IP Library › Granted Patent US 11,044,085
Granted Patent B2
US 11,044,085 · App. 15/980,587 · Granted Jun 22, 2021

Method employed in user authentication system and information processing apparatus included in user authentication system

Inventor: Hirotaka Funayama (Kawasaki, JP)
H04L9/0866H04L9/14H04L9/30H04L9/3231H04L9/3247H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,044,085
App. No.
15/980,587
Granted
Jun 22, 2021
Kind
B2
Abstract

The present disclosure provides a system in which a migration operation which is different from a normal registration operation performed on a system is started in one of a terminal before replacement and a terminal after the replacement so that a registration operation performed on the terminal after the replacement is easily completed only by causing a user to consecutively perform an authentication operation on both of the terminals.

Claims (21)

1. A method employed in a user authentication system including:

a service providing system in which a first public key has been registered, a first information processing apparatus including a first authentication module and a first storage region having tamper resistance, the first storage region storing authentication information of a user and a first secret key paired with the registered first public key, and a second information processing apparatus including a communication function for communication with the first information processing apparatus, a second authentication module and a second storage region having tamper resistance, the method comprising:

executing an access from the first information processing apparatus by using a hardware processor and URL information which is managed by the first authentication module and corresponds to the service providing system, wherein the access is a process for a registration process to newly register the second information processing apparatus with the service providing system based on a start operation input by the user to the first information processing apparatus;

receiving verification data which is issued by the service providing system according to the access; and

transmitting, to the service providing system, signature data generated using the first secret key encrypting the verification data, in a case where a process of authenticating the user by the first authentication module is successfully performed,

wherein, on the registration process of the second information processing apparatus according to a verification of the signature data using the first public key by the service providing system, a second public key paired with the second secret key is registered in the service providing system by using the second authentication module of the second information processing apparatus as an external authenticator for the first information processing apparatus;

wherein the authentication information is based on biometric information of the user;

and the biometric information indicates at least one of a fingerprint, a face, an iris, a vein, and a voiceprint of the user.

2. The method according to claim 1 , wherein the first authentication module is an internal authenticator for the first information processing apparatus.

3. The method according to claim 1 , wherein the execution of the access is performed by an application different from the first authentication module.

4. A user authentication system including:

a service providing system in which a first public key has been registered,

a first information processing apparatus including a first authentication module and a first storage region having tamper resistance, the first storage region storing authentication information of a user and a first secret key paired with the registered first public key, and

a second information processing apparatus including a communication function for communication with the first information processing apparatus, a second authentication module and a second storage region having tamper resistance,

wherein the first information processing apparatus is configured to:

execute an access from the first information processing apparatus by using a hardware processor and URL information which is managed by the first authentication module and corresponds to the service providing system, wherein the access is a process for a registration process to newly register the second information processing apparatus with the service providing system based on a start operation input by the user to the first information processing apparatus;

receive verification data which is issued by the service providing system according to the access; and

transmit, to the service providing system, signature data generated using the first secret key encrypting the verification data, in a case where a process of authenticating the user by the first authentication module is successfully performed,

wherein, on the registration process of the second information processing apparatus according to a verification of the signature data using the first public key by the service providing system, a second public key paired with the second secret key is registered in the service providing system by using the second authentication module of the second information processing apparatus as an external authenticator for the first information processing apparatus;

wherein the authentication information is based on biometric information of the user;

and the biometric information indicates at least one of a fingerprint, a face, an iris, a vein, and a voiceprint of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2018
From: FUNAYAMA, HIROTAKA
To: CANON KABUSHIKI KAISHA
Reel/Frame 046545/0862 →
Priority Claims (1)
JP JP2017-102857 · May 24, 2017 · national
Continuity (1)
Related Publication 20180343118A1 · Nov 29, 2018
Cited By (1)
US 12,452,518