Access control system

The passage management system addresses communication challenges between mobile devices and authentication terminals by sharing restriction lifting information among terminals, ensuring efficient and secure passage management through group-based communication management.

JP2025152048APending Publication Date: 2025-10-09DENSO WAVE INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024053756
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-28
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Existing systems face challenges in expanding communication areas between mobile devices and authentication terminals, leading to unnecessary authentication communications and disruptions, especially when multiple terminals are in close proximity, which can hinder efficient passage management.

Method used

A passage management system where multiple authentication terminals communicate with each other and share passage restriction lifting information to prevent unnecessary re-authentication of mobile devices, allowing reliable authentication of authorized users by dividing terminals into groups and managing communication based on group affiliations.

Benefits of technology

This system ensures efficient and rapid lifting of passage restrictions by preventing unnecessary authentication attempts, reducing waiting times, and enhancing security by preventing unauthorized access through spoofing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025152048000001_ABST
    Figure 2025152048000001_ABST
Patent Text Reader

Abstract

To provide a security system which allows an authentication terminal can reliably communicate with an unauthorized portable terminal.SOLUTION: In a security gate system 1, authentication terminals 6(1) to 6(4) wirelessly perform authentication communication with a portable terminal 5 carried by an employee 4, and determine whether to release the security, or open a gate 3, according to a result of the authentication communication. When the security is released by the authentication terminal 6(1), the portable terminal 5 transmits security release information added to an advertisement, for a predetermined time, to the authentication terminals 6(1) to 6(4). The authentication terminals 6(1) to 6(4) having received the security release information prohibit authentication communication with the portable terminal 5 that has transmitted the advertisement when the received advertisement includes the security release information.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a system that communicates between an authentication terminal and a mobile terminal and determines whether or not to lift a traffic restriction depending on the result of authentication. [Background technology]

[0002] For example, there is a security system in which a gate is set up at the entrance and exit of a company to authenticate the identity of the employee when the employee enters or leaves the company, and the gate opens if the employee is authenticated. In recent years, as disclosed in Patent Document 1, for example, it has become common to use a mobile terminal such as a smartphone carried by an employee for authentication, and to communicate with the authentication terminal. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-162069 Summary of the Invention [Problem to be solved by the invention]

[0004] If the mobile device is an IC card, the communication distance with the authentication terminal is short, so one-to-one communication can be assumed. On the other hand, if the mobile device is a smartphone, authentication via wireless communication with the authentication terminal generally takes about 1 to 2 seconds. For this reason, it is necessary to expand the area in which communication between the two devices can begin, so that communication for authentication can begin more quickly and the time it takes to release security and open the gate can be shortened. As a result, communication between the mobile device and the authentication terminal must be one-to-many or many-to-many.

[0005] As described above, if the communication area between a mobile device and an authentication terminal is expanded, the authentication terminal may communicate with a mobile device other than an unauthenticated mobile device, such as a mobile device already authenticated by another authentication terminal, which may disrupt communication with the unauthenticated mobile device. Furthermore, if multiple authentication terminals are located in a relatively small area, a mobile device may perform unnecessary authentication communication with a second authentication terminal other than the first authentication terminal with which the first authentication communication was performed. In this case, when a mobile device carried by another user approaches the second authentication terminal and attempts to perform authentication communication, the authentication communication will be disrupted.

[0006] The present invention has been made in consideration of the above-mentioned situation, and its purpose is to provide a passage management system that enables an authenticated terminal to reliably communicate with an unauthenticated mobile terminal. [Means for solving the problem]

[0007] According to the passage management system of claim 1, multiple authentication terminals can communicate with each other and perform wireless authentication communication with mobile devices carried by users, and determine whether to lift the passage restriction based on the results of that authentication communication. When an authentication terminal authenticates a mobile device and lifts the passage restriction, it shares passage restriction lifting information indicating that the passage restriction has been lifted with the other authentication terminals. The other authentication terminals then prohibit authentication of the mobile device for a certain period of time based on the acquired passage restriction lifting information. This configuration allows the other authentication terminals to avoid unnecessary re-authentication of mobile devices whose passage restrictions have been lifted, and allows authentication of mobile devices whose passage restrictions have not been lifted.

[0008] According to the traffic management system of claim 2, the authentication terminal performs authentication communication with a plurality of mobile terminals. The authentication terminal that has acquired the traffic restriction lifting information prohibits authentication of the mobile terminals for which the traffic restriction has been lifted for a certain period of time, and allows authentication of the mobile terminals for which the traffic restriction has not been lifted. This allows the authentication terminal to reliably authenticate the mobile terminals for which the traffic restriction has not been lifted.

[0009] According to the passage management system of claim 3, the authentication terminal pre-authenticates a mobile terminal through authentication communication, stores information about the mobile terminal, and lifts the passage restriction in response to a lifting request from the pre-authenticated mobile terminal. Other authentication terminals delete information about pre-authenticated mobile terminals for which the passage restriction has been lifted from the stored information about the pre-authenticated mobile terminals based on the acquired passage restriction lifting information. This allows the other authentication terminals to delete information about pre-authenticated mobile terminals that they have already retained through unnecessary authentication communication, and to perform authentication communication with the mobile terminals in a proper procedure.

[0010] According to the passage management system of claim 4, the multiple authentication terminals are divided into multiple groups according to the target of passage restriction lifting. An authentication terminal that authenticates a mobile terminal and lifts the passage restriction transmits passage restriction lifting information along with the type of group to which it belongs. Among the authentication terminals that receive the information, authentication terminals that belong to the same group as the mobile terminal prohibit authentication of the mobile terminal for a certain period of time, while authentication terminals that belong to a group of a different type from the mobile terminal allow authentication of the mobile terminal. With this configuration, authentication terminals that belong to the same group are prevented from being hindered from communicating with other mobile terminals, while authentication terminals that belong to other groups can communicate with the mobile terminal for which the passage restriction has been lifted, thereby shortening the waiting time until passage is permitted.

[0011] According to the passage management system of claim 5, the multiple authentication terminals perform wireless authentication communication with the mobile terminals carried by the users and decide whether to lift the passage restriction based on the results of the authentication communication. The management device is capable of communicating with the multiple authentication terminals, and the authentication terminals acquire and store passage restriction lifting information indicating that they have authenticated the mobile terminal and lifted the passage restriction, and share this information with the multiple authentication terminals. The authentication terminals prohibit authentication with the mobile terminals for a certain period of time based on the passage restriction lifting information acquired from the management device. With this configuration, by having the management device share the passage restriction lifting information with other authentication terminals, the other authentication terminals can avoid performing unnecessary authentication on mobile terminals for which the passage restriction has been lifted, and can authenticate mobile terminals for which the passage restriction has not been lifted.

[0012] According to the passage management system described in claim 6, multiple authentication terminals perform wireless authentication communication with mobile devices carried by users and determine whether to lift the passage restriction based on the results of the authentication communication. The multiple authentication terminals can communicate with each other, pre-authenticate the mobile devices through authentication communication, store information about the mobile devices, and lift the passage restriction in response to a lifting request from the pre-authenticated mobile device. The authentication terminal that first pre-authenticates the mobile device, upon authenticating the mobile device, transmits pre-authentication completion information to the other authentication terminals indicating that authentication was completed before the lifting request from the mobile device. The authentication terminal that receives the pre-authentication completion information stores and retains the information in its memory and prohibits authentication of the mobile device. With this configuration, the other authentication terminals can prevent unnecessary authentication of pre-authenticated mobile devices, while lifting the passage restriction in response to a lifting request from the pre-authenticated mobile device without pre-authentication based on the stored pre-authentication completion information.

[0013] According to the passage management system of claim 7, the authentication terminal that has stored the pre-authentication completion information in its storage unit deletes the information from the storage unit and permits authentication communication with the mobile terminal after a certain period of time has elapsed. This allows the authentication terminal to prevent spoofing by unauthorized users who use the pre-authentication completion information to pass through illegally.

[0014] According to the passage management system of claim 8, the multiple authentication terminals perform wireless authentication communication with mobile devices carried by users and determine whether to lift the passage restriction based on the results of the authentication communication. The authentication terminals pre-authenticate the mobile devices through the authentication communication and store information about the mobile devices, and lift the passage restriction in response to a lifting request from the pre-authenticated mobile devices. The management device acquires and stores pre-authentication completion information indicating that the authentication terminal has pre-authenticated the mobile devices, and shares the information with the multiple authentication terminals. The authentication terminals prohibit authentication with the mobile devices based on the pre-authentication completion information acquired from the management device. With this configuration, the multiple authentication terminals can prevent unnecessary authentication with pre-authenticated mobile devices based on the pre-authentication completion information acquired from the management device, and can lift the passage restriction in response to a lifting request from the pre-authenticated mobile device without performing pre-authentication based on the stored pre-authentication completion information or pre-authentication results.

[0015] According to the traffic control system of claim 9, the multiple authentication terminals wirelessly communicate with the mobile terminals carried by the users to perform authentication and determine whether to lift the traffic restriction based on the results of the authentication communication. When the mobile terminal is authenticated by an authentication terminal and the traffic restriction is lifted, it transmits traffic restriction lifting information to at least the authentication terminal other than the authentication terminal for a certain period of time. The other authentication terminals prohibit authentication with the mobile terminal based on the received traffic restriction lifting information. With this configuration, the mobile terminal for which the traffic restriction has been lifted will not engage in unnecessary authentication communication with other authentication terminals, including already authenticated authentication terminals. This prevents communication for lifting the traffic restriction between the authentication terminal and other mobile terminals for which the traffic restriction has not yet been lifted, and allows the traffic restriction to be lifted quickly.

[0016] According to the passage management system of claim 10, the multiple authentication terminals are divided into multiple groups according to the targets for which passage restrictions are to be lifted. A mobile terminal that lifts a passage restriction transmits passage restriction lifting information to the authentication terminal, along with the type of group to which the authentication terminal that lifted the passage restriction belongs. If the group type attached to the received passage restriction lifting information differs from the group to which the authentication terminal belongs, the authentication terminal allows authentication of the mobile terminal. This configuration prevents interference with communication between an authentication terminal belonging to the same group A and other mobile terminals, and allows communication between the authentication terminal and the mobile terminal belonging to other groups, thereby reducing the waiting time until passage is permitted for other groups.

[0017] According to the passage management system of claim 11, the multiple authentication terminals perform wireless authentication communication with the portable terminals carried by the users, and decide whether to lift the passage restriction based on the results of the authentication communication. When the portable terminal is authenticated by the authentication terminal and the passage restriction is lifted, the portable terminal prohibits subsequent authentication communication for a certain period of time. This configuration makes it possible to prevent interference with communication between other portable terminals and the authentication terminal, and to quickly lift the passage restriction on other portable terminals. [Brief explanation of the drawings]

[0018] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a security gate system according to a first embodiment. [Figure 2] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 3] FIG. 2 is a diagram showing the configuration of a security gate system and a security door system arranged in the vicinity of the security gate system according to a second embodiment. [Figure 4] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 5] FIG. 10 is a diagram illustrating the configuration of a security gate system according to a third embodiment. [Figure 6] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 7]FIG. 10 is a diagram illustrating the configuration of a security gate system according to a fourth embodiment. [Figure 8] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 9] FIG. 10 is a diagram illustrating a communication sequence between a user, a mobile terminal, and multiple authentication terminals according to a fifth embodiment. [Figure 10] FIG. 10 is a diagram showing the configuration of a security gate system and a security door system arranged in the vicinity of the security gate system according to a sixth embodiment. [Figure 11] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 12] FIG. 13 is a diagram showing the configuration of a security gate system according to a seventh embodiment. [Figure 13] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 14] FIG. 13 is a diagram illustrating the configuration of a security gate system according to an eighth embodiment. [Figure 15] Diagram showing the communication sequence between a user, a mobile device, and multiple authentication devices (part 1) [Figure 16] Diagram showing the communication sequence between a user, a mobile device, and multiple authentication devices (part 2) [Figure 17] FIG. 9 is a diagram showing the configuration of a security gate system and a security door system arranged in the vicinity of the security gate system according to the ninth embodiment. [Figure 18] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. [Figure 19] FIG. 19 is a diagram showing the configuration of a security gate system according to a tenth embodiment. [Figure 20] FIG. 1 is a diagram showing a communication sequence between a user, a mobile terminal, and multiple authentication terminals. DETAILED DESCRIPTION OF THE INVENTION

[0019] (First embodiment) A first embodiment will be described below. The passage management system of this embodiment is assumed to be a so-called security gate system that is installed, for example, at the entrance and exit of a company, and when an employee clocks in or out, opens the gate to allow the employee to pass after authenticating that the employee is an employee of the company. As shown in FIG. 1, the security gate system 1 has multiple passage walls 2A to 2C arranged at predetermined intervals. Between the passage walls 2A and 2B, a flapper-type gate 3A is provided on the passage wall 2A side, and between the passage walls 2B and 2C, a similar gate 3B is provided on the passage wall 2B side.

[0020] In the figure, an employee 4, who is a user, uses a mobile terminal 5 such as a smartphone that he or she owns for authentication in the security gate system 1. In the figure, employees clock in (enter) from the top downwards, and clock out (exit) from the bottom upwards. Authentication terminals 6(1) and 6(2) are located on the upper side of the passage walls 2A and 2B, respectively. Authentication terminals 6(3) and 6(4) are located on the lower side of the passage walls 2B and 2C, respectively. The IDs of the authentication terminals 6(1) to 6(4) are ID1 to ID4, respectively.

[0021] When an employee clocks in, the mobile terminal 5 performs authentication communication with the authentication terminal 6(1) or 6(2), and when the employee clocks out, the mobile terminal 5 performs authentication communication with the authentication terminal 6(3) or 6(4). When the authentication terminal 6 authenticates that the employee is an employee of the company, it releases the security and opens the closed gate 3 by rotating it with a drive mechanism (not shown), thereby lifting the restriction on the passage of the employee 4 and allowing the employee 4 to pass through.

[0022] An application program (app) compatible with the security gate system 1 is downloaded in advance to the mobile terminal 5. By starting the app when using the security gate system 1, the mobile terminal 5 becomes capable of wireless authentication communication with the authentication terminal 6. The authentication terminals 6(1) to 6(4) communicate with each other using, for example, beacons.

[0023] Next, the operation of this embodiment will be described with reference to Figure 2. When employee 4 carrying mobile terminal 5 approaches authentication terminal 6(1) from above, mobile terminal 5 transmits an advertisement, which is a broadcast communication, at a predetermined interval. When user 4 enters the authentication communication range of authentication terminal 6(1) and authentication terminal 6(1) receives the advertisement transmitted by mobile terminal 5, authentication communication first takes place between mobile terminal 5 and authentication terminal 6(1). As a result, when authentication terminal 6(1) confirms the ID information of the employee registered on mobile terminal 5, mobile terminal 5 is authenticated, and authentication terminal 6(1) stores the ID information of the employee registered on the authenticated mobile terminal 5 for a predetermined period of time.

[0024] When employee 4 approaches authentication terminal 6(1) and holds mobile terminal 5 over the position of authentication terminal 6(1) (corresponding to a deactivation request), this triggers security deactivation communication and deactivates security. For example, if the ID information of employee 4 included in the advertisement matches the employee ID information stored in the authentication communication, security is deactivated. Then, gate 3A opens, the passage restriction is lifted, and employee 4 can pass through. When mobile terminal 5 recognizes that security has been deactivated, it sends advertisements with security deactivation information, which is information to lift the passage restriction, attached for a certain period of time.

[0025] The authentication terminal 6(1) performs pre-authentication of the mobile terminal 5 when the mobile terminal 5 approaches within the authentication communication range, and performs security deactivation communication when the mobile terminal 5 approaches a security deactivation communication range that is narrower than the authentication communication range, i.e., an area closer to the authentication terminal (1) than the authentication communication range. Note that the deactivation request, which is the trigger for initiating security deactivation communication, may be something other than holding the mobile terminal 5 over the authentication terminal 6. For example, the trigger may be pressing a button on the authentication terminal 6, holding the employee 4's hand over it, or detecting that the mobile terminal 5 is approaching the authentication terminal 6 in a hands-free state, i.e., while the employee 4 is carrying the mobile terminal 5 in their pocket or bag and not holding it over the authentication terminal 6. Note that the location of the mobile terminal 5 is determined based on the reception strength of the advertisements received by the authentication terminal 6, GPS information from the mobile terminal 5, etc.

[0026] At this point, the mobile terminal 5 has reached a position where it can perform authentication communication with the other authentication terminals 6(2) to 6(4), but if the security release information is added to the received advertisement, the authentication terminals 6(2) to 6(4) will not perform authentication communication with the mobile terminal 5 that sent the advertisement. In other words, it is possible to prohibit authentication communication with the mobile terminal 5.

[0027] As described above, according to this embodiment, in the security gate system 1, the authentication terminals 6(1) to 6(4) perform wireless authentication communication with the portable terminal 5 carried by the employee 4, and determine whether to deactivate security, i.e., whether to open the gate 3, based on the result of the authentication communication. When the portable terminal 5 is authenticated by the authentication terminal 6(1) and security is deactivated, the portable terminal 5 adds security deactivation information to an advertisement and transmits it to the authentication terminals 6(1) to 6(4) for a certain period of time. The authentication terminals 6(1) to 6(4) that receive the advertisement prohibit authentication communication with the portable terminal 5.

[0028] With this configuration, the mobile terminal 5 for which security has been released will not perform unnecessary authentication communication with the authentication terminals 6(1) to 6(4), so communication for releasing security between other mobile terminals for which security has not been released and the authentication terminals 6(1) to 6(4) will not be impeded, and security can be released quickly to allow the employee 4 to pass through. Note that the mobile terminal 5 may perform authentication communication and security release communication with the authentication terminal 6 using multicast or unicast communication instead of broadcast communication.

[0029] (Second embodiment) In the following, the same parts as in the first embodiment are given the same reference numerals and their explanations are omitted, and only the different parts are explained. In the second embodiment, it is assumed that a security door system 11 is installed adjacent to the security gate system 1 of the first embodiment, as shown in Fig. 3. Although it is shown simply in Fig. 3, the security door system 11 is for security management of the opening and closing of a door 12 installed at the entrance and exit of a building, such as a company building, and an authentication terminal 6(5) is installed on the entrance side and an authentication terminal 6(6) is installed on the exit side. These IDs are ID5 and ID6, respectively.

[0030] Similar to the security gate system 1, the security door system 11 opens the door 12 to allow entry and exit when an employee 4 holds a mobile terminal 5 over the authentication terminal 6(5) or 6(6), if the employee is authenticated as an employee. The mobile terminal 5 that has been authenticated and deactivated by the authentication terminal 6(1) sends an advertisement with security deactivation information. At this time, it is unclear whether the authentication terminal 6 whose security has been deactivated by the mobile terminal 5 belongs to the security door system 11 or the security gate system 1.

[0031] Then, even if employee 4 passes through gate 3 and approaches door 12 to enter the company building, authentication terminals 6(5), 6(6) will not perform authentication communication with mobile terminal 5 based on the fact that the security deactivation information is attached to the received advertisement. Therefore, employee 4 will not be able to deactivate the security of door 12 while mobile terminal 5 is sending the advertisement with the security deactivation information attached.

[0032] Therefore, in the second embodiment, the authentication terminals 6(1) to 6(4) and the authentication terminals 6(5) to 6(6) are divided into groups. For example, the former are a person gate group, and the latter are a door group. When the mobile terminal 5 transmits an advertisement with security deactivation information, the advertisement is assigned with the respective group IDs.

[0033] Next, the operation of the second embodiment will be described. As shown in Fig. 4, when the process up to security deactivation is performed in the same manner as in the first embodiment, the mobile terminal 5 transmits an advertisement with a group ID and security deactivation information attached for a certain period of time. Therefore, even if the authentication terminal 6(5) or 6(6) receives an advertisement with security deactivation information attached, it can be determined that the advertisement is security deactivation information within the person gate group.

[0034] Therefore, when authentication terminals 6(1) to 6(6) receive security release information for a group to which they belong, they do not perform authentication communication with mobile terminal 5 for a certain period of time, but when they receive security release information for a group different from their own, they do not prohibit but allow authentication of mobile terminal 5. For example, even if the received advertisement contains security release information, authentication terminal 6(5) or 6(6) does not prohibit authentication communication with mobile terminal 5 because it knows that the security release information is not for a group to which it belongs.

[0035] (Third embodiment) As shown in Figures 5 and 6, the security gate system 13 of the third embodiment is obtained by replacing the mobile terminal 5 of the security gate system 1 of the first embodiment with a mobile terminal 14. The system is the same as the first embodiment until security is deactivated. After that, the mobile terminal 14 stops sending advertisements for a certain period of time, instead of sending advertisements with security deactivation information attached. As a result, the authentication terminal 6 does not perform authentication communication with the mobile terminal 14 for a certain period of time, as in the first embodiment.

[0036] (Fourth embodiment) As shown in FIGS. 7 and 8, a security gate system 7 of the fourth embodiment uses a mobile terminal 8 and an authentication terminal 9 instead of the mobile terminal 5 and the authentication terminal 6. Next, the operation of the fourth embodiment will be described. The communication sequence up to the deactivation of security is the same as in the first embodiment. After that, the authentication terminal 9(1), which has deactivated security by authenticating the mobile terminal 8, transmits a security deactivation notification to the other authentication terminals 9(2) to 9(4). The authentication terminals 9(2) to 9(4) that have received the security deactivation notification prohibit authentication communication with the mobile terminal 8 whose security has been deactivated for a certain period of time. This provides the same effect as in the first embodiment.

[0037] For example, if the identification information unique to the mobile terminal 8 included in the advertising advice received from the mobile terminal 8, such as employee ID information, matches the identification information included in the security deactivation notification, the authentication terminals 9(2) to 9(4) prohibit authentication communication with the mobile terminal 8. Note that the method of sharing the security deactivation notification is not limited to the above. For example, the authentication terminal 9(1) that receives the advertisement from the mobile terminal 8 inquires of the other authentication terminals 9(2) to 9(4) whether the security of the mobile terminal 8 has been deactivated, and if it receives notification from the other authentication terminals 9(2) to 9(4) that the security has been deactivated, it prohibits authentication communication with the mobile terminal 8.

[0038] (Fifth embodiment) In the fifth embodiment, the authentication terminal 9 of the fourth embodiment is configured to hold information about a mobile terminal 8 that has been authenticated. When security release communication is performed between the mobile terminal 8 and the authentication terminal 9(1), as shown in Fig. 9, it is assumed that authentication communication is also completed between the nearby authentication terminal 9(2) and the mobile terminal 8, and that information about the mobile terminal 8 is already held in the authentication terminal 9(2) as information about the authenticated mobile terminal. In this case, when the authentication terminal 9(2) receives a security release notification related to the mobile terminal 8 from the authentication terminal 9(1), it deletes the authentication completion information about the mobile terminal 8 that it holds that is related to the security release mobile terminal 8.

[0039] (Sixth embodiment) As shown in Fig. 10, the sixth embodiment assumes that a security door system 11 is placed adjacent to the security gate system 7 of the fourth embodiment, as in the second embodiment. In this case, the authentication terminal 9(1) that authenticates the mobile terminal 8 and deactivates the security function sends a security deactivation notification to the other authentication terminals 9. In this case, if the authentication terminals 9(5) and 9(6) that belong to the security door system 11 are placed near the authentication terminal 9(1), the authentication terminals 9(5) and 9(6) will receive the security deactivation notification sent by the authentication terminal 9(1).

[0040] Then, even if employee 4 passes through gate 3 and approaches door 12 to enter the company building, authentication terminal 9(5) or 9(6) will not perform authentication communication with mobile terminal 8 held by employee 4 for a certain period of time based on the received security release notification. Therefore, employee 4 may not be able to release the security of door 12 until the certain period of time has passed.

[0041] Therefore, in the sixth embodiment, similar to the second embodiment, the authentication terminals 9(1) to 9(4) and the authentication terminals 9(5) to 9(6) are divided into groups. For example, the former are grouped as a person gate group, and the latter are grouped as a door group, and when each authentication terminal 9 communicates, it is assigned a group ID.

[0042] Next, the operation of the sixth embodiment will be described. As shown in Fig. 11, when the process up to the deactivation of security is performed in the same manner as in the second embodiment, the authentication terminal 9(1) transmits a personnel gate security deactivation notification to the other authentication terminals 9(2) to 9(4). At that time, even if the authentication terminal 9(5) or 9(6) receives the personnel gate security deactivation notification, it will know that it is a notification within the personnel gate group.

[0043] Therefore, authentication terminals 9(1) to 9(6) do not prohibit but allow authentication of mobile terminal 8 when the notification is from a group different from their own terminal, and do not perform authentication communication with mobile terminal 8 for a certain period of time when the notification is from the same group as their own terminal. For example, authentication terminal 9(5) or 9(6) allows authentication of mobile terminal 8 by discarding the received notification.

[0044] (Seventh embodiment) 12 and 13, a security gate system 21 of the seventh embodiment includes authentication terminals 22(1) to 22(4) that replace the authentication terminals 9(1) to 9(4) of the fourth embodiment, and a management device 23 that manages these. The authentication terminals 22 and the management device 23 can communicate with each other via wire or wirelessly. Next, the operation of the seventh embodiment will be described. As shown in Fig. 13, the communication sequence up to the deactivation of security is the same as that of the fourth embodiment. After that, the authentication terminal 22(1) deactivates security by authenticating the mobile terminal 8, and transmits a security deactivation notification to the management device 23. The management device 23, which has received the security deactivation notification, accumulates and holds the information of the notification in a memory or the like.

[0045] Each of the authentication terminals 22(1) to 22(4) periodically accesses the management device 23 to determine whether or not there is stored information. If the security deactivation notification information is acquired by an access made after the information has been stored, the authentication terminals 22(2) to 22(4) prohibit authentication communication with the mobile terminal 8 whose security has been deactivated for a certain period of time. This provides the same effect as the fourth embodiment. Note that instead of the authentication terminals 22(1) to 22(4) accessing the management device 23, the management device 23 may transmit the security deactivation notification information to the authentication terminals 22(2) to 22(4), thereby sharing the security deactivation notification information.

[0046] Furthermore, as in the sixth embodiment, when a security door system 11 is placed adjacent to a security gate system 21 of the seventh embodiment, as in the second embodiment, the multiple authentication devices may be divided into groups, for example, into a personnel gate group and a door group. The management device 23 transmits security deactivation notification information including the grouping information to each authentication device, and an authentication device that receives a security deactivation notification shared from a different group discards the notification. Furthermore, the management device 23 may transmit security deactivation notification information only to authentication terminals in the same group as the group to which the authentication terminal that deactivated the security belongs.

[0047] (Eighth embodiment) As shown in FIGS. 14 to 16, in a security gate system 15 of the eighth embodiment, the authentication terminal 9 in the security gate system 7 of the fourth embodiment is replaced with an authentication terminal 16. Next, the operation of the sixth embodiment will be described. The process up to the authentication communication is the same as in the second embodiment. Thereafter, the authentication terminal 16(1) transmits a pre-authentication completion notification to the other authentication terminals 16(2) to 16(4). Upon receiving the notification, the authentication terminals 16(2) to 16(4) store and accumulate information that pre-authentication of the mobile terminal 8 has been completed in their respective memories or the like. Thereafter, the authentication terminals 16(1) to 16(4) prohibit authentication communication with the mobile terminal 8 based on the information that pre-authentication of the mobile terminal 8 has been completed, which is stored in their own memories or the like.

[0048] Then, the mobile terminal 8 performs security release communication with the authentication terminal 16(1). However, as shown in FIG. 16, when the mobile terminal 8 approaches one of the authentication terminals 16(2) to 16(4), the pre-authentication of the mobile terminal 8 is completed, so that the security release communication can be started without performing authentication communication again.

[0049] Furthermore, after a certain period of time has elapsed, the authentication terminals 16(1) to 16(4) delete the information stored in their own memories or the like that indicates that pre-authentication of the mobile terminal 8 has been completed. This allows authentication communication with the mobile terminal 8 to be performed again.

[0050] (Ninth embodiment) 17 and 18, a security gate system 17 of the ninth embodiment is obtained by applying the sixth embodiment to the eighth embodiment. Authentication terminals 18(1) to 18(6) correspond to the authentication terminals 9(1) to 9(6) of the sixth embodiment.

[0051] Next, the operation of the ninth embodiment will be described. As shown in Fig. 18, after performing authentication communication, authentication terminal 18(1) assigns the ID of the person gate group to the pre-authentication completion notification and transmits it to the other authentication terminals 18(2) to 18(4). At that time, even if authentication terminal 18(5) or 18(6) receives the person gate pre-authentication completion notification, it can be determined that it is a notification within the person gate group. Therefore, authentication terminal 18(5) or 18(6) discards the received notification.

[0052] (Tenth embodiment) 19 and 20, a security gate system 24 of the tenth embodiment includes authentication terminals 25(1) to 25(4) that replace the authentication terminals 16(1) to 16(4) of the eighth embodiment, and a management device 26 that manages these. The authentication terminals 25 and the management device 26 can communicate with each other via wire or wirelessly.

[0053] Next, the operation of the tenth embodiment will be described. As shown in Fig. 20, the sequence up to the authentication communication is the same as that of the eighth embodiment. After that, the authentication terminal 25(1) that authenticates the mobile terminal 8 transmits a pre-authentication completion notice to the management device 26. Upon receiving the pre-authentication completion notice, the management device 26 accumulates and holds the information of the notice in a memory or the like.

[0054] Each of the authentication terminals 25(1) to 25(4) periodically accesses the management device 26 to determine whether or not there is stored information. When the authentication terminals 25(2) to 25(4) acquire the pre-authentication completion notification information through an access made after the information has been stored, the authentication terminals 25(2) to 25(4) prohibit authentication communication with the authenticated mobile terminal 8 for a certain period of time. The management device 26 deletes the pre-authentication completion notification information after a certain period of time has passed since the management device 26 stored the information. After that point, the authentication terminals 25(1) to 25(4) that access the management device 26 can perform authentication communication with the mobile terminal 8. Note that the pre-authentication completion notification information may be shared by the management device 23 transmitting the pre-authentication completion notification information to the authentication terminals 25(2) to 25(4) instead of the authentication terminals 25(1) to 25(4) accessing the management device 23.

[0055] Furthermore, as in the sixth embodiment, when a security door system 11 is placed adjacent to the security gate system 24 of the tenth embodiment, the multiple authentication devices may be divided into groups, for example, into a personnel gate group and a door group. The management device 26 transmits pre-authentication completion notification information including the grouping information to each authentication device, and an authentication device that receives a pre-authentication completion notification shared from a different group discards the notification. Furthermore, the management device 26 may transmit security deactivation notification information only to authentication terminals in the same group as the authentication terminal that deactivated the security setting.

[0056] The present invention is not limited to the embodiments described above or illustrated in the drawings, but can be modified or expanded as follows. The system is not limited to security gates and security doors, but also includes systems that manage entry and exit to areas that do not have physical restrictions such as electric locks, by authenticating the mobile device carried by the user and releasing the restrictions (security) on the user's passage. The number of authentication terminals may be changed as appropriate depending on the individual system. Users are not limited to employees. [Explanation of symbols]

[0057] In the drawings, 1 is a security gate system, 3 is a gate, 4 is an employee, 5 is a mobile terminal, 6 is an authentication terminal, 7 is a security gate system, 8 is a mobile terminal, 9 is an authentication terminal, 11 is a security door system, 13 is a security gate system, 14 is a mobile terminal, 15 is a security gate system, 16 is an authentication terminal, 17 is a security gate system, 18 is an authentication terminal, 21 is a security gate system, 22 is an authentication terminal, 23 is a management device, 24 is a security gate system, 24 is an authentication terminal, and 26 is a management device.

Claims

1. a mobile terminal possessed by a user and having a wireless communication function; a plurality of authentication terminals that perform authentication communication with the portable terminal by wireless and decide whether or not to lift the traffic restriction depending on the result of the authentication communication; the plurality of authentication terminals are capable of communicating with each other; When the authentication terminal authenticates the mobile terminal and lifts the traffic restriction, the authentication terminal shares traffic restriction lifting information indicating that the traffic restriction on the mobile terminal has been lifted with other authentication terminals; The other authentication terminal is a traffic management system that prohibits authentication of the mobile terminal for a certain period of time based on the acquired traffic restriction lifting information.

2. the authentication terminal performs authentication communication with the plurality of mobile terminals; A traffic management system as described in claim 1, wherein an authentication terminal that acquires the traffic restriction lifting information prohibits authentication of a mobile terminal among the plurality of mobile terminals for which the traffic restriction has been lifted for a certain period of time, and allows authentication of a mobile terminal for which the traffic restriction has not been lifted.

3. the authentication terminal is configured to pre-authenticate the portable terminal through the authentication communication, store information about the portable terminal, and release the passage restriction in response to a release request from the pre-authenticated portable terminal; A traffic management system as described in claim 1 or 2, wherein the other authentication terminal deletes information about the mobile terminal for which traffic restrictions have been lifted from the information about the pre-authenticated mobile terminals stored based on the acquired traffic restriction lifting information.

4. the plurality of authentication terminals are divided into a plurality of groups according to targets for which traffic restrictions are to be lifted; The authentication terminal that authenticates the mobile terminal and releases the traffic restriction transmits the traffic restriction release information together with the type of group to which the authentication terminal belongs, A passage management system as described in claim 1 or 2, wherein among the authentication terminals that receive the passage restriction lifting information, authentication terminals that belong to the same group as the type prohibit authentication of the mobile terminal for a certain period of time, and authentication terminals that belong to a group of a different type from the type allow authentication of the mobile terminal.

5. a mobile terminal possessed by a user and having a wireless communication function; a plurality of authentication terminals that perform authentication communication with the mobile terminal by wireless and decide whether or not to lift the traffic restriction based on the result of the authentication communication; a management device capable of communicating with the plurality of authentication terminals; the management device acquires and stores traffic restriction lifting information indicating that the authentication terminal has authenticated the mobile terminal and lifted the traffic restriction, and shares the information with the plurality of authentication terminals; The authentication terminal is a traffic management system that prohibits authentication with the mobile terminal for a certain period of time based on the traffic restriction lifting information obtained from the management device.

6. a mobile terminal possessed by a user and having a wireless communication function; a plurality of authentication terminals that perform authentication communication with the portable terminal by wireless and decide whether or not to lift the traffic restriction depending on the result of the authentication communication; the plurality of authentication terminals are capable of communicating with each other; pre-authenticates the portable terminal through the authentication communication and stores information about the portable terminal, and releases the traffic restriction in response to a release request from the pre-authenticated portable terminal; an authentication terminal that first performed the pre-authentication with the mobile terminal, upon authenticating the mobile terminal, transmits pre-authentication completion information indicating that the authentication was completed before the release request from the mobile terminal to the other authentication terminals; The authentication terminal that receives the pre-authentication completion information stores and retains the information in a memory unit, and prohibits authentication of the mobile terminal.

7. A passage management system as described in claim 6, wherein the authentication terminal that has stored the pre-authentication completion information in the memory unit deletes the information from the memory unit after a certain period of time has elapsed and allows authentication communication with the mobile terminal.

8. a mobile terminal possessed by a user and having a wireless communication function; a plurality of authentication terminals that perform authentication communication with the mobile terminal by wireless and decide whether or not to lift the traffic restriction based on the result of the authentication communication; a management device capable of communicating with the plurality of authentication terminals; the authentication terminal pre-authenticates the portable terminal through the authentication communication, stores information about the portable terminal, and lifts the traffic restriction in response to a lifting request from the pre-authenticated portable terminal; the management device acquires and stores pre-authentication completion information indicating that the authentication terminal has pre-authenticate the mobile terminal, and shares the information with the plurality of authentication terminals; The authentication terminal prohibits authentication with the mobile terminal based on pre-authentication completion information acquired from the management device.

9. a mobile terminal possessed by a user and having a wireless communication function; a plurality of authentication terminals that perform authentication communication with the portable terminal by wireless and decide whether or not to lift the traffic restriction depending on the result of the authentication communication; When the mobile terminal is authenticated by an authentication terminal and the traffic restriction is lifted, the mobile terminal transmits traffic restriction lift information to at least other authentication terminals other than the authentication terminal for a certain period of time; The other authentication terminal prohibits authentication of the mobile terminal based on the received traffic restriction lifting information.

10. the plurality of authentication terminals are divided into a plurality of groups according to targets for which traffic restrictions are to be lifted; the mobile terminal transmits the traffic restriction lifting information to the authentication terminal, together with a type of group to which the authentication terminal for which the mobile terminal lifted the traffic restriction belongs; The traffic management system according to claim 9, wherein the authentication terminal allows authentication of the mobile terminal when the type of group attached to the received traffic restriction lifting information is different from the group to which the authentication terminal belongs.

11. a mobile terminal possessed by a user and having a wireless communication function; a plurality of authentication terminals that perform authentication communication with the portable terminal by wireless and decide whether or not to lift the traffic restriction depending on the result of the authentication communication; The traffic management system prohibits subsequent authentication communication for a certain period of time when the mobile terminal is authenticated by an authentication terminal and the traffic restriction is lifted.

Citation Information

Patent Citations

  • Terminal authentication system, gate system, entrance / exit management system, and terminal authentication method

    JP2015162069A