Authentication system, authentication device, and authentication method
The authentication system addresses authentication delays by staging the process, performing initial authentication at a distance and subsequent authentication upon approach, enhancing efficiency and reducing wait times for multiple users.
Patent Information
- Application Number
- JP2024088553
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-31
- Publication Date
- 2025-12-11
AI Technical Summary
In scenarios where multiple users attempt to unlock an electric lock simultaneously, there is a risk of authentication delays due to the time-consuming nature of existing authentication processes, which can lead to congestion and inefficiencies.
An authentication system that performs authentication in two stages: a first authentication is conducted when the user is farther from the device, followed by a second authentication when closer, allowing for quicker processing and reduced overlap of authentication requests.
This approach reduces the likelihood of authentication delays and congestion by distributing the processing load, ensuring faster access for multiple users.
Smart Images

Figure 2025180884000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an authentication system, an authentication device, and an authentication method. [Background technology]
[0002] Patent Document 1 describes an electric lock device that performs authentication through communication with a lock device carried by a user and unlocks the lock if the authentication is successful. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2018-66130 Summary of the Invention [Problem to be solved by the invention]
[0004] There is a usage scenario in which multiple users use one electric lock. In this usage scenario, if multiple users want to unlock the same electric lock at the same time, there is a risk that authentication for unlocking the lock will be delayed. This issue is not only applicable to traffic control using electric locks, but also to traffic control using other means. [Means for solving the problem]
[0005] The present disclosure can be realized in the following forms.
[0006] (1) According to a first aspect of the present disclosure, there is provided an authentication system including a mobile terminal carried by a user and an authentication device that lifts a traffic restriction in accordance with an authentication result of the mobile terminal. The mobile terminal has a signal transmission unit that transmits an identification signal including identification information of the mobile terminal to the authentication device. The authentication device has a communication unit that communicates with the mobile terminal in a connected state where wireless communication is established or in an unconnected state where the wireless communication is not established, an authentication unit that performs a first authentication to determine whether the mobile terminal is a pre-registered mobile terminal based on the identification signal received from the mobile terminal and a second authentication to determine whether the first authentication has been successful for the mobile terminal, and a lifting unit that lifts the traffic restriction if the second authentication is successful. The authentication unit establishes wireless communication and performs the first authentication in the connected state with the mobile terminal in a first area, and then releases the connected state with the mobile terminal, and performs the second authentication in the unconnected state with the mobile terminal in a second area closer to the authentication device than the first area. According to this embodiment, the authentication unit performs authentication in two stages, first authentication and second authentication. The first authentication is performed in a connected state, and the second authentication is performed in a disconnected state when the mobile terminal approaches the authentication device. That is, the first authentication is performed when the mobile terminal is located farther from the authentication device than the location of the mobile terminal when the second authentication is performed. The first authentication in the connected state takes longer to process than the second authentication performed in a disconnected state. This first authentication is performed when the mobile terminal is located farther from the authentication device. By performing authentication in two stages, first authentication and second authentication, it is possible to reduce the possibility that multiple authentication processes corresponding to multiple mobile terminals will overlap at the same time. Furthermore, by performing the first authentication, which takes a long time to process, when the mobile terminal is located far from the authentication device, it is possible to reduce the possibility that the authentication process will be delayed when the user carrying the mobile terminal approaches the authentication device. In addition, the authentication device can quickly connect to a mobile terminal other than the currently connected mobile terminal by canceling the connected state after performing the first authentication. Therefore, when multiple users want to unlock the access restriction at the same time, the possibility that users carrying mobile terminals will have to wait for authentication processing can be further reduced. (2) In the above embodiment, the authentication unit may establish wireless communication with a first mobile terminal among the plurality of mobile terminals in the first area and perform the first authentication, then terminate the connection with the first mobile terminal, and then establish wireless communication with a second mobile terminal and perform the first authentication. According to this embodiment, the authentication unit may terminate the connection after performing the first authentication, and then perform the first authentication with the second mobile terminal. (3) In the above aspect, after the connection state with the first portable terminal is terminated, the authentication unit may establish the wireless communication with the second portable terminal among the plurality of portable terminals, with which the first authentication has not been successful, and perform the first authentication. According to this aspect, after the connection state with the first portable terminal is terminated, the authentication unit can perform the first authentication with the second portable terminal with which the first authentication has not been successful. (4) In the above embodiment, the authentication device may further include a storage unit that stores result information including identification information of the mobile terminal on which the first authentication was successful for a predetermined retention time, and the authentication unit may perform the second authentication by comparing the received identification information of the mobile terminal with the stored result information. According to this embodiment, the authentication unit can perform the second authentication using the result information of the first authentication. (5) In the above embodiment, the authentication device may determine that the mobile terminal is located in the first area if the reception strength of the received identification signal is equal to or less than a predetermined reference value, and may determine that the mobile terminal is located in the second area if the reception strength is greater than the reference value. According to this embodiment, the authentication device can efficiently determine whether the mobile terminal is located in the first area or the second area by using the reception strength of the identification signal used for authentication. (6) In the above aspect, the authentication device may further include an input unit that accepts a passage request from the user, and the authentication unit may cancel the passage restriction on the condition that the input unit accepts the passage request and the second authentication is successful. According to this aspect, the authentication unit can cancel the passage restriction on the condition that the passage request is accepted and the second authentication is successful. (7) In the above aspect, if the second authentication with the portable terminal in the second area fails, the authentication unit may establish the wireless communication with the portable terminal and perform the first authentication in the connected state, and if the first authentication is successful, the authentication unit may cancel the connected state and cancel the passage restriction by the cancellation unit without performing the second authentication. According to this aspect, it is possible to perform the first authentication with a portable terminal in the second area that has not been successful in the first authentication, and to cancel the passage restriction if the first authentication is successful. (8) According to a second aspect of the present disclosure, there is provided an authentication device including: a communication unit that communicates with a mobile terminal in a connected state where wireless communication is established or in an unconnected state where the wireless communication is not established; an authentication unit that performs a first authentication to determine whether the mobile terminal is a pre-registered mobile terminal based on identification information included in an identification signal received from the mobile terminal and a second authentication to determine whether the first authentication has been successful for the mobile terminal; and a release unit that releases a passage restriction if the second authentication is successful, wherein the authentication unit establishes wireless communication with the mobile terminal in a first area and performs the first authentication in the connected state, and then releases the connected state with the mobile terminal, and performs the second authentication with a mobile terminal in a second area closer to the authentication device than the first area and in the unconnected state without establishing wireless communication. (9) According to a third aspect of the present disclosure, there is provided an authentication method using an authentication device that communicates with a mobile terminal, the authentication method including: a first authentication step of performing a first authentication to determine whether the mobile terminal in a first area is a pre-registered mobile terminal by using an identification signal including identification information of the mobile terminal transmitted from the mobile terminal in a connected state in which wireless communication is established between the authentication device and the mobile terminal; a release step of canceling the connected state after the first authentication; a second authentication step of performing a second authentication to determine whether the mobile terminal is a mobile terminal for which the first authentication has been successful by using the identification signal of the mobile terminal transmitted from the mobile terminal in a disconnected state in which wireless communication is not established between the authentication device and the mobile terminal in a second area closer to the authentication device than the first area; and an unlocking step of unlocking access restriction after the second authentication is successful in the second authentication step. The present disclosure can be realized in various forms other than the above-described forms, for example, in the form of a mobile terminal. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a schematic diagram showing a schematic configuration of an authentication system. [Figure 2] FIG. 1 is a block diagram of an authentication system. [Figure 3] FIG. 10 is a sequence diagram of authentication. [Figure 4] FIG. 10 is a diagram illustrating result information. [Figure 5] 10 is a flowchart of an authentication process performed by the authentication device. DETAILED DESCRIPTION OF THE INVENTION
[0008] A. First embodiment: A1. Overall configuration of the authentication system: FIG. 1 is a schematic diagram showing the overall configuration of an authentication system 1. As shown in FIG. 1, the authentication system 1 is a system for limiting people who can enter a security area SA to people who have been previously authorized to enter. The authentication system 1 includes a mobile terminal 30 and an authentication device 10. In this embodiment, the authentication device 10 is located near a door GE located at the entrance of the security area SA. The authentication device 10 is located within reach of a person at the entrance. Specifically, the distance between the authentication device 10 and an electric lock EL is, for example, several tens of centimeters or less. In this disclosure, a "person authorized to enter the security area SA" is referred to as a "user US." The mobile terminal 30 is carried by the user US. In this embodiment, the door GE is locked and unlocked by an electric lock EL. In this disclosure, the electric lock EL refers to a lock whose locking and unlocking are electrically controlled, regardless of whether it is battery-powered. In other words, in this embodiment, the door GE and the electric lock EL restrict the passage of a user US carrying the mobile terminal 30. The authentication device 10 lifts the traffic restriction in accordance with the authentication result of the mobile terminal 30.
[0009] In FIG. 1, the security area SA is depicted as a room, with a door GE at the entrance to the security area SA, but this is not a limitation. For example, the security area SA may be located within a building or a train station, and the structure for restricting passage placed at the ticket gates in the station or at the entrance to the building may be an electrically controlled automatic door or a flapper gate. Note that the structure for restricting passage is not limited to physically restricting the entry of the user US using a door GE or the like. The following description will mainly focus on entry into the security area SA, but the present disclosure can also be applied to the case of exiting from the security area SA.
[0010] Fig. 2 is a block diagram of the authentication system 1. As shown in Fig. 2, the authentication device 10 includes a control unit 11, a storage unit 12, an operation unit interface 13, an input unit 14, and a communication unit 15. The control unit 11, the storage unit 12, the operation unit interface 13, and the communication unit 15 are communicatively connected via a bus 17. The control unit 11 is realized by a processor such as a CPU. The storage unit 12 is realized by a memory such as a RAM or a ROM.
[0011] The control unit 11 includes a release unit 20 and an authentication unit 23. The release unit 20, the authentication unit 23, and the authentication unit 23 are functional units realized by executing a program stored in the storage unit 12. The authentication unit 23 acquires registration information 26, which associates identification information 51 with authentication information 52 corresponding to the identification information 51, as described below. The authentication unit 23 performs authentication, which is a process of confirming whether a person attempting to enter the security area SA is a user US. The authentication unit 23 performs first and second authentication based on the received identification signal. The first authentication is a determination based on the received identification information 51 and the authentication information 52 in the registration information 26 whether the mobile terminal 30 that is the sender of the received identification signal is a pre-registered mobile terminal 30. The second authentication is a determination based on the received identification information 51 and the authentication information 52 in the registration information 26 whether the mobile terminal 30 that sent the identification signal is a mobile terminal 30 for which the first authentication has been successful. A pre-registered mobile terminal 30 refers to a mobile terminal 30 that matches the authentication information 52 included in the registration information 26. The release unit 20 and authentication unit 23 will be described in detail later.
[0012] The storage unit 12 stores a program executed by the control unit 11. In this embodiment, the storage unit 12 pre-stores registration information 26. The acquisition unit 22 reads and acquires the registration information 26 stored in the storage unit 12 to perform the first authentication. The registration information 26 is information in which identification information 51 and authentication information 52 are pre-associated. The identification information 51 is information uniquely assigned to the mobile terminal 30. Details of the identification information 51 will be described later. The authentication information 52 is information corresponding to the identification information 51. The identification information 51 is information uniquely assigned to the user US. For example, the authentication information 52 may be a number such as an employee number or a personal number assigned by an administrative agency, or information combining a name and date of birth. The registration information 26 is created, for example, by an administrator of the authentication system 1. The storage unit 12 stores result information 53 stored in the first authentication, which will be described later.
[0013] The input unit 14 is communicatively connected to the operation unit interface 13. The operation unit interface 13 mediates communication between the control unit 11 and the input unit 14. As shown in FIG. 1, the input unit 14 is disposed near the electric lock EL. Specifically, the distance between the input unit 14 and the electric lock EL is, for example, several tens of centimeters or less. The input unit 14 has a sensor group 28 and an operation button 29. The sensor group 28 includes an infrared sensor and a capacitance sensor. The infrared sensor accepts a "hand-over operation" by the user US. When a person's hand is brought close to the sensor group 28, the infrared sensor detects heat emitted from the hand. The capacitance sensor accepts a "touch operation" by the user US. When a person's hand touches the sensor group 28, the capacitance sensor detects a change in capacitance. The operation button 29 accepts a "button operation" by the user US. When the sensor group 28 detects the above operation or when the operation button 29 accepts a button operation, the input unit 14 transmits a detection signal to the control unit 11. This allows the control unit 11 to determine that a predetermined operation has been performed on the input unit 14.
[0014] The communication unit 15 shown in FIG. 2 is realized by a wireless communication module. The communication unit 15 performs wireless communication between the mobile terminal 30 and the electric lock EL. The communication unit 15 communicates in a connected state where wireless communication is established or in an unconnected state where wireless communication is not established. In this embodiment, wireless communication is performed in accordance with the BLE (Bluetooth (registered trademark) Low Energy) standard. In the following description, "BLE communication" may be simply referred to as "communication." Note that, in addition to BLE communication, communication in accordance with the BR / EDR (Bluetooth (registered trademark) Basic Rate / Enhanced Data Rate) standard or wireless LAN (Local area network) communication can also be used as wireless communication between the mobile terminal 30 and the electric lock EL. Furthermore, the communication standard for wireless communication between the communication unit 15 and the mobile terminal 30 may be the same as or different from the communication standard for wireless communication between the communication unit 15 and the electric lock EL.
[0015] The electric lock EL includes a communication module that communicates wirelessly with the communication unit 15, and locks or unlocks the door in response to a command sent from the authentication device .
[0016] The mobile terminal 30 includes a control unit 31, a storage unit 32, a display operation unit 33, and a communication unit 34. The control unit 31, the storage unit 32, the display operation unit 33, and the communication unit 34 are communicatively connected via a bus 35. The control unit 31 is realized by a processor such as a CPU. The storage unit 32 is realized by a memory such as a RAM or a ROM, for example.
[0017] The control unit 31 has a signal transmission unit 40. The signal transmission unit 40 is a functional unit that is realized by executing a program stored in the storage unit 32. The signal transmission unit 40 transmits an identification signal including identification information 51 of its own terminal to the authentication device 10.
[0018] The storage unit 32 stores a program executed by the control unit 31. The storage unit 32 stores an authentication application 42 and identification information 51.
[0019] The display operation unit 33 is realized by a touch panel. The display operation unit 33 displays images and accepts operations such as touch operations by the user US.
[0020] The communication unit 34 is realized by a wireless communication module. The communication unit 34 performs wireless communication with the communication unit 34 of the authentication device 10. As described above, in this embodiment, the communication unit 34 performs BLE communication with the authentication device 10. As described above, in addition to BLE communication, communication between the authentication device 10 and the mobile terminal 30 can also be communication conforming to the BR / EDR standard, wireless LAN communication, or the like.
[0021] A2. Certification Overview: The authentication device 10 communicates with the mobile terminal 30 to perform authentication to confirm that the person carrying the mobile terminal 30 is authorized to enter the security area SA. One possible authentication method is to store authentication information 52 previously assigned to the user US in the storage unit 32 of the mobile terminal 30 and then transmit the authentication information 52 from the mobile terminal 30 to the authentication device 10. In this case, to prevent leakage of the authentication information 52, the communication method used to transmit the authentication information 52 must be a highly secure communication method. However, highly secure communication methods generally require a long communication time. For example, if a communication method using BLE communication in a connected state is used to transmit the authentication information 52, the entire communication process takes, for example, about two seconds. Therefore, if multiple users US enter a single door GE at the same time, there is a risk of waiting for authentication.
[0022] Therefore, in the authentication sequence of this embodiment, authentication is performed in stages, including a first authentication and a second authentication, which has lower security than the first authentication. Typically, the first authentication, which requires more processing time than the second authentication, is performed when the user US is located farther from the authentication device 10, while the second authentication is performed when the user US is located closer to the authentication device 10. In FIG. 1, a first area AR1 indicates the area where the first authentication is performed. A second area AR2 indicates the area where the second authentication is performed. The first area AR1 and the second area AR2 are collectively referred to as the authentication area. By dividing the authentication into the first authentication and the second authentication, the possibility of multiple authentications overlapping at the same time can be reduced. Furthermore, by performing the first authentication, which requires more processing time, when the mobile terminal 30 is located far from the authentication device 10, the possibility of the authentication process being delayed when the user US approaches the authentication device 10 can be reduced.
[0023] Additionally, in this embodiment, the authentication device 10 terminates the connection state of communication after performing the first authentication. Specifically, the authentication device 10 performs the first authentication in a connection state of BLE communication, and terminates the connection state of BLE communication after the first authentication. This allows for early connection with a mobile terminal 30 different from the mobile terminal 30 connected for the first authentication. This further reduces the possibility that the user US will have to wait for authentication at the door GE.
[0024] The determination of whether the user US is near or far from the authentication device 10 can typically be made using RSSI (Received Signal Strength Indicator) as the reception strength when the authentication device 10 receives a signal transmitted from the mobile terminal 30. Note that the determination of whether the user US is near or far from the authentication device 10 may be made using a method other than reception strength. For example, the authentication device 10 transmits a beacon signal to the mobile terminal 30 and stores the time T1 at which the beacon signal was transmitted; when the mobile terminal 30 receives the beacon signal, it transmits an identification signal containing the time T2 at which the beacon signal was received and the time T3 at which the identification signal was transmitted; when the authentication device 10 receives the identification signal, it stores the times T2 and T3 contained in the identification signal and also stores the time T4 at which the identification signal was received; by subtracting T1 from T4, it calculates the transmission and reception time from when the beacon signal is transmitted by the authentication device 10 to when the authentication device 10 receives the identification signal, and uses the distance calculated using the ToF (Time of Flight) method by dividing half of the transmission and reception time by the speed of radio waves (speed of light) to determine whether the user US is near or far from the authentication device 10.
[0025] In this embodiment, the start of the first authentication is determined using RSSI. The second authentication is started when an unlocking start condition is satisfied. The unlocking start condition includes a reception strength condition that uses RSSI, similar to the first authentication, and a passage request condition that uses the acceptance and acquisition of a passage request.
[0026] A user operation, which is one of the passage request conditions, refers to an operation that the user US performs on the input unit 14 to make a predetermined passage request. Specifically, the user operation is, for example, any one of a "touch operation" of touching the input unit 14, a "hand-over operation" of holding a hand over the input unit 14, and a "button operation" of pressing the operation button 29 on the input unit 14, and there may be multiple input units 14. A user operation is an operation that is performed only when the user US is within reach of the authentication device 10. Therefore, when a user operation is performed, it can be determined that the user US is located near the authentication device 10.
[0027] The user operation may be a "terminal-over-hand operation" in which the user US holds the mobile terminal 30 over the input unit 14. In this case, the distance between the mobile terminal 30 and the input unit 14 is closer than when the user US approaches the authentication device 10 with the mobile terminal 30 in a bag, for example, and the determination of whether the "terminal-over-hand operation" has been performed can be made using RSSI. In this embodiment, the "terminal-over-hand operation" is determined based on a reception strength condition using RSSI. However, since RSSI is used to determine whether the user US has held the mobile terminal 30 over the input unit 14, that is, whether an operation has been performed by the user US, it is treated as a passage request condition.
[0028] In addition, instead of user operation, the user US's request to pass may be determined to have been accepted without any special operation by, for example, acquiring detection information that a human presence sensor (not shown) provided on the door GE or the authentication device 10 has detected that the user US has stopped in front of the door GE.
[0029] The unlocking start condition may be, for example, based only on the RSSI, and for example, the RSSI is used to determine whether the mobile terminal 30 is placed in a bag and approaches the authentication device 10. In this case, the threshold value for determining whether the mobile terminal 30 is approaching the authentication device 10 is set to be smaller than the RSSI threshold value for determining whether the "terminal-over-hand operation" has occurred.
[0030] In the following description of the authentication sequence, for simplicity, a case in which the second authentication is initiated by a "terminal-over-hand operation" will be described as an example. Specifically, the first authentication is initiated when the RSSI of the signal transmitted from the mobile terminal 30 is greater than a predetermined first reference value Ith1 and equal to or less than a predetermined second reference value Ith2. In the following description, the range greater than the first reference value Ith1 and equal to or less than the second reference value Ith2 is also referred to as a "reference range." The second authentication is initiated when the RSSI of the signal transmitted from the mobile terminal 30 is greater than the second reference value Ith2. In this embodiment, the first reference value Ith1 and the second reference value Ith2 are set so that the first authentication is initiated when the distance between the mobile terminal 30 and the authentication device 10 is approximately shorter than 3 m and longer than 0.2 m, and the second authentication is initiated when the distance between the mobile terminal 30 and the authentication device 10 is approximately 0.2 m or shorter. The first reference value Ith1 and the second reference value Ith2 can be appropriately set through experiments, etc. In this embodiment, the first reference value Ith1 is −80 dBm, and the second reference value Ith2 is −35 dBm.
[0031] For ease of explanation, the following description of the authentication sequence will be given assuming that pairing between the mobile terminal 30 and the authentication device 10 has been performed in advance, and that the keys for data encryption and decryption exchanged during pairing are stored in the mobile terminal 30 and the authentication device 10, respectively. Pairing is performed, for example, when an authentication application 42 for enabling authentication by the authentication device 10 is installed in the mobile terminal 30. As described above, the registration information 26 stored in the authentication device 10 is information that associates identification information 51 with authentication information 52. As described above, the identification information 51 is information uniquely assigned to the mobile terminal 30. Examples of the identification information 51 that can be used include a personal identifier, a wireless communication address, and an identifier created by adding the model name of the mobile terminal 30 to the serial number. Here, the personal identifier is an identifier assigned by the authentication device 10 when installing and configuring the authentication application 42 on the mobile terminal 30.
[0032] The identification information 51 is not limited to one piece of data, but may include multiple pieces of data. A piece of data refers to a collection of information indicating one content, such as the personal identifier described above. The same applies to the authentication information 52.
[0033] A3. Authentication Sequence: FIG. 3 is a sequence diagram of authentication. An outline of the sequence up to when the user US enters the security area SA will be described using FIG. 3. Details of the processing will be described later using a flowchart. As described above, in this embodiment, authentication in the authentication system 1 is performed by BLE communication between the authentication device 10 and the mobile terminal 30. The authentication device 10 repeatedly transmits a beacon signal. When the signal transmitting unit 40 of the mobile terminal 30 receives the beacon signal, it transmits an advertising signal as an identification signal, which is a response signal. The advertising signal includes identification information 51 of the mobile terminal itself.
[0034] The user US enters the first area AR1 shown in Fig. 1. The authentication device 10 transmits a beacon signal in step S10 shown in Fig. 3. Upon receiving the beacon signal transmitted by the authentication device 10, the mobile terminal 30 transmits an advertising signal in step S12. In step S14, the authentication device 10 confirms that the RSSI of the received advertising signal is within a reference range.
[0035] As described above, the authentication device 10 repeatedly transmits a beacon signal. Then, when the mobile terminal 30 receives a beacon signal, it transmits an advertising signal. The first authentication is initiated when the RSSI of the advertising signal received by the authentication device 10 is within a reference range. The second authentication is initiated when the RSSI of the advertising signal received by the authentication device 10 is greater than a second reference value Ith2. Therefore, for ease of understanding, FIG. 3 shows only the beacon signal and advertising signal that are the triggers.
[0036] In step S16, the authentication device 10 and the mobile terminal 30 establish wireless communication and transition to a connected state in which one-to-one communication is performed. For example, if the RSSI of the received advertising signal is within a reference range, the authentication device 10 transmits a connection request to the mobile terminal 30 that transmitted the advertising signal, and establishes wireless communication between the authentication device 10 and the mobile terminal 30 that accepts the connection request, transitioning to a connected state. In the present disclosure, the "connected state" refers to a state in which one-to-one communication is performed with a specific party. In communication in the connected state, signal confidentiality can be improved compared to when a signal is transmitted to a large number of parties by broadcast, such as an advertising signal.
[0037] Specifically, in this sequence, the authentication device 10 and the mobile terminal 30 use keys for encryption and decryption to transition to a connection state in which encrypted data can be exchanged.
[0038] In the connected state, the authentication device 10 uses the identification information 51 transmitted from the mobile terminal 30 to perform a first authentication to confirm that the received identification information 51 is consistent with the authentication information 52. If the first authentication is successful in step S20, the authentication device 10 stores result information 53 in step S22.
[0039] FIG. 4 is a diagram illustrating result information 53. Result information 53 is information in which identification information 51 and authentication information 52 are associated with each other. When the first authentication is successful, authentication device 10 stores result information 53 in which successful identification information 51 is associated with authentication information 52. In this way, when identification information 51 is included in result information 53, authentication device 10 can confirm that this identification information 51 has successfully passed the first authentication. Alternatively, identification information 51 may not be associated with authentication information 52, and identification information 51 may be treated as result information 53.
[0040] In step S24 of Fig. 3, the authentication device 10 releases the connection with the mobile terminal 30. The user US approaches the door GE further and enters the second area AR2 shown in Fig. 1. In step S26 of Fig. 3, the authentication device 10 transmits a beacon signal. Upon receiving the beacon signal transmitted by the authentication device 10, the mobile terminal 30 transmits an advertising signal in step S28.
[0041] In step S32, the authentication device 10 confirms that the RSSI of the received advertising signal is greater than the second reference value Ith2 and satisfies the unlocking start condition. After performing step S32, the authentication device 10 compares the identification information 51 included in the received advertising signal with the result information 53, and performs second authentication to confirm that the sender of the advertising signal has succeeded in the first authentication. Specifically, in the second authentication, the authentication device 10 confirms that the identification information 51 included in the received advertising signal is included in the result information 53. Note that the advertising signal is a signal transmitted in an unconnected state where the authentication device 10 and the mobile terminal 30 are not connected. The second authentication is then performed without transitioning to a connected state.
[0042] If the second authentication is successful in step S36, the authentication device 10 lifts the restriction on the passage of the user US carrying the mobile terminal 30 for which the second authentication was successful in step S38. For example, the authentication unit 23 commands the electric lock EL to unlock. This unlocks the electric lock EL, allowing the user US to enter the security area SA.
[0043] In the authentication sequence, steps S10 to S24 are also referred to as "pre-authentication." Steps S26 to S38 are also referred to as "passing authentication." Typically, "pre-authentication" is performed when the user US is in the first area AR1, and "passing authentication" is performed when the user US is in the second area AR2.
[0044] A4.Authentication Flowchart: 5 is a flowchart of the authentication process performed by the authentication device 10. The authentication method is realized by performing the authentication process. The same processing steps as those shown in FIG. 3 are given the same reference numerals, and detailed explanations will be omitted as appropriate. The authentication device 10 repeatedly performs the authentication process while the authentication function of the authentication system 1 is enabled.
[0045] In step S13, when the communication unit 15 receives an advertising signal as an identification signal transmitted from the signal transmission unit 40 of the mobile terminal 30, the authentication unit 23 performs a first determination to determine whether the detection value Im, which is the RSSI of the received advertising signal, is within a reference range. In detail, after confirming that the received advertising signal is from a legitimate sender, the authentication unit 23 determines whether the detection value Im is greater than a first reference value Ith1 and equal to or less than a second reference value Ith2. Here, a legitimate sender refers to a sender whose information included in the advertising signal is consistent with the identification information 51 or authentication information 52 stored in the registration information 26. Note that if the authentication unit 23 determines in step S13 that the RSSI is within the reference range, this corresponds to step S14 in FIG. 3.
[0046] In step S13 of FIG. 5, if the authentication unit 23 determines that the detection value Im is within the reference range, the user US is located within the first area AR1. Therefore, in step S16, connection authentication is performed, and the authentication unit 23 transitions to a connected state. Note that the first reference value does not need to be set. For example, if the RSSI of the received advertising signal is equal to or less than the second reference value Ith2, the authentication unit 23 may determine that the user US is located within the first area AR1. In step S17, the authentication unit 23 performs first authentication to confirm that the received identification information 51 is consistent with the authentication information 52. The first authentication is not limited to a process of confirming that the received identification information 51 matches the identification information 51 stored as the registration information 26. For example, the first authentication may be a process of confirming that information obtained by decrypting the received encrypted identification information 51 using a key exchanged during pairing matches the identification information 51 or authentication information 52 stored as the registration information 26. Because pairing is performed by identifying the user US, this confirmation process can also confirm the consistency between the received identification information 51 and the registration information 26. Since the first authentication is performed in a connected state, signals can be exchanged with high confidentiality of the signals being communicated.
[0047] As described above, the mobile terminal 30 transmits an advertising signal regardless of whether the first authentication has already been performed. Therefore, in detail, when the authentication unit 23 determines that the detection value Im is within the reference range, the authentication unit 23 performs the processing steps from step S16 onwards for the mobile terminal 30 for which the first authentication has not yet been performed. In other words, the first authentication process is omitted for the mobile terminal 30 for which the first authentication has already been performed.
[0048] In step S19, authentication unit 23 determines whether or not the first authentication has been successful. If it is determined in step S19 that the first authentication has been successful, in step S22, authentication unit 23 stores result information 53. Note that the case where the first authentication has been successful in step S19 corresponds to step S20 in FIG. 3.
[0049] 5, the authentication unit 23 immediately disconnects communication with the mobile terminal 30 that has successfully passed the first authentication. For example, the authentication unit 23 transmits a packet to the mobile terminal 30 to disconnect communication, thereby releasing the connection state. This allows the authentication device 10 to quickly connect to a mobile terminal 30 different from the mobile terminal 30 that performed the first authentication. Note that the order in which steps S22 and S24 are performed is not limited to the order in FIG. 5; step S22 may be performed after step S24, or step S22 and step S24 may be performed simultaneously.
[0050] In some cases, both the authentication device 10 and the mobile terminal 30 are configured to terminate the connection state if a predetermined timeout period has elapsed without receiving a signal from the other party since the most recent signal was transmitted in the connection state. Step S24 may be configured to be performed within a predetermined period that is shorter than the timeout period. Furthermore, after completing the first authentication with the mobile terminal 30 that performed the first authentication, the authentication unit 23 terminates the connection state in step S24 without subsequently performing the second authentication. Therefore, step S24 can also be defined as being performed before the second authentication.
[0051] After performing step S24, the authentication unit 23 ends this processing routine. If it is determined in step S19 that the first authentication has not been successful, the authentication unit 23 ends this processing routine. Note that if the authentication unit 23 determines that the first authentication has not been successful, it may transmit information indicating that the authentication has failed to the mobile terminal 30. Then, when the mobile terminal 30 receives the information indicating that the authentication has failed, it notifies the user US, for example, by displaying a message on the display operation unit 33. This allows the user US to know that the authentication has failed.
[0052] If it is determined in step S13 that the detection value Im is not within the reference range, then in step S31 the authentication unit 23 performs a second determination to determine whether the detection value Im is greater than a second reference value Ith2. If in step S31 the authentication unit 23 determines that the detection value Im is greater than the second reference value Ith2, then the user US is in the second area AR2, and therefore in step S33 the authentication unit 23 performs a second authentication to confirm that the mobile terminal 30 that is the sender of the advertising signal has succeeded in the first authentication. Note that if the authentication unit 23 determines that the detection value Im is greater than the second reference value Ith2, this corresponds to step S32 in FIG. 3.
[0053] The content of the identification information 51 included in the identification signal transmitted in the first area AR1 and the content of the identification information 51 included in the identification signal transmitted in the second area AR2 may be the same or different. Specifically, when the identification information 51 includes multiple pieces of data, at least some of the multiple pieces of data in the identification information 51 included in the identification signal transmitted in the first area AR1 may be different from those in the identification information 51 included in the identification signal transmitted in the second area AR2. Furthermore, each of the identification information 51 included in the identification signal transmitted in the first area AR1 and the identification information 51 included in the identification signal transmitted in the second area AR2 may include only one piece of data.
[0054] In step S35 of FIG. 5, the authentication unit 23 determines whether the mobile terminal 30, which is the sender of the advertising signal, has successfully completed the second authentication. If the authentication unit 23 determines in step S35 that the second authentication has been successful, in step S38, the authentication unit 23 deletes the identification information 51 indicating the successful second authentication from the result information 53, and the release unit 20 commands the electric lock EL to unlock as a process to release the passage restriction, thereby terminating this processing routine. Note that in step S38, the authentication unit 23 may update the result information 53 by associating the date and time of the successful second authentication with the authentication information 52 in the result information 53. This allows the entry time of the user US associated with the authentication information 52 to be stored as history. In step S38, the security of the authentication system 1 can be enhanced by deleting the identification information 51 associated with the authentication information 52. More specifically, the identification signal used for the second authentication is transmitted in an unconnected state and therefore may be intercepted. Therefore, by deleting unnecessary identification information 51 from result information 53, it is possible to prevent the electric lock EL from being unlocked even when a signal containing fraudulently obtained identification information 51 is transmitted. Note that the case where it is determined in step S35 that the second authentication is successful corresponds to step S36 in Fig. 3. Also, it is not necessary to create history information in step S38.
[0055] The timing for deleting unnecessary identification information 51 from the result information 53 is not limited to after the second authentication is successful. It may be deleted when a predetermined retention time has elapsed since the result information 53 was stored, or when the number of identification information 51 stored as the result information 53 exceeds a predetermined upper limit. When the number of identification information 51 stored as the result information 53 exceeds the upper limit, the oldest identification information 51 may be deleted. The retention time is, for example, approximately 10 seconds. Deleting unnecessary identification information 51 from the result information 53 can enhance the security of the authentication system 1. This prevents unauthorized persons from illegally using unnecessary identification information 51 to enter the security area SA. A case in which the retention time has elapsed without second authentication being performed since the result information 53 was stored may occur when the user US simply passes through the first area AR1 without intending to enter the security area SA.
[0056] In step S31 of FIG. 5, if the authentication unit 23 determines that the detection value Im is not greater than the second reference value Ith2, the detection value Im is less than or equal to the first reference value Ith1 and the user US is outside the authentication area, so the authentication unit 23 terminates this processing routine.
[0057] If it is determined in step S35 that the second authentication has not been successful, then in step S41 the authentication unit 23 transitions to a connected state, as in step S16. A case in which it is determined that the second authentication has not been successful may be when there are many users US in the first area AR1, and a user US enters the second area AR2 before the first authentication is completed due to a waiting period for the first authentication. Therefore, in this case, the first authentication is performed in the second area AR2.
[0058] In step S43, the authentication unit 23 performs the first authentication, similarly to step S17. In step S45, the authentication unit 23 determines whether the first authentication was successful. If it is determined in step S45 that the first authentication was not successful, the authentication unit 23 terminates this processing routine. If it is determined that the first authentication was not successful, the authentication unit 23 may transmit information indicating that the authentication was unsuccessful to the mobile terminal 30. If the authentication unit 23 determines in step S45 that the first authentication was successful, in step S47, the identification information 51 indicating that the second authentication was successful is deleted from the result information 53, and the release unit 20 commands the electric lock EL to unlock without performing the second authentication. In step S49, the authentication unit 23 releases the connection state and terminates this processing routine. The order in which steps S47 and S49 are performed is not limited to the order shown in FIG. 5; step S47 may be performed after step S49, or steps S47 and S49 may be performed simultaneously.
[0059] A5. Other embodiments of the processing steps: In the above, the first authentication is exemplified as a case where pairing is performed in advance in BLE communication, but this is not limited to this. Pairing may also be performed after the first authentication is initiated. Furthermore, the communication format used for the first authentication is not limited to a communication format in which data is encrypted. For example, the first authentication may be performed without encrypting data by using a one-time password. Methods for generating a one-time password include a method of generating a one-time password using a time that has been synchronized in advance between the authentication device 10 and the mobile terminal 30, and a method of generating a new one-time password using a one-time password used in the installation settings of the authentication application 42.
[0060] The above describes a case where the RSSI of the advertising signal is used as a trigger for starting the second authentication. The following describes a case where a user operation condition is used as a trigger for starting the second authentication. In this case, when an operation signal indicating a user operation is transmitted from the input unit 14, the authentication unit 23 performs step S31 of FIG. 5 after receiving the operation signal. That is, even in this case, the authentication unit 23 performs the second authentication when it determines that the RSSI of the advertising signal is greater than the second reference value Ith2. This eliminates the need for the second determination, which is performed when the reception strength is equal to or less than the second reference value, thereby reducing the processing load. Furthermore, when there are multiple users US in the second area AR2, it is possible that the user US who performed the user operation does not match the user US carrying the mobile terminal 30 that is the target of the second authentication. Therefore, by performing step S31, it is possible to increase the match between the user US who performed the user operation and the user US who is the target of the second authentication.
[0061] While FIG. 3 illustrates a sequence for one user US, the flowchart of FIG. 5 can also be applied to a situation where multiple users US are located in the first area AR1 or the second area AR2. Specifically, when the communication unit 15 receives multiple advertising signals corresponding to multiple mobile terminals 30, the authentication unit 23 uses the largest RSSI as the determination target in step S13. That is, the authentication unit 23 performs the first authentication in descending order of RSSI. For example, when multiple mobile terminals 30 are present in the first area AR1, the authentication unit 23 establishes wireless communication with the mobile terminal 30 with the largest RSSI among the multiple advertising signals received and performs the first authentication in a connected state, terminates the connection with the mobile terminal 30 for which the first authentication was successful, and then establishes wireless communication with the mobile terminal 30 with the largest RSSI among the multiple advertising signals received, excluding the mobile terminal 30 for which the first authentication was successful, and performs the first authentication. Note that the mobile terminals 30 for which wireless communication is established after the connection state is terminated may also include mobile terminals 30 for which the first authentication failed. In this case, the authentication device 10 may include mobile terminals 30 whose authentication failure count has not reached a predetermined upper limit (e.g., two times) as targets for establishing wireless communication, and may store information about mobile terminals 30 for which the first authentication failed the maximum number of times for a predetermined period of time and exclude them from targets for establishing wireless communication. This allows the first authentication to be performed on multiple mobile terminals 30 present in the first area AR1 before multiple users US approach the door GE, thereby reducing the possibility of the users US waiting to unlock. Similarly, the authentication unit 23 performs the second authentication in descending order of RSSI. This increases the likelihood that the user US who performed the user operation will match the user US who is the target of the second authentication. It also reduces the possibility of the users US waiting to unlock. Note that the authentication unit 23 may perform the first and second authentications in the order in which they received advertising signals, rather than in descending order of RSSI. For example, after the connection with the mobile terminal 30 that performed the first authentication is released, wireless communication may be established with the mobile terminal 30 that first received an advertising signal among multiple mobile terminals 30 present in the first area AR1, and the first authentication may be performed.In this case, if there are mobile terminals 30 in the first area AR1 and the second area AR2, and advertising signals are received from each mobile terminal 30 at the same time, or if a request for passage is accepted, authentication processing of the mobile terminal 30 present in the second area AR2 is performed with priority.
[0062] In BLE communication, it is possible to communicate with multiple parties simultaneously in a connected state, but in this embodiment, it is preferable that the connection state for the first authentication be a one-to-one connection state. Specifically, after completing the first authentication with the first mobile terminal 30 and releasing the connection state with the first mobile terminal 30, the first authentication with the second mobile terminal 30 is performed. This makes it possible to perform multiple first authentications corresponding to multiple mobile terminals 30 in a short time. The inventors have confirmed that sequentially performing first authentications in a one-to-one connection state has a faster processing speed than performing multiple first authentications in parallel in a one-to-many connection.
[0063] As another embodiment in which a user operation condition is used as a trigger for starting the second authentication, the second authentication may be performed without performing step S31 when an operation signal indicating that a user operation has been performed is transmitted from the input unit 14. That is, instead of step S31 for determining the RSSI, a processing step for determining whether or not a user operation has been performed may be performed. The user US closest to the electric lock EL is likely to have performed the user operation. Therefore, the second authentication may be started when a user operation has been performed.
[0064] Step S17 is also referred to as a first authentication step, step S22 is also referred to as a storage step, step S24 is also referred to as a release step, step S33 is also referred to as a second authentication step, and step S38 is also referred to as an unlocking step.
[0065] According to the first embodiment described above, the authentication system 1 includes an authentication device 10 and a mobile terminal 30. The authentication device 10 includes a release unit 20, a communication unit 15, and an authentication unit 23. In step S17, the authentication unit 23 performs a first authentication while connected to the mobile terminal 30 in the first area AR1. If the first authentication is successful, the authentication unit 23 stores result information 53 including the identification information 51 and releases the connection. In step S33, the authentication unit 23 performs a second authentication while disconnected from the mobile terminal 30 in the second area AR2. If the second authentication is successful, the release unit 20 commands the electric lock EL to unlock. By releasing the connection state after performing the first authentication, the authentication unit 23 can quickly connect to a mobile terminal 30 different from the currently connected mobile terminal 30. This reduces the likelihood that the user US carrying the mobile terminal 30 will have to wait for authentication processing.
[0066] The authentication device 10 also has an input unit 14. The authentication unit 23 accepts a passage request transmitted from the input unit 14 and, on the condition that the second authentication is successful, lifts the passage restriction. This allows the authentication unit 23 to accept a passage request and, on the condition that the second authentication is successful, lift the passage restriction.
[0067] Furthermore, the authentication unit 23 performs the first authentication in step S43 with any mobile terminal 30 that failed the second authentication as a result of performing the second authentication in step S33. After the authentication unit 23 succeeds in the first authentication, the release unit 20 commands the electric lock EL to release it in step S47, and after the release unit 20 commands the release, the authentication unit 23 releases the connection state in step S49. This allows the first authentication to be performed on any mobile terminal 30 in the second area AR2 that did not succeed in the first authentication, and the electric lock EL to be unlocked if the first authentication is successful.
[0068] B. Second embodiment: In the first embodiment, if the second authentication fails for a portable terminal 30 in the second area AR2, i.e., if the first authentication has not been performed, an unlocking command is issued after the first authentication has been performed. This second area AR2 is set to be a range very close to the electric lock EL, specifically, a range approximately 20 cm away from the electric lock EL. In this embodiment, a third area is set to be closer to the electric lock EL than the first area AR1 and farther from the electric lock EL than the second area AR2. In this embodiment, this third area is set to be a range approximately 50 cm away from the electric lock EL. In this embodiment, if there is a portable terminal 30 in the third area that has not undergone the first authentication, the first authentication is performed, and unlocking is performed when the portable terminal 30 enters the second area AR2 while maintaining the connection.
[0069] Specifically, the detection value Im is used to determine whether the user US is in the first area AR1. If the user US is determined to be in the first area AR1, the processing procedure is the same as that from step S16 onward in the first embodiment. On the other hand, if the user US is determined to be in the third area AR1, not the first area AR1, the first authentication is performed. If the first authentication is successful, the connected state is maintained. If the user US is determined to have entered the second area AR2, the second authentication is omitted, an unlock command is issued, and the connected state is then terminated. In this embodiment, the third reference value of the RSSI used to determine whether the user US is in the third area is −45 dBm. In this way, if the user US is likely to enter the second area AR2 soon, the connected state is terminated after unlocking, thereby shortening the time required for the process to terminate the connected state. This embodiment is particularly effective when the processing power of the authentication device 10 is not high.
[0070] If the first authentication is successful and the connected state is maintained, it is repeatedly checked whether the detection value Im has become equal to or less than the first reference value Ith1 in the connected state. If the detection value Im has become equal to or less than the first reference value Ith1, that is, if the mobile terminal 30 has left the authentication area, the connected state is released.
[0071] According to the second embodiment described above, the authentication unit 23 performs the second authentication with a mobile terminal 30 in the third area, performs the first authentication with a mobile terminal 30 that fails the second authentication, and after confirming that the mobile terminal 30 that succeeded in the first authentication is located in the second area AR2, the release unit 20 commands the electric lock EL to release it. After the release unit 20 commands the release, the authentication unit 23 releases the connection state. As a result, if there is a high probability that the user US carrying the mobile terminal 30 will quickly enter the second area AR2 where unlocking is to be performed, the electric lock EL can be unlocked early without waiting for the process of releasing the connection state and the authentication process of the second authentication. This reduces the time the user US has to wait for unlocking.
[0072] C. Other Embodiments: (C1) In the first embodiment, the registration information 26 is stored in the storage unit 12 of the authentication device 10. In another embodiment, the registration information 26 may be stored in a server connected to the authentication device 10 so that the server can communicate with the authentication device 10. That is, the acquisition unit 22 may acquire the registration information 26 stored in the server by communicating with the server. The authentication unit 23 may then request authentication from the server using the identification information 51 and perform authentication using the authentication result provided. This authentication may be performed after the first authentication or after the second authentication. This embodiment is useful when multiple entrances are provided in the security area SA and multiple authentication devices 10 use the same registration information 26.
[0073] (C2) In the first embodiment, the result information 53 is stored in the storage unit 12 of the authentication device 10. In another embodiment, the result information 53 may be stored in a server communicatively connected to the authentication device 10. That is, the communication unit 15 may transmit the authentication result of the first authentication to the server, and the server may store the result information 53 based on the received authentication result. When performing the second authentication, the authentication unit 23 requests authentication from the server using the identification information 51 and performs authentication using the authentication result received from the server. That is, when receiving an authentication result from the server indicating that the second authentication was successful, the authentication unit 23 determines that the mobile terminal 30 that performed the second authentication is a mobile terminal 30 for which the first authentication has already been successful. This embodiment is useful when a security area SA has multiple entrances and multiple authentication devices 10 use the same result information 53.
[0074] (C3) In the first embodiment described above, when performing first authentication with multiple mobile terminals 30, the authentication device 10 performs the first authentication with the mobile terminals 30 in a one-to-one connection state. As another embodiment, the authentication device 10 may perform the first authentication with the mobile terminals 30 in a one-to-many connection state. In this case, the number of mobile terminals 30 connected simultaneously should be less than the upper limit of the number of mobile terminals that can be connected simultaneously. Even when the connection state is not one-to-one, the total time for first authentication with multiple mobile terminals 30 can be shortened by connecting to fewer mobile terminals 30 than the upper limit of the number of mobile terminals that can be connected simultaneously. Note that when multiple mobile terminals 30 are connected simultaneously, it is preferable to terminate the connection state with the mobile terminal 30 that has completed the first authentication, in order, and then connect to a new mobile terminal 30 after the connection states with all mobile terminals 30 have been terminated.
[0075] (C4) In the first embodiment, when the connected state is released, the authentication unit 23 of the authentication device 10 transmits a packet for disconnecting communication. In another embodiment, when the authentication device 10 transmits a packet to the mobile terminal 30 notifying that the first authentication has ended, the connected state may be released by the mobile terminal 30 transmitting a packet for disconnecting communication.
[0076] (C5) In the first embodiment, the authentication device 10 has the sensor group 28 and the operation button 29. In another embodiment, the authentication device 10 may not have at least one of the sensor group 28 and the operation button 29. The sensor group 28 and the operation button 29 may be provided depending on the unlocking start condition to be adopted. For example, if only "holding a device over the device" is adopted as the unlocking start condition, the authentication device 10 may not have either the sensor group 28 or the operation button 29.
[0077] (C6) In the first embodiment, the authentication device 10 determines whether the mobile terminal 30 is in the first area AR1 using RSSI. In another embodiment, the authentication device 10 may make the determination using location information of the mobile terminal 30. Also, in the first embodiment, the authentication device 10 performs the second authentication using BLE communication. In another embodiment, the second authentication may be performed using RFID (radio frequency identification).
[0078] The controller and methods described herein may be implemented by a special-purpose computer configured with a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the controller and methods described herein may be implemented by a special-purpose computer configured with a processor configured with one or more dedicated hardware logic circuits. Alternatively, the controller and methods described herein may be implemented by one or more special-purpose computers configured with a processor and memory programmed to perform one or more functions in combination with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory storage medium.
[0079] The present disclosure is not limited to the above-described embodiments and modifications, and can be realized in various configurations without departing from the spirit thereof. For example, the technical features in the embodiments and modifications corresponding to the technical features in each aspect described in the Summary of the Invention section can be appropriately replaced or combined to solve some or all of the above-described problems or achieve some or all of the above-described effects. Furthermore, if a technical feature is not described as essential in this specification, it can be appropriately deleted. [Explanation of symbols]
[0080] 1...authentication system, 10...authentication device, 11...control unit, 12...storage unit, 13...operation unit interface, 14...input unit, 15...communication unit, 17...bus, 20...release unit, 22...acquisition unit, 23...authentication unit, 26...registration information, 28...sensor group, 29...operation button, 30...mobile terminal, 31...control unit, 32...storage unit, 33...display operation unit, 34...communication unit, 35...bus, 40...signal transmission unit, 42...authentication application, 51...identification information, 52...authentication information, 53...result information, AR1...first area, AR2...second area, EL...electric lock
Claims
1. An authentication system including a mobile terminal carried by a user and an authentication device that releases a traffic restriction in accordance with an authentication result of the mobile terminal, the mobile terminal has a signal transmitting unit that transmits an identification signal including identification information of the mobile terminal to the authentication device; The authentication device a communication unit that communicates with the mobile terminal in a connected state where wireless communication is established or in an unconnected state where wireless communication is not established; an authentication unit that performs a first authentication to determine whether the portable terminal is a pre-registered portable terminal based on the identification signal received from the portable terminal, and a second authentication to determine whether the first authentication has been successful for the portable terminal; a lifting unit that lifts the traffic restriction when the second authentication is successful, The authentication unit With the portable terminal in the first area, the wireless communication is established, and the first authentication is performed in the connected state, and then the connected state with the portable terminal is terminated; An authentication system in which the second authentication is performed in the disconnected state without establishing wireless communication with the mobile terminal in a second area that is closer to the authentication device than the first area.
2. 2. The authentication system according to claim 1, An authentication system in which the authentication unit establishes wireless communication with a first mobile terminal among the multiple mobile terminals in the first area and performs the first authentication, then terminates the connection state with the first mobile terminal, and then establishes wireless communication with a second mobile terminal and performs the first authentication.
3. 3. The authentication system according to claim 2, An authentication system in which, after the authentication unit releases the connection state with the first mobile terminal, it establishes wireless communication with a second mobile terminal among the plurality of mobile terminals for which the first authentication has not yet been successful, and performs the first authentication.
4. The authentication system according to any one of claims 1 to 3, the authentication device further includes a storage unit configured to store result information including identification information of the portable terminal for which the first authentication has succeeded for a predetermined period of time; The authentication unit performs the second authentication by comparing the received identification information of the mobile terminal with the stored result information.
5. The authentication system according to any one of claims 1 to 3, The authentication device determines that the mobile terminal is located in the first area if the reception strength of the received identification signal is below a predetermined reference value, and determines that the mobile terminal is located in the second area if the reception strength is greater than the reference value.
6. The authentication system according to any one of claims 1 to 3, The authentication device an input unit for receiving a passage request from the user; The authentication unit releases the passage restriction on condition that the input unit accepts the passage request and the second authentication is successful.
7. The authentication system according to any one of claims 1 to 3, An authentication system in which, if the second authentication with the mobile terminal in the second area fails, the authentication unit establishes wireless communication with the mobile terminal and performs the first authentication in the connected state, and if the first authentication is successful, the connection state is released and the release unit releases the passage restriction without performing the second authentication.
8. An authentication device, a communication unit that communicates with the mobile terminal in a connected state where wireless communication is established or in a non-connected state where the wireless communication is not established; an authentication unit that performs a first authentication to determine whether the portable terminal is a pre-registered portable terminal based on identification information included in an identification signal received from the portable terminal, and a second authentication to determine whether the first authentication has been successful for the portable terminal; a lifting unit that lifts the traffic restriction when the second authentication is successful, The authentication unit With the portable terminal in the first area, the wireless communication is established, and the first authentication is performed in the connected state, and then the connected state with the portable terminal is terminated; The authentication device performs the second authentication in the disconnected state without establishing the wireless communication with the mobile terminal in a second area that is closer to the authentication device than the first area.
9. An authentication method using an authentication device that communicates with a mobile terminal, a first authentication step of performing a first authentication to determine whether the portable terminal in the first area is a pre-registered portable terminal by using an identification signal including identification information of the portable terminal transmitted from the portable terminal in a connected state in which wireless communication is established between the authentication device and the portable terminal in the first area; a release step of releasing the connection state after the first authentication; a second authentication step of performing a second authentication by using the identification signal of the mobile terminal transmitted from the mobile terminal in a second area closer to the authentication device than the first area in an unconnected state where the wireless communication is not established between the mobile terminal and the authentication device, to determine whether the mobile terminal is a mobile terminal for which the first authentication has been successful; an unlocking step of unlocking the access restriction after the second authentication is successful in the second authentication step; authentication methods, including
Citation Information
Patent Citations
Electric lock device and electric lock system
JP2018066130A