EP2000939A2

Person oneself authenticating system and person oneself authenticating method

Abstract

There is provided person oneself authenticating means for authentication of a user, which is mainly used for person oneself authentication in Internet banking or the like and is high in security, and is realizable by functions ordinarily provided in a PC, a mobile phone, or the like, the authenticating means being less in burden required for user authentication key management and authentication operations. Sound or an image is adopted as an authentication key for person oneself authentication. Authentication data is edited by combining an authentication key, which is selected by a registered user, and sound or an image that is other than the authentication key, and the authentication data is continuously reproduced in a user terminal. A time in which a user has discriminated the authentication key from the reproduced audio or video is compared with a time in which the authentication key should normally be discriminated, which is specified from the authentication data. When both times agree, the user is authenticated as a registered user.

EP2000939A2, drawing sheet 1
Sheet 1 of 15

Term

Term ended

Projected expiry passed 31 May 2026, 0.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

14 claims: 4 independent, 10 dependent

  1. 1
    A person oneself authenticating system, provided in a transaction system, for authenticating whether a user who has accessed the transaction system from a terminal device is a registered user, characterized by comprising:authentication request accepting means for accepting an authentication request by the user who has accessed from the terminal device;authentication key list memory means for storing one or two or more authentication keys, which are selected by the registered user, as an authentication key list;authentication data creating means for selecting at least one authentication key from the authentication key list, which is stored in the authentication key list memory means, of the user whose authentication request is accepted, combining at least a part of authentication key data, which constitutes the authentication key, and at least a part of key data of one or two or more keys, which are not included in the authentication key list, thereby creating authentication data which is continuously reproduced;authentication data transmission means for transmitting the authentication data to the terminal device;authentication information reception means for receiving authentication information which is generated by an authenticating action which is performed by the user on the terminal device by reproducing the authentication data in the terminal device;and authentication information collation means for collating the authentication information and normal authentication information which is specified from the authentication data, thereby determining whether the user is an authenticated person, wherein each of the authentication key data and the key data, which are used in the authentication data creating means, is sound source data or image data, which varies with time at a time of reproduction, the authentication information, which is received by the authentication information reception means, is data for specifying a time in which the authentication key recognized by the user is reproduced, the data being generated from a time in which an authentication operation, which is executed by the user by recognizing that the authentication key is being reproduced, is accepted in the terminal device during the reproduction of the authentication data, and the authentication information collation means collates whether the time in which the authentication key is reproduced, which is specified from the authentication information, agrees with a time in which the authentication key should be reproduced, which is specified from the authentication data, thereby determining whether the user is the authenticated person.
  2. 2
    A person oneself authenticating system, provided in a transaction system, for authenticating whether a user who has accessed the transaction system from a terminal device is a registered user, characterized by comprising:authentication request accepting means for accepting an authentication request by the user who has accessed from the terminal device;authentication key list memory means for storing one or two or more authentication keys, which are selected by the registered user, as an authentication key list;authentication data creating means for selecting at least one authentication key from the authentication key list, which is stored in the authentication key list memory means, of the user whose authentication request is accepted, designating a combination between the authentication key and a time of reproduction of the authentication key and one or two or more keys, which are not included in the authentication key list, and a time of reproduction of the one or two or more keys, thereby creating authentication data which is continuously reproduced;authentication data transmission means for transmitting the authentication data to the terminal device;authentication information reception means for receiving authentication information which is generated by an authenticating action which is performed by the user on the terminal device by reproducing the authentication data in the terminal device;and authentication information collation means for collating the authentication information and normal authentication information which is specified from the authentication data, thereby determining whether the user is an authenticated person, wherein each of the authentication key and the key, which are used in the authentication data creating means, specifies sound or an image, which is reproduced at a time of authentication, the authentication information, which is received by the authentication information reception means, is data for specifying a time in which the authentication key recognized by the user is reproduced, the data being generated from a time in which an authentication operation, which is executed by the user by recognizing that the authentication key is being reproduced, is accepted in the terminal device during the reproduction of the authentication data, and the authentication information collation means collates whether the time in which the authentication key is reproduced, which is specified from the authentication information, agrees with a time in which the authentication key should be reproduced, which is specified from the authentication data, thereby determining whether the user is the authenticated person.
  3. 8
    A person oneself authenticating method for authenticating, in a transaction system, whether a user who has accessed the transaction system from a terminal device is a registered user, characterized by comprising:an authentication request accepting step of accepting, by the transaction system, an authentication request by the user who has accessed from the terminal device;an authentication data creating step of selecting, by the transaction system, at least one authentication key from an authentication key list of the user whose authentication request is accepted, the authentication key list being stored in an authentication key list memory unit that stores an authentication key, which is selected by the registered user, as the authentication key list, combining at least a part of authentication key data of the authentication key and at least a part of key data of one or two or more keys, which are not included in the authentication key list, thereby creating authentication data which is continuously reproduced;an authentication data transmission step of transmitting, by the transaction system, the authentication data to the terminal device;an authentication information reception step of receiving, by the transaction system, authentication information which is generated by an authenticating action which is performed by the user on the terminal device by reproducing the authentication data in the terminal device;and an authentication information collation step of collating, by the transaction system, the authentication information and normal authentication information which is specified from the authentication data, thereby determining whether the user is an authenticated person, wherein each of the authentication key data and the key data, which are used in the authentication data creating step, is sound source data or image data, which varies with time at a time of reproduction, the authentication information, which is received in the authentication information reception step, is data for specifying a time in which the authentication key recognized by the user is reproduced, the data being generated from a time in which an authentication operation, which is executed by the user by recognizing that the authentication key is being reproduced, is accepted in the terminal device during the reproduction of the authentication data, and the authentication information collation step collates whether the time in which the authentication key is reproduced, which is specified from the authentication information, agrees with a time in which the authentication key should be reproduced, which is specified from the authentication data, thereby determining whether the user is the authenticated person.
  4. 9
    A person oneself authenticating method for authenticating, in a transaction system, whether a user who has accessed the transaction system from a terminal device is a registered user, characterized by comprising:an authentication request accepting step of accepting, by the transaction system, an authentication request by the user who has accessed from the terminal device;an authentication data creating step of selecting, by the transaction system, at least one authentication key from an authentication key list of the user whose authentication request is accepted, the authentication key list being stored in an authentication key list memory unit that stores an authentication key, which is selected by the registered user, as the authentication key list, designating a combination between the authentication key and a time of reproduction of the authentication key and one or two or more keys, which are not included in the authentication key list, and a time of reproduction of the one or two or more keys, thereby creating authentication data which is continuously reproduced;an authentication data transmission step of transmitting, by the transaction system, the authentication data to the terminal device;an authentication information reception step of receiving, by the transaction system, authentication information which is generated by an authenticating action which is performed by the user on the terminal device by reproducing the authentication data in the terminal device;and an authentication information collation step of collating, by the transaction system, the authentication information and normal authentication information which is specified from the authentication data, thereby determining whether the user is an authenticated person, wherein each of the authentication key data and the key data, which are used in the authentication data creating step, specifies sound or an image, which is reproduced at a time of authentication, the authentication information, which is received in the authentication information reception step, is data for specifying a time in which the authentication key recognized by the user is reproduced, the data being generated from a time in which an authentication operation, which is executed by the user by recognizing that the authentication key is being reproduced, is accepted in the terminal device during the reproduction of the authentication data, and the authentication information collation step collates whether the time in which the authentication key is reproduced, which is specified from the authentication information, agrees with a time in which the authentication key should be reproduced, which is specified from the authentication data, thereby determining whether the user is the authenticated person.