IP Library › Granted Patent US 12,107,956
Granted Patent B2
US 12,107,956 · App. 17/688,700 · Granted Oct 1, 2024

Information processing device, information processing method, and non-transitory computer readable storage medium

Inventors: Hidehito Gomi (Tokyo, JP); Shuji Yamaguchi (Tokyo, JP)
Assignee: Yahoo Japan Corporation
H04L9/321H04L9/0869H04L9/0894H04L9/3073
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,956
App. No.
17/688,700
Granted
Oct 1, 2024
Kind
B2
Abstract

An information processing device according to the present application includes a control unit. The control unit acquires, from an authentication server in a state in which a first authenticator used for FIDO authentication and a second authenticator used for recovery for the FIDO authentication cooperate with each other, a recovery execution request that is transmitted from a user terminal including the second authenticator to the authentication server, and if the recovery execution request meets a predetermined authentication condition that is set in advance, notifies the user terminal including the second authenticator of a recovery execution permission.

Claims (13)

1. An information processing device comprising:

a control unit that acquires, from an authentication server in a state in which a first authenticator used for Fast Identity Online (FIDO) authentication and a second authenticator used for recovery for the FIDO authentication cooperate with each other, a recovery execution request that is transmitted from a user terminal including the second authenticator to the authentication server, and if the recovery execution request meets a predetermined authentication condition that is set in advance, notifies the user terminal including the second authenticator of a recovery execution permission,

wherein the second authenticator is registered as a backup authenticator for the first authenticator through transmission of a seed registration request from the control unit to the authentication server.

2. The information processing device according to claim 1 , wherein the control unit links a key for the first authenticator and a recovery key for the second authenticator by attribute-based encryption.

3. The information processing device according to claim 1 , wherein the control unit links a seed for generating a key for the first authenticator and a seed for generating a recovery key for the second authenticator by attribute-based encryption.

4. The information processing device according to claim 1 , wherein the control unit acquires, from the authentication server, a recovery registration request for the second authenticator, the recovery registration request being issued from a user terminal including the first authenticator, generates a recovery key pair for the second authenticator on the basis of the recovery registration request, stores a public key of the recovery key pair in the authentication server, and stores a secret key of the recovery key pair in the second authenticator.

5. The information processing device according to claim 2 , wherein the control unit confirms recovery authority for the second authenticator by verifying a signature that as added with use of a recovery secret key, with respect to a signed assertion that is obtained by adding, with use of a secret key that is acquired in advance by the second authenticator, a signature to an assertion that is generated based on the recovery execution request, and transmits the recovery execution permission.

6. An information processing method implemented by a computer, the information processing method comprising:

a control step of acquiring, from an authentication server in a state in which a first authenticator used for Fast Identity Online (FIDO) authentication and a second authenticator used for recovery for the FIDO authentication cooperate with each other, an authenticator verification request that is transmitted from a user terminal including the second authenticator to the authentication server, and notifying, if the authenticator verification request meets a predetermined authentication condition that is set in advance, the user terminal including the second authenticator of a recovery execution permission,

wherein the second authenticator is registered as a backup authenticator for the first authenticator through transmission of a seed registration request to the authentication server.

7. A non-transitory computer-readable recording medium having stored therein an information processing program that causes a computer to execute a process, the process comprising:

a control step of acquiring, from an authentication server in a state in which a first authenticator used for Fast Identity Online (FIDO) authentication and a second authenticator used for recovery for the FIDO authentication cooperate with each other, an authenticator verification request that is transmitted from a user terminal including the second authenticator to the authentication server, and notifying, if the authenticator verification request meets a predetermined authentication condition that is set in advance, the user terminal including the second authenticator of a recovery execution permission,

wherein the second authenticator is registered as a backup authenticator for the first authenticator through transmission of a seed registration request to the authentication server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2024
From: GOMI, HIDEHITO; YAMAGUCHI, SHUJI
To: YAHOO JAPAN CORPORATION
Reel/Frame 068456/0452 →
Priority Claims (1)
JP 2021-101696 · Jun 18, 2021 · national
Continuity (1)
Related Publication 20220417020A1 · Dec 29, 2022