Authentication system, portable terminal, display device, authentication method and program
The authorization system uses a portable terminal with a wearing distance detector and biometric authentication to securely authorize users by transmitting unique identification information, addressing security risks in existing systems and enabling cost-effective, battery-less operation.
Patent Information
- Application Number
- DE112023004191
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-04-25
- Publication Date
- 2025-09-04
AI Technical Summary
Existing authorization systems face security vulnerabilities as portable devices storing personal and biometric information can be compromised if lost or stolen, leading to unauthorized access.
An authorization system that includes a portable terminal with a wearing distance detector and biometric authentication, where the terminal transmits unique identification information and detection results to an authorization device, which determines user authorization based on pre-registered biometric data and operation permissions, ensuring secure operation without storing sensitive information on the terminal.
Enhances user authorization security by identifying authorized users through linked biometric data without storing personal information, reducing the risk of unauthorized access and enabling cost-effective, battery-less operation of the portable terminal.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical area
[0001] The present disclosure relates to an authorization system, a wearable terminal, a display device, an authorization method, and a program. State of the art
[0002] In the manufacturing industry, a technique for authorizing a limited number of users to operate equipment is known. For example, Patent Literature 1 describes an authorization system including a wearable device that, upon detecting that the device is worn on a user's arm, receives and stores an input of authorization data for connection to an external device, and the external device determines whether to authorize the user based on the authorization data received from the wearable device. Citation listPatent literature
[0003] Patent Literature 1: Unexamined Japanese Patent Application Laid-Open No. 2000-200315 Brief description of the inventionTechnical problem
[0004] The wearable device stores authorization data, such as personal information and biometric information, in the authorization system. Such information can be exposed / leaked if the wearable device is lost or stolen, for example. The authorization system should therefore be improved to maintain security and authorize users more securely.
[0005] In response to the above problem, an object of the present disclosure is to provide an authorization system, a portable terminal, a display device, an authorization method, and a program that can authorize a user more securely. Solution to the problem
[0006] To achieve the above object, an authorization system according to one aspect of the present disclosure includes a portable terminal that can be carried by a user, a registration device for registering the user, and an authorization device connected to production equipment. The authorization device determines whether an operation on the production equipment should be authorized. The portable terminal includes a wear-distance detector for detecting whether the portable terminal is worn or not, a portable terminal information storage device, and a portable terminal information transmitter. The portable terminal information storage device stores portable terminal information, which includes terminal identification information uniquely identifying the portable terminal, as well as a detection result from the wear-distance detector.The portable terminal information transmitter transmits the portable terminal information stored in the portable terminal information storage. The registration device includes a portable terminal information receiver for receiving the portable terminal information, an authentication information acquirer for acquiring authentication information of the user, and a determination device. The determination device determines whether the user is authenticated based on the acquired authentication information, generates linking information that links user identification information uniquely identifying the authenticated user with the terminal identification information contained in the received portable terminal information, and transmits the linking information to the authorization device.The authorization device includes an operation input device for receiving the operation on the resource, a terminal information receiver for receiving the portable terminal information, a wearing distance determination device for determining whether the portable terminal is being worn based on the received portable terminal information, and an authorization device. The authorization device identifies the user wearing the portable terminal when it is determined that the portable terminal is being worn based on the terminal identification information included in the received portable terminal information and the linkage information sent by the determination device, and determines whether to authorize the operation received by the operation input device based on authorization information indicating whether the user has an operation authorization for the resource. Advantageous effects of the invention
[0007] In the technique according to the above aspect of the present disclosure, the portable terminal carried by the user sends to the authorization device the portable terminal information including the terminal identification information and the detection result of whether the portable terminal is carried. The authorization device identifies the user based on the linkage information sent from the registration device that authenticated the user. The authorization device determines whether to authorize the operation of the resource based on the authorization information of the identified user. This enables more secure user authorization. Short description of the drawings Fig. 1 is a block diagram of an authorization system according to Embodiment 1 of the present disclosure; Fig. 2 is a diagram of exemplary portable terminal state information stored in a data memory in a portable terminal used in Fig. 1 is shown; Fig. Figure 3 is a diagram of an exemplary operator assignment table stored in a data memory in a registration device used in Fig. 1 is shown; Fig. 4 is a diagram of exemplary operator authorization information stored in the data memory in the registration device shown in Fig. 1 is shown; Fig. 5 is a block diagram of the portable terminal of Fig. 1, which represents the physical structure; Fig. Figure 6 is a block diagram of the registration device and a manufacturing device shown in Fig. 1, which represents the physical structure; Fig. 7 is a flowchart of a registration process performed by the authorization system; and Fig. Figure 8 is a flowchart of an authorization process performed by the authorization system. Description of embodiments
[0008] An authorization system, a portable terminal, a display device, an authorization method, and a program according to an embodiment of the present disclosure will be described below with reference to the drawings. Like reference numerals denote like or corresponding components throughout the drawings.
[0009] An authorization system according to the present embodiment is used at a production facility, such as a factory or plant, to determine whether an operator has the authority to operate a manufacturing device installed at the production facility. As shown in Fig. 1, an authorization system 1 includes a portable terminal 100 that can be worn on a body part of an operator, a registration device 200 that registers the operator wearing the portable terminal 100 and a specific ID of the portable terminal 100, and a display device 300 connected to a manufacturing device 400 to display information used to control the manufacturing device 400. The display device 300 is used to perform operations that include inputting parameters for controlling the manufacturing device 400. The display device 300 reads the specific ID of the portable terminal 100 and determines whether an operation on an operation panel included in the display device 300 should be authorized.
[0010] The wearable terminal 100 is wearable on a body part of the operator, such as a wrist or ankle, and is thus portable. The wearable terminal 100 has, for example, a wristband form. The wearable terminal 100 includes, for example, a near-field communication tag (NFC tag) or a wear-removal sensor that detects whether the wearable terminal 100 is worn or removed. The wearable terminal 100 detects whether the wearable terminal 100 is worn or not worn by the operator and stores the detected wear state, a removal history indicating a history of the removal of the wearable terminal 100, and the unique ID of the wearable terminal 100. The registration device 200 acquires biometric information of the operator and identifies the operator.The registration device 200 also registers the identified operator and the specific ID of the portable terminal 100 in a linked manner, and sends the information to the display device 300. The display device 300 reads the specific ID from the portable terminal 100 worn by the operator and refers to an operator's operation authorization preset in the registration device 200 to determine whether to authorize the operation on the operation panel. The display device 300 also reads the removal history from the portable terminal 100, which indicates the history of the removal of the portable terminal 100. If it is determined that the portable terminal 100 has a history of being removed, the display device 300 does not authorize the operation.
[0011] The functional components of the portable terminal 100, the recording device 200 and the display device 300 will now be described.
[0012] The portable terminal 100 includes a sensor 101 that acquires information used to identify the wearing state of the portable terminal 100, a wearing removal detector 102 that detects that the portable terminal 100 has been worn or removed by the operator, a power generator 103 that supplies power to the wearing removal detector 102, a data controller 104 that stores the wearing state and removal history of the portable terminal 100 in a data storage 105, wherein the data storage 105 stores the wearing state and removal history of the portable terminal 100 as well as the specific ID of the portable terminal 100, which is information that uniquely identifies the portable terminal 100, an antenna 106 that transmits and receives wireless signals to and from the registration device 200 and the display device 300 for wireless communication, and a radio frequency controller (HF controller) 107,which controls the antenna 106 to transmit the information stored in the data memory 105, and a voltage generator 108 which generates a voltage to operate the data controller 104 and the data memory 105.
[0013] The sensor 101 acquires the information used to identify the wearing state of the wearable terminal 100, whether worn or not worn by the operator. Examples of the sensor 101 include a temperature sensor that determines body temperature and detects a change in body temperature during the wearing or removal of the wearable terminal 100, a pressure sensor that determines the degree of contact with the operator's body part and detects the pressure based on the degree of contact during the wearing or removal, and an optical sensor that detects the light intensity during the wearing or removal.
[0014] The wear-removal detector 102 determines the wear state, which indicates whether the wearable terminal 100 is being worn or removed by the user, based on the information detected by the sensor 101. Specifically, the wear-removal detector 102 detects the wear or removal of the wearable terminal 100 based on a change in, for example, temperature, pressure, or light detected by the sensor 101.
[0015] The power generator 103 supplies power to the wear distance detector 102. Specifically, the power generator 103 includes a power generation module that generates power using body temperature. When the wearable terminal 100 is worn, the power generator 103 generates power using a difference between the user's body temperature and the outside temperature and supplies the power to the wear distance detector 102.
[0016] The data controller 104 stores the detection result of the wearing state from the wearing removal detector 102 in the data storage 105. Specifically, the data controller 104 causes the data storage 105 to store wearing state information detected by the wearing removal detector 102, which indicates whether the portable terminal 100 is worn or removed by the operator.
[0017] The data storage 105 stores portable terminal information including the specific ID, which is information that uniquely identifies the portable terminal 100, the wearing state of the portable terminal 100, and the history of removing the portable terminal 100. As shown in Fig. As shown in Figure 2, the portable terminal information includes the specific ID indicating the specific ID of the portable terminal 100, the wearing state indicating the wearing state of the portable terminal 100, and the removal history indicating the removal history of the portable terminal 100. The wearing state includes a flag 1 indicating that the portable terminal 100 is being worn by the operator, or a flag 0 indicating that the portable terminal 100 is away from the operator. The removal history includes a flag 1 indicating that the portable terminal 100 has a history of being worn and then removed, or a flag 0 indicating that the portable terminal 100 has a history of being worn and then removed. The data storage 105 is an example of a portable terminal information storage.The specific ID is an example of terminal identification information, and the distance history is an example of distance history information.
[0018] Returning to Fig. 1, the antenna 106 transmits and receives wireless signals to and from the recording device 200 and the display device 300 for wireless communication. The antenna 106 is an example of a portable terminal information transmitter.
[0019] The RF controller 107 controls the antenna 106 to transmit the portable terminal information stored in the data memory 105. Specifically, when the wear-distance detector 102 detects that the portable terminal 100 is being worn by the user, the RF controller 107 controls the antenna 106 to transmit a carrier wave at predetermined intervals or continuously. When the wear-distance detector 102 detects that the portable terminal 100 is being removed, the RF controller 107 controls the antenna 106 to stop transmitting the carrier wave.
[0020] The voltage generator 108 generates a voltage for operating the data controller 104 and the data memory 105. In particular, the voltage generator 108 uses, for example, a preamble signal in an electrical signal received from the antenna 106 to generate the voltage for operating the data controller 104 and the data memory 105, and supplies the voltage to the data controller 104 and the data memory 105.
[0021] The registration device 200 includes an antenna 201 that transmits and receives wireless signals to and from the portable terminal 100 for wireless communication, an RF controller 202 that converts a wireless signal received by the antenna 201 into digital data, a biometric information acquisition device 203 that obtains biometric information, a determination device 204 that determines whether the operator is authenticated, a data controller 205 that generates an operator mapping table that links the authenticated operator to the specific ID of the portable terminal 100, a data storage 206 that stores various pieces of information, and a network controller 207 that transmits and receives data to and from the display device 300.
[0022] The antenna 201 transmits and receives wireless signals to and from the portable terminal 100 for wireless communication. The antenna 201 is an example of a portable terminal information receiver.
[0023] The RF controller 202 converts the wireless signal received by the antenna 201 into digital data. More specifically, the RF controller 202 detects the wireless signal received by the antenna 201 in Fig. 2 from the portable terminal 100 and provides the portable terminal state information to the destination device 204.
[0024] The biometric information acquisition device 203 acquires the operator's biometric information. Specifically, the biometric information acquisition device 203 includes, for example, a fingerprint sensor or a biometric information reader that reads biometric information, such as veins, a voiceprint, or an iris, and acquires the operator's biometric information. The biometric information acquisition device 203 is an example of an authentication information acquisition device.
[0025] The determination device 204 determines whether the operator is authenticated. More specifically, the determination device 204 determines whether the biometric information acquired by the biometric information acquisition device 203 is pre-registered in the registration device 200 to determine whether the operator is authenticated. The determination device 204 refers to biometric data linking information that links the operator ID, which is the information that uniquely identifies the operator and is stored in the data storage 206, with biometric data, such as fingerprint data, a vein pattern, a voiceprint pattern, or an iris pattern, and determines whether the acquired biometric information matches any set of the biometric data.If it is determined that the acquired biometric information matches a set of biometric data, the determining device 204 determines that the operator is authenticated with the acquired biometric information. The operator ID is an example of user identification information, and the biometric data linking information is an example of authorization linking information.
[0026] The data controller 205 creates an operator mapping table that links the operator authenticated by the destination device 204 to the specific ID of the portable terminal 100. As shown in Fig. As shown in Figure 3, the operator mapping table contains the operator ID that uniquely identifies the operator and the specific ID that uniquely identifies the portable terminal 100. The data controller 205 causes the data storage 206 to store the generated operator mapping table. The operator mapping table is an example of link information.
[0027] With further reference to Fig. 1, the data memory 206 stores information about the operator authorization and operation authorization information, which indicates the operation authorization of each operator. In particular, the data memory 206 stores the Fig. 3, which is generated by the data controller 205 and which is shown in Fig. 4. As shown in the figure, the operation authorization information includes the operator ID that uniquely identifies the operator, a device ID that uniquely identifies the manufacturing device 400, and the operation authorization that indicates whether the operator has operation authorization. Each item in the operation authorization includes a flag 1 indicating that the operator has operation authorization, or a flag 0 indicating that the operator does not have operation authorization. In the illustrated example, the operator with operator ID A0001 has the operation authorization to log in to, start, operate, and stop the manufacturing device 400 with device ID X01, and does not have the operation authorization to change settings of the manufacturing device 400 with device ID X01. The data storage 206 is an example of an authorization link information storage.
[0028] Returning to Fig. 1, the network controller 207 sends and receives data to and from the display device 300. More specifically, the network controller 207 sends the operator assignment table generated by the data controller 205 and the operation authorization information of the operator authenticated by the destination device 204 to the display device 300.
[0029] The display device 300 includes an antenna 301 that transmits and receives wireless signals to and from the portable terminal 100 for wireless communication, an RF controller 302 that converts a wireless signal received by the antenna 301 into digital data, a data controller 303 that generates data to be transmitted to the registration device 200, an authorization device 304 that determines whether operation on the resource should be authorized, a data storage 305 that stores various information items, and a network controller 306 that transmits and receives data to and from the registration device 200.
[0030] The antenna 301 transmits and receives wireless signals to and from the portable terminal 100 for wireless communication. The antenna 301 is an example of a terminal information receiver.
[0031] The RF controller 302 converts the wireless signal received from the antenna 201 into digital data. More specifically, the RF controller 302 detects from the portable terminal 100 via the antenna 301 the Fig. 2 and provides the portable terminal status information to the authorizing device 304.
[0032] Returning to Fig. 1, the data controller 303 generates data to be sent to the registration device 200. More specifically, when the authorization device 304 determines that the portable terminal 100 worn by the operator has a history of being removed, the data controller 303 generates a message indicating that the portable terminal 100 has a history of being removed.
[0033] The authorizing device 304 determines whether the portable terminal 100 is being worn, whether the portable terminal 100 has a history of being removed, and whether the operation of the resource should be authorized. More specifically, the authorizing device 304 reads the Fig. 2, which is obtained from the RF controller 302. The authorizer 304 determines that the portable terminal 100 is being worn when the wearing state includes the flag 1, and determines that the portable terminal 100 is being removed when the wearing state includes the flag 0. The authorizer 304 also determines that the portable terminal 100 has a history of being removed when the removal history includes the flag 1, and determines that the portable terminal 100 has no history of being removed when the removal history includes the flag 0. If it is determined that the portable terminal 100 is being removed, or if it is determined that the portable terminal 100 has a history of being removed, the authorizer 304 determines not to authorize the operation by the operator.When it is determined not to authorize the operation, the authorizing device 304 performs an operation such as displaying a black screen on the operation panel, displaying no operation button, or not responding to operations on operation buttons.
[0034] If it is determined that the portable terminal 100 is worn and has no history of being removed, the authorizing device 304 responds to the Fig. 4, which is obtained from the registration device 200, and determines whether a specific operation input on the operation panel should be authorized. For example, when the operator with operator ID A0001 inputs a login operation on the display device 300 connected to the production device 400 with device ID X01, the authorization device 304 refers to the operation authorization information. If the operator has the authority to log in to the production device 400 with device ID X01, the authorization device 304 authorizes the specific operation. The authorization device 304 is an example of a wearing state determination device and an example of a determination device. The operation panel is an example of an operation input device.
[0035] Returning to Fig. 1, the data memory 305 stores the Fig. 3 shown operator assignment table and the one in Fig. 4, which is transmitted by the network controller 207 in the registration device 200.
[0036] Returning to Fig. 1, the network controller 306 sends and receives data to and from the display device 300. More specifically, the network controller 306 receives the Fig. 3 shown operator assignment table and the one in Fig. 4 from the network controller 207 in the registration device 200, and sends the message generated by the data controller 303 indicating that the portable terminal 100 has the history of being removed to the registration device 200. The network controller 306 is an example of a link information acquirer.
[0037] Now, with reference to Fig. Figure 5 describes the physical structure of the portable terminal 100. Both the registration device 200 and the portable terminal 100 include a processor 11 that executes program-based processes, a memory 12 that stores various programs, and a wireless communicator 13 that sends and receives information. These components are interconnected via an internal bus 99.
[0038] Processor 11 reads programs stored in memory 12 and executes the programs. Processor 11 includes, for example, various types of processors, such as a central processing unit (CPU) or a microprocessor unit (MPU). Processor 11 causes data controller 104 to execute processes as the main function provided by the programs.
[0039] Memory 12 includes a storage element such as a read-only memory (ROM) or a random access memory (RAM). Memory 12 stores control programs in advance and stores portable terminal status information. Memory 12 functions as data storage 105.
[0040] The wireless communicator 13 is a communication interface for wireless communication that conforms to wireless communication standards such as Wi-Fi, Bluetooth (registered trademark), NFC, and Zigbee (registered trademark). The wireless communicator 13 functions as the antenna 106 and the RF controller 107.
[0041] Now, with reference to Fig. 6 describes the physical structure of the recording device 200 and the display device 300. Both the recording device 200 and the display device 300 include a processor 21 that executes program-based processes, a RAM 22, which is a volatile memory, a ROM 23, which is a non-volatile memory, a storage device 24 that stores data, an input device 25 that receives input information, a display 26 that visualizes and displays information, a communicator 27 that sends and receives information, and the internal bus 99 that interconnects the components.
[0042] The processor 21 includes a CPU. The processor 21 reads programs stored in the storage device 24 into the RAM 22 and executes the programs to perform various processes. As the main function provided by the programs, the processor 21 causes the RF controller 202, the determination device 204, the data controller 205, the data controller 303, and the authorization device 304 to execute processes.
[0043] The RAM 22 serves as a work area for the CPUs. The ROM 23 stores, for example, a control program executable by the CPU for basic operations of the recorder 200 and the display device 300, and a basic input / output system (BIOS).
[0044] The storage device 24 includes a hard disk drive. The storage device 24 stores programs executable by the CPUs and stores various sets of data used in program execution. The storage device 24 functions as the data memory 206 and the data memory 305.
[0045] Input device 25 is a user interface that includes, for example, a keyboard, a mouse, and a touchscreen. Input device 25 functions as the control panel included in display device 300.
[0046] The display 26 is, for example, a liquid crystal display or an organic electroluminescence (EL) display that visualizes and displays information.
[0047] The communicator 27 includes a network terminator or a radio communication device connected to a network, and a serial interface or a local area network (LAN) interface connected to the network terminator or communication device. The communicator 27 receives an external signal and outputs data specified by the signal to the processor 21. The communicator 27 functions as the antenna 201, the RF controller 202, the network controller 207, the antenna 301, the RF controller 302, and the network controller 306.
[0048] The operation of the authorization system 1 having the above structure will now be described. The authorization system 1 performs a registration process to determine whether the operator carrying the portable terminal 100 is authenticated and to associate the portable terminal 100 with the authenticated operator, as well as an authorization process to determine whether the operation on the operation panel in the display device 300 performed by the operator carrying the portable terminal 100 should be authorized. First, with reference to Fig. 7 the registration process is described. Registration process
[0049] A manager stores the Fig. 4, which specifies the operation authorization of each operator, in advance in the data storage 206 in the registration device 200. The manager creates and stores the operator authorization information for each operation day of a production facility in the data storage 206, for example, based on the operation schedule of each production device 400 and the shift schedule of each operator. The manager also stores a biometric information table, which stores the operator ID and the biometric information in a linked manner, in advance in the data storage 206.When an operator is assigned to the manufacturing site, the manager acquires the operator's biometric data, such as fingerprint data, voiceprint pattern, and iris pattern, to generate the biometric information table, and stores the generated biometric information table in the data storage 206.
[0050] For example, when the operator wears the portable terminal 100 in a changing room in the manufacturing plant, the power generator 103 in the portable terminal 100 generates power using the difference between the operator's body temperature and the outside temperature and supplies the power to the wear-distance detector 102. The wear-distance detector 102 determines that the portable terminal 100 is being worn by the operator, for example, based on a temperature change or the degree of contact detected by the sensor 101, and changes a detection bit from the initial value of LOW to HIGH. The data controller 104 generates the Fig. 2, which includes the specific ID predetermined for the portable terminal 100 and wearing information indicating that the portable terminal 100 is being worn, and causes the data storage 105 to store the portable terminal status information.
[0051] The operator carrying the portable terminal 100 causes the registration device 200 to perform the registration process to associate the portable terminal 100 with the operator. Upon receiving a radio wave from the antenna 201 in the registration device 200, the RF controller 107 in the portable terminal 100 transmits the portable terminal status information via the antenna 106 (step S11).
[0052] The RF controller 202 in the registration device 200 receives the wearable terminal status information via the antenna 201 (step S12). The RF controller 202 acquires the specific ID and the wearing status from the received wearable terminal status information.
[0053] The biometric information acquisition device 203 then acquires the operator's biometric information (step S13). Specifically, the biometric information acquisition device 203 acquires the operator's biometric information using, for example, a fingerprint sensor or a biometric information reader that reads biometric information such as veins, a voiceprint, or an iris.
[0054] The determination device 204 then refers to the biometric information table stored in advance in the data storage 206 and determines whether the operator is authenticated based on whether the acquired biometric information is registered (step S14). If it is determined that the acquired biometric information is registered in the biometric information table (YES in step S14), the determination device 204 generates the Fig. 3, which links the operator ID in the biometric information table to the specific ID acquired in step S12, and stores the operator association table in the data storage 206 (step S15). Specifically, the determination unit 204 adds the link between the operator ID of the newly authenticated operator and the specific ID of the portable terminal 100 to the operator association table that stores the link between the operator ID of the authenticated operator and the specific ID of the portable terminal 100.
[0055] The network controller 207 then sends the operator assignment table generated in step S15 and the operation authorization information specifying the operation authorization of the authorized operator to the display device 300 (step S16). The display device 300 causes the data storage device 305 to store the received operator assignment table and the received operation authorization information (step S17).
[0056] The data controller 205 then reads the removal history from the portable terminal status information received in step S12 and determines whether the flag 1 indicating that the portable terminal has a removal history is stored. If it is determined that the removal history includes the flag 1, the data controller 205 changes the removal history to the flag 0 via the antenna 201 (step S18) and terminates the process.
[0057] Returning to step S14, if the wearing state detected in step S12 includes the flag 0 indicating that the portable terminal 100 is removed, or if it is determined that the biometric information acquired in step S13 is not registered in the biometric information table, the determination device 204 determines that the operator is not authenticated (NO in step S14) and outputs a message indicating that the operator is not authenticated (step S19). The determination device 204 then causes the display 26 to display the message and terminates the process. Authorization process
[0058] The authorization process performed by the display device 300 to determine whether the operation on the control panel performed by the operator should be authorized will now be described with reference to Fig. 8 described.
[0059] After the registration process, when it is determined that the portable terminal 100 is away from the operator, the wear distance detector 102 changes to the state shown in Fig. 2, the wear state to flag 0 and the removal history to flag 1. When it is determined that the portable terminal 100 is worn again by the operator, the wear removal detector 102 changes the wear state to flag 1 in the portable terminal state information. In this case, the flag 1 remains in the removal history. Therefore, if the wear state and the removal history each include flag 1, the portable terminal 100 can have a history of being removed from the authenticated operator and being worn by another operator after the registration process.
[0060] Returning to Fig. 8, the RF controller 107 in the portable terminal 100 transmits the portable terminal state information via the antenna 106 (step S21).
[0061] The RF controller 302 in the display device 300 receives the specific ID, the wearing state information, and the removal history of the portable terminal 100 via the antenna 301. The authorizing device 304 reads the received wearing state information and determines whether the portable terminal 100 is worn (step S22). More specifically, if the wearing state is within the range detected in Fig. If the portable terminal status information shown in Figure 2 includes flag 1, the authorizing device 304 determines that the portable terminal is being carried (YES in step S22) and proceeds to step S23. If the carrying status includes flag 0, the authorizing device 304 determines that the portable terminal is not being carried (NO in step S22) and thus determines not to authorize the input operation (step S33) and ends the process.
[0062] Returning to Fig. 8, the authorizing device 304 determines whether the portable terminal 100 has the history of being removed (step S23). More specifically, if the removal history is included in the acquired portable terminal status information from Fig. 2 contains the flag 1, the authorizing device 304 determines that the portable terminal has a history of being removed (YES in step S23). If the removal history contains the flag 0, the authorizing device 304 determines that the portable terminal has no history of being removed (NO in step S23).
[0063] Returning to Fig. 8, if it is determined that the portable terminal has no history of being removed (NO in step S23), the authorizing device 304 reads the specific operation input by the operator (step S24). Specifically, based on the operator's operation on the control panel, the authorizing device 304 detects the specific operation, such as logging in to the display device 300, starting up, changing the settings, operating, or stopping the manufacturing device 400.
[0064] Returning to Fig. 8, the authorizing device 304 then determines whether the specific operation detected in step 24 is to be authorized (step S25). More specifically, the authorizing device 304 refers to the operator assignment table of Fig. 3 and an operating authorization table of Fig. 4 acquired by the registration device 200 in the registration process, and determines whether the operator has the authority to perform the acquired specific operation. For example, if the operator with operator ID A0001 performs the login operation on the display device 300 connected to the production device 400 with device ID X01, the operator with operator ID A0001 has the authority to log in to the production device 400 with device ID X01. The authorization device 304 thus determines to authorize the specific operation (YES in step S25) and authorizes the execution of the specific operation (step S26).
[0065] When it is determined that the operator does not have authorization for the specific operation detected in step S24 (NO in step S25), the authorizing means 304 determines not to authorize the execution of the specific operation (step S29).
[0066] Returning to Fig. 8, the authorizing device 304 then determines whether another operation is being input (step S27). Specifically, if no operation has been input for a predetermined period of time or longer, the authorizing device 304 determines that no further operation is being input (NO in step S27), deauthorizes the operator (step S28), and terminates the process. If an operation is input from the operator within a predetermined period of time, the authorizing device 304 determines that another operation is being input (YES in step S27) and returns to step S24 to detect the specific operation.
[0067] Returning to step S23, if it is determined that the portable terminal 100 has a history of being removed (YES in step S23), the authorizing device 304 determines not to authorize the input operation (step S30). The authorizing device 304 then sends a message indicating that the portable terminal has a history of being removed to the registering device 200 via the RF controller 302, along with the specific ID (step S31). The registering device 200 extracts the received specific ID from the Fig. 3, deletes the link between the specific ID and the operator ID from the operator assignment table (step S32), and ends the process.
[0068] As described above, in the authorization process, to determine whether the operator has the operation authority for the display device 300, the authorization system 1 determines whether the specific ID of the portable terminal 100 matches the specific ID assigned to the operator authenticated by the registration device 200. Thus, the authorization process can be performed without storing personal information, such as biometric information, in the portable terminal 100. This enables more secure operator authorization.
[0069] The wear-distance detector 102 in the wearable terminal 100 operates with power supplied by the power generator 103, which includes the power generation module that generates power using body temperature. This allows the wearable terminal 100 to operate without a power supply such as a battery or a secondary battery. In addition, the wearable terminal 100 stores the specific ID, the wear state, and the removal history. The wearable terminal 100 can thus operate with a smaller memory capacity and lower processing power than a structure in which the wearable terminal 100 stores, for example, biometric information or other personal information and has the authorization function. This allows the wearable terminal 100 to be manufactured at a lower cost.
[0070] Although the embodiment of the present disclosure is described above, the present disclosure is not limited to the above embodiment.
[0071] In the above embodiment, the manufacturing device 400 is not limited to a device for manufacturing finished products or components, and may be a manufacturing device or a tool for manufacturing products, or may be a control device for controlling devices. In this case, the Fig. 4 may be stored in the data memory 206 in the registration device 200 for each piece of equipment, each piece of production equipment, or each control device. The authorization device 304 in the display device 300 may determine whether the operation should be authorized based on the operation authorization information for each piece of equipment, each piece of production equipment, or each control device.
[0072] In the above embodiment, the display device 300 connected to the manufacturing device 400 determines the operator's authorization to display the information used to control the manufacturing device 400. However, the structure is not limited to this example. For example, the operation panel may have the function of determining the operator's authorization, or an authorization device other than the display device 300 may determine the operator's authorization based on the specific operation input to an input device.
[0073] In the above embodiment, if no operation is input for a predetermined period or longer, the authorizing device 304 determines that no other operation is input and deauthorizes the operator. However, the structure is not limited to this example. For example, the authorizing device 304 may deauthorize the operator if it is determined that the distance between the portable terminal 100 and the display device 300 is greater than or equal to a predetermined threshold. For example, the authorizing device 304 may periodically determine whether the display device 300 can communicate with the portable terminal 100.If the portable terminal 100 responds, the authorizing device 304 may determine that the distance between the portable terminal 100 and the display device 300 is less than the threshold, and if the portable terminal 100 responds, the authorizing device 304 may determine that the distance between the portable terminal 100 and the display device 300 is greater than or equal to the threshold and deauthorize the operator.
[0074] In the above embodiment, the registration device 200 obtains the operator's biometric information to determine whether the operator is authenticated. In some embodiments, the registration device 200 may determine whether the operator is authenticated based on any authentication information, such as a login ID or password, instead of the biometric information. In this case, the data storage 206 in the registration device 200 may store the operator ID and the authentication information in a linked manner, and the determination device 204 may perform authentication based on the obtained authentication information and the information stored in the data storage 206 that links the operator ID to the authentication information.
[0075] During the authorization process, the display device 300 may simply display an operation button on the control panel for performing an operation for which the operator has the operation authorization. Specifically, after step S23, the display device 300 may access the Fig. 3 shown operator assignment table and the one in Fig. 4 to determine the operator's operation authority for each specific operation. The display device 300 can then simply display the operation button for executing the operation for which the operator has the operation authority and hide the operation buttons for executing the operations for which the operator does not have the authority.
[0076] In the above embodiment, a single computer performs the functions of both the registration device 200 and the display device 300. In some embodiments, multiple computers may perform the processes of both the registration device 200 and the display device 300. A single computer may perform the functions of the registration device 200 and the functions of the display device 300.
[0077] The registration device 200 need not include the data storage 206, and the display device 300 need not include the data storage 305. The information stored in the data storage 206 and the data storage 305 can be jointly managed by a cloud server on a network, and the registration device 200 and the display device 300 can access the cloud server as needed to read or write information.
[0078] The functions of the recording device 200 and the display device 300 may be implemented by a common computer system rather than by dedicated devices. For example, programs for implementing the functions of the recording device 200 and the display device 300 may be stored, distributed, and installed in a computer on a non-transitory computer-readable recording medium, such as a compact disc read-only memory (CD-ROM) or a digital versatile disc read-only memory (DVD-ROM), to implement the above functions.
[0079] If the functions are implemented by the operating system (OS) and an application in a joint manner or through cooperation between the operating system (OS) and the application, the application alone may be stored in a non-volatile recording medium.
[0080] The components described in the above embodiment may be selected or modified as needed without departing from the spirit and scope of the present disclosure.
[0081] The foregoing describes some exemplary embodiments for illustrative purposes. Although the foregoing discussion has shown specific embodiments, those skilled in the art will recognize that changes may be made in form and detail without departing from the broader spirit and scope of the invention. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense. This detailed description, therefore, is not to be taken in a limiting sense, and the scope of the invention will be defined only by the appended claims, along with the full range of equivalents to which such claims are entitled. List of reference symbols 1 Authorization system 100 portable devices 200 registration device 300 ad 400 manufacturing devices 101 Sensor 102 Wear Distance Detector 103 power generators 104 Data Controller 105 data storage 106 Antenna 107 RF controllers 108 voltage generators 201 Antenna 202 RF controller 203 Biometric Information Capture Device 204 Destination facility 205 Data Controller 206 data storage 207 Network Controller 301 Antenna 302 RF controller 303 Data Controller 304 Authorization device 305 data storage 306 Network Controller 11, 21 processor 12 storage 13 Wireless Communicator 22 RAM 23 ROM 24 storage device 25 Input device 26 Advertisement 27 Communicator 99 Internal Bus QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] JP 2000 - 200 315
[0003]
Claims
[1] Authorization system comprising: a portable terminal that can be carried by a user; a registration device for registering the user; and an authorization device connected to a piece of equipment and configured to determine whether an operation on the equipment should be authorized, wherein the portable terminal comprises: a wear-distance detector for detecting whether the portable terminal is worn or not worn, a portable terminal information storage device for storing portable terminal information including terminal identification information uniquely identifying the portable terminal and a detection result from the wear distance detector, and a portable terminal information transmitter for transmitting the portable terminal information stored in the portable terminal information storage device, the registration device comprising: a portable terminal information receiver for receiving the portable terminal information, an authentication information acquirer for acquiring authentication information of the user, and a determination device for determining, based on the acquired authentication information, whether the user is authenticated, for generating linking information that links user identification information that uniquely identifies the authenticated user with the terminal identification information contained in the received portable terminal information, and for sending the linking information to the authorization device, and the authorization device comprising: an operating input device for receiving the operation on the equipment, a terminal information receiver for receiving the portable terminal information, a carrying distance determining means for determining whether the portable terminal is carried based on the received portable terminal information, and an authorization device for identifying the user carrying the portable terminal when it is determined that the portable terminal is carried, based on the terminal identification information included in the received portable terminal information and the link information sent by the determination device, and for determining whether the operation received by the operation input device should be authorized based on authorization information indicating whether the user has an operation authorization for the resource. [2] Authorization system according to claim 1, wherein the portable terminal information further includes removal history information indicating a history of removal of the portable terminal, and the authorizing device determines whether the portable terminal has a history of being removed based on the history of being removed included in the portable terminal information received by the terminal information receiver, and if it is determined that the portable terminal has the history, the authorizing device does not authorize the operation received by the operation input device. [3] Authorization system according to claim 1 or 2, wherein the registration device further comprises an authentication link information storage for storing authentication link information linking the user's authentication information to the user identification information, and the determining means determines whether the user is authenticated based on the authentication link information stored in the authentication link information storage and the authentication information acquired by the authentication information acquirer. [4] Authorization system according to one of claims 1 to 3, wherein the authorization information includes information indicating whether the user has the authorization to perform a specific operation on the equipment, and the authorizing device determines whether the specific operation on the equipment by the identified user is included in the operating authorization of the identified user, and if it is determined that the specific operation is included, the authorizing device authorizes the execution of the specific operation. [5] A portable terminal that can be carried by a user, the portable terminal comprising: a wear-distance detector for detecting whether the portable terminal is worn or not worn; a portable terminal information storage device for storing portable terminal information including terminal identification information uniquely identifying the portable terminal and a detection result from the wear-distance detector; and a portable terminal information transmitter for transmitting the portable terminal information stored in the portable terminal information storage device to an authorization device, wherein the authorization device is configured to determine whether the user should be authorized to perform an operation on the resource based on the terminal identification information. [6] Display device, comprising: an operator input device for receiving an operator input to a piece of equipment; a display for displaying a specific operation received from the operation input device; a terminal information receiver for receiving portable terminal information including terminal identification information that uniquely identifies a portable terminal that can be carried by a user, and for receiving carrying information that indicates whether the portable terminal is carried; a linking information acquirer for acquiring linking information that links user identification information that uniquely identifies the user with the terminal identification information; a carrying distance determining means for determining whether the portable terminal is carried based on the received portable terminal information; and an authorization device for identifying the user carrying the portable terminal when it is determined that the portable terminal is carried based on the terminal identification information included in the received portable terminal information and the acquired linkage information, and for determining whether the operation received by the operation input device should be authorized based on authorization information indicating whether the user has an operation authorization for the resource. [7] An authorization method that can be implemented with a computer, the method comprising: Acquiring portable terminal information including a portable terminal that can be worn by a user, terminal identification information uniquely identifying it, and a detection result of detecting wearing or not wearing the portable terminal; Acquiring user authentication information; Determining, based on the acquired authentication information, whether the user is authenticated, and generating linking information that links user identification information uniquely identifying the authenticated user to the terminal identification information included in the acquired portable terminal information; Receiving an operation on a piece of equipment; Determining whether the portable terminal is being worn based on the portable terminal information; and Identifying the user carrying the portable terminal when it is determined that the portable terminal is carried based on the terminal identification information included in the portable terminal information and the linkage information, and determining whether to authorize the received operation based on authorization information indicating whether the user has an operation authority for the resource. [8] A program for causing a computer to perform operations, comprising: Acquiring portable terminal information including a portable terminal that can be worn by a user, terminal identification information uniquely identifying it, and a detection result of detecting wearing or not wearing the portable terminal; Acquiring user authentication information; Determining, based on the acquired authentication information, whether the user is authenticated, and generating linking information that links user identification information uniquely identifying the authenticated user to the terminal identification information included in the acquired portable terminal information; Receiving an operation on a piece of equipment; Determining whether the portable terminal is being worn based on the portable terminal information; and Identifying the user carrying the portable terminal when it is determined that the portable terminal is carried based on the terminal identification information included in the portable terminal information and the linkage information, and determining whether to authorize the received operation based on authorization information indicating whether the user has an operation authority for the resource. [9] A program executable by a computer which is a registration device for registering a user, the program causing the computer to perform operations comprising: Acquiring portable terminal information including a portable terminal that can be worn by a user, terminal identification information uniquely identifying it, and a detection result of detecting wearing or not wearing the portable terminal; Acquiring user authentication information; and Determining, based on the acquired authentication information, whether the user is authenticated, and generating linking information that links user identification information uniquely identifying the authenticated user to the terminal identification information included in the acquired portable terminal information.
Citation Information
Patent Citations
JP002017107387A
JP002006048470A