device 2. The second data acquisition unit 14 may, for example, acquire the shared data from the authentication device 2 or generate the shared data. In this embodiment, the former case will be mainly described. When information is exchanged between the authenticated device 1 and the authentication device 2 via communication, as shown in FIG. 2 , (2) the authentication device 2 may transmit the shared data to the authenticated device 1, and the second data acquisition unit 14 may receive the transmitted shared data from the authentication device 2. When the second data acquisition unit 14 generates the shared data, it is preferable to generate the shared data using the same algorithm as the authentication device 2. This is to enable the shared data to be shared between the authenticated device 1 and the authentication device 2. Note that the second data may be, for example, the shared data or may include data other than the shared data. In the latter case, for example, the second data may include information that the authenticated device 1 wants to communicate to the authentication device 2 but that should not be made known to third parties. In this embodiment, the case where the second data is shared data will mainly be described.
[0064] The shared data may include, for example, a random number. In this case, the shared data may be, for example, random number data, or may include data other than random number data. Furthermore, data other than random numbers may be used as the shared data. In this embodiment, the case where the shared data is a random number will be mainly described. Furthermore, it is preferable that the shared data be different for each device to be authenticated 1, but this is not necessary. In the former case, the shared data is, for example, information specific to a single authentication process performed using multiple authentication requests for a certain device to be authenticated 1. Different shared data may be used in different authentication processes, or the same shared data may be used in multiple authentication processes. Furthermore, when different shared data is used in different authentication processes, for example, the shared data may be different for each authentication request used in a single authentication process, or the same shared data may be used for multiple authentication requests used in a single authentication request. In this embodiment, the case where the shared data is different for each device to be authenticated 1 and different for each authentication process, but the same shared data is used in a single authentication process will be mainly described. The second data acquisition unit 14 may, for example, store the acquired shared data or second data in the storage unit 11 .
[0065] The second encryption unit 15 obtains second encrypted data by encrypting the second data obtained by the second data obtaining unit 14 using the first data generated by the first encryption unit 13. The second encryption unit 15 may, for example, encrypt the second data using the first data as an encryption key. Alternatively, the second encryption unit 15 may obtain second encrypted data ER, which is the exclusive OR of the first data R1 and the second data R2, as shown in FIG. 3 . This case will be mainly described in this embodiment. When the second encryption unit 15 calculates the exclusive OR of the first data and the second data, it is preferable that the data amounts of the first data and the second data are the same. The data amounts being the same may, for example, mean that the number of bits is the same.
[0066] The output unit 16 outputs a plurality of different authentication requests to the authentication device 2. The authentication requests are information including the initial data acquired by the initial data acquisition unit 12 and the second encrypted data acquired by the second encryption unit 15. The authentication requests may include only the initial data and the second encrypted data, or may include other information as well.
[0067] The multiple authentication requests may each include multiple different pieces of initial data. In this way, the multiple authentication requests each contain different information. Note that the second encrypted data included in a certain authentication request is second data encrypted using first data generated using the initial data included in that authentication request. Furthermore, the second data used to obtain the second encrypted data included in the multiple authentication requests used in one authentication process may all be the same, for example. However, since the first data is different each time the second encrypted data is obtained, the multiple pieces of second encrypted data included in the multiple authentication requests used in one authentication process will each be different. The multiple authentication requests used in one authentication process refer to the multiple authentication requests used in the process of determining whether the authenticated device 1 is legitimate.
[0068] The authentication request may be, for example, encrypted in its entirety before being output. As an example, this encryption may be performed using an encryption key that is common to multiple devices to be authenticated 1 that transmit the authentication request to the authentication device 2. In this embodiment, the case where this encryption is not performed will be mainly described.
[0069] Here, this output may be, for example, transmitted to a predetermined device via a communication line, displayed on a display device (e.g., a liquid crystal display or an organic EL display), printed by a printer, output as sound through a speaker, or handed over to another component. When information is exchanged between the device to be authenticated 1 and the authentication device 2 via communication, the output unit 16 may transmit multiple authentication requests to the authentication device 2. In this case, as shown in FIG. 2 , (3) the transmission of authentication requests from the device to be authenticated 1 to the authentication device 2 may be repeated multiple times. Note that the output unit 16 may or may not include a device that performs output (e.g., a communication device, a display device, etc.). Furthermore, the output unit 16 may be realized by hardware, or may be realized by software such as a driver that drives those devices.
[0070] Furthermore, when the authentication result is output from the authenticating device 2 to the authenticated device 1, the authenticated device 1 may include a reception unit that receives the authentication result output from the authenticating device 2. When the information exchange between the authenticated device 1 and the authenticating device 2 is by communication, the reception unit may receive the authentication result from the authenticating device 2. In this case, as shown in Fig. 2, (4) the authentication result may be transmitted from the authenticating device 2 to the authenticated device 1, and the transmitted authentication result may be received by the authenticated device 1. For example, the received authentication result may be output to the user of the authenticated device 1. The output may be, for example, a display or sound output.
[0071] 1 , the authentication device 2 according to this embodiment includes a reception unit 21, an encryption unit 22, a storage unit 23, a determination unit 24, an authentication unit 25, an authentication result output unit 26, and a data output unit 27. The authentication device 2 may be, for example, a device that authenticates the device to be authenticated 1 in an automatic ticket barrier, a gate for entering a venue such as an event, a vending machine, a control device that locks and unlocks doors of a hotel or a rental conference room, a cash register, or the like, or may be an information terminal with a communication function such as a computer or smartphone that authenticates the device to be authenticated 1. In this embodiment, the case where the device to be authenticated 1 is an information terminal with a communication function will be mainly described.
[0072] The reception unit 21 receives a plurality of different authentication requests from the authenticated device 1. When information is exchanged between the authenticated device 1 and the authenticating device 2 via communication, the reception unit 21 may receive a plurality of authentication requests from the authenticated device 1. As described above, the received authentication request includes initial data including a user identifier for identifying a user and unique information that is unique information, and second encrypted data generated using the initial data. As described above, the second encrypted data is data obtained by encrypting second data including shared data using the first data. Furthermore, the first data is data generated by obtaining first encrypted data obtained by encrypting the initial data included in the authentication request using an encryption key corresponding to the user identifier included in the initial data. When the reception time of the authentication request is also used to authenticate the authenticated device 1, the reception unit 21 may, for example, obtain the reception time when receiving the authentication request and pass it to the authenticating unit 25.
[0073] In addition, in the case where the authentication request is encrypted before being output in the authenticated device 1, the encrypted authentication request may be decrypted after the authentication request is accepted. In this embodiment, the case where the encryption and decryption are not performed as described above will be mainly described.
[0074] The reception unit 21 may receive information transmitted via a wireless communication line, or may read displayed information as described below, or may receive information by other methods. The reception unit 21 may or may not include a device for receiving the information (e.g., a communication device or an imaging device). The reception unit 21 may be realized by hardware, or may be realized by software such as a driver that drives a specific device.
[0075] The encryption unit 22 generates first data using initial data included in the authentication request accepted by the acceptance unit 21. It is preferable that the generation of this first data be performed in the same manner as the generation of first data by the first encryption unit 13 of the device to be authenticated 1. This is to generate first data that is the same as the first data generated in the device to be authenticated 1. The encryption unit 22 may generate the first data by, for example, obtaining first encrypted data obtained by encrypting the initial data included in the authentication request accepted by the acceptance unit 21 using an encryption key corresponding to the user identifier included in the initial data. Alternatively, the encryption unit 22 may generate the first data by, for example, obtaining first encrypted data obtained by encrypting a predetermined amount of data including the initial data included in the authentication request accepted by the acceptance unit 21 using an encryption key corresponding to the user identifier included in the initial data. 4, the encryption unit 22 may include a generation unit 22-1 that generates a predetermined amount of padded initial data by padding the initial data, and an encryption unit 22-2 that encrypts the padded initial data using an encryption key K that corresponds to a user identifier ID included in the initial data, and outputs first encrypted data ER1. For example, information that associates the user identifier with an encryption key may be stored in the storage unit 23, and the encryption unit 22 may use the information to obtain the encryption key K that corresponds to the user identifier ID included in the initial data.
[0076] Furthermore, the encryption unit 22 may use the first encrypted data itself as the first data, or may generate the first data by reducing the amount of data from the first encrypted data. The encryption unit 22 may reduce the amount of data by hashing the first encrypted data, or by extracting a portion of the first encrypted data. This embodiment will mainly describe the former case. In this case, the encryption unit 22 may include a hash generation unit 22-3 that hashes the first encrypted data ER1 and outputs the first data R1, as shown in FIG. 4 . As described above, the generation of the first data by the encryption unit 22 is performed in the same manner as the generation of the first data by the first encryption unit 13 of the device to be authenticated 1, and therefore a detailed description thereof will be omitted.
[0077] The storage unit 23 stores shared data shared with the legitimate device to be authenticated 1. Sharing of the shared data with the legitimate device to be authenticated 1 may be performed, for example, by outputting the shared data from the authentication device 2 to the device to be authenticated 1, or by generating the same shared data in the device to be authenticated 1 and the authentication device 2. In this embodiment, the former case will be mainly described. The storage unit 23 may store, for example, information that associates a user identifier with the shared data used in the device to be authenticated 1 of the user identified by that user identifier. In this way, it becomes possible to identify the shared data corresponding to the user identifier. It is preferable that the shared data be different for each user identifier. As described above, the storage unit 23 may also store an encryption key for each user.
[0078] The process by which information is stored in the storage unit 23 is not important. For example, information may be stored in the storage unit 11 via a recording medium, a communication line, or an input device, or information may be accumulated in the storage unit 11 by other components. The storage unit 23 may be realized by a non-volatile recording medium or a volatile recording medium. The recording medium may be, for example, a semiconductor memory, a magnetic disk, an optical disk, or the like.
[0079] The determination unit 24 determines, using the first data generated by the encryption unit 22, whether the shared data corresponding to the second encrypted data included in the authentication request accepted by the acceptance unit 21 matches the shared data stored in the storage unit 23. The shared data corresponding to the second encrypted data included in the authentication request refers to the shared data included in the second data used to generate the second encrypted data. For example, by decrypting the second encrypted data using the first data generated by the encryption unit 22, the second data corresponding to the second encrypted data can be identified, and the shared data included in the second data can be identified. Furthermore, the shared data stored in the storage unit 23 may be, for example, the shared data stored in the storage unit 23 in association with the user identifier included in the authentication request.
[0080] The determination unit 24 may, for example, decrypt the second encrypted data included in the accepted authentication request using the first data generated by the encryption unit 22 to obtain the second data, and compare the shared data included in the obtained second data with the shared data stored in the storage unit 23 in association with the user identifier included in the authentication request to determine whether the two match. As an example, if the authentication target device 1 encrypts the second data using the first data by calculating an exclusive OR between the first data and the second data, the decryption of the second encrypted data may be performed by calculating an exclusive OR between the second encrypted data and the first data. In this case, the determination unit 24 may, for example, as shown in FIG. 4, include an operation unit 24-1 that performs an exclusive OR between the second encrypted data ER2 included in the authentication request and the generated first data R1 and outputs the second data R2, and a comparison unit 24-2 that compares the shared data S1 stored in the storage unit 23 with the shared data S2 included in the second data R2 output from the operation unit 24-1. The comparison section 24-2 may output the result of the determination as to whether or not the two pieces of shared data S1 and S2 match.
[0081] Furthermore, when the second data is shared data, the determination unit 24 may, for example, use the first data generated by the encryption unit 22 to encrypt the second data, which is shared data stored in association with the user identifier included in the accepted authentication request, to obtain second encrypted data, and compare the obtained second encrypted data with the second encrypted data included in the accepted authentication request to determine whether the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit 23. In this case, when the two sets of second encrypted data match, it may be determined that the two sets of shared data match, and when the two sets of second encrypted data do not match, it may be determined that the two sets of shared data do not match.
[0082] The authentication unit 25 determines that the device to be authenticated 1 is legitimate when it is determined that the unique information included in the multiple authentication requests received from the device to be authenticated 1 is consistent and that, for each of the multiple authentication requests, the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the memory unit 23; otherwise, it determines that the device to be authenticated 1 is not legitimate. In the latter case, for example, the authentication unit 25 may determine that the device to be authenticated 1 is not legitimate when the unique information included in the multiple authentication requests received from the device to be authenticated 1 is not consistent, or may determine that the device to be authenticated 1 is not legitimate when it is determined that, for at least one of the multiple authentication requests, the shared data corresponding to the second encrypted data included in the authentication request does not match the shared data stored in the memory unit 23.
[0083] The authentication unit 25 may use a predetermined number of authentication requests to determine whether the authenticated device 1 is valid, or may use a predetermined number of authentication requests received within a predetermined period of time. The period may start, for example, from the time the first authentication request is received.
[0084] Here, we will explain how to determine whether the unique information included in the multiple authentication requests is consistent. Whether the multiple pieces of unique information are consistent may be determined, for example, by comparing the multiple pieces of unique information included in the multiple authentication requests with the multiple pieces of unique information generated or acquired by the authentication device 2, or by determining whether the multiple pieces of unique information conform to a predetermined rule.
[0085] When the unique information is a counter value or a random number value, the authentication unit 25 may, for example, acquire the counter value or random number value using a function for acquiring the counter value or random number value or a table such as a random number table, compare the acquired counter value or random number value with each of the multiple pieces of unique information, and determine that the multiple pieces of unique information are consistent if they all match, or determine that the multiple pieces of unique information are inconsistent if at least one piece does not match.
[0086] When the unique information is a counter value, the authentication unit 25 may determine that the multiple pieces of unique information are consistent when the counter values included in the multiple authentication requests satisfy a predetermined rule, and may determine that the multiple pieces of unique information are inconsistent when the counter values do not satisfy a predetermined rule. The predetermined rule may be, for example, that "the counter value increments by two." In this case, the authentication unit 25 may determine that the multiple pieces of unique information are consistent when the counter values, which are unique information included in the multiple authentication requests, are incremented by two when sorted in the order in which the authentication requests were received, and may determine that the multiple pieces of unique information are inconsistent when at least some of the counter values do not increment by two.
[0087] When the unique information is a time, the authenticating unit 25 may determine that the multiple pieces of unique information are consistent when, for example, the time difference between the time as the unique information included in an authentication request and the reception time of the authentication request is smaller than a predetermined threshold for all of the multiple authentication requests used to authenticate the authenticated device 1, and may determine that the multiple pieces of unique information are inconsistent when this difference is not the case. The reception time of the authentication request may be obtained by the receiving unit 21 from a clock unit (not shown), for example, when the authentication request is received.
[0088] When the unique information is a time, the authentication unit 25 may determine that the multiple pieces of unique information are inconsistent, for example, when the time in the unique information does not increase according to the order of acceptance, for example, when the time in the unique information included in an authentication request accepted at time A indicates a later time than the time in the unique information included in an authentication request accepted at time B, which is after time A. In this case, it is considered that the authentication request accepted at time B was an authentication request that was output from a legitimate device to be authenticated 1 earlier than the authentication request accepted at time A, and that was copied and output again by an attacker's device.
[0089] When the unique information is time, the authentication unit 25 may, for example, acquire the time difference between the time included in the unique information in each authentication request and the time at which the authentication request was received for each of the multiple authentication requests used to authenticate the device to be authenticated 1. If all of the acquired time differences are constant, the authentication unit 25 may determine that the multiple pieces of unique information are consistent. If not, the authentication unit 25 may determine that the multiple pieces of unique information are inconsistent. This allows the authentication unit 25 to appropriately determine whether the multiple pieces of unique information are consistent even if the clock units of the device to be authenticated 1 and the authentication device 2 are not completely synchronized. This is because the device to be authenticated 1 and the authentication device 2 typically exchange authentication requests over a short distance, and therefore the delay due to this exchange is considered to be approximately constant for multiple authentication requests. Note that the multiple time differences being consistent may mean, for example, that the difference between the maximum and minimum values of the multiple time differences is smaller than a predetermined threshold, or that the variance (e.g., variance or standard deviation) of the multiple time differences is smaller than a predetermined threshold.
[0090] Note that the authentication unit 25 may, for example, make any two or more of multiple determinations regarding whether the multiple pieces of unique information are consistent. In this case, if it is determined in each of the two or more determinations that the multiple pieces of unique information are consistent, the multiple pieces of unique information may be finally determined to be consistent. If it is determined in at least some of the determinations that the multiple pieces of unique information are inconsistent, the multiple pieces of unique information may be finally determined to be inconsistent. Even if the unique information includes any two or more types of information, such as time, counter value, and random number value, a determination regarding whether each type of information included in the unique information is consistent may be made separately. In this case, too, if all types of information are consistent, the multiple pieces of unique information may be finally determined to be consistent, and if not, the multiple pieces of unique information may be finally determined to be inconsistent.
[0091] Note that, for example, if all of the multiple authentication requests are transmitted from an unauthorized device to be authenticated 1, the authentication unit 25 will determine that the device to be authenticated 1 is unauthorized. Furthermore, for example, if the multiple authentication requests include an authentication request transmitted from an unauthorized device, the authentication unit 25 will also determine that the device to be authenticated 1 that transmitted the multiple authentication requests is unauthorized. In other words, even if multiple authentication requests are transmitted from a legitimate device to be authenticated 1 and an unauthorized device to be authenticated 1, the device to be authenticated 1 that transmitted the multiple authentication requests will be determined to be unauthorized. In this case, the transmission sources of the authentication requests will include at least the attacker's device, and even if a legitimate device to be authenticated 1 is included as a transmission source, it will be impossible to distinguish between the two, and therefore both will be determined to be unauthorized.
[0092] The authentication result output unit 26 outputs the authentication result, which is the determination result made by the authenticating unit 25. The authentication result may be, for example, information indicating whether the authenticated device 1 is legitimate or not. The authentication result output unit 26 may, for example, output the authentication result to a component or device that performs processing according to the authentication result. Furthermore, the authentication result output unit 26 may, for example, also output the authentication result to the authenticated device 1 that has output multiple authentication requests, i.e., the authenticated device 1 that is the target of authentication. In this case, the user of the authenticated device 1 will be able to know the authentication result. When information is exchanged between the authenticated device 1 and the authenticating device 2 via communication, the authentication result output unit 26 may transmit the authentication result to the authenticated device 1.
[0093] The data output unit 27 may generate shared data, output it to the device to be authenticated 1, and store the shared data in the storage unit 23. For example, the data output unit 27 may associate the shared data output to a certain device to be authenticated 1 with a user identifier identifying the user of the device to be authenticated 1 and store the associated data in the storage unit 23. When information is exchanged between the device to be authenticated 1 and the authentication device 2 via communication, the data output unit 27 may transmit the shared data to the device to be authenticated 1. This transmission may be performed, for example, by unicast. Note that the output of the shared data by the data output unit 27 to the device to be authenticated 1 is preferably performed in a secure manner so that the shared data is not known to a third party, but this is not essential. In the former case, the shared data may be encrypted using an encryption key associated with a user identifier identifying the user of the device to be authenticated 1, which is stored in the storage unit 23, and output, or may be output via a path separate from the path used for exchanging authentication requests. As an example, when the authentication request is transmitted and received via short-range wireless communication such as Bluetooth (registered trademark), the shared data may be transmitted and received via a wide-area communication network such as the Internet. In this manner, when the shared data is output by the data output unit 27, the second encrypted data included in the authentication request accepted by the accepting unit 21 from the legitimate authenticated device 1 is the encrypted second data including the output shared data. In this embodiment, a case will be mainly described in which the shared data is transmitted from the authenticating device 2 to the authenticated device 1 so as not to be known to a third party.
[0094] Here, the output from the authentication result output unit 26 and the data output unit 27 may be, for example, transmission to a predetermined device via a communication line, printing by a printer, sound output by a speaker, display on a display device (e.g., a liquid crystal display or an organic EL display), storage on a recording medium, or delivery to another component. The authentication result output unit 26 and the data output unit 27 may or may not include a device that performs the output (e.g., a communication device or a display device). The authentication result output unit 26 and the data output unit 27 may be realized by hardware, or may be realized by software such as a driver that drives those devices.
[0095] Next, the operation of the device to be authenticated 1 will be described with reference to the flowchart of Fig. 5. Fig. 5 is a flowchart showing an authentication request output method, which is the processing of the device to be authenticated 1 after communication between the device to be authenticated 1 and the authenticating device 2 is established in Fig. 2. The flowchart of Fig. 5 explains the case where information exchange between the device to be authenticated 1 and the authenticating device 2 is performed by communication, as described above.
[0096] (Step S101) The second data acquisition unit 14 determines whether or not shared data has been received. If shared data has been received, the process proceeds to step S102. If not, the process of step S101 is repeated until shared data is received.
[0097] (Step S102) The initial data acquisition unit 12 acquires initial data.
[0098] (Step S103) The first encryption unit 13 generates first data using the initial data acquired in step S102.
[0099] (Step S104) The second encryption unit 15 obtains second encrypted data by encrypting the second data including the shared data received in step S101 using the first data generated in step S103.
[0100] (Step S105) The output unit 16 transmits to the authentication device 2 an authentication request including the initial data acquired in step S102 and the second encrypted data acquired in step S104.
[0101] (Step S106) The output unit 16 determines whether to end the transmission of authentication requests. If the transmission of authentication requests is to be ended, the series of processes for transmitting multiple authentication requests ends; if not, the process returns to step S102. Note that the output unit 16 may determine to end the transmission of authentication requests when, for example, a predetermined number of authentication requests have been transmitted, or may determine to end the transmission of authentication requests when a predetermined period has elapsed since the transmission of the first authentication request. The process of determining whether to end the transmission of authentication requests may be performed, for example, by a component other than the output unit 16.
[0102] It is preferable that the interval between transmissions of the authentication requests is short. This is because the authentication process by the authentication device 2 is not completed until the transmission of multiple authentication requests is completed. As an example, the interval between transmissions of the authentication requests may be 200 ms or less, or may be 100 ms or less. Furthermore, the processing order in the flowchart of FIG. 5 is an example, and the order of the steps may be changed as long as the same results are obtained.
[0103] Next, the operation of the authentication device 2 will be described using the flowchart of Fig. 6. Fig. 6 is a flowchart showing an authentication method, which is the processing of the authentication device 2 after communication is established between the device to be authenticated 1 and the authentication device 2 in Fig. 2. The flowchart of Fig. 6 explains the case where information exchange between the device to be authenticated 1 and the authentication device 2 is performed by communication, as described above.
[0104] (Step S201) The data output unit 27 generates shared data and transmits it to the device to be authenticated 1, and also stores the shared data in the storage unit 23.
[0105] (Step S202) The reception unit 21 determines whether or not an authentication request has been received. If an authentication request has been received, the process proceeds to step S203, and if not, the process proceeds to step S206.
[0106] (Step S203) The encryption unit 22 generates first data using the initial data included in the received authentication request.
[0107] (Step S204) The determination unit 24 uses the first data generated in step S203 to determine whether the shared data corresponding to the second encrypted data included in the received authentication request matches the shared data stored in the storage unit 23. If they match, the process returns to step S202; if not, the process proceeds to step S205.
[0108] (Step S205) The authenticating unit 25 determines that the authenticated device 1 that sent the authentication request is not valid.
[0109] (Step S206) The authentication unit 25 determines whether to authenticate the authenticated device 1 using multiple authentication requests. If the authenticated device 1 is to be authenticated, the process proceeds to step S207; if not, the process returns to step S202. For example, the authentication unit 25 may determine to authenticate the authenticated device 1 when a predetermined number of authentication requests have been received from the authenticated device 1, or may determine to authenticate the authenticated device 1 when a predetermined period has elapsed since the first authentication request was received from the authenticated device 1.
[0110] (Step S207) The authentication unit 25 determines whether or not the multiple pieces of unique information included in the multiple authentication requests received from a certain device to be authenticated 1 are consistent. If the multiple pieces of unique information are consistent, the process proceeds to step S208; if not, the process proceeds to step S205.
[0111] (Step S208) The authenticating unit 25 determines that the authenticated device 1 that has sent the authentication request is valid.
[0112] (Step S209) The authentication result output unit 26 outputs the authentication result, which is the result of the determination made by the authenticating unit 25. Then, the series of processes for authenticating the device to be authenticated 1 is completed.
[0113] The order of the processes in the flowchart of FIG. 6 is an example, and the order of the steps may be changed as long as the same results are obtained.
[0114] Next, the operation of the authenticated device 1 and the authenticating device 2 according to this embodiment will be described using a specific example. In this specific example, the legitimate authenticated device 1 transmits ten authentication requests to the authenticating device 2. In this specific example, the unique information is time, and the authenticating unit 25 determines that the ten pieces of unique information are consistent if the time difference between the unique information time included in the authentication request and the reception time of the authentication request is constant for all ten authentication requests and if the time difference between the unique information time and the reception time is smaller than a predetermined threshold for all ten authentication requests. In this specific example, we will first describe a case where authentication requests are transmitted only from the legitimate authenticated device 1, and then describe a case where an attacker, a malicious third party, transmits authentication requests by impersonating another party.
[0115] [Transmission of an authentication request only from the legitimate device to be authenticated 1] Assume that communication is established between the device to be authenticated 1 and the authenticating device 2. At that time, the authenticating device 2 acquires the user identifier "U001" of the user of the device to be authenticated 1. Then, the data output unit 27 of the authenticating device 2 generates shared data, which is a random number, and transmits it to the device to be authenticated 1, and stores the shared data in the storage unit 23 in association with the user identifier "U001" (step S201). It is assumed that the number of bits of the shared data is predetermined.
[0116] The second data acquisition unit 14 of the device to be authenticated 1 receives the shared data transmitted from the authentication device 2 and passes the shared data, that is, the second data, to the second encryption unit 15 (step S101). The received shared data, that is, the second data, may be stored in a recording medium (not shown).
[0117] Next, the initial data acquisition unit 12 acquires the current time, reads the user identifier "U001" stored in the storage unit 11, and passes initial data including the unique information representing the acquisition time and the read user identifier to the encryption unit 22 and the output unit 16 (step S102). Upon receiving the initial data, the encryption unit 22 pads the initial data to generate data of a predetermined number of bits, encrypts the generated data using the encryption key stored in the storage unit 11 to obtain first encrypted data, and hashes the first encrypted data to generate first data of a predetermined number of bits, which is passed to the second encryption unit 15 (step S103). Note that the number of bits of the first data and the number of bits of the second data are assumed to be the same.
[0118] Upon receiving the first data, the second encryption unit 15 obtains second encrypted data, which is the exclusive OR of the first data and the second data, and passes the second encrypted data to the output unit 16 (step S104). Upon receiving the second encrypted data, the output unit 16 transmits an authentication request including the initial data and the second encrypted data to the authentication device 2 (step S105).
[0119] The authentication request sent from the device to be authenticated 1 is received by the reception unit 21 of the authentication device 2, the initial data included in the authentication request is passed to the encryption unit 22, a pair of unique information included in the initial data and the time of receipt of the authentication request is passed to the authentication unit 25, and the second encrypted data included in the authentication request is passed to the judgment unit 24 (step S202).
[0120] Upon receiving the initial data, the encryption unit 22 generates data of a predetermined number of bits by padding the initial data, encrypts the generated data using an encryption key stored in the memory unit 23 in correspondence with the user identifier "U001" included in the initial data to obtain first encrypted data, hashes the first encrypted data to generate first data of a predetermined number of bits, and passes the first data and the user identifier included in the initial data to the judgment unit 24 (step S203).
[0121] Upon receiving the first data and the user identifier, the determination unit 24 obtains the second data, which is the shared data, by performing an exclusive OR operation on the second encrypted data and the first data. The determination unit 24 also reads the shared data stored in the storage unit 23 in association with the user identifier and determines whether the two pieces of shared data match (step S204). Here, it is assumed that the two pieces of shared data match. Thereafter, the process of transmitting an authentication request in the authenticated device 1 and the process of receiving an authentication request in the authenticating device 2 and determining whether the two pieces of shared data match are repeated (steps S102 to S106, S202 to S204). In this specific example, it is assumed that the two pieces of shared data match for all ten authentication requests sent from the authenticated device 1 to the authenticating device 2.
[0122] When ten authentication requests are received, the authentication unit 25 determines to authenticate the authenticated device 1 (step S206), obtains the time difference for each of the ten pairs of unique information, which are the times of reception up to that point, and the reception time, and determines whether the ten time differences are consistent and whether the ten time differences are smaller than a threshold (step S207). In this specific example, it is assumed that the ten time differences are consistent and smaller than the threshold. The authentication unit 25 then determines that the ten pieces of unique information are consistent, determines that the authenticated device 1 is legitimate, and passes the authentication result, which is the determination result, to the authentication result output unit 26 (step S208). Upon receiving the authentication result, the authentication result output unit 26 transmits the authentication result to the authenticated device 1 and outputs it to a component or device that performs processing according to the authentication result (step S209). As a result, the user of the authenticated device 1, i.e., the user identified by the user identifier "U001", can learn the authentication result that he or she has been authenticated as legitimate, and can receive services, etc. according to that authentication result.
[0123] [Transmission of an Authentication Request Using a Different Encryption Key and Shared Data] Assume that a malicious third party, an attacker's device, receives an authentication request transmitted from the legitimate authenticated device 1 and acquires a user identifier from the initial data included in the authentication request. The attacker's device then constructs new initial data using the acquired user identifier and unique information representing the time at which the attacker's device transmits the authentication request. Using this initial data, the attacker acquires second encrypted data in the same manner as the authenticated device 1, and repeatedly transmits an authentication request including the initial data and the second encrypted data to the authentication device 2. In this case, although the multiple pieces of unique information are consistent, the malicious third party cannot reproduce the second encrypted data included in the authentication request transmitted from the legitimate authenticated device 1 because he does not know the encryption key corresponding to the user identifier and the shared data. As a result, the authentication device 2 determines that the shared data corresponding to the second encrypted data included in the received authentication request does not match the shared data stored in the storage unit 23 (step S204), and the attacker's device is determined to be invalid (step S205). In this way, it is possible to prevent impersonation by a malicious third party attacker who does not know the encryption key and shared data used by the legitimate device to be authenticated 1.
[0124] Even if the shared data is known to a malicious third party, the third party does not have the encryption key and therefore cannot reproduce the second encrypted data that is deemed legitimate. Therefore, for example, the shared data may be passed from the authenticator 2 to the authenticatee 1 via an insecure path.
[0125] [Later Transmission of Multiple Authentication Requests] This section describes a case where a malicious third party, an attacker's device, receives all authentication requests transmitted from the legitimate authenticated device 1 and later transmits the multiple authentication requests to the authentication device 2. If the attacker's device transmits multiple authentication requests at a different transmission interval than the legitimate authenticated device 1, the time difference between the unique information included in the authentication requests and the reception time of the authentication requests is not constant. This causes the authentication device 2 to determine that the multiple pieces of unique information are inconsistent (step S207), and the attacker's device is determined to be invalid (step S205). Even if the attacker's device can transmit multiple authentication requests at the same transmission interval as the legitimate authenticated device 1, if a time exceeding a threshold has elapsed between the transmission of the authentication requests by the legitimate authenticated device 1 and the transmission of the authentication requests by the attacker's device, the time difference between the unique information included in the authentication requests and the reception time of the authentication requests is not smaller than the threshold. This causes the authentication device 2 to determine that the multiple pieces of unique information are inconsistent (step S207), and the attacker's device is determined to be invalid (step S205). In this way, it is possible to prevent impersonation by an attacker's device that receives multiple authentication requests.
[0126] Finally, examples of devices and systems incorporating the authentication device 2 according to this embodiment will be briefly described.
[0127] The authentication device 2 may be incorporated into an automatic ticket gate. The automatic ticket gate may then establish communication with a nearby device to be authenticated 1 and transmit shared data to the device to be authenticated 1. When the device to be authenticated 1 owned by the user receives the shared data, it transmits multiple authentication requests to the authentication device 2 of the automatic ticket gate as described above. If the authentication device 2 determines that the device to be authenticated 1 is legitimate based on the multiple authentication requests, the gate of the automatic ticket gate opens, allowing the user to enter or exit the gate. In addition, the user is charged when entering or exiting the gate. In this way, for example, the user can ride a train or the like without operating the device to be authenticated 1, such as a smartphone.
[0128] The authentication device 2 may be incorporated into a vending machine for drinks or the like. When a user presses the purchase button on the vending machine, the vending machine may establish communication with a nearby device to be authenticated 1 and transmit shared data to the device to be authenticated 1. When the device to be authenticated 1 owned by the user receives the shared data, it transmits multiple authentication requests to the authentication device 2 of the vending machine as described above. If the authentication device 2 determines that the device to be authenticated 1 is legitimate based on the multiple authentication requests, a product such as a drink corresponding to the purchase button pressed by the user will be dispensed from the vending machine, and the user will be able to receive the product. In addition, the user will be charged appropriately depending on the processing. In this way, for example, the user can purchase a product from a vending machine without operating a smartphone or the like, which is the device to be authenticated 1.
[0129] The authentication device 2 may be installed near the entrance of an event venue such as a concert, sporting event, or seminar, or an art gallery, museum, theme park, sports club, or members-only lounge. In this case, the encryption key may be a ticket or membership card for the event. The authentication device 2 may then establish communication with a nearby device to be authenticated 1 and transmit shared data to the device to be authenticated 1. The user's device to be authenticated 1 receives the shared data and transmits multiple authentication requests to the authentication device 2 located near the entrance to the venue as described above. If the authentication device 2 determines that the device to be authenticated 1 is legitimate based on the multiple authentication requests, it may identify the location of the device to be authenticated 1 using, for example, the strength of the radio waves of the authentication requests, and output information such as a ticket corresponding to the encryption key (e.g., information about the type of ticket or information about the pre-registered ticket owner) at the identified location. By viewing this display, event staff can identify people entering through the entrance who do not have a ticket or membership card. Note that the staff may request that people without a ticket or membership card present their ticket or membership card. In this way, for example, the user can enter an event venue, museum, sports club, etc. without operating the device to be authenticated 1 such as a smartphone.
[0130] The authentication device 2 may be incorporated into a cash register in a store. For example, when a user or a store clerk operates the payment button on the cash register, the cash register may establish communication with a nearby authenticated device 1 and transmit shared data to the authenticated device 1. Upon receiving the shared data, the authenticated device 1 owned by the user transmits multiple authentication requests to the authentication device 2 of the cash register as described above. If the authentication device 2 determines that the authenticated device 1 is legitimate based on the multiple authentication requests, the user may receive the purchased item, such as a product, by charging a payment method (e.g., a credit card or electronic money) registered in association with the key of the common key encryption, according to the purchase amount. In this way, for example, the user may be able to purchase a product at a store without operating the authenticated device 1, such as a smartphone.
[0131] The authentication device 2 may be incorporated into a device requiring personal authentication, such as a PC (Personal Computer) or an ATM (Automated Teller Machine). For example, when a user operates a device such as a PC or ATM, the device may establish communication with a nearby device to be authenticated 1 and transmit shared data to the device to be authenticated 1. Upon receiving the shared data, the device to be authenticated 1 owned by the user transmits multiple authentication requests to the authentication device 2 of the device as described above. If the authentication device 2 determines that the device to be authenticated 1 is legitimate based on the multiple authentication requests, the user, who is registered in association with a key for common key encryption, may, for example, log in to a PC, log in to a website operated on the PC, or withdraw cash from an ATM. In this way, for example, a user can be authenticated on a device such as a PC or ATM and operate the device without having to enter a personal identification number, etc.
[0132] The authenticated device 1 and the authenticating device 2 according to this embodiment can also be used in situations other than those described above. For example, they may be used for authentication in car sharing, rental cars, airplane boarding procedures, etc. Furthermore, they may also be used for user authentication when operating equipment such as a personal computer.
[0133] Note that, in the above example, the case where the shared data is transmitted after communication between the authenticated device 1 and the authenticating device 2 is established has been mainly described, but this is not necessarily the case. For example, the authenticating device 2 may transmit different shared data depending on the time by broadcasting, such as a beacon. Then, the authenticated device 1 may generate and transmit an authentication request using the shared data received from the authenticating device 2. In this case, the authentication device 2 may associate the shared data with the user identifier when the first authentication request is received. As an example, if the memory unit 23 stores shared data that matches the shared data included in the second data obtained by decrypting the second encrypted data included in the first authentication request received from the authenticated device 1 to be authenticated, the authentication device 2 may associate the shared data stored in the memory unit 23 with the user identifier included in the received first authentication request.
[0134] Furthermore, before communication between the device to be authenticated 1 and the authenticating device 2 is established, shared data may be transmitted from the authenticating device 2 to the device to be authenticated 1. In this case, for example, one piece of shared data may be transmitted, or multiple pieces of shared data may be transmitted. In the latter case, the device to be authenticated 1 may use different shared data for each authentication, for example. Furthermore, the transmission of shared data from the authenticating device 2 to the device to be authenticated 1 may be performed, for example, via a route different from that used for the authentication request, or via the same route as that used for the authentication request. In the latter case, the shared data may be transmitted, for example, encrypted.
[0135] As described above, according to the authenticated device 1 and the authenticating device 2 of this embodiment, the second encrypted data included in the authentication request is obtained by encrypting the second data with the first data. Therefore, if, for example, the first data is generated using first encrypted data obtained by encrypting initial data with an encryption key, a malicious third party cannot newly generate the second encrypted data included in the authentication request. Therefore, a malicious third party cannot newly generate an authentication request that can be determined to be legitimate, thereby preventing spoofing. Furthermore, even if a malicious third party obtains an authentication request transmitted from a legitimate authenticated device 1 and transmits the authentication request to the authenticating device 2, for example, if the unique information is a time, the time difference between the time of the unique information and the time of reception of the authentication request can be used to determine that the device used by the malicious third party to transmit the authentication request is not the legitimate authenticated device 1. Furthermore, even if the unique information is a counter value or a random number, if the counter value or random number generated varies depending on the time, the unique information, which is a counter value or a random number, cannot be reused in a different situation, thereby preventing spoofing by a malicious third party.
[0136] Furthermore, because the initial data includes unique information, which is unique information, the first data created using the initial data can be different each time. That is, the first data can also be uniquely determined data, similar to the unique information. Therefore, the second encrypted data obtained by encrypting the second data using the first data can also be different each time. As a result, it is possible to make it difficult to predict the second data. Furthermore, by reducing the data amount of the first encrypted data, it is also possible to reduce the data amount of the second encrypted data. Therefore, it is possible to reduce the data amount of the authentication request.
[0137] Furthermore, since the authentication request includes initial data, the authentication device 2 that receives the authentication request can use the authentication request to authenticate the authenticated device 1 and can also obtain information necessary for processing after the device is authenticated as legitimate, such as a user identifier. Therefore, there is no need for the authenticated device 1 to send information necessary for processing after authentication, and post-authentication processing can be performed more quickly. As described above, the initial data may further include, for example, information necessary for processing after authentication.
[0138] Furthermore, the authentication request includes initial data in plain text, and this initial data is used to determine whether the shared data corresponding to the second encrypted data is equal to the shared data stored in authentication device 2, so that it is possible to confirm whether the initial data included in the authentication request is correct. Therefore, for example, even if a malicious third party sends an authentication request in which the initial data included in the authentication request has been rewritten to authentication device 2, the shared data corresponding to the second encrypted data included in the authentication request will not be equal to the shared data stored in authentication device 2, and the device that sent the authentication request will be determined to be invalid, thereby preventing spoofing.
[0139] In the present embodiment, the case where information is exchanged between the authenticated device 1 and the authenticating device 2 has been mainly described as communication. However, as described above, information may be exchanged between the two devices by means other than communication. Information exchange other than communication may be performed, for example, by displaying information and reading the displayed information, by outputting and receiving a blinking light signal, by outputting and receiving a sound wave or ultrasonic wave, or by other information transfer. When information is exchanged between the devices by displaying information and reading the displayed information, for example, the information to be output may be displayed on a display device as an image of a code such as a barcode or a two-dimensional code, and the image of the displayed code may be captured and read by an imaging device such as a camera, thereby transferring information between the authenticated device 1 and the authenticating device 2. For example, the output unit 16 of the authenticated device 1 may display a barcode or two-dimensional code of an authentication request. Then, the receiving unit 21 of the authenticating device 2 may acquire the authentication request from, for example, a captured image of the displayed code. Furthermore, for example, the data output unit 27 of the authentication device 2 may display a barcode or two-dimensional code of the shared data. Then, the second data acquisition unit 14 of the device to be authenticated 1 may acquire the shared data from, for example, a captured image of the displayed code. Furthermore, when information exchange between devices is performed by outputting and receiving a blinking light signal, for example, information to be output may be output from the light-emitting unit as a blinking light signal, and the output blinking light signal may be received by the light-receiving unit, thereby transferring information between the device to be authenticated 1 and the authentication device 2. Furthermore, when information exchange between devices is performed by outputting and receiving sound waves or ultrasound, for example, information to be output may be output from the output unit as sound waves or ultrasound, and the output sound waves or ultrasound may be received by the receiving unit, thereby transferring information between the device to be authenticated 1 and the authentication device 2.
[0140] Furthermore, in the present embodiment, the first encrypted data is mainly described as data obtained by encrypting initial data using an encryption key corresponding to a user identifier included in the initial data, but this is not necessarily the case. The first encrypted data may also be data encrypted without using an encryption key. In this case, the first encryption unit 13 may generate the first data by, for example, obtaining first encrypted data obtained by encrypting the initial data, and the encryption unit 22 may generate the first data by obtaining first encrypted data obtained by encrypting initial data included in the authentication request accepted by the acceptance unit 21. In this case, for example, the first encrypted data itself may be the first data.
[0141] The encryption without a cryptographic key may be, for example, a process for reducing the amount of data in the initial data. This process may be, for example, hashing, partial data extraction, a combination thereof, or any other process for reducing the amount of data. The encryption without a cryptographic key may be different for each authenticated device 1, or may be common to multiple authenticated devices 1. In the former case, the encryption unit 22 of the authentication device 2 may obtain the first encrypted data using an encryption process corresponding to a user identifier included in the accepted authentication request. In this case, a malicious third party cannot generate the first data from the initial data, thereby preventing spoofing by a malicious third party. Note that even if the encryption without a cryptographic key is common to multiple authenticated devices 1, appropriate authentication can be performed if, for example, the common data is unknown to a malicious third party and the encryption performed by the second encryption unit 15 is encryption that cannot be decrypted using the first data. In this case, for example, the second data may be common data.
[0142] Furthermore, in this embodiment, as described above, the second data may be, for example, data including data other than the shared data. In this case, for example, the second encrypted data may be obtained by encrypting data including the shared data and other data using the first data. By encrypting information other than the shared data, it becomes possible for the authenticated device 1 to output information that should not be made known to third parties to the authentication device 2. In this case, when determining whether the shared data corresponding to the second encrypted data matches the shared data stored in the storage unit 23 of the authentication device 2, it is preferable to compare the shared data included in the second data obtained by decrypting the second encrypted data using the first data with the shared data stored in the storage unit 23. In this way, by decrypting the second encrypted data, the authentication device 2 can obtain information other than the shared data that was encrypted together with the shared data.
[0143] Furthermore, in the present embodiment, when shared data is output from the authentication device 2 to the device to be authenticated 1, the case where the entire shared data is output has been mainly described. However, this is not necessarily the case. For example, a first portion, which is a part of the shared data, may be output from the authentication device 2 to the device to be authenticated 1. In this case, the remaining part of the shared data, the second portion, may be, for example, stored in advance in the authentication device 2 and the device to be authenticated 1, or may be passed from the authentication device 2 to the device to be authenticated 1 via a path different from that used for the first portion. In this case, for example, the first portion of the shared data may be used in common by multiple devices to be authenticated 1, and the second portion may be different for each device to be authenticated 1. As an example, the authentication device 2 may broadcast the first portion of the shared data, and the device to be authenticated 1 that receives it may construct the shared data using the received first portion and the second portion it stores. As another example, the authentication device 2 may transmit the first portion of the shared data to the device to be authenticated 1 via a first path and transmit the second portion of the shared data to the device to be authenticated 1 via a second path different from the first path. The first route may be, for example, a route such as short-range wireless communication through which an authentication request is transmitted and received, and the second route may be, for example, a route of a wide area communication network such as the Internet.
[0144] Furthermore, in this embodiment, the case where the shared data is output from the authentication device 2 to the device to be authenticated 1 has been described, but as described above, the shared data may be generated by the device to be authenticated 1. In this case, the authentication device 2 does not need to include the data output unit 27. In this case, the authentication device 2 may further include, for example, a shared data generation unit for generating the same shared data as that of the device to be authenticated 1.
[0145] Furthermore, in this embodiment, a case has been mainly described in which a predetermined amount of data including initial data is used to obtain the first encrypted data, but this is not necessarily the case. For example, the first encrypted data may be obtained by encrypting the initial data itself using an encryption key. In this case, for example, the amount of data of each piece of data included in the initial data may be predetermined. By doing so, for example, it is possible to make the first encrypted data have a predetermined amount of data.
[0146] In addition, in the present embodiment, the encryption of the second data using the first data is mainly explained by an exclusive OR operation, but this is not the only option. For example, it goes without saying that the second data may be encrypted using the first data as an encryption key by another encryption method.
[0147] Furthermore, when an authentication request is transmitted from the device to be authenticated 1 to the authentication device 2 via wireless communication, depending on the wireless communication standard, a single authentication request may be transmitted multiple times for redundancy, and the same authentication request transmitted multiple times may be received simultaneously by the authentication device 1. In this case, only one of the multiple authentication requests received simultaneously may be used for authentication processing, and the other authentication requests may not be used for authentication processing. Note that even in such a case, it is generally considered rare for the authentication device 2 to receive the same authentication request multiple times. Therefore, for example, if the authentication device 2 receives all authentication requests used in a single authentication request two or more times, or if the authentication device 2 receives more than a predetermined percentage (e.g., more than 50%, more than 80%) of the authentication requests two or more times, the authenticating unit 25 of the authentication device 2 may determine that the senders of the authentication requests include a device belonging to a malicious third party, i.e., an attacker, and may determine that the device to be authenticated 1 is not legitimate.
[0148] Furthermore, in the above embodiments, each process or function may be realized by centralized processing by a single device or a single system, or may be realized by distributed processing by multiple devices or multiple systems.
[0149] Furthermore, in the above-described embodiments, the transfer of information between components may be performed, for example, by one component outputting information and the other component receiving information if the two components transferring the information are physically different, or, if the two components transferring the information are physically the same, by moving from a processing phase corresponding to one component to a processing phase corresponding to the other component.
[0150] Furthermore, in the above-described embodiments, information related to the processing performed by each component, such as information accepted, acquired, selected, generated, transmitted, or received by each component, and information such as thresholds, formulas, and addresses used in processing by each component, may be temporarily or long-term stored in a recording medium (not shown), even if not explicitly stated in the above description. Furthermore, the storage of information in the recording medium (not shown) may be performed by each component or a storage unit (not shown). Furthermore, the reading of information from the recording medium (not shown) may be performed by each component or a reading unit (not shown).
[0151] Furthermore, in the above-described embodiments, if the information used by each component, such as thresholds, addresses, and various setting values used by each component in processing, may be changed by the user, the user may or may not be able to change the information as appropriate, even if not explicitly stated in the above description. If the information is changeable by the user, the change may be realized, for example, by a receiving unit (not shown) that receives a change instruction from the user and a changing unit (not shown) that changes the information in accordance with the change instruction. The change instruction may be received by the receiving unit (not shown), for example, from an input device, by receiving information transmitted via a communication line, or by receiving information read from a predetermined recording medium.
[0152] Furthermore, in the above embodiments, when two or more components included in the authenticated device 1 or the authenticating device 2 have a communication device, an input device, etc., the two or more components may physically have a single device or may have separate devices.
[0153] Furthermore, in the above-described embodiments, each component may be configured by dedicated hardware, or a component that can be realized by software may be realized by executing a program. For example, each component may be realized by a program execution unit such as a CPU reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. During execution, the program execution unit may execute the program while accessing a storage unit or recording medium. Note that the software realizing the authenticated device 1 in the above-described embodiments may be the following program. That is, this program may cause a computer to function as an initial data acquisition unit that acquires initial data including a user identifier that identifies a user and unique information, a first encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data, a second data acquisition unit that acquires second data including shared data shared with the authentication device, a second encryption unit that encrypts the second data using the first data to generate second encrypted data, and an output unit that outputs multiple different authentication requests, each including the initial data and the second encrypted data, to the authentication device.
[0154] Furthermore, the software that realizes the authentication device 2 in the above embodiment may be the following program. In other words, this program may be a program to cause a computer that can access a memory unit in which shared data shared with a legitimate device to be authenticated is stored to function as: a reception unit that receives from the device to be authenticated a plurality of different authentication requests, each including initial data including a user identifier that identifies the user and unique information that is unique information, and second encrypted data in which second data including the shared data is encrypted using first data generated by obtaining first encrypted data in which the initial data is encrypted; a first encryption unit that generates first data by obtaining first encrypted data in which the initial data included in the authentication request received by the reception unit; a determination unit that determines, using the first data generated by the first encryption unit, whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit matches the shared data stored in the memory unit; an authentication unit that determines that the device to be authenticated is legitimate when it is determined that the unique information included in the plurality of authentication requests received from the device to be authenticated is consistent and that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the memory unit for each of the plurality of authentication requests; and an authentication result output unit that outputs the authentication result that is the determination result by the authentication unit.
[0155] Note that the functions realized by the program do not include functions that can only be realized by hardware, such as a modem or interface card in an acquisition unit that acquires information or an output unit that outputs information.
[0156] This program may be executed by being downloaded from a server or the like, or by being read from a predetermined recording medium (for example, an optical disk such as a CD-ROM, a magnetic disk, or a semiconductor memory). This program may also be used as a program constituting a program product.
[0157] Furthermore, the computer that executes this program may be a single computer or multiple computers, and may perform centralized processing or distributed processing.
[0158] 7 is a diagram showing an example of a computer system 900 that executes the above program to realize the authenticated device 1 and the authenticating device 2 according to the above embodiment. The above embodiment can be realized by computer hardware and a computer program executed thereon.
[0159] 7, the computer system 900 includes an MPU (Micro Processing Unit) 911, a ROM 912 such as a flash memory that stores programs such as a boot-up program, application programs, system programs, and data, a RAM 913 connected to the MPU 911 that temporarily stores instructions for application programs and provides temporary storage space, a touch panel 914, a wireless communication module 915, and a bus 916 that interconnects the MPU 911, the ROM 912, etc. Note that if information exchange between the device to be authenticated 1 and the authenticating device 2 is performed by a method other than communication, the computer system 900 may further include a device used for the information exchange, such as a camera, a light-emitting device, or a light-receiving device, as needed. Instead of the touch panel 914, a display and an input device such as a mouse or a keyboard may be included.
[0160] A program that causes the computer system 900 to execute the functions of the authenticatee device 1 and the authenticator device 2 according to the above-described embodiments may be stored in the ROM 912 via the wireless communication module 915. The program is loaded into the RAM 913 when executed. The program may also be loaded directly from the network.
[0161] The program does not necessarily include an operating system (OS) or a third-party program that causes the computer system 900 to execute the functions of the authenticated device 1 and the authenticating device 2 according to the above-described embodiments. The program may include only an instruction portion that calls appropriate functions or modules in a controlled manner to achieve the desired results. How the computer system 900 operates is well known, and a detailed description thereof will be omitted.
[0162] Furthermore, the above-described embodiments are merely examples for specifically implementing the present invention, and are not intended to limit the technical scope of the present invention. The technical scope of the present invention is defined by the claims, not by the description of the embodiments, and is intended to include modifications within the literal scope of the claims and within the scope of equivalent meanings.
Claims
1. An authentication device comprising: an initial data acquisition unit that acquires initial data including a user identifier for identifying a user and unique information that is unique information; a first encryption unit that generates first data by acquiring first encrypted data obtained by encrypting the initial data; a second data acquisition unit that acquires second data including shared data shared with an authentication device; a second encryption unit that generates second encrypted data by encrypting the second data using the first data; and an output unit that outputs a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device respectively.
2. The authentication device according to claim 1, wherein the unique information includes at least one of a time, a counter value, and a random number value.
3. The authentication device according to claim 1, wherein the first encryption unit acquires first encrypted data obtained by encrypting the initial data using an encryption key corresponding to the user identifier included in the initial data.
4. The authentication device according to claim 3, wherein the first encryption unit acquires first encrypted data obtained by encrypting data of a predetermined data amount including the initial data using the encryption key.
5. The authentication device according to claim 1, wherein the first encryption unit generates first data by reducing the data amount of the first encrypted data.
6. The authentication device according to claim 5, wherein the first encryption unit reduces the data amount by hashing the first encrypted data.
7. The authentication device according to claim 5, wherein the first encryption unit reduces the data amount by extracting a part of the first encrypted data.
8. The data amount of the first data and the data amount of the second data are the same, and the second encryption unit generates second encrypted data that is an exclusive logical sum of the first data and the second data. The authentication device according to any one of claims 1 to 7.
9. The authentication device according to any one of claims 1 to 7, wherein the second data acquisition unit acquires the shared data from the authentication device.
10. The authentication device according to any one of claims 1 to 7, wherein the shared data includes a random number.
11. A receiving unit that receives a plurality of different authentication requests including second encrypted data obtained by encrypting second data including shared data, using first data generated by obtaining initial data including a user identifier for identifying a user and unique information that is unique information, and first encrypted data obtained by encrypting the initial data; An encryption unit that generates first data by obtaining first encrypted data obtained by encrypting the initial data included in the authentication request received by the receiving unit; A storage unit that stores shared data shared with a legitimate authentication device; A determination unit that determines whether the shared data corresponding to the second encrypted data included in the authentication request received by the receiving unit matches the shared data stored in the storage unit, using the first data generated by the encryption unit; An authentication unit that determines that the authentication target authentication device is legitimate when the unique information included in the plurality of authentication requests received from the authentication target authentication device is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; An authentication result output unit that outputs an authentication result that is a determination result by the authentication unit; An authentication device comprising:
12. The authentication device according to claim 11, wherein the unique information includes at least one of a time, a counter value, and a random number value.
13. The encryption unit of the authentication device according to claim 11 obtains first encrypted data obtained by encrypting the initial data included in the authentication request received by the receiving unit using an encryption key corresponding to the user identifier included in the initial data.
14. The encryption unit of the authentication device according to claim 13 obtains first encrypted data obtained by encrypting data of a predetermined data amount including the initial data included in the authentication request received by the receiving unit using the encryption key.
15. The encryption unit of the authentication device according to claim 11 generates first data by reducing the data amount of the obtained first encrypted data.
16. The authentication device according to any one of claims 11 to 15, wherein the data amount of the first data is the same as the data amount of the second data, and the second encrypted data is an exclusive logical sum of the first data and the second data.
17. The authentication device according to any one of claims 11 to 15, further comprising a data output unit that generates shared data, outputs the shared data to the authenticated device, and stores the shared data in the storage unit, wherein the second encrypted data included in the authentication request received by the reception unit is the second data including the shared data output by the data output unit encrypted.
18. The authentication device according to any one of claims 11 to 15, wherein the shared data includes a random number.
19. A method for outputting an authentication request, comprising: obtaining initial data including a user identifier for identifying a user and unique information that is unique information; generating first data by obtaining first encrypted data obtained by encrypting the initial data; obtaining second data including shared data shared by an authentication device; generating second encrypted data by encrypting the second data using the first data; and outputting a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device, respectively. Step of receiving, from an authentication target device, a plurality of different authentication requests including first encrypted data generated by obtaining initial data including a user identifier for identifying a user and unique information that is unique information, and second encrypted data obtained by encrypting second data including shared data; step of generating first data by obtaining first encrypted data obtained by encrypting the initial data included in the received authentication request; a determination unit that determines, using the first data generated in the step of generating the first data, whether the shared data corresponding to the second encrypted data included in the received authentication request matches the shared data stored in a storage unit in which the shared data shared with a legitimate authentication target device is stored; step of determining that the authentication target device is legitimate when the unique information included in the plurality of authentication requests received from the authentication target device is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; and step of outputting an authentication result that is a determination result in the step of determining whether the authentication target device is legitimate. An authentication method comprising: A program for causing a computer to function as an initial data acquisition unit that acquires initial data including a user identifier for identifying a user and unique information that is unique information, a first encryption unit that generates first data by obtaining first encrypted data obtained by encrypting the initial data, a second data acquisition unit that acquires second data including shared data shared with an authentication device, a second encryption unit that generates second encrypted data by encrypting the second data using the first data, and an output unit that outputs a plurality of different authentication requests including the initial data and the second encrypted data to the authentication device, respectively.
22. A computer that can access a storage unit storing shared data shared with a legitimate authentication device uses initial data including a user identifier for identifying a user and unique information that is unique information, and first data generated by acquiring first encrypted data obtained by encrypting the initial data to receive from the authentication device a plurality of different authentication requests including second encrypted data obtained by encrypting second data including the shared data; an encryption unit that generates the first data by acquiring the first encrypted data obtained by encrypting the initial data included in the authentication request received by the reception unit; a determination unit that determines whether the shared data corresponding to the second encrypted data included in the authentication request received by the reception unit matches the shared data stored in the storage unit, using the first data generated by the encryption unit; an authentication unit that determines that the authentication target authentication device is legitimate when the unique information included in the plurality of authentication requests received from the authentication target authentication device is consistent, and for each of the plurality of authentication requests, it is determined that the shared data corresponding to the second encrypted data included in the authentication request matches the shared data stored in the storage unit; and a program for functioning as an authentication result output unit that outputs an authentication result that is a determination result by the authentication unit.
Citation Information
Patent Citations
Authenticated device, authentication device, authentication request transmitting method, authentication method, and program
WO2020080301A1
One-time id generating method, authentication method, authentication system, server, client, and program
JP2004282295A
Authentication verification system, device to be authenticated, authentication device, authentication verification method, authentication verification program, computer readable recording medium, and recorded apparatus
JP2021170757A
Device to be authenticated, authentication device, authentication request transmission method, authentication method, and program
JP2021170758A
Device to be authenticated, authentication device, authentication request transmission method, authentication method, and program
JP6732326B1