Portable terminal, access control method, and access control program

The mobile terminal system controls access based on proximity, addressing the risk of simultaneous theft and ensuring secure server access only when devices are near each other, enhancing usability and security.

JP2025108132AActive Publication Date: 2025-07-23NEC PLATFROMS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024001841
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-10
Publication Date
2025-07-23
Estimated Expiration
2044-01-10

AI Technical Summary

Technical Problem

Existing access control methods require the loss prevention device and smartphone to be carried together, increasing the risk of both being stolen and limiting their usability when separated.

Method used

A mobile terminal system that grants access permission to a device based on proximity, allowing access only when within a predetermined threshold distance, using units to receive, grant, and instruct access permissions.

Benefits of technology

Prevents unauthorized access to servers by ensuring proximity and reduces the risk of simultaneous theft of both devices, while allowing normal use when separated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025108132000001_ABST
    Figure 2025108132000001_ABST
Patent Text Reader

Abstract

To appropriately prevent access to a server from a mobile terminal.SOLUTION: A portable terminal receives an access permission request for a prescribed device from another mobile terminal. If the distance from an own device to another mobile terminal is below a prescribed threshold value, the portable terminal grants a license for accessing the prescribed terminal to another portable terminal as a response to the request, and instructs the prescribed device to permit access from another portable terminal which has granted the license.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a mobile terminal, an access control method, and an access control program.

Background Art

[0002] There are cases where data and the like are downloaded by accessing a server from a mobile terminal such as a smartphone. Here, there is a technique for preventing access to the server from a lost or stolen mobile terminal (for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] The following analysis is made from the perspective of the present invention. Each disclosure of the above prior art documents is incorporated herein by reference.

[0005] In Patent Document 1, a smartphone whose distance from the loss prevention device exceeds a predetermined value transitions to a locked state. Therefore, according to the technique of Patent Document 1, it is possible to prevent access to the server from a lost or stolen smartphone.

[0006] However, in Patent Document 1, there is an inconvenience that the loss prevention device and the smartphone must always be carried as a set. In addition, since it is necessary to always carry them as a set, there is also a risk that both the loss prevention device and the smartphone will be stolen at once.

[0007] Therefore, an object of the present invention is to provide a technique that contributes to appropriately preventing access from a mobile terminal to a server.

Means for Solving the Problems

[0008] According to a first aspect of the present invention, an application receiving unit that receives an application for access permission to a predetermined device from another mobile terminal, a license granting unit that grants a license for access to the predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value, an access permission instruction unit that instructs the predetermined device to permit access from another mobile terminal to which the license has been granted, A mobile terminal including the above is provided.

[0009] According to a second aspect of the present invention, an application receiving step of receiving an application for access permission to a predetermined device from another mobile terminal, a license granting step of granting a license for access to the predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value, an access permission instruction step of instructing the predetermined device to permit access from another mobile terminal to which the license has been granted, An access control method by a mobile terminal including the above is provided.

[0010] According to a third aspect of the present invention, an application receiving process of receiving an application for access permission to a predetermined device from another mobile terminal, a license granting process of granting a license for access to the predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value, An access permission instruction process for instructing the predetermined device to allow access from other mobile terminals that have been licensed, An access control program is provided that causes a computer acting as a mobile terminal to execute.

Advantages of the Invention

[0011] According to each aspect of the present invention, a mobile terminal, an access control method, and an access control program that contribute to appropriately preventing access from the mobile terminal to the server are provided.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Modes for Carrying Out the Invention

[0013] Preferred embodiments of the present invention will be described in detail with reference to the drawings. Note that the reference numerals attached to the following description are for convenience of each element as an example to assist understanding, and are not intended to limit the present invention to the illustrated embodiments. Also, the connection lines between the blocks in each figure include both bidirectional and unidirectional ones. The one-way arrow schematically shows the flow of the main signal (data) and does not exclude bidirectionality. Further, in the circuit diagrams, block diagrams, internal configuration diagrams, connection diagrams, etc. shown in the present application disclosure, although not explicitly shown, input ports and output ports exist at the input ends and output ends of each connection line, respectively. The same applies to the input / output interface.

[0014] First, an overview of the present invention will be described. As shown in FIG. 1, the mobile terminal 100 includes an application receiving unit 110, a license granting unit 120, and an access permission instructing unit 130. The application receiving unit 110 receives an application for access permission to a predetermined device 300 from another mobile terminal 200. The license granting unit 120 grants a license for access to the predetermined device 300 to another mobile terminal 200 as a response to the application when the distance from the own device (mobile terminal 100) to another mobile terminal 200 is equal to or less than a predetermined threshold value. The access permission instructing unit 130 instructs the predetermined device 300 to permit access from another mobile terminal 200 to which the license has been granted.

[0015] A more specific example will be described. Here, let the predetermined device 300 be the server 300. Assume that the owner of the mobile terminal 100 is the person in charge of the server 300. Therefore, hereinafter, the mobile terminal 100 will be referred to as the "responsible person terminal 100". Also, assume that another mobile terminal 200 is a terminal personally owned by a subordinate of the responsible person. Therefore, hereinafter, another mobile terminal 200 will be referred to as the "subordinate terminal 200".

[0016] According to the present invention, access from the subordinate terminal 200 to the server 300 is permitted only when the distance from the supervisor terminal 100 is equal to or less than a predetermined threshold value (for example, a distance within which communication is possible by short-range wireless communication). Therefore, even if the subordinate terminal 200 is stolen, the thief has to perform access from the subordinate terminal 200 to the server 300 within the range where the supervisor can see, which is practically impossible.

[0017] On the other hand, even when the distance from the supervisor terminal 100 exceeds the predetermined threshold value, the functions of the subordinate terminal 200 are effective except for access to the server 300. That is, even if the subordinate terminal 200 is a terminal personally owned by a subordinate, there is no impact on private use.

[0018] In addition, since the owners of the supervisor terminal 100 and the subordinate terminal 200 are different persons, it can be said that the possibility that both the supervisor terminal 100 and the subordinate terminal 200 are stolen at the same time is low.

[0019] As described above, according to the present invention, it is possible to appropriately prevent access to the server from another mobile terminal (subordinate terminal 200).

[0020] [Embodiment 1] The above general outline will be described more specifically as Embodiment 1. Hereinafter, the mobile terminal 100 will also be referred to as the supervisor terminal 100, the other mobile terminal 200 will be referred to as the subordinate terminal 200, and the predetermined device 300 will be referred to as the server 300.

[0021] As shown in FIG. 2, the supervisor terminal 100 further includes an access rejection instruction unit 140 in addition to an application reception unit 110, a license granting unit 120, and an access permission instruction unit 130.

[0022] The application receiving unit 110 receives an application for access permission from the subordinate terminal 200 to the server 300. When the distance from the own device (the responsible person terminal 100) to the subordinate terminal 200 is equal to or less than a predetermined threshold value, the license granting unit 120 grants a license for access to the server 300 as a reply to the application to the subordinate terminal 200.

[0023] Here, the threshold value regarding the distance from the responsible person terminal 100 to the subordinate terminal 200 can be defined, for example, according to the standard of short-range wireless communication such as Bluetooth (registered trademark). A specific numerical example regarding the threshold value is 10 m of Bluetooth Class 2. If communication using Bluetooth is possible between the responsible person terminal 100 and the subordinate terminal 200, the license granting unit 120 determines that the distance from the responsible person terminal 100 to the subordinate terminal 200 is equal to or less than a predetermined threshold value.

[0024] Also, the application receiving unit 110 may receive the application for access permission from the subordinate terminal 200 to the server 300 via Bluetooth. That is, when the responsible person terminal 100 receives the application for access permission to the server 300 from the subordinate terminal 200 via Bluetooth, it can be said that the distance between the responsible person terminal 100 and the subordinate terminal 200 is equal to or less than a predetermined threshold value. Therefore, it is also possible to eliminate the distance determination by the license granting unit 120.

[0025] Note that the measurement of the distance from the responsible person terminal 100 to the subordinate terminal 200 is not limited to using short-range wireless communication, and various techniques can be applied. For example, the GPS (Global Positioning System) provided in the responsible person terminal 100 and the subordinate terminal 200 may be used.

[0026] The access permission instruction unit 130 instructs the server 300 to permit access from the subordinate terminal 200 to which a license has been granted. For example, the application reception unit 110 acquires the MAC address of the subordinate terminal 200 as an application from the subordinate terminal 200. The access permission instruction unit 130 notifies the acquired MAC address to the server 300 and configures the server 300 to permit access from the terminal having the notified MAC address (i.e., the subordinate terminal 200).

[0027] When the distance from the own device (the responsible person terminal 100) to the subordinate terminal 200 exceeds a predetermined threshold value, the access rejection instruction unit 140 instructs the server 300 to reject access from the subordinate terminal 200 to which a license has been granted. For example, when the Bluetooth communication being performed between the responsible person terminal 100 and the subordinate terminal 200 is disconnected, the access rejection instruction unit 140 determines that the distance from the responsible person terminal 100 to the subordinate terminal 200 exceeds a predetermined threshold value. Further, the access rejection instruction unit 140 may periodically measure the distance between the responsible person terminal 100 and the subordinate terminal 200.

[0028] Note that the function of the access rejection instruction unit 140 can also be achieved by making the license granted to the subordinate terminal 200 a license with an expiration date. That is, when the license granted to the subordinate terminal 200 is permanently valid, once permitted, access from the subordinate terminal 200 to the server 300 is possible even if it is not within the range where the responsible person can see. Therefore, the access rejection instruction unit 140 instructs the server 300 to reject access. On the other hand, when it is a license with an expiration date, when the expiration date has passed and access from the subordinate terminal 200 to the server 300 becomes impossible, the access rejection instruction to the server 300 becomes unnecessary.

[0029] For example, it is conceivable to use a license with a time password as a license with an expiration date. If the distance between the supervisor terminal 100 and the subordinate terminal 200 is equal to or less than a predetermined threshold value, the license granting unit 120 periodically grants a license with a time password to the subordinate terminal 200. The access permission instruction unit 130 notifies the server 300 of the time password. The server 300 determines whether to permit or reject access by verifying the time password when accessing from the subordinate terminal 200.

[0030] Hereinafter, the processing flow by the supervisor terminal 100 will be described. As shown in FIG. 3, the supervisor terminal 100 receives an application for access permission to the server 300 from the subordinate terminal 200 (step S01, Yes). Here, when the distance from the supervisor terminal 100 to the subordinate terminal 200 is equal to or less than a predetermined threshold value, the supervisor terminal 100 grants a license for accessing the server 300 to the subordinate terminal 200 (step S02). Then, the supervisor terminal 100 instructs the server 300 to permit access from the subordinate terminal 200 to which the license has been granted (step S03).

[0031] Thereafter, when the distance from the supervisor terminal 100 to the subordinate terminal 200 exceeds the predetermined threshold value (step S04, Yes), the supervisor terminal 100 instructs the server 300 to reject access from the subordinate terminal 200 (step S05).

[0032] As described above, according to the present invention, it is possible to appropriately prevent access to the server 300 from the subordinate terminal 200.

[0033] [Modification] The above model can be developed into various variations. As an example, as shown in FIG. 4, a predetermined device 300 is taken as a mobile router 300, and the owner of the mobile terminal 100 is assumed to be the owner of the mobile router 300. Also, the owner of another mobile terminal 200 is assumed to be a friend of the owner. In this variation model, it is possible to allow a friend to connect to the network via the mobile router 300 only within the range visible to the owner.

[0034] Moreover, the processing by the responsible terminal 100 (mobile terminal 100) may be executed by the server 300. For example, as shown in FIG. 5, the server 300 receives an application for access permission to itself (server 300) from another mobile terminal (subordinate terminal 200) (corresponding to the application receiving unit 110). Here, the server 300 inquires of the responsible terminal 100 whether the distance to the subordinate terminal 200 is equal to or less than a predetermined threshold value. As a result of the inquiry, if it is equal to or less than the predetermined threshold value, the server 300 grants a license for access to itself (server 300) to the subordinate terminal 200 (corresponding to the license granting unit 120 and the access permission instructing unit 130). Thereafter, when receiving a report from the responsible terminal 100 that the distance to the subordinate terminal 200 has exceeded the predetermined threshold value, the server 300 rejects the access from the subordinate terminal 200 (corresponding to the access rejection instructing unit 140).

[0035] [Embodiment 2] In Embodiment 1, when the distance from the responsible terminal 100 to the subordinate terminal 200 exceeds a predetermined threshold value, the access from the subordinate terminal 200 is rejected by the server 300. Therefore, in order to permit the access from the subordinate terminal 200 to the server 300 again, it is necessary to apply for access permission to the responsible terminal 100 again, which is troublesome. Here, it is conceivable to simplify the process of re-permitting the access from the subordinate terminal 200 to the server 300.

[0036] For example, as shown in FIG. 6, the supervisor terminal 100 may further include a rejection cancellation instruction unit 150. After instructing the server 300 to reject access, when the distance from the self-device (supervisor terminal 100) to the subordinate terminal 200 becomes equal to or less than a predetermined threshold again, the rejection cancellation instruction unit 150 instructs the server 300 to cancel the access rejection.

[0037] More specifically, even when the server 300 is in a state of rejecting access from the subordinate terminal 200, the server 300 may receive access from the subordinate terminal 200. At this time, the server 300 inquires of the supervisor terminal 100 about the distance from the supervisor terminal 100 to the subordinate terminal 200. If the distance from the supervisor terminal 100 to the subordinate terminal 200 is equal to or less than a predetermined threshold, the supervisor terminal 100 that has received the inquiry instructs the server 300 to cancel the access rejection.

[0038] Alternatively, the supervisor terminal 100 may actively measure the distance to the subordinate terminal 200 and, when the distance becomes equal to or less than a predetermined threshold, instruct the server 300 to cancel the access rejection.

[0039] In any case, the subordinate terminal 200 can resume access to the server 300 without going through the step of applying for access permission.

[0040] Note that from the above perspective, the license granted to the subordinate terminal 200 can also be regarded as a "conditional license" that becomes valid when the distance from the supervisor terminal 100 is equal to or less than the threshold.

[0041] [Variation] Note that the present invention can also be implemented as a guidance program that causes a computer, which serves as the mobile terminal 100, to execute the above-described processing. For example, as shown in FIG. 7, a computer serving as the mobile terminal 100 includes a memory, a CPU (Central Processing Unit), and an interface. By reading and executing the guidance program of the present invention from the memory, the CPU realizes processing modules corresponding to the application reception unit 110, the license granting unit 120, and the access permission instruction unit 130.

[0042] Some or all of the above-described embodiments can be described as follows in the appended claims, but are not limited thereto.

[0043] (Appended Claim 1) An application reception unit that receives an application for access permission to a predetermined device from another mobile terminal, A license granting unit that grants a license for access to a predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value, An access permission instruction unit that instructs the predetermined device to permit access from another mobile terminal to which the license has been granted, A mobile terminal including:

[0044] (Appended Claim 2) An access rejection instruction unit that instructs the predetermined device to reject access from another mobile terminal to which the license has been granted when the distance from the own device to the other mobile terminal exceeds a predetermined threshold value, the mobile terminal according to Appended Claim 1.

[0045] (Appended Claim 3) The mobile terminal according to Appended Claim 1 or 2, wherein the license is a license with an expiration date.

[0046] (Appended Claim 4) After instructing access rejection to the predetermined device, when the distance from the own device to another mobile terminal becomes equal to or less than a predetermined threshold again, a rejection cancellation instruction unit that instructs to cancel the access rejection to the predetermined device, A mobile terminal according to any one of Appendices 1 to 3, including.

[0047] (Appendix 5) An application reception step of receiving an application for access permission to a predetermined device from another mobile terminal, A license granting step of granting a license for access to a predetermined device to another mobile terminal as a response to the application when the distance from the own device to another mobile terminal is equal to or less than a predetermined threshold, An access permission instruction step of instructing the predetermined device to allow access from another mobile terminal to which the license has been granted, An access control method by a mobile terminal, including.

[0048] (Appendix 6) An application reception process of receiving an application for access permission to a predetermined device from another mobile terminal, A license granting process of granting a license for access to a predetermined device to another mobile terminal as a response to the application when the distance from the own device to another mobile terminal is equal to or less than a predetermined threshold, An access permission instruction process of instructing the predetermined device to allow access from another mobile terminal to which the license has been granted, An access control program that causes a computer as a mobile terminal to execute.

[0049] Note that the features described in Appendices 2 to 4 can also be expanded to the access control method and the access control program. For example, the rejection cancellation instruction unit can also be expanded as a rejection cancellation instruction step or a rejection cancellation instruction process.

[0050] Note that the disclosures of the above-cited patent documents and the like are hereby incorporated by reference into this document and can be used as the basis or part of the present invention as necessary. Within the scope of the entire disclosure of the present invention (including the claims), modifications and adjustments of the embodiments or examples can be made based on the basic technical idea. Also, within the scope of the entire disclosure of the present invention, various combinations or selections (including partial deletion) of various disclosure elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. That is, the present invention naturally includes all disclosures including the claims and various variations and modifications that could be made by those skilled in the art according to the technical idea. In particular, regarding the numerical ranges described in this document, any numerical value or small range included within the range should be construed as specifically described even without separate description. Furthermore, each disclosure item of the above-cited documents is, as necessary and in accordance with the spirit of the present invention, considered to be included in the disclosure of the present application as part of the disclosure of the present invention, and can be used in combination with the description items of this document, either in part or in whole.

Explanation of Reference Numerals

[0051] 100: Mobile terminal, responsible person terminal 110: Application reception unit 120: License granting unit 130: Access permission instruction unit 140: Access rejection instruction unit 150: Rejection cancellation instruction unit 200: Other mobile terminals, subordinate terminals 300: Predetermined device, server, mobile router

Claims

1. An application receiving unit that receives an application for access permission to a predetermined device from another mobile terminal; A license granting unit that grants a license for access to the predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value; An access permission instruction unit that instructs the predetermined device to permit access from another mobile terminal to which the license has been granted; A mobile terminal comprising the above.

2. The mobile terminal according to claim 1, further comprising an access rejection instruction unit that instructs the predetermined device to reject access from another mobile terminal to which the license has been granted when the distance from the own device to the other mobile terminal exceeds the predetermined threshold value.

3. The mobile terminal according to claim 1, wherein the license is a license with an expiration date.

4. The mobile terminal according to claim 1, further comprising a rejection cancellation instruction unit that instructs the predetermined device to cancel the access rejection when the distance from the own device to the other mobile terminal becomes equal to or less than the predetermined threshold value again after instructing the predetermined device to reject access.

5. An access control method by a mobile terminal, comprising: an application receiving step of receiving an application for access permission to a predetermined device from another mobile terminal; A license granting step of granting a license for access to the predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value; An access permission instruction step of instructing the predetermined device to permit access from another mobile terminal to which the license has been granted. An access control method by a mobile terminal, comprising the above.

6. An access control program that causes a computer as a mobile terminal to execute: an application receiving process of receiving an application for access permission to a predetermined device from another mobile terminal; A license granting process of granting a license for access to the predetermined device to another mobile terminal as a response to the application when the distance from the own device to the other mobile terminal is equal to or less than a predetermined threshold value; An access permission instruction process of instructing the predetermined device to permit access from another mobile terminal to which the license has been granted. An access control program that causes a computer as a mobile terminal to execute the above.

Citation Information

Patent Citations

  • Content management system and content management method

    JP2009009204A

  • System access using mobile devices

    JP2020511069A

  • Portable communication terminal, control method and control program thereof

    JP2014170429A