JP2006229948A

Method and system which authenticate certainly service specialized user of remote service interface to storage medium

Abstract

[Subject] The method and system which attest a service person in charge about the remote access to a storage medium are offered. [Solution means] In order to attest the positive low overhead about a user, a pair of servers are used. The proof server of [the] the pair receives a user's personal information from the 1st client through the 1st network, and provides the 1st client with the enciphered user certificate through the 1st network. The device control server in the above of a pair receives the enciphered user certificate from the 2nd client through the 2nd network, and provides the 2nd client with remote access information through the 2nd network. In addition, the remote access information makes easy remote access to the equipment by the user through the 2nd network based on the response to verification by the device control server of the enciphered user certificate. [Selection figure] Fig. 1

Term

Term ended

Projected expiry passed 27 January 2026, 0.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

31 claims: 14 independent, 17 dependent

  1. 1
    A method for allowing the first and second clients to establish user authentication for remote access to the device, the first client to the first server over the first network. A step of providing a first set of personal information of the user, and the first client having at least one personal attribute of the user corresponding to the first set of personal information encrypted by the server. The step of receiving the encrypted user certificate from the first server via the first network, and the second client receiving the encrypted user certificate from the first server to the second server via the second network. The steps provided and the second client facilitate remote access to the device by the user over the second network based on the response to the verification of the encrypted user certificate by the second server. A method including a step of receiving remote access information from the second server via the second network. 第1クライアントおよび第2クライアントが装置を遠隔的にアクセスするためにユーザの認証を確立することを可能にするための方法であって、 前記第1クライアントが第1ネットワークを介して第1サーバに前記ユーザの個人情報の第1セットを提供するステップと、 前記第1クライアントが、前記個人情報の第1セットに対応する前記ユーザの少なくとも1つの個人属性を前記サーバにより暗号化されたものを含む暗号化されたユーザ証明書を、前記第1サーバから前記第1ネットワークを介して受け取るステップと、 前記第2クライアントが前記暗号化されたユーザ証明書を、第2ネットワークを介して第2サーバに提供するステップと、 前記第2クライアントが、前記第2サーバによる前記暗号化されたユーザ証明書の検証に対する応答に基づいて、前記ユーザによる装置への前記第2ネットワークを介したリモート・アクセスを容易にするリモート・アクセス情報を、前記第2サーバから前記第2ネットワークを介して受け取るステップと、 を含む方法。
  2. 4
    The first aspect of the invention, wherein the encrypted user certificate further includes at least one operational attribute related to remote access to the device by the user encrypted by the first server. the method of. 前記暗号化されたユーザ証明書が、前記ユーザによる前記装置へのリモート・アクセスに関連した少なくとも1つの動作上の属性を前記第1サーバにより暗号化されたものを更に含む、請求項1に記載の方法。
  3. 5
    Claim 1 further comprises the encrypted user certificate encrypted by the first server with a set of application-specific data for adding specific security to the encrypted user certificate. The method described in. 前記暗号化されたユーザ証明書が、特定のセキュリティを前記暗号化されたユーザ証明書に加えるためのアプリケーション特有のデータのセットを前記第1サーバにより暗号化されたものを更に含む、請求項1に記載の方法。
  4. 8
    Claim 1 wherein the remote access information includes a user account and a random password set by the second server for the user to gain access to the device over the second network. The method described. 前記リモート・アクセス情報が、ユーザ・アカウントと、前記ユーザが前記第2ネットワークを介した前記装置へのアクセスを得るために前記第2サーバによって設定されたランダム・パスワードとを含む、請求項1に記載の方法。
  5. 11
    A method for allowing a first server and a second server to authenticate a user to remotely access a device connected to the second server in an operational relationship, wherein the first server , The step of receiving the first set of personal information of the user from the first client via the first network, and the first server of at least one personal attribute of the user corresponding to the first set of personal information. A step of supplying an encrypted user certificate including an encrypted one by the server to the first client via the first network, and a second server from the second client via the second network. Based on the step of receiving the encrypted user certificate and the response of the second server to the verification of the encrypted user certificate by the second server, the user via the second network. A method comprising supplying remote access information to the second client over the second network, facilitating remote access to the device by the server. 第1サーバおよび第2サーバが、該第2サーバに動作関係に接続された装置を遠隔的にアクセスするためにユーザを認証することを可能にするための方法であって、 前記第1サーバが、第1クライアントから第1ネットワークを介して前記ユーザの個人情報の第1セットを受け取るステップと、 前記第1サーバが、前記個人情報の第1セットに対応する前記ユーザの少なくとも1つの個人属性の前記サーバにより暗号化されたものを含む暗号化されたユーザ証明書を、前記第1ネットワークを介して前記第1クライアントに供給するステップと、 前記第2サーバが第2クライアントから第2ネットワークを介して前記暗号化されたユーザ証明書を受け取るステップと、 前記第2サーバが、前記第2サーバによる前記暗号化されたユーザ証明書の検証に対する応答に基づいて、前記第2ネットワークを介した前記ユーザによる装置へのリモート・アクセスを容易にするリモート・アクセス情報を、前記第2ネットワークを介して前記第2クライアントに供給するステップと、 を含む方法。
  6. 14
    11. The encrypted user certificate further comprises at least one operational attribute associated with remote access to the device by the user encrypted by the first server. the method of. 前記暗号化されたユーザ証明書が、前記ユーザによる前記装置へのリモート・アクセスに関連した少なくとも1つの動作上の属性を前記第1サーバにより暗号化されたものを更に含む、請求項11に記載の方法。
  7. 15
    11. The encrypted user certificate further comprises an encrypted set of application-specific data for adding specific security to the encrypted user certificate, encrypted by the first server. The method described in. 前記暗号化されたユーザ証明書が、特定のセキュリティを前記暗号化されたユーザ証明書に加えるためのアプリケーション特有のデータのセットを前記第1サーバにより暗号化されたものを更に含む、請求項11に記載の方法。
  8. 18
    11. The remote access information comprises a user account and a random password set by the second server for the user to gain access to the device over the second network. The method described. 前記リモート・アクセス情報が、ユーザ・アカウントと、前記ユーザが前記第2ネットワークを介した前記装置へのアクセスを得るために前記第2サーバによって設定されたランダム・パスワードとを含む、請求項11に記載の方法。
  9. 21
    A means for receiving a first set of user's personal information from a first client via a first network and at least one personal attribute of the user corresponding to the first set of personal information is encrypted by a first server. Means for supplying an encrypted user certificate including the encrypted user certificate to the first client via the first network, and the encrypted user certificate from the second client via the second network. Remote access that facilitates remote access to the device by the user over the second network based on the means for receiving the document and the response to the verification of the encrypted user certificate by the second server. A system comprising means for supplying information to the second client via the second network. 第1クライアントから第1ネットワークを介してユーザの個人情報の第1セットを受け取るために手段と、 前記個人情報の第1セットに対応する前記ユーザの少なくとも1つの個人属性を第1サーバにより暗号化されたものを含む暗号化されたユーザ証明書を、前記第1ネットワークを介して前記第1クライアントに供給するための手段と、 第2クライアントから第2ネットワークを介して前記暗号化されたユーザ証明書を受け取るための手段と、 第2サーバによる前記暗号化されたユーザ証明書の検証に対する応答に基づいて前記第2ネットワークを介した前記ユーザによる装置へのリモート・アクセスを容易にするリモート・アクセス情報を、前記第2ネットワークを介して前記第2クライアントに供給するための手段と、 を含むシステム。
  10. 22
    The instruction includes a processor and a memory for storing instructions that can be operated by the processor and providing an encrypted user certificate to the user, and the instruction is a personal information of the user from a client via a network. Received the set of personal information of the user with an encrypted user certificate containing the steps of receiving the set and the encrypted at least one personal attribute of the user corresponding to the set of personal information of the user. A server that executes a step of generating in response to the above and a step of providing the encrypted user certificate to the client via the network. プロセッサと、 前記プロセッサによって動作し得る命令を記憶し、暗号化されたユーザ証明書をユーザに提供するためのメモリと、 を含み、前記命令が、 クライアントからネットワークを介して前記ユーザの個人情報のセットを受け取るステップと、 前記ユーザの個人情報のセットに対応する前記ユーザの少なくとも1つの個人属性を暗号化したものを含む暗号化されたユーザ証明書を、前記ユーザの個人情報のセットを受け取ったことに応答して生成するステップと、 前記暗号化されたユーザ証明書を、前記ネットワークを介して前記クライアントに提供するステップと、を実行する、サーバ。
  11. 24
    23. Claim 23, wherein the step of generating the encrypted user certificate in response to receiving the set of personal information of the user further comprises the step of encrypting the unencrypted user data. server. 前記ユーザの個人情報のセットを受け取ったことに応答して前記暗号化されたユーザ証明書を生成するステップが未暗号化のユーザ・データを暗号化するステップを更に含む、請求項23に記載のサーバ。
  12. 26
    The encrypted user certificate further relates to at least one of at least a portion of the user's set of personal information and at least one related to remote access by the user to a device that is operational controlled by the server. 22. Claim 22 includes one operational attribute, a set of application-specific data for adding specific security to the encrypted user certificate, and at least a unique key associated with the authentication of the user. The server described in. 前記暗号化されたユーザ証明書が、更に、前記ユーザの個人情報のセットの少なくとも一部分の少なくとも1つと、前記ユーザによる前記サーバにより動作上の制御を受ける装置へのリモート・アクセスに関連した少なくとも1つの動作上の属性と、特定のセキュリティを前記暗号化されたユーザ証明書に加えるためのアプリケーション特有のデータのセットと、前記ユーザの認証に関連した少なくとも独特のキーと、を含む、請求項22に記載のサーバ。
  13. 27
    It includes a processor and a memory for storing instructions that can be operated by the processor and providing remote access information to the user, the instruction including encrypting at least one personal attribute of the user. The encryption includes steps to receive the user's encrypted user certificate from the client over the network, and remote access information that facilitates remote access by the user to devices that are operational controlled by the server. A server that performs a step of generating based on the validation of a encrypted user certificate and a step of providing the remote access information to the client over the network. プロセッサと、 前記プロセッサによって動作し得る命令を記憶し、リモート・アクセス情報をユーザに提供するためのメモリと、 を含み、前記命令が、 前記ユーザの少なくとも1つの個人属性を暗号化したものを含む前記ユーザの暗号化されたユーザ証明書をクライアントからネットワークを介して受け取るステップと、 サーバにより動作上の制御を受ける装置への前記ユーザによるリモート・アクセスを容易にするリモート・アクセス情報を、前記暗号化されたユーザ証明書の検証に基づいて生成するステップと、 前記ネットワークを介して前記クライアントに前記リモート・アクセス情報を提供するステップと、 を実行する、サーバ。
  14. 29
    28. Claim 28, wherein the step of generating the remote access information based on the validity of the encrypted user certificate further comprises a step of decrypting the encrypted user data. server. 前記暗号化されたユーザ証明書の有効性に基づいて前記リモート・アクセス情報を生成するステップが、更に、前記暗号化されたユーザ・データを暗号化解除するステップを含む、請求項28に記載のサーバ。
Independent claims14