WO2004095301A1 - 端末機器認証システム - Google Patents
端末機器認証システム Download PDFInfo
- Publication number
- WO2004095301A1 WO2004095301A1 PCT/JP2004/005740 JP2004005740W WO2004095301A1 WO 2004095301 A1 WO2004095301 A1 WO 2004095301A1 JP 2004005740 W JP2004005740 W JP 2004005740W WO 2004095301 A1 WO2004095301 A1 WO 2004095301A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- distribution
- server
- authentication
- receiving
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F15/00—Digital computers in general; Data processing equipment in general
Definitions
- the present invention relates to a device authentication system and the like, and in particular, when there are a plurality of authentication servers for authenticating a device, performs authentication with an appropriate authentication server by associating the authentication server for authentication with a device ID in advance.
- a device authentication system and the like and in particular, when there are a plurality of authentication servers for authenticating a device, performs authentication with an appropriate authentication server by associating the authentication server for authentication with a device ID in advance.
- CE Consume r Electron nics
- CE devices include, for example, audio-visual devices such as VCRs, hard disk recorders, stereos, and televisions; personal computers, digital cameras, camcorders, PDAs (Persona 1 Digital Assistant), game machines, home routers, etc. It can be used for services via a network by incorporating a computer into electronic devices, home appliances such as rice cookers and refrigerators, and other electronic devices.
- the user can use the services provided by the server, such as accessing the server from the CE device and downloading the content.
- the services provided by the server include those provided for CE devices in general and those provided for specific CE devices that have been certified.
- the superuser When providing a service that requires device authentication, the superuser authenticates the CE device with the authentication server, and provides the service if the CE device is authenticated.
- FIG. 8 is a diagram showing an example of a configuration of a CE device authentication system 100.
- authentication information information important for security, such as passphrases and device IDs
- passphrases and device IDs information important for security, such as passphrases and device IDs
- a CE device 101 In the authentication system 100, a CE device 101, an authentication server 102, and a service server 103 are provided so as to be connectable to the Internet 104.
- the user can use the service provided by the service server 103 by connecting the CE device 101 to the service server 103.
- the service server 103 transmits the information of the authentication server 102 to the CE device 101 and authenticates the device with the authentication server 102.
- a request is made to the CE device 101, and in response, the CE device 101 receives device authentication at the authentication server 102.
- the service server 103 confirms that the CE device 101 has been authenticated by the authentication server 102 and provides a service to the CE device 101.
- the service server 103 when performing authentication of the CE device 101, since the authentication server 102 was single, the service server 103 requests authentication. It was possible to know which authentication server E device 101 was authenticated with (authentication server 102 in FIG. 8).
- the service server 103 was able to pass information on the authentication server 102 to the CE device 101 when requesting device authentication.
- the service server 103 sends the information of the appropriate authentication server 102 to the CE device 101 to the accessed CE device 101. There is no scheme available. Therefore, there is a problem that the CE device 101 cannot acquire the information of the appropriate authentication server 102.
- Multiple authentication servers 102 are prepared because there are multiple companies that manufacture and sell CE devices 101, and the authentication server 102 is distributed according to the CE device 101 that has accessed it. Is needed. Although it is not a technology related to device authentication of CE devices, there are multiple authentication servers, and the following inventions are available for sorting authentication servers according to the accessing user.
- Japanese Patent Application Laid-Open No. 2002-1970761 is based on whether a user registered with an ISP (Internet Service Provider) is a general user or a specific user. This is to sort the user authentication process.
- ISP Internet Service Provider
- the distribution procedure is as follows.
- the distribution server determines the general specification based on the telephone number, and distributes it to each authentication server.
- the terminal sends the user ID / password to the distribution server.
- the technique described in Japanese Patent Application Laid-Open Publication No. 2000-0-331095 allows an authentication server that issued an ID at the time of user registration to distribute user access when an access from the user is received. It is.
- the distribution procedure is as follows.
- the user sends the user ID and password to the distribution server. Then, the distribution server determines the authentication server that issued the user ID from a predetermined digit of the user ID. Further, the user ID and the password are transmitted to the determined authentication server to authenticate the user.
- an object of the present invention is to provide a device authentication system and the like that can appropriately assign the authentication destinations of CE devices. Disclosure of the invention
- the present invention provides, when providing a service requiring device authentication to a terminal device, transmitting connection information to a first distribution server to the terminal device, and performing authentication from the terminal device.
- a service server that receives the result, a first distribution server that receives the first distribution information from the terminal device, and transmits connection information to the second distribution server corresponding to the first distribution information.
- a second distribution server that receives the second distribution information from the terminal device and transmits connection information to the authentication server corresponding to the second distribution information, and a device that receives the authentication information from the terminal device and An authentication server for authenticating and transmitting an authentication result to the terminal device.
- a terminal device authentication system is provided (first configuration).
- a terminal device using a service provided by a service server in the terminal device authentication system of the first configuration includes a first device for receiving connection information to the first distribution server from the service server.
- Receiving means A first transmission unit that connects to the first distribution server using the connection information received by the first reception unit and transmits the first distribution information; and A second receiving unit that receives connection information to the second distribution server corresponding to the first distribution information; and a connection to the second distribution server using the connection information received by the second reception unit.
- Second transmitting means for transmitting connection information to the authentication server corresponding to the transmitted second distribution information from the second distribution server; and third receiving means for receiving connection information from the second distribution server to the authentication server corresponding to the transmitted second distribution information.
- An authentication information transmitting unit that connects to the authentication server using the connection information received by the third receiving unit and transmits authentication information; and an authentication result based on the authentication information transmitted by the authentication information transmitting unit.
- Authentication result receiving means for receiving from the authentication server, and authentication result transmitting means for transmitting the authentication result received by the authentication result receiving means to the service server (second configuration) .
- the first distribution server that provides the terminal device with the connection information to the second distribution server receives the connection from the terminal device, Receiving means for receiving the first distribution information; and transmission means for transmitting connection information to the second distribution server corresponding to the received first distribution information to the terminal device.
- the present invention when providing a service requiring device authentication to a terminal device, receives distribution information from the terminal device, and receives connection information from the distribution system to an authentication server from the distribution system using the received distribution information.
- a service server that transmits the received connection information to the terminal device, receives an authentication result from the authentication server from the terminal device, receives the distribution information from the service server, and receives the received distribution information.
- the distribution system for transmitting connection information to the service server to be authenticated to the service server, receiving authentication information from the terminal device, performing device authentication of the terminal device, and transmitting the authentication result of the device authentication to the terminal device. It is possible to provide a terminal device authentication system characterized by comprising the above-mentioned authentication server for transmitting and the terminal device (fourth configuration).
- the distribution system for providing the service server with the connection information to the authentication server includes: a distribution information receiving unit that receives the distribution information from the service server; And a connection information transmitting means for transmitting connection information to the authentication server corresponding to the distribution information (fifth configuration).
- a service server that provides service to a terminal device in the terminal device authentication system having the fourth configuration includes: a distribution information receiving unit that receives distribution information from the terminal device; and a distribution device that distributes the received distribution information. Distribution information transmitting means for transmitting to the system; connection information receiving means for receiving connection information to the authentication server corresponding to the transmitted distribution information from the distribution system; and transmitting the received connection information to the terminal device. And connection information transmitting means (sixth configuration).
- the present invention provides the distribution system according to the fifth configuration, wherein the distribution information is composed of first distribution information and second distribution information, and the distribution system is configured to perform the first distribution from a service server. Receiving the information, and transmitting the connection information to the second distribution server corresponding to the first distribution information to the service server; and receiving the second distribution information from the service server. Sends connection information to the authentication server corresponding to the second distribution information to the service server. And a second distribution server to communicate with (a seventh configuration).
- the present invention provides a distribution server receiving first connection information and second distribution information from a terminal device, the service server receiving connection information from the distribution system having the seventh configuration to the authentication server.
- First transmission means for connecting to the first distribution server, transmitting the received first distribution information to the first distribution server, and transmitting the first transmitted information from the first distribution server.
- a first receiving unit for receiving connection information to the second distribution server corresponding to the first distribution information, and a connection information received by the first reception unit for the second distribution server.
- a second transmitting unit that transmits the second distribution information by connecting to the authentication server corresponding to the transmitted second distribution information from the second distribution server.
- Receiving Second receiving means for can constitute the connection information received by the second reception hand stage to include a, a connection information transmitting means for transmitting to said terminal device (eighth configuration).
- a first distribution server that provides a service server with connection information to a second distribution server in a distribution system having a seventh configuration includes a receiving unit that receives the first distribution information from the service server. And a transmission means for transmitting connection information to the second distribution server corresponding to the received first distribution information (a ninth configuration).
- the present invention provides a distribution system having a seventh configuration, wherein the second distribution server that provides the service server with the connection information to the authentication server is a receiving unit that receives the second distribution information from the service server; And a transmission means for transmitting connection information to the authentication server corresponding to the second distribution information described above (10th configuration).
- the present invention is a terminal device method for using a service provided by a service server in a terminal device authentication system of the first configuration by a computer, wherein the computer comprises: a first receiving unit; Means, a second receiving means, a second transmitting means, a third receiving means, an authentication information transmitting means, an authentication result receiving means, and an authentication result transmitting means.
- To server A second receiving step of receiving the second connection information by the second receiving means; and connecting to the second distribution server by using the connection information received in the second receiving step.
- the present invention provides a first distribution method for providing terminal equipment with connection information to a second distribution server in a terminal equipment authentication system having a first configuration, the computer comprising a receiving unit and a transmitting unit.
- the receiver Receiving a connection from a terminal device, receiving a first distribution information from the terminal device, and a second distribution server corresponding to the received first distribution information by the transmission means. And a transmitting step of transmitting connection information to the terminal device to the terminal device.
- the present invention is a distribution method for providing connection information to an authentication server to a service server in a terminal device authentication system having a fourth configuration, wherein the distribution information receiving means, the connection information transmitting means, A distribution information receiving step of receiving distribution information from a service server by the distribution information receiving unit; and a connection information transmitting unit transmitting to the authentication server corresponding to the received distribution information by the connection information transmitting unit. And a connection information transmitting step of transmitting connection information.
- the present invention is a service providing method for providing a service to a terminal device in the terminal device authentication system of the fourth configuration, comprising: a sorting information receiving unit; a sorting information transmitting unit; a connection information receiving unit; A connection information transmitting unit, wherein the distribution information receiving unit receives distribution information from a terminal device, and the distribution information transmitting unit distributes the received distribution information.
- the present invention is a service server method for receiving connection information from a distribution system having a seventh configuration to an authentication server, wherein the distribution information receiving means, a first transmitting means, and a first receiving means are provided.
- the present invention provides a first distribution method for providing connection information to a second distribution server to a service server in a distribution system having a seventh configuration, the computer comprising: a receiving unit; and a transmitting unit.
- a first distribution method comprising: a transmission step of transmitting; and a transmission method.
- the present invention also provides a second distribution method for providing connection information to an authentication server to a service server in a distribution system having a seventh configuration, wherein the computer includes: a receiving unit; and a transmitting unit.
- the present invention provides a terminal device configured by a computer that uses a service provided by a service server in the terminal device authentication system having the first configuration, wherein the terminal device is configured to transmit the service from the service server to the first distribution server.
- the present invention is configured by a computer that provides the terminal device with connection information to the second distribution server in the terminal device authentication system having the first configuration.
- a first distribution server that receives a connection from a terminal device and receives first distribution information from the terminal device; and a connection to a second distribution server corresponding to the received first distribution information. It provides a transmission function that transmits information to the terminal device and a first distribution program that implements the function.
- the present invention provides a terminal device authentication system having a fourth configuration, wherein the distribution system includes a computer that provides a service server with connection information to the authentication server, and receives the distribution information from the service server.
- the distribution system includes a computer that provides a service server with connection information to the authentication server, and receives the distribution information from the service server.
- a distribution program that realizes a distribution information receiving function and a connection information transmission function of transmitting connection information to an authentication server corresponding to the received distribution information.
- the present invention provides a service server configured by a computer which provides services to terminal devices in the terminal device authentication system having the fourth configuration, wherein a distribution information receiving function of receiving distribution information from the terminal devices; A distribution information transmitting function of transmitting the received distribution information to the distribution system, a connection information receiving function of receiving connection information to the authentication server corresponding to the transmitted distribution information from the distribution system, and the received connection information And a service information transmission function for transmitting a connection information to the terminal device.
- the service server receives the first sorting information and the second sorting information from the terminal device.
- a distribution information receiving function a first transmission function for connecting to the first distribution server connected to the first distribution server, and transmitting the received first distribution information to the first distribution server; and A first receiving connection information to the second distribution server corresponding to the transmitted first distribution information
- It provides a connection information transmission function that implements a service server program that implements the service.
- the present invention also provides a first distribution server comprising a computer which provides a service server with connection information to the second distribution server in the distribution system having the seventh configuration, wherein the first distribution information is transmitted from the service server to the first distribution information. And a transmission function of transmitting connection information to the second distribution server corresponding to the received first distribution information.
- the present invention provides a second distribution server comprising a computer which provides a service server with connection information to an authentication server in a distribution system having a seventh configuration, wherein the second distribution server receives the second distribution information from the service server. And a transmission function of transmitting connection information to the authentication server corresponding to the received second distribution information.
- the present invention also provides a computer-readable storage medium storing each of the programs.
- the present invention provides a terminal device according to the second configuration, wherein the connection information storage means for storing connection information to the authentication server received by the third reception means, and the first distribution from the service server.
- Confirmation means for confirming whether or not the connection information is stored in the connection information storage means when connection information to the server is received, wherein the connection information is stored in the confirmation means.
- the authentication information transmitting unit may be configured to connect to the authentication server using the stored connection information and transmit the authentication information (the second embodiment). 1 1 configuration).
- the authentication information transmitting means cannot connect to the authentication server using the connection information stored in the connection information storage means, Based on the connection information received by the receiving unit, the connection information of the authentication server obtained by using the first transmitting unit, the second receiving unit, the second transmitting unit, and the third receiving unit
- the authentication server is connected to the authentication server to transmit authentication information
- the connection information storage unit is configured to update the stored connection information using the acquired connection information to the authentication server. You can also (1st and 2nd configuration).
- the authentication destination of CE apparatus can be apportioned appropriately.
- FIG. 1 is a diagram showing a network configuration of a device authentication system according to the present embodiment.
- FIG. 2 is a diagram showing an example of a logical configuration of the device ID.
- FIG. 3 is a diagram for explaining the relationship between the CE device and each server in the first embodiment.
- FIG. 4 is a flowchart for explaining a procedure in which the service server provides a service requiring authentication in the first embodiment.
- 5A to 5B show an example of a protocol used as a device authentication trigger.
- FIG. 6 is a diagram for explaining the relationship between the CE device and each server in the second embodiment.
- FIG. 7 is a flowchart for explaining a procedure in which the service server provides a service requiring authentication in the second embodiment.
- FIG. 8 is a diagram showing a configuration of a CE device authentication system according to an undisclosed patent document. BEST MODE FOR CARRYING OUT THE INVENTION
- the CE device 3 stores a device ID 13 composed of company information 15 for identifying a company and additional information 16 that can be freely set by the company.
- the service server 10 when providing a service requiring device authentication to the CE device 3, the service server 10 transmits the connection information to the company information distribution server 6 to the CE device 3.
- the CE device 3 transmits the company information 15 to the company information distribution server 6 using the connection information.
- the company information distribution server 6 retrieves the company information 15 with the distribution server table 21 and obtains connection information to the authentication destination distribution server 8.
- company information 15 is associated with an authentication destination distribution server 8 operated for each company. Then, the company information distribution server 6 transmits the obtained connection information to the CE device 3.
- the C E device 3 connects to the authentication destination distribution server 8 operated by the company using the connection information, and transmits the device ID 13.
- the authentication destination distribution server 8 searches for the device ID 13 in the authentication server table 22 and obtains the connection information to the authentication server 9 that is responsible for the authentication of the CE device 3. Get.
- each device ID 13 is associated with an authentication server 9 responsible for authentication of the CE device 3. This is because the CE device 3 of the same company may provide a plurality of authentication servers 9 depending on the CE device 3. Then, the authentication destination distribution server 8 transmits the obtained connection information to the CE device 3.
- the CE device 3 can identify the authentication server 9 that is in charge of the self authentication based on the connection information.
- the CE device 3 connects to the authentication server 9 using the connection information, and transmits authentication information required for device authentication, such as a passphrase and a device ID 13. In response, the authentication server 9 performs device authentication of the CE device 3.
- the CE device 3 inquires of the authentication destination distribution server 8 to be connected to the enterprise information distribution server 6, and further inquires of the authentication server 9 to be connected to the authentication destination distribution server 8. .
- connection destination according to the company information is distributed in the company information distribution server 6, and the device ID 13 is distributed in the authentication destination distribution server 8.
- FIG. 1 is a diagram showing a network configuration of a device authentication system 1 according to the present embodiment.
- Device authentication system 1 includes CE device 3, corporate information distribution server 6, authentication destination distribution server 8a, 8b, 8c, ..., authentication server 9a, 9b, 9 c,..., service server 10, etc. are provided so as to be connectable via Internet 5.
- CE device 3 and one service server 10 are shown in FIG. 1, there are a plurality of these devices.
- enterprise information distribution server 6 in the device authentication system 1.
- authentication destination distribution servers 8a, 8b, 8c, ... are simply referred to as authentication destination distribution servers 8 unless otherwise specified.
- authentication destination distribution servers 8 when no distinction is made between the authentication servers 9a, 9b, 9c,.
- the CE device 3 is, for example, a CE device configured with electric appliances such as a television, a video, a recorder, an audio, a game machine, a PDA, a rice cooker, and an air conditioner.
- electric appliances such as a television, a video, a recorder, an audio, a game machine, a PDA, a rice cooker, and an air conditioner.
- the CE device 3 has a built-in computer with a communication function.
- Various servers service super server 10, corporate information distribution server 6, authentication destination distribution server 8, authentication server 9) are connected via the Internet 5. , And other servers), and constitute terminal equipment.
- the CE device 3 stores a device ID for distinguishing the individual from other CE devices, and the communication destination server identifies the CE device 3 by receiving the device ID from the CE device 3. Can be.
- the device ID is composed of company information indicating the company that manufactures or sells the CE device 3, and additional information that can be freely set by each company.
- the CE device 3 also stores a passphrase for performing device authentication, and is used at the time of device authentication.
- a passphrase is a character string that performs the same function as a password, and a longer one is called a passphrase.
- a passphrase or a password may be used to perform device authentication.
- the service provider 10 is a server on which a service site for providing a service to the CE device 3 is opened.
- the service server 10 transmits contents and provides services to the CE device 3 accessing the service site.
- the user can use the content on the CE device 3, receive a service, or use a service provided by the service server 10.
- the contents provided by the service server 10 include, for example, music contents, travel information contents, movie contents, and recipe contents.
- the services provided by the service server 10 include, for example, personal information including hobbies and preferences, device information of CE devices, provision of information such as Internet connection setting parameters, maintenance of CE devices, and software updates. And so on.
- personal information including hobbies and preferences
- device information of CE devices provision of information such as Internet connection setting parameters, maintenance of CE devices, and software updates.
- online storage services and affinity services can be provided.
- the CE device 3 is a toilet, and it is possible to provide a service in which a user's stool is sensed with a sensor to check a health condition.
- the services provided by the service server 10 include those that can be provided without requiring device authentication and those that require device authentication.
- the service server 10 requests the CE device 3 to connect to the enterprise information distribution server 6.
- the CE device 3 requests a service that requires device authentication
- a service for transmitting music data to a stereo device incorporating the CE device 3 will be described.
- the service server 10 transmits screen data for displaying a selection screen for selecting music to the stereo device.
- the selection screen data is described in a computer language such as, for example, HTML (Hypert ext t Ma rkup Lan gu a ge).
- the stereo apparatus uses the screen data to display a selection screen for selecting music on a display provided in the stereo apparatus.
- songs to be downloaded can be narrowed down in stages, such as music genre, artist name, and song name.
- This refinement operation can be performed without device authentication, and the corresponding screen is displayed each time the user refines.
- the stage of downloading them is set so that device authentication is required. This is realized by embedding a tag in the screen data that notifies the service server 10 that an operation requiring device authentication is going to be performed in response to the down-clicking button displayed on the selection screen. be able to.
- the CE device 3 sends a notification to the service server 10 that device authentication is required, whereas the service server 10 sends the device information to the CE device 3. Sends information that triggers authentication (called device authentication trigger).
- the CE device 3 receives the device authentication trigger from the service server 10 and performs a series of authentication operations.
- Device authentication triggers include The connection information to the information distribution server 6 is included, and the CE device 3 can use this to connect to the enterprise information distribution server 6.
- the company information distribution server 6 is a server that directs the CE device 3 to the authentication destination distribution server 8 to be connected.
- the company information distribution server 6 stores a distribution server table in which the company information and the authentication destination distribution server 8 are associated with each other, receives the company information included in the device ID from the CE device 3, and connects to the authentication destination to be connected.
- the connection information of the distribution server 8 is transmitted to the CE device 3.
- the authentication destination distribution server 8 is provided for each company, and is a server that directs the CE device 3 to the authentication server 9 to be connected.
- the authentication destination distribution server 8 stores an authentication server table in which the device ID and the authentication server 9 are associated with each other, receives the device ID from the CE device 3, and stores the connection information of the authentication server 9 to be connected. Send to CE device 3.
- the authentication server 9 is a server device that performs device authentication of the CE device 3.
- One or more authentication servers 9 are provided for each company.
- the authentication server 9 performs device authentication based on the device ID of the CE device 3 and the passphrase.
- the service sites of the above-mentioned company information distribution server 6, authentication destination distribution server 8, authentication server 9, and service server 10 are URL (Uniform Resource Locators) ⁇ UR I (Unique Resource Source I dentifier) can be specified on the Internet 5.
- connection information exchanged between the CE device 3 and each server includes the URL, the URI, and the like, and the CE device 3 connects to a predetermined server using the information. That is, the connection information is the connection destination of the CE device 3 (such as “http: /Zabc.Z0ny.co.jp”) (company information distribution server 6, authentication destination distribution server 8, authentication server 9, etc.). ) Is included.
- all data transmitted and received by the CE device 3 and each server is encrypted to prevent unauthorized access by third parties.
- the enterprise information distribution server 6 and the authentication destination distribution server 8 constitute the first distribution server and the second distribution server, respectively.
- the connection information to the distribution server 6 is transmitted, the company information distribution server 6 transmits the connection information to the authentication destination distribution server 8, and the authentication destination distribution server 8 transmits the connection information to the authentication server 9.
- FIG. 2 is a diagram showing an example of a logical configuration of the device ID 13 provided in the CE device 3.
- the device ID 13 is composed of company information 15 for identifying a company and ancillary information 16 that can be freely set by each company.
- the ancillary information 16 can include various types of information, such as the serial number of the CE device 3, the type of the CE device 3, and the date of manufacture.
- the serial number of the CE device 3 is an example. Is assumed to be included. With this serial number, the individual CE device 3 can be specified.
- EU I — 64 Extende Unidue Indenetti, 64bit
- IEEE American Electrical and Electronic Engineers Association
- EU I — 64 is a standard for managing CE devices 3 with 64 bits of information.
- the upper 24 bits are called OU I (Organizationa 11y Unique Identifier), which is a code provided by the IEEE to each company (vendor).
- @UI corresponds to company information 15.
- the lower 40 bits other than UI can be freely managed by each company, and correspond to the auxiliary information 16 of the present embodiment.
- the company information 15 constitutes first distribution information used by the company information distribution server 6 to acquire connection information of the authentication destination distribution server 8, and the device ID 13 is The authentication destination distribution server 8 constitutes second distribution information used for acquiring connection information of the authentication server 9.
- 'FIG. 3 is a diagram for explaining the relationship between the CE device 3 and each server.
- Step 1 When the CE device 3 requests the service server 10 for a service requiring device authentication, the service server 10 transmits connection information for connecting to the enterprise information distribution server 6.
- Step 2 The CE device 3 connects to the company information distribution server 6 using the connection information, and transmits the company information 15 to the company information distribution server 6.
- the company information sorting server 6 includes a sorting server 21 that associates each piece of company information 15 with connection information for connecting to the authentication destination sorting server 8.
- the distribution server table 21 links the CE device 3 and the authentication destination distribution server 8 operated by each company.
- the enterprise information distribution server 6 searches the distribution server table 21 using the enterprise information 15 received from the CE device 3 as a key, and transmits the obtained connection information of the authentication destination distribution server 8 to the CE device 3.
- Step 3 The CE device 3 uses the connection information received from the company information distribution server 6 to connect to its own authentication destination distribution server 8 which is responsible for the CE device 3 among the respective authentication destination distribution servers 8. .
- the CE device 3 reads out its own device ID 13 and transmits it to the authentication distribution server 8.
- the authentication destination distribution server 8 includes a device ID 13 and an authentication server table 22 in which connection information of an authentication server 9 responsible for authentication of the CE device 3 is associated.
- each CE device 3 and each authentication server 9 are associated.
- the authentication server 9 is associated with each of the CE devices 3.
- the present invention is not limited to this configuration. Is also good.
- the CE device 3 of the model No. authenticates with the authentication server 9 specified by the connection information 1
- the CE device 3 of the model No. authenticates with the authentication server 9 specified by the connection information 2. It can be said. That is, the association between the CE device 3 and the authentication server 9 can be freely performed by each company.
- the authentication destination distribution server 8 searches the authentication server table 22 using the device ID 13 received from the CE device 3 as a key, and transmits the obtained connection information of the authentication server 9 to the CE device 3.
- Step 4 The CE device 3 receives the connection information to the authentication server 9 from the company information distribution server 6, and uses this to connect to the authentication server 9. So Then, the CE device 3 transmits authentication information necessary for device authentication, such as the passphrase and the device ID 13, to the authentication server 9.
- the authentication server 9 includes an authentication information table 23 in which the device IDs 13 are associated with the authentication information.
- the authentication server 9 compares the authentication information received from the CE device 3 with the authentication information in the authentication information table 23. Perform device authentication. Then, the authentication server 9 transmits the authentication result to the CE device 3.
- Step 5 The CE device 3 transmits the authentication result received from the authentication server 9 to the service server 10 and requests provision of the service.
- the service server 10 receives the authentication result, determines the authentication result of the CE device 3, provides the service to the CE device 3 when the CE device 3 is authenticated by the authentication server 9, and provides the service to the CE device 3 when the CE device 3 is not authenticated. An alarm to that effect is sent to CE device 3, and no service is provided.
- FIG. 4 is a flowchart for explaining a procedure in which the service server 10 provides a service requiring authentication to the CE device 3 in the device authentication system 1.
- CE device 3 and the company information distribution server 6 have the procedures as shown in the flowcharts.
- the CE device 3 requests the service server 10 to provide a service that requires authentication (step 5).
- the service server 10 transmits a device authentication trigger to the CE device 3 and instructs connection to the enterprise information distribution server 6 (step 50).
- the CE device 3 receives the device authentication trigger from the service server 10 (first receiving means) and connects to the company information distribution server 6. Then, the CE device 3 reads the device ID 13 set to itself, acquires the company information 15 from the device ID 13 and sends it to the company information distribution server 6. Yes (first transmission means). Accordingly, the CE device 3 requests the enterprise information distribution server 6 to confirm which authentication destination distribution server 8 should be connected (step 10).
- the enterprise information distribution server 6 receives the enterprise information 15 from the CE device 3 (receiving means), and uses this as a key to transmit connection information to the authentication destination distribution server 8 to which the CE device 3 should connect from the distribution server table 21. Search for. Then, the found connection information is transmitted to the CE device 3 (transmission means) (step 70).
- the C E device 3 receives the connection information from the company information distribution server 6 (second receiving means) and uses this to connect to the authentication destination distribution server 8. Then, the CE device 3 transmits the device ID 13 to the authentication destination distribution server 8 (second transmission means), and requests confirmation of which authentication server 9 to connect to (step 1). Five ) .
- the authentication destination distribution server 8 receives the device ID 13 from the CE device 3 and searches the authentication server table 22 for connection information to the authentication server 9 to which the CE device 3 is to be connected, using the device ID 13 as a key. . Then, the found connection information is transmitted to the CE device 3 (transmission means) (step 80).
- the CE device 3 connects to the authentication server 9 using the connection information for the authentication server 9 received from the authentication destination distribution server 8. Then, the CE device 3 transmits the authentication information to the authentication server 9 (authentication information transmitting means), and receives the authentication result from the authentication server 9 (authentication information receiving means). In this way, the CE device 3 and the authentication server 9 perform a series of device authentication sequences together while communicating (steps 20 and 93).
- This device authentication sequence is performed, for example, by transmitting authentication information such as a device ID 13 and a passphrase to the authentication server 9, and the authentication server 9 confirming this with the authentication information table 23.
- authentication information such as a device ID 13 and a passphrase
- the security of the line connection between the CE device 3 and the authentication server 9 is ensured by using encryption technology such as SSL (Secure Sockets Layer). May be.
- SSL Secure Sockets Layer
- the authentication server 9 transmits an authentication result to the CE device 3 based on the authentication information received from the CE device 3 (step 95). At this time, the authentication server 9 issues a one-time password after the service server 10 to confirm that the CE device 3 has been authenticated by the authentication server 9. Send to 3.
- the authentication server 9 stores the issued one-time password in association with the device ID 13 of the CE device 3 to be issued.
- the CE device 3 transmits the authentication result and the one-time password received from the authentication server 9 to the service server 10 (authentication result transmitting means), and requests provision of a service (step 25). Also in this case, security of the line connection can be enhanced by using an encryption technique such as SSL.
- the service server 10 receives the authentication result, the device ID 13, and the one-time password from the CE device 3.
- the service server 10 transmits the received device ID 13 and the one-time password to the authentication server 9, and checks whether the authentication result received from the CE device 3 is the one issued by the authentication server 9. It requests confirmation from the authentication server 9 (step 55).
- the authentication server 9 receives the device ID 13 of the service supervisor 10 and the one-time password, and the device ID 13 previously associated in step 95. And the one-time password, and confirm that the authentication has been performed by the authentication server 9. Then, the authentication result is transmitted to the service server 10 (step 98).
- the communication between the service server 10 and the authentication server 9 in the above steps 55 and 98 can be enhanced in security by using an encryption technique such as SSL.
- the service server 10 receives the authentication confirmation result from the authentication server 9 and confirms that the authentication result transmitted from the CE device 3 is indeed the one issued by the authentication server 9. If the received authentication result proves the authentication of the CE device 3, provision of service to the CE device 3 is started (step 60).
- the CE device 3 receives the service target such as content from the service server 10 and the user uses it (step 30).
- step 60 if the authentication from the authentication server 9 cannot be confirmed, or if the authentication result received from the CE device 3 does not permit the authentication of the CE device 3, the service server 10 indicates that no service is provided to the CE device 3.
- 5A to 5B show an example of a protocol used as a device authentication trigger.
- Figure 5A shows the protocol used in conventional device authentication.
- Several versions of device authentication are available, and the service used by the service superuser differs depending on the version to be authenticated.
- Device certification version 35 shows this.
- the conventional protocol includes the connection information (URL) to the authentication server, and the CE device 3 uses this to connect to the authentication server.
- FIG. 5B shows an example of a protocol used as a device authentication trigger in the present embodiment.
- This protocol has a primary protocol 41 and a secondary protocol 50.
- the primary information protocol 4 1 is used to connect to the corporate information distribution server 6, but the corporate information distribution server 6 has failed or the corporate information distribution server 6 is congested. If the connection to the information distribution server 6 cannot be established, the secondary company protocol 50 is used to connect to the spare company information distribution server 6. Basically, the primary protocol 41 and the secondary protocol 50 are composed of the same information. '
- the primary protocol 41 includes the URL 42 of the corporate information distribution server 6, the name of the service (distribution service) provided by the corporate information distribution server 6, and the CE device 3 after successful authentication.
- the URL 44 of the site to connect to, the URL 45 of the connection destination to connect to when authentication is not performed, and the device authentication purge 46 are included.
- the primary protocol 41 includes connection information (URL) to the company information distribution server 6, and the CE device 3 uses this to connect to the company information distribution server 6. According to the first embodiment described above, the following effects can be obtained.
- Device authentication destinations can be assigned to each company that controls the authentication of CE devices 3, and can be assigned to individual authentication servers 9 at the assignment destinations.
- the case where the authentication trigger from the service server 10 does not include the connection information to the authentication server 9, that is, the case where the authentication server 9 is not specified, is not limited to this.
- Authentication server 9 specified It is also possible to configure so that the distribution phase is entered only when not performed, and if specified, the distribution is bypassed and the CE device 3 goes directly to the authentication server 9 for authentication.
- the spread of CE equipment 3 is expected, and the equipment authentication system 1 can be adopted as the basic method of the equipment authentication standardization scheme.
- the authentication server 9 for authenticating the CE device 3 has been allocated in the enterprise information distribution server 6 and the authentication destination distribution server 8, but once the enterprise information distribution server 6 and the authentication destination distribution have been performed. If the CE device 3 has obtained the connection information of the authentication server 9 by the server 8, the connection information is stored (connection information storage means), and the CE device 3 distributes the enterprise information distribution server 6 and the authentication destination. The connection to the server 8 may be skipped, the stored connection information of the authentication server 9 may be read, and the connection to the authentication server 9 may be made.
- the CE device In order for the CE device to directly connect to the authentication server 9, it is necessary for the device authentication trigger received from the service server 10 to have information that indicates that the device supports the distribution service.
- the service name 43 in Fig. 5B describes the object ID that identifies the distribution service, for example, D AD P (Device Au thentication Service D iscovery Protocol). There is a need.
- the CE device 3 When the CE device 3 reads out the Object ID that specifies the distribution service in the device authentication trigger, does the CE device 3 have the connection information of the authentication server 9 that authenticates the CE device 3 that was previously distributed by the distribution service? Confirm whether or not (confirmation means). If the CE device 3 already has the connection information of the authentication server 9, the CE device 3 Connect directly to the authentication server 9 for authentication without connecting to the distribution server 8.
- connection information of the authentication server 9 is acquired using the distribution service according to the above-described steps.
- the CE device 3 When the CE device 3 receives the authentication confirmation from the authentication server 9, it caches (updates) the connection information of the authentication server received from the authentication destination distribution server 8.
- the CE device 3 transmits the device ID 13 having the configuration shown in FIG. 2 to the company information distribution server 6, but outputs all the device ID information.
- the company information distribution server 6 may transmit only information on which company the CE device 3 is a CE device manufactured by, ie, only the company information 15.
- the authentication destination distribution server 8 stores only the device type information 16-1.
- the device ID 13 may be transmitted to the authentication server 9 only. Whether to send all the device IDs or only the minimum required is determined as long as the corporate information distribution server 6 and the authentication destination distribution server 8 have enough information to determine the next connection destination. Good.
- the service server 10 and the company information distribution server 6 determine the amount of information required for the device ID by determining the amount of information required by the company information distribution server 6 and the authentication destination distribution server 8, respectively. 3 may be specified.
- the company information distribution server 6 and the authentication destination distribution server It is also possible for the server 8 to inform the CE device 3 of the information amount of the device ID required for connection beforehand.
- the device ID 13 is composed of "1 0 1 0" as the company information 15 and "1 1 0 0 1 1 0 1" as the additional information 16 and only the company information 15 is required
- “1 1 1 1 1 0 0 0 0 0 0 0 0 0” is given as mask information
- "1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0" is transmitted as the logical product of the device ID and the mask information. It may be information.
- the method of specifying a part of the device ID is not limited to this, but may be any form that allows only necessary data to be understood.
- the CE device 3 when the CE device 3 requests the service server 10 to provide a service requiring device authentication, the CE device 3 transmits the device ID 13 to the service server 10.
- the service server 10 extracts the company information 15 from the device ID 13 and sends it to the company information distribution server 6.
- the company information distribution server 6 retrieves the company information 15 with the distribution server table 21 and obtains connection information to the authentication destination distribution server 8. Then, the company information distribution server 6 transmits the acquired connection information to the service server 10.
- the service server 10 uses the connection information to connect to the authentication destination distribution server 8 operated by the CE device 3 company, and transmits the device ID 13.
- the authentication destination distribution server 8 searches for the device ID 13 in the authentication server table 22 and obtains the connection information to the authentication server 9 that is responsible for the authentication of the CE device 3. Get. Then, the authentication destination distribution server 8 transmits the acquired connection information to the service server 10.
- the service server 10 transmits this connection information to the CE device 3.
- the CE device 3 can identify the authentication server 9 that is in charge of the self authentication based on the connection information.
- the C E device 3 connects to the authentication server 9 using the connection information, and transmits authentication information necessary for device authentication, such as a passphrase and device ID 13. In response, the authentication server 9 performs device authentication of the CE device 3.
- the service server 10 specifies the authentication server 9 by the device ID 13.
- the network configuration of this embodiment is the same as that of the first embodiment (FIG. 1).
- the corresponding components will be described with the same reference numerals.
- the device ID used by the CE device 3 of the present embodiment is the same as that shown in FIG.
- FIG. 6 is a diagram for explaining the relationship between the CE device 3 and each server constituting the device authentication system 1.
- Step 1 CE device 3 requests service server 10 for a service that requires device authentication. Then, it reads out its own device ID 13 in response to the request and sends it to the service server 10.
- Step 2 The service server 10 receives the device ID 13 from the CE device 3, extracts the company information 15 from the device ID 13 and sends it to the company information distribution server 6.
- the company information distribution server 6 includes a distribution server table 21 in which each of the company information 15 and the connection information for connecting to the authentication destination distribution server 8 are associated with each other as in the first embodiment. According to the distribution server table 21, the CE device 3 and the authentication destination distribution server 8 operated by each company are linked.
- the company information distribution server 6 searches the distribution server table 21 using the company information 15 received from the service server 10 as a key, and obtains the connection information of the authentication destination distribution server 8 obtained as a result, and the service server 10 Send to.
- Step 3 The service server 10 uses the connection information received from the company information distribution server 6 to connect to the authentication destination distribution server 8 that is in charge of the CE device 3 among the authentication destination distribution servers 8.
- the service server 10 transmits the device ID 13 received from the CE device 3 to the authentication destination distribution server 8.
- the authentication destination distribution server 8 includes an authentication service 22 that associates the device ID 13 with the connection information of the authentication server 9 that is responsible for authentication of the CE device 3. I have.
- each CE device 3 and each authentication server 9 are associated.
- the authentication destination distribution server 8 searches the authentication server table 22 using the device ID 13 received from the CE device 3 as a key, and transmits the connection information of the authentication server 9 obtained as a result to the service server 10. .
- Step 4 The service server 10 receives the connection information to the authentication server 9 starting from the authentication of the CE device 3 from the authentication destination distribution server 8, and transmits this to the CE device 3.
- Step 5 The CE device 3 receives the connection information from the service server 10 to the authentication server 9, and uses this to connect to the authentication server 9. Then, the CE device 3 transmits authentication information necessary for device authentication, such as a passphrase and device ID 13, to the authentication server 9.
- the authentication server 9 includes an authentication information table 23 in which the device ID 13 and the authentication information are associated with each other, as in the first embodiment, and stores the authentication information received from the CE device 3 and the authentication information table 23. Perform device authentication by comparing authentication information. Then, the authentication server 9 transmits the authentication result to the CE device 3. Step 6: The CE device 3 sends the authentication result received from the authentication server 9 to the service server 10 and requests provision of the service.
- the service server 10 receives the authentication result, determines the authentication result of the CE device 3, provides the service to the CE device 3 when the CE device 3 is authenticated by the authentication server 9, and provides the service to the CE device 3 when the CE device 3 is not authenticated. An alarm to that effect is sent to CE device 3, and no service is provided.
- the company information distribution server 6 (first distribution server) and the authentication destination distribution server 8 (second distribution server) are combined and viewed as a distribution system that transmits the connection information of the distribution destination to the CE device 3. be able to.
- the distribution system includes a distribution information receiving unit that receives distribution information (device ID 13 and company information 15) from the service server 10 and a connection that transmits connection information (URL) to the authentication server 9. It has information transmission means.
- this sorting system can be realized by one sorting server having both the functions of the company information sorting server 6 and the authentication destination sorting server 8.
- the service server 10 is a CE device.
- the enterprise information distribution server 6 first distribution server
- the connection information to the authentication destination distribution server 8 (second distribution server) is transmitted to the service server 10, and the authentication destination distribution server 8 receives the second distribution information (device ID 13) from the service server 10. Is received, and connection information to the authentication server 9 is transmitted.
- FIG. 7 is a flowchart for explaining a procedure in which the service server 10 provides a service requiring authentication to the CE device 3 in the device authentication system 1 according to the second embodiment.
- the service server 10, the company information distribution server 6, and the authentication destination distribution server 8 have respective procedures as shown in the flowcharts.
- the CE device 3 requests the service server 10 to provide a service that requires authentication (step 105).
- the service server 10 transmits a device authentication trigger to the CE device 3 and requests transmission of the device ID 13 to the service server 10 (step 130).
- the CE device 3 receives the device authentication trigger from the service server 10, reads out its own device ID 13, and transmits it to the service server 10 (step 110).
- the service server 10 receives the device ID 13 from the CE device 3 (distribution information receiving means). Then, the service server 10 extracts the company information 15 from the device ID 13 and sends it to the company information distribution server 6 (first transmission means) (step 135).
- the service server 10 requests the enterprise information distribution server 6 to confirm which authentication destination distribution server 8 the CE device 3 should connect to.
- the company information distribution server 6 receives the company information 15 from the service server 10 (reception means), and uses this as a key to connect from the distribution server table 21 to the authentication destination distribution server 8 to which the CE device 3 should connect. Search for information.
- the searched connection information is transmitted to the service server 10 (transmission means) (step 160).
- the service server 10 receives the connection information from the company information distribution server 6 (first receiving means), and uses this to connect to the authentication destination distribution server 8. Then, the service server 10 transmits the device ID 13 received from the CE device 3 to the authentication destination distribution server 8 (second transmitting means), and determines to which authentication server 9 the CE device 3 should connect. Request confirmation (step 140).
- the authentication destination distribution server 8 receives the device ID 13 from the service server 10 (receiving means), and uses this as a key to connect the authentication server 9 to the authentication server 9 from the authentication server table 22. Search for connection information to. Then, the found connection information is transmitted to the service server 10 (transmission means) (step 170).
- the service server 10 receives the connection information from the authentication destination distribution server 8 to the authentication server 9 (second receiving means) and transmits this to the CE device 3 (connection information transmitting means).
- the service server 10 The device authentication trigger, which is information for instructing the device 3 to receive device authentication by the authentication server 9, is also transmitted to the CE device 3 (step 144).
- the CE device 3 connects to the authentication server 9 using the connection information to the authentication server 9 received from the service server 10 and performs a series of device authentication sequences together with the authentication server 9 (steps 1 15 and 15). Step 180).
- This device authentication sequence is performed, for example, by transmitting authentication information such as the device ID 13 and a passphrase to the authentication server 9, and the authentication server 9 confirming this with the authentication information table 23.
- the authentication server 9 sends an authentication result to the CE device 3 based on the authentication information received from the CE device 3 (step 1885). At this time, the authentication server 9 issues a one-time password that the service server 10 later confirms that the CE device 3 has been authenticated by the authentication server 9 later. Send.
- the authentication server 9 stores the issued one-time password in association with the device ID 13 of the CE device 3 to be issued.
- the CE device 3 transmits the authentication result and the one-time password received from the authentication server 9 to the service server 10 and requests provision of a service (step 120). Also in this case, security of the line connection can be enhanced by using an encryption technique such as SSL.
- the service server 10 receives the authentication result, the device ID 13, and the one-time password from the CE device 3.
- the service server 10 sends the received device ID 13 and the one-time passcode to the authentication server 9 and checks whether the authentication result received from the CE device 3 is the one issued by the authentication server 9. A request is made to the authentication server 9 (step 150).
- the authentication server 9 receives the device ID 13 and the one-time password from the service server 10 and verifies the device ID 13 and the one-time password previously associated in step 18 5 with the authentication server 9. Confirm that 9 is the authentication performed. Then, the authentication confirmation result is transmitted to the service server 10 (step 190).
- the communication between the service server 10 and the authentication server 9 in the above steps 150 and 190 can increase the security by using an encryption technique such as SSL ′.
- the service server 10 receives the authentication confirmation result from the authentication server 9 and confirms that the authentication result transmitted from the CE device 3 is indeed the one issued by the authentication server 9. If the received authentication result proves the authentication of the CE device 3, the provision of the service to the CE device 3 is started (step 1555).
- the CE device 3 receives the service target such as contents from the service server 10 and the user uses it (step 125).
- the server 10 does not provide a service to the CE device 3.
- the CE device 3 When requesting a service requiring device authentication from the service server 10, the CE device 3 sends the device ID 13 to the service server 10, and the connection information from the service server 10 to the authentication server 9. To receive. Since this operation performed by the CE device 3 is similar to that of the conventional device authentication system, a conventional product can be used as the CE device 3.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computing Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Transfer Between Computers (AREA)
- Computer And Data Communications (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
Claims
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
EP04728680A EP1626347A1 (en) | 2003-04-21 | 2004-04-21 | Terminal device authentication system |
US10/518,990 US20060036858A1 (en) | 2003-04-21 | 2004-04-21 | Terminal device authentication system |
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2003115754 | 2003-04-21 | ||
JP2003-115754 | 2003-04-21 | ||
JP2004095272A JP2004342088A (ja) | 2003-04-21 | 2004-03-29 | 端末機器認証システム、端末機器、第1の振り分けサーバ、振り分けシステム、サービスサーバ、第2の振り分けサーバ、端末機器方法、第1の振り分け方法、振り分け方法、サービス提供方法、サービスサーバ方法、第1の振り分け方法、第2の振り分け方法、端末機器プログラム、第1の振り分けプログラム、振り分けプログラム、サービスサーバプログラム、第2の振り分けプログラム、及び記憶媒体 |
JP2004-095272 | 2004-03-29 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2004095301A1 true WO2004095301A1 (ja) | 2004-11-04 |
Family
ID=33312610
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/JP2004/005740 WO2004095301A1 (ja) | 2003-04-21 | 2004-04-21 | 端末機器認証システム |
Country Status (6)
Country | Link |
---|---|
US (1) | US20060036858A1 (ja) |
EP (1) | EP1626347A1 (ja) |
JP (1) | JP2004342088A (ja) |
KR (1) | KR20060003318A (ja) |
TW (1) | TW200428850A (ja) |
WO (1) | WO2004095301A1 (ja) |
Families Citing this family (21)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7734929B2 (en) * | 2004-04-30 | 2010-06-08 | Hewlett-Packard Development Company, L.P. | Authorization method |
US7814216B2 (en) * | 2004-09-07 | 2010-10-12 | Route 1 Inc. | System and method for accessing host computer via remote computer |
US20090089435A1 (en) * | 2005-04-01 | 2009-04-02 | Stephen Terrill | Method for initiating IMS based communications |
CA2607562C (en) | 2005-05-06 | 2016-07-12 | Verisign, Inc. | Token sharing system and method |
SE532098C2 (sv) * | 2005-08-23 | 2009-10-20 | Smarttrust Ab | Autenticeringssystem och -förfarande |
JP4235676B2 (ja) * | 2005-12-09 | 2009-03-11 | 日立ソフトウエアエンジニアリング株式会社 | 認証システム及び認証方法 |
KR100755025B1 (ko) * | 2006-02-27 | 2007-09-06 | (주)유브릿지 | 무선데이터 통신인증시스템 |
US20080242405A1 (en) * | 2007-03-30 | 2008-10-02 | Microsoft Corporation | On-line gaming authentication |
JP5444639B2 (ja) * | 2007-11-20 | 2014-03-19 | パナソニック株式会社 | サーバ装置と分散サーバシステム |
US20090183246A1 (en) * | 2008-01-15 | 2009-07-16 | Authlogic Inc. | Universal multi-factor authentication |
JP5153591B2 (ja) * | 2008-11-26 | 2013-02-27 | 株式会社日立製作所 | 認証仲介サーバ、プログラム、認証システム及び選択方法 |
JP5161053B2 (ja) * | 2008-12-11 | 2013-03-13 | 日本電信電話株式会社 | ユーザ認証方法、ユーザ認証システム、サービス提供装置、及び認証制御装置 |
JP2010157012A (ja) * | 2008-12-26 | 2010-07-15 | Nippon Telegr & Teleph Corp <Ntt> | 認証システム、ユーザ端末接続サーバ装置、ユーザ端末装置、これらのプログラム |
US9253168B2 (en) * | 2012-04-26 | 2016-02-02 | Fitbit, Inc. | Secure pairing of devices via pairing facilitator-intermediary device |
CN103428696B (zh) * | 2012-05-22 | 2017-04-19 | 中兴通讯股份有限公司 | 实现虚拟sim卡的方法、系统及相关设备 |
US8843741B2 (en) * | 2012-10-26 | 2014-09-23 | Cloudpath Networks, Inc. | System and method for providing a certificate for network access |
DE102013108925A1 (de) * | 2013-08-19 | 2015-02-19 | Deutsche Post Ag | Unterstützung der Nutzung eines geheimen Schlüssels |
CN105099692B (zh) * | 2014-05-22 | 2020-01-14 | 创新先进技术有限公司 | 安全校验方法、装置、服务器及终端 |
CN105577624B (zh) | 2014-10-17 | 2019-09-10 | 阿里巴巴集团控股有限公司 | 客户端交互方法与客户端以及服务器 |
CN109286932B (zh) | 2017-07-20 | 2021-10-19 | 阿里巴巴集团控股有限公司 | 入网认证方法、装置及系统 |
KR102015700B1 (ko) * | 2017-08-23 | 2019-08-28 | 에스케이 주식회사 | 블록체인 기반 one ID 서비스 시스템 및 방법 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2002073556A (ja) * | 2000-08-25 | 2002-03-12 | Nippon Telegr & Teleph Corp <Ntt> | 認証システム |
JP2002082911A (ja) * | 2000-09-11 | 2002-03-22 | Nec Corp | 認証システム |
JP2002207649A (ja) * | 2001-01-04 | 2002-07-26 | Nec Corp | インターネット負荷分散中継接続方式 |
JP2002259606A (ja) * | 2001-02-28 | 2002-09-13 | Internatl Business Mach Corp <Ibm> | プログラム使用許諾期間の更新方法、プログラムの使用許諾方法、情報処理システムおよびプログラム |
Family Cites Families (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
ATE407503T1 (de) * | 1999-07-02 | 2008-09-15 | Nokia Corp | Authentifizierungsverfahren und system |
EP1120945A1 (de) * | 2000-01-27 | 2001-08-01 | TELEFONAKTIEBOLAGET LM ERICSSON (publ) | Zuordnung einer Serveradresse zu einem Endgerät |
US6915272B1 (en) * | 2000-02-23 | 2005-07-05 | Nokia Corporation | System and method of secure payment and delivery of goods and services |
JP4617533B2 (ja) * | 2000-03-14 | 2011-01-26 | ソニー株式会社 | 情報提供装置および方法、情報処理装置および方法、並びにプログラム格納媒体 |
US7185360B1 (en) * | 2000-08-01 | 2007-02-27 | Hereuare Communications, Inc. | System for distributed network authentication and access control |
JP3634742B2 (ja) * | 2000-11-15 | 2005-03-30 | 三洋電機株式会社 | 配信システムおよび携帯電話機 |
US20020091645A1 (en) * | 2000-12-20 | 2002-07-11 | Kagemoto Tohyama | Software licensing system |
JP2003101570A (ja) * | 2001-09-21 | 2003-04-04 | Sony Corp | 通信処理システム、通信処理方法、およびサーバー装置、並びにコンピュータ・プログラム |
JP4449288B2 (ja) * | 2001-10-31 | 2010-04-14 | ヤマハ株式会社 | 認証方法およびその装置 |
AU2002232187A1 (en) * | 2002-02-14 | 2003-09-04 | Shimada, Kennichi | Authenticating method |
US7024177B2 (en) * | 2002-03-14 | 2006-04-04 | Openwave Systems Inc. | Method and apparatus for authenticating users of mobile devices |
-
2004
- 2004-03-29 JP JP2004095272A patent/JP2004342088A/ja not_active Abandoned
- 2004-04-16 TW TW093110767A patent/TW200428850A/zh unknown
- 2004-04-21 WO PCT/JP2004/005740 patent/WO2004095301A1/ja not_active Application Discontinuation
- 2004-04-21 KR KR1020047019913A patent/KR20060003318A/ko not_active Application Discontinuation
- 2004-04-21 EP EP04728680A patent/EP1626347A1/en not_active Withdrawn
- 2004-04-21 US US10/518,990 patent/US20060036858A1/en not_active Abandoned
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2002073556A (ja) * | 2000-08-25 | 2002-03-12 | Nippon Telegr & Teleph Corp <Ntt> | 認証システム |
JP2002082911A (ja) * | 2000-09-11 | 2002-03-22 | Nec Corp | 認証システム |
JP2002207649A (ja) * | 2001-01-04 | 2002-07-26 | Nec Corp | インターネット負荷分散中継接続方式 |
JP2002259606A (ja) * | 2001-02-28 | 2002-09-13 | Internatl Business Mach Corp <Ibm> | プログラム使用許諾期間の更新方法、プログラムの使用許諾方法、情報処理システムおよびプログラム |
Also Published As
Publication number | Publication date |
---|---|
KR20060003318A (ko) | 2006-01-10 |
EP1626347A1 (en) | 2006-02-15 |
JP2004342088A (ja) | 2004-12-02 |
US20060036858A1 (en) | 2006-02-16 |
TW200428850A (en) | 2004-12-16 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2004095301A1 (ja) | 端末機器認証システム | |
JP4413774B2 (ja) | 電子メールアドレスとハードウェア情報とを利用したユーザ認証方法及びシステム | |
US7260720B2 (en) | Device authentication system and method for determining whether a plurality of devices belong to a group | |
JP5346025B2 (ja) | 保安署名方法、保安認証方法及びiptvシステム | |
JP5065305B2 (ja) | データ伝送制御方法、コンテンツ伝送制御方法、コンテンツ処理情報獲得方法及びコンテンツ伝送システム | |
US8543707B2 (en) | Data transfer controlling method, content transfer controlling method, content processing information acquisition method and content transfer system | |
JP4800377B2 (ja) | 認証システム、ce機器、携帯端末、鍵証明発行局および鍵証明取得方法 | |
US9973487B2 (en) | Authentication method | |
WO2014164034A1 (en) | Online personalization update system for externally acquired keys | |
CN102597981A (zh) | 模块化装置认证框架 | |
US20040205201A1 (en) | System, apparatus, method and program for processing information | |
WO2006025308A1 (ja) | コンテンツ購入処理端末とその方法、及びプログラム | |
CN103765843A (zh) | 混合终端机的用户验证方法及实现该方法的装置 | |
WO2004097659A1 (ja) | 端末機器、提供サーバ、電子情報利用方法、電子情報提供方法、端末機器プログラム、提供サーバプログラム、仲介プログラム、及び記憶媒体 | |
JP2003198544A (ja) | 機器認証システムおよび機器認証方法 | |
KR20180135232A (ko) | 전자장치, 전자장치의 제어방법 및 시스템 | |
JP6319006B2 (ja) | 認証サービス方法、認証サービスサーバ、及び認証サービスシステム | |
WO2009110156A1 (ja) | コンテンツ配布システム及びコンテンツ配布方法 | |
JP2004355396A (ja) | 情報機器用セキュリティ確保方法およびシステム、ならびに情報機器用セキュリティ確保プログラム | |
WO2023080075A1 (ja) | Nft発行方法、コンピュータ、及びプログラム | |
JP2009282718A (ja) | 表示領域管理装置、方法、プログラム、及びシステム | |
JP5299152B2 (ja) | 通信システム、通信方法、及び設定管理サーバ | |
JP3496482B2 (ja) | 通信ネットワークにおけるファイル識別方法及びシステム及び通信ネットワークにおけるファイル識別プログラムを格納した記憶媒体 | |
JP6572172B2 (ja) | 関係データ作成装置、関係データ作成方法、および、関係データ作成プログラム | |
JP2011018128A (ja) | Avコンテンツ配信システム、avコンテンツ再生端末、プログラム及び記録媒体 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW |
|
AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): BW GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2004728680 Country of ref document: EP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 1020047019913 Country of ref document: KR |
|
WWE | Wipo information: entry into national phase |
Ref document number: 20048003875 Country of ref document: CN |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
ENP | Entry into the national phase |
Ref document number: 2006036858 Country of ref document: US Kind code of ref document: A1 |
|
WWE | Wipo information: entry into national phase |
Ref document number: 10518990 Country of ref document: US |
|
WWP | Wipo information: published in national office |
Ref document number: 1020047019913 Country of ref document: KR |
|
WWP | Wipo information: published in national office |
Ref document number: 2004728680 Country of ref document: EP |
|
WWP | Wipo information: published in national office |
Ref document number: 10518990 Country of ref document: US |
|
WWW | Wipo information: withdrawn in national office |
Ref document number: 2004728680 Country of ref document: EP |