Authentication program, authentication device, and authentication system
The authentication system addresses security and cost challenges by using a mobile phone's telephone number for authentication, incorporating password and location-based security measures, thereby enhancing security and reducing costs.
Patent Information
- Application Number
- JP2023181335
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-20
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2043-10-20
AI Technical Summary
Existing authentication systems for restricted entry zones in apartment complexes and commercial facilities face challenges in security, particularly with password-based systems that can be vulnerable to impersonation and biometric systems that require dedicated devices, increasing costs.
An authentication program and system that uses a mobile phone's telephone number for authentication, incorporating password authentication, location-based region-specific telephone numbers, and scheduled usage information to enhance security while reducing costs.
The system improves security by utilizing a unique telephone number for authentication, reduces costs by eliminating the need for dedicated biometric devices, and ensures secure access by limiting usage to region-specific and scheduled times.
Smart Images

Figure 2025070789000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an authentication program, an authentication device, and an authentication system, and more particularly to an authentication program, an authentication device, and an authentication system that perform authentication processing using a telephone number. [Background technology]
[0002] Generally, buildings such as apartment buildings or commercial facilities have restricted access areas where shared facilities such as an electrical room, an elevator machine room, and a water tank room are installed. Such restricted access areas are locked and controlled with a key, and entry is restricted. Therefore, when a maintenance worker is performing maintenance work on the shared facilities, he or she must borrow a key to enter the restricted access area from the manager or security officer. Therefore, if the manager or security officer is absent, not only is it impossible to borrow the key, but it also leads to a delay in the maintenance work.
[0003] Therefore, a key management system has been proposed that allows the lending and returning of keys even when the building manager or security officer is absent. Patent Document 1 discloses a security system that allows a specific person who has been given authority in advance to enter the manager's room and obtain a key to enter the restricted access area, even if the manager is absent due to being caught up in a natural disaster or other trouble. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2015-151739 A Summary of the Invention [Problem to be solved by the invention]
[0005] The technology disclosed in the above-mentioned Patent Document 1 allows a specific person to enter the caretaker's room and borrow a key even when the caretaker is absent. However, further improvements are desired for the valuables management system described in Patent Document 1. In other words, in consideration of the importance of security in restricted access areas such as apartment complexes and commercial facilities, there is a need for improved security of an authentication system that determines the legitimacy of a person entering a restricted access area.
[0006] Specifically, the technology disclosed in Patent Document 1 uses an authentication password and biometric information (fingerprint or iris) to authenticate a person entering a restricted access area. However, an authentication system using a password has a problem in that it cannot prevent impersonation if the password becomes known to a third party. In addition, a biometric authentication system requires a dedicated device to obtain biometric information, which incurs implementation costs.
[0007] The present invention has been made in consideration of the above problems, and an object of the present invention is to provide an authentication program, an authentication device, and an authentication system that can improve security while reducing costs by performing authentication using the telephone number of a mobile phone terminal used by a user. [Means for solving the problem]
[0008] According to the authentication program of the present invention, the above problem is solved by having a computer of an authentication system using the telephone number of a mobile phone terminal used by a user function as: a registration information accepting means for accepting the authentication password of the user and the telephone number of the mobile phone terminal as registration information; a password authentication means for performing password authentication using the authentication password; a location information acquiring means for acquiring location information of the user from the mobile phone terminal; a telephone number notifying means for notifying the mobile phone terminal of the user who has succeeded in the password authentication of a regional telephone number associated with the location information acquired by the location information acquiring means; a calling information acquiring means for acquiring, when an incoming call is received to the regional telephone number, calling information including a calling telephone number related to the incoming call; and a telephone number authentication means for comparing the calling telephone number acquired by the calling information acquiring means with the telephone number accepted by the registration information accepting means.
[0009] According to the above configuration, the authentication program causes the computer of the authentication system to function as a password authentication means for authenticating a user using an authentication password, and as a telephone number authentication means for authenticating a user using the telephone number of the user's mobile phone terminal. Therefore, since the user is authenticated using a telephone number that cannot be forged without introducing a dedicated device for acquiring biometric information, it is possible to improve security while suppressing costs. The authentication program also notifies the user of a pre-assigned area-specific telephone number based on the user's location information, and waits for an incoming call to the pre-assigned area-specific telephone number. Therefore, by not allowing the use of a mobile phone terminal located outside the pre-assigned area, it is possible to prevent a user located in an inappropriate location from using the authentication system, thereby improving security.
[0010] In addition, the authentication program causes the computer to function as a schedule information receiving means for receiving schedule information including a scheduled time of use of the authentication system, and when the call information acquiring means receives an incoming call to the area-specific telephone number, it acquires the calling telephone number and the incoming call time related to the incoming call, and the telephone number authentication means compares the incoming call time with the scheduled time of use. According to the above configuration, the authentication program receives schedule information including the scheduled time of use of the authentication system, compares the incoming call time for the area-specific telephone number with the scheduled time of use, and performs user authentication, thereby making it possible to further improve security.
[0011] The area-specific telephone number may be associated with the output of a one-way function to which at least one of the location information and the scheduled use time is input. According to the above configuration, the area-specific telephone number is associated with the output obtained when at least one of the location information and the scheduled time of use is input to the one-way function. Therefore, it becomes difficult to guess the scheduled time of use from the area-specific telephone number, and it is possible to further improve security.
[0012] In addition, the scheduled information may include a planned location where the user plans to use the authentication system, together with the planned time of use, and the telephone number authentication means may compare the planned location of use with the location information acquired by the location information acquisition means. According to the above configuration, the authentication program compares the user's location information with the intended use location to perform user authentication, thereby improving security.
[0013] In addition, the authentication program may cause the computer to function as an unlocking permission signal transmitting means for transmitting an unlocking permission signal to the valuables storage device which stores one or more valuables related to a building and is managed for locking and unlocking when matching by the telephone number authentication means is successful. According to the above configuration, it is possible to improve security while suppressing costs in locking and unlocking a valuables storage device that stores valuables in a building.
[0014] The telephone number notifying means may transmit to the valuables storage device a telephone number display instruction signal for causing a display unit of the valuables storage device to display the area-specific telephone number. According to the above configuration, the area-specific telephone number is displayed on the display unit of the valuables storage device, so that the user can easily grasp the area-specific telephone number.
[0015] In addition, the valuables storage device is equipped with an identification information reading means for reading user identification information capable of identifying the user from an identification information storage medium carried by the user, and the authentication program causes the computer to function as a user identification information acquisition means for acquiring the user identification information read by the identification information reading means and a user identification information authentication means for verifying the user identification information, the registration information accepting means accepts the user identification information as registration information together with the location information and the telephone number, and the user identification information authentication means compares the user identification information acquired by the user identification information acquisition means with the user identification information accepted by the registration information accepting means. According to the above configuration, the authentication program performs user authentication using user identification information (personal identification information such as a driver's license number or a My Number) stored in an identification information storage medium possessed by the user. This makes it possible to improve security while suppressing costs.
[0016] The authentication device may further include a computer, and the computer may be caused to execute the authentication program. According to the above configuration, the authentication device includes a password authentication means for authenticating a user using an authentication password, and a telephone number authentication means for authenticating a user using the telephone number of the user's mobile phone terminal. Therefore, since the user is authenticated using a telephone number that cannot be forged without introducing a dedicated device for acquiring biometric information, it is possible to improve security while suppressing costs. The authentication device also notifies the user of a pre-assigned area-specific telephone number based on the user's location information and waits for incoming calls to the pre-assigned area-specific telephone number. Therefore, by not allowing the use of a mobile phone terminal located outside the pre-assigned area, it is possible to prevent a user located in an inappropriate location from using the authentication system, thereby improving security.
[0017] The authentication system may include an authentication device and a valuables storage device. According to the above configuration, the authentication system includes a password authentication means for authenticating a user using an authentication password, and a telephone number authentication means for authenticating a user using the telephone number of the user's mobile phone terminal. Therefore, since the user is authenticated using a telephone number that cannot be forged without introducing a dedicated device for acquiring biometric information, it is possible to improve security while suppressing costs. The authentication system also notifies the user of a pre-assigned area-specific telephone number based on the user's location information, and waits for incoming calls to the pre-assigned area-specific telephone number. Therefore, by not allowing the use of a mobile phone terminal located outside the pre-assigned area, it is possible to prevent users located in inappropriate locations from using the authentication system, thereby improving security. Effect of the Invention
[0018] According to the authentication program, authentication device, and authentication system of the present invention, by performing authentication using the telephone number of the mobile phone terminal used by the user, it is possible to suppress costs and improve security. [Brief description of the drawings]
[0019] [Figure 1] FIG. 1 is a diagram for explaining an overview of an authentication system. [Diagram 2] FIG. 1 is a diagram for explaining an overview of authentication processing. [Diagram 3] FIG. 2 is a diagram illustrating a configuration of an authentication server. [Figure 4] Data structure of user database [Diagram 5] FIG. 4 is a diagram illustrating an example of a data structure of a schedule information database. [Figure 6] FIG. 11 is a diagram showing a sequence of authentication processing. [Figure 7] FIG. 13 is a diagram illustrating an overview of a valuables management system according to a second embodiment. [Figure 8] 1 is a perspective view of the entrance key storage box with the entrance key storage space closed; FIG. [Figure 9] 1 is a perspective view of the entrance key storage box with the entrance key storage space open; FIG. [Figure 10] 2 is a perspective view of the equipment key storage box with the equipment key storage space closed; FIG. [Figure 11] 1 is an oblique view of the equipment key storage box with the equipment key storage space open; FIG. [Figure 12] FIG. 2 is a diagram illustrating a configuration of a key management server. [Figure 13] FIG. 2 is a diagram showing a configuration of a maintenance company database. [Figure 14] FIG. 2 is a diagram illustrating an example of a data structure of a key use schedule database. [Figure 15] FIG. 2 is a diagram illustrating an example of a data structure of a key usage history database. [Figure 16] FIG. 2 is a diagram showing the configuration of an entrance key storage box. [Figure 17]1A and 1B are diagrams showing the configuration of an equipment key storage box. [Figure 18] FIG. 11 is a diagram showing the sequence of an entrance key lending process. [Figure 19] 13 shows a flow of a facility key lending process. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0020] An authentication system 1 according to one embodiment of the present invention (hereinafter, this embodiment) will be described below with reference to Figures 1 to 6. However, the embodiment described below is merely an example for facilitating understanding of the present invention, and does not limit the present invention. In other words, the present invention may be modified or improved without departing from the spirit thereof, and the present invention naturally includes equivalents thereof.
[0021] <<Overview of Authentication System 1>> FIG. 1 is a diagram illustrating an overview of an authentication system 1. As shown in FIG. The authentication system 1 mainly comprises an authentication server 10 and a mobile phone terminal 20. The authentication server 10 is a server device that provides an authentication service to a user who uses a mobile phone terminal 20. The authentication server 10 is operated by a service provider that provides information services and management services. The information services are paid news distribution and content (music, video content, etc.) distribution, and include a distribution service of limited information for specific users. In addition, the management services include a valuables storage box usage management service, as will be described in the second embodiment.
[0022] The mobile phone terminal 20 is an information communication terminal operated by a person who receives the provision of an information service. The mobile phone terminal 20 is used when registering account information and scheduled use information in the authentication server 10 prior to using the service. The mobile phone terminal 20 is also used when the user receives the provision of the service. The mobile phone terminal 20 is a smartphone, but is not limited to this. The mobile phone terminal 20 may be a mobile communication terminal prior to the third generation.
[0023] The flow of user authentication by the authentication system 1 will be described below with reference to FIG. [1] Prior to using the authentication system 1, the user registers account information and planned use information. Specifically, the user registers account information when using the authentication system 1 for the first time. The account information includes a user ID, a password, a user name, the telephone number of the mobile phone terminal 20 used by the user, and an email address. However, without being limited to this, the account information may also include the user's date of birth, etc.
[0024] The user also operates the mobile phone terminal 20 to register planned use information. Here, the planned use information includes a user ID, planned use date, planned use time, and place of use (corresponding to planned use location). However, the planned use information is not limited to this. The planned use information may include information that can identify the service to be used.
[0025] [2] When receiving an information service, the user operates the mobile phone terminal 20 to request password authentication. Specifically, the user accesses a website for password authentication using a specified URL. Next, the user inputs a user ID and a password into an ID input field and a password input field displayed on the website for password authentication, and sends the input to the authentication server 10 to request password authentication. Here, the user ID and the password are encrypted to prevent unauthorized acquisition of the user ID and the password by a third party.
[0026] Moreover, the mobile phone terminal 20 transmits location information of the mobile phone terminal 20 to the authentication server 10. Specifically, the mobile phone terminal 20 includes a GPS receiver, and acquires location information including the latitude, longitude, and altitude of the mobile phone terminal 20 based on a GPS positioning signal received by the GPS receiver, and transmits this to the authentication server 10.
[0027] [3] Upon receiving the password authentication request, the authentication server 10 performs password authentication. Specifically, the authentication server 10 performs user authentication by comparing the received user ID and password with the user ID and password in the registered account information.
[0028] [4] If the password authentication is successful, the authentication server 10 notifies the mobile phone terminal 20 of the region-specific telephone number. Specifically, the authentication server 10 notifies the mobile phone terminal 20 of the region-specific telephone number to the email address of the mobile phone terminal 20. The region-specific telephone number is a telephone number that is assigned based on the user's location information acquired in [2] from among multiple authentication telephone numbers available to the authentication server 10 in order to perform telephone number authentication. The authentication server 10 may also assign the region-specific telephone number based on the scheduled use time registered as scheduled use information of the service in addition to the location information. Details of the region-specific telephone numbers will be described later with reference to FIG. 2.
[0029] [5] Upon receiving the notification of the regional telephone number, the user operates the mobile phone terminal 20 to request telephone number authentication. In other words, the mobile phone terminal 20 makes a call to the notified regional telephone number. The authentication server 10 obtains the telephone number (calling telephone number) of the caller's mobile phone terminal 20 by receiving a call to the regional telephone number.
[0030] [6] Upon receiving the request for telephone number authentication, the authentication server 10 performs telephone number authentication. Specifically, the authentication server 10 performs user authentication by comparing the calling telephone number with registered telephone numbers.
[0031] [7] If the telephone number authentication is successful, the authentication server 10 provides the service to the user. At this time, the telephone line between the user's mobile phone terminal 20 and the authentication server 10 is not connected. This makes it possible to provide the service while preventing the occurrence of telephone charges associated with connecting the telephone line. Note that, although the service is provided by the authentication server 10 in FIG. 1, it goes without saying that the service may be provided by another server operated by a service provider.
[0032] The above is an overview of the authentication process by the authentication server 10. As described above, the authentication server 10 performs user authentication by combining password authentication using a password and telephone number authentication using a telephone number. As a result, compared to using biometric information (fingerprint, iris, etc.), there is no need to introduce a dedicated device for acquiring biometric information, and user authentication is performed using a telephone number that cannot be forged, making it possible to improve security while suppressing costs.
[0033] <<Authentication process overview>> Next, an overview of the authentication process will be described. 2 is a diagram for explaining an overview of the above-mentioned authentication process. As described above, password authentication and telephone number authentication are performed in the authentication system 1. Since the password authentication is performed by a known method, a detailed description thereof will be omitted.
[0034] Regarding telephone number authentication, the authentication server 10 has a regional telephone number table 11c in which regions are associated with regional telephone numbers assigned to each region. Regional telephone numbers are toll-free telephone numbers that the authentication server 10 can use, and the fifth and sixth digits following "0120" are assigned to correspond to a specific region. In FIG. 2, a toll-free telephone number is assigned to each "ward" that is an administrative division within Tokyo, but this is not limiting. A telephone number may be assigned to each prefecture, or a telephone number may be assigned to a specific address.
[0035] The authentication server 10 acquires the location information of the mobile phone terminal 20, and judges in which of the multiple regions defined in the region-specific telephone number table 11c the mobile phone terminal 20 is located. When it is judged that the mobile phone terminal 20 is located in any of the regions, the authentication server 10 notifies the mobile phone terminal 20 of the region-specific telephone number associated with that region. Specifically, the authentication server 10 acquires the email address of the mobile phone terminal 20 of the user who has succeeded in password authentication from the registered account information, and transmits the region-specific telephone number. In addition, the authentication server 10 acquires the telephone number of the mobile phone terminal 20 from the registered account information, and registers it as an authentication telephone number in the region-specific telephone number table 11c. The authentication telephone number is a telephone number that is a target for matching in telephone number authentication. When the authentication server 10 receives an incoming call to a region-specific telephone number, it acquires the calling telephone number related to the incoming call and checks whether the calling telephone number is a valid user by comparing the calling telephone number with the authentication telephone number.
[0036] On the other hand, if it is determined that the mobile phone terminal 20 is not located in any of the areas defined in the area-specific telephone number table 11c, the user authentication fails. This makes it possible to determine that an incoming call from outside the area covered by the authentication system 1 is an unauthorized incoming call.
[0037] As shown in Figure 2, the four digits from the seventh to the tenth digits of the regional telephone number are assigned in correspondence with the scheduled time of use of the information service (numerals indicating hours and minutes). By assigning regional telephone numbers in correspondence with the scheduled time of use in this way, the scheduled time of use can be checked against the actual time of incoming calls, and if an incoming call occurs during a time period when use is not scheduled, it can be determined that the incoming call is fraudulent. Note that the method of assigning regional telephone numbers is not limited to the method shown in Figure 2. The scheduled start time of use and the scheduled end time of use may also be assigned to the regional telephone number.
[0038] 2, the location information and the scheduled use time of the mobile phone terminal 20 are directly associated with the 5th to 10th six digits of the area-specific telephone number, but this is not limiting. The output of at least one of the location information and the scheduled use time of the mobile phone terminal 20 inputted into a one-way function (e.g., a hash function) may be associated with the 5th to 10th six digits of the area-specific telephone number. This makes it difficult to guess the scheduled use time from the area-specific telephone number, making it possible to improve security.
[0039] <Configuration of authentication server 10> Next, the configuration of the authentication server 10 will be described. Fig. 3 shows the configuration of the authentication server 10. As shown in Fig. 3, the authentication server 10 mainly includes a storage device 11, a control device 12, an input device 13, and a communication device 14.
[0040] The storage device 11 is a non-volatile auxiliary storage device consisting of a hard disk drive (HDD) or a solid state drive (SSD), etc. The storage device 11 stores a user database 11a, a schedule information database 11b, and a region-specific telephone number table 11c, as well as an authentication program executed by the control device 12.
[0041] The user database 11a stores account information of users who use the authentication system 1. The user database 11a is updated when a user who uses the authentication system 1 for the first time performs user registration prior to using the authentication system 1. Fig. 4 shows an example of the data structure of the user database 11a. As shown in Fig. 4, the user database 11a stores data records including a user ID, a password, a user name, a telephone number, and an email address.
[0042] The user ID is a character string consisting of alphanumeric characters, and is identification information capable of identifying a user of the authentication system 1. The password corresponding to the authentication password is an authentication password used for password authentication. The password is stored in an encrypted state in the user database 11a. The user name is the name of the user, and the telephone number and email address are the telephone number and email address of the mobile phone terminal 20 used by the user.
[0043] The schedule information database 11b stores information about a schedule for using a service. When a user wishes to use a service, the user accesses the authentication server 10 in advance to register schedule information. Fig. 5 shows an example of the data structure of the schedule information database 11b. As shown in Fig. 5, the schedule information database 11b stores data records including a schedule ID, a user ID, a scheduled date of use, a scheduled time of use, and a location of use.
[0044] The schedule ID is an identification number capable of identifying schedule information, and is automatically assigned by the schedule information registration unit 12b. The user ID is the user ID of the user who registered the schedule information, and is input by the user. The scheduled use date and scheduled use time are information relating to the scheduled date and time of use of the service, and are also the scheduled date and time when the authentication process by the authentication system 1 is to be performed. The location of use is the location where the service is to be provided. In the case of an information service distributed nationwide via an Internet line, the location of use is, for example, the user's home address. In the case of a service provided at a specific location (for example, the key management service described in the second embodiment), the location of use is the specific location (the address of the apartment building H in which the key storage box is located).
[0045] The area-specific telephone number table 11c is referred to when a telephone number authentication unit 12f, which will be described later, performs telephone number authentication. As shown in Fig. 2, the area-specific telephone number table 11c has items of area name, area-specific telephone number, and authentication telephone number. The area name and area-specific telephone number are the area and the area-specific telephone number set for the area. The area-specific telephone number is a toll-free telephone number. By using a toll-free telephone number, it is possible to execute the authentication process without imposing an economic burden on the user of the authentication system 1. However, it is not limited to this, and the area-specific telephone number may of course be an existing landline telephone number. The authentication telephone number is a telephone number in the registered account information, and stores the telephone number of the mobile phone terminal 20 whose area-specific telephone number has been notified by the telephone number notifying unit 12d, which will be described later.
[0046] The control device 12 has a CPU, a volatile memory, and a non-volatile memory, and is a control circuit that controls the authentication server 10. The CPU of the control device 12 loads the authentication programs stored in the storage device 11 into the volatile memory and executes them sequentially. As a result, the control device 12 functions as a user registration unit 12a, a schedule information registration unit 12b, a password authentication unit 12c, a phone number notification unit 12d, a call line control unit 12e, a phone number authentication unit 12f, and a service provision unit 12g, which will be described later. The control device 12 corresponds to a computer.
[0047] The user registration unit 12a accepts input of account information by a user who uses the authentication system 1 for the first time, and registers the account information in the user database 11a. Specifically, the user registration unit 12a acquires a user ID, a password (authentication password), a telephone number (authentication telephone number) of the mobile phone terminal 20, and an email address via the mobile phone terminal 20. The user registration unit 12a corresponds to a registration information accepting means.
[0048] The schedule information registration unit 12b receives schedule information relating to a schedule of service use and registers it in the schedule information database 11b. Specifically, the schedule information registration unit 12b acquires a scheduled date of use, a scheduled time of use, and a location of use via the mobile phone terminal 20. The schedule information registration unit 12b corresponds to a schedule information receiving means.
[0049] The password authentication unit 12c performs user authentication using a password. More specifically, the password authentication unit 12c provides a Web page having input fields for a user ID and a password to the mobile phone terminal 20, and accepts input of the user ID and password via the Web page. Next, the password authentication unit 12c obtains the user ID and password registered in the user database 11a, and compares the two. In this way, the password authentication unit 12c authenticates whether or not the user who accessed the Web page is a legitimate user. The password authentication unit 12c corresponds to a password authentication means.
[0050] The telephone number notification unit 12d acquires location information calculated by the mobile phone terminal 20 based on the GPS positioning signal, and notifies the mobile phone terminal 20 of the area-specific telephone number based on the acquired location information. The telephone number notification unit 12d refers to the area-specific telephone number table 11c, determines in which of a plurality of pre-set regions the mobile phone terminal 20 is located, and identifies the area-specific telephone number. The identified area-specific telephone number is notified to the user by email. However, without being limited thereto, the area-specific telephone number may be notified to the user by SMS (Short Message Service) or via a web page.
[0051] In addition, the telephone number notification unit 12d registers the telephone number of the mobile phone terminal 20 of the user who has succeeded in password authentication in the regional telephone number table 11c in association with the regional telephone number. This enables the telephone number authentication unit 12f, which will be described later, to perform telephone number authentication when acquiring the telephone number of the mobile phone terminal 20 that made a call to the regional telephone number. In addition, the area-specific telephone number is associated with the scheduled use time stored in the schedule information database 11b. This allows the telephone number authentication unit 12f, which will be described later, to check the incoming call time for the area-specific telephone number against the scheduled use time to determine whether or not the telephone number has been fraudulently used. The telephone number notification unit 12d corresponds to the location information acquisition means and the telephone number notification means.
[0052] The communication line control unit 12e controls the communication line between the authentication server 10 and the mobile phone terminal 20. Specifically, the communication line control unit 12e is a SIP server that controls the communication line using SIP (Session Initiation Protocol). The communication line control unit 12e accepts an incoming call to the area-specific telephone number notified by the telephone number notifying unit 12d, and acquires the telephone number (calling telephone number) of the mobile phone terminal 20 as the call source and the time of the incoming call. Then, the communication line control unit 12e outputs the acquired telephone number and the time of the incoming call to the telephone number authentication unit 12f described later. The communication line control unit 12e corresponds to a calling information acquisition means.
[0053] The telephone number authentication unit 12f authenticates a user using the telephone number. In detail, the telephone number authentication unit 12f acquires a calling telephone number via the communication line control unit 12e and checks the telephone number against the authentication telephone number stored in the area-specific telephone number table 11c. In this way, the telephone number authentication unit 12f authenticates whether the user who has accessed the authentication system 1 is a legitimate user.
[0054] Furthermore, the telephone number authentication unit 12f acquires the incoming call time via the telephone line control unit 12e and compares it with the scheduled use time associated with the area-specific telephone number. The incoming call time does not need to match the scheduled use time exactly. Even if there is a time difference between the incoming call time and the scheduled use time, if the time difference is within a predetermined range, the telephone number authentication unit 12f can determine that the user of the mobile phone terminal 20 is a valid user. The telephone number authentication unit 12f corresponds to a telephone number authentication means.
[0055] The service providing unit 12g provides a service to the mobile phone terminal 20 of a user who has been successfully authenticated by the phone number authentication unit 12f. The service providing unit 12g may deliver the service itself to the successfully authenticated user, or may transmit information necessary for using the service. This allows the user to receive the service.
[0056] The input unit 13 is an input device including a keyboard and a mouse, and receives input from an administrator who manages the authentication server 10, etc. The communication device 14 is connected to a telecommunication line such as the Internet, and performs two-way data communication with the mobile phone terminal 20. Specifically, the communication device 14 receives a user ID and a password entered by a user who operates the mobile phone terminal 20. The communication device 14 also transmits an e-mail to the mobile phone terminal 20 notifying the mobile phone terminal 20 of a region-specific telephone number.
[0057] <Authentication process> Next, the flow of the authentication process will be described. Fig. 6 shows a sequence of authentication processing executed by the user's mobile phone terminal 20 and the authentication server 10. As shown in Fig. 6, first, the mobile phone terminal 20 acquires current location information (step S10). Specifically, the mobile phone terminal 20 includes a GPS receiver, and calculates location information of the mobile phone terminal 20 based on a GPS positioning signal received by the GPS receiver.
[0058] Next, the mobile phone terminal 20 judges whether or not a user ID and a password for password authentication have been input (step S11). Specifically, the mobile phone terminal 20 accesses a website for password authentication that can be accessed by a specific URL. Then, it judges whether or not a user ID and a password have been input in the user ID and password input fields displayed on the website for password authentication.
[0059] If it is determined that the user ID and password have not been input (step S11: No), the mobile phone terminal 20 waits until the user ID and password are input. On the other hand, if it is determined that the user ID and password have been input (step S11: Yes), the mobile phone terminal 20 requests password authentication from the authentication server 10 (step S12). Specifically, the mobile phone terminal 20 requests password authentication by transmitting the input user ID, password, and the location information acquired in step S10 to the authentication server 10.
[0060] The authentication server 10 performs password authentication (step S13). Specifically, the authentication server 10 checks the user ID and password transmitted by the mobile phone terminal 20 against the user ID and password stored in the user database 11a. If the password authentication fails, the authentication server 10 transmits a message indicating that the authentication has failed to the mobile phone terminal 20.
[0061] If the password authentication is successful, the authentication server 10 notifies the mobile phone terminal 20 of the area-specific telephone number (step S14). Specifically, the authentication server 10 refers to the area-specific telephone number table 11c and identifies the area-specific telephone number based on the area in which the mobile phone terminal 20 is located and the scheduled time of use. At this time, the telephone number of the user whose password authentication has been successful (authenticated telephone number) is stored in the area-specific telephone number table 11c in association with the area-specific telephone number.
[0062] Next, the authentication server 10 transmits the identified regional telephone number to the email address of the mobile phone terminal 20. The method of notifying the regional telephone number is not limited to email. The regional telephone number may be notified to the mobile phone terminal 20 by an SMS message. The regional telephone number may be displayed on the password authentication website together with a message indicating that the authentication has been successful.
[0063] The authentication server 10 may perform user authentication by checking the location information of the mobile phone terminal 20 against the usage location stored in the user database 11a. Specifically, after password authentication is successful, the authentication server 10 refers to the schedule information database 11b to obtain the usage location associated with the user's user ID, and checks it against the location information of the mobile phone terminal 20. This makes it possible to improve the security of the authentication system 1.
[0064] The mobile phone terminal 20 that has received the notification of the area-specific telephone number accepts an operation for making a call to the area-specific telephone number (step S15). When a call to a region-specific telephone number arrives at the authentication server 10, the communication line control unit 12e (SIP server) of the authentication server 10 acquires the calling telephone number (step S16). In other words, the mobile phone terminal 20 requests telephone number authentication from the authentication server 10 by calling the region-specific telephone number.
[0065] When the authentication server 10 acquires the calling phone number, it performs phone number authentication (step S17). Specifically, the authentication server 10 performs phone number authentication by comparing the calling phone number with the authentication phone number stored in the area-specific phone number table 11c. In this way, by authenticating the user who possesses the mobile phone terminal 20 using the phone number, which is information unique to the mobile phone terminal 20 and cannot be forged, it is possible to improve the security of the authentication system 1.
[0066] If the telephone number authentication is successful, the authentication server 10 provides the service (step S18). In addition, the service may be provided to the mobile phone terminal 20 from another server when the authentication server 10 permits the use of the service.
[0067] The sequence of the authentication process executed by the mobile phone terminal 20 and the authentication server 10 has been described above. Although password authentication is widespread, a third party can "impersonate" the user by illegally obtaining the password. In contrast, a telephone number is a number unique to a mobile phone, and even if a third party obtains the telephone number, they cannot use it to "impersonate" the user. Therefore, by performing telephone number authentication, it is possible to improve the security of the authentication system 1. Furthermore, by combining telephone number authentication with authentication using pre-registered schedule information (scheduled time of use and place of use), it is possible to improve the security of the authentication system 1.
[0068] Second Embodiment Next, a second embodiment will be described in which the above-mentioned authentication system 1 is applied to a key management system 101. The key management system 101 provides a management service that manages the use of keys for entering restricted areas of the apartment building H on behalf of the manager of the apartment building H.
[0069] <Key Management System 101 Overview> FIG. 7 is a diagram showing an overview of the key management system 101. As shown in FIG. The key management system 101 is mainly composed of a key management server 110 , an entrance key storage box 120 , an equipment key storage box 130 , an entrance key 150 , an equipment key 155 , and a maintenance company terminal 160 . The key management server 110 is an information processing server that is responsible for managing the use of keys for the apartment complex H, and is operated by the management company that manages the apartment complex H, or a contractor that has been commissioned by the management company. More specifically, the key management server 110 authenticates the user of the entrance key 150 required to enter the apartment complex H and the equipment key 155 required to enter the equipment room, which is an access-restricted area of the apartment complex H, and permits the use of the entrance key 150 and the equipment key 155 by a person who has been successfully authenticated. Here, the equipment room includes an electrical room in which electrical equipment (substation equipment, etc.) is installed, an elevator machine room in which an elevator machine is installed, a water tank room in which a water tank is installed, etc. The key management server 110 corresponds to an authentication device, and the key management system 101 corresponds to an authentication system.
[0070] The entrance key storage box 120 is disposed outdoors near the entrance of the apartment complex H, and stores an entrance key 150 for unlocking the entrance lock (auto-lock lock) installed at the entrance. The entrance key storage box 120 may also store an entrance key for entering the caretaker's room in the apartment complex H. The entrance key storage box 120 is managed under lock and key and is unlocked by receiving an unlock permission signal transmitted by the key management server 110 and performing an unlocking operation.
[0071] The facility key storage box 130 is disposed in a caretaker's room inside the housing complex H, and stores facility keys 155 therein. The facility key storage box 130 is managed in a locked state, and is unlocked by performing an unlocking operation using the entrance key 150 stored in the above-mentioned entrance key storage box 120. The entrance key storage box 120 and the facility key storage box 130 correspond to valuables storage devices.
[0072] The entrance key 150 is stored in the entrance key storage box 120 and is used to lock and unlock the entrance lock installed at the entrance, the manager's room, and the facility key storage box 130. The facility key 155 is stored in the facility key storage box 130 and is used to unlock and lock the facility room. The facility key 155 corresponds to valuables. The building entrance key 150 and the facility key 155 will be described in detail later.
[0073] The maintenance provider terminal 160 is an information communication terminal operated by a maintenance worker for the shared facilities of the apartment building H and a person in charge of maintenance work, and is used to input a usage schedule of the key for entering the facility room and to request the unlocking of the entrance key storage box 120. The maintenance provider terminal 160 is a smartphone, but is not limited to this. The maintenance provider terminal 160 may be a mobile communication terminal of the third generation or earlier.
[0074] The key management server 110, the entrance key storage box 120, and the maintenance company terminal 160 are communicatively connected to each other via a publicly available communication line such as the Internet. On the other hand, the equipment key storage box 130 is not communicatively connected to the key management server 110 or the maintenance company terminal 160.
[0075] The flow of operations when a maintenance worker borrows the building key 150 and the facility key 155 will be described below with reference to FIG. [1] Prior to maintenance work, a maintenance worker registers account information and information to be used. Specifically, the maintenance company registers account information when using the key management system 101 for the first time. The account information includes a maintenance company ID, a password, a maintenance company name, a telephone number of the maintenance company terminal 160, and an email address. However, without being limited to this, the account information may also include the address of the maintenance company's business establishment.
[0076] The maintenance company also operates the maintenance company terminal 160 to register planned use information for the key to enter the equipment room. Here, the planned use information includes the maintenance company ID, planned maintenance date, planned maintenance time, the apartment building H to be maintained, and equipment room identification information. The equipment room identification information is information that can identify the equipment room in which the equipment to be maintained is installed. However, the planned use information is not limited to this.
[0077] [2] On the day of the maintenance work, when the maintenance worker arrives at apartment complex H, he operates maintenance company terminal 160 to request password authentication. Specifically, the maintenance worker accesses a website for password authentication that can be accessed by a specific URL. Next, the maintenance worker inputs a user ID and a password in the user ID and password input fields displayed on the website for password authentication, and transmits the input to key management server 110 to request password authentication.
[0078] Furthermore, the maintenance provider terminal 160 transmits location information of the maintenance provider terminal 160 to the key management server 110. Specifically, the maintenance provider terminal 160 includes a GPS receiver, and calculates location information including latitude, longitude, and altitude of the maintenance provider terminal 160 based on a GPS positioning signal received by the GPS receiver, and transmits this information to the key management server 110.
[0079] [3] Upon receiving the password authentication request, the key management server 110 performs password authentication. Specifically, the authentication server 10 performs user authentication by comparing the maintenance provider ID and password received together with the password authentication request with the maintenance provider ID and password in the account information registered prior to use of the authentication system 1.
[0080] [4] If the password authentication is successful, the key management server 110 notifies the maintenance provider terminal 160 of the region-specific telephone number. Specifically, the key management server 110 notifies the maintenance provider terminal 160 of the region-specific telephone number described in the first embodiment to the email address of the maintenance provider terminal 160.
[0081] [5] Upon receiving the notification of the regional telephone number, the user operates the maintenance company terminal 160 to request telephone number authentication. The maintenance company terminal 160 makes a call to the notified regional telephone number. The key management server 110 obtains the calling telephone number by receiving a call to the regional telephone number.
[0082] [6] Upon receiving a request for telephone number authentication, the key management server 110 performs telephone number authentication. Specifically, the key management server 110 authenticates the maintenance worker by comparing the calling telephone number with the telephone number of the maintenance company terminal 160 that was registered prior to use of the key management system 101.
[0083] [7] If the telephone number authentication is successful, the key management server 110 sends an unlock permission signal to the entrance key storage box 120. This allows the maintenance worker to unlock the entrance key storage box 120 even if the manager is not present.
[0084] [8] When the entrance key storage box 120 receives the unlock permission signal, the unlocking operation of the entrance key storage box 120 is enabled. When a maintenance worker performs the unlocking operation, an image of the maintenance worker is captured by a camera 123 (see FIG. 8) disposed in the entrance key storage box 120. [9] Simultaneously with or after the shooting is completed, the entrance key storage box 120 is unlocked. This allows the maintenance worker to obtain the entrance key 150 for entering the apartment building H. The maintenance worker can also use the entrance key 150 to unlock the equipment key storage box 130.
[0085]
[10] When the entrance key storage box 120 is unlocked, key usage history information is sent from the entrance key storage box 120 to the key management server 110. The key usage history information includes the time information when the entrance key storage box 120 is unlocked and the image of the maintenance worker photographed in [8].
[0086]
[11] When the entrance key 150 obtained in [9] is inserted into the equipment key storage box 130, the unlocking operation of the equipment key storage box 130 is enabled, and when the maintenance worker performs the unlocking operation, the equipment key storage box 130 is unlocked. At this time, the camera 134 (see FIG. 10) disposed in the equipment key storage box 130 captures an image of the maintenance operator.
[12] A maintenance worker can borrow an equipment key 155 stored in the equipment key storage box 130 and enter the equipment room.
[0087] The above is the flow when a maintenance worker of apartment complex H borrows entrance key 150 and equipment key 155. As described above, by registering the scheduled use information of the key in advance, the maintenance worker can enter the equipment room and perform maintenance work even when the manager or security officer is absent.
[0088] <Exterior of entrance key storage box 120> First, we will explain the entrance key storage box 120 that constitutes the key management system 101. The entrance key storage box 120 is installed at the entrance of the apartment building H and stores the entrance key 150. Here, the entrance key 150 is a key used to lock or unlock the lock installed at the entrance of the apartment building H and the lock of the equipment key storage box 130 described later. The entrance key storage box 120 is connected to a key management server 110 (described later) via an electric communication line, and can be unlocked when it receives an unlock permission signal output by the key management server 110.
[0089] Figures 8 and 9 show perspective views of the entry key storage box 120. Figure 8 is a perspective view of the entry key storage box 120 with the opening and closing door 121a closing the entry key storage space S1. Figure 9 is a perspective view of the entry key storage box 120 with the opening and closing door 121a opening the entry key storage space S1.
[0090] As shown in FIG. 8, the entrance key storage box 120 has a key storage box main body 121 and an opening / closing door 121a that is provided on the key storage box main body 121 so as to be openable and closable. The key storage box main body 121 has a generally rectangular parallelepiped shape, and an operation receiving section 121b is formed on the front surface thereof. An unlock button 122, a camera 123, an LED light 123a, an emergency cylinder lock 124, and a card reader 125 are disposed in the operation reception unit 121b.
[0091] The unlock button 122 is a button that is pressed to unlock the opening / closing door 121a. The unlock button 122 is enabled when an unlock permission signal is received from the key management server 110. By pressing the unlock button 122 at the timing when the unlock button 122 is enabled, an image is taken by a camera 123, which will be described later, and the locking device 126 (see FIG. 16) is unlocked to open the opening / closing door 121a. Camera 123 is disposed above unlock button 122 and in a position close to unlock button 122. Camera 123 is disposed in a position and direction facing unlock button 122 such that it can capture an image of an operator (maintenance worker) operating unlock button 122.
[0092] The LED lighting 123a is disposed below the camera 123. The LED lighting 123a incorporates multiple LEDs (Light Emitting Diodes) and outputs white light to a maintenance worker who operates the unlock button 122. By controlling the LED lighting 123a to turn on in accordance with the timing of shooting by the camera 123, it becomes possible to clearly shoot an image of the face of the maintenance worker even in a situation where the surrounding brightness is insufficient.
[0093] The emergency cylinder lock 124 is a cylinder lock used to unlock the entrance key storage box 120 with an emergency key in the event of a power outage or the like. The card reader 125 is a wireless interface device capable of reading personal identification information (corresponding to user identification information) stored in an identification information storage medium (e.g., a driver's license or a My Number card) carried by a maintenance worker. Here, the personal identification information is identification information that can identify an individual maintenance worker, but is not limited to this. The card reader 125 corresponds to an identification information reading means.
[0094] 9 shows the entrance key storage box 120 with the entrance key storage space S1 open. A hinge (not shown) that connects the opening and closing door 121a so that it can be opened and closed is attached to the left end of the key storage box body 121, and the entrance key storage space S1 is opened by rotating the opening and closing door 121a around the hinge as a rotation axis.
[0095] A locking device 126 (see FIG. 16) that regulates the opening and closing of the opening and closing door 121a is disposed inside the key storage box body 121, and an engagement piece 124a is fixed to the inside of the opening and closing door 121a. In detail, the locking device 126 is composed of a locking member (not shown) that regulates the opening and closing of the opening and closing door 121a by displacing left and right, an actuator (not shown) that drives the locking member, and an engagement piece 126a that engages with the locking member. The actuator drives the locking member to displace left and right based on a control signal output by a control device 129, which will be described later, thereby regulating the opening and closing of the opening and closing door 121a.
[0096] An entrance key 150 is stored in the entrance key storage space S1. The entrance key 150 is a key used to lock or unlock the door lock of the apartment building H and the equipment key storage box 130. The entrance key 150 has a key body 151 and an equipment room memory unit 152 that stores equipment room identification information capable of identifying an equipment room that is an access-restricted area that is the target of maintenance. The key body 51 is a key for unlocking the door lock of the apartment building H. The key body 151 may further have a key for locking and unlocking the caretaker's room. The equipment room memory unit 152 is a non-volatile memory that stores equipment room identification information capable of identifying an equipment room of the apartment building H, and is a key for unlocking the equipment key storage box 130. 9, the key body 151 is illustrated as a mechanical cylinder key having a complex concave-convex shape, but is not limited thereto. The key body 151 may be an electronic or optical key in which predetermined identification information is stored.
[0097] The entrance key storage box 120 is formed with a plurality of entrance key insertion ports 127 into which the equipment room memory unit 152 of the entrance key 150 can be inserted. Inside the entrance key insertion port 127, there is provided an entrance key interface 127a (see FIG. 16) that is electrically connected to the equipment room memory unit 152 and can read and write equipment room identification information stored in the equipment room memory unit 152. The equipment room identification information is used to identify, from among the plurality of equipment keys 155 stored in the equipment key storage box 130, the equipment key 155 for entering the equipment room that is the maintenance target. This point will be described later.
[0098] Furthermore, inside the entrance key insertion port 127 is built an entrance key locking device 127b (see FIG. 16) that restricts the removal of the entrance key 150 from the entrance key insertion port 127. The equipment room memory unit 152 is formed with a locked portion 152a that engages with the entrance key locking device 127b. In more detail, the entrance key locking device 127b can be shifted between a locked state that restricts the removal of the entrance key 150 and an unlocked state that does not restrict the removal of the entrance key 150. The entrance key locking device 127b is set to a locked state when the locking device 126 is locked, and is set to an unlocked state when the locking device 126 is unlocked. 9, the entrance key storage box 120 is formed with two entrance key insertion openings 127, but is not limited to this. There may be one entrance key insertion opening 127, or three or more entrance key insertion openings 127.
[0099] A communication device 128 and a control device 129 (see FIG. 16), which will be described later, are stored inside the entrance key storage box 120 and to the right of the entrance key storage space S1. The communication device 128 is a communication interface circuit capable of communicating with the key management server 110 via a communication line such as the Internet. The communication device 128 transmits images captured by the camera 123 to the key management server 110. The control device 129 will be described later.
[0100] <Appearance of Equipment Key Storage Box 130> Next, the equipment key storage box 130 will be described. The equipment key storage box 130 is installed in the manager's room of the apartment building H, and stores an equipment key 155. Here, the equipment key 155 is a key used to lock or unlock access-restricted compartments such as the electrical room, elevator machine room, or water tank room. The facility key storage box 130 is unlocked by the building entry key 150.
[0101] 10 and 11 are perspective views of the equipment key storage box 130. Fig. 10 is a perspective view of the equipment key storage box 130 with the opening / closing door 131a closing the equipment key storage space S2. Fig. 11 is a perspective view of the equipment key storage box 130 with the opening / closing door 131a opening the equipment key storage space S2.
[0102] As shown in FIG. 10, the facility key storage box 130 has a key storage box main body 131 and an opening / closing door 131a that is provided on the key storage box main body 131 so as to be openable and closable. The key storage box body 131 is a box-like body having a substantially rectangular parallelepiped shape, and has an operation reception section 31b that constitutes the front wall. An entrance key insertion slot 132, an unlock button 133, a camera 134, an LED light 134a, and an emergency cylinder lock 135 are disposed in the operation reception section 131b.
[0103] The entrance key insertion port 132 is an insertion port into which the equipment room memory unit 152 of the entrance key 150 can be inserted. Inside the entrance key insertion port 132 is provided an entrance key interface 132a (see FIG. 17) that is electrically connected to the equipment room memory unit 152 and can read the equipment room identification information stored in the equipment room memory unit 152. The control device 139 of the equipment key storage box 130 can obtain the equipment room identification information stored in the equipment room memory unit 152 via the entrance key interface 132a.
[0104] The unlock button 133 is a button that is pressed to unlock the opening and closing door 131a. The unlock button 133 is enabled when the entrance key 150 is inserted into the entrance key insertion slot 132. By pressing the unlock button 133 at the timing when the unlock button 133 is enabled, a photograph is taken by the camera 134, which will be described later, and the locking device 136 (see FIG. 17) is controlled to open the opening and closing door 131a. Camera 134 is disposed above unlock button 133 and in a position close to unlock button 133. Camera 134 is disposed in a position and direction facing unlock button 133 such that it can capture an image of an operator (maintenance worker) operating unlock button 133.
[0105] As will be described later, when the maintenance worker operates the unlock button 133, an image of the operator is captured by the camera 134. By disposing the unlock button 133 below the camera 134, it becomes possible to capture an image of the maintenance worker without the imaging area of the camera 35 being covered by fingers or forearm, whether the unlock button 133 is pressed with the right hand or the left hand.
[0106] The LED lighting 134a is disposed below the camera 134. The LED lighting 134a has multiple built-in LEDs and outputs white light to the maintenance worker who operates the unlock button 133. By controlling the LED lighting 134a to turn on in accordance with the timing of shooting by the camera 134, it becomes possible to clearly shoot the face of the maintenance worker even in a situation where the surrounding brightness is insufficient. The emergency cylinder lock 135 is a cylinder lock used to unlock the opening and closing door 131a with an emergency key in the event of a power outage or the like.
[0107] 11 shows the equipment key storage box 130 with the equipment key storage space S2 open. A hinge (not shown) that connects the opening / closing door 131a so that it can be opened and closed is attached to the left end of the key storage box body 131, and the equipment key storage space S2 is opened by rotating the opening / closing door 131a around the hinge as a rotation axis. The opening and closing door 131a is a plate-like body that covers the front surface of the equipment key storage box 130, and opens and closes the equipment key storage space S2.
[0108] A locking device 136 (see FIG. 17) that regulates the opening and closing of the opening and closing door 131a is disposed inside the key storage box body 131, and an engagement piece 136a is fixed to the inside of the opening and closing door 131a. In detail, the locking device 136 is composed of a locking member (not shown) that regulates the opening and closing of the opening and closing door 131a by displacing left and right, an actuator (not shown) that drives the locking member, and the engagement piece 136a that engages with the locking member. The actuator drives the locking member to displace left and right based on a control signal output by a control device 139, which will be described later, thereby regulating the opening and closing of the opening and closing door 131a.
[0109] The equipment key storage space S2 stores an equipment key 155. The equipment key 155 is a key used to lock and unlock the equipment room. The equipment key 155 has a key body 156 and an equipment room memory unit 157 that stores equipment room identification information capable of identifying the equipment room to be maintained. The key body 156 is a key for unlocking the door lock of the equipment room. The equipment room memory unit 157 is a non-volatile memory that stores the equipment room identification information. 11, the key body 156 is illustrated as a mechanical cylinder key having a complex concave-convex shape, but is not limited thereto. The key body 156 may be an electronic or optical key in which predetermined identification information is stored.
[0110] The equipment key storage box 130 is formed with a plurality of equipment key insertion slots 137 into which the equipment room memory units 157 of the equipment keys 155 can be inserted. Inside the equipment key insertion slots 137, there is provided an equipment key interface 137a (see FIG. 17 ) that is electrically connected to the equipment room memory unit 157 to read the equipment room identification information stored in the equipment room memory unit 157.
[0111] The facility key insertion port 137 also includes an facility key locking device 137b (see FIG. 17) that restricts removal of the facility key 155 from the facility key insertion port 137. The facility room memory unit 157 is formed with a locked portion 157a that engages with the facility key locking device 137b. In more detail, the facility key locking device 137b can be switched between a locked state that restricts removal of the facility key 155 and an unlocked state that does not restrict removal of the facility key 155. When the entrance key 150 is inserted into the entrance key insertion port 132, the facility key locking device 137b is released from restriction so that the facility key 155 that stores the same facility room identification information as the facility room identification information stored in the facility room memory unit 152 of the entrance key 150 can be removed.
[0112] 11, the equipment key storage box 130 is formed with eleven equipment key insertion openings 137, but is not limited to this. A greater number of equipment key insertion openings 137 may be formed. The equipment key storage box 130 may be formed with 15 to 30 equipment key insertion openings 137 corresponding to the number of restricted access areas in the apartment building H.
[0113] <Configuration of the key management server 110> Next, the configuration of the key management server 110 will be described. Fig. 12 shows the configuration of the key management server 110. As shown in Fig. 12, the key management server 110 has a storage device 111, a control device 112, an input device 113, and a communication device 114 as its main components.
[0114] The storage device 111 is a non-volatile auxiliary storage device consisting of a hard disk drive (HDD) or a solid state drive (SSD), etc. The storage device 111 stores a maintenance business database 111a, a key usage schedule database 111b, a region-specific telephone number table 111c, a key usage history database 111d, a captured image storage unit 111e, and an authentication program executed by the control device 112.
[0115] The maintenance business database 111a stores information about maintenance businesses that use the key management system 101. The maintenance business database 111a is updated when a maintenance business that uses the key management system 101 for the first time registers as a maintenance business prior to using the key management system 101. Fig. 13 shows an example of the data structure of the maintenance company database 111a. As shown in Fig. 13, the maintenance company database 111a stores data records including a maintenance company ID, a password, a maintenance company name, a telephone number, and an email address.
[0116] The key use schedule database 111b stores information regarding the schedule of use of the entrance key 150 and the facility key 155. The key use schedule database 111b is updated by a maintenance worker or a responsible person accessing the key management server 110 via the maintenance company terminal 160. However, the key use schedule database 111b may also be updated by the manager of the apartment building H. Fig. 14 shows an example of the data structure of the key usage schedule database 111b. As shown in Fig. 14, the key usage schedule database 111b is made up of data records including a maintenance ID, a maintenance company ID, a building, a maintenance equipment, a scheduled maintenance date, a scheduled maintenance time, and an address.
[0117] As in the above-described embodiment, the area-specific telephone number table 111c stores areas, area-specific telephone numbers assigned to each area and scheduled time, and authentication telephone numbers that are telephone numbers of the maintenance company terminal 160 associated with the area-specific telephone numbers. The area-specific telephone number table 111c is referred to when the telephone number authentication unit 112f described later performs telephone number authentication.
[0118] The key usage history database 111d stores information about the usage record of the key for the equipment room. The key usage history database 111d is updated by the key usage history update unit 112h. However, the key usage history database 111d may be updated by the manager of the apartment building H. Fig. 15 shows an example of the data structure of the key usage history database 111d. As shown in Fig. 15, the key usage history database 111d is composed of data records including a maintenance ID, a maintenance company ID, a building, a maintenance facility, a maintenance implementation date, a maintenance implementation time, and an image file.
[0119] The captured image storage unit 111e stores images of the maintenance worker captured by the camera 123 of the entrance key storage box 120. The captured images stored in the captured image storage unit 111e are still images compressed by a known image compression algorithm, but are not limited to this. The captured images stored in the captured image storage unit 111e may also be moving images.
[0120] The control device 112 is a control circuit having a CPU, a volatile memory, and a non-volatile memory, and controls the key management server 110. The CPU of the control device 112 loads the authentication programs stored in the storage device 111 into the volatile memory and executes them sequentially. As a result, the control device 112 functions as a maintenance business registration unit 112a, a key use schedule registration unit 112b, a password authentication unit 112c, a phone number notification unit 112d, a communication line control unit 112e, a phone number authentication unit 112f, an unlocking permission signal output unit 112g, and a key use history update unit 112h. The control device 112 corresponds to a computer.
[0121] The maintenance company registration unit 112a registers information about the maintenance company in the maintenance company database 111a. More specifically, the maintenance company registration unit 112a acquires the maintenance company ID, password (authentication password), telephone number and email address of the maintenance company terminal 160 inputted via the maintenance company terminal 160, and registers them in the maintenance company database 111a. The maintenance company registration unit 112a corresponds to a registration information receiving means.
[0122] The key use schedule registration unit 112b registers, in the key use schedule database 111b, key use schedule information relating to the schedule of use of the entrance key 150 and the facility key 155. The key use schedule registration unit 112b corresponds to schedule information receiving means.
[0123] The password authentication unit 112c authenticates the maintenance worker using the password. The password authentication unit 112c accepts input of a maintenance company ID and a password via a Web page having input fields for the maintenance company ID and password. Next, the password authentication unit 112c acquires the maintenance company ID and password registered in the maintenance company database 111a and compares the two. In this way, the password authentication unit 112c authenticates whether the maintenance worker who accessed the Web page is a legitimate person. The password authentication unit 112c corresponds to a password authentication means.
[0124] The telephone number notifying unit 112d acquires location information calculated by the maintenance company terminal 160 based on the GPS positioning signal, and notifies the mobile phone terminal 20 of the area-specific telephone number based on the acquired location information. In detail, the telephone number notifying unit 112d refers to the area-specific telephone number table 111c and identifies the area-specific telephone number based on the location information of the maintenance company terminal 160. The identified area-specific telephone number is notified to the maintenance worker by a known means such as email. In addition, the telephone number notification unit 112d registers the telephone number of the maintenance company terminal 160 in the regional telephone number table 111c in association with the regional telephone number. This enables the telephone number authentication unit 112f, which will be described later, to perform telephone number authentication when receiving an incoming call to the regional telephone number.
[0125] In addition, the area-specific telephone number is associated with the scheduled use time stored in the key use schedule database 111b. This allows the telephone number authentication unit 112f, which will be described later, to authenticate the maintenance worker by comparing the incoming call time for the area-specific telephone number with the scheduled use time. The telephone number notification unit 112d corresponds to a location information acquisition means and a telephone number notification means.
[0126] The communication line control unit 112 e is a SIP server that controls the communication line between the key management server 110 and the maintenance company terminal 160 . The communication line control unit 112e receives an incoming call to the area-specific telephone number notified by the telephone number notifying unit 112d, and acquires the telephone number (calling telephone number) of the maintenance company terminal 160 that is the caller and the time of the incoming call. The communication line control unit 112e outputs the calling telephone number and the time of the incoming call to the telephone number authentication unit 112f. The communication line control unit 112e corresponds to a calling information acquisition means.
[0127] The telephone number authentication unit 112f authenticates the maintenance worker using the telephone number. In detail, the telephone number authentication unit 112f checks the calling telephone number against the authentication telephone number stored in the area-specific telephone number table 111c. In this way, the telephone number authentication unit 112f authenticates whether the user who has accessed the authentication system 1 is a legitimate maintenance worker. The telephone number authentication unit 112f may also compare the incoming call time for the area-specific telephone number with the scheduled use time associated with the area-specific telephone number. The telephone number authentication unit 112f corresponds to telephone number authentication means.
[0128] The unlocking permission signal output unit 112g transmits an unlocking permission signal that permits unlocking of the entrance key storage box 120 to the entrance key storage box 120 based on the result of the comparison by the telephone number authentication unit 112f. The unlocking permission signal output unit 112g corresponds to an unlocking permission signal transmitting means.
[0129] The key usage history update unit 112h stores information about the usage history of the key for the equipment room in the key usage history database 111d and the captured image storage unit 111e. More specifically, the key usage history update unit 112h receives the key usage history information output by the lock control unit 129c of the entrance key storage box 120, updates the key usage history database 111d, and stores the captured image in the captured image storage unit 111e.
[0130] The input unit 113 is an input device including a keyboard and a mouse, and receives input from an administrator who manages the key management server 110, etc. The communication device 114 is connected to a telecommunications line such as the Internet, and performs two-way data communication with the entrance key storage box 120 and the maintenance company terminal 160 .
[0131] <Configuration of the entrance key storage box 120> Next, the configuration of the building entry key storage box 120 will be described. 16 shows the configuration of the entrance key storage box 120. The control device 129 is connected to the unlock button 122, the camera 123, the card reader 125, the entrance key interface 127a, the LED lighting 123a, the locking device 126, the entrance key lock device 127b, and the communication device 128, and controls the entrance key storage box 120. The control device 129 is a control circuit having a processor, a volatile memory, and a non-volatile memory. The processor of the control device 129 reads and sequentially executes programs stored in the non-volatile memory, so that the control device 129 functions as an unlock permission signal acquisition unit 129a, an image capture control unit 129b, and a lock control unit 129c, which will be described later.
[0132] The unlocking permission signal acquisition unit 129a acquires the unlocking permission signal transmitted by the key management server 110 via the communication device 128. Upon acquiring the unlocking permission signal, the unlocking permission signal acquisition unit 129a notifies the photography control unit 129b and the lock control unit 129c that the unlocking permission signal has been acquired. Here, the unlocking permission signal includes equipment room identification information.
[0133] When the photography control unit 129b receives a notification of the unlock permission signal from the unlock permission signal acquisition unit 129a, it enables the operation of the unlock button 122. In other words, the photography control unit 129b waits for a predetermined time (e.g., 30 seconds) after receiving the notification of the unlock permission signal until the unlock button 122 is pressed. Then, when the unlock button 122 is pressed, the photography control unit 129b turns on the LED lighting 123a to brightly illuminate the maintenance worker and photographs the maintenance worker with the camera 123. Moreover, the photography control unit 129b notifies the lock control unit 129c of the photography at the same time as or after the photography is completed. If the unlock button 122 is not operated within a predetermined time after receiving a notification of the unlock permission signal from the unlock permission signal acquisition unit 129a, the unlock button 122 is disabled.
[0134] When the lock control unit 129c receives a notification of photography from the photography control unit 129b, it stores the equipment room identification information acquired by the unlock permission signal acquisition unit 129a in the equipment room memory unit 152 of the entrance key 150 via the entrance key interface 127a. In addition, the lock control unit 129c unlocks the locking device 126 to enable the opening and closing door 121a to be opened and closed. In addition, the lock control unit 129c transmits key usage history information, including the date and time when the locking device 126 was unlocked and the image of the maintenance worker captured by the camera 123, to the key management server 110 via the communication device 128.
[0135] <Configuration of the equipment key storage box 130> Next, the configuration of the equipment key storage box 130 will be described. 17 shows the functional configuration of the facility key storage box 130. The control device 139 is connected to the unlock button 133, the camera 134, the entrance key interface 132a, the facility key interface 137a, the LED lighting 134a, the locking device 136, the facility key lock device 137b, and the storage device 138, and controls the facility key storage box 130. The control device 139 is a control circuit having a processor, a volatile memory, and a non-volatile memory. The processor of the control device 139 reads and sequentially executes programs stored in the non-volatile memory, so that the control device 139 functions as an facility room identification information acquisition unit 139a, an imaging control unit 139b, and a locking control unit 139c, which will be described later.
[0136] The equipment room identification information acquisition unit 139a acquires equipment room identification information from the equipment room memory unit 152 of the entry key 150 inserted into the entry key insertion slot 132, via the entry key interface 132a. Upon acquiring the equipment room identification information, the equipment room identification information acquisition unit 139a notifies the photography control unit 139b and the lock control unit 139c that the equipment room identification information has been acquired.
[0137] Upon receiving the notification from the equipment room identification information acquisition unit 139a, the photography control unit 139b enables the operation of the unlock button 133. In other words, the photography control unit 139b waits for a predetermined time (e.g., 30 seconds) after receiving the notification until the unlock button 133 is pressed. Then, when the unlock button 133 is pressed, the photography control unit 139b turns on the LED lighting 134a to brightly illuminate the maintenance worker, and also photographs the maintenance worker with the camera 134. Moreover, the photography control unit 139b notifies the lock control unit 139c of the photography at the same time as or after the photography is completed. If the unlock button 133 is not operated within a predetermined time after receiving a notification from the equipment room identification information acquisition unit 139a, the unlock button 133 is disabled.
[0138] The locking control unit 139c reads the equipment room identification information stored in the equipment room memory unit 152 of the equipment key 155 via the equipment key interface 137a and compares it with the equipment room identification information read from the entrance key 150. Next, the locking control unit 139c controls the equipment key lock device 137b to release the restriction on the removal of the equipment key 155 based on the comparison result. Specifically, if the equipment room identification information matches, the locking control unit 139c releases the restriction on the removal of the equipment key 155, and if the equipment room identification information does not match, the locking control unit 139c does not release the restriction on the removal of the equipment key 155 (does not unlock). In addition, the locking control unit 139c controls the locking device 136 to allow the opening and closing door 131a to be opened. Next, the lock control unit 139c stores the key usage record information including the time when the locking device 136 was unlocked and the equipment room identification information in the storage device 138 as a key usage history.
[0139] <Key lending process> Next, the flow of lending the entrance key 150 and the facility key 155 to the maintenance company will be described. The lending of keys to a maintenance company is performed in two stages: an entrance key lending process in which an entrance key 150 is lent as a first stage, and an equipment key lending process in which an equipment key 155 is lent as a second stage. The entrance key lending process in the first stage is performed by the maintenance company terminal 160, the key management server 110, and the entrance key storage box 120, which are connected via an electric communication line. The equipment key lending process in the second stage is performed by the equipment key storage box 130 without communication via an electric communication line. This makes it possible to realize lending of the entrance key 150 in the entrance key storage box 120 installed in a good radio wave environment and lending of the equipment key 155 in the equipment key storage box 130 installed in a not necessarily good radio wave environment without performing complex control.
[0140] <<Entry key lending process>> First, the sequence of the first stage entry key lending process will be described. As described above, the entry key lending process is a process executed by the maintenance company terminal 160, the key management server 110, and the entry key storage box 120. Note that, prior to the execution of the entry key lending process, the maintenance company is registered and key use schedule information is registered, and the maintenance company database 111a and the key use schedule database 111b store the maintenance company's account information and key use schedule information, respectively.
[0141] Fig. 18 shows the sequence of the entry key lending process. As shown in Fig. 18, when the maintenance worker arrives at the apartment building H to be maintained, the maintenance company terminal 160 first acquires the current location (step S20). Specifically, the maintenance company terminal 160 acquires location information of the maintenance company terminal 160 based on the GPS positioning signal received by the GPS receiver.
[0142] Next, the maintenance company terminal 160 judges whether or not a maintenance company ID and a password for password authentication have been input (step S21). Specifically, the maintenance company terminal 160 judges whether or not a maintenance company ID and a password have been input in the maintenance company ID and password input fields via a website for password authentication accessed by a specific URL.
[0143] If it is determined that the maintenance company ID and password have not been input (step S21: No), the maintenance company terminal 160 waits until the maintenance company ID and password are input. On the other hand, if it is determined that the maintenance provider ID and password have been input (step S21: Yes), the maintenance provider terminal 160 requests password authentication from the key management server 110 (step S22). Specifically, the maintenance provider terminal 160 requests password authentication by transmitting the input maintenance provider ID, password, and the location information acquired in step S20 to the key management server 110.
[0144] The key management server 110 performs password authentication by checking the user ID and password transmitted by the maintenance company terminal 160 against the maintenance company ID and password stored in the maintenance company database 111a (step S23). If the password authentication fails, the authentication server 10 transmits a message indicating that the authentication has failed to the maintenance company terminal 160.
[0145] If the password authentication is successful, the key management server 110 notifies the maintenance provider terminal 160 of the region-specific telephone number (step S24). Specifically, the key management server 110 first identifies the region in which the maintenance provider terminal 160 is located based on the location information of the maintenance provider terminal 160. Next, the key management server 110 refers to the key use schedule database 111b and the region-specific telephone number table 111c, and identifies the region-specific telephone number based on the scheduled use time and the region in which the maintenance provider terminal 160 is located. Finally, the key management server 110 transmits the identified region-specific telephone number to the email address of the maintenance provider terminal 160. Note that the method of notifying the region-specific telephone number is not limited to email. The region-specific telephone number may be notified to the maintenance provider terminal 160 by an SMS message. Also, the region-specific telephone number may be displayed on a website for password authentication together with a message indicating that authentication has been successful.
[0146] The key management server 110 may perform authentication based on the user's location information by comparing the location information of the maintenance provider terminal 160 with the usage location stored in the key usage schedule database 111b. In this case, after password authentication is successful, the key management server 110 may refer to the key usage schedule database 111b and compare the usage location associated with the maintenance provider ID with the location information received from the maintenance provider terminal 160. By performing authentication based on location information in this way, it is possible to improve the security of the authentication system 1.
[0147] The maintenance company terminal 160 that has received the notification of the area-specific telephone number accepts an operation for making a call to the area-specific telephone number (step S25). When a call to a region-specific telephone number arrives at the key management server 110, the communication line control unit 112e of the key management server 110 simultaneously acquires the telephone number (calling telephone number) of the maintenance company terminal 160 (step S26).
[0148] When the key management server 110 acquires the calling telephone number, it performs telephone number authentication (step S27). Specifically, the key management server 110 performs authentication by checking the calling telephone number against the authentication telephone number stored in the area-specific telephone number table 111c. In this way, by authenticating the person who possesses the maintenance company terminal 160 using a telephone number that is information unique to the maintenance company terminal 160 and cannot be forged, it is possible to improve the security of the key management system 101.
[0149] If the telephone number authentication is successful, the key management server 110 generates an unlock request signal and transmits an unlock permission signal to the entrance key storage box 120 to permit unlocking of the entrance key storage box 120 (step S28). Here, the unlock permission signal includes the equipment room identification information.
[0150] When the control device 129 of the entrance key storage box 120 receives the unlock permission signal, it enables operation of the unlock button 122 (step S29). Next, the entrance key storage box 120 judges whether the unlock button 122 has been pressed (step S30). If it is judged that the unlock button 122 has not been pressed (step S30: No), the entrance key storage box 120 waits until the unlock button 122 is pressed.
[0151] If it is determined that the unlock button 122 has been pressed (step S30: Yes), the entrance key storage box 120 controls the camera 123 to capture an image of the maintenance worker (step S31). More specifically, the entrance key storage box 120 uses the LED lighting 123a to illuminate the maintenance worker who is positioned opposite the unlock button 122, and controls the camera 123 to capture an image of the maintenance worker.
[0152] Next, the entrance key storage box 120 stores the equipment room identification information acquired in step S28 in the equipment room memory unit 152 of the entrance key 150 via the entrance key interface 127a (step S32). The entrance key storage box 120 also sets the entrance key lock device 127b to an unlocked state (step S33). Specifically, the entrance key storage box 120 transmits a drive signal to the entrance key lock device 127b to enable the entrance key 150 to be removed from the entrance key insertion port 127.
[0153] Next, the entrance key storage box 120 controls the locking device 126 to unlock the entrance key storage box 120 (step S34). More specifically, the entrance key storage box 120 outputs a drive signal to the locking device 126 to displace the lock member. This allows the maintenance worker to open the opening and closing door 121a and borrow the entrance key 150 stored in the entrance key storage space S1.
[0154] Next, the entrance key storage box 120 transmits key usage history information to the key management server 110 (step S35). The key usage history information includes the unlocking time and the captured image. Upon receiving the key usage history information, the key management server 110 updates the key usage history database 111d and the captured image storage unit 111e (step S36) and ends the entrance key lending process.
[0155] <<Equipment key lending process>> Next, the sequence of the second stage of the equipment key lending process will be described. As described above, the equipment key lending process is a process executed by the equipment key storage box 130. It will be described that, prior to the equipment key lending process, the maintenance worker borrows the entrance key 150 and uses the entrance key 150 to enter the apartment building H and the manager's room of the apartment building H.
[0156] 19 shows the sequence of the facility key lending process. A maintenance worker first inserts the facility entry key 150 into the facility entry key insertion slot 132 of the facility key storage box 130. The control device 139 of the facility key storage box 130 determines whether the facility entry key 150 has been inserted via the facility entry key interface 132a (step S40). If it is not determined that the facility entry key 150 has been inserted (step S40: No), the facility key storage box 130 waits until the facility entry key 150 is inserted.
[0157] If it is determined that the entrance key 150 has been inserted (step S40: Yes), the control device 139 reads the equipment room identification information stored in the equipment room storage unit 152 of the entrance key 150 (step S41). Next, the control device 139 enables the operation on the unlock button 133 (step S42). Here, the control device 139 may compare the equipment room identification information acquired in step S41 with the equipment room identification information stored in the equipment room storage unit 157 of the equipment key 155 inserted in the equipment key insertion port 137, and enable the unlock button 133 if they match.
[0158] Next, the control device 139 determines whether or not the unlock button 133 has been pressed (step S43). If it is determined that the unlock button 133 has not been pressed (step S43: No), the control device 139 waits until the unlock button 133 is pressed. If it is determined that the unlock button 133 has been pressed (step S43: Yes), the control device 139 controls the camera 134 to capture an image of the maintenance worker (step S44). More specifically, the control device 139 illuminates the maintenance worker who is positioned opposite the unlock button 133 with the LED lighting 134a, and controls the camera 134 to capture an image of the maintenance worker.
[0159] Next, the control device 139 unlocks the equipment key lock device 137b of the equipment key 155 in which the same equipment room identification information as the equipment room identification information read in step S45 is stored (step S45). Specifically, the control device 139 transmits a drive signal to the equipment key lock device 137b. This releases the restriction, and the equipment key 155 becomes capable of being removed from the equipment key insertion port 137.
[0160] Finally, the control device 139 controls the locking device 136 to unlock it (step S52). This allows the maintenance worker to open the opening and closing door 131a and borrow the equipment key 155 stored in the equipment key storage space S2. The above describes the case where the maintenance worker receives a loan of a key. On the other hand, when returning a key, the flow is the same as the flow of loan described above, except that the equipment key 155 is inserted into an equipment key insertion port 137 in which the equipment key 155 is not inserted, among the multiple equipment key insertion ports 137.
[0161] By executing the key lending process according to the above-mentioned procedure, manual key handover is not required, and it is possible to reduce the cost of key management. As in the above-mentioned embodiment, by performing telephone number authentication in addition to password authentication, it is possible to improve the security of the key management system 101. Furthermore, by combining telephone number authentication with authentication using preregistered schedule information (scheduled time of use and place of use), it is possible to further improve the security of the key management system 101.
[0162] Although the key management system 101 according to one embodiment of the present invention has been described, the above-mentioned embodiment is merely an example for facilitating understanding of the present invention and does not limit the present invention. In other words, the present invention can be modified and improved without departing from the spirit thereof, and the present invention naturally includes equivalents thereof.
[0163] In the above embodiment, the unlocking permission signal output unit 64e of the key management server 110 has been described as transmitting an unlocking permission signal to the entrance key storage box 120 based on the result of the comparison by the telephone number authentication unit 112f, but this is not limiting. The unlocking permission signal output unit 64e may output an unlocking permission signal to the entrance key storage box 120 based on the comparison result after the telephone number authentication unit 112f has succeeded in telephone number authentication and further compares the personal identification information read by the card reader 125 of the entrance key storage box 120 from the identification information storage medium (driver's license or My Number card).
[0164] In this case, the maintenance company registration unit 112a accepts the personal identification information of the maintenance worker as registration information in advance and registers it in the maintenance company database 111a. If the telephone number authentication is successful, the telephone number authentication unit 112f acquires the personal identification information read by the card reader 125 of the entrance key storage box 120 via the communication device 114. Then, the telephone number authentication unit 112f compares the personal identification information read by the card reader 125 with the personal identification information registered in the maintenance company database 111a. If the comparison process is successful, the unlocking permission signal output unit 64e transmits an unlocking permission signal to the entrance key storage box 120. In this way, by combining authentication using personal identification information, it is possible to further improve the security of the key management system 101. The telephone number authentication unit 112f corresponds to a user identification information acquisition means and a user identification information authentication means.
[0165] In the above embodiment, the area-specific telephone number is described as being sent to the email address of the maintenance company terminal 160, but this is not limiting. The entrance key storage box 120 may be provided with an LCD display (corresponding to a display unit) that displays the area-specific telephone number, and the area-specific telephone number may be displayed on the LCD display to notify the maintenance worker of the area-specific telephone number.
[0166] In this case, the telephone number notifying unit 112d transmits a telephone number display instruction signal to the entrance key storage box 120 to cause the LCD display to display the area-specific telephone number. Upon receiving the telephone number display instruction signal, the entrance key storage box 120 causes the LCD display to display the area-specific telephone number. In this way, by displaying the area-specific telephone number on the LCD display provided in the entrance key storage box 120, the maintenance worker can easily grasp the area-specific telephone number compared to receiving the area-specific telephone number by email.
[0167] In the above embodiment, the facility key storage box 130 is described as being installed in the manager's room, but this is not limited thereto. The facility key storage box 130 may be installed in a security room.
[0168] In the above embodiment, the equipment key storage box 130 is described as storing the equipment key 155, but this is not limited to the above. The equipment key storage box 130 may store valuables that the manager deems necessary. For example, the equipment key storage box 130 may store documents such as ledgers and management books related to the apartment building H, or a safe. [Explanation of symbols]
[0169] 1 Authentication System 10 Authentication Server 11 Storage device 11a User Database 11b Schedule information database 11c Regional Telephone Number Table 12 Control device (computer) 12a User registration unit (registration information receiving means) 12b Schedule information registration unit (schedule information receiving means) 12c Password authentication section (password authentication means) 12d Telephone number notification unit (location information acquisition means, telephone number notification means) 12e Call line control unit (call information acquisition means) 12f Phone number authentication section (phone number authentication means) 12g Service Department 13 Input Devices 14 Communication equipment 20 Mobile phone terminals 101 Key management system (authentication system) 110 Key management server (authentication device) 111 Storage device 111a Maintenance Business Database 111b Key Usage Schedule Database 111c Regional Telephone Number Table 111d Key usage history database 111e Captured image storage unit 112 Control device (computer) 112a Maintenance business registration unit (registration information receiving means) 112b Key usage schedule registration unit (scheduled information receiving means) 112c Password authentication unit (password authentication means) 112d Telephone number notification unit (location information acquisition means, telephone number notification means) 112e Call line control unit (call information acquisition means) 112f telephone number authentication unit (telephone number authentication means, user identification information acquisition means, user identification information authentication means) 112g Unlock permission signal output unit (unlock permission signal transmitting means) 112h Key usage history update section 113 Input Devices 114 Communication equipment 120 Entrance key storage box (valuables storage device) 121 Key storage box body 121a Opening and closing door 121b Operation reception section 122 Unlock button 123 Camera 123a LED lighting 124 Emergency cylinder lock 125 Card reader (means for reading identification information) 126 Locking device 126a Engagement piece 127 Entrance key slot 127a Entrance key interface 127b Entrance key lock device 128 Communication Equipment 129 Control Device 129a Unlock permission signal acquisition unit 129b Shooting control unit 129c Lock control unit 130 Equipment key storage box (valuables storage device) 131 Key storage box body 131a Opening and closing door 131b Operation reception section 132 Entrance key slot 132a Entrance key interface 133 Unlock button 134 Camera 134a LED lighting 135 Emergency cylinder lock 136 Locking device 136a Engagement piece 137 Equipment key slot 137a Equipment Key Interface 137b Equipment key locking device 138 Storage device 139 Control Device 139a Equipment room identification information acquisition unit 139b Shooting control section 139c Lock control unit 150 Entrance key 151 Key body 152 Equipment room storage section 152a Locked part 155 Equipment key 156 Key body 157 Equipment room storage section 157a Locked part 160 Maintenance company terminal H apartment complex S1 Entrance key storage space S2 Equipment key storage space
Claims
1. A computer of an authentication system that performs authentication processing using the telephone number of a mobile phone terminal used by a user, a registration information receiving means for receiving an authentication password of the user and the telephone number of the mobile phone terminal as registration information; a password authentication means for performing password authentication using the authentication password; a location information acquiring means for acquiring location information of the user from the mobile phone terminal; a telephone number notifying means for notifying the mobile phone terminal of the user who has succeeded in the password authentication of a region-specific telephone number associated with the location information acquired by the location information acquiring means; a call information acquiring means for acquiring, when receiving an incoming call to the area-specific telephone number, call information including a calling telephone number relating to the incoming call; an authentication program that functions as a telephone number authentication means for comparing the calling telephone number acquired by the calling information acquisition means with the telephone number accepted by the registration information acceptance means;
2. the authentication program causes the computer to function as a schedule information receiving means for receiving schedule information including a scheduled time of use of the authentication system; When the call information acquisition means receives the call to the area-specific telephone number, the call information acquisition means acquires the caller telephone number and the time of the call related to the call, 2. The authentication program according to claim 1, wherein said telephone number authentication means collates said incoming call time with said scheduled use time.
3. 3. The authentication program according to claim 2, wherein the area-specific telephone number is associated with an output of a one-way function to which at least one of the location information and the scheduled use time is input.
4. the schedule information includes a planned location when the user uses the authentication system together with the planned time of use, 3. The authentication program according to claim 2, wherein the telephone number authentication means collates the location information acquired by the location information acquisition means with the intended use location.
5. The authentication program according to any one of claims 1 to 4, characterized in that the authentication program causes the computer to function as an unlocking permission signal sending means for sending an unlocking permission signal to a valuables storage device that stores one or more valuables related to a building and is managed for locking and unlocking when a match by the telephone number authentication means is successful.
6. 6. The authentication program according to claim 5, wherein the telephone number notification means transmits to the valuables storage device a telephone number display instruction signal for causing the valuables storage device to display the area-specific telephone number on a display unit of the valuables storage device.
7. the valuables storage device includes an identification information reading means for reading user identification information capable of identifying the user from an identification information storage medium carried by the user, The authentication program includes a user identification information acquiring means for acquiring the user identification information read by the identification information reading means, functioning as a user identification information authentication means for verifying the user identification information; The registration information receiving means receives the user identification information as registration information, 6. The authentication program according to claim 5, wherein the user identification information authentication means collates the user identification information acquired by the user identification information acquisition means with the user identification information accepted by the registration information acceptance means.
8. 2. An authentication device comprising the computer according to claim 1, the authentication device causing the computer to execute the authentication program.
9. An authentication system comprising: the authentication device according to claim 8; and the valuables storage device according to claim 5.
Citation Information
Patent Citations
Illegal access prevention system
JP1999282803A
Lock device, lock control system and method for controlling lock
JP2003148017A
Delivery and collection system by home delivery locker
JP2020154572A
Security system
JP2015151739A