Access control system

The access control system shares personal authentication via a mobile terminal with another management system, simplifying user data management and reducing administrative burden by verifying external authentication results.

JP2025114978APending Publication Date: 2025-08-06AT WORKS
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
JP2024009248
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-08-06

AI Technical Summary

Technical Problem

Existing access control systems require the creation of a dedicated personal authentication system for each security system, which is time-consuming and costly, especially for large companies, and maintaining these systems is burdensome due to employee transfers, retirements, or hires.

Method used

An access control system that shares a personal authentication system via a mobile terminal with another management system, utilizing a communication unit, verification information storage, user authentication unit, and door opening authorization to verify and manage user authentication data efficiently.

Benefits of technology

Facilitates easy management of user personal authentication data across multiple systems, reducing administrative burden by verifying authentication results from an external system, thus allowing seamless integration and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025114978000001_ABST
    Figure 2025114978000001_ABST
Patent Text Reader

Abstract

To provide an access control system in which a configuration of personal authentication through a portable terminal can be shared with another management system, while facilitating management of personal authentication data.SOLUTION: An open / close control apparatus 16 includes a communication unit 18, a verification information storage unit 20, a user authentication unit 22, and a first door-open permission unit 26. When the communication unit 18 receives, from a portable terminal 12 used by a user M, authentication success information indicating a success of personal authentication using a predetermined personal authentication system, the user authentication unit 22 verifies, based on verification information stored in the verification information storage unit 20, as to whether the authentication success information is legitimate information created by a personal authentication system 28 authorized by an administrator, and identifies the user M when the authentication success information is legitimate. The first door-open permission unit 26 permits a door member 14a to be opened on condition that the user is identified by the user authentication unit 22.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an access control system for controlling the entry and exit of people into a building, a room, or the like. [Background technology]

[0002] As disclosed in Patent Document 1, for example, there has been a security system that includes a short-range wireless communication unit that receives personal authentication information (e.g., a combination of a user ID and a password) from a user's mobile terminal, an authentication unit that determines whether the user is an authorized user based on the received personal authentication information, and a security management unit that controls security based on the determination result by the authentication unit. The authentication unit has an authentication information storage unit in which the authentication information of authorized users is registered, and collates the received authentication information with the authentication information registered in the authentication information storage unit. If the received authentication information matches, the security management unit authenticates the user as an authorized user. The security management unit then performs a process to release security, with one of the conditions being that the user has been authenticated as an authorized user.

[0003] The technology behind this security system is expected to be used for a variety of purposes, such as an access control system that manages people entering and exiting buildings and rooms, and a CS login management system that manages logins to computer systems.

[0004] Furthermore, as disclosed in Patent Document 2, there is a keyless system in which a user's mobile terminal, a management server, and a locking / unlocking device are communicably connected via a network. The management server has a database in which personal authentication information of authorized users (for example, personal ID and fingerprint data) and unlocking data for unlocking the locking / unlocking device are registered, and the personal authentication information sent from the user's mobile terminal is compared with the personal authentication information registered in the database, and if there is a match, the user is authenticated as an authorized user.

[0005] In the case of the keyless system shown in Figures 1 to 5 of Patent Document 2, when the user is authenticated as an authorized user, the management server transmits unlocking data for the locking / unlocking device to the user's mobile terminal, and the unlocking data is transmitted from the mobile terminal to the locking / unlocking device, thereby unlocking the door. Also, in the case of the keyless system shown in Figures 7 to 9 of Patent Document 2, when the user is authenticated as an authorized user, the management server transmits unlocking data (unlock command) for the locking / unlocking device to the locking / unlocking device, thereby unlocking the door. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2014-191438 [Patent Document 2] Japanese Patent Application Laid-Open No. 2002-288750 Summary of the Invention [Problem to be solved by the invention]

[0007] When a company introduces an access control system to its own building or office, it usually has to create a new, dedicated personal authentication system. When creating a personal authentication system, it is necessary to prepare the personal authentication information of all employees who will be using it and register it in a database, which can be very time-consuming and costly, especially for companies with a large number of employees. Moreover, database maintenance must be performed each time an employee is transferred, retires, or is hired, placing a heavy burden on the administrator.

[0008] When a company introduces an access control system, if it can share a personal authentication system created for another management system (such as a CS login management system) already in operation at that company, there is no need to create a new, dedicated personal authentication system. Even when employees are transferred, it is only necessary to maintain the database of one personal authentication system, which significantly reduces the burden on administrators.

[0009] For example, the technology of Patent Document 1 is intended to create a personal authentication system (personal authentication unit and authentication information storage unit) dedicated to one security system (e.g., an access control system), and is configured in such a way that it is difficult to share one personal authentication system with multiple security systems (e.g., an access control system and a CS login management system).

[0010] Similarly, the technology of Patent Document 2 is intended to create a dedicated personal authentication system (user identification means and database) for one keyless system (e.g., an access control system), and is configured in a way that makes it difficult to share one personal authentication system with multiple keyless systems (e.g., an access control system and a CS login management system).

[0011] The present invention has been made in consideration of the above-mentioned background art, and aims to provide an entry / exit management system that can share the configuration of the part that performs personal authentication via a mobile terminal with another management system, and that makes it easy to manage personal authentication data. [Means for solving the problem]

[0012] The present invention is an access control system that includes a door device having a door element that opens or closes an entrance and a door closing mechanism that makes the closed door element unable to be opened manually, and an opening / closing control device that controls the state of the door device, The opening and closing control device includes a communication unit for communicating with a mobile terminal used by a user, a verification information storage unit in which verification information for determining whether predetermined information received by the communication unit is genuine information created by a specific personal authentication system authorized by an administrator is stored, a user authentication unit for determining whether the user who accessed through the mobile terminal is the user himself / herself, and a first door opening authorization unit for determining whether to authorize opening of the door element, When the communication unit receives authentication success information from the mobile terminal indicating that personal authentication by a specified personal authentication system has been successful, the user authentication unit verifies whether the authentication success information received by the communication unit is genuine information created by the specified personal authentication system based on the verification information stored in the verification information storage unit, and if it determines that the information is genuine, it authenticates the user using the mobile terminal as the actual user, and the first door opening authorization unit is an entry / exit management system that authorizes the door element to be opened, at least on the condition that the user authentication unit has authenticated that the user is the actual user.

[0013] The opening / closing control device preferably has a door-opening permission condition information storage unit in which information on door-opening permission conditions that are linked to the attributes of the user is stored, and when the communication unit receives the authentication success information and attribute information of the user using the mobile terminal via the mobile terminal, the first door-opening authorization unit is configured to authorize the opening of the door element, at least on the condition that the user authentication unit has authenticated that the user is the user himself / herself and that the user satisfies the door-opening permission conditions.

[0014] The first door opening authorization unit may be configured such that, if it authorizes the opening of the door element, it transmits a first door opening command to the door device, and upon receiving the first door opening command, the door device automatically opens the door element or makes the door element capable of being opened manually.

[0015] Alternatively, the opening / closing control device can be configured to include: an authorization code creation unit that, when the first door opening authorization unit authorizes the opening of the door element, creates an authorization code that expresses this in the form of a two-dimensional code; a two-dimensional code reader that is installed near the entrance and that, when operated by the user, reads the two-dimensional code displayed on the display of the mobile terminal used by the user; and a second door opening authorization unit that, when the authorization code created by the authorization code creation unit is recognized through the two-dimensional code reader, authorizes the opening of the door element and transmits a second door opening command to the door device; and when the authorization code creation unit creates the authorization code, the communication unit transmits the authorization code to the mobile terminal used by the user to be authorized, and when the door device receives the second door opening command, automatically opens the door element or makes the door element openable manually.

[0016] The present invention also provides an entry / exit management system comprising: a door device having a door element that opens and closes an entrance and an exit, and a door closing mechanism that sets the closed door element in a state where it cannot be opened manually; and an operational authentication device having a data input device into which personal authentication data of a user attempting to pass through the entrance is input by operating the device, and which determines whether the user is the user himself / herself by comparing the input personal authentication data with the personal authentication data for each user stored in a personal authentication data storage unit; when the operational authentication device determines that the user is the user himself / herself, it transmits a door open command to the door device, and when the door device receives the door open command, it automatically opens the door element or sets the door element in a state where it can be opened manually; A personal authentication data management device is provided for managing the personal authentication data storage unit, and the personal authentication data management device comprises: a communication unit for communicating with a portable terminal used by the user; a verification information storage unit in which verification information for determining whether predetermined information received by the communication unit is genuine information created by a specific personal authentication system authorized by an administrator is stored; a user authentication unit for determining whether the user who has accessed the portable terminal is the user himself / herself; and a registration authorization unit for determining whether to authorize the registration of the personal authentication data of the user in the personal authentication data storage unit. When the communication unit receives from the mobile terminal authentication success information indicating that personal authentication by a specified personal authentication system has been successful, and the personal authentication data that the user wishes to register, the user authentication unit verifies whether the authentication success information received by the communication unit is genuine information created by the specified personal authentication system based on the verification information stored in the verification information storage unit, and if it determines that the information is genuine, it authenticates the user using the mobile terminal as the user himself / herself, and the registration approval unit approves the registration of the personal authentication data that the user wishes to register in the personal authentication data storage unit, on the condition that at least the user authentication unit has authenticated that the user is the user himself / herself.

[0017] It is preferable that the personal authentication data management device has a registration permission condition information storage unit in which information on registration permission conditions specified in association with the attributes of the user is stored, and when the communication unit receives the authentication success information and attribute information of the user using the mobile terminal via the mobile terminal, the first door opening authorization unit authorizes the personal authentication data that the user wishes to register to be registered in the personal authentication data storage unit, on the condition that at least the user authentication unit has authenticated that the user is the user himself / herself and that the user satisfies the registration permission conditions. [Effects of the Invention]

[0018] The access control system of the present invention has a unique configuration in which, when authenticating a user who has accessed the system via a mobile terminal, the authentication result (authentication success information) issued by an external personal authentication system is verified by the user authentication unit of the access control system, making it easy to share an existing personal authentication system (a personal authentication system created for another control system) as the personal authentication system for the access control system. Therefore, when operating multiple control systems including the access control system, it is possible to easily manage user personal authentication data for the external personal authentication system, significantly reducing the burden on the administrator. [Brief explanation of the drawings]

[0019] [Figure 1] 1 is a system configuration diagram showing a first embodiment of an entry / exit management system of the present invention; [Figure 2] FIG. 10 is a system configuration diagram showing a second embodiment of the entry / exit management system of the present invention. [Figure 3] FIG. 10 is a system configuration diagram showing a third embodiment of the entry / exit management system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0020] <Entry / Exit Management System 10 of the First Embodiment> A first embodiment of the access control system of the present invention will now be described with reference to Figure 1. The access control system 10 of this embodiment is comprised of a door device 14 having a door element 14a and a door closing mechanism 14b, and an opening / closing control device 16 that controls the state of the door device 14. When a user M accesses the opening / closing control device 16 via a mobile terminal 12 and requests that the door element 14a be opened, the system executes a predetermined process to check whether or not a specified condition is met, and if the condition is met, the system opens the door element 14a, among other actions.

[0021] To briefly explain the door device 14, the door element 14a is a component that opens or closes the entrance to a building or room of a company or the like, and the door closing mechanism 14b makes it impossible to manually open the closed door element 14a. For example, if the door element 14a is a type that can be opened and closed manually, an electric lock or the like would be the door closing mechanism 14b. Also, if the door element 14a is a type that can be opened and closed by a drive device, such as an automatic door, the drive device would be the door closing mechanism 14b.

[0022] The opening / closing control device 16 is made up of a communication unit 18, a verification information storage unit 20, a user authentication unit 22, a door-opening permission condition information storage unit 24, and a first door-opening authorization unit .

[0023] To briefly explain each functional block, the communication unit 18 is a block that communicates with the mobile terminal 12 used by the user M. The verification information storage unit 20 is a database that stores verification information for determining whether or not predetermined information received by the communication unit 18 is genuine information created by a specific personal authentication system 28 certified by the administrator of the entry / exit management system 10.

[0024] The personal authentication system 28 is an external system that communicates with the mobile terminal 12 to authenticate the user M, and does not belong to the access control system 10. For example, in a company that has introduced the access control system 10, it is possible to reuse a personal authentication system 28 that was created for another management system (such as a CS login management system) that has been in operation since before the introduction of the access control system 10. The location where the personal authentication system 28 is installed may be in the same building as the access control system 10 or in a remote location, as long as it is capable of communicating with the mobile terminal 12. Alternatively, a cloud security authentication service on the Internet may be used.

[0025] The verification information may be, for example, a unique system identification code assigned to the personal authentication system 28, or a public key corresponding to a private key held by the personal authentication system 28 in the case where the personal authentication system 28 is a system that uses an electronic signature.

[0026] The user authentication unit 22 is a block that determines whether the user M who accessed through the mobile terminal 12 is the actual user. The door-opening permission condition information storage unit 24 is a database that stores information on the door-opening permission conditions that are defined in association with the attributes (e.g., department, position, etc.) of the user M. The first door-opening authorization unit 26 is a block that determines whether to authorize the opening of the door element 14a based on the authentication result of the user authentication unit 22, etc.

[0027] Next, an example of the usage and operation of the entry / exit control system 10 will be described. When user M approaches the closed door member 14a, he / she first accesses the personal authentication system 28 via the mobile terminal 12 and transmits the personal authentication data of user M (for example, his / her own user ID) to request personal authentication of himself / herself. The personal authentication system 28 then verifies the received personal authentication data and transmits the personal authentication result of user M to the mobile terminal 12.

[0028] If personal authentication by personal authentication system 28 is successful, mobile terminal 12 automatically (or by operation of user M) transmits authentication success information to communication unit 18 of opening and closing control device 16. The authentication success information is information indicating that personal authentication by personal authentication system 28 has been successful, and also includes information corresponding to the above-mentioned verification information (for example, information on the unique system identification code assigned to personal authentication system 28). User M's attribute information is also transmitted.

[0029] When the communication unit 18 receives the authentication success information and the attribute information of user M, the user authentication unit 22 verifies whether the authentication success information is genuine information created by the personal authentication system 28 certified by the administrator, based on the verification information stored in the verification information storage unit 20. For example, the system identification code included in the authentication success information is compared with the system identification code stored in the verification information storage unit 20, and if they match, the authentication success information is determined to be genuine information and user M is authenticated as the user.

[0030] When the user authentication unit 22 authenticates that the user is the actual user, the first door opening authorization unit 26 refers to the door-opening permission condition information storage unit 24 based on the attribute information of the user M, and if it is confirmed that the user M satisfies the door-opening permission conditions, it authorizes the door element 14a to be opened and transmits a first door opening command to the door device 14. For example, if the attribute of the user M is "development department chief" and the door-opening permission condition is "general manager or above," it does not authorize the door element 14a to be opened.

[0031] When the door device 14 receives the first door open command, it operates the door closing mechanism 14b to automatically open the door element 14a (open the automatic door) or to make the door element 14 openable manually (unlock the electronic lock). This allows the user M, who is an authorized user, to pass through the entrance without any hindrance.

[0032] As explained above, the entry / exit control system 10 has a unique configuration in which, when authenticating a user M who has accessed through the mobile terminal 12, the authentication result (authentication success information) issued by the external personal authentication system 28 is verified by the user authentication unit 22 of the entry / exit control system 10, which makes it easy to share an existing personal authentication system (a personal authentication system created for another control system) as the personal authentication system 28 for the entry / exit control system 10. Therefore, when operating multiple control systems including the entry / exit control system 10, the personal authentication data of user M for the personal authentication system 28 can be easily managed, significantly reducing the burden on the administrator.

[0033] In the above explanation, as an example of the operation of the door device 14, it was explained that "when a first door open command is received, the electronic lock is unlocked, thereby making the door element 14a available for manual opening." In addition, there may be a case where the door closing mechanism 14b is a locking device that is manually locked and unlocked by a person using a key member, and the key member is stored in a key box installed near the door element 14a. In this case, the operation of the door element 14 is explained as "when a first door open command is received, the door element 14a is made available for manual opening (the electric lock of the key box is unlocked, making the key member available)."

[0034] <Second embodiment of the entry / exit management system 30> Next, a second embodiment of the access control system of the present invention will be described with reference to Fig. 2. Here, the same components as those in the access control system 10 described above will be denoted by the same reference numerals.

[0035] The entry / exit management system 30 of the second embodiment is composed of the above-mentioned door device 14 (door element 14a, door closing mechanism 14b) and a new opening / closing control device 32 that controls the state of the door device 14. When a user M accesses the opening / closing control device 32 via a mobile terminal 12 and requests that the door element 14a be opened, the system executes a predetermined process to check whether or not the specified conditions are met, and if the conditions are met, performs an action such as opening the door element 14a.

[0036] The opening and closing control device 32 has the same communication unit 18, verification information storage unit 20, user authentication unit 22 and door-opening permission condition information storage unit 24 as the opening and closing control device 16, but the first door-opening authorization unit 26 is replaced with a first door-opening authorization unit 26x, and further has been added with new components, an authorization code creation unit 34, a two-dimensional code reader 26 and a second door-opening authorization unit 38. Here, a description of the components that are the same as the opening and closing control device 16 will be omitted, and only the first door-opening authorization unit 26x and the newly added components will be briefly described.

[0037] The first door opening authorization unit 26x is a block that performs the same processing as the first door opening authorization unit 26 to determine whether or not to authorize the opening of the door element 14a, and transmits a first door opening command if authorization is granted. However, the first door opening authorization unit 26x differs in that it transmits the first door opening command not to the door device 14 but to the authorization code creation unit 34.

[0038] The authorization code creation unit 34 is a block that creates an authorization code that indicates, in the form of a two-dimensional code, that the first door opening authorization unit 26 has authorized the opening of the door element 26 (when the first door opening command has been received). The authorization code created by the authorization code creation unit 34 is transmitted from the communication unit 18 to the mobile terminal 12, and is also transmitted to the second door opening authorization unit 38, which will be described later.

[0039] The two-dimensional code reader 36 is a device that is installed near the entrance and that, when operated by the user M, reads the two-dimensional code displayed on the display of the mobile terminal 12 used by the user M. The second door opening authorization unit 38 is a block that, when the authorization code created by the authorization code creation unit 34 is recognized through the two-dimensional code reader 36, authorizes the door element 14a to be opened and transmits a second door opening command to the door device 14.

[0040] Next, an example of the usage and operation of the entry / exit control system 30 will be described. When user M approaches the closed door member 14a, he / she first accesses the personal authentication system 28 via the mobile terminal 12 and transmits the personal authentication data of user M (for example, his / her own user ID) to request personal authentication of himself / herself. The personal authentication system 28 then verifies the received personal authentication data and transmits the personal authentication result of user M to the mobile terminal 12.

[0041] If personal authentication by personal authentication system 28 is successful, mobile terminal 12 automatically (or by operation of user M) transmits authentication success information to communication unit 18 of opening and closing control device 16. The authentication success information is information indicating that personal authentication by personal authentication system 28 has been successful, and also includes information corresponding to the above-mentioned verification information (for example, information on the unique system identification code assigned to personal authentication system 28). User M's attribute information is also transmitted.

[0042] When the communication unit 18 receives the authentication success information and the attribute information of user M, the user authentication unit 22 verifies whether the authentication success information is genuine information created by the personal authentication system 28 certified by the administrator, based on the verification information stored in the verification information storage unit 20. For example, the system identification code included in the authentication success information is compared with the system identification code stored in the verification information storage unit 20, and if they match, the authentication success information is determined to be genuine information and user M is authenticated as the user.

[0043] When the user authentication unit 22 authenticates that the user is the actual user, the first door opening authorization unit 26x refers to the door-opening permission condition information storage unit 24 based on the attribute information of the user M, and if it is confirmed that the user M satisfies the door-opening permission conditions, authorizes the opening of the door element 14a, and transmits a first door opening command to the authorization code creation unit 34. For example, if the attribute of the user M is "Section Chief of the Development Department" and the door-opening permission condition is "General Manager or above," it does not authorize the opening of the door element 14a.

[0044] When the authorization code creation unit 34 receives the first door opening command, it creates an authorization code in the form of a two-dimensional code indicating that the first door opening authorization unit 26 has authorized the opening of the door element 26. This authorization code is then sent from the communication unit 18 to the mobile terminal 12, and is also transmitted to the second door opening authorization unit 38. Note that it is preferable to use an authorization code that changes depending on the time of generation so that it cannot be reused.

[0045] Next, the user M operates the two-dimensional code reader 36 and inputs the authorization code displayed on the display of the mobile terminal 12 into the two-dimensional code reader 36. Then, the second door opening authorization unit 38 compares the authorization code recognized through the two-dimensional code reader 36 with the authorization code transmitted from the authorization code creation unit 34, and if they match, authorizes the door element 14a to be opened and transmits a second door opening command to the door device 14.

[0046] When the door device 14 receives the second door open command, it operates the door closing mechanism 14b to automatically open the door element 14a (open the automatic door) or to make the door element 14 openable manually (unlock the electronic lock). This allows the user M, who is an authorized user, to pass through the entrance without any hindrance.

[0047] The entry / exit control system 30 can also achieve the same effects as the entry / exit control system 10. Furthermore, although the entry / exit control system 10 has a very simple system configuration, there is a possibility that the door element 14 may be opened even when the user M is not near the entrance / exit, making it difficult to adopt in cases where a very high level of security performance is required. In contrast, the entry / exit control system 30 can achieve a higher level of security performance than the entry / exit control system 10, because the door element 14 cannot be opened unless the user M directly operates a two-dimensional code reader 36 installed near the entrance / exit.

[0048] In the above explanation, as an example of the operation of the door device 14, it was explained that "when the second door open command is received, the door element 14a is brought into a state where it can be opened manually (the electric lock is unlocked)." In addition to this, there may be a case where the door closing mechanism 14b is a locking device of a type that is manually locked and unlocked using a dedicated key member, and the key member is stored in a key box installed near the door element 14a. In this case, the operation of the door element 14 is explained as "when the second door open command is received, the door element 14a is brought into a state where it can be opened manually (the electric lock of the key box is unlocked, allowing the user to use the key member)."

[0049] In the entry / exit control system 30, the authorization code is transmitted between the mobile terminal 12 and the second door opening authorization unit 38 by reading a two-dimensional code with a two-dimensional code reader 36, but it may also be transmitted using short-range wireless communication, sound waves, or other means. Also, in the entry / exit control system 30, the authorization code creation unit 34 and the second door opening authorization unit 38 are provided as separate functional blocks, but they may also be provided as an integrated functional block.

[0050] <Entry / Exit Management System 40 of the Third Embodiment> Next, a third embodiment of the access control system of the present invention will be described with reference to Fig. 3. Here, the same components as those in the access control system 10 described above will be denoted by the same reference numerals.

[0051] The entry / exit management system 40 of the third embodiment has the above-mentioned door device 14 (door element 14a, door closing mechanism 14b) and an operational authentication device 42 that is operated by a user M to perform personal authentication, and is a system that opens the door element 14a to a user M who has been authenticated as a legitimate user by the operational authentication device 42. A distinctive feature of the system is that it is provided with a unique personal authentication data management device 44 to facilitate the registration (new registration and changed registration) of personal authentication data for each user required for personal authentication by the operational authentication device 42. Each device will be described in order below.

[0052] First, we will explain the operational authentication device 42. The operational authentication device 42 has a data input device 42a into which personal authentication data of user M is input by being operated by user M who is about to pass through the entrance / exit, and a door opening authorization unit 42b compares the personal authentication data of user M input into the data input device 42a with the personal authentication data for each user stored in a personal authentication data storage unit 42c, thereby determining whether user M is the user himself or herself.

[0053] For example, when personal authentication is performed using fingerprints, a fingerprint reader serves as the data input device 42a, and fingerprint data for each user is registered as personal authentication data in the personal authentication data storage unit 42c. When personal authentication is performed using a user's facial image, a face reader serves as the data input device 42a, and facial image data for each user is registered as personal authentication data in the personal authentication data storage unit 42c. When personal authentication is performed using an IC card, an IC card reader serves as the data input device 42a, and a card ID assigned to the IC card is registered as personal authentication data in the personal authentication data storage unit 42c.

[0054] To explain the usage and operation of the parts related to the operation-type authentication device 42, when user M approaches the closed door element 14a, he or she operates the data input device 42a to input his or her personal authentication data (for example, fingerprint data). When the personal authentication data is input, the door open authorization unit 42b performs the process of determining whether user M is the user in question as described above, and if it determines that user M is the user in question, it transmits a door open command to the door device 14. Then, upon receiving the door open command, the door device 14 operates the door closing mechanism 14b to automatically open the door element 14a (open the automatic door) or to make the door element 14 available for manual opening (unlock the electronic lock). The configuration, usage, and operation of this operation authentication device 42 and door device 14 are general and have been used in the past.

[0055] Next, a description will be given of the personal authentication data management device 44, which is the main part of the invention. The personal authentication data management device 44 is composed of a communication unit 18, a verification information storage unit 20, a user authentication unit 22, and a registration authentication unit .

[0056] Among the functional blocks, the blocks other than the registration authorization unit 46 are the same as those in the opening and closing control device 16. The registration authorization unit 46 is a new configuration, and is a block that determines whether to authorize the registration (new registration or changed registration) of the personal authentication data of user M in the personal authentication data storage unit 42c.

[0057] To explain an example of the method of use and operation of the entry / exit control system 40, in order for user M to register his / her own personal authentication data (e.g., fingerprint data) in the personal authentication data storage unit 42c, he / she first accesses the personal authentication system 28 via the portable terminal 12, transmits the personal authentication data of user M (e.g., user ID), and requests that his / her own personal authentication be performed. The personal authentication system 28 then verifies the received personal authentication data and transmits the personal authentication result of user M to the portable terminal 12.

[0058] If personal authentication by the personal authentication system 28 is successful, the mobile terminal 12 automatically (or by operation of the user M) transmits authentication success information to the communication unit 18 of the personal authentication data management device 44. The authentication success information is information indicating that personal authentication by the personal authentication system 28 has been successful, and also includes information corresponding to the above-mentioned verification information (for example, information on the unique system identification code attached to the personal authentication system 28). The authentication success information also transmits personal authentication data (for example, fingerprint data) that the user M wishes to register in the personal authentication data storage unit 42c.

[0059] When the communication unit 18 receives the authentication success information and the personal authentication data desired to be registered, the user authentication unit 22 verifies whether the authentication success information is genuine information created by the personal authentication system 28 approved by the administrator, based on the verification information stored in the verification information storage unit 20. For example, the system identification code included in the authentication success information is compared with the system identification code stored in the verification information storage unit 20, and if they match, the authentication success information is determined to be genuine information and user M is authenticated as the user.

[0060] When the user authentication unit 22 authenticates that the user is the user himself / herself, the registration permission unit 46 authorizes the registration of the personal authentication data (for example, fingerprint data) desired to be registered in the personal authentication data storage unit 42c, and updates the personal authentication data storage unit 42c. In other words, the personal authentication data of user M is properly registered without the administrator having to perform any special work.

[0061] As explained above, the personal authentication data management device 44 possessed by the entry / exit control system 40 has a unique configuration in which, when authenticating a user M who has accessed through the mobile terminal 12, the authentication result (authentication success information) issued by the external personal authentication system 28 is verified by the user authentication unit 22 of the entry / exit control system 40, which makes it easy to share an existing personal authentication system (a personal authentication system created for another control system) as the personal authentication system 28 for the entry / exit control system. Therefore, when operating multiple control systems including the entry / exit control system 40, the personal authentication data for the user's personal authentication system 28 and the personal authentication data for the operational authentication device 42 can be easily managed, significantly reducing the burden on the administrator.

[0062] The entry / exit control system 40 does not have a function to delete the personal authentication data (e.g., fingerprint data) of a specific user from the personal authentication data storage unit 42c when the registration of the specific user in the personal authentication system 28 is deleted. However, it is possible to add a function to automatically acquire information that the user registration has been deleted from the personal authentication system 28 and automatically delete the personal authentication data (e.g., fingerprint data) of the deleted user, thereby preventing unnecessary personal authentication data (e.g., fingerprint data) from accumulating in the personal authentication data storage unit 42c.

[0063] <Other embodiments> The access control system of the present invention is not limited to the above-described embodiment. For example, the access control systems 10, 30, and 40 described above are configured to "manage one door device 14," but can be modified to "manage multiple door devices 14."

[0064] For example, if the access control system 10 is changed to a configuration in which it "manages a plurality of door devices 14," the numbers of the communication unit 18, verification information storage unit 20, user authentication unit 22, door-opening permission condition information storage unit 24, and first door-opening authorization unit 26 of the opening / closing control device 16 may remain at one each, and the first door-opening authorization unit 26 may send a first door opening command only to the door device 14 that user M has requested to be opened. In this case, since it is expected that the door-opening permission conditions will differ for each door device 14, when storing the door-opening permission conditions in the door-opening permission condition information storage unit 24, the door-opening permission conditions may be organized and stored for each door device 14.

[0065] Furthermore, when the entry / exit control system 30 is modified to a configuration that "manages a plurality of door devices 14," it is preferable to leave the number of communication units 18, verification information storage units 20, user authentication units 22, door-opening permission condition information storage units 24, first door-opening authorization units 26x, and authorization code generation units 34 of the opening / closing control device 32 at one each, add two-dimensional code readers 36 and second door-opening authorization units 38 according to the number of door devices 14, and modify the configuration so that the authorization code generation unit 34 transmits authorization codes only to the door device 14 that the user M is requesting to open. In this case, too, it is expected that the door-opening permission conditions will differ for each door device 14, so when storing the door-opening permission conditions in the door-opening permission condition information storage unit 24, it is preferable to organize and store the door-opening permission conditions for each door device 14.

[0066] Furthermore, when changing the configuration of the entry / exit management system 40 to one that "manages a plurality of door devices 14," for example, it is advisable to add an additional operational authentication device 42 according to the number of door devices 14, keep the number of personal authentication data management devices 44 at one, and change the configuration so that the registration authorization unit 46 authorizes the registration of personal authentication data (e.g., fingerprint data) desired by user M only in the personal authentication data storage unit 42c desired by user M.

[0067] In the case of the above-mentioned entry / exit management systems 10, 30, the first door opening authorization unit 26, 26x has two conditions for authorizing the opening of the door element 14a: "user M is authenticated as the person who is using the door" and "user M's attributes satisfy the door opening authorization conditions." However, if no special door opening authorization conditions are set, the door opening authorization condition information storage unit 24 can be deleted, and the only authorization condition can be "user M is authenticated as the person who is using the door."

[0068] On the other hand, in the case of the entry / exit management system 40, the condition when the registration approval unit 46 approves the registration of personal authentication data is only that "user M is authenticated as the actual user." However, if registration permission conditions are set according to the user's attributes, a new registration permission condition information storage unit can be created and "user M's attributes must satisfy the registration permission conditions" can be added to the approval conditions.

[0069] In addition, the access control system of the present invention not only controls the entry and exit of people into buildings and rooms, but also includes a system that controls the entry and exit of vehicles into parking lots, etc. In this case, the gate device (gate member that prevents vehicles from passing / driving device that drives the gate member) installed at the entrance and exit of the parking lot becomes the door device (door member / door closing mechanism).

[0070] The above embodiments have been explained generally on the assumption that the access control systems 10, 30, and 40 are introduced in a situation where another management system (for example, a CS login management system) is already in operation. However, it is also possible that the access control systems 10, 30, and 40 are introduced first, and then another management system is introduced. In the latter case, when the access control systems 10, 30, and 40 are introduced, a personal authentication system 28 must also be created, which places a certain burden on the administrator. However, when another management system is introduced later, the user authentication technology of the access control systems 10, 30, and 40 (technology that uses an external personal authentication system 28) can be applied to the other management system, eliminating the need to create a new personal authentication system, which is a great benefit for companies and the like overall. It is also easy to deploy multiple management systems, including the access control system, in the form of a single sign-on management system. [Explanation of symbols]

[0071] 10, 30, 40 Access control system 12 Mobile devices 14 Door device 14a Door member 14b Door closing mechanism 16,32 Switching control device 18 Communications Department 20 Verification information storage section 22 User authentication unit 24 Door opening permission condition information storage section 26,26x First Door Opening Authorization Department 28 Administrator-certified personal authentication system 34 Authorization Code Creation Department 36 Two-dimensional code reader 38 Second Door Opening Authorization Department 42 Operational authentication device 42a Data entry devices 42b Door Opening Authorization Department 42c Personal authentication data storage section 44 Personal authentication data management device 46 Registration and Approval Division M User

Claims

1. In an access control system comprising a door device having a door element that opens or closes an entrance and a door closing mechanism that makes the closed door element unable to be opened manually, and an opening / closing control device that controls the state of the door device, The opening and closing control device includes a communication unit for communicating with a mobile terminal used by a user, a verification information storage unit in which verification information for determining whether predetermined information received by the communication unit is genuine information created by a specific personal authentication system authorized by an administrator is stored, a user authentication unit for determining whether the user who accessed through the mobile terminal is the user himself / herself, and a first door opening authorization unit for determining whether to authorize opening of the door element, When the communication unit receives authentication success information from the portable terminal, the authentication success information indicates that personal authentication by a predetermined personal authentication system has been successful, the user authentication unit verifies whether the authentication success information received by the communication unit is genuine information created by the specific personal authentication system based on the verification information stored in the verification information storage unit, and if it determines that the information is genuine, authenticates the user using the mobile terminal as the user himself; The first door opening authorization unit authorizes the opening of the door element on the condition that the user is authenticated as the person in question by the user authentication unit.

2. The opening / closing control device has a door-opening permission condition information storage unit in which information on the door-opening permission condition specified in association with the attribute of the user is stored, When the communication unit receives the authentication success information and attribute information of the user using the mobile terminal via the mobile terminal, 2. The access control system according to claim 1, wherein the first door opening authorization unit authorizes the opening of the door element on the condition that the user has been authenticated as the user by the user authentication unit and that the user satisfies the door opening permission conditions.

3. the first door opening authorization unit transmits a first door opening command to the door device when authorizing the opening of the door element; 3. The access control system according to claim 1, wherein the door device, upon receiving the first door opening command, automatically opens the door element or makes the door element manually openable.

4. The opening / closing control device is provided with: an authorization code creation unit that, when the first door opening authorization unit authorizes the opening of the door element, creates an authorization code that expresses that fact in the form of a two-dimensional code; a two-dimensional code reader that is installed near the entrance and that, when operated by the user, reads the two-dimensional code displayed on the display of the mobile terminal used by the user; and a second door opening authorization unit that, when the authorization code created by the authorization code creation unit is recognized through the two-dimensional code reader, authorizes the opening of the door element and transmits a second door opening command to the door device; when the authorization code generation unit generates the authorization code, the communication unit transmits the authorization code to the mobile terminal used by the user to be authorized; 3. The access control system according to claim 1, wherein the door device, upon receiving the second door opening command, automatically opens the door element or makes the door element manually openable.

5. an operational authentication device having a data input device into which personal authentication data of a user attempting to pass through the entrance is input by operating the data input device, and which determines whether the user is the user himself or herself by comparing the input personal authentication data with the personal authentication data for each user stored in a personal authentication data storage unit; wherein the operational authentication device transmits a door open command to the door device when it determines that the user is the user himself or herself; and upon receiving the door open command, the door device automatically opens the door element or puts the door element into a state where it can be opened manually; A personal authentication data management device is provided for managing the personal authentication data storage unit, and the personal authentication data management device comprises: a communication unit for communicating with a portable terminal used by the user; a verification information storage unit in which verification information for determining whether predetermined information received by the communication unit is genuine information created by a specific personal authentication system authorized by an administrator is stored; a user authentication unit for determining whether the user who has accessed the portable terminal is the user himself / herself; and a registration authorization unit for determining whether to authorize the registration of the personal authentication data of the user in the personal authentication data storage unit. When the communication unit receives, from the portable terminal, authentication success information indicating that personal authentication by a predetermined personal authentication system has been successful, and the personal authentication data that the user wishes to register, the user authentication unit verifies whether the authentication success information received by the communication unit is genuine information created by the specific personal authentication system based on the verification information stored in the verification information storage unit, and if it determines that the information is genuine, authenticates the user using the mobile terminal as the user himself; The entry / exit management system is characterized in that the registration approval unit approves the registration of the personal authentication data that the user wishes to register in the personal authentication data storage unit, on the condition that the user is authenticated as the user by the user authentication unit.

6. the personal authentication data management device has a registration permission condition information storage unit that stores information on registration permission conditions that are specified in association with the attributes of the user; When the communication unit receives the authentication success information and attribute information of the user using the mobile terminal via the mobile terminal, 6. The entry / exit management system according to claim 5, wherein the first door opening authorization unit authorizes the user to register the personal authentication data that the user wishes to register in the personal authentication data storage unit, on the condition that the user has been authenticated as the user by the user authentication unit and that the user satisfies the registration permission conditions.

Citation Information

Patent Citations

  • Gate control method, gate control system, gate control device, server, portable communication terminal, program, and recording medium

    JP2003138816A

  • Key distribution system

    JP2014158222A

  • Information processing system, control method of information processing system and program

    JP2015124594A

  • Biological collation system, biological collation method, biological collation device and control program

    JP2017059060A

  • Entrance / exit management system

    JP2020147993A