US2015026789A1PendingUtilityA1

Apparatus, method, and program for validating user

Assignee: BANK OF TOKYO MITSUBISHI UFJPriority: Mar 29, 2006Filed: Oct 9, 2014Published: Jan 22, 2015
Est. expiryMar 29, 2026(expired)· nominal 20-yr term from priority
Inventors:Takaya Kato
G06F 21/31G06F 17/30091H04L 63/08H04L 63/083G06F 21/34G06F 2221/2111H04L 2463/082G06F 16/13H04L 63/101H04L 63/126H04L 63/168G06F 2221/2101
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

User validation accuracy is improved without inconveniencing a user. When an authentication request packet is received from a terminal and the authentication is successful based on a user ID and a password, an HTTP header, user-agent information, and access source IP address are extracted from the packet, and user authentication is performed by verifying the IP address and the user-agent information against usage history information where at most two sets of the IP address and the user-agent information extracted from the authentication request packet which is received from the same user previously are registered. When the set of the IP address and the UA information corresponding to the new extracted IP address and the new extracted UA information is registered in the usage history information, the authentication is successful, and the usage history information is overwritten with the new IP address and the new UA information.

Claims

exact text as granted — not AI-modified
1 . A user validation apparatus comprising:
 a storage unit;   an extraction unit configured to extract user-agent information and an access source internet protocol (IP) address in an HTTP header of a packet received from a terminal device by applying HTTP as a protocol of an application layer;   an information management unit configured to store the user-agent information and IP address extracted by the extraction unit from the packet received from the terminal device operated by an individual user, in the storage unit so as to correspond to user identification information of the individual user;   a determination unit configured to determine that a user operating a given terminal device is a conditionally valid user, when: (a) the user-agent information extracted by the extraction unit corresponds to each of two sets of user-agent information stored as usage history information in the storage unit, but the extracted IP address does not correspond to either of two IP addresses stored as usage history information in the storage unit, or (b) the extracted IP address corresponds to each of the two stored IP addresses, but the extracted user-agent information does not correspond to either of the two stored sets of user-agent information; and   a re-authentication unit configured to request re-authentication through a web page to the terminal device, when the determination unit determines that the user is the conditionally valid user.   
     
     
         2 . An authentication apparatus, comprising:
 a storage unit;   an extraction unit configured to extract user-agent information related to a software running in a terminal device and an access source internet protocol (IP) address from a packet header received from the terminal device;   an information management unit configured to store the user-agent information and IP address extracted by the extraction unit from the packet received from the terminal device, operated by a user, in the storage unit; and   a determination unit configured to determine that a user operating a given terminal device is: (i) a valid user when user login information is identical to stored user login information, the extracted user-agent information corresponds to each of two sets of user-agent information stored as usage history information in the storage unit, and the extracted IP address corresponds to each of two IP addresses stored as usage history information in the storage unit, (ii) an invalid user when the user login information is not identical to the stored user login information, and (iii) a conditionally valid user when the user login information is identical to the stored user login information, and: (a) the user-agent information extracted by the extraction unit corresponds to each of the two stored sets of user-agent information, but the extracted IP address does not correspond to either of the two stored IP addresses, or (b) the extracted IP address corresponds to each of the two stored IP addresses, but the extracted user-agent information does not correspond to either of the two stored sets of user-agent information.   
     
     
         3 . The authentication apparatus according to  claim 2 , further comprising:
 a re-authentication unit configured to request re-authentication through a web page to the terminal device, when the user is determined to be the conditionally valid user.   
     
     
         4 . An authentication apparatus, comprising:
 a storage unit;   an extraction unit configured to extract user-agent information related to a software running in a terminal device and an access source internet protocol (IP) address from a packet header received from the terminal device;   an information management unit configured to store the user-agent information and IP address extracted by the extraction unit;   a determination unit configured to determine that a user operating a given terminal device is (i) a valid user when user login information is identical to stored user login information, the extracted user-agent information corresponds to each of two sets of user-agent information stored as usage history information in the storage unit, and the extracted IP address corresponds to each of two IP addresses stored as usage history information in the storage unit, (ii) an invalid user when the user login information is not identical to the stored user login information, and (iii) a conditionally valid user when the user login information is identical to the stored user login information, and: (a) the user-agent information extracted by the extraction unit corresponds to each of the two stored sets of user-agent information, but the extracted IP address does not correspond to either of the two stored sets of IP addresses, or (b) the extracted IP address corresponds to each of the two stored sets of IP addresses, but the extracted user-agent information does not correspond to either of the two stored sets of user-agent information; and   a re-authentication unit configured to request re-authentication through a web page to the terminal device, when the determination unit determines that the user is the conditionally valid user.   
     
     
         5 . The user validation apparatus of  claim 1 , wherein the user-agent information comprises at least one of: a version of the operating system (OS) of the terminal device, a browser of the terminal device, a number of patches of the browser of the OS and a number of updates of the browser. 
     
     
         6 . The authentication apparatus of  claim 2 , wherein the user-agent information comprises at least one of: a version of the operating system (OS) of the terminal device, a browser of the terminal device, a number of patches of the browser of the OS and a number of updates of the browser. 
     
     
         7 . The authentication apparatus of  claim 4 , wherein the user-agent information comprises at least one of: a version of the operating system (OS) of the terminal device, a browser of the terminal device, a number of patches of the browser of the OS and a number of updates of the browser. 
     
     
         8 . The user validation apparatus of  claim 1 , wherein the two stored sets of user-agent information comprise: a latest user-agent information and a previous user-agent information. 
     
     
         9 . The authentication apparatus of  claim 2 , wherein the two stored sets of user-agent information comprise: a latest user-agent information and a previous user-agent information. 
     
     
         10 . The authentication apparatus of  claim 4 , wherein the two stored sets of user-agent information comprise: a latest user-agent information and a previous user-agent information. 
     
     
         11 . The user validation apparatus of  claim 1 , wherein the two stored IP addresses comprise: a latest IP address and a previous IP address. 
     
     
         12 . The authentication apparatus of  claim 2 , wherein the two stored IP addresses comprise: a latest IP address and a previous IP address. 
     
     
         13 . The authentication apparatus of  claim 4 , wherein the two stored IP addresses comprise: a latest IP address and a previous IP address.

Join the waitlist — get patent alerts

Track US2015026789A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.