In the present invention, a "two-parts-are-one password" is the phenomenon of "the probability of two becoming one" = 1.0. A "two-parts-are-not-one password" is the phenomenon of the probability << 1.0. There is no harm even if the service-side password leaks out. Password maintenance management costs are unnecessary. Because there is a responsibility demarcation point with the "two-parts-are-one password", the side filing a lawsuit is at a disadvantage. There is no password file on the authentication server segment. The core that gives rise to these innovative effects is the mounting technology of "split knowledge of keys and use under dual control" during operation. This is the first time in the world that PCIDSS requirement 3.6.6, version 1.2.1 has been satisfied.