Service providing system, automatic transaction apparatus, and communication control method
By increasing the radio wave strength of advertising signals upon user interaction and authenticating with hash data, the system securely establishes Bluetooth Low Energy communication with the appropriate user terminal, addressing vulnerabilities in conventional ATM communication methods.
Patent Information
- Application Number
- JP2024099924
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-20
- Publication Date
- 2026-01-08
AI Technical Summary
Conventional methods for establishing wireless communication at ATMs without a cash card are vulnerable to unauthorized connections, as interfering parties can detect and connect before the legitimate user, compromising security and transaction integrity.
The system employs a user terminal and ATM that utilize Bluetooth Low Energy (BLE) communication, where the ATM increases the radio wave strength of an advertising signal upon detecting a user operation, allowing the terminal to identify the connection partner based on radio wave strength and authenticate using hash data, ensuring secure communication with the appropriate user terminal.
This approach ensures secure and reliable wireless communication with the intended user terminal, preventing unauthorized connections and maintaining transaction security by authenticating through hash data verification, thus enhancing the security and efficiency of deposit and withdrawal transactions.
Smart Images

Figure 2026002157000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a service providing system, an automated transaction device, and a communication control method. [Background technology]
[0002] Conventionally, there has been an increase in services that allow users to perform transactions such as deposits and withdrawals at automated teller machines (ATMs) without using a cash card. When depositing or withdrawing money without using a cash card, a user terminal and the ATM are connected via wireless communication such as Bluetooth (registered trademark), and user data and transaction details are sent and received.
[0003] Patent Document 1 discloses a technology for preventing wireless communication with unauthorized destinations. It states, "It is possible to effectively avoid invalid connection requests from unspecified information terminals to a wireless communication device." It also states, "One aspect of the present invention is a wireless communication device that transfers data via a wireless link with a specific information terminal among multiple information terminals. When a connection request is received from one of the multiple information terminals, the device determines whether the connection request is valid from the specific information terminal or invalid from other unspecified information terminals, and generates and stores statistical information indicating the occurrence status of the connection requests that are determined to be invalid. The statistical information is then compared with a preset avoidance condition, and if the statistical information satisfies the avoidance condition, an avoidance process is performed to avoid the connection request from the unspecified information terminal." [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Publication No. 2022-123675 Summary of the Invention [Problem to be solved by the invention]
[0005] In the conventional technology, in order to prevent connections by an interfering party, the transmission power value of the advertising packet is gradually reduced so that only the nearest terminal can connect. However, even when the conventional technology is used, there may be cases where another user or an interfering party detects the advertising signal and connects before the legitimate user can establish a connection. Therefore, an object of the present invention is to establish wireless communication with an appropriate user terminal. [Means for solving the problem]
[0006] In order to achieve the above-mentioned object, one representative deposit and withdrawal transaction system of the present invention comprises a first terminal that provides services to an unspecified number of users, and a user terminal that performs first wireless communication with the first terminal, which is communication using a first wireless communication method, wherein the first terminal periodically transmits an advertising signal for the first wireless communication, the first terminal increases the radio wave strength of the advertising signal when it detects a predetermined operation by the user, the user terminal scans the advertising signal, the user terminal identifies a connection partner based on the value of the radio wave strength of the advertising signal and / or changes in the radio wave strength, and the user terminal establishes the first wireless communication with the first terminal by responding to the advertising signal transmitted by the first terminal identified as the connection partner. Furthermore, one representative automatic transaction device of the present invention comprises a currency storage vault for storing currency, a first wireless communication unit for performing first wireless communication with the first terminal, which is communication using a first wireless communication method, and an operation reception unit for receiving a predetermined operation from a user, wherein the first wireless communication unit periodically transmits an advertising signal, increases the radio wave strength of the advertising signal when the predetermined operation is received, and establishes the first wireless communication with the user terminal that receives the advertising signal, and the currency storage vault performs deposit and withdrawal of currency based on the data received via the first wireless communication. Furthermore, one representative communication control method of the present invention is a communication control method in a service providing system having a first terminal that provides services to an unspecified number of users and a user terminal that performs first wireless communication with the user terminal, which is communication using a first wireless communication method, and is characterized by including the steps of: the first terminal periodically transmitting an advertising signal for the first wireless communication; the first terminal detecting a predetermined operation by the user and increasing the radio wave strength of the advertising signal; the user terminal scanning the advertising signal; the user terminal identifying a connection partner based on the value of the radio wave strength of the advertising signal and / or changes in the radio wave strength; and the user terminal establishing the first wireless communication with the first terminal by responding to the advertising signal transmitted by the first terminal identified as the connection partner. [Effects of the Invention]
[0007] According to the present invention, wireless communication can be established with an appropriate user terminal. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is an explanatory diagram of a communication connection according to an embodiment; [Figure 2] System configuration diagram [Figure 3] ATM configuration diagram [Figure 4] User device configuration diagram [Figure 5] Flowchart showing an example of a processing procedure of an ATM [Figure 6] Flowchart showing the processing steps of the user terminal [Figure 7] Communication connection sequence diagram DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, an embodiment will be described with reference to the drawings. [Example]
[0010] FIG. 1 is an explanatory diagram of communication connections according to an embodiment. The user terminal 10 is a mobile terminal, such as a smartphone or tablet terminal, carried by a user who is an operator. By executing a predetermined application, the user terminal 10 communicates with an Internet transaction server and can perform Internet banking. A cash card is not required for this Internet banking. If the Internet banking transaction is, for example, a transfer, the user terminal 10 can complete the transaction by communicating with the Internet transaction server. However, when performing a transaction involving the deposit or withdrawal of currency (deposit / withdrawal transaction), such as depositing money into an account or withdrawing money from an account, the user terminal 10 must be linked to an automated teller machine such as an ATM 20 or a cash dispenser.
[0011] The user terminal 10 and the ATM 20 communicate with each other when conducting deposit and withdrawal transactions. For communication related to deposit and withdrawal transactions, a protocol that identifies a connection partner, establishes a connection, and enables bidirectional data communication is desirable. For example, Bluetooth (registered trademark), BLE (Bluetooth Low Energy), UWB (Ultra-Wide Band), etc. are suitable. In this embodiment, an example will be described in which BLE is used for communication related to deposit and withdrawal transactions.
[0012] In BLE, when in a connection standby state, an advertising packet (advertising signal) is sent to the surrounding area, and by pairing with the communication partner that receives the advertising packet, the connection partner is identified and a connection is established.
[0013] Here, if a plurality of ATMs 20 are installed in close proximity, advertising packets will be transmitted from the plurality of ATMs 20, and the user terminal 10 will need to select which ATM 20 to connect to. Similarly, when the ATM 20 receives responses to the advertising packet from a plurality of user terminals 10, it becomes necessary to select which user terminal 10 to connect to. The ATM 20 sequentially provides service to an unspecified number of user terminals 10, but does not simultaneously provide service to multiple user terminals 10. In other words, if there are responses from multiple user terminals 10, it is possible that some of the responses are from the wrong user's terminal or the terminal of an interfering party.
[0014] Therefore, in this embodiment, the ATM 20 receives a predetermined operation from the user and increases the radio wave strength of the advertising signal, and the user terminal 10 identifies a connection partner based on the radio wave strength of the advertising signal. The predetermined operation may be, for example, an operation of bringing the user terminal 10 close to the ATM 20 and establishing near field communication (NFC). The predetermined operation may also be an operation such as pressing a button for starting a linked transaction on the operation screen of the ATM.
[0015] For example, the user terminal 10 responds to the advertising signal with the highest radio wave intensity among multiple advertising signals and establishes a connection with that ATM 20. Because the communication distance of NFC is significantly shorter than that of BLE, if an ATM 20 detects an NFC RF (Radio Frequency) signal and increases its radio wave intensity, the radio wave intensity of the advertising signal from this ATM 20 will be stronger than the radio wave intensity of advertising signals from other ATMs 20. This difference in radio wave intensity is significant even when taking into account changes due to the user terminal 10 approaching the ATM 20. Therefore, by responding to the advertising signal with the highest radio wave intensity, the user terminal 10 can reliably establish a BLE communication connection with the target ATM 20.
[0016] The user terminal 10 may also use a change in the radio wave strength of the advertising signal as a basis for the determination. By responding to an advertising signal whose radio wave strength increases after NFC communication occurs, the user terminal 10 can reliably establish a connection for BLE communication with the target ATM 20.
[0017] The ATM 20 can transmit authentication information, which is data for authentication, to the user terminal 10 via NFC. Before accepting a predetermined operation, the ATM 20 periodically transmits a weak advertising signal to notify its presence to those around it, but BLE connection is not permitted. After accepting a predetermined operation, the ATM 20 transmits a strong advertising signal and enters a state in which BLE connection is permitted. In this state, if there is a response to the advertising signal, the ATM 20 establishes BLE communication. If there are responses from multiple user terminals 10, the ATM 20 establishes BLE communication with the multiple user terminals 10. After that, if the ATM 20 receives response data corresponding to the authentication information transmitted via NFC from any one of the user terminals 10 via BLE communication, it continues BLE communication with that user terminal 10 and terminates BLE communication with the other user terminals 10.
[0018] That is, the user terminal 10 selects an appropriate BLE connection destination from among the multiple ATMs 20 based on the radio wave intensity of the advertising signal. Then, the ATM 20 selects an appropriate BLE connection destination from among the multiple user terminals 10 based on the authentication information transmitted by NFC.
[0019] The authentication information will now be described. The ATM 20 holds ATM data that associates the ATM ID, which is its own identification information, with information unique to the ATM. The information unique to the ATM can be, for example, a serial number. The ATM 20 generates hash data H1 and hash data H2 from the information unique to the ATM. The ATM 20 then transmits the ATM ID and hash data H1 to the user terminal 10 as authentication information. The hash data H2 is not transmitted to the user terminal 10 but is held therein.
[0020] The user terminal 10 or a higher-level device capable of communicating with the user terminal 10 identifies information unique to the ATM from the received ATMID and generates hash data H1 and hash data H2. The user terminal 10 or the higher-level device compares the generated hash data H1 with the received hash data H1 to verify whether the sender of the authentication information is a legitimate ATM. For convenience, a verification result indicating a legitimate ATM is referred to as "OK." If the verification result is "OK," the user terminal 10 transmits the generated hash data H2 as response data to the ATM 20 via BLE communication. The ATM 20 authenticates the user terminal 10 by comparing the hash data H2 stored in its own device with the hash data H2 received from the user terminal 10. If the hash data H2 match during authentication, it can be confirmed that the user terminal 10 that sent the authentication information is the same as the user terminal 10 that returned the response data.
[0021] 1, the ATMs 20a, 20b, and 20c each transmit a weak advertising signal. The user terminal 10 is located away from each ATM and detects the weak advertising signal from each ATM by scanning the advertising signal, but does not establish a BLE connection with any of the ATMs.
[0022] Thereafter, when the user brings the user terminal 10 close to the ATM 20b and establishes NFC communication between the user terminal 10 and the ATM 20, the ATM 20b increases the radio wave strength of the advertising signal. The radio wave strength of the advertising signal received by the user terminal 10 is the strongest from the ATM 20b, while the radio wave strength of the advertising signals from the ATM 20a and the ATM 20c remains weak. This allows the user terminal 10 to identify the ATM 20b as the BLE connection destination.
[0023] The user terminal 10 and ATM 20b use BLE to perform deposit and withdrawal transactions. The BLE pairing is disconnected at the end of one transaction. That is, even if the user terminal 10 performs multiple transactions in cooperation with the same ATM 20b, the BLE pairing is released when one transaction is completed, and the user starts over from the specified operation when performing the next transaction. If the user terminal 10 and ATM 20b unintentionally continue to communicate with each other after a transaction, there is a risk of unauthorized use by a third party, but this risk can be avoided by severing the pairing after each transaction. Also, since operators of the ATM 20b generally change frequently, continuing the communication connection between the user terminal 10 and ATM 20b after a transaction could hinder use by the next operator, but severing the pairing after each transaction allows for a smooth change of operator.
[0024] 2 is an explanatory diagram of the system configuration. The service providing system includes a user terminal 10, an ATM 20, and a server 50. The server 50 is a higher-level device that can communicate with the user terminal 10 via the Internet or the like. The server 50 includes a storage unit 51, a hash data generation unit 53, and a hash data verification unit 54 therein.
[0025] The storage unit 51 stores user data 52a and ATM data 52b. The user data 52a includes a user name and identification information of the user terminal 10. The ATM data 52b includes an ATMID, which is identification information of the ATM 20, and information unique to the ATM. The information unique to the ATM is, for example, a serial number, and is the same information as the unique information stored in the ATM 20.
[0026] When the hash data generation unit 53 receives the ATMID of the ATM 20 and the hash data H1 from the user terminal 10, it refers to the ATM data 52b based on the ATMID to identify information unique to the ATM 20. The hash data generation unit 53 generates hash data H1 and hash data H2 from the identified information.
[0027] The hash data verification unit 54 verifies whether the sender of the authentication information is a legitimate ATM by comparing the hash data H1 generated by the hash data generation unit 53 with the hash data H1 received from the user terminal 10. If the verification result indicates that the ATM is legitimate, the verification result is determined to be "OK." The hash data verification unit 54 transmits the verification result and the hash data H2 generated by the hash data generation unit 53 to the user terminal 10.
[0028] 3 is a configuration diagram of the ATM 20. The ATM 20 has a control unit 21, an accounting system communication unit 22, a display unit 23, an operation unit 24, a BLE communication unit 25, an NFC communication unit 26, a camera 27, a proximity sensor 28, a memory unit 29, a currency storage vault 30, and a card reader 31.
[0029] The accounting system communication unit 22 is an interface that communicates with the accounting system transaction server via the accounting system network. The display unit 23 is a device that displays and outputs various information to the operator, and is, for example, a liquid crystal display. The operation unit 24 is a device that accepts operations by an operator, and is, for example, a touch panel.
[0030] The BLE communication unit 25 is an interface that communicates with the user terminal 10 and the like using BLE. The NFC communication unit 26 is an interface that communicates with the user terminal 10 and the like via NFC. The camera 27 is an imaging device installed so as to be able to capture an image of a person operating the ATM 20 . The approach sensor 28 is a sensor that detects the approach of an operator.
[0031] The storage unit 29 stores various data related to the operation of the ATM 20. The data stored in the storage unit 29 includes ATM data and a refusal list. The ATM data is data in which an ATMID, which is identification information that uniquely identifies the ATM 20, is associated with information specific to the ATM 20. The rejection list is a list that registers the identification information of devices that have communicated with BLE but failed authentication.
[0032] The currency storage vault 30 stores coins and notes by denomination and manages the inventory. When a deposit is received, the currency storage vault 30 updates the inventory and notifies the control unit 21 of the amount of the deposit. The currency storage vault 30 also dispenses the amount specified by the control unit 21 and updates the inventory. The card reader 31 accepts a cash card, reads card data from the cash card, and transmits the card data to the control unit 21.
[0033] The control unit 21 controls the operation of the ATM 20. The control unit 21 may be configured to realize various functions by, for example, a CPU (Central Processing Unit) executing a predetermined program.
[0034] The control unit 21 includes a transaction processing unit 21a, a BLE communication management unit 21b, a hash data generation unit 21c, and a hash data authentication unit 21d. The transaction processing unit 21a is a processing unit that performs various transactions. The transactions performed by the transaction processing unit 21a include normal transactions and terminal-linked transactions. In a normal transaction, the transaction processing unit 21a determines the transaction contents based on the card data read by the card reader 31 and the operation contents accepted by the operation unit 24, and processes the transaction by communicating with the accounting transaction server.Normal transactions include transfers, deposits, withdrawals, and balance inquiries.For convenience, operations to perform normal transactions are called normal transaction operations.
[0035] In a terminal-linked transaction, the transaction processing unit 21a processes the transaction based on data received from the user terminal 10 via BLE. Terminal-linked transactions include deposits and withdrawals. For convenience, the operation of conducting a terminal-linked transaction is referred to as a terminal-linked transaction operation.
[0036] The BLE communication management unit 21b is a processing unit that manages communication by the BLE communication unit 25. The BLE communication management unit 21b periodically transmits an advertising signal with a "weak" radio wave strength and a "not possible" connection until a predetermined operation is received. Once the BLE communication management unit 21b receives a predetermined operation, it switches the radio wave strength to "strong" and the connection to "permitted" and periodically transmits an advertising signal. The predetermined operation is an operation of bringing the user terminal 10 close to the ATM 20 to perform NFC, and the BLE communication management unit 21b determines that the predetermined operation has been performed when the NFC communication unit 26 detects the user terminal 10. When the BLE communication management unit 21b receives a notification from the hash data authentication unit 21d that the user terminal 10 has been successfully authenticated, the BLE communication management unit 21b continues BLE communication with the successfully authenticated user terminal 10 and disconnects BLE communication with any user terminal other than the successfully authenticated user terminal 10. Furthermore, the BLE communication management unit 21b registers the identification information of the disconnected user terminal 10 in a reject list, and thereafter does not attempt to connect BLE communication with any terminal registered on the reject list. Furthermore, the BLE communication management unit 21b establishes BLE communication with multiple user terminals in plain text until it receives notification of the authentication result, and switches to BLE communication in cipher text for user terminals 10 that have been successfully authenticated.
[0037] When the hash data generating unit 21c receives a user operation performed before the predetermined operation, the hash data generating unit 21c stores the authentication information in a data packet to be transmitted by NFC. The user operation performed before the BLE connection detection, which is the predetermined operation, is an operation indicating that a terminal-linked transaction will be performed, and may be an operation on a button provided on a touch panel. Alternatively, the user operation performed before the predetermined operation may be replaced by recognizing that the user is in front of the ATM 20 from the image captured by the camera 27, or detecting the user with the proximity sensor 28.
[0038] The hash data generating unit 21c refers to the ATM data and generates hash data H1 and hash data H2 from the unique information of its own device. The hash data generation unit 21c stores the ATMID and hash data H1 in an NFC data packet as authentication information. The hash data generation unit 21c retains the hash data H2 without storing it in the NFC data packet.
[0039] When the hash data authentication unit 21d receives hash data H2 from the user terminal 10 via BLE communication, it compares the received hash data H2 with the hash data H2 generated by the hash data generation unit 21c to authenticate the user terminal 10. If the hash data H2 match during authentication, the authentication is successful. Successful authentication means that the user terminal 10 that sent the authentication information is the same as the user terminal 10 that returned the response data. The hash data authentication unit 21d notifies the BLE communication management unit 21b of the user terminal 10 that has been successfully authenticated.
[0040] 4 is a configuration diagram of the user terminal 10. The user terminal 10 has a control unit 11, an internet communication unit 12, a display unit 13, an operation unit 14, a BLE communication unit 15, an NFC communication unit 16, a camera 19, and a storage unit 18.
[0041] The internet communication unit 12 is an interface that connects and communicates with the server 50 via the internet. The display unit 13 is a device that displays and outputs various information to the operator, and is, for example, a liquid crystal display. The operation unit 14 is a device that accepts operations by an operator, and is, for example, a touch panel.
[0042] The BLE communication unit 15 is an interface that communicates with the ATM 20 and the like using BLE. The NFC communication unit 16 is an interface that communicates with the ATM 20 and the like via NFC. The camera 19 can be used to read, for example, a two-dimensional barcode. The storage unit 18 stores various data relating to the operation of the user terminal 10. The storage unit 18 stores an internet transaction application program.
[0043] The control unit 11 controls the operation of the user terminal 10. The control unit 11 realizes various functions by causing the CPU to execute an internet transaction application.
[0044] The control unit 11 includes a hash data processing unit 11a, a BLE communication management unit 11b, and a transaction request unit 11c. When the hash data processing unit 11a receives the ATMID and the hash data H1 from the ATM 20 via NFC, the hash data processing unit 11a transmits the ATMID and the hash data H1 to the server 50.
[0045] The BLE communication management unit 11b periodically scans for advertising signals, associates the ATMID included in the advertising signals with the radio wave intensity, and stores the results. If the verification result of the hash data H1 received from the server 50 is "OK," the BLE communication management unit 11b selects and responds with the strongest advertising signal or the advertising signal whose radio wave intensity has increased after the NFC communication, and establishes BLE communication. Then, the BLE communication management unit 11b transmits the hash data H2 received from the server 50 as response data to the ATM 20 via BLE communication.
[0046] After starting the internet transaction application, the transaction request unit 11c logs in to the internet transaction server. After logging in, the transaction request unit 11c displays a menu screen on the display unit 23. When a transfer or balance inquiry is selected from the menu screen, communication with the Internet transaction server is performed to process the transfer or balance inquiry. For convenience, these are called normal transactions, and the transfer or balance inquiry operations are called normal transaction operations. When deposit or withdrawal is selected from the menu screen, coordination with an ATM is required. For convenience, these are called ATM-coordinated transactions, and deposit and withdrawal operations are called ATM-coordinated transaction operations.
[0047] When an ATM-linked transaction operation is performed, the transaction request unit 11c acquires the operator's account information from the Internet transaction server, accepts the details of the deposit and withdrawal, and processes the transaction. In an ATM-linked transaction, the transaction request unit 11c communicates with the ATM 20 using BLE and processes the transaction.
[0048] 5 is a flowchart showing an example of a processing procedure of the ATM 20. The ATM 20 sequentially executes steps S101 to S112. Step S101 The BLE communication management unit 21b transmits an advertising signal with a signal strength of "weak" and a connection of "not possible." Then, the process proceeds to step S102. Step S102 The transaction processing unit 21a determines whether or not a normal transaction operation has been accepted. If a normal transaction operation has been accepted (step S102; Yes), the process proceeds to step S112. If a normal transaction operation has not been accepted (step S102; No), the process proceeds to step S103.
[0049] Step S103 The transaction processing unit 21a determines whether or not a terminal-linked transaction operation has been accepted. If a terminal-linked transaction operation has been accepted (step S103; Yes), the process proceeds to step S104. If a terminal-linked transaction operation has not been accepted (step S103; No), the process proceeds to step S101. Step S104 The hash data generation unit 21c generates hash data H1 and hash data H2. The hash data generation unit 21c stores the ATMID and hash data H1 in an NFC data packet. Then, the process proceeds to step S105. Step S105 The NFC communication unit 26 detects NFC communication with the user terminal 10. After that, the process proceeds to step S106. Step S106 The NFC communication unit 26 transmits the data packet storing the ATMID and the hash data H1 to the user terminal 10. After that, the process proceeds to step S107.
[0050] Step S107 The BLE communication management unit 21b switches the radio wave intensity to "strong" and the connection to "permitted" based on the NFC communication detection as a predetermined operation, and then transmits an advertising signal. After that, the process proceeds to step S108. Step S108 The BLE communication unit 25 establishes BLE communication with the terminal that responded to the advertising signal. If there are responses from multiple terminals, BLE communication is established with the multiple terminals. Then, the process proceeds to step S109.
[0051] Step S109 The hash data authentication unit 21d receives the hash data H2 from the user terminal 10 via BLE communication, and compares the received hash data H2 with the hash data H2 generated by the hash data generation unit 21c to authenticate the user terminal 10. Then, the process proceeds to step S110.
[0052] Step S110 The BLE communication management unit 21b continues BLE communication with successfully authenticated user terminals 10 and disconnects BLE communication with user terminals 10 other than those successfully authenticated, thereby selecting BLE communication destinations. At this time, the identification information of the disconnected user terminals 10 is registered in a rejection list. Then, the process proceeds to step S111. Step S111 The transaction processing unit 21a communicates with the successfully authenticated user terminal 10 via BLE, processes the deposit / withdrawal transaction, and then terminates the process. Step S112 The transaction processing unit 21a executes the normal transaction and ends the process.
[0053] 6 is a flowchart showing an example of a processing procedure of the user terminal 10. The user terminal 10 sequentially executes steps S201 to S213.
[0054] Step S201 The control unit 11 starts the internet transaction application and logs in to the internet transaction server, and then proceeds to step S202. Step S202 The transaction request unit 11c determines whether or not a normal transaction operation has been accepted. If a normal transaction operation has been accepted (step S202; Yes), the process proceeds to step S213. If a normal transaction operation has not been accepted (step S202; No), the process proceeds to step S203.
[0055] Step S203 The BLE communication management unit 11b starts periodic scanning for advertising signals. Then, the process proceeds to step S204. When an advertising signal is detected during scanning, the BLE communication management unit 11b stores the ATMID included in the advertising signal in association with the radio wave intensity.
[0056] Step S204 When the ATM 20 enters the communication range, the NFC communication unit 16 performs NFC communication. Then, the process proceeds to step S205. Step S205 The hash data processing unit 11a receives the ATMID and hash data H1 via NFC from the ATM 20. Then, the process proceeds to step S206. Step S206 The hash data processing unit 11a transmits the ATMID and the hash data H1 as authentication information to the server 50. The authentication information is transmitted to the server 50 using the Internet communication unit 12. After that, the process proceeds to step S207.
[0057] Step S207 The Internet communication unit 12 receives the verification result of the hash data H1 and the hash data H2, and then proceeds to step S208. Step S208 The BLE communication management unit 11b determines whether the verification result of the hash data H1 received from the server 50 is "OK." If the verification result is "NG," the process ends immediately, and if the verification result is "OK," the process proceeds to step S209.
[0058] Step S209 The BLE communication management unit 11b selects the strongest advertising signal or the advertising signal whose radio wave intensity has increased after the NFC communication as the partner of the BLE communication and responds to it. Then, the process proceeds to step S210. Step S210 The BLE communication management unit 11b establishes BLE communication with the ATM 20, which is the transmission source of the selected advertising signal. After that, the process proceeds to step S211. Step S211 The BLE communication management unit 11b transmits the hash data H2 received from the server 50 as response data to the ATM 20 through BLE communication. After that, the process proceeds to step S212.
[0059] Step S212 The transaction request unit 11c processes the deposit / withdrawal transaction using BLE, and then ends the process. Step S211 The transaction request unit 11c executes the normal transaction and ends the process.
[0060] FIG. 7 is a sequence diagram of communication connection. In FIG. 7, ATM 20b and ATM 20c transmit weak advertising signals to the surrounding area. The user terminal 10 and the user terminal 10x are present within the range of the advertising signal. Since the ATMs 20b and 20c do not allow BLE connections, even if the user terminal 10 or the user terminal 10x responds to the advertising signal, BLE communication cannot be established.
[0061] When ATM 20b accepts the linked transaction operation, ATM 20b generates hash data H1 and hash data H2. After that, when NFC communication between ATM 20b and user terminal 10 occurs, ATM 20b transmits the ATMID and hash data H1 to the user terminal 10 via NFC. Furthermore, ATM 20b increases the strength of the BLE advertisement signal and changes it to connection "permitted." At this time, the advertisement signal from ATM 20c remains with signal strength "weak" and connection "not permitted."
[0062] The user terminal 10 transmits to the server 50 the ATM ID and hash data H1 received from the ATM 20b. The server 50 generates hash data H1 and hash data H2 based on the ATMID, and verifies the hash data H1. The server 50 transmits the verification result of the hash data H1 and the hash data H2 to the user terminal 10. If the verification result is "OK," the user terminal 10 selects the ATM 20b based on the radio wave strength of the advertising signal and establishes a BLE communication connection. The user terminal 10x can also establish a BLE communication connection with the ATM 20b. Here, the user terminal 10x is assumed to be a terminal of another user or a terminal of an interfering party.
[0063] The ATM 20b performs authentication using the hash data H2, continues BLE communication with the user terminal 10 that has been successfully authenticated, and disconnects BLE communication with the user terminal 10x that has not been successfully authenticated.
[0064] As described above, the disclosed service providing system comprises an ATM 20, which is a first terminal that provides services to an unspecified number of users, and a user terminal 10 that performs first wireless communication with the first terminal, which is communication using a first wireless communication method, wherein the first terminal periodically transmits an advertising signal for the first wireless communication, the first terminal increases the radio wave strength of the advertising signal when it detects a predetermined operation by the user, the user terminal 10 scans the advertising signal, the user terminal 10 identifies a connection partner based on the value of the radio wave strength of the advertising signal and / or changes in the radio wave strength, and the user terminal 10 establishes the first wireless communication with the first terminal by responding to the advertising signal transmitted by the first terminal identified as the connection partner. This configuration and operation allows wireless communication to be established with an appropriate user terminal.
[0065] As an example, the first wireless communication method is Bluetooth, the first terminal and the user terminal are capable of second wireless communication using a short-range wireless communication method with a communication distance significantly shorter than that of the first wireless communication method, the specified operation is an operation of bringing the user terminal close to the first terminal to perform the second wireless communication, and the first terminal transmits authentication information to be used in the first wireless communication to the user terminal via the second wireless communication. According to this configuration and operation, the second wireless communication is used to enable the first wireless communication with an appropriate user terminal.
[0066] As an example, the authentication information is hash data generated from identification information of the first terminal and information unique to the first terminal, and when the first terminal accepts a user operation performed before the specified operation, it stores the authentication information in a data packet transmitted via the second wireless communication. According to this configuration and operation, it is possible to perform first wireless communication with an appropriate user terminal by using information specific to the first terminal.
[0067] Further, the first terminal generates first hash data and second hash data from information unique to the first terminal, and transmits the identification information of the first terminal and the first hash data to the user terminal via the second wireless communication; the user terminal, on the condition that the first hash data generated based on the identification information of the first terminal received via the second wireless communication matches the first hash data received via the second wireless communication, transmits second hash data generated based on the identification information of the first terminal received via the second wireless communication to the first terminal via the first wireless communication; and the first terminal authenticates the user terminal by comparing the second hash data received via the first wireless communication with the second hash data it has stored in its own terminal. According to this configuration and operation, the user terminal can select an appropriate first terminal, and the first terminal can authenticate the user terminal.
[0068] In addition, the first terminal establishes the first wireless communication with multiple user terminals that responded to the advertising signal, continues the first wireless communication with user terminals among the multiple user terminals that have been successfully authenticated, and disconnects the first wireless communication with user terminals among the multiple user terminals other than those that have been successfully authenticated. According to this configuration and operation, the first terminal can select an appropriate user terminal and avoid inappropriate communication with other terminals.
[0069] Furthermore, the first terminal establishes the first wireless communication with the plurality of user terminals in plain text, and switches to the first wireless communication in cipher text for the user terminals that have been successfully authenticated. This makes it possible to establish connections with an unspecified number of user terminals without having to store information about the user terminals in advance, and ensures high security once an appropriate user terminal has been selected.
[0070] In addition, the first terminal stores identification information of the user terminals other than those that have been successfully authenticated among the plurality of user terminals, and when the identification information of a user terminal that responded to the advertising signal matches the stored identification information, the first wireless communication with that user terminal is suppressed. Therefore, even if an interfering terminal repeatedly attempts to make an unauthorized connection, it can be reliably prevented.
[0071] The first terminal is an automated teller machine having a currency storage vault, and provides a currency deposit and withdrawal service to the user. This configuration and operation allows deposit and withdrawal services to be provided safely using user terminals, achieving both convenience and security.
[0072] Furthermore, when the user terminal receives the advertising signals from multiple first terminals, it identifies the first terminal that is the sender of the advertising signal with the largest radio wave strength value or the first terminal that is the sender of the advertising signal with increased radio wave strength as the connection partner. Therefore, connection to the correct first terminal can be reliably established through simple determination.
[0073] The present invention is not limited to the above-described embodiments, but includes various modifications. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, not only can the configurations be deleted, but also replacements and additions of configurations are possible.
[0074] For example, in the above embodiment, an example was given of using BLE for communication related to deposit and withdrawal transactions, but any communication method can be used as long as it identifies the connection partner, establishes a connection, and performs two-way communication. In addition, in the above embodiment, an example was given of a case where authentication information is transmitted to the user terminal using NFC, but this can also be replaced by a method in which a two-dimensional barcode displayed on the display unit 23 of the ATM is read and transmitted by the camera 19 of the user terminal 10, and the BLE communication management unit 21b performs a predetermined operation to start advertising by having the ATM control unit 21 recognize the user's action of taking a photo with the camera 19 of the user terminal using the camera 27 mounted on the ATM. Furthermore, in the above embodiment, a configuration was shown in which a connection destination was selected based on the value of radio wave strength, but the radio wave strength may be an average of values obtained by multiple scans. Furthermore, in the above embodiment, the host device verifies the hash data H1, but the user terminal 10 may also be configured to verify the hash data H1. Furthermore, the identification information of a user terminal 10 that has been successfully authenticated may be registered on a whitelist, and if a reconnection request is made before the completion of a deposit / withdrawal transaction, the user terminal 10 may be connected as a legitimate user terminal 10. It is preferable to reset the whitelist when the deposit / withdrawal transaction is completed. In the above configuration, an ATM is shown as an example of an automated teller machine, but any device used for depositing and dispensing currency, such as a cashier or cash dispenser, can be used. Furthermore, instead of an automated teller machine, this embodiment can also be applied to a service providing device for providing any service to an unspecified number of users, regardless of whether currency is deposited or dispensed, such as a payment terminal, a counter terminal or an entry management terminal used at a store counter, a reception terminal at a public facility, a reception terminal and a payment terminal at a parking lot, or an entry management device installed at a facility or gate. [Explanation of symbols]
[0075] 10: User terminal, 11: Control unit, 11a: Hash data processing unit, 11b: BLE communication management unit, 11c: Transaction request unit, 12: Internet communication unit, 13: Display unit, 14: Operation unit, 15: BLE communication unit, 16: NFC communication unit, 18: Memory unit, 19: Camera, 20: ATM, 21: Control unit, 21a: Transaction processing unit, 21b: BLE communication management unit, 21c: Hash data generation unit, 21d: Hash data authentication unit, 22: Accounting system communication unit, 23: Display unit, 24: Operation unit, 25: BLE communication unit, 26: NFC communication unit, 27: Camera, 28: Proximity sensor, 29: Memory unit, 30: Coin storage, 31: Card reader, 50: Server, 51: Memory unit, 52a: User data, 52b: ATM data, 53: Hash data generation unit, 54: Hash data verification unit
Claims
1. a first terminal that provides services to an unspecified number of users; a user terminal that performs first wireless communication, which is communication using a first wireless communication method, with the first terminal; Equipped with the first terminal periodically transmits an advertisement signal for the first wireless communication; When the first terminal detects a predetermined operation by a user, the first terminal increases the radio wave intensity of the advertising signal; the user terminal scans for the advertising signal; The user terminal identifies a connection partner based on the value of radio wave strength of the advertising signal and / or a change in radio wave strength, The user terminal responds to an advertising signal transmitted by a first terminal identified as a connection partner, thereby establishing the first wireless communication with the first terminal. A service providing system characterized by:
2. The service providing system according to claim 1, the first wireless communication method is Bluetooth (registered trademark), the first terminal and the user terminal are capable of second wireless communication using a short-range wireless communication method having a communication distance that is sufficiently shorter than that of the first wireless communication method; the predetermined operation is an operation of bringing the user terminal close to the first terminal to perform the second wireless communication, A service providing system, characterized in that the first terminal transmits authentication information used in the first wireless communication to the user terminal via the second wireless communication.
3. The service providing system according to claim 2, the authentication information is hash data generated from identification information of the first terminal and information unique to the first terminal, A service providing system characterized in that the first terminal stores the authentication information in a data packet transmitted via the second wireless communication when it accepts a user operation performed before the specified operation.
4. The service providing system according to claim 3, the first terminal generates first hash data and second hash data from information unique to the first terminal, and transmits the identification information of the first terminal and the first hash data to the user terminal via the second wireless communication; the user terminal transmits, via the first wireless communication, second hash data generated based on the identification information of the first terminal received via the second wireless communication, to the first terminal, on condition that the first hash data generated based on the identification information of the first terminal received via the second wireless communication matches the first hash data received via the second wireless communication; The first terminal authenticates the user terminal by comparing the second hash data received through the first wireless communication with the second hash data stored in the first terminal. A service providing system characterized by:
5. The service providing system according to claim 4, The first terminal establishes the first wireless communication with a plurality of user terminals that have responded to the advertising signal, continues the first wireless communication with user terminals that have been successfully authenticated among the plurality of user terminals, and disconnects the first wireless communication with user terminals other than the user terminals that have been successfully authenticated among the plurality of user terminals. A service providing system characterized by:
6. The service providing system according to claim 5, A service providing system characterized in that the first terminal establishes the first wireless communication in plain text with the multiple user terminals, and switches to the first wireless communication in encrypted text for user terminals that are successfully authenticated.
7. The service providing system according to claim 5, A service providing system characterized in that the first terminal stores identification information of all of the multiple user terminals other than the user terminal that has successfully been authenticated, and when the identification information of the user terminal that responded to the advertising signal matches the stored identification information, the first wireless communication with the user terminal is suppressed.
8. The service providing system according to claim 1, the first terminal is an automated teller machine having a currency storage vault, A service providing system that provides a currency deposit and withdrawal service to the user.
9. The service providing system according to claim 1, When the user terminal receives the advertising signals from a plurality of first terminals, A service providing system characterized by identifying a first terminal that is the sender of an advertising signal with the greatest radio wave strength value, or a first terminal that is the sender of an advertising signal with increased radio wave strength, as the connection partner.
10. a currency storage cabinet for storing currency; a first wireless communication unit that performs first wireless communication with a user terminal, the first wireless communication being communication using a first wireless communication method; an operation reception unit that receives a predetermined operation from a user; Equipped with The first wireless communication unit Periodically transmit advertising signals, When the predetermined operation is received, the radio wave intensity of the advertising signal is increased; Establishing the first wireless communication with the user terminal that has received the advertising signal; The currency storage performs deposit and withdrawal of currency based on the data received via the first wireless communication. An automatic transaction device characterized by:
11. A communication control method in a service providing system having a first terminal that provides a service to an unspecified number of users and a user terminal that performs first wireless communication with the first terminal, the first wireless communication being communication using a first wireless communication method, comprising: The first terminal periodically transmits an advertisement signal for the first wireless communication; The first terminal detects a predetermined operation by a user and increases the radio wave intensity of the advertising signal; the user terminal scanning for the advertising signal; The user terminal identifies a connection partner based on the value of radio wave strength of the advertising signal and / or changes in radio wave strength; a step of establishing the first wireless communication with the first terminal by the user terminal responding to an advertising signal transmitted by the first terminal identified as a connection partner; A communication control method comprising:
Citation Information
Patent Citations
Wireless communication device, wireless communication method, and program
JP2022123675A