Processor configuring authentication system, authentication system and its operation method
Abstract
[Subject] It aims at controlling or preventing the personal identification by an unjust means in an authentication system. [Solution means] 2nd partial authentication data that is some authentication data and is the remainder of the 1st partial authentication data memorized by other equipment, A memory means to memorize the 2nd partial processing data that is some processing data used in the case of the collation processing of input data and authentication data, and is the remainder of the 1st partial processing data memorized by other equipment, A receiving means to receive the 1st partial authentication data and the 1st partial processing data, It has an attestation means which attests by performing processing which compares a data coupling means to generate authentication data from the 1st partial authentication data and the 2nd partial authentication data, and to generate processing data from the 1st partial processing data and the 2nd partial processing data, and input data and authentication data. [Selection figure] Fig. 1
Term
Term ended
Projected expiry passed 10 May 2026, 0.4 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
9 claims: 4 independent, 5 dependent
- 1A processing device that constitutes an authentication system, which is a part of authentication data that is prepared in advance for collation with input input data, and is stored in a storage means of another device that constitutes the authentication system. It is a part of the processing data used when executing at least a part of the process of collating the input data with the authentication data with the second partial authentication data which is the remainder of the first partial authentication data. The storage means for storing the second partial processing data, which is the remainder of the first partial processing data stored in the storage means of the other device, and the first partial authentication data from the other device. A receiving means for receiving the first partial processing data, a first data combining means for generating the authentication data from the first partial authentication data and the second partial authentication data, and the first Authentication is performed by executing a process of collating the input data with the authentication data based on the processing data and the second data combining means for generating the processing data from the partial processing data and the second partial processing data. A processing device comprising an authentication means for performing the above. 認証システムを構成する処理装置であって、 入力される入力データと照合するためにあらかじめ用意されている認証データの一部であって、認証システムを構成する他の装置の記憶手段に記憶されている第1の部分認証データの残余である第2の部分認証データと、前記入力データと前記認証データとを照合する処理の少なくとも一部を実行する際に使用される処理データの一部であって、前記他の装置の記憶手段に記憶されている第1の部分処理データの残余である第2の部分処理データとを記憶する記憶手段と、 前記他の装置から前記第1の部分認証データと前記第1の部分処理データとを受信する受信手段と、 前記第1の部分認証データ及び前記第2の部分認証データから前記認証データを生成する第1のデータ結合手段と、 前記第1の部分処理データ及び前記第2の部分処理データから前記処理データを生成する第2のデータ結合手段と、 前記処理データに基づいて、前記入力データと前記認証データとを照合する処理を実行して認証を行う認証手段とを備える、処理装置。
- 7In the processing devices according to claims 1 to 4, the processing device is an authentication terminal device of an authentication system, and is an input data acquisition means for acquiring input data and two partial authentication data divided by a control device of the authentication system. A processing device including a receiving means for receiving one of the data and one of the two partial processing data divided by the control device. 請求項1から4に記載の処理装置において、 前記処理装置は、認証システムの認証端末装置であり、 入力データを取得する入力データ取得手段と、 認証システムの制御装置が分割した2つの部分認証データの一方と前記制御装置が分割した2つの部分処理データの一方とを受信する受信手段と、 を備える、処理装置
- 8An authentication system consisting of an authentication terminal device and a control device, wherein the authentication terminal device is an input data acquisition means for acquiring input data and a part of authentication data prepared in advance for collation with the input data. The first partial authentication data, which is a part of the processing data used when executing at least a part of the processing for collating the input data with the authentication data, is stored. The control device includes a second partial authentication data which is a remainder of the first partial authentication data, and a second partial processing data which is a remainder of the first partial processing data. A storage means to be stored, a first data combining means for generating the authentication data from the first partial authentication data and the second partial authentication data, the first partial processing data, and the second partial processing. A second data combining means for generating the processed data from the data, an authentication means for performing authentication by executing a process of collating the input data with the authentication data based on the processed data, and the authentication data. The first data division means to divide into two partial authentication data, It includes a second data dividing means for dividing the processed data into two partial processed data, and a communication means for transmitting and receiving one of the two partial authentication data and one of the two partial processed data to and from the authentication terminal device. , Authentication system. 認証端末装置と制御装置とからなる認証システムであって、 前記認証端末装置は、 入力データを取得する入力データ取得手段と、 前記入力データと照合するためにあらかじめ用意されている認証データの一部である第1の部分認証データと、前記入力データと前記認証データとを照合する処理の少なくとも一部を実行する際に使用される処理データの一部である第1の部分処理データとを記憶する記憶手段とを備え、 前記制御装置は、 前記第1の部分認証データの残余である第2の部分認証データと、前記第1の部分処理データの残余である第2の部分処理データとを記憶する記憶手段と、 前記第1の部分認証データ及び前記第2の部分認証データから前記認証データを生成する第1のデータ結合手段と、 前記第1の部分処理データ及び前記第2の部分処理データから前記処理データを生成する第2のデータ結合手段と、 前記処理データに基づいて、前記入力データと前記認証データとを照合する処理を実行して認証を行う認証手段と、 前記認証データを2つの部分認証データに分割する第1のデータ分割手段と、 前記処理データを2つの部分処理データに分割する第2のデータ分割手段と、 前記2つの部分認証データの一方と2つの部分処理データの一方とを前記認証端末装置と送受信する通信手段とを備える、 認証システム。
- 9It is a data management method of an authentication system consisting of an authentication terminal device and a control device, and the control device divides authentication data prepared in advance for collation with input data in the authentication terminal device into two partial authentication data. Then, the control device divides the processing data used when executing at least a part of the process of collating the input data with the authentication data into two partial processing data, and the authentication terminal device is described in the above. One of the two divided partial authentication data is stored as the first partial authentication data in the storage means of the authentication terminal device, and one of the two divided partial processing data is stored as the first partial processing data in the authentication terminal device. Stored in the means, the control device stores the other of the divided two partial authentication data as the second partial authentication data in the storage means of the control device, and stores the other of the divided two partial processing data in the second. It is stored in the storage means of the control device as the partial processing data of the above, and at a predetermined time, the control device authenticates the authentication device by the authentication terminal device confirmation data, and the authentication terminal device controls the control by the control device confirmation data. Authenticate the device and When the control device can authenticate the terminal authentication device and the authentication terminal device can authenticate the control device, the control device combines the first partial authentication data and the second partial authentication data. To restore the authentication data, combine the first partial processing data and the second partial processing data to restore the processed data, and use the restored authentication data as the first partial authentication data and the first partial processing data. It is divided into two partial authentication data different from the partial authentication data of 2, and the restored processing data is divided into two partial processing data different from the first partial processing data and the second partial processing data. The authentication terminal device receives one of the two divided partial authentication data as the first partial authentication data from the control device and stores it in the storage means of the authentication terminal device, and stores one of the divided partial processing data. The first partial processing data is received from the control device and stored in the storage means of the authentication terminal device, and the control device stores the other of the divided partial authentication data as the second partial authentication data of the control device. The other of the divided partial processing data is stored in the storage means of the control device as the second partial processing data. When the authentication terminal device cannot authenticate the control device, the authentication terminal device deletes at least one of the first partial authentication data or the first partial processing data, and the control device causes the control device to delete at least one of the first partial authentication data or the first partial processing data. A data management method of an authentication system, wherein when the authentication terminal device cannot be authenticated, the control device deletes at least one of the second partial authentication data or the second partial processing data. 認証端末装置と制御装置とからなる認証システムのデータ管理方法であって、 前記制御装置は、認証端末装置に入力データと照合するためにあらかじめ用意されている認証データを2つの部分認証データに分割し、 前記制御装置は、前記入力データと前記認証データとを照合する処理の少なくとも一部を実行する際に使用される処理データを2つの部分処理データに分割し、 前記認証端末装置は、前記分割した2つの部分認証データの一方を第1の部分認証データとして認証端末装置の記憶手段に記憶し、 前記分割した2つの部分処理データの一方を第1の部分処理データとして認証端末装置の記憶手段に記憶し、 前記制御装置は、前記分割した2つの部分認証データの他方を第2の部分認証データとして制御装置の記憶手段に記憶し、 前記分割した2つの部分処理データの他方を第2の部分処理データとして制御装置の記憶手段に記憶し、 所定の時間に、前記制御装置は、認証端末装置確認データにより前記認証装置の認証を行い、前記認証端末装置は制御装置確認データにより前記制御装置の認証を行い、 前記制御装置が前記端末認証装置を認証でき、前記認証端末装置が前記制御装置を認証できた場合には、前記制御装置は、前記第1の部分認証データと前記第2の部分認証データを結合して認証データを復元し、前記第1の部分処理データと前記第2の部分処理データとを結合して処理データを復元し、前記復元した認証データを前記第1の部分認証データと前記第2の部分認証データとは異なる2つの部分認証データに分割し、前記復元した処理データを前記第1の部分処理データと前記第2の部分処理データとは異なる2つの部分処理データに分割し、前記認証端末装置は、前記分割した2つの部分認証データの一方を第1の部分認証データとして前記制御装置から受信して認証端末装置の記憶手段に記憶し、前記分割した部分処理データの一方を第1の部分処理データとして前記制御装置から受信して認証端末装置の記憶手段に記憶し、前記制御装置は、前記分割した部分認証データの他方を第2の部分認証データとして制御装置の記憶手段に記憶し、前記分割した部分処理データの他方を第2の部分処理データとして制御装置の記憶手段に記憶し、 前記認証端末装置が前記制御装置を認証できなかった場合には、前記認証端末装置は、前記第1の部分認証データ又は前記第1の部分処理データの少なくとも一方を削除し、 前記制御装置が前記認証端末装置を認証できなかった場合には、前記制御装置は、前記第2の部分認証データ又は前記第2の部分処理データの少なくとも一方を削除する、 認証システムのデータ管理方法。
Independent claims4
83 paragraphs, as filed
The present invention relates to an authentication system that performs identity verification by a control device and a terminal device.
In an authentication system consisting of a control device and an authentication terminal device, authentication is performed by collating the input data input to the authentication terminal device with the authentication data prepared in advance. Here, if all the authentication data is stored in either the control device or the authentication terminal device, the authentication data may be decrypted and illegally authenticated. Therefore, in the conventional authentication system, there is a technique of dividing the authentication data using an electronic tally, holding the divided authentication data in each of the control device and the authentication terminal device, and preventing the authentication data from being decrypted. (Patent Document 1). According to the prior art, for example, even if one device is stolen, it is difficult to restore the authentication data unless both devices are stolen.
<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2004-234633</text></patcit>
<p> However, in the prior art, the authentication data is divided and stored in the control device and the authentication terminal device, but the processing data used when collating the input data and the authentication data is stored in either the control device or the authentication terminal device. It had been. Here, the processed data is data such as an algorithm used when collating the input data with the authentication data, and is, for example, data such as an encryption key, a function, an authentication program, and a library. If the control device or authentication terminal device that stores the processed data is stolen, the processed data may be analyzed to forge the authentication data and verify the identity. Further, when the processing data is stored in the control device and the authentication terminal device is replaced, the processed data is eavesdropped and analyzed by the access to the control device from the replaced authentication terminal device, and the authentication data is forged. There is a possibility that identity verification will be carried out.</p><p> Further, if both the control device and the authentication terminal device are stolen, the authentication data and the processing data can be easily analyzed, and there is a high possibility that the identity verification will be performed by forgery of the authentication data.</p><p> An object of the present invention has been made to solve at least a part of the above problems, and an object of the present invention is to suppress or prevent identity verification by improper means.</p>
<p> In order to solve the above problems, the processing device according to the present invention is a processing device constituting an authentication system, and authentication data prepared in advance for collation with input data input via the authentication terminal device. The second partial authentication data, which is a part of the first partial authentication data stored in the storage means of the other device constituting the authentication system, and the input data and the authentication data. A second part that is a part of the processing data used when executing at least a part of the collating process and is the remainder of the first partial processing data stored in the storage means of the other device. A storage means for storing processed data, a receiving means for receiving the first partial authentication data and the first partial processing data from the other device, the first partial authentication data, and the second portion. A first data combining means for generating the authentication data from the authentication data, a second data combining means for generating the processing data from the first partial processing data and the second partial processing data, and the processing data. Based on the above, an authentication means for performing authentication by executing a process of collating the input data with the authentication data is provided.</p><p> According to the present invention, the processing apparatus stores not only the authentication data but also only a part of the processing data. Therefore, even if the partially processed data is known to a third party by an illegal means such as theft or eavesdropping of the processing device, it is difficult to restore the entire processed data. If the processed data is not restored, it is difficult to analyze and forge the identification data, so it is possible to suppress and prevent identity verification by unauthorized means.</p><p> The processing apparatus according to the present invention further has device confirmation data for confirming whether the other device is legitimate, and when the device confirmation data satisfies a predetermined condition, the first coupling means is The authentication data is generated from the first partial authentication data and the second partial authentication data, and the second combining means obtains the processing data from the first partial processing data and the second partial processing data. The authentication means generates and executes a process of collating the input data with the authentication data based on the processing data to perform authentication.</p><p> According to the present invention, the processing apparatus confirms that the other apparatus is a legitimate apparatus, and after confirming, generates / restores the authentication data and the processing data. Therefore, if it is not possible to confirm that the other device is a legitimate device, the authentication data and processing data will not be restored, so the authentication data and processing data will not be read, and identity verification by unauthorized means will be suppressed. , Can be prevented.</p><p> When the device confirmation data does not satisfy a predetermined condition, the processing device according to the present invention deletes at least one of the second partial authentication data and the second partial processing data from the storage means. ..</p><p> According to the present invention, the processing device stores at least one of the second partial authentication data and the second partial processing data when it cannot be confirmed that the other device is a legitimate device. Authentication data or processed data cannot be restored because it is deleted from. As a result, it is possible to suppress or prevent identity verification by improper means.</p><p> The processing apparatus according to the present invention includes a battery power source.</p><p> According to the present invention, for example, a processing device provided with a battery power source continues to operate for a certain period of time because power is supplied from the battery power source even if the device is stolen. However, the processing device cannot confirm the other device during that time. Since the processing device deletes at least one of the second partial authentication data and the second partial processing data from the storage means, the authentication data or the processed data cannot be restored. As a result, it is possible to suppress or prevent identity verification by improper means.</p><p> The processing device according to the present invention is a control device for an authentication system, a first data dividing means for dividing the authentication data into two partial authentication data, and a second data dividing means for dividing the processing data into two partial processing data. Data division means and a transmission means for transmitting one of the two partial authentication data and one of the two partial processing data to the other device.</p><p> According to the present invention, since the processing device includes the data dividing means in the device, it is not necessary to divide the authentication data and the processing data by using, for example, another server device. Therefore, there is no possibility that authentication data and processing data will be leaked from other server devices. As a result, it is possible to suppress and prevent identity verification by unauthorized means using the lost authentication data and processed data.</p><p> In the processing apparatus according to the present invention, the first dividing means generates two partial authentication data different from the first partial authentication data and the second partial authentication data, and the second dividing means , The first partial processing data and two partial processing data different from the second partial processing data are generated, and the transmission means is one of the two generated partial authentication data and the generated partial processing data. One is transmitted to the other device, and the storage means stores the other of the two generated partial authentication data and the other of the two generated partial authentication data.</p><p> According to the present invention, the partial authentication data divided and generated by the dividing means of the processing device and the partial processing data are different each time, so that even if the partial authentication data and the partial processing data at a certain time are eavesdropped, the authentication data If the processing data is subdivided, the authentication data and the processing data are not restored from the eavesdropped partial authentication data and the partial processing data. Therefore, the security against data eavesdropping is enhanced, and it is possible to suppress or prevent identity verification by unauthorized means.</p><p> The processing device according to the present invention is an authentication terminal device of an authentication system, and the input data acquisition means for acquiring input data, one of the two partial authentication data divided by the control means of the authentication system, and the control device are divided. It is provided with a receiving means for receiving one of the two partially processed data. According to the present invention, since the authentication terminal device has only one of the partial authentication data and one of the partial processing data, for example, the partial authentication data and the partial processing data stored in the authentication terminal device may be eavesdropped. Even if this is done, it is difficult to restore the authentication data and the processed data, and it is possible to suppress or prevent identity verification by unauthorized means.</p><p> The authentication system according to the present invention is an authentication system including an authentication terminal device and a control device, and the authentication terminal device is prepared in advance with an input data acquisition means for acquiring input data and for collating with the input data. The first partial authentication data, which is a part of the authentication data, is a part of the processing data used when executing at least a part of the process of collating the input data with the authentication data. The control device includes a storage means for storing the partial processing data of 1, the second partial authentication data which is the remainder of the first partial authentication data, and the remainder of the first partial processing data. A storage means for storing the second partial processing data, a first data combining means for generating the authentication data from the first partial authentication data and the second partial authentication data, and the first partial processing. Authentication is performed by executing a process of collating the input data with the authentication data based on the data and the second data combining means for generating the processing data from the second partial processing data and the processing data. An authentication means, a first data division means for dividing the authentication data into two partial authentication data, a second data division means for dividing the processed data into two partial processing data, and the two partial authentication data. A communication means for transmitting and receiving one of the data and one of the two partially processed data to and from the authentication terminal device is provided.</p><p> According to the present invention, the authentication system separately holds the authentication data and the processing data between the authentication terminal device and the control device. Only one partial authentication data and one partial processing data can be obtained from one device. Since it is difficult to restore the authentication data and the processed data from one partial authentication data and one partial processing data, it is possible to suppress or prevent identity verification by unauthorized means.</p><p> The operation method of the authentication system according to the present invention is a data management method of an authentication system including an authentication terminal device and a control device, and the control device is prepared in advance in the authentication terminal device to collate with input data. The authentication data is divided into two partial authentication data, and the control device divides the processing data used when executing at least a part of the process of collating the input data with the authentication data into two partial processing data. The authentication terminal device stores one of the two divided partial authentication data as the first partial authentication data in the storage means of the authentication terminal device, and stores one of the two divided partial processing data as the first partial authentication data. The partial processing data of 1 is stored in the storage means of the authentication terminal device, and the control device stores the other of the two divided partial authentication data as the second partial authentication data in the storage means of the control device, and the division is performed. The other of the two partial processing data is stored as the second partial processing data in the storage means of the control device, and at a predetermined time, the control device authenticates the authentication terminal device with the authentication terminal device confirmation data, and the above-mentioned The terminal authentication device authenticates the control device based on the control device confirmation data, and when the control device can authenticate the terminal authentication device and the authentication terminal device can authenticate the control device, the control device can be used. The first partial authentication data and the second partial authentication data are combined to restore the authentication data, and the first partial processing data and the second partial processing data are combined to restore the processed data. The restored authentication data is divided into two partial authentication data different from the first partial authentication data and the second partial authentication data, and the restored processing data is divided into the first partial processing data and the second partial processing data. The authentication terminal device is divided into two partial processing data different from the partial processing data of the above, and the authentication terminal device receives one of the two divided partial authentication data as the first partial authentication data from the control device and receives the authentication terminal device. It is stored in the storage means, and one of the divided partial processing data is received from the control device as the first partial processing data and stored in the storage means of the authentication terminal device.The other of the divided partial authentication data is stored in the storage means of the control device as the second partial authentication data, and the other of the divided partial processing data is stored in the storage means of the control device as the second partial processing data. When the authentication terminal device cannot authenticate the control device, the authentication terminal device deletes at least one of the first partial authentication data or the first partial processing data, and the control device causes the control device to delete at least one of the first partial authentication data or the first partial processing data. If the authentication terminal device cannot be authenticated, the control device deletes at least one of the second partial authentication data or the second partial processing data.</p><p> The present invention can be realized in various aspects, such as a processing device, an authentication system, and a data management method of an authentication system.</p>
A. Configuration of the control device 200 of the authentication system 100 according to the present embodiment: The control device 200 constituting the authentication system 100 according to the present embodiment will be described with reference to FIG. FIG. 1 is an explanatory diagram showing a configuration of a control device 200 constituting the authentication system 100. In this embodiment, the authentication system 100 is used to control entry and exit from a non-security area (eg, outdoors) to a security area (eg, indoors or indoors with restricted access), and the control device 200 Is installed in the security area.
The control device 200 includes a CPU 201, a ROM 202, a hard disk 203, a RAM 204, a CD-ROM 205, an input interface 206, an output interface 207, and an authentication terminal interface 208.
The CPU 201 is the center of the control device 200, controls the operation of the entire control device 200, performs various calculations, stores the calculation results on the hard disk 203, and displays the calculation results on the display 209 via the output interface 207. Communicates with the authentication terminal device 300 via the authentication terminal interface 208.
The ROM 202 stores a BIOS (Basic Input Output System) that controls peripheral devices such as a hard disk 203 connected to the control device 200, a keyboard 210 connected via an input interface 206, and a mouse 211, and is usually rewritable. A flash memory, which is a non-volatile memory, is used.
The hard disk 203 is a storage device that stores an OS, data, and applications. For example, partial authentication data, partial processing data, and authentication terminal device confirmation data are stored as data, and an authentication program, division program, combination program, and authentication terminal device confirmation program are stored as applications.
The RAM 204 is a rewritable volatile memory, and the operating system (hereinafter referred to as OS) and applications of the control device 200 stored in the hard disk 203 are copied onto the RAM 204 and executed on the RAM 204. .. The RAM 204 temporarily stores the result of the calculation by the CPU 201 or the data being calculated.
The authentication data is data prepared in advance for collating with the input data input via the authentication terminal device for authentication. In this embodiment, the authentication data used is a data of the blood vessel pattern of the finger vein. The partial authentication data is a part of the authentication data.
The processing data is processing data used when executing at least a part of the processing of collating the input data with the authentication data. That is, it is a data of an algorithm or the like used when collating the input data with the authentication data, and is, for example, a data of an encryption key, a function, an authentication program, a library, or the like. The partial processing data is a part of the processing data.
The authentication terminal device confirmation data is data for confirming whether the authentication terminal device 300 connected to the control device 200 is a legitimate device. For example, the identification number of the authentication terminal device 300 may be used. In order to prevent forgery of the identification number of the authentication terminal device 300, it may be encrypted. The CPU 201 collates the authentication terminal device data received from the authentication terminal device 300 with the authentication terminal device confirmation data to confirm that the authentication terminal device 300 is a legitimate device.
The authentication program is a program that authenticates by collating the input data from the authentication terminal input with the authentication data prepared in advance.
The division program is a program that divides the authentication data into a first partial authentication data stored in the hard disk 203 of the control device 200 and a second partial authentication data stored in the authentication terminal device 300. Further, the division program divides the processing data into the first partial processing data stored in the hard disk 203 of the control device 200 and the second partial processing data stored in the authentication terminal device 300. The division program divides the authentication data and the processing data into different partial authentication data and partial processing data each time. As a result, when a new division is performed, it becomes impossible to restore the authentication data and the processed data from the previously divided partial authentication data and partial processing data.
The combination program is a program that generates authentication data by combining the first partial authentication data stored in the hard disk 203 of the control device 200 and the second partial authentication data stored in the authentication terminal device 300. Further, the combining program combines the first partial processing data stored in the hard disk 203 of the control device 200 and the second partial processing data stored in the authentication terminal device 300 to generate the authentication data.
The authentication device confirmation program is a program for determining whether the authentication terminal device is a legitimate device.
The CD-ROM device 205 is a read-only storage device for a computer that uses a compact disc (hereinafter referred to as "CD"). For example, it is used when a program is installed in the control device 200 and the deleted authentication data and processing data are re-entered. The authentication data and processing data are encrypted and recorded on a CD-ROM in order to make it difficult to read by other devices.
The input interface 206 connects between an input device such as a keyboard 210 and a mouse 211 and a control device 200, for example. The output interface 207 connects the control device 200 and the display 209, and outputs, for example, the authentication result to the display 209. The authentication terminal interface 208 connects the control device 200 and the authentication terminal device 300.
B. Configuration of the authentication terminal device 300 of the authentication system 100 according to this embodiment: The configuration of the authentication terminal device 300 of the authentication system 100 according to this embodiment will be described with reference to FIG. FIG. 2 is an explanatory diagram showing the configuration of the authentication terminal device 300 of the authentication system 100. The authentication terminal device 300 is installed in both a security area and a non-security area, for example.
The authentication terminal device 300 includes a CPU 301, a flash memory 302, a RAM 303, a vein measurement unit 304, a control device interface 305, a battery 306, and a door control unit 307.
The CPU 301 is the center of the authentication terminal device 300 and controls the overall operation of the authentication terminal device 300.
The flash memory 302 is a rewritable non-volatile memory that stores an OS, data, and an application. For example, partial authentication data, partial processing data, and control device confirmation data are stored as data, and for example, a vein measuring unit control program, an image processing program, and a control device confirmation program are stored as applications.
Of the authentication data, the flash memory 302 stores the second partial authentication data that is not stored in the hard disk 203 of the control device 200. Further, among the processed data, the flash memory 302 stores the second partial processed data that is not stored in the hard disk 203 of the control device 200.
The control device confirmation data is data for confirming whether the control device 200 connected to the authentication terminal device 300 is a legitimate device, such as an identification number of the control device 200. In addition, in order to prevent forgery of the identification number of the control device 200, it may be encrypted.
The vein measurement unit control program is a program that controls the vein measurement unit 304 that measures the blood vessel pattern of the finger vein. The image processing program is a program that converts an image of a blood vessel pattern of a finger vein measured by the vein measuring unit 304 into a digital signal and generates input data. The control device confirmation program is a program for determining whether the control device 200 is a legitimate device.
The RAM 303 is a rewritable volatile memory, and the operating system (hereinafter referred to as OS) and applications of the authentication terminal device 300 stored in the flash memory 302 are copied onto the RAM 303 and executed on the RAM 303. .. The RAM 303 temporarily stores the result of the calculation by the CPU 301 or the data being calculated.
The vein measuring unit 304 places a finger on the measuring table (not shown), and when the switch 311 at the back of the measuring table is pressed with a fingertip, the near-infrared light source 308 installed on the upper part of the measuring table. The finger is irradiated with near-infrared rays, and the transmitted light is photographed by the camera 309 installed at the bottom of the measuring table to measure the finger vein pattern.
The control device interface 305 connects the authentication terminal device 300 and the control device 200. The battery 306 is an auxiliary power source for operating the authentication terminal device 300 for a certain period of time even when the AC power of the authentication terminal device 300 is turned off.
The door control unit 307 controls the opening and closing of the key of the security door 310 connected to the authentication terminal device 300.
C. Operation at the time of authentication of the authentication system 100 according to this embodiment: With reference to FIGS. 3 to 11, the operation at the time of authentication of the authentication system 100 according to this embodiment and the storage state of the authentication data and the processing data are explained. To do. FIG. 3 is an explanatory diagram showing a flowchart up to device confirmation of the authentication system 100 according to this embodiment. FIG. 4 is an explanatory diagram showing a flowchart of a process in which the control device confirms the authentication terminal device. FIG. 5 is an explanatory diagram showing a flowchart of a process in which the authentication terminal device confirms the control device. FIG. 6 is an explanatory diagram showing a flowchart from device confirmation to authentication of the authentication system 100 according to this embodiment. FIG. 7 is an explanatory diagram showing a flowchart of the authentication data of the authentication system 100 according to the present invention and the subdivision processing of the processing data. In FIGS. 3 to 7, the flow on the left side is the operation flow of the control device, and the flow on the right side is the operation flow of the authentication terminal device.
FIG. 8 is a conceptual explanatory diagram of the storage state of the authentication data and the processing data when neither the control device nor the authentication terminal device is stolen. FIG. 9 is a conceptual explanatory diagram of the storage state of the authentication data and the processing data when the authentication terminal device is stolen. FIG. 10 is a conceptual explanatory diagram of the storage state of the authentication data and the processed data when the control device is stolen. FIG. 11 is a conceptual explanatory diagram of the storage state of the authentication data and the processing data when both the control device and the authentication terminal device are stolen.
First, the operation from FIG. 3 and FIGS. 8 to 11 to the device confirmation will be described. When the authentication system is started, the authentication data is the first partial authentication data and the second partial authentication data, as shown in FIGS. 8 (a) to 11 (a) and 8 (b) to 11 (b). It is divided into partial authentication data, and the processed data is divided into a first partial processing data and a second partial processing data. The division is performed, for example, by arranging the authentication data in a line and dividing the data string into two parts before and after by a random number. Since the division only divides the data string into two parts, the authentication data can be easily combined / restored. The first partial authentication data and the first partial processing data are stored in the hard disk 203 of the control device 200, and the second partial authentication data and the second partial processing data are stored in the flash memory 302 of the authentication terminal device 300. There is.
The CPU 301 of the authentication terminal device 300 waits until the switch 311 of the vein measurement unit 304 is pressed (step S410, Yes) and the authentication operation is started (step S400). When the authentication operation is started, the CPU 301 acquires the authentication input data for verifying the identity by collating with the authentication data prepared in advance (step S420).
When a finger is placed on the measuring table (not shown) and the switch 311 at the back of the measuring table is pressed with the fingertip, the near infrared light source 308 installed at the top of the measuring table sends the near infrared ray to the finger. Be irradiated. Reducing red blood cells in veins Hemoglobin absorbs light of near-infrared wavelengths. When the transmitted light is photographed with the camera 309 installed at the bottom of the measuring table, only the vein part appears black. As a result, the vascular pattern of the finger vein is measured. The CPU 301 processes the measured blood vessel pattern of the finger vein using an image processing program, creates authentication input data, and sends the authentication input data to the control device 200 (step S430).
The CPU 201 of the control device 200 waits until the authentication input data is received from the authentication terminal device 300 (step S450, Yes) until it is transmitted (step S440).
The CPU 301 confirms the control device 200 even if the switch 311 of the vein measuring unit 304 is not pressed (step S410, No) and the predetermined time elapses (step S460, Yes) (step S470). On the other hand, the CPU 201 confirms the authentication terminal device 300 (step S490) even if the input data is not received (step S450, No) and the predetermined time has elapsed (step S480, Yes). The predetermined time may be a fixed time or a random time.
Next, a process in which the control device 200 confirms the authentication terminal device 300 will be described with reference to FIGS. 4 and 8 to 9. The CPU 201 of the control device 200 requests the authentication terminal device 300 for the authentication terminal device identification data (step S500). Upon receiving the request for the authentication terminal device identification data, the CPU 301 of the authentication terminal device 300 transmits the authentication terminal device identification data to the control device 200 (step S510).
The CPU 201 receives the authentication terminal device identification data (step S520) and confirms the authentication terminal device 300 (step S530). The CPU 201 compares the received authentication terminal device identification data with the authentication terminal device confirmation data stored in the hard disk 203, and determines whether the authentication terminal device 300 is a legitimate device. When the CPU 201 cannot confirm that the authentication terminal device 300 is a legitimate device (step S530, No), the CPU 201 stores the first partial authentication stored in the hard disk 203 as shown in FIG. 9 (c). Delete the data, the first partial processing data (step S540). As shown in FIG. 9D, when the first partial authentication data and the first partial processing data are deleted, the authentication data and the processing data are not restored.
When the CPU 201 can confirm that the authentication terminal device 300 is a legitimate device (step S530, Yes), the CPU 201 outputs the second partial authentication data and the second partial processing data to the authentication terminal device 300. Request (step S550).
When the CPU 301 of the authentication terminal device 300 receives a request for the second partial authentication data and the second partial processing data from the control device 200, the CPU 301 reads the second partial authentication data and the second partial processing data from the flash memory 302. , Send to controller 200 (step S560).
The CPU 201 receives the second partial authentication data and the second partial processing data (step S570). As shown in FIG. 8 (c), the CPU 201 reads the first partial authentication data from the hard disk 203, combines it with the received second partial authentication data to restore the authentication data, and restores the authentication data from the hard disk 203 to the first part. The processed data is read and combined with the received second partial processed data to restore the processed data (step S580). Restoration is performed, for example, by simply combining the first partial authentication data and the second partial authentication data, and simply combining the first partial processing data and the second partial processing data.
When simply combining the second partial authentication data and the first partial authentication data, for example, the control device 200 holds the public key A and the private key B, and the authentication control device 300 holds the public key C and the private key. It is good to have D. When sending the second partial authentication data and the second partial processing data to the control device 200, the CPU 301 of the authentication terminal device 300 encrypts and sends the second partial authentication data with the public key A. The CPU 201 of the control device 200 receives the encrypted second partial authentication data and the second partial processing data. The CPU 201 decodes the second partial authentication data and the second partial processing data. CPU201 restores the authentication data and the processed data by simply combining the first partial authentication data and the second partial authentication data, and simply combining the first partial processing data and the second partial processing data. Can be executed. In the encrypted state, the authentication data is not restored even if the second partial authentication data is simply combined with the first partial authentication data. Further, even if the second partial authentication data and the second partial processing data during communication are eavesdropped, it is difficult to decrypt the second partial authentication data and the second partial processing data.
When the CPU 201 cannot receive the second partial authentication data and the second partial processing data (step S570, No), or there is an abnormality in the second partial authentication data or the second partial processing data, the authentication data, If the processed data cannot be restored (step S580, No), the first partial authentication data and the second partial processing data are deleted from the hard disk 203 as shown in FIG. 9 (c) (step S540). The case where the second partial authentication data is abnormal is, for example, the case where the checksum of the second partial authentication data does not match. When the authentication data cannot be restored, for example, when the second partial authentication data cannot be decrypted with the private key B, or when the checksum of the second authentication data decrypted with the private key B does not match, the restored authentication data If the checksum of is not correct. The same applies to the processed data. The CPU 201 displays on the display 209 that the authentication terminal device 300 is abnormal, and terminates the operation of the control device 200.
When the authentication data and the processing data can be restored (step S580, Yes), the CPU 201 performs collation of the input data and the authentication data, or subdividing the authentication data and the processing data. The CPU 301 waits for the collation result of the input data and the authentication data, or waits for the authentication data, the partial authentication data obtained by subdividing the processing data, and the partial processing data to be transmitted.
The process in which the authentication terminal device 300 confirms the control device 200 will be described with reference to FIGS. 5, 8, 10, and 11. The CPU 301 of the authentication terminal device 300 requests the control device identification data from the control device 200 (step S600). Upon receiving the request for the control device identification data, the CPU 201 of the control device 200 transmits the control device identification data to the authentication terminal device 300 (step S610).
The CPU 301 receives the controller identification data (step S620) and confirms the controller 200 (step S630). The CPU 301 compares the received control device identification data with the control device confirmation data stored in the flash memory 302, and determines whether the control device 200 is a legitimate device. When the CPU 301 cannot confirm that the control device 200 is a legitimate device (step S630, No), the CPU 301 stores the second part stored in the flash memory 302 as shown in FIG. 10 (c). Delete the authentication data and the second partial processing data (step S640). When the second partial authentication data and the second partial processing data are deleted, the authentication data and the processed data are not restored as shown in FIG. 10 (d).
If both the authentication terminal device 300 and the control device 200 are stolen, the authentication terminal device 300 operates on the battery 306, but the control device 200 does not operate because the power is cut off. Therefore, since the CPU 301 of the authentication terminal device 300 cannot confirm the control device 200, the second partial authentication data and the second partial processing data are deleted as shown in FIG. 11 (c)). When the power of the control device 200 is restored, the second partial authentication data and the second partial processing data are deleted from the authentication terminal device 300, so that the CPU 201 is the second from the authentication terminal device 300. The partial authentication data and the second partial processing data cannot be received. As a result, the CPU 201 deletes the first partial authentication data and the first partial processing data, as shown in FIG. 11 (d). In either case, the authentication data and processed data cannot be restored as shown in Fig. 11 (e).
When the CPU 301 can confirm that the control device 200 is a legitimate device (step S630, Yes), the CPU 301 requests the control device 200 for the first partial authentication data and the first partial processing data. (Step S650).
When the CPU 201 of the control device 200 receives a request for the first partial authentication data and the first partial processing data from the authentication terminal device 300, the CPU 201 reads the first partial authentication data and the first partial processing data from the hard disk 203. It is transmitted to the authentication terminal device 300 (step S660).
The CPU 301 receives the first partial authentication data and the first partial processing data (step S670). As shown in FIG. 8 (c), the CPU 301 reads the second partial authentication data from the flash memory 302, combines it with the received first partial authentication data to restore the authentication data, and restores the authentication data from the flash memory 302 to the second. The partially processed data of is read out and combined with the received first partially processed data to restore the processed data (step S680). Restoration is performed, for example, by simply combining the first partial authentication data and the second partial authentication data, and simply combining the first partial processing data and the second partial processing data.
When sending the first partial authentication data and the first partial processing data to the authentication terminal device 300, the CPU 201 of the control device 200 encrypts the first partial authentication data and the first partial processing data with the public key C, for example. The CPU 301 of the authentication terminal device 300 receives the encrypted first partial authentication data and the first partial processing data. The CPU 301 decodes the first partial authentication data and the first partial processing data. The CPU301 restores the authentication data and the processed data by simply combining the first partial authentication data and the second partial authentication data, and simply combining the first partial processing data and the second partial processing data. Can be executed. In the encrypted state, the authentication data is not restored even if the first partial authentication data is simply combined with the second partial authentication data.
When the CPU301 cannot receive the first partial authentication data and the first partial processing data (step S670, No), or there is an abnormality in the first partial authentication data or the first partial processing data, the authentication data, If the processed data cannot be restored (step S680, No), the second partial authentication data and the second partial processing data are deleted from the flash memory 302 as shown in FIG. 10 (c) (step S640). The case where the first partial authentication data is abnormal is, for example, the case where the checksum of the first partial authentication data does not match. When the authentication data cannot be restored, for example, when the first partial authentication data cannot be decrypted with the private key D, or when the checksum of the first authentication data decrypted with the private key D does not match, the restored authentication data This is the case when the checksum of is not correct. The same applies to the processed data.
The CPU 301 waits for the collation result of the input data and the authentication data, or waits for the authentication data, the partial authentication data obtained by subdividing the processing data, and the partial processing data to be transmitted.
The process from device confirmation to authentication will be described with reference to FIG. When the CPU 201 of the control device 200 has received the authentication input data (step S700, Yes), the CPU 201 collates the authentication input data with the restored authentication data (step S710). The CPU 201 transmits the collation result to the terminal control unit 300 (step S720).
When the switch 311 of the vein measurement unit 304 is pressed (step S730, Yes), the CPU 301 of the authentication terminal device 300 receives the collation result (step S740) and determines whether or not the entry can be permitted (step S750). ). When the CPU 301 determines that the entry is permitted (step S750, Yes), the CPU 301 unlocks the security door 310 (step S760). On the other hand, when the CPU 301 determines that entry is not permitted (step S750, No), the CPU 301 maintains the lock of the security door 310 (step S770).
The subdivision processing of the authentication data and the processing data will be described with reference to FIGS. 7 and 8. The CPU 201 of the control device 200 subdivides the authentication data and the processing data, and generates the third partial authentication data, the fourth partial authentication data, the third partial processing data, and the fourth partial processing data (step S800). ). As shown in FIG. 8D, the CPU 201 divides the third partial authentication data and the fourth partial authentication data so as to be different from the first partial authentication data and the second partial authentication data, respectively. , The third partial processing data and the fourth partial processing data are divided so as to be different from the first partial processing data and the second partial processing data, respectively. The CPU 201 divides the authentication data into two parts before and after, for example, by using a random number. Since it is divided into two by random numbers, the two partial authentication data that can be created are different each time. Also, since the authentication data is only divided into two parts before and after, it can be easily restored by simply combining them.
The CPU 201 transmits the fourth partial authentication data and the fourth partial processing data to the authentication terminal device 300 (step S810), and stores the third partial authentication data and the third partial processing data in the hard disk 203 (step). S840). At this time, the CPU 201 may encrypt the fourth partial authentication data and the fourth partial processing data with the public key C and send them to the authentication terminal device 300. CPU201 deletes the restored authentication data and processing data from RAM204 (step S850).
When the CPU 301 of the authentication terminal device 300 receives the fourth partial authentication data and the fourth partial processing data from the control device 200 (step S820), the CPU 301 flashes the fourth partial authentication data and the fourth partial processing data. Store in 302 (step S830). At this time, when the fourth partial authentication data and the fourth partial processing data are encrypted, the CPU 301 decrypts the decrypted fourth partial authentication data and the fourth partial authentication data using the private key D. The partial processing data is stored in the flash memory 302. The CPU 301 returns to step S400 and waits for the switch 311 of the finger vein recognition unit 304 to be pressed.
The CPU 301 waits until the switch 311 of the finger vein recognition device 304 is pressed (step S410) (step S400). The CPU 201 returns to step S440 and waits (step S450) until it receives the authentication input data from the authentication terminal device 300 (step S440). When the switch 311 of the finger vein recognition unit 304 is pressed, or at a predetermined time, the above-mentioned contents are repeated again, and the authentication data and the processed data are restored as shown in FIG. 8 (e)).
After that, the same process is repeated every time the switch 311 of the vein recognition unit 304 is pressed or every predetermined time.
As described above, according to the present embodiment, not only the authentication data prepared in advance for collating with the input data but also at least a part of the process of collating the input data with the authentication data is executed. The processing data used for is stored separately in the control device and the authentication terminal device. It is difficult to restore the processed data from the partial processed data of one device. That is, since the partial processing data is a part of the data of the authentication algorithm or the like, it is difficult to infer / restore the entire processing data from the partial processing data. If the processed data cannot be restored, the identification data cannot be analyzed. Therefore, forgery of identification data is difficult, and identity verification by improper means can be suppressed or prevented.
According to this embodiment, for example, the control device 200 generates / restores the authentication data and the processing data after confirming that the authentication terminal device 300 is a legitimate device by the authentication terminal device identification data and the authentication terminal confirmation data. Therefore, the authentication data and the processing data are not restored until the control device 200 confirms the authentication terminal device 300. Therefore, during this period, it is difficult to read the authentication data and the processing data from the control device 200. As a result, it is possible to suppress or prevent identity verification by improper means.
According to this embodiment, the restored authentication data and the processed data itself are not stored in the hard disk 203 and the flash memory 302. For example, if the control device 200 is stolen immediately after the authentication data and the processing data are restored, the AC power is turned off, so that the restored authentication data and the processing data are erased. Therefore, even if the control device is stolen, it is possible to prevent or suppress the analysis of the authentication data and the processed data.
According to this embodiment, the control device periodically confirms that the authentication terminal device is a legitimate authentication terminal device, and if it cannot be confirmed, the first partial authentication data and the first partial processing data. Is deleted, the authentication terminal device periodically confirms that the control device is a legitimate control device, and if it cannot be confirmed, the second partial authentication data and the second partial processing data are deleted. Therefore, when the other device cannot be confirmed, for example, when the authentication terminal device or the control device is temporarily replaced, the partial authentication data and the partial processing data are deleted. As a result, the authentication data and the processed data cannot be restored even if the replaced control device and authentication terminal device are restored. As a result, it becomes difficult to analyze and forge the authentication data, and it is possible to suppress and prevent identity verification by unauthorized means.
Even if the partial authentication data or partial processing data of any of the control device and the authentication terminal device is deleted, if the authentication data and the processing data are recorded on the CD-ROM, for example, the authentication data and the authentication data and the processing data from the CD-ROM By reading the processed data, it is possible to recover the authentication data and the processed data.
According to this embodiment, when both the control device and the authentication terminal device are stolen, the control device is operated by the AC power supply, so that the power is turned off at the time of the theft. On the other hand, since the authentication terminal device has a battery 306 inside, it can operate for a certain period of time without an AC power supply. If the authentication terminal device performs the confirmation process of the control device during that period, the second partial authentication data and the second partial processing data are deleted because the control device cannot be confirmed. Therefore, even if the power of the control device is restored, the authentication data and the processing data are not restored. Further, since the second partial authentication data and the second partial processing data of the authentication terminal device do not exist, the first partial authentication data and the first partial processing data are also deleted. As a result, even if both the control device and the authentication terminal device are stolen, it is difficult to restore the authentication data and the processing data, and it is possible to suppress or prevent identity verification by unauthorized means.
According to this embodiment, since the control device includes the data division means, it is not necessary to divide the authentication data and the processing data by another server device. Therefore, there is no risk of authentication data and processing data leaking from other server devices. As a result, it is possible to suppress or prevent identity verification by improper means.
According to this embodiment, the division pattern of the authentication data and the processing data is different each time. For example, even if the partial authentication data and the partial processing data at a certain time are eavesdropped, if the authentication data and the processing data are subdivided, the eavesdropped partial authentication data and the partial processing data cannot be used. As a result, when the device that stores the eavesdropped partial authentication data and partial processing data is replaced, the authentication data and processing data are not restored. It is possible to suppress and prevent identity verification by improper means.
D. Modification example: (1) In this embodiment, the control device divides the authentication data and the processing data, but the authentication terminal device may perform the division.
(2) In the present embodiment, the CPU 201 divides the authentication data so that the first partial authentication data and the second partial authentication data are different, but at that time, the authentication data may be divided so as to partially overlap. Further, the processed data may be divided so that the first partial processed data and the second partial processed data partially overlap. Further, whether or not the data is partially duplicated, and the size of the data of the overlapping portion in the case of duplication may be determined by a random number.
(3) In this embodiment, the data of the control device identification data, the authentication terminal device identification data, the control device confirmation data, and the authentication terminal device confirmation data are not divided, but the control device identification data and the authentication terminal device identification data are not divided. , The control device confirmation data and the authentication terminal device confirmation data may be stored by dividing the data between the control device and the identification device.
(4) It is possible not to check the corresponding authentication terminal device and control device for a certain period of time after startup. This is because the corresponding authentication terminal device or control device may not be started immediately after the control device or authentication terminal device is started.
(5) In this embodiment, when the CPU 301 of the authentication terminal device 300 confirms the control device 200, the partial authentication data and the partial processing data are requested, but the partial authentication data and the partial processing data are not requested. The control device 200 may be confirmed only by the control device identification data.
(6) In this embodiment, the authentication terminal device is provided with a battery, but the control device may be provided with a battery. Further, both the control device and the authentication terminal device may be provided with batteries so that the duration of the batteries can be changed. This is because if one of them stops first, the partial authentication data and the partial processing data can be deleted from the operating device.
(7) In this embodiment, public key cryptography is used for transmitting and receiving partial authentication data and partial processing data, but common key cryptography may be used for encryption. Also, it is not necessary to use encryption.
(8) In this embodiment, the authentication system is used for entry / exit management, but it can be used as long as it requires identity verification such as ATM, electronic application, and access control to confidential data.
(9) In this embodiment, the blood vessel pattern of the finger vein is used as a means of identity verification. For example, in addition to biological information such as face shape, palm shape, fingerprint, retinal blood vessel pattern, and voice print. , IC card, PIN, password, passphrase, etc. can be used.
Although the embodiments of the present invention have been described above based on some examples, the above-described embodiments of the invention are for facilitating the understanding of the present invention and limit the present invention. It's not a thing. The present invention can be modified and improved without departing from the spirit and claims, and it goes without saying that the present invention includes an equivalent thereof.
<figref num="1">Explanatory drawing which shows the structure of the control device of an authentication system.</figref><figref num="2">Explanatory drawing which shows the structure of the authentication terminal apparatus of an authentication system.</figref><figref num="3">The explanatory view which shows the flowchart of the operation (until the device confirmation) executed at the time of authentication of the authentication system which concerns on this Example.</figref><figref num="4">The explanatory view which shows the flowchart of the process which a control device confirms an authentication terminal device.</figref><figref num="5">The explanatory view which shows the flowchart of the process which an authentication terminal device confirms a control device.</figref><figref num="6">Explanatory drawing which shows the flowchart of operation (from device confirmation to authentication) executed at the time of authentication of the authentication system which concerns on this Example</figref><figref num="7">The explanatory view which shows the flowchart of the operation (authentication data, the subdivision processing of processing data) executed at the time of authentication of the authentication system which concerns on this Example.</figref><figref num="8">The conceptual explanatory diagram of the storage state of the authentication data and the processing data when neither the control device nor the authentication terminal device is stolen.</figref><figref num="9">The conceptual explanatory diagram of the storage state of the authentication data and the processing data when the authentication terminal device is stolen.</figref><figref num="10">The conceptual explanatory diagram of the storage state of the authentication data and the processing data when a control device is stolen.</figref><figref num="11">The conceptual explanatory diagram of the storage state of the authentication data and the processing data when both the control device and the authentication terminal device are stolen.</figref>
Code description
100 ... Authentication system 200 ... Control unit 201 ... CPU202 ... ROM203 ... Hard disk 204 ... RAM205 ... CD-ROM206 ... Input interface 207 ... Output interface 208 .. .Authentication terminal device interface 209 ... Display 210 ... Keyboard 211 ... Mouse 300 ... Authentication terminal device 301 ... CPU302 ... Flash memory 303 ... RAM304 ... Finger vein measurement unit 305 ... Control interface 306 ... Battery 307 ... Door control 308 ... Near infrared light source 309 ... Camera 310 ... Security door 311 ... Switch
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8813184B2 | Cited by | United States of America | Applicant |
| US9361450B2 | Cited by | United States of America | Applicant |
| JP2015529364A | Cited by | Japan | Search report |
| JP2013519178A | Cited by | Japan | Search report |
| JP2013519178A | Cited by | Japan | Examiner |
| JP2001211160A | Cites | Japan | Search report |
| JP2002312317A | Cites | Japan | Examiner |
| JP2003114853A | Cites | Japan | Search report |
| JP2003263415A | Cites | Japan | Examiner |
| JP2004234633A | Cites | Japan | Examiner |
| JP2005228299A | Cites | Japan | Examiner |
| JPH0586012A | Cites | Japan | Search report |
11 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2006131605 | Japan | A | |
| JP20060131605 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| CN101071467A | China | A | |
| EP1855227A2 | European Patent Office (EPO) | A2 | |
| KR20070109889A | Republic of Korea | A | |
| US2007266240A1 | United States of America | A1 | |
| JP2007304792AThis record | Japan | A | |
| TW200813772A | Taiwan Province of China | A | |
| KR100889651B1 | Republic of Korea | B1 | |
| CN100533458C | China | C | |
| EP1855227A3 | European Patent Office (EPO) | A3 | |
| TWI336046B | Taiwan Province of China | B | |
| US8151111B2 | United States of America | B2 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalA02 | A02 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2007304792
- Publication, DOCDB
- 2007304792
- Publication, EPODOC
- JP2007304792
- Application
- 131605
- Application, DOCDB
- 2006131605
- Application, EPODOC
- JP20060131605
Titles2
- Japanese
- 認証システムを構成する処理装置及び認証システム及びその動作方法
- English
- Processing devices and authentication systems that make up the authentication system and their operation methods
Classification
- CPC, 4
- G06F21/34
- H04L9/32
- G06F15/00
- G06K17/00
- IPC, 5
- G06F21 20
- H04L9 32
- G06F21 31
- G06F21 32
- G06F21 33