IP Library Granted Patent US 11,188,625
Granted Patent B2
US 11,188,625 · App. 14/392,235 · Granted Nov 30, 2021

User authentication system, user authentication method, program, and information storage medium

Inventor: Takaaki Koshinuma (Tokyo, JP)
Assignee: Rakuten Group, Inc.
G06F21/31G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,188,625
App. No.
14/392,235
Granted
Nov 30, 2021
Kind
B2
Abstract

A stranger who has come across user information of a user is prevented from being successfully authenticated as the user. A user authentication system includes: an authentication information acquisition unit ( 20 ) configured to obtain an entered password of a user; a user authentication unit ( 22 ) configured to execute authentication of the user based on the entered password; and an authentication procedure change unit ( 28 ) configured to change, when the authentication of the user fails and the entered password matches or is similar to a password candidate that is based on information associated with the user, a procedure of the authentication of the user which is executed by the user authentication unit ( 22 ), based on whether or not a genuine password of the user matches or is similar to the password candidate.

Claims (41)

1. A user authentication system, comprising:

an authentication information acquisition unit for acquiring an entered password of a user;

an user authentication unit for executing authentication of the user based on the entered password;

a determination unit for determining whether or not a genuine password of the user matches or is similar to a password candidate that is based on information associated with the user; and

an authentication procedure change unit for changing, when the authentication of the user fails and the entered password matches or is similar to the password candidate, a procedure of the authentication of the user which is executed by the user authentication unit, based on a result of the determination by the determination unit.

2. The user authentication system according to claim 1 ,

wherein the authentication procedure change unit is configured to be restricted from making a change when the entered password matches or is similar to a past genuine password of the user.

3. The user authentication system according to claim 1 ,

wherein the authentication procedure change unit is configured to vary specifics of the change depending on specifics of the password candidate.

4. The user authentication system according to claim 1 ,

wherein the authentication procedure change unit comprises unit for changing the genuine password of the user.

5. The user authentication system according to claim 1 ,

wherein the user authentication unit is configured to stop the authentication of the user when the authentication of the user fails as many times as a given upper limit count in succession, and

wherein the authentication procedure change unit comprises unit for lowering the given upper limit count.

6. The user authentication system according to claim 1 , further comprising:

a message transmission unit for transmitting a message to the user when the authentication of the user fails and the entered password matches or is similar to the password candidate.

7. The user authentication system according to claim 1 , further comprising:

a password candidate generation unit for generating the password candidate based on the information that is associated with the user.

8. The user authentication system according to claim 7 ,

wherein the information associated with the user comprises at least one information item, and

wherein the password candidate generation unit is configured to generate the password candidate by breaking each of the at least one information item into a plurality of elements, and selecting some of the plurality of elements or rearranging the plurality of elements.

9. The user authentication system according to claim 7 ,

wherein the information associated with the user comprises at least two information items, and

wherein the password candidate generation unit is configured to generate the password candidate by combining at least a part of each of the at least two information items.

10. The user authentication system according to claim 1 , further comprising:

an invalid access determination unit for determining a possibility of invalid access,

wherein the determination by the determination unit and the change by the authentication procedure change unit are based on a result of the determination by the invalid access determination unit.

11. A user authentication method, comprising:

acquiring an entered password of a user;

executing authentication of the user based on the entered password;

determining whether or not a genuine password of the user matches or is similar to a password candidate that is based on information associated with the user; and

changing, when the authentication of the user fails and the entered password matches or is similar to the password candidate, a procedure of the authentication of the user, based on whether or not the genuine password matches or is similar to the password candidate.

12. A non-transitory computer-readable storage medium having stored thereon a program for causing a computer to function as:

an authentication information acquisition unit for acquiring an entered password of a user;

an user authentication unit for executing authentication of the user based on the entered password;

a determination unit for determining whether or not a genuine password of the user matches or is similar to a password candidate that is based on information associated with the user; and

an authentication procedure change unit for changing, when the authentication of the user fails and the entered password matches or is similar to the password candidate, a procedure of the authentication of the user which is executed by the user authentication unit, based on a result of the determination by the determination unit.

13. A user authentication system, comprising:

an authentication information acquisition unit configured to obtain an entered password of a user;

a user authentication unit configured to execute authentication of the user based on the entered password; and

an authentication procedure change unit configured to change, when the authentication of the user fails and the entered password matches or is similar to a password candidate that is based on information associated with the user, a procedure of the authentication of the user which is executed by the user authentication unit, based on whether or not a genuine password of the user matches or is similar to the password candidate.

Assignments (3)
CHANGE OF NAME Recorded Jul 9, 2021
From: RAKUTEN INC
To: RAKUTEN GROUP INC
Reel/Frame 056816/0068 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2016
From: KOSHINUMA, TAKAAKI
To: RAKUTEN. INC
Reel/Frame 038463/0703 →
CHANGE OF ADDRESS Recorded Feb 3, 2016
From: RAKUTEN, INC.
To: RAKUTEN, INC.
Reel/Frame 037690/0315 →