Data distribution system, connector device, and user authentication method

The data distribution system uses connector devices to authenticate users via telephone communication services, addressing impersonation risks and reducing costs by verifying subscriber information, ensuring secure and efficient user identification.

WO2025197755A1PCT designated stage Publication Date: 2025-09-25NTT COMM CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/009649
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-18
Filing Date
2025-03-13
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Existing user authentication methods in data sharing platforms are vulnerable to impersonation, requiring complex and costly trust infrastructure and authentication systems, posing a risk of unauthorized data access.

Method used

A data distribution system utilizing connector devices that authenticate users through telephone communication services by verifying subscriber information, including telephone numbers, stored in self and other party information storage units, ensuring legitimate user identification without building new large-scale systems.

Benefits of technology

Provides highly reliable user authentication, preventing impersonation and reducing operational effort and cost by leveraging existing telephone carrier services to manage and verify user identities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025009649_25092025_PF_FP_ABST
    Figure JP2025009649_25092025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention enables highly reliable user authentication by preventing impersonation, without imposing significant effort or cost burdens on the operator or the user. According to one aspect of the present invention, when data transmission is performed between users through connector devices using a data space, user information of the users trying to perform the data transmission is stored in the connector devices, in a state including subscriber information allocated to each user by the subscribed telephone communication operator. Each connector device is provided with a call originating and termination function that uses the subscriber information. When the data transmission is performed between the users, the user information including the counterpart user's subscriber information is mutually transmitted and received between the connector devices using the call originating and termination function, and the communication-counterpart user is authenticated by comparing the received counterpart user information with the previously stored user information.
Need to check novelty before this filing date? Find Prior Art

Description

Data distribution system, connector device and user authentication method

[0001] One aspect of the present invention relates to a data distribution system that distributes data between companies or industries using a data linkage platform, and a connector device and a user authentication method used in the data distribution system.

[0002] In recent years, a data sharing platform (hereafter referred to as "data space") has been proposed, which allows the mutual exchange of unique data held by multiple companies or industries within a domestic or international supply chain. This data sharing platform makes it possible to efficiently collect and manage data on goods such as products and parts stored in different locations across multiple companies, as well as data on services.

[0003] However, user authentication is essential for safe use of the data sharing platform. Therefore, a technology has been proposed that connects a user terminal to the data sharing platform via a connector device called a data space connector, and executes an authentication procedure in this connector device to prevent unauthorized access to the data sharing platform and enable safe data distribution (see, for example, Non-Patent Document 1).

[0004] “Prototype platform for interconnection with the core technology of the European GAIA-X, IDS Connector,” NTT Communications Corporation, April 8, 2021, Internet <URL: https: / / www.ntt.com / about-us / press-releases / news / article / 2021 / 0408.html>

[0005] However, the user authentication method described in Non-Patent Document 1 is a system in which user IDs issued by the data linkage platform operator or by an external ID provider are linked to the connector number of each user, and are managed and authenticated. Therefore, if someone copies the software that runs the connector device or the user ID and impersonates a legitimate user, there is a risk that data may be illegally stolen.

[0006] Furthermore, preventing the above-mentioned spoofing would require the construction of a new trust infrastructure and authentication system, along with tedious procedures and management systems such as strict credit screening, which would impose a great deal of effort and cost on the operators and users of the data sharing infrastructure.

[0007] This invention has been made in light of the above circumstances, and aims to provide a technology that prevents impersonation and enables highly reliable user authentication without imposing a significant burden on operators and users in terms of effort and cost.

[0008] In order to solve the above problems, one aspect of the data distribution system and its user authentication method of the present invention is a data distribution system in which data is transmitted between multiple connector devices used by each user via a data linkage infrastructure, and the connector devices and the data linkage infrastructure communicate with each other by making and receiving calls using subscriber information assigned to them by their respective telephone carriers, and each of the multiple connector devices stores its own user information, including the subscriber information assigned to its own connector device, in a self-information storage unit, and stores the other party's user information, including the subscriber information assigned to the connector device that is the other party in the data transmission, in a other party information storage unit.

[0009] In this state, the first connector device requesting the data transmission transmits communication request information including its own user information stored in its own information storage unit to the second connector device, which is the other party of the data transmission, via the telephone communication using the outgoing and incoming call. In response, when the second connector device receives the communication request information, it compares the user information of the first connector device included in the received communication request information with the user information of the other party stored in its other party information storage unit to determine the legitimacy of the received user information, and if it determines that the received user information is legitimate, it transmits communication response information including the user information of the second connector device stored in its own information storage unit to the first connector device via the telephone communication. Upon receiving the communication response information, the first connector device compares the user information of the second connector device included in the communication response information with the user information of the second connector device stored in its other party information storage unit to determine the legitimacy of the received second user information.

[0010] According to one aspect of the present invention, the following advantageous effects can be achieved: Telephone communication services provided by telephone carriers in each country in accordance with international standards and laws and regulations provide services that are virtually impossible to spoof by verifying the identity of users and strictly managing and authenticating their subscriber information (e.g., telephone numbers).

[0011] Therefore, by performing user authentication by combining the call originating and receiving functions of telephone communication services as described above, operators can prevent impersonation without having to build a new large-scale authentication system and without requiring users to go through cumbersome procedures such as credit checks, thereby making it possible to reliably identify, specify, and authenticate the other party of a communication.

[0012] In other words, according to one aspect of the present invention, it is possible to provide a technology that prevents impersonation and enables highly reliable user authentication without imposing a significant effort or cost burden on the operating company or user.

[0013] FIG. 1 is a diagram showing an example of the overall configuration of a data distribution system according to an embodiment of the present invention. FIG. 2 is a block diagram showing an example of the hardware configuration of a connector device used in the data distribution system shown in FIG. 1. FIG. 3 is a block diagram showing an example of the software configuration of a connector device used in the data distribution system shown in FIG. 1. FIG. 4 is a block diagram showing an example of the hardware configuration of a data space management device used by an operator of a data linkage platform in the data distribution system shown in FIG. 1. FIG. 5 is a block diagram showing an example of the software configuration of a data space management device used by an operator of a data linkage platform in the data distribution system shown in FIG. 1. FIG. 6 is a diagram showing the connection configuration between the connector device, the data space management device, and a telephone carrier in the data distribution system shown in FIG. 1. FIG. 7 is a sequence diagram showing the procedure of registration control processing performed between the connector device and the data space management device when registering user information for user A in the data distribution system shown in FIG. 1. FIG. 8 is a sequence diagram showing the procedure of registration control processing performed between the connector device and the data space management device when registering information required for authenticating user B in the data distribution system shown in FIG. 1. Fig. 9 is a sequence diagram showing the processing procedure for registering user information of communication partners in the connector devices of users A and B in the data distribution system shown in Fig. 1. Fig. 10 is a sequence diagram showing the processing procedure for authentication processing executed before data transmission between users' connector devices in the data distribution system shown in Fig. 1. Fig. 11 is a diagram showing an example of user information managed by a data space management device. Fig. 12 is a diagram showing an example of communication path information indicating the communication path when data transmission is performed between users.

[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0015] [One Embodiment] (Configuration Example) (1) System FIG. 1 is a diagram showing an example of the configuration of a data distribution system according to one embodiment of the present invention.

[0016] In Fig. 1, NW denotes an international network including a data sharing platform. The data sharing platform is also called a data space, and the data space is managed by a data space management device DSM installed by the data sharing platform operator.

[0017] User terminals UTa, UTb, ..., UTk used by industries, companies or individuals in each country who wish to use the data space are connected to the network NW via connector devices CNa, CNb, ..., CNk, each of which is called a data space connector.

[0018] The network NW also includes telephone communication networks operated by telephone communication carriers in each country. Each telephone communication network is managed by central office devices TEx, TEy, and TEz installed by the respective telephone communication carrier. Each central office device TEx, TEy, and TEz is equipped with a user database SDx, SDy, ..., SDz. The user databases SDx, SDy, ..., SDz securely store and manage user information, such as telephone numbers assigned as subscriber information to users who subscribe to the telephone communication network, linked to identification information (e.g., a corporate number) for verifying the user's identity. The data space administrator is also a subscriber to the telephone communication network in his or her own country, and his or her telephone number is stored in the user database of the telephone communication carrier to which he or she subscribes.

[0019] (2) Devices (2-1) Connector Devices CNa, CNb, . . . , CNk FIGS. 2 and 3 are block diagrams showing examples of the hardware and software configurations of the connector devices CNa, CNb, .

[0020] The connector devices CNa, CNb, ..., CNk are equipped with a control unit 1 that uses a hardware processor such as a central processing unit (CPU), and this control unit 1 is connected via a bus to a storage unit having a program storage unit 2 and a data storage unit 3, an IP communication interface (hereinafter, the interface will be abbreviated as I / F) unit 4, and a telephone communication I / F unit 5.

[0021] The IP communication I / F unit 4 transmits and receives data via the network NW with the connector device that is the destination of the data transmission in accordance with the communication protocol specified in the IP network, and also transmits and receives control information necessary for using the data space with the data space management device DSM.

[0022] The telephone communication I / F unit 5 transmits and receives information necessary for authenticating the connector device of the communication partner, and between the telephone communication carrier's central office devices TEx, TEy, ..., TEz, respectively, via the telephone communication network.

[0023] The program storage unit 2 is configured by combining, for example, a nonvolatile memory such as a solid-state drive (SSD) as a storage medium that can be written to and read from at any time, and a nonvolatile memory such as a read-only memory (ROM), and stores middleware such as an operating system (OS), as well as application programs required to execute various control processes according to an embodiment. Hereinafter, the OS and each application program will be collectively referred to as the program.

[0024] The data storage unit 3 is, for example, a combination of a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium, and a volatile memory such as RAM (Random Access Memory), and has a user management area 31 and a telephone carrier management area 32.

[0025] The user management area 31 is an area managed by the data space operator and the user, and includes a self ID storage unit 311 and a partner ID storage unit 312. The self ID storage unit 311 stores the user's own identification information (self ID) used when transmitting data using the data space. The partner ID storage unit 312 stores the identification information (partner ID) of the partner with whom data is transmitted using the data space.

[0026] The telephone carrier management area 32 includes a telephone number storage unit 321. The telephone number storage unit 32 stores telephone numbers assigned to users as subscriber information by the telephone carriers to which the users subscribe.

[0027] The control unit 1 includes a user registration control processing unit 11, a communication partner registration control processing unit 12, a data transmission control processing unit 13, and an authentication control processing unit 14 as processing functions required to implement one embodiment.

[0028] These processing units 11 to 14 are all realized by causing a hardware processor in the control unit 1 to execute an application program stored in the program storage unit 2. Note that some or all of the processing units 11 to 14 may be realized using hardware such as an LSI (Large Scale Integration) or an ASIC (Application Specific Integrated Circuit).

[0029] The user registration control processing unit 11 executes a process for registering the user's own user information, which is necessary for the user to use the data space as a sender, in the data space management device DSM.

[0030] The communication partner registration control processing unit 12 executes a process for registering user information of a user who is to be a communication partner in its own connector device when the user transmits data using the data space.

[0031] When transmitting data between a communication partner connector device and the data transmission control processing unit 13 using the data space, the data transmission control processing unit 13 establishes a communication link with the communication partner connector device and transmits the data.

[0032] The authentication control processing unit 14 performs an authentication procedure with the communication partner in advance when transmitting data to the communication partner's connector device, and is equipped with a telephone communication control unit 141, a partner ID matching processing unit 142, and a telephone number validity confirmation processing unit 143 as processing functions for this purpose.

[0033] The telephone communication control unit 141 uses the call originating and receiving functions of the telephone communication service to send and receive communication requests and access information to and from the connector device of the other party of the communication.

[0034] When the other party ID matching processing unit 142 receives a communication request from the above-mentioned originating connector device, it compares the user information contained in the communication request with the other party's user information pre-stored in the other party ID storage unit 312 and determines whether there is any matching user information.

[0035] When the telephone number validity confirmation processing unit 143 receives the above-mentioned communication request, it inquires about the validity of the telephone number included in the user information of the requester included in the communication request from the central office equipment of the telephone communication carrier to which both of the above-mentioned communication requesters subscribe.

[0036] Details of the authentication procedure using the telephone communication control unit 141, the other party ID matching processing unit 142, and the telephone number validity confirmation processing unit 143 will be explained in the operation example.

[0037] (2-2) Data Space Management Device DSM FIGS. 4 and 5 are block diagrams showing examples of the hardware and software configurations of the data space management device DSM, respectively.

[0038] Like the connector device, the data space management device DSM also has a control unit 6 that uses a hardware processor such as a central processing unit (CPU). A storage unit having a program storage unit 7 and a data storage unit 8, a telephone communication I / F unit 9, and an IP communication I / F unit 10 are connected to the control unit 6 via a bus.

[0039] The telephone communication I / F unit 9 transmits and receives information for verifying the telephone number of a user between the central office devices TEx, TEy, . . . , TEz of the telephone communication carrier via the telephone communication network.

[0040] The IP communication I / F unit 10 transmits and receives requests for user registration and notifications of registration results between the user's connector devices CNa, CNb, ..., CNk via the IP network, and also transmits and receives requests to confirm communication permission and responses thereto.

[0041] The program storage unit 7 is configured by combining, for example, a nonvolatile memory such as an SSD as a storage medium that can be written to and read from at any time, and a nonvolatile memory such as a ROM, and stores middleware such as an OS as well as application programs required to execute various control processes according to an embodiment. Hereinafter, the OS and each application program will be collectively referred to as the program.

[0042] The data storage unit 8 is, for example, a combination of a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium, and a volatile memory such as RAM, and is equipped with a user information storage unit 81 and a telephone number storage unit 822 as the main storage units required to implement one embodiment.

[0043] The user information storage unit 81 stores the user information of all users who have registered with the data space in association with their telephone numbers.

[0044] The telephone number storage unit 82 stores the telephone number assigned to the data space management device DSM by the telephone carrier to which the data space management device DSM subscribes.

[0045] The control unit 6 includes a user registration reception processing unit 61 and a user-to-user registration relay processing unit 62 as processing functions required to implement an embodiment.

[0046] The processing units 61 and 62 are both realized by causing a hardware processor in the control unit 6 to execute an application program stored in the program storage unit 7. Note that part or all of the processing units 61 and 62 may be realized using hardware such as an LSI or an ASIC.

[0047] When the user registration reception processing unit 61 receives a user registration request from the user's connector devices CNa, CNb, ..., CNk, it requests the station devices TEx, TEy, ..., TEz of the telephone communication carrier to which the requesting user subscribes to verify the user's telephone number via the telephone communication network. Then, when it receives a response to the verification request indicating that the telephone numbers match, it stores the user information of the user in the user information storage unit 81.

[0048] When the user-to-user registration relay processing unit 62 receives a request for permission to communicate from a connector device used by a user on the sending side, it transfers the request to a connector device used by a user on the receiving side. Also, when a response to the request is returned from the connector device used by the user on the receiving side, it transfers the response to the connector device used by the user on the sending side.

[0049] (Example of Operation) Next, an example of operation of the data distribution system configured as above will be described.

[0050] Here, as shown in Figure 6, for example, we will take the case of data transmission via a data space between a sending user A (also called sender A) and a receiving user B (also called receiver B), and explain the process of registering users A and B in the data space management device DSM, the process of registering the communication partner users B and A in their own connector devices DNa and DNb, the process of performing an authentication procedure using telephone numbers with the communication partner users prior to data transmission, and the process of transmitting data between users A and B after authentication.

[0051] (1) Process for registering users A and B in the data space management device DSM (1-1) Registration of user A Figure 7 is a sequence diagram showing an example of the procedure and processing content of the user registration process for user A, which is executed between the connector device CNa used by user A and the data space management device DSM.

[0052] When user A performs a registration request operation for his / her own user registration on the user terminal UTa, in response to the registration request operation, the connector device CNa, under the control of the user registration control processing unit 11, transmits a request for user registration from the IP communication I / F unit 4 to the data space management device DSM. The registration request includes, for example, the corporate number of the company to which user A belongs, which is one of the attribute information of user A, and the telephone number assigned to user A by the telephone carrier as subscriber information. Note that, instead of or in addition to the corporate number, information identifying the industry to which the user belongs, place of residence, etc. may be used as the user attribute information.

[0053] In response to this, when the data space management device DSM receives the request via the IP communication I / F unit 10, under the control of the user registration reception processing unit 61, it first sends a confirmation request for user A from the telephone communication I / F unit 9 to the central office device TEx of the telephone communication carrier to which user A subscribes, based on the corporate number and telephone number of user A contained in the request.

[0054] Upon receiving the confirmation request, the central office device TEx of the telephone carrier checks the telephone number and corporate number of user A included in the confirmation request against the user information stored in the user database SDx to determine whether they match, and then returns the result of the check to the data space management device DSM.

[0055] When the data space management device DSM confirms that the telephone number and corporate number of user A match based on the above judgment result, it issues a connector number to the connector device CNa used by user A under the control of the user registration reception processing unit 61, and generates user information in which the connector number is added to the telephone number and corporate number.The generated user information of user A is then stored in the user information storage unit 81.

[0056] 11 shows an example of user information stored in the user information storage unit 81. In this example, a telephone number, a corporate number, and a connector number are stored in association with the user's name, and information indicating the user's location of use is also stored.

[0057] Upon completing the registration process of the user information, the user registration reception processing unit 61 sends a registration completion notification including the connector number of the connector device CNa and the corporate number of user A from the IP communication I / F unit 10 to the connector device CNa of user A, who sent the request.

[0058] When the connector device CNa receives the registration completion notification, under the control of the user registration control processing unit 11, it stores the corporate number and connector number of user A contained in the received registration completion notification in the self ID memory unit 311.

[0059] In addition, when the data space management device DSM receives a request from the connector device CNa, it may call user A using the telephone number included in the request, and determine the validity of user A's telephone number, i.e., whether the telephone number is alive or dead, based on user A's response to the call.

[0060] (1-2) Registration of User B User B is registered in the same manner as the user A registration process described above.

[0061] FIG. 8 is a sequence diagram showing an example of the procedure and processing contents of the user registration process for user B, which is executed between the connector device CNb used by user B and the data space management device DSM.

[0062] That is, in response to a registration request operation of the user terminal UTb, a request for registration of user B is sent from the connector device CNb to the data space management device DSM via the IP communication network. The corporate number and telephone number of user B are inserted into the registration request.

[0063] In response, when the data space management device DSM receives the registration request via the IP communication I / F unit 10, it sends a confirmation request for user B from the telephone communication I / F unit 9 to the central office device TEz of the telephone communication carrier to which user B subscribes, based on the corporate number and telephone number of user B contained in the registration request.

[0064] The central office device TEz of the telephone carrier checks whether the telephone number and corporate number of User B included in the confirmation request match the user information stored in the user database SDz, and then returns the confirmation result to the data space management device DSM.

[0065] When the data space management device DSM confirms that the telephone number and corporate number of user B match based on the above judgment result, it issues a connector number to the connector device CNb used by user B under the control of the user registration reception processing unit 61, and generates user information in which the connector number is added to the telephone number and corporate number.The generated user information of user B is then stored in the user information storage unit 81.

[0066] In this case, too, as shown in FIG. 11, in addition to the telephone number of user B, the corporate number, and the connector number of the connector device CNb, information indicating the location of use may be stored.

[0067] Upon completing the user information registration process, the data space management device DSM sends a registration completion notification including the connector number of the connector device CNb and the corporate number of user B from the IP communication I / F unit 10 to the connector device CNb of user B, which sent the request.

[0068] When the connector device CNb receives the registration completion notification, the connector device CNb stores the corporate number and connector number of user B included in the received registration completion notification in its own ID storage unit 311 .

[0069] In this case, too, when the data space management device DSM receives a request from the connector device CNb, it may call user B using the telephone number included in the request, and determine the validity of user B's telephone number, i.e., whether the telephone number is alive or dead, based on user B's response to the call.

[0070] (2) Process of registering communication partner users in their own connector devices Prior to data transmission, users A and B perform a process of registering the user information of the user who will be the communication partner of the data transmission in their own connector devices CNa and CNb.

[0071] FIG. 9 is a sequence diagram showing an example of a processing procedure for registering user information of the communication partners between the connector devices DNa and DNb of users A and B. In FIG.

[0072] For example, suppose that user A performs an operation on the user terminal UTa to request permission to communicate with user B in order to transmit data to user B. In this case, the connector device CNa generates a request for permission to communicate under the control of the communication partner registration control processing unit 12, and transmits the generated request to the data space management device DSM from the IP communication I / F unit 4. At this time, the corporate number of user B, who is the communication partner, as well as user A's own telephone number, corporate number, and connector number of the connector device CNa are inserted into the request.

[0073] In response, when the data space management device DSM receives the request via the IP communication I / F unit 10, under the control of the user-to-user registration relay processing unit 62, it identifies user B from the corporate number of the communication destination included in the received request, and transmits request information from the IP communication I / F unit 10 to the connector device CNb of the identified user B. The telephone number of the requesting user A, the corporate number, and the connector number of the connector device CNa are inserted into this request information.

[0074] Upon receiving the request information, user B's connector device CNb, under the control of the communication partner registration control processing unit 12, presents the corporate number of requesting user A, which is included in the received request information, to the user terminal UTb. If user B responds by granting permission, the communication partner registration control processing unit 12 of the connector device CNb stores user A's telephone number, corporate number, and connector device, which are included in the request information, in the partner ID storage unit 312. The communication partner registration control processing unit 12 then returns response information indicating the result of whether or not the communication is permitted to the data space management device DSM. At this time, the response information includes user B's telephone number, corporate number, and connector number, along with user A's telephone number, corporate number, and connector number, only if communication is permitted.

[0075] When the data space management device DSM receives response information from the connector device CNb of user B, under the control of the user-to-user registration relay processing unit 62, it identifies the destination user A based on the telephone number, corporate number, and connector number of user A contained in the response information, and transmits the registration information of user B from the IP communication I / F unit 10 to the connector device CNa of the identified user A.

[0076] When the connector device CNa receives the above registration information, under the control of the communication partner registration control processing unit 12, it stores the telephone number, corporate number, and connector number of the connector device CNb of the destination user B contained in the received registration information in the destination ID memory unit 312.

[0077] (3) Authentication process of the communication partner during data transmission For example, when data is to be transmitted (shared) between user A and user B, authentication process of the communication partner is first executed between user A's connector device DNa and user B's connector device DNb.

[0078] FIG. 10 is a sequence diagram showing an example of the procedure of the authentication process executed between the connector devices DNa and DNb and the procedure of the subsequent data transmission process.

[0079] When an operation to request data transmission to user B is performed on user A's terminal UTa, connector device DNa calls connector device DNb based on the telephone number of user B under the control of telephone communication control unit 141. Then, when a telephone communication link is established with connector device DNb, telephone communication control unit 141 transmits a communication channel opening request (e.g., a data sharing request) to connector device DNb from telephone communication I / F unit 5 via the telephone communication link using, for example, a short mail or a sound signal such as a DTMF (Dual-Tone Multi-Frequency) signal.

[0080] The above-mentioned opening request includes the telephone number and corporate number of user A stored in the self ID memory unit 311, the other party ID memory unit 312, and the telephone number memory unit 321, respectively, the connector number of the connector device DNa used by user A, and the telephone number of the other party, user B.

[0081] In response to this, when the authentication control processing unit 14 of user B's connector device DNb receives the opening request message sent from the originating user A's connector device DNa via the telephone communication I / F unit 5, it first, under the control of the other party ID matching processing unit 142, matches user A's telephone number, corporate number, and connector number contained in the received opening request request with the subscriber information of the communication partner stored in the other party ID memory unit 312, and determines whether the numbers match.

[0082] Next, under the control of the telephone number validity confirmation processing unit 143, the authentication control processing unit 14 transmits the telephone number and corporate number of the sender user A contained in the received activation request from the telephone communication I / F unit 5 to the central office device TEx of the telephone communications carrier to which user A subscribes. In response, the central office device TEx compares the telephone number and corporate number of user A with the user information managed by the user database SDx to confirm the validity of the corresponding telephone number. Then, it returns information indicating the confirmation result (whether or not there is a match) to the connector device DNb that originated the inquiry. Note that the process of confirming the validity of the sender's telephone number does not necessarily have to be performed.

[0083] When user A's identity is confirmed as a result of comparing user A's telephone number, corporate number, and connector number, the authentication control processing unit 14 of connector device DNb first generates authentication information representing a password / encryption key / certificate and its expiration date for accessing the URL (Uniform Resource Locator) where user B's data is stored, and stores the generated authentication information in the other party ID memory unit 312 while linking it to user A.

[0084] Then, the authentication control processing unit 14 generates access information including the above-mentioned access URL and the above-mentioned authentication information for user B's telephone number, corporate number, and connector number, and sends the generated access information to the connector device CNa of the calling user A using short mail or voice from the telephone communication I / F unit 5 under the control of the telephone communication control unit 141.

[0085] Upon receiving the access information, the connector device DNa, under the control of the authentication control processing unit 14, checks whether the telephone number, corporate number, and connector number of user B contained in the received access information are correct by comparing them with the user information of the communication partner stored in the partner ID storage unit 312. If the authentication control processing unit 14 confirms the validity of the received telephone number, corporate number, and connector number of user B through the above check, it notifies the data transmission control processing unit 13 of the confirmation result.

[0086] (4) Data Transmission Processing Once the authenticity of users A and B is confirmed by the above authentication processing, data transmission processing is carried out between user A's connector device DNa and user B's connector device DNb as follows.

[0087] That is, first, in response to an access operation by user A on user terminal TEa, the data transmission control processing unit 13 of connector device DNa generates a data sharing request and transmits the generated data sharing request from the IP communication I / F unit 4 to connector device DNb of user B. The data sharing request includes the access destination URL included in the access information sent from user B, the password / encryption key / certificate for accessing the URL, the type of data to be requested, and the like.

[0088] In response to this, when the data sharing request is received by the IP communication I / F unit 4, the data transmission control processing unit 13 of the connector device DNb of user B compares the password / encryption key / certificate included in the received data sharing request with the authentication information corresponding to user A stored in the partner ID storage unit 312. If the comparison results in a match, the data to be shared that is stored at the URL specified by the data sharing request is read, and the read data to be shared is transmitted from the IP communication I / F unit 4 to the connector device DNa of user A.

[0089] (Effects) As described above, in one embodiment, in a data distribution system in which data is transmitted between users A and B using a data space, connector devices DNa and DNb, which are located between the terminals UTa and UTb of users A and B and the data space management device DSM, store user information for each user A and B who intends to transmit data, including telephone numbers assigned to users A and B by their respective telephone communication carriers. Each connector device DNa and DNb also has a function for making and receiving calls using the telephone numbers. When transmitting data between users A and B, the connector devices DNa and DNb use the function to send and receive user information, including the telephone numbers of the other users B and A, and verify the received user information against the previously stored user information to authenticate the other users A and B.

[0090] In other words, the user information includes the telephone number that is securely managed by the telephone communication carrier for each user, and the above user information is sent and received via the telephone communication network using the call originating and receiving function for telephone communication between the connector devices DNa and DNb, thereby allowing each party to mutually authenticate the other user.

[0091] Therefore, even if a user ID or a connector number is duplicated by someone, authentication is performed using a telephone number that is associated with the user and strictly managed by the telephone communication carrier, so that user spoofing is prevented, thereby realizing highly reliable authentication.

[0092] [Other Embodiments] (1) In one embodiment, when the connector device DNa requests the connector device DNb to open a communication channel, the request includes the telephone number and corporate number of the sender, user A, the connector number of the connector device DNa used by user A, and the telephone number of the destination user, user B. However, communication path information may be inserted in addition to these numbers.

[0093] The communication path information is information representing the communication path exchanged among the central office device TEx of the telephone communication carrier to which user A subscribes, the central office device TEy of the telephone communication carrier to which the data space management device DSM subscribes, and the central office device TEz of the telephone communication carrier to which user B, the communication partner, subscribes, and is configured as shown in FIG. 12, for example.

[0094] The connector device DNa of user A adds the communication path information it uses to a communication channel opening request and transmits it to the connector device DNb of user B. In this way, the connector device DNb that receives the communication channel opening request can confirm, based on the communication path information included in the communication channel opening request, whether user A is communicating from a location declared in advance.

[0095] (2) The telephone numbers used in this invention are not limited to those used for fixed-line telephone services, but may also be those used for mobile telephone services or IP telephone services. In one embodiment, the user and the data space operator use different telephone carriers, but they may use the same telephone carrier. Various existing methods can also be used for telephone number configuration and call origination / reception functions.

[0096] (3) In addition, the functional configuration of the connector device and data space management device, as well as the processing procedures and processing contents thereof, can be modified in various ways without departing from the spirit of the present invention.

[0097] Although the embodiments of the present invention have been described in detail above, the above description is merely an example of the present invention in every respect. It goes without saying that various improvements and modifications can be made without departing from the scope of the present invention. In other words, when implementing the present invention, specific configurations according to the embodiments may be appropriately adopted.

[0098] In short, this invention is not limited to the above-described embodiments, and in the implementation stage, the components can be modified and embodied without departing from the spirit of the invention. Furthermore, various inventions can be formed by appropriately combining multiple components disclosed in the above-described embodiments. For example, some components may be omitted from all the components shown in the embodiments. Furthermore, components from different embodiments may be appropriately combined.

[0099] DSM...data space management device CNa, CNb, CNk...connector device UTa, UTb, UTk...user terminal TEx, TEy, TEz...telephone carrier's central office equipment SDx, SDy, SDz...user database 1, 6...control unit 2, 7...program storage unit 3, 8...data storage unit 4, 10...IP communication I / F unit 5, 9...telephone communication I / F unit 11...user registration control processing unit 12...communication partner registration control processing unit 13...data transmission control processing unit 14...authentication control processing unit 141...telephone communication control unit 142...partner ID matching processing unit 143...telephone number validity confirmation processing unit 31...user management area 311...own ID storage unit 312...partner ID storage unit 32...telephone carrier management area 321...telephone number storage unit 61...user registration acceptance processing unit 62...user-to-user registration relay processing unit 81...user information storage unit 82...Telephone number storage unit

Claims

1. A data distribution system for transmitting data between a plurality of connector devices used by respective users via a data linkage infrastructure, wherein the connector devices and the data linkage infrastructure have telephone communication functions for making and receiving calls using subscriber information assigned by their respective telephone carriers, and each of the plurality of connector devices has: a self-information storage unit that stores its own user information including the subscriber information assigned to its own connector device; and a counterpart information storage unit that stores counterpart user information including the subscriber information assigned to the connector device that is the counterpart of the data transmission, wherein a first connector device that is the requesting party for the data transmission has a processing unit that uses the telephone communication function to transmit communication request information including its own user information stored in its own information storage unit to a second connector device that is the counterpart of the data transmission, and wherein the second connector device has a processing unit that, when receiving the communication request information, compares the user information of the first connector device included in the received communication request information with the user information of the counterpart stored in the counterpart information storage unit to determine the legitimacy of the received user information, A data distribution system comprising: a processing unit that, when it is determined that the received user information is legitimate, sends communication response information including the user information of the second connector device stored in the self-information storage unit to the first connector device using the telephone communication function; and when the first connector device receives the communication response information, a processing unit that, when it receives the communication response information, compares the user information of the second connector device included in the received communication response information with the user information of the second connector device stored in the other party information storage unit to determine the legitimacy of the received user information of the second connector device.

2. The data distribution system of claim 1, wherein each of the plurality of connector devices further comprises a processing unit that transmits a user registration request to the data integration platform, the processing unit including the user's own user information, including subscriber information of the connector device, receives connector identification information assigned to the connector device from the data integration platform in response to the user registration request, and stores the received connector identification information in the self-information storage unit in addition to the user's own user information.

3. The data distribution system described in claim 1, wherein the first connector device comprises a processing unit that transmits a communication permission request including its own user information to the second connector device, and the second connector device comprises a processing unit that, when receiving the communication permission request, determines whether to permit communication based on the user information of the first connector device included in the received communication permission request, a processing unit that stores the received user information of the first connector device in the other party information storage unit if communication is permitted, and a processing unit that transmits a registration request to the first connector device including the user information of the second connector device stored in its own information storage unit, and when receiving the registration request, the first connector device stores the user information of the second connector device included in the received registration request in the other party information storage unit.

4. The data distribution system described in claim 3, further comprising a processing unit that, when receiving the communication permission request, performs call processing using the telephone communication function based on the subscriber information included in the user information of the first connector device included in the received communication permission request, and confirms the validity of the subscriber information based on the result of the call response of the first connector device to the call processing.

5. The data distribution system described in claim 1, wherein the user information includes the subscriber information, the user's attribute information, and connector identification information assigned to the connector device by the data integration platform, and when the second connector device receives the communication request information, it determines the legitimacy of the user information of the first connector device by comparing the subscriber information, the user's attribute information, and the connector identification information contained in the user information of the first connector device included in the received communication request information with the corresponding information contained in the user information stored in the partner information storage unit.

6. The data distribution system described in claim 1, wherein the first connector device uses the telephone communication function to transmit the communication request information, which includes its own user information and information representing the communication path from the first connector device to the second connector device, and the second connector device further comprises a processing unit that confirms the location of the first connector device based on the information representing the communication path included in the received communication request information.

7. A connector device used in a data distribution system that transmits data via a data linkage platform between multiple connector devices used by each user, comprising: a telephone communication control unit that performs telephone communications with other connector devices via telephone communication lines by making and receiving calls using subscriber information assigned by the subscriber's telephone carrier; a self-information storage unit that stores its own user information including the subscriber information; a counterpart information storage unit that stores counterpart user information including the subscriber information assigned to the connector device that is the counterpart of the data transmission; a processing unit that transmits and receives user information including the subscriber information stored in the self-information storage unit between the connector device that is the counterpart of the data transmission via the telephone communication line established by the telephone communication control unit; and a processing unit that compares the received user information with user information including the subscriber information stored in the counterpart information storage unit and determines the legitimacy of the received user information.

8. A user authentication method implemented by a data distribution system in which data is transmitted between multiple connector devices used by each user via a data linkage infrastructure, and the connector devices and the data linkage infrastructure communicate with each other by making and receiving calls using subscriber information assigned by their respective telephone carriers, wherein each of the multiple connector devices stores its own user information, including the subscriber information assigned to its own connector device, in its own information storage unit, and stores the other party's user information, including the subscriber information assigned to the connector device that is the other party in the data transmission, in its other party's information storage unit; a first connector device that requests the data transmission transmits communication request information, including its own user information stored in its own information storage unit, to a second connector device that is the other party in the data transmission by telephone communication using the calling and receiving call; when the second connector device receives the communication request information, it compares the user information of the first connector device included in the received communication request information with the other party's user information stored in its other party's information storage unit to determine the validity of the received user information of the first connector device; and the second connector device: A user authentication method in which, when the received user information of a first connector device is determined to be valid, communication response information including the user information of the second connector device stored in the self-information storage unit is sent to the first connector device using the telephone communication, and when the first connector device receives the communication response information, it compares the user information of the second connector device included in the received communication response information with the user information of the second connector device stored in the other party information storage unit to determine the validity of the received user information of the second connector device.

Citation Information

Patent Citations

  • Server for dial-up connection

    JP2000349926A

  • Authentication system and authentication method of information terminal

    JP2005191830A

  • Authentication method, and network system

    JP2008028709A

  • Communication system, transmission side terminal equipment, and incoming side terminal equipment

    JP2008160212A

  • Information distribution control device, information distribution control method, program, and computer-readable storage medium

    WO2023224076A1