Apparatus, method, and program for validating user
Abstract
User validation accuracy is improved without inconveniencing a user. When an authentication request packet is received from a terminal and the authentication is successful based on a user ID and a password, an HTTP header, user-agent information, and access source IP address are extracted from the packet, and user authentication is performed by verifying the IP address and the user-agent information against usage history information where at most two sets of the IP address and the user-agent information extracted from the authentication request packet which is received from the same user previously are registered. When the set of the IP address and the UA information corresponding to the new extracted IP address and the new extracted UA information is registered in the usage history information, the authentication is successful, and the usage history information is overwritten with the new IP address and the new UA information.
Claims
exact text as granted — not AI-modified1 . A user validation apparatus comprising:
a memory, and a processor programmed to:
extract user-agent information and an access source internet protocol (IP) address in an HTTP header of a packet received from a terminal device operated by an individual user by applying HTTP as a protocol of an application layer;
store the extracted user-agent information and the extracted access source IP address in the memory as usage history information that corresponds to user identification information of the individual user;
determine that the user is conditionally valid, when:
the received user login information is identical to login information stored in the memory, and
(a) the extracted user-agent information corresponds to user-agent information stored in the memory, but the extracted IP address does not correspond to IP address stored in the memory, or (b) the extracted user-agent information does not correspond to user-agent information stored in the memory, but the extracted IP address corresponds to IP address stored in the memory; and
transmit a further authentication information based on contact information corresponding to the received user login information and stored in the memory, when the user is determined to be conditionally valid.
2 . A user validation apparatus comprising:
a memory, and a processor programmed to:
extract user-agent information from HTTP header of a packet received from the terminal device;
store the extracted user-gent information or the extracted access source IP address onto the memory as usage history information that corresponds to user identification information of the individual user;
determine that the user is conditionally valid, when: (i) the received user login information is identical to login information stored in the memory, and (ii) the extracted user-agent information does not correspond to user-agent information stored in the memory; and
transmit a further authentication information based on contact information corresponding to the received user login information and stored in the memory, when the user is determined to be conditionally valid.
3 . The user validation apparatus according to claim 2 , wherein the processor is further programmed to:
request re-authentication to the given terminal device from which the user login information is transmitted, when the user operating the given terminal device is determined to be the conditionally valid user.
4 . The user validation apparatus according to claim 2 , wherein the processor is further programmed to:
store a plurality of sets of the access source IP addresses and the user-agent information.
5 . The user validation apparatus according to claim 2 , wherein the processor is further programmed to:
additionally store a new access source IP address or new user-agent information.
6 . A user validation method executed by a computer comprising:
receiving user login information from a terminal device operated by a user; extracting user-agent information from HTTP header of a packet received from the terminal device; determining that the user is conditionally valid, when: (i) the received user login information is identical to login information stored in a first database, and (ii) the extracted user-agent information does not correspond to user-agent information stored in a second database; and transmitting a further authentication information based on contact information corresponding to the received user login information and stored in a third database, when the user is determined to be conditionally valid.
7 . The user validation method according to claim 6 , wherein the contact information is an electronic mail address.
8 . The user validation method according to claim 6 , wherein the further authentication information is a confirmation link.
9 . The user validation method according to claim 6 , further comprising:
updating the second database, when the further authentication is performed successfully.Join the waitlist — get patent alerts
Track US2020204533A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.