Service vertification system, vertification require terminal, service operating terminal and providing method
Abstract
The invention claims a service providing method for providing service and a server b to the service can be used to perform a authentication request of terminal of the user authentication and the operation of the related service a the certification under the condition of judging whether the user can use server b. When judging to the server b when memory using permission message and to the authentication request terminal sends based on service b the use permit information in response to using permission. And then validates the service usage terminal transmits the using requirement message of according to the use permit response if it is can be used in the state of the service using terminal can be used in the state of server b. By using the related service a the certification result is no necessary to the server b is equipped with a new authentication part so as to make the cost is reduced.
Term
Term ended
Expired 16 October 2023, 2.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
20 claims: 4 independent, 16 dependent
- 1First 第 1. A service verification system, which provides multiple services, is characterized by:an authentication information storage component that stores authentication information for authenticating users who can use the first service;and an authentication information storage component that stores information about the services that can be used by each user Usable service information storage component;when the use of a second service different from the first service is permitted, a use permission message information storage component that stores message information based on a use permission message identifying the use permission;receiving according to the first The first message receiving component of the message of the authentication mode of the service;verify the message received by the first message receiving component according to the authentication information stored in the authentication information storage component, and thereby specify the first services The user and the authentication component that authenticates whether the user can use the first service;receiving other service use requirement receiving components that are sent by the user who is authenticated by the authentication component as being able to use the first service and the use requirements of the second service;When the other service use request receiving component receives the use request, it determines whether the user can use the other service use determination component of the second service according to the information of the usable service information storage component;When the other service use availability determination unit determines that the second service can be used, the use permission message information storage unit enables the use permission based on the use permission message identifying the use permission of the second service. Message information update component;When it is determined by the other service availability determination component that the second service can be used, the L usage permission response sending component of the usage permission response based on the usage permission message is sent to the authentication request terminal;receiving the sending from the service user terminal A second message receiving component based on the use permission response message;1. 一种服务验证系统,提供多种服务,其特征在于:包括: 存储了用于认证能使用第一服务的用户的认证信息的认证信息 存储部件; 存储了有关各用户能使用的服务的信息的可使用服务信息存储 部件; 当许可使用与所述第一服务不同的第二服务时,存储基于识别 该使用许可的使用许可消息的消息信息的使用许可消息信息存储部 件; 接收按照所述第一服务的认证方式的消息的第一消息接收部 件; 根据存储在所述认证信息存储部件中的认证信息来验证由所述 第一消息接收部件接收的消息,据此来特定所述第一服务的用户并且 认证所述用户是否能使用第一服务的认证部件; 接收由被所述认证部件认证为能使用第一服务的用户发送的第 二服务的使用要求的其他服务使用要求接收部件; 当由所述其他服务使用要求接收部件接收了所述使用要求时, 根据所述可使用服务信息存储部件的信息来判定所述用户是否能使用 所述第二服务的其他服务使用可否判定部件; 当由所述其他服务使用可否判定部件判定为能使用所述第二服 务时,在所述使用许可消息信息存储部件中使基于识别第二服务的使 用许可的使用许可消息的消息信息可以使用的使用许可消息信息更新 部件; 当由所述其他服务使用可否判定部件判定为能使用所述第二服 务时,向认证要求终端发送基于所述使用许可消息的使用许可响应的L 使用许可响应发送部件; 接收从服务使用终端发送的、基于所述使用许可响应的消息的 第二消息接收部件; 200310102605.3 The first service provision determination component that determines whether the second service can be provided to the service user terminal based on the message received by the second message receiving component and the message information stored in the use permission message information storage component And when it is determined by the service provision availability determination component that the second service can be provided, the use of the second service is permitted, and the use of the message information stored in the use permission message information storage component is in an unusable state License message status release component. 200310102605.3 第 根据由所述第二消息接收部件接收的消息和存储在所述使用许 可消息信息存储部件中的消息信息,来判定能否向所述服务使用终端 提供第二服务的服务提供可否判定部件;和 当由所述服务提供可否判定部件判定为能提供第二服务时,许 可第二服务的使用,并使存储在所述使用许可消息信息存储部件中的 消息信息处于不能使用的状态的使用许可消息状态解除部件。
- 89. An authentication request terminal capable of using a first service provided by a service verification system and performing authentication for using the first service, characterized in that it includes:an authentication information storage unit storing authentication information for using the first service ;According to the authentication information stored in the authentication information storage component, the first message sending component that sends a message according to the authentication method to the service verification system;when the service verification system determines that the first service can be used, send Another service use request sending component required by the use of the second service;and a use permission response receiving component that receives the use permission response based on the use permission message sent by the service verification system. 9. 一种认证要求终端,能使用由服务验证系统提供的第一服 务,并且进行为了使用第一服务的认证,其特征在于:包括: 存储了用于使用第一服务的认证信息的认证信息存储部件; 根据存储在认证信息存储部件中的认证信息,来向所述服务验 证系统发送根据认证方式的消息的第一消息发送部件; 当通过所述服务验证系统判定为能使用第一服务时,发送第二 服务的使用要求的其他服务使用要求发送部件;和 接收由所述服务验证系统发送的、基于使用许可消息的使用许 可响应的使用许可响应接收部件。
- 1112. A service user terminal accepts the provision of a second service according to a response sent to an authentication request terminal in order to use the second service, characterized in that it includes:sending a message for using the second service to the service verification system The second message sending component;the message is based on the use permission response received by the authentication request terminal from the service verification system. 12. 一种服务使用终端,根据为了使用第二服务而向认证要求 终端发送的响应,来接受第二服务的提供,其特征在于: 包括向所述服务验证系统发送用于使用第二服务的消息的第二 消息发送部件; 所述消息基于所述认证要求终端从所述服务验证系统接收的使 用许可响应。
- 1314. A service provision method includes a service verification system that provides multiple services, an authentication request terminal that is authenticated by the service verification system and uses the first service provided by the service verification system, and sends a request to the service verification system to use the second service. The authentication requires the terminal to send a response to use the second service provided by the service verification system to use the terminals server to verify the service provided in the network system, and is characterized in that it includes:the authentication requires the terminal to send the authentication according to the authentication information The first message sending step received by the service verification system;verify the message received in the first message sending step according to the authentication information pre-stored in the service verification system, and specify the The authentication step of authenticating the user who requires the terminal and authenticating whether the user can use the first service;when the first service can be used, the authentication requires the terminal to send the use requirement of the second service to other services sent by the service verification system Use request sending step;when the use request is received in the other service use request sending step, the service verification system determines whether the user can use the service according to the information pre-stored in the service verification system The step of determining whether to use other services of the second service;when it is determined that the second service can be used in the step of determining whether to use the other service, store the information based on second The use permission message information update step of the use permission message of the use permission message of the service use permission;when it is determined that the second service can be used in the other service use permission determination step, the service verification system authenticates The terminal is required to send a use permission response based on the use permission message in the use permission response sending step;the service user terminal sends to the service verification system the use permission response based on the authentication request terminal received in the use permission response sending step The second message sending step of the message;according to the message received in the second message receiving step and the message stored in the using 14. 一种服务提供方法,在具有提供多种服务的服务验证系 统、由所述服务验证系统认证并且使用由所述服务验证系统提供的第 一服务的认证要求终端、和为了使用第二服务而向认证要求终端发送 的响应,来使用由所述服务验证系统提供的第二服务的服务使用终端 的服务器验证网络系统中提供服务,其特征在于:包括: 所述认证要求终端根据认证信息发送符合认证方式的消息,来 使所述服务验证系统接收的第一消息发送步骤; 根据预先存储在所述服务验证系统中的认证信息来验证第一消 息发送步骤中接收的消息,据此来特定所述认证要求终端的用户并且 认证所述用户是否能使用第一服务的认证步骤; 当能使用第一服务时,所述认证要求终端把第二服务的使用要 求向所述服务验证系统发送的其他服务使用要求发送步骤; 当在所述其他服务使用要求发送步骤中接收了所述使用要求 时,所述服务验证系统根据预先存储在所述服务验证系统中的信息, 来判定所述用户是否能使用所述第二服务的其他服务使用可否判定步 骤; 当在所述其他服务使用可否判定步骤中判定为能使用所述第二 服务时,在所述使用许可消息信息存储部件中存储基于用来识别第二 服务的使用许可的使用许可消息的消息信息的使用许可消息信息更新 步骤; 当在所述其他服务使用可否判定步骤中判定为能使用所述第二 服务时,所述服务验证系统向所述认证要求终端发送基于使用许可消 息的使用许可响应的使用许可响应发送步骤; 所述服务使用终端向所述服务验证系统发送基于所述认证要求 终端在所述使用许可响应发送步骤中接收的使用许可响应的消息的第 二消息发送步骤; 根据在所述第二消息接收步骤中接收的消息和存储在所述使用 200310102605.3 The message information in the storage component of the permission message status is used to determine whether the second service can be provided to the service user terminal to determine whether the second service can be provided;when it is determined that the second service can be provided through the service provision determination step , The use permission message state release step of permitting the use of the second service, and making the message information stored in the use permission message information storage component in an unusable state. 200310102605.3 第 许可消息状态存储部件中的消息信息,来判定能否向所述服务使用终 端提供第二服务的服务提供可否判定步骤; 当通过所述服务提供可否判定步骤判定为能提供第二服务时, 许可第二服务的使用,使存储在所述使用许可消息信息存储部件中的 消息信息处于不能使用的状态的使用许可消息状态解除步骤。
Independent claims4
167 paragraphs, as filed
Technical Field The present invention relates to a service verification system (system) that provides multiple services (servis), the service verification system verifies and uses the services provided by the service verification system The authentication request terminal, the service use terminal and the service providing method that use the service provided by the service verification system according to the authentication result of the authentication request terminal.
BACKGROUND ART Conventionally, systems that provide services to mobile phones or PHS in mobile communications and the like have been known. In order to use such services, it is necessary to sign a contract with the company that provides the service. Most of the companies that provide services only provide services to users who have signed a service contract (regular users), and do not provide services to users who have not signed a contract. Therefore, a way to allow only regular users to use the service is necessary, and such a way has been implemented.
At present, in the service verification system that provides services, the customer information for managing regular users is used, and the customer information is used to verify whether the user requesting the service is a regular user, and the control method that allows the use of the service only when the verification result is correct. In order to allow only regular users to use the service, it is necessary to construct such a system.
Non-Patent Document 1-Bruce Schneier,<sup>M</sup>APPLIED CRYPTOGRAPHY^^, John Wiley &Sons, Inc., 1996, pp.52-56 Non-Patent Document 2-"NTT Docomo Technical Journal (Technical Journal) Vol.9 No.4", (Co., Ltd.) Electrical Communications Association, 2002 January, pp.34-43.
Non-Patent Document 3-Keiji Tachikawa, "W-CDMA MOBILE COMMUNICATIONS SYSTEM, John Wiley & Sons, Ltd, 2002, pp.345-356. However, in the above-mentioned system, when a company that provides a certain service has to provide other services
200310102605.3 In the first task, it is necessary to construct a system from the very beginning that only connects the contractor, that is, regular users, so it takes a lot of cost and design time. In addition, in order to prevent service suspension caused by failures, etc., the system needs to be maintained and managed, but there is a tendency that the larger the system, the greater the management cost. In these respects, the above-mentioned system has room for further improvement.
SUMMARY OF THE INVENTION In view of the above problems, the purpose of the present invention is to provide a service verification system, a certification request terminal, a service user terminal, and a service providing method that can suppress the increase in cost.
In order to achieve the above object, the present invention provides a service verification system that provides a variety of services, including: an authentication information storage component that stores authentication information for authenticating users who can use the first service; A usable service information storage component for the information of the used service; when a second service different from the first service is permitted to be used, a use permission message information storage component that stores message information based on a use permission message identifying the use permission; The first message receiving component that receives the message according to the authentication method of the first service; verifies the message received by the first message receiving component according to the authentication information stored in the authentication information storage component, and specifies accordingly The user of the first service and the authentication component that authenticates whether the user can use the first service; receive the use of other services that require the use of the second service sent by the user who is authenticated by the authentication component as being able to use the first service Request receiving component; when the other service use request receiving component receives the use request, it determines whether the user can use the other service use of the second service according to the information of the usable service information storage component Whether the second service can be used is determined by the other service use availability determining means, the use permission message information storage means uses a message based on the use permission message identifying the use permission of the second service Information update department of the use permission message that the information can be used When it is determined by the other service availability determination component that the second service can be used, the use permission response sending component based on the use permission response of the use permission message is sent to the authentication request terminal; Sent based on the license
200310102605.3 The second message receiving component of the first respondable message; according to the message received by the second message receiving component and the message information stored in the use permission message information storage component, it is determined whether the service can be used The terminal provides the second service availability determination component; and when it is determined by the service availability determination component that the second service can be provided, the use of the second service is permitted and stored in the use permission message information storage component The use permission message status release component whose message information is in an unusable state.
Preferably, the service verification system further includes additional information storage means for storing additional information for verifying a message that is also based on additional information used for using the second service; in the second message receiving part, it also receives A message based on additional information; in the service provision availability determination component, it is also determined whether the second service can be provided to the service user terminal based on the additional information stored in the additional information storage component.
Preferably, the service verification system further includes: an area information storage unit that stores usable area information about the area where the second service can be used; and when the usage request is received through the other service usage request receiving unit, The area information update part that derives the usable area information from the information about the circled area of the authentication-requiring terminal, and stores the usable area information in the area information storage part; the service provision availability determination part It is also determined whether the circled area of the service user terminal is within the area derived from the available area information stored in the area information storage unit, and if it is within the area, it is determined that the second service can be provided.
More preferably, the area information update component is based on the message information stored in the usable message information storage component, when the use permission response sent to the authentication requesting terminal can be used, in the presence of the authentication requesting terminal When the circle area moves outside the usable area identified by the area information storage means, the usable area information derived from the information about the circle area after the authentication request terminal has moved is stored in the area Information storage component.
More preferably, the area information update component is based on the message information stored in the usable message information storage component, when the use permission response sent to the authentication requesting terminal can be used, in the presence of the authentication requesting terminal If the area is moved outside the usable area identified by the area information storage means, if the other service is used
200310102605.3 When the first use request receiving component receives the use request, it stores in the area information storage component the usable area information derived from the information about the circled area after the authentication request terminal has moved.
Preferably, the service verification system further includes: a time information storage unit that stores usable time information about the time when the second service can be used; and when the use request is received through the other service use request receiving unit , The time information update part that stores the usable time information about the time when the second service can be used in the time information storage part; the service provision availability determination part is based on the time information stored in the time information storage part The available time information is used to determine whether the time when the message is received by the second message receiving component is included in the time when the service can be used, and when the time when the message is received is included in the time when the second service can be used, it is determined To be able to provide a second service.
More preferably, the use permission response sending component sends the use permission response based on the usable area information derived from the information about the circled area of the authentication request terminal; the service provision determination component also determines Whether the circled area of the service user terminal is in the area that can be derived from the message received from the second message receiving component, and if it is in the area, it is determined that the second service can be provided.
More preferably, the use permission response sending component sends the use permission response that is also based on usable time information about the time when the second service can be used; the service provision availability determination component also determines that the second service Whether the time when the message receiving component receives the message is included in the time that can be derived from the message received by the second message receiving component, when the time when the information is received is included in the time indicated by the available time information, It is judged to be able to provide the second service.
In addition, the present invention provides an authentication request terminal that can use the first service provided by the service verification system and perform authentication for using the first service, which includes: authentication information storing authentication information for using the first service Storage component; a first message sending component that sends a message according to the authentication method to the service verification system according to the authentication information stored in the authentication information storage component; when the service verification system determines that the first service can be used , Send other service use request sending components of the second service use request; and receive the use based on the use permission message sent by the service verification system
200310102605.3 The license response receiving part of the license response.
More preferably, the use permission response receiving component receives a use permission response that is also based on the usable area information of the second service.
More preferably, the use permission response receiving component receives a use permission response that is also based on the available time information of the second service.
In addition, the present invention provides a service using terminal, which accepts the provision of a second service based on a response sent to the authentication request terminal in order to use the second service, which includes sending to the service verification system information for using the second service. The second message sending component of the message; the message is based on the use permission response received by the authentication request terminal from the service verification system.
Preferably, the service using terminal further includes an additional information storage unit that stores additional information used to use the second service; the message sent by the second information transmission unit is also based on the additional information stored in the additional information Additional information in the storage component.
In addition, the present invention provides a service provision method that has a service verification system that provides a variety of services, a terminal that is certified by the service verification system and uses the first service provided by the service verification system, and is required to use The second service sends a response to the authentication requesting terminal to use the service of the second service provided by the service verification system to use the terminals server to verify the service provided in the network system, including: the authentication requesting terminal sends a response based on the authentication information. The message in the authentication mode is used to enable the first message sending step received by the service verification system; the message received in the first message sending step is verified according to the authentication information pre-stored in the service verification system, and the message received in the first message sending step is verified accordingly. Said authentication requires the user of the terminal and the authentication step of authenticating whether the user can use the first service; when the first service can be used, the authentication requires the terminal to send the request for the use of the second service to other services sent by the service verification system The service use request sending step; when the use request is received in the other service use request sending step, the service verification system determines whether the user can Step for determining whether to use other services using the second service; when it is determined that the second service can be used in the step for determining whether to use the other service, store the use permission message information storage component based on Identify the use license of the second service license
200310102605.3 The use permission message information update step of the message information of the first message; when it is determined that the second service can be used in the other service use determination step, the service verification system sends to the authentication request terminal the use-based The use permission response sending step of the use permission response of the permission message; the service user terminal sends to the service verification system the second part of the message based on the use permission response received by the authentication request terminal in the use permission response sending step Message sending step; determining whether to provide the second service to the service user terminal according to the message received in the second message receiving step and the message information stored in the use permission message state storage component Whether it is possible to determine step; when the second service can be provided through the service provision determination step, the use of the second service is permitted, so that the message information stored in the use permission message information storage component is in an unusable state Use permission message status release procedure.
More preferably, in the second message receiving step, a message based on additional information is also received; in the service provision availability judging unit, the additional information stored in the additional information storage unit is also used to verify that it is in the first The message received in the second message receiving step determines whether the second service can be used in the service user terminal.
More preferably, the service provision method includes: when the use request is received in the step of sending the other service use request, deriving the usable area information from the information about the circled area of the authentication request terminal, To store the usable area information in the area information storage unit; the service provision determination step also determines whether the area of the service using terminal is stored in the area information storage unit Within the area indicated by the usable area information in, if it is within the area, it is determined that the second service can be provided.
More preferably, when the use permission response sent to the authentication requesting terminal can be used based on the message information stored in the usable message information storage component, when the authentication requesting terminal's in-circle area is moved to the area where the authentication requesting terminal is located. When the information storage means determines that the usable area is outside, in the region information update step, the usable area information derived from the information about the circled area after the movement is stored in the area information storage means.
More preferably, when the use permission response sent to the authentication request terminal can be used based on the message information stored in the usable message information storage component, when the
200310102605.3 When the area of the authentication requesting terminal moves outside the usable area identified by the area information storage component, if the authentication requesting terminal sends the second service usage request in the other service usage request sending step, then In the area information updating step, the usable area information derived from the information about the circled area after the movement is stored in the area information storage means.
More preferably, the service providing method includes: when the use request is received in the other service use request sending step, storing the available time information that can use the second service in a time information storage component In the step of determining whether the service can be provided, based on the available time information stored in the time information storage component, it is also determined whether the time when the message is received by the second message receiving component is included in the availability During the service use time, when the time of receiving the message is included in the time when the second service can be used, it is determined that the second service can be provided.
More preferably, in the use permission response sending step, the use permission response that is also based on the usable area information derived from the information about the circled area of the authentication request terminal is sent; whether the service can be provided In the determining step, it is also determined whether the circled area of the service user terminal is within the area that can be derived from the message received from the second message receiving component, and if it is within the area, it is determined that the second service can be provided.
More preferably, in the use permission response sending step, the use permission response that is also based on the available time information of the second service is sent; in the service provision determination step, it is also determined that the second service can be used or not. In the second message sending step, whether the time when the service verification system receives the message is included in the time that can be derived from the message received from the second message receiving component, when the time when the message is received is included in the available time information Within the indicated time, it is determined that the second service can be provided.
In addition, the service verification system of the present invention provides a variety of services, and is characterized in that it includes: an authentication information storage unit that stores authentication information for authenticating users who can use the first service; and stores information about the services that can be used by each user. Information storage component for the usable service information of the information; when the use of a second service different from the first service is permitted, a use permission message information storage component that stores message information based on the use permission message identifying the use permission; The first message receiving component of the message in the authentication mode of the terminal; according to
200310102605.3 The authentication information stored in the authentication information storage unit is used to verify the message received by the first message receiving unit, based on which the user of the first terminal is specified and whether the user can use the first service The authentication component; the other service usage request receiving component that receives the second service usage request sent by the first terminal that is authenticated to be able to use the first service by the authentication component; when the other service usage request receiving component When the usage request is received, it is determined whether the user can use the other service availability determining component of the second service based on the information of the available service information storage component; when the other service availability determining component is used by the other service When it is determined that the second service can be used, in the use permission message information storage component, a use permission message information update component that enables use of the message information based on the use permission message identifying the use permission of the second service; When the other service use availability determination component determines that the second service can be used, it sends a usage permission response sending component based on the usage permission response of the usage permission message to the first terminal; and receives, The second message receiving part based on the message of the use permission response; determining whether to send the message to the use permission message information storage part according to the message received by the second message receiving part and the message information stored in the use permission message information storage part First The second service is provided by the terminal providing the second service availability determination component; and when the service availability determination component determines that the second service can be provided, the use of the second service is permitted, and the information stored in the use permission message is stored The use permission message status release component whose message information in the component is in an unusable state.
More preferably, the service verification system of the present invention includes: an authentication information storage component that stores authentication information for authenticating users who can use the first service; an available service information storage that stores information about services that can be used by each user Component; when a second service different from the first service is permitted to be used, a use permission message information storage component that stores the message information used to restore the use permission message (message) identifying the use permission; storage indicates whether the message information can be used Use permission of message status information: message status storage component; a first message receiving component that receives a message according to the authentication method of the first terminal; verifying the message received by the first message receiving component according to the authentication information stored in the authentication information storage component , Specify the user of the first terminal, and verify whether the user can use the authentication component of the first service; receive the authentication component from the first terminal that is authenticated by the authentication component as being able to use the first service
200310102605.3 The other service use request receiving component required by the use of the second service; when the use request is received by the other service use request receiving component, it is determined whether the user can use other services of the second service based on the information of the usable service information storage component Service use availability determination component; when another service availability determination component determines that the second service can be used, the use permission message information storage component stores message information for restoring the use permission message identifying the use permission of the second service, and The usage permission message status storage component stores the usage permission message status update component that indicates the status of the message information that can be used; when it is determined by the other service availability determination component that the second service can be used, it sends a message to the first terminal based on The use permission response sending part of the use permission response of the use permission message; the second message receiving part that receives the message based on the use permission response sent from the second terminal; verify according to the message status information stored in the use permission message status storage part Whether the message received by the second message receiving component can be used, and based on the message information stored in the use permission message information storage component, verify whether the matching of the message can be obtained, and determine whether the second terminal can be provided with the service provision of the second service Whether the component can be determined; when the component determines that the second service can be provided by the service provider, the use of the second service is permitted, and the use of the second service is permitted. The message status information of the permission message status storage component is the unusable status of the use permission message status, which is interpreted as the component.
In this way, the service verification system of the present invention has an authentication system. If a message that complies with the terminal's authentication method is sent from the first terminal, the user of the first terminal is specified based on the message, and whether the first terminal can use the first service is authenticated. . Moreover, in the state where the user who has passed the authentication and authenticated the first terminal as a regular user, if the other service use request receiving component receives the second service use request sent from the first terminal, the other service use availability determination component is based on the use The service information storage component determines whether the user can use the second service. According to such a configuration, it is determined whether the second service can be used in a state where the user who has authenticated the first terminal is a regular user, so the authentication result of the first service is used, and authentication can be omitted for the second service. When the result of the determination is that it is determined that the second service can be used, the message information for restoring the use permission message identifying the use permission is stored in the use permission message information storage part, the message status information for the use permission message information is stored, and the The first terminal sends a use permission response based on the use permission message. and,
200310102605.3 First, when a message based on a use permission message is sent from the second terminal, the message is received by the second message receiving component, and the storage component verifies whether the use permission message according to the message is in a usable state according to the storage component of the use permission message state, and according to the storage In the message information in the use permission message information storage component, verify whether the use permission message is correctly formed, and when the use permission message is in a usable state, and when the use permission message itself is correctly formed, the second terminal is provided with the second terminal Two services. In this way, when it is determined by the service verification system that the second service can be used, by sending a use permission response based on the use permission message to the first terminal, the second terminal sends the message based on the use permission message received by the first terminal to the service verification system. If the service verification system verifies whether the use permission message on which the message sent from the second terminal is based is in a usable state, it can determine whether the service can be provided to the second terminal without determining the user of the second terminal. As described above, when the second service is used, by using the verification result of the first service, there is no need to construct a new authentication component from the beginning when the second service is provided, which can reduce cost and design time. The method for letting the second terminal know the use permission response received by the first terminal may be any method. For example, it can be sent from the first terminal to the second terminal through short-range wireless, or it can be a user who observes the first terminal to the second terminal. Enter manually. It should be pointed out that the first terminal and the second terminal can be the same terminal. In this case, the use permission response can be communicated within the terminal, which is very good.
The service verification system is characterized by further comprising: additional information storage means for storing additional information for verifying a message based on the additional information used to use the second service; in the second message receiving part, it also receives additional information based on the additional information. For informational messages, in the service provision availability judging component (that is, the service provision judging component), based on the additional information stored in the additional information storage component, the message received by the second message receiving component is verified, and it is determined whether it can be sent to the second message receiving component. The second terminal provides the second service.
By using the additional information in this way, security can be improved and the second service can be provided more securely. As additional information, for example, identification information for identifying the second terminal and authentication information for authenticating the second terminal are considered.
The service verification system is characterized in that it includes: an area information storage component that stores usable area information about an area (area) where the second service can be used; The first terminal is in the circle
200310102605.3 The available area information is derived from the information of the first domain, and the area information update part that stores the available area information in the area information storage part; the service provision availability determination part determines whether the second terminals in-circle area is from the area information stored in the area information If it is within the area where the usable area information in the storage component is derived, it is determined that the second service can be provided.
When the request for the use of the second service is received in this way, the area information in which the second service can be used is derived from the circled area of the first terminal and stored as the available area information in the area information storage unit. When sending a message, according to the area information storage component, it is determined whether the circled area of the second terminal is within the usable area, and whether the second service can be provided, and the second service is only used in the permitted area to reduce the chance of illegal use. Can improve safety.
The service verification system is characterized in that: when the area information update part is available, it sends it to the first place based on the message information stored in the usable message information storage part and the message information stored in the use permission message information storage part. In response to the use permission of the terminal, when the circled area of the first terminal moves outside the usable area identified by the area information storage component, the usable area derived from the information about the circled area after the first terminal has moved The area information is stored in the area information storage part.
When the first terminal authenticated in this way moves in the circled area, the area information update part is used to update the usable area information stored in the area information storage part, which can also correspond to the situation when the user moves.
The service verification system is characterized in that: the area information update component sends to the first terminal based on the message information stored in the usable message information storage component and the message information stored in the use permission message information storage component. In response to the use permission, when the first terminals in-circle area moves outside the required area identified by the area information storage component, if the use request is received through the other service use request receiving component, it will be stored in the area information storage component. Usable area information derived from the information of the surrounding area after the first terminal moves.
After the first terminal authenticated in this way moves in the circle area, it can derive the usable area information from the circle area of the first terminal that has received other service use requirements through the other service use request receiving component, which can also correspond to the situation when the user moves. .
200310102605.3 The service verification system is characterized in that it also includes: time information storage means for storing usable time information about the time when the second service can be used; when the use request is received through other service use request receiving means, the relevant The available time information of the time when the second service can be used is stored in the time information updating part; the service provision availability determination part determines that the second message receiving part is based on the available time information stored in the time information storage part When the time of receiving the message is included in the time when the service can be used, and the time of receiving the message is included in the time when the second service can be used, it is determined that the second service can be provided.
In this way, by storing the time when the second service can be used as the available time information in the time information storage, when the information is sent from the second terminal, it is determined whether the receiving time of the information is included in the available time of the second service , The structure to determine whether the second service can be provided, the second service can only be used within the permitted time, which reduces the chance of illegal use and improves security. It should be noted that the method of setting the time when the second service can be used can be set to a few minutes from the time when the use permission response is sent to the first terminal, and can be set according to the type of the second service.
The service verification system is characterized in that: the use permission response sending part sends a use permission response that is also based on the usable area information derived from the information on the circled area of the first terminal, and the service provision availability determining part determines the second terminals Whether the circle area is within the area that can be derived from the message received from the second message receiving component, and if it is within the area, it is determined that the second service can be provided.
By adopting that when the use request for the second service is received in this way, the area information in which the second service can be used is derived from the circled area of the first terminal, and a use permission response based on the useable area information is sent to the first terminal. When a message is sent from the second terminal, it is determined whether the second terminal is included in the usable area on which the message is based, and the structure of determining whether the second service can be provided can only provide the second service in the permitted area, which can reduce illegality Use opportunities, improve security, and the service verification system can become a structure that does not store information about the usable area.
The service verification system is characterized in that: the use permission response sending component sends a use permission response that is also based on usable time information about the time when the second service can be used, and
200310102605.3 The first service provision availability determination component determines whether the time when the message is received by the second message receiving component is included in the time that can be derived from the message received from the second message receiving component, when the time when the message is received is included in the available time information Within the time period, it is determined that the second service can be provided.
In this way, by using the first terminal to send a usage permission response based on the time when the second service can be used as the available time information, when a message is sent from the second terminal, it is determined whether the receiving time of the message is included in the message The structure that determines whether the second service can be provided within the available time on which it is based can provide the second service only within the permitted time, which can reduce the chance of illegal use, improve security, and the service verification system can become a non-storage related The structure of the available time information.
The authentication of the present invention requires the terminal to be able to use the first service provided by the service verification system and perform authentication for the provision of using the first service, and is characterized in that it includes: authentication for storing authentication information for using the first service Information storage component; according to the authentication information stored in the authentication information storage component, the first message sending component that sends a message according to the authentication method to the service verification system; when the service verification system determines that the first service can be used, it sends the second Other service use request sending components required by the service use; use permission response receiving component that receives the use permission response based on the use permission message sent by the service verification system.
In this way, by sending a message based on the authentication information for using the first service to the service verification system, a request for the use of the second service is sent in the state of being authenticated as a regular user by the service verification system, and the second service can be used for the second service. The authentication result of a service, the authentication is omitted. Furthermore, the authentication requires that the terminal has a use permission response receiving part to receive the use permission response based on the use permission message. Moreover, if the second terminal (service use device) is made aware of the use permission response, the second terminal sends a message based on the use permission response to the service verification system, and the service verification system can verify whether the use permission message on which the message is based is In the usable state, the second service can be used even if the second terminal is not independently authenticated. It should be pointed out that the authentication requires that the terminal itself can have the function of the second terminal. At this time, you can enjoy the advantage of being able to omit authentication when using the second service.
In the authentication request terminal, it is characterized in that: use permission response receiving means
200310102605.3 The first received a license response based on the useable area information of the second service.
The use permission response receiving component receives the use permission response that is also based on the usable area information, and sends a message based on the use permission response to the service verification system. The service verification system can determine whether the second terminal is included in the usability based on the message. within the area. Accordingly, by limiting the usable area of the second service, the chance of illegal use can be reduced, and the security can be improved.
In the authentication request terminal, it is characterized in that the use permission response receiving part receives a use permission response that is also based on the available time information of the second service.
The use permission response receiving component receives the use permission response that is also based on the available time information, and sends a message based on the use permission response to the service verification system. The service verification system can determine whether the message from the second terminal is received at the time the message is based on Available time. Accordingly, by limiting the available time of the second service, the chance of illegal use can be reduced, and the security can be improved.
The service user terminal of the present invention accepts the provision of the second service based on the response sent to the authentication request terminal in order to use the second service, and is characterized in that it includes a second service that sends a message for using the second service to the service verification system. The message sending component; the message is based on the authorization request that the terminal receives the use permission response from the service verification system.
In this way, by sending a message based on the use permission response received by the authentication request terminal to the service verification system, the service verification system can determine whether the use permission message on which the sent message is based is in a usable state, so the user can be omitted in the service use terminal The certification can use the second service.
The service using terminal is characterized in that it further includes: an additional information storage unit that stores additional information used for using the second service, and the message sent by the second information transmission unit is also based on the additional information stored in the additional information storage unit. information.
In this way, by using additional information, it is possible to improve the reliability and provide the second service more safely. As additional information, it is considered that the identification information of the terminal for identifying the service user, the authentication information for authenticating the terminal of the service user, and the like are considered.
The service providing method of the present invention has a service verification system that provides multiple services, is authenticated by the service verification system, and uses the first service provided by the service verification system.
200310102605.3 The authentication request terminal of the first service uses the service of the second service provided by the service verification system based on the response sent to the authentication request terminal in order to use the second service. It is characterized in that it includes: the authentication requires the terminal to send a message conforming to the authentication mode according to the authentication information, and the first message sending step received by the service verification system; the evidence is stored in the service verification system in advance The authentication information for verifying the message received in the first message sending step, the authentication step of specifying the user of the authentication requesting terminal, and verifying whether the user can use the first service; when the first service can be used, the authentication The other service usage requirement sending step that requires the terminal to send the usage requirement of the second service to the service verification system; when the usage requirement is received in the other service usage requirement sending step, the service verification system is stored in advance according to The information in the service verification system is used to determine whether the user can use other services of the second service to determine whether the user can use the second service; when it is determined in the other service availability determining step that the second service can be used, The use permission message information update step based on the message information of the use permission message used to identify the use permission of the second service is stored in the use permission message information storage component; When it is determined in the negative determination step that the second service can be used, the service verification system sends a use permission response based on a use permission message, so that the authentication request terminal receives the use permission response sending step; the service user terminal sends In the use permission response sending step, based on the use permission response message received by the authentication request terminal method, the service verification system receives the second message sending step; according to the second message receiving step received in the second message receiving step And the message information stored in the use permission message information storage component to determine whether the second service can be provided to the service user terminal to determine whether the service can be provided or not; when the service provision can be determined as being able to be provided through the service provision determination step When the second service is provided, the use of the second service is permitted, so that the message information stored in the use permission message information storage component is a use permission message state cancellation component that is in a non-use state.
In this way, the service providing method of the present invention specifies the user of the authentication requesting terminal based on the message sent from the authentication requesting terminal that complies with the authentication method of the authentication requesting terminal, and verifies whether the authentication requesting terminal can use the first service in the authentication step. Moreover, in the authentication step, the user who authenticated the authentication request terminal is a regular user, in other services
200310102605.3 In the first use request sending step, if the second service use request sent from the authentication request terminal is received, in the other service use determination step, it is determined whether the user can use the second service based on the use of the service information storage component . According to this configuration, by determining whether the second service can be used in a state where the user who has authenticated the authentication request terminal is a regular user, the authentication result of the first service can be used, and authentication is omitted for the second service. When the result of the determination is that the second service can be used, the message information for restoring the use permission message identifying the use permission is stored in the use permission message information storage part, and the storage means that the use permission message identifying the use permission is in a usable state. Message status information, and send a license response to the authentication requesting terminal. Then, in the second message sending step, when the use request based on the use permission response is sent from the service user terminal, the use request is received, and the use permission message state storage component verifies whether the use permission message on which the message is based is enabled. The status of use is verified based on the message information stored in the use permission message information storage component to verify whether the use permission message is correctly constituted. When the use permission message is in a usable state and it is determined that the use permission message itself is correctly constituted, The service user terminal provides the second service. In this way, when it is determined that the second service can be used, it includes The use permission response of the use permission message is sent to the authentication request terminal, and the service user terminal sends a message based on the use permission response received by the authentication request terminal to the service verification system. If the service verification system determines that the message sent in the second message sending step is Whether the status of the basis of the use permission message is a usable state, the user who does not need to determine the service user terminal can determine whether the service can be provided to the service user terminal. As described above, when using the second service, by using the authentication result of the first service, it is not necessary to construct a new authentication component from the beginning when providing the second service, which can reduce the cost and system design time. The method of letting the service user terminal know the use permission response received by the authentication request terminal may be any method. For example, the authentication request terminal can be sent to the service user terminal via short-range wireless transmission, or the user who observes the authentication request terminal can manually input the service user terminal. It should be pointed out that the authentication requires that the terminal and the service user terminal can be the same terminal. In this case, the use permission response can be communicated within the terminal, so it is good.
The service providing method is characterized in that: in the second message receiving step, a message based on additional information is also received, and the service provision can be determined according to the stored information.
200310102605.3 The additional information in the additional information storage component verifies the message received by the second message receiving step, and determines whether the second service can be used at the service user terminal.
By using the additional information in this way, security can be improved, and the second service can be provided more safely. As additional information, for example, identification information for identifying a terminal using a service and authentication information for authenticating a terminal using a service are considered.
The service providing method is characterized in that it includes: when the use request is received in the step of sending the other service use request, deriving the usable area information from the information about the circled area of the authentication request terminal, and storing the usable area information The area information update step in the area information storage component; the service provision availability determination step determines whether the area of the service user terminal is within the area indicated by the usable area information stored in the area information storage component. If it is in the area, It is judged to be able to provide the second service.
In this way, when the service verification system receives the use request of the second service in the other service use request sending step, it derives the available area of the second service from the circled area of the authentication request terminal, and stores it in the area as the available area information. In the information storage component, in the second message sending step, when a message is sent from the service user terminal, it is determined whether the service user terminal is included in the usable area stored in the area information storage component, and it is determined whether the second service can be provided, Therefore, the second service can be used only in the permitted area, which reduces the chance of illegal use and improves security.
The service providing method is characterized in that: when the use permission response sent to the authentication requesting terminal can be used based on the message information stored in the usable message information storage component, when the authentication requesting terminal moves in the circle area When it reaches outside the usable area as determined by the region information storage means, in the region information update step, the usable region information derived from the information about the circled region after the movement is stored in the region information storage Parts.
When such authentication requires the terminal to move in the circled area, by updating the usable information stored in the area information storage part, it can also respond to the situation when the user moves.
The service providing method is characterized in that: when the use permission response sent to the authentication requesting terminal can be used according to the message information stored in the usable message information storage component, when the authentication requesting terminal is in the circle The area is moved to be stored by the area information
200310102605.3 When it is outside the usable area identified by the first storage component, if the authentication request terminal sends the second service usage request in the other service usage request sending step, then the related mobile device will be removed from the relevant mobile in the area information update step if the authentication request terminal sends the second service usage request in the other service usage request sending step. The subsequent usable area information derived from the information of the circle area is stored in the area information storage part.
After the first terminal authenticated in this way moves in the circled area, the available area information is derived from the circled area of the first terminal when the other service use request is received in the other service use request receiving step, which can also correspond to the user's movement Time situation.
The service providing method is characterized in that it includes: when the use request is received in the other service use request sending step, the time information update step of storing the available time information of the second service that can be used in the time information storage component; In the service provision availability determination step, based on the available time information stored in the time information storage unit, it is also determined whether the time when the message is received by the second message receiving unit is included in the service available time. When the time of the message is included in the time when the second service can be used, it is determined that the second service can be provided.
In this way, the time when the second service can be used is stored as the available time information in the time information storage unit, and when a message is sent from the second terminal in the second message sending step, it is determined whether the receiving time of the message is included in the available time information. During the use time, it is determined whether the second service can be provided, and the second service can be used only within the permitted time, so as to reduce the chance of illegal use and improve security. It should be pointed out that the method for setting the time when the second service can be used can be set to a few minutes after the terminal sends a use permission response to the authentication request, and can be set according to the type of the second service.
The service provision method is characterized in that: in the use permission response sending step, a use permission response based on the usable area information derived from the information on the circled area of the authentication request terminal is sent; in the service provision permission determination step, It is determined whether the circled area of the service user terminal is in the area that can be derived from the message received from the second message receiving component, and if it is in the area, it is determined that the second service can be provided.
In this way, when a request for the use of the second service is received, the area information in which the second service can be used is derived from the circled area of the first terminal, and a use permission response based on the available area information is sent to the first terminal. When the second terminal sends a message, it is determined that the second
200310102605.3 Whether the first terminal is included in the usable area on which the message is based, it is determined whether the second service can be provided, the second service can be used only in the permitted area, the chance of illegal use is reduced, the security is improved, and the service verification system can The structure does not store information about the usable area.
The service provision method is characterized in that: in the use permission response sending step, a use permission response based on the available time information of the second service is sent; in the service provision availability determination step, when it is determined that the service is in the second message sending step When the time when the verification system receives the message is included in the time that can be derived from the message received by the second message receiving component, it is determined that the second service can be provided.
In this way, a use permission response based on the time when the second service can be used as the available time information is sent to the first terminal. When a message is sent from the second terminal, whether the receiving time of the message is included in the judgment on which the message is based During the available time, it is determined whether the second service can be provided, and the second service can be provided only within the permitted time, which can reduce the chance of illegal use, improve security, and the service verification system can not store information about the available area Structure.
According to the present invention, in a state where the user of the authentication request terminal is authenticated as a regular user through the authentication based on the authentication component, it is determined whether the user can use the second service, so the authentication result of the first service can be used, and the second service can be used. Omit authentication. Furthermore, a use permission message identifying the use permission is stored, and a use permission response based on the use permission message is sent to the authentication request terminal. When a use request message based on the use permission response learned from the authentication request terminal is sent from the second terminal, According to the usage permission message status DB, the message status information of the usage request message on which the usage request message is based is verified, and when it is in a usable state, a second service is provided to the second terminal. According to this, the service verification system only verifies the status of the usable message, and does not need to determine the user of the second terminal, and can determine whether the service can be provided to the second service. As described above, when using the second service, by using the authentication result of the first service, there is no need to construct a new authentication component from the beginning when the second service is provided, which can reduce cost and design time.
Through the description given below and the drawings given through the illustrations, the present invention will be understood more fully, and should not be considered as a limitation to the present invention.
200310102605.3 The detailed description given below will further clarify the applicability of the present invention in a wider range. However, when describing the preferred embodiments of the present invention, detailed descriptions and special examples are only given through explanations. For those skilled in the art, it is easy for those skilled in the art to perform various operations within the scope of the present invention based on these detailed descriptions. Various changes and modifications.
BRIEF DESCRIPTION OF THE DRAWINGS The drawings are briefly described below.
FIG. 1 is a block diagram showing the structure of the service verification network system of the embodiment.
Fig. 2 is a diagram showing an example of data items stored in an authentication information DB.
Fig. 3 is a diagram showing an example of data items stored in a usable service information DB.
Fig. 4 is a diagram showing an example of data items stored in a use permission message status DB.
Fig. 5 is a program flowchart showing the operation of the service verification network system of the first embodiment.
Fig. 6 is a program flowchart showing authentication processing.
FIG. 7 is a block diagram showing the structure of the service verification system of the second embodiment.
FIG. 8 is a diagram showing an example of data stored in the area information DB.
Fig. 9 is a diagram showing an example of data stored in a time information DB.
Fig. 10 is a program flowchart showing the operation of the service verification network system of the second embodiment.
Fig. 11 is a program flowchart showing the operation of the service verification network system of the second embodiment.
DETAILED DESCRIPTION Hereinafter, a preferred embodiment of the service verification system of the present invention will be described in detail with reference to the accompanying drawings. It should be noted that in the description of the drawings, the same elements are given the same symbols, and repeated descriptions are omitted.
(Example 1)
200310102605.3 Fig. 1 is a block diagram showing the structure of the service verification network system according to the first embodiment of the present invention. As shown in FIG. 1, the service verification network system 1 has a service verification system 10, an authentication request terminal 30, and a service user terminal 40. If the outline of each constituent element is initially described, the service verification system 10 has a function of providing a variety of services. The authentication request terminal 30 is a terminal that uses the service A (first service) provided by the service verification system 10 and is a terminal that is authenticated by the service verification system 10 in order to use the service A. The service use terminal 40 is a terminal that uses the service B (second service) provided by the service verification system 10. As an example of the service provided in the service verification network system 1 of this embodiment, as service A, there is a mobile phone, as service B, there is a wireless LAN. In this case, a mobile phone can be assumed. The terminal is the authentication request terminal 30, assuming A PC with a wireless LAN card serves as the service user terminal 40. It should be noted that the authentication requirement terminal 30 and the service user terminal 40 may be the same terminal. As an example of the same terminal, for example, assume that in one terminal, both the mobile phone and PHS can be used anywhere (registered trademark).
The service verification system 10 includes: an authentication information storage component (referred to as "authentication information DB") 11, a usable service information storage component (referred to as "available service information DB") 12, a use permission message status storage component (referred to as " Use permission message status DB") 13 and other three databases, communication components 14, 15 that communicate with the authentication request terminal 30 and service use terminal 40, respectively, authentication component 16, other service use availability determination component 17, use permission message status update component 18. The service provision availability judging unit 19, the use permission message state canceling unit 20. Here, the service verification system 10 is constituted by one device, but may be constituted by a plurality of devices. For example, it can be divided into: a first device consisting of an authentication information DB11, an authentication part 16, and a communication part 14; a usable service information DB12, other service availability determination means 17, a communication means 14, a use permission message status update means 18 The second device constituted by the use permission message status DB 13; the third device constituted by the service provision availability determination unit 19, the communication unit 15, and the usage permission message status release unit 20. Here, the service verification system 10 has three databases, but it may also have two databases, namely, the authentication information DB and the usable service information DB.<sub>0</sub> The authentication information DB11 is a database in which authentication information for authenticating users who can use the service A is stored. Figure 2 shows an example of data items stored in the authentication information DB11
200310102605.3 No. figure. As shown in FIG. 2, the authentication information DB11 stores data of items indicated by "ID", "password", "shared secret", "secret key", "public key" and "authentication method". It should be noted that for items other than "ID", the description of the data content is omitted. "ID" is the identification information used to determine the user who uses the service A. Information such as "password", "shared secret", "secret key", and "public key" is necessary for authentication. The "authentication method" is information indicating what method is used for authentication, and by having this information, the authentication method can be changed according to the user. It should be noted that data of items other than the data items shown in FIG. 2 can be stored in the authentication information DB11.
The usable service information DB 12 is a database that stores information about services that can be used by each user. FIG. 3 is a diagram showing an example of data items stored in the usable service information DB 12. As shown in Fig. 3, data of the items indicated by "ΠΓ and "service B" are stored in the usable service information DB 12. The "ID" and the "ID" in the authentication information DB11 are the same identification information used to determine the user "Service B" is a service different from service A provided by the service verification system 10. Here, there is information about service B, but if there are other services provided by the service verification system 10, the number is increased according to the number Subtract the items stored in the usable service information DB 12. If you refer to Figure 3, it can be seen that the user with the ID U100 can use the service B outside of the service A, and the user with the ID U101 cannot use the service B.
The use permission message status DB 13 is a database that stores the message status information of the use permission message identifying the use permission when the use of the service B different from the service A is permitted. FIG. 4 is a diagram showing an example of data items stored in the use permission message status DB13. As shown in FIG. 4, the use permission message status DB 13 stores data of items indicated by "use permission ID" and "status". The "use permission ID" is identification information for determining the use permission message. Identify that a certain user is permitted to use service B. The use permission ID may also be the use permission message itself. Here, the use permission ID is the use permission message. The "status" is information indicating whether or not the service B indicated by the use permission ID can be used. It should be noted that when multiple services are provided, the use permission message status DB 13 has the table shown in FIG. 4 for each service. The use permission message status DB 13 of this embodiment stores a use permission ID (a use permission message), and has a function of storing and restoring a use permission message message information.
200310102605.3 The function of the storage component for the first license message information. Here, the use permission message and the message status information are stored together in the use permission message status DB 13, but there may be storage means for separately storing these information. When the use permission message and the message status information are stored separately, for example, the two information can be associated by using the permission ID.
The communication unit 14 has a function of performing communication with the authentication request terminal 30. Specifically, the communication component 14 includes: 1) a function as a first message receiving component for receiving authentication information sent from the authentication requesting terminal 30; 2) a function as an authentication result sending component for sending an authentication result to the authentication requesting terminal 30; 3) The function of other service request receiving means that receives the use request of service B sent from the authentication request terminal 30; 4) When service B can be used, it acts as a use permission response sending means that sends a use permission response to the authentication request terminal 30 Function.
The communication unit 15 has a function of performing communication with the service using terminal 40. Specifically, the communication component 15 includes: 1) a function of a second message receiving component that receives a request for use of service B sent from the service user terminal 40; 2) a function of providing a service to the service user terminal 40. It should be noted that the service usage request message sent from the service usage terminal 40 is based on the usage permission response received by the authentication request terminal 30. Here, a structure having two communication components 14 and 15 respectively communicating with the authentication request terminal 30 and the service user terminal 40 is adopted. However, when the communication protocol of the authentication request terminal 30 and the service user terminal 40 are the same, they can also be passed through A communication component communicates with the terminals 30, 40.
The authentication unit 16 has a function of determining the user of the authentication requesting terminal 30 using the message received from the authentication requesting terminal 30 through the communication unit 14 and verifying whether the user can use the service A. The authentication component 16 is connected to the authentication information DB11, and verifies the authentication information contained in the message received from the authentication request terminal 30 based on the authentication information stored in the authentication information DB11, and authenticates whether the user of the authentication request terminal 30 who sent the message is a regular one user. The authentication here can adopt a method of verifying an ID and a password, or a public key encryption method. If the user is authenticated as a regular user, the user can request the terminal 30 to use the service A provided by the service verification system 10 through the authentication.
The other service availability component 17 has when the slave authentication is received through the communication component 14
200310102605.3 When the authentication requires the use of other services sent by the terminal 30, it is determined whether the user of the authentication requesting terminal 30 can use the function of the service. The other service availability component 17 is connected to the available service information DB 12, and when another service usage request is sent, it refers to the available service information DB 12, and the user of the authentication request terminal 30 determines whether the service is an available service. For example, in the case of the usable service information DB 12 shown in FIG. 3, when the use request for service B is received from the authentication request terminal 30 authenticated for use with the ID U101, the other service use availability component 17 determines that it cannot be used.
The use permission message status update part 18 has a function of updating the use permission message status DB13. Specifically, when it is determined by the other service availability component 17 that the other service can be used, an ID (use permission ID) is paid to the use permission, and the ID is newly updated in a new style. It should be pointed out that the "status" at this time becomes usable (in Figure 3, it is indicated by the mark).
The service provision availability determination unit 19 has a function of determining whether or not the service B can be provided to the service use terminal 40 when a service use request transmitted from the service use terminal 40 is received through the communication section 14. The service provision availability determination unit 19 verifies the message status information of the use permission message on which the use request message is based on the use permission message status DB13 to determine whether the service can be provided. When the status of the use permission message is available, it is determined that the service can be provided. Service B.
The use permission message cancellation unit 20 has a function of sending a message from the service use terminal 40, and when it is determined that the service can be provided by the service provision availability determination unit 19, the status of the use permission message is updated from the usable state to the unusable state. That is, once the use request containing the use permission message is received and other services are provided, it is updated to be unavailable (indicated by X in Figure 3). In this way, if the use request for using one use message is not accepted multiple times, even if a third party is notified of the use permission message, the risk of abuse by the third party can be reduced.
Next, the authentication request terminal 30 of this embodiment will be explained. The authentication request terminal 30 of this embodiment is shown in FIG. 1, and includes: an authentication information storage component (referred to as "authentication information DB") 31, a first message sending component 33, an authentication result receiving component 34, and other service use request sending components 35. Use permission response receiving part 36 and communication part 32.
200310102605.3 The first authentication information DB31 is a database storing authentication information for using the first service, and the items of the stored data are the same as the authentication information DB11 of the service verification system 10 (refer to FIG. 2) ο The first message sending unit 33 extracts and stores The authentication information in the authentication information DB 31 is a function of sending a message for authentication to the service authentication system 10. The information extracted from the authentication information DB31 differs according to the authentication method. For example, when authentication is performed by a password, the ID, password, and authentication method are extracted; when authentication is performed with a secret key, the ID, secret key, and authentication method are extracted, and the secret key is used to The given message is encrypted. In any case, the information about the authentication method is information necessary for synchronization of the authentication method between the authentication request terminal 30 and the service verification system 10.
The authentication result receiving part 34 has a function of receiving an authentication result sent from the service verification system 10.
The other service use request sending unit 35 has a function of sending a service B usage request. When the other service use request sending unit 35 determines that the service A can be used based on the authentication result received by the authentication result receiving unit 34, it sends the service B usage request.
The use permission response receiving part 36 has a function of receiving a use permission response based on the use permission message sent from the service verification system 10.
The communication part 14 has a function of communicating with the service verification system 10.
Next, the service using terminal 40 of this embodiment will be described. As shown in FIG. 1, the service user terminal 40 has a second message sending part 41 and a communication part 42.
The second message sending part 41 has a function of generating and sending a message that requires the use of service B different from the authenticated service A. The second message sending part 41 generates a message according to the use permission response received by the authentication request terminal 30 through the use permission response receiving part 36. For example, by processing the usage permission response with a given function, a usage request message can be generated. In such a method, in the authentication request terminal 30 or the service user terminal 40, the use permission message does not become clear, so the risk of information omission can be reduced. It should be pointed out that any method can be used for the method of transmitting the use permission response from the authentication request terminal 30 to the service user terminal 40. For example, the authentication request terminal 30 and the service user terminal 40 can be communicated with the service using terminal 40 by short-range wireless, or can be connected by a cable. In addition, you can also pass
200310102605.3 The service user terminal 40 inputs and transmits the use permission message displayed on the display of the authentication request terminal 30 first.
Hereinafter, the operation of the service verification network system 1 of this embodiment will be described with reference to FIG. 5 and FIG. 6, and the service provision method of the embodiment will be described together.
Initially, the authentication requires the terminal 30 to perform authentication for using the service A (S10) <sub>0 </sub>Hereinafter, the authentication process will be described in detail with reference to FIG. 6. First, the authentication request terminal 30 sends a message based on the authentication information to the service verification system 10 (S11). If the service verification system 10 receives the message sent from the authentication request terminal 30 (S12), it performs authentication processing based on the received message (S13). ). The service verification system 10 analyzes the authentication information from the message sent by the authentication request terminal 30, and performs the authentication of the authentication request terminal 30 based on the authentication information stored in the authentication information DB11. If the authentication process is completed, the service verification system 10 sends the authentication result to the authentication requesting terminal 30 (S14). Here, the user of the authentication requesting terminal 30 is a regular user and is authenticated as being able to use the service A. However, when the authentication is an authentication When the user of the request terminal 30 is not a regular user, the authentication request terminal 30 cannot use the service A. The authentication request terminal 30 receives the authentication result sent from the service verification system 10 (S15). When the authentication result received by the authentication requesting terminal 30 indicates that the authentication is correct, the authentication requesting terminal 30 can use the service Ao. The flow to this is the same as that of the conventional service verification network system, and the user is authenticated in order to use a given service.
Refer to Figure 5 again. The authentication request terminal 30 sends a usage request of the service B different from the service A to the service verification system 10 (S20). If the service verification system 10 receives another service use request sent from the authentication request terminal 30 (S22), it determines whether the user of the authentication request terminal 30 can use the service B (S24). Specifically, it is determined whether the service can be used based on the usable service information DB 12 regarding service information that can be used by the user of the authentication request terminal 30 through a contract or the like. It should be noted that the user is determined by the authentication process, so it can The information of the available service is extracted from the available service information DB12. For example, when the user ID is a user of U100, it is determined that service B can be used (refer to FIG. 3). Here, it is determined that service B can be used. If it is determined that the service B can be used, the service verification system 10 provides a use permission ID (use permission message) that identifies the user's permission to use the service B, and updates the use permission message status DB 13
200310102605.3 Section (S26). For example, in the license message status DB13 shown in FIG. 4, "A102" in the third row is added as a new license message. Initially, a use permission message is added in a state where it can be used (indicated by "ο" in Figure 4).
Next, the service verification system 10 transmits a usage permission response regarding the service B related to the usage request to the authentication request terminal 30 (S28). If the authentication requesting terminal 30 receives the use permission response (S30), it transmits the received use permission response to the service user terminal 40. In this embodiment, the authentication requires that the terminal 30 and the service user terminal 40 can communicate wirelessly, the authentication requires the terminal 30 to send a use permission response to the service user terminal 40 via wireless (S32), and the service user terminal 40 receives the use permission response ( S34).
If the service user terminal 40 receives the use permission response sent from the authentication request terminal 30 (S34), it generates a message requesting the use of service B based on the use permission response, and the service user terminal 40 sends the generated message to the service verification system 10 ( S36) ο The service verification system 10 receives the message sent from the service user terminal 40 (S38), analyzes the use permission message on which the received message is based, and retrieves the message status information from the use permission message status DB 13 (S40)<sub>0</sub>Next, it is determined whether the use permission message on which the received message is based is in a usable state, and then whether the received message itself is correctly constituted and compatible, and whether the service can be provided (S46). For example, if the use is extracted from the use request If the permission message is "Α102, according to the use permission message status DB13, the status is "ο, so it is determined that it can be used, and the service verification system 10 can provide the service to the service user terminal 40. When the service can be provided, the use permission message state release unit 20 changes the state of the use permission message stored in the use permission message state DB 13 from the usable state to the unusable state, and cancels the usable state of the service B.
The service verification system 10 sends a usage permission response to the service usage terminal 40 (S48), and the service usage terminal 40 receives the usage permission response sent from the service providing terminal (S50), and becomes able to use the service B. As above, the operation flow of the service verification network system 1 of this embodiment ends.
The service verification system 10 (service verification network system 1) of this embodiment has an authentication unit 16 that determines whether the service A can be used, a determination unit 17 whether to use other services, a use permission message status DB 13, and the user is determined by the authentication unit 16, and Can make
200310102605.3 In the state of the first service A, it is judged whether service B can be used. Based on this, the use of service B can be judged whether it can be used without authentication. In addition, when it is determined that the service B can be used, the message status information of the use permission message for the use permission is stored in the use permission message status DB 13, and a use permission response based on the use permission message is sent to the authentication request terminal 30. Accordingly, when the service verification system 10 transmits a message based on the use permission response, it can provide the service B to the service use terminal 40 that transmitted the message without authentication. Therefore, in the service verification system 10 that provides the service A, when a new service B is provided, even if the authentication unit 16 for authenticating users who can use the service B is not newly constructed, the authentication result based on the authentication unit 16 of the service A is used, The service verification system 10 can also be prepared at low cost and in a short time.
In addition, the service providing method of this embodiment determines the user of the authentication request terminal 30 through the authentication process, and receives the use request of the service B in the state where the service A can be used, and determines the use of the service B. Therefore, it is possible to determine only specific Whether the user can use service B does not require new authentication. Furthermore, when it is determined that the service B can be used, a use permission message is provided to the use permission, the message status information called usable is stored in the use permission message status DB 13, and the authentication request terminal 30 is sent to the authentication requesting terminal 30 based on the use permission message. License response. Accordingly, in this service providing method, when a use request including the use permission message is sent, service B can be provided to the service user terminal 40 that sent the use request without authentication. Therefore, in the service verification system 10 that provides the service A, when a new service B is provided, even if the authentication component 16 that can use the service B is not newly constructed, only the authentication result based on the authentication component 16 of the service A is used. The service verification system 10 can be prepared in a short time and at low cost.
(Embodiment 2) Next, the service verification network system of Embodiment 2 of the present invention will be described. The basic structure of the service verification network system of Embodiment 2 is the same as that of the service verification network system of Embodiment 1, but the structure of the service verification system 10a is different. FIG. 7 is a block diagram showing the structure of the service verification system 10a of the second embodiment. As shown in FIG. 7, the service verification system 10a of the second embodiment, in addition to the structure of the service verification system 10 of the first embodiment, further has an area information storage unit (referred to as "area information DB") 22 and an area information update unit 21. Time
200310102605.3 The first information storage component (called "time information DB") 24, the time information update component 23.
The area information DB 22 is a database that stores area information about areas where the second service can be used. FIG. 8 is a diagram showing an example of data stored in the area information DB 22. In the area information DB 22, various pieces of information of "use permission ID" and "usable area" are stored. The "use permission ID" is identification information for determining the use permission message, and is the same as that stored in the use permission message status DB13. The "available area" is information about the area where the second service can be used. If the service using terminal 40 does not exist in the available area, the service is not provided. Here, the usable area information is associated with the use permission ID, but it does not have to be such a data structure. For example, it may be stored in association with the identification information of the authentication request terminal 30, or may be stored independently of other information.
The area information update part 21 has a function of updating the area information DB 22. When the area information update unit 21 determines that the service B can be used by the other service use availability determination unit 17, it derives the usable area in which the service B can be used from the circled area of the authentication request terminal 30 that has sent the use request. For example, it is possible to make the area in the circled area including the authentication requesting terminal 30 the usable area, and it is also possible to make a part of the circled area including the authentication requesting terminal 30 as the usable area. Of course, authentication requires that the circled area and usable area of the terminal 30 can be the same. Then, the derived usable area information is stored in the area information DB 22. In addition, the use of other services is permitted, and the message status information stored in the use permission message status DB 13 is an authentication request terminal 30 that can be used to move. When its area changes, the authentication request terminal 30 sends another service use again. However, at this time, the usable area is also derived from the circled area of the authentication request terminal 30, and the area information DB 22 is updated by storing the newly derived usable area information<sub>O</sub>It should be pointed out that the license response for the use of other services has been sent, so the license response is not sent at this time. If such a structure is adopted, it can match the area of the authentication request terminal 30, and always keep the available area up-to-date, and when the service verification system 10a receives other service requirements again, it can update the use permission message status DB13. Since all authentication request terminals 30 in the connection area are not monitored, the burden on the service verification system 10 can be reduced.
The time information DB24 stores the available time related to the time when the second service can be used
200310102605.3 The second information database. FIG. 9 is a diagram showing an example of data stored in the time information DB24. In the time information DB 24, various information such as "use permission ID" and "available time" are stored. The "use permission ID" is identification information for determining the use permission message, and is the same as that stored in the use permission message status DB13. The "available time" is information about the time when the second service can be used. During the available time, if the second service usage request is not received from the service user terminal, the service will not be provided. Here, the usable time information is associated with the use permission ID, but such a data structure does not have to be adopted. For example, it may be stored in association with the identification information of the authentication request terminal 30, or may be stored independently of other information.
The time information update component 23 has a function of updating the time information DB 24. When the time information update component 23 determines that the service B can be used by the other service use availability determination component 17, it sets the available time when the service B can be used. For example, it is possible to set the available time from the time when the request for the use of other services is determined to 10 minutes later, the available time can be set for each service, and the service B can be set for 5 minutes. The service C is set for 10 minutes. Then, the time information update component 23 stores the set available time information in the area information DB 22.
Hereinafter, the operation of the service verification network system of the second embodiment will be described with reference to FIG. 10, and the service providing method of the second embodiment will be described together.
Initially, the authentication requires the terminal 30 to perform an authentication method for using the service A (S10). This step is the same as the authentication step of the first embodiment (refer to FIG. 6).
Next, the authentication request terminal 30 sends a use request of the service B different from the service A to the service verification system 10 (S20). If the service verification system 10 receives another service use request sent from the authentication request terminal 30 (S22), it determines whether the user of the authentication request terminal 30 can use the service B (S24). Here, it is determined that the service Bo can be used. If it is determined that the service B can be used, the service verification system 10 provides a license ID that identifies the user's license to use the service B, and updates the license message status DB13 (S26). A use permission message is added to the state that can be used (indicated by. In Fig. 4).
Next, the service verification system 10a receives the authentication request from the area information update part 21
200310102605.3 derives the available area information of the second service in the circled area of the first terminal 30, and stores it in the area information DB22. In addition, the service verification system 10a sets the usable time information of the second service that can be used through the time information update part 23, and stores it in the time information DB24.
Next, the service verification system 10 sends a use permission response based on the use permission message to the authentication request terminal 30 regarding the service B related to the use request (S28). If the authentication request terminal 30 receives the use permission response (S30), it transmits the received use permission response to the service user terminal 40. In this embodiment, the authentication request terminal 30 and the service user terminal 40 can use wireless communication, the authentication request terminal 30 sends a use permission response to the service user terminal 40 via wireless (S32), and the service user terminal 40 receives the use permission response (S34). ) Ο If the service user terminal 40 receives the use permission response sent from the authentication request terminal 30 (S34), it generates a message requesting the use of service B based on the use permission response, and the service user terminal 40 sends the generated message to the service verification system 10 ( S36). The service verification system 10 receives the message sent from the service user terminal 40 (S38), analyzes the use permission message on which the received message is based, and retrieves the message status information from the use permission message status DB 13 (S40). Then, according to the use permission message status DB13, it is determined whether the use permission message on which the received message is based is in a usable state, and then it is determined whether the received message itself is correctly constituted. The service verification system 10a of the second embodiment retrieves the information of the usable area from the area information DB 22, and retrieves the usable time from the time information DB 24 Time information (S43). Then, the service verification system 10a determines whether or not the service use terminal 40 exists in the area indicated by the usable area information stored in the area information DB 22 through the service provision availability determination unit 19. Furthermore, the service provision availability determination unit 19 determines whether or not the time when the use request message of the second service is received is within the usable time stored in the time information DB 24. According to these determinations, when the service user terminal sends a message within the available time, the service provision availability determination component 19 determines that the second service can be used (S46). When the service can be provided, the use permission message The state canceling unit 20 changes the state of the use permission message stored in the use permission message state DB 13 from the state that can be used to the state that cannot be used, and cancels the use of service B.
200310102605.3 The first state of use.
Next, the service verification system 10 sends a usage permission response to the service usage terminal 40 (S48), and the service usage terminal 40 receives the usage permission response sent from the service provider terminal (S50), and becomes able to use the service Bo or more, the service of this embodiment The process of verifying the network system ends.
The service verification system 10a of the second embodiment is the same as the service verification system 10 of the first embodiment. In the service verification system 10a that provides the service A, when a new service B is provided, the authentication component 16 that can use the service B is not newly constructed for authentication. The service verification system 10a can also be prepared at low cost and in a short time by using the authentication result based on the authentication component 16 of the service A. The service verification system 10a of the second embodiment stores the usable area information in the area information DB 22, and is permitted to The service can be used in the usable area, so the area where the service can be used can be limited, the chance of illegal use can be reduced, and the security can be improved. In addition, the usable time information is stored in the time information DB 24, and the use of the service is permitted during this time, so the time during which the service can be used can be limited, the chance of illegal use can be reduced, and the security can be improved.
In addition, the service provision method of the second embodiment is the same as the service provision method of the first embodiment. In the service verification system 10 that provides the service A, when a new service B is provided, the authentication component 16 that can use the service B is not newly constructed even if it is not newly constructed. By using the authentication result based on the authentication component 16 of the service A, the service verification system 10 can also be prepared at low cost and in a short time. (Embodiment 3) Next, the service verification network system of Embodiment 3 of the present invention will be described. The service verification network system of the third embodiment has the same basic structure as the service verification network system 1 of the first embodiment (refer to FIG. 1), but the information contained in the use permission response sent from the service verification system 10 is sent from the service user terminal 40 The information contained in the usage requirements of is different from the service verification network system 1 of the first embodiment. Next, the differences from the service verification network system 1 of the first embodiment will be described.
In addition, the communication component 14 of the service verification system 10 of the third embodiment requests the use of other services and sends a use permission response when the other service is available, but the use
200310102605.3 The license response is based on the information about the license message, and also based on the usable area information and the usable time information. Along with this, the second message sending unit 41 of the service use terminal 40 of the third embodiment has the function of generating a message based on the use request information of the usable area information and the usable time information, in addition to the information about the use permission message, to the service verification system 10 send function.
Next, referring to FIG. 11, the operation of the service verification network system of the third embodiment will be described, and the service providing method of the third embodiment will be described together.
The operation of the service verification network system of the third embodiment is basically the same as the operation of the service verification network system 1 of the first embodiment, so the difference from the operation of the service verification system 10 of the first embodiment will be described. In step S28, when the use permission response of the service B is sent, a use permission response based on the use permission message, the usable area information, and the usable time information is sent to the authentication request terminal 30. Then, in step S34, when the service user terminal 40 that has received the use permission response sends the use request message in step S36, it generates a message based on the use request response based on the use permission message, the usable area information, and the usable time information, Send to the service verification system 10 (S36). If the service verification system 10 receives the message sent from the service using terminal 40 (S38), it determines the compatibility of the status of the usage permission message on which the message is based and whether the received message itself is correctly constituted based on the usage permission message status DB13. Here, if the usage permission message on which the usage request message is based is "A102", the usage permission message status DB13 is referred to, and the status is "0". In addition, the use request area information and the use request time information on which the use request message received from the service use terminal 40 is based are analyzed (S44), and it is determined whether the circled area of the service use terminal 40 is included in the usable area. In addition, it is determined to use Whether the receiving time of the request message is within the available time, to determine whether the service can be provided B (S46).
The server verification network system and method of Embodiment 3 are the same as the server verification network system 1 and method of Embodiment 1. By using the authentication result of service A, the use of service B becomes possible, and there is no need to prepare a new one for service B. The authentication component can prepare the service verification system 10 that provides service B at low cost and in a short time.
In addition, in the server verification network system of the third embodiment, the use permission message status DB 13 of the service verification system 10 does not have the usable area information or the usable time information.
200310102605.3 The structure of the second information, so it can reduce the amount of data stored in the service verification system 10.
The embodiments listed above describe the server verification network system of the present invention in detail, but the present invention is not limited to the embodiments.
For example, in the second embodiment, when determining whether service B can be used, the usable area information or usable time information is used, but either one may be used. According to this, it is possible to improve the safety, reduce the number of determination steps, and increase the speed of the admissibility determination process.
In addition, the service user terminal also has an identification information storage unit that stores identification information for identifying its own terminal as additional information. Based on the identification information and the use permission response received by the authentication request terminal 30, it generates a use request message for service B and sends it to the service The verification system 10 sends. If such a structure is adopted, the terminals that can use the second service can be restricted, so the security can be improved.
In addition, the service user terminal also has an authentication information storage unit that stores authentication information as additional information. Based on the authentication information and the use permission response received by the authentication request terminal 30, a message requesting the use of service B is generated and sent to the service verification system 10. If such a structure is adopted, the second service can be provided more safely.
From the above description of the present invention , it can be known that those skilled in the art can easily make various changes and modifications to the present invention based on the above detailed description, provided that these changes and modifications do not deviate from the spirit and scope of the present invention. , Should belong to the protection scope of the present invention.
200310102605.3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US6134431A | Cites | United States of America | Search report |
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 2002302102 | Japan | A | |
| 2002302102 | Japan | A | |
| 3021022002 | Japan | – | |
| 3021022002 | – | – | – |
| JP20020302102 | – | – | – |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cessation of patent rightC17 | C17 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 100419736
- Publication, DOCDB
- 100419736
- Publication, EPODOC
- CN100419736C
- Application
- 101026053
- Application, DOCDB
- 200310102605
- Application, EPODOC
- CN200310102605
Titles3
- English
- Service verification system, authentication request terminal, service use terminal and providing method
- Chinese
- 服务验证系统、认证要求终端、服务使用终端及提供方法
- English
- Service vertification system, vertification require terminal, service operating terminal and providing method
Classification
- CPC, 4
- H04L63/08
- G06F21/35
- G06F2221/2115
- Y04S40/20
- IPC, 9
- G06F17 00
- G06F13 00
- H04Q7 24
- G06F1 00
- G06F17 30
- G06F21 35
- G09C1 00
- H04L9 00
- H04L29 06