摘要:
A method of verifying a user, performed by a verification server, the method comprising: registering a password derivation pattern for a usage target system, the password derivation pattern being based on at least one specific element selected from a plurality of elements constituting a predetermined pattern; receiving system identification information of the usage target system and a restriction code from an information terminal device owned by a user, the restriction code being for restricting access to personal information for using the usage target system; generating a presentation pattern in which a plurality of predetermined characters are assigned to a plurality of elements constituting the predetermined pattern; generating an internal system password based on the password derivation pattern and the presentation pattern; sending the presentation pattern to the information terminal device to cause the information terminal device to display a screen containing the presentation pattern thereon and thereby to allow the user to input at least one character assigned to the at least one specific element corresponding to the password derivation pattern using into the usage target system; receiving the inputted at least one character, as an inputted password, from the usage target system; determining whether the inputted password is legitimate based on the system identification information and the internal system password; sending a result of the determination made to the usage target system; and restricting the personal information of the user to be provided to the usage target system based on the restriction code.
摘要:
[Problem] To provide a user authentication technology whereby hacking of a system by a third party is effectively prevented. [Solution] The present invention is a user authentication method and system, wherein: an information communication terminal allocates numerals, etc., which configure a token code which is generated by time synchronizing with an authentication system side to each cell which configures a user's password derivation pattern, and displays upon a user interface a personal identification table whereupon numerals, etc., are allocated which have been randomly generated with other cells; the user, with reference to the personal identification table, selects the numerals, etc., which are allocated to each cell which configures the user's password derivation pattern, and inputs same as a password; and the authentication system carries out an authentication determination upon the inputted password on the basis of the generated time synchronized token code.
摘要:
A method of verifying a user, performed by a verification server, the method comprising: registering a password derivation pattern for a usage target system, the password derivation pattern being based on at least one specific element selected from a plurality of elements constituting a predetermined pattern; receiving system identification information of the usage target system and a restriction code from an information terminal device owned by a user, the restriction code being for restricting access to personal information for using the usage target system; generating a presentation pattern in which a plurality of predetermined characters are assigned to a plurality of elements constituting the predetermined pattern; generating an internal system password based on the password derivation pattern and the presentation pattern; sending the presentation pattern to the information terminal device to cause the information terminal device to display a screen containing the presentation pattern thereon and thereby to allow the user to input at least one character assigned to the at least one specific element corresponding to the password derivation pattern using into the usage target system; receiving the inputted at least one character, as an inputted password, from the usage target system; determining whether the inputted password is legitimate based on the system identification information and the internal system password; sending a result of the determination made to the usage target system; and restricting the personal information of the user to be provided to the usage target system based on the restriction code.
摘要:
A method of registering a password derivation pattern for deriving a password to be used in user verification, the method comprising: upon control of a server, generating a presentation pattern in which a predetermined character is assigned to each element in a predetermined pattern; presenting the generated presentation pattern to a user in order to cause the user to input a character assigned to a specific element in the generated presentation pattern; repeating the generating and the presenting until the password derivation pattern is specified based on the inputted character, and registering the specified password derivation pattern.
摘要:
According to the present invention there is provided a site check method for checking whether a predetermined site is legitimate or not, the method comprising the steps of providing a first server that is provided with site identification information and manages the predetermined site; and a second server that holds the site identification information provided to the first server and synchronizes its time with a time in the first server, receiving, by the first server, a first access from a first information terminal used by a user and creating first check information based on the time of the first access obtained from its own time information and the site identification information, displaying, by the first server, a login screen containing the created first check information on the first information terminal, receiving, by the second server, a second access from a second information terminal used by the user and creating second check information based on the time of the second access obtained from its own time information and the site identification information, and displaying, by the second server, the created second check information on the second information terminal. The site check method enables a user to easily check whether a site the user has accessed is legitimate or not.
摘要:
A method of registering a password derivation pattern for deriving a password to be used in user verification, the method comprising: upon control of a server, generating a presentation pattern in which a predetermined character is assigned to each element in a predetermined pattern; presenting the generated presentation pattern to a user in order to cause the user to input a character assigned to a specific element in the generated presentation pattern; repeating the generating and the presenting until the password derivation pattern is specified based on the inputted character, and registering the specified password derivation pattern.