Access control system, access control method, and access control program
The access control system uses unique information generation for each tag reading to authenticate and authorize access, preventing unauthorized access to target devices, thereby enhancing security.
Patent Information
- Application Number
- JP2025169385
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-07
- Publication Date
- 2025-12-11
AI Technical Summary
Existing systems using electronic tags for access control do not adequately prevent unauthorized access to target devices at intended times, allowing duplicate or unauthorized access.
An access control system that generates unique information for each reading process of an electronic tag, ensuring that access to a target device is only permitted when the unique information is acquired for the first time, using a combination of tag identification, unique information, and validation processes to authenticate and authorize access.
Prevents unauthorized access by ensuring that each access to a target device is validated uniquely, thereby enhancing security and preventing duplicate or unauthorized access attempts.
Smart Images

Figure 2025182087000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an access control system, an access control method, and an access control program. [Background technology]
[0002] In recent years, near-field wireless communication using electronic tags such as NFC (Near Field Communication) tags has been utilized in a wide variety of fields. For example, an electronic tag is attached to an advertising poster, a product, or the vicinity thereof, and by bringing an information terminal such as a smartphone close to the electronic tag, it is possible to display a web page that contains information about the product, such as an advertisement. For example, Patent Document 1 discloses a technology for managing such electronic tags. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-250934 Summary of the Invention [Problem to be solved by the invention]
[0004] Some services that use electronic tags may require that service users be permitted to access a web page at a specific URL when they visit a location where an electronic tag is installed. Therefore, it is desirable that access to a target device such as a server be performed at a time intended by the service provider.
[0005] An object of the present disclosure is to provide an access control system, an access control method, and an access control program that are capable of preventing unauthorized access. [Means for solving the problem]
[0006] In order to achieve the above-mentioned object, the access control system of the present disclosure comprises a system identified by a first URL, storing tag identification information and a second URL in correspondence with each other, and issuing second unique information, and an access target device identified by the second URL, wherein the system acquires the tag identification information and the first unique information from an electronic tag via a reading device, and issues the second unique information when it is determined that the first unique information is being acquired for the first time, and allows the reading device to access the access target device at the second URL corresponding to the tag identification information by adding the second unique information, and the access target device transmits the second unique information to the system, and when it receives a determination result that the second unique information is valid, allows access from the reading device, the first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time it is determined that the system is acquiring the first unique information for the first time.
[0007] In order to achieve the above-mentioned object, the access control method of the present disclosure is an access control method for an access control system including a system identified by a first URL, storing tag identification information and a second URL in correspondence with each other, and issuing second unique information, and an access target device identified by the second URL, the access control method including the steps of: the system acquiring the tag identification information and the first unique information from an electronic tag via a reading device; issuing the second unique information when it is determined that the first unique information is being acquired for the first time; causing the reading device to access the access target device of the second URL corresponding to the tag identification information by adding the second unique information; and the access target device transmitting the second unique information to the system and, when it receives a determination result that the second unique information is valid, allowing access from the reading device, wherein the first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time it is determined that the system is acquiring the first unique information for the first time.
[0008] In order to achieve the above-mentioned object, the access control program of the present disclosure is an access control program executed on a computer of an access control system including a system identified by a first URL, storing tag identification information and a second URL in correspondence with each other, and issuing second unique information, and an access target device identified by the second URL, wherein the access control program causes the computer to execute the following steps: acquiring the tag identification information and the first unique information from an electronic tag via a reading device; issuing the second unique information when it is determined that the first unique information is being acquired for the first time; causing the reading device to access the access target device of the second URL corresponding to the tag identification information by adding the second unique information; and causing the access target device to transmit the second unique information to the system and, when a determination result that the second unique information is valid, allowing access from the reading device; wherein the first unique information is unique information issued for each reading process by the reading device, and the second unique information is unique information issued each time it is determined that the system is acquiring the first unique information for the first time. [Effects of the Invention]
[0009] According to the access control system, access control method, and access control program of the present disclosure that use the above means, unauthorized access can be prevented. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is an overall configuration diagram of an access control system according to a first embodiment. [Figure 2] FIG. 2 is a configuration diagram of a reader and a tag management device. [Figure 3] FIG. 1 is a schematic block diagram showing the configuration of a computer. [Figure 4] FIG. 10 is an overall configuration diagram of an access control system according to a second embodiment. [Figure 5] FIG. 10 is an overall configuration diagram of an access control system according to a third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] Each embodiment of the present disclosure will be described below. In this disclosure, an "electronic tag" is also called an IC tag, an RF tag, or a wireless tag, and is a tag that uses RFID (Radio Frequency Identification) technology to read and write data on an IC chip in a tag without contact using radio waves. An "NFC tag" is one of the standards for electronic tags, and is a tag that uses a frequency of 13.56 MHz and short-range wireless communication with a communication distance of about 10 cm, which is relatively shorter than other RFIDs. In the following embodiments, an example will be described in which an NFC tag is used as the electronic tag, but the electronic tag is not limited to an NFC tag. Other electronic tags that use short-range wireless communication similar to that of an NFC tag may also be used.
[0012] [Embodiment 1] <Configuration> 1 is an overall configuration diagram of an access control system 1 according to embodiment 1. The access control system 1 includes a reader 2, a tag management device 4, a subscriber terminal 4-1, a parameter determination device 5, an access target device 6 functioning as a web server, and a one-time ID determination device 7, which are connected via a communication network such as the Internet.
[0013] The reading device 2 is an information processing terminal owned by a general customer (end user) who receives services from a contractor. The reading device 2 in this embodiment is assumed to be a smartphone, but may be other information terminals or devices such as a server, a personal computer, a tablet terminal, or a mobile phone.
[0014] The NFC tag 3 is a passive electronic tag from which information can be read by a reader 2 (information terminal). The NFC tag 3 stores, in a memory unit within an internal IC, a first URL 311 that identifies the tag management device 4 and tag identification information 312 that is associated with each NFC tag 3. The NFC tag 3 also has a function of generating first unique information 313 when a reading process is performed by the reader 2 and having the reader 2 acquire the first unique information 313. The first unique information 313 is unique information that is issued as a unique value that differs each time the reader 2 reads the NFC tag 3. In this embodiment, the first unique information 313 is a rolling code added to the first URL 311.
[0015] The tag management device 4 is an information processing terminal under the management of a service provider that provides services using a plurality of NFC tags 3. In this embodiment, the tag management device 4 is assumed to be a server, but may be other devices such as a personal computer, a smartphone, a tablet terminal, or a mobile phone. The tag management device 4 is identified by a first URL 311.
[0016] The contractor terminal 4-1 is a processing terminal of a contractor who has entered into a contract with the service provider to manage information under contract. In this embodiment, the contractor terminal 4-1 is assumed to be a personal computer, but may also be other terminals or devices such as a server, a smartphone, a tablet terminal, a mobile phone, or a smartphone.
[0017] The parameter determination device 5 has a function of managing the first unique information 313 acquired when the reading device 2 reads the NFC tag 3 as first unique information 511, and controlling access of the reading device 2 to the access target device 6. The parameter determination device 5 of this embodiment is assumed to be a server, but may also be other devices such as a personal computer, a smartphone, a tablet terminal, or a mobile phone.
[0018] The access target device 6 is, for example, a general web server identified by a second URL 432 (described later), and may be under the management of a service provider or a third party. The access target device 6 may also have a web server function as part of its functions. The access target device 6 stores so-called web page data. The web page includes content information such as text, images, and videos, as well as functions such as account authentication and settlement.
[0019] The one-time ID determination device 7 has a function of issuing second unique information 711 to the tag management device 4. The one-time ID determination device 7 also has a function of determining whether or not access to the access target device 6 is directly linked to the reading operation (reading process) of the NFC tag 3 by the reading device 2, using the second unique information 711 and an access flag 712. The access flag 712 is history data of accesses by the reading device 2 to the access target device 6, and can be, for example, a counter that counts the number of accesses, or an arbitrary value indicating "accessed." The one-time ID determination device 7 of this embodiment is assumed to be a server, but may also be other devices such as a personal computer, a smartphone, a tablet terminal, or a mobile phone.
[0020] The reading device 2, tag management device 4, contractor terminal 4-1, parameter determination device 5, access target device 6, and one-time ID determination device 7 each include some or all of an input unit, display unit, communication unit, information processing unit (control unit), and memory unit, as appropriate. The reading device 2 also has a reader function that can acquire tag information by holding it over (or in contact with or close to) an NFC tag 3. The NFC tag 3 is, for example, a sticker-type tag, and is affixed to products, posters, etc. in the contractor's store. Each component will be described in detail below.
[0021] The reading device 2 has a control unit 21, a communication unit 22, a display unit 23, and a storage unit 24. The communication unit 22 has a function of reading information from the NFC tag 3 and a function of communicating with external devices such as the tag management device 4 via wired or wireless communication. The display unit 23 displays an access screen (specifically, for example, a web page screen) of the access target device 6 identified by the second URL 432 that the tag management device 4 has linked to the tag identification information 312.
[0022] The storage unit 24 stores the reader identification information 241. The reader identification information 241 is, for example, unique information of the reader 2 or user information linked to the reader 2. The storage unit 24 stores programs such as the access control program of this embodiment.
[0023] The tag management device 4 includes a control unit 41 , a communication unit 42 , and a storage unit 43 .
[0024] The communication unit 42 has a function of acquiring tag information (first URL 311, tag identification information 312, and first unique information 313) from the reading device 2, which has read the tag information from the NFC tag 3, via the communication network. The reading device 2 acquires the first URL 311 by reading the tag information from the NFC tag 3, and accesses the tag management device 4 based on the first URL 311. The reading device 2 then transmits the tag identification information 312 and first unique information 313, which are the tag information that has been read, to the tag management device 4.
[0025] The control unit 41 has a function of referring to the storage unit 43 and transmitting the second URL 432 linked to the tag identification information 312 acquired by the communication unit 42 to the reading device 2. The control unit 41 is also capable of editing (creating, changing, deleting) the information stored in the storage unit 43.
[0026] The storage unit 43 stores information such as tag identification information 431, a second URL 432 (redirect information), and second unique information 433 in a corresponding manner. The storage unit 43 also stores programs such as the access control program of this embodiment.
[0027] <Processing flow> Next, the operation of the access control system 1 according to the first embodiment will be described with reference to Fig. 1. Note that, although a processing example in which one reader 2 performs a reading operation on an NFC tag 3 is described here, if there are multiple readers 2, the same operation is performed for each reader 2. Furthermore, the processing of each device (2, 4 to 7, 4-1) is executed by the control unit of each device (2, 4 to 7, 4-1).
[0028] In step S101, the reading device 2 acquires the first URL 311, tag identification information 312, and first unique information 313 from one NFC tag 3 using a read function for the NFC tag 3. The reading device 2 uses the acquired first URL 311 to access the tag management device 4 via the communication network. At this time, the reading device 2 transmits the tag identification information 312 and the first unique information 313 to the tag management device 4. Therefore, the tag management device 4 can acquire the tag identification information 312, the first unique information 313, etc. from the NFC tag 3 via the reading device 2.
[0029] In step S102, the tag management device 4 encrypts the first unique information 313 and transmits it to the parameter determination device 5.
[0030] In step S103, the parameter determination device 5 decodes the first unique information 313 transmitted from the tag management device 4, and determines whether the decoded first unique information 313 matches any of the multiple pieces of first unique information 511 stored in the memory unit of the parameter determination device 5. If the first unique information 313 does not match the first unique information 511, the parameter determination device 5 transmits a determination result of "valid" to the tag management device 4, and adds and stores the acquired first unique information 313 as first unique information 511 in the memory unit. If the tag management device 4 receives a determination result of "valid", it executes the process of step S104.
[0031] On the other hand, if the first unique information 313 matches the first unique information 511, the parameter determination device 5 transmits a determination result of "invalid" to the tag management device 4. When the tag management device 4 receives a determination result of "invalid", it suspends execution of the processing from step S104 onwards. When suspending the processing, the tag management device 4 transmits an output such as a display conveying an error or warning to the reading device 2, and causes it to be displayed on the display unit 23.
[0032] By performing the determination process in this manner, when the reader 2 reads the NFC tag 3 and accesses the tag management device 4, the first unique information 313 is generated for each reading process of the reader 2, and therefore a determination result of "valid" is obtained. On the other hand, if the reader 2 attempts to access the tag management device 4 by duplicating the first URL 311 and the first unique information 313 using, for example, the result of a past reading process or the result of reading by another reader 2, without performing the operation of reading the NFC tag 3, the first unique information 511 stored in the parameter determination device 5 matches the first unique information 313, and therefore a determination result of "invalid" is obtained. As a result, access to the tag management device 4 by the reader 2 that does not go through the reading process of the NFC tag 3 is determined to be unauthorized and is rejected.
[0033] In step S104, the tag management device 4 transmits a request to acquire second unique information to the one-time ID determination device 7. Upon receiving the acquisition request from the tag management device 4, the one-time ID determination device 7 issues second unique information 711 (see FIG. 3). The one-time ID determination device 7 then stores the issued second unique information 711 in a storage unit. The processing of step S104 is premised on the premise that a determination result that the first unique information 313 is "valid" has been obtained in step S103. Therefore, the second unique information 711 is unique information that is issued each time the parameter determination device 5 determines in step S103 that the first unique information 511 has been acquired for the first time.
[0034] In step S105, the one-time ID determination device 7 transmits the second unique information 711 to the tag management device 4. Therefore, when the parameter determination device 5 determines that the first unique information 313 is being obtained for the first time, the tag management device 4 can obtain the second unique information 711 from the one-time ID determination device 7.
[0035] In step S106, the tag management device 4 refers to the storage unit 43 and acquires the second URL 432 linked to the tag identification information 312 (431) acquired from the reading device 2. The tag management device 4 accesses the access target device 6 identified by the second URL 432 corresponding to the tag identification information 431. At this time, the second unique information 433 is added to the second URL 432 (i.e., a URL including the second URL 432 and the second unique information 433) and transmitted to the access target device 6.
[0036] Alternatively, after step S105, the tag management device 4 transmits the second URL 432 and the second unique information 433 to the reading device 2. Thereafter, the reading device 2 may be configured to access the access target device 6 as the redirect destination using the second URL 432 acquired from the tag management device 4.
[0037] In step S107, the access target device 6 transmits the second unique information 433 received from the tag management device 4 (or the reader 2) to the one-time ID determination device 7.
[0038] In step S108, the one-time ID determination device 7 determines whether the second unique information 433 transmitted from the tag management device 4 matches any of the multiple pieces of second unique information 711 stored in the memory unit of the one-time ID determination device 7. If the second unique information 433 matches the second unique information 711 and the access flag 712 corresponding to the second unique information 433 used in the determination indicates the first (or initial) reference, the one-time ID determination device 7 transmits a determination result of "valid" to the access target device 6 and sets the access flag 712 to "referenced" (or increments the count by one if it indicates the number of references). If the access target device 6 receives a determination result of "valid," it permits access from the reading device 2 and displays information such as a web page on the display unit 23 of the reading device 2 via the tag management device 4 or directly.
[0039] On the other hand, if the second unique information 433 does not match the second unique information 711, or if the second unique information 433 matches the second unique information 711 and the access flag 712 corresponding to the second unique information 711 used in the determination indicates that it has been referenced (or that it has been referenced two or more times), the one-time ID determination device 7 transmits a determination result of "invalid" to the access target device 6. Whether the access flag 712 indicates that it has been referenced two or more times can be determined based on whether the access flag 712 is 1 or greater, or whether the access flag 712 has a value indicating "referenced" or "accessed." If the access target device 6 receives a determination result of "invalid," it rejects access from the reading device 2 and suspends execution of subsequent processing. When suspending processing, the access target device 6 transmits an output, such as a display conveying an error or warning, to the reading device 2 to display it on the display unit 23. In this way, when the one-time ID determination device 7 determines that the second unique information 433 sent by the access target device 6 is being obtained for the first time, it allows the tag management device 4 and the reading device 2 to access the access target device 6.
[0040] (program) 3 is a schematic block diagram showing the configuration of the computer 101. The computer 101 includes a CPU 102, a main storage device 103, an auxiliary storage device 104, and an interface 105. The CPU 102 may be a GPU.
[0041] Here, a detailed description will be given of the programs for realizing the functions constituting the tag management device 4 according to the first embodiment. The same applies to the programs of the tag management devices 4 according to the second and third embodiments.
[0042] The reading device 2, tag management device 4, customer terminal 4-1, parameter determination device 5, access target device 6 functioning as a web server, and one-time ID determination device 7 of this embodiment are implemented in a computer 101. A reading timing management device 8 (embodiment 2) and an access time management device 9 (embodiment 3), which will be described later, are also implemented in the computer 101. The operations of the components of the devices 2, 4, 4-1, 5 to 9 are stored in the auxiliary storage device 104 in the form of a program. The CPU 102 reads the program from the auxiliary storage device 104 and loads it into the main storage device 103, and executes the above-mentioned processing in accordance with the program. The CPU 102 also allocates storage areas in the main storage device 103 corresponding to the above-mentioned storage units in accordance with the program.
[0043] Specifically, the program includes a program for causing a computer 101 to execute the following steps: acquiring tag identification information 312 and first unique information 313 from an NFC tag 3 (electronic tag) via a reading device 2; acquiring second unique information 433 from a one-time ID determination device 7 when the parameter determination device 5 determines that the first unique information 313 is being acquired for the first time; accessing the access target device 6 of the second URL 432 corresponding to the tag identification information 312 by adding the second unique information 433 to the second URL 432; and permitting access to the access target device 6 by the tag management device 4 and the reading device 2 when the one-time ID determination device 7 determines that the second unique information 433 sent by the access target device 6 is being acquired for the first time.
[0044] The auxiliary storage device 104 is an example of a non-transitory tangible storage medium. Other examples of non-transitory tangible storage media include storage media such as magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, and semiconductor memories connected via the interface 105.
[0045] The program may also be a program for realizing some of the above-described functions. Furthermore, the program may be a so-called differential file (differential program) that realizes the above-described functions in combination with another program already stored in the auxiliary storage device 104.
[0046] [Embodiment 2] Next, an access control system 1A according to embodiment 2 will be described. Fig. 4 is a diagram showing the overall configuration of the access control system 1A according to embodiment 2. In the description of the access control system 1A, components similar to those in the access control system 1 according to embodiment 1 will be denoted by the same reference numerals, and the description thereof will be omitted or simplified.
[0047] The access control system 1A further includes a read timing management device 8 in addition to the reading device 2, tag management device 4, parameter determination device 5, access target device 6, and one-time ID determination device 7 described in the first embodiment. The read timing management device 8 stores tag identification information 811 and the reading time 812 of the tag identification information 312 by the reading device 2.
[0048] Next, a description will be given of the operation of the access control system 1A according to embodiment 2. The access control system 1A further includes processing of steps S111 and S112 in addition to the processing of the access control system 1. Furthermore, step S101′ performs processing that is almost the same as step S101, and details will be described below.
[0049] First, in step S101′, the reading device 2 acquires tag information (first URL 311, tag identification information 312, and first unique information 313) from the NFC tag 3. The reading device 2 accesses the tag management device 4 via the communication network using the first URL 311 included in the acquired tag information. At this time, the reading device 2 transmits the tag identification information 312, the first unique information 313, the read time of the NFC tag 3, and the user attribute information of the reading device 2 to the tag management device 4. Therefore, the tag management device 4 can acquire the tag identification information 312, the first unique information 313, the read time, etc. from the NFC tag 3 via the reading device 2. The read time can be acquired from the local time (for example, an internal clock) of the reading device 2. Alternatively, the read time may be acquired from the local time (for example, an internal clock) of the tag management device 4. After the processing of step S101′, the processing of step S111 is performed.
[0050] In step S111, the tag management device 4 transmits the time at which the reader 2 reads the NFC tag 3 to the read timing management device 8. Upon receiving the tag identification information 312 and the read time from the tag management device 4, the read timing management device 8 stores them in an internal storage unit as tag identification information 811 and read time 812, respectively.
[0051] In step S112, the read timing control device 8 refers to the storage unit and searches whether tag identification information 811 identical to the currently acquired tag identification information 312 is registered. If tag identification information 811 identical to the currently acquired tag identification information 312 is registered, the read timing control device 8 determines whether a predetermined time has passed since the time taken by the reader 2 to read the currently acquired tag identification information 312 from the most recently acquired tag identification information 811. If the read timing control device 8 determines that the predetermined time has passed, it transmits a determination result of "valid" (or access "permitted") to the tag management device 4. If the read timing control device 8 determines that the access is "valid," the processes from step S102 onwards described above are then executed.
[0052] On the other hand, if the reading timing control device 8 determines that the above-mentioned predetermined time has not elapsed, it transmits the determination result of "invalid" (or access "rejected") to the tag management device 4. Thereafter, execution of subsequent processing is suspended. When suspending processing, the tag management device 4 transmits an output such as a display conveying an error or warning to the reading device 2, and causes it to be displayed on the display unit 23.
[0053] In this way, the tag management device 4 is permitted to access the access target device 6 if the time taken by the reader 2 to read the currently acquired tag identification information 312 has elapsed a predetermined time since the time taken by the reader 2 to read the most recently acquired tag identification information 431. The predetermined time used in the determination process of step S112 can be set in advance, dynamically, or according to the type of service. The predetermined time used in the determination of step S112 may be set as an elapsed time in units of, for example, days, hours, minutes, or seconds. Alternatively, the predetermined time elapsed may be set as a predetermined absolute time, such as whether 12 o'clock has passed or midnight has passed.
[0054] The access control system 1A of the second embodiment can be configured, for example, so that an NFC tag 3 is installed in a restaurant, and a customer brings the reader 2 close to or touches the NFC tag 3, causing the reader 2 to access the access target device 6 for awarding point data. In this case, the access control system 1A can deny the reader 2 from accessing the access target device 6 multiple times unless a predetermined time has elapsed since the reader 2 began reading the NFC tag 3. This can prevent points from being awarded multiple times for a single meal (e.g., breakfast, lunch, or dinner) that exceeds the number of visits to the restaurant. This allows a contractor to use the access control system 1A to provide the intended service of awarding points to customers for each visit.
[0055] [Embodiment 3] Next, an access control system 1B according to embodiment 3 will be described. Fig. 5 is a diagram showing the overall configuration of the access control system 1B according to embodiment 3. In the description of the access control system 1B, components similar to those in the access control system 1 according to embodiment 1 will be denoted by the same reference numerals, and the description thereof will be omitted or simplified.
[0056] The access control system 1B further includes an access time management device 9 in addition to the reading device 2, tag management device 4, parameter determination device 5, access target device 6, and one-time ID determination device 7 described in the first embodiment. The access time management device 9 stores access time 911 of the access target device 6 by the reading device 2 and reading device identification information 912 of the reading device 2. The access time management device 9 of this embodiment is installed corresponding to the access target device 6.
[0057] Next, a description will be given of the operation of the access control system 1B according to embodiment 3. The access control system 1B further includes the processes of steps S121 and S122 in addition to the processes of the access control system 1.
[0058] In step S101", the reading device 2 acquires the first URL 311, tag identification information 312, and first unique information 313 from one NFC tag 3. The reading device 2 uses the acquired first URL 311 to access the tag management device 4 via the communication network. At this time, the reading device 2 transmits the tag identification information 312, the first unique information 313, and reading device identification information 241 (see Figure 2) to the tag management device 4.
[0059] Furthermore, in step S106′ which is executed after the processing of step S105, the tag management device 4 refers to the storage unit 43 and acquires the second URL 432 linked to the tag identification information 312 acquired from the reading device 2. The tag management device 4 accesses the access target device 6 of the second URL 432 corresponding to the tag identification information 312 by adding second unique information 711 to the second URL 432. Furthermore, in step S106′, the tag management device 4 transmits the reading device identification information 241 (see FIG. 2 ) of the reading device 2 to the access target device 6.
[0060] Next, the processes of steps S107 and S108 are performed. If the access target device 6 receives a determination result of "valid" in step S108, the process of step S121 is performed. On the other hand, if the access target device 6 receives a determination result of "invalid", the same process as in the first embodiment is performed, and access from the reading device 2 to the access target device 6 is denied.
[0061] In step S121, the access target device 6 transmits the access time from the tag management device 4 or the reader 2 and the reader identification information 241 of the reader 2 to the access time management device 9, and these are stored in the memory of the access time management device 9 as the access time 911 and the reader identification information 912, respectively. Note that if the memory of the access time management device 9 stores the reader identification information 241 of the currently accessed reader 2, the access time management device 9 updates the access time 911. Note that if this is the first time that the reader 2 has read the NFC tag 3, the access time management device 9 stores the reader identification information 241 of the currently accessing reader 2 as the reader identification information 912.
[0062] In step S122, the access time management device 9 refers to the storage unit and searches the reader identification information 912 for the reader identification information 241 of the currently accessing reader 2. If the same reader identification information 912 as the reader identification information 241 is registered, the access time management device 9 determines whether a predetermined time has elapsed since the last access attempt by the reader 2 to the access target device 6. If the access time management device 9 determines that the predetermined time has not elapsed, it transmits a determination result of "valid" (or access "permitted") to the access target device 6. If the access time management device determines that the access is "valid," it permits access from the reader 2 and causes the display unit 23 of the reader 2 to display information such as a web page on the reader 2 via the tag management device 4 or directly.
[0063] It should be noted that the access time management device 9 also transmits the determination result of "valid" (or access "permitted") to the access target device 6 when the reading device 2 reads the NFC tag 3 for the first time.
[0064] On the other hand, if the access time management device 9 determines that the above-mentioned predetermined time has elapsed, it transmits a determination result of "invalid" (or access "rejected") to the access target device 6. Thereafter, execution of subsequent processing is suspended. When suspending processing, the access target device 6 transmits an output such as a display conveying an error or warning to the reading device 2 via the tag management device 4, for example, and causes the display unit 23 to display it.
[0065] In this way, when the reader 2 attempts to access the access target device 6 for the second or subsequent time without reading the NFC tag 3, if the current access attempt time to the access target device 6 has not elapsed a predetermined time since the last access attempt time to the access target device 6 via the NFC tag 3 reading process, access to the access target device 6 is permitted. The predetermined time used in the determination process of step S122 can be set in advance, dynamically, or according to the type of service. The predetermined time used in step S122 may be set as an elapsed time in units of, for example, days, hours, minutes, or seconds. Alternatively, the predetermined time elapsed may be set as a predetermined absolute time, such as when 12 o'clock or midnight has passed.
[0066] In the access control system 1B of embodiment 3, for example, an NFC tag 3 is installed at a golf course or a destination far from home, and a visitor brings the reading device 2 close to or touches the NFC tag 3, thereby limiting the locations from which the reading device 2 can access a web page, or permitting access to a specific web page only at a specified time or on the condition that the visitor must visit a specific location.
[0067] Although several embodiments of the present disclosure have been described above, these embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and modifications are intended to be included in the scope of the inventions and their equivalents as defined in the claims, as well as in the scope and spirit of the inventions.
[0068] For example, the tag management device 4, parameter determination device 5, access target device 6, one-time ID determination device 7, read timing management device 8, and access time management device 9 are each configured as separate devices, but some of them may also be configured as a single device or system.
[0069] The access time management device 9 described in the third embodiment may be communicably connected to another access target device 6 (not shown). In this case, the access time management device 9 may store the second URL (452) of the access target device 6 in association with the access time 911 and the reading device identification information 912 in the storage unit.
[0070] Furthermore, in step S121, if the reading device identification information 241 (912) of the currently accessed reading device 2 is stored in the storage unit of the access time management device 9, the access time 911 and the reading device identification information 912 may not be stored (i.e., rewritten or updated). Therefore, the access time 911 in this case is the time when the reading device 2 first accessed the access target device 6. In this way, the reading device 2 can access the access target device 6 multiple times using the second URL 432, or the second URL 432 and the second unique information 433, for a predetermined time or period after first reading the NFC tag 3 and accessing the access target device 6, without performing a read operation on the NFC tag 3 again.
[0071] Furthermore, the system configurations shown in the first to third embodiments may be arbitrarily combined. For example, the access control system may be configured to include the read timing management device 8 described in the second embodiment and the access time management device 9 described in the third embodiment.
[0072] The present disclosure includes, for example, the following aspects. [1] a tag management device that is specified by a first URL and stores tag identification information and a second URL in association with each other; a parameter determination device; an access target device identified by the second URL; a one-time ID determination device that issues second unique information to the tag management device; Equipped with The tag management device acquiring the tag identification information and the first unique information from the electronic tag via a reader; When the parameter determination device determines that the first unique information has been acquired for the first time, the second unique information is acquired from the one-time ID determination device; accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; when the one-time ID determination device determines that the second unique information transmitted by the access target device is acquired for the first time, access to the access target device by the tag management device and the reading device is permitted; the first unique information is unique information issued for each reading process by the reading device, the second unique information is unique information that is issued each time the parameter determination device determines that it is the first time that the first unique information has been acquired; Access control system. [2] a read timing management device that stores the tag identification information and the time at which the tag identification information is read by the reader; the tag management device is permitted to access the access target device when a predetermined time has elapsed since the time when the tag identification information currently acquired by the reader was read by the reader, and [1] The access control system according to [1]. [3] an access time management device that stores an access time of the access target device by the reading device and reading device identification information of the reading device; When the reading device attempts to access the access target device for the second or subsequent time without going through the reading process of the electronic tag, if the current access attempt time to the access target device has not elapsed a predetermined time since the last access attempt time to the access target device via the reading process of the electronic tag, access to the access target device is permitted. [1] The access control system according to [1]. [4] a tag management device that is specified by a first URL and stores tag identification information and a second URL in association with each other; a parameter determination device; an access target device identified by the second URL; a one-time ID determination device that issues second unique information to the tag management device; An access control method for an access control system comprising: The tag management device acquiring the tag identification information and the first unique information from the electronic tag via a reader; acquiring the second unique information from the one-time ID determination device when the parameter determination device determines that the first unique information has been acquired for the first time; accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; a step of permitting access to the access target device by the tag management device and the reader device when the one-time ID determination device determines that the second unique information transmitted by the access target device is acquired for the first time; Including, the first unique information is unique information issued for each reading process by the reading device, the second unique information is unique information that is issued each time the parameter determination device determines that it is the first time that the first unique information has been acquired; Access control methods. [5] a tag management device that is specified by a first URL and stores tag identification information and a second URL in association with each other; a parameter determination device; an access target device identified by the second URL; a one-time ID determination device that issues second unique information to the tag management device; An access control program executed on a computer of an access control system comprising: The access control program acquiring the tag identification information and the first unique information from the electronic tag via a reader; acquiring the second unique information from the one-time ID determination device when the parameter determination device determines that the first unique information has been acquired for the first time; accessing the access target device of the second URL corresponding to the tag identification information by adding the second unique information to the second URL; a step of permitting access to the access target device by the tag management device and the reader device when the one-time ID determination device determines that the second unique information transmitted by the access target device is acquired for the first time; on the computer, the first unique information is unique information issued for each reading process by the reading device, the second unique information is unique information that is issued each time the parameter determination device determines that it is the first time that the first unique information has been acquired; Access control programs. [Explanation of symbols]
[0073] 1,1A,1B Access Control System 2. Reading device 3. NFC Tags 4. Tag management device 4-1 Subscriber terminal 5 Parameter determination device 6. Access target device 7 One-time ID identification device 8. Reading timing control device 9. Access Time Management Device 21 Control section 22 Communications Department 23 Display section 24 Memory section 41 Control Unit 42 Communications Department 43 Storage section 101 Computer 102 CPU 103 Main storage 104 Auxiliary storage 105 Interface 241 Reader identification information 311 First URL 312 Tag Identification Information 313 First unique information 431 Tag Identification Information 432 Secondary URL 433 Second unique information 511 First unique information 711 Second unique information 712 Access Flags 811 Tag Identification Information 812 reading times 911 Access Time 912 Reader identification information
Claims
1. a system that is specified by a first URL, stores tag identification information and a second URL in association with each other, and issues second unique information; an access target device identified by the second URL; Equipped with The system comprises: acquiring the tag identification information and the first unique information from the electronic tag via a reader; issuing the second unique information when it is determined that the first unique information has been acquired for the first time; causing the reading device to access the access target device at the second URL corresponding to the tag identification information by adding the second unique information; the access target device transmits the second unique information to the system, and when receiving a determination result that the second unique information is valid, permits access from the reading device; the first unique information is unique information issued for each reading process by the reading device, The second unique information is unique information that is issued each time it is determined that the system has acquired the first unique information for the first time. Access control system.
2. The access control system according to claim 1 , wherein the access target device permits access from the reading device when it is determined that the second unique information has been acquired for the first time.
3. a system that is specified by a first URL, stores tag identification information and a second URL in association with each other, and issues second unique information; an access target device identified by the second URL; An access control method for an access control system comprising: The system comprises: acquiring the tag identification information and the first unique information from the electronic tag via a reader; issuing the second unique information when it is determined that the first unique information has been acquired for the first time; a step of causing the reading device to access the access target device of the second URL corresponding to the tag identification information by adding the second unique information; a step of transmitting the second unique information to the system by the access target device, and permitting access from the reading device when a determination result that the second unique information is valid is received; Including, the first unique information is unique information issued for each reading process by the reading device, The second unique information is unique information that is issued each time it is determined that the system has acquired the first unique information for the first time. Access control methods.
4. a system that is specified by a first URL, stores tag identification information and a second URL in association with each other, and issues second unique information; an access target device identified by the second URL; An access control program executed on a computer of an access control system comprising: The access control program acquiring the tag identification information and the first unique information from the electronic tag via a reader; issuing the second unique information when it is determined that the first unique information has been acquired for the first time; a step of causing the reading device to access the access target device of the second URL corresponding to the tag identification information by adding the second unique information; a step of causing the access target device to transmit the second unique information to the system, and permitting access from the reading device when a determination result that the second unique information is valid is received; on the computer, the first unique information is unique information issued for each reading process by the reading device, The second unique information is unique information that is issued each time it is determined that the system has acquired the first unique information for the first time. Access control programs.
Citation Information
Patent Citations
Management server, information distribution system, application program and registration terminal
JP2013250934A