Authentication system, authentication device, and authentication method

The authentication system addresses the issue of user mismatch by employing a two-stage authentication process, ensuring the user carrying the mobile terminal matches the user unlocking the lock, thereby reducing waiting times and enhancing security.

JP2025181111APending Publication Date: 2025-12-11DENSO WAVE INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024088895
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-31
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing authentication systems fail to ensure that the user who is successfully authenticated matches the user issuing the command to unlock the electric lock, especially in scenarios where multiple users share a single lock.

Method used

An authentication system that performs a two-stage authentication process, using a mobile terminal and an authentication device, where the first authentication is conducted at a distance and requires less processing time, and the second authentication is conducted closer to the lock, ensuring the user carrying the mobile terminal matches the user who initiated the command.

Benefits of technology

This approach reduces the likelihood of mismatch between the authenticated user and the user unlocking the lock, minimizing waiting times and enhancing security by confirming user identity through proximity-based authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025181111000001_ABST
    Figure 2025181111000001_ABST
Patent Text Reader

Abstract

To reduce the possibility that a user who has succeeded in first authentication is different from a user who has instructed second authentication in two-step authentication.SOLUTION: An authentication system includes a mobile terminal and an authentication device. An authentication unit provided in the authentication device is configured to perform first authentication to determine whether the mobile terminal is a pre-registered mobile terminal based on identification information received from the mobile terminal when it is determined that a distance between the mobile terminal and the authentication device is shorter than a first reference distance, create result information including identification information of the mobile terminal that has succeeded in the first authentication when the first authentication is successful, and perform second authentication to determine whether the mobile terminal is a mobile terminal for which the first authentication has succeeded by comparing the identification information received from the mobile terminal with the result information when, in a second determination, it is determined that the distance is shorter than a second reference distance.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an authentication system, an authentication device, and an authentication method. [Background technology]

[0002] Patent document 1 discloses a technology in which authentication is performed using radio waves transmitted from an electric key carried by the user, and if the user performs an operation to instruct the electric lock attached to the door to be unlocked within a certain period of time after successful authentication, the electric lock is unlocked. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-194201 Summary of the Invention [Problem to be solved by the invention]

[0004] There are usage scenarios in which multiple users use a single electric lock. When the above technology is applied to such usage scenarios, the user who is successfully authenticated may be different from the user who issues the command to unlock the electric lock. This issue is common to devices that are controlled according to commands issued when authentication is successful. [Means for solving the problem]

[0005] The present disclosure can be realized in the following forms.

[0006] (1) According to a first aspect of the present disclosure, there is provided an authentication system including a mobile terminal and an authentication terminal. The mobile terminal has a signal transmitting unit that transmits an identification signal including identification information of the mobile terminal to the authentication device, and the authentication device has a communication unit that receives the identification signal, a judgment unit that makes a first judgment to determine whether the distance between the mobile terminal and the authentication device is shorter than a predetermined first reference distance based on a value representing the distance between the mobile terminal and the authentication device, and a second judgment to determine whether the distance is shorter than a second reference distance that is set shorter than the first reference distance, and an authentication unit, wherein if the judgment unit determines in the first judgment that the distance is shorter than the first reference distance, the authentication unit performs a first authentication to determine whether the mobile terminal is a pre-registered mobile terminal based on the identification information received from the mobile terminal, and if the first authentication is successful, creates result information including the identification information of the mobile terminal that succeeded in the first authentication, and if the judgment unit determines in the second judgment that the distance is shorter than the second reference distance, performs a second authentication by comparing the identification information received from the mobile terminal with the result information to determine whether the mobile terminal is a mobile terminal that has successfully undergone the first authentication. According to this embodiment, the second authentication is performed using the identification signal used for the second judgment, thereby reducing the possibility that the user carrying the mobile terminal that triggers the second authentication is different from the user carrying the mobile terminal that sent the identification signal that succeeded in the first authentication. (2) In the above embodiment, the value representing the distance may be the reception strength of the identification signal received in an unconnected state where wireless communication with the mobile terminal is not established, and the authentication unit may perform the first authentication using the identification signal received in a connected state where wireless communication with the mobile terminal is established. According to this embodiment, the first authentication can be performed using communication in a connected state where the confidentiality of communicated data is higher than in an unconnected state. Furthermore, the determination unit can perform the first determination and the second determination using the reception strength, which is a value representing the distance. As a method for making the first determination and the second determination based on the received power strength, there is a method for making the first determination of whether the received power strength is greater than a predetermined first reference value, and a method for making the second determination of whether the received power strength is greater than a second reference value that is greater than the first reference value. In this case, the mobile terminal that is the target of the second authentication is specified by the identification information included in the identification signal whose received power strength is determined to be greater than the second reference value. In addition to reception strength, a value representing distance is also known as ToF (Time of Flight). A specific method using the ToF (Time of Flight) method involves, for example, the authentication device transmitting a beacon signal to the portable terminal and storing the time T1 at which the beacon signal was transmitted; upon receiving the beacon signal, the portable terminal transmitting an identification signal including the time T2 at which the beacon signal was received and the time T3 at which the identification signal was transmitted; upon receiving the identification signal, the authentication device storing the times T2 and T3 contained in the identification signal and storing the time T4 at which the identification signal was received; and subtracting the value obtained by subtracting T2 from T3 from the value obtained by subtracting T1 from T4 to calculate the transmission and reception time from when the beacon signal was transmitted by the authentication device to when the identification signal was received by the authentication device; and dividing half of the transmission and reception time by the speed of radio waves (the speed of light) to calculate the distance. In this case, the portable terminal that is the target of the second authentication is identified by the identification information included in the identification signal used to calculate the estimated distance that is determined to be shorter than the second reference distance. According to this aspect, the same effect as above can be obtained. (3) In the above embodiment, the authentication unit may establish wireless communication with a first mobile terminal and perform the first authentication, then terminate the connection with the first mobile terminal, and then establish wireless communication with a second mobile terminal and perform the first authentication. (4) In the above embodiment, the authentication device may have a lock command unit that issues a command to an electric lock, and after the authentication unit has succeeded in the second authentication, the lock command unit may issue a command to the electric lock to unlock. This embodiment provides an authentication system that unlocks an electric lock when the second authentication has succeeded. (5) In the above embodiment, if the second authentication with the mobile terminal fails, the authentication unit may perform the first authentication with the mobile terminal, and if the first authentication is successful, the lock command unit may command the electric lock to unlock without performing the second authentication. According to this embodiment, the first authentication for unlocking can be performed even for a user who approaches the electric lock before the first authentication is completed, and the electric lock can be unlocked without performing the second authentication. (6) In the above embodiment, if the second authentication is successful, the authentication unit may delete the identification information for which the second authentication was successful from the result information. The identification signal in the second authentication may be intercepted. Therefore, according to this embodiment, unnecessary identification information is deleted early from the result information, thereby preventing successful authentication due to transmission of a signal including fraudulently obtained identification information. (7) In the above aspect, the authentication unit may delete the identification information from the result information after a predetermined retention time has elapsed since the result information was created. According to this aspect, unnecessary identification information is deleted from the result information early, so that successful authentication due to transmission of a signal including fraudulently obtained identification information can be prevented. (8) In the above embodiment, when the second authentication with the mobile terminal is successful, the authentication unit may create history information in which the identification information of the mobile terminal is associated with the date and time when the second authentication was successful. According to this embodiment, history information can be created for a user who has succeeded in the second authentication. (9) In the above embodiment, the authentication device may further include an input unit that receives an authentication request from a user carrying the mobile terminal, and the authentication unit may perform the second authentication based on the identification signal received when the authentication request is received. According to this embodiment, the second determination is performed when the user is near an electric lock, and therefore the second determination that is performed when the reception strength is equal to or less than a second reference value can be omitted, thereby reducing the processing load. (10) According to a second aspect of the present disclosure, there is provided an authentication device including: a communication unit that receives an identification signal transmitted from a portable terminal and including identification information of the portable terminal; a determination unit that performs a first determination based on a value representing a distance between the portable terminal and the authentication device to determine whether the distance is shorter than a predetermined first reference distance and a second determination to determine whether the distance is shorter than a second reference distance that is set shorter than the first reference distance; and an authentication unit, wherein, if the determination unit determines in the first determination that the distance is shorter than the first reference distance, the authentication unit performs a first authentication to determine whether the portable terminal is a pre-registered portable terminal based on the identification information received from the portable terminal, and, if the first authentication is successful, creates result information including the identification information of the portable terminal that has been successfully authenticated; and, if the determination unit determines in the second determination that the distance is shorter than the second reference distance, performs a second authentication to determine whether the portable terminal has been successfully authenticated in the first authentication by comparing the identification information received from the portable terminal with the result information. (11) According to a third aspect of the present disclosure, there is provided an authentication method using an authentication device that communicates with a mobile terminal. The authentication device has a communication unit that receives an identification signal transmitted from the mobile terminal, the identification signal including identification information of the mobile terminal. The authentication method includes: a first authentication step of performing a first authentication based on a value representing a distance between the mobile terminal and the authentication device, and determining, when the distance is determined to be shorter than a predetermined first reference distance, whether the mobile terminal is a pre-registered mobile terminal based on the identification information received from the mobile terminal; a creation step of creating result information including the identification information of the mobile terminal that has succeeded in the first authentication; and a second authentication step of performing a second authentication based on the result information, when the distance is determined to be shorter than a second reference distance that is set shorter than the first reference distance, to determine whether the mobile terminal has been successfully authenticated in the first authentication. The present disclosure can be realized in various forms other than the above-described forms, for example, in the form of a mobile terminal. [Brief explanation of the drawings]

[0007] [Figure 1] FIG. 1 is a schematic diagram showing a schematic configuration of an authentication system. [Figure 2] FIG. 1 is a block diagram of an authentication system. [Figure 3] FIG. 10 is a sequence diagram of authentication. [Figure 4] FIG. 10 is a diagram illustrating result information. [Figure 5] 10 is a flowchart of an authentication process performed by the authentication device. DETAILED DESCRIPTION OF THE INVENTION

[0008] A. First embodiment: A1. Overall configuration of the authentication system: In the following embodiment, a case will be described in which the reception strength of an identification signal received from a mobile terminal 30 (to be described later) is a value that represents the distance between the mobile terminal 30 and the authentication device 10.

[0009] FIG. 1 is a schematic diagram showing the overall configuration of an authentication system 1. As shown in FIG. 1, the authentication system 1 is a system for limiting people who can enter a security area SA to people who have been previously authorized to enter. The authentication system 1 includes a mobile terminal 30 and an authentication device 10. In this embodiment, the authentication device 10 is located near a door GE located at the entrance of the security area SA. The authentication device 10 is located within reach of a person at the entrance. Specifically, the distance between the authentication device 10 and an electric lock EL is, for example, several tens of centimeters or less. In this disclosure, a "person authorized to enter the security area SA" is referred to as a "user US." The mobile terminal 30 is carried by the user US. In this embodiment, the door GE is locked and unlocked by an electric lock EL. In this disclosure, the electric lock EL refers to a lock whose locking and unlocking are electrically controlled, regardless of whether it is battery-powered or not.

[0010] In FIG. 1, the security area SA is depicted as a room, with a door GE at the entrance to the security area SA, but this is not a limitation. For example, the security area SA may be located within a building or a train station, and the structure for restricting passage placed at the ticket gates in the station or at the entrance to the building may be an electrically controlled automatic door or a flapper gate. Note that the structure for restricting passage is not limited to physically restricting the entry of the user US using a door GE or the like. The following description will mainly focus on entry into the security area SA, but the present disclosure can also be applied to the case of exiting from the security area SA.

[0011] Fig. 2 is a block diagram of the authentication system 1. As shown in Fig. 2, the authentication device 10 includes a control unit 11, a storage unit 12, an operation unit interface 13, an input unit 14, and a communication unit 15. The control unit 11, the storage unit 12, the operation unit interface 13, and the communication unit 15 are communicatively connected via a bus 17. The control unit 11 is realized by a processor such as a CPU. The storage unit 12 is realized by a memory such as a RAM or a ROM.

[0012] The control unit 11 has a lock command unit 20, a determination unit 21, an acquisition unit 22, and an authentication unit 23. The lock command unit 20, the determination unit 21, the acquisition unit 22, and the authentication unit 23 are functional units realized by executing programs stored in the storage unit 12. The determination unit 21 performs a first determination (described later) and a second determination (described later). The acquisition unit 22 acquires registration information 26 (described later) that associates identification information 51 with authentication information 52 corresponding to the identification information 51. The authentication unit 23 performs authentication, which is a confirmation operation to determine whether a person attempting to enter the security area SA is a user US. The authentication unit 23 performs a first authentication and a second authentication based on a received identification signal. The first authentication is a determination, based on the received identification signal and the authentication information 52 in the registration information 26, of whether the mobile terminal 30 that is the sender of the received identification signal is a pre-registered mobile terminal 30. The second authentication is a determination as to whether the portable terminal 30 that transmitted the identification signal is a portable terminal 30 for which the first authentication has been successful. A pre-registered portable terminal 30 refers to a portable terminal 30 that matches the authentication information 52 included in the registration information 26. Details of the lock command unit 20, the determination unit 21, and the authentication unit 23 will be described later.

[0013] The storage unit 12 stores a program executed by the control unit 11. In this embodiment, the storage unit 12 pre-stores registration information 26. The acquisition unit 22 reads and acquires the registration information 26 stored in the storage unit 12 to perform the first authentication. The registration information 26 is information in which identification information 51 and authentication information 52 are pre-associated. The identification information 51 is information uniquely assigned to the mobile terminal 30. Details of the identification information 51 will be described later. The authentication information 52 is information corresponding to the identification information 51. The identification information 51 is information uniquely assigned to the user US. For example, the authentication information 52 may be a number such as an employee number or a personal number assigned by an administrative agency, or information combining a name and date of birth. The registration information 26 is created, for example, by an administrator of the authentication system 1. The storage unit 12 stores result information 53 created in the first authentication, which will be described later.

[0014] The input unit 14 is communicatively connected to the operation unit interface 13. The operation unit interface 13 mediates communication between the control unit 11 and the input unit 14. As shown in FIG. 1, the input unit 14 is disposed near the electric lock EL. Specifically, the distance between the input unit 14 and the electric lock EL is, for example, several tens of centimeters or less. The input unit 14 has a sensor group 28 and an operation button 29. The sensor group 28 includes an infrared sensor and a capacitance sensor. The infrared sensor accepts a "hand-over operation" by the user US. When a person's hand is brought close to the sensor group 28, the infrared sensor detects heat emitted from the hand. The capacitance sensor accepts a "touch operation" by the user US. When a person's hand touches the sensor group 28, the capacitance sensor detects a change in capacitance. The operation button 29 accepts a "button operation" by the user US. When the sensor group 28 detects the above operation or when the operation button 29 accepts a button operation, the input unit 14 transmits a detection signal to the control unit 11. This allows the control unit 11 to determine that a predetermined operation has been performed on the input unit 14.

[0015] The communication unit 15 shown in FIG. 2 is realized by a wireless communication module. The communication unit 15 performs wireless communication between the mobile terminal 30 and the electric lock EL. The communication unit 15 communicates in a connected state where wireless communication is established or in an unconnected state where wireless communication is not established. In this embodiment, wireless communication is performed in accordance with the BLE (Bluetooth (registered trademark) Low Energy) standard. In the following description, "BLE communication" may be simply referred to as "communication." Note that, in addition to BLE communication, communication in accordance with the BR / EDR (Bluetooth (registered trademark) Basic Rate / Enhanced Data Rate) standard or wireless LAN (Local area network) communication can also be used as wireless communication between the mobile terminal 30 and the electric lock EL. Furthermore, the communication standard for wireless communication between the communication unit 15 and the mobile terminal 30 may be the same as or different from the communication standard for wireless communication between the communication unit 15 and the electric lock EL.

[0016] The electric lock EL includes a communication module that communicates wirelessly with the communication unit 15, and locks or unlocks the door in response to a command sent from the authentication device .

[0017] The mobile terminal 30 includes a control unit 31, a storage unit 32, a display operation unit 33, and a communication unit 34. The control unit 31, the storage unit 32, the display operation unit 33, and the communication unit 34 are communicatively connected via a bus 35. The control unit 31 is realized by a processor such as a CPU. The storage unit 32 is realized by a memory such as a RAM or a ROM, for example.

[0018] The control unit 31 has a signal transmission unit 40. The signal transmission unit 40 is a functional unit that is realized by executing a program stored in the storage unit 32. The signal transmission unit 40 transmits an identification signal including identification information 51 of its own terminal to the authentication device 10.

[0019] The storage unit 32 stores a program executed by the control unit 31. The storage unit 32 stores an authentication application 42 and identification information 51.

[0020] The display operation unit 33 is realized by a touch panel. The display operation unit 33 displays images and accepts operations such as touch operations by the user US.

[0021] The communication unit 34 is realized by a wireless communication module. The communication unit 34 performs wireless communication with the communication unit 34 of the authentication device 10. As described above, in this embodiment, the communication unit 34 performs BLE communication with the authentication device 10. As described above, in addition to BLE communication, communication between the authentication device 10 and the mobile terminal 30 can also be communication conforming to the BR / EDR standard, wireless LAN communication, or the like.

[0022] A2. Certification Overview: The authentication device 10 communicates with the mobile terminal 30 to perform authentication to confirm that the person carrying the mobile terminal 30 is authorized to enter the security area SA. One possible authentication method is to store authentication information 52 previously assigned to the user US in the storage unit 32 of the mobile terminal 30 and then transmit the authentication information 52 from the mobile terminal 30 to the authentication device 10. In this case, to prevent leakage of the authentication information 52, the communication method used to transmit the authentication information 52 must be a highly secure communication method. However, highly secure communication methods generally require a long communication time. For example, if a communication method using BLE communication in a connected state is used to transmit the authentication information 52, the entire communication process takes, for example, about two seconds. Therefore, if multiple users US enter a single door GE at the same time, there is a risk of waiting for authentication.

[0023] Therefore, in the authentication sequence of this embodiment, authentication is performed in stages, including a first authentication and a second authentication, which has lower security than the first authentication. Typically, the first authentication, which requires more processing time than the second authentication, is performed when the user US is located farther from the authentication device 10, while the second authentication is performed when the user US is located closer to the authentication device 10. The second authentication confirms that the user US has successfully passed the first authentication. That is, the second authentication is confirmed based on the results of the first authentication. In FIG. 1, a first area AR1 indicates the area where the first authentication is performed. A second area AR2 indicates the area where the second authentication is performed. The first area AR1 and the second area AR2 are collectively referred to as the authentication area. By dividing the authentication into the first authentication and the second authentication, the possibility of multiple authentications overlapping at the same time can be reduced. Furthermore, by performing the first authentication, which requires more processing time, when the mobile terminal 30 is located farther from the authentication device 10, the possibility of the user US having to wait for authentication processing when approaching the authentication device 10 can be reduced.

[0024] When two-stage authentication is performed in this manner and multiple users US are near the electric lock EL, it may happen that the user US carrying the mobile terminal 30 that is the subject of the second authentication is different from the user US carrying the mobile terminal 30 that sent the identification signal that succeeded in the first authentication on which the second authentication is based. Specifically, if another user US carrying a mobile terminal 30 that sends a signal used for the second authentication is near the user US that performed the unlocking operation, a mismatch between these users US may occur.

[0025] Therefore, in this embodiment, the second authentication is performed on a mobile terminal 30 that transmits a signal with a large RSSI (Received Signal Strength Indicator), which is the reception strength when the authentication device 10 receives a signal transmitted from the mobile terminal 30. In other words, the consistency between the user US who wishes to unlock and the user US carrying the mobile terminal 30 that transmits the signal used for the second authentication is improved. This reduces the possibility that the user US carrying the mobile terminal 30 that is the target of the second authentication is different from the user US carrying the mobile terminal 30 that transmitted the identification signal that succeeded in the first authentication, on which the second authentication is based.

[0026] Whether the user US is near or far from the authentication device 10 may be determined by a method other than reception strength. For example, the authentication device 10 transmits a beacon signal to the mobile terminal 30 and stores the time T1 at which the beacon signal was transmitted. When the mobile terminal 30 receives the beacon signal, it transmits an identification signal containing the time T2 at which the beacon signal was received and the time T3 at which the identification signal was transmitted. When the authentication device 10 receives the identification signal, it stores the times T2 and T3 included in the identification signal and also stores the time T4 at which the identification signal was received. The authentication device 10 calculates the transmission and reception time from when the beacon signal is transmitted by the authentication device 10 to when the authentication device 10 receives the identification signal by subtracting T2 from T3 from T4. The distance calculated by the ToF (Time of Flight) method is calculated by dividing half of the transmission and reception time by the speed of radio waves (the speed of light), and the authentication device 10 determines whether the user US is near or far from the authentication device 10.

[0027] The authentication device 10 of this embodiment has an input unit 14 that accepts a user operation of a user US who wishes to unlock the door. A user operation refers to an operation performed by the user US on the input unit 14 to make a predetermined authentication request. Specific examples of user operations include a "touch operation" in which the user touches the input unit 14, a "hand-over operation" in which the user holds a hand over the input unit 14, and a "button operation" in which the user presses the operation button 29 on the input unit 14. A user operation is an operation that is performed only when the user US is within reach of the authentication device 10. Therefore, when a user operation is performed, it can be determined that the user US is located near the authentication device 10.

[0028] The user operation may include a "terminal-over-hand operation" in which the user US holds the mobile terminal 30 over the input unit 14. In this case, the distance between the mobile terminal 30 and the input unit 14 is closer than when the user US approaches the authentication device 10 with the mobile terminal 30 in, for example, a bag. Therefore, whether or not a "terminal-over-hand operation" has been performed can be determined using RSSI. In addition, to distinguish this from the "terminal-over-hand operation," a state in which the user US approaches the authentication device 10 with the mobile terminal 30 in, for example, a bag, without performing any special operation is also referred to as "hands-free." The distinction between "hands-free" and "terminal-over-hand operation" using RSSI can be made by setting the RSSI threshold for determining the "terminal-over-hand operation" higher than the RSSI threshold for determining the "hands-free" operation.

[0029] In the following description of the authentication sequence, for simplicity, a case where the second authentication is initiated by a "terminal-over-hand operation" will be described as an example. As will be described later, in another embodiment, the second authentication may be triggered by a user operation other than the "terminal-over-hand operation." In this case, the second authentication is also performed on the mobile terminal 30 that transmitted a signal with a large RSSI. Therefore, this embodiment also reduces the possibility that the user US carrying the mobile terminal 30 that is the target of the second authentication is different from the user US carrying the mobile terminal 30 that transmitted the identification signal that succeeded in the first authentication, on which the second authentication is based. Note that the user operation is performed only when the user US is within reach of the authentication device 10. Therefore, there is a high probability that the second authentication will be performed on a signal transmitted from the mobile terminal 30 carried by the user US who performed a user operation other than the "terminal-over-hand operation."

[0030] When the second authentication is initiated by the "terminal-over-hand operation," specifically, the first authentication is initiated when the RSSI of the signal transmitted from the mobile terminal 30 is greater than a predetermined first reference value Ith1 and equal to or less than a predetermined second reference value Ith2. In the following description, the range greater than the first reference value Ith1 and equal to or less than the second reference value Ith2 is also referred to as the "reference range." The second authentication is initiated when the RSSI of the signal transmitted from the mobile terminal 30 is greater than the second reference value Ith2. In this embodiment, the first reference value Ith1 and the second reference value Ith2 are set so that the first authentication is initiated when the distance between the mobile terminal 30 and the authentication device 10 is approximately shorter than 3 m and longer than 0.2 m, and the second authentication is initiated when the distance between the mobile terminal 30 and the authentication device 10 is approximately 0.2 m or shorter. The first reference value Ith1 and the second reference value Ith2 can be appropriately set through experiments, etc. In this embodiment, the first reference value Ith1 is −80 dBm, and the second reference value Ith2 is −35 dBm.

[0031] For ease of explanation, the following description of the authentication sequence will be given assuming that pairing between the mobile terminal 30 and the authentication device 10 has been performed in advance, and that the keys for data encryption and decryption exchanged during pairing are stored in the mobile terminal 30 and the authentication device 10, respectively. Pairing is performed, for example, when an authentication application 42 for enabling authentication by the authentication device 10 is installed in the mobile terminal 30. As described above, the registration information 26 stored in the authentication device 10 is information that associates identification information 51 with authentication information 52. As described above, the identification information 51 is information uniquely assigned to the mobile terminal 30. Examples of the identification information 51 that can be used include a personal identifier, a wireless communication address, and an identifier created by adding the model name of the mobile terminal 30 to the serial number. Here, the personal identifier is an identifier assigned by the authentication device 10 when installing and configuring the authentication application 42 on the mobile terminal 30.

[0032] The identification information 51 is not limited to one piece of data, but may include multiple pieces of data. A piece of data refers to a collection of information indicating one content, such as the personal identifier described above. The same applies to the authentication information 52.

[0033] A3. Authentication Sequence: FIG. 3 is a sequence diagram of authentication. An outline of the sequence up to when the user US enters the security area SA will be described using FIG. 3. Details of the processing will be described later using a flowchart. As described above, in this embodiment, authentication in the authentication system 1 is performed by BLE communication between the authentication device 10 and the mobile terminal 30. The authentication device 10 repeatedly transmits a beacon signal. When the signal transmitting unit 40 of the mobile terminal 30 receives the beacon signal, it transmits an advertising signal as an identification signal, which is a response signal. The advertising signal includes identification information 51 of the mobile terminal itself.

[0034] The user US enters the first area AR1 shown in Fig. 1. The authentication device 10 transmits a beacon signal in step S10 shown in Fig. 3. Upon receiving the beacon signal transmitted by the authentication device 10, the mobile terminal 30 transmits an advertising signal in step S12. In step S14, the authentication device 10 confirms that the RSSI of the received advertising signal is within a reference range.

[0035] As described above, the authentication device 10 repeatedly transmits a beacon signal. Then, when the mobile terminal 30 receives a beacon signal, it transmits an advertising signal. The first authentication is initiated when the RSSI of the advertising signal received by the authentication device 10 is within a reference range. The second authentication is initiated when the RSSI of the advertising signal received by the authentication device 10 is greater than a second reference value Ith2. Therefore, for ease of understanding, FIG. 3 shows only the beacon signal and advertising signal that are the triggers.

[0036] In step S16, the authentication device 10 and the mobile terminal 30 establish wireless communication and transition to a connected state in which one-to-one communication is performed. For example, if the RSSI of the received advertising signal is within a reference range, the authentication device 10 transmits a connection request to the mobile terminal 30 that transmitted the advertising signal, and establishes wireless communication between the authentication device 10 and the mobile terminal 30 that accepts the connection request, transitioning to a connected state. In the present disclosure, the "connected state" refers to a state in which one-to-one communication is performed with a specific party. In communication in the connected state, signal confidentiality can be improved compared to when a signal is transmitted to a large number of parties by broadcast, such as an advertising signal.

[0037] Specifically, in this sequence, the authentication device 10 and the mobile terminal 30 use keys for encryption and decryption to transition to a connection state in which encrypted data can be exchanged.

[0038] In the connected state, the authentication device 10 uses the identification information 51 transmitted from the mobile terminal 30 to perform a first authentication to confirm that the received identification information 51 is consistent with the authentication information 52. If the first authentication is successful in step S20, the authentication device 10 creates result information 53 and stores it in the memory unit 12 in step S22.

[0039] FIG. 4 is a diagram illustrating result information 53. Result information 53 is information in which identification information 51 and authentication information 52 are associated with each other. When the first authentication is successful, authentication device 10 creates result information 53 in which successful identification information 51 is associated with authentication information 52, and stores the result information in storage unit 12. In this way, when identification information 51 is included in result information 53, authentication device 10 can confirm that this identification information 51 has succeeded in the first authentication. Alternatively, identification information 51 may not be associated with authentication information 52, and identification information 51 may be treated as result information 53.

[0040] In step S24 of Fig. 3, the authentication device 10 releases the connection with the mobile terminal 30. The user US approaches the door GE further and enters the second area AR2 shown in Fig. 1. In step S26 of Fig. 3, the authentication device 10 transmits a beacon signal. Upon receiving the beacon signal transmitted by the authentication device 10, the mobile terminal 30 transmits an advertising signal in step S28.

[0041] In step S32, the authentication device 10 confirms that the RSSI of the received advertising signal is greater than a second reference value Ith2, which is the upper limit of a reference range. After performing step S32, the authentication device 10 compares the identification information 51 included in the received advertising signal with the result information 53, and performs a second authentication to confirm that the sender of the advertising signal has succeeded in the first authentication. Specifically, in the second authentication, the authentication device 10 confirms that the identification information 51 included in the received advertising signal is included in the result information 53. Note that the advertising signal is a signal transmitted in an unconnected state where the authentication device 10 and the mobile terminal 30 are not connected. The second authentication is then performed without transitioning to a connected state.

[0042] If the second authentication is successful in step S36, the authentication device 10 cancels the restriction on the passage of the user US carrying the mobile terminal 30 for which the second authentication was successful in step S38. For example, the authentication device 10 commands the electric lock EL to unlock. This unlocks the electric lock EL, allowing the user US to enter the security area SA.

[0043] In the authentication sequence, steps S10 to S24 are also referred to as "pre-authentication." Steps S26 to S38 are also referred to as "passing authentication." Typically, "pre-authentication" is performed when the user US is in the first area AR1, and "passing authentication" is performed when the user US is in the second area AR2.

[0044] A4.Authentication Flowchart: 5 is a flowchart of the authentication process performed by the authentication device 10. The authentication method is realized by performing the authentication process. The same processing steps as those shown in FIG. 3 are given the same reference numerals, and detailed explanations will be omitted as appropriate. The authentication device 10 repeatedly performs the authentication process while the authentication function of the authentication system 1 is enabled.

[0045] Based on a value representing the distance between the mobile terminal 30 and the authentication device 10, the judgment unit 21 makes a first judgment to determine whether the distance between the mobile terminal 30 and the authentication device 10 is shorter than a first reference distance, and a second judgment to determine whether the distance between the mobile terminal 30 and the authentication device 10 is shorter than a second reference distance. The second reference distance is shorter than the first reference distance. The first reference distance corresponds to a first area AR1. The second reference distance corresponds to a second area AR2. In this embodiment, in the first judgment, the judgment unit 21 determines whether the distance between the mobile terminal 30 and the authentication device 10 is shorter than the first reference distance and whether the distance between the mobile terminal 30 and the authentication device 10 is longer than the second reference distance.

[0046] The determination unit 21 makes a first determination and a second determination based on RSSI, which is a value representing the distance between the mobile terminal 30 and the authentication device 10. In the first determination and the second determination, the determination unit 21 uses a first reference value Ith1 corresponding to the first reference distance and a second reference value Ith2 corresponding to the second reference distance. The first reference value Ith1 and the second reference value Ith2 are RSSI values. The second reference value Ith2 is greater than the first reference value Ith1. In the first determination, if the RSSI is greater than the first reference value Ith1 and less than or equal to the second reference value Ith2, the determination unit 21 determines that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the first reference distance and equal to or greater than the second reference distance. In the second determination, if the RSSI is greater than the second reference value, the determination unit 21 determines that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the second reference distance. In addition, the judgment unit 21 may determine in the first judgment that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the first reference distance if the RSSI is greater than the first reference value Ith1, and may determine in the second judgment that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the second reference distance if the RSSI is greater than the second reference value Ith2.Even with this configuration, the same effect as the above configuration can be obtained.

[0047] Another embodiment of the value representing the distance between the mobile terminal 30 and the authentication device 10 is ToF (Time of Flight). Here, ToF is the estimated distance between the mobile terminal 30 and the authentication device 10, calculated from the time it takes for either the mobile terminal 30 or the authentication device 10 to receive the message after the other of the mobile terminal 30 and the authentication device 10 sends the message. When ToF is used, the determination unit 21 uses a first reference estimated distance corresponding to the first reference distance and a second reference estimated distance corresponding to the second reference distance. In the first determination, if the calculated ToF is shorter than the first reference estimated distance but equal to or greater than the second reference estimated distance, the determination unit 21 determines that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the first reference distance and equal to or greater than the second reference distance. In the second determination, if the calculated ToF is shorter than the second reference estimated distance, the determination unit 21 determines that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the second reference distance.

[0048] Another embodiment of the value representing the distance between the mobile terminal 30 and the authentication device 10 is the communication time required from when one of the mobile terminal 30 and the authentication device 10 sends a message until the other of the mobile terminal 30 and the authentication device 10 receives the message. When using this communication time, the determination unit 21 uses a first reference time corresponding to the first reference distance and a second reference time corresponding to the second reference distance. When the communication time determined in the first determination is shorter than the first reference time but equal to or greater than the second reference time, the determination unit 21 determines that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the first reference distance but equal to or greater than the second reference distance. When the communication time determined in the second determination is shorter than the second reference time, the determination unit 21 determines that the distance between the mobile terminal 30 and the authentication device 10 is shorter than the second reference distance.

[0049] In step S13, when the communication unit 15 receives an advertising signal as an identification signal transmitted from the signal transmission unit 40 of the mobile terminal 30, the determination unit 21 performs a first determination to determine whether the detection value Im, which is the RSSI of the received advertising signal, is within a reference range. In detail, after confirming that the received advertising signal is from a legitimate sender, the determination unit 21 determines whether the detection value Im is greater than a first reference value Ith1 and equal to or less than a second reference value Ith2. Here, a legitimate sender refers to a sender whose information included in the advertising signal is consistent with the identification information 51 or authentication information 52 stored in the registration information 26. Note that if the determination unit 21 determines that the RSSI is within the reference range in step S13, this corresponds to step S14 in FIG. 3.

[0050] In step S13 of FIG. 5 , if the determination unit 21 determines that the detection value Im is within the reference range, the user US is in the first area AR1. Therefore, in step S16, connection authentication is performed, and the authentication unit 23 transitions to a connected state. In step S17, the authentication unit 23 performs first authentication to confirm that the received identification information 51 matches the authentication information 52. The first authentication is not limited to a process of confirming that the identification information 51 stored as the registration information 26 matches the received identification information 51. For example, it may be a process of confirming that information obtained by decrypting the received encrypted identification information 51 using a key exchanged during pairing matches the identification information 51 or authentication information 52 stored as the registration information 26. Because pairing is performed by identifying the user US, even in this confirmation process, it is possible to confirm the consistency between the received identification information 51 and the registration information 26. Because the first authentication is performed in a connected state, signals can be exchanged with high confidentiality.

[0051] As described above, the mobile terminal 30 transmits an advertising signal regardless of whether the first authentication has already been performed. In particular, when the determination unit 21 determines that the detection value Im is within the reference range, the authentication unit 23 performs the processing steps from step S16 onwards for the mobile terminal 30 that has not yet performed the first authentication. In other words, the first authentication process is omitted for the mobile terminal 30 that has already performed the first authentication.

[0052] In step S19, authentication unit 23 determines whether or not the first authentication has been successful. If it is determined in step S19 that the first authentication has been successful, in step S22, authentication unit 23 creates result information 53 and stores it in storage unit 12. Note that the case where the first authentication has been successful in step S19 corresponds to step S20 in FIG. 3.

[0053] 5, the authentication unit 23 immediately disconnects communication with the mobile terminal 30 that has successfully passed the first authentication. For example, the authentication unit 23 transmits a packet to the mobile terminal 30 to disconnect communication, thereby releasing the connection state. This allows the authentication device 10 to quickly connect to a mobile terminal 30 different from the mobile terminal 30 that performed the first authentication. Note that the order in which steps S22 and S24 are performed is not limited to the order in FIG. 5; step S22 may be performed after step S24, or step S22 and step S24 may be performed simultaneously.

[0054] In some cases, both the authentication device 10 and the mobile terminal 30 are configured to terminate the connection state if a predetermined timeout period has elapsed without receiving a signal from the other party since the most recent signal was transmitted in the connection state. Step S24 may be configured to be performed within a predetermined period that is shorter than the timeout period. Furthermore, after completing the first authentication with the mobile terminal 30 that performed the first authentication, the authentication unit 23 terminates the connection state in step S24 without subsequently performing the second authentication. Therefore, step S24 can also be defined as being performed before the second authentication.

[0055] After performing step S24, the authentication unit 23 ends this processing routine. If it is determined in step S19 that the first authentication has not been successful, the connection state is released in step S24, and the authentication unit 23 ends this processing routine. If it is determined that the first authentication has not been successful, the authentication unit 23 may transmit information indicating that the authentication has failed to the mobile terminal 30. Then, when the mobile terminal 30 receives information indicating that the authentication has failed, it notifies the user US, for example, by displaying a message on the display operation unit 33. This allows the user US to know that the authentication has failed.

[0056] If it is determined in step S13 that the detection value Im is not within the reference range, then in step S31 the determination unit 21 performs a second determination of whether the detection value Im is greater than a second reference value Ith2. If the determination unit 21 determines in step S31 that the detection value Im is greater than the second reference value Ith2, the user US is in the second area AR2, and therefore in step S33 the authentication unit 23 performs a second authentication of the mobile terminal 30 that is the sender of the advertising signal, to confirm that the first authentication has been successful. Note that if the determination unit 21 determines that the detection value Im is greater than the second reference value Ith2, this corresponds to step S32 in FIG. 3.

[0057] The content of the identification information 51 included in the identification signal transmitted in the first area AR1 and the content of the identification information 51 included in the identification signal transmitted in the second area AR2 may be the same or different. Specifically, when the identification information 51 includes multiple pieces of data, at least some of the multiple pieces of data in the identification information 51 included in the identification signal transmitted in the first area AR1 may be different from those in the identification information 51 included in the identification signal transmitted in the second area AR2. Furthermore, each of the identification information 51 included in the identification signal transmitted in the first area AR1 and the identification information 51 included in the identification signal transmitted in the second area AR2 may include only one piece of data.

[0058] In step S35 of FIG. 5 , the authentication unit 23 determines whether the mobile terminal 30, which is the sender of the advertising signal, has successfully completed the second authentication. If the authentication unit 23 determines in step S35 that the second authentication has been successful, in step S38, the authentication unit 23 creates history information (not shown) that associates the date and time of the successful second authentication with the authentication information 52 associated with the identification information 51 indicating the successful second authentication. The authentication unit 23 then deletes the identification information 51 indicating the successful second authentication from the result information 53. The lock command unit 20 then commands the electric lock EL to unlock, and the processing routine ends. By creating the history information in step S38, the entry time of the user US associated with the authentication information 52 can be stored as history. In step S38, the security of the authentication system 1 can be enhanced by deleting the identification information 51 associated with the authentication information 52. More specifically, the identification signal used for the second authentication is transmitted in an unconnected state and therefore may be intercepted. Therefore, by deleting unnecessary identification information 51 from result information 53, it is possible to prevent the electric lock EL from being unlocked even when a signal containing illegally obtained identification information 51 is transmitted. Note that the case where it is determined in step S35 that the second authentication is successful corresponds to step S36 in FIG. 3. Furthermore, it is not always necessary to create history information in step S38.

[0059] The timing for deleting unnecessary identification information 51 from the result information 53 is not limited to after the second authentication is successful. It may be when a predetermined retention time has elapsed since the result information 53 was created and stored in the storage unit 12, or when the number of identification information 51 stored as the result information 53 exceeds a predetermined upper limit. When the number of identification information 51 stored as the result information 53 exceeds the upper limit, the oldest identification information 51 may be deleted. The retention time is, for example, approximately 10 seconds. Deleting unnecessary identification information 51 from the result information 53 can enhance the security of the authentication system 1. Deleting unnecessary identification information 51 from the result information 53 can also ensure free space in the storage unit 12. An example of a case in which the retention time has elapsed without second authentication being performed since the result information 53 was created and stored in the storage unit 12 is when the user US simply passes through the first area AR1 without intending to enter the security area SA.

[0060] In step S31 of FIG. 5, if the judgment unit 21 determines that the detection value Im is not greater than the second reference value Ith2, the detection value Im is less than or equal to the first reference value Ith1 and the user US is outside the authentication area, so the authentication unit 23 terminates this processing routine.

[0061] If it is determined in step S35 that the second authentication has not been successful, then in step S41 the authentication unit 23 transitions to a connected state, as in step S16. A case in which it is determined that the second authentication has not been successful may be when there are many users US in the first area AR1, and a user US enters the second area AR2 before the first authentication is completed due to a waiting period for the first authentication. Therefore, in this case, the first authentication is performed in the second area AR2.

[0062] In step S43, the authentication unit 23 performs the first authentication, similarly to step S17. In step S45, the authentication unit 23 determines whether the first authentication was successful. If it is determined in step S45 that the first authentication was not successful, the authentication unit 23 terminates this processing routine. If it is determined that the first authentication was not successful, the authentication unit 23 may send information indicating that the authentication was unsuccessful to the mobile terminal 30. If the authentication unit 23 determines in step S45 that the first authentication was successful, in step S47, history information is created, the identification information 51 indicating that the second authentication was successful is deleted from the result information 53, and the lock command unit 20 commands the electric lock EL to unlock without performing the second authentication. In step S49, the authentication unit 23 releases the connection state and terminates this processing routine. The order in which steps S47 and S49 are performed is not limited to the order shown in FIG. 5; step S47 may be performed after step S49, or steps S47 and S49 may be performed simultaneously.

[0063] A5. Other embodiments of the processing steps: In the above, the first authentication is exemplified as a case where pairing is performed in advance in BLE communication, but this is not limited to this. Pairing may also be performed after the first authentication is initiated. Furthermore, the communication format used for the first authentication is not limited to a communication format in which data is encrypted. For example, the first authentication may be performed without encrypting data by using a one-time password. Methods for generating a one-time password include a method of generating a one-time password using a time that has been synchronized in advance between the authentication device 10 and the mobile terminal 30, and a method of generating a new one-time password using a one-time password used in the installation settings of the authentication application 42.

[0064] In the above, a case where the RSSI of the advertising signal is used as a trigger for starting the second authentication has been described. A case where a user operation condition is used as a trigger for starting the second authentication will now be described. In this case, when an operation signal indicating that a user operation has been performed is transmitted from the input unit 14, the determination unit 21 performs step S31 in FIG. 5 after receiving the operation signal. That is, even in this case, the authentication unit 23 performs the second authentication when it determines that the RSSI of the advertising signal is greater than the second reference value Ith2. By performing the second determination after receiving the operation signal, it is possible to omit the second determination that is performed when the reception strength is equal to or less than the second reference value, thereby reducing the processing load.

[0065] While FIG. 3 illustrates a sequence for one user US, the flowchart of FIG. 5 can also be applied to a situation where multiple users US are located in the first area AR1 or the second area AR2. Specifically, when the communication unit 15 receives multiple advertising signals corresponding to multiple mobile terminals 30, the authentication unit 23 uses the largest RSSI as the determination target in step S13. That is, the authentication unit 23 performs the first authentication in descending order of RSSI. For example, when multiple mobile terminals 30 are present in the first area AR1, the authentication unit 23 establishes wireless communication with the mobile terminal 30 with the largest RSSI among the multiple advertising signals received and performs the first authentication in a connected state, terminates the connection with the mobile terminal 30 for which the first authentication was successful, and then establishes wireless communication with the mobile terminal 30 with the largest RSSI among the multiple advertising signals received, excluding the mobile terminal 30 for which the first authentication was successful, and performs the first authentication. Note that the mobile terminals 30 for which wireless communication is established after the connection state is terminated may also include mobile terminals 30 for which the first authentication failed. In this case, portable terminals 30 whose authentication failure count has not reached a predetermined upper limit (e.g., two times) may be included as targets for establishing wireless communication, and the authentication device 10 may store information about portable terminals 30 for which the first authentication failed the upper limit number of times for a predetermined retention time and exclude them from targets for establishing wireless communication. This reduces the possibility of the user US waiting to unlock. Similarly, when the communication unit 15 receives multiple advertising signals, the determination unit 21 determines the largest RSSI as the target for determination in step S31. That is, the authentication unit 23 performs the second authentication in descending order of RSSI. This increases the likelihood that the user US who performed the user operation and the user US who is the target of the second authentication will match. It also reduces the possibility of the user US waiting to unlock. Note that the authentication unit 23 may perform the first authentication in the order in which the advertising signals were received, rather than in descending order of RSSI. For example, after the connection state with the portable terminal 30 that performed the first authentication is released, wireless communication is established with the portable terminal 30 that first received an advertising signal among multiple portable terminals 30 present in the first area AR1, and the first authentication and second authentication are performed.In this case, if there are mobile terminals 30 in the first area AR1 and the second area AR2, and advertising signals are received from each mobile terminal 30 at the same time, or if a request for passage is accepted, authentication processing of the mobile terminal 30 present in the second area AR2 is performed with priority.

[0066] In BLE communication, it is possible to communicate with multiple parties simultaneously in a connected state, but in this embodiment, it is preferable that the connection state for the first authentication be a one-to-one connection state. Specifically, after completing the first authentication with the first mobile terminal 30 and releasing the connection state with the first mobile terminal 30, the first authentication with the second mobile terminal 30 is performed. This makes it possible to perform multiple first authentications corresponding to multiple mobile terminals 30 in a short time. The inventors have confirmed that sequentially performing first authentications in a one-to-one connection state has a faster processing speed than performing multiple first authentications in parallel in a one-to-many connection.

[0067] Step S17 is also referred to as a first authentication step, step S22 is also referred to as a creation step, step S33 is also referred to as a second authentication step, and step S38 is also referred to as an unlocking step.

[0068] According to the first embodiment described above, the authentication system 1 includes an authentication device 10 and a mobile terminal 30. The authentication device 10 includes a storage unit 12, a communication unit 15, and an authentication unit 23. When the determination unit 21 determines that the RSSI of a received identification signal is greater than a first reference value Ith1 and less than or equal to a second reference value Ith2, the authentication unit 23 performs first authentication to confirm that the identification information 51 included in the identification signal is consistent with the authentication information 52 in the registration information 26. When the first authentication is successful, the authentication unit 23 creates result information 53. When the authentication unit 23 determines that the RSSI of the identification signal is greater than the second reference value Ith2, the authentication unit 23 performs second authentication by comparing the identification information 51 included in the identification signal determined to be greater than the second reference value Ith2 with the result information 53. This reduces the possibility that the user US carrying the mobile terminal 30 that triggers the second authentication is different from the user US carrying the mobile terminal 30 that transmitted the identification signal that resulted in the first authentication.

[0069] The authentication device 10 also has a lock command unit 20. After the authentication unit 23 has successfully completed the second authentication, the lock command unit 20 commands the electric lock EL to unlock. This makes it possible to provide an authentication system 1 that unlocks the electric lock EL if the second authentication is successful. The judgment unit 21 also makes the first judgment and the second judgment using an identification signal received in a disconnected state. The authentication unit 23 performs the first authentication using an identification signal received in a connected state. This makes it possible to perform the first authentication using communication in a connected state, which provides higher confidentiality of data communicated than in a disconnected state.

[0070] Furthermore, if the second authentication is successful, the authentication unit 23 creates history information in which the date and time when the second authentication was successful is associated with the authentication information 52 associated with the identification information 51 for which the second authentication was successful. This makes it possible to create history information about the user US who has succeeded in the second authentication.

[0071] Furthermore, after the second authentication is successful, the authentication unit 23 deletes the identification information 51 for which the second authentication was successful from the result information 53. This allows unnecessary identification information 51 to be deleted from the result information 53 early, thereby preventing the electric lock EL from being unlocked by transmitting fraudulently obtained identification information 51. Furthermore, if a predetermined retention time has passed since the result information 53 was created without the identification information 51 being deleted from the result information 53, the authentication unit 23 deletes the identification information 51 remaining in the result information 53 from the result information 53. This allows unnecessary identification information 51 to be deleted from the result information 53 early, thereby preventing the electric lock EL from being unlocked by transmitting a signal including fraudulently obtained identification information 51.

[0072] Furthermore, when the authentication unit 23 performs the second authentication with the mobile terminal 30 and the second authentication fails, the authentication unit 23 connects to the mobile terminal 30 and performs the first authentication. After the first authentication is successful, the lock command unit 20 commands the electric lock EL to unlock without performing the second authentication. This allows the first authentication for unlocking to be performed even for a user US who approaches the electric lock EL before the first authentication is completed, and unlocking can be performed without performing the second authentication. This improves convenience for the user US.

[0073] Furthermore, after performing the first authentication, the authentication unit 23 releases the connection state within a predetermined time. By releasing the connection state, it is possible to quickly connect to a mobile terminal 30 different from the currently connected mobile terminal 30. Therefore, when multiple users US want to unlock the electric lock EL at the same time, it is possible to reduce the possibility that the users US carrying the mobile terminals 30 will have to wait for authentication processing.

[0074] B. Second embodiment: In the first embodiment, if the second authentication fails for a portable terminal 30 in the second area AR2, i.e., if the first authentication has not been performed, an unlocking command is issued after the first authentication has been performed. This second area AR2 is set to be a range very close to the electric lock EL, specifically, a range approximately 20 cm away from the electric lock EL. In this embodiment, a third area is set to be closer to the electric lock EL than the first area AR1 and farther from the electric lock EL than the second area AR2. In this embodiment, this third area is set to be a range approximately 50 cm away from the electric lock EL. In this embodiment, if there is a portable terminal 30 in the third area that has not undergone the first authentication, the first authentication is performed, and unlocking is performed when the portable terminal 30 enters the second area AR2 while maintaining the connection.

[0075] Specifically, the detection value Im is used to determine whether the user US is in the first area AR1. If the user US is determined to be in the first area AR1, the processing procedure is the same as that from step S16 onward in the first embodiment. On the other hand, if the user US is determined to be in the third area AR1, not the first area AR1, the first authentication is performed. If the first authentication is successful, the connected state is maintained. If the user US is determined to have entered the second area AR2, the second authentication is omitted, an unlock command is issued, and the connected state is then terminated. In this embodiment, the third reference value of the RSSI used to determine whether the user US is in the third area is −45 dBm. In this way, if the user US is likely to enter the second area AR2 soon, the connected state is terminated after unlocking, thereby shortening the time required for the process to terminate the connected state. This embodiment is particularly effective when the processing power of the authentication device 10 is not high.

[0076] If the first authentication is successful and the connected state is maintained, it is repeatedly checked whether the detection value Im has become equal to or less than the first reference value Ith1 in the connected state. If the detection value Im has become equal to or less than the first reference value Ith1, that is, if the mobile terminal 30 has left the authentication area, the connected state is released.

[0077] According to the second embodiment described above, the authentication unit 23 performs the second authentication with the portable terminal 30 in the third area, performs the first authentication with the portable terminal 30 that failed the second authentication, and after confirming that the portable terminal 30 that succeeded in the first authentication is located in the second area AR2, the lock command unit 20 commands the electric lock EL to unlock. After the lock command unit 20 commands the unlocking, the authentication unit 23 releases the connection state. As a result, if there is a high probability that the user US carrying the portable terminal 30 will quickly enter the second area AR2 where unlocking is to be performed, the electric lock EL can be unlocked early without waiting for the process of releasing the connection state and the authentication process of the second authentication. Therefore, the time spent by the user US waiting for unlocking can be reduced.

[0078] C. Other Embodiments: (C1) In the first embodiment, the registration information 26 is stored in the storage unit 12 of the authentication device 10. In another embodiment, the registration information 26 may be stored in a server communicably connected to the authentication device 10. That is, the acquisition unit 22 may acquire the registration information 26 stored in the server by communicating with the server. The authentication unit 23 may then request authentication from the server using the identification information 51 and perform authentication using the authentication result provided. This authentication may be performed after the first authentication or after the second authentication. This embodiment is useful when multiple entrances are provided in the security area SA and common registration information 26 is used.

[0079] (C2) In the first embodiment, the result information 53 is stored in the storage unit 12 of the authentication device 10. In another embodiment, the result information 53 may be stored in a server communicatively connected to the authentication device 10. That is, the communication unit 15 may transmit the authentication result of the first authentication to the server, and the server may store the result information 53 based on the received authentication result. Then, when performing the second authentication, the authentication unit 23 may request authentication from the server using the identification information 51 and perform the authentication using the authentication result received from the server. That is, when receiving an authentication result from the server indicating that the second authentication was successful, the authentication unit 23 determines that the mobile terminal 30 that performed the second authentication is a mobile terminal 30 for which the first authentication has already been successful. This embodiment is useful when a security area SA has multiple entrances and multiple authentication devices 10 use the same result information 53.

[0080] (C3) In the first embodiment described above, when performing first authentication with multiple mobile terminals 30, the authentication device 10 performs the first authentication with the mobile terminals 30 in a one-to-one connection state. As another embodiment, the authentication device 10 may perform the first authentication with the mobile terminals 30 in a one-to-many connection state. In this case, the number of mobile terminals 30 connected simultaneously should be less than the upper limit of the number of mobile terminals that can be connected simultaneously. Even when the connection state is not one-to-one, the total time for first authentication with multiple mobile terminals 30 can be shortened by connecting to fewer mobile terminals 30 than the upper limit of the number of mobile terminals that can be connected simultaneously. Note that when multiple mobile terminals 30 are connected simultaneously, it is preferable to terminate the connection state with the mobile terminal 30 that has completed the first authentication, in order, and then connect to a new mobile terminal 30 after the connection states with all mobile terminals 30 have been terminated.

[0081] (C4) In the first embodiment, when the connected state is released, the authentication unit 23 of the authentication device 10 transmits a packet for disconnecting communication. In another embodiment, when the authentication device 10 transmits a packet to the mobile terminal 30 notifying that the first authentication has ended, the connected state may be released by the mobile terminal 30 transmitting a packet for disconnecting communication.

[0082] (C5) In the first embodiment, the authentication device 10 has the sensor group 28 and the operation button 29. In another embodiment, the authentication device 10 may not have at least one of the sensor group 28 and the operation button 29. The sensor group 28 and the operation button 29 may be provided depending on the user operation to be adopted. For example, if only "holding the device over" is adopted as the user operation, the authentication device 10 may not have either the sensor group 28 or the operation button 29.

[0083] (C6) In the first embodiment, the authentication device 10 determines whether the mobile terminal 30 is in the first area AR1 using RSSI. In another embodiment, the authentication device 10 may make the determination using location information of the mobile terminal 30. Also, in the first embodiment, the authentication device 10 performs the second authentication using BLE communication. In another embodiment, the second authentication may be performed using RFID (radio frequency identification).

[0084] The controller and methods described herein may be implemented by a special-purpose computer configured with a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the controller and methods described herein may be implemented by a special-purpose computer configured with a processor configured with one or more dedicated hardware logic circuits. Alternatively, the controller and methods described herein may be implemented by one or more special-purpose computers configured with a processor and memory programmed to perform one or more functions in combination with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory storage medium.

[0085] The present disclosure is not limited to the above-described embodiments and modifications, and can be realized in various configurations without departing from the spirit thereof. For example, the technical features in the embodiments and modifications corresponding to the technical features in each aspect described in the Summary of the Invention section can be appropriately replaced or combined to solve some or all of the above-described problems or achieve some or all of the above-described effects. Furthermore, if a technical feature is not described as essential in this specification, it can be appropriately deleted. [Explanation of symbols]

[0086] 1...Authentication system, 10...Authentication device, 11...Control unit, 12...Memory unit, 13...Operation unit interface, 14...Input unit, 15...Communication unit, 17...Bus, 20...Lock command unit, 21...Determination unit, 22...Acquisition unit, 23...Authentication unit, 26...Registration information, 28...Sensor group, 29...Operation button, 30...Mobile terminal, 31...Control unit, 32...Memory unit, 33...Display operation unit, 34...Communication unit, 35...Bus, 40...Signal transmission unit, 42...Authentication application, 51...Identification information, 52...Authentication information, 53...Result information, AR1...First area, AR2...Second area, EL...Electric lock

Claims

1. An authentication system including a mobile terminal and an authentication device, the portable terminal has a signal transmitting unit that transmits an identification signal including identification information of the portable terminal to the authentication device; The authentication device a communication unit that receives the identification signal; a determination unit that performs a first determination based on a value representing a distance between the portable terminal and the authentication device to determine whether the distance is shorter than a predetermined first reference distance, and a second determination that determines whether the distance is shorter than a second reference distance that is set shorter than the first reference distance; an authentication unit; The authentication unit When the determination unit determines in the first determination that the distance is shorter than the first reference distance, it performs a first authentication based on the identification information received from the portable terminal to determine whether the portable terminal is a pre-registered portable terminal, and when the first authentication is successful, it creates result information including the identification information of the portable terminal that has succeeded in the first authentication; An authentication system in which, when the judgment unit determines in the second judgment that the distance is shorter than the second reference distance, the identification information received from the mobile terminal is compared with the result information to perform a second authentication to determine whether the mobile terminal is a mobile terminal for which the first authentication has been successful.

2. 2. The authentication system according to claim 1, the value representing the distance is a reception strength of the identification signal received in an unconnected state where wireless communication with the mobile terminal is not established, The authentication unit performs the first authentication using the identification signal received in a connected state in which the wireless communication with the mobile terminal is established.

3. 3. The authentication system according to claim 2, an authentication system in which the authentication unit establishes wireless communication with a first mobile terminal and performs the first authentication, then terminates the connection with the first mobile terminal, and then establishes wireless communication with a second mobile terminal and performs the first authentication.

4. 4. The authentication system according to claim 1, The authentication device has a lock command unit that commands an electric lock, After the authentication unit has succeeded in the second authentication, the lock command unit commands the electric lock to unlock.

5. 5. The authentication system according to claim 4, An authentication system in which, if the second authentication with the mobile terminal fails, the authentication unit performs the first authentication with the mobile terminal, and if the first authentication is successful, the lock command unit commands the electric lock to unlock without performing the second authentication.

6. 4. The authentication system according to claim 1, When the second authentication is successful, the authentication unit deletes the identification information for which the second authentication was successful from the result information.

7. 4. The authentication system according to claim 1, The authentication unit deletes the identification information from the result information when a predetermined retention time has elapsed since the result information was created.

8. 4. The authentication system according to claim 1, An authentication system, wherein, when the second authentication with the mobile terminal is successful, the authentication unit creates history information that associates the identification information of the mobile terminal with the date and time when the second authentication was successful.

9. 4. The authentication system according to claim 1, the authentication device further includes an input unit that accepts an authentication request from a user who carries the mobile terminal; The authentication unit performs the second authentication based on the identification signal received when the authentication request is accepted.

10. An authentication device, a communication unit that receives an identification signal including identification information of the mobile terminal transmitted from the mobile terminal; a determination unit that performs a first determination based on a value representing a distance between the portable terminal and the authentication device to determine whether the distance is shorter than a predetermined first reference distance, and a second determination that determines whether the distance is shorter than a second reference distance that is set shorter than the first reference distance; an authentication unit; The authentication unit When the determination unit determines in the first determination that the distance is shorter than the first reference distance, it performs a first authentication based on the identification information received from the portable terminal to determine whether the portable terminal is a pre-registered portable terminal, and when the first authentication is successful, it creates result information including the identification information of the portable terminal that has succeeded in the first authentication; An authentication device that, when the judgment unit determines in the second judgment that the distance is shorter than the second reference distance, performs a second authentication in which the identification information received from the mobile terminal is compared with the result information to determine whether the mobile terminal is a mobile terminal that has already been successfully authenticated in the first authentication.

11. An authentication method using an authentication device that communicates with a mobile terminal, the authentication device has a communication unit that receives an identification signal that includes identification information of the portable terminal and is transmitted from the portable terminal; The authentication method includes: a first authentication step of performing a first authentication based on the identification information received from the portable terminal to determine whether the portable terminal is a pre-registered portable terminal when it is determined that the distance is shorter than a predetermined first reference distance based on a value representing the distance between the portable terminal and the authentication device; a creation step of creating result information including the identification information of the mobile terminal that has succeeded in the first authentication; a second authentication step of performing a second authentication in which, when it is determined that the distance is shorter than a second reference distance that is set shorter than the first reference distance, the identification information received from the mobile terminal is compared with the result information to determine whether the mobile terminal has been successfully authenticated in the first authentication; authentication methods, including

Citation Information

Patent Citations

  • Operation controller

    JP2016194201A