System and authentication method

The authentication system ensures devices meet network security conditions by authenticating and preventing non-compliant connections, reducing user burden and enhancing network reliability through accurate compliance checks.

WO2025173154A1PCT designated stage Publication Date: 2025-08-21NT T INC

Patent Information

Application Number
PCT/JP2024/005196
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-15
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Conventional network security technologies fail to prevent devices that do not meet security conditions from connecting to the network, imposing a burden on users by requiring time-consuming checks on the device itself before login, and traditional MDM solutions increase costs and psychological burden.

Method used

An authentication system with an information processing device that acquires and authenticates terminal configuration information, determining compliance with network security conditions, and prevents non-compliant devices from connecting, using complementary configuration information to enhance accuracy.

Benefits of technology

Prevents non-compliant devices from connecting to the network, reducing user burden and enhancing network reliability and safety by ensuring devices meet security conditions before access, without the need for additional support like MDM.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024005196_21082025_PF_FP_ABST
    Figure JP2024005196_21082025_PF_FP_ABST
Patent Text Reader

Abstract

A system (100) is provided with a terminal (2) that requests connection to a network (3), and an information processing device (1) that authenticates the terminal. The information processing device has an acquisition unit (12a), an authentication unit (12b), a determination unit (12d), and a communication processing unit (11). The acquisition unit acquires authentication information of the terminal and configuration information indicating a component of the terminal. The authentication unit authenticates the terminal on the basis of the acquired authentication information. When the authentication of the terminal is successful, the determination unit determines whether the terminal satisfies the security condition of the network on the basis of the acquired configuration information of the terminal. When it is determined that the terminal does not satisfy the security condition, the communication processing unit notifies the terminal that the terminal will not be connected to the network.
Need to check novelty before this filing date? Find Prior Art

Description

System and authentication method

[0001] The present invention relates to a system and an authentication method.

[0002] When a user attempts to connect a terminal to a network, technologies such as antivirus software, EDR (Endpoint Detection and Response), and behavior detection have been proposed to prevent terminals that do not meet security conditions from connecting to the network (see, for example, Non-Patent Document 1).

[0003] Also, tools such as MDM (Mobile Device Management) that control applications that can be installed on a terminal and OS (Operating System) on the server side are known (see, for example, Non-Patent Document 2).

[0004] “CROWDSTRIKE FALCON INSIGHTTM ENDPOINT DETECTION AND RESPONSE(EDR)”, CROWDSTRIKE, [searched on February 1, 2020], Internet <URL: https: / / www.crowdstrike.jp / wp-content / uploads / 2019 / 08 / CS-Pub-Insight-JP1712.pdf> “Ivanti Neurons for MDM (formerly) Mobilelron Cloud)”, Ivanti, [searched on February 1, 2020], Internet <URL: ttps: / / www.ivanti.com / resources / v / doc / ivi / 2627 / 8258527a5ae6>

[0005] However, conventional technologies have the drawback of being unable to prevent devices that do not meet the network security requirements from connecting to the network while reducing the burden on users. For example, technologies such as antivirus software, EDR, and behavior detection are primarily implemented on the device itself, and it takes a certain amount of time to complete the operation check. Therefore, it is a significant burden for users to have to implement these technologies on their devices before logging in to the network.

[0006] The present invention has been made in view of the above, and has as its object to prevent a terminal that does not satisfy the security conditions of a network from connecting to the network while reducing the burden on the user.

[0007] In order to solve the above-mentioned problems and achieve the object, a system includes a terminal that requests connection to a network and an information processing device that authenticates the terminal. The information processing device has an acquisition unit, an authentication unit, a determination unit, and a communication processing unit. The acquisition unit acquires authentication information for the terminal and configuration information indicating the components of the terminal. The authentication unit authenticates the terminal based on the acquired authentication information. If authentication of the terminal is successful, the determination unit determines whether the terminal satisfies the security conditions of the network based on the acquired configuration information of the terminal. If the communication processing unit determines that the terminal does not satisfy the security conditions, it notifies the terminal that the terminal will not be connected to the network.

[0008] According to the present invention, it is possible to prevent a terminal that does not satisfy the security conditions of a network from connecting to the network while reducing the burden on the user.

[0009] Fig. 1 is a diagram showing the configuration of a system including an authentication device according to a first embodiment. Fig. 2 is a block diagram showing the configuration of the authentication device according to the first embodiment. Fig. 3 is a diagram showing an example of configuration information of a terminal. Fig. 4 is a flowchart showing the flow of authentication in the system. Fig. 5 is a flowchart of authentication processing by the authentication device. Fig. 6 is a diagram showing an example of a computer that executes an authentication processing program.

[0010] Hereinafter, embodiments of the system and authentication method disclosed in the present application will be described in detail with reference to the accompanying drawings. However, the system and authentication method according to the present application are not limited to these embodiments.

[0011] A network may have predefined guidelines that indicate security conditions for connecting to the network, such as guidelines for implementing a security policy.

[0012] If a terminal that has been successfully authenticated is connected to a network without determining whether it complies with the guidelines, the terminal will be able to connect to the network even if it does not comply with the guidelines. However, terminal authentication only involves limited checks, such as checking the OS version. Therefore, when connecting a terminal to a network that requires guidelines that indicate security conditions, it is desirable to be able to check whether the terminal that wishes to connect meets the network's guidelines, so that malicious terminals that do not comply with the guidelines are not able to connect to the network.

[0013] To address the above-mentioned issues, mobile device management (MDM) has traditionally been used. Using MDM technology, the device that authenticates the device controls the device's apps and OS details. However, this requires the device to subscribe to and use an MDM service. Furthermore, the device must install software to function as an MDM client and create a control account. This places a heavy burden on device users and raises concerns about increased overall system costs. Furthermore, MDM allows devices to be freely controlled from the device side, placing a significant psychological burden on device users.

[0014] Therefore, in the present disclosure, a terminal that has been successfully authenticated is determined to conform to guidelines that indicate the network's security policy, and terminals that do not conform to the guidelines are not allowed to connect to the network.

[0015] [First embodiment] In the following embodiment, the configuration of a system according to the first embodiment, the configuration of an authentication device, the flow of authentication in the system, and the flow of an authentication method implemented by the authentication device will be described in order, and finally the effects of the first embodiment will be described.

[0016] [System Configuration] Fig. 1 is a diagram showing the configuration of a system including an authentication device according to a first embodiment. The system 100 shown in Fig. 1 includes an authentication device 1, multiple terminals 2, and a storage unit 13. The multiple terminals 2 may be connected to the authentication device 1 and a network 3 via a network 4 such as the Internet. The authentication device 1 is an example of an information processing device that authenticates the terminals 2, and may be, for example, an authentication server. The system 100 is not limited to multiple terminals 2, and may include a single terminal 2.

[0017] Terminal 2 is a device that is subject to authentication when connecting to network 3. Terminal 2 requests connection to network 3. Network 3 authenticates the terminal. Network 3 is an example of a network that requires security conditions when connecting. Guideline information indicating the security conditions for connecting to network 3 is set in advance on the network 3 side. An example of guideline information is a security policy implementation guideline.

[0018] For example, the authentication device 1 performs terminal authentication to determine whether the terminal authentication information transmitted from the terminal 2 matches or does not match the authentication information stored in the authentication information storage unit 13c shown in Fig. 1, and determines whether the terminal authentication is successful. If the terminal authentication is successful, the authentication device 1 determines whether the configuration information of the terminal 2 matches or does not match the guideline information stored in the guideline information storage unit 13b shown in Fig. 1. If the authentication device 1 determines that there is a mismatch between the configuration information of the terminal 2 and the guideline information, it determines that the configuration of the applications, OS, etc. held by the terminal 2 violates the security conditions of the network 3, and does not allow the terminal 2 to connect to the network 3.

[0019] Furthermore, for example, the authentication device 1 determines the continuity between the configuration information of the terminal 2 and the past configuration information of the terminal 2 stored in the configuration information storage unit 13a shown in Fig. 1. If the authentication device 1 determines that the configuration information of the terminal 2 is not consistent with the past configuration information as continuity information, it determines that the configuration of the applications, OS, etc. held by the terminal 2 violates the security conditions of the network 3, and does not allow the terminal 2 to connect to the network 3.

[0020] As a result, the authentication device 1 allows a terminal that satisfies the security conditions to connect to the network 3 as a terminal 2 of a legitimate user, and determines a terminal that does not satisfy the security conditions to be a terminal 2 of an attacker attempting to log in, and does not allow the terminal to connect to the network 3. As a result, in the system 100, compared to when MDM technology is used, the burden on the user of the terminal 2 is reduced, while the reliability and safety of the network 3 can be improved by not allowing a terminal 2 that does not satisfy the security conditions to connect to the network 3.

[0021] 1, the authentication device 1 may use information complementing technology to generate complementary configuration information that complements the configuration information of the terminal 2 stored in the configuration information storage unit 13a, and may determine the compatibility of the complementary configuration information with the guideline information or the continuity of the complementary configuration information with past configuration information. This allows the sophistication of the configuration information of the terminal 2 to be improved.

[0022] [Configuration of Authentication Device] Next, the configuration of the authentication device 1 shown in Fig. 1 will be described using Fig. 2. Fig. 2 is a block diagram showing the configuration of the authentication device 1 according to the first embodiment. As shown in Fig. 2, this authentication device 1 has a communication processing unit 11, a control unit 12, and a storage unit 13. The processing of each of these units will be described below.

[0023] The communication processing unit 11 controls communication regarding various information exchanged with the terminal 2. For example, the communication processing unit 11 receives terminal authentication information and terminal components from the terminal 2 during authentication. Also, for example, the communication processing unit 11 may notify the terminal 2 of the authentication result. Specifically, if the communication processing unit 11 determines that the terminal 2 does not satisfy the security conditions, it may notify the terminal 2 that the terminal 2 will not be connected to the network. Also, if the communication processing unit 11 determines that the acquired configuration information of the terminal 2 does not match the previous configuration information of the terminal as continuous information, it may notify the terminal 2 that the terminal 2 will not be connected to the network 3.

[0024] The storage unit 13 stores data and programs necessary for various processes by the control unit 12, and includes a configuration information storage unit 13a, a guideline information storage unit 13b, and an authentication information storage unit 13c that are particularly closely related to the present disclosure. For example, the storage unit 13 is a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk.

[0025] The configuration information storage unit 13a stores previously obtained configuration information of the terminal 2. An example of the configuration information is software bill of materials (SBOM). The configuration information is information that the provider of the terminal 2 has provided and permitted to disclose, and does not include information that the provider has not permitted to be disclosed, such as confidential information of the terminal 2, among all the components of the terminal 2.

[0026] The configuration information is information describing the components of the terminal 2. Here, the components are components included in the terminal 2 that realize those functions, including software components. For example, the configuration information may include, as software components, the software component name, version information, the name of the supplier that provides the software, and attribute information associated with them. Note that, in the following, an example will be described in which the configuration information of the terminal 2 is provided from the terminal 2 to the authentication device 1, but it may also be provided by the provider of the system 100, etc.

[0027] The past configuration information may be, for example, configuration information transmitted from the terminal 2 when logging in at the time of past initial registration. Also, the past configuration information may be configuration information transmitted from the terminal 2 when logging in, for example, one year ago, one month ago, etc. Note that the past configuration information stored in the configuration information storage unit 13a does not include configuration information that has been tampered with or that contains fraudulent information.

[0028] FIG. 3 is a diagram showing an example of configuration information of a terminal. For example, as shown in FIG. 3, the configuration information storage unit 13a may store, as an example of configuration information of the terminal 2, a "component name," "version information," and "supplier information" in association with each other. The "component name" indicates the name of a software component installed on the terminal 2. The "version information" indicates the version of the software component. The "supplier information" indicates information about the provider of the software component. The supplier information may be at least one of the personal name or company name of the creator of the software component. The supplier information may be a URL (Uniform Resource Locator) or the like, as long as it is information about the provider of the software component.

[0029] 3, the configuration information storage unit 13a stores, in association with each other, a component name "Application A," version information "1.1.1," and supplier information "aa" as an example of the configuration information of the terminal 2. The configuration information storage unit 13a also stores, in association with each other, a component name "OpenSSL," version information "2.0," and supplier information "bb" as an example of the configuration information of the terminal 2.

[0030] The configuration information of the terminal 2 is obtained, for example, from data in an OS (Operating System) package management system or SBOM information. Note that the configuration information of the terminal 2 is not limited to software components and may also include hardware components. For example, the configuration information of the terminal 2 may include the product number, model number, and serial number of the terminal 2 as information on the hardware components. Furthermore, the configuration information of the terminal 2 may include information indicating the user's usage status of the software components or the user's usage status of the hardware components. Furthermore, the configuration information storage unit 13a may store complementary configuration information generated based on the above configuration information and the dependencies between the components of the terminal 2.

[0031] The guideline information storage unit 13b stores guideline information related to security conditions of the network 3. Examples of guideline information include an OS or an app that is prohibited from use within the network 3, such as an OS with a vulnerability, an app with a vulnerability, or an app whose use is prohibited within the network 3. For example, an example of an OS with a vulnerability is an OS for which security support from the OS provider has ended. An example of an app with a vulnerability is an app that is expected to allow unauthorized acquisition of root privileges, such as a jailbreak app for smartphones. An example of an app whose use is prohibited within the network 3 is an app whose use is prohibited by specific government agencies. Based on the guideline information stored in the guideline information storage unit 13b, a terminal 2 on which a specific OS or app whose use is prohibited by the guideline information is installed is considered to be a terminal that does not comply with the security conditions of the network 3 and is not permitted to connect to the network 3.

[0032] The authentication information storage unit 13c stores terminal authentication information. The terminal authentication information may be, for example, a user ID (identification) and password of the user who uses the terminal, a client certificate, a cookie history, etc. The terminal authentication information is used to authenticate the terminal 2 when logging in.

[0033] The control unit 12 has an internal memory for storing programs that define various processing procedures and necessary data, and performs various processes using these. In particular, the control unit 12 has an acquisition unit 12a, an authentication unit 12b, a generation unit 12c, a judgment unit 12d, and an output unit 12e that are closely related to the present disclosure.

[0034] The acquiring unit 12a acquires authentication information and configuration information of the terminal 2. For example, the acquiring unit 12a acquires a client certificate of the terminal 2 as the authentication information of the terminal 2. Furthermore, for example, the acquiring unit 12a acquires SBOM information of the terminal 2 as the configuration information of the terminal 2.

[0035] The authentication unit 12b authenticates the terminal 2 based on the acquired authentication information. For example, when logging in from the terminal 2, the authentication unit 12b performs terminal authentication on the terminal 2 based on authentication information such as a client certificate acquired from the terminal 2. Furthermore, for example, the authentication unit 12b performs connection authentication on the terminal 2 to the network 3 based on configuration information such as SBOM information acquired from the terminal 2. Hereinafter, this terminal authentication may be referred to as "normal terminal authentication" and may be distinguished from connection authentication on the network 3.

[0036] The generation unit 12c estimates the components of the terminal 2 based on the configuration information of the terminal 2 and the dependencies between the components included in the terminal 2, and generates supplemented configuration information for the terminal 2 by adding the estimated components of the terminal 2 to the acquired components of the terminal 2. For example, the generation unit 12c crawls open source on the web and extracts keywords from the component name indicating the open source included in the configuration information acquired from the terminal 2. The generation unit 12c then identifies a library that has a dependency relationship with the software, i.e., a library used to run the software having the component name, and acquires the library name. In this case, the dependency relationship between the software and the library is an example of a dependency relationship between components. The generation unit 12c generates supplemented configuration information by adding the library name to the configuration information of the terminal 2.

[0037] If the authentication of the terminal is successful, the determination unit 12d determines whether the terminal 2 satisfies the security conditions of the network 3 based on the acquired configuration information of the terminal 2. For example, the determination unit 12d determines whether the acquired configuration information of the terminal 2 matches or does not match the guideline information stored in the guideline information storage unit 13b. As a result, if it is determined that there is a mismatch, the determination unit 12d determines that the terminal 2 does not satisfy the security conditions of the network 3. In this case, the determination unit 12d may not allow the terminal 2 to connect to the network 3.

[0038] In addition, for example, a case will be described in which the acquired configuration information of the device 2 includes the configuration of a component named "app A," and the guideline information stored in the guideline information storage unit 13b shown in FIG. 3 identifies app A as a vulnerable app. In this case, the determination unit 12d determines that the acquired configuration information of the device 2 includes the vulnerable "app A" and does not match the security conditions indicated by the guideline information. An example of a vulnerable app is a jailbreak app for a smartphone. The determination unit 12d may prevent a device 2 on which such a vulnerable app is installed and which is suspected of having root privileges illegally obtained, for example, from connecting to the network 3.

[0039] As another example, the determination unit 12d may determine whether software components essential for security, as indicated by the guideline information, are still installed in the configuration information of the acquired terminal 2. For example, if the acquired configuration information of the terminal 2 does not include software components indicated by the guideline information, such as antivirus software or software that realizes the functions of an EDR client, the determination unit 12d determines that the configuration information does not match the security conditions indicated by the guideline information. The determination unit 12d may prevent a terminal 2 that does not have such software components essential for security installed from connecting to the network 3.

[0040] As another example, the determination unit 12d may determine whether the practically essential software components indicated in the guideline information are still incorporated in the configuration information of the acquired terminal 2. For example, if the acquired configuration information of the terminal 2 does not include software components indicated in the guideline information, such as a dedicated application for accessing the in-house office network or an application for connecting to the company's VPN server, the determination unit 12d determines that the configuration information does not match the security conditions indicated in the guideline information. The determination unit 12d may prevent a terminal 2 that does not incorporate such practically essential software components from connecting to the network 3.

[0041] As another example, the determination unit 12d may determine whether the acquired configuration information of the terminal 2 continues to incorporate software components required for each attribute of the terminal 2 indicated in the guideline information. For example, if the attribute of the terminal 2 is an accounting department terminal, and the acquired configuration information of the terminal 2 does not include a software component indicated in the guideline information, such as an accounting application, the determination unit 12d determines that the configuration information does not match the security conditions indicated in the guideline information. For example, if the attribute of the terminal 2 is a building control department terminal, and the acquired configuration information of the terminal 2 does not include a software component indicated in the guideline information, such as a BACnet driver, the determination unit 12d determines that the configuration information does not match the security conditions indicated in the guideline information. The determination unit 12d may prevent a terminal 2 that does not incorporate software components required for the attribute of the terminal 2 from connecting to the network 3.

[0042] As another example, if a lower-level library or lower-level application used in a vulnerable application indicated by the guideline information is included in the acquired configuration information of the device 2, the determination unit 12d may determine whether the lower-level library or lower-level application is vulnerable. If the lower-level library or lower-level application does not match the security conditions indicated by the guideline information, the determination unit 12d may prevent the device 2 from connecting to the network 3.

[0043] As another example, if the supplier name of an app included in the acquired configuration information of the device 2 is indicated by a URL, the determination unit 12d may be able to infer the country, company, or individual of the supplier (creator) from the URL. In this case, if the guideline information prohibits access to an app created by the supplier's country, company, or individual inferred from the URL, the determination unit 12d determines that the security conditions indicated by the guideline information do not match. In this case, the determination unit 12d may prevent the device 2 from connecting to the network 3.

[0044] In this way, if a terminal 2 that wishes to connect to the network 3 does not conform to the guideline information, that terminal 2 is prevented from connecting to the network 3. For example, if a malicious person illegally obtains terminal authentication information for a terminal 2 and logs in from the terminal 2 to attempt to access the network 3, normal terminal authentication will be successful. However, if the configuration information held by the malicious person's terminal 2 does not match the guideline information, the terminal 2 is determined to not satisfy the security conditions of the network 3. This makes it possible to prevent the terminal 2 from connecting to the network 3. Even if a legitimate user logs in from the terminal 2 and attempts to access the network 3, if the configuration information of the terminal 2 does not satisfy the security conditions indicated in the guideline information, the terminal 2 can be prevented from connecting to the network 3.

[0045] Furthermore, for example, the determination unit 12d may determine whether the acquired configuration information of the terminal 2 is consistent as continuation information with respect to past configuration information of the terminal 2. For example, the determination unit 12d compares the acquired configuration information of the terminal 2 with the configuration information (past configuration information) stored in the configuration information storage unit 13a, and determines whether the acquired configuration information of the terminal 2 is consistent as continuation information with respect to the past configuration information of the terminal 2. If it is determined that there is an inconsistency as a result, the determination unit 12d may determine that the configuration information of the terminal 2 does not have continuity with the past configuration information. In this case, the determination unit 12d may prevent the terminal 2 from connecting to the network 3.

[0046] Specifically, a case will be described in which the acquired configuration information for the terminal 2 indicates that the version information for the component named "OpenSSL" is "1.1.1," while the past configuration information stored in the configuration information storage unit 13a shown in FIG. 3 indicates that the version information for the component named "OpenSSL" is "2.0." In this case, the version information for the component named "OpenSSL" in the current configuration information for the terminal 2, "1.1.1," is older than the version information for the component named "OpenSSL" in the past configuration information, "2.0," resulting in an inconsistency. In this case, when there is no continuity between the current configuration information for the terminal 2 and the past configuration information, and the software component versions have unnaturally reverted, the determination unit 12d determines that the terminal 2 does not satisfy the security conditions of the network 3. In this case, the determination unit 12d may prevent the terminal 2 from connecting to the network 3.

[0047] As another example, if version information of a certain OS in past configuration information stored in the configuration information storage unit 13a is newer than the version information of the OS in the acquired configuration information of the terminal 2, the version of the OS currently used by the terminal 2 is older than the version of the OS used in the past by the terminal 2, and there is an inconsistency. If the acquired configuration information of the terminal 2 does not have continuity with the past configuration information in this way, the determination unit 12d may not allow the terminal 2 to connect to the network 3.

[0048] As another example, when a lower-level library or lower-level application used in a vulnerable application indicated by the guideline information is included in the acquired configuration information of the terminal 2, the determination unit 12d may extract changes from past configuration information to determine continuity. For example, when the determination unit 12d determines that the driver of the lower-level library has changed from company A to company B based on the past configuration information and the component name and supplier name in the acquired configuration information, the determination unit 12d may determine that there is no continuity between the configuration information of the terminal 2 and the past configuration information, and may not allow the terminal 2 to connect to the network 3.

[0049] In this way, if the configuration information of a terminal 2 wishing to connect to the network 3 does not match the past configuration information, the terminal 2 is prevented from connecting to the network 3. For example, if a malicious person illegally obtains the terminal authentication information of the terminal 2 and attempts to log in from the terminal 2 and access the network 3, the normal terminal authentication will be successful. However, if it is determined that there is a discrepancy between the acquired configuration information of the terminal 2 and the past configuration information of the terminal 2, for example, if the software versions of the OS, browser, etc. in the configuration information of the malicious person's terminal 2 are older than the software versions in the past configuration information, the terminal 2 that does not satisfy the security conditions of the network 3 can be prevented from connecting to the network 3. Even if a legitimate user logs in from the terminal 2 and attempts to access the network 3, if the configuration information of the terminal 2 does not match the past configuration information and does not satisfy the security conditions, the terminal 2 can be prevented from connecting to the network 3.

[0050] Furthermore, for example, the determination unit 12d may use supplementary configuration information instead of the configuration information of the terminal 2 used in the determination. Specifically, the determination unit 12d may determine whether the supplementary configuration information of the terminal 2, which supplements the acquired configuration information of the terminal 2, matches or does not match the guideline information stored in the guideline information storage unit 13b. In other words, the determination unit 12d may determine whether the terminal 2 satisfies the security conditions of the network 3 based on the supplementary configuration information of the terminal 2. The determination unit 12d may also determine the continuity between the supplementary configuration information of the terminal 2 and the past configuration information of the terminal 2 stored in the configuration information storage unit 13a. By using the supplementary configuration information, the precision of the configuration information of the terminal 2 can be improved.

[0051] In this way, a terminal 2 on which a specific application, software such as an OS that is suspected to be highly malicious or an application, software such as an OS that is suspected to be unsafe is installed can be more reliably prevented from connecting to the network 3. This can further improve the reliability and safety of the network 3.

[0052] If the terminal authentication is successful but the terminal 2 is not connected to the network 3, the output unit 12e outputs to the terminal 2 information indicating the cause and a solution to the problem.

[0053] [Authentication Flow by the System] Next, an example of the authentication flow in the system 100 will be described using FIG. 4. FIG. 4 is a flowchart showing the authentication flow in the system 100. In the system 100, when a terminal 2 logs in, the authentication device 1 performs terminal authentication of the terminal 2 and authentication for connection to the network 3. Note that, in the following, an example is described in which complementary configuration information is generated and compared with guideline information, but the configuration information and guideline information may be compared without generating complementary configuration information. In the following, an example is described in which complementary configuration information is generated and compared with previous configuration information, but the configuration information and previous configuration information may be compared without generating complementary configuration information.

[0054] 4, when logging in, the terminal 2 transmits terminal authentication information and terminal configuration information to the authentication device 1 via a network 4 such as the Internet (step S10). For example, the terminal 2 may transmit SBOM information as terminal configuration information in addition to a user ID, password, etc. as terminal authentication information.

[0055] The communication processing unit 11 of the authentication device 1 receives the terminal authentication information and the terminal configuration information and outputs them to the control unit 12 of the authentication device 1, the acquisition unit 12a of the control unit 12 acquires the terminal authentication information and the terminal configuration information, and the authentication unit 12b authenticates the terminal 2 based on the acquired terminal authentication information (step S20).

[0056] Then, the authentication unit 12b of the authentication device 1 determines whether the terminal authentication is successful (step S21). If the terminal authentication is unsuccessful, the output unit 12e of the authentication device 1 outputs a login failure to the terminal 2 (step S22). If the terminal authentication is successful, the generation unit 12c of the authentication device 1 generates complementary configuration information that complements the acquired configuration information of the terminal 2 based on the configuration information of the terminal 2 and the dependencies between the components included in the terminal (step S23).

[0057] Next, the determination unit 12d compares the supplementary configuration information with the guideline information stored in the guideline information storage unit 13b (step S24). Then, the determination unit 12d determines whether there is a mismatch between the supplementary configuration information and the guideline information (step S25). If there is a mismatch between the supplementary configuration information and the guideline information, the output unit 12e outputs information indicating the cause of the inability to connect the terminal 2 to the network 3 and a solution to the problem to the terminal 2 (step S26).

[0058] If there is no mismatch between the supplementary configuration information of terminal 2 and the guideline information, the judgment unit 12d compares the supplementary configuration information of terminal 2 with the past configuration information of terminal 2 stored in the configuration information storage unit 13a (step S27).

[0059] Then, the determination unit 12d determines whether there is continuity between the supplementary configuration information and the past configuration information (step S28). If the configuration information of the terminal 2 is not consistent with the past configuration information as continuity information, the determination unit 12d determines that there is no continuity in the configuration information. If there is no continuity in the configuration information, the output unit 12e outputs information to the terminal 2 prompting the terminal authentication information to be updated (step S29). If there is continuity in the configuration information, the determination unit 12d permits the terminal 2 to connect (log in) to the network 3 (step S30).

[0060] [Authentication Process] Next, an example of an authentication method executed by the authentication device 1 will be described with reference to FIG. 5. FIG. 5 is a flowchart of the authentication process by the authentication device 1. Note that, in the following, an example is described in which complementary configuration information is generated and compared with guideline information, but the configuration information and guideline information may be compared without generating complementary configuration information. In the following, an example is described in which complementary configuration information is generated and compared with previous configuration information, but the configuration information and previous configuration information may be compared without generating complementary configuration information.

[0061] 5, the communication processing unit 11 determines whether a login operation from the terminal 2 has been accepted (step S120). When the communication processing unit 11 receives terminal authentication information and terminal configuration information from the terminal 2, it determines that the login operation has been accepted.

[0062] When a login operation is accepted, the communication processing unit 11 outputs terminal authentication information and terminal configuration information, the acquisition unit 12a acquires the terminal authentication information and terminal configuration information, and the authentication unit 12b authenticates the terminal 2 based on the terminal authentication information acquired by the acquisition unit 12a (step S121).

[0063] Then, the authentication unit 12b determines whether the terminal authentication is successful (step S122). If the terminal authentication is unsuccessful, the output unit 12e outputs a login failure to the terminal 2 (step S123). For example, the output unit 12e displays on the display of the terminal 2 that login is not possible. If the terminal authentication is successful, the generation unit 12c generates complementary configuration information that complements the acquired configuration information of the terminal 2 based on the configuration information of the terminal 2 and the dependencies between the components included in the terminal (step S124).

[0064] Next, the determination unit 12d compares the supplementary configuration information with the guideline information stored in the guideline information storage unit 13b (step S125). Then, the determination unit 12d determines whether there is a mismatch between the supplementary configuration information and the guideline information (step S126). If there is a mismatch between the supplementary configuration information and the guideline information, the output unit 12e outputs information indicating the cause of the inability to connect the terminal 2 to the network 3 and a solution to the problem to the terminal 2 (step S127).

[0065] For example, the output unit 12e may output, as the cause of the inability to connect to the network 3 and a solution, something like, "The OpenSSL version 1.1.1 you are using has security vulnerabilities. We recommend version 2.0 or higher for the network 3, so please switch to the new version." The user of the terminal 2 can quickly connect to the network 3 based on the presented cause and solution. Note that the above output is an example of information indicating the cause of the inability to connect the terminal 2 to the network 3 and the solution, and is not limited to this.

[0066] If there is no mismatch between the supplementary configuration information of the terminal 2 and the guideline information, the determination unit 12d compares the supplementary configuration information of the terminal 2 with the past configuration information of the terminal 2 stored in the configuration information storage unit 13a (step S128).The determination unit 12d then determines whether there is continuity between the supplementary configuration information and the past configuration information (step S129).If the configuration information of the terminal 2 is not consistent as continuation information with the past configuration information, the determination unit 12d determines that there is no continuity in the configuration information.If there is no continuity in the configuration information, the output unit 12e outputs information to the terminal 2 prompting the terminal authentication information to be updated (step S130).

[0067] When the terminal 2 itself is replaced with another terminal 2 or when the terminal 2 is initialized, a different OS is installed on the terminal 2 than before, and the terminal 2 needs to re-register its authentication information. Therefore, the authentication device 1 prompts the terminal 2 to update its terminal authentication information. This allows the user of the terminal 2 to quickly update the terminal authentication information based on the presented information and connect to the network 3. Note that the above output is an example of information indicating the cause of the inability of the terminal 2 to connect to the network 3 and how to deal with it, and is not limited to this.

[0068] If there is continuity in the configuration information, the determining unit 12d permits the terminal 2 to connect (log in) to the network 3 (step S131). This allows the terminal 2 to use the network 3.

[0069] In step S131, the determining unit 12d may store the configuration information acquired from the terminal 2 that is permitted to connect to the network 3 as past configuration information in the configuration information storage unit 13a.

[0070] In addition, the generation unit 12c may not generate the correction configuration information in step S124. In this case, the process of step S124 is skipped, and the complementary configuration information used in steps S125, S126, S128, and S129 is replaced with the configuration information acquired from the terminal 2.

[0071] [Effects of the First Embodiment] For example, when antivirus software, EDR, behavior detection, etc. are used, these technologies are mainly implemented on the terminal 2 side, not on the authentication device 1, and it takes a certain amount of time to complete the operation check. For this reason, it is inappropriate for the terminal 2 attempting to connect to the network 3 to implement these technologies before logging in.

[0072] Furthermore, when a terminal 2 logs in to a network 3 that requires security conditions, it is appropriate to be able to confirm whether the terminal 2 that wishes to connect meets the guidelines of the security policy of that network 3. However, with conventional technology, as long as authentication of the terminal 2 is successful at the time of login, even a terminal 2 that does not meet the guidelines of the security policy of the network 3 can effectively connect to the network 3. As a result, the reliability and safety of the network 3 are reduced.

[0073] Furthermore, it is desirable to prompt terminals 2 that do not satisfy the security policy guidelines of network 3 by presenting specific corrections in accordance with the security policy guidelines of network 3. However, presenting information equivalent to the security policy guidelines of network 3 to an unspecified number of people without any restrictions is not desirable from the perspective of security operations.

[0074] Furthermore, using MDM technology allows the authentication device 1 to control the apps and OS of the terminal 2. However, this requires the installation of software to function as an MDM client on the terminal and the creation of a control account, which places a significant burden on the user. Furthermore, with MDM, the user's terminal 2 is freely controlled by the authentication device 1, which places a significant psychological burden on the user and raises concerns about increased costs for the overall system. Furthermore, MDM generally inspects only the current configuration information of the apps and OS of the terminal 2. Therefore, past configuration information of the terminal 2 cannot be used during authentication.

[0075] In contrast, in the system 100 according to the first embodiment, when logging in, the terminal 2 transmits configuration information of the terminal 2, such as SBOM information, to the authentication device 1 in addition to normal terminal authentication information. This allows the authentication device 1 to check whether the configuration information of the terminal 2 satisfies the guidelines of the security policy of the network 3. As a result, it is possible to prevent a terminal 2 that does not satisfy the security conditions indicated by the guidelines of the security policy of the network 3 from connecting to the network 3. Furthermore, the terminal 2 does not need additional support, such as MDM. This reduces the burden on the user and prevents a terminal 2 that does not satisfy the security conditions of the network 3 from connecting to the network 3.

[0076] For example, when terminal 2 transmits configuration information to authentication device 1, the configuration information stored in terminal 2 may be transmitted as is without being processed, i.e., correct configuration information may be transmitted, or a malicious user may transmit the configuration information stored in terminal 2 after processing it, i.e., falsified configuration information may be transmitted. Alternatively, a legitimate user may transmit the configuration information stored in terminal 2 after processing it due to some kind of trouble. In such cases, authentication device 1 can prevent terminal 2 from connecting to network 3 if the configuration information and guideline information do not match, regardless of whether the user of terminal 2 that transmitted the processed configuration information is a malicious user or a legitimate user.

[0077] Furthermore, the authentication device 1 compares the configuration information presented at the time of login of the terminal 2 with past configuration information, and if there is no continuity in the configuration information, it does not allow that terminal 2 to connect to the network 3. This makes it possible to prevent a terminal 2 of an unauthorized user who does not know the past configuration information of the legitimate terminal 2 from connecting to the network 3. Furthermore, even if for some reason only the terminal authentication information is leaked to an attacker, the attacker will not be able to connect to the network 3 unless he separately obtains information equivalent to the configuration information in the legitimate terminal 2 and sends it at the same time. This further reduces the success rate of attacks.

[0078] Furthermore, the authentication device 1 may use information complementing technology for the configuration information transmitted from the terminal. In this case, the authentication device 1 uses the information complementing technology to generate complementary configuration information for the terminal 2 by adding new configuration information inferred from the configuration information provided by the terminal 2. The authentication device 1 then checks whether the complementary configuration information of the terminal 2 satisfies the guidelines of the security policy of the network 3, based on the complementary configuration information of the terminal 2. This allows the authentication device 1 to more accurately determine whether the configuration information conforms to the guidelines of the security policy of the network 3, even when the terminal 2 presents configuration information such as SBOM information, which has many uncertainties.

[0079] Furthermore, the authentication device 1 presents information indicating the cause of and a solution to the inability to connect to the network 3 to a terminal 2 that has been successfully authenticated and has a discrepancy between the configuration information or complementary configuration information and the guideline information. This makes it possible to present a specific method for connecting to the network 3 only to the user of the terminal 2 that has been successfully authenticated, and to prevent the guideline information from being made public to an unspecified number of people. It is also possible to avoid a situation in which the user of the terminal 2 is unable to take measures because they do not know why they are not permitted to log in to connect to the network 3 even though the terminal authentication has been successful.

[0080] Furthermore, the authentication device 1 presents information urging a terminal 2 that has been successfully authenticated and for which there is no continuity between the configuration information or complementary configuration information and the past configuration information, to update the authentication information. This makes it possible to present a specific method for connecting to the network 3 only to the user of the terminal 2 that has been successfully authenticated, and to prevent the guideline information from being made public to an unspecified number of people. It also makes it possible to avoid a situation in which the user of the terminal 2 is unable to take measures because they do not know why they are not permitted to log in to connect to the network 3 even though they have been successfully authenticated.

[0081] Furthermore, the authentication device 1 may, as necessary, perform the following confirmation operation in cooperation with the terminal 2. For example, if the terminal 2 has an EDR client function, the authentication device 1 may cooperate with the EDR client in the terminal 2 to obtain software version information and characteristic response information obtained on the terminal 2 side via an API (Application Programming Interface).

[0082] In this case, the authentication device 1 may determine whether the acquired version information and response information are consistent with the acquired configuration information of the terminal 2. For example, the configuration information of the terminal 2 may indicate a version of an app to which a security patch is supposed to be applied, but the information acquired on the terminal 2 via an API may include response information characteristic of a version of the app that remains vulnerable when the security patch is not applied. In this case, the authentication device 1 determines that the acquired response information is inconsistent with the configuration information and prevents the terminal 2 from connecting to the network 3. Furthermore, for example, if version 1.1 of a specific app has a fatal vulnerability that allows a third party to obtain root privileges via the network, the configuration information of the terminal 2 may not include the configuration indicated by version 1.1 of the specific app, but may include response information that suggests that the terminal 2 has a version of the specific app that is version 1.1 or lower. In this case, the authentication device 1 determines that the acquired response information is inconsistent with the configuration information and prevents the terminal 2 from connecting to the network 3.

[0083] Furthermore, the authentication device 1 may obtain a copy of a packet transmitted from the terminal 2 to the outside by working with an EDR client in the terminal 2. The authentication device 1 determines whether the obtained packet is consistent with the configuration information of the terminal 2. For example, the configuration information of the terminal 2 may not include an application whose use is prohibited by a specific government agency, but the packet transmitted from the terminal 2 to the outside may include a packet specific to the application whose use is prohibited by the specific government agency. In this case, the authentication device 1 determines that the obtained packet is inconsistent with the configuration information. In this case, the authentication device 1 prevents the terminal 2 from connecting to the network 3.

[0084] As another example, when encrypted packets are transmitted from terminal 2 to a C&C server (Command and Control server) at a predetermined frequency, authentication device 1 may obtain destination information and a port number of the packets transmitted from terminal 2 to the C&C server by working with an EDR client in terminal 2. The authentication device 1 identifies an application used by terminal 2 from the obtained destination information and port number of the packets, and if the configuration information of terminal 2 does not include the application, determines that there is a conflict with the configuration information and does not allow terminal 2 to connect to network 3. Note that authentication device 1 may also identify an application used by terminal 2 based on the content of the obtained packet, and if the configuration information of terminal 2 does not include the application, determines that there is a conflict with the configuration information and does not allow terminal 2 to connect to network 3.

[0085] [System Configuration, etc.] The components of each device shown in the figure are conceptual functional units and do not necessarily need to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown in the figure. All or part of the devices can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU and a program analyzed and executed by the CPU, or can be realized as hardware using wired logic. For example, at least one of the acquisition unit 12a, authentication unit 12b, generation unit 12c, and determination unit 12d may be integrated.

[0086] Furthermore, among the processes described in this embodiment, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0087] [Program] It is also possible to create a program in which the processing executed by the authentication device 1 according to the above embodiment is written in a language executable by a computer. In this case, the same effects as those of the above embodiment can be obtained by having a computer execute the program. Furthermore, such a program may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read and executed by a computer to realize processing similar to that of the above embodiment. An example of a computer that executes an authentication processing program that realizes functions similar to those of the authentication device 1 will be described below.

[0088] Fig. 6 is a diagram showing a computer that executes an authentication processing program. As shown in Fig. 6, the computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0089] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.

[0090] 6, the hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. Each storage unit described in the above embodiment is stored in, for example, the hard disk drive 1090 or the memory 1010.

[0091] The authentication processing program is stored in the hard disk drive 1090 as a program module in which commands to be executed by the computer 1000 are written. Specifically, the hard disk drive 1090 stores a program module 1093 in which each process executed by the authentication device 1 described in the above embodiment is written.

[0092] Furthermore, data used for information processing by the authentication processing program is stored as program data, for example, in the hard disk drive 1090. Then, the CPU 1020 reads the program module 1093 and program data 1094 stored in the hard disk drive 1090 into the RAM 1012 as necessary, and executes each of the above-described procedures.

[0093] The program module 1093 and program data 1094 related to the authentication processing program are not limited to being stored in the hard disk drive 1090, and may be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100. Alternatively, the program module 1093 and program data 1094 related to the authentication processing program may be stored in another computer connected via a network such as a LAN (Local Area Network) or a WAN (Wide Area Network), and read by the CPU 1020 via the network interface 1070.

[0094] REFERENCE SIGNS LIST 1 authentication device 2 terminal 3 network 11 communication processing unit 12 control unit 12a acquisition unit 12b authentication unit 12c generation unit 12d determination unit 12e output unit 13 storage unit 13a configuration information storage unit 13b guideline information storage unit 13c authentication information storage unit 100 system

Claims

1. A system comprising a terminal requesting connection to a network and an information processing device that authenticates the terminal, wherein the information processing device has: an acquisition unit that acquires authentication information for the terminal and configuration information indicating the components of the terminal; an authentication unit that authenticates the terminal based on the acquired authentication information; a determination unit that, if authentication of the terminal is successful, determines whether the terminal satisfies the security conditions of the network based on the acquired configuration information of the terminal; and a communication processing unit that, if it is determined that the terminal does not satisfy the security conditions, notifies the terminal that the terminal will not be connected to the network.

2. The system described in claim 1, wherein the determination unit refers to stored past configuration information of the acquired terminal and determines whether the acquired configuration information of the terminal is consistent as continuous information with respect to the terminal's past configuration information, and the communication processing unit notifies the terminal that the terminal will not be connected to the network if it is determined that the acquired configuration information of the terminal is not consistent as continuous information with respect to the terminal's past configuration information.

3. The system described in claim 1, wherein the information processing device has a generation unit that estimates the components of the terminal based on the configuration information of the terminal and dependencies regarding the components included in the terminal, and generates complementary configuration information of the terminal by adding the estimated components of the terminal to the acquired components of the terminal, and the determination unit determines whether the terminal satisfies the security conditions of the network based on the complementary configuration information of the terminal.

4. An authentication method executed by an information processing device that authenticates a terminal that requests connection to a network, comprising: an acquisition step of acquiring authentication information for the terminal and configuration information indicating the components of the terminal; an authentication step of authenticating the terminal based on the acquired authentication information; a determination step of determining, if authentication of the terminal is successful, whether the terminal satisfies the security conditions of the network based on the acquired configuration information of the terminal; and a notification step of notifying the terminal that the terminal will not be connected to the network if it is determined that the terminal does not satisfy the security conditions.

Citation Information

Patent Citations

  • Network connection control program, network connection control method, and network connection control system

    JP2007213550A

  • Authentication method, authentication system, authentication device, and computer program

    WO2009001447A1

  • Quarantine program, quarantine method, and information processing device

    WO2012049761A1

Cited By

  • Integrated Verification System for Software Supply Chain Deployment and Monitoring

    KR102981543B1