Utilization management system, utilization control device, management device, utilization management method, and program
The system addresses geographical inconvenience and security risks by enabling remote reservation and verification through short-range communication and facial authentication, ensuring legitimate access to reserved objects.
Patent Information
- Application Number
- JP2025144989
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-01-20
- Filing Date
- 2025-09-01
- Publication Date
- 2025-11-18
AI Technical Summary
Existing usage management systems for facilities and mobile objects face issues of geographical inconvenience, increased security risks due to internet connectivity, and lack of legitimate user verification, particularly when users reserve online.
A usage management system that includes a usage control device, a photographing device, a management device, and a user terminal, utilizing short-range wireless communication, facial authentication, and cryptographic signatures to control access and ensure legitimate use.
Enhances convenience by allowing remote reservation and use verification, reduces security risks through localized communication, and ensures only authorized users can access the object.
Smart Images

Figure 2025170394000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a usage management technology for objects of use that can be restricted by locking / unlocking, startup control, access control, or encryption / decryption, including vehicles (automobiles, motorcycles, bicycles, etc.), ships, and other mobile objects, facilities such as hotels, inns, private lodgings, houses, and warehouses, and devices for viewing electronic media such as electronic medical records and e-books. In particular, the technology can be widely used in general usage management technologies that require verification of the person who has reserved the object of use with the person who actually uses the reserved object of use. It can also be widely used in general usage management technologies that require verification of the person who uses the object of use with a personal certificate with a photograph (such as an ID card). [Background technology]
[0002] Patent Document 1 discloses a system that allows users to use various services, including room locking and unlocking, in facilities such as companies, hospitals, amusement parks, and public facilities, simply by carrying a room key.
[0003] This system includes room keys each having a readable and writable RFID (Radio Frequency Identification) tag that stores information such as a room number, a PIN number, and customer information, RFID readers installed at various locations within the facility for reading and writing information from the RFID tags of the room keys, a database that stores information about each room and piece of equipment within the facility, and a server connected to the RFID readers and database via a network and managing each room and piece of equipment within the facility. For example, an RFID reader installed on the door or inside each room within the facility reads the information stored in the RFID tag of the room key and transmits it to the server. The server then compares the room number included in the information received from the RFID reader with the room number of the room in which the RFID reader is installed, and locks and unlocks the room. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2003-132435 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the system of Patent Document 1 is based on the premise that room keys are lent and returned at the reception desk of a facility such as a company, hospital, amusement park, or public facility. Therefore, even if a user makes a reservation for a facility online, the user must stop by the reception desk of the management department that manages the facility to borrow a room key before proceeding to the reserved facility. Furthermore, after using the facility, the user must stop by the reception desk of the management department to return the room key. Therefore, for example, if the reserved facility and the reception desk of the management department that manages the facility are geographically distant from each other, this system is inconvenient.
[0006] Furthermore, in the system of Patent Document 1, RFID readers installed at various locations within the facility read information stored in the RFID wireless tags of room keys and transmit the information to a server via a network. Therefore, if the server is installed outside the facility and the RFID readers installed at various locations within the facility are connected to the server via the Internet, each time the RFID reader reads information from the RFID wireless tags of room keys, the read information will be transmitted over the Internet. This increases security risks.
[0007] Furthermore, the system of Patent Document 1 does not take into consideration the verification of whether a user who uses a facility while carrying a loaned room key is a legitimate user authorized to use the facility.
[0008] The present invention has been made in consideration of the above circumstances, and its purpose is to provide a usage management technology for objects of use that can be restricted by locking / unlocking, startup control, access control, or encryption / decryption, including mobile objects such as vehicles and ships, facilities such as hotels, inns, private lodging facilities, houses, and warehouses, and devices for viewing electronic media such as electronic medical records and e-books, which can improve convenience while reducing security risks, and furthermore can limit specified usage of objects of use to only legitimate users. [Means for solving the problem]
[0009] In order to solve the above problems, the present invention comprises a usage control device that controls the usage of a usage object by locking / unlocking, startup control, access control, or encryption / decryption based on a usage license, a photographing device that photographs the user of the usage object, a management device that manages the usage control device by associating it with the usage object, and a user terminal that notifies the usage control device of the usage license.
[0010] Here, the management device stores a private key paired with a public key stored in the usage control device, and the user's facial authentication information. When a usage object is reserved by a user, the management device generates a usage permit including the usage conditions of the usage object, and generates a signature for the usage permit using the private key paired with the public key stored in the usage control device. The management device then transmits the usage permit, facial authentication information, and signature to the user terminal.
[0011] The user terminal transmits the usage permit and signature received from the management device to the usage control device via short-range wireless communication.
[0012] The usage control device stores a public key paired with a private key stored in the management device in association with the device itself. When the usage control device receives a usage permit and facial authentication information together with a signature from a user terminal via short-range wireless communication, it verifies the signature with the public key possessed by the device itself, and if the verification is successful and the usage conditions included in the usage permit are satisfied, it releases the first usage restriction on the usage target. Furthermore, when the first usage restriction on the usage target is released, it performs facial authentication using photographic data including a facial image of the user captured by the photographing device and the facial authentication information, and if facial authentication is successful, it releases the second usage restriction on the usage target.
[0013] For example, the present invention provides A usage management system that manages the usage of a usage target, a usage control device that controls the use of the target of use by locking / unlocking, activation control, access control, or encryption / decryption based on a usage license including the conditions for use of the target of use; an image capturing device that captures a face of the target user and transmits the captured image data to the usage control device; a management device that manages the usage control device by associating it with the usage object; a user terminal that notifies the usage control device of the usage license, The management device a key management means for managing a private key paired with a public key set in the usage control device in association with the usage control device; A facial authentication information management means for managing facial authentication information of a user; a license transmitting means for generating a signature for the license by using the private key managed by the key managing means, and transmitting the license and the face authentication information together with the signature to the user terminal, The user terminal a usage restriction release request means for transmitting a usage restriction release request, including the usage permit, the face authentication information, and the signature received from the management device, to the usage control device by short-range wireless communication; The usage control device includes: a signature verification means for verifying the signature included in the usage restriction release request received from the user terminal via short-range wireless communication using the public key set in the device itself; a first release means for releasing a first usage restriction on the target of use if the usage condition of the license included in the usage restriction release request is satisfied when the signature verification by the signature verification means is successful; a face authentication means for performing face authentication using the photographed data received from the photographing device and the face authentication information included in the usage restriction release request when the first usage restriction on the target user is released by the first release means; and second release means for releasing the second usage restriction on the target user if face authentication by the face authentication means is successful. [Effects of the Invention]
[0014] In the present invention, the usage control device acquires a usage license and facial authentication information from a user terminal using short-range wireless communication, and determines whether to release usage restrictions on a user using the acquired usage license and facial authentication information without outputting the acquired usage license and facial authentication information to an external device. Furthermore, the authenticity of the usage license is verified by verifying the signature using a public key. Therefore, security risks are reduced.
[0015] Furthermore, in the present invention, the first use restriction on the target of use is lifted only when the use conditions included in the license are satisfied (for example, unlocking the doors if the target of use is a car), and the first use restriction on the target of use is not lifted if the conditions are not satisfied. Therefore, by setting use conditions such as the date and time of use and the number of uses, a license that does not meet the use conditions becomes invalid even if its validity is proven, so there is no need to have the user (owner of the user terminal) return the license. This improves convenience.
[0016] Furthermore, in the present invention, when the first use restriction on the target of use is lifted, face authentication is performed using photographic data including a facial image of the user taken by the photographing device and face authentication information, and if face authentication is successful, the second use restriction on the target of use is lifted (for example, if the target of use is a car, the engine start lock is unlocked). Therefore, even if the validity of the use permit is proven and the use conditions included in the use permit are met, if the target of use is not a legitimate user managed by the management device, the second use restriction on the target of use is not lifted. Therefore, it is possible to limit the specified use of the target of use (lifting of the second use restriction) to only legitimate users.
[0017] In this way, according to the present invention, in a usage management technology for a usage object that can restrict usage by locking / unlocking, startup control, access control, or encryption / decryption, it is possible to improve convenience while reducing security risks, and further to limit specified usage of the usage object to only legitimate users. [Brief explanation of the drawings]
[0018] [Figure 1] FIG. 1 is a schematic diagram of a vehicle utilization management system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a sequence diagram showing an example of an account registration operation of a user in a vehicle utilization management system according to an embodiment of the present invention. [Figure 3] FIG. 3 is a sequence diagram showing an example of the operation of registering face authentication information of a user in the vehicle utilization management system according to the embodiment of the present invention. [Figure 4] FIG. 4 is a sequence diagram showing an example of a reservation operation for the vehicle 5 in the vehicle utilization management system according to the embodiment of the present invention. [Figure 5] FIG. 5 is a sequence diagram showing an example of a usage restriction release operation for the vehicle 5 in the vehicle usage management system according to the embodiment of the present invention. [Figure 6]FIG. 6 is a sequence diagram showing an example of the operation of removing the usage restriction on the vehicle 5 in the vehicle usage management system according to the embodiment of the present invention, and is a continuation of FIG. [Figure 7] FIG. 7 is a schematic functional configuration diagram of the usage control device 1. As shown in FIG. [Figure 8] FIG. 8 is a flow diagram for explaining the operation of the usage control device 1. As shown in FIG. [Figure 9] FIG. 9 is a flow chart for explaining the operation of the usage control device 1, and is a continuation of FIG. [Figure 10] FIG. 10 is a diagram showing a schematic functional configuration of the user terminal 4. As shown in FIG. [Figure 11] FIG. 11(A) is a flow diagram for explaining the account registration request operation of the user terminal 4, and FIG. 11(B) is a flow diagram for explaining the login request operation of the user terminal 4. As shown in FIG. [Figure 12] FIG. 12(A) is a flow diagram for explaining the operation of the user terminal 4 to request registration of face authentication information, and FIG. 12(B) is a flow diagram for explaining the operation of the user terminal 4 to request removal of usage restrictions. [Figure 13] FIG. 13 is a flow diagram for explaining the reservation request operation of the user terminal 4. [Figure 14] FIG. 14 is a diagram showing a schematic functional configuration of the management device 3. As shown in FIG. [Figure 15] FIG. 15 is a diagram showing an example of registered contents in the user information storage unit 30. As shown in FIG. [Figure 16] FIG. 16 is a diagram showing an example of registered contents in the usage control device information storage unit 31. As shown in FIG. [Figure 17] FIG. 17 is a diagram showing an example of registered contents in the reservation information storage unit 32. As shown in FIG. [Figure 18] FIG. 18(A) is a flow diagram for explaining the operation of the management device 3 to process an account registration request, and FIG. 18(B) is a flow diagram for explaining the operation of the management device 3 to process a login request. [Figure 19] FIG. 19 is a flowchart for explaining the operation of the management device 3 to process a request for registration of face authentication information. [Figure 20]FIG. 20 is a flow diagram for explaining the reservation request processing operation of the management device 3. DETAILED DESCRIPTION OF THE INVENTION
[0019] An embodiment of the present invention will be described below, taking as an example a case where the present invention is applied to a vehicle utilization management system.
[0020] FIG. 1 is a schematic diagram of a vehicle utilization management system according to the present embodiment.
[0021] As shown in the figure, the vehicle usage management system according to this embodiment includes a usage control device 1, a camera 2, a management device 3, and a user terminal 4.
[0022] The usage control device 1 is provided for each vehicle (rental car) 5 to be used, for example, in the glove compartment of the vehicle 5, and can communicate with vehicles other than the vehicle 5 only via short-range wireless communication 63 such as IrDA (Infrared Data Association) or Bluetooth (registered trademark). The usage control device 1 is equipped with a key box 10 for storing a vehicle key, and controls the unlocking of the key box 10 based on a usage permit. Furthermore, the usage control device 1 is connected to an in-vehicle network (not shown) of the vehicle 5, and controls the unlocking of the vehicle 5 door locks based on the usage permit, and controls the unlocking of the vehicle 5 engine start lock based on the usage permit and face authentication information.
[0023] The camera 2 is installed in a position where it can capture an image of the face of the driver sitting in the driver's seat, and has a human detection sensor (not shown) such as an infrared sensor that detects the driver sitting in the driver's seat. When the human detection sensor detects the driver sitting in the driver's seat, it transmits photographed data including an image of the driver's face to the usage control device 1.
[0024] The management device 3 manages the usage control device 1 in association with the vehicle 5 in which the usage control device 1 is installed. The management device 3 also manages the reservation status of the vehicle 5, and upon receiving a reservation request from a user terminal 4 via a WAN (Wide Area Network) 60, transmits to the user terminal 4 a usage permit and face authentication information for using the vehicle 5 of the type included in the reservation request on the date and time included in the reservation request.
[0025] A user terminal 4 is provided for each user and is connected to a WAN 60 via a wireless network 62 such as a wireless LAN (Local Area Network) and a relay device 61. The user terminal 4 also transmits a reservation request to the management device 3 and receives a usage permit and facial authentication information from the management device 3. The user terminal 4 then transmits the usage permit and facial authentication information received from the management device 3 to the usage control device 1 via short-range wireless communication 63.
[0026] FIG. 2 is a sequence diagram showing an example of an account registration operation of a user in the vehicle utilization management system according to the present embodiment.
[0027] When the user terminal 4 receives an account registration operation from the user, including the user's personal information (S100), it sends an account registration request including the user's personal information to the management device 3 via the wireless network 62, the relay device 61 and the WAN 60 (S101).
[0028] In response to this, the management device 3 generates account information (user ID, password (PW)) (S102), and registers this account information in association with the user's personal information included in the account registration request (S103).The management device 3 then transmits an account registration completion notification including the account information to the user terminal 4 that sent the account registration request via the WAN 60, relay device 61, and wireless network 62 (S104).
[0029] FIG. 3 is a sequence diagram showing an example of the operation of registering face authentication information of a user in the vehicle utilization management system according to the present embodiment.
[0030] First, when the user terminal 4 receives a login operation accompanied by account information (user ID, password) from the user (S110), it transmits a login request including this account information to the management device 3 (S111).
[0031] In response to this, the management device 3 performs authentication processing using the account information included in the login request and the account information registered in the management device 3 (S112). If the authentication is successful, the management device 3 permits login of the user terminal 4 that sent the login request, and transmits a login permission notification to this user terminal 4 (S113).
[0032] Next, when the user terminal 4 receives a facial authentication information registration operation from the user (S114), it photographs the user's face and driver's license (hereinafter, license) in a predetermined order using the built-in camera or an external camera of the user terminal 4 (S115). Then, it transmits a facial authentication information registration request including photographed data of the user's face and license to the management device 3 (S116).
[0033] In response to this, the management device 3 extracts facial features from each of the facial image data and the license image data (S117). Then, the management device 3 performs face authentication of the user using the facial features extracted from each of the facial image data and the license image data (S118). Specifically, the management device 3 analyzes the degree of match between the facial features extracted from the facial image data and the facial features extracted from the license image data, and determines that face authentication is successful if the degree of match is equal to or greater than a predetermined value, and determines that face authentication is unsuccessful if the degree of match is less than the predetermined value. If face authentication is successful, the management device 3 registers the facial features extracted from the facial image data or the license image data as the user's face authentication information, linking them to the user's account information along with the license image data (S119).
[0034] Then, the management device 3 transmits a face authentication information registration completion notification to the user terminal 4 that is the sender of the face authentication information registration request (S120).
[0035] FIG. 4 is a sequence diagram showing an example of a reservation operation for the vehicle 5 in the vehicle utilization management system according to the present embodiment.
[0036] First, when the user terminal 4 receives a login operation accompanied by account information (user ID, password) from the user (S130), it transmits a login request including this account information to the management device 3 (S131).
[0037] In response to this, the management device 3 performs authentication processing using the account information included in the login request and the account information registered in the management device 3 (S132). If the authentication is successful, the management device 3 permits login of the user terminal 4 that sent the login request, and transmits a login permission notification to this user terminal 4 (S133).
[0038] Next, when the user terminal 4 receives a viewing operation including the date and time of use from the user (S134), it transmits a viewing request including this date and time of use to the management device 3 (S135).
[0039] In response to this, the management device 3 searches the reservation status for vehicle types 5 that are available on the date and time included in the viewing request (S136), and then transmits a list of vehicle types that are available on the date and time to the user terminal 4 (S137).
[0040] Next, the user terminal 4 displays the list data of available vehicle models received from the management device 3 and accepts a reservation operation from the user, including the selection of the vehicle model to be reserved (S138).Then, the user terminal 4 transmits a reservation request including the vehicle model selected by the reservation operation and the date and time of use specified by the viewing operation to the management device 3 (S139).
[0041] In response to this, the management device 3 performs reservation processing to reserve the vehicle 5 of the type included in the reservation request for the date and time included in the reservation request (S140), and then issues a usage permit that includes the reserved date and time as a usage condition (S141), and searches for face authentication information registered in association with the user's account information (S142).
[0042] Next, the management device 3 encrypts the usage permit and face authentication information using a common key set in the usage control device 1 managed in association with the reserved vehicle 5 to generate cryptographic information, and generates a signature for the cryptographic information using a private key paired with the public key set in the usage control device 1 (S143).The management device 3 then transmits the cryptographic information and the signature to the user terminal 4 (S144).
[0043] 5 and 6 are sequence diagrams showing an example of the operation of removing restrictions on use of the vehicle 5 in the vehicle use management system according to the present embodiment.
[0044] It is assumed that the user, carrying the user terminal 4, moves close to the reserved vehicle 5. Here, when the user terminal 4 receives a usage restriction release operation from the user (S150), it transmits a usage restriction release request including the encryption information and signature received from the management device 3 for the reserved vehicle 5 via short-range wireless communication 63 to the usage control device 1 (S151).
[0045] In response to this, the usage control device 1 uses the public key set in the device 1 to verify the signature for the cryptographic information included together with the cryptographic information in the usage restriction release request received from the management device 3 (S152). If the signature verification is successful, the usage control device 1 uses the common key set in the device 1 to decrypt the cryptographic information included in the usage restriction release request into a usage permit and face authentication information (S153).
[0046] The usage control device 1 then checks whether the usage conditions included in the usage permit are satisfied (S154). Specifically, it checks whether the current date and time falls within the usage time period (the time period from the usage start date and time to the usage end date and time) included in the usage permit as a usage condition. If it is confirmed that the usage conditions are satisfied, it unlocks the doors of the vehicle 5 and also unlocks the key box 10 (S155). This allows the user to open the door of the vehicle 5, enter the vehicle, and obtain the vehicle key from the key box 10 (S156).
[0047] The usage control device 1 also locks the engine start of the vehicle 5 (S157). Therefore, at this timing, the ignition of the vehicle 5 can be turned on using the vehicle key, but the engine of the vehicle 5 cannot be started unless the lock on engine start is released.
[0048] Next, it is assumed that the user sits in the driver's seat of vehicle 5 as the driver and turns on the ignition of vehicle 5 using the vehicle key. This powers on camera 2, and camera 2 starts up (S158). Camera 2 then monitors the presence or absence of a driver sitting in the driver's seat using a human detection sensor, and when it detects that a driver is sitting in the seat based on the output of the human detection sensor (S159), it photographs or captures the driver (S160) and transmits the photographed data including an image of the driver's face to the usage control device 1 (S161).
[0049] When the usage control device 1 receives the photographed data from the camera 2, it extracts facial features of the driver captured in this photographed data (S162). Then, the usage control device 1 performs facial authentication of the driver using the facial features extracted from the photographed data of the camera 2 and the facial authentication information included in the usage restriction release request received from the user terminal 4 (S163). Specifically, the usage control device 1 analyzes the degree of matching between the facial features extracted from the photographed data and the facial authentication information, and determines that facial authentication is successful if the degree of matching is equal to or greater than a predetermined value, and determines that facial authentication is not successful if the degree of matching is less than the predetermined value.
[0050] If face authentication is successful, the usage control device 1 unlocks the engine start lock of the vehicle 5 (S164). As a result, the user of the user terminal 4 who has reserved the vehicle 5 (the person reserving the vehicle 5) can start the engine using the vehicle key and drive the vehicle 5 as the driver. On the other hand, a user other than the person reserving the vehicle 5 (such as a passenger) can borrow the user terminal 4 or vehicle key from the person reserving the vehicle 5 and get into the vehicle 5, but cannot start the engine of the vehicle 5.
[0051] Next, we will explain in detail the usage control device 1, user terminal 4, and management device 3 that make up the usage management system according to this embodiment. Note that, since an existing camera equipped with a human detection sensor can be used as camera 2, detailed explanation thereof will be omitted.
[0052] First, the usage control device 1 will be described in detail.
[0053] FIG. 7 is a schematic functional configuration diagram of the usage control device 1. As shown in FIG.
[0054] As shown in the figure, the usage control device 1 includes a key box 10, a short-range wireless communication unit 11, an in-vehicle network connection unit 12, a hall data storage unit 13, a usage restriction removal request receiving unit 14, a signature verification unit 15, a decryption unit 16, a photographic data acquisition unit 17, a feature extraction unit 18, a face authentication unit 19, and a usage restriction removal unit 20.
[0055] The key box 10 is a storage box for vehicle keys and has an auto-lock function.
[0056] The short-distance wireless communication unit 11 communicates with the user terminal 4 by short-distance wireless communication 63 such as IrDA or Bluetooth (registered trademark).
[0057] The in-vehicle network connection unit 12 is an interface for connecting to an in-vehicle network (not shown) of the vehicle 5.
[0058] The hole data storage unit 13 stores hole data including a public key (a public key paired with a private key assigned to the self-utilization control device 1) and a common key (a common key secretly held between the self-utilization control device 1 and the management device 3).
[0059] The usage restriction lifting request receiving unit 14 receives a usage restriction lifting request including the usage permit, the encrypted information of the face authentication information, and a signature for this encrypted information from the user terminal 4 via the short-range wireless communication unit 11.
[0060] The signature verification unit 15 verifies the signature included in the usage restriction removal request received by the usage restriction removal request receiving unit 14 using the public key included in the hole data stored in the hole data storage unit 13.
[0061] The decryption unit 16 uses the common key contained in the hole data stored in the hole data storage unit 13 to decrypt the encrypted information contained in the usage restriction release request received by the usage restriction release request receiving unit 14 into a usage permit and facial authentication information.
[0062] The photographed data acquisition unit 17 acquires photographed data including a facial image of the driver from the camera 2 via the in-vehicle network connection unit 12.
[0063] The feature extraction unit 18 extracts features of the driver's face from the photographic data of the driver acquired by the photographic data acquisition unit 17.
[0064] The face authentication unit 19 performs face authentication using the facial features of the driver extracted by the feature extraction unit 18 and the facial authentication information decoded by the decoding unit 16. Specifically, it analyzes the degree of matching between the facial features of the driver and the facial authentication information, and determines that face authentication is successful if the degree of matching is equal to or greater than a predetermined value, and that face authentication is unsuccessful if the degree of matching is less than the predetermined value.
[0065] If the signature verification by the signature verification unit 15 is successful and the usage conditions included in the usage permit decrypted by the decryption unit 16 are satisfied, the usage restriction release unit 20 unlocks the key box 10 and transmits a command to unlock the doors and a command to lock the engine start to the vehicle 5 via the in-vehicle network connection unit 12. If face authentication by the face authentication unit 19 is successful in a state where the key box 10 and doors are unlocked and the engine start is locked, the usage restriction release unit 20 transmits a command to unlock the engine start lock to the vehicle 5 via the in-vehicle network connection unit 12.
[0066] 7 may be realized in hardware using an integrated logic IC such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array), or in software using a computer such as a DSP (Digital Signal Processor). Alternatively, the usage control device 1 may be realized as a process in a general-purpose computer equipped with a CPU, memory, an auxiliary storage device such as a flash memory, a short-range wireless communication device such as an IrDA communication device or a Bluetooth (registered trademark) communication device, and an in-vehicle network interface device, by the CPU loading a predetermined program from the auxiliary storage device into the memory and executing it.
[0067] 8 and 9 are flow charts for explaining the operation of the usage control device 1. FIG.
[0068] This flow starts when the usage restriction removal request receiving unit 14 receives a usage restriction removal request from the user terminal 4 via the short-range wireless communication unit 11.
[0069] First, the usage restriction removal request receiving unit 14 passes the encryption information and signature included in the usage restriction removal request received from the user terminal 4 to the signature verifying unit 15. In response to this, the signature verifying unit 15 verifies the signature for the encryption information using the public key included in the hole data stored in the hole data storage unit 13 (S200). Specifically, the signature is decrypted using the public key, and the authenticity of the signature is verified by determining whether the decrypted information matches the encryption information or its message digest (hash value).
[0070] If the signature verification fails (NO in S201), the signature verification unit 15 performs a predetermined error processing such as notifying the user terminal 4 of this fact via the short-range wireless communication unit 11 (S202), and ends this flow.
[0071] On the other hand, if the signature verification is successful (YES in S201), the signature verification unit 15 passes the encrypted information to the decryption unit 16. In response to this, the decryption unit 16 decrypts the encrypted information received from the signature verification unit 15 into a license and facial authentication information using the common key included in the hole data stored in the hole data storage unit 13 (S203). Then, the usage license and facial authentication information are passed to the usage restriction release unit 20.
[0072] Next, the usage restriction lifting unit 20 checks whether the usage conditions included in the usage certificate received from the decryption unit 16 are satisfied (S204). For example, it checks whether the current date and time falls within the usage time period (the time period from the usage start date and time to the usage end date and time) included in the usage certificate as a usage condition. If the usage conditions are not satisfied (NO in S205), the usage restriction lifting unit 20 performs a predetermined error process, such as notifying the user terminal 4 of this fact via the short-range wireless communication unit 11 (S202), and ends this flow.
[0073] On the other hand, if the usage conditions are satisfied (YES in S205), the usage restriction release unit 20 transmits a door unlock command to the vehicle 5 via the in-vehicle network connection unit 12 to cause the vehicle 5 to unlock the doors and also unlock the key box 10 (S206). This allows the user of the user terminal 4 to open the door of the vehicle 5, get inside the vehicle, and obtain the vehicle key from the key box 10. Then, the usage restriction release unit 20 transmits an engine start lock command to the vehicle 5 via the in-vehicle network connection unit 12 to cause the vehicle 5 to lock the engine start (S207). Therefore, at this time, the ignition of the vehicle 5 can be turned on using the vehicle key, but the engine cannot be started unless the engine start lock is released.
[0074] Next, the usage restriction removal unit 20 checks whether the usage conditions are still satisfied while monitoring the ignition state of the vehicle 5 via the in-vehicle network connection unit 12. Then, when the ignition is off (NO in S208), the usage restriction removal unit 20 ends this flow if the usage conditions are no longer satisfied (NO in S209). On the other hand, when the ignition is on (YES in S208), the usage restriction removal unit 20 waits for the face authentication result to be sent from the face authentication unit 19.
[0075] Next, when the ignition is on (YES in S208), the photographic data acquisition unit 17 receives photographic data from the camera 2 via the in-vehicle network connection unit 12 (YES in S210) and passes this photographic data to the feature extraction unit 18. In response to this, the feature extraction unit 18 extracts facial features of the driver from the photographic data received from the photographic data acquisition unit 17 (S211) and passes the extracted features to the face authentication unit 19. Then, the face authentication unit 19 obtains facial authentication information decoded by the decoding unit 16 from the usage restriction release unit 20, performs facial authentication using this facial authentication information and the facial features of the driver received from the feature extraction unit 18 (S212), and passes the facial authentication result to the usage restriction release unit 20.
[0076] When the usage restriction removal unit 20 receives the face authentication result from the face authentication unit 19, if the face authentication result indicates that face authentication has been successful (YES in S213), it transmits an engine startup lock release command to the vehicle 5 via the in-vehicle network connection unit 12, causing the vehicle 5 to release the engine startup lock (S214). As a result, the user of the user terminal 4 who has made the reservation for the vehicle 5 (the person reserving the vehicle 5) can start the engine using the vehicle key and drive the vehicle 5 as the driver.
[0077] On the other hand, if the face authentication result received from the face authentication unit 19 indicates that face authentication has not been established (NO in S213), the usage restriction release unit 20 performs predetermined error processing, such as outputting an error message to the vehicle 5 via the in-vehicle network connection unit 12, without unlocking the lock on engine start (S215). Therefore, a user (passenger, etc.) other than the person who reserved the vehicle 5 cannot start the engine of the vehicle 5, even if they borrow the user terminal 4 or vehicle key from the person who reserved the vehicle 5 and get into the vehicle 5.
[0078] Furthermore, if the ignition of the vehicle 5 changes from the on state to the off state (YES in S216), the usage restriction lifting unit 20 returns to S207 and locks the engine of the vehicle 5 from starting.
[0079] Next, the user terminal 4 will be described in detail.
[0080] FIG. 10 is a diagram showing a schematic functional configuration of the user terminal 4. As shown in FIG.
[0081] As shown in the figure, the user terminal 4 includes a man-machine interface unit 40, a wireless network interface unit 41, a short-range wireless communication unit 42, a built-in or external camera 43, an account information storage unit 44, an encryption information storage unit 45, an account registration request unit 46, a login request unit 47, a face authentication information registration request unit 48, a reservation request unit 49, and a usage restriction release request unit 50.
[0082] The man-machine interface unit 40 is an interface for presenting information to a user and accepting various operations from the user, and includes, for example, a touch panel display.
[0083] The wireless network interface unit 41 is an interface for connecting to the WAN 60 via the wireless network 62 and the relay device 61 .
[0084] The short-distance wireless communication unit 42 communicates with the usage control device 1 by short-distance wireless communication 63 such as IrDA or Bluetooth (registered trademark).
[0085] The account information storage unit 44 stores account information (user ID, password) for the user terminal 4 to log in to the management device 3.
[0086] The encryption information storage unit 45 stores encryption information for the license and face authentication information, and a signature for this encryption information.
[0087] In accordance with an account registration operation received from a user via the man-machine interface unit 40, the account registration request unit 46 transmits an account registration request to the management device 3, acquires account information from the management device 3, and stores it in the account information storage unit 44.
[0088] In accordance with a login operation received from a user via the man-machine interface unit 40, the login request unit 47 sends a login request including the account information stored in the account information storage unit 44 to the management device 3, and logs in to the management device 3.
[0089] In accordance with the facial authentication information registration operation received from the user via the man-machine interface unit 40, the facial authentication information registration request unit 48 causes the camera 43 to photograph the face and driver's license of the user of the user terminal 4, and sends a facial authentication information registration request including this photographed data to the management device 3, thereby registering the facial authentication information of the user of the user terminal 4 in the management device 3.
[0090] The reservation request unit 49, in accordance with a viewing operation received from the user via the man-machine interface unit 40, obtains from the management device 3 a list of vehicle types of vehicles 5 available on the user's desired date and time of use, and displays the list on the man-machine interface unit 40. Furthermore, when the reservation request unit 49 receives a reservation operation from the user via the man-machine interface unit 40 to select one of the vehicle types displayed in the list on the man-machine interface unit 40, it transmits a reservation request including the selected vehicle type and the user's desired date and time of use to the management device 3. As a result, the reservation request unit 49 obtains from the management device 3 the encryption information of the usage permit and facial authentication information required to use the vehicle 5 of the desired model on the desired date and time of use, as well as a signature for this encryption information, and stores these in the encryption information storage unit 45.
[0091] In accordance with the usage restriction removal operation received from the user via the man-machine interface unit 40, the usage restriction removal request unit 50 transmits a usage restriction removal request including the encryption information and signature stored in the encryption information memory unit 45 to the usage control device 1 via the short-range wireless communication unit 42.
[0092] 10 may be realized in hardware using an integrated logic IC such as an ASIC or FPGA, or in software using a computer such as a DSP. Alternatively, it may be realized as a process by the CPU loading a predetermined program from the auxiliary storage device into the memory and executing it in a network terminal such as a smartphone or tablet PC that includes a CPU, memory, an auxiliary storage device such as a flash memory, a short-range wireless communication device such as an IrDA communication device or a Bluetooth (registered trademark) communication device, a wireless network communication device such as a wireless LAN adapter, and a camera.
[0093] FIG. 11(A) is a flow diagram for explaining the account registration request operation of the user terminal 4. As shown in FIG.
[0094] This flow starts when the account registration request unit 46 accepts an account registration operation from the user via the man-machine interface unit 40.
[0095] First, the account registration request unit 46 accepts personal information (e.g., name, address, contact information, etc.) from the user via the man-machine interface unit 40 (S300). Then, it transmits an account registration request including the personal information, etc. accepted from the user to the management device 3 via the wireless network interface unit 41 (S301).
[0096] Next, when the account registration request unit 46 receives an account registration completion notification from the management device 3 via the wireless network interface unit 41 (YES in S302), it stores the account information (user ID, password) included in this account registration completion notification in the account information storage unit 44 (S303).
[0097] FIG. 11(B) is a flow diagram for explaining the login request operation of the user terminal 4.
[0098] This flow starts when the login request unit 47 accepts a login operation from the user via the man-machine interface unit 40 after the account information has been registered.
[0099] First, the login request unit 47 reads the account information from the account information storage unit 44, and transmits a login request including this account information to the management device 3 via the wireless network interface unit 41 (S310).
[0100] Next, when the login request unit 47 receives a login permission notification from the management device 3 via the wireless network interface unit 41 (YES in S311), it sets the login status of its own user terminal 4 to the management device 3 to "logged in" (S312). On the other hand, when the login request unit 47 receives a login rejection notification from the management device 3 via the wireless network interface unit 41 (NO in S311), it performs a predetermined error process, such as displaying an error message on the man-machine interface unit 40 to the effect that login to the management device 3 has been rejected, and leaves the login status of its own user terminal 4 to the management device 3 as "logged out" (S313).
[0101] FIG. 12(A) is a flow diagram for explaining the operation of the user terminal 4 to request registration of face authentication information.
[0102] This flow starts when the face authentication information registration request unit 48 receives a face authentication information registration operation from the user via the man-machine interface unit 40 while the user terminal 4 is logged in to the management device 3.
[0103] First, the face authentication information registration request unit 48 outputs guidance from the man-machine interface unit 40 to cause the camera 43 to photograph the user's face, and causes the camera 43 to photograph the user's face (S320). Then, the face authentication information registration request unit 48 outputs guidance from the man-machine interface unit 40 to cause the camera 43 to photograph the user's driver's license, and causes the camera 43 to photograph the user's driver's license (S321). Note that the user's face and driver's license may be photographed in the reverse order of the preceding photographing order, or may be photographed simultaneously.
[0104] Next, the face authentication information registration request unit 48 transmits a face authentication information registration request including photographed data of the user's face and driver's license to the management device 3 via the wireless network interface unit 41 (S322). Then, the unit 48 receives a face authentication information registration completion notification from the management device 3 (YES in S323), and ends this flow.
[0105] FIG. 13 is a flow diagram for explaining the reservation request operation of the user terminal 4.
[0106] This flow starts when the reservation request unit 49 receives a viewing operation from the user via the man-machine interface unit 40 while the user terminal 4 is logged in to the management device 3 after the facial authentication information is registered.
[0107] First, the reservation request unit 49 receives the desired vehicle 5 usage dates and times (usage start date and time and usage end date and time) from the user via the man-machine interface unit 40 (S330). Then, a viewing request including the usage dates and times received from the user is transmitted to the management device 3 via the wireless network interface unit 41 (S331).
[0108] Next, when the reservation request unit 49 receives the list data of available vehicle models from the management device 3 via the wireless network interface unit 41 (YES in S332), it displays this list data of available vehicle models on the man-machine interface unit 40 and accepts a reservation operation from the user, including selection of the vehicle model to be reserved (S333).Then, it transmits a reservation request including the selected vehicle model and the date and time of use to the management device 3 via the wireless network interface unit 41 (S334).
[0109] Next, when the reservation request unit 49 receives the encryption information and signature from the management device 3 via the wireless network interface unit 41 along with guidance information including the vehicle number and storage location of the reserved vehicle 5 (YES in S335), it outputs the guidance information from the man-machine interface unit 40 and stores the encryption information and signature in the encryption information memory unit 45 (S336).
[0110] FIG. 12(B) is a flow diagram for explaining the operation of the user terminal 4 to request removal of usage restrictions.
[0111] This flow starts when the usage restriction removal request unit 50 receives a usage restriction removal operation from the user via the man-machine interface unit 40.
[0112] First, the usage restriction removal request unit 50 determines whether the short-range wireless communication unit 42 is capable of communicating with the nearest usage control device 1 via short-range wireless communication 63 (S340).
[0113] If communication with the nearest usage control device 1 via short-range wireless communication 63 is possible (YES in S340), the usage restriction removal request unit 50 reads out the encryption information and signature stored in the encryption information storage unit 45, and transmits a usage restriction removal request including these from the short-range wireless communication unit 42 to the usage control device 1 via short-range wireless communication 63 (S341).
[0114] On the other hand, if communication with the nearest usage control device 1 via short-range wireless communication 63 is not possible (NO in S340), the usage restriction release request unit 50 performs a predetermined error processing, such as displaying a message on the man-machine interface unit 40 prompting the user to perform the usage restriction release operation near the reserved vehicle 5 (S342).
[0115] Next, the management device 3 will be described in detail.
[0116] FIG. 14 is a diagram showing a schematic functional configuration of the management device 3. As shown in FIG.
[0117] As shown in the figure, the management device 3 includes a WAN interface unit 29, a user information storage unit 30, a usage control device information storage unit 31, a reservation information storage unit 32, a user management unit 33, a usage control device management unit 34, a reservation management unit 35, an account registration request processing unit 36, a login processing unit 37, a face authentication information registration request processing unit 38, and a reservation processing unit 39.
[0118] The WAN interface unit 29 is an interface for connecting to the WAN 60 .
[0119] The user information storage unit 30 stores user information including the user's account information and face authentication information for each user.
[0120] FIG. 15 is a diagram showing an example of registered contents in the user information storage unit 30. As shown in FIG.
[0121] As shown in the figure, the user information storage unit 30 stores a user information record 300 for each user. The user information record 300 has a field 301 in which account information including the user's user ID and password is registered, a field 302 in which address information on the WAN 60 of the user terminal 4 is registered, a field 303 in which personal information such as the user's name, address, and contact information is registered, a field 304 in which the user's driver's license data is registered, a field 305 in which the user's facial authentication information is registered, and a field 306 in which the user's login status (logged in or logged out) is registered.
[0122] The usage control device information storage unit 31 stores, for each usage control device 1, usage control device information including the hall data set in the usage control device 1 and the vehicle number of the vehicle 5 in which the usage control device 1 is installed.
[0123] FIG. 16 is a diagram showing an example of registered contents in the usage control device information storage unit 31. As shown in FIG.
[0124] As shown in the figure, the usage control device information storage unit 31 stores a record 310 of usage control device information for each usage control device 1. The usage control device information record 310 has a field 311 in which an object ID, which is identification information of the usage control device 1, is registered, a field 312 in which hall data including a public key and a common key set in the usage control device 1 is registered, a field 313 in which a private key paired with the public key set in the usage control device 1 is registered, and a field 314 in which the vehicle number of the vehicle 5 in which the usage control device 1 is installed is registered.
[0125] The reservation information storage unit 32 stores reservation information for each vehicle 5, linked to vehicle information including the vehicle number, vehicle model, and storage location of the vehicle 5.
[0126] FIG. 17 is a diagram showing an example of registered contents in the reservation information storage unit 32. As shown in FIG.
[0127] As shown in the figure, the reservation information storage unit 32 stores, for each vehicle 5, a table 320 of reservation information for the vehicle 5 linked to vehicle information 321 including the vehicle number 322, vehicle model 323, and storage location 324 of the vehicle 5. The reservation information table 320 stores, for each date 326, a record 325 indicating the reservation status 327 for that day.
[0128] The user management unit 33 uses the user information storage unit 30 to associate a user with a user terminal 4 that the user possesses and manages the information.
[0129] The usage control device management unit 34 uses the usage control device information storage unit 31 to manage the usage control device 1 by linking it to the vehicle 5 in which the usage control device 1 is installed.
[0130] The reservation management unit 35 manages the reservation status of the vehicle 5 using the reservation information storage unit 32.
[0131] The account registration request processing unit 36 cooperates with the user management unit 33 to process the account registration request received from the user terminal 4 .
[0132] The login processing unit 37 cooperates with the user management unit 33 to process a login request received from the user terminal 4 .
[0133] The face authentication information registration request processing unit 38 cooperates with the user management unit 33 to process a face authentication information registration request received from the user terminal 4.
[0134] The reservation processing unit 39 cooperates with the reservation management unit 35 to process the viewing request and reservation request received from the user terminal 4 .
[0135] The schematic functional configuration of the management device 3 shown in Fig. 14 may be realized in hardware using an integrated logic IC such as an ASIC or FPGA, or in software using a computer such as a DSP. Alternatively, it may be realized as a process in a general-purpose computer equipped with a CPU, memory, an auxiliary storage device such as a flash memory or hard disk drive, and a communication device such as a network interface card (NIC), by the CPU loading a predetermined program from the auxiliary storage device into the memory and executing it. It may also be realized on a distributed system consisting of multiple general-purpose computers working together. For example, the user information storage unit 30, user management unit 33, account registration request processing unit 36, login processing unit 37, and face authentication information registration request processing unit 38 (functional configurations that handle the account registration operation shown in Figure 2, the login operation and face authentication information registration operation shown in Figure 3), and the usage control device information storage unit 31, reservation information storage unit 32, usage control device management unit 34, reservation management unit 35, and reservation processing unit 39 (functional configurations that handle the reservation operation shown in Figure 4 (excluding login operations S132 and S133)) may each be realized on separate computers.
[0136] FIG. 18A is a flow diagram for explaining the account registration request processing operation of the management device 3.
[0137] This flow starts when the account registration request processor 36 receives an account registration request from the user terminal 4 via the WAN interface unit 29 .
[0138] First, the account registration request processing unit 36 generates account information (user ID, password) (S400), and passes this account information and the personal information included in the account registration request, together with the address information of the user terminal 4 that is the sender of the account registration request, to the user management unit 33. In response to this, the user management unit 33 adds a new user information record 300 to the user information storage unit 30, and registers the account information, address information, and personal information received from the account registration request processing unit 36 in fields 301 to 303 of this record 300 (S401).
[0139] Then, the account registration request processing unit 36 transmits an account registration completion notification including the account information to the user terminal 4 that is the sender of the account registration request via the WAN interface unit 29 (S402).
[0140] FIG. 18B is a flowchart for explaining the login request processing operation of the management device 3.
[0141] This flow starts when the login processing unit 37 receives a login request from the user terminal 4 via the WAN interface unit 29 .
[0142] First, the login processing unit 37, in cooperation with the user management unit 33, performs login authentication using the account information included in the login request received from the user terminal 4 (S410). Specifically, the login processing unit 37 requests the user management unit 33 to search for a password including the user ID included in the account information. In response to this, the user management unit 33 uses the user ID received from the login processing unit 37 as a key to search the user information storage unit 30 for a record 300 including this user ID. If a corresponding record 300 is found, the login processing unit 37 notifies the login processing unit 37 of the password registered in this record 300. If a corresponding record 300 is not found, the login processing unit 37 notifies the login processing unit 37 that a corresponding record does not exist. In response to this, if the password received from the user management unit 33 matches the password included in the account information of the login request, the login processing unit 37 permits the login (authentication successful); if they do not match or if the user management unit 33 notifies the login processing unit 37 that a corresponding record does not exist, the login processing unit 37 rejects the login (authentication unsuccessful).
[0143] Next, if the login processing unit 37 permits the login (YES in S411), it updates the login status registered in field 306 of record 300 of the user information detected from the user information storage unit 30 using the user ID of the account information included in the login request as a key, and transmits a login permission notification to the user terminal 4 that sent the login request via the WAN interface unit 29 (S412).On the other hand, if the login is denied (NO in S411), it performs predetermined error processing, such as transmitting a message to that effect to the user terminal 4 that sent the login request via the WAN interface unit 29 (S413).
[0144] FIG. 19 is a flowchart for explaining the operation of the management device 3 to process a request for registration of face authentication information.
[0145] This flow begins when the facial authentication information registration request processing unit 38 receives a facial authentication information registration request via the WAN interface unit 29 from a user terminal 4 held by a logged-in user (a user terminal 4 whose user information storage unit 30 has its own address information stored in field 302 and has a user information record 300 registered in which the login status in field 306 is "logged in").
[0146] First, the face authentication information registration request processing unit 38 performs image processing on the photographed data of the user's face and the photographed data of the driver's license included in the face authentication information registration request, and extracts facial features from each photographed data (S420).
[0147] Next, the face authentication information registration request processor 38 performs face authentication processing using the facial feature amounts extracted from the photographed data of the user's face and the photographed data of the driver's license (S421). Specifically, it analyzes the degree of matching between the facial feature amounts extracted from the photographed data of the face and the facial feature amounts extracted from the photographed data of the driver's license, and determines that face authentication is successful if the degree of matching is equal to or greater than a predetermined value, and that face authentication is unsuccessful if it is less than the predetermined value.
[0148] If face authentication is successful (YES in S422), the face authentication information registration request processing unit 38 passes the facial feature amount extracted from the face photograph data or the driver's license photograph data to the user management unit 33, and the user management unit 33 registers this feature amount as face authentication information in field 305 of the user information record 300 of the currently logged-in user registered in the user information storage unit 30 (the user information record 300 in which the address information of the sender of the face authentication information registration request is registered in field 302) (S423). Then, the face authentication information registration request processing unit 38 transmits a face authentication information registration completion notification to the user terminal 4 that sent the face authentication information registration request via the WAN interface unit 29 (S424).
[0149] On the other hand, if facial authentication is not successful (NO in S422), the facial authentication information registration request processing unit 38 performs a predetermined error processing, such as sending a message to that effect to the user terminal 4 that sent the facial authentication information registration request via the WAN interface unit 29 (S425).
[0150] FIG. 20 is a flow diagram for explaining the reservation request processing operation of the management device 3.
[0151] This flow starts when the reservation processing unit 39 receives a viewing request via the WAN interface unit 29 from the user terminal 4 held by the currently logged-in user.
[0152] First, the reservation processing unit 39 notifies the reservation management unit 35 of the use dates and times (use start date and time and use end date and time) included in the viewing request and instructs it to search for available vehicle models. In response, the reservation management unit 35 references the reservation information storage unit 32 and searches for available vehicle models within the time period of the use date and time (the time period from the use start date and time to the use end date and time) (S430). Specifically, the reservation information storage unit 32 searches the table 320 of reservation information for vehicles 5 that have not been reserved within the time period of the use date and time. The vehicle model 323 included in the vehicle information 321 linked to the searched table 320 is then identified as an available vehicle model.
[0153] Next, the reservation management unit 35 notifies the reservation processing unit 39 of the list of available vehicle models. In response to this, the reservation processing unit 39 transmits the list data of available vehicle models to the user terminal 4 that sent the view request via the WAN interface unit 29 (S431).
[0154] Next, when the reservation processing unit 39 receives a reservation request from the user terminal 4 that sent the view request via the WAN interface unit 29 (YES in S432), it passes the vehicle model and use date and time specified in the reservation request to the reservation management unit 35 and instructs the reservation of a vehicle. From the reservation information tables 320 searched in S430, the reservation management unit 35 identifies one reservation information table 320 linked to vehicle information 321 including a vehicle model 323 that matches the passed vehicle model. Then, it adds a reservation for the time period of the passed use date and time (the time period from the use start date and time to the use end date and time) to the identified reservation information table 320, and updates the reservation information (S433). Note that if a reservation for the time period of the passed use date and time has already been registered after S430, it identifies one other reservation information table 320 linked to vehicle information 321 including a vehicle model 323 that matches the passed vehicle model from the reservation information tables 320 searched in S430, and updates the reservation information.
[0155] Then, the reservation processing unit 39 issues a usage permit that includes the usage date and time reserved by the reservation management unit 35 as a usage condition (S434). The reservation processing unit 39 also notifies the user management unit 33 of the address information of the user terminal 4 that sent the reservation request, and instructs it to acquire facial authentication information. In response to this, the user management unit 33 searches the user information storage unit 30 for a user information record 300 in which the address information notified from the reservation processing unit 39 is registered in field 302, and notifies the reservation processing unit 39 of the facial authentication information registered in field 305 of this record 300 (S435).
[0156] Next, the reservation processing unit 39 notifies the usage control device management unit 34 of the vehicle number 322 of the vehicle information 321 linked to the reservation information table 320 whose reservation information has been updated in S433, and instructs it to search for usage control device information of the usage control device 1 installed in the vehicle 5 to which this vehicle number 322 has been assigned. In response to this, the usage control device management unit 34 searches the usage control device information storage unit 31 for a record 310 of usage control device information in which the notified vehicle number is registered in the field 314, and passes the searched record 310 of usage control device information to the reservation processing unit 39.
[0157] Next, the reservation processing unit 39 adds, as necessary, to the issued usage permit the object ID and vehicle number registered in fields 311 and 314 of record 310 of the usage control device information received from the usage control device management unit 34, and generates cryptographic information by encrypting this usage permit and the face authentication information received from the user management unit 33 with the common key registered in field 312 of record 310 of this usage control device information. In addition, the reservation processing unit 39 generates a signature for this cryptographic information using the private key registered in field 313 of record 310 of this usage control device information (S436).
[0158] Then, the reservation processing unit 39 transmits the encryption information and the corresponding signature to the user terminal 4 that sent the reservation request via the WAN interface unit 29, along with guidance information including vehicle information 321 linked to the reservation information table 320 whose reservation information was updated in S433 (S437).
[0159] One embodiment of the present invention has been described above.
[0160] In this embodiment, the usage control device 1 acquires a usage permit and facial authentication information used to lift the usage restrictions on the vehicle 5 that is the target of use from the user terminal 4 using short-range wireless communication 63, and determines whether or not to lift the usage restrictions on the vehicle 5 using the acquired usage permit and facial authentication information without outputting the acquired usage permit and facial authentication information to an external device. In addition, the signatures of the usage permit and facial authentication information are verified using a public key, thereby proving their authenticity. This reduces security risks.
[0161] Furthermore, in this embodiment, the door locks of the vehicle 5 and the lock of the key box 10 (first usage restriction) are released only when the usage conditions included in the usage permit are satisfied, and if the conditions are not satisfied, the door locks of the vehicle 5 and the lock of the key box 10 are not released. Therefore, a usage permit that does not meet the usage conditions is invalid even if its validity is proven, so there is no need to have the user of the user terminal 4 return the usage permit. This improves convenience.
[0162] Furthermore, in this embodiment, when the door locks of the vehicle 5 and the lock of the key box 10 (first usage restriction) are released, and the user sits in the driver's seat of the vehicle 5 and turns on the ignition of the vehicle 5 using the vehicle key obtained from the key box 10, facial authentication is performed using photographic data including a facial image of the user captured by the camera 2 and facial authentication information. If facial authentication is successful, the engine start lock of the vehicle 5 (second usage restriction) is released. Therefore, even if the authenticity of the usage permit is proven and the usage conditions included in the usage permit are met, the engine of the vehicle 5 cannot be started unless the user in the driver's seat is a legitimate user of the user terminal 4 managed by the management device 3. Therefore, driving of the vehicle 5 can be limited to only legitimate users.
[0163] As such, according to this embodiment, the vehicle 5 usage management technology can improve convenience while reducing security risks, and furthermore, can limit the driving of the vehicle 5 to only legitimate users.
[0164] Furthermore, in this embodiment, by registering a driver's license in advance, it is possible to prevent a person without a registered driver's license from driving. This makes it possible to prevent a person other than the person who made the reservation (a person whose driver's license has been registered in advance), such as a person who is not insured or does not have a driver's license, from driving in a vehicle sharing service, thereby enabling risk control.
[0165] Furthermore, in this embodiment, the user terminal 4 transmits a facial authentication information registration request, including photographed data of the user's face captured by the camera 43 and photographed data of the driver's license, to the management device 3. The management device 3 then extracts facial features from the photographed data of the user's face and the photographed data of the driver's license included in the facial authentication information registration request received from the user terminal 4, and performs facial authentication. If facial authentication is successful, the management device 3 manages the facial features extracted from the photographed data of the user's face or the photographed data of the driver's license as the user's facial authentication information. Therefore, according to this embodiment, the user can register his or her own facial authentication information in the management device 3 using the user terminal 4, thereby improving convenience. In this embodiment, a driver's license is used for facial authentication when registering the user's facial authentication information. However, other documents than a driver's license, such as a photo ID (e.g., a photo document such as a passport issued by a government agency) that can be used as identification, may also be used.
[0166] Furthermore, in this embodiment, the management device 3 encrypts the usage permit and face authentication information for the usage control device 1 using a common key associated with this usage control device 1 to generate cryptographic information, generates a signature for the cryptographic information using a private key associated with this usage control device 1, and transmits the cryptographic information and the signature to the user terminal 4. The usage control device 1 then verifies the signature received from the user terminal 4 together with the cryptographic information using the public key set in the private usage control device 1, and if the signature verification is successful, decrypts the cryptographic information into the usage permit and face authentication information using the common key set in the private usage control device 1. Therefore, according to this embodiment, it is possible to further strengthen the security of the usage permit and face authentication information.
[0167] The present invention is not limited to the above-described embodiment, and various modifications are possible within the scope of the present invention.
[0168] For example, in the above embodiment, the management device 3 is provided with the reservation information storage unit 32, the reservation management unit 35, and the reservation processing unit 39, and is configured to process reservation requests for vehicles 5. However, the present invention is not limited to this. A reservation server having the reservation information storage unit 32, the reservation management unit 35, and the reservation processing unit 39 may be provided separately from the management device 3, and the reservation server may be configured to process reservation requests for vehicles 5. That is, the reservation server receives a view request from the user terminal 4 and transmits to the user terminal 4 a list of vehicle models available for the date and time of use specified in the view request. Then, upon receiving a reservation request from the user terminal 4, the reservation server identifies a vehicle 5 of the model specified in the reservation request that is available for the date and time of use specified in the reservation request, and notifies the management device 3 of the vehicle 5 and the date and time of use together with the address information of the user terminal 4 that made the reservation request. In response to this, the management device 3 issues a usage permit that includes the usage date and time notified by the reservation server as a usage condition, and uses a private key linked to the usage control device 1 installed in the vehicle 5 notified by the reservation server to generate a signature for the encryption information of this usage permit and the facial authentication information linked to the user of the user terminal 4 that made the reservation request, and transmits the encryption information and signature to the user terminal 4 that made the reservation request. In this case, the reservation information storage unit 32, reservation management unit 35, and reservation processing unit 39 can be omitted from the management device 3.
[0169] Furthermore, in the above embodiment, the management device 3 encrypts the usage permit and facial authentication information to be sent to the user terminal 4 using a common key secretly shared between the management device 3 and the usage control device 1, and the usage control device 1 decrypts the encrypted information received from the user terminal 4 into the usage permit and facial authentication information. However, the present invention is not limited to this. The usage permit and facial authentication information may be sent from the management device 3 to the usage control device 1 via the user terminal 4 in plain text without being encrypted.
[0170] Furthermore, in the above embodiment, the management device 3 generates a signature for the usage permit and face authentication information using a private key paired with a public key set in the usage control device 1. However, the present invention is not limited to this. The management device 3 may also generate a signature for the usage permit or a part of it using a private key paired with a public key set in the usage control device 1.
[0171] Furthermore, in the above embodiment, the key box 10 may be incorporated in the usage control device 1 in advance, or may be externally attached to the usage control device 1 later.
[0172] Furthermore, in the above embodiment, it is assumed that the ignition of the vehicle 5 is turned on using a vehicle key (by inserting the vehicle key into the key cylinder). However, the present invention is not limited to this. The vehicle 5 may be one in which the ignition can be turned on by operating the ignition button, provided that the vehicle key is inside or near the vehicle 5. In this case, since there is no need to take the vehicle key out of or into the key box 10, the usage control device 1 may keep the key box 10 locked even if the usage conditions included in the usage permit are satisfied. Furthermore, the vehicle 5 may be a so-called keyless type. In this case, the key box 10 can be omitted.
[0173] Furthermore, in the above embodiment, when the door lock (first usage restriction) of the vehicle 5 is unlocked and the user sits in the driver's seat of the vehicle 5 and turns on the ignition of the vehicle 5, the usage control device 1 performs face authentication using photographed data including a facial image of the user captured by the camera 2 and face authentication information obtained together with the usage permit by decrypting encrypted information received from the user terminal 4 together with the signature. Then, when face authentication is successful, the engine start lock (second usage restriction) of the vehicle 5 is unlocked. However, the present invention is not limited to this.
[0174] For example, other biometric authentication information such as fingerprint authentication information or vein authentication information may be used instead of facial authentication information. That is, a biometric authentication information reader is installed near the driver's seat of the vehicle 5 instead of the camera 2. Then, when the door lock (first usage restriction) of the vehicle 5 is unlocked and the user sits in the driver's seat of the vehicle 5 and turns on the ignition of the vehicle 5, the usage control device 1 performs biometric authentication using the user's biometric authentication information read by the biometric authentication information reader and the biometric authentication information obtained together with the usage permit by decrypting encrypted information received from the user terminal 4 together with the signature. Then, when the biometric authentication is successful, the engine start lock (second usage restriction) of the vehicle 5 is unlocked.
[0175] In this case, in S322 of the flow shown in Fig. 12(A), the user terminal 4 transmits to the management device 3 the biometric authentication information read by the biometric authentication information reader provided in the user terminal 4, together with the photographed data of the user's face acquired in S320 and the photographed data of the user's driver's license acquired in S321. Then, in S423 of the flow shown in Fig. 19, the management device 3 registers the biometric authentication information received from the user terminal 4 in place of facial authentication information in field 305 of the record 300 of the user information registered in the user information storage unit 300. Furthermore, in S435 to S437 of the flow shown in Fig. 20, the management device 3 searches the user information storage unit 300 for the record 300 of the user's usage information, encrypts the biometric authentication information registered in field 305 of this record 300 and the usage permit issued in S434, generates a signature for this encrypted information, and transmits the encrypted information and the signature to the user terminal 4.
[0176] Furthermore, in the above embodiment, when the management device 3 issues a usage permit (S434 in the flow shown in Figure 20), the usage permit may include the personal information of the user registered in field 303 of the user information record 300 of the user registered in the user information storage unit 300, and a list of personal information of people who are permitted to drive the vehicle 5 may be pre-registered in the usage control device 1, and if the personal information included in the usage permit is not pre-registered in the usage control device 1, the engine start lock (second usage restriction) of the vehicle 5 may not be released regardless of whether the above-mentioned facial authentication and biometric authentication are successful or not.
[0177] Furthermore, in the above embodiment, an alcohol detection sensor may be installed near the driver's seat of the vehicle 5, and if this alcohol detection sensor detects a predetermined amount of alcohol or more from a user seated in the driver's seat, the engine start lock (second usage restriction) of the vehicle 5 may not be released regardless of whether the above-mentioned facial authentication and biometric authentication are successful or not.
[0178] Furthermore, in the above embodiment, when the management device 3 issues a usage permit (S434 in the flow shown in Figure 20), the license data (e.g., license number) registered in field 304 of the user information record 300 of the user registered in the user information storage unit 300 is used as a search key to obtain the user's insurance information or accident history information from an insurance information database that manages the licensee's insurance information or an accident history information database that manages the licensee's accident history information, which are connected to the WAN 60, and include this in the usage permit.In addition, the insurance contract details or accident history details of the person who is permitted to drive the vehicle 5 are registered in advance in the usage control device 1, and if the insurance information or accident history information included in the usage permit does not satisfy the insurance contract details or accident history details registered in advance in the usage control device 1, the engine start lock (second usage restriction) of the vehicle 5 may not be released regardless of whether the above-mentioned facial authentication and biometric authentication are successful or not.
[0179] In addition, the above-mentioned facial recognition and biometric authentication may be omitted when determining whether the personal information included in the usage permit is included in the list of personal information registered in the usage control device 1, when determining whether an alcohol detection sensor has detected a predetermined amount of alcohol or more in the user sitting in the driver's seat, and when determining whether the insurance information or accident history information included in the usage permit satisfies the contract terms of the insurance or accident history previously registered in the usage control device 1.
[0180] In other words, the usage control device 1 may release the engine start lock (second usage restriction) of the vehicle 5 if the personal information included in the usage permit is included in the list of personal information registered in the usage control device 1, if the alcohol detection sensor does not detect a predetermined amount of alcohol in the user sitting in the driver's seat, and if the insurance information or accident history information included in the usage permit satisfies the contract details of the insurance or accident history details pre-registered in the usage control device 1.
[0181] In the above embodiment, the management device 3 is provided with the user information storage unit 30, the usage control device information storage unit 31, and the reservation information storage unit 32. However, the present invention is not limited to this. These storage units 30 to 32 may be held in a file server connected to the WAN 60. In this case, the user information storage unit 30, the usage control device information storage unit 31, and the reservation information storage unit 32 may each be held in a separate file server. Alternatively, each may be divided into multiple units and distributed and held on multiple file servers. Furthermore, the authenticity of the information stored in these storage units 30 to 32 may be guaranteed using blockchain technology or the like.
[0182] In the above embodiment, the usage control device 1 is described as being used to release usage restrictions (door locks, key box 10 locks, and engine start locks) on a vehicle 5 that has a door lock mechanism. However, the present invention is not limited to this. The usage control device 1 may be used to release usage restrictions on a vehicle (motorcycle, bicycle, etc.) that has a lock mechanism instead of a door lock mechanism, or may be used to release usage restrictions on a moving body other than a vehicle 5, such as a ship.
[0183] Alternatively, the usage control device 1 may be used to unlock usage restrictions (locks on entrances and exits, activation locks on equipment installed in the facility, etc.) for facilities such as hotels, inns, private lodging facilities, houses, warehouses, etc. That is, when the verification of the signature received from the user terminal 4 together with the usage permit and face authentication information is successful and the usage conditions included in the usage permit are satisfied, the usage control device 1 unlocks the locks on the entrances and exits of the facility, and further, when the locks on the entrances and exits of the facility are unlocked, performs face authentication using the face authentication information and imaging data including the face image of the user captured by the imaging device, and when face authentication is successful, unlocks the activation locks on the equipment installed in the facility, etc.
[0184] Alternatively, the usage control device 1 may be used to release usage restrictions (access lock, write lock) on a viewing terminal or the like of electronic media such as electronic medical records or electronic books as the target of use. That is, when the verification of the signature received from the user terminal 4 together with the usage license and face authentication information is successful and the usage conditions included in the usage license are satisfied, the usage control device 1 releases the access lock or the like to the file by the viewing terminal, and further, when the access lock or the like to the file by the viewing terminal is released, performs face authentication using the photographed data including the face image of the user photographed by the photographing device and the face authentication information, and if face authentication is successful, releases the write lock or the like to the file by the viewing terminal.
[0185] Furthermore, the present invention is not limited to these examples and can be widely used in all usage management technologies that require confirmation of the person who has reserved a usage object with the person who will actually use the reserved usage object, and can also be widely used in all usage management technologies that require matching of a personal certificate with a photograph (such as an ID card) with the person who will use the usage object.
[0186] In the above embodiment, the use date and time (use start date and time and use end date and time) is used as the use condition to be included in the use permit. However, the present invention is not limited to this. The use condition to be included in the use permit may be any condition that defines the condition for lifting the use restriction on the target of use. For example, the number of uses may be included instead of or in addition to the use date and time. In this case, the use control device 1 may manage the number of uses of the use permit for each use permit, thereby determining whether the use condition is satisfied. [Explanation of symbols]
[0187] 1: Usage control device 2: Camera 3: Management device 4: User terminal 5: Vehicle 10: Key box 11: Short-range wireless communication unit 12: In-vehicle network connection unit 13: Hall data storage unit 14: Usage restriction removal request receiving unit 15: Signature verification unit 16: Decryption unit 17: Shooting data acquisition unit 18: Feature extraction unit 19: Face recognition unit 20: Usage restriction removal unit 29: WAN interface unit 30: User information storage unit 31: Usage control device information storage unit 32: Reservation information storage unit 33: User management unit 34: Usage control device management unit 35: Reservation management unit 36: Account registration request processing unit 37: Login processing unit 38: Face authentication information registration request processing unit 39: Reservation processing unit 40: Man-machine interface section 41: Wireless network interface unit 42: Short-range wireless communication unit 43: Camera 44: Account information storage unit 45: Encryption information storage unit 46: Account registration request section 47: Login request section 48: Face authentication information registration request unit 49: Reservation request unit 50: Usage restriction release request unit 63: Near field communication
Claims
[Claim 1] A usage management system that manages the usage of a usage target, a usage control device that controls the use of the target of use by locking / unlocking, activation control, access control, or encryption / decryption based on a usage license including the usage conditions of the target of use; an image capturing device that captures a face of the target user and transmits the captured image data to the usage control device; a management device that manages the usage control device by associating it with the usage object; a user terminal that notifies the usage control device of the usage license, The management device a key management means for managing a private key paired with a public key set in the usage control device in association with the usage control device; A facial authentication information management means for managing facial authentication information of a user; a license transmitting means for generating a signature for the license by using the private key managed by the key managing means, and transmitting the license and the face authentication information together with the signature to the user terminal, The user terminal a usage restriction release request means for transmitting a usage restriction release request, including the usage permit, the face authentication information, and the signature received from the management device, to the usage control device by short-range wireless communication; The usage control device includes: a signature verification means for verifying the signature included in the usage restriction release request received from the user terminal via short-range wireless communication using the public key set in the device itself; a first release means for releasing a first usage restriction on the target of use if the usage condition of the license included in the usage restriction release request is satisfied when the signature verification by the signature verification means is successful; a face authentication means for performing face authentication using the photographed data received from the photographing device and the face authentication information included in the usage restriction release request when the first usage restriction on the target user is released by the first release means; and second release means for releasing the second usage restriction on the target user when face authentication by the face authentication means is successful. A usage management system characterized by:
Citation Information
Patent Citations
Hotel guest service system and method using RFID and hotel guest service program using RFID
JP2003132435A