Lock management system and read / write device

The lock management system with a switching device and RFID tags enforces time-limited access by managing lock states based on planned use information, addressing the lack of time restrictions in existing RFID systems.

JP7765197B2Active Publication Date: 2025-11-06CANON KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021081836
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-13
Publication Date
2025-11-06
Estimated Expiration
2041-05-13

AI Technical Summary

Technical Problem

Existing RFID-based systems do not impose time restrictions on the use of managed objects, allowing unrestricted access once permission is granted, which is unsuitable for applications requiring time-limited usage.

Method used

A lock management system utilizing a switching device, a first RFID tag with rewritable storage, a writing device, and a reading device to manage lock states based on planned use information stored in a database, enabling time-limited access without complex user operations.

Benefits of technology

Enables time-limited use of objects without requiring users to perform complicated operations, enhancing security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007765197000001
    Figure 0007765197000001
  • Figure 0007765197000002
    Figure 0007765197000002
  • Figure 0007765197000003
    Figure 0007765197000003
Patent Text Reader

Abstract

To make it possible to impose a time limit on use of an object without requiring a complicated operation from a user.SOLUTION: A lock management system comprises: a switching apparatus that is capable of switching a state of a lock target between a locked state and an unlocked state; a writing apparatus that writes authentication information to a first storage area of a first RFID tag based on usage plan information related to the lock target; and a reading apparatus that is connected to the switching apparatus, reads the authentication information returned from the first RFID tag using energy of radiated electromagnetic waves, and causes the switching apparatus to switch the state of the lock target if authentication based on the read authentication information is successful.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to lock management systems and read-write devices. [Background technology]

[0002] RFID (Radio Frequency Identification) is a technology that enables information embedded in small devices, also known as tags, to be read by an external reader via short-range wireless communication. Passive RFID tags, which transmit information using the energy of electromagnetic waves emitted from a reader, are widely used in a variety of situations because they do not require batteries, are inexpensive to manufacture, and can operate semi-permanently.

[0003] For example, Patent Document 1 discloses a system in which an individual's ID is stored in an RFID tag embedded in a name tag worn by a user, and whether or not to permit activation of a terminal device function is determined based on the ID read from the RFID tag by a reader on the terminal device. Patent Document 2 discloses the use of an RFID tag as a medium for storing authentication data in an access control system that unlocks an electric lock if authentication is successful. Patent Document 2 also discloses that in the access control system, the cost required for history management is reduced by analyzing the number of electric lock operation histories.

[0004] As with the technologies disclosed in Patent Documents 1 and 2, authentication information for determining whether to allow a function to be activated or an electric lock to be unlocked is read from an RFID tag embedded in an item carried by the user, eliminating the need for the user to perform complicated operations during authentication. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Publication No. 9-245138 [Patent Document 2] Japanese Patent Application Laid-Open No. 2011-221907 Summary of the Invention [Problem to be solved by the invention]

[0006] However, in the system disclosed in Patent Document 1, which functions are permitted to be activated are defined for each individual ID, so a user who has been granted permission to use a certain function can use that function at any time. In the system disclosed in Patent Document 2, a user who carries a medium storing valid authentication data for a certain room is also permitted to enter that room at any time. Therefore, neither system is suitable for applications that impose time restrictions on the use of managed objects.

[0007] In view of the above, the present invention aims to realize a mechanism that can impose a time limit on the use of an object without requiring the user to perform complicated operations. [Means for solving the problem]

[0008] According to one aspect, the present invention includes a switching device capable of switching the state of a lock target between a locked state and an unlocked state, a first RFID tag having a rewritable first storage area, a writing device capable of writing information to an RFID tag, the writing device writing authentication information to the first storage area of ​​the first RFID tag based on planned use information related to the lock target, and a reading device connected to the switching device and capable of reading information from an RFID tag, the reading device reading the authentication information returned from the first RFID tag using electromagnetic wave energy emitted by the reading device, and causing the switching device to switch the state of the lock target when authentication based on the read authentication information is successful. the planned use information is registered in a database in association with tag identification information that identifies an RFID tag carried or attached by a user who uses the lock target, the first RFID tag further has a second storage area that stores first tag identification information that identifies the first RFID tag, the writing device is capable of reading information from an RFID tag, the writing device reads the first tag identification information from the second storage area of ​​the first RFID tag, obtains the planned use information associated with the read first tag identification information from the database, and writes the authentication information to the first storage area of ​​the first RFID tag based on the obtained planned use information. A lock management system is provided, and a corresponding read / write device is also provided.

[0009] From another perspective, a first RFID (Radio Frequency IDentification) tag having a rewritable first storage area; a writing device capable of writing information to an RFID tag, the writing device writing authentication information to the first storage area of ​​the first RFID tag based on planned use information related to the lock target; and a reading device connected to the switching device and capable of reading information from an RFID tag, the reading device reading the authentication information returned from the first RFID tag by utilizing electromagnetic wave energy emitted by the reading device, and causing the switching device to switch the state of the lock target when authentication based on the read authentication information is successful; wherein the planned use information is registered in a database in association with user identification information that identifies a user who will use the lock target, and the writing device obtains, from the database, the planned use information associated with first user identification information of a first user who has accessed the writing device, and writes the authentication information to the first storage area of ​​the first RFID tag based on the obtained planned use information. is provided. [Effects of the Invention]

[0010] According to the present invention, it is possible to impose a time limit on the use of an object without requiring the user to perform complicated operations. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a schematic diagram showing an overview of a lock management system according to a first embodiment; [Figure 2] 2 is an enlarged schematic diagram showing a state in which a switching device and a tag reader are attached to a lock target in the lock management system of FIG. 1; [Figure 3] FIG. 2 is an explanatory diagram for explaining an example of a memory structure of an RFID tag. [Figure 4] FIG. 2 is a block diagram showing an example of the configuration of a reader / writer and a management server according to the first embodiment. [Figure 5] FIG. 5 is a block diagram showing an example of a detailed configuration of a reading / writing section of the reader / writer of FIG. 4. [Figure 6] FIG. 2 is a block diagram showing an example of the configuration of a tag reader and a switching device according to the first embodiment. [Figure 7] FIG. 4 is a sequence diagram showing an example of a workflow related to lock management in the first embodiment. [Figure 8] 10 is a flowchart showing a first example of the flow of a write process that can be executed by a reader / writer. [Figure 9] 10 is a flowchart showing a second example of the flow of a write process that can be executed by the reader / writer. [Figure 10] 10 is a flowchart showing a third example of the flow of a write process that can be executed by a reader / writer. [Figure 11] 10 is a flowchart showing a first example of the flow of an authentication information generation process that can be executed by a reader / writer. [Figure 12] 10 is a flowchart showing a second example of the flow of an authentication information generation process that can be executed by the reader / writer. [Figure 13] 10 is a flowchart showing a first example of the flow of authentication processing that can be executed by a tag reader. [Figure 14] 10 is a flowchart showing a second example of the flow of authentication processing that can be executed by a tag reader. [Figure 15] FIG. 10 is a schematic diagram showing an overview of a lock management system according to a second embodiment. [Figure 16] FIG. 10 is a block diagram showing an example of the configuration of a reader / writer and a management server according to the second embodiment. [Figure 17] FIG. 10 is a block diagram showing an example of the configuration of a tag reader and a switching device according to a second embodiment. [Figure 18] 10 is a flowchart showing an example of the flow of authentication processing that can be executed by a tag reader. [Figure 19] 10 is a flowchart showing an example of the flow of an information collection process that can be executed by a reader / writer. [Figure 20] FIG. 10 is a schematic diagram showing an overview of a lock management system according to a first modified example. [Figure 21] FIG. 10 is a schematic diagram showing an overview of a lock management system according to a second modification. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.

[0013] 1. First Embodiment <1-1. System Overview> 1 is a schematic diagram showing an overview of a lock management system 1 according to a first embodiment. The lock management system 1 is a system that manages the status of one or more lock targets existing in real space through authentication based on information written to an RFID tag.

[0014] In this specification, a lock target refers to an object used by a user, whose use is subject to time restrictions. In this specification, the state of a lock target that has restrictions on its use is referred to as a "locked state," and the state of a lock target that has no restrictions is referred to as an "unlocked state." Furthermore, imposing restrictions on the use of a lock target is referred to as "locking," and removing those restrictions is referred to as "unlocking."

[0015] As an example, the object to be locked may be an item or a space, and an electronic lock that can switch the state of the object to be locked between a locked state and an unlocked state may be used. The electronic lock may be attached to, for example, the item itself, a storage unit that stores the item, or a gate or door provided on an access route to the item or space. In this case, locking the object to be locked may include locking the electronic lock to restrict use of the object to be locked, and unlocking the object to be locked may include unlocking the electronic lock to enable use of the object to be locked.

[0016] As another example, the lock target may be a function specific to a certain device, and the device itself may be able to switch the state of the lock target between a locked state and an unlocked state using software or hardware functions. In this case, locking the lock target may include the device inhibiting operation of the function, and unlocking the lock target may include the device releasing the inhibition and enabling operation of the function.

[0017] In the example of FIG. 1 , the locking target 10 is an aerial work platform, which is a type of industrial or construction machine. Generally, industrial or construction machines have unique functions specialized for their purpose. For example, the functions of an aerial work platform include the function of raising and lowering a work platform carrying a worker and the function of self-propelling. If such equipment (including not only machines but also simpler tools) is used at times not anticipated in the work plan, there is a risk of management or safety issues arising. For this reason, an operation method is often adopted in which the use of equipment is normally restricted and its use is allowed by specific users at times or for periods permitted according to the plan.

[0018] According to conventional methods, a physical lock such as a cylinder lock is installed in a storage facility where a device is stored or on an operation panel for operating the device. The keys used to lock and unlock the lock are then centrally managed at a location such as a management station. Authorized users borrow keys from the management station to use the device. However, this method not only imposes the user with the cumbersome task of locking and unlocking the device using a key, but also entails many inconveniences, such as the cost of taking measures against loss or theft of the physical key and the heavy burden on human resources involved in management.

[0019] In this embodiment, in order to eliminate or at least reduce the above-mentioned inconveniences, a tag reader 300 connected to the switching device 50 is introduced together with the switching device 50. The switching device 50 and the tag reader 300 are attached to the lock target 10. Fig. 2 shows an enlarged view of the switching device 50 and the tag reader 300 attached to the lock target 10.

[0020] Referring to FIG. 2, an operation panel 11 is provided on the vehicle body of the lock target 10, and the operation panel 11 has a keyhole 12. Inserting a key into the keyhole 12 and turning the key clockwise enables the lifting and self-propelling functions of the lock target 10 (the lock target 10 is in an unlocked state), and turning the key counterclockwise prevents these functions from operating (the lock target 10 is in a locked state). In the example of FIG. 2, a switching device 50 is attached to cover the keyhole 12. The switching device 50 is an electronic lock. The switching device 50 has an actuator that can rotate a physical key (not shown) inserted into the keyhole 12. The tag reader 300 is connected to the switching device 50 via a connection line 301. The tag reader 300 may have a button 302 and a light 303. The switching device 50 locks or unlocks the lock target 10 by operating the actuator and turning the key in accordance with a command received from the tag reader 300 via the connection line 301. More specific configuration examples of the switching device 50 and the tag reader 300 will be described later. Note that the connection between the switching device 50 and the tag reader 300 may be a wired connection via the connection line 301 as in the example of FIG. 2, or a wireless connection.

[0021] Returning to FIG. 1, the lock management system 1 includes a reader / writer 100 and a management server 200 in addition to the switching device 50 and the tag reader 300.

[0022] The reader / writer 100 is a reading / writing device that can write information to an RFID tag 25 carried or worn by a user 20, and can read information from the RFID tag 25. In the example of FIG. 1, a user 20a carries a helmet equipped with an RFID tag 25a, and a user 20b carries a helmet equipped with an RFID tag 25b. In this specification, when it is not necessary to distinguish between the users 20a, 20b, ..., the alphabet at the end of the reference numeral will be omitted and they will be collectively referred to as the user 20. The same applies to the RFID tags 25a, 25b, ... (RFID tags 25) and other components.

[0023] The reader / writer 100 is connected to the management server 200 via a network 5. The network 5 may be a wired network, a wireless network, or any combination thereof. Examples of the network 5 may include the Internet, an intranet, and a cloud network. As will be described in detail later, the reader / writer 100 acquires planned use information related to the lock target 10 from the management server 200, and writes authentication information to a rewritable storage area of ​​the RFID tag 25 based on the acquired planned use information (arrow W1 in the figure).

[0024] The RFID tag 25 is a type of wireless device, specifically a passive RFID tag (passive tag). A passive tag consists of a small integrated circuit (IC) chip with built-in memory and an antenna, and stores identification information and other information for identifying the tag in the memory. In this specification, the identification information is also referred to as an ID, and the identification information for identifying the tag is also referred to as a tag ID. The IC chip of a passive tag operates using the energy of electromagnetic waves emitted from a reader or writer. When a read command is modulated into the emitted electromagnetic waves, the IC chip modulates the information stored in the memory into an information signal and transmits (returns) the information signal from the antenna. When a write command is modulated into the emitted electromagnetic waves, the IC chip demodulates the information received following the write command, writes it into the memory, and transmits (returns) a response indicating the success or failure of the operation from the antenna.

[0025] The RFID tag 25 has a memory structure that complies with the standard EPC GEN2 (EPC Class 1 Generation 2) established by EPC Global, a subsidiary of GS1. Figure 3 shows a schematic diagram of the memory structure defined by EPC GEN2. The illustrated memory structure consists of the following four storage areas: Reserved area of ​​memory bank '00' (RESERVED) EPC area of ​​memory bank '01' (EPC) Chip information area (TID) of memory bank '10' User area (USER) of memory bank '11'

[0026] Control data for controlling memory access is written in advance to the reserved area, and external reading and writing of data is disabled (R='No', W='No'). A tag ID for uniquely identifying each RFID tag is written to the EPC area. The tag ID may be in a format that combines, for example, the GSI company code with an item code and serial number defined by each company, to enable unique identification of each RFID. Data in the EPC area can be both read and written (R='Yes', W='Yes'). Chip manufacturers can also allow data to be written to the EPC area only once. The model number, serial number, and chip setting information determined by the chip manufacturer are written to the chip information area. Data in the chip information area can be read but not written (R='Yes', W='No'). Information freely determined by each company introducing RFID tags into their system is written to the user area. Both reading and writing of data in the user area is possible (R='Yes', W='Yes'). In the lock management system 1, the reader / writer 100 can write authentication information to the user area of ​​the RFID tag 25, for example.

[0027] The management server 200 is an information processing device that uses a database to manage usage schedule information indicating when and which users plan to use a lock target. The management server 200 may be implemented, for example, as an application server, database server, or cloud server using a high-performance general-purpose computer. While FIG. 1 shows only one lock target 10, the management server 200 may manage usage schedule information for more lock targets. Furthermore, while FIG. 1 shows only two users 20a and 20b, the number of users who may potentially use each lock target is not limited to this example and may be any number. A more specific example of the configuration of the management server 200 will be described later.

[0028] In the example of Fig. 1, the management server 200 is a cloud server deployed in a cloud environment. Although Fig. 1 shows a single management server 200, the functions of the management server 200 may be provided by a single device, or may be provided by multiple physically separate devices working together. In addition, in this embodiment, an example is described in which the management server 200 holds a database that stores usage schedule information, but a device separate from the management server 200 may hold part or all of the database. For example, part of the data may be held by the reader / writer 100.

[0029] The tag reader 300 is a reading device capable of reading information from the RFID tag 25. The tag reader 300 reads from the RFID tag 25 the authentication information written to the RFID tag 25 by the reader / writer 100 (arrow R2 in the figure). The tag reader 300 then attempts authentication based on the read authentication information, and if the authentication is successful, causes the switching device 50 to switch the state of the lock target 10. For example, assume that a user 20a approaches the tag reader 300 wearing a helmet equipped with an RFID tag 25a in which valid authentication information is written, in order to use the lock target 10. Then, the tag reader 30 0 reads the authentication information from the RFID tag 25a, attempts authentication, and if the authentication is successful, sends an unlock command to the switching device 50. In response to the unlock command received from the tag reader 300, the switching device 50 rotates the key of the locked lock target 10 to unlock the locked lock target 10. As a result, the user 20a becomes able to use the functions of the locked lock target 10.

[0030] In the example of FIG. 1 , the lock target 10 is stored at a site 15. The site 15 is, for example, a construction site. If the site 15 is located in a place where radio waves from a base station cannot reach, such as underground, in a tunnel, indoors, or offshore, the switching device 50 and tag reader 300 attached to the lock target 10 cannot communicate with an external authentication server. However, according to this embodiment, the tag reader 300 performs authentication based only on local communication with the RFID tag 25, so authentication can be performed regardless of the location of the site 15.

[0031] Although not shown in Fig. 1, each of the users 20 may have a user terminal such as a PC (Personal Computer), a smartphone, or a mobile phone. The user terminal includes, for example, an input device, a processor, a memory, an output device, and a communication interface, and is used to input and transmit planned use information to be registered in the database.

[0032] <1-2. Configuration examples of each device> Next, more specific examples of the configuration of the devices that make up the lock management system 1 will be described in order using FIGS.

[0033] (1) Reader / Writer 4 is a block diagram showing an example of the configuration of the reader / writer 100 and management server 200 according to this embodiment. Referring to FIG. 4, the reader / writer 100 includes a read / write unit 110, a connection interface (I / F) 130, a communication I / F 140, a storage unit 150, a user I / F 160, a control unit 170, and a generation unit 180.

[0034] The read / write unit 110 performs communication for reading information from the RFID tag 25 and writing information to the RFID tag 25. Fig. 5 shows an example of a detailed configuration of the read / write unit 110. Referring to Fig. 5, the read / write unit 110 includes a controller 111, a memory 112, a modulation / demodulation unit 120, a power amplifier 121, a filter 122, a first coupler 123, a second coupler 124, an antenna 125, a power detection unit 126, and a canceller 127.

[0035] The controller 111 controls the communication function of the reader / writer 110. For example, the controller 111 periodically radiates electromagnetic waves from the antenna 125 within the tag reading range of the reader / writer 110, and attempts to read information from the RFID tag 25. When the controller 111 detects a received signal from the RFID tag 25, it outputs the information read from the RFID tag 25 to the control unit 170 via the connection I / F 130. Furthermore, in response to an instruction from the control unit 170, the controller 111 causes the antenna 125 to transmit a transmission signal modulated with information to be written to the RFID tag 25. The memory 112 is, for example, a semiconductor memory such as a ROM or a RAM, and temporarily stores the information read from the RFID tag 25 and the information to be written to the RFID tag 25.

[0036] The modem unit 120 outputs a transmission signal (for example, a signal modulated in the UHF band) from the TX terminal to the power amplifier 121 under the control of the controller 111. The power amplifier 121 amplifies the transmission signal input from the modem unit 120 and outputs it to the filter 122. The filter 122 may be, for example, a low-pass filter, and is used to remove unwanted components from the transmission signal after amplification by the power amplifier 121. frequencyThe first coupler 123 distributes the transmission signal that has passed through the filter 122 to the coupler 124 and the power detection unit 126. The second coupler 124 outputs the transmission signal input from the first coupler 123 to the antenna 125, and outputs the reception signal input from the antenna 125 to the modem unit 120. The antenna 125 transmits the transmission signal input from the coupler 124 into the air as an electromagnetic wave. The antenna 125 also receives a signal returned from an RFID tag 25 present within the read range of the read / write unit 110 in response to the transmission signal, and outputs the reception signal to the coupler 124. The power detection unit 126 detects the power level of the signal input from the first coupler 123, and outputs a signal RF_DETECT indicating the detected power level to the controller 111. The canceller 127 receives a signal CARRIER_CANCEL indicating the power level of the carrier wave from the controller 111. Then, based on CARRIER_CANCEL, the canceller 127 cancels the carrier component of the signal received from the antenna 125 using the second coupler 124, thereby extracting the desired signal component of the received signal to be output to the RX terminal of the modem unit 120. The modem unit 120 demodulates the signal input from the RX terminal, acquires information returned from the RFID tag, and outputs the acquired information to the controller 111.

[0037] The connection I / F 130 is an interface for connecting the read / write unit 110 to the control unit 170. The connection I / F 130 may be, for example, a wired interface such as a USB (Universal Serial Bus) interface, or a wireless interface such as a Bluetooth (registered trademark) interface. The connection I / F 130 may include a power supply line for supplying power to the read / write unit 110.

[0038] The communication I / F 140 is an interface for the reader / writer 100 to communicate with the management server 200 and other devices. For example, the communication I / F 140 may be a WLAN (Wireless Local Area Network) interface for communicating with a WLAN access point, or a cellular communication interface for communicating with a cellular base station.

[0039] The storage unit 150 stores one or more computer programs executed by the control unit 170, and various information such as usage schedule information (described later). The storage unit 150 may include any type of storage medium, for example, a semiconductor memory such as a ROM or RAM, an optical disk, or a magnetic disk.

[0040] The user I / F 160 is an interface through which the reader / writer 100 accepts information input from a user and presents information to the user. The user I / F 160 may include an input device that may include, for example, one or more of a touch panel, a keypad, a keyboard, and a microphone, and an output device that may include one or more of a display, an LED, and a speaker.

[0041] The control unit 170 controls the overall functions of the reader / writer 100 described herein. For example, the control unit 170 causes the read / write unit 110 to read tag IDs from RFID tags detected within the tag reading range of the reader / writer 100. The tag IDs are typically read from the EPC area of ​​the memory structure described with reference to FIG. 3 . However, the control unit 170 may also supplementarily or alternatively use information read from the chip information area or the user area to identify each RFID tag. If the read tag ID is the ID of an RFID tag 25 under the management of the lock management system 1, the control unit 170 queries the management server 200 via the communication interface 140 whether there is usage schedule information related to the detected RFID tag 25.

[0042] As an example, assume that user 20a plans to use lock target 10 during a specific time period on a certain day. Planned use information indicating this planned use is registered in the database of management server 200. When user 20a stops by reader / writer 100 before starting use, reader / writer 100 detects RFID tag 25a and transmits a query to management server 200. In response to the query, management server 200 transmits related planned use information back to reader / writer 100. Control unit 170 receives this planned use information via communication interface 140 and causes generation unit 180 to generate authentication information to be written to RFID tag 25a. Then, under the control of control unit 170, reading / writing unit 110 writes the authentication information generated by generation unit 180 to a rewritable storage area (e.g., a user area) of RFID tag 25a.

[0043] In a first example of this embodiment, the planned use information is associated with tag identification information (tag ID) that identifies the RFID tag 25 carried or attached by a user who uses the lock target 10, and is registered in the database of the management server 200. The control unit 170 includes the tag ID read from the RFID tag 25 in a query for planned use information and sends the query to the management server 200. The management server 200 acquires, from the database, the planned use information associated with the tag ID received from the reader / writer 100, and returns the acquired planned use information to the reader / writer 100. The control unit 170 causes the generation unit 180 to generate authentication information to be written to the RFID tag 25 based on the planned use information acquired from the database in this manner. According to the first example, each user 20 can easily obtain the authentication information required to use the lock target 10 during the scheduled period by simply bringing the RFID tag 25 carried or attached by the user 20 close to the reader / writer 100 during work.

[0044] In a second example of this embodiment, the planned use information is associated with identification information identifying a user who uses the lock target 10 and registered in the database of the management server 200. For example, each user 20 holds an IC card (e.g., an employee ID card) equipped with an additional RFID tag storing a user ID that identifies the user. This additional RFID tag is not shown in FIG. 1 . The control unit 170 causes the reading / writing unit 110 to read the user ID from the RFID tag of the IC card held by the user. The control unit 170 includes the read user ID in a query for planned use information and sends the query to the management server 200. The management server 200 obtains, from the database, planned use information associated with the user ID received from the reader / writer 100 and returns the obtained planned use information to the reader / writer 100. The control unit 170 causes the generation unit 180 to generate authentication information to be written to the RFID tag 25 based on the planned use information thus obtained from the database. According to the second embodiment, each user 20 can obtain the authentication information required to use the locked object 10 for the scheduled period of time simply by bringing the RFID tag 25 that he or she carries or wears while working and an additional RFID tag for user identification close to the reader / writer 100.

[0045] In a third example of this embodiment, the planned use information is associated with a user ID that identifies a user who uses the lock target 10 and registered in a database of the management server 200. The control unit 170 displays an input screen (e.g., a login screen for logging in to the system) on the display for inputting a user ID and accepts the user ID (and, if necessary, a login password) entered by the user 20 on the screen. The control unit 170 then includes the accepted user ID in a query for planned use information and transmits the query to the management server 200. The management server 200 acquires, from a database, planned use information associated with the user ID received from the reader / writer 100 and returns the acquired planned use information to the reader / writer 100. The control unit 170 causes the generation unit 180 to generate authentication information to be written to the RFID tag 25 based on the planned use information acquired from the database in this manner. According to the method of accepting user identification information (user ID) via a user interface as in the third example, authentication information can be provided to a legitimate user based on a general access management mechanism without requiring an additional RFID tag.

[0046] In any embodiment, the usage schedule information provided from the management server 200 to the reader / writer 100 may include, for example, an ID associated with the lock target to be used (e.g., a target ID or reader ID, described below), and usage period information related to the corresponding period. The period here is predefined in the form of a division on a time axis, such as morning or afternoon on each date, or a time slot having a duration of one to several hours. The usage period information identifies the period during which the lock target will be used by a reference time (e.g., a start time) or other identifier.

[0047] The generation unit 180 generates authentication information to be written to the user area of ​​the RFID tag 25 based on authentication basis information specific to the lock target identified by the usage schedule information and the usage period information. The authentication basis information is information that serves as the basis for generating the authentication information. The authentication basis information may be different for each of one or more lock targets.

[0048] In a first example of a method for generating authentication information, the authentication base information may be a target ID for use that identifies the lock target to be used. In this case, the generator 180 generates authentication information by encoding a bit string based on the target ID and usage period information according to a predetermined encoding method. The predetermined encoding method may be, for example, a method that outputs an authentication code corresponding to an input of an arbitrary bit string (message), such as a hash-based message authentication code (HMAC) method. Generally, the length of such an authentication code is a fixed length that is shorter than the original bit string. Therefore, by writing this to the RFID tag 25 as authentication information, the limited storage area of ​​the RFID tag 25 can be efficiently utilized. The authentication code here may be referred to as a one-time password. The storage unit 150 may previously store a symmetric key (common key) used by the generator 180 for encoding. For example, by previously storing a symmetric key common to the entire system in the storage unit 150, exchange of key information between the reader / writer 100 and the management server 200 is unnecessary. Alternatively, the symmetric key used by generation unit 180 may be received together with the planned use information from management server 200. Tag readers 300 pre-store (share) the same symmetric key for authentication purposes, as will be described later.

[0049] As a variation of the first example, the authentication base information may be a different symmetric key for each lock target. In this case, the generating unit 180 can generate authentication information specific to the lock target to be used without including the usage target ID in the input bit string to the encoding process. That is, the generating unit 180 generates authentication information by encoding a bit string based on the usage period information with a symmetric key specific to the lock target to be used.

[0050] In a second example of the method for generating authentication information, the authentication basis information may be a different encryption key for each lock target. The encryption key here may be a symmetric key or an asymmetric key different from that used for decryption. In the second example, the generation unit 180 generates a different encryption key for each lock target. elephantThe authentication information is generated by encrypting the usage period information with an encryption key (first encryption key) unique to the tag reader 300. In this case, the authentication information is encrypted usage period information. The storage unit 150 may store the first encryption key in advance. Alternatively, the first encryption key may be received from the management server 200 along with the usage schedule information. As will be described later, the tag reader 300 stores in advance a second encryption key (which is the same as the first encryption key when a symmetric key is used) corresponding to the first encryption key to restore the usage period information for authentication purposes. In the first example described above, the usage period information is irreversibly converted into an authentication code, whereas in the second example, the usage period information is reversibly converted and written to the RFID tag 25. Therefore, the (restored) usage period information after the reverse conversion on the tag reader 300 side has logically interpretable content. Therefore, in the second example, it is possible to provide flexibility in information transmission from the reader / writer 100 to the tag reader 300 (for example, by incorporating additional information according to system requirements or user needs).

[0051] The read / write unit 110, under the control of the control unit 170, writes the authentication information generated by the generation unit 180 according to any of the methods described above into the RFID tag 25.

[0052] (2) Management Server Referring to FIG. 4, the management server 200 includes a communication I / F 210, a lock management unit 220, and a management database (DB) 230.

[0053] The communication I / F 210 is a communication interface that enables the management server 200 to communicate with other devices. The communication I / F 210 may be a wired communication interface or a wireless communication interface. In this embodiment, the communication I / F 210 communicates with the reader / writer 100 and a user terminal (not shown).

[0054] The lock management unit 220 is a software module that provides a management function for managing one or more lock targets 10 under the management of the lock management system 1. The software module can be operated by one or more processors (not shown) of the management server 200 executing a computer program stored in a memory (not shown).

[0055] In this embodiment, the lock management unit 220 accepts input of planned use information (use reservation) for the lock target 10 from the user terminal via the communication I / F 210. For example, the lock management unit 220 may display an input acceptance screen on the display of the user terminal and have the user or administrator select a user ID, the lock target to be used, and the usage period on the input acceptance screen. The lock management unit 220 then registers the input planned use information in the management DB 230.

[0056] The lock management unit 220 also receives an inquiry about planned use information from the reader / writer 100 via the communication I / F 210. In the first embodiment described above, the lock management unit 220 extracts planned use information associated with the tag ID included in the received inquiry from the management DB 230. Then, the lock management unit 220 returns the extracted planned use information to the reader / writer 100. In the second or third embodiment described above, the lock management unit 220 extracts planned use information associated with the user ID (user ID of the user who accessed the reader / writer 100) included in the received inquiry from the management DB 230. Then, the lock management unit 220 returns the extracted planned use information to the reader / writer 100.

[0057] The management DB 230 is made up of a group of tables for holding usage schedule information for one or more lock targets under the management of the lock management system 1. In this embodiment, the management DB 230 includes a tag table 240, a user table 250, a lock target table 260, and a usage schedule table 270.

[0058] The tag table 240 is a table that holds information about RFID tags under the management of the lock management system 1. The tag table 240 may include, for example, one or more of the following information items: Tag ID "Tag type" The "tag ID" is identification information for uniquely identifying each RFID tag. As described above, each tag ID is determined in a standard format that is a concatenation of a company code, an item code, and a serial number, and can be written in advance in the EPC area of ​​each RFID tag and registered in the tag table 240. However, a tag ID in a unique format instead of the standard format may be used. The "tag type" indicates the type of each RFID tag. For example, multiple different tag types can be defined, such as an "authentication tag" for the RFID tag 25 into which authentication information should be written, and a "user identification tag" for a further RFID tag that stores a user ID.

[0059] The user table 250 is a table that holds information about users who may use the lock target. The user table 250 may include, for example, one or more of the following information items: "User ID" ·"name" Related tag ID ·"authority" "User ID" is identification information for uniquely identifying each user. "Name" represents the name of each user (e.g., the user name displayed on the screen or recorded in the history information). "Associated tag ID" identifies the RFID tag associated with each user by the "tag ID" in the tag table 240. The RFID tag associated with each user may be, for example, an RFID tag carried or worn by each user (e.g., an RFID tag on a helmet owned by each user 20). "Authority" represents the authority given to each user regarding the use of a lock target. For example, if there are two or more lock targets under the management of the lock management system 1, each user may be given different authority for each lock target. The lock management unit 220 may refuse to register a planned use of a lock target by a user who is not authorized to use that lock target.

[0060] The lock target table 260 is a table that holds information about lock targets under the management of the lock management system 1. The lock target table 260 may include, for example, one or more of the following information items: "Target ID" ·"name" "Target type" "Reader ID" "Object ID" is identification information for uniquely identifying each lock object. "Name" indicates the name of each lock object (for example, the name displayed on the screen or recorded in the history information). "Object type" indicates the type of each lock object. For example, the "object type" of lock object 10 in Figure 1 could be "aerial work vehicle." "Reader ID" is identification information for identifying the tag reader attached to each lock object.

[0061] The usage schedule table 270 is a table that holds usage schedule information indicating which user is scheduled to use each lock target and when. The usage schedule table 270 may include, for example, one or more of the following information items: "Target ID" "User" "Usage Period" The "usage target ID" identifies the lock target to be used by the "target ID" in the lock target table 260. The "using user" identifies the user who plans to use the lock target identified by the "usage target ID" by the "user ID" or "associated tag ID" in the user table 250. The "usage period" identifies the period during which the user identified by the "usage user" will use the lock target identified by the "usage target ID". Each usage period may be identified by a reference time (e.g., start time) if the length of the period is constant, or by a pair of start and end times, or by an identifier assigned to each period in advance.

[0062] The table configuration of the management DB 230 described here is merely an example. The management DB 230 may be configured with more or fewer tables. Furthermore, each table may include more or fewer information items. For example, the lock target table 260 may further include information about the switching device attached to each lock target (e.g., a device ID, name, and type for identifying each device). Furthermore, the management DB 230 may include an independent table for holding information about the switching device. To identify the lock target, a device ID for identifying the switching device or a reader ID for identifying the tag reader may be used instead of the above-mentioned target ID.

[0063] (3) Tag reader 6 is a block diagram showing an example of the configuration of tag reader 300 and switching device 50 according to this embodiment. Referring to Fig. 6, tag reader 300 includes a reading unit 310, a battery 320, an input detection unit 330, a storage unit 350, a control unit 370, a generation unit 380, and a lock I / F 390.

[0064] The reading unit 310 performs communication to read information from the RFID tag 25. The basic configuration of the reading unit 310 may be the same as the configuration of the reading / writing unit 110 of the reader / writer 100 described with reference to FIG. 5. In this embodiment, the reading unit 310 periodically emits electromagnetic waves within the tag reading range of the reading unit 310 and attempts to read information from the RFID tag 25. When the reading unit 310 detects a received signal from the RFID tag 25, it outputs the information read from the RFID tag 25 (for example, tag ID and authentication information) to the control unit 370.

[0065] Battery 320 is a secondary battery that supplies power to each component of tag reader 300. Battery 320 may be, for example, a lithium-ion battery. Although not shown, tag reader 300 may have a connection terminal for connecting tag reader 300 to an external power source in order to charge battery 320. Battery 320 may be removable from tag reader 300 so that it can be replaced with a spare battery.

[0066] The input detection unit 330 is a circuit that detects user input to the tag reader 300. The input detection unit 330 may detect, as user input, some kind of physical operation, such as pressing the button 302 shown in Fig. 2. The input detection unit 330 may also detect, as user input, a voice uttered by the user.

[0067] The storage unit 350 stores one or more computer programs executed by the control unit 370 and various information. The storage unit 350 may include any type of storage medium, such as a semiconductor memory such as a ROM or RAM, an optical disk, or a magnetic disk. In this embodiment, the storage unit 350 stores in advance authentication basic information unique to the lock target 10.

[0068] The control unit 370 controls the overall functions of the tag reader 300 described herein. For example, when the reading unit 310 reads authentication information from the RFID tag 25, the control unit 370 attempts authentication based on the read authentication information. More specifically, when performing authentication, the control unit 370 first obtains the current time and determines period information related to the current time. For example, the period information here may represent the period to which the current time belongs, among periods defined at the same granularity as the time units used to register the aforementioned usage schedule, using a reference time or other identifier for the period. The control unit 370 then attempts authentication based on the determined period information and the authentication information read from the RFID tag 25.

[0069] In a first example of an authentication method based on authentication information, the storage unit 350 pre-stores, as authentication basic information, identification information (here, assumed to be a target ID) unique to the lock target 10. The storage unit 350 also pre-stores a symmetric key (common key) for encoding according to a predetermined encoding method. The symmetric key may be common to the entire system. As a variation of the first example, the symmetric key may be different for each lock target. The predetermined encoding method may be a method that outputs an authentication code corresponding to an input of an arbitrary bit string, such as an HMAC method. The generation unit 380 generates verification authentication information (an authentication code or a one-time password) by encoding, with the symmetric key, a bit string based on the target ID of the lock target 10 and period information determined by the control unit 370. The control unit 370 then determines that authentication is successful if the authentication information read from the RFID tag 25 matches the verification authentication information generated by the generation unit 380.

[0070] In a second example of the authentication method based on authentication information, the storage unit 350 pre-stores an encryption key (a second encryption key corresponding to the first encryption key used by the reader / writer 100) unique to the lock target 10 as authentication basic information. The generation unit 380 generates (restores) usage period information by decrypting the authentication information read from the RFID tag 25 with this second encryption key. The control unit 370 then determines that the authentication is successful if the usage period indicated by the restored usage period information properly corresponds to a period related to the current time. The proper correspondence between the two periods may include, for example, one or both of the following: the usage period matches the period related to the current time, and the usage period includes the period related to the current time.

[0071] When the control unit 370 determines that authentication has been successful according to any of the authentication methods described above, it transmits a switching command to the switching device 50 via the lock I / F 390 to switch the state of the lock target 10. The switching command transmitted here may be an unlock command to unlock the lock target 10. After the lock target 10 is unlocked, the control unit 370 may maintain the unlocked state of the lock target 10 until the scheduled usage period ends or until the RFID tag 25 is no longer detected for a predetermined length of time. When the period for maintaining the unlocked state ends, the control unit 370 transmits a lock command to the switching device 50 via the lock I / F 390 to lock the lock target 10.

[0072] Note that the control unit 370 may attempt authentication based on the authentication information read from the RFID tag 25 only when a predetermined user input is detected by the input detection unit 330, and may cause the switching device 50 to switch the state of the lock target 10 if the authentication is successful. The predetermined user input may be, for example, pressing the button 302. By configuring the reading of authentication information from the RFID tag 25 in response to a user input as a trigger, it is possible to reduce the frequency of electromagnetic wave radiation from the reading unit 310 and save power for the battery 320. It is also possible to prevent the state of the lock target 10 from being switched at a time when the user does not intend to switch the state of the lock target 10.

[0073] The lock I / F 390 is an interface that mediates control communication (wired communication or wireless communication) between the tag reader 300 and the switching device 50. The lock I / F 390 transmits a switching command (unlock command or lock command) input from the control unit 370 to the controller 57 of the switching device 50. The lock I / F 390 also receives a response indicating the result of executing the switching command from the controller 57 of the switching device 50, and outputs the received response to the control unit 370.

[0074] The control unit 370 may notify the user 20 of the result of authentication based on the authentication information read from the RFID tag 25 via some kind of notification device. The notification device may be the light 303 (e.g., an LED) shown in FIG. 2, or a display, speaker, or vibrator (not shown).

[0075] (4) Switching device Referring to FIG. 6, the switching device 50 includes an actuator 51 , a sensor 53 , a battery 55 and a controller 57 .

[0076] The actuator 51 is an element for physically moving the locking mechanism of the lock target 10. For example, if the lock target 10 is a machine with a cylinder lock, the actuator 51 may be a motor for rotating a key inserted into the cylinder lock. Note that if the locking mechanism of the lock target 10 is an electronic or digital mechanism that does not require physical movement, the switching device 50 does not need to include the actuator 51.

[0077] The sensor 53 is an element for detecting the state of the lock target 10. The sensor 53 detects, for example, whether the lock target 10 is in a locked state or an unlocked state, and outputs a sensor signal indicating the detected state to the controller 57.

[0078] The battery 55 is a secondary battery that supplies power to each component of the switching device 50. The battery 55 may be, for example, a lithium-ion battery. However, without being limited to the above example, each of the tag reader 300 and the switching device 50 may be driven by power from a replaceable dry cell battery.

[0079] The controller 57 is a control circuit that controls the operation of the switching device 50. For example, when the controller 57 receives an unlock command from the tag reader 300 while the lock target 10 is in a locked state, the controller 57 drives the actuator 51 to unlock the lock target 10. For example, in the example shown in FIG. 2 , the key inserted in the keyhole 12 is turned clockwise by the rotation of the actuator 51, and the function of the lock target 10 that was previously inhibited is enabled. Furthermore, when the controller 57 receives a lock command from the tag reader 300 while the lock target 10 is in an unlocked state, the controller 57 drives the actuator 51 to lock the lock target 10. For example, in the example shown in FIG. 2 , the key inserted in the keyhole 12 is turned counterclockwise by the rotation of the actuator 51, and the function of the lock target 10 is inhibited. The controller 57 returns responses indicating the results of the execution of these switching commands to the tag reader 300.

[0080] 6 shows an example in which the switching device 50 and the tag reader 300 are separate devices connected to each other, a single device having the functions of both the switching device 50 and the tag reader 300 may be provided. Also, the switching device 50 may be incorporated as a part of the object to be locked 10, and the tag reader 300 may be connected to the object to be locked 10.

[0081] <1-3. Processing flow> In this section, examples of the flow of several processes that can be executed by the devices that make up the lock management system 1 in this embodiment will be explained using the sequence diagram in Fig. 7 and the flowcharts in Fig. 8 to Fig. 14. In the following explanation, processing steps will be abbreviated as S (step).

[0082] <1-3-1. Overall flow> Fig. 7 is a sequence diagram showing an example of the flow of work related to lock management in this embodiment. The sequence shown in Fig. 7 involves the reader / writer 100, the management server 200, the tag reader 300, the switching device 50, and the RFID tag 25 carried by the user 20.

[0083] First, in S11, the system administrator or user 20 inputs information related to the scheduled use of the lock target 10 into an input reception screen provided by the management server 200. The lock management unit 220 of the management server 200 registers the scheduled use information input on the screen in the scheduled use table 270 of the management DB 230.

[0084] Thereafter, when the time for the user 20 to use the lock target 10 approaches, the user 20 stops by the reader / writer 100 with a helmet equipped with the user's RFID tag 25. Then, in S21, the reading / writing unit 110 of the reader / writer 100 reads the tag ID of the RFID tag 25. Next, in S23, the control unit 170 queries the management server 200 for usage schedule information associated with the read tag ID (or the corresponding user ID). In S25, the lock management unit 220 of the management server 200 searches the usage schedule table 270 of the management DB 230 using the ID included in the query from the reader / writer 100, and extracts the usage schedule information from the usage schedule table 270. Next, in S27, the lock management unit 220 returns the usage schedule information extracted from the usage schedule table 270 to the reader / writer 100.

[0085] In S29, the generation unit 180 of the reader / writer 100 generates authentication information to be written to the RFID tag 25 based on the usage period information included in the usage schedule information received from the management server 200 and the authentication basic information of the lock target 10 to be used. Next, in S31, the reading / writing unit 110 writes the authentication information generated by the generation unit 180 to the RFID tag 25.

[0086] The user 20 visits the site 15 wearing the helmet equipped with the RFID tag 25 on which the authentication information is written in this manner, and enters the tag reading range of the tag reader 300 to use the locked object 10 .

[0087] In S33, the reading unit 310 of the tag reader 300 emits electromagnetic waves within the tag reading range and uses the energy of the emitted electromagnetic waves to read the authentication information returned from the RFID tag 25. Next, in S35, the control unit 370 of the tag reader 300 performs authentication based on the read authentication information. Here, it is assumed that the authentication is successful. In response to the success of the authentication, in S37, the control unit 370 transmits a switching command to the switching device 50 via the lock I / F 390 to switch the state of the lock target 10.

[0088] In response to receiving the switching command from tag reader 300, in S39, controller 57 of switching device 50 drives actuator 51 in accordance with the received switching command to switch the state of lock target 10. Then, in S41, controller 57 returns a response indicating the result of executing the switching command to tag reader 300.

[0089] <1-3-2. Write process (first embodiment)> Fig. 8 is a flowchart showing a first example of the flow of a write process that can be executed by the reader / writer 100 according to this embodiment. This write process is related to the flow from S21 to S31 in Fig. 7. The first example corresponds to the first example described above.

[0090] First, in S111, the reader / writer 110 reads the tag ID from the second storage area (for example, the EPC area) of the RFID tag 25. The reader / writer 110 outputs the read tag ID to the control unit 170.

[0091] Next, in S113, the control unit 170 includes the tag ID read by the reading / writing unit 110 in an inquiry about the usage schedule information, and transmits the inquiry to the management server 200 via the communication I / F 140.

[0092] Next, in S115, the control unit 170 receives a response to the transmitted query from the management server 200 via the communication I / F 140. If the management DB 230 does not contain an upcoming usage schedule related to the tag ID included in the query, the response received here may include information indicating that there is no usage schedule. If an upcoming usage schedule exists, the response received here includes usage schedule information related to at least one usage schedule.

[0093] In S117, the control unit 170 determines whether or not planned use information is included in the response received from the management server 200. If planned use information is not included, the subsequent steps S119 to S132 are skipped, and the writing process in Fig. 8 ends without writing authentication information to the RFID tag 25. If planned use information is included, the process proceeds to S119.

[0094] In S119, the control unit 170 acquires authentication basic information specific to the lock target 10 that is scheduled to be used. For example, the authentication basic information is received from the management server 200 together with the scheduled use information, or is stored in the storage unit 150 in advance.

[0095] Next, in S120, the control unit 170 and the generation unit 180 execute an authentication information generation process to generate authentication information. Some examples of more specific flows of the authentication information generation process executed here will be further described later.

[0096] Next, in S131, the reader / writer 110 writes the authentication information generated in S120 to the first storage area (for example, the user area) of the RFID tag 25 under the control of the controller 170. Then, the write process in FIG. 8 ends.

[0097] <1-3-3. Write process (second embodiment)> 9 is a flowchart showing a second example of the flow of the write process that can be executed by the reader / writer 100 according to this embodiment. This write process is related to the flow from S21 to S31 in FIG. 7. The second example corresponds to the second example described above.

[0098] First, in S111, the reader / writer 110 reads the tag ID from the RFID tag 25 (first RFID tag). The reader / writer 110 outputs the read tag ID to the control unit 170.

[0099] Next, in S112a, the reader / writer 110 reads the user ID from the further RFID tag (second RFID tag). The reader / writer 110 outputs the read user ID to the control unit 170.

[0100] Next, in S114, the control unit 170 includes the user ID read by the reading / writing unit 110 in an inquiry about the usage schedule information, and transmits the inquiry to the management server 200 via the communication I / F 140.

[0101] Next, in S116, the control unit 170 receives a response to the transmitted inquiry from the management server 200 via the communication I / F 140. If the management DB 230 does not contain an upcoming usage schedule related to the user ID included in the inquiry, the response received here may include information indicating that there is no usage schedule. If an upcoming usage schedule exists, the response received here includes usage schedule information related to at least one usage schedule.

[0102] In S117, the control unit 170 determines whether or not planned use information is included in the response received from the management server 200. If planned use information is not included, the subsequent steps S119 to S131 are skipped, and the writing process in Fig. 9 ends without writing authentication information to the first RFID tag. If planned use information is included, the process proceeds to S119.

[0103] In S119, the control unit 170 acquires authentication basic information specific to the lock target 10 that is scheduled to be used. For example, the authentication basic information is received from the management server 200 together with the scheduled use information, or is stored in the storage unit 150 in advance.

[0104] Next, in S120, the control unit 170 and the generation unit 180 execute an authentication information generation process to generate authentication information.

[0105] Next, in S131, the reader / writer 110 writes the authentication information generated in S120 to the first RFID tag under the control of the controller 170. Then, the write process in FIG.

[0106] <1-3-4. Write process (third embodiment)> 10 is a flowchart showing a third example of the flow of the write process that can be executed by the reader / writer 100 according to this embodiment. This write process is related to the flow from S21 to S31 in FIG. 7. The third example corresponds to the third example described above.

[0107] First, in S111, the reader / writer 110 reads the tag ID from the RFID tag 25. The reader / writer 110 outputs the read tag ID to the control unit 170.

[0108] Next, in S112b, the control unit 170 accepts the user ID and other information input by the user 20 on, for example, a login screen displayed on the display.

[0109] Next, in S114, the control unit 170 includes the user ID received in S112b in an inquiry about the usage schedule information, and transmits the inquiry to the management server 200 via the communication I / F 140.

[0110] Next, in S116, the control unit 170 receives a response to the transmitted inquiry from the management server 200 via the communication I / F 140. If the management DB 230 does not contain an upcoming usage schedule related to the user ID included in the inquiry, the response received here may include information indicating that there is no usage schedule. If an upcoming usage schedule exists, the response received here includes usage schedule information related to at least one usage schedule.

[0111] In S117, the control unit 170 determines whether or not planned use information is included in the response received from the management server 200. If planned use information is not included, the subsequent steps S119 to S131 are skipped, and the writing process in Fig. 10 ends without writing authentication information to the RFID tag 25. If planned use information is included, the process proceeds to S119.

[0112] The processing flow from S119 to S131 may be the same as that described with reference to FIG. When the authentication information is written to the RFID tag 25 by the reader / writer 110 in S131, the write process of FIG. 10 ends.

[0113] <1-3-5. Authentication information generation process (first example)> FIG. 11 is a flowchart showing a first example of the flow of an authentication information generation process that can be executed by the reader / writer 100 according to this embodiment.

[0114] First, in S121, the control unit 170 identifies the usage period indicated by the usage schedule information received from the management server 200.

[0115] Next, in S122, the generating unit 180 generates a bit string to be input to the encoding algorithm based on the authentication basic information (for example, a usage target ID) and usage period information.

[0116] Next, in S123, the generation unit 180 generates authentication information by encoding the bit string generated in S122 according to a predetermined encoding method using a symmetric key that is common to the entire system or specific to the lock target that is used.

[0117] <1-3-6. Authentication information generation process (second example)> FIG. 12 is a flowchart showing a second example of the flow of the authentication information generation process that can be executed by the reader / writer 100 according to this embodiment.

[0118] First, in S126, the control unit 170 identifies the usage period indicated by the usage schedule information received from the management server 200.

[0119] Next, in S127, the generation unit 180 generates authentication information by encrypting the usage period information related to the identified usage period with authentication basic information (for example, a first encryption key unique to the lock target to be used).

[0120] <1-3-7. Authentication process (first example)> 13 is a flowchart showing a first example of the flow of authentication processing that can be executed by the tag reader 300 according to this embodiment. This authentication processing relates to the flow from S33 to S41 in FIG.

[0121] First, in S211, the input detection unit 330 continuously monitors user input. When the input detection unit 330 detects a predetermined user input (for example, pressing the button 302), the process proceeds to S213.

[0122] In S213, the reading unit 310 emits electromagnetic waves within the tag reading range and reads the tag ID and authentication information returned from the RFID tag 25. The authentication information read here is assumed to be information (e.g., authentication code) generated by the authentication information generation process described with reference to FIG.

[0123] Next, in S215, the control unit 370 acquires the current time by referring to an internal clock that keeps track of real time, and identifies the period associated with the acquired current time.

[0124] Next, in S217, the generation unit 380 reads out from the storage unit 350 the authentication basic information (for example, the usage target ID) and a symmetric key that is common to the entire system or unique to the lock target 10.

[0125] Next, in S219, the generation unit 380 generates verification authentication information by encoding time information related to the identified period (e.g., a reference time or a period identifier) ​​and a bit string based on the read authentication basic information with the read symmetric key.

[0126] Next, in S221, the control unit 370 determines whether the authentication information read from the RFID tag 25 in S213 matches the verification authentication information generated by the generation unit 380 in S219. If the two pieces of authentication information do not match, authentication has failed, and the subsequent step S223 is skipped, and the authentication process in Fig. 13 ends without unlocking (or locking) the lock target 10.

[0127] If the two pieces of authentication information match in S221, the control unit 370 determines in S223 that the authentication has been successful and instructs the switching device 50 to switch the state of the lock target 10 (for example, from the locked state to the unlocked state). When a response indicating that the state switching has been completed is received from the switching device 50, the authentication process in Fig. 13 ends.

[0128] <1-3-8. Authentication process (second example)> 14 is a flowchart showing a second example of the flow of authentication processing that can be executed by the tag reader 300 according to this embodiment. This authentication processing relates to the flow from S33 to S41 in FIG.

[0129] First, in S211, the input detection unit 330 continuously monitors user input. When the input detection unit 330 detects a predetermined user input, the process proceeds to S213.

[0130] In S213, the reading unit 310 emits electromagnetic waves within the tag reading range and reads the tag ID and authentication information returned from the RFID tag 25. The authentication information read here is assumed to be the information (encrypted usage period information) generated by the authentication information generation process described with reference to FIG.

[0131] Next, in S215, the control unit 370 acquires the current time by referring to an internal clock that keeps track of real time, and identifies the period associated with the acquired current time.

[0132] Next, in S218, the generation unit 380 reads out the second encryption key (authentication basic information) unique to the lock target 10 from the storage unit 350.

[0133] Next, in S220, the generation unit 380 decrypts the authentication information read from the RFID tag 25 with the second encryption key read in S218, thereby restoring the usage period information.

[0134] Next, in S222, the control unit 370 determines whether the usage period indicated by the usage period information restored by the generation unit 380 properly corresponds to the period identified in S215. If the two periods do not properly correspond to each other, authentication has failed, so the subsequent S223 is skipped, and the authentication process in Fig. 14 ends without unlocking (or locking) the lock target 10.

[0135] If the two periods correspond appropriately in S222, the control unit 370 determines in S223 that the authentication is successful and instructs the switching device 50 to switch the state of the lock target 10 (for example, from the locked state to the unlocked state). When a response indicating that the state switching has been completed is received from the switching device 50, the authentication process in Fig. 14 ends.

[0136] 12 and the authentication process of FIG. 14, examples have been described in which the usage period information is encrypted and decrypted using an encryption key. However, the usage period information may be written to the RFID tag without being encrypted. For example, in an environment where the threat of unauthorized writing of information to an RFID tag can be ignored, the usage period information may be written in plaintext to the RFID tag (together with the target ID, for example), and simple authentication may be performed by comparing it with a period related to the current time in the tag reader 300. This reduces the computational load on the reader / writer 100 and the tag reader 300, and reduces the complexity of implementation, thereby suppressing the cost required for system construction. Furthermore, the terms encryption and decryption may be replaced with conversion and inverse conversion, respectively.

[0137] 2. Second Embodiment In this section, as a second embodiment, an example will be described in which, in addition to the functions described above, a function for collecting information related to lock management is implemented in each device that constitutes the lock management system described in the previous section.

[0138] <2-1. System Overview> 15 is a schematic diagram showing an overview of a lock management system 2 according to a second embodiment. Similar to the lock management system 1, the lock management system 2 is a system that manages the status of one or more lock targets existing in real space through authentication based on information written to RFID tags. The lock management system 2 includes a switching device 60, a reader / writer 400, a management server 500, and a tag reader 600. The switching device 60 and the tag reader 600 are attached to the lock target 10, which is an aerial work vehicle, and may be movable together with the lock target 10.

[0139] The reader / writer 400 is a reading / writing device capable of writing information to an RFID tag 25 carried or worn by a user 20 and reading information from the RFID tag 25. The reader / writer 400 is connected to a management server 500 via a network 5. The management server 500 is an information processing device that uses a database to manage usage schedule information indicating when and which user plans to use a lock target. In this embodiment, the management server 500 manages, in addition to the usage schedule information, history information related to switching the state of the lock target and status information indicating the status of the device. The device here may include one or more of the lock target, the switching device, and the tag reader. This information can be viewed by a system administrator and used for purposes such as supporting system maintenance and operation, and supporting users in formulating work plans.

[0140] Tag reader 600 is a reading device capable of reading information from RFID tag 25. However, in this embodiment, tag reader 600 may also be capable of writing information to RFID tag 25. Tag reader 600 is connected to switching device 60. Switching device 60 is a device capable of switching the state of lock target 10 between a locked state and an unlocked state.

[0141] In this embodiment as well, the reader / writer 400 acquires planned use information related to the lock target 10 from the management server 500, and writes authentication information to a rewritable storage area of ​​the RFID tag 25 based on the acquired planned use information (arrow W1 in the figure). The tag reader 600 reads from the RFID tag 25 the authentication information written to the RFID tag 25 by the reader / writer 400 (arrow R2 in the figure). Then, if authentication based on the read authentication information is successful, the tag reader 600 causes the switching device 60 to switch the state of the lock target 10. For example, when the state of the lock target 10 switches from a locked state to an unlocked state, the user becomes able to use the functions of the lock target 10.

[0142] Furthermore, the tag reader 600 generates history information related to switching the status of the lock target 10. The tag reader 600 also detects the status of one or more of the lock target 10, the switching device 60, and the tag reader 600, and generates status information indicating the detected status. The tag reader 600 writes the generated history information and status information to a rewritable storage area of ​​the RFID tag 25 (arrow W3 in the figure). The user 20 returns from the site 15 with the RFID tag 25 in which the history information and status information have been written, and drops by the reader / writer 400 again. The reader / writer 400 reads the history information and status information generated by the tag reader 600 from the RFID tag 25 (arrow R4 in the figure) and transmits the read information to the management server 500.

[0143] In this embodiment, various information related to lock management can be collected from one or more sites 15 using the RFID tag 25 as an information transmission medium in this manner and stored in the database of the management server 500.

[0144] <2-2. Configuration examples of each device> Next, with reference to FIGS. 16 and 17, examples of more specific configurations of each of the devices that make up the lock management system 2 will be described in order.

[0145] (1) Reader / Writer Fig. 16 is a block diagram showing an example of the configuration of the reader / writer 400 and management server 500 according to this embodiment. Referring to Fig. 16, the reader / writer 400 includes a read / write unit 410, a connection I / F 130, a communication I / F 140, a storage unit 150, a user I / F 160, a control unit 470, and a generation unit 180. Note that only differences in the configuration of the reader / writer 400 compared to the reader / writer 100 according to the first embodiment will be described here.

[0146] The read / write unit 410 performs communication to read information from the RFID tag 25 and write information to the RFID tag 25. The detailed configuration of the read / write unit 410 may be similar to the configuration of the read / write unit 110 of the reader / writer 100 according to the first embodiment described with reference to FIG.

[0147] The control unit 470 controls the overall functions of the reader / writer 400 according to this embodiment. For example, when the user 20 places an RFID tag within the tag reading range of the reader / writer 400, the control unit 470 causes the reading / writing unit 410 to read the tag ID from a predetermined storage area of ​​the RFID tag. If the read tag ID is the ID of an RFID tag 25 managed by the lock management system 2, the control unit 470 queries the management server 500 for usage schedule information to determine whether authentication information should be written to the RFID tag 25. The query for usage schedule information to the management server 500 may be made according to any of the first to third embodiments described above. In response to this query, the management server 500 returns the usage schedule information to the reader / writer 400. When the control unit 470 receives the usage schedule information from the management server 500, it causes the generation unit 180 to generate authentication information based on the usage period information included in the usage schedule information and the authentication basic information specific to the lock target to be used. Then, the control unit 470 causes the reading / writing unit 410 to write the generated authentication information to the RFID tag 25.

[0148] Furthermore, in this embodiment, when history information and status information are written to an RFID tag 25 within the tag reading range of the reader / writer 400, the control unit 470 causes the read / write unit 410 to read the history information and status information. The control unit 470 transmits the history information and status information read by the read / write unit 410 to the management server 500 via the communication I / F 140. The control unit 470 may erase the history information and status information transmitted to the management server 500 from the RFID tag 25.

[0149] (2) Management Server 16, the management server 500 includes a communication I / F 210, a lock management unit 220, an information providing unit 525, and a management DB 530. Note that only the differences in the configuration of the management server 500 compared to the management server 200 according to the first embodiment will be described here.

[0150] The management DB 530 is made up of a group of tables for holding information indicating the usage schedule for the lock targets 10 under the management of the lock management system 2 and for holding information related to lock management. In this embodiment, the management DB 530 includes a tag table 240, a user table 250, a lock target table 260, a usage schedule table 270, a history table 580, and a status table 590.

[0151] The history table 580 is a table that holds history information collected from tag readers 600 located at one or more sites 15 using RFID tags 25 as an information transmission medium. The history table 580 may include, for example, one or more of the following information items: "Authentication attempt time" "Authentication Results" "Source tag ID" "Related Users" Related Lock Targets ·“Measurement position” "Lock type" "Authentication attempt time" indicates the time when authentication was attempted based on the authentication information written in the RFID tag 25. "Authentication result" is information indicating whether the authentication performed at the time indicated by "Authentication attempt time" was successful or failed. "Reader tag ID" may be the tag ID of the RFID tag from which the authentication information used in the authentication was read. "Associated user" may be the user ID or user name of the user who carried or wore the RFID tag. "Associated lock target" may be the target ID or name of the lock target that was to be used during authentication. "Measured location" is location information (e.g., two-dimensional or three-dimensional coordinates) indicating the location measured by the tag reader when authentication was attempted. "Lock type" is information indicating whether the lock target was unlocked or locked.

[0152] The status table 590 is a table that holds status information collected from tag readers 600 located at one or more sites 15 using RFID tags 25 as an information transmission medium. The status table 590 may include, for example, one or more of the following information items: ·“Device ID” "Operation Status" "Battery remaining" "Status detection time" The "device ID" is information that identifies which device the status information indicated by each record in the status table 590 represents. The "device ID" may be, for example, an ID assigned to one of the lock target 10, the switching device 60, and the tag reader 600. The "operation status" may indicate whether the operation of the device identified by the "device ID" is normal or abnormal, and if abnormal, the type of abnormality. The "battery remaining capacity" is numerical information (e.g., a charge rate ranging from 0% to 100%) that indicates the level of power remaining in the battery of the device identified by the "device ID." The "battery remaining capacity" may be included in the status information only if the device is battery-powered. The "status detection time" indicates the time when the status information indicated by each record in the status table 590 was generated.

[0153] The information providing unit 525 provides information managed in the management DB 530 to a user terminal (not shown in FIG. 15 ) via the communication I / F 210. For example, in response to a request for history information received from a user terminal, the information providing unit 525 may extract history information stored in the history table 580 and transmit it to the user terminal. The history information may be provided in the form of a data file, or may be displayed on the display of the user terminal and viewed by a system administrator. Similarly, in response to a request for status information received from a user terminal, the information providing unit 525 may extract status information stored in the status table 590 and transmit it to the user terminal. The status information may be provided in the form of a data file, or may be displayed on the display of the user terminal and viewed by a system administrator. The information providing unit 525 may provide not only history information and status information, but also usage schedule information and other information in the management DB 530 to the user terminal.

[0154] For example, if the status information indicates that an abnormality has occurred in a certain lock target, the system administrator can refer to the history information to determine which user was using the lock target at the time the abnormality was detected. If the history information includes location information, the system administrator can also determine where the lock target was used or stored at the time the abnormality was detected. Furthermore, if the history information indicates that the lock target was actually used for a shorter period of time than indicated by the planned use information, the system administrator may suggest to the user that they reconsider their work plan. Furthermore, if the status information indicates that the battery level of a certain device is low, the system administrator may dispatch maintenance personnel to site 15 to replace or charge the battery.

[0155] (3) Tag reader Fig. 17 is a block diagram showing an example of the configuration of a tag reader 600 and a switching device 60 according to this embodiment. Referring to Fig. 17, tag reader 600 includes a read / write unit 610, a battery 320, an input detection unit 330, a storage unit 350, a positioning unit 660, a control unit 670, a generation unit 380, and a lock I / F 390. Note that only differences in the configuration of tag reader 600 compared to tag reader 300 according to the first embodiment will be described here.

[0156] The read / write unit 610 performs communication to read information from the RFID tag 25. The basic configuration of the read / write unit 610 may be the same as the configuration of the read / write unit 110 of the reader / writer 100 described with reference to FIG. 5. In this embodiment, the read / write unit 610 periodically emits electromagnetic waves within the tag reading range of the read / write unit 610 and attempts to read information from the RFID tag 25. When a reception signal from the RFID tag 25 is detected, the read / write unit 610 outputs information read from the RFID tag 25 (e.g., tag ID and authentication information) to the control unit 670. In addition, the read / write unit 610 writes history information and status information generated or acquired by the control unit 670 to a rewritable storage area (e.g., a user area) of the RFID tag 25.

[0157] The positioning unit 660 is a positioning module for measuring or estimating the current location of the tag reader 600. For example, the positioning unit 660 may measure the amount of relative movement from a reference position using a three-axis acceleration sensor, a gyro sensor, and a geomagnetic sensor according to a known self-position estimation method, and calculate the position coordinates of the current position by adding the known coordinates of the reference position and the amount of relative movement. Furthermore, depending on the communication means available at the site 15, the positioning unit 660 may measure the geographical position of the tag reader 600 using radio waves from GPS satellites, or may estimate the current location using the known position coordinates of the connected base station or access point. The positioning unit 660 outputs two-dimensional or three-dimensional position coordinates indicating the current location of the tag reader 600 obtained as a result of the positioning to the control unit 670.

[0158] The control unit 670 controls the overall functions of the tag reader 600 described herein. For example, when the reading / writing unit 610 reads authentication information from the RFID tag 25, the control unit 670 performs authentication based on the read authentication information. More specifically, when performing authentication, the control unit 670 first obtains the current time and determines period information related to the current time. For example, the period information here may represent a reference time (e.g., a start time) of a period to which the current time belongs, defined at the same granularity as the time unit used to register the use schedule described above. The control unit 670 then attempts authentication based on the determined period information and the authentication information read from the RFID tag 25. This authentication may be performed according to either the first or second example of the authentication method described above. When attempting authentication, the control unit 670 generates history information related to the result. The information items of the history information generated by the control unit 670 may be the same as those described in relation to the history table 580 of the management DB 530 of the management server 500. For example, in this embodiment, since the locking target 10 is movable, it is beneficial to include in the history information the current position of the tag reader 600 measured (or estimated) by the positioning unit 660 at the time the locking target 10 is unlocked or locked.

[0159] Regardless of whether authentication is successful or unsuccessful, the control unit 670 may cause the read / write unit 610 to write history information to the RFID tag 25. Alternatively, the control unit 670 may cause the read / write unit 610 to write history information to the RFID tag 25 only if authentication is successful. This can reduce the possibility that history information will be written to an inappropriate RFID tag.

[0160] If the authentication is successful, the control unit 670 transmits a switching command to the switching device 60 via the lock I / F 390 to switch the state of the lock target 10. The switching command transmitted here may be an unlock command to unlock the lock target 10. After the lock target 10 is unlocked, the control unit 670 may maintain the unlocked state of the lock target 10 until the scheduled usage period ends or until the RFID tag 25 is no longer detected for a predetermined length of time. When the period during which the unlocked state should be maintained ends, the control unit 670 transmits a lock command to the switching device 60 via the lock I / F 390 to lock the lock target 10.

[0161] The control unit 670 further monitors the status of the lock target 10, the switching device 60, and the tag reader 600, and maintains the status information in the storage unit 350. For example, the control unit 670 may periodically determine whether these devices are operating normally and store operational status information indicating the determination result (whether the device is operating normally or abnormally, and if abnormal, the type of abnormality) in the storage unit 350. The control unit 670 may also periodically determine the remaining battery capacity of a battery-powered device and update the remaining battery capacity information. The control unit 670 causes the read / write unit 610 to write such status information to the RFID tag 25. Writing the status information to the RFID tag 25 may also be performed regardless of the authentication result, or may be performed only if authentication is successful. The information items of the status information written to the RFID tag 25 may be similar to those described in relation to the status table 590 of the management DB 530 of the management server 500.

[0162] (4) Switching device 17, the switching device 60 includes an actuator 51, a sensor group 63, a battery 55, and a controller 67. Note that only the differences in the configuration of the switching device 60 from the switching device 50 according to the first embodiment will be described here.

[0163] The sensor group 63 includes a sensor for detecting the state of the lock target 10 and a sensor for detecting the status of the switching device 60, such as the operation status and the remaining battery capacity.

[0164] The controller 67 is a control circuit that controls the operation of the switching device 60. For example, when the controller 67 receives an unlock command from the tag reader 600 while the lock target 10 is in a locked state, the controller 67 drives the actuator 51 to unlock the lock target 10. Furthermore, when the controller 67 receives a lock command from the tag reader 600 while the lock target 10 is in an unlocked state, the controller 67 drives the actuator 51 to lock the lock target 10. The controller 67 returns responses indicating the results of the execution of these switching commands to the tag reader 600.

[0165] Furthermore, the controller 67 notifies the tag reader 600 of the status of the lock target 10 and the switching device 60 detected by the sensor group 63 in response to a status inquiry from the tag reader 600 or periodically. At least a part of the above-mentioned status information can be generated based on the status notified in this manner.

[0166] <2-3. Processing flow> In this section, examples of the flow of some processes that can be executed by the devices that make up the lock management system 2 in this embodiment will be described using the flowcharts in FIGS.

[0167] <2-3-1. Authentication process> FIG. 18 is a flowchart showing an example of the flow of authentication processing that can be executed by tag reader 600.

[0168] First, in S311, the input detection unit 330 continuously monitors user input. If a predetermined user input (e.g., pressing the button 302) is not detected, the process proceeds to S313. On the other hand, if a predetermined user input is detected, the process proceeds to S317.

[0169] In S313, the control unit 670 collects the status (e.g., operation status and remaining battery power) of the lock target 10, the switching device 60, and the tag reader 600. Next, in S315, the control unit 670 generates or updates status information based on the status collected in S313. Thereafter, the process returns to S311.

[0170] In S317, the read / write unit 610 emits electromagnetic waves within the tag reading range and reads the tag ID and authentication information returned from the RFID tag 25. Next, in S319, the control unit 670 attempts authentication based on the read authentication information. This authentication may be performed based on a comparison between the authentication information and verification authentication information, as described with reference to Fig. 13, or may be performed based on a correspondence relationship between the usage period indicated by the usage period information and a period related to the current time, as described with reference to Fig. 14.

[0171] If the authentication attempted in S319 is successful (S321-Yes), in S323 the control unit 670 instructs the switching device 50 to switch the state of the lock target 10 (for example, from the locked state to the unlocked state). If the authentication fails (S321-No), S323 is skipped and the state of the lock target 10 is not switched.

[0172] Next, in S325, the control unit 670 generates history information related to the authentication result. At this time, the positioning unit 660 may measure the current position of the tag reader 600, and information indicating the measured position may be included in the history information. Next, in S327, the read / write unit 610 writes the history information generated in S325 and the status information generated or updated in S315 to the RFID tag 25. Then, the processing returns to S311.

[0173] <2-3-2. Information collection and processing> Fig. 19 is a flowchart showing an example of the flow of information collection processing executed by the reader / writer 400. Note that the flow of the write processing for writing authentication information to the RFID tag 25 may be the same as that explained using Figs. 8 to 10, and therefore Fig. 19 shows only the flow of processing for information collection.

[0174] First, in S411 , the read / write unit 410 reads history information and status information from the rewritable storage area of ​​the RFID tag 25 that is within the tag reading range of the reader / writer 400 .

[0175] Next, in S413, the control unit 470 transmits the history information and status information read by the reading / writing unit 410 to the management server 500 via the communication I / F 140.

[0176] When the transmission of information to the management server 500 is completed, in S415, the read / write unit 410, under the control of the control unit 470, erases the history information and status information in the rewritable storage area of ​​the RFID tag 25. Then, the information processing shown in Fig. 19 ends.

[0177] In this section, an example has been described in which the reader / writer 400 that writes authentication information to the RFID tag 25 collects history information and status information from the RFID tag 25, but the present embodiment is not limited to this example. That is, a tag reader that does not write authentication information to the RFID tag 25 may collect information from the RFID tag 25 and relay it to the management server 200.

[0178] <2-4. Modifications> There are many possible variations on how information is collected from devices that may be located in multiple sites 15. Two variations will be described below.

[0179] <2-4-1. First modified example> 20 is a schematic diagram showing an overview of a lock management system 3 according to a first modification. In the lock management system 3, a tag reader 700 is connected to a switching device 60 instead of the tag reader 600 of the lock management system 2. Furthermore, authentication information can be written to the RFID tag 25 by a reader / writer 100.

[0180] The tag reader 700 is a reading device capable of reading information from the RFID tag 25. Like the tag reader 600, the tag reader 700 generates history information related to switching the state of the lock target 10, as well as status information about one or more of the lock target 10, the switching device 60, and the tag reader 700. In this modification, the tag reader 700 is equipped with a short-range communication I / F and is capable of short-range communication with a nearby communication terminal. When a communication link is established with a nearby communication terminal, the tag reader 700 transmits the history information and status information stored in its internal memory to the communication terminal via the short-range communication I / F. Arrow C5 in FIG. 20 represents the transmission of information from the tag reader 700 to a communication terminal 750 carried by the user 20c. The communication terminal 750, having received the history information and status information, uploads the history information and status information to the management server 500 using any communication path (for example, arrow C6 in the figure via a wireless LAN access point). The management server 500 stores the received history information and status information in a history table 580 and a status table 590, respectively.

[0181] While FIG. 20 shows an example in which a communication terminal 750 that relays information between the tag reader 700 and the management server 500 is held by a user 20c, the communication terminal 750 may also be held by a user 20a who uses the lock target 10. The communication terminal 750 may be any type of terminal device, such as a smartphone, a tablet PC, or a dedicated terminal for information relay. Instead of being held by a user, the communication terminal 750 may be mounted on a machine such as a vehicle (e.g., an automated guided vehicle), a drone, or a robot. The communication link between the tag reader 700 and the communication terminal 750 may be based on any type of communication method, such as Bluetooth (registered trademark), Wi-Fi Direct (registered trademark), or Wireless USB.

[0182] According to this modification, the management server 500 can collect history information and status information from devices under the management of the system even when the user 20 is not using the lock target 10.

[0183] <2-4-2. Second modified example> 21 is a schematic diagram showing an overview of a lock management system 4 according to a second modification. In the lock management system 4, a tag reader 800 is connected to the switching device 60 instead of the tag reader 600 of the lock management system 2. An RFID tag 805 is fixedly installed inside or near the tag reader 800.

[0184] The tag reader 800 is a reading device capable of reading information from the RFID tag 25. Like the tag reader 600, the tag reader 800 generates history information related to switching the state of the lock target 10, as well as status information about one or more of the lock target 10, the switching device 60, and the tag reader 800. In this modification, the tag reader 800 is further capable of writing information to the RFID tag 805, and writes the generated history information and status information to the user area of ​​the RFID tag 805. An arrow W7 in FIG. 21 represents the writing of information from the tag reader 800 to the RFID tag 805.

[0185] The lock management system 4 further includes a tag reader 850 for collecting information, which is capable of reading history information and status information from an RFID tag 805 to which the information is written and transmitting the read information to another device. In the example of FIG. 21 , when a user 20d carrying the tag reader 850 approaches the RFID tag 805, the tag reader 850 reads the history information and status information from the RFID tag 805 (arrow R8 in the figure). The user 20d then returns to the location of the reader / writer 400 and connects the tag reader 850 to the reader / writer 400. The reader / writer 400 then receives the history information and status information from the tag reader 850 (arrow C9 in the figure) and relays the received information to the management server 500. The management server 500 stores the history information and status information received from the reader / writer 400 in a history table 580 and a status table 590, respectively.

[0186] 21 shows an example in which user 20d carries tag reader 850, but instead of being carried by the user, tag reader 850 may be mounted on a machine such as a vehicle, a drone, or a robot. The connection between tag reader 850 and reader / writer 400 may be based on any type of wired or wireless connection method. Furthermore, tag reader 850 may communicate with management server 500 without going through reader / writer 400.

[0187] According to this modification, history information and status information of devices within the site 15 can be collected simply by having users who visit the site 15 carry a tag reader for collecting information.

[0188] <3. Summary> Various embodiments and modifications of the technology according to the present disclosure have been described above using FIGS. 1 to 22. In the above-described embodiments, a writing device capable of writing information to an RFID tag writes authentication information based on planned use information related to a lock target to a rewritable first storage area of ​​a first RFID tag carried or attached by a user. Then, a reading device connected to a switching device capable of switching the state of the lock target between a locked state and an unlocked state reads the authentication information from the first RFID tag, and attempts authentication based on the read authentication information. If this authentication is successful, the reading device instructs the switching device to switch the state of the lock target. With this configuration, the state of the lock target can be switched (e.g., unlocked) to allow the user to use the lock target only for the period indicated by the planned use without requiring the user to perform complicated operations. If there is no planned use, the authentication information is not written to the RFID tag, authentication is not successful, and the state of the lock target is not switched. This eliminates or minimizes the possibility that the user will use the lock target at a time not anticipated in the work plan.

[0189] In the above-described embodiment, the authentication information written to the first storage area of ​​the first RFID tag may be generated based on usage period information related to the period during which the lock target is used and authentication basic information specific to the lock target. In this case, even if the first RFID tag stores authentication information for another lock target or authentication information that is not valid for that time period, authentication will not be successful. Therefore, in a situation where multiple different lock targets are managed or multiple different users can use the same lock target, it is possible to prevent the lock target from being released to an inappropriate user.

[0190] In addition, in the above-described embodiment, the reader does not need to communicate with any device other than the RFID tag when performing authentication. Therefore, utilizing the above-described lock management mechanism is an effective solution for imposing time restrictions on the use of locked items in places where radio waves are difficult to reach.

[0191] In the second embodiment, the reading device that performs the authentication generates history information related to the switching of the state of the lock target and status information indicating the status of the device, and the generated information is collected via an RFID tag and tag reader or via a communication terminal. Therefore, information about lock targets that can be used in various places can be efficiently collected, and the collected information can be used for purposes such as verifying usage history, investigating the cause of abnormalities, or monitoring the remaining battery level.

[0192] <4. Other embodiments> The above-described embodiment can also be realized in the form of a process in which a program for realizing one or more functions is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program, or by a circuit (e.g., ASIC) that realizes one or more functions.

[0193] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]

[0194] 1, 2, 3, 4: Lock management system, 10: Lock target, 20: User, 25: RFID tag, 50, 60: Lock target, 100, 400: Reader / writer (writing device), 200, 500: Management server, 300, 600, 700, 800: Tag reader (reading device), 750: Communication terminal, 850: Tag reader (reading device for collecting information)

Claims

1. a switching device capable of switching the state of a lock target between a locked state and an unlocked state; a first RFID (Radio Frequency Identification) tag having a rewritable first storage area; a writing device capable of writing information to an RFID tag, the writing device writing authentication information to the first storage area of ​​the first RFID tag based on planned use information related to the lock target; a reader connected to the switching device and capable of reading information from an RFID tag, the reader reading the authentication information returned from the first RFID tag using electromagnetic wave energy emitted by the reader, and causing the switching device to switch the state of the lock target when authentication based on the read authentication information is successful; Including, The scheduled use information is registered in a database in association with tag identification information that identifies an RFID tag carried or attached by a user who uses the lock target, the first RFID tag further has a second storage area for storing first tag identification information for identifying the first RFID tag; the writing device is capable of reading information from an RFID tag; The writing device reading the first tag identification information from the second storage area of ​​the first RFID tag; The planned use information associated with the read first tag identification information is acquired from the database; The lock management system writes the authentication information to the first storage area of ​​the first RFID tag based on the acquired usage schedule information.

2. A switching device capable of switching the state of a lock target between a locked state and an unlocked state; a first RFID (Radio Frequency Identification) tag having a rewritable first storage area; a writing device capable of writing information to an RFID tag, the writing device writing authentication information to the first storage area of ​​the first RFID tag based on planned use information related to the lock target; a reader connected to the switching device and capable of reading information from an RFID tag, the reader reading the authentication information returned from the first RFID tag using electromagnetic wave energy emitted by the reader, and causing the switching device to switch the state of the lock target when authentication based on the read authentication information is successful; Including, the scheduled use information is registered in a database in association with user identification information that identifies a user who uses the lock target; The writing device obtaining, from the database, the planned use information associated with first user identification information of a first user who has accessed the writing device; The lock management system writes the authentication information to the first storage area of ​​the first RFID tag based on the acquired usage schedule information.

3. The lock management system of claim 2 , wherein the writing device reads the first user identification information from a second RFID tag carried by the first user.

4. The lock management system of claim 2 , wherein the writing device accepts the first user identification information via a user interface of the writing device.

5. the planned use information includes use period information relating to a period during which the lock target will be used; the authentication information is generated based on the usage period information and authentication basic information specific to the lock target, and is written into the first storage area of ​​the first RFID tag by the writing device; The lock management system according to any one of claims 1 to 4.

6. The reading device The authentication basic information specific to the lock target is stored in advance, determining that the authentication has been successful when the authentication information read from the first RFID tag matches verification authentication information generated based on period information related to the current time and the authentication base information; The lock management system of claim 5 .

7. 7. The lock management system according to claim 5, wherein the authentication information is generated by encoding a bit string based on the usage period information and the authentication basic information according to a predetermined encoding method.

8. the planned use information includes use period information relating to a period during which the lock target will be used; the authentication information is generated by encrypting the usage period information with a first encryption key, and is written into the first storage area of ​​the first RFID tag by the writing device; The lock management system according to any one of claims 1 to 4.

9. The reading device a second encryption key corresponding to the first encryption key is stored in advance; determining that the authentication has been successful when the usage period information restored by decrypting the authentication information read from the first RFID tag with the second encryption key corresponds to a period related to the current time; The lock management system of claim 8 .

10. The lock management system according to any one of claims 1 to 9, wherein the reading device causes the switching device to switch the state of the lock target in response to success of the authentication based on the authentication information read from the first RFID tag only when a predetermined user input is detected.

11. The reader is capable of writing information to the RFID tag; The reading device generating history information relating to the switching of the state of the lock target; writing the generated history information to an RFID tag; The lock management system according to any one of claims 1 to 10.

12. The lock management system according to claim 11 , wherein the reader writes the history information to the first RFID tag when the authentication based on the authentication information read from the first RFID tag is successful.

13. The lock management system includes: a third RFID tag placed near the reader; further comprising The reader writes the history information to the third RFID tag. The lock management system of claim 11 .

14. The lock management system includes: a reading device for collecting information that reads the history information from the RFID tag in which the history information is written and transmits the read history information to another device; 14. The lock management system of claim 12 or 13, comprising:

15. the reading device is capable of short-distance communication with a nearby communication terminal, The reading device generating history information relating to the switching of the state of the lock target; transmitting the generated history information to the communication terminal; The lock management system according to any one of claims 1 to 10.

16. The history information is The time of the authentication attempt, Authentication success or failure, Information about the RFID tag from which the authentication information was read; Information about the user carrying or wearing the RFID tag from which the authentication information is read; Information about the lock target; and Whether the lock target has been unlocked or locked; The lock management system of any one of claims 11 to 15, comprising one or more of:

17. The switching device and the reading device are movable together with the lock target, The reading device measures the position of the reading device at the time when the lock target is unlocked or locked, the history information includes position information indicating a position measured by the reading device; The lock management system according to any one of claims 11 to 16.

18. the reading device writes status information indicating the status of one or more of the lock target, the switching device, and the reading device to the RFID tag; The lock management system includes: a reading device for collecting information that reads the status information from the RFID tag in which the status information is written and transmits the read status information to another device; The lock management system of any one of claims 1 to 17, comprising:

19. The status information is Equipment malfunctions, and If the device is battery-powered, the remaining battery charge; 20. The lock management system of claim 18, including information relating to one or more of:

20. The switching device is an electronic lock, The locking target is an article or a space, Unlocking the locked object includes unlocking the electronic lock to enable use of the locked object. The lock management system according to any one of claims 1 to 19.

21. The switching device is a device having a specific function, the lock target is the function specific to the device, Unlocking the locked object includes enabling the function to be activated. The lock management system according to any one of claims 1 to 19.

22. A reading / writing device capable of reading information from an RFID tag and writing information to an RFID tag, comprising: reading first tag identification information from a first RFID (Radio Frequency Identification) tag carried or worn by a user, the first tag identification information identifying the first RFID tag; acquiring planned use information associated with the first tag identification information read from a database in which planned use information associated with tag identification information that identifies an RFID tag is registered, the planned use information being related to a lock target whose state can be switched between a locked state and an unlocked state by a switching device; writing authentication information to a rewritable storage area of ​​the first RFID tag based on the acquired usage schedule information, for enabling the switching device to switch the state of the lock target; Read-write device.

Citation Information

Patent Citations

  • Room ingress and egress controller

    JP1989151673A

  • Card key device

    JP1992327666A

  • Locking device by selector card

    JP1994264661A

  • Name card, security terminal and security system using these

    JP1997245138A

  • Room entry and exiting system and room entry and exiting control method

    JP1999232514A