Log-in management system, server, client, log-in management method, program, and storage medium

The login management system strengthens security by authenticating user and client identities and preventing new logins during active sessions, addressing vulnerabilities in existing systems and ensuring secure access in mobile environments.

JP2025143136APending Publication Date: 2025-10-01HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024042906
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-18
Publication Date
2025-10-01

AI Technical Summary

Technical Problem

Existing login management systems lack robust security measures, particularly when users access remote servers via networks from local terminals, making them vulnerable to unauthorized access.

Method used

Implementing a login management system that authenticates user and client identification information and prevents new logins during an active session to enhance security, using a server control unit to manage login permissions and a client control unit to enforce authentication protocols.

Benefits of technology

Enhances the security of login processes by preventing unauthorized access and ensuring secure transitions between online and offline environments, particularly in mobile contexts like electric bicycles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025143136000001_ABST
    Figure 2025143136000001_ABST
Patent Text Reader

Abstract

To provide a log-in management system improved in security of log-in in a system including a client and a server, the server, the client, a log-in management method, a program, and a storage medium.SOLUTION: In a log-in management system 1, when a user logs in to a server 90 via a network NW from a user terminal 8 used by the user, a control section 901 of the server 90 authenticates identification information and the like of the user and permits the log-in of the user when the authentication is successful. When receiving a log-in request of a first user before the log-out of the first user is executed, during the log-in of the first user, after the log-in of the first user is permitted, the control section 901 does not permit a new log-in of the first user.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a login management system, a server, a client, a login management method, a program, and a storage medium. [Background technology]

[0002] Patent Document 1 discloses technology that enables communication between a vehicle such as an electrically assisted bicycle and a mobile terminal carried by the vehicle's occupant and onto which predetermined application software (hereinafter also referred to as an app) has been downloaded. The mobile terminal is set up so that it can also communicate with an external server when the app is in use, and various information related to the vehicle, such as driving data, is stored on the server from the vehicle via the mobile terminal, allowing the occupant to check the various pieces of information on the app. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] International Publication No. 2023 / 171800 Summary of the Invention [Problem to be solved by the invention]

[0004] As in Patent Document 1, when a user logs in to a remote server via a network from a client (mobile terminal) used as a terminal, it is desired to improve the security of the login management.

[0005] The present invention provides a login management system, a server, a client, a login management method, a program, and a storage medium that improve the security of logins in a system including a client and a server. [Means for solving the problem]

[0006] A first aspect of the present invention is When a user logs in to a server, which is a remote computer, via a network from a client, which is a local computer used as a terminal, or to an application running on a remote server via a network, authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; A login management system including a server control unit that permits the login of the user when authentication is successful, The server control unit, during the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, When a login request accompanied by the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login by the first user is not permitted.

[0007] A second aspect of the present invention is A server is a remote computer that can communicate with a client, which is a local computer used as a terminal by a user, via a network, and When the client logs into the server via the network or into an application running on the server, authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; a server control unit that permits the user to log in if the authentication is successful; The server control unit, during the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, When a login request accompanied by the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login by the first user is not permitted.

[0008] A third aspect of the present invention is A client is a local computer that can communicate with a server that is a remote computer via a network and is used as a terminal by a user, When logging into the server via the network or into an application running on the server, Sending at least one of first identification information, which is identification information of the user, second identification information, which is identification information of the client, and authentication information to the server; a client control unit that receives permission for the user to log in from the server when the server has successfully authenticated at least one of the first identification information, the second identification information, and the information to be authenticated; The client control unit, during the login of a first user who is one of the users after receiving permission to log in from the first user, and before the first user logs out, When a login request accompanied by the first identification information of the first user, the second identification information of the client, or the authenticated information is made to the server, the new login of the first user is denied.

[0009] A fourth aspect of the present invention is When a user logs in to a server, which is a remote computer, via a network from a client, which is a local computer used as a terminal, or to an application running on a remote server via a network, authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; and permitting the login of the user if the authentication is successful, During the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, The method further includes a step of disallowing a new login by the first user when a login request is received that includes the first identification information of the first user, the second identification information of the client, or the authenticated information.

[0010] A fifth aspect of the present invention is When a user logs in to a server, which is a remote computer, via a network from a client, which is a local computer used as a terminal, or to an application running on a remote server via a network, authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; and permitting the login of the user if the authentication is successful, During the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, The program further causes the computer to execute a step of disallowing a new login by the first user when a login request is received that includes the first identification information of the first user, the second identification information of the client, or the authenticated information.

[0011] A sixth aspect of the present invention is It is a computer-readable storage medium that stores the above-mentioned program. [Effects of the Invention]

[0012] According to the present invention, it is possible to improve the security of login in a system including a client and a server. [Brief explanation of the drawings]

[0013] [Figure 1] 10 is a diagram showing the correlation between users, sales stores, and a server 90. FIG. [Figure 2] 1 is a block diagram of a login management system 1 according to each embodiment of the present invention. [Figure 3] 1 is a side view of an electric bicycle 10 according to an embodiment of the vehicle. [Figure 4] 10 is an example of an assistance setting screen displayed on a user terminal 8. [Figure 5] 10 is a sequence diagram for explaining the connection between the user terminal 8 and the control circuit 40 of the electric bicycle 10. FIG. [Figure 6] FIG. 6 is a sequence diagram showing a continuation of the sequence diagram of FIG. 5. [Figure 7] 10 is a sequence diagram showing details of a process of logging in to the server 90 by the user terminal 8. FIG. [Figure 8] 10 is an example of a login screen displayed on a user terminal 8. [Figure 9] 10 is a sequence diagram showing an example of processing by the login management system 1 of the first embodiment when there are multiple login requests to the server 90 based on the account information of a user U. FIG. [Figure 10] 10 is a sequence diagram showing another example of the processing of the login management system 1 of the first embodiment when there are multiple login requests to the server 90 based on the account information of the user U. FIG. [Figure 11] FIG. 10 is a sequence diagram showing an example of processing by the login management system 1 of the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.

[0015] [First embodiment] First, with reference to Fig. 1, the correlation between the parties involved in the login management system 1 (see Fig. 2) of the first embodiment of the present invention will be described. The parties involved in the login management system 1 are mainly the user who purchases and uses an electric bicycle 10 from a sales store, and a server 90 that collects and stores information about the electric bicycle 10 and performs necessary processing. The server 90 is a server managed by the operator of the application software described below.

[0016] Before describing the user and the server 90, the sales store will be described. The sales store manufactures and sells the electric bicycle 10. The sales store manufactures the electric bicycle 10 by attaching an electric assist device to a new non-electric bicycle purchased from a vehicle manufacturer (not shown), for example. The electric bicycle 10 is an electric assist bicycle configured to be able to output assist power using an electric assist device. The sales store then sells the electric bicycle 10 to users. The sales store also manages the electric bicycle 10 and customers using a store terminal 60 (for example, a tablet terminal, smartphone, or PC (Personal Computer)) on which store application software (hereinafter also referred to as a store app) for managing the electric bicycle 10 has been installed. The sales store may display and sell the electric assist device in the store, or may attach the electric assist device to a non-electric bicycle brought in by a user, for example.

[0017] A user is a person who wishes to purchase an electric bicycle 10, and pays the price to a sales store when purchasing the electric bicycle 10. The user downloads user application software (hereinafter also referred to as a user app), which will be described later, to a portable user terminal 8 (for example, a smartphone or tablet terminal) that the user owns, and uses the electric bicycle 10 with the user app running. The electric bicycle 10 is configured to be able to communicate with the user terminal 8, and is configured to be able to send riding data obtained while riding to the user terminal 8. The riding data includes, for example, riding speed, cadence (speed of rotation of the crank pedals), riding distance, and riding time. Details of the electric bicycle 10 will be described later.

[0018] The server 90 is managed by, for example, the operator of the user app or the store app. The server 90 communicates with the user's user terminal 8 and / or the electric bicycle 10 via the user app, and exchanges riding data and the like for the electric bicycle 10. The server 90 also communicates with the store terminal 60 of the sales store via the store app, and exchanges vehicle information and the like for the electric bicycle 10.

[0019] Next, the process up to when a user uses the electric bicycle 10 will be described. Before the electric bicycle 10 is delivered from the retailer, the user downloads the user app to the user terminal 8. When downloading, the user accesses the service introduction website for the user app, moves from the service introduction website to the app store, and downloads the user app from the app store. Note that the user may also access the app store directly to download the user app without accessing the service introduction website.

[0020] After downloading the user app, the user accesses the user website of the server 90 on the user app and performs the membership registration procedure required to use the user app. Specifically, the user inputs user information such as the user's name, gender, address, telephone number, and email address. The server 90 stores the user information input by the user, and the user's membership registration is completed. After membership registration, the user app is assigned a user ID (Identification) unique to the user, and the user ID is stored in the server 90 linked to the input user information. Information related to the user ID and a password, which will be described later, becomes account information required to log in to the server 90 from the user terminal 8. Note that the user may also perform the membership registration procedure by directly accessing the user website rather than on the user app.

[0021] The sales store first installs the store app on the store terminal 60. For example, the sales store accesses the server 90 from the store terminal 60 to download the store app, or physically connects a storage medium storing an executable file of the store app to the store terminal 60 and installs the store app on the store terminal 60. The store app and the server 90 are linked via a store API (Application Programming Interface), and various processes in the store app, specifically screen displays and various operations, are executed by calling the store API.

[0022] When assembling a non-electric bicycle and an electric assist device, staff at the sales store input assembly information into the store app. The assembly information includes, for example, information such as vehicle model information and identification numbers for identifying parts mounted on the vehicle body. After completing assembly of the electric bicycle 10, the staff checks whether the assembly work was performed properly using checklists, and also checks the operation of the electric bicycle 10. The assembly information also includes information related to checking the assembly work and the operation of the electric bicycle 10. The assembly information input into the store app is saved in the server 90 as vehicle information.

[0023] After the assembly check and operation confirmation of the electric bicycle 10 are completed, the results are displayed on the store terminal 60. If the results pass, the electric bicycle 10 can be handed over from the sales store to the user, i.e., sold.

[0024] When a user purchases an electric bicycle 10 from a sales store, the user uses the user app to display a QR code (registered trademark) containing user information on the user terminal 8. A staff member at the sales store reads the QR code using a camera built into the store terminal 60 and obtains the user's user information. The sales store then carries out the delivery procedure using the store app, changing the ownership of the electric bicycle 10 from the sales store to the user. At this time, the ownership of the vehicle information stored in the server 90 is changed from the sales store to the user. In other words, the server 90 rewrites the entity with the right to own the electric bicycle 10 (hereinafter also referred to as ownership) from the sales store to the user, and ownership of the electric bicycle 10 belongs to the user. The electric bicycle 10 is then handed over to the user, and the purchase of the electric bicycle 10 is completed. In the following description, "having ownership of the electric bicycle 10" may also be referred to as "owning the electric bicycle 10."

[0025] When using the electric bicycle 10, the user launches the user app. The user app and the server 90 are linked via a user API, and various processes in the user app, specifically screen displays and various operations, are executed by calling the user API. When the electric bicycle 10 is being used with the user app running, the user terminal 8 acquires riding data and error information for each component from the electric bicycle 10. The server 90 also acquires riding data and error information for each component from the user terminal 8 and / or the electric bicycle 10 and saves this as a riding log. The user can access the server 90 via the user app and check the riding log. The user can also access the server 90's management website to view and edit data stored on the server 90 (membership information, vehicle information, riding log, etc.).

[0026] FIG. 2 is a functional block diagram of the login management system 1. The login management system 1 includes an electric bicycle 10, a user terminal 8, and a server 90. As described above, the server 90 is the party that provides the user application service, and the user terminal 8 is the party that uses the service (i.e., the client). The login management system 1 manages logins to the server 90 by the user terminal 8. Note that while FIG. 2 shows only one user terminal 8, the login management system 1 includes multiple user terminals 8 that can download user applications and link with the server 90.

[0027] The electric bicycle 10 includes a battery unit 4, a power unit 20 electrically connected to the battery unit 4 to drive the wheels, a control circuit 40 that controls the power unit 20, a sensor group 41, a memory 42, a GNSS (Global Navigation Satellite System) unit 43, and a BLE (Bluetooth Low Energy) unit 44. The electric bicycle 10 will be described with reference to Figure 3. The battery unit 4, power unit 20, etc. make up the aforementioned electric assist device, and the electric bicycle 10 is manufactured by attaching the electric assist device to a non-electric bicycle.

[0028] The battery unit 4 includes a base 3 attached to the vehicle body frame 67, a battery 2 detachably attached to the base 3, and a light-emitting unit 47 attached to the base 3 and emitting light according to the state of the battery 2, etc. The base 3 is detachably fixed to the vehicle body frame 67. The battery 2 has multiple battery cells therein and stores energy. The battery 2 is electrically connected to the power unit 20 and supplies power to the power unit 20. The battery 2 also steps down the DC voltage as it is via a DC / DC converter (not shown), and supplies power to the control circuit 40, memory 42, GNSS unit 43, BLE unit 44, etc. The light-emitting unit 47 is, for example, an LED (Light Emitting Diode) lamp, and emits light in a predetermined light-emitting mode based on a command from the control circuit 40.

[0029] The power unit 20 has a motor M, which generates an assist force that compensates for the pedal force (hereinafter also referred to as pedal force) input by the rider to the crank pedal 79. The pedal force is transmitted to a crankshaft 83 and input to an endless chain 82 via a drive sprocket 80. The chain 82 is wound around the drive sprocket 80 and a driven sprocket 81 provided on the axle of the rear wheel. In accordance with a command from the control circuit 40, the motor M transmits the generated torque to the drive sprocket 80 via a gear (not shown) to compensate for the pedal force.

[0030] The control circuit 40 includes, for example, a CPU (Central Processing Unit) capable of performing various calculations, a RAM (Random Access Memory) used as a work area for the CPU, and a storage medium such as a ROM (Read Only Memory) for storing various information.

[0031] The sensor group 41 includes multiple sensors that detect the state of the electric bicycle 10. The sensor group 41 includes, for example, a motor rotation speed sensor that detects the rotation speed of the motor M, a torque sensor that detects the pedal torque value generated by the pedal force, a rear wheel rotation speed sensor that detects the rotation speed of the rear wheel, a cadence sensor that detects cadence, and an inertial measurement unit that detects acceleration, angular velocity, etc. The control circuit 40 calculates the traveling speed, traveling distance, etc. of the electric bicycle 10 from the measurement values ​​of the sensor group 41.

[0032] The memory 42 is, for example, an SD card, and temporarily or permanently stores information about the electric bicycle 10, riding data, and the like.

[0033] The GNSS unit 43 acquires the position information of the electric bicycle 10 .

[0034] The BLE unit 44 is a communication device for establishing a connection via Bluetooth (registered trademark) with the user terminal 8, the store terminal 60, etc. The BLE unit 44 consumes a small amount of power from the battery 2 and is always in a standby state.

[0035] The user terminal 8 is a local computer used as a terminal by the user, who is the rider of the electric bicycle 10. A holder 6 capable of holding the user terminal 8 is provided on the steering handlebars 74 of the electric bicycle 10, and the user terminal 8 is installed in a position that is visible to the rider when the electric bicycle 10 is in use. Note that the holder 6 is not necessarily required, and the user terminal 8 may be carried by the rider, that is, it may be attached to or stored on the rider or on something worn by the rider (clothing, bag, etc.).

[0036] The user terminal 8 includes a touch panel 800 , a short-range communication unit 801 , a network communication unit 802 , a control unit 803 , a clock unit 804 , and a storage unit 805 .

[0037] The touch panel 800 functions as an interface unit of the user terminal 8. Specifically, the touch panel 800 has, as functions related to input and output of the user terminal 8, an information display unit that displays various information to the user and an information input unit that accepts information input by the user's touch operation.

[0038] The short-range communication unit 801 wirelessly communicates with the control circuit 40 of the electric bicycle 10 based on a communication standard such as Bluetooth or Wi-Fi (registered trademark). The short-range communication unit 801 may also be configured to communicate with the control circuit 40 of the electric bicycle 10 via a wired connection using a USB (Universal Serial Bus).

[0039] The network communication unit 802 wirelessly communicates with the server 90 via the network NW, for example, by mobile communication. The mobile communication is, for example, a cellular communication method such as 3G (third generation mobile communication method), 4G (fourth generation mobile communication method), LTE (Long Term Evolution), or 5G (fifth generation mobile communication method).

[0040] The control unit 803 has a processor such as a CPU capable of performing various calculations that executes a user application stored in a storage unit 805 such as a ROM that stores various information. As described above, the user application is downloaded in advance by the user and stored in the storage unit 805. As will be described in detail later, when the user terminal 8 is permitted to log in by the server 90, the control unit 803 connects to the control circuit 40 of the electric bicycle 10 via the short-range communication unit 801 and becomes able to control the control circuit 40. The control unit 803 also connects to the server 90 via the network communication unit 802 and appropriately calls a user API in response to a touch operation on the touch panel 800 by the user.

[0041] The timekeeping unit 804 is a timer that measures the time used for control by the control unit 803.

[0042] In addition to input by touching the touch panel 800, the user terminal 8 may also receive input from a button (not shown) provided on the user terminal 8 or voice input.

[0043] The server 90 is a remote computer that can communicate with the user terminal 8, which is a local terminal, via the network NW. The server 90 may be a distributed server made up of multiple servers or a distributed virtual server (cloud server) created in a cloud environment.

[0044] The server 90 includes a network communication unit 900, a control unit 901, a clock unit 902, and a storage unit 903. The network communication unit 900 communicates wirelessly with the user terminal 8 via the network NW.

[0045] The control unit 901 is realized by a processor executing a program (not shown) stored in a storage unit 903 of the server 90. For example, the control unit 901 calls an API and executes a predetermined process in response to a request transmitted from the user terminal 8.

[0046] The timekeeping unit 902 is a timer that measures the time used for control by the control unit 901 .

[0047] The storage unit 903 stores user information input by a user who is using the user application, vehicle information of multiple vehicles (including the electric bicycle 10) linked to the user application, driving data, etc. The server 90 appropriately manages this information and data.

[0048] 4 shows an example of a screen that can be displayed on the user terminal 8 and that allows the user to set various functions of the electric assist device. This screen displays an assist power switch 851, a sudden acceleration prevention switch 852, an automatic mode switch 853, a power change unit 854, a response change unit 855, and a driving mode selection unit 856.

[0049] The assist power switch 851 is a toggle switch for permitting / prohibiting the generation of power by the motor M. When the assist power switch 851 is ON, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 permitting the generation of an assist force that supplements the pedaling force, thereby permitting the motor M to generate power. On the other hand, when the assist power switch 851 is OFF, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 prohibiting the generation of an assist force, thereby prohibiting the motor M from generating power. Note that the assist power switch 851 may also be a switch for switching the power of the motor M ON / OFF. In this case, when the assist power switch 851 is ON, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 to turn on the power of the motor M, and when the assist power switch 851 is OFF, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 to turn on the power of the motor M. In these cases, the generation of power by the motor M is similarly permitted or prohibited.

[0050] The sudden acceleration prevention switch 852 is a toggle switch for switching sudden acceleration prevention control ON / OFF when the electric bicycle 10 starts moving. Sudden acceleration prevention control is control that prohibits torque generation by the motor M when the cadence and acceleration are each below a predetermined threshold when the electric bicycle 10 starts moving. When the sudden acceleration prevention switch 852 is ON, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 to permit sudden acceleration prevention control. On the other hand, when the sudden acceleration prevention switch 852 is OFF, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 to prohibit sudden acceleration prevention control.

[0051] The automatic mode switch 853 is a toggle switch for switching ON / OFF a mode that automatically switches the power level and response level (described later) depending on the riding conditions of the electric bicycle 10, the riding characteristics of the rider, etc. When the automatic mode switch 853 is ON, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 that permits automatic switching of the power level and response level. On the other hand, when the automatic mode switch 853 is OFF, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 that prohibits automatic switching of the power level and response level.

[0052] The power change unit 854 accepts input to change the power level of the motor M when the assist power switch 851 is ON and the automatic mode switch 853 is OFF. Power levels range, for example, from level 1, which has a low assist ratio, to level 4, which has a high assist ratio. Here, the assist ratio is the ratio of the force used to compensate for the pedaling force using the motor M to the pedaling force. When a change in power level is input, the user terminal 8 transmits a signal indicating the changed power level to the control circuit 40 of the electric bicycle 10, and the control circuit 40 causes the motor M to generate power based on the changed power level.

[0053] When the assist power switch 851 is ON and the automatic mode switch 853 is OFF, the response change unit 855 accepts input to change the response level, which indicates the degree of responsiveness to power changes of the motor M. The response levels range, for example, from level 1, which indicates low responsiveness, to level 4, which indicates high responsiveness. When a change in the response level is input, the user terminal 8 transmits a signal indicating the changed response level to the control circuit 40 of the electric bicycle 10, and the control circuit 40 controls the responsiveness of the motor M based on the changed response level.

[0054] The riding mode selection unit 856 accepts input for selecting one of multiple riding modes. The multiple modes include standard mode and sport mode. Sport mode is a mode in which the motor M has a higher responsiveness to power changes than standard mode, and the electric bicycle 10 has better performance than standard mode. When the standard mode switch in the riding mode selection unit 856 is ON, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 indicating that standard mode has been selected, and the control circuit 40 controls the responsiveness of the motor M based on the performance in standard mode. On the other hand, when the sport mode switch in the riding mode selection unit 856 is ON, the user terminal 8 sends a signal to the control circuit 40 of the electric bicycle 10 indicating that sport mode has been selected, and the control circuit 40 controls the responsiveness of the motor M based on the performance in sport mode. Note that the multiple modes may include modes other than standard mode and sport mode, and may include, for example, a battery save mode in which the target torque generated by the motor M is reduced to reduce power consumption of the battery 2.

[0055] 5 and 6 are sequence diagrams illustrating the connection between the user terminal 8 and the control circuit 40 of the electric bicycle 10. FIG. 6 is a continuation of the sequence diagram of FIG. 5. The following describes the case where a user U, among multiple users who use the user application, owns the user terminal 8 and the electric bicycle 10.

[0056] To connect the user terminal 8 and the control circuit 40, the user U first launches a user application on the user terminal 8. The user application is launched, for example, by touching an icon of the user application displayed on the home screen of the user terminal 8. Alternatively, the user application may be launched by bringing the user terminal 8 close to an NFC (Near Field Communication) tag that is attached to the electric bicycle 10 and linked to the user application.

[0057] After the user application is launched, the user terminal 8 makes a login request to the server 90 based on the account information of the user U, and when the login is permitted by the server 90, the user terminal 8 completes the login to the server 90 (step S100). Details of the login process performed between the user terminal 8 and the server 90 will be described later.

[0058] After completing the login, the user terminal 8 performs Bluetooth authentication with the control circuit 40 of the electric bicycle 10 (step S300). Specifically, the user terminal 8 transmits Bluetooth authentication information that has been previously assigned to the user application and the control circuit 40 to the control circuit 40. The Bluetooth authentication information is identification information such as a PIN (Personal Identification Number) code. The Bluetooth authentication information is a fixed value regardless of the user ID of the user application or the type of control circuit. The control circuit 40 compares the Bluetooth authentication information transmitted from the user terminal 8 with the Bluetooth authentication information previously stored in the control circuit 40, and if they match, completes the Bluetooth authentication (step S301).

[0059] After completing the login, the user terminal 8 requests the server 90 for identification information of the control circuit 40 (step S302). The identification information of the control circuit 40 is, for example, a PIN code. This identification information is a unique value that differs for each control circuit mounted on the electric bicycle, and is given, for example, as a random number. When the electric bicycle 10 is manufactured, specifically when the electric assist device is attached to the body frame 67, unique identification information is assigned to the control circuit 40, and the identification information is associated with the control circuit 40 and stored in the server 90.

[0060] When the server 90 receives a request for the identification information of the control circuit 40 from the user terminal 8, it determines whether the user U has ownership or the right to use the electric bicycle 10 equipped with the control circuit 40 (step S303). If the server 90 determines that the user U has ownership or the right to use the electric bicycle 10, it transmits the identification information of the control circuit 40 to the user terminal 8 (step S304). On the other hand, if the server 90 determines that the user U does not have ownership or the right to use the electric bicycle 10, it does not transmit the identification information of the control circuit 40 to the user terminal 8, and notifies the user terminal 8 that it does not permit the request for the identification information of the control circuit 40 from the user terminal 8.

[0061] When the user terminal 8 receives the identification information of the control circuit 40 from the server 90, it transmits the identification information to the control circuit 40 (step S305). Here, the identification information that the user terminal 8 receives from the server 90 is temporarily stored in the RAM of the user terminal 8, but is not stored in a storage medium such as a ROM of the user terminal 8. Therefore, every time the user terminal 8 connects to the control circuit 40, it requests the identification information of the control circuit 40 from the server 90.

[0062] The control circuit 40 compares the received identification information with pre-stored identification information and determines whether they match (step S306). If the received identification information matches the identification information pre-stored in the control circuit 40 (step S306: YES), connection between the control circuit 40 and the user terminal 8 is permitted (step S307), and communication begins between the control circuit 40 and the user terminal 8 (step S308). In this way, connection between the user terminal 8 and the control circuit 40 is completed. On the other hand, if the received identification information does not match the pre-stored identification information (step S306: NO), the control circuit 40 does not permit connection between the control circuit 40 and the user terminal 8, and notifies the user terminal 8 that the connection is not permitted.

[0063] After communication starts, the user terminal 8 transmits the state of the assist power switch 851 set by the user application to the control circuit 40 (step S309). The control circuit 40 determines whether the assist power switch 851 is ON (step S310), and if it is ON, turns ON the power supply to the motor M (step S311), and if it is OFF, turns OFF the power supply to the motor M.

[0064] When the assist power switch 851 is ON, the user terminal 8 transmits an assist setting value, which is information necessary for assist control by the power unit 20, to the control circuit 40 (step S312). The assist setting value specifically includes various information set on the screen of FIG. 4. The control circuit 40 acquires the assist setting value transmitted from the user terminal 8 (step S313) and controls the power unit 20 based on the assist setting value. Note that the user terminal 8 or the server 90 stores the assist setting value last set at the previous login, and when the user logs out and logs in again, the assist setting value at the previous login is transmitted to the control circuit 40.

[0065] 7 is a sequence diagram showing details of the login process to the server 90 by the user terminal 8, that is, showing details of the above-mentioned step S100. Also, FIG. 8 is an example of a login screen displayed on the user terminal 8.

[0066] First, the user U performs a login operation on the user terminal 8 (step S101). Specifically, after the user application is launched, the login screen of FIG. 8 is displayed on the user terminal 8, and the user U inputs his / her own account information in the account information input field 861 and touches the login button 862. The account information includes, for example, a user ID, which is identification information of the user U, and a password, which is information to be authenticated. Note that the account information is not limited to this, and may include other information, for example, identification information such as the telephone number or email address of the user U, or identification information uniquely assigned to the user terminal 8.

[0067] The user ID and password may be stored in the storage unit 805 of the user terminal 8 at the time of initial login, etc. When the user ID and password are stored in the storage unit 805, the user U does not have to manually input the user ID and password at subsequent logins.

[0068] After touching the login button 862, the user terminal 8 transmits the input account information of the user U (specifically, the user ID and password) to the server 90 and requests login (step S102). The account information is subjected to processing such as encryption as appropriate when transmitted.

[0069] The server 90 compares the transmitted account information of the user U with the account information of the user U stored in the storage unit 903, and if they match, authenticates the login based on the account information of the user U (step S103). The authentication of the login by the server 90 is performed, for example, by calling an API for login. In the following description, the login based on the account information of the user U may also be referred to as "login of the user U."

[0070] When the login authentication of user U is completed, the server 90 generates an access token, associates it with the account information of user U, and stores it in the storage unit 903 (step S104). The server 90 grants login permission and an access token to the user terminal 8 (step S105), and the login to the server 90 by the user terminal 8 is completed (step S105). The access token granted to the user terminal 8 is stored in the storage unit 805.

[0071] The access token is information indicating that the user has the authority to access the server 90, and is, for example, a random character string. A different access token is assigned to each of multiple users who are logged in to the server 90. During login, the user terminal 8 communicates with the server 90 using the access token, so there is no need to perform login authentication each time communication with the server 90 is performed.

[0072] The access token has an expiration date, and is stored in the server 90 and the user terminal 8 for a predetermined period of time (e.g., 24 hours) in association with the account information of user U. The access token expires after the predetermined period of time has elapsed, and is deleted from the server 90 and the user terminal 8. The starting time of the access token's expiration date is, for example, the time when the server 90 permitted user U to log in, the time when the server 90 last communicated with the user terminal 8, or the time when the server 90 last executed processing in response to a request from the user terminal 8. The timing unit 902 of the server 90 and the timing unit 804 of the user terminal 8 measure the elapsed time from the starting time. Note that the starting time of the elapsed time may be different between the server 90 and the user terminal 8. Furthermore, the access token may be periodically changed while being associated with the account information of user U within the expiration date.

[0073] During login after user U's login is permitted, as described in FIG. 5, the user terminal 8 is permitted to connect to the control circuit 40 of the electric bicycle 10. Furthermore, when user U's login is permitted, the user terminal 8 is permitted to control the control circuit 40. Specifically, the user terminal 8 is permitted to control the control circuit 40 based on the assist setting input by user U. Furthermore, when user U's login is permitted, the user terminal 8 is permitted to send information to the control circuit 40. On the other hand, when user U is not logged in, the user terminal 8 is not permitted to connect to the control circuit 40 of the electric bicycle 10.

[0074] While the user U is logged in and riding the electric bicycle 10, the user terminal 8 acquires the riding data transmitted from the control circuit 40 as needed and transmits the riding data to the server 90 at predetermined time intervals. Also, while the user U is logged in and riding the electric bicycle 10, map information and current riding data (riding speed, cadence, assist power, etc.) are displayed on the user terminal 8. Also, while the user U is logged in, the user terminal 8 can access past riding data stored in the server 90, allowing the user U to view the past riding data.

[0075] 9 is an example of a sequence diagram showing the processing of the login management system 1 when there are multiple login requests to the server 90 based on the account information of user U. Here, two different user terminals 8A and 8B appear, but the functional configurations of user terminals 8A and 8B are assumed to be the same as the above-mentioned user terminal 8. Furthermore, user terminals 8A and 8B may be owned by the same user U, or user terminal 8A may be owned by user U and user terminal 8B may be owned by another user.

[0076] First, we will explain login and logout of the user terminal 8A in Fig. 9. After completing login to the user terminal 8A using the account information of the user U (step S106), the user terminal 8A transitions to an offline environment (dashed line in Fig. 9) as the electric bicycle 10 is driven, and communication between the user terminal 8A and the server 90 is cut off. An offline environment is an environment where radio waves are difficult to reach and communication via the network NW is poor, such as inside a tunnel, an underground passage, or a mountainous area.

[0077] Even if the user terminal 8A transitions to an offline environment, the user terminal 8A maintains the login state of user U for a predetermined time. Furthermore, even if communication with the user terminal 8A is interrupted, the server 90 maintains the login state of user U for a predetermined time. Specifically, the user terminal 8A and the server 90 maintain the login state of user U for the validity period of the access token. Here, the starting time of the access token is the time when the server 90 last communicated with the user terminal 8A. If the elapsed time from the last communication is less than a predetermined time (e.g., less than 24 hours), the login state of user U is maintained even if communication between the server 90 and the user terminal 8A becomes impossible. Note that, as a repetition of the explanation, the starting time of the access token may be the time when the server 90 permitted user U to log in or the time when the server 90 last executed processing in response to a request from the user terminal 8A. The elapsed time from these times is measured by the timer 902 of the server 90 and the timer 902 of the user terminal 8A, respectively.

[0078] In the example shown in Figure 9, the user terminal 8A transitions from an offline environment to an online environment when the elapsed time from the last communication is less than a predetermined time, and resumes communication with the server 90. In this way, even if the user terminal 8A temporarily transitions to an offline environment due to riding the electric bicycle 10, the user U's login state is maintained for a predetermined time, so the connection between the user U and the control circuit 40 of the electric bicycle 10 is maintained, and assist control of the power unit 20 by the control circuit 40 becomes possible. In other words, the login management system 1 is a system constructed to prevent the assist control of the electric bicycle 10 from becoming impossible, taking into account cases where the electric bicycle 10, which is a mobile object, moves intermittently between online and offline environments.

[0079] Furthermore, the riding data acquired in the offline environment is temporarily stored in the storage unit 805 of the user terminal 8 or the memory 42 of the electric bicycle 10, and when the user terminal 8 transitions to an online environment, it is transmitted all at once to the server 90. This makes it possible to avoid loss of riding data when riding in an offline environment.

[0080] It is assumed that the user U performs a logout operation some time after the user terminal 8A transitions to an online environment (step S201). The logout operation is performed, for example, by touching a logout button (not shown) displayed on a user application. When the logout operation is performed, the user terminal 8A transmits a logout request to the server 90, and the server 90 executes a logout process for the user U in response to the logout request (step S202). The logout process by the server 90 is performed, for example, by calling an API for logout. The server 90 permits the user terminal 8A to log out the user U, and the user terminal 8A executes the logout process in response to the logout permission from the server 90 (step S203). In the logout process, the access token stored in association with the account information of the user U becomes invalid. As a result of this process, the user U enters a logged-out state.

[0081] Next, a description will be given of login to the server 90 by the user terminal 8B. In the login management system 1 of the first embodiment, when the server 90 receives a login request including account information of the user U while the user U is logged in after permitting the user U to log in and before executing logout of the user U, the server 90 denies a new login by the user U.

[0082] Specifically, while user U is logged in after step S105 in which the server 90 permits user U to log in to the user terminal 8A, the server 90 denies user U a new login (step S107) before step S202 in which the server 90 executes (permits) logout of user U. That is, the server 90 denies user U a new login during the period indicated by the thick solid line in FIG. 9. If a login request is made from user terminal 8B based on user U's account information during the period indicated by the thick solid line (step S121), the server 90 denies user U's login from user terminal 8B (step S122), and login to the server 90 by user terminal 8B fails (step S123). Note that when a login request is made from user terminal 8B based on user U's account information, the server 90 may authenticate the login based on user U's account information as in step S103 of FIG. 7. However, even if the authentication is successful, the server 90 denies user U's login from user terminal 8B.

[0083] This configuration can prevent multiple logins using the same account information, improving security. Also, while user U is logged in with his / her own account information, no one other than user U is permitted to log in to server 90 using user U's account information, preventing unauthorized access.

[0084] If the user U has logged out (i.e., after steps S202 and S203), the user terminal 8B makes a login request to the server 90 based on the user U's account information (step S131), and the server 90 permits the user U to log in (step S132), and the login to the server 90 by the user terminal 8B is completed (step S133).

[0085] FIG. 10 is another example of a sequence diagram showing the processing of the login management system 1 when there are multiple login requests to the server 90 based on the account information of the user U.

[0086] First, the login and logout of the user terminal 8A in Fig. 10 will be described. After the login to the user terminal 8A is completed using the account information of the user U (step S106), it is assumed that the user U terminates the user application without logging out after a while, or the user terminal 8A transitions to an offline environment (step S108). At this time, no communication is performed between the user terminal 8A and the server 90 (dashed line in Fig. 10).

[0087] The user terminal 8A maintains the login state of the user U for a predetermined time after the user application is terminated or the user terminal 8A transitions to an offline environment. Furthermore, the server 90 maintains the login state of the user U for a predetermined time even if communication with the user terminal 8A is interrupted. Specifically, the user terminal 8A and the server 90 maintain the login state of the user U when the time elapsed since the last communication is less than a predetermined time (for example, less than 24 hours), that is, when the access token is still within the expiration date. This eliminates the need for a login operation (login authentication) when the user application is resumed or the user terminal 8A transitions to an online environment within the predetermined time, thereby improving the convenience of the user application.

[0088] In the example shown in FIG. 10, a predetermined time has passed since the user terminal 8A and the server 90 last communicated. When the time that has elapsed since the user terminal 8A last communicated with the server 90 becomes equal to or greater than the predetermined time, the user terminal 8A executes a logout process for the user U, and logs out the user U (step S211). When the time that has elapsed since the server 90 last communicated with the user terminal 8A becomes equal to or greater than the predetermined time, the server 90 executes a logout process for the user U (step S212). In the logout process, the access token that has been stored in association with the account information of the user U becomes invalid. Through this process, the user U enters a logged-out state.

[0089] After the user terminal 8A is permitted to log in by the server 90, the user terminal 8A may be configured to maintain the logged-in state and be permitted to connect to the control circuit 40 of the electric bicycle 10, control the control circuit 40, or send information to the control circuit 40 until it receives from the server 90 a notification that the logout process for user U (the process of step S212) has been executed. In other words, even after the server 90 has executed the logout of user U, the user terminal 8A may be configured to maintain the logged-in state and be permitted to connect to the control circuit 40 of the electric bicycle 10, control the control circuit 40, or send information to the control circuit 40 until it receives from the server 90 a notification that the logout of user U has been executed.

[0090] With this configuration, the user terminal 8A can communicate with the control circuit 40 until it receives a notification from the server 90 that the user U has logged out, thereby improving user convenience.

[0091] Next, a description will be given of login to the server 90 by the user terminal 8B. While the user U is logged in after step S105 in which the server 90 permits the user U to log in to the user terminal 8A, the server 90 denies the user U from logging in again (step S107) before step S212 in which the server 90 logs out the user U. That is, the server 90 denies the user U from logging in again during the period indicated by the thick solid line in Fig. 10. If a login request is made from the user terminal 8B based on the account information of the user U during the period indicated by the thick solid line (step S121), the server 90 denies the user U from logging in through the user terminal 8B (step S122), and the login to the server 90 by the user terminal 8B fails (step S123). In addition, when a login request is received from user terminal 8B based on user U's account information, server 90 may authenticate the login based on user U's account information, as in step S103 of Figure 7, but even if the authentication is successful, server 90 will not allow user U to log in via user terminal 8B.

[0092] 9, multiple logins using the same account information can be avoided, improving security. Also, while user U is logged in with his / her own account information, no one other than user U is permitted to log in to server 90 using user U's account information, preventing unauthorized access.

[0093] After user U logs out (i.e., after steps S211 and S212), when user terminal 8B makes a login request to server 90 based on user U's account information (step S131), server 90 permits user U to log in (step S132), and login to server 90 by user terminal 8B is completed (step S133).

[0094] [Second embodiment] Next, a login management system 1 according to a second embodiment of the present invention will be described. The login management system 1 according to the second embodiment differs from the first embodiment in the control regarding login permission by the server 90. Note that the configuration of the login management system 1 is the same in the first and second embodiments, so a description thereof will be omitted and the same reference numerals will be used.

[0095] 11, assume that a temporary communication failure occurs in the user terminal 8 after the user terminal 8 transmits a login request to the server 90 in response to a login operation by the user U (step S101) (step S102) and before the server 90 transmits login permission to the user terminal 8 (step S105). In this case, the user terminal 8 fails to receive the login permission and access token transmitted from the server 90, resulting in a login failure (step S140). Meanwhile, the server 90 performs login authentication (step S103), generates and stores an access token linked to the account information of the user U (step S104), and permits login to the user terminal 8 and grants the access token (step S105), and therefore recognizes that the user terminal 8 has successfully logged in to the server 90.

[0096] If the server 90 denies new logins by the user U after permitting the user U to log in, even if the user U attempts to log in again immediately after the login failure in step S140, the login request including the account information of the user U will be denied. In this case, the logins of the user U are limited for a predetermined time until the server 90 performs a logout process (corresponding to step S212 in the first embodiment) that is executed over time.

[0097] Therefore, in the login management system 1 of the second embodiment, when the server 90 receives a login request including user U's account information while user U is logged in after allowing user U to log in, the server 90 allows user U to log in again.

[0098] Specifically, after the login failure in step S140 and after communication with the user terminal 8 is restored, if the user U attempts to log in again on the user terminal 8 (step S141), the user terminal 8 transmits the input account information of the user U to the server 90 and makes a login request again (step S142). The server 90 compares the transmitted account information of the user U with the account information of the user U stored in the storage unit 903, and if they match, authenticates the login based on the account information of the user U (step S143).

[0099] When login authentication of user U is complete, the server 90 invalidates the access token generated in step S104 and linked to the account information of user U (step S144), and generates and stores a new access token linked to the account information of user U (step S145). Then, the server 90 permits login to the user terminal 8 and grants the new access token (step S146), completing login to the server 90 by the user terminal 8 (step S147). The new access token granted to the user terminal 8 is stored in the storage unit 805.

[0100] By allowing a new login by user U while the other user U is logged in, it is possible to eliminate the possibility that login by user U may be restricted for a predetermined period of time due to a temporary communication failure, thereby improving user convenience.

[0101] The user U may retry the login operation (step S141) using a user terminal different from the user terminal used when the login failed.

[0102] Although the embodiments of the present invention have been described above with reference to the accompanying drawings, it goes without saying that the present invention is not limited to such embodiments. It is clear that those skilled in the art can conceive of various modifications and alterations within the scope of the claims, and it is understood that these also fall within the technical scope of the present invention. Furthermore, the components of the above embodiments may be combined in any manner without departing from the spirit of the invention.

[0103] For example, in each of the above-described embodiments, the user terminal 8 logs in to the server 90 via the network NW, but the present invention is not limited to this. For example, the user terminal 8 may log in to an application executed on the server 90, for example, an application executed by calling a predetermined API.

[0104] In addition, in each of the above-described embodiments, the vehicle that can be connected to the user terminal 8 via the user application has been exemplified as the electric bicycle 10, but this is not limited to this. For example, the vehicle may be an electric two-wheeled vehicle that does not require pedal input from the rider. Furthermore, the number of wheels of the vehicle is not limited, and it may be, for example, an electric three-wheeled or four-wheeled vehicle. Furthermore, the vehicle may be a non-electric vehicle (such as a human-powered vehicle or an engine-powered vehicle) other than an electric vehicle (the above-described electric bicycle, electric two-wheeled, electric three-wheeled, and electric four-wheeled vehicle).

[0105] Furthermore, although the electric bicycle 10 in each of the above-described embodiments is configured to include a power unit 20 and a control circuit 40, it may be configured not to include a control circuit 40. If the electric bicycle 10 does not include a control circuit 40, the user terminal 8 may be configured to directly control the power unit 20 instead of the control circuit 40 while logged in to the server 90.

[0106] The control methods described in the above various embodiments can be realized, for example, by executing a prepared program on a computer (processor). The program is stored in a computer-readable storage medium and is executed by being read from the storage medium. The program may also be provided in a form stored in a non-transitory storage medium such as a flash memory, or provided via a network such as the Internet.

[0107] This specification describes at least the following: In parentheses, components corresponding to those in the above-described embodiments are shown as examples, but the present invention is not limited to these.

[0108] (1) When a user logs in to a server (server 90), which is a remote computer, via a network (network NW) from a client (user terminal 8), which is a local computer used as a terminal, or to an application executed on a remote server via the network, At least one of the first identification information, which is the identification information of the user, the second identification information, which is the identification information of the client, and the information to be authenticated transmitted from the client is authenticated (step S103); A login management system (login management system 1) including a server control unit (control unit 901) that permits the login of the user if the authentication is successful (step S105), The server control unit, during the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login by the first user is not permitted (step S122). Login management system.

[0109] According to (1), after a login of the first user is permitted, new logins by the first user are not permitted during the login, so multiple logins by the first user can be prevented. This improves security regarding logins.

[0110] (2) The login management system according to (1), After the server control unit permits the login of the first user, The time elapsed since the login was permitted, The time since the last communication with the client; Or, The time elapsed since the last time a process was executed in response to a request from the client; Further provided is a timing unit (timing unit 902) that measures Login management system.

[0111] According to (2), the elapsed time used for processing after login is permitted can be measured appropriately.

[0112] (3) The login management system according to (2), After permitting the login of the first user, the server control unit: When the elapsed time measured by the timer unit reaches or exceeds a predetermined time, the first user is logged out without receiving a logout request from the first user (step S212). Login management system.

[0113] According to (3), if the client does not communicate with the server for a predetermined period of time after allowing the first user to log in, the first user is logged out, allowing the first user to log in again.

[0114] (4) A login management system according to any one of (1) to (3), The user is a rider of a vehicle (electric bicycle 10), The client has a client control unit (control unit 803) that is capable of communicating with the vehicle or a vehicle control unit (control circuit 40) of the vehicle. Login management system.

[0115] According to (4), even if the client moves to an offline environment after the first user has been permitted to log in due to a change in vehicle, new logins by the first user are not permitted while the first user is logged in, thereby preventing multiple logins by the first user.

[0116] (5) The login management system according to (4), When the login is permitted by the server control unit, the client control unit: Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. It will be set up so that Login management system.

[0117] According to (5), communication between the client control unit and the vehicle or the vehicle control unit can be performed upon permission of login.

[0118] (6) The login management system according to (5), The vehicle has an electric motor (motor M) that drives wheels of the vehicle, or the vehicle control unit controls the electric motor (motor M) that drives wheels of the vehicle, The interface unit (touch panel 800) of the client permission information for permitting the electric motor to generate power; ON information for turning on the power supply of the electric motor; Decision / change information for determining or changing the power generation mode of the electric motor; and, automation information for automatically setting a change of a power generation mode of the electric motor having a plurality of power generation modes; an information input unit (an assist power switch 851, a power change unit 854, a response change unit 855, an automatic mode switch 853) for inputting at least one of the input information; Login management system.

[0119] According to (6), the motor can be controlled based on the input information input to the client, that is, based on the user's intention.

[0120] (7) A login management system according to (5) or (6), The client: Other elapsed time from the time when the login was permitted by the server, Other elapsed time since the last time of communication with said server, Or, Other elapsed time since the last time the server executed a process in response to a request from the client; Further, the apparatus has another timer unit (timer unit 804) for measuring Login management system.

[0121] According to (7), the client can properly measure the elapsed time used for processing after login is permitted.

[0122] (8) The login management system according to (7), the client control unit also performs the following when communication with the server becomes impossible after the login is permitted by the server control unit and the other elapsed time measured by the other timing unit is less than the other predetermined time. Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. Login management system.

[0123] According to (8), even in an environment where communication with the server is no longer possible, the client can communicate with the vehicle or the vehicle control unit, thereby improving user convenience.

[0124] (9) A login management system according to (5) or (6), After the login is permitted by the server control unit, the client control unit continues to Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. Login management system.

[0125] According to (9), the client can communicate with the vehicle or the vehicle control unit until it receives from the server that the logout has been executed, thereby improving user convenience.

[0126] (10) The login management system according to (9), Even after the server control unit has executed the logout of the client, the client control unit continues to Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. Login management system.

[0127] According to (10), even after the server control unit has executed the logout of the client, the client can communicate with the vehicle or the vehicle control unit until it receives from the server that the logout has been executed, thereby improving user convenience.

[0128] (11) A login management system according to any one of (1) to (10), The server control unit, during the login of the first user after permitting the login of the first user and before executing logout of the first user, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login of the first user is not permitted even if the authentication is successful (step S122). Login management system.

[0129] According to (11), even if the authentication is successful, new logins by the first user are not permitted, so multiple logins by the first user can be avoided.

[0130] (12) A server (server 90) that is a remote computer and can communicate with a client (user terminal 8) that is a local computer used by a user as a terminal via a network (network NW), When the client logs into the server via the network or into an application running on the server, At least one of the first identification information, which is the identification information of the user, the second identification information, which is the identification information of the client, and the information to be authenticated transmitted from the client is authenticated (step S103); If the authentication is successful, the server allows the user to log in (step S105). The server control unit, during the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login by the first user is not permitted. server.

[0131] According to (12), after the first user's login is permitted, new logins by the first user are not permitted during the login period, so multiple logins by the first user can be prevented. This improves security regarding logins.

[0132] (13) A client (user terminal 8) is a local computer that can communicate with a server (server 90) that is a remote computer via a network (network NW) and is used by a user as a terminal, When logging into the server via the network or into an application running on the server, Transmitting at least one of first identification information, which is identification information of the user, second identification information, which is identification information of the client, and authentication information to the server (step S102); a client control unit (control unit 803) that, when the server has successfully authenticated at least one of the first identification information, the second identification information, and the information to be authenticated, receives permission for the user to log in from the server (step S105); The client control unit, during the login of a first user who is one of the users after receiving permission to log in from the first user, and before the first user logs out, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is sent to the server, the new login of the first user is denied (step S122). client.

[0133] According to (13), if a login request is made while the first user is logged in after being permitted to log in, the first user's new login is denied, which prevents the first user from logging in multiple times. This improves security regarding logins.

[0134] (14) The client according to (13), Other elapsed time from the time when the login was permitted by the server, Other elapsed time since the last time of communication with said server, Or, Other elapsed time since the last time the server executed a process in response to a request from the client; Further, another timer unit (timer unit 804) is provided to measure client.

[0135] According to (14), other elapsed times used in processing after login is permitted can be measured appropriately.

[0136] (15) The client according to (14), The user is a rider of a vehicle (electric bicycle 10), the client control unit is provided to be able to communicate with the vehicle or a vehicle control unit (control circuit 40) of the vehicle; the client control unit also performs the following when communication with the server becomes impossible after the login is permitted by the server and the other elapsed time measured by the other timing unit is less than the other predetermined time. Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. It will be set up so that client.

[0137] According to (15), even in an environment where communication with the server is no longer possible, the client can communicate with the vehicle or the vehicle control unit, thereby improving user convenience.

[0138] (16) When a user logs in to a server (server 90) which is a remote computer via a network (network NW) from a client (user terminal 8) which is a local computer used as a terminal, or to an application executed on a remote server via the network, a step of authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client (step S102); and permitting the login of the user if the authentication is successful (step S105), During the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, The method further includes a step (step S122) of disallowing a new login by the first user when a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received. How to manage logins.

[0139] According to (16), after the first user's login is permitted, new logins by the first user are not permitted during the login period, so multiple logins by the first user can be prevented. This improves security regarding logins.

[0140] (17) When a user logs in to a server (server 90) which is a remote computer via a network (network NW) from a client (user terminal 8) which is a local computer used as a terminal, or to an application executed on a remote server via the network, a step of authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client (step S102); and a step (step S105) of permitting the login of the user if the authentication is successful, During the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, causing the computer to further execute a step (step S122) of disallowing a new login by the first user when a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received; program.

[0141] According to (17), after the first user's login is permitted, new logins by the first user are not permitted during the login period, so multiple logins by the first user can be prevented. This improves security regarding logins.

[0142] (18) A computer-readable storage medium storing the program described in (17).

[0143] According to (18), the program described in (17) can be executed by a computer. [Explanation of symbols]

[0144] 1. Login Management System 8. User terminal (client) 800 Touch panel (interface section) 803 Control section (client control section) 804 Timekeeping unit (other timekeeping unit) 10 Electric bicycle (vehicle) 40 Control circuit (vehicle control unit) 90 Servers (computers) 901 Control unit (server control unit) 902 Timing section M motor (electric motor) NW Network

Claims

1. When a user logs in to a server, which is a remote computer, via a network from a client, which is a local computer used as a terminal, or to an application running on a remote server via a network, authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; A login management system including a server control unit that permits the login of the user when authentication is successful, The server control unit, during the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login by the first user is not permitted. Login management system.

2. 2. The login management system according to claim 1, After the server control unit permits the login of the first user, The time elapsed since the login was permitted, The time since the last communication with the client; Or, The time elapsed since the last time a process was executed in response to a request from the client; Further comprising a timing unit for measuring Login management system.

3. 3. The login management system according to claim 2, After permitting the login of the first user, the server control unit: When the elapsed time measured by the timing unit reaches or exceeds a predetermined time, the first user is logged out without receiving a logout request from the first user. Login management system.

4. 4. The login management system according to claim 1, The user is a passenger in a vehicle, The client has a client control unit that is provided to be able to communicate with the vehicle or a vehicle control unit of the vehicle. Login management system.

5. The login management system according to claim 4, When the login is permitted by the server control unit, the client control unit: Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. It will be set up so that Login management system.

6. 6. The login management system according to claim 5, the vehicle has an electric motor that drives wheels of the vehicle, or the vehicle control unit controls an electric motor that drives wheels of the vehicle, The interface unit of the client permission information for permitting the electric motor to generate power; ON information for turning on the power supply of the electric motor; determination / change information for determining or changing the power generation mode of the electric motor; and, automation information for automatically setting a change of a power generation mode of the electric motor having a plurality of power generation modes; an information input unit that inputs input information that is at least one of the following: Login management system.

7. 7. The login management system according to claim 5, The client: Other elapsed time from the time when the login was permitted by the server, Other elapsed time since the last time of communication with said server, Or, Other elapsed time since the last time the server executed a process in response to a request from the client; Further, the timekeeping unit measures Login management system.

8. The login management system according to claim 7, the client control unit also performs the following when communication with the server becomes impossible after the login is permitted by the server control unit and the other elapsed time measured by the other timing unit is less than the other predetermined time. Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. Login management system.

9. 7. The login management system according to claim 5, After the login is permitted by the server control unit, the client control unit continues to Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. Login management system.

10. The login management system according to claim 9, Even after the server control unit has executed the logout of the client, the client control unit continues to Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. Login management system.

11. The login management system according to any one of claims 1 to 10, The server control unit, during the login of the first user after permitting the login of the first user and before executing logout of the first user, when a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login of the first user is not permitted even if the authentication is successful. Login management system.

12. A server is a remote computer that can communicate with a client, which is a local computer used as a terminal by a user, via a network, and When the client logs into the server via the network or into an application running on the server, authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; a server control unit that permits the user to log in if the authentication is successful; The server control unit, during the login of a first user who is one of the users after permitting the login of the first user, and before executing logout of the first user, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received, the new login by the first user is not permitted. server.

13. A client is a local computer that can communicate with a server that is a remote computer via a network and is used as a terminal by a user, When logging into the server via the network or into an application running on the server, transmitting at least one of first identification information, which is identification information of the user, second identification information, which is identification information of the client, and authentication information to the server; a client control unit that receives permission for the user to log in from the server when the server has successfully authenticated at least one of the first identification information, the second identification information, and the information to be authenticated; The client control unit, during the login of a first user who is one of the users after receiving permission to log in from the first user, and before the first user logs out, When a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is sent to the server, the new login of the first user is denied. client.

14. 14. The client of claim 13, Other elapsed time from the time when the login was permitted by the server, Other elapsed time since the last time of communication with said server, Or, Other elapsed time since the last time the server executed a process in response to a request from the client; Further, another timing unit is provided to measure client.

15. 15. The client of claim 14, The user is a passenger in a vehicle, the client control unit is provided to be able to communicate with the vehicle or a vehicle control unit of the vehicle, the client control unit also performs the following when communication with the server becomes impossible after the login is permitted by the server and the other elapsed time measured by the other timing unit is less than the other predetermined time. Connection to the vehicle or the vehicle control unit of the vehicle is permitted. Control of the vehicle or the vehicle control unit is permitted. Or, Transmission of information to the vehicle or the vehicle control unit is permitted. It will be set up so that client.

16. When a user logs in to a server, which is a remote computer, via a network from a client, which is a local computer used as a terminal, or to an application running on a remote server via a network, a step of authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; and permitting the login of the user if the authentication is successful, During the login of a first user after permitting the login of the first user, and before executing logout of the first user, The method further includes a step of disallowing a new login by the first user when a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received. How to manage logins.

17. When a user logs in to a server, which is a remote computer, via a network from a client, which is a local computer used as a terminal, or to an application running on a remote server via a network, a step of authenticating at least one of first identification information which is identification information of the user, second identification information which is identification information of the client, and information to be authenticated transmitted from the client; and permitting the login of the user if the authentication is successful, During the login of a first user after permitting the login of the first user, and before executing logout of the first user, and causing the computer to further execute a step of disallowing a new login by the first user when a login request including the first identification information of the first user, the second identification information of the client, or the authenticated information is received. program.

18. A computer-readable storage medium storing the program according to claim 17.

Citation Information

Patent Citations

  • Management method for vehicle, management program for vehicle, storage medium, and information processing device

    WO2023171800A1