IP Library › Granted Patent US 10,686,768
Granted Patent B2
US 10,686,768 · App. 15/591,824 · Granted Jun 16, 2020

Apparatus and method for controlling profile data delivery

Inventors: Junji Takagi (Kawasaki, JP); Ikuya Morikawa (Kawasaki, JP); Takao Ogura (Yokohama, JP); Dai Yamamoto (Kawasaki, JP); Yumi Sakemi (Kawasaki, JP); Naoya Torii (Hachiouji, JP)
Assignee: FUJITSU LIMITED
H04L63/061G06F9/4451G06F21/32G06F21/33G06F21/64H04L9/12H04L9/3247H04L63/0435H04L63/0442H04L63/08H04L63/083H04L63/0861H04L63/10H04L63/123H04L63/20H04W4/50H04W8/245H04W12/0023H04W12/06H04W12/08H04L67/34H04W12/00505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,768
App. No.
15/591,824
Granted
Jun 16, 2020
Kind
B2
Abstract

In a profile data delivery control apparatus, a storage unit stores therein a public key and a private key. A control unit obtains profile data including the identification information of a service provided using a server, and when the profile data satisfies a prescribed validity condition, attaches a signature to the profile data using the private key. The control unit embeds the public key to be used to verify the signature, in a client application that causes a client to perform an authentication process based on the profile data, and delivers the client application with the public key embedded.

Claims (27)

1. A profile data delivery control apparatus comprising:

a memory that stores therein a public key and a private key corresponding to the public key; and

a processor that performs a process including

obtaining, with respect to each of two or more services provided using a server, first profile data used in server authentication and including identification information of the server, and responsive to determining that the first profile data satisfies a prescribed validity condition, attaching a signature to the first profile data using the private key, and

embedding the public key in a client application so that the public key is used to verify the signature, and delivering the client application with the public key embedded, the client application causing a client to perform an authentication process based on the first profile data, the client application causing the client to access the server by using the identification information and to obtain second profile data used in service authentication from the server for accessing a service,

wherein the client application permits the client to obtain the second profile data to be used in the authentication process from the server responsive to determining that the verifying of the signature using the public key is successful; and

the client application prohibits the client from obtaining the second profile data to be used in the authentication process from the server responsive to determining that the verifying of the signature using the public key has failed.

2. The profile data delivery control apparatus according to claim 1 , wherein:

the client application permits the client to access a service corresponding to the first profile data responsive to determining that the verifying of the signature using the public key is successful; and

the client application prohibits the client from accessing the service corresponding to the first profile data responsive to determining that the verifying of the signature using the public key has failed.

3. The profile data delivery control apparatus according to claim 1 , wherein:

the memory further stores therein license information indicating a license of an authentication method; and

the process further includes

determining whether the client has the license based on the license information in response to a request for the second profile data from the client, and

rejecting the request responsive to determining that the client does not have the license.

4. A profile data delivery control method to be executed by a computer including a memory and a processor, the profile data delivery control method comprising:

reading, by the processor, a public key and a private key corresponding to the public key from the memory;

obtaining, by the processor, with respect to each of two or more services provided using a server, first profile data used in server authentication and including identification information of the server, and responsive to determining that the first profile data satisfies a prescribed validity condition, attaching a signature to the first profile data using the private key; and

embedding, by the processor, the public key in a client application so that the public key is used to verify the signature, and delivering the client application with the public key embedded, the client application causing a client to perform an authentication process based on the first profile data, the client application causing the client to access the server by using the identification information and to obtain second profile data used in service authentication from the server for accessing a service,

wherein the client application permits the client to obtain the second profile data to be used in the authentication process from the server responsive to determining that the verifying of the signature using the public key is successful; and

the client application prohibits the client from obtaining the second profile data to be used in the authentication process from the server responsive to determining that the verifying of the signature using the public key has failed.

5. A non-transitory computer-readable storage medium storing a profile data delivery control program that causes a processor of a computer including a memory and the processor to perform a process including:

reading a public key and a private key corresponding to the public key from the memory;

obtaining, with respect to each of two or more services provided using a server, first profile data used in server authentication and including identification information of the server, and responsive to determining that the first profile data satisfies a prescribed validity condition, attaching a signature to the first profile data using the private key; and

embedding the public key in a client application so that the public key is used to verify the signature, and delivering the client application with the public key embedded, the client application causing a client to perform an authentication process based on the first profile data, the client application causing the client to access the server by using the identification information and to obtain second profile data used in service authentication from the server for accessing a service,

wherein the client application permits the client to obtain the second profile data to be used in the authentication process from the server responsive to determining that the verifying of the signature using the public key is successful; and

the client application prohibits the client from obtaining the second profile data to be used in the authentication process from the server responsive to determining that the verifying of the signature using the public key has failed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2017
From: TAKAGI, JUNJI; MORIKAWA, IKUYA; OGURA, TAKAO; YAMAMOTO, DAI; SAKEMI, YUMI; TORII, NAOYA
To: FUJITSU LIMITED
Reel/Frame 042327/0560 →
Priority Claims (1)
JP 2016-120401 · Jun 17, 2016 · national
Continuity (1)
Related Publication 20170366525A1 · Dec 21, 2017