Entry-exit management system, entry-exit management method, and entry-exit management program

The access control system allows second area administrators to manage accounts and authorization for a first area, addressing the cumbersome registration process and reducing administrative load.

JP2026010633AActive Publication Date: 2026-01-22MITSUBISHI ESTATE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024189250
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-28
Publication Date
2026-01-22
Estimated Expiration
2044-07-09

AI Technical Summary

Technical Problem

The process of registering user accounts and assigning authorization information across multiple areas is cumbersome for administrators, requiring coordination between administrators of different areas, leading to increased processing load.

Method used

An access control system that allows an administrator of a second area to assign and manage authority information for a first area, including account generation and registration, reducing the need for direct interaction with the first area's administrator.

Benefits of technology

This system reduces the processing load on administrators by enabling the second area administrator to manage accounts in the first area independently, streamlining the account registration and authorization process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026010633000001_ABST
    Figure 2026010633000001_ABST
Patent Text Reader

Abstract

To provide an entering / leaving management system capable of performing entering / leaving management in a first area in a second area in the first area.SOLUTION: An entrance and exit management system includes a granting unit that grants a predetermined number of pieces of authority information for entering a first area to a manager of a second area included in the first area, a reception unit that receives an input of authentication information of a user of the second area, a generation unit that generates an account of the user of the second area based on the authentication information of the user, an assignment unit that assigns one of the predetermined number of pieces of authority information to the account of the user generated by the generation unit, and a registration unit that registers the account in an account database.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an entrance / exit management system, an entrance / exit management method, and an entrance / exit management program for performing entrance / exit management. [Background technology]

[0002] In recent years, entry and exit to buildings and the like has been controlled by authentication using ID cards, irises, etc. Patent Document 1 discloses an example of such authentication using face recognition technology. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-84586 Summary of the Invention [Problem to be solved by the invention]

[0004] In such access control, it is essential for an administrator to register user information, i.e., to register an account and assign authorization information to the account. For example, in the case of a user who uses a second area included in a first area, i.e., a tenant included in a building, the administrator of the second area may also register an account on the tenant side in the second area. Since the user also uses the first area, the administrator of the second area must also request the administrator of the first area to register an account in the first area and assign authorization information to the account. However, this process is cumbersome for both the administrators of the first and second areas.

[0005] Therefore, the present invention has been made in consideration of the above problems, and aims to provide an entry / exit management system, an entry / exit management method, and an entry / exit management program that can reduce the processing load on the administrator of the first area and the administrator of the second area. [Means for solving the problem]

[0006] In order to solve the above problem, an access control system according to one embodiment of the present invention includes an assignment unit that assigns a predetermined number of pieces of authority information for entering a first area to an administrator of a second area included in the first area; a reception unit that accepts input of authentication information for a user of the second area; a generation unit that generates an account for a user of the second area based on the user's authentication information; an assignment unit that assigns one of the predetermined number of pieces of authority information to the user account generated by the generation unit; and a registration unit that registers the account in an account database.

[0007] In addition, in order to solve the above problem, an entry / exit management method according to one embodiment of the present invention includes an assignment step in which a computer assigns a predetermined number of pieces of authority information for entering a first area to an administrator of a second area included in the first area; a reception step in which input of authentication information for a user of the second area is accepted; a generation step in which an account for a user of the second area is generated based on the user's authentication information; an assignment step in which one of the predetermined number of pieces of authority information is assigned to the user account generated in the generation step; and a registration step in which the account is registered in an account database.

[0008] In addition, in order to solve the above problem, an entry / exit management program according to one embodiment of the present invention enables a computer to implement the following functions: an assignment function that assigns a predetermined number of pieces of authority information for entering a first area to an administrator of a second area included in the first area; a reception function that accepts input of authentication information for a user of the second area; a generation function that generates an account for a user of the second area based on the user's authentication information; an assignment function that assigns one of the predetermined number of pieces of authority information to the user account generated by the generation function; and a registration function that registers the account in an account database.

[0009] In addition, in the above-mentioned access control system, the account may include information on a second area authentication medium used by the user to enter the second area, and may be equipped with a second area reading unit that reads the second area medium information when entering the second area, and a second area authentication unit that authenticates the user based on whether the second area medium information read by the second area reading unit is registered in the account database.

[0010] In addition, in the above-mentioned entry / exit management system, the authority information may include information on a first area authentication medium used by a user to enter the first area, and the system may be equipped with a first area reading unit that reads the first area medium information when entering the first area, and a first area authentication unit that authenticates the user based on whether the first area medium information read by the first area reading unit is registered in the account database.

[0011] In addition, in the above-mentioned entry / exit control system, the second area authentication medium may be biometric information of a user, and the registration unit may register, as the first area authentication medium, the biometric information of the user registered as the second area authentication medium.

[0012] The above-mentioned entry / exit management system may also include a first storage unit that stores first area history information that is recorded in response to authentication by the first area authentication unit and indicates the history of users entering and exiting the first area, and a first providing unit that provides the first area history information to an administrator of the second area within the scope of the authority information granted for the second area.

[0013] The above-mentioned entry / exit management system may also be provided with a second storage unit that stores second area history information that is recorded in response to authentication by the second area authentication unit and indicates the history of users entering and exiting the second area, and a second providing unit that provides the second area history information to an administrator of the second area.

[0014] The above-mentioned entry / exit management system may also include a third area authentication unit that authenticates users entering a third area outside the first area, a third memory unit that stores third area history information that is recorded in response to authentication by the third area authentication unit and indicates the history of users entering and exiting the third area, a notification unit that notifies the administrator of the first area of ​​information about the authenticated user, and a reward granting unit that grants points to users of the second area who have used the third area.

[0015] In addition, in the above-mentioned entry / exit management system, the privilege granting unit may grant a first privilege to a user who uses the third area, which is beneficial to the user when using the third area, and the privilege granting unit may grant a second privilege, which is more beneficial than the first privilege, to a user who uses the third area and is able to enter the second area.

[0016] The above-mentioned access control system may further include a determination unit that determines whether the remaining number obtained by subtracting the number of pieces of authority information assigned by the assignment unit from the predetermined number is equal to or less than a predetermined threshold, and a request unit that requests the administrator of the first area to increase the predetermined number when the determination unit determines that the remaining number is equal to or less than the predetermined threshold, and the granting unit may grant additional authority information to the administrator of the second area. [Effects of the Invention]

[0017] An access control system according to one embodiment of the present invention allows the administrator of the second area to also manage accounts in the first area, eliminating the need for the administrator of the second area to contact the administrator of the first area when registering an account, thereby reducing the processing load on the administrators of the first and second areas. [Brief explanation of the drawings]

[0018] [Figure 1] FIG. 1 is a system diagram illustrating an example of the configuration of an entrance / exit management system. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of a first area management device. [Figure 3]FIG. 2 is a block diagram showing an example of the configuration of a second area management device. [Figure 4] FIG. 10 is a conceptual data diagram showing an example of the configuration of first account information. [Figure 5] FIG. 10 is a conceptual data diagram showing an example of the configuration of second account information. [Figure 6] 1A is a conceptual data diagram showing an example of the configuration of first area history information showing the entry and exit history of a first area, and FIG. 1B is a conceptual data diagram showing an example of the configuration of second area history information showing the entry and exit history of a second area. [Figure 7] FIG. 10 is a sequence diagram showing an example of an exchange in the access control system when an account is created. [Figure 8] 10 is a flowchart showing an example of an operation of the second area management device when creating an account. [Figure 9] 10 is a flowchart showing an example of an operation of the first area management device when creating an account. [Figure 10] 10 is a flowchart showing an example of an operation during authentication of the second area. [Figure 11] 10 is a flowchart showing an example of an operation during authentication of the first area. [Figure 12] 10 is a flowchart showing an example of an operation of the second area management device when a user checks a history. [Figure 13] 10 is a flowchart showing an example of an operation performed when checking history in the first area management device. [Figure 14] FIG. 10 is a block diagram showing an example of the configuration of a third area management device. [Figure 15] 10 is a flowchart showing an example of operation of adding authority information in the second area management device. [Figure 16] 10 is a flowchart showing an example of operation of authority information addition processing in the first area management device. [Figure 17] FIG. 10 is a sequence diagram showing an example of an exchange in the entrance / exit control system when entering a third area. [Figure 18] 10 is a flowchart showing an example of the operation of the third area management device when entering the third area. [Figure 19]10 is a flowchart showing an example of the operation of the first area management device when entering a third area. [Figure 20] FIG. 10 is a diagram illustrating a configuration example of an access control system in which account information is integrated and centrally managed. [Figure 21] FIG. 10 is a conceptual data diagram showing an example of the configuration of integrated account information. DETAILED DESCRIPTION OF THE INVENTION

[0019] Hereinafter, an access control system according to one aspect of the present invention will be described in detail with reference to the drawings.

[0020] <Summary> FIG. 1 is a system diagram showing an example of the configuration of an access control system 1. The access control system 1 includes a first area management device 100 and a second area management device 200 connected to each other via a network 400, and a third area management device 300 may also be connected to each other via the network 400. The first area management device 100 is a device for managing a first area 10 (an area surrounded by a dotted line), and the second area management device 200 is a device for managing a second area 20 (an area surrounded by a dashed-dotted line). Area management includes at least one of, or may include all of, authentication of users entering and leaving the area, recording of entry and exit history, and management of accounts of users entering and leaving the area. Here, the first area 10 is an area that includes the second area 20, and is, for example, a building, but is not limited to this. The first area 10 may also be, for example, a shopping mall or an amusement park. The second area 20 is an area included in the first area 10, and is, for example, a tenant in a building, but is not limited to this. The second area 20 is an area that cannot be entered without passing through a gate provided in the first area 10.

[0021] The first area management device 100 is an information processing device (computer system) that authenticates a gate through which all users using the building 50 must pass and authenticates users using the gate, and may be realized, for example, by a server device, a PC, a tablet terminal, etc., but is not limited to these. The first area management device 100, for example, reads user authentication information using a reading unit 121 (121a, 121b, 121c, 121d), authenticates the read user authentication information, and if the authentication is successful, unlocks a gate 122 (122a, 122b, 122c, 122d) to allow the user to enter the first area 10. The first area management device 100 may also authenticate users when they exit the first area 10. Note that user authentication information can take various forms, and can be anything that can uniquely identify the user. As an example, authentication information may be an ID (identifier) ​​card, a two-dimensional barcode, a password, biometric information (iris or fingerprint), etc., but is not limited to these.

[0022] The second area management device 200 is an information processing device (computer system) that authenticates a gate 222 through which all users who use the second area 20 must pass and authenticates users who use the gate 222, and may be realized by, for example, but not limited to, a server device, a PC, a tablet terminal, etc. For example, the second area management device 200 reads authentication information of a user using a reading unit 221, authenticates the read authentication information of the user, and if the authentication is successful, unlocks the gate 222 and allows the user to enter the second area 20. The second area management device 200 may also authenticate a user when he or she exits the second area 20. The authentication information used by the second area management device 200 may be the same as or different from that used by the first area management device 100.

[0023] In this embodiment, the first area management device 100 grants the administrator of the second area 20 (the second area management device 200) multiple pieces of authority information for users of the second area 20 to enter the first area 10. Each piece of authority information is assigned to each user of the second area 20, and is information for managing the users of the second area 20 as users who will enter the first area 10. The authority information includes at least identification information that allows the first area management device 100 to individually and uniquely identify each user, and may also include information about the medium if a specific medium (e.g., an ID card) is used for authentication.

[0024] The second area management device 200 registers account information of users who use the second area 20, and also registers account information of users who use the first area 10 within the scope of the authority information granted by the first area management device 100.

[0025] That is, in the entrance / exit control system 1 according to this embodiment, the authority to manage accounts performed by the first area management device 100 is also given to the administrator of the second area management device 200.

[0026] Each device will be described in detail below.

[0027] <Configuration> <First area management device 100> FIG. 2 is a block diagram showing an example of the configuration of the first area management device 100. As shown in FIG.

[0028] As shown in FIG. 2, the first area management device 100 includes a communication unit 110, an input unit 120, an output unit 130, a storage unit 140, and a control unit 150.

[0029] The communication unit 110 is a communication interface that communicates with devices external to the first area management device 100 via the network 400. The communication unit 110 transmits specified information to the specified external device in accordance with an instruction from the control unit 150. The communication unit 110 also transmits information received from the external device via the network 400 to the control unit 150. For example, the communication unit 110 transmits authority information to the second area management device 200, which is an external device, in accordance with an instruction from the control unit 150. For example, the communication unit 110 also receives user information, etc. associated with the authority information, from the second area management device 200 and transmits it to the control unit 150.

[0030] The input unit 120 has a function of accepting input from the administrator of the first area management device 100 and transmitting the input to the control unit 150. The input unit 120 can be realized, for example, by hardware keys or a mouse provided in the first area management device 100, or soft keys such as a touch panel or touch keys. Note that the input to the input unit 120 may be input by voice, in which case the input unit 120 is realized by a microphone. The input unit 120 may, for example, accept input of authority information to be given to the administrator of the second area 20 (the second area management device 200) and transmit the information to the control unit 150. Alternatively, the input unit 120 may, for example, accept input of information regarding a new user entering the first area 10 and transmit the information to the control unit 150.

[0031] Input unit 120 includes first area reading unit 121. First area reading unit 121 is provided at gate 122, which is the entrance to first area 10, and is a device that reads authentication information of a user. First area reading unit 121 may be, for example, a card reader if the authentication information is an ID card, or a camera if the authentication information is an iris. Input unit 120 transmits the authentication information of the user read by first area reading unit 121 to control unit 150.

[0032] The output unit 130 has a function of outputting data instructed by the control unit 150. The output by the output unit 130 may be realized by displaying characters or images on a monitor (display device) or the like that is attached to or connected to the first area management device 100, or by outputting audio from a speaker or earphones (audio output device) that is attached to or connected to the first area management device 100. Alternatively, the output by the output unit 130 may be realized by transmitting information to an external device via the communication unit 110.

[0033] The storage unit 140 is a recording medium that stores various programs and various data required for the operation of the first area management device 100. The storage unit 140 may be realized, for example, by a hard disk drive (HDD), a solid state drive (SSD), a flash memory, or the like, but is not limited to these. The storage unit 140 may also be realized by cloud storage accessible by the first area management device 100. The storage unit 140 may also be configured as a read-only memory (ROM) or a random access memory (RAM) that serves as a work area for executing programs. The storage unit 140 may store a program that authenticates the authentication information read by the first area reading unit 121 and unlocks the gate if the authentication is successful. The storage unit 140 may also store first area account information 141 and first area history information 142. The first area account information 141 is information indicating the account of a user who enters (uses) the first area 10. The first area history information 142 is information relating to the history of users entering and leaving the first area 10. The first area account information 141 and the first area history information 142 will be described in detail later.

[0034] The control unit 150 is a processor that executes the processes to be realized by the first area management device 100, using various programs and various data stored in the storage unit 140. The control unit 150 authenticates users who enter the first area 10 and registers user account information in response to input from the administrator of the first area management device 100.

[0035] The control unit 150 includes an assigning unit 151 , a registration unit 152 , a first area authentication unit 153 , and a first providing unit 154 .

[0036] The granting unit 151 grants authority information to the administrator of the second area 20 (second area management device 200) in accordance with instructions from the administrator of the first area management device 100 input to the input unit 120. The granting unit 151 grants a predetermined number of pieces of authority information to the administrator of the second area 20. As described above, the authority information includes at least identification information (authentication ID) for identifying a user in the first area 10.

[0037] The registration unit 152 registers information about users who use the first area 10 in the first area account information 141. The registration unit 152 may register information about new users in the first area account information in accordance with content input by the administrator of the first area management device 100 via the input unit 120. Furthermore, the registration unit 152 may be triggered by the registration of user information for any of the pieces of authority information sent from the second area management device 200 to the second area management device 200, receive the transmitted user information and the authority information via the communication unit 110, and register the received user information for the received authority information in the first area account information. That is, user information may be registered in the first area account information 141 by the administrator of the first area 10 or by the administrator of the second area 20. Note that the term "registration" here may include updating or deleting information. Therefore, the administrator of the first area 10 does not have to register information about all users, thereby reducing the workload of the administrator. Furthermore, if the user's biometric information (e.g., facial recognition) is used as an authentication medium in the first and second areas, it can be registered as common information, eliminating the need for the user to carry a medium such as an ID card and preventing the user from losing the authentication medium, which is expected to improve the security of authentication in the first and second areas.

[0038] The first area authentication unit 153 authenticates the authentication information read by the first area reading unit 121. Here, authentication may refer to determining whether or not a user holding the authentication information has the authority to enter the first area 10. That is, the first area authentication unit 153 determines whether or not the authentication information transmitted from the first area reading unit 121 is registered in the first area account information 141. If the authentication information is registered in the first area account information 141, the authentication is deemed successful. If the authentication information is not registered, the authentication is deemed unsuccessful. If the authentication is successful, the first area authentication unit 153 unlocks the corresponding gate of the first area reading unit 121, allowing the user to pass through the gate. If the authentication is unsuccessful, the first area authentication unit 153 does not unlock the gate and outputs information indicating the authentication failure to the first area reading unit 121. In this case, the first area reading unit 121 may output a character string or a sound indicating the authentication failure to notify the user that the authentication has failed.

[0039] The first providing unit 154 provides the first area history information upon receiving an instruction from the administrator of the first area 10 via the input unit 120 or upon receiving access from the administrator of the second area 20 from the second area management device 200 via the communication unit 110. When receiving an instruction from the administrator of the first area 10, the first providing unit 154 provides all of the information in the first area history information 142. In this case, the provision of the first area history information by the first providing unit 154 may be realized by displaying it on a monitor as the output unit 130. Furthermore, when receiving access from the administrator of the second area 20, the first providing unit 154 provides the first area history information 142 within the scope of the authority information granted to the administrator of the second area 20 by the granting unit 151. In other words, the first providing unit 154 provides only the entry / exit history information for the authentication ID indicated by the authority information assigned to the second area 20. In this case, the provision of the first area history information by the first providing unit 154 may be realized in the form of transmission to the second area management device 200 via the communication unit 110.

[0040] The above is the description of the configuration of the first area management device 100.

[0041] <Second area management device 200> FIG. 3 is a block diagram showing an example of the configuration of the second area management device 200. As shown in FIG.

[0042] As shown in FIG. 3, the second area management device 200 includes a communication unit 210, an input unit 220, an output unit 230, a storage unit 240, and a control unit 250.

[0043] The communication unit 210 is a communication interface that communicates with devices external to the second area management device 200 via the network 400. The communication unit 210 transmits specified information to the specified external device in accordance with an instruction from the control unit 250. The communication unit 210 also transmits information received from the external device via the network 400 to the control unit 250. For example, the communication unit 210 transmits authority information and user information associated with the authority information to the first area management device 100, which serves as an external device, in accordance with an instruction from the control unit 250. For example, the communication unit 210 also receives authority information from the first area management device 100 and transmits the authority information to the control unit 250.

[0044] The input unit 220 has a function of accepting input from an administrator of the second area management device 200 and transmitting the input to the control unit 250. The input unit 220 can be realized, for example, by hardware keys or a mouse provided in the second area management device 200, or soft keys such as a touch panel or touch keys. Note that input to the input unit 220 may be input by voice, in which case the input unit 220 is realized by a microphone. The input unit 220 may accept input of information about users who use the second area 200 from the administrator of the second area management device 200, for example, and transmit the information to the control unit 250.

[0045] Input unit 220 includes second area reading unit 221. Second area reading unit 221 is provided at gate 222, which is the entrance to second area 20, and is a device that reads authentication information of a user. Second area reading unit 221 may be, for example, a card reader if the authentication information is an ID card, or a camera if the authentication information is an iris. Input unit 220 transmits the authentication information of the user read by second area reading unit 221 to control unit 250.

[0046] The output unit 230 has a function of outputting data instructed by the control unit 250. The output by the output unit 230 may be realized by displaying characters or images on a monitor (display device) or the like that is attached to or connected to the second area management device 200, or may be realized by outputting audio from a speaker or earphones (audio output device) that is attached to or connected to the second area management device 200. Alternatively, the output by the output unit 230 may be realized by transmitting information to an external device via the communication unit 210.

[0047] The storage unit 240 is a recording medium that stores various programs and various data required for the operation of the second area management device 200. The storage unit 240 may be realized, for example, by a hard disk drive (HDD), a solid state drive (SSD), a flash memory, or the like, but is not limited to these. The storage unit 240 may also be realized by cloud storage accessible by the second area management device 200. The storage unit 240 may also be configured with ROM or RAM as a work area for executing programs. The storage unit 240 may store a program that authenticates the authentication information read by the second area reading unit 221 and unlocks the gate if the authentication is successful. The storage unit 240 may also store second area account information 241 and second area history information 242. The second area account information 241 is information indicating the account of a user who enters (uses) the second area 20. The second area history information 242 is information relating to the history of users entering and leaving the second area 20. The second area account information 241 and the second area history information 242 will be described in detail later.

[0048] The control unit 250 is a processor that executes the processes to be realized by the second area management device 200, using various programs and various data stored in the storage unit 240. The control unit 250 authenticates users who enter and exit the second area 20, and registers user account information in response to input from the administrator of the second area management device 200.

[0049] The control unit 250 includes a receiving unit 251 , a generating unit 252 , an allocating unit 253 , a registering unit 254 , a second area authentication unit 255 , and a second providing unit 256 .

[0050] The reception unit 251 receives a predetermined number of pieces of authority information from the first area management device 100. The authority information received by the reception unit 251 is information for entering the first area 10, is information associated with each user who uses the second area 20, and is information that allows the first area management device 100 to individually manage each user and their authentication information.

[0051] The generation unit 252 generates account information for a user who uses the second area 20. Specifically, the generation unit 252 generates the user's account information based on an input to the input unit 220 by an administrator of the second area 20. The input by the administrator includes an input specifying which second area authentication ID the user will use in the second area 20 and an input of information that enables the second area management device 200 to uniquely identify the user (e.g., the user's name), and may also include an input of other information about the user (e.g., personal information such as the user's email address, age, gender, address, and telephone number). Furthermore, if the authentication information used in the second area 20 is the user's biometric information, the input may include an input of the biometric information. Furthermore, if the authentication information used in the second area 20 is an ID card or the like, the input may include an input of information indicating which ID card will be given to the user. Therefore, the generation unit 252 may generate the user's account information by associating a pre-existing (or newly created) second area authentication ID and second area authentication information for entering and leaving the second area 20 with information about a new user.

[0052] The allocation unit 253 allocates, to the user's account information generated by the generation unit 252, the authority information that has not yet been associated with the user, among the predetermined number of authority information received by the reception unit 251.

[0053] The registration unit 254 associates the account information of the user who uses the second area 20, generated by the generation unit 252, with the authority information assigned by the assignment unit 253, and registers the account information in the second area account information 241. The registration by the registration unit 254 includes not only new registration but also updating and deleting information, and the updating and deletion of information is performed by input by the administrator of the second area management device 200 via the input unit 220.

[0054] The second area authentication unit 255 authenticates the authentication information read by the second area reading unit 221. Here, authentication may refer to determining whether or not a user holding the authentication information has the authority to enter the second area 20. That is, the second area authentication unit 255 determines whether or not the authentication information transmitted from the second area reading unit 221 is registered in the second area account information 241. If the authentication information is registered in the second area account information 241, the authentication is deemed successful. If the authentication information is not registered, the authentication is deemed unsuccessful. If the authentication is successful, the second area authentication unit 255 causes the second area reading unit 221 to unlock the corresponding gate, allowing the user to pass through the gate. If the authentication is unsuccessful, the second area authentication unit 255 does not unlock the gate, but outputs information indicating the authentication failure to the second area reading unit 221. In this case, the second area reading unit 221 may output a character string or a sound indicating the authentication failure to notify the user that the authentication has failed.

[0055] The second providing unit 256 receives an instruction from the manager of the second area 20 via the input unit 220 and provides the second area history information 242. Providing the second area history information 242 may mean outputting (displaying) the second area history information 242 to the output unit 230. Furthermore, the second providing unit 256 receives an instruction from the manager of the second area 20 via the input unit 220 and provides the first area history information 142.

[0056] The above is the description of the configuration of the second area management device 200.

[0057] <Data> From here, the first area account information 141, the first area history information 142, the second area account information 241, and the second area history information 242 will be explained.

[0058] <2nd Area Account Information 241> Fig. 4 is a conceptual data diagram showing an example of the configuration of second area account information 241. The second area account information 241 is information indicating the account of a user who uses the second area 20. As shown in Fig. 4, the second area account information 241 is information in which a management ID 401, a first area authentication ID 402, first area authentication information 403, a second area authentication ID 404, second area authentication information 405, a user name 406, and an email address 407 are associated with each other.

[0059] The second area account information 241 is information for managing the accounts of users who use the second area 20 (users who enter and exit the second area 20), and is also information for managing the accounts of those users in the first area 10.

[0060] The management ID 401 is identification information for individually managing the accounts registered in the second area account information 241. The management ID 401 is automatically assigned to each user of the second area 20.

[0061] The first area authentication ID 402 is information included in a predetermined number of pieces of authority information transmitted from the first area management device 100, and is identification information used by the first area management device 100 to identify each account of a user in the first area 10.

[0062] The first area authentication information 403 is information used to enter the first area 10, i.e., information to be compared with the authentication information read by the first area reading unit 121. The first area authentication information 403 may be determined in advance by an administrator of the first area management device 100, or may be the same as the second area authentication information 405 when the second area authentication information 405 is registered. The first area authentication information 403 may be unique information recorded on the ID card if the authentication medium is an ID card, image information of a two-dimensional barcode unique to the user if the authentication medium is a two-dimensional barcode, image information of an image of the user's eye if the authentication medium is an iris, or image information of an image of the user's fingerprint if the authentication medium is a fingerprint. The authentication medium may basically be common to each user, but may also be different. If the first area authentication information 403 is a predetermined medium such as an ID card, it is predetermined information, and if it is biometric information, it is information that is registered by accepting the user's biometric information later. If the first area authentication information 403 is the same as the second area authentication information 405, when the second area authentication information 405 is registered, that information is copied and registered as the first area authentication information 403.

[0063] The second area authentication ID 404 is identification information that the second area management device 200 uses to identify each account of a user in the second area 20. The second area authentication ID 404 may be the same as the first area authentication ID 402.

[0064] The second area authentication information 405 is information used to enter the second area 20, i.e., information to be compared with the authentication information read by the second area reading unit 221. The second area authentication information 405 is set by an administrator of the second area 20. If the authentication medium is an ID card, the second area authentication information 405 may be unique information recorded on the ID card; if the authentication medium is a two-dimensional barcode, the second area authentication information 405 may be image information of a two-dimensional barcode unique to the user; if the authentication medium is an iris, the second area authentication information 405 may be image information of an image of the user's eye; if the authentication medium is a fingerprint, the second area authentication information 405 may be image information of an image of the user's fingerprint. The authentication medium may basically be common to each user, but may also be different.

[0065] The user name 406 is information indicating the user who uses the corresponding first area authentication ID 402 or second area authentication ID 404, and is information indicating the name of the user.

[0066] The email address 407 is information indicating the email address of the user indicated by the corresponding username 406 .

[0067] 4, an account with management ID 401 of "mn0201" has registered "1A20021" as first area authentication ID 402, and image information "20021A.jpg" is associated with first area authentication information 403. The account also has registered "2A021" as second area authentication ID 404 and image information "20021A.jpg" as second area authentication information 405. The user is "Ayama Ao" as indicated by user name 406, and email address 407 is "ayama@XXX.com."

[0068] The second area account information 241 may include information other than that shown in the figure. For example, the second area account information 241 may include information related to entry and exit, such as the gender of the user indicated by the user name 406, a telephone number, authentication information different from the authentication information indicated in the second area authentication information 405 when the second area reading unit 221 can read multiple pieces of authentication information, and a registration date. The second area account information 241 may not include non-essential information among the information shown in the figure. For example, the management ID 401 may not be included. If the second area 20 does not have a gate, the second area authentication information 405 may not be included. As shown in FIG. 4, the first area authentication ID 402, which serves as authorization information provided by the first area management device 100, may be pre-registered. If no user is associated with the first area management device 100, the other information may be left blank. When a new user is registered, information may be added to the blank spaces.

[0069] <1st Area Account Information 141> Fig. 5 is a conceptual data diagram showing an example of the configuration of first area account information 141. The first area account information 141 is information indicating the account of a user who uses the first area 10. As shown in Fig. 5, the first area account information 141 is information in which a management ID 501, a first area authentication ID 502, first area authentication information 503, a second area ID 504, a user name 505, and an email address 506 are associated with each other.

[0070] The management ID 501 is identification information for individually managing the accounts registered in the first area account information 141. The management ID 501 is automatically assigned to each user in the first area 10.

[0071] The first area authentication ID 502 is identification information for the first area management device 100 to identify each account of a user in the first area 10. The first area authentication ID 502 also includes the first area authentication ID 402 as authority information granted to the administrator of the second area 20 (the second area management device 200).

[0072] The first area authentication information 503 is information used to enter the first area 10, i.e., information to be compared with the authentication information read by the first area reading unit 121. The first area authentication information 503 is set by an administrator of the first area 10. If the authentication medium is an ID card, the first area authentication information 503 may be unique information recorded on the ID card; if the authentication medium is a two-dimensional barcode, the first area authentication information 503 may be image information of a two-dimensional barcode unique to the user; if the authentication medium is an iris, the first area authentication information 503 may be image information of an image of the user's eye; and if the authentication medium is a fingerprint, the first area authentication information 503 may be image information of an image of the user's fingerprint. The authentication medium may basically be common to each user, but may also be different.

[0073] The second area ID 504 indicates which second area 20 the account is granted to when the account is included in the authority information granted to the administrator of the second area 20, and is identification information for identifying which second area 20 the first area management device 100 is. The second area ID 504 is left blank when the account belongs to a user who does not use the second area 20.

[0074] The user name 505 is information indicating the user who uses the corresponding first area authentication ID 502, and is information indicating the name of the user.

[0075] The email address 506 is information indicating the email address of the user indicated by the corresponding username 505 .

[0076] In an example shown in FIG. 5, for an account with a management ID 501 of "M02206", "1A20022" is registered as the first area authentication ID 502, and the first area authentication information 403 is associated with the image information of "20022A.jpg". Also, for the said account, "2A" is associated as the second area ID 504, the user is "B Tian B Zi" as shown by the user name 505, and the email address 407 is "bta@XXX.com".

[0077] Each account of the first area account information 141 may be registered by the administrator of the first area 10, or may be automatically registered when the second area 20 triggers user registration in the second area management device 200.

[0078] <Second area history information 242> FIG. 6(a) is a data conceptual diagram showing a configuration example of the second area history information 242. The second area history information 242 is information indicating the history of user entry and exit to the second area 20. As shown in FIG. 6(a), the second area history information 242 is information in which a management ID 601, an entry / exit person ID 602, entry / exit information 603, and a usage date and time 604 are associated.

[0079] The management ID 601 is identification information assigned for convenience for the second area management device 200 to manage each history information.

[0080] The entry / exit person ID 602 is identification information of a user who has entered or exited the second area 20 and has been authenticated, and is information corresponding to the second area authentication ID 404 of the second area account information 241 shown in FIG. 4.

[0081] The entry / exit information 603 is information indicating whether a user has entered or exited the second area 20. The entry / exit information 603 is information recorded by the second area authentication unit 255 depending on whether the second area reading unit 221 that read the authentication information is installed outside the second area 20 or inside the second area 20, or whether it is set for entry or exit. If the second area reading unit 221 is installed outside the second area 20 or set for entry, "IN" is recorded, and if it is installed inside the second area 20 or set for exit, "OUT" is recorded.

[0082] The usage date and time 604 is information indicating the date and time when the user entered or left the second area 20. That is, it is information indicating the date and time when the second area authentication unit 255 performed authentication.

[0083] In the example shown in Figure 6(a), the history with management ID 601 "m092801" has entry / exit user ID 602 ​​of "2A022", entry / exit information 603 of "IN", and usage date / time 604 of "2024 / 5 / 18 15:30". From this history information and the second area account information 241 shown in Figure 4, it can be seen that Bda Bko entered the second area 20 at 15:30 on May 18, 2024.

[0084] Each history entry in the second area history information 242 may be added each time a user enters or leaves the second area 20, and if authentication fails, information indicating authentication failure may be added.

[0085] 6(a) , the second area history information 242 may include other information related to the entry / exit history. For example, if there are multiple gates through which the user can enter or exit the second area 20, the second area history information 242 may include information indicating which gate the user passed through.

[0086] The existence of the second area history information 242 makes it possible to confirm who entered or left the second area 20 and when.

[0087] <1st Area History Information 142> Fig. 6(b) is a conceptual data diagram showing an example of the configuration of the first area history information 142. The first area history information 142 is information showing the history of users entering and leaving the second area 20. As shown in Fig. 6(b), the first area history information 142 is information in which a management ID 611, an entry / exit user ID 612, entry / exit information 613, and a usage date and time 614 are associated with each other.

[0088] The management ID 611 is identification information that is assigned for the purpose of the first area management device 100 managing each piece of history information.

[0089] The entry / exit user ID 612 is the identification information of a user who has entered or exited the first area 10 and has been authenticated, and is information corresponding to the first area authentication ID 502 of the first area account information 141 shown in Figure 5.

[0090] The entry / exit information 613 is information indicating whether a user has entered or exited the first area 10. The entry / exit information 613 is information recorded by the first area authentication unit 153 depending on whether the first area reading unit 121 that read the authentication information is installed outside or inside the first area 10, or whether it is set for entry or exit. If the first area reading unit 121 is installed outside the first area 10 or set for entry, "IN" is recorded, and if it is installed inside the first area 10 or set for exit, "OUT" is recorded.

[0091] The usage date and time 614 is information indicating the date and time when the user entered or left the first area 10. That is, it is information indicating the date and time when the first area authentication unit 153 performed authentication.

[0092] In the example shown in FIG. 6(b), the history record with management ID 611 "R0239030" has entry / exit user ID 612 of "1A20022," entry / exit information 613 of "IN," and usage date / time 614 of "2024 / 5 / 18 15:27." From this history information and the first area account information 141 shown in FIG. 5, it can be seen that B-da B-ko entered the first area 10 at 15:27 on May 18, 2024. Therefore, from the history record with management ID 611 "R0239030" and the history record with management ID 601 "m092801," it can be seen that B-da B-ko passed through the gate to enter the second area 20 three minutes after passing through the gate to enter the first area 10.

[0093] Each history entry in the first area history information 142 may be added each time a user enters or leaves the first area 10, and information indicating authentication failure may also be added if authentication fails.

[0094] 6(b) , the first area history information 142 may include other information related to the entry / exit history. For example, if there are multiple gates through which the user can enter or exit the first area 10, the first area history information 142 may include information indicating which gate the user passed through.

[0095] The existence of the first area history information 142 makes it possible to confirm who entered or left the first area 10 and when.

[0096] As shown in FIGS. 6(a) and 6(b), the configuration of the first area history information 142 may be the same as the configuration of the second area history information 242, but may also be different.

[0097] <Operation> Now, the operation of the entrance / exit control system 1 will be described.

[0098] <Account registration process> First, an example of interactions between the devices in the access control system 1 for registering account information in the second area management device 200 will be described with reference to Fig. 7. Fig. 7 is a sequence diagram showing an example of interactions between the devices in the access control system 1.

[0099] 7, the first area management device 100 grants a predetermined number of pieces of authority information, including a first area authentication ID for entering the first area 10, to the second area management device 200 (step S701). The second area management device 200 stores the granted authority information.

[0100] The second area management device 200 generates (registers) new account information for a user who uses the second area 20 based on input from the administrator of the second area management device 200 (step S702). After generating (registering) the account information for the new user, the second area management device 200 associates the account information with any of a predetermined number of pieces of authority information granted by the first area management device 100, that is, authority information that has not yet been assigned to a user among the predetermined authority information (step S703). After associating the authority information, the second area management device 200 transmits the associated authority information and information on the registered user to the first area management device 100 (step S704).

[0101] When the first area management device 100 receives the authority information and the user information from the second area management device 200, it associates the user information with the authority information and registers the user information in the first area account information 141 (step S705). This process reduces the burden on the administrator of the first area management device 100 of registering accounts, simply by registering the user's account in the second area management device 200. Furthermore, since a user who uses the second area 20 within the first area 10 naturally also uses the first area 10, the processing burden on the administrators of both the first and second areas in registering user account information can be reduced compared to the conventional method. Furthermore, the administrator of the second area can freely register and change information within the scope of the authority information provided by the first area management device 100, without relying on the administrator who manages the first area. This allows for faster registration of user information and change of authority information than before.

[0102] FIG. 8 is a flowchart showing an example of the operation of the second area management device 200 for realizing the exchange shown in FIG.

[0103] 8, the communication unit 210 of the second area management device 200 receives a predetermined number of pieces of authority information transmitted from the first area management device 100 (step S801). The communication unit 110 transmits the received predetermined number of pieces of authority information to the control unit 250.

[0104] The control unit 250 registers each of the predetermined number of pieces of authority information that have been transmitted in the second area account information 241, leaving the corresponding user information blank (step S802).

[0105] The administrator of the second area management device 200 inputs information about the new user to the input unit 220. The input unit 220 transmits the received input content to the control unit 250. Then, the reception unit 251 of the control unit 250 receives the input of the information about the new user (step S803). The reception unit 251 transmits the received information about the new user to the generation unit 252.

[0106] The generation unit 252 generates account information for the new user by associating the transmitted information of the new user with a second area authentication ID (which may be a newly created ID) that is not associated with a user (step S804).

[0107] The allocation unit 253 associates (allocates) the authority information granted by the first area management device 100 to which no user has yet been associated with the generated account information of the new user (step S805).

[0108] The registration unit 254 associates the account information generated by the generation unit 252 with the authority information assigned by the assignment unit 253 and registers the account information in the second area account information 241 (step S806).

[0109] Then, the registration unit 254 transmits the information of the newly registered user together with the associated authority information to the first area management device 100 via the communication unit 210 (step S807), and ends the process.

[0110] In the process shown in FIG. 8, the processes in steps S801 and S802 are basically performed only the first time, and the processes in steps S803 to S806 are repeatedly performed for each user registration.

[0111] FIG. 9 is a flowchart showing an example of the operation of the first area management device 100 for realizing the exchange shown in FIG.

[0112] As shown in FIG. 9, the granting unit 151 of the first area management device 100 transmits a predetermined number of pieces of authority information to the second area management device 200 via the communication unit 110 based on input from the administrator of the first area management device 100 to the input unit 120 (step S901).

[0113] The communication unit 110 receives the account information of the new user transmitted from the second area management device 200 (step S902). The account information includes user information and authority information. The communication unit 110 transmits the received information to the control unit 150.

[0114] The registration unit 152 registers the user information in the first area account information 141 in association with the transmitted authority information (step S903). Then, the registration unit 152 registers the account information in association with the area ID set for the second area management device 200 that transmitted the account information (step S904), and ends the process.

[0115] In the process shown in FIG. 9, step S901 is basically executed when the second area 20 is newly established, and the processes of steps S902 to S904 are executed in the second area management device 200 each time an account is registered.

[0116] <Authentication process> FIG. 10 is a flowchart showing the authentication process in the second area management device 200 in the entrance / exit control system 1.

[0117] As shown in FIG. 10, when the second area reading unit 221 provided in the second area 20 reads authentication information from the user's authentication medium, it transmits the information to the second area authentication unit 255 of the control unit 250 (step S1001).

[0118] When the second area authentication unit 255 receives the authentication information, it performs authentication based on whether the authentication information is registered in the second area authentication information 405 of the second area account information 241 (step S1002). That is, the second area authentication unit 255 performs authentication based on whether the received authentication information matches any of the second area authentication information 405. If the authentication information is a data string read from an ID card, the second area authentication unit 255 searches for second area authentication information 405 that matches the data string. If found, the authentication is successful; if not, the authentication is unsuccessful. If the received authentication information is an iris image, the second area authentication unit 255 searches for second area authentication information 405 that correlates with any of the iris images registered as second area authentication information 405 to a predetermined degree or more. If found, the authentication is successful; if not, the authentication is unsuccessful.

[0119] If the authentication is successful (YES in step S1002), the second area authentication unit 255 outputs a notification of authentication success to the electronic lock of the gate 222 (step S1003). This unlocks the electronic lock of the gate 222, allowing the user to enter or exit the second area 20.

[0120] Then, the second area authentication unit 255 registers the second area authentication ID 404 corresponding to the second area authentication information 405 to which the read authentication information corresponds, the entry / exit information indicating whether the entry into the second area 20 or the exit from the second area 20 occurred, and the date and time of authentication as the usage date and time in the second area history information 242 (step S1004), and terminates the processing.

[0121] On the other hand, if the authentication fails (NO in step S1002), the second area authentication unit 255 outputs information indicating that the authentication failed to the gate 222 or the second area reading unit 221 (step S1005), and ends the process. This allows the gate 222 in the second area 20 to notify the user that the authentication failed, and may prompt the user to read the authentication information again. At this time, the second area authentication unit 255 may also register information indicating that the authentication failed in the second area history information 242.

[0122] The authentication process in the second area management device 200 has been described above.

[0123] This allows the second area management device 200 to authenticate users who enter or exit the second area 20, and record the history thereof. By recording the history, it is possible to later confirm when and who entered or exited the second area 20.

[0124] 11 is a flowchart showing the authentication process in the first area management device 100 in the access control system 1. The authentication process in the first area management device 100 is the same as the authentication process in the second area management device 200.

[0125] As shown in FIG. 11, when the second area reading unit 221 provided in the first area 10 reads authentication information from the user's authentication medium, it transmits the information to the first area authentication unit 153 of the control unit 250 (step S1101).

[0126] When the first area authentication unit 153 receives the authentication information, it performs authentication based on whether the authentication information is registered in the first area authentication information 503 of the second area account information 241 (step S1102). That is, the first area authentication unit 153 performs authentication based on whether the received authentication information matches any of the first area authentication information 503. If the authentication information is a data string read from an ID card, the first area authentication unit 153 searches for first area authentication information 503 that matches the data string. If found, the authentication is successful; if not, the authentication is unsuccessful. If the received authentication information is an iris image, the first area authentication unit 153 searches for first area authentication information 503 that correlates with any of the iris images registered as first area authentication information 503 to a predetermined degree or more. If found, the authentication is successful; if not, the authentication is unsuccessful.

[0127] If the authentication is successful (YES in step S1102), the first area authentication unit 153 outputs a notification of authentication success to the electronic lock of the gate 122 (step S1103). This unlocks the electronic lock of the gate 122, allowing the user to enter or exit the first area 10.

[0128] Then, the first area authentication unit 153 registers the first area authentication ID 502 corresponding to the first area authentication information 503 corresponding to the read authentication information, the entry / exit information indicating whether the entry into or exit from the first area 10 occurred, and the date and time of authentication as the usage date and time in the first area history information 142 (step S1104), and terminates the processing.

[0129] On the other hand, if the authentication fails (NO in step S1102), the first area authentication unit 153 outputs information indicating that the authentication failed to the gate 122 or the second area reading unit 221 (step S1105), and ends the process. This allows the gate 122 in the first area 10 to notify the user that the authentication failed, and may prompt the user to read the authentication information again. At this time, the first area authentication unit 153 may also register information indicating that the authentication failed in the first area history information 142.

[0130] This allows the first area management device 100 to authenticate users who enter or exit the first area 10, and record the history thereof. By recording the history, it is possible to later confirm when and who entered or exited the first area 10.

[0131] <History confirmation process> The entry and exit history can be checked in the second area management device 200 and the first area management device 100. Fig. 12 is a flowchart showing an example of an operation when the manager checks the history information in the second area management device 200.

[0132] 12, the second area management device 200 receives an access to check the history information (step S1201). The second providing unit 256 of the control unit 250 of the second area management device 200 determines whether the received access is from a user with access authority, i.e., an administrator (step S1202). This determination can be made, for example, based on the administrator's ID and password. If the user does not have access authority (NO in step S1202), the user does not have authority to check the history information, and the process ends.

[0133] If there is access authority (YES in step S1202) and the history information that the administrator wants to check is the second area history information 242 (YES in step S1203), the second providing unit 256 reads the second area history information 242 from the storage unit 240 and outputs it to the output unit 230 (step S1204). This allows the administrator of the second area management device 200 to check the users who entered and left the second area 20 and the dates and times.

[0134] On the other hand, if there is access authority (NO in step S1202) and the history information that the administrator wants to check is the first area history information 142 (NO in step S1203), the second providing unit 256 requests the first area history information 142 from the first area management device 100 via the communication unit 210 (step S1205). The request includes the second area ID or the ID of the second area management device 200 to indicate which second area management device 200 is making the request.

[0135] The communication unit 210 receives, from the first area management device 100, the first area history information within the scope of the authority information granted to the second area 20 (second area management device 200) (step S1206). The communication unit 210 transmits the received first area history information to the second providing unit 256.

[0136] The second providing unit 256 causes the output unit 230 to display (output) the transmitted first area history information (step S1207). As a result, the second area management device 200 can provide the manager of the second area 20 with history information of entry and exit to the first area 10 within the scope of the authority information granted to the second area management device 200, i.e., history information of the first area authentication ID indicated by the authority information.

[0137] If the second area management device 200 receives an input to end the display of history information via the input unit 220 (YES in step S1208), it ends the processing; if it does not receive an input (NO in step S1208), it returns to the processing of step S1203.

[0138] In this way, the second area management device 200 can provide the user with not only the history of entry and exit to the second area 20 but also the history of entry and exit to the first area 10.

[0139] FIG. 13 is a flowchart showing an example of the operation of the first area management device 100 in providing history information.

[0140] As shown in FIG. 13, the first area management device 100 receives an access request to check history information (step S1301). The first providing unit 154 of the control unit 150 of the first area management device 100 determines whether the received access is from a user with access authority, i.e., an administrator (step S1302). This determination can be made, for example, based on the administrator's ID and password. Here, the administrator may be the administrator of the first area 10 or the administrator of the second area 20 included in the first area 10. If the user does not have access authority (NO in step S1302), the user does not have authority to check history information, and the process is terminated.

[0141] If there is access authority and the accessor is the administrator of the first area 10 (YES in step S1303), the first providing unit 154 reads the first area history information 142 from the storage unit 140 and outputs (displays) all of the information to the output unit 130. This allows the administrator of the first area 10 to check all of the first area history information 142.

[0142] On the other hand, if there is access authority and the accessor is the administrator of the second area 20 and not the first area 10 (NO in step S1303), only the history information of the user of the second area 20 corresponding to the accessing second area administrator is extracted from the first area history information 142 and transmitted to the second area management device 200 via the communication unit 110 (step S1305). This allows the administrator of the second area management device 200 to check the first area history information 142 with respect to the portion related to the user of the second area 20.

[0143] If the first area management device 100 receives an input to terminate the output of history information via the input unit 120, or if it receives an input to terminate access from the second area management device 200 (YES in step S1306), it terminates the processing, and if it does not receive an input (NO in step S1306), it returns to the processing of step S1303.

[0144] In this way, in the entrance / exit control system 1, the administrator of each area control device can check the entry / exit history as needed.

[0145] <Authorization information addition process> However, when the number of users using the second area 20 increases, the number of pieces of authority information initially given to the second area management device 200 by the first area management device 100 may become insufficient. Therefore, the second area management device 200 may request the first area management device 100 to add more authority information. Fig. 14 is a flowchart showing an example of the operation of the second area management device 200 when adding authority information, and Fig. 15 is a flowchart showing an example of the operation of the first area management device 100 when a request to add authority information is received.

[0146] As shown in FIG. 14, it is assumed that a new user is registered in the second area management device 200 (step S1401).

[0147] Then, the control unit 250 counts the number of pieces of authority information that are not associated with user information (step S1402). Then, the counted number is compared with a predetermined threshold (step S1403). Here, the predetermined threshold is a threshold that triggers a request for additional authority information, and may be any number, or may be 0.

[0148] If the counted number is equal to or less than a predetermined threshold (YES in step S1403), that is, if the remaining number of pieces of authority information not associated with user information is small or there is no usable authority information, the control unit 250 communicates with the first area management device 100 via the communication unit 210 to request addition of authority information (step S1404). In response to the request, the first area management device 100 grants the additional authority information to the manager of the second area 20 (the second area management device 200).

[0149] The communication unit 210 receives the additional authority information transmitted from the second area management device 200 (step S1405). The communication unit 210 transmits the received additional authority information to the control unit 250.

[0150] The control unit 250 adds the transmitted additional authority information to the second area account information 241 (or stores it in the storage unit 240) (step S1406), and ends the process.

[0151] FIG. 15 is a flowchart showing an example of the operation of the first area management device 100 in response to this.

[0152] 15, the communication unit 110 of the first area management device 100 receives a request to add authority information from the second area management device 200 (step S1501). The communication unit 110 transmits the received request to add authority information to the control unit 150.

[0153] When the request to add authority information is transmitted, the granting unit 151 of the control unit 150 generates or assigns authority information (step S1502). Generating authority information means generating a new first area authentication ID, which may be generating a predetermined number of first area authentication IDs according to a predetermined algorithm, and generating an authentication ID that is different from all existing first area authentication IDs. At this time, if the authentication medium is, for example, an ID card, association with the ID card is also performed. The ID card needs to be separately mailed or handed over between administrators.

[0154] Furthermore, allocating authority information may mean using, among the first area authentication IDs managed by the first area management device 100, one that is not associated with a user, as authority information to be granted to the second area management device 200 that has made the addition request. Furthermore, in the request to add authority information, the number of pieces of authority information to be granted may be a predetermined number, or may be a number corresponding to a predetermined percentage (for example, 10%, but not limited to this) of the number of pieces of authority information initially granted to the second area management device 200 that has made the request.

[0155] The assigning unit 151 associates the generated or assigned first area authentication ID 502 with the second area ID 504 of the second area management device 200 making the addition request, and registers the association in the first area account information 141 (step S1503).

[0156] The granting unit 151 transmits the newly generated or assigned authority information for the manager of the second area 20 to the second area management device 200 via the communication unit 110 (step S1504), and ends the process.

[0157] The authority information is essential for users who use the second area 20 because they must pass through the gate 122 related to the first area 10. A predetermined number of pieces of authority information that are expected to be necessary depending on the size and scale of the second area 20 are initially granted by the first area management device 100 (for example, when the second area 20 is established as a tenant or a company). However, as the number of users in the second area 20 increases, there is a possibility that the authority information will run out. Conventionally, in such a case, the administrator of the second area management device 200 would request additional user registration from the administrator of the first area management device 100, and the administrator of the second area management device 200 would then register the user, which was a hassle for both administrators. With this configuration, this hassle can be reduced.

[0158] <Configuration> <Third area management device 300> As shown in FIG. 1 , the access control system 1 may include a third area management device 300 that manages a third area different from the first area 10. The third area management device 300 (third area) may have some kind of partnership with the first area management device 100 (first area 10). For example, the third area and the first area 10 may both be buildings of a group company. In such a group, it is conceivable that some kind of reward or benefit is given to users who use the area. Therefore, for example, in a third area that has some kind of partnership with the first area 10, if a user who uses the second area 20 within the first area 10 is successfully authenticated, it is conceivable that the third area management device 300 gives some kind of reward or benefit to the user. The reward or benefit may be, for example, preferential treatment at stores in each area. Examples of preferential treatment devices include, but are not limited to, a higher discount rate than other users, the issuance of a gift certificate, a higher point accrual rate or value on a point card that can be used to purchase products or services, or priority purchasing rights for specific products. Furthermore, the reward or benefit may be a right to use a specific facility in the third area. This right of use may be limited in the number of times it can be used within a specified period, and the number of times it can be used may be a time period.

[0159] The third area management device 300 may be a computer system having substantially the same configuration as the first area management device 100.

[0160] 16 is a block diagram showing an example of the configuration of the third area management device 300. As shown in FIG. 16, the third area management device 300 includes a communication unit 310, an input unit 320, a storage unit 330, a storage unit 340, and a control unit 350.

[0161] The communication unit 310 is a communication interface that communicates with devices external to the third area management device 300 via the network 400. The communication unit 310 transmits specified information to the specified external device in accordance with an instruction from the control unit 350. The communication unit 310 also transmits information received from the external device via the network 400 to the control unit 350. For example, the communication unit 310 transmits information about a user who has entered the third area to the first area management device 100, which is an external device, in accordance with an instruction from the control unit 350.

[0162] The input unit 320 has a function of accepting input from the administrator of the third area management device 300 and transmitting the input to the control unit 350. The input unit 320 can be realized, for example, by hardware keys or a mouse provided in the third area management device 300, or soft keys such as a touch panel or touch keys. Note that input to the input unit 320 may be input by voice, in which case the input unit 320 is realized by a microphone. The input unit 320 may, for example, accept input of authority information to be given to the administrator of the second area 20 (the second area management device 200) and transmit the information to the control unit 350. Alternatively, the input unit 320 may, for example, accept input of information regarding a new user entering the first area 10 and transmit the information to the control unit 350.

[0163] Input unit 320 includes third area reading unit 321. Third area reading unit 321 is a device provided at a gate that is an entrance to the third area and reads the user's authentication information. Third area reading unit 321 may be, for example, a card reader if the authentication information is an ID card, or a camera if the authentication information is an iris. Input unit 320 transmits the user's authentication information read by third area reading unit 321 to control unit 350.

[0164] The output unit 330 has a function of outputting data instructed by the control unit 350. The output by the output unit 330 may be realized by displaying characters or images on a monitor (display device) or the like that is attached to or connected to the third area management device 300, or by outputting audio from a speaker or earphones (audio output device) that is attached to or connected to the third area management device 300. Alternatively, the output by the output unit 330 may be realized by transmitting information to an external device via the communication unit 310.

[0165] The storage unit 340 is a recording medium that stores various programs and various data required for the operation of the third area management device 300. The storage unit 340 may be realized, for example, by a hard disk drive (HDD), a solid state drive (SSD), a flash memory, etc., but is not limited to these. The storage unit 340 may also be realized by cloud storage accessible by the third area management device 300. The storage unit 340 may also be configured as a read-only memory (ROM) or a random access memory (RAM) that serves as a work area for executing programs. The storage unit 340 may store a program that authenticates the authentication information read by the third area reading unit 321 and unlocks the gate if the authentication is successful. The storage unit 340 may also store third area account information 341 and third area history information 342. The third area account information 341 is information indicating the account of a user entering (using) the third area. The third area history information 342 is information relating to the entry and exit history of users who enter and exit the third area. The configuration of the third area account information 341 may be the same as that of the first area account information 141. The configuration of the third area history information 342 may be the same as that of the first area history information 142.

[0166] The control unit 350 is a processor that executes the processes to be realized by the third area management device 300, using various programs and various data stored in the storage unit 340. The control unit 350 authenticates users who enter the third area and registers user account information in response to input from the administrator of the third area management device 300.

[0167] The control unit 350 includes a third area authentication unit 351, a notification unit 352, and a reward granting unit 353.

[0168] The third area authentication unit 351 authenticates the authentication information read by the third area reading unit 321. Here, authentication may refer to determining whether a user holding the authentication information has the authority to enter the first area 10. That is, the third area authentication unit 351 determines whether the authentication information transmitted from the third area reading unit 321 is registered in the first area account information 141. If the authentication information is registered in the first area account information 141, the authentication is successful. If the authentication information is not registered, the authentication is unsuccessful. If the authentication is successful, the third area authentication unit 351 unlocks the corresponding gate to allow the user to pass through the gate. If the authentication is unsuccessful, the third area authentication unit 351 does not unlock the gate and outputs information indicating the authentication failure to the third area reading unit 321. In this case, the third area reading unit 321 may output a character string or a sound indicating the authentication failure to notify the user of the authentication failure.

[0169] When the third area authentication unit 351 authenticates a user and the authentication is successful, the notification unit 352 notifies (transmits) information about the successfully authenticated user to the affiliated first area management device 100 via the communication unit 310.

[0170] In response to a notification to the first area management device 100 made by the notification unit 352, the reward granting unit 353 grants a reward to the authenticated user when the first area management device 100 receives information from the first area management device 100 via the communication unit 310 that the authenticated user is a specific user (a user who uses the second area within the first area). Note that when there are a specific user and other users (for example, users who do not use the second area in the first area) and rewards or benefits are to be granted to both users, the reward granting unit 353 may change the content of the reward or benefit, and in that case, may be configured to grant better rewards or benefits to the specific user than to the other users. For example, the reward granting unit 353 may grant more points or widen the range in which the specific store or space can be used.

[0171] This concludes the description of the configuration of the third area management device 300. The first area management device 100 further receives information about a successfully authenticated user from the third area management device 300, and if the user is a user of the second area 20 within the first area 10, notifies the third area management device 300 that the authenticated user is a specific user (a user who uses the second area 20 within the first area 10).

[0172] <Operation> Figure 17 is a sequence diagram showing the interactions between devices in the access control system 1 when a user from the first area 10 enters a third area 30 that is affiliated with the first area 10, Figure 18 is a flowchart showing an example of the operation of the third area management device 300 at that time, and Figure 19 is a flowchart showing an example of the operation of the first area management device 100 at that time.

[0173] 17, the third area management device 300 authenticates a user entering the third area (step S1701). Then, the third area management device 300 transmits information (e.g., email address) of the user who has been successfully authenticated to the first area management device 100 (step S1702).

[0174] The first area management device 100 determines whether the received user information is a user in the second area 20 (step S1703). For example, the third area management device 300 transmits the user's email address as user information to the first area management device, and determines whether the email address is registered in the first area account information 131, and if so, whether the information is associated with a second area ID, thereby determining whether the user is a user in the second area 20. When the first area management device 100 determines that the user is a user in the second area 20, it notifies the third area management device 300 that the user is a specific user (a user in the second area 20 who uses the first area 10) (step S1704).

[0175] When the third area management device 300 receives information that the authenticated user is a specific user, it grants a reward to the user. That is, the third area management device 300 transmits information about the granted reward or benefit to the user terminal (email address) of the authenticated user, that is, the user terminal (email address) of the user in the second area 20.

[0176] The user terminal displays information about the received reward or benefit (step S1705), which allows the user in the second area 20 to recognize that the third area management device 300 has given them a reward or benefit.

[0177] FIG. 18 is a flowchart showing an example of the operation of the third area management device 300 for realizing the exchange shown in FIG.

[0178] As shown in FIG. 18, the third area reading unit 321 reads the authentication information and transmits it to the control unit 350 (step S1801).

[0179] The third area authentication unit 351 determines whether the transmitted authentication information is registered or not (step S1802) by referring to the third area account information 341. If the authentication information is not registered (NO in step S1802), the third area authentication unit 351 causes the output unit 330 to output a message indicating authentication failure (step S1808), and ends the process.

[0180] On the other hand, if the authentication is successful (YES in step S1802), the third area authentication unit 351 outputs a successful authentication to the gate of the third area and instructs it to unlock (step S1803). The third area authentication unit 351 also registers the entry / exit person ID, whether it is entry / exit, and the date and time of use in the third area history information 342 (step S1804). The third area authentication unit 351 transmits information about the user who has been successfully authenticated to the notification unit 352. Here, the user information is information that can identify the user, and may include at least the user's name, as well as other information that is registered in the third area account information 341, such as the user's email address, age, and gender, and is information that can uniquely identify the user.

[0181] The notification unit 352 transmits the information of the successfully authenticated user transmitted from the third area authentication unit 351 to the first area management device 100 of the partner via the communication unit 310 (step S1805). Then, the reward granting unit 353 determines whether or not information indicating that the successfully authenticated user is a specific user (user in the second area) has been received from the first area management device 100 (step S1806). If the information has not been received (NO in step S1806), the process ends. On the other hand, if information indicating that the successfully authenticated user is a specific user (user in the second area) has been received from the first area management device 100 (YES in step S1806), the reward granting unit 353 grants a reward to the authenticated user (step S1807) and ends the process. That is, the reward granting unit 353 transmits information indicating the content of the reward to the user's terminal (email address) via the communication unit 110, and ends the process. The reward may be, for example, information such as points that can be used in the first area or the third area that is associated with the user's account, and the points may be deducted by using the points for shopping at a store or the like in the first area or the third area. In this way, the third area management device 300 can provide some kind of reward or benefit (for example, a reward or benefit associated with using the third area) to a user who uses the second area 20 within the first area 10 of the first area management device 100 that is affiliated with the third area management device 300, thereby encouraging the user to repeatedly use the first area or the third area.

[0182] FIG. 19 is a flowchart showing an example of the operation of the first area management device 100 for realizing the exchange shown in FIG.

[0183] 19, the communication unit 110 of the first area management device 100 receives the user information transmitted from the third area management device 300 (step S1901). The communication unit 110 transmits the received user information to the control unit 150.

[0184] The control unit 150 determines whether the transmitted user information is registered in the first area account information 141 and whether the second area ID is associated with the information (step S1902).

[0185] If the transmitted user information is registered in the first area account information 141 and is associated with a second area ID (YES in step S1902), the control unit 150 notifies the third area management device 300 that the user who performed authentication in the third area is a specific user (second area user) (step S1903), and ends the process. In this case, the privilege to be granted may be a privilege related to the third area that the user entered, such as a privilege related to a store located in the third area, or a right to use a specific store or space within the third area. On the other hand, if the transmitted user information is not registered in the first area account information 141, or is registered but is not associated with a second area ID (NO in step S1902), the control unit 150 notifies the third area management device 300 that the user is not a specific user (second area user) (step S1904), and ends the process.

[0186] In this way, in the access control system 1, the third area management device 100 can be configured to, when detecting that a user of the second area 20 belonging to the first area 10 has entered the third area, allow the user of the second area 20 to receive some kind of benefit in the third area. As a result, the user of the second area 20 can feel that they are getting a good deal when using the third area. Note that, although the third area management device 100 is configured to grant a reward to the user here, the entity that grants the reward may be the first area management device 100 or the second area management device 200, and the reward granted at that time is not limited to the third area, but may also be a reward or benefit related to the first area.

[0187] <Summary> As described in the above embodiment, in the access control system 1, the second area management device 200 of the second area 20 included in the first area 10 is granted a predetermined number of pieces of authority information from the first area 10 by the first area management device 100, so that the second area management device 200 can also manage accounts for access to and exit from the first area 10. Therefore, the processing load on the administrator of the first area management device 100 when registering accounts of users of the second area 20 in the first area 10 can be reduced.

[0188] <Supplementary information> The access control system according to the above embodiment is not limited to the above embodiment, and may be realized by other methods. Various modifications will be described below.

[0189] (1) In the above embodiment, an example was shown in which the first area account information 141 and the second area account information 241 are stored in the respective management devices, but this is not limited to this.

[0190] The first area management device 100 and the second area management device 200 may be configured to access and manage information related to authentication of the first area 10 by using a common database. Specifically, in this case, for example, as shown in FIG. 20 , a network storage 1000 is connected to a network 400. The network storage 1000 is a cloud storage on the network 400 that accepts access from the first area management device 100 and the second area management device 200 and provides the stored information to the first area management device 100 and the second area management device 200. The network storage 1000 may include a processor that processes data in the database. The cloud storage 1000 may also be configured to accept access from a third area management device 300. The network storage 1000 may be a device that accepts access only from predetermined devices, and for example, when it accepts access from an area management device (100, 200, 300), the area management device may be configured to accept access only from the area management device by presenting unique information such as an electronic certificate to the cloud storage 100.

[0191] The cloud storage 1000 stores integrated account information that is used to register user account information or grant authority information to the account in the first area management device 100, the second area management device 200, and the third area management device 300.

[0192] FIG. 21 is a conceptual data diagram showing an example of the configuration of integrated account information 2100 stored in the cloud storage 100. As shown in FIG.

[0193] 21, integrated account information 2100 is account information managed for each user, and is information in which accounts for the first area, second area, and third area are associated with authority information if there is authority. Specifically, the integrated account information 2100 is information in which a management ID 2101, a first area authentication ID 2102, first area authentication information 2103, a second area authentication ID 2104, second area authentication information 2105, a third area authentication ID 2106, and third area authentication information 2107 are associated with each other.

[0194] The management ID 2101 is identification information that is assigned for the sake of convenience in order to manage each account. The management ID 2101 is identification information that is unique to each user, and therefore can also be called a user ID.

[0195] The first area authentication ID 2102 is identification information of the user in the first area.

[0196] The first area authentication information 2103 is information used for authentication when passing through a gate in the first area. When performing authentication, the first area management device 100 performs authentication by comparing the first area authentication information 2103 with the authentication information read by the reading unit.

[0197] The second area authentication ID 2104 is identification information of the user in the second area.

[0198] The second area authentication information 2105 is information used for authentication when passing through a gate in the second area. When performing authentication, the second area management device 200 performs authentication by comparing the second area authentication information 2105 with the authentication information read by the reading unit.

[0199] The third area authentication ID 2106 is identification information of the user in the third area.

[0200] The third area authentication information 2107 is information used for authentication when passing through a gate in the third area. When performing authentication, the third area management device 300 performs authentication by comparing the third area authentication information 2107 with the authentication information read by the reading unit.

[0201] The user name 2108 is information indicating the name of the user indicated by the corresponding user ID 2102 .

[0202] The email address 2109 is an email address at which the user indicated by the corresponding user ID 2102 can be contacted. The email address 2109 may be an email address provided by the administrator of the second area, or may be an email address at which the user's personal terminal can be contacted.

[0203] In the integrated account information 2100, the first area authentication ID 2102 and the first area authentication information 2103 may be configured so that they can be read and written basically only by the administrator of the first area management device 100. In addition, in the integrated account information 2100, the second area authentication ID 2104 and the second area authentication information 2105 may be configured so that they can be read and written basically only by the administrator of the second area management device 200. In addition, in the integrated account information 2100, the third area authentication ID 2106 and the third area authentication information 2107 may be configured so that they can be read and written basically only by the administrator of the third area management device 300.

[0204] In the integrated account information 2100, when an administrator of the second area management device 200 registers a new user, the administrator registers information in the second area authentication ID 2104 and the second area authentication information 2105, and also registers information in the corresponding user name 2108 and email address 2109.

[0205] Then, when the second area authentication ID 2104 and the second area authentication information 2105 are registered, the network storage 1000 may copy and register the first area authentication ID 2102 and the first area authentication information 2103 within the scope of the authority information granted by the first area management device 100 to the second area management device 200. Furthermore, when the first area authentication ID 2102 and the first area authentication information 2103 are registered, if it is determined that authentication information is to be shared between the first area and the third area, the network storage 1000 may also copy and register the third area authentication ID 2106 and the third area authentication information 2106.

[0206] In this way, the presence of the integrated account information 2100 allows for the unified management of user account information and its authority information between mutually related areas.

[0207] In the integrated account information 2100, the first area authentication ID 2102, the second area authentication ID 2104, and the third area authentication ID 2106 may use a common ID or may be the same as the user ID 2102, in which case they may not be registered in the integrated account information 2100. The first area authentication ID 2102, the second area authentication ID 2104, and the third area authentication ID 2106 may be provided when each area management device wishes to manage accounts individually. Instead of these area authentication IDs, information indicating whether a user has the right to enter (or exit) the corresponding area may be associated with each area authentication ID, and each area management device may be configured, when its reading unit reads authentication information, to determine that authentication is successful if the authentication information is associated with information indicating that the user corresponding to the authentication information has the right to enter (or exit) the area and the authentication information matches. If the area is associated with information indicating that the user does not have the right to enter (or exit) the area, it may be determined that authentication has failed for that area without checking the authentication information.

[0208] Furthermore, when a common authentication medium is used for the first area authentication information 2103, the second area authentication information 2105, and the third area authentication information 2107, only one piece of authentication information (for example, a facial image) may be registered, and each area management device may be configured to use this common single piece of authentication information during authentication. Note that this does not need to be configured to use common authentication information in all areas, and a configuration may be adopted in which one piece of authentication information is used in two or more areas, and different authentication information is used in the remaining areas.

[0209] The history information may be configured so that each area management device manages the entry / exit history for the corresponding gate, or the history information may be integrated and managed on the cloud storage 1000. In this case, the history information may be a collection of information in which information is associated with which area (area ID), which gate (gate ID), when (date and time), and who (enter / exit person ID) entered or exited. In this case, the range of history information that can be confirmed (referenced) may be determined depending on which area management device (which administrator) is accessing the cloud storage 1000. For example, when an access is from the second area management device 200, the history information provided in the cloud storage 1000 is the history information for the second area and history information associated with the authority information granted by the first area management device 100, and the history of entry and exit for, for example, the third area is not provided.

[0210] In this way, by storing one integrated account information in storage accessible to all area management devices, it is possible to make it easier to manage user account information and also to perform the same operation as described in the above embodiment, thereby reducing the workload of the administrator of the first area management device 100 and the administrator of the second area management device 200. Furthermore, by unifying the authentication information and using biometric information, not only will the authentication information not be used by others, but in the event of a problem, it will be possible to reliably determine whether the authentication information belongs to the same person, so that the user's movement route can be traced by linking the history information of the first area, second area, and third area, and improved security can also be expected.

[0211] (2) In the above embodiment, the process of step S802 may be limited to simply storing the received authority information in the storage unit 240, and then registering it in the second area account information 241 in step S806.

[0212] (3) In the above embodiment, the second area management device 200 may be configured to, when detecting the exit of a user, notify the first area management device 100 of that fact. Furthermore, the first area management device 100 may be configured to, when detecting the entry of a user, notify the second area management device 200 of that fact.

[0213] (4) In the above embodiment, the second area management device 200 requests the first area management device 100 to add authority information, but this is not limited to the above. In the first area management device 100, it is possible to check whether user information is associated with the authority information assigned to the second area 20 using the first area account information 141. Therefore, the assigning unit 151 may determine whether the number of pieces of authority information not associated with user information is equal to or less than a predetermined number, and, if it determines that the number is equal to or less than the predetermined number, automatically assign the additional authority information to the second area management device 200.

[0214] (5) In the above embodiment, when adding authority information, the second area management device 200 may inquire of the administrator whether to apply for the addition of authority information, and may be configured to make the application for the addition of authority information to the first area management device 100 if permission is obtained from the administrator. Furthermore, when adding authority information, the second area management device 200 may inquire of the administrator of the second area 20 as to the input of the number of pieces to be added.

[0215] In response to this, the first area management device 100 may also be configured to inquire of the manager of the first area 10 that there is an application for additional authority information and whether it is okay to grant additional authority information.

[0216] (6) In the above embodiment, if a fourth area exists within the second area 20 and the fourth area is managed by a fourth area management device other than the second area management device 200, the second area management device 200 may be configured to grant authority information for entering the second area 20 to the fourth area management device, similar to the first area management device 100. In this case, unlike the first area management device 100, the authority information that the second area management device 200 grants as the second area authentication ID also includes part of the authority information granted by the first area management device 100.

[0217] In this way, the relationship between the first area management device 100 and the second area management device 200 may be configured to also apply to the relationship between the second area management device 200 and the fourth area management device.

[0218] (7) In the above embodiment, the third area management device 300 is configured to transmit information about all successfully authenticated users to the first area management device 100. This configuration increases communication volume and may cause congestion in traffic between the first area management device 100 and the third area management device 300. Therefore, the third area management device 300 may be configured to transmit information about only some of the successfully authenticated users, rather than all of them. Specifically, the first area management device 100 transmits information about users in the second area 20 who use the first area 10 to the third area management device 300 in advance, and the third area management device 300 stores this information. Then, when performing authentication, the third area management device 300 may transmit information about the successfully authenticated users to the first area management device 100 only if it is determined that authentication has been performed for a user corresponding to the stored information about the second area users. The user information transmitted from the first area management device 100 to the third area management device 300 may be information about all users who use the first area 10, or may be information about specific users selected by the administrator of the first area management device 100. The user information to be transmitted may be information about users to whom the administrator of the first area management device or the like wishes to grant rewards or benefits.

[0219] (8) In the above embodiment, when an administrator of the second area registers an account for a user in the second area and grants authority information to the account, the account information in the first area is configured to be reflected. However, this may be reversed. That is, when an administrator of the first area registers an account for a user in the first area and grants authority information to the account, if it is known that the user is also a user in the second area, the account information in the second area may be configured to be reflected.

[0220] (9) In the above embodiment, when registering account information and assigning authority information to the account, the first area management device 100 may send a confirmation email to the email address stored as the account information. If it is confirmed that the confirmation email has been delivered (if the mailer daemon does not reply), the first area management device 100 may register the account information and its authority information, assuming that the user actually exists. Furthermore, if the first area management device 100 is unable to send an email to the email address, it may not register the information in the first area account information, and may even inquire of the second area management device 200 whether the registered email address is correct or whether the registered user actually exists.

[0221] (10) In the above embodiments, the account management and access control in the access control system are performed by the processor of the area management device of the access control system executing a predetermined program (management application), etc. However, this may be realized by a logic circuit (hardware) or dedicated circuit formed in an integrated circuit (IC (Integrated Circuit) chip, LSI (Large Scale Integration)) or the like in the device. Furthermore, these circuits may be realized by one or more integrated circuits, and the functions of the multiple functional units described in the above embodiments may be realized by a single integrated circuit. LSIs are sometimes referred to as VLSIs, super LSIs, ultra LSIs, etc., depending on the degree of integration.

[0222] The program may be recorded on a processor-readable recording medium, which may be a "non-transitory tangible medium" such as a tape, disk, card, semiconductor memory, or programmable logic circuit. The program may be supplied to the processor via any transmission medium capable of transmitting the program (such as a communication network or broadcast waves). That is, the program may be downloaded from a network and executed using an information processing device such as a smartphone. The present invention may also be realized in the form of a data signal embedded in a carrier wave, in which the program is embodied by electronic transmission.

[0223] The above program can be implemented using, for example, scripting languages ​​such as ActionScript and JavaScript (registered trademark), or object-oriented programming languages ​​such as Objective-C, Java (registered trademark), C++, Python, and R, but these languages ​​are just examples.

[0224] (11) The various examples shown in the above embodiments may be combined as appropriate. [Explanation of symbols]

[0225] 1. Access control system 100 First area control device 110 Communications Department 120 Input section 121 First area reading unit Gate 122 130 Output section 140 Storage section 141 Area 1 Account Information 142 Area 1 History Information 150 control section 151 Granting Department 152 Registration Department 153 Area 1 Authentication Department 154 1st provision part 200 Second area control device 210 Communications Department 220 Input section 221 Second area reading unit Gate 222 230 Output section 240 Storage section 241 Area 2 Account Information 242 Area 2 History Information 250 control section 251 Reception Department 252 Generation part 253 Allocation Section 254 Registration Department 255 Second Area Authentication Department 256 2nd provision part 300 Third area control device 310 Communications Department 320 Input section 321 Third area reading unit 330 Output section 340 Storage section 341 Third Area Account Information 342 Area 3 History Information 350 control section 351 Third Area Authentication Department 352 Notification Department 353 Reward Division

Claims

1. an assigning unit that assigns a predetermined number of pieces of authority information for entering a first area, the authority information including information on a first area authentication medium used by the user to enter the first area, to a manager of a second area included in the first area; a reception unit that receives input of authentication information of a user of the second area; a generation unit that generates an account for the user in the second area based on authentication information of the user; an allocation unit that allocates one of the predetermined number of pieces of authority information to the user account generated by the generation unit; a registration unit that registers the account, including information on a second area authentication medium used by the user to enter the second area, in an account database; a second area reading unit that reads second area medium information when entering the second area; a second area authentication unit that authenticates the second area medium information read by the second area reading unit based on whether the second area medium information is registered in the account database; a first area reading unit that reads first area medium information when entering the first area; a first area authentication unit that authenticates the first area medium information read by the first area reading unit based on whether the first area medium information is registered in the account database; Equipped with the second area authentication medium is biometric information of the user, The registration unit registers biometric information of a user registered as the second area authentication medium as the first area authentication medium. Access control system.

2. a first storage unit configured to store first area history information that is recorded in response to authentication by the first area authentication unit and indicates a history of users entering and exiting the first area; a first providing unit that provides the first area history information to a manager of the second area within the scope of authority information granted to the second area. The entrance / exit management system according to claim 1 .

3. a second storage unit configured to store second area history information that is recorded in response to authentication by the second area authentication unit and indicates a history of users entering and exiting the second area; a second providing unit that provides the second area history information to a manager of the second area; Equipped with 3. The entrance / exit management system according to claim 1 or 2.

4. a determination unit that determines whether a remainder obtained by subtracting the number of pieces of authority information assigned by the assignment unit from the predetermined number is equal to or less than a predetermined threshold; a request unit that requests an increase of the predetermined number from a manager of the first area when the determination unit determines that the remaining number is equal to or less than the predetermined threshold, The access control system according to claim 1 , wherein the granting unit grants additional authority information to the manager of the second area.

5. The computer in the access control system a granting step of granting a predetermined number of pieces of authority information for entering a first area, the authority information including information on a first area authentication medium used by the user to enter the first area, to an administrator of a second area included in the first area; a receiving step of receiving input of authentication information of the user of the second area; creating an account for the user in the second area based on authentication information of the user; an allocating step of allocating one of the predetermined number of pieces of authority information to the user account generated in the generating step; a registration step of registering the account including information of a second area authentication medium used by the user to enter the second area in an account database; a second area reading step of reading second area medium information when entering the second area; a second area authentication step of authenticating the second area medium information read in the second area reading step based on whether the second area medium information is registered in the account database; a first area reading step of reading first area medium information when entering the first area; a first area authentication step of authenticating the first area medium information read in the first area reading step based on whether the first area medium information is registered in the account database; Run the second area authentication medium is biometric information of the user, The registration step includes registering biometric information of a user registered as the second area authentication medium as the first area authentication medium. Entrance / exit management method.

Citation Information

Patent Citations

  • Entry control device and entry control method

    JP2022084586A