IP Library › Granted Patent US 12,652,283
Granted Patent B2
US 12,652,283 · App. 18/018,001 · Granted Jun 9, 2026

Authentication system, authentication method, and program

Inventor: Yeongnam Chae (Tokyo, JP)
Assignee: Rakuten Group, Inc.
H04L63/0861H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,283
App. No.
18/018,001
Granted
Jun 9, 2026
Kind
B2
Abstract

An authentication system, comprising: a user device; and an authentication device, wherein the user device is configured to: acquire transformation information for transforming authentication information different from biometric information; transform the authentication information based on the transformation information; and transmit, to the authentication device, the transformed authentication information and the biometric information, and wherein the authentication device is configured to: receive, from the user device, the transformed authentication information and the biometric information; acquire inverse transformation information for inversely transforming the transformed authentication information; inversely transform the transformed authentication information based on the inverse transformation information; and execute multi-factor authentication based on the authentication information inversely transformed by the authentication device and the biometric information.

Claims (99)

1 . An authentication system, comprising:

a user device; and

an authentication device,

a management device configured to store transformation information corresponding to combinations of days and time slots,

wherein the user device is configured to:

transmit, to the management device, a first request for transformation information that comprise a randomly generated value, wherein the first request comprises a command that excludes information revealing an acquisition rule that the transformation information corresponds to a combination of a day and time slot;

acquire, from the management device, the transformation information that comprise the randomly generated value for transforming authentication information different from biometric information;

transform the authentication information based on the transformation information, wherein only the authentication information is transformed while maintaining the biometric information untransformed, wherein the authentication information is a temporary user ID that becomes invalid when a predetermined invalidation condition is satisfied; and

transmit, to the authentication device, the transformed authentication information and the biometric information, and

wherein the authentication device is configured to:

receive, from the user device, the transformed authentication information and the biometric information;

transmit, to the management device, a second request for inverse transformation information, wherein the second request comprises a command that excludes information revealing the acquisition rule;

acquire, from the management device, inverse transformation information comprising the randomly generated value for inversely transforming the transformed authentication information;

inversely transform the transformed authentication information based on the inverse transformation information;

execute multi-factor authentication based on the authentication information inversely transformed by the authentication device and the biometric information; and

upon successful multi-factor authentication, generate a new temporary user ID different from the inversely transformed temporary user ID and transmit the new temporary user ID to the user device,

wherein the user device is further configured to:

receive the new temporary user ID and replace the stored temporary user ID with the new temporary user ID for use in a subsequent authentication;

wherein both the user device and the authentication device independently acquire the randomly generated value from the management device based on a same time period without the transmission of the randomly generated value between the user device and the authentication device.

2 . The authentication system according to claim 1 ,

wherein the user device is configured to acquire the transformation information corresponding to a first acquisition period that comprises a first acquisition time point at which the transformation information is acquired,

wherein the authentication device is configured to acquire the inverse transformation information corresponding to the first acquisition period,

wherein the first acquisition period is represented by the combination of the day and time slot.

3 . The authentication system according to claim 2 ,

wherein the user device is configured to further transmit, to the authentication device, first acquisition period information relating to the first acquisition period,

wherein the authentication device is configured to further receive the first acquisition period information from the user device, and

wherein the authentication device is configured to acquire the inverse transformation information corresponding to the first acquisition period based on the first acquisition period information.

4 . The authentication system according to claim 3 , further comprising a management device configured to manage the inverse transformation information,

wherein the authentication device is configured to request the management device for the inverse transformation information,

wherein the management device is configured to transmit a plurality of pieces of the inverse transformation information to the authentication device when a request is received from the authentication device, the plurality of pieces of the inverse transformation information including the inverse transformation information corresponding to a second acquisition period that comprises a second acquisition time point at which the inverse transformation information is acquired and the inverse transformation information corresponding to a third period previous or subsequent to the second acquisition period, and

wherein the authentication device is configured to acquire, based on the first acquisition period information, the inverse transformation information corresponding to the first acquisition period from among the plurality of pieces of the inverse transformation information.

5 . The authentication system according to claim 1 ,

wherein the user device is configured to acquire the transformation information corresponding to a part of the authentication information,

wherein the user device is configured to further transmit, to the authentication device, an untransformed part, which is the part that has not been transformed by the user device,

wherein the authentication device is configured to further receive the untransformed part from the user device, and

wherein the authentication device is configured to acquire the inverse transformation information corresponding to the untransformed part.

6 . The authentication system according to claim 1 , wherein the management device is configured to associate predetermined identification information and the inverse transformation information with each other,

wherein the user device is configured to acquire the predetermined identification information,

wherein the user device is configured to further transmit the predetermined identification information to the authentication device,

wherein the authentication device is configured to further receive the predetermined identification information from the user device, and

wherein the authentication device is configured to acquire the inverse transformation information that comprises the predetermined identification information.

7 . The authentication system according to claim 6 ,

wherein the management device is configured to generate, when a predetermined generation request is received from the user device, the predetermined identification information and the transformation information and associate the predetermined identification information and the transformation information with each other,

wherein the user device is configured to acquire the transformation information generated in response to the predetermined generation request, and

wherein the user device is configured to acquire the predetermined identification information generated in response to the predetermined generation request.

8 . The authentication system according to claim 1 ,

wherein the user device is configured to select any one of a plurality of transformation methods,

wherein the user device is configured to transform, based on the transformation information, the authentication information through use of the any one of the plurality of transformation methods selected by the user device,

wherein the authentication device is configured to select an inverse transformation method corresponding to the any one of the plurality of transformation methods selected by the user device from among a plurality of the inverse transformation methods, and

wherein the authentication device is configured to inversely transform, based on the inverse transformation information, the transformed authentication information through use of the inverse transformation method selected by the authentication device.

9 . The authentication system according to claim 8 ,

wherein the user device is configured to select one of the plurality of transformation methods corresponding to a first transformation period that comprises a first transformation time point at which the authentication information is transformed belongs, and

wherein the authentication device is configured to select the inverse transformation method corresponding to the first transformation period as the inverse transformation method corresponding to the one of the plurality of transformation methods selected by the user device.

10 . The authentication system according to claim 9 ,

wherein the first transformation period corresponds to a time slot,

wherein the user device is configured to select one of the plurality of transformation methods corresponding to the time slot, and

wherein the authentication device is configured to select the inverse transformation method corresponding to the time slot.

11 . The authentication system according to claim 9 ,

wherein the user device is configured to further transmit, to the authentication device, transformation period information relating to the first transformation period,

wherein the authentication device is configured to further receive the transformation period information from the user device, and

wherein the authentication device is configured to select the inverse transformation method corresponding to the first transformation period based on the transformation period information.

12 . The authentication system according to claim 8 , wherein the management device is configured to associate predetermined identification information and the inverse transformation information with each other,

wherein the user device is configured to acquire the predetermined identification information,

wherein the user device is configured to further transmit the predetermined identification information to the authentication device,

wherein the authentication device is configured to further receive the predetermined identification information from the user device,

wherein the authentication device is configured to acquire the inverse transformation information that comprises the predetermined identification information, and

wherein the authentication device is configured to select the inverse transformation method based on the predetermined identification information.

13 . The authentication system according to claim 12 ,

wherein the management device is configured to generate, when a predetermined generation request is received from the user device, the predetermined identification information and the transformation information and associate the predetermined identification information and the transformation information with each other,

wherein the user device is configured to acquire the transformation information generated in response to the predetermined generation request, and

wherein the user device is configured to acquire the predetermined identification information generated in response to the predetermined generation request.

14 . The authentication system according to claim 8 , further comprising a selection device configured to select one of the plurality of transformation methods and the inverse transformation method,

wherein the user device is configured to request the selection device to select the one of the plurality of transformation methods,

wherein the authentication device is configured to request the selection device to select the inverse transformation method,

wherein the selection device is configured to:

transmit, when a request is received from the user device, a selection result of any one of the plurality of transformation methods to the user device; and

transmit, when a request is received from the authentication device, a selection result of any one of the plurality of inverse transformation methods to the authentication device,

wherein the user device is configured to select one of the plurality of transformation methods based on the selection result obtained by the selection device, and

wherein the authentication device is configured to select the inverse transformation method based on the selection result obtained by the selection device.

15 . An authentication method using a user device, an authentication device, and a management device, the authentication method comprising:

transmitting, by the user device and to the management device, a first request for transformation information that comprise a randomly generated value, wherein the first request comprises a command that excludes information revealing an acquisition rule that the transformation information corresponds to a combination of a day and time slot;

acquiring, by the user device and from the management device, the transformation information that comprise the randomly generated value for transforming authentication information different from biometric information;

transforming, by the user device, the authentication information based on the transformation information, wherein only the authentication information is transformed while maintaining the biometric information untransformed, wherein the authentication information is a temporary user ID that becomes invalid when a predetermined invalidation condition is satisfied;

transmitting, by the user device, to the authentication device, the transformed authentication information and the biometric information;

receiving, by the authentication device, from the user device, the transformed authentication information and the biometric information;

transmitting, by the authentication device, to the management device, a second request for inverse transformation information, wherein the second request comprises a command that excludes information revealing the acquisition rule;

acquiring, by the authentication device, from the management device, inverse transformation information comprising the randomly generated value for inversely transforming the transformed authentication information;

inversely transforming, by the authentication device, the transformed authentication information based on the inverse transformation information;

executing, by the authentication device, multi-factor authentication based on the authentication information inversely transformed in the inverse transformation step and the biometric information,

upon successful multi-factor authentication, generating, by the authentication device, a new temporary user ID different from the inversely transformed temporary user ID and transmitting the new temporary user ID to the user device,

receiving, by the user device, the new temporary user ID and replace the stored temporary user ID with the new temporary user ID for use in a subsequent authentication;

wherein both the user device and the authentication device independently acquire the randomly generated value from the management device based on a same time period without the transmission of the randomly generated value between the user device and the authentication device.

16 . A non-transitory computer-readable information storage medium for storing a program for causing a user device communicable to/from an authentication device and a management device that executes multi-factor authentication to:

transmit, by the user device and to the management device, a first request for transformation information that comprise a randomly generated value, wherein the first request comprises a command that excludes information revealing an acquisition rule that the transformation information corresponds to a combination of a day and time slot;

acquire, by the user device and from the management device, the transformation information that comprise the randomly generated value for transforming authentication information different from biometric information;

transform, by the user device, the authentication information based on the transformation information, wherein only the authentication information is transformed while maintaining the biometric information untransformed, wherein the authentication information is a temporary user ID that becomes invalid when a predetermined invalidation condition is satisfied; and

transmit, by the user device, to the authentication device, the transformed authentication information and the biometric information,

upon successful multi-factor authentication, receive, by the user device, a new temporary user ID and replace a stored temporary user ID with the new temporary user ID for use in a subsequent authentication;

wherein both the user device and the authentication device independently acquire the randomly generated value from the management device based on a same time period without the transmission of the randomly generated value between the user device and the authentication device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2023
From: CHAE, YEONGNAM
To: RAKUTEN GROUP, INC.
Reel/Frame 062537/0035 →
Continuity (1)
Related Publication 20250071110A1 · Feb 27, 2025
References Cited (34)
US 6128735A · Goldstein et al. · 2000 [cited by applicant]
US 10862873B1 · Carru · 2020 [cited by examiner]
US 20060112272A1 · Morioka · 2006 [cited by examiner]
US 20060136732A1 · Vandermolen · 2006 [cited by examiner]
US 20060204003A1 · Takata et al. · 2006 [cited by applicant]
US 20060291662A1 · Takahashi et al. · 2006 [cited by applicant]
US 20070133800A1 · Kim · 2007 [cited by examiner]
US 20070156829A1 · Deboy · 2007 [cited by examiner]
US 20090007257A1 · Hirata et al. · 2009 [cited by applicant]
US 20110167264A1 · Takahashi et al. · 2011 [cited by applicant]
US 20160050291A1 · Haug · 2016 [cited by examiner]
US 20180241728A1 · Burgess · 2018 [cited by examiner]
US 20190052632A1 · Takagi · 2019 [cited by applicant]
US 20210374219A1 · Suwa et al. · 2021 [cited by applicant]
JP 5102961A · 1993 [cited by applicant]
JP 983506A · 1997 [cited by applicant]
JP 2689383B2 · 1997 [cited by applicant]
JP 2001524771A · 2001 [cited by applicant]
JP 2002259343A · 2002 [cited by applicant]
JP 2002290397A · 2002 [cited by applicant]
JP 2004318691 · 2003 [cited by examiner]
JP 2003338814A · 2003 [cited by applicant]
JP 2004318691A · 2004 [cited by applicant]
JP 2006238273A · 2006 [cited by applicant]
JP 2006340296A · 2006 [cited by applicant]
JP 2007156785A · 2007 [cited by applicant]
JP 4966765B2 · 2012 [cited by applicant]
JP WO2020085141A1 · 2020 [cited by applicant]
JP 6866803B2 · 2021 [cited by applicant]
Menezes et al. (Alfred J. Menezes, Paul C. van Oorschot, Scott A. Vanstone, “Handbook of applied cryptography”, 1997, ISBN: 0849385237) (Year: 1997). [cited by examiner]
International Search Report for PCT/JP2021/049015 dated Apr. 12, 2022 [PCT/ISA/210]. [cited by applicant]
Extended European Search Report dated Jul. 24, 2023 in European Application No. 21950374.5. [cited by applicant]
Japanese Office Action dated Aug. 8, 2023 in Japanese Application No. 2023-540796. [cited by applicant]
Davies et al., “Security for Computer Networks”, Nikkei McGraw-Hill, Inc., Dec. 5, 1985, pp. 136-138 (5 pages total). [cited by applicant]