Access control system, access control method, and access control program
The access control system addresses the challenge of unauthorized access by using a tag management device and one-time ID determination device to control access with unique information, ensuring secure and timely access to web pages or servers.
Patent Information
- Application Number
- JP2025043561
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-11-04
AI Technical Summary
Existing access control systems using electronic tags struggle to ensure timely and authorized access to web pages or servers, leading to potential unauthorized access.
An access control system that includes a tag management device, a parameter determination device, an access target device, and a one-time ID determination device, which uses unique information from electronic tags to control access by determining the first-time acquisition of unique information and issuing second unique information for secure access.
The system effectively prevents unauthorized access by ensuring that access to the access target device is only permitted when the second unique information is acquired for the first time, thereby controlling and securing access.
Smart Images

Figure 2025087926000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an access control system, an access control method, and an access control program.
Background Art
[0002] In recent years, short-range wireless communication using electronic tags such as NFC (Near Field Communication) tags has been utilized in a wide variety of fields. For example, electronic tags are installed on advertising posters, products, or their peripheries, and by bringing an information terminal such as a smartphone close to the electronic tag, it is possible to display a web page containing information about the product such as an advertisement. For example, Patent Document 1 discloses a technique for managing such an electronic tag.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Depending on services that utilize electronic tags, for example, when a service user visits a location where an electronic tag is installed, there may be a case where access to a web page at a specific URL is to be permitted using the electronic tag. Therefore, it is desirable that access to an access target device such as a server be performed at a timing intended by the service provider.
[0005] An object of the present disclosure is to provide an access control system, an access control method, and an access control program capable of preventing unauthorized access.
Means for Solving the Problems
[0006] To achieve the above object, the access control system according to the present disclosure includes a tag management device that stores the tag identification information and the second URL in association with each other specified by the first URL, a parameter determination device, an access target device specified by the second URL, and a one-time ID determination device that issues the second unique information to the tag management device. The tag management device acquires the tag identification information and the first unique information from the electronic tag via a reading device, and when the parameter determination device determines that the acquisition of the first unique information is the first time, the tag management device acquires the second unique information from the one-time ID determination device, accesses the access target device of the second URL corresponding to the tag identification information with the second unique information added to the second URL, and when the one-time ID determination device determines that the acquisition of the second unique information transmitted by the access target device is the first time, access to the access target device by the tag management device and the reading device is permitted. The first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time the parameter determination device determines that the acquisition of the first unique information is the first time.
[0007] To achieve the above object, the access control method according to the present disclosure is an access control method of an access control system including a tag management device that stores the tag identification information and the second URL in correspondence with each other specified by the first URL, a parameter determination device, an access target device specified by the second URL, and a one-time ID determination device that issues second unique information to the tag management device. The method includes: a step in which the tag management device acquires the tag identification information and the first unique information from an electronic tag via a reading device; a step in which when the parameter determination device determines that the acquisition of the first unique information is the first acquisition, the second unique information is acquired from the one-time ID determination device; a step in which the access target device of the second URL corresponding to the tag identification information is accessed by adding the second unique information to the second URL; and a step in which when the one-time ID determination device determines that the acquisition of the second unique information transmitted by the access target device is the first acquisition, access to the access target device by the tag management device and the reading device is permitted. The first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time the parameter determination device determines that the acquisition of the first unique information is the first acquisition.
[0008] To achieve the above object, an access control program according to the present disclosure is an access control program executed by a computer of an access control system including a tag management device that stores, in association with each other, tag identification information and a second URL specified by a first URL, a parameter determination device, an access target device specified by the second URL, and a one-time ID determination device that issues second unique information to the tag management device. The access control program includes a step of acquiring the tag identification information and first unique information from an electronic tag via a reading device, a step of acquiring the second unique information from the one-time ID determination device when the parameter determination device determines that the first unique information is acquired for the first time, a step of accessing the access target device at the second URL by adding the second unique information to the second URL corresponding to the tag identification information, and a step of permitting access to the access target device by the tag management device and the reading device when the one-time ID determination device determines that the second unique information transmitted by the access target device is acquired for the first time. The first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time the parameter determination device determines that the first unique information is acquired for the first time.
Effect of the Invention
[0009] According to the access control system, access control method, and access control program of the present disclosure using the above means, unauthorized access can be prevented.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0011] Each embodiment of the present disclosure will be described below. In the present disclosure, the “electronic tag” is also called an IC tag, an RF tag, or a wireless tag, and is a tag using RFID (Radio Frequency Identification) technology that reads and writes data of an IC chip in the tag in a non-contact manner using radio waves. The “NFC tag” is one of the standards of electronic tags, and is a tag that uses a frequency of 13.56 MHz and uses short-range wireless communication with a communication distance of about 10 cm, which is relatively shorter than that of other RFID. In the following embodiments, an example using an NFC tag as the electronic tag will be described, but the electronic tag is not limited to the NFC tag. Other electronic tags using short-range wireless communication similar to the NFC tag may be used.
[0012] [Embodiment 1] [Configuration] FIG. 1 is an overall configuration diagram of an access control system 1 according to Embodiment 1. The access control system 1 includes a reader device 2, a tag management device 4, a contractor terminal 4-1, a parameter determination device 5, an access target device 6 functioning as a web server, and a one-time ID determination device 7, which are connected via a communication network such as the Internet.
[0013] The reader device 2 is an information processing terminal owned by a general customer (end user) who receives services from a contractor. The reader device 2 in the present embodiment is assumed to be a smartphone, but it may be other information terminals or devices such as a server, a personal computer, a tablet terminal, or a mobile phone.
[0014] The NFC tag 3 is a passive electronic tag that can be read by a reading device 2 (information terminal). The NFC tag 3 stores, in a storage unit within the internal IC, a first URL 311 that identifies the tag management device 4 and tag identification information 312 associated with each NFC tag 3. Further, the NFC tag 3 has a function of generating first unique information 313 and causing the reading device 2 to acquire it when a reading process is performed by the reading device 2. The first unique information 313 is unique information issued as a different unique value for each reading process of the NFC tag 3 by the reading device 2. The first unique information 313 in the present embodiment is a rolling code added to the first URL 311.
[0015] The tag management device 4 is an information processing terminal under the management of a service provider that provides services using a plurality of NFC tags 3. Although the tag management device 4 in the present embodiment assumes a server, it may be other devices such as a personal computer, smartphone, tablet terminal, mobile phone, etc. The tag management device 4 is specified by the first URL 311.
[0016] The contractor terminal 4-1 is a processing terminal of a contractor who has concluded a contract under the contract management of the service provider. Although the contractor terminal 4-1 in the present embodiment assumes a personal computer, it may be other terminals or devices such as a server, smartphone, tablet terminal, mobile phone, smartphone, etc.
[0017] The parameter determination device 5 manages the first unique information 313 acquired when the reading device 2 reads the NFC tag 3 as the first unique information 511 and has a function of controlling access by the reading device 2 to the access target device 6. Although the parameter determination device 5 in the present embodiment assumes a server, it may be other devices such as a personal computer, smartphone, tablet terminal, mobile phone, etc.
[0018] The access target device 6 is, for example, a general web server specified by the second URL 432 described later, and may be under the management of a service provider or under the management of others. Further, the access target device 6 may have a web server function as a part of its functions. The access target device 6 stores data of so-called web pages. The web pages include content information such as text, images, videos, etc., and various functions such as an account authentication function and a settlement function.
[0019] The one-time ID determination device 7 has a function of issuing the second unique information 711 to the tag management device 4. Further, the one-time ID determination device 7 has a function of determining whether or not the access to the access target device 6 is directly associated with the reading operation (reading process) of the NFC tag 3 by the reading device 2, using the second unique information 711 and the access flag 712. The access flag 712 is history data of the access of the reading device 2 to the access target device 6, and can be, for example, a counter that counts the number of accesses, or an arbitrary value indicating "accessed". Although the one-time ID determination device 7 of the present embodiment assumes a server, it may be other devices such as a personal computer, a smartphone, a tablet terminal, or a mobile phone.
[0020] The reading device 2, the tag management device 4, the contractor terminal 4-1, the parameter determination device 5, the access target device 6, and the one-time ID determination device 7 appropriately include some or all of an input unit, a display unit, a communication unit, an information processing unit (control unit), and a storage unit. Further, the reading device 2 has a reader function capable of acquiring tag information by holding (or contacting or approaching) the NFC tag 3. The NFC tag 3 is, for example, a seal-type tag, and is attached to products, posters, etc. in the contractor's store. Hereinafter, each configuration will be described in detail.
[0021] The reading device 2 includes a control unit 21, a communication unit 22, a display unit 23, and a storage unit 24. The communication unit 22 has a function of reading information from the NFC tag 3 and a wired or wireless communication function with external devices such as the tag management device 4. The display unit 23 displays an access screen (specifically, for example, a web page screen) of the access target device 6 specified by the second URL 432 associated with the tag identification information 312 by the tag management device 4.
[0022] The storage unit 24 stores the reading device identification information 241. The reading device identification information 241 is, for example, the unique information of the reading device 2 or the user information associated with the reading device 2. Note that programs such as the access control program of the present embodiment are stored in the storage unit 24.
[0023] The tag management device 4 includes a control unit 41, a communication unit 42, and a storage unit 43.
[0024] The communication unit 42 has a function of acquiring the tag information (the first URL 311, the tag identification information 312, and the first unique information 313) from the NFC tag 3 from the reading device 2 via a communication network. The reading device 2 reads the tag information from the NFC tag 3 to acquire the first URL 311 and accesses the tag management device 4 based on the first URL 311. Then, the reading device 2 transmits the tag identification information 312 and the first unique information 313, which are the read tag information, to the tag management device 4.
[0025] The control unit 41 has a function of referring to the storage unit 43 and transmitting the second URL 432 associated with the tag identification information 312 acquired by the communication unit 42 to the reading device 2. In addition, the control unit 41 can also edit (create, change, delete) the information stored in the storage unit 43.
[0026] The storage unit 43 stores information such as the tag identification information 431, the second URL 432 (redirect information), and the second unique information 433 in correspondence. Note that programs such as the access control program of the present embodiment are stored in the storage unit 43.
[0027] <Flow of processing> Next, the operation of the access control system 1 according to Embodiment 1 will be described with reference to FIG. 1. Here, a processing example in which one reading device 2 performs a reading operation on the NFC tag 3 is described. However, when there are a plurality of reading devices 2, it is assumed that the same operation is performed for each reading device 2. Further, the processing of each device (2, 4 to 7, 4-1) is executed by the control unit of each device (2, 4 to 7, 4-1).
[0028] In step S101, the reading device 2 uses the reading function for the NFC tag 3 to acquire the first URL 311, the tag identification information 312, and the first unique information 313 from one NFC tag 3. The reading device 2 accesses the tag management device 4 via the communication network using the acquired first URL 311. At this time, the reading device 2 transmits the tag identification information 312 and the first unique information 313 to the tag management device 4. Therefore, the tag management device 4 can acquire the tag identification information 312, the first unique information 313, etc. from the NFC tag 3 via the reading device 2.
[0029] In step S102, the tag management device 4 encrypts the first unique information 313 and transmits it to the parameter determination device 5.
[0030] In step S103, the parameter determination device 5 decrypts the first unique information 313 transmitted from the tag management device 4, and determines whether the decrypted first unique information 313 matches any of the plurality of first unique information 511 stored in the storage unit of the parameter determination device 5. When the first unique information 313 does not match the first unique information 511, the parameter determination device 5 transmits a determination result of "valid" to the tag management device 4, and adds and stores the acquired first unique information 313 as the first unique information 511 in the storage unit. When the tag management device 4 receives the determination result of "valid", it executes the processing of step S104.
[0031] On the other hand, when the first unique information 313 matches the first unique information 511, the parameter determination device 5 transmits a determination result of "invalid" to the tag management device 4. When the tag management device 4 receives the determination result of "invalid", it interrupts the execution of the processing after step S104. When interrupting the processing, the tag management device 4 transmits, for example, an output such as a display for transmitting an error or a warning to the reading device 2 and causes it to be displayed on the display unit 23.
[0032] By performing the determination process in this way, when the reading device 2 reads the NFC tag 3 and accesses the tag management device 4, since the first unique information 313 is generated for each reading process of the reading device 2, a determination result of "valid" is obtained. On the other hand, when the reading device 2 does not perform the operation of reading the NFC tag 3 and attempts to access the tag management device 4 by, for example, replicating the first URL 311 and the first unique information 313 using the result of a past reading process or the reading result by another reading device 2, the first unique information 511 stored in the parameter determination device 5 and the first unique information 313 match, so a determination result of "invalid" is obtained. As a result, the access of the reading device 2 to the tag management device 4 without going through the reading process of the NFC tag 3 is determined to be unauthorized and rejected.
[0033] In step S104, the tag management device 4 transmits a request for acquiring second unique information to the one-time ID determination device 7. The one-time ID determination device 7 that has received the acquisition request from the tag management device 4 issues second unique information 711 (see FIG. 3). Then, the one-time ID determination device 7 stores the issued second unique information 711 in the storage unit. The process of step S104 is premised on the determination result that the first unique information 313 is "valid" in step S103. Therefore, the second unique information 711 is unique information that is issued every time it is determined in step S103 that the parameter determination device 5 has acquired the first unique information 511 for the first time.
[0034] In step S105, the one-time ID determination device 7 transmits the second unique information 711 to the tag management device 4. Therefore, when it is determined by the parameter determination device 5 that the acquisition of the first unique information 313 is the first time, the tag management device 4 can acquire the second unique information 711 from the one-time ID determination device 7.
[0035] In step S106, the tag management device 4 refers to the storage unit 43 and acquires the second URL 432 associated with the tag identification information 312(431) acquired from the reading device 2. The tag management device 4 accesses the access target device 6 specified by the second URL 432 corresponding to the tag identification information 431. At this time, the second unique information 433 is added to the second URL 432 (that is, as a URL including the second URL 432 and the second unique information 433) and transmitted to the access target device 6.
[0036] Alternatively, after step S105, the tag management device 4 may transmit the second URL 432 and the second unique information 433 to the reading device 2. Thereafter, the reading device 2 may be configured to access the access target device 6 of the redirect destination using the second URL 432 acquired from the tag management device 4.
[0037] In step S107, the access target device 6 receives the second unique information 433 received from the tag management device 4 (or the reading device 2) by the one-time ID determination device 7.
[0038] In step S108, the one-time ID determination device 7 determines whether the second unique information 433 transmitted from the tag management device 4 matches any of the multiple pieces of second unique information 711 stored in the storage unit of the one-time ID determination device 7. When the second unique information 433 matches the second unique information 711 and the access flag 712 corresponding to the second unique information 433 used for the determination indicates the first (or initial) reference, the one-time ID determination device 7 transmits the determination result of "valid" to the access target device 6 and sets the access flag 712 to "referenced" (or, when representing the number of references, increases the count by 1). When the access target device 6 receives the determination result of "valid", it permits access from the reading device 2 and causes information such as a web page to be displayed on the display unit 23 of the reading device 2 via the tag management device 4 or directly to the reading device 2.
[0039] On the other hand, when the second unique information 433 does not match the second unique information 711, or when the second unique information 433 matches the second unique information 711 and the access flag 712 corresponding to the second unique information 711 used for the determination indicates "referenced" (or has been referenced two or more times), the one-time ID determination device 7 transmits the determination result of "invalid" to the access target device 6. Whether the access flag 712 indicates two or more references can be determined based on whether the access flag 712 is 1 or more, or whether the access flag 712 has a value indicating "referenced" or "accessed". When the access target device 6 receives the determination result of "invalid", it rejects access from the reading device 2 and interrupts the execution of subsequent processing. When interrupting the processing, the access target device 6 transmits, for example, an output such as a display conveying an error or a warning to the reading device 2 and causes it to be displayed on the display unit 23. In this way, the one-time ID determination device 7 permits access to the access target device 6 by the tag management device 4 and the reading device 2 when it is determined that the second unique information 433 transmitted by the access target device 6 is the first acquisition.
[0040] (Program) FIG. 3 is a schematic block diagram showing the configuration of the computer 101. The computer 101 includes a CPU 102, a main memory device 103, an auxiliary storage device 104, and an interface 105. The CPU 102 may be a GPU.
[0041] Here, the details of the program for realizing each function constituting the tag management device 4 according to the first embodiment will be described. Note that the programs of the tag management device 4 according to the second and third embodiments are the same.
[0042] The reading device 2, the tag management device 4, the contractor terminal 4-1, the parameter determination device 5, the access target device 6 functioning as a web server, and the one-time ID determination device 7 of the present embodiment are implemented on the computer 101. Note that the reading timing management device 8 (second embodiment) and the access time management device 9 (third embodiment) described later are also implemented on the computer 101. Then, the operations of the respective components of each of the devices 2, 4, 4-1, 5 to 9 are stored in the auxiliary storage device 104 in the form of a program. The CPU 102 reads the program from the auxiliary storage device 104 and expands it in the main memory device 103, and executes the above processing according to the program. Further, the CPU 102 secures a storage area corresponding to the above-described storage unit in the main memory device 103 according to the program.
[0043] Specifically, the program causes the computer to execute a process of acquiring tag identification information 312 and first unique information 313 from the NFC tag 3 (electronic tag) via the reading device 2 in the computer 101, a process of acquiring second unique information 433 from the one-time ID determination device 7 when the parameter determination device 5 determines that the first unique information 313 is acquired for the first time, a process of accessing the access target device 6 of the second URL 432 corresponding to the tag identification information 312 by adding the second unique information 433 to the second URL 432, and a process of permitting access to the access target device 6 by the tag management device 4 and the reading device 2 when the one-time ID determination device 7 determines that the second unique information 433 transmitted by the access target device 6 is acquired for the first time.
[0044] Note that the auxiliary storage device 104 is an example of a non-transitory tangible storage medium. Other examples of non-transitory tangible storage media include storage media such as magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, and semiconductor memories connected via the interface 105.
[0045] Also, the program may be for realizing a part of the functions described above. Furthermore, the program may be what realizes the functions described above in combination with other programs already stored in the auxiliary storage device 104, that is, a so-called differential file (differential program).
[0046] [Embodiment 2] Next, the access control system 1A of Embodiment 2 will be described. FIG. 4 is an overall configuration diagram of the access control system 1A according to Embodiment 2. In the description of the access control system 1A, for configurations similar to those of the access control system 1 of Embodiment 1, the same reference numerals are used and the description thereof is omitted or simplified.
[0047] The access control system 1A further includes a reading timing management device 8 in addition to the reading device 2, the tag management device 4, the parameter determination device 5, the access target device 6, and the one-time ID determination device 7 described in Embodiment 1. The reading timing management device 8 stores the tag identification information 811 and the reading time 812 of the tag identification information 312 by the reading device 2.
[0048] Next, the operation of the access control system 1A according to Embodiment 2 will be described. The access control system 1A further includes the processes of step S111 and step S112 in addition to the processes of the access control system 1. Also, step S101' performs substantially the same process as step S101, but the details will be described below.
[0049] First, in step S101', the reading device 2 acquires tag information (the first URL 311, tag identification information 312, and first unique information 313) from the NFC tag 3. Using the first URL 311 included in the acquired tag information, the reading device 2 accesses the tag management device 4 via the communication network. At this time, the reading device 2 transmits the tag identification information 312, the first unique information 313, the reading time of the NFC tag 3, and the user attribute information of the reading device 2 to the tag management device 4. Therefore, the tag management device 4 can acquire the tag identification information 312, the first unique information 313, the reading time, etc. from the NFC tag 3 via the reading device 2. Note that the reading time can be acquired from the local time (e.g., internal clock) of the reading device 2. Also, the reading time may be acquired from the local time (e.g., internal clock) of the tag management device 4. After the process of step S101', the process of step S111 is performed.
[0050] In step S111, the tag management device 4 transmits the reading time of the NFC tag 3 by the reading device 2 to the reading timing management device 8. When the reading timing management device 8 receives the tag identification information 312 and the reading time from the tag management device 4, it stores them in the internal storage unit as the tag identification information 811 and the reading time 812, respectively.
[0051] In step S112, the reading timing management device 8 refers to the storage unit and searches for whether the same tag identification information 811 as the currently acquired tag identification information 312 is registered. When the same tag identification information 811 as the currently acquired tag identification information 312 is registered, the reading timing management device 8 determines whether a predetermined time has elapsed from the reading time by the reading device 2 of the currently acquired tag identification information 312 to the reading time by the reading device 2 of the most recently acquired tag identification information 811. If the reading timing management device 8 determines that the predetermined time has elapsed, it transmits the determination result of "valid" (or access "permitted") to the tag management device 4. When the reading timing management device 8 determines "valid", the subsequent processes from step S102 and later described above are executed.
[0052] On the other hand, if the reading timing management device 8 determines that the predetermined time has not elapsed, it transmits the determination result of "invalid" (or access "denied") to the tag management device 4. After that, the execution of subsequent processing is interrupted. When interrupting the processing, the tag management device 4 transmits, for example, an output such as a display for transmitting an error or a warning to the reading device 2 and causes it to be displayed on the display unit 23.
[0053] In this way, when the reading time of the currently acquired tag identification information 312 by the reading device 2 has elapsed a predetermined time from the reading time of the tag identification information 431 most recently acquired by the reading device 2, the tag management device 4 permits access to the access target device 6. The predetermined time for the determination process in step S112 can be set in advance, set dynamically, or set according to the service mode. The predetermined time used in the determination in step S112 may be set as the elapsed time in units of, for example, days, hours, minutes, or seconds. Alternatively, for the elapse of the predetermined time, it may be set as an absolute time set in advance, such as whether 12 o'clock has elapsed or 24 o'clock has elapsed.
[0054] In the access control system 1A of Embodiment 2, for example, the NFC tag 3 is installed in a restaurant, and a customer who visits the store performs a proximity or contact operation of the reading device 2 to the NFC tag 3, thereby accessing the access target device 6 for adding point data to the reading device 2. It can be configured to let. In this case, if the reading process of the NFC tag 3 by the reading device 2 has not elapsed a predetermined time, the access control system 1A can reject multiple accesses of the reading device 2 to the access target device 6. Therefore, it is possible to prevent multiple point givings that exceed the number of store visits in one meal (for example, breakfast, lunch, or dinner). As a result, the contractor can provide the intended service of giving points to customers for each store visit using the access control system 1A.
[0055] [Embodiment 3] Next, the access control system 1B of Embodiment 3 will be described. FIG. 5 is an overall configuration diagram of the access control system 1B according to Embodiment 3. In the description of the access control system 1B, for the configurations similar to those of the access control system 1 of Embodiment 1, the same reference numerals will be used and the description thereof will be omitted or simplified.
[0056] In addition to the reader 2, tag management device 4, parameter determination device 5, access target device 6, and one-time ID determination device 7 described in Embodiment 1, the access control system 1B further includes an access time management device 9. The access time management device 9 stores the access time 911 of the access target device 6 by the reader 2 and the reader identification information 912 of the reader 2. The access time management device 9 of this embodiment is installed corresponding to the access target device 6.
[0057] Next, the operation of the access control system 1B according to Embodiment 3 will be described. The access control system 1B further includes the processes of step S121 and step S122 with respect to the processes of the access control system 1.
[0058] In step S101, the reader 2 acquires the first URL 311, tag identification information 312, and first unique information 313 from one NFC tag 3. The reader 2 accesses the tag management device 4 via the communication network using the acquired first URL 311. At this time, the reader 2 transmits the tag identification information 312, the first unique information 313, and the reader identification information 241 (see FIG. 2) to the tag management device 4.
[0059] Also, in step S106' executed after the process of step S105, the tag management device 4 refers to the storage unit 43 and acquires a second URL 432 associated with the tag identification information 312 obtained from the reading device 2. The tag management device 4 accesses the access target device 6 of the second URL 432 by adding the second unique information 711 to the second URL 432. Also, in step S106', the tag management device 4 transmits the reader identification information 241 (see FIG. 2) of the reading device 2 to the access target device 6.
[0060] Subsequently, the processes of step S107 and step S108 are performed. In step S108, when the access target device 6 receives a determination result of "valid", the process of step S121 is performed. On the other hand, when the access target device 6 receives a determination result of "invalid", the same process as in the first embodiment is performed, and access from the reading device 2 to the access target device 6 is rejected.
[0061] In step S121, the access target device 6 transmits the access time from the tag management device 4 or the reading device 2 and the reader identification information 241 of the reading device 2 to the access time management device 9, and stores them as the access time 911 and the reader identification information 912 in the storage unit of the access time management device 9, respectively. When the reader identification information 241 of the currently accessed reading device 2 is stored in the storage unit of the access time management device 9, the access time 911 is updated by the access time management device 9. When the reading device 2 reads the NFC tag 3 for the first time, the access time management device 9 stores the reader identification information 241 of the currently accessed reading device 2 as the reader identification information 912.
[0062] In step S122, the access time management device 9 refers to the storage unit and searches for the reader identification information 241 of the currently accessed reader device 2 from the reader identification information 912. When the same reader identification information 912 as the reader identification information 241 is registered, the access time management device 9 determines whether the current access trial time by the reader device 2 to the access target device 6 has elapsed a predetermined time from the last access trial time by the reader device 2 to the access target device 6. If the access time management device 9 determines that the predetermined time has not elapsed, it transmits a determination result of "valid" (or access "permitted") to the access target device 6. When the access time management device determines "valid", it permits access from the reader device 2 and causes information such as a web page to be displayed on the display unit 23 of the reader device 2 via the tag management device 4 or directly to the reader device 2.
[0063] Note that even when the reading of the NFC tag 3 by the reader device 2 is the first time, the access time management device 9 transmits a determination result of "valid" (or access "permitted") to the access target device 6.
[0064] On the other hand, if the access time management device 9 determines that the predetermined time has elapsed, it transmits a determination result of "invalid" (or access "denied") to the access target device 6. Thereafter, the execution of subsequent processing is interrupted. When interrupting the processing, the access target device 6 transmits, for example, an output such as a display of an error or a warning to the reader device 2 via the tag management device 4 and causes it to be displayed on the display unit 23.
[0065] In this way, when the reading device 2 attempts an access to the access target device 6 for the second and subsequent times without going through the reading process of the NFC tag 3, if the current access attempt time to the access target device 6 has not elapsed a predetermined time from the last access attempt time to the access target device 6 through the reading process of the NFC tag 3, the access to the access target device 6 is permitted. The predetermined time for the determination process in step S122 can be set in advance, set dynamically, or set according to the mode of the service. The predetermined time used in step S122 may be set as an elapsed time in units of, for example, days, hours, minutes, or seconds. Alternatively, for the elapse of the predetermined time, it may be set as an absolute time set in advance, such as whether 12 o'clock has elapsed or 24 o'clock has elapsed.
[0066] In the access control system 1B of Embodiment 3, for example, the NFC tag 3 is installed at a golf course or a remote visiting place far from home, etc., and a visitor can limit the place where the reading device 2 can access a web page by performing a proximity or contact operation of the reading device 2 to the NFC tag 3, or can permit access to a specific web page on the condition of access for a predetermined time only or periodically while making access to a specific place essential.
[0067] As described above, some embodiments of the present disclosure have been explained. However, these embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are to be included in the scope and gist of the invention, and are also to be included in the invention described in the claims and the equivalent scope thereof.
[0068] For example, although the tag management device 4, the parameter determination device 5, the access target device 6, the one-time ID determination device 7, the reading timing management device 8, and the access time management device 9 are configured as separate devices, a part of them may be configured as one device or system.
[0069] In addition, the access time management device 9 described in Embodiment 3 may be communicably connected to another access target device 6 (not shown). In this case, the access time management device 9 may further store, in the storage unit, corresponding to the access time 911 and the reader device identification information 912, the second URL (452) of the access target device 6.
[0070] In step S121, when the reader device identification information 241 (912) of the currently accessed reader device 2 is stored in the storage unit of the access time management device 9, the storage (that is, rewriting or updating) of the access time 911 and the reader device identification information 912 may not be performed. Therefore, in this case, the access time 911 is the time when the reader device 2 first accessed the access target device 6. By doing so, the reader device 2 can access the access target device 6 multiple times using the second URL 432, or the second URL 432 and the second unique information 433, without performing a read operation on the NFC tag 3 again for a predetermined time or period after first reading the NFC tag 3 and accessing the access target device 6.
[0071] In addition, the configurations of the systems shown in Embodiments 1 to 3 may be arbitrarily combined. For example, the access control system may include the read timing management device 8 described in Embodiment 2 and the access time management device 9 described in Embodiment 3.
[0072] The present disclosure includes, for example, the following aspects. [1] A tag management device that stores the tag identification information and the second URL in correspondence with each other, specified by the first URL, A parameter determination device, An access target device specified by the second URL, A one-time ID determination device that issues second unique information to the tag management device, Comprising: The tag management device: Acquires the tag identification information and the first unique information from the electronic tag via a reader device, When it is determined by the parameter determination device that the acquisition of the first unique information is the first time, the second unique information is acquired from the one-time ID determination device, The second URL with the second unique information added is accessed to the access target device corresponding to the tag identification information, When it is determined by the one-time ID determination device that the acquisition of the second unique information transmitted by the access target device is the first time, access to the access target device by the tag management device and the reading device is permitted, The first unique information is unique information issued for each reading process by the reading device, The second unique information is unique information issued each time the parameter determination device determines that the acquisition of the first unique information is the first time, Access control system. [2] The access control system further includes a reading timing management device that stores the tag identification information and the reading time of the tag identification information by the reading device, When the reading time of the currently acquired tag identification information by the reading device has elapsed a predetermined time from the reading time of the tag identification information acquired most recently by the reading device, access to the access target device is permitted by the tag management device, The access control system according to [1]. [3] The access control system further includes an access time management device that stores the access time of the access target device by the reading device and the reading device identification information of the reading device, When the reading device attempts a second or subsequent access to the access target device without going through the reading process of the electronic tag, and the current access attempt time to the access target device has not elapsed a predetermined time from the last access attempt time to the access target device through the reading process of the electronic tag, access to the access target device is permitted, The access control system according to [1]. [4] A tag management device that is specified by a first URL and stores the tag identification information and a second URL in correspondence with each other, a parameter determination device, an access target device specified by the second URL, a one-time ID determination device that issues second unique information to the tag management device, and an access control method for an access control system including: the tag management device acquiring the tag identification information and first unique information from an electronic tag via a reading device; when it is determined by the parameter determination device that the acquisition of the first unique information is the first acquisition, acquiring the second unique information from the one-time ID determination device; accessing the access target device of the second URL by adding the second unique information to the second URL; when it is determined by the one-time ID determination device that the acquisition of the second unique information transmitted by the access target device is the first acquisition, permitting access to the access target device by the tag management device and the reading device; including wherein the first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time the parameter determination device determines that the acquisition of the first unique information is the first acquisition. An access control method. [5] A tag management device that is specified by a first URL and stores the tag identification information and a second URL in correspondence with each other, a parameter determination device, an access target device specified by the second URL, a one-time ID determination device that issues second unique information to the tag management device, and an access control program executed by a computer of an access control system including: the access control program A step of obtaining the tag identification information and the first unique information from the electronic tag via a reading device; A step of obtaining the second unique information from the one-time ID determination device when the parameter determination device determines that the acquisition of the first unique information is the first time; A step of accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; A step of permitting access to the access target device by the tag management device and the reading device when the one-time ID determination device determines that the acquisition of the second unique information transmitted by the access target device is the first time; To cause a computer to execute, The first unique information is unique information issued for each reading process by the reading device, The second unique information is unique information issued each time the parameter determination device determines that the acquisition of the first unique information is the first time. Access control program.
Explanation of symbols
[0073] 1, 1A, 1B Access control system 2 Reading device 3 NFC tag 4 Tag management device 4-1 Contractor terminal 5 Parameter determination device 6 Access target device 7 One-time ID determination device 8 Reading timing management device 9 Access time management device 21 Control unit 22 Communication unit 23 Display unit 24 Storage unit 41 Control unit 42 Communication unit 43 Storage unit 101 Computer 102 CPU 103 Main memory device 104 Auxiliary storage device 105 Interface 241 Reader identification information 311 First URL 312 Tag identification information 313 First unique information 431 Tag identification information 432 Second URL 433 Second unique information 511 First unique information 711 Second unique information 712 Access flag 811 Tag identification information 812 Reading time 911 Access time 912 Reader identification information
Claims
1. a tag management device that is specified by a first URL and that stores tag identification information and a second URL in association with each other; A parameter determination device; an access target device identified by the second URL; a one-time ID determination device that issues second unique information to the tag management device; Equipped with The tag management device includes: acquiring the tag identification information and the first unique information from the electronic tag via a reader; When the parameter determination device determines that the first unique information has been obtained for the first time, the second unique information is obtained from the one-time ID determination device; accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; when the one-time ID determination device determines that the second unique information transmitted by the access target device is acquired for the first time, access to the access target device by the tag management device and the reading device is permitted; the first unique information is unique information issued for each reading process by the reading device, the second unique information is unique information issued each time the parameter determination device determines that the first unique information has been acquired for the first time; Access control systems.
2. a read timing management device that stores the tag identification information and a time at which the tag identification information is read by the reader, the tag management device is permitted to access the access target device when a predetermined time has elapsed since a time when the tag identification information currently obtained was read by the reader from the tag identification information most recently obtained by the reader; The access control system of claim 1 .
3. an access time management device that stores an access time of the access target device by the reader and reader identification information of the reader, When the reading device attempts to access the access target device for the second or subsequent time without going through the reading process of the electronic tag, if the current access attempt time to the access target device has not elapsed a predetermined time from the last access attempt time to the access target device via the reading process of the electronic tag, access to the access target device is permitted. The access control system of claim 1 .
4. a tag management device that is specified by a first URL and that stores tag identification information and a second URL in association with each other; A parameter determination device; an access target device identified by the second URL; a one-time ID determination device that issues second unique information to the tag management device; An access control method for an access control system comprising: The tag management device, acquiring the tag identification information and the first unique information from the electronic tag via a reader; acquiring the second unique information from the one-time ID judgment device when the parameter judgment device judges that the first unique information has been acquired for the first time; accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; when it is determined by the one-time ID determination device that the second unique information transmitted by the access target device is acquired for the first time, access to the access target device by the tag management device and the reading device is permitted; Including, the first unique information is unique information issued for each reading process by the reading device, the second unique information is unique information issued each time the parameter determination device determines that the first unique information has been acquired for the first time; Access control methods.
5. a tag management device that is specified by a first URL and that stores tag identification information and a second URL in association with each other; A parameter determination device; an access target device identified by the second URL; a one-time ID determination device that issues second unique information to the tag management device; An access control program executed on a computer of an access control system comprising: The access control program is acquiring the tag identification information and the first unique information from the electronic tag via a reader; acquiring the second unique information from the one-time ID judgment device when the parameter judgment device judges that the first unique information has been acquired for the first time; accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; when it is determined by the one-time ID determination device that the second unique information transmitted by the access target device is acquired for the first time, access to the access target device by the tag management device and the reading device is permitted; Run the following on your computer: the first unique information is unique information issued for each reading process by the reading device, the second unique information is unique information issued each time the parameter determination device determines that the first unique information has been acquired for the first time; Access control programs.
Citation Information
Patent Citations
Information provision system, information provision method, and portable wireless communication terminal
JP2004309836A
Secure storage systems and methods
US20190333304A1
Authentication method, authentication system, and tag device thereof, information reference client, authentication server, and information server
WO2006087784A1
Management server, information distribution system, application program and registration terminal
JP2013250934A