Authentication system, wearing terminal, display, authentication method, and program

By combining wear terminals and registration equipment, using disengagement detection and bioinformatic authentication, the problem of information leakage in the existing authentication system is solved, and a safer user authentication and production equipment operation permission management is achieved.

CN120457426AActive Publication Date: 2025-08-08MITSUBISHI ELECTRIC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202380089929.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-04-25
Publication Date
2025-08-08
Estimated Expiration
2043-04-25

AI Technical Summary

Technical Problem

In the existing authentication system, users' biological information and personal information are easily leaked, resulting in insufficient security and inability to effectively authenticate user authentication.

Method used

Wearing terminals are used for wear detection. Through the combination of wear terminal information and biological information, the registered equipment is used to confirm user legality, and the authentication device connected to the production equipment is authorized to ensure that only legal wearers can operate the production equipment.

Benefits of technology

It realizes safer user authentication, avoids personal information leakage, and ensures the safety and legality of production equipment operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120457426A_ABST
    Figure CN120457426A_ABST
Patent Text Reader

Abstract

An authentication system (1) is provided with a wearing terminal (100), a registration device (200), and a display (300). The wearing terminal (100) is provided with: a wearing-off detection unit (102); a wearable terminal information storage unit that stores wearable terminal information including terminal identification information and a detection result; and a wearing terminal information transmission unit that transmits the wearing terminal information, the registration device (200) being provided with: a wearing terminal information reception unit that receives the wearing terminal information; an authentication information acquisition unit that acquires authentication information of the user; and a determination unit (204) that confirms the legality of the user and generates correspondence information in which the user identification information and the terminal identification information are associated, the display (300) having: an operation input unit that receives an operation to the production facility; a terminal information receiving unit that receives wearing terminal information; a take-off and wear determination unit; and an authentication unit (304) that, when it is determined that the wearable terminal (100) is worn, authenticates whether or not to permit the received operation on the basis of the permission information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system, a wearable terminal, a display, an authentication method and a program. Background Art

[0002] In the manufacturing industry, technologies for allowing limited users to operate production equipment are known. For example, Patent Document 1 discloses an authentication system comprising: a body-worn device that, upon detecting that the device body is worn on a wrist, receives and stores authentication data for connecting to an external device; and an external device that determines whether authentication is permitted based on the authentication data received from the body-worn device.

[0003] Patent Document 1: Japanese Patent Application Laid-Open No. 2000-200315 Summary of the Invention

[0004] In this authentication system, since authentication data such as personal information and biometric information is stored in the body-worn device, there is a risk of leakage of this information due to loss or theft, etc. Therefore, there is room for improvement from the perspective of ensuring security and performing user authentication more safely.

[0005] The present invention has been made in view of the above-mentioned problems, and an object of the present invention is to provide an authentication system, a wearable terminal, a display, an authentication method, and a program that can more securely authenticate a user.

[0006] In order to achieve the above-mentioned purpose, the authentication system of the present invention comprises: a wearing terminal, which is worn by the user; a registration device, which registers the user; and an authentication device, which is connected to the production equipment and authenticates whether the operation to the production equipment is allowed. In the authentication system, the wearing terminal comprises: a wearing-off detection unit, which detects whether the wearing terminal is worn; a wearing terminal information storage unit, which stores the wearing terminal information, the wearing terminal information including terminal identification information that uniquely identifies the wearing terminal and the detection result obtained by the wearing-off detection unit; and a wearing terminal information sending unit, which sends the wearing terminal information stored in the wearing terminal information storage unit. The registration device comprises: a wearing terminal information receiving unit, which receives the wearing terminal information; an authentication information acquisition unit, which acquires the user's authentication information; and a judgment unit, which, based on the acquired authentication information, The legitimacy of the user is confirmed, and corresponding information is generated and sent to the authentication device. The corresponding information is information that associates user identification information that uniquely identifies the user confirmed as legitimate with terminal identification information contained in the received wearing terminal information. The authentication device includes: an operation input unit that receives operations to the production equipment; a terminal information receiving unit that receives wearing terminal information; a wearing / taking-off determination unit that determines whether the wearing terminal is worn based on the received wearing terminal information; and an authentication unit that, when it is determined that the wearing terminal is worn, determines the user wearing the wearing terminal based on the terminal identification information contained in the received wearing terminal information and the corresponding information sent by the determination unit, and authenticates whether the operation received by the operation input unit is allowed based on the permission information indicating whether each user has the permission to operate the production equipment.

[0007] Effects of the Invention

[0008] According to the present invention, a wearable terminal worn by a user transmits wearable terminal information, including terminal identification information and a detection result indicating whether the wearable terminal is being worn, to an authentication device. The authentication device then identifies the user based on corresponding information sent from a registration device that has verified the user's legitimacy. Based on the identified user's permission information, the authentication device then verifies whether operations on production equipment are permitted. This allows for more secure user authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 This is a diagram showing the configuration of an authentication system according to Embodiment 1 of the present invention.

[0010] Figure 2 Yes Figure 1 FIG. 1 is a diagram showing an example of worn terminal state information stored in the data storage unit of the worn terminal.

[0011] Figure 3 Yes Figure 1FIG. 1 is a diagram showing an example of an operator correspondence table stored in the data storage unit of the registered device.

[0012] Figure 4 Yes Figure 1 FIG. 1 is a diagram showing an example of operation authority information stored in the data storage unit of the registered device.

[0013] Figure 5 Yes Figure 1 A block diagram of the physical structure of the wearable terminal is shown.

[0014] Figure 6 Yes Figure 1 A block diagram of the physical structure of the registration equipment and manufacturing equipment is shown.

[0015] Figure 7 This is a flowchart showing the registration process performed by the authentication system.

[0016] Figure 8 This is a flowchart showing the authentication process performed by the authentication system. DETAILED DESCRIPTION

[0017] Hereinafter, referring to the accompanying drawings, the authentication system, wearable terminal, display, authentication method and program according to the embodiment of the present invention will be described.

[0018] The authentication system involved in this embodiment is a system used in production sites such as factories and workshops to authenticate whether an operator has the authority to operate the manufacturing equipment installed at the production site. Figure 1 As shown, the authentication system 1 includes a wearable terminal 100, which is worn on a portion of a worker's body; a registration device 200, which registers the worker wearing the wearable terminal 100 and the unique ID of the wearable terminal 100; and a display 300, which is connected to the manufacturing equipment 400 and displays information related to the control of the manufacturing equipment 400, allowing operations including input of parameters used to control the manufacturing equipment 400. The display 300 reads the unique ID of the wearable terminal 100 and determines whether operations on the operation panel of the display 300 are permitted.

[0019] The wearable terminal 100 can be worn on a part of the worker's body, such as the wrist or ankle, and is, for example, in the form of a wristband. The wearable terminal 100 includes, for example, an NFC tag and a removal detection sensor for detecting when the wearable terminal 100 is worn or removed. The wearable terminal 100 detects whether the wearable terminal 100 is worn by the worker and stores the detected wearing status, a removal history indicating when the wearable terminal 100 has been removed, and the unique ID of the wearable terminal 100. The registration device 200 obtains the worker's biometric information to identify the worker, registers the identified worker in association with the unique ID of the wearable terminal 100, and transmits the information to the display 300. The display 300 reads the unique ID from the wearable terminal 100 worn by the worker and, referring to the operator's operation permissions pre-set on the registration device 200, determines whether to allow operation on the operation panel. Furthermore, the display 300 reads the removal history indicating when the wearable terminal 100 has been removed from the wearable terminal 100. If it determines that the wearable terminal 100 has been removed, authentication is denied and the operation is rejected.

[0020] Next, the functional structures of the wearable terminal 100 , the registration device 200 , and the display 300 will be described respectively.

[0021] The wearable terminal 100 includes: a sensor unit 101, which obtains information required to identify the wearing status of the wearable terminal 100; a wearing and removing detection unit 102, which detects the wearing and removing of the wearable terminal 100 by the operator; a power generation unit 103, which supplies power to the wearing and removing detection unit 102; a data control unit 104, which stores the wearing status and removal history of the wearable terminal 100 in the data storage unit 105; the data storage unit 105, which stores the wearing status, removal history and information uniquely identifying the wearable terminal 100, namely, the inherent ID of the wearable terminal 100; an antenna unit 106, which transmits and receives wireless signals for wireless communication with the registration device 200 and the display 300; an RF control unit 107, which controls the information stored in the data storage unit 105 to be sent from the antenna unit 106; and a voltage generation unit 108, which generates a voltage for driving the data control unit 104 and the data storage unit 105.

[0022] The sensor unit 101 acquires information necessary to identify the wearable terminal 100 being worn by the operator. Examples of the sensor unit 101 include: a temperature sensor that identifies body temperature and detects temperature changes when the wearable terminal is removed; a pressure sensor that identifies the fit of a portion of the operator's body and detects pressure based on the fit when the wearable terminal is removed; and a light sensor that detects light intensity when the wearable terminal is removed.

[0023] The wearing and removing detection unit 102 detects whether the wearable terminal 100 is worn or removed by the operator based on the information obtained by the sensor unit 101. Specifically, the wearing and removing detection unit 102 detects whether the wearable terminal 100 is worn or removed based on changes in temperature, pressure, light, etc. detected by the sensor unit 101.

[0024] The power generation unit 103 supplies power to the wearable device detection unit 102. Specifically, the power generation unit 103 includes a power generation module that generates electricity using body temperature. When the wearable terminal 100 is worn, the power generation unit 103 generates electricity using the temperature difference between the wearer's body temperature and the external temperature, and supplies the electricity to the wearable device detection unit 102.

[0025] The data control unit 104 stores the wearing state detection result obtained by the wearing detection unit 102 in the data storage unit 105 . Specifically, the data control unit 104 stores wearing state information indicating whether the operator has worn or removed the wearable terminal 100 , as detected by the wearing detection unit 102 .

[0026] The data storage unit 105 stores the wearable terminal information, which includes the unique ID that uniquely identifies the wearable terminal 100, the wearing state of the wearable terminal 100, and the history of the wearable terminal 100 being removed. Figure 2 As illustrated, the wearable terminal information includes information such as "unique ID" indicating the unique ID of the wearable terminal 100, "wearing status" indicating the wearing status of the wearable terminal 100, and "removal history" indicating the history of the wearable terminal 100 being removed. In the "wearing status" item, a flag "1" indicating that the operator is wearing the wearable terminal 100 or a flag "0" indicating that the operator has removed the wearable terminal 100 is stored. In the "removal history" item, a flag "1" indicating that there is a history of the wearable terminal 100 being removed after being worn or a flag "0" indicating that there is a history of the wearable terminal 100 being removed after being worn is stored. In addition, the data storage unit 105 is an example of a wearable terminal information storage unit, the unique ID is an example of terminal identification information, and the removal history is an example of removal history information.

[0027] Return to Figure 1 The antenna unit 106 transmits and receives wireless signals for wireless communication with the registration device 200 and the display 300. The antenna unit 106 is an example of a wearable terminal information transmitting unit.

[0028] The RF control unit 107 controls the transmission of the wearable terminal information stored in the data storage unit 105 from the antenna unit 106. Specifically, if the wearable terminal 100 is detected by the wearable terminal removal detection unit 102 as being worn by the user, the RF control unit 107 controls the antenna unit 106 to transmit a carrier wave at predetermined intervals or continuously. Furthermore, if the wearable terminal 100 is detected by the wearable terminal removal detection unit 102 as being removed, the RF control unit 107 stops the transmission of the carrier wave from the antenna unit 106.

[0029] The voltage generating unit 108 generates a voltage for driving the data control unit 104 and the data storage unit 105. Specifically, the voltage generating unit 108 generates a voltage for driving the data control unit 104 and the data storage unit 105 based on the electrical signal received from the antenna unit 106, for example, using the preamble portion included in the electrical signal, and supplies the voltage to the data control unit 104 and the data storage unit 105.

[0030] The registration device 200 includes: an antenna unit 201, which transmits and receives wireless signals for wireless communication with the wearable terminal 100; an RF control unit 202, which converts the wireless signals received by the antenna unit 201 into digital data; a biometric information acquisition unit 203, which acquires biometric information; a determination unit 204, which authenticates whether the operator is legitimate; a data control unit 205, which generates an operator correspondence table that associates the operator authenticated as legitimate with the inherent ID of the wearable terminal 100; a data storage unit 206, which stores various information; and a network control unit 207, which transmits and receives data with the display 300.

[0031] The antenna unit 201 transmits and receives wireless signals for wireless communication with the wearable terminal 100. The antenna unit 201 is an example of a wearable terminal information receiving unit.

[0032] The RF control unit 202 converts the wireless signal received by the antenna unit 201 into digital data. Specifically, the RF control unit 202 obtains the wireless signal from the wearable terminal 100 via the antenna unit 201. Figure 2 The illustrated wearing terminal state information is transferred to the determination unit 204.

[0033] The biometric information acquisition unit 203 acquires the operator's biometric information. Specifically, the biometric information acquisition unit 203 includes a fingerprint sensor or a biometric information reader that reads biometric information such as veins, voiceprints, or irises, and acquires the operator's biometric information. The biometric information acquisition unit 203 is an example of an authentication information acquisition unit.

[0034] The determination unit 204 determines whether the operator is legitimate. Specifically, the determination unit 204 determines whether the biometric information obtained by the biometric information acquisition unit 203 is pre-registered in the registration device 200, thereby determining whether the operator is legitimate. The determination unit 204 refers to the biometric data corresponding information stored in the data storage unit 206, which associates information that uniquely identifies the operator, namely the operator ID, with biometric data such as fingerprint data, vein pattern, voice pattern, and iris pattern, and determines whether there is biometric data that is consistent with the acquired biometric information. If it is determined that there is biometric data that is consistent with the acquired biometric information, the determination unit 204 determines that the operator with the acquired biometric information is legitimate. In addition, the operator ID is an example of user identification information, and the biometric data corresponding information is an example of authentication corresponding information.

[0035] The data control unit 205 generates an operator correspondence table that associates the operator authenticated as legitimate by the determination unit 204 with the unique ID of the wearable terminal 100. Figure 3 As illustrated, the operator correspondence table includes information that uniquely identifies the operator's "operator ID" and uniquely identifies the wearable terminal 100. The data control unit 205 stores the generated operator correspondence table in the data storage unit 206. The operator correspondence table is an example of correspondence information.

[0036] Return to Figure 1 The data storage unit 206 stores information related to the authentication of the operator and the operation authority information indicating the operation authority of each operator. Specifically, the data storage unit 206 stores the information generated by the data control unit 205. Figure 3 The illustrated operator correspondence table, Figure 4 The illustrated operation authority information is stored. As shown in the figure, the operation authority information includes an "operator ID" that uniquely identifies the operator, an "equipment ID" that uniquely identifies the manufacturing equipment 400, and "operation authority" information indicating whether the operation authority is granted. In each item of "operation authority", a flag "1" indicating that the operator is granted operation authority, or a flag "0" indicating that it is not granted is stored. In the example shown in the figure, the operator with operator ID "A0001" is granted the operation authority of "login", "start", "operation" and "stop" of the equipment ID "X01", i.e., the manufacturing equipment 400, but is not granted the operation authority of "setting change". In addition, the data storage unit 206 is an example of an authentication corresponding information storage unit.

[0037] Return to Figure 1The network control unit 207 transmits and receives data to and from the display 300. Specifically, the network control unit 207 transmits the operator correspondence table generated by the data control unit 205 and the operation authority information of the operator authenticated as legitimate by the determination unit 204 to the display 300.

[0038] The display 300 has: an antenna unit 301, which transmits and receives wireless signals for wireless communication with the wearable terminal 100; an RF control unit 302, which converts the wireless signal received by the antenna unit 301 into digital data; a data control unit 303, which generates data to be sent to the registration device 200; an authentication unit 304, which authenticates whether operation to the production equipment is allowed; a data storage unit 305, which stores various information; and a network control unit 306, which transmits and receives data to the registration device 200.

[0039] The antenna unit 301 transmits and receives wireless signals for wireless communication with the wearable terminal 100. The antenna unit 301 is an example of a terminal information receiving unit.

[0040] The RF control unit 302 converts the wireless signal received by the antenna unit 201 into digital data. Specifically, the RF control unit 302 obtains the wireless signal from the wearable terminal 100 via the antenna unit 301. Figure 2 The terminal state information shown is passed to the authentication unit 304.

[0041] Return to Figure 1 The data control unit 303 generates data to be sent to the registration device 200. Specifically, if the authentication unit 304 determines that there is a history of the wearable terminal 100 worn by the operator being removed, the data control unit 303 generates a message notifying of this situation.

[0042] The authentication unit 304 determines whether the wearable terminal 100 is worn, whether there is a history of the wearable terminal 100 being removed, and whether the operation to the production equipment is allowed. Specifically, the authentication unit 304 reads the RF control unit 302 obtained from the RF control unit 302. Figure 2 The illustrated wearable terminal status information determines that the wearable terminal 100 is being worn when the wearable status is "1," and determines that the wearable terminal 100 has been removed when the wearable status is "0." Furthermore, the authentication unit 304 determines that there is a history of removal when the removal history is "1," and determines that there is no history of removal when the removal history is "0." If the authentication unit 304 determines that the wearable terminal 100 has been removed or that there is a history of removal, it determines that the operator's operation is not permitted. If the authentication unit 304 determines that the wearable terminal 100 is not permitted, it performs processing such as rendering the operation panel completely black, not displaying the operation buttons, or ignoring any operation on the operation buttons.

[0043] In addition, when it is determined that the wearable terminal 100 is worn and has not been removed, the authentication unit 304 refers to the data obtained from the registration device 200. Figure 4 The operation permission information shown determines whether the operation input to the operation panel is permitted. For example, if an operator with operator ID "A0001" logs in to display 300 connected to manufacturing equipment 400 with device ID "X01," authentication unit 304 references the operation permission information and, since the operator is authorized to log in to device ID "X01," permits the operation. Authentication unit 304 is an example of a donning / removal determination unit or a determination unit, and the operation panel is an example of an operation input unit.

[0044] Return to Figure 1 The data storage unit 305 receives the data sent by the network control unit 207 of the registration device 200. Figure 3 The operator correspondence table shown, Figure 4 The operation permission information shown is stored.

[0045] Return to Figure 1 , the network control unit 306 sends and receives data with the display 300. Specifically, the network control unit 306 receives data from the network control unit 207 of the registration device 200. Figure 3 The operator correspondence table shown, Figure 4 The operation authority information shown is received, and a message indicating that there is a history of the wearable terminal 100 being removed, generated by the data control unit 303, is transmitted to the registration device 200. The network control unit 306 is an example of a corresponding information acquisition unit.

[0046] Next, refer to Figure 5 The physical structure of the wearable terminal 100 will be described. The registration device 200 and the wearable terminal 100 include a processor 11 that executes processing according to a program, a memory 12 that stores various programs, and a wireless communication unit 13 that transmits and receives information, and are connected via an internal bus 99 .

[0047] The processor 11 reads and executes the program stored in the memory 12. The processor 11 includes various processing devices such as a CPU (Central Processing Unit) and an MPU (Micro-processing Unit). The processor 11 executes the processing performed by the data control unit 104 as the main function provided by the program.

[0048] The memory 12 includes storage elements such as ROM (Read Only Memory) and RAM (Random Access Memory). The memory 12 stores a control program in advance and stores information about the state of the worn terminal. The memory 12 functions as the data storage unit 105.

[0049] The wireless communication unit 13 is a communication interface for performing wireless communication in compliance with a wireless communication standard such as Wi-Fi, Bluetooth (registered trademark), NFC, or Zigbee (registered trademark), and operates as the antenna unit 106 and the RF control unit 107 .

[0050] Next, refer to Figure 6 The physical structure of the registration device 200 and the display 300 will be described. The registration device 200 and the display 300 include a processor 21 that executes processing according to a program; RAM 22 (volatile memory); ROM 23 (non-volatile memory); a storage unit 24 that stores data; an input unit 25 that receives input information; a display unit 26 that visually displays information; and a communication unit 27 that transmits and receives information. These components are connected via an internal bus 99.

[0051] The processor 21 includes a CPU. The processor 21 reads programs stored in the storage unit 24 into the RAM 22 and executes the programs, thereby performing various processes. As the main functions provided by the programs, the processor 21 executes the processes performed by the RF control unit 202, the determination unit 204, the data control unit 205, the data control unit 303, and the authentication unit 304.

[0052] The RAM 22 is used as a work area for the CPU. The ROM 23 stores a control program executed by the CPU for basic operations of the registration device 200 and the display 300, a BIOS (Basic Input Output System), and the like.

[0053] The storage unit 24 includes a hard disk drive, stores programs executed by the CPU, and stores various data used when executing the programs. The storage unit 24 functions as the data storage unit 206 and the data storage unit 305.

[0054] The input unit 25 is a user interface including a keyboard, a mouse, a touch panel, etc. The input unit 25 functions as an operation panel included in the display 300 .

[0055] The display unit 26 is a display device such as a liquid crystal display or an organic EL (ElectroLuminescence) display that displays information in a visual manner.

[0056] The communication unit 27 is a network terminal device or wireless communication device connected to the network, and a serial interface or LAN (Local Area Network) interface connected thereto. The communication unit 27 receives signals from the outside and outputs the data represented by these signals to the processor 21. The communication unit 27 functions as the antenna unit 201, the RF control unit 202, the network control unit 207, the antenna unit 301, the RF control unit 302, and the network control unit 306.

[0057] Next, the operation of the authentication system 1 having the above structure will be described. The authentication system 1 performs a registration process and an authentication process. The registration process is to confirm the legitimacy of the operator wearing the wearable terminal 100 and associate the wearable terminal 100 with the operator whose legitimacy has been confirmed. The authentication process is to authenticate whether the operator wearing the wearable terminal 100 is allowed to operate the operation panel of the display 300. Here, first, refer to Figure 7 The operation of the registration process will be described.

[0058] (Registration Processing)

[0059] In the data storage unit 206 of the registration device 200, the administrator pre-stores the data that defines the operation authority of each operator. Figure 4 The operator authority information shown is shown. The administrator creates operator authority information for each factory operating day, taking into account the operating schedule of each manufacturing facility 400 and the operator's shifts. For example, this information is stored in the data storage unit 206. Furthermore, the administrator pre-stores a biometric information table in the data storage unit 206, which associates operator IDs with biometric information. When an operator is assigned to the factory, the administrator obtains the operator's biometric data, such as fingerprint data, voiceprint, and iris pattern, and creates a biometric information table, which is then stored in the data storage unit 206.

[0060] If a worker wears the wearable terminal 100 in a locker room of a factory, for example, the power generation unit 103 of the wearable terminal 100 generates electricity using the temperature difference between the worker's body temperature and the outside temperature, and supplies the electricity to the wear-off detection unit 102. The wear-off detection unit 102 detects whether the worker is wearing the wearable terminal 100 based on the temperature change and fit detected by the sensor unit 101, and changes the detection bit from the initial value "Low" to "High". The data control unit 104 generates Figure 2 The worn terminal state information shown is stored in the data storage unit 105 . The worn terminal state information includes a unique ID preset for the worn terminal 100 and wearing information for identifying the wearer of the worn terminal 100 .

[0061] The operator wearing the wearable terminal 100 causes the registration device 200 to perform a registration process to associate the wearable terminal 100 with the operator. When the antenna unit 201 of the registration device 200 receives electromagnetic waves, the RF control unit 107 of the wearable terminal 100 transmits the wearable terminal status information via the antenna unit 106 (step S11).

[0062] Next, the RF control unit 202 of the registration device 200 receives the wearing terminal state information via the antenna unit 201 (step S12). The RF control unit 202 obtains the unique ID and the wearing state from the received wearing terminal state information.

[0063] Next, the biometric information acquisition unit 203 acquires the biometric information of the operator (step S13). Specifically, the biometric information acquisition unit 203 acquires the biometric information of the operator using a fingerprint sensor or a biometric information reader that reads biometric information such as veins, voiceprints, or irises.

[0064] Next, the determination unit 204 refers to the biometric information table pre-stored in the data storage unit 206 and determines whether the operator is legitimate based on whether the acquired biometric information is registered (step S14). If the determination unit 204 determines that the acquired biometric information is registered in the biometric information table (step S14; Yes), it associates the operator ID included in the biometric information table with the unique ID acquired in step S12 to generate a Figure 3 The illustrated operator correspondence table is stored in the data storage unit 206 (step S15). Specifically, the determination unit 204 adds the association between the operator ID of the operator whose legitimacy has been confirmed and the unique ID of the wearable terminal 100 to the operator correspondence table that already stores the association between the operator ID of the operator whose legitimacy has been confirmed and the unique ID of the wearable terminal 100.

[0065] Next, the network control unit 207 sends the operator correspondence table generated in step S15 and the operation authority information defining the operation authority of the authenticated operator to the display 300 (step S16). The display 300 stores the received operator correspondence table and operation authority information in the data storage unit 305 (step S17).

[0066] Next, the data control unit 205 reads the removal history from the wearing terminal state information received in step S12 and determines whether a "1" indicating a removal history is stored. If it is determined that a "1" is stored in the removal history, the data control unit 205 rewrites the removal history to "0" via the antenna unit 201 (step S18), and the process ends.

[0067] On the other hand, returning to step S14, when the wearing state obtained in step S12 is "0" indicating a removed state, or when it is determined that the biometric information obtained in step S13 is not registered in the biometric information table, the determination unit 204 determines that the operator is not legal (step S14; No), outputs a message to the effect that the operator is not legal (step S19), displays it on the display unit 26, and ends the processing.

[0068] (Authentication Process)

[0069] Next, refer to Figure 8 , explaining the authentication process of the display 300 to authenticate whether the operator's operation on the operation panel is permitted.

[0070] After the registration process, if the wearable terminal 100 is detected to be removed by the wearable terminal 100 detection unit 102, Figure 2 The "Wearing Status" field of the wearable terminal status information shown is changed to "0," and the "Removal History" field is changed to "1." If the removal detection unit 102 subsequently detects that the operator has worn the wearable terminal 100 again, it changes the "Wearing Status" field of the wearable terminal status information to "1." In this case, the "Removal History" field remains "1." Therefore, if both the "Wearing Status" and "Removal History" fields are "1," there is a possibility that, after the registration process, the wearable terminal 100 was removed from the operator whose legitimacy was verified and worn by another operator.

[0071] Return to Figure 8 , the RF control unit 107 of the wearable terminal 100 transmits the wearable terminal state information via the antenna unit 106 (step S21 ).

[0072] Next, the RF control unit 302 of the display 300 receives the unique ID, wearing status information, and removal history of the wearable terminal 100 via the antenna unit 301. The authentication unit 304 reads the received wearing status information and determines whether the wearable terminal 100 is being worn (step S22). Specifically, the authentication unit 304 receives the received Figure 2 If the wearing status of the illustrated wearing terminal status information is "1," the authentication unit 304 determines that the device is being worn (step S22: Yes), and the process proceeds to step S23. On the other hand, if the wearing status is "0," the authentication unit 304 determines that the device is not being worn (step S22: No), determines that the input operation is not permitted (step S33), and ends the process.

[0073] Return to Figure 8 Then, the authentication unit 304 determines whether there is a history of the wearing terminal 100 being removed (step S23). Specifically, the authentication unit 304 obtains Figure 2If the removal history of the illustrated wearing terminal state information is "1", it is determined that there is a removal history (step S23; Yes), and if the removal history is "0", it is determined that there is no removal history (step S23; No).

[0074] Return to Figure 8 If the authentication unit 304 determines that the history has not been removed (step S23: No), it reads the operator's operation content (step S24). Specifically, the operator's operation content such as logging into the display 300, starting the manufacturing equipment 400, changing settings, operating, and stopping is obtained through the operation of the operation panel performed by the operator.

[0075] Return to Figure 8 Then, the authentication unit 304 determines whether the operation content obtained in step 24 is allowed (step S25). Specifically, the authentication unit 304 refers to the data obtained from the registration device 200 through the registration process. Figure 3 The operator correspondence table shown, Figure 4 The operation permission table shown in FIG. 1 determines whether the operator has the permission to perform the acquired operation. For example, if an operator with operator ID "A0001" performs a login operation on display 300 connected to manufacturing equipment 400 with device ID "X01," authentication unit 304 determines that the operation is permitted (step S25: Yes) based on the operator ID "A0001" having the permission to log in to device ID "X01," and permits execution of the operation (step S26).

[0076] On the other hand, when the authentication unit 304 determines that the operator does not have the authority to perform the operation content acquired in step S14 (step S25 ; No), it does not permit the execution of the operation content (step S29 ).

[0077] Return to Figure 8 Next, the authentication unit 304 determines whether another operation has occurred (step S27). Specifically, if no operation input has occurred for a period of time equal to or greater than a predetermined time, the authentication unit 304 determines that no other operation has occurred (step S27: No), deauthenticates the operator (step S28), and terminates the process. On the other hand, if the operator inputs an operation within the predetermined time, the authentication unit 304 determines that another operation has occurred (step S27: Yes), returns to step S24, and obtains the operation details.

[0078] Returning to step S23, if the authentication unit 304 determines that there is a history of the wearable terminal 100 being removed (step S23; Yes), it determines that the input operation is not allowed (step S30). Then, the authentication unit 304 sends the existence of the removal history along with the unique ID to the registration device 200 via the RF control unit 302 (step S31). The registration device 200 Figure 3 The received unique ID is extracted from the operator correspondence table shown, and the association between the unique ID and the operator ID is deleted from the operator correspondence table (step S32), and the processing ends.

[0079] As described above, during the authentication process to determine whether a user has permission to operate the display 300, the authentication system 1 uses the registration device 200 to determine whether the unique ID of the wearable terminal 100 is the unique ID associated with the authenticated user. Therefore, authentication can be performed without storing personal information such as biometric information in the wearable terminal 100. This allows for more secure authentication of the user.

[0080] Furthermore, the wearable terminal 100's removal detection unit 102 is powered by a power generation unit 103, which includes a power generation module that generates electricity using body heat. Therefore, the wearable terminal 100 does not require a power source such as a battery or storage battery. Furthermore, the wearable terminal 100 stores a unique ID, wearing status, and removal history. Therefore, compared to configurations where the wearable terminal 100 stores biometric information, personal information, and the wearable terminal 100 itself has authentication capabilities, a smaller memory capacity is sufficient, eliminating the need for a high-performance processor. Consequently, the wearable terminal 100 can be manufactured at a low cost.

[0081] As mentioned above, although embodiment of this invention was described, this invention is not limited to the said embodiment.

[0082] In the above embodiment, the manufacturing equipment 400 is not limited to equipment for manufacturing finished products or parts, but can also be production equipment, production machines, or control devices for controlling machines. In this case, for each production equipment, each production machine, and each control device, Figure 4 The operation authority information shown is stored in the data storage unit 206 of the registration device 200. The authentication unit 304 of the display 300 may authenticate whether the operation is permitted based on the operation authority information for each production device, each production machine, and each control apparatus.

[0083] Furthermore, in the above embodiment, the display 300, which is connected to the manufacturing equipment 400 and displays information related to the control of the manufacturing equipment 400, determines the operator's authority. However, this is not limiting. For example, the operation panel itself may have the function of determining the operator's authority, or an authentication device separate from the display 300 may determine the operator's authority based on the content of the operation performed on the input device.

[0084] In the above embodiment, the authentication unit 304 determines that there is no other operation when there is no input for a period of time greater than or equal to a predetermined time, and deauthenticates the operator, but the present invention is not limited to this. For example, the authentication unit 304 may also deauthenticate the operator when it determines that the distance between the wearable terminal 100 and the display 300 is greater than or equal to a predetermined threshold. For example, the authentication unit 304 periodically determines whether it can communicate with the wearable terminal 100. If there is a response from the wearable terminal 100, it determines that the distance between the wearable terminal 100 and the display 300 is less than the threshold. If there is a response, it determines that the distance between the wearable terminal 100 and the display 300 is greater than or equal to the threshold, and deauthenticates the operator.

[0085] Furthermore, in the above embodiment, the registration device 200 obtains the operator's biometric information to verify the operator's legitimacy. However, this is not limiting. Instead of biometric information, the legitimacy can be verified using arbitrary authentication information such as a login ID or password. In this case, the operator ID and authentication information are associated and stored in the data storage unit 206 of the registration device 200. The determination unit 204 can verify legitimacy based on the obtained authentication information and the information associated with the operator ID and authentication information stored in the data storage unit 206.

[0086] In addition, during the authentication process, the display 300 may also display only the operation buttons for executing the operation authorized to the operator on the operation panel. Figure 3 The operator correspondence table shown and Figure 4 The operation authority table shown confirms the operator's operation authority for each operation content, and only the operation buttons for executing the operation content allowed to the operator are displayed on the operation panel, while the operation buttons for executing the operation content not allowed are set to be hidden.

[0087] In the above embodiment, the functions of the registration device 200 and the display 300 are each executed by a single computer, but this is not limiting and the respective processes may be executed by multiple computers. Alternatively, the functions of the registration device 200 and the display 300 may be executed by a single computer.

[0088] Furthermore, the registration device 200 and the display 300 do not need to have separate data storage units 206 and 305. Alternatively, the data stored in the data storage units 206 and 305 may be centrally managed by a cloud server located on the network, and the registration device 200 and the display 300 may access the cloud server as needed to read and write information.

[0089] Furthermore, the functions of the registration device 200 and the display 300 are not limited to dedicated devices and can be implemented using a conventional computer system. For example, a program for implementing the functions of the registration device 200 and the display 300 can be stored on a computer-readable recording medium such as a CD-ROM (Compact Disc Read Only Memory) or DVD-ROM (Digital Versatile Disc Read Only Memory) and distributed. By installing this program on a computer, a computer capable of implementing the aforementioned functions can be constructed.

[0090] Furthermore, when each function is realized by sharing the responsibility between the OS and the application, or by cooperation between the OS and the application, only the application may be stored in the recording medium.

[0091] The configurations described in the above embodiments can be selectively selected and appropriately changed to other configurations without departing from the spirit of the present invention.

[0092] In addition, the present invention can be set as various embodiments and modifications without departing from the broad spirit and scope of the present invention. In addition, the above-mentioned embodiments are used to illustrate the present invention and are not intended to limit the scope of the present invention. That is, the scope of the present invention is not represented by the embodiments, but by the claims. Moreover, various modifications implemented within the scope of the claims and the scope of the disclosure equivalent thereto are considered to fall within the scope of the present invention.

[0093] Description of the label

[0094] 1 Authentication system, 100 Wearing terminal, 200 Registration device, 300 Display, 400 Manufacturing equipment, 101 Sensor unit, 102 Wear / removal detection unit, 103 Power generation unit, 104 Data control unit, 105 Data storage unit, 106 Antenna unit, 107 RF control unit, 108 Voltage generation unit, 201 Antenna unit, 202 RF control unit, 203 Biometric information acquisition unit, 204 Determination unit, 205 Data control unit, 206 Data storage unit, 207 Network control unit, 301 Antenna unit, 302 RF control unit, 303 Data control unit, 304 Authentication unit, 305 Data storage unit, 306 Network control unit, 11, 21 Processor, 12 Memory, 13 Wireless communication unit, 22 RAM, 23 ROM, 24 Storage unit, 25 Input unit, 26 Display unit, 27 Communication unit, 99 Internal bus

Claims

1. An authentication system comprising: a wearable terminal worn by a user; a registration device for registering the user; and an authentication device connected to the production equipment to authenticate whether operations to the production equipment are permitted. In the authentication system, the wearable terminal has: a wearing and removing detection unit, which detects whether the wearable terminal is worn; a wearing terminal information storage unit for storing wearing terminal information, the wearing terminal information including terminal identification information for uniquely identifying the wearing terminal and a detection result obtained by the wearing and removing detection unit; and a wearing terminal information sending unit, which sends the wearing terminal information stored in the wearing terminal information storage unit, The registration device has: a wearing terminal information receiving unit, which receives the wearing terminal information; an authentication information acquisition unit configured to acquire authentication information of the user; as well as A determination unit that confirms the legitimacy of the user based on the obtained authentication information, generates corresponding information, and sends it to the authentication device, wherein the corresponding information is information that associates the user identification information that uniquely identifies the user confirmed to be legitimate with the terminal identification information included in the received wearing terminal information, The authentication device comprises: an operation input unit for receiving an operation to the production equipment; a terminal information receiving unit, which receives the wearing terminal information; a wearing / taking-off determination unit that determines whether the wearing terminal is being worn based on the received wearing terminal information; and An authentication unit, when it is determined that the user is wearing the wearable terminal, determines the user wearing the wearable terminal based on the terminal identification information contained in the received wearable terminal information and the corresponding information sent by the determination unit, and authenticates whether to allow the operation received by the operation input unit based on the permission information indicating whether each user has the operation permission to the production equipment.

2. The authentication system according to claim 1, wherein: The wearing terminal information further includes removal history information indicating a history of the wearing terminal being removed. The authentication unit determines whether there is a history of the wearable terminal being removed based on the removal history information included in the wearable terminal information received by the terminal information receiving unit, and if it is determined that there is such a history, does not permit the operation received by the operation input unit.

3. The authentication system according to claim 1 or 2, wherein: The registration device also has: an authentication correspondence information storage unit that stores authentication correspondence information that associates the authentication information and the user identification information of each user, The determination unit determines the legitimacy of the user based on the authentication correspondence information stored in the authentication correspondence information storage unit and the authentication information acquired by the authentication information acquisition unit.

4. The authentication system according to any one of claims 1 to 3, wherein: The authority information includes information indicating whether or not there is an operation authority for each operation content of the production equipment. The authentication unit determines whether the operation content of the determined user on the production equipment is included in the operation authority granted to the user, and permits execution of the operation content if it is determined that the operation content is included.

5. A wearable terminal, which is worn by the user, The wearable terminal has: a wearing and removing detection unit, which detects whether the wearable terminal is worn; a wearing terminal information storage unit for storing wearing terminal information, the wearing terminal information including terminal identification information for uniquely identifying the wearing terminal and a detection result obtained by the wearing and removing detection unit; and The wearing terminal information transmitting unit transmits the wearing terminal information stored in the wearing terminal information storage unit to an authentication device. The authentication device authenticates whether the user is allowed to operate the production equipment based on the terminal identification information.

6. A display comprising: an operation input unit for receiving an operation to the production equipment; a display unit that displays the operation content received by the operation input unit; a terminal information receiving unit for receiving wearable terminal information, the wearable terminal information including terminal identification information for uniquely identifying a wearable terminal worn by a user and wearing information indicating whether the wearable terminal is being worn; a correspondence information acquisition unit that acquires correspondence information associating user identification information that uniquely identifies the user with the terminal identification information; a wearing / disappearing determination unit configured to determine whether the wearing terminal is being worn based on the received wearing terminal information; as well as An authentication unit, when it is determined that the wearable terminal is being worn, determines the user wearing the wearable terminal based on the terminal identification information contained in the received wearable terminal information and the corresponding information obtained, and authenticates whether to allow the operation received by the operation input unit based on the permission information indicating whether each user has the operation permission to the production equipment.

7. An authentication method comprising the following steps: The computer obtains wearable terminal information, the wearable terminal information including terminal identification information uniquely identifying the wearable terminal worn by the user and a detection result obtained by detecting whether the wearable terminal is worn; The computer obtains authentication information of the user; The computer confirms the legitimacy of the user based on the obtained authentication information and generates corresponding information, which is information that associates user identification information that uniquely identifies the user confirmed to be legitimate with the terminal identification information included in the obtained wearing terminal information; The computer receives an operation to the production equipment; The computer determines whether the wearable terminal is worn based on the wearable terminal information; as well as When it is determined that the wearable terminal is being worn, the computer determines the user wearing the wearable terminal based on the terminal identification information and the corresponding information contained in the wearable terminal information, and authenticates whether the received operation is allowed based on the permission information indicating whether each user has the permission to operate the production equipment.

8. A program that causes a computer to execute the following processing: Obtaining wearable terminal information, the wearable terminal information including terminal identification information that uniquely identifies a wearable terminal worn by a user and a detection result obtained by detecting whether the wearable terminal is worn; Obtaining authentication information of the user; Confirming the legitimacy of the user based on the obtained authentication information, and generating corresponding information, the corresponding information being information that associates user identification information that uniquely identifies the user confirmed to be legitimate with the terminal identification information included in the obtained wearing terminal information; Receive operations to production equipment; Determining whether the wearable terminal is being worn based on the wearable terminal information; as well as When it is determined that the wearable terminal is being worn, the user wearing the wearable terminal is determined based on the terminal identification information and the corresponding information contained in the wearable terminal information, and authentication is performed on whether the received operation is allowed based on the permission information indicating whether each user has the permission to operate the production equipment.

9. A program that causes a computer serving as a registration device for registering a user to execute the following processing: Obtaining wearable terminal information, the wearable terminal information including terminal identification information that uniquely identifies a wearable terminal worn by a user and a detection result obtained by detecting whether the wearable terminal is worn; Obtaining authentication information of the user; and The legitimacy of the user is confirmed based on the obtained authentication information, and corresponding information is generated, which is information that associates user identification information that uniquely identifies the user confirmed to be legitimate with the terminal identification information included in the obtained wearing terminal information.

Citation Information

Patent Citations

  • Electronic key system

    CN107921927A

  • Control method and device for household appliance permission

    CN110531627A

  • Apparatus control system, apparatus, wearing type terminal, and computer program

    JP2022116712A

  • Identity authentication method and wearable device

    WO2016082229A1