US2014380440A1PendingUtilityA1

Authentication information management of associated first and second authentication information for user authentication

Assignee: FUJITSU LTDPriority: Apr 1, 2009Filed: Sep 10, 2014Published: Dec 25, 2014
Est. expiryApr 1, 2029(~2.7 yrs left)· nominal 20-yr term from priority
G06F 21/33H04L 9/3271H04L 63/0861H04L 9/321H04L 63/08G06F 21/556H04L 63/083
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authentication information management program of an authentication information management apparatus allowing the authentication information management apparatus to execute: changing the first authentication information in correspondence information which is information including the first authentication information and second authentication information in association with each other and stored in a storage section of the authentication information management apparatus; transmitting the authentication apparatus of the changed first authentication information; determining, in response to a request from the apparatus to be authenticated, whether the second authentication information in the authentication request coincides with the second authentication information in the correspondence information; and returning, in the case where it is determined that the second authentication information in the authentication request coincides with the second authentication information in the correspondence information, the first authentication information associated with the second authentication information read from the storage section.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for controlling an authentication server which manages a first password for a login process from a client terminal to an application comprising:
 managing the first password and authentication information for the login process from the client terminal to the authentication server; and   generating a second password which is different from the first password based on policy information to change the first password.   
     
     
         2 . The method for controlling the authentication server according to  claim 1 , further comprising:
 requesting the application to change the first password to the second password; and   changing the first password which is managed in association with the authentication information to the second password.   
     
     
         3 . The method for controlling the authentication server according to  claim 2 , wherein the policy information includes an authentication key generation condition. 
     
     
         4 . The method for controlling the authentication server according to  claim 3 , wherein the authentication key generation condition includes a character type, an occurrence frequency of characters, a password length or dissimilarity among passwords. 
     
     
         5 . The method for controlling the authentication server according to  claim 2 , wherein the policy information includes a change timing. 
     
     
         6 . The method for controlling the authentication server according to  claim 5 , wherein the change timing includes change at every login, change at periodic intervals, change at every authentication, or whether to allow a change to be made in-use. 
     
     
         7 . An authentication method for a login process from a client terminal to an application comprising:
 receiving authentication information inputted to the client terminal;   managing a first password for the login process to the application in association with the authentication information; and   generating a second password which is different from the first password based on policy information to change the first password.   
     
     
         8 . The authentication method according to  claim 7 , wherein an authentication method of the authentication information inputted to the client terminal is different from an authentication method for a login process to the application. 
     
     
         9 . The authentication method according to  claim 8 , wherein the authentication method of the authentication information inputted to the client terminal is a biometric authentication method. 
     
     
         10 . The authentication method according to  claim 8 , wherein the authentication method of the authentication information inputted to the client terminal is selectable among a plurality of authentication methods which an authentication strength differ from each other. 
     
     
         11 . The authentication method according to  claim 7 , wherein the generated second password is transmitted to a screen for a change of a password of the application. 
     
     
         12 . The authentication method according to  claim 11 , wherein the second password is stored in association with the authentication information after the password of the application is changed to the second password. 
     
     
         13 . The authentication method according to  claim 7 , wherein the policy information includes an authentication key generation condition. 
     
     
         14 . The authentication method according to  13 , wherein the authentication key generation condition includes a character type, an occurrence frequency of characters, a password length or dissimilarity among passwords. 
     
     
         15 . The authentication method according to  13 , wherein the authentication key generation condition includes a character type. 
     
     
         16 . The authentication method according to  13 , wherein the authentication key generation condition includes an occurrence frequency of characters. 
     
     
         17 . The authentication method according to  13 , wherein the authentication key generation condition includes a password length. 
     
     
         18 . The authentication method according to  13 , wherein the authentication key generation condition includes dissimilarity among passwords. 
     
     
         19 . The authentication method according to  13 , wherein the policy information includes a change timing. 
     
     
         20 . The authentication method according to  19 , wherein the change timing includes change at every login, change at periodic intervals, change at every authentication, or whether to allow a change to be made in-use. 
     
     
         21 . An authentication server which manages a first password for a login process from a client terminal to an application comprising:
 a storage configured to store the first password and authentication information for the login process from the client terminal to the authentication server, the authentication information being associated with the first password; and   a CPU configured to generate a second password which is different from the first password based on policy information to change the first password.   
     
     
         22 . The authentication server according to  claim 17 , wherein the CPU further requests the application to change the first password to the second password and changes the first password which is managed in association with the authentication information to the second password.

Join the waitlist — get patent alerts

Track US2014380440A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.