Authentication systems, mobile devices, and authentication devices

The authentication system optimizes communication states between a mobile terminal and multiple devices to address positional challenges, ensuring timely and efficient authentication completion.

JP2026104221APending Publication Date: 2026-06-25DENSO WAVE INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
DENSO WAVE INC
Filing Date
2024-12-13
Publication Date
2026-06-25

AI Technical Summary

Technical Problem

Existing authentication systems face challenges in appropriately setting authentication devices based on positional relationships between terminals and devices, leading to potential delays in authentication timing when multiple devices are involved.

Method used

An authentication system with a mobile terminal and multiple authentication devices that manage communication states to prioritize and optimize authentication processes, including signal transmission and reception to ensure timely completion of authentication without interference.

Benefits of technology

The system reduces authentication delays and improves usability by allowing the mobile terminal to complete authentication with multiple devices efficiently, minimizing waiting times and optimizing communication states.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026104221000001_ABST
    Figure 2026104221000001_ABST
Patent Text Reader

Abstract

If a mobile device can be authenticated by multiple authentication devices, the completion time of authentication may be delayed. [Solution] The authentication system comprises a mobile terminal and multiple authentication devices. The mobile terminal has a mobile terminal-side communication unit that communicates with each authentication device in a connected state with wireless communication established or in an unconnected state without wireless communication established. Each authentication device has an authentication device-side communication unit that communicates with the mobile terminal in a connected state with wireless communication established or in an unconnected state without wireless communication established, and an authentication unit that regulates communication with the mobile terminal in a connected state based on whether the mobile terminal is communicating with another authentication device in a connected state. The authentication unit of one of the multiple authentication devices will not communicate with a mobile terminal in a connected state if the mobile terminal is communicating with another authentication device in a connected state, until the communication between the mobile terminal and the other authentication device in a connected state is completed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an authentication system, a mobile terminal, and an authentication device.

Background Art

[0002] Patent Document 1 discloses an authentication system including a key terminal used in a vehicle and an authentication unit that authenticates the key terminal mounted on the vehicle. In this authentication system, when one key terminal can be used in a plurality of vehicles, an authentication unit for which the key terminal requests authentication is set based on the positional relationship between the communication module and the key terminal.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] When there are a plurality of authentication devices for performing authentication, as in the above document, it may not be possible to appropriately set the authentication device for performing authentication only based on the positional relationship between the terminal receiving authentication and the authentication device. For example, each of a plurality of security areas may include an authentication device, and a user carrying a terminal for receiving authentication may try to enter any of the plurality of security areas. In this case, for example, the user may not enter the nearest security area, so it is difficult to appropriately set the authentication device for performing authentication only based on the positional relationship between the terminal and the authentication device. Thus, when a plurality of authentication devices are provided and the terminal receiving authentication can communicate with each of the plurality of authentication devices, if communication for authentication between this terminal and a second authentication device is started while authentication by the first authentication device is being performed, there is a risk that the timing for ending authentication by the first authentication device will be delayed.

Means for Solving the Problems

[0005] This disclosure can be implemented in the following forms:

[0006] (1) According to one embodiment of the present disclosure, an authentication system is provided comprising a mobile terminal and a plurality of authentication devices. The mobile terminal has a mobile terminal-side communication unit that communicates with each of the plurality of authentication devices in a connected state in which wireless communication has been established or in an unconnected state in which wireless communication has not been established. Each authentication device has an authentication device-side communication unit that communicates with the mobile terminal in a connected state in which wireless communication has been established or in an unconnected state in which wireless communication has not been established, and an authentication unit that restricts communication with the mobile terminal in the connected state based on whether or not the mobile terminal is communicating with another authentication device in the connected state. The authentication unit of one of the plurality of authentication devices refrains from communicating with the mobile terminal in the connected state if the mobile terminal is communicating with another authentication device in the connected state, until the communication between the mobile terminal and the other authentication device in the connected state is completed. In this configuration, since communication does not occur while the authentication device and the mobile terminal are connected for authentication, the mobile terminal can communicate for authentication with other authentication devices without being hindered by communication with one authentication device. Therefore, the mobile terminal can complete authentication with other authentication devices earlier compared to when it communicates with each of multiple authentication devices in parallel while connected. (2) In the authentication system of the above form, the authentication unit transmits a first signal to initiate the connection state, and the mobile terminal has a signal transmitting unit that transmits a second signal to request the termination of the connection state. The signal transmitting unit, upon receiving the first signal from the first authentication device while communicating with the other authentication device in the connection state, initiates communication with the first authentication device in the connection state, transmits the second signal to the first authentication device during the communication in the connection state, and the authentication unit, upon receiving the second signal, may terminate the connection state with the mobile terminal. In this configuration, one authentication device can disconnect from a mobile device when authentication is being performed between the mobile device and another authentication device, without communicating with the other authentication device. (3) In the authentication system of the above form, the signal transmission unit transmits an identification signal including identification information of the mobile terminal, and the authentication unit, in the connection state, authenticates whether the mobile terminal that is the source of the identification signal is a mobile terminal that has been registered in advance, and upon receiving the second signal, may terminate the connection state with the mobile terminal before starting the authentication. (4) In the authentication system of the above form, the authentication unit of the authentication device does not need to transmit the first signal to the mobile terminal until a predetermined waiting time has elapsed after the connection state with the mobile terminal has been terminated. In this configuration, by setting the waiting time to the time required for authentication between the mobile terminal and other authentication devices, the mobile terminal can complete authentication with other authentication devices without being interrupted by communication with one authentication device. Furthermore, one authentication device can avoid the unnecessary processing of transmitting the first signal during periods when there is a high probability that the second signal will be transmitted from the mobile terminal. (5) In the authentication system of the above form, the identification signal is an advertisement signal transmitted in the disconnected state, the second signal transmitted in the connected state includes the identification information, each authentication device is equipped with a storage unit, and when the authentication unit receives the second signal, it records the identification information included in the second signal and the time of reception of the second signal in the storage unit, and transmits the first signal to the mobile terminal in either the case where the identification information included in the received advertisement signal is not recorded in the storage unit, or where the identification information included in the received advertisement signal is recorded in the storage unit and the waiting time has elapsed since the time of reception, and does not need to transmit the first signal to the mobile terminal if the identification information included in the received advertisement signal is recorded in the storage unit and the waiting time has not elapsed since the time of reception. In this configuration, the authentication unit can determine whether the mobile terminal that sent the advertisement signal is the same mobile terminal that previously sent the second signal, by referring to its own memory unit, without communicating with other devices. (6) In the authentication system of the above form, the authentication unit performs the authentication on the mobile terminal located in the first area, and performs passage authentication to determine whether the mobile terminal located in the second area, which is closer to the authentication unit than the first area, is the mobile terminal that has already been successfully authenticated, and each authentication device has a release unit that releases the passage restriction when the passage authentication is successful, and the authentication unit may release the connection state while the mobile terminal that transmitted the second signal is located in the first area. In this configuration, one authentication device can terminate its connection with a mobile device early, thereby enabling it to initiate communication with other mobile devices for authentication sooner. Therefore, the possibility of mobile devices waiting for authentication can be reduced. This disclosure can be implemented in forms other than the authentication system described above, such as authentication devices, mobile terminals, authentication methods, computer programs, and non-temporary tangible recording media on which computer programs are recorded in a way that can be read by a computer. [Brief explanation of the drawing]

[0007] [Figure 1] This is a schematic diagram showing the general configuration of the authentication system. [Figure 2] This is a block diagram of the authentication system. [Figure 3] This is a diagram showing the authentication sequence. [Figure 4] This is a flowchart of the startup process on the mobile device side. [Figure 5] This is a flowchart of the authentication process at startup. [Figure 6] This is a sequence diagram showing the case where two authentication devices transmit the first signal. [Modes for carrying out the invention]

[0008] A. Embodiments: A1. Overall configuration of the authentication system: Figure 1 is a schematic diagram showing the general configuration of the authentication system 1. The authentication system 1 is a system for limiting the users US who can enter the security area SA to users US who have been previously authorized to enter. The authentication system 1 comprises a portable terminal 30 and an authentication device 10. In this embodiment, the authentication device 10 is located near the door GE, which is located at the entrance to the security area SA. The portable terminal 30 is carried by the user US. In this embodiment, the door GE is locked and unlocked by an electric lock EL. In this disclosure, the electric lock EL refers to a lock whose locking and unlocking are controlled electrically, regardless of whether it is battery-operated or not. In other words, in this embodiment, the passage of the user US carrying the portable terminal 30 is restricted by the door GE and the electric lock EL. The authentication device 10 releases the passage restriction according to the result of the authentication process performed with the portable terminal 30.

[0009] In Figure 1, the security area SA is depicted as a room, with a door GE at its entrance, but the configuration is not limited to this. For example, the security area SA may be a building or a train station, and the access restriction measures, such as ticket gates in a train station or entrances to buildings, may be electrically controlled automatic doors or flapper gates. Furthermore, access restriction measures are not limited to physically restricting user entry using doors GE or the like. The following explanation will mainly describe entry into the security area SA, but this disclosure can also be applied to exiting the security area SA.

[0010] In this embodiment, the authentication system 1 comprises a plurality of authentication devices 10. The plurality of authentication devices 10 include a first authentication device 10A and a second authentication device 10B. The security area SA, electric lock EL, and door GE corresponding to the first authentication device 10A are referred to as the first security area SA1, the first electric lock EL1, and the first door GE1, respectively. The security area SA, electric lock EL, and door GE corresponding to the second authentication device 10B are referred to as the second security area SA2, the second electric lock EL2, and the second door GE2, respectively.

[0011] In the following explanation, when the distinction between the first security area SA1 and the second security area SA2 is not made, they will simply be referred to as security area SA. When the distinction between the first electric lock EL1 and the second electric lock EL2 is not made, they will simply be referred to as electric lock EL. When the distinction between the first door GE1 and the second door GE2 is not made, they will simply be referred to as door GE.

[0012] In this embodiment, user US is permitted to enter both the first security area SA1 and the second security area SA2. Also, in this embodiment, the first authentication device 10A and the second authentication device 10B do not share the result information 53, which will be described later. Therefore, in order for user US to enter the first security area SA1, authentication by the first authentication device 10A must be successful, and in order for user US to enter the second security area SA2, authentication by the second authentication device 10B must be successful.

[0013] Figure 2 is a block diagram of the authentication system 1. The authentication device 10 comprises a control unit 11, a storage unit 12, an operation unit interface 13, an input unit 14, and a communication unit 15. The control unit 11, the storage unit 12, the operation unit interface 13, and the communication unit 15 are communicated to each other via a bus 17. The control unit 11 is composed of a processor such as a CPU. The storage unit 12 is composed of memory such as RAM or ROM. The communication unit 15 is also referred to as the authentication device side communication unit.

[0014] The control unit 11 includes a release unit 20 and an authentication unit 23. The release unit 20 and the authentication unit 23 are functional units that are realized by executing a program stored in the storage unit 12. The control unit 11 also includes a timing unit (not shown).

[0015] The storage unit 12 stores the programs executed by the control unit 11. In the present embodiment, the storage unit 12 further stores the registration information 26, the device identification information 54, the result information 53 stored in the first authentication described later, and the mobile list 55 described later. The device identification information 54 is information uniquely assigned to the authentication device 10.

[0016] The registration information 26 is information in which the identification information 51 and the authentication information 52 are associated in advance. The identification information 51 is information uniquely assigned to the mobile terminal 30. As the identification information 51, for example, an identifier such as an individual identifier, an address in wireless communication, or an identifier created by adding a manufacturing number to the model name of the mobile terminal 30 can be used. The individual identifier is an identifier given from the authentication device 10 in the setting of installing the authentication application 42 in the mobile terminal 30 described later. The authentication information 52 is information corresponding to the identification information 51. The authentication information 52 is information uniquely assigned to the user US. As the authentication information 52, for example, a number such as an employee number or an individual number assigned by the administration, or information combining a name and a date of birth can be used. The registration information 26 is created, for example, by the administrator of the authentication system 1. Note that the identification information 51 is not limited to only one piece of data and may include a plurality of pieces of data. One piece of data refers to a collection of information indicating one content like the above individual identifier. The same applies to the authentication information 52.

[0017] The authentication unit 23 uses the registration information 26 to perform authentication, which is an operation to confirm whether the user US attempting to enter the security area SA is an authorized user US. The authentication unit 23 performs first authentication and second authentication based on the identification signal received from the mobile terminal 30. The first authentication is to determine whether the mobile terminal 30 that is the source of the received identification signal is a pre-registered mobile terminal 30 based on the identification information 51 received from the mobile terminal 30 and the authentication information 52 of the registration information 26. The pre-registered mobile terminal 30 refers to a mobile terminal 30 having identification information 51 that matches the authentication information 52 of the registration information 26. The second authentication is to determine whether the mobile terminal 30 that transmitted the identification signal is the mobile terminal 30 that has successfully passed the first authentication. In addition, the authentication unit 23 restricts the communication of the connection state with the mobile terminal 30 based on whether the mobile terminal 30 is communicating with another authentication device 10 in a connected state. Specifically, when the mobile terminal 30 is communicating with another authentication device 10 in a connected state, the communication of the connection state with the mobile terminal 30 is restricted. The restriction is not limited to not performing communication in the connection state with the mobile terminal 30, but also includes disconnecting the communication in the existing connection state.

[0018] When the second authentication is successful by the authentication unit 23, the release unit 20 transmits an unlocking command to the electric lock EL to release the passage restriction.

[0019] An input unit 14 is communicably connected to the operation unit interface 13. The operation unit interface 13 mediates the communication between the control unit 11 and the input unit 14. The input unit 14 is arranged near the electric lock EL. Specifically, the distance between the input unit 14 and the electric lock EL is, for example, several tens of cm or less. The input unit 14 includes operation buttons and the like for performing various operations on the authentication device 10.

[0020] The communication unit 15 is composed of a wireless communication module. The communication unit 15 performs wireless communication between the mobile terminal 30 and the electric lock EL. The communication unit 15 communicates in either a connected state where wireless communication has been established or in an unconnected state where wireless communication has not been established. In this embodiment, BLE (Bluetooth® Low Energy) communication in accordance with the BLE standard is performed as the wireless communication. In the following description, "BLE communication" may be simply referred to as "communication". In addition to BLE communication, communication in accordance with the BR / EDR (Bluetooth® Basic Rate / Enhanced Data Rate) standard or wireless LAN (Local Area Network) communication can be used as the wireless communication between the mobile terminal 30 and the electric lock EL. Furthermore, the communication standard for wireless communication between the communication unit 15 and the mobile terminal 30 and the communication standard for wireless communication between the communication unit 15 and the electric lock EL may be the same or different.

[0021] The electric lock EL is equipped with a communication module that communicates wirelessly with the communication unit 15, and locks or unlocks in response to commands transmitted from the authentication device 10. The electric lock EL and the authentication device 10 may be connected by a wire.

[0022] The mobile terminal 30 comprises a control unit 31, a storage unit 32, a display and operation unit 33, and a communication unit 34. The control unit 31, the storage unit 32, the display and operation unit 33, and the communication unit 34 are communicated with each other via a bus 35. The control unit 31 is composed of a processor such as a CPU. The storage unit 32 is composed of memory such as RAM or ROM. The storage unit 32 stores the aforementioned identification information 51 and the authentication application 42. The storage unit 32 also stores the device list 44, which will be described later. The communication unit 34 is also referred to as the mobile terminal side communication unit.

[0023] The control unit 31 includes a signal transmission unit 40. The signal transmission unit 40 is a functional unit realized when the control unit 31 executes an authentication application 42 stored in the storage unit 32. The signal transmission unit 40 transmits an identification signal to the authentication device 10, which includes identification information 51 stored in the storage unit 32. The identification signal will also be referred to as the advertised signal below.

[0024] The display operation unit 33 is implemented by a touch panel. The display operation unit 33 displays images and accepts operations such as touch operations from the user US.

[0025] The communication unit 34 is composed of a wireless communication module. The communication unit 34 performs wireless communication with the communication unit 15 of the authentication device 10. The communication unit 34 communicates in either a connected state where wireless communication has been established or an unconnected state where wireless communication has not been established. As described above, in this embodiment, the communication unit 34 performs BLE communication with the authentication device 10. As described above, in addition to BLE communication, communication compliant with the BR / EDR standard or wireless LAN communication can be used for communication between the authentication device 10 and the mobile terminal 30.

[0026] A2. Authentication Sequence: The authentication device 10 uses communication with the mobile terminal 30 to perform authentication, confirming that the person carrying the mobile terminal 30 is authorized to enter the security area SA. In the authentication sequence of this embodiment, authentication is performed in stages: first authentication and second authentication. First authentication is performed in a connected state where wireless communication has been established. First authentication takes, for example, about 2 seconds. First authentication is also simply referred to as authentication.

[0027] In Figure 1, pre-authentication area AR1 indicates the area where the first authentication takes place. Passage area AR2 indicates the area where the second authentication takes place. Pre-authentication area AR1 and passage area AR2 together are also called the authentication area. Pre-authentication area AR1 and passage area AR2 corresponding to the first authentication device 10A are called the first pre-authentication area AR1A and the first passage area AR2A, respectively. Pre-authentication area AR1 and passage area AR2 corresponding to the second authentication device 10B are called the second pre-authentication area AR1B and the second passage area AR2B, respectively.

[0028] In the following explanation, unless otherwise distinguished from the first pre-area AR1A and the second pre-area AR1B, it will simply be referred to as pre-area AR1. Unless otherwise distinguished from the first passage area AR2A and the second passage area AR2B, it will simply be referred to as passage area AR2.

[0029] By dividing the authentication process into a first authentication and a second authentication, and performing the first authentication, which takes time to process, when the mobile terminal 30 is located away from the authentication device 10, the possibility of the user US having to wait for the authentication process to finish while approaching the authentication device 10 can be reduced.

[0030] In this embodiment, the determination of whether user US has entered the pre-area AR1 and whether user US has entered the passage area AR2 is made using the RSSI (Received Signal Strength Indicator) when the authentication device 10 receives a signal transmitted from the mobile terminal 30. In this embodiment, it is set that user US has entered the passage area AR2 when user US holds the mobile terminal 30 over the input unit 14. The operation of user US holding the mobile terminal 30 over the input unit 14 is also called "holding the mobile terminal over".

[0031] Furthermore, the determination of whether or not the vehicle has entered the pre-area AR1 and the passage area AR2 may be made using a method other than RSSI. For example, the authentication device 10 may use the time it takes for the authentication device 10 to send and receive signals during communication with the mobile terminal 30 to determine whether or not the vehicle has entered the pre-area AR1 and the passage area AR2.

[0032] Furthermore, the determination of whether or not a person has entered the passage area AR2 may be made based on whether or not a "touch operation" such as touching the input unit 14, a "hand-waving operation" such as holding a hand over the input unit 14, or a "button operation" such as pressing an operation button on the input unit 14 has been performed. Alternatively, the determination of whether or not a person has entered the passage area AR2 may be made using, for example, the detection by a human presence sensor provided on the door GE or the authentication device 10 that a person has stopped in front of the door GE.

[0033] Figure 3 shows the authentication sequence. In the authentication system 1 of this embodiment, the mobile terminal 30 is used as a peripheral, and the authentication device 10 is used as a central. The authentication device 10 repeatedly transmits a beacon signal. When the signal transmission unit 40 of the mobile terminal 30 receives the beacon signal, it transmits an advertisement signal, which is a response signal. The advertisement signal includes the identification information 51 of the mobile terminal.

[0034] User US enters the pre-area AR1 shown in Figure 1. In step S10 shown in Figure 3, the authentication device 10 transmits a beacon signal. When the mobile terminal 30 receives the beacon signal transmitted by the authentication device 10, it transmits an advertisement signal in step S12. In step S14, the authentication device 10 determines that User US has entered the pre-area AR1. Specifically, the authentication device 10 determines that User US has entered the pre-area AR1 if the RSSI of the signal transmitted from the mobile terminal 30 is greater than a predetermined first criterion value Ith1 and less than or equal to a predetermined second criterion value Ith2. The first criterion value Ith1 and the second criterion value Ith2 are predetermined through experiments, etc. In the following explanation, the range greater than the first criterion value Ith1 and less than or equal to the second criterion value Ith2 is also called the reference range.

[0035] As described above, the authentication device 10 repeatedly transmits beacon signals. When the mobile terminal 30 receives a beacon signal, it transmits an advertisement signal. First authentication is initiated when the RSSI of the advertisement signal received by the authentication device 10 is within the reference range. Second authentication is initiated when the RSSI of the advertisement signal received by the authentication device 10 is greater than the second reference value Ith2. To facilitate understanding, Figure 3 shows the beacon signal and advertisement signal that trigger these authentications.

[0036] In step S16, the authentication device 10 and the mobile terminal 30 establish wireless communication and transition to a connected state for one-to-one communication. For example, if the RSSI of the received advertisement signal is within the reference range, the authentication device 10 sends a connection request to the mobile terminal 30 that sent the advertisement signal, and establishes wireless communication between the mobile terminal 30, which has received the connection request, and the authentication device 10 and the authentication device 10 transition to a connected state. In this disclosure, "connected state" means a state in which one-to-one communication is performed with a specific party. Communication in the connected state can be made more secure than when a signal is sent to a large number of parties by broadcast, such as an advertisement signal. This connection request is also called the first signal.

[0037] In the connected state, the authentication device 10 performs a first authentication using the identification information 51 transmitted from the mobile terminal 30 to confirm that the received identification information 51 is consistent with the authentication information 52. In step S20, if the authentication device 10 succeeds in the first authentication, in step S22, it stores the result information 53. Note that the signal transmitted from the mobile terminal 30 to the authentication device 10 in the connected state includes the identification information 51 and is therefore a type of identification signal.

[0038] Result information 53 is information that associates identification information 51 with authentication information 52. When the authentication device 10 succeeds in the first authentication, it stores result information 53 that associates the successful identification information 51 with authentication information 52. This allows the authentication device 10 to confirm that the identification information 51 has succeeded in the first authentication if it is included in the result information 53. Alternatively, the authentication device 10 may treat the identification information 51 as result information 53 without associating it with authentication information 52.

[0039] In step S24 of Figure 3, the authentication device 10 disconnects communication by releasing the connection with the mobile terminal 30. User US then approaches door GE and enters the passage area AR2 shown in Figure 1. In step S26 of Figure 3, the authentication device 10 transmits a beacon signal. When the mobile terminal 30 receives the beacon signal transmitted by the authentication device 10, it transmits an advertisement signal in step S28.

[0040] In step S32, the authentication device 10 confirms that the RSSI of the received advertisement signal is greater than the second reference value Ith2, and that user US has entered the passage area AR2. After step S32, the authentication device 10 compares the identification information 51 contained in the received advertisement signal with the result information 53 and performs a second authentication to confirm that the sender of the advertisement signal has succeeded in the first authentication. Specifically, in the second authentication, the authentication device 10 confirms that the identification information 51 contained in the received advertisement signal is included in the result information 53. Note that the advertisement signal is a signal transmitted in an unconnected state where the authentication device 10 and the mobile terminal 30 are not connected. The second authentication is performed without transitioning to a connected state.

[0041] If the authentication device 10 succeeds in the second authentication in step S36, in step S38, it releases the access restriction for user US carrying the mobile terminal 30 that has successfully undergone the second authentication. For example, the authentication unit 23 commands the electric lock EL to unlock. As a result, the electric lock EL is unlocked, and user US enters the security area SA.

[0042] In the authentication sequence, steps S10 to S24 are also called "pre-authentication." Steps S26 to S38 are also called "pass-through authentication." Furthermore, pre-area AR1 is also called the first area, and pass-through area AR2 is also called the second area.

[0043] As shown in Figure 1, when the first authentication device 10A and the second authentication device 10B are located close to each other, the first pre-area AR1A and the second pre-area AR1B overlap. Therefore, when a user US enters the area where the first pre-area AR1A and the second pre-area AR1B overlap, communication in a connected state is initiated with both the first authentication device 10A and the second authentication device 10B. The inventors have found that when the mobile terminal 30 communicates in a connected state with both the first authentication device 10A and the second authentication device 10B in parallel, the completion time of the first authentication is delayed compared to when the mobile terminal 30 communicates with only one authentication device 10. Therefore, in the authentication sequence of this embodiment, even when the mobile terminal 30 can communicate in a connected state with both the first authentication device 10A and the second authentication device 10B, it prioritizes communication with either the first authentication device 10A or the second authentication device 10B. This allows the mobile device 30 to complete authentication earlier. Therefore, the user US is less likely to experience authentication delays, thus improving usability.

[0044] A3. Details of startup processing: As described above, in step S16 of Figure 3, the authentication device 10 and the mobile terminal 30 transition to a connected state where wireless communication is established and one-to-one communication takes place. Specifically, the authentication device 10 sends a first signal, which is a connection request, to the mobile terminal 30 in order to transition to the connected state. As a result, the communication between the authentication device 10 and the mobile terminal 30 transitions from a disconnected state to a connected state. The authentication device 10 includes its own device identification information 54 in the first signal.

[0045] Figure 4 is a flowchart of the startup process performed by the mobile terminal 30. When the control unit 31 of the mobile terminal 30 receives the first signal from the authentication device 10, it starts the startup process.

[0046] In step S50 of Figure 4, the signal transmission unit 40 of the mobile terminal 30 acquires device identification information 54 included in the first signal. In step S52, the signal transmission unit 40 determines whether any of the device identification information 54 is recorded in the device list 44. The device list 44 is a list in which the device identification information 54 of the other party with whom communication is currently ongoing is recorded. If the connection state is to be continued, the signal transmission unit 40 records the other party's device identification information 54 in the device list 44 in step S54 described later. If any of the device identification information 54 is recorded in the device list 44, the signal transmission unit 40 determines that it is currently communicating with one of the authentication devices 10.

[0047] In step S52, if it is determined that the device identification information 54 is not included in the device list 44, it means that communication is not taking place in a connected state, and therefore, in step S54, the signal transmission unit 40 records the acquired device identification information 54 in the device list 44. Subsequently, communication with the authentication device 10 that transmitted the first signal continues in a connected state, and in this communication, the first authentication is performed by the authentication device 10.

[0048] After completing the first authentication, the authentication device 10 sends a disconnection packet to the mobile terminal 30 to terminate the communication while connected. Upon receiving the disconnection packet, the signal transmission unit 40 terminates the communication in step S56 by releasing the connection. In step S58, the signal transmission unit 40 deletes the device identification information 54 from the device list 44 and terminates this processing routine.

[0049] In step S52, if the device list 44 determines that any device identification information 54 is included, the signal transmission unit 40, since it is currently communicating with another authentication device 10 in a connected state, transmits a second signal to the authentication device 10 in step S60 to disconnect communication with the authentication device 10 that is the source of the first signal. The second signal is a signal indicating that it is connected to an authentication device other than the authentication device 10, for example, a signal to request the authentication device 10 to disconnect. The signal transmission unit 40 includes its own identification information 51 in the second signal. As will be described later, when the authentication device 10 receives the second signal, it transmits a disconnection packet to the mobile terminal 30. When the signal transmission unit 40 receives the disconnection packet, in step S62, it disconnects the communication by releasing the connection and terminates this processing routine.

[0050] In addition, if an error occurs during communication while connected, a first signal may be transmitted from the authentication device 10 to which the device identification information 54 stored in the device list 44 is attached, even though step S58 has not been performed. Therefore, after it is determined in step S52 that any device identification information 54 is recorded in the device list 44, a determination step may be added to determine whether the acquired device identification information 54 is the same as the device identification information 54 stored in the device list 44. If it is determined that the acquired device identification information 54 is the same as the device identification information 54 stored in the device list 44, the signal transmission unit 40 may release the connection. If it is determined that it is not the same as the device identification information 54, the signal transmission unit 40 may perform step S60. This allows for early detection of communication abnormalities and early termination of abnormal communications.

[0051] Figure 5 is a flowchart of the authentication-side startup process performed by the authentication device 10. The control unit 11 of the authentication device 10 receives an advertisement signal from the mobile terminal 30 (S12), and using the received signal strength of the advertisement signal, confirms that the user carrying the mobile terminal 30 has entered the pre-area AR1 (S14), and then starts the authentication-side startup process.

[0052] In step S70 of Figure 5, the authentication unit 23 extracts and acquires the identification information 51 contained in the received advertisement signal. In step S72, the authentication unit 23 determines whether the acquired identification information 51 is recorded in the mobile list 55. The mobile list 55 is a list in which the identification information 51 of mobile terminals 30 that have previously received the second signal is recorded. When the authentication unit 23 receives the second signal, in step S82 described later, it records the identification information 51 contained in the second signal and the reception time of the second signal in the device list 44. If the acquired identification information 51 is recorded in the mobile list 55, the authentication unit 23 determines that the source of the advertisement signal is the mobile terminal 30 that previously transmitted the second signal.

[0053] In step S72, if it is determined that the acquired identification information 51 is not recorded in the mobile list 55, in step S78, the authentication unit 23 transmits a first signal to start communication in the connected state. As described above, if the mobile terminal 30 is communicating with another authentication device 10, it transmits a second signal requesting the disconnection.

[0054] In step S80, the authentication unit 23 determines whether or not it has received the second signal. If it determines in step S80 that it has received the second signal, in step S82, the authentication unit 23 records the identification information 51 contained in the second signal in the mobile list 55 along with the time the second signal was received. In this disclosure, time refers to information including the date. After performing step S82, the authentication unit 23 proceeds to step S90.

[0055] If, in step S80, it is determined that the second signal has not been received, then in step S84, the authentication unit 23 performs the first authentication. In step S86, the authentication unit 23 determines whether the first authentication was successful. If, in step S86, it is determined that the first authentication was successful, then in step S88, the authentication unit 23 records the result information 53 in the storage unit 12 and proceeds to step S90. If, in step S86, it is determined that the first authentication was not successful, the authentication unit 23 proceeds to step S90.

[0056] In step S90, the authentication unit 23 sends a disconnection packet to the mobile terminal 30 to terminate communication with the mobile terminal 30. In this embodiment, the authentication unit 23 disconnects the connection with the mobile terminal 30 and terminates communication while the mobile terminal 30 is located in the pre-area AR1. Specifically, the authentication unit 23 immediately sends a disconnection packet upon receiving the second signal. This allows the authentication unit 23 to terminate communication with the mobile terminal 30 before the user US moves to the passage area AR2. This allows the authentication unit 23 to start authentication communication with other mobile terminals 30 earlier. After performing step S90, the authentication unit 23 terminates this processing routine.

[0057] In step S72, if it is determined that the acquired identification information 51 is recorded in the mobile list 55, in step S74, the authentication unit 23 refers to the mobile list 55 and determines whether a predetermined waiting time has elapsed from the reception time corresponding to the acquired identification information 51. In this embodiment, the waiting time is set to the time required for the first authentication and is stored in the storage unit 12 in advance. In step S74, if it is determined that the waiting time has elapsed, in step S76, the authentication unit 23 deletes the acquired identification information 51 from the mobile list 55 and proceeds to step S78.

[0058] In step S74, if the authentication unit 23 determines that the waiting time has not elapsed, it terminates this processing routine. In other words, if the authentication unit 23 determines in step S74 that the waiting time has not elapsed, it does not initiate communication with the mobile terminal 30 while connected. This eliminates the need for unnecessary communication while connected during periods when it is highly likely that the first authentication between the mobile terminal 30 and other authentication devices 10 is already being performed.

[0059] Figure 6 is a sequence diagram showing the case when two authentication devices 10 transmit a first signal. Figure 6 illustrates the case where the first authentication device 10A starts the first authentication before the second authentication device 10B. In Figure 6 and the following description, the same reference numerals are used for the same processing steps as described above, and detailed processing content is omitted as appropriate. Also, in Figure 6 and the following description, some of the processing steps performed by the mobile terminal 30 and the authentication device 10 are omitted as appropriate.

[0060] When the first authentication device 10A receives the advertisement signal in step S12, it transmits a first signal to the mobile terminal 30 in step S78 to begin communication in a connected state. Since the mobile terminal 30 is not communicating with any other authentication device 10 in a connected state for first authentication, in step S52 of Figure 4, it determines that no device identification information 54 is recorded in the device list 44 and continues to communicate with the first authentication device 10A in a connected state. The communication between the first authentication device 10A and the mobile terminal 30 after the first authentication device 10A transmits the first signal and the mobile terminal 30 transmits a signal in response to the first signal is the communication for first authentication.

[0061] If the mobile terminal 30 receives a first signal from the second authentication device 10B to initiate communication in a connected state while communicating with the first authentication device 10A for first authentication, then it is connected to the first authentication device 10A. Therefore, in step S52 of Figure 4, the mobile terminal 30 determines that one of the device identification information 54 is recorded in the device list 44. Next, in step S60, the mobile terminal 30 transmits a second signal to the second authentication device 10B.

[0062] Since the second authentication device 10B has received the second signal, in step S80 of Figure 5, the authentication unit 23 determines that it has received the second signal and disconnects the communication by releasing the connection in step S90. As a result, the mobile terminal 30 can prioritize communication with the first authentication device 10A, which has already started the first authentication. Therefore, compared to the case where the mobile terminal 30 performs the first authentication in parallel with both the first authentication device 10A and the second authentication device 10B, the mobile terminal 30 can complete the first authentication earlier.

[0063] Furthermore, after the mobile terminal 30 completes the first authentication with the first authentication device 10A, it is no longer connected to the first authentication device 10A. Therefore, if the mobile terminal 30 receives the first signal from the second authentication device 10B, it does not transmit the second signal. Consequently, the mobile terminal 30 can cause the second authentication device 10B to perform the first authentication.

[0064] In the above explanation, it was stated that the first authentication is performed in the pre-area AR1. However, the above explanation is a typical example, and the timing of the first authentication is not limited to when the user US is located in the pre-area AR1. For example, the user US may enter the passage area AR2 without successfully completing the first authentication, or the user US may fail the second authentication. In such cases, the authentication device 10 performs the first authentication on the mobile terminal 30 located in the passage area AR2.

[0065] According to the embodiment described above, the authentication system 1 comprises a mobile terminal 30 and a plurality of authentication devices 10. The mobile terminal 30 has a signal transmission unit 40. The authentication device 10 has a communication unit 15 and an authentication unit 23. The authentication unit 23 of the second authentication device 10B refrains from communicating with the mobile terminal 30 in the state of communication for the first authentication, including sending and receiving identification information, when the mobile terminal 30 is connected to the first authentication device 10A and performing communication for the first authentication, until the communication between the mobile terminal 30 and the first authentication device 10A is completed. As a result, the mobile terminal 30 can perform authentication communication with the first authentication device 10A without being hindered by communication with the second authentication device 10B. Therefore, the mobile terminal 30 can complete the first authentication with the first authentication device 10A earlier compared to when it performs communication in the state of connection for the first authentication in parallel with each of the plurality of authentication devices 10. Therefore, when a user US carrying a mobile device 30 enters a security area SA, the possibility of the user US having to wait for authentication can be reduced.

[0066] Furthermore, when the signal transmission unit 40 of the mobile terminal 30 receives a first signal from the second authentication device 10B to initiate the connection state while communicating with the first authentication device 10A, it initiates communication in the connection state and then transmits a second signal to the second authentication device 10B requesting the termination of the connection state (step S60). When the authentication unit 23 of the second authentication device 10B receives the second signal, it terminates communication with the mobile terminal 30 in the connection state before initiating the first authentication. In this way, the mobile terminal 30 transmits the second signal to the second authentication device 10B. Therefore, the second authentication device 10B can determine that the mobile terminal 30 is performing the first authentication with another authentication device 10 without, for example, querying the first authentication device 10A whether or not it is currently performing the first authentication with the mobile terminal 30, and terminate communication with the mobile terminal 30 in the connection state. Even if the second authentication device 10B that sent the first signal is configured to start the authentication process for the mobile terminal 30, upon receiving the second signal from the mobile terminal 30, the second authentication device 10B will interrupt the authentication process and disconnect the connection.

[0067] Furthermore, the authentication unit 23 of the second authentication device 10B does not transmit the first signal to the mobile terminal 30 until a waiting period has elapsed after disconnecting communication with the mobile terminal 30. As a result, the mobile terminal 30 can complete authentication with the first authentication device 10A without being hindered by communication with the second authentication device 10B. In addition, the second authentication device 10B can avoid the unnecessary transmission of the first signal during periods when there is a high probability that the mobile terminal 30 will transmit the second signal.

[0068] Furthermore, the authentication unit 23 records the identification information 51 contained in the second signal and the reception time of the second signal in the storage unit 12. The authentication unit 23 then receives an advertisement signal from the mobile terminal 30, and if the identification information 51 contained in the advertisement signal is recorded in the mobile list 55 of the storage unit 12, and if the waiting time has not elapsed since the recorded reception time, it does not transmit the first signal to the mobile terminal 30. In this way, the authentication device 10 can determine whether or not to transmit the first signal without communicating with other information processing devices, for example, by recording the mobile terminal 30 that transmitted the second signal in the mobile list 55 stored in its storage unit 12.

[0069] Furthermore, the second authentication device 10B disconnects from the mobile terminal 30 while the mobile terminal 30 is located in the pre-area AR1. By disconnecting from the mobile terminal 30 early, the second authentication device 10B can initiate communication for the first authentication with other mobile terminals 30 earlier. Therefore, the possibility of the mobile terminal 30 waiting for authentication can be reduced.

[0070] B. Other embodiments: (B1) In the above embodiment, the second signal is transmitted during communication between the mobile terminal 30 and the second authentication device 10B while they are connected. In another embodiment, the second signal may be transmitted during communication between the mobile terminal 30 and the second authentication device 10B while they are not connected. In this case, the authentication unit 23 of the second authentication device 10B does not communicate with the mobile terminal 30 while they are connected until at least a waiting period has elapsed after receiving the second signal, which is a signal that rejects communication while connected. This form also produces the same effects as the above embodiment.

[0071] (B2) In the above embodiment, the authentication unit 23 does not transmit the first signal to a mobile terminal 30 that has previously received the second signal until the waiting time has elapsed. In another embodiment, the authentication unit 23 may transmit the first signal regardless of whether the mobile terminal 30 has previously received the second signal or whether the waiting time has elapsed. If the mobile terminal 30 is undergoing first authentication with another authentication device 10, it transmits the second signal upon receiving the first signal, thus avoiding a situation where first authentication is performed in parallel with multiple authentication devices 10. In other words, the same effects as in the above embodiment can be achieved.

[0072] (B3) In the above embodiment, the first authentication device 10A and the second authentication device 10B do not share result information 53, and the user US must succeed in authentication by the corresponding authentication device 10 when entering each security area SA. In another embodiment, the first authentication device 10A and the second authentication device 10B may share the result of whether or not the first authentication was successful.

[0073] Specifically, when the authentication device 10 succeeds in the first authentication, it generates a ticket according to a pre-shared generation formula between the first authentication device 10A and the second authentication device 10B, and transmits the generated ticket to the mobile terminal 30. The mobile terminal 30 includes the transmitted ticket in the advertisement signal. In the second authentication, the authentication device 10 determines whether the ticket is valid by determining whether the ticket included in the advertisement signal transmitted from the mobile terminal 30 was generated according to the shared generation formula. If the ticket is valid, the authentication device 10 determines that the second authentication has been successful. According to this embodiment, if the first authentication is successful with any of the multiple authentication devices 10, the first authentication can be omitted for authentication devices 10 other than the one that performed the first authentication.

[0074] In addition, as another method for sharing the results of whether the first authentication was successful or not between the first authentication device 10A and the second authentication device 10B, a higher-level device between the first authentication device 10A and the second authentication device 10B may manage the results of the first authentication.

[0075] (B4) In the above embodiment, the registration information 26 is stored in the storage unit 12 of the authentication device 10. In another embodiment, the registration information 26 may be stored in a server that is communicatively connected to the authentication device 10. That is, the authentication unit 23 may obtain the registration information 26 stored in the server by communicating with the server. The authentication unit 23 may then request authentication from the server using the identification information 51 and perform authentication using the provided authentication result. This authentication may be performed after the first authentication or after the second authentication. This embodiment is useful when multiple entrances are provided in the security area SA and multiple authentication devices 10 use common registration information 26.

[0076] (B5) In the above embodiment, the program stored in the authentication device 10 or the mobile terminal 30 may be recorded on a tangible, non-temporary recording medium that is readable by a computer. Some or all of the functional units implemented in software by the program may be implemented by hardware such as circuits or integrated circuits.

[0077] (B6) In the above embodiment, the first authentication is not limited to a process of confirming that the identification information 51 stored as registration information 26 is consistent with the received identification information 51. For example, it may be a process of confirming that the information decrypted using the key exchanged during pairing from the received encrypted identification information 51 is consistent with the identification information 51 or authentication information 52 stored as registration information 26. Since pairing is performed by identifying user US, the consistency between the received identification information 51 and registration information 26 can be confirmed even in such a confirmation process. Since the first authentication is performed while connected, signals can be exchanged while maintaining a high level of confidentiality of the transmitted signals.

[0078] (B7) In the above embodiment, the content of the identification information 51 included in the identification signal transmitted in the pre-area AR1 and the content of the identification information 51 included in the identification signal transmitted in the passage area AR2 may be the same or different. Specifically, if the identification information 51 includes multiple data, at least a portion of the multiple data in the identification information 51 included in the identification signal transmitted in the pre-area AR1 and the multiple data in the identification information 51 included in the identification signal transmitted in the passage area AR2 may be different. Also, the identification information 51 included in the identification signal transmitted in the pre-area AR1 and the identification information 51 included in the identification signal transmitted in the passage area AR2 may each contain only one data.

[0079] (B8) In the above embodiment, the authentication unit 23 causes the storage unit 12 to record the identification information 51 included in the second signal and the reception time of the second signal. In another embodiment, the mobile terminal 30 may have a timing unit, and the second signal may include the transmission time of the second signal, causing the storage unit 12 to record the identification information 51 included in the second signal and the transmission time of the second signal.

[0080] This disclosure is not limited to the embodiments described above, and can be implemented in various configurations without departing from its spirit. For example, the technical features of the embodiments corresponding to the technical features in each form described in the summary of the invention can be replaced or combined as appropriate in order to solve some or all of the above-described problems, or to achieve some or all of the above-described effects. Furthermore, if a technical feature is not described as essential in this specification, it can be deleted as appropriate. [Explanation of Symbols]

[0081] 1…Authentication system, 10…Authentication device, 10A…First authentication device, 10B…Second authentication device, 11…Control unit, 12…Storage unit, 13…Operation unit interface, 14…Input unit, 15…Communication unit, 17…Bus, 20…Release unit, 23…Authentication unit, 26…Registration information, 30…Mobile terminal, 31…Control unit, 32…Storage unit, 33…Display operation unit, 34…Communication unit, 35…Bus, 40…Signal transmission unit, 42…Authentication application, 44…Device list, 51…Identification information, 52…Authentication information, 53…Result information, 54…Device identification information, 55…Mobile list

Claims

1. An authentication system comprising a mobile terminal and multiple authentication devices, The aforementioned mobile terminal is The mobile terminal side has a communication unit that communicates with each of the multiple authentication devices either in a connected state where wireless communication has been established or in an unconnected state where wireless communication has not been established. Each of the aforementioned authentication devices, The authentication device side communication unit communicates with the aforementioned mobile terminal either in a connected state where wireless communication has been established or in an unconnected state where wireless communication has not been established. The system includes an authentication unit that regulates communication with the mobile terminal regarding the connection state based on whether the mobile terminal is communicating with another authentication device in the connection state, The authentication unit of one of the multiple authentication devices is An authentication system that, with respect to a mobile terminal that is communicating with another authentication device among the plurality of authentication devices in the connected state, refrains from communicating with the mobile terminal in the connected state until the communication between the mobile terminal and the other authentication device in the connected state ends.

2. The authentication system according to claim 1, The authentication unit, A first signal is transmitted to initiate the aforementioned connection state. The aforementioned mobile terminal is It has a signal transmission unit that transmits a second signal requesting the release of the aforementioned connection state, The signal transmission unit is When the first signal is received from the first authentication device during communication with the other authentication device in the aforementioned connection state, communication with the first authentication device in the aforementioned connection state is initiated, and the second signal is transmitted to the first authentication device during the communication in the aforementioned connection state. The authentication unit, upon receiving the second signal, terminates the connection with the mobile terminal, thereby completing the authentication system.

3. The authentication system according to claim 2, The signal transmission unit is The mobile terminal transmits an identification signal containing identification information, The authentication unit, In the aforementioned connection state, authentication is performed to determine whether the mobile terminal that is the source of the identification signal is a mobile terminal that has been registered in advance. An authentication system that, upon receiving the second signal, disconnects the connection with the mobile terminal before initiating the authentication.

4. The authentication system according to claim 3, An authentication system in which the authentication unit of the authentication device does not transmit the first signal to the mobile terminal until a predetermined waiting period has elapsed after the connection state with the mobile terminal has been terminated.

5. The authentication system according to claim 4, The aforementioned identification signal is an advertisement signal transmitted in the disconnected state. The second signal transmitted in the aforementioned connection state includes the identification information, Each of the authentication devices includes a storage unit, The authentication unit, When the second signal is received, the identification information contained in the second signal and the reception time of the second signal are recorded in the storage unit. The first signal is transmitted to the mobile terminal in either case: when the identification information contained in the received advertised signal is not recorded in the storage unit, or when the identification information contained in the received advertised signal is recorded in the storage unit and the waiting time has elapsed since the time of reception. An authentication system that does not transmit the first signal to the mobile terminal if the identification information contained in the received advertisement signal is recorded in the storage unit and the waiting time has not elapsed since the time of reception.

6. An authentication system according to any one of claims 3 to 5, The authentication unit performs authentication on the mobile terminal located in the first area, and performs access authentication to determine whether the mobile terminal located in the second area, which is closer to the authentication unit than the first area, is the mobile terminal that has already been successfully authenticated. Each of the aforementioned authentication devices has a release unit that releases the traffic restriction when the traffic authentication is successful. The authentication unit, if the mobile terminal that transmitted the second signal is located in the first area, terminates the connection while the mobile terminal is located in the first area, the authentication system.

7. A mobile terminal that communicates with multiple authentication devices, It has a signal transmission unit that transmits an identification signal including identification information of the mobile terminal, Each of the plurality of authentication devices, in a connection state in which wireless communication has been established with the mobile terminal, authenticates whether the mobile terminal that is the source of the identification signal is the mobile terminal that has been registered in advance. A portable terminal wherein, while communicating with the authentication device in the connection state for authentication, the signal transmitting unit receives a first signal from another authentication device to initiate communication in the connection state, and transmits a second signal to the other authentication device requesting the termination of the connection state.

8. Authentication device, A mobile terminal and a communication unit on the authentication device side that communicates while a wireless connection has been established, The system includes an authentication unit that authenticates whether the mobile terminal is a pre-registered mobile terminal in the aforementioned connection state, Authentication device wherein the authentication unit transmits a first signal to the mobile terminal to initiate the connection state, and then, during communication in the connection state, receives a signal from the mobile terminal requesting the termination of the connection state, terminates the connection state with the mobile terminal.

Citation Information

Patent Citations

  • Authentication system and authentication method

    JP2022076704A