Electronic lock device, electronic lock system, and locking / unlocking method
The electronic lock system addresses authentication challenges in battery-less devices by generating power from electromagnetic waves to create challenge data and manage authentication dynamically, ensuring secure and efficient operation without fixed information.
Patent Information
- Application Number
- JP2024092969
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-07
- Publication Date
- 2025-12-18
AI Technical Summary
Existing electronic lock systems face challenges with battery-less devices that are not connected to a power source, as updating authentication information is difficult and there is a risk of authentication information leakage or duplication, and challenge data is not effectively managed in offline scenarios.
An electronic lock device that generates power from electromagnetic waves, uses this power to create challenge data, calculates authentication information, and performs authentication processing using a battery-less design, with challenge data stored in volatile memory and managed by a management server.
The system ensures secure, dynamic authentication without fixed information, preventing interception and duplication, and allows for efficient challenge data management, even in offline conditions, enhancing security and reducing processing time.
Smart Images

Figure 2025184515000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an electronic lock device, an electronic lock system, and a locking / unlocking method. [Background technology]
[0002] 2. Description of the Related Art Conventionally, an electronic lock system is known in which an electronic key and an electronic lock communicate with each other to control locking and unlocking. In existing electronic lock systems, authentication information is set in advance and stored in the mobile terminal device and the electronic lock device. When unlocking, the mobile terminal device is held up to the electronic lock device, establishing an electrical connection and transmitting the authentication information from the mobile terminal device to the electronic lock device. The electronic lock device compares the received authentication information with the authentication information stored internally, and unlocks if the two match. However, because existing electronic lock systems use fixed authentication information, there are threats such as the leakage or duplication of authentication information, and therefore authentication using challenge data so that authentication information is different for each authentication is beginning to be used. However, since an encryption algorithm and encryption key are required to generate authentication information from challenge data, it is not desirable from a security standpoint to have the encryption algorithm and encryption key reside on many mobile terminal devices, and so it is common for them to be managed by a management server device.
[0003] In an offline electronic lock system equipped with an electronic lock device that is not connected to a management server device, there are cases where lockers or doors that are locked or unlocked by an electronic lock device are installed in a company, etc. In this case, electronic key information is stored in a mobile terminal device (smartphone) carried by an employee, etc., and when the employee leaves the company, it is necessary to prohibit the opening and closing of the electronic lock on the locker or door after leaving. For example, even if electronic key information is stored in a mobile terminal device, no major security problems will arise if opening and closing can be reliably prohibited by an electronic lock device or if the electronic key information of the mobile terminal device can be reliably invalidated. For this reason, existing electronic lock systems utilize an online electronic lock system that connects electronic lock devices to a management server device that manages users, and the administrator updates the user information in the management server device, thereby updating the user information for all electronic lock devices. Furthermore, when a mobile terminal device that invalidates electronic key information is connected to the management server device, the information in the mobile terminal device is updated to invalidate the electronic key information.
[0004] Furthermore, in existing electronic lock systems, the techniques described in the following Patent Documents 1 to 3 are known. Patent Document 1 describes that when a mobile terminal device and a car sharing device connect to establish short-range wireless communication, they perform challenge-response authentication, and after the challenge-response authentication is established, they perform communication via one-way communication.The technology in Patent Document 1 describes that when a mobile terminal device and a car sharing device perform short-range wireless communication, they perform challenge-response authentication only when they connect to establish communication, and after the authentication is established, they perform communication via one-way communication thereafter.
[0005] Patent Document 2 describes a server device that, in response to a request for digital signature attachment from a user's mobile terminal, attaches a digital signature to an electronic document related to the request. This server device receives an access request from the user's mobile terminal along with the identification ID of the mobile terminal, authenticates the user based on the received identification ID of the mobile terminal, attaches a digital signature to the electronic document specified by the user's mobile terminal, and transmits a message to the user's mobile terminal notifying the completion of the attachment of the digital signature.
[0006] In Patent Document 3, the server device, in response to receiving an application to unlock an electronic lock from an applicant terminal, inquires of the owner whether or not to permit the applicant to unlock the electronic lock. When the server device receives an application permission notice from the owner terminal as a result of the inquiry to permit the electronic lock to be unlocked, the server device enables the applicant terminal to obtain a one-time password. When the applicant terminal obtains the one-time password from the server device, it transmits the one-time password to the electronic lock to operate the electronic lock. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Japanese Patent Application Publication No. 2019-070276 [Patent Document 2] Japanese Patent Application Laid-Open No. 2004-023406 [Patent Document 3] Japanese Patent Application Publication No. 2018-013002 Summary of the Invention [Problem to be solved by the invention]
[0008] The electronic lock system described above performs authentication by storing the same authentication information in the mobile terminal device and the electronic lock device. However, if the authentication information is intercepted or leaked during communication, the authentication information must be updated. However, there are also battery-less electronic locking devices in electronic locking systems that are not connected to a power source. Battery-less electronic locking devices are typically offline and not connected to a management server, so administrators must visit the electronic locking device they want to update and use a mobile terminal to update the authentication information. Therefore, when using a battery-less electronic locking device, it is not easy to update the authentication information. Furthermore, storing the authentication information in the mobile terminal increases the risk of the authentication information on the mobile terminal being duplicated.
[0009] In the case of an electronic lock device in an online electronic lock system, the administrator can easily update the user information of the electronic lock device by updating the user information of the management server device and sending the user information from the management server device to the electronic lock device. However, in the case of an offline electronic lock system in which the management server device and electronic lock device are not connected via a communication network, in order to update the user information of the electronic lock device, it is necessary to send the retired employee information to the electronic lock device using a mobile terminal device, and have the electronic lock device update the user information inside the electronic lock device based on the retired employee information.
[0010] In the case of an online electronic lock system, it is also conceivable that the management server device may directly perform a process to invalidate electronic key information on a mobile terminal device in which electronic key information is stored. However, there may be cases where it is not possible to reliably disable the electronic key information for the mobile terminal device app by the retirement date. For example, if the person to be retired maliciously turns off the mobile terminal device, the management server device will not be able to connect to the mobile terminal device, and the access authority will not be disabled, so there is a risk that the person may turn on the mobile terminal device just before accessing the electronic lock device after retirement and access the electronic lock device to unlock it.
[0011] Furthermore, in the case of electronic lock devices equipped with authentication technology using existing challenge data, as in the above-mentioned Patent Documents 1-3, challenge authentication is performed while the power is constantly supplied. Therefore, even if the electronic lock device generates challenge data and stores the generated challenge data in volatile memory, the challenge data is not erased. Therefore, even if the mobile terminal device that received the challenge data is temporarily removed from the electronic lock device, the electronic lock device requests the management server device to generate authentication information, receives the authentication information from the management server device, and then brings the mobile terminal device close to the electronic lock device again, the authentication process continues to be executed. However, if the electronic lock device is replaced with a battery-less device, the challenge data stored in the volatile memory will be lost if the power supply from the mobile terminal device is interrupted. Therefore, it is difficult to perform authentication processing using the challenge data with a battery-less electronic lock device.
[0012] The present disclosure has been made in consideration of these circumstances, and aims to provide an electronic lock device, an electronic lock system, and a locking / unlocking method that can unlock a vehicle using challenge data with a battery-less electronic lock device. [Means for solving the problem]
[0013] The present disclosure has been made to solve the above-mentioned problems, and one aspect of the present disclosure is an electronic lock device comprising: an antenna unit that generates power from electromagnetic waves output from an electronic device; a generation unit that operates using the power generated by the antenna unit and generates challenge data; a memory unit that stores the challenge data generated by the generation unit; a calculation unit that operates using the power generated by the antenna unit and calculates authentication information based on the challenge data stored in the memory unit; a communication unit that causes the challenge data generated by the generation unit to be transmitted from the antenna unit to an external device and causes the antenna unit to receive authentication information calculated based on the challenge data from the external device; an authentication unit that operates using the power generated by the antenna unit and performs authentication processing based on the authentication information received from the external device and the authentication information calculated by the calculation unit; and a locking / unlocking unit that operates using the power generated by the antenna unit and locks / unlocks based on the authentication result of the authentication processing.
[0014] Another aspect of the present disclosure is an electronic lock system including an electronic lock device, an electronic device, and a management server device, wherein the electronic lock device includes an antenna unit that generates power using electromagnetic waves output from the electronic device, a generation unit that operates using the power generated by the antenna unit and generates challenge data, a storage unit that stores the challenge data generated by the generation unit, a calculation unit that operates using the power generated by the antenna unit and calculates authentication information based on the challenge data stored in the storage unit, a communication unit that causes the antenna unit to transmit the challenge data generated by the generation unit to the electronic device and causes the antenna unit to receive authentication information calculated by the management server device based on the challenge data, and a communication unit that operates using the power generated by the antenna unit. and an authentication unit that performs authentication processing based on authentication information calculated by the management server device and the authentication information calculated by the calculation unit, and a locking / unlocking unit that operates using power generated by the antenna unit and locks / unlocks based on the authentication result of the authentication processing, wherein the electronic device requests challenge data from the electronic lock device, transmits the challenge data to the management server device in response to receiving the challenge data from the electronic lock device, transmits the received authentication information to the electronic lock device in response to receiving the authentication information calculated by the management server device, and the management server device performs the same calculation as the authentication unit in response to receiving the challenge data from the electronic device to calculate authentication information and transmits the calculated authentication information to the electronic device.
[0015] Another aspect of the present disclosure is a method for locking and unlocking an electronic lock system including an electronic lock device, an electronic device, and a management server device, wherein the electronic device requests challenge data from the electronic lock device, the electronic lock device generates challenge data in response to an antenna unit generating power due to electromagnetic waves output from the electronic device, stores the generated challenge data, and transmits the generated challenge data from the antenna unit to the electronic device, the electronic device transmits the challenge data to the management server device in response to receiving the challenge data from the electronic device, the management server device performs a predetermined calculation in response to receiving the challenge data from the electronic device to calculate authentication information, and stores the calculated authentication information. a control server device that controls the electronic lock device to operate the electronic device; a management server device that controls the electronic device to operate the electronic device; a control server device that controls the electronic ... [Effects of the Invention]
[0016] According to one aspect of the present invention, a battery-less electronic lock device can be unlocked using challenge data. [Brief explanation of the drawings]
[0017] [Figure 1] 1 is a schematic diagram showing an example of an electronic lock system in a first embodiment. [Figure 2] 1 is a block diagram showing an example of the configuration of an electronic lock device according to a first embodiment. [Figure 3]FIG. 2 is a diagram illustrating an example of a functional configuration of an IC chip according to the first embodiment. [Figure 4] FIG. 2 is a sequence diagram showing an example of the operation of the electronic lock system in the first embodiment. [Figure 5] FIG. 10 is a sequence diagram illustrating an example of a processing procedure when a timer interrupt is used in the first embodiment. [Figure 6] FIG. 10 is a block diagram showing an example of a functional configuration of an IC chip according to a second embodiment. [Figure 7] FIG. 10 is a sequence diagram showing an example of the operation of the electronic lock system in the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0018] An electronic lock device, an electronic lock system, and a locking / unlocking method to which the present invention is applied will be described below with reference to the drawings. FIG. 1 is a schematic diagram showing an example of an electronic lock system 1 according to the first embodiment. The electronic lock system of the embodiment includes a battery-less electronic lock device 100, a mobile terminal device 200, and a management server device 300. The battery-less electronic lock device 100 is not connected to a commercial power source, but generates power from electromagnetic waves output from the mobile terminal device 200 as an electronic device, and operates each component of the electronic lock device 100 with the power generated by the electromagnetic waves. The electronic lock device 100 uses the power generated by the electromagnetic waves to operate a generation unit that generates challenge data, a calculation unit that calculates authentication information based on the challenge data stored in a memory unit, a communication unit that transmits the challenge data from an antenna unit to the management server device 300 and receives, from the management server device 300, the authentication unit that performs authentication processing based on the authentication information received from the management server device 300 and the authentication information calculated by the calculation unit, and a lock / unlock unit that locks and unlocks the device based on the authentication result of the authentication processing. In such embodiments, an electronic lock system having an electronic lock device 100 that uses volatile memory as a memory unit will be described as a first embodiment, and an electronic lock system having an electronic lock device 100 that uses non-volatile memory as a memory unit will be described as a second embodiment.
[0019] (First embodiment) As shown in FIG. 1 , the electronic lock system 1 of the first embodiment includes, for example, a number of electronic lock devices 100, a number of mobile terminal devices 200, and a management server device 300. The electronic lock device 100 locks and unlocks the door 10, thereby permitting and prohibiting the opening and closing of the door 10 using the handle 12. The mobile terminal device 200 is, for example, an electronic device such as a smartphone carried by a user. The management server device 300 is an information processing device connected to the mobile terminal device 200 via a communication network NW. The communication network NW may include, for example, a general-purpose network such as the Internet, and a private network such as local 5G or WiFi (registered trademark).
[0020] The mobile terminal device 200 includes, for example, a communication unit 202, an NFC (Near Field Communication) communication circuit 204, a processing unit 206, a user interface unit 208, and a storage unit 210. The communication unit 202 has a communication interface (not shown) such as a network interface card (NIC) or a wireless communication module for connecting to the communication network NW. The NFC communication circuit 204 transmits and receives electromagnetic waves compatible with NFC. When the mobile terminal device 200 is in a state where it can communicate with the electronic lock device 100, the NFC communication circuit 204 continues to transmit electromagnetic waves to the electronic lock device 100, thereby continuing to supply power. The processing unit 206 is realized by a processor such as a CPU (Central Processing Unit) executing a program stored in a program memory. The processing unit 206 controls the communication unit 202, the NFC communication circuit 204, the processing unit 206, the user interface unit 208, and the storage unit 210. The mobile terminal device 200 downloads and installs, for example, application software for using the door 10. The mobile terminal device 200 executes the application software using the processing unit 206, thereby accessing the management server device 300 and performing various processes for using the door 10. The user interface unit 208 includes, for example, a display device, an operation input device, and an audio input / output device.
[0021] The storage unit 210 is realized by, for example, a flash memory or an EEPROM (Electrically Erasable Programmable Read Only Memory). The storage unit 210 stores, for example, user information and unlocking information. The user information includes, for example, a user ID, user name information, and user terminal information. The user ID is information for identifying the user by the electronic lock device 100 and the management server device 300. The user terminal information is information for identifying the mobile terminal device 200 and information for the mobile terminal device 200 to communicate with the management server device 300 and the door 10. The unlocking information includes, for example, a door ID, challenge data, and authentication information.
[0022] The management server device 300 includes, for example, a communication unit 302, an authentication information calculation unit 304, an access authority confirmation unit 306, and a storage unit 308. The management server device 300 corresponds to an external device for the electronic lock device 100. The communication unit 302 has a communication interface such as an NIC or a wireless communication module that communicates with each of the multiple mobile terminal devices 200 via the communication network NW. The authentication information calculation unit 304 and the access authority confirmation unit 306 are realized by a processor such as a CPU executing a program stored in a program memory. The authentication information calculation unit 304 calculates authentication information in response to receiving challenge data from the mobile terminal device 200. An algorithm for generating authentication information using the challenge data as a main element is assumed to be pre-installed. The algorithm for generating authentication information is the same as that of the electronic lock device 100. When the access authority confirmation unit 306 receives access from the mobile terminal device 200, it confirms the user terminal information and confirms that the mobile terminal device 200 belongs to a user who has been registered in advance. The storage unit 308 is realized by a storage medium such as a flash memory, an EEPROM, a HDD, or an SSD. The storage unit 308 stores, for example, access authority-related information and authentication-related information. The access authority-related information includes, for example, a user ID, user name information, user terminal information, and access authority information. The authentication-related information includes, for example, a door ID, challenge data, and authentication information.
[0023] The access authority information is stored and managed for each user who is permitted to access one or more electronic lock devices 100. The access authority information is promptly updated by the management server device 300 as needed, for example, upon receiving a request from a terminal device operated by an administrator to add or delete a user, or to allow or prohibit access to the door 10.
[0024] 2 is a block diagram showing an example of the configuration of electronic lock device 100 in the first embodiment. Electronic lock device 100 includes, for example, antenna unit 110, IC chip 120, timer 130, rectifier circuit 140, control microcomputer 150, and locking / unlocking mechanism 160. In this embodiment, locking / unlocking mechanism 160 may perform both locking and unlocking operations, but is not limited to this and may only perform unlocking operation.
[0025] The antenna unit 110 generates power from electromagnetic waves output from the mobile terminal device 200, which is an electronic device. The antenna unit 110 receives, for example, electromagnetic waves compatible with NFC from the mobile terminal device 200. The transmission method of the electromagnetic waves compatible with NFC is, for example, a radio wave method (microwave method), but it may also be an electromagnetic induction method. If the electromagnetic waves for NFC communication are in the UHF band or 2.45 GHz band, the electromagnetic waves may be transmitted and received using a radio wave method (microwave method). If the electromagnetic waves for NFC communication are in a low frequency of 13.56 MHz or less, the electromagnetic waves may be transmitted and received using an electromagnetic induction method. The antenna unit 110 outputs an electric signal corresponding to the electromagnetic waves received from the mobile terminal device 200 to the IC chip 120.
[0026] The IC chip 120 performs a predetermined decoding process on the electric signal corresponding to the electromagnetic waves, acquires various information transmitted from the mobile terminal device 200, and performs a process to lock or unlock the door 10. The timer 130 starts and stops timing according to the control of the IC chip 120.
[0027] The rectifier circuit 140 generates DC power by rectifying an electrical signal corresponding to the electromagnetic waves, and supplies the DC power to the control microcomputer 150 and the locking / unlocking mechanism 160. When the control microcomputer 150 receives a lock / unlock signal from the IC chip 120 , it outputs a drive signal to the lock / unlock mechanism 160 .
[0028] The locking / unlocking mechanism 160 moves the tip of the deadbolt 162 toward the strike 13 of the door 10 in accordance with the drive signal. The locking / unlocking mechanism 160 may include an actuator such as a solenoid and a motor, and may include a cylinder that generates a drive force, such as a hydraulic cylinder, a pneumatic cylinder, or a water hydraulic cylinder, or may include an artificial muscle (soft actuator) using a polymer.
[0029] Regarding locking, the door 10 may be automatically locked (auto-locked) when closed using a latch mechanism (such as a spring) of the locking / unlocking mechanism 160. In this case, the locking / unlocking mechanism 160 compresses a spring attached to a latch bar (a rod-shaped member) when unlocking. When the locking / unlocking mechanism 160 is stopped, the latch is automatically locked due to the spring's restoring force. However, the spring is merely an example, and rubber or other elastic materials may also be used. The latch bar may also be a cylindrical part (such as a cylinder) that contains a fluid such as gas or liquid. In practice, these examples are not limited to these, and an auto-locking method that does not require power for locking may also be used. In this case, the electronic locking device 100 can maintain the unlocked state by constantly receiving electromagnetic waves compatible with NFC. However, a mechanism (such as a lock and a stopper) that can maintain the unlocked state after unlocking and release the unlocked state when locking may also be provided.
[0030] 3 is a diagram showing an example of the functional configuration of IC chip 120 in the first embodiment. IC chip 120 includes, for example, a communication unit 121, a challenge data generation unit 122, an authentication information calculation unit 123, an authentication unit 124, a storage unit 125, and a lock / unlock signal output unit 126. Communication unit 121, challenge data generation unit 122, authentication information calculation unit 123, authentication unit 124, and lock / unlock signal output unit 126 operate using power generated by antenna unit 110. The communication unit 121 causes the challenge data generated by the challenge data generation unit 122 to be transmitted from the antenna unit 110 to the management server device 300, and causes the antenna unit 110 to receive authentication information calculated based on the challenge data from the management server device 300. The challenge data generation unit 122 operates using the power generated by the antenna unit 110 to generate challenge data. The challenge data is, for example, a pseudo-random number, but is not limited to this and may be unspecified data that is different each time it is generated. The authentication information calculation unit 123 operates using the power generated by the antenna unit 110 and calculates authentication information based on the challenge data stored in the storage unit 125. The authentication information generation algorithm, which uses the challenge data as a main element, is, for example, a data encryption process and is assumed to be pre-installed. The authentication information generation algorithm is the same as that of the management server device 300. The authentication unit 124 operates using the power generated by the antenna unit 110 and performs authentication processing based on the authentication information received from the management server device 300 and the authentication information calculated by the authentication information calculation unit 123 . The storage unit 125 stores the challenge data generated by the challenge data generation unit 122. The locking / unlocking signal output unit 126 outputs a locking signal for locking and an unlocking signal for unlocking in response to successful authentication by the authentication unit 124. The locking / unlocking unit may be any one of the components for locking and unlocking the door 10, such as the locking / unlocking signal output unit 126, the control microcomputer 150, and the locking / unlocking mechanism 160.
[0031] The storage unit 125 includes, for example, a volatile memory 125A and a non-volatile memory 125B. The volatile memory 125A is a memory, such as a RAM, that stores data while power is being supplied. The volatile memory 125A stores, for example, challenge data, authentication information calculated by the authentication information calculation unit 123, and authentication information received from the management server device 300. The information stored in the volatile memory 125A disappears when the mobile terminal device 200 is moved away from the electronic lock device 100 and power is no longer generated by the antenna unit 110. The nonvolatile memory 125B is a memory that retains data even when power is cut off, such as an EEPROM, and stores, for example, a door ID as door-specific information.
[0032] FIG. 4 is a sequence diagram showing an example of the operation of the electronic lock system 1 in the first embodiment. First, the mobile terminal device 200 downloads a door unlocking application (step ST10) and executes the door unlocking application to register user information (step ST11). The process of registering the user information involves, for example, accepting a user operation in accordance with the door unlocking application, acquiring a user ID, user name information, and user terminal information based on the user operation, and transmitting the acquired user ID, user name information, and user terminal information to the management server device 300 to store in the storage unit 308.
[0033] Next, the mobile terminal device 200 is brought close to the electronic lock device 100, and transmits NFC-compatible electromagnetic waves S10 to the electronic lock device 100 near the door 10 via the NFC communication circuit 204 (step ST12). The electronic lock device 100 uses the electromagnetic waves S10 as electromotive force via the antenna unit 110 to supply power to the IC chip 120, the rectifier circuit 140, the control microcomputer 150, and the locking / unlocking mechanism 160. This activates the IC chip 120, and it transitions to a standby state for receiving an unlock command from the mobile terminal device 200 (step ST30).
[0034] Next, the mobile terminal device 200 transmits a connection request S12 to the electronic lock device 100 to request the door ID and challenge data (step ST13). The electronic lock device 100 receives the connection request S12. The electronic lock device 100 reads the door ID from the nonvolatile memory 125B, generates challenge data using the challenge data generation unit 122, and transmits the door ID and the challenge data S14 to the mobile terminal device 200 (step ST32). The electronic lock device 100 also stores the challenge data in the volatile memory 125A (step ST32). In addition, when the mobile terminal device 200 requests the electronic lock device 100 for the door ID and challenge data, the electronic lock device 100 may confirm the legitimacy of the mobile terminal device 200 by performing authentication processing such as authentication code and challenge authentication to confirm the legitimacy of the mobile terminal device 200. The mobile terminal device 200 receives the door ID and challenge data S14 transmitted from the electronic lock device 100, and transmits the received door ID, challenge data, and user information S16 to the management server device 300 (step ST14).
[0035] The management server device 300 uses the access authority confirmation unit 306 to confirm permission for use based on the door ID and user information received from the mobile terminal device 200 and the door ID and user information stored in the storage unit 308. If permission for use is denied, the management server device 300 transmits error information to the mobile terminal device 200. When granting permission to use the mobile terminal device 200, the management server device 300 calculates authentication information using the challenge data received from the mobile terminal device 200 using the authentication information calculation unit 304, and transmits the calculated authentication information S18 to the mobile terminal device 200 (step ST20). The management server device 300 may verify the authenticity of the mobile terminal device 200 by performing authentication processing such as authentication code, challenge authentication, or biometric authentication in addition to verifying the user information. The mobile terminal device 200 transmits the authentication information received from the management server device 300 and the unlock command S20 to the electronic lock device 100 (step ST15).
[0036] The electronic lock device 100 uses the authentication information calculation unit 123 to calculate authentication information using the challenge data stored in the volatile memory 125A (step ST34), and the authentication unit 124 performs authentication processing using the received authentication information and the calculated authentication information (step ST36). The electronic lock device 100 uses the authentication unit 124 to determine whether or not the authentication has been successful (step ST38). The authentication unit 124 determines that the authentication has been successful if the authentication information received from the management server device 300 matches the authentication information calculated by the authentication information calculation unit 123 (step ST38: YES), and determines that the authentication has failed if they do not match (step ST38: NO).
[0037] If the authentication is successful (step ST38: YES), the locking / unlocking signal output unit 126 outputs an unlocking command to the control microcomputer 150 (step ST40). The control microcomputer 150 performs the unlocking operation by operating the locking / unlocking mechanism 160 (step ST42). The IC chip 120 generates a success response of the unlocking operation (step ST44) and transmits the generated success response S22 to the mobile terminal device 200 (step ST48). The mobile terminal device 200 receives the success response S22 from the electronic lock device 100 (step ST16).
[0038] If the authentication is not successful (step ST38: NO), the IC chip 120 generates a failure response to the unlocking operation (step ST46) and transmits the generated failure response S22 to the mobile terminal device 200 (step ST48). The mobile terminal device 200 receives the failure response S22 from the electronic lock device 100 (step ST16).
[0039] As described above, according to the electronic lock device 100 of the first embodiment, even if the electronic lock device 100 is battery-less, challenge data is generated in response to the antenna unit 110 generating power due to electromagnetic waves output from the mobile terminal device 200, the generated challenge data is stored in the volatile memory 125A, and the generated challenge data is transmitted to the mobile terminal device 200. In response to receiving the challenge data from the electronic lock device 100, the mobile terminal device 200 transmits the challenge data to the management server device 300. In response to receiving the challenge data from the mobile terminal device 200, the management server device 300 performs a predetermined calculation to calculate authentication information, transmits the calculated authentication information to the mobile terminal device 200, and In response to receiving authentication information calculated by the management server device 300, the mobile terminal device 200 transmits the received authentication information to the electronic lock device 100, the electronic lock device 100 receives from the mobile terminal device 200 the authentication information calculated by the management server device 300 based on the challenge data, the electronic lock device 100 calculates the authentication information based on the challenge data stored in the volatile memory 125A using the power generated by the antenna unit 110, performs authentication processing based on the authentication information calculated by the management server device 300 using the power generated by the antenna unit 110, and locks and unlocks based on the authentication result of the authentication processing using the power generated by the antenna unit 110. With this electronic lock device 100, the battery-less electronic lock device 100 can unlock using the challenge data.
[0040] Furthermore, according to the electronic lock system 1 of the first embodiment, different challenge data is generated by the electronic lock device 100 each time the door 10 is accessed, and the management server device 300 calculates authentication information using the challenge data, so the authentication information can also be different for each access. As a result, according to the electronic lock system 1, fixed authentication information is not stored, so it is possible to prevent the authentication information used for authentication from being leaked. Furthermore, according to the electronic lock system 1, even if the authentication information is intercepted, it is possible to prevent the intercepted authentication information from being used to unlock the door.
[0041] In the electronic lock system 1 according to the embodiment, there is no need to manage the validity period of the authentication information. However, since the authentication information disappears when the power supply to the electronic lock device 100 is stopped, a limit such as a validity period is actually imposed. Therefore, even if a user holds the mobile terminal device 200 that has received authentication information from the management server device 300 and then attempts to unlock the door 10 using the electronic lock device 100 after some time has passed, the user will be unable to do so. Furthermore, since new challenge data is always generated when accessing the electronic lock device 100, the mobile terminal device 200 must access the management server device 300 to receive authentication information. However, this is eliminated because confirmation of locking or unlocking authority occurs when the management server device 300 is accessed. These features enable the security of the electronic lock system 1 to be maintained.
[0042] Furthermore, in the case of challenge authentication between devices equipped with batteries, the device that generated the challenge data retains the challenge data and uses it for authentication, and then performs an erasure process to erase the challenge data. In contrast, according to the electronic lock system 1 of the embodiment, the challenge data can be erased by moving the mobile terminal device 200 that supplies power to the electronic lock device 100 away from the electronic lock device 100, thereby stopping the power supply. As a result, according to the electronic lock system 1, the challenge data erasure process can be omitted, thereby shortening the processing time.
[0043] Furthermore, according to the first embodiment of the electronic lock system 1, the challenge data is stored in the volatile memory 125A, and further, the authentication information calculated by the authentication information calculation unit 123 and the authentication information received from the management server device 300 are stored in the volatile memory 125A, and not stored in the non-volatile memory 125B, thereby improving security.
[0044] Furthermore, the electronic lock system 1 of the first embodiment is equipped with a battery-less electronic lock device 100, which operates by receiving power from the mobile terminal device 200, so that the challenge data and authentication information stored in the volatile memory 125A can be erased by stopping the power supply from the mobile terminal device 200. As a result, the electronic lock system 1 can improve security.
[0045] Furthermore, according to the electronic lock system 1 of the first embodiment, the electronic lock device 100 can generate authentication information using the same calculation algorithm as the management server device 300 from the challenge data stored in its own volatile memory 125A during the period from immediately after transmitting the challenge data to the mobile terminal device 200 until receiving the authentication information from the mobile terminal device 200, and store the generated authentication information in the volatile memory 125A. As a result, by having the electronic lock device 100 perform calculation processing of the authentication information in advance, the overall processing time can be shortened compared to performing calculations after receiving the authentication information from the mobile terminal device 200.
[0046] 5 is a sequence diagram showing an example of a processing procedure when a timer interrupt is used in the first embodiment. Note that in the explanation of FIG. 5, explanations of parts that overlap with the explanation of FIG. 4 will be omitted. The authentication unit 124 may not perform authentication processing if the time between storing the challenge data generated by the authentication information calculation unit 123 and receiving the authentication information calculated based on the challenge data from the management server device 300 exceeds a threshold. After storing the challenge data in the volatile memory 125A (step ST32), the electronic lock device 100 sets a timer interrupt in the timer 130 (step ST50). The timer 130 operates on the system clock while power is being supplied to the IC chip 120.
[0047] If the electronic lock device 100 receives the authentication information and the unlock command S20 within a predetermined time after setting the timer interrupt, it resets the timer interrupt (step ST52), which causes the electronic lock device 100 to proceed to the processing of step ST34 and subsequent steps. If the electronic lock device 100 does not receive the authentication information and the unlock command S20 within a predetermined time after setting the timer interrupt, the electronic lock device 100 generates a timer interrupt (step ST54), generates a failure response of the unlocking operation (step ST46), and transmits the generated failure response S22 to the mobile terminal device 200 (step ST48). The mobile terminal device 200 receives the failure response S22 from the electronic lock device 100 (step ST16). That is, if the authentication unit 124 does not receive the authentication information and the unlock command S20 after setting the timer interrupt and the threshold is exceeded, the authentication process is not performed and the locking / unlocking mechanism 160 is not performed to unlock the door.
[0048] After transmitting the challenge data to the mobile terminal device 200, the electronic lock device 100 starts measuring time using the timer 130 in the IC chip 120, and can abort the locking or unlocking process if it cannot receive authentication information from the mobile terminal device 200 even when the elapsed time exceeds a threshold. Furthermore, the electronic lock device 100 can stop the operation of the timer 130 and abort the authentication process when the power supply from the mobile terminal device 200 is stopped.
[0049] The electronic lock device 100 may start measuring time using the timer 130 in the IC chip 120, and if a time extension request is received before the time exceeds a threshold, the electronic lock device 100 may permit the time extension request up to a predetermined number of times. If the number of permitted time extension requests exceeds the predetermined number, the electronic lock device 100 may abort the locking or unlocking process.
[0050] The authentication unit 124 may set an authentication processing flag in response to generating or transmitting challenge data by the communication unit 121, and store the authentication processing flag in the volatile memory 125A. The authentication unit 124 performs authentication processing when it receives authentication information from the management server device 300 while the authentication processing flag is set. The authentication unit 124 resets the authentication processing flag in response to performing the authentication processing. The authentication unit 124 may reset the authentication processing flag when receiving a command other than an authentication command linked with authentication information. The authentication command linked with authentication information may be an authentication command including authentication information, or may be an authentication command transmitted simultaneously with the authentication information. Normally, the mobile terminal device 200 receives challenge data from the electronic lock device 100 as an authentication processing procedure, and then transmits to the electronic lock device 100 an authentication command including authentication information generated by the management server device 300. However, transmitting a processing command to the electronic lock device 100 that is incompatible with this procedure is an abnormal behavior that violates security and may indicate some kind of malicious fraud. In response to this, the authentication unit 124 can maintain security by resetting the authentication flag when receiving a command other than an authentication command linked with authentication information. The authentication process flag may be set at any timing between the time when the challenge data is generated and the time when the challenge data is completely stored in the volatile memory 125A. The authentication process flag may be reset at any timing between when the authentication information is received and it is determined that the authentication process can be executed, and when a response is sent after the authentication process has been determined to be successful or unsuccessful.
[0051] (Second embodiment) The second embodiment will be described below, with the same components as those in the first embodiment being given the same reference numerals and detailed descriptions thereof being omitted. FIG. 6 is a block diagram showing an example of the functional configuration of the IC chip 120 according to the second embodiment. IC chip 120# includes, for example, communication unit 121, challenge data generation unit 122, authentication information calculation unit 123, authentication unit 124, memory unit 125#, and lock / unlock signal output unit 126. Communication unit 121, challenge data generation unit 122, authentication information calculation unit 123, authentication unit 124, and lock / unlock signal output unit 126 operate using power generated by antenna unit 110.
[0052] The communication unit 121 causes the challenge data generated by the challenge data generation unit 122 to be transmitted from the antenna unit 110 to the management server device 300, and causes the antenna unit 110 to receive authentication information calculated based on the challenge data from the management server device 300. The challenge data generation unit 122 operates using the power generated by the antenna unit 110 and generates challenge data. The authentication information calculation unit 123 operates using the power generated by the antenna unit 110 and calculates authentication information based on the challenge data stored in the storage unit 125 . The authentication unit 124 operates using the power generated by the antenna unit 110, and performs authentication processing based on the authentication information received from the management server device 300 and the authentication information calculated by the authentication information calculation unit 123. The authentication unit 124 may erase the challenge data stored in the nonvolatile memory 125B in response to performing the authentication processing. Storage unit 125# stores the challenge data generated by challenge data generation unit 122. The locking / unlocking signal output unit 126 outputs a locking signal for locking and an unlocking signal for unlocking in response to successful authentication by the authentication unit 124. The locking / unlocking unit may be any one of the components for locking and unlocking the door 10, such as the locking / unlocking signal output unit 126, the control microcomputer 150, and the locking / unlocking mechanism 160.
[0053] Storage unit 125# includes, for example, volatile memory 125A and nonvolatile memory 125B. Volatile memory 125A stores, for example, authentication information calculated by authentication information calculation unit 123 and authentication information received from management server device 300. Nonvolatile memory 125B stores, for example, a door ID, challenge data, and an authentication processing flag as door-specific information.
[0054] FIG. 7 is a sequence diagram showing an example of the operation of the electronic lock system 1 in the second embodiment. First, the mobile terminal device 200 downloads a door unlocking application (step ST10) and executes the door unlocking application to register user information (step ST11). The process of registering the user information involves, for example, accepting a user operation in accordance with the door unlocking application, acquiring a user ID, user name information, and user terminal information based on the user operation, and transmitting the acquired user ID, user name information, and user terminal information to the management server device 300 to store in the storage unit 308.
[0055] Next, mobile terminal device 200 transmits NFC-compatible electromagnetic waves S10 to electronic lock device 100 near door 10 via NFC communication circuit 204 (step ST12). Electronic lock device 100 converts electromagnetic waves S10 into electromotive force via antenna unit 110 to supply power to IC chip 120#, rectifier circuit 140, control microcomputer 150, and locking / unlocking mechanism 160. This activates IC chip 120#, which transitions to a standby state for receiving an unlock command from mobile terminal device 200 (step ST30).
[0056] Next, the mobile terminal device 200 transmits a connection request S12 to the electronic lock device 100 to request the door ID and challenge data (step ST13). The electronic lock device 100 receives the connection request S12. The electronic lock device 100 reads the door ID from the nonvolatile memory 125B, generates challenge data using the challenge data generation unit 122, and transmits the door ID and the challenge data S14 to the mobile terminal device 200 (step ST32#). The electronic lock device 100 also stores the challenge data in the nonvolatile memory 125B (step ST32#). Next, the electronic lock device 100 sets an authentication processing flag in the nonvolatile memory 125B (step ST60). Thereafter, the user can operate the mobile terminal device 200 while away from the electronic lock device 100. The electronic lock device 100 may temporarily notify the user that it is okay to remove the mobile terminal device 200 from the electronic lock device 100. This allows the mobile terminal device 200 to interrupt the power supply to the electronic lock device 100.
[0057] The mobile terminal device 200 receives the door ID and challenge data S14 transmitted from the electronic lock device 100, and transmits the received door ID, challenge data, and user information S16 to the management server device 300 (step ST14).
[0058] The management server device 300 uses the access authority confirmation unit 306 to confirm permission to use based on the door ID and user information received from the mobile terminal device 200 and the door ID and user information stored in the storage unit 308. The management server device 300 uses the authentication information calculation unit 304 to calculate authentication information using the challenge data received from the mobile terminal device 200, and transmits the calculated authentication information S18 to the mobile terminal device 200 (step ST20). When the mobile terminal device 200 is once separated from the electronic lock device 100, the mobile terminal device 200 may be held over the electronic lock device 100 again, and after the electronic lock device 100 is started, authentication information may be sent to the electronic lock device 100 to instruct it to unlock.
[0059] When the mobile terminal device 200 receives the authentication information S18 from the management server device 300 (step ST16), it transmits an electromagnetic wave S30 to the electronic lock device 100 (step ST62). The electronic lock device 100 is activated by the electromagnetic wave S30 transmitted from the mobile terminal device 200 and goes into standby mode (step ST64). Next, the mobile terminal device 200 transmits the authentication information received from the management server device 300 and the unlock command S20 to the electronic lock device 100 (step ST15).
[0060] The electronic lock device 100 checks whether the authentication process flag in the nonvolatile memory 125B is set (step ST66). If the authentication process flag is set (step ST66: YES), the electronic lock device 100 causes the authentication information calculation unit 123 to calculate authentication information using the challenge data stored in the nonvolatile memory 125B (step ST34#), and the authentication unit 124 performs authentication processing using the received authentication information and the calculated authentication information (step ST36). The electronic lock device 100 causes the authentication unit 124 to determine whether the authentication has been successful (step ST38). If the authentication information received from the management server device 300 matches the authentication information calculated by the authentication information calculation unit 123, the authentication unit 124 determines that the authentication has been successful (step ST38: YES), and if they do not match, the authentication has been unsuccessful (step ST38: NO).
[0061] If the authentication is successful (step ST38: YES), the locking / unlocking signal output unit 126 outputs an unlocking command to the control microcomputer 150 (step ST40). The control microcomputer 150 performs the unlocking operation by operating the locking / unlocking mechanism 160 (step ST42). The IC chip 120# generates a success response of the unlocking operation (step ST44), resets the authentication processing flag in the nonvolatile memory 125B (step ST70), and transmits the generated success response S22 to the mobile terminal device 200 (step ST48). The mobile terminal device 200 receives the success response S22 from the electronic lock device 100 (step ST16).
[0062] The authentication processing flag is saved in the nonvolatile memory 125B, set when challenge data is generated, and reset when authentication processing is executed. This prevents the value stored in the nonvolatile memory 125B after the challenge data is erased from being treated as challenge data, even though the value is a value specified by the administrator, such as FFh or 00h.
[0063] The authentication process flag may be set at any timing between after the challenge data is generated and after the challenge data is completely saved in the nonvolatile memory 125B. The timing for resetting the authentication processing flag may be any timing between receiving authentication information from the mobile terminal device 200 and determining that the authentication processing can be performed, and determining whether the authentication processing has succeeded or failed and sending a response. Furthermore, the electronic lock device 100 may reset the authentication processing flag when it receives a command other than an authentication command linked with authentication information from the mobile terminal device 200. This allows the electronic lock device 100 to maintain security against fraud caused by sending commands other than authentication commands from an external device.
[0064] If the authentication process flag is not set (step ST66: NO) or if the authentication is not successful (step ST38: NO), the electronic lock device 100 generates a failure response for the unlocking operation (step ST46), resets the authentication process flag in the nonvolatile memory 125B (step ST70), and transmits the generated failure response S22 to the mobile terminal device 200 (step ST48). The mobile terminal device 200 receives the failure response S22 from the electronic lock device 100 (step ST16).
[0065] As described above, according to the electronic lock system 1 of the second embodiment, even in the battery-less electronic lock device 100, challenge data is generated in response to the antenna unit 110 generating power due to electromagnetic waves output from the mobile terminal device 200, the generated challenge data is stored in the non-volatile memory 125B, and the generated challenge data is transmitted to the mobile terminal device 200, the mobile terminal device 200 transmits the challenge data to the management server device 300 in response to receiving the challenge data from the electronic lock device 100, the management server device 300 performs a predetermined calculation in response to receiving the challenge data from the mobile terminal device 200 to calculate authentication information, and transmits the calculated authentication information to the mobile terminal device 200, In response to receiving authentication information calculated by the management server device 300, the mobile terminal device 200 transmits the received authentication information to the electronic lock device 100, the electronic lock device 100 receives from the mobile terminal device 200 the authentication information calculated by the management server device 300 based on the challenge data, the electronic lock device 100 calculates the authentication information based on the challenge data stored in the non-volatile memory 125B using the power generated by the antenna unit 110, performs authentication processing based on the authentication information calculated by the management server device 300 using the power generated by the antenna unit 110, and can lock and unlock based on the authentication result of the authentication processing using the power generated by the antenna unit 110. With this electronic lock device 100, the battery-less electronic lock device 100 can unlock the door using the challenge data.
[0066] Furthermore, according to the second embodiment of the electronic lock system 1, authentication can be performed using challenge data even in an environment where the mobile terminal device 200 needs to be operated away from the electronic lock device 100 when generating authentication information in the management server device 300.
[0067] Although each embodiment and variant example has been described, these are merely examples and are not intended to limit the scope of the present invention. For example, one of the embodiments or variant examples, or a part of each embodiment or a part of each variant example, may be combined with one or more other embodiments or one or more other variant examples to realize one aspect of the present invention. In the electronic lock system 1 described above, the challenge data is generated by the electronic lock device 100 and the authentication information is calculated by the electronic lock device 100, but this is not limited to this, and the challenge data may be generated by the mobile terminal device 200 and the authentication information may be calculated by the mobile terminal device 200. Also, the mobile terminal device 200 may perform authentication processing using the authentication information generated by the mobile terminal device 200 and transmit the authentication result to the electronic lock device 100. [Explanation of symbols]
[0068] 1. Electronic lock system 10 doors 12 Handle 13 Strike 100 Electronic Locking Device 110 Antenna section 120 IC chips 121 Communications Department 122 Challenge Data Generation Unit 123 Authentication information calculation unit 124 Authentication Section 125 Storage section 125A Volatile Memory 125B non-volatile memory 126 Unlock signal output unit 130 Timer 140 Rectifier circuit 150 Control Microcomputer 160 Locking / Unlocking Mechanism 160 162 Deadbolt 200 Portable terminal device 202 Communications Department 204 NFC communication circuit 206 Processing section 208 User Interface Section 210 Storage section 300 Management server device 302 Communications Department 304 Authentication Information Calculation Unit 306 Access Permission Verification Section 308 Storage section
Claims
1. an antenna unit that generates power using electromagnetic waves output from an electronic device; a generation unit that operates using the power generated by the antenna unit and generates challenge data; a storage unit that stores the challenge data generated by the generation unit; a calculation unit that operates using the power generated by the antenna unit and calculates authentication information based on the challenge data stored in the storage unit; a communication unit that causes the antenna unit to transmit the challenge data generated by the generation unit to an external device and causes the antenna unit to receive authentication information calculated based on the challenge data from the external device; an authentication unit that operates using power generated by the antenna unit and performs authentication processing based on authentication information received from an external device and the authentication information calculated by the calculation unit; a locking / unlocking unit that operates using the power generated by the antenna unit and locks / unlocks the door based on the authentication result of the authentication process; An electronic lock device comprising:
2. The electronic lock device according to claim 1 , wherein the storage unit is a volatile memory.
3. The electronic lock device according to claim 2 , wherein the authentication information stored in the calculation unit is stored in the volatile memory.
4. The electronic lock device described in claim 1, wherein the authentication unit does not perform authentication processing if the time between storing the challenge data generated by the generation unit and receiving authentication information calculated based on the challenge data from the external device exceeds a threshold value.
5. The authentication unit setting an authentication processing flag in response to the communication unit transmitting the challenge data and storing the authentication processing flag in the volatile memory; performing the authentication process when the authentication information is received from the external device while the authentication process flag is set; resetting the authentication processing flag in response to the completion of the authentication processing; The electronic lock device according to claim 3.
6. The electronic lock device according to claim 1 , wherein the storage unit is a non-volatile memory.
7. The electronic lock device according to claim 6 , wherein the authentication unit erases the challenge data stored in the nonvolatile memory in response to the authentication process being performed.
8. The authentication unit setting an authentication processing flag in response to the communication unit transmitting the challenge data and storing the authentication processing flag in the nonvolatile memory; performing the authentication process when the authentication information is received from the external device while the authentication process flag is set; resetting the authentication processing flag in response to the completion of the authentication processing; The electronic lock device according to claim 7.
9. The electronic lock device according to claim 5 or claim 8, wherein the authentication unit resets the authentication processing flag when it receives a command other than an authentication command linked to the authentication information from an external device while the authentication processing flag is set.
10. In an electronic lock system including an electronic lock device, an electronic device, and a management server device, The electronic lock device is an antenna unit that generates power using electromagnetic waves output from the electronic device; a generation unit that operates using the power generated by the antenna unit and generates challenge data; a storage unit that stores the challenge data generated by the generation unit; a calculation unit that operates using the power generated by the antenna unit and calculates authentication information based on the challenge data stored in the storage unit; a communication unit that causes the challenge data generated by the generation unit to be transmitted from the antenna unit to the electronic device and causes the authentication information calculated by the management server device based on the challenge data to be received by the antenna unit; an authentication unit that operates using power generated by the antenna unit and performs authentication processing based on authentication information calculated by the management server device and the authentication information calculated by the calculation unit; a locking / unlocking unit that operates using the power generated by the antenna unit and performs locking / unlocking based on the authentication result of the authentication process, The electronic device requests challenge data from the electronic lock device, transmits the challenge data to the management server device in response to receiving the challenge data from the electronic lock device, and transmits the received authentication information to the electronic lock device in response to receiving authentication information calculated by the management server device, the management server device, upon receiving the challenge data from the electronic device, performs the same calculation as the authentication unit to calculate authentication information, and transmits the calculated authentication information to the electronic device. Electronic locking system.
11. A method for locking and unlocking an electronic lock system including an electronic lock device, an electronic device, and a management server device, The electronic device requests challenge data from the electronic lock device, The electronic lock device generates challenge data in response to the antenna unit generating power due to the electromagnetic waves output from the electronic device, stores the generated challenge data, and transmits the generated challenge data from the antenna unit to the electronic device, The electronic device transmits the challenge data to the management server device in response to receiving the challenge data from the electronic lock device, the management server device performs a predetermined calculation to calculate authentication information in response to receiving the challenge data from the electronic device, and transmits the calculated authentication information to the electronic device; The electronic device transmits the authentication information calculated by the management server device to the electronic lock device in response to receiving the authentication information. The electronic lock device receives authentication information calculated by the management server device based on the challenge data from the electronic device, The electronic lock device calculates authentication information based on the stored challenge data using the power generated by the antenna unit, the electronic lock device performs authentication processing based on authentication information calculated by the management server device and the authentication information calculated by the electronic lock device using the power generated by the antenna unit; The power generated by the antenna unit is used to lock and unlock the door based on the authentication result of the authentication process. Locking and unlocking method.
Citation Information
Patent Citations
Electronic signature attaching method
JP2004023406A
Server device, terminal device, equipment management system, equipment management method, and program
JP2018013002A
Carsharing system
JP2019070276A
Cited By
Unlocking management system, receiver, management server and program
JP7909344B1