Apparatus, method, and program for validating user
Abstract
User validation accuracy is improved without inconveniencing a user. When an authentication request packet is received from a terminal and the authentication is successful based on a user ID and a password, an HTTP header, user-agent information, and access source IP address are extracted from the packet, and user authentication is performed by verifying the IP address and the user-agent information against usage history information where at most two sets of the IP address and the user-agent information extracted from the authentication request packet which is received from the same user previously are registered. When the set of the IP address and the UA information corresponding to the new extracted IP address and the new extracted UA information is registered in the usage history information, the authentication is successful, and the usage history information is overwritten with the new IP address and the new UA information.
Claims
exact text as granted — not AI-modified1 . A user validation apparatus comprising:
a storage unit; an extraction unit configured to extract user-agent information and an access source internet protocol (IP) address in an HTTP header of a packet received from a terminal device by applying HTTP as a protocol of an application layer; an information management unit configured to store the user-agent information and IP address extracted by the extraction unit from the packet received from the terminal device operated by an individual user, in the storage unit so as to correspond to user identification information of the individual user; a determination unit configured to determine that a user operating a given terminal device is a conditionally valid user, when: (a) the user-agent information extracted by the extraction unit corresponds to each of two sets of user-agent information stored as usage history information in the storage unit, but the extracted IP address does not correspond to either of two IP addresses stored as usage history information in the storage unit, or (b) the extracted IP address corresponds to each of the two stored IP addresses, but the extracted user-agent information does not correspond to either of the two stored sets of user-agent information; and a re-authentication unit configured to request re-authentication through a web page to the terminal device, when the determination unit determines that the user is the conditionally valid user.
2 . An authentication apparatus, comprising:
a storage unit; an extraction unit configured to extract user-agent information related to a software running in a terminal device and an access source internet protocol (IP) address from a packet header received from the terminal device; an information management unit configured to store the user-agent information and IP address extracted by the extraction unit from the packet received from the terminal device, operated by a user, in the storage unit; and a determination unit configured to determine that a user operating a given terminal device is: (i) a valid user when user login information is identical to stored user login information, the extracted user-agent information corresponds to each of two sets of user-agent information stored as usage history information in the storage unit, and the extracted IP address corresponds to each of two IP addresses stored as usage history information in the storage unit, (ii) an invalid user when the user login information is not identical to the stored user login information, and (iii) a conditionally valid user when the user login information is identical to the stored user login information, and: (a) the user-agent information extracted by the extraction unit corresponds to each of the two stored sets of user-agent information, but the extracted IP address does not correspond to either of the two stored IP addresses, or (b) the extracted IP address corresponds to each of the two stored IP addresses, but the extracted user-agent information does not correspond to either of the two stored sets of user-agent information.
3 . The authentication apparatus according to claim 2 , further comprising:
a re-authentication unit configured to request re-authentication through a web page to the terminal device, when the user is determined to be the conditionally valid user.
4 . An authentication apparatus, comprising:
a storage unit; an extraction unit configured to extract user-agent information related to a software running in a terminal device and an access source internet protocol (IP) address from a packet header received from the terminal device; an information management unit configured to store the user-agent information and IP address extracted by the extraction unit; a determination unit configured to determine that a user operating a given terminal device is (i) a valid user when user login information is identical to stored user login information, the extracted user-agent information corresponds to each of two sets of user-agent information stored as usage history information in the storage unit, and the extracted IP address corresponds to each of two IP addresses stored as usage history information in the storage unit, (ii) an invalid user when the user login information is not identical to the stored user login information, and (iii) a conditionally valid user when the user login information is identical to the stored user login information, and: (a) the user-agent information extracted by the extraction unit corresponds to each of the two stored sets of user-agent information, but the extracted IP address does not correspond to either of the two stored sets of IP addresses, or (b) the extracted IP address corresponds to each of the two stored sets of IP addresses, but the extracted user-agent information does not correspond to either of the two stored sets of user-agent information; and a re-authentication unit configured to request re-authentication through a web page to the terminal device, when the determination unit determines that the user is the conditionally valid user.
5 . The user validation apparatus of claim 1 , wherein the user-agent information comprises at least one of: a version of the operating system (OS) of the terminal device, a browser of the terminal device, a number of patches of the browser of the OS and a number of updates of the browser.
6 . The authentication apparatus of claim 2 , wherein the user-agent information comprises at least one of: a version of the operating system (OS) of the terminal device, a browser of the terminal device, a number of patches of the browser of the OS and a number of updates of the browser.
7 . The authentication apparatus of claim 4 , wherein the user-agent information comprises at least one of: a version of the operating system (OS) of the terminal device, a browser of the terminal device, a number of patches of the browser of the OS and a number of updates of the browser.
8 . The user validation apparatus of claim 1 , wherein the two stored sets of user-agent information comprise: a latest user-agent information and a previous user-agent information.
9 . The authentication apparatus of claim 2 , wherein the two stored sets of user-agent information comprise: a latest user-agent information and a previous user-agent information.
10 . The authentication apparatus of claim 4 , wherein the two stored sets of user-agent information comprise: a latest user-agent information and a previous user-agent information.
11 . The user validation apparatus of claim 1 , wherein the two stored IP addresses comprise: a latest IP address and a previous IP address.
12 . The authentication apparatus of claim 2 , wherein the two stored IP addresses comprise: a latest IP address and a previous IP address.
13 . The authentication apparatus of claim 4 , wherein the two stored IP addresses comprise: a latest IP address and a previous IP address.Join the waitlist — get patent alerts
Track US2015026789A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.